feat(core): 리버스 프록시 신뢰 설정 지원 및 미설정 진단

TLS 가 앞단에서 종단되고 앱에는 HTTP 로 전달되는 구성에서 X-Forwarded-* 가 전부
무시되어 화면 백지·IP 왜곡·webhook 403 이 함께 발생했다. 코어에 신뢰 프록시 설정
지점이 아예 없던 것이 원인이다.

- config/trustedproxy.php 로 내장 TrustProxies 미들웨어에 값을 공급한다.
 bootstrap/app.php 는 건드리지 않는다 — withMiddleware 클로저는 .env 로드 전에
 평가되어 env 가 항상 null 이 되는 조용한 no-op 이다.
- 판정은 App\Support\TrustedProxyDiagnostic 단일 SSoT 에서 계산하고 대시보드
 알림·환경설정 고급 탭·설치 마법사·trusted-proxy:status 네 면이 소비한다.
 판정식은 "HTTPS 인식 실패" 가 아니라 "X-Forwarded-* 수신 중 AND 신뢰 프록시
 미설정" 이다 — HTTP 전용 사이트가 프록시 뒤에 있으면 화면은 정상인 채로
 나머지만 조용히 어긋나기 때문이다.
- 값 편집 UI 와 쓰기 엔드포인트는 두지 않는다(잠금 역설 + XFF 위조 경로).
- 혼합 콘텐츠 차단을 부트스트랩 폴백의 별도 사유로 가른다. 새로고침으로 낫지
 않으므로 버튼을 렌더하지 않고, 원인·조치는 콘솔로 운영자에게 보낸다.
- 대시보드 알림을 심각도로 배치한다 — warning 은 상단 배너, 그 외는 하단 카드.
 같은 알림이 두 곳에 뜨지 않으며, 여러 건은 간격을 두고 쌓인다.

공개 이슈: (@lyg-kaban 제보)
This commit is contained in:
HeuJung
2026-08-28 18:09:27 +09:00
parent 46ada4dddb
commit b6c5e1f323
55 changed files with 2861 additions and 38 deletions
+54 -3
View File
@@ -504,6 +504,13 @@ class ValidationApi
/**
* HTTPS 사용 여부 확인
*
* 이 검사는 저장소에서 유일하게 X-Forwarded-Proto 를 실제로 읽는 지점이었다. 그래서
* 설치 마법사는 "HTTPS 정상" 이라고 보고하는데 그 직후 앱은 http:// 절대 URL 을 만드는
* 비대칭이 있었다 — 운영자 입장에서 원인 추적이 사실상 불가능한 조합이다 (#124).
*
* 프록시 헤더가 감지되면 신뢰 프록시 설정이 필요하다는 안내를 결과에 덧붙인다.
* 설치를 차단하지는 않는다 (HTTPS 항목이 `required = false` 인 기존 정책과 동일).
*/
private function checkHttps(): array
{
@@ -514,15 +521,59 @@ class ValidationApi
$isHttps = strtolower($_SERVER['HTTP_X_FORWARDED_PROTO']) === 'https';
}
$forwardedHeaders = $this->detectForwardedHeaders();
$behindProxy = $forwardedHeaders !== [];
$message = $isHttps
? lang('https_enabled')
: lang('https_disabled');
// HTTP 전용 사이트가 프록시 뒤에 있는 구성도 대상이다 — 화면은 정상 렌더되지만
// 방문자 IP·결제 통보 수신은 그대로 어긋난다. HTTPS 여부로 가르지 않는다.
if ($behindProxy) {
$message .= ' '.lang('https_behind_proxy');
}
return [
'required' => false, // HTTPS는 선택 사항
'enabled' => $isHttps,
'message' => $isHttps
? lang('https_enabled')
: lang('https_disabled'),
'behind_proxy' => $behindProxy,
'forwarded_headers' => $forwardedHeaders,
'message' => $message,
];
}
/**
* 수신 중인 X-Forwarded-* 계열 헤더 이름 목록을 반환합니다 (#124).
*
* 설치 마법사는 순수 PHP 영역이라 Laravel 헬퍼를 쓸 수 없다. 목록은
* App\Support\TrustedProxyDiagnostic::FORWARDED_HEADERS 와 같은 집합을 유지한다.
*
* @return array<int, string> 수신 중인 헤더 이름 목록
*/
private function detectForwardedHeaders(): array
{
$headers = [
'X-Forwarded-For' => 'HTTP_X_FORWARDED_FOR',
'X-Forwarded-Proto' => 'HTTP_X_FORWARDED_PROTO',
'X-Forwarded-Host' => 'HTTP_X_FORWARDED_HOST',
'X-Forwarded-Port' => 'HTTP_X_FORWARDED_PORT',
'X-Forwarded-Prefix' => 'HTTP_X_FORWARDED_PREFIX',
'X-Forwarded-Aws-Elb' => 'HTTP_X_FORWARDED_AWS_ELB',
'Forwarded' => 'HTTP_FORWARDED',
];
$present = [];
foreach ($headers as $name => $serverKey) {
if (isset($_SERVER[$serverKey])) {
$present[] = $name;
}
}
return $present;
}
/**
* OPcache 활성화 여부 검증 (권장 사항 — 설치를 차단하지 않음)
*
+1
View File
@@ -235,6 +235,7 @@ return [
// HTTPS Messages
'https_enabled' => 'HTTPS is enabled (recommended)',
'https_disabled' => 'HTTPS is disabled. We recommend using HTTPS for security.',
'https_behind_proxy' => 'This site appears to be running behind a reverse proxy. Unless TRUSTED_PROXIES is set in .env after installation, the site address and visitor IP will be recognized from the proxy instead of the real visitor. (https://github.com/gnuboard/g7/blob/main/docs/backend/reverse-proxy.md)',
// OPcache Messages
'opcache_enabled' => 'OPcache is enabled (recommended)',
+1
View File
@@ -235,6 +235,7 @@ return [
// HTTPS 메시지
'https_enabled' => 'HTTPS가 활성화되어 있습니다. (권장)',
'https_disabled' => 'HTTPS가 비활성화되어 있습니다. 보안을 위해 HTTPS 사용을 권장합니다.',
'https_behind_proxy' => '리버스 프록시 뒤에서 구동 중인 것으로 보입니다. 설치 후 .env 에 TRUSTED_PROXIES 를 지정하지 않으면 접속 주소와 방문자 IP 가 프록시 기준으로 인식됩니다. (https://github.com/gnuboard/g7/blob/main/docs/backend/reverse-proxy.md)',
// OPcache 메시지
'opcache_enabled' => 'OPcache가 활성화되어 있습니다. (권장)',