Files
spring-boot/documentation/spring-boot-docs
Brian Clozel 7a6d92cbff Document security considerations for forwarded headers
This commit highlights that while "forwarded headers" support is enabled
automatically for cloud platforms, we generally assume that apps are
behind trusted HTTP proxies.

If this is not the case, app developers should disable this feature if
they choose to expose the application to direct Internet traffic.

Closes gh-49507
2026-03-09 09:41:11 +01:00
..