Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

The OSB Calling service may display an Unauthorized message when using the X-FORWARDED-FOR header because the header can be easily spoofed or manipulated. The X-FORWARDED-FOR header is typically used to indicate the client IP address when a request passes through one or more proxies or load balancers. However, an attacker can easily modify or inject a fake IP address in the header to bypass authentication and authorization checks. Therefore, the OSB Calling service may reject a request with an X-FORWARDED-FOR header for security reasons.