django-xff
Django X-Forwarded-For Properly
Decision gist · record as of 2026-08-14
Yes, if you run Django behind one or more reverse proxies and need reliable client IP extraction. The middleware is straightforward to configure and has no external dependencies beyond Django. However, maintenance is dormant (last release 547 days ago); verify that it works with your specific Django and Python versions before relying on it in production, and monitor the repository for any security issues or compatibility breaks.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Django must be installed and configured; the middleware must be placed early in MIDDLEWARE_CLASSES to prevent malicious requests from reaching authentication layers.
- Low friction: pure Python wheel with only Django as a runtime dependency.
- Dormant maintenance (last release 547 days ago, last commit 2025-02-13) but repository is not archived and supports Django 4.2, 5.0, and 5.1.
License · maintenance · safety
MIT License (permissive) — MIT License (permissive) — you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.
last release 2025-02-13 (547 days) · last repo commit 2025-02-13 · 17 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 93,650 downloads/mo, #13,374 on PyPI
Alternatives
Verify before relying
# settings.py
MIDDLEWARE_CLASSES = [
'xff.middleware.XForwardedForMiddleware',
]
XFF_TRUSTED_PROXY_DEPTH = 2
# request.META['REMOTE_ADDR'] will now contain the real client IP- Whether the package works correctly with Django versions beyond 5.1 or with modern Python versions (requires_python is unspecified).
- Real-world effectiveness of spoofing detection modes (XFF_NO_SPOOFING, XFF_STRICT) against current attack patterns.
- Whether the 17 GitHub stars and dormant status indicate sufficient community adoption or testing for production use.
What it is and what it does
django-xff is middleware that solves a common problem in reverse-proxy deployments: extracting the real client IP address from the X-Forwarded-For header. When requests pass through one or more reverse proxies (load balancers, CDNs, etc.), the original client IP gets buried in a comma-separated list of addresses. A malicious client can prepend fake IPs to this header to spoof their origin, potentially bypassing IP-based security checks or rate limiting.
The middleware works by trusting a fixed depth of proxies—you tell it how many proxies sit between the client and your Django app, and it extracts the IP at the correct position in the chain. It can optionally sanitize the header, validate that the expected number of proxies are present, and reject requests that fail validation. Configuration is entirely through Django settings, with modes ranging from permissive (do nothing if the header is missing) to strict (reject any request that doesn't match the expected proxy depth).
Use it for
- Running Django behind an AWS Elastic Load Balancer or similar managed proxy where you need accurate client IPs for logging and analytics.
- Implementing IP-based rate limiting or geographic restrictions when requests arrive through a CDN or reverse proxy.
- Rejecting spoofed X-Forwarded-For headers in strict security configurations to prevent attackers from bypassing IP-based access controls.
- Exempting specific URLs (health checks, admin endpoints) from X-Forwarded-For validation while enforcing it elsewhere.
- Debugging request chains by cleaning up the X-Forwarded-For header to remove extraneous entries added by misconfigured proxies.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you run Django behind one or more reverse proxies and need reliable client IP extraction.
The middleware is straightforward to configure and has no external dependencies beyond Django. However, maintenance is dormant (last release 547 days ago); verify that it works with your specific Django and Python versions before relying on it in production, and monitor the repository for any security issues or compatibility breaks.
Install
django-xff on PyPI
Before you install
Low friction: pure Python wheel with only Django as a runtime dependency. Dormant maintenance (last release 547 days ago, last commit 2025-02-13) but repository is not archived and supports Django 4.2, 5.0, and 5.1.
Django must be installed and configured; the middleware must be placed early in MIDDLEWARE_CLASSES to prevent malicious requests from reaching authentication layers.
License in practice
MIT License (permissive) — you can use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.
Quickstart
# settings.py
MIDDLEWARE_CLASSES = [
'xff.middleware.XForwardedForMiddleware',
]
XFF_TRUSTED_PROXY_DEPTH = 2
# request.META['REMOTE_ADDR'] will now contain the real client IP
Verify before relying
- Whether the package works correctly with Django versions beyond 5.1 or with modern Python versions (requires_python is unspecified).
- Real-world effectiveness of spoofing detection modes (XFF_NO_SPOOFING, XFF_STRICT) against current attack patterns.
- Whether the 17 GitHub stars and dormant status indicate sufficient community adoption or testing for production use.
Package facts
| License | MIT License permissive |
| Python support | Not specified |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packageDjango |
| Maintenance | Dormant 547 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 93,650 / month, #13,374 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Environment :: Web EnvironmentFramework :: DjangoFramework :: Django :: 4.2Framework :: Django :: 5.0Framework :: Django :: 5.1Intended Audience :: DevelopersLicense :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: PythonTopic :: Internet :: WWW/HTTPTopic :: Internet :: WWW/HTTP :: Dynamic Content |
Evidence: django_xff-1.5.0-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “django x-forwarded-for header”
- django-xffDjango middleware that extracts the real client IP address from the…
- django-ipwareRetrieves the client's IP address from a Django request object,…
- python-ipwareExtracts a client's IP address from web request headers, handling…
Give your agent the search over MCP, or paste the wish link into any chat.
More WWW/HTTP packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
h11 is a pure-Python HTTP/1.1 protocol implementation that handles parsing and serializing HTTP messages without any built-in I/O, letting you integrate it with any network layer you choose.
HTTPX is a fully featured HTTP client library for Python that provides both sync and async APIs, with support for HTTP/1.1 and HTTP/2, plus an integrated command-line client.
Install it if you are building new projects or modernizing existing ones that rely on HTTP.
A minimal low-level HTTP client library that sends HTTP requests with thread-safe and task-safe connection pooling, supporting HTTP/1.1, HTTP/2, proxies, and both sync and async interfaces.
aiohttp is an async HTTP client and server framework built on asyncio, supporting both WebSockets and middleware-based routing for building concurrent web applications.
Install it if you need async HTTP client or server capabilities in asyncio-based applications.
See also django-ipware · django-revproxy · python-ipware · django-ebhealthcheck · django-allow-cidr · proxy-protocol · vercel-headers · requests-hardened · django-defender · xclienttransaction