Skip to main content

wsgi_cloudflare_proxy_fix is a WSGI middleware that safely sets the REMOTE_ADDR environment variable to the value of the Cf-Connecting-Ip header for requests originating from Cloudflare.

In addition, it sets a CF_TRUSTED environment variable to True for all requests originating from Cloudflare.

Installation

Install wsgi_cloudflare_proxy_fix using pip:

pip install wsgi_cloudflare_proxy_fix

Usage

The following examples assume werkzeug.middleware.proxy_fix.ProxyFix is being used to read the X-Forwarded-For and X-Forwarded-Proto headers.

For a standalone WSGI application:

import logging
from wsgi_cloudflare_proxy_fix import CloudflareProxyFix
from werkzeug.middleware.proxy_fix import ProxyFix

application = CloudflareProxyFix(application, log_level=logging.INFO)
application = ProxyFix(application)

For a Flask application:

import logging
from wsgi_cloudflare_proxy_fix import CloudflareProxyFix
from werkzeug.middleware.proxy_fix import ProxyFix

def create_app():
    app = Flask(__name__)
    app.wsgi_app = CloudflareProxyFix(app.wsgi_app, log_level=logging.INFO)
    app.wsgi_app = ProxyFix(app.wsgi_app)
    return app

Testing

To verify the proxy fix is working as expected in your production environment, the CloudflareProxyFixTest middleware can be used by adding the following to your application:

import logging
from wsgi_cloudflare_proxy_fix import CloudflareProxyFix, CloudflareProxyFixTest
from werkzeug.middleware.proxy_fix import ProxyFix

def create_app():
    app = Flask(__name__)
    app.wsig_app = CloudflareProxyFixTest(app.wsgi_app, path="/debug/cf-test")
    app.wsgi_app = CloudflareProxyFix(app.wsgi_app, log_level=logging.INFO)
    app.wsgi_app = ProxyFix(app.wsgi_app)
    return app

And making a request to the debug/cf-test endpoint:

$ curl http://localhost:5000/debug/cf-test
{
    "CF_TRUSTED": null,
    "REMOTE_ADDR": "127.0.0.1"
    "wsgi_cloudflare_proxy_fix.orig": null,
}
$ curl -H 'X-Forwarded-For: 103.31.4.1' -H 'Cf-Connecting-Ip: 1.2.3.4' http://localhost:5000/debug/cf-test
{
    "CF_TRUSTED": true,
    "REMOTE_ADDR": "1.2.3.4",
    "wsgi_cloudflare_proxy_fix.orig": {
        "REMOTE_ADDR": "103.31.4.1"
    }
}

Metadata

Release files for wsgi-cloudflare-proxy-fix 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for wsgi-cloudflare-proxy-fix 0.1.2
File Size Uploaded
wsgi_cloudflare_proxy_fix-0.1.2.tar.gz 3.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for wsgi-cloudflare-proxy-fix 0.1.2
File Interpreter ABI Platform
wsgi_cloudflare_proxy_fix-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 7.0 kB

Release files / wsgi_cloudflare_proxy_fix-0.1.2.tar.gz

Download URL wsgi_cloudflare_proxy_fix-0.1.2.tar.gz
Size 3.2 kB
Tags Source
SHA-256 checksum
How to use checksums
4599087b5a0a7162e1a29a62235aedc35b2a95ada9c05f21fa67a2de41774daa
BLAKE2b-256 checksum
How to use checksums
6cb3fd2281a91ffe55a69e74aa4b71d031c238059800b3307a8f21184b13b00c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.4.1 CPython/3.9.12 Darwin/21.6.0

Release files / wsgi_cloudflare_proxy_fix-0.1.2-py3-none-any.whl

Download URL wsgi_cloudflare_proxy_fix-0.1.2-py3-none-any.whl
Size 3.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
801b5585845c3f69033198c231a9234a82fd3a67bfa7bccc7b2221887bfb8c4c
BLAKE2b-256 checksum
How to use checksums
fe2bedf1c3be586d26a152d7c36ad1281d3a974a0be07bc74b0a01c7be54c01b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.4.1 CPython/3.9.12 Darwin/21.6.0

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page