Does Fusion Apps (HCM, ERP) honour the X-Forward-For (XFF) HTTP header for client IP decisions?
Summary:
Does Fusion Applications (HCM or ERP) honour the X-Forward-For (XFF) HTTP request header for client IP decisions like environment IP "allowlisting" or LBAC?
Content (please ensure you mask any confidential information):
It is common for end users to access web user interfaces on cloud based SaaS services through web proxies. The XFF HTTP request header stores both the original client IP and any web proxy IPs the HTTP request has traversed through. Fusion Applications makes decisions on client IP, so which client IP does it use? Original end user client IP, or latest web proxy IP?
Version (include the version you are using, if applicable):