Attempt to spoof header (Shib-Cookie-Name) was detected

Cantor, Scott cantor.2 at osu.edu
Tue Oct 4 12:02:20 EDT 2016


> Of course, disabling protection from cookie theft is very bad idea and should
> be avoided.An other solution would be to have a list of exceptions like
> 127.0.0.1. So is there any way to do that, or is it not developed yet?

If you're proxying you should pass the client address in a header, and then it can pick that header up via the REMOTE_ADDR setting.

-- Scott



More information about the users mailing list