Skip to Content
Menu
This question has been flagged
2 Replies
4016 Views

Hi,

I have Odoo 18 (using source) running behind Nginx successfully. For some reasons, the odoo logs do not show the real IP address for users. Nginx is configured to forward the IP (X-Forwarded-For) to backend and odoo config has proxy_mode set to true. I have done some searching on the Internet already and couldn't find anything in particular that may fix this issue.

Odoo log entry:

2025-05-01 03:39:19,437 4086 INFO odoo odoo.addons.base.models.res_users: Login failed for db:odoo login:oodf from 127.0.0.1

I am providing the nginx and odoo config files below as well below.

Nginx config

# Odoo servers
geo $limit {
  default 1;
  1.2.3.4/22 0;
  1.2.3.4/24 0;
  1.2.3.4/24 0;
  1.2.3.4/24 0;
  1.2.3.4/20 0;
}

map $limit $limit_key {
        0 "";
        1 $binary_remote_addr;
}

limit_req_zone $limit_key zone=general:10m rate=200r/m;

upstream odoo {
server 127.0.0.1:8069;
}

upstream odoochat {
server 127.0.0.1:8072;
}

map $http_upgrade $connection_upgrade {
  default upgrade;
  ''      close;
}

# HTTP -> HTTPS
server {
  listen 80;
  server_name mywebsite.example.com;
  include snippets/letsencrypt.conf;
  return 301 https://mywebsite.example.com$request_uri;
}
# WWW -> NON WWW
server {
    listen 443 ssl http2;
    server_name www.mywebsite.example.com;
    ssl_certificate /etc/letsencrypt/live/mywebsite.example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/mywebsite.example.com/privkey.pem;
    ssl_trusted_certificate /etc/letsencrypt/live/mywebsite.example.com/chain.pem;
    include snippets/ssl.conf;
    include snippets/letsencrypt.conf;

    return 301 https://mywebsite.example.com$request_uri;
}

server {
    listen 443 ssl http2;
    server_name mywebsite.example.com;
    proxy_read_timeout 720s;
    proxy_connect_timeout 720s;
    proxy_send_timeout 720s;

    # Proxy headers
    proxy_set_header X-Forwarded-Host $host;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_set_header X-Real-IP $remote_addr;

    # SSL parameters
    ssl_certificate /etc/letsencrypt/live/mywebsite.example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/mywebsite.example.com/privkey.pem;
    ssl_trusted_certificate /etc/letsencrypt/live/mywebsite.example.com/chain.pem;
    include snippets/ssl.conf;
    include snippets/letsencrypt.conf;


    # Increase client_max_body_size to your required ammount
    client_max_body_size 20M;

    # log files
    access_log /var/log/nginx/odoo.access.log;
    error_log /var/log/nginx/odoo.error.log;

    # Redirect websocket requests to odoo gevent port
    location /websocket {
    proxy_pass http://odoochat;
    proxy_set_header Upgrade $http_upgrade;
    proxy_set_header Connection $connection_upgrade;
    proxy_set_header X-Forwarded-Host $http_host;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_set_header X-Real-IP $remote_addr;
    add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
    proxy_cookie_flags session_id samesite=lax secure;
    proxy_redirect off;
  }

  # Handle longpoll requests
    location /longpolling {
        proxy_pass http://odoochat;
    }

    # Redirect requests to odoo backend server
    location / {
            # Add Headers for odoo proxy mode

            limit_req zone=general burst=50 nodelay;
            proxy_set_header X-Forwarded-Host $http_host;
            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
            proxy_set_header X-Forwarded-Proto $scheme;
            proxy_set_header X-Real-IP $remote_addr;
            proxy_redirect off;
            proxy_pass http://odoo;

            # Enable HSTS
            add_header Strict-Transport-Security "max-age=31536000; includeSubDomains";
            # requires nginx 1.19.8
            proxy_cookie_flags session_id samesite=lax secure;
    }

    # Cache static files
    location ~*/web/static/ {
        limit_req zone=general;
        proxy_set_header X-Forwarded-Host $http_host;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_cache_valid 200 90m;
        proxy_buffering on;
        expires 864000;
        proxy_pass http://odoo;
        #add_header Content-Security-Policy $content_type_csp;
    }

    # Gzip
    gzip_types text/css text/less text/plain text/xml application/xml application/json application/javascript;
    gzip on;
}

Odoo Config file

[DEFAULT]
admin_passwd = abcdefghijklmn
db_host = False
db_port = False
db_user = odoo
db_password = False
addons_path = /opt/odoo/odoo/addons,/opt/odoo/odoo-custom-addons
proxy_mode = true
list_db = False

Does anyone have any ideas as to what could the problem be?


Thanks,

Mohammad

Avatar
Discard
Author Best Answer

Thanks for the suggestion. 

Unfortunately, changing "true" to "True" in the odoo config made no difference. Yes, I restarted the services as mentioned. Just  to be sure, I also rebooted the server after making the changes but odoo log is still showing 127.0.0.1

[DEFAULT]
admin_passwd = xxxxxxxxxxxx
db_host = False
db_port = False
db_user = odoo
db_password = False
addons_path = /opt/odoo/odoo/addons,/opt/odoo/odoo-custom-addons
proxy_mode = True
list_db = False

2025-05-03 10:13:23,229 1536 INFO odoo werkzeug: 127.0.0.1 - - [03/May/2025 10:13:23] "POST /web/login HTTP/1.0" 200 - 6 0.010 0.008
2025-05-03 10:13:23,369 1536 INFO odoo werkzeug: 127.0.0.1 - - [03/May/2025 10:13:23] "GET /web/binary/company_logo HTTP/1.0" 304 - 2 0.001 0.002
2025-05-03 10:13:23,728 1536 INFO odoo werkzeug: 127.0.0.1 - - [03/May/2025 10:13:23] "GET /web/webclient/translations/1746267203712 HTTP/1.0" 200 - 2 0.001 0.002
Avatar
Discard
Best Answer

Hi, 
Shouldn't "proxy_mode = true" instead of "proxy_mode = True"?
Try restarting the service after the fix.

Summary of Steps:

  1. Ensure proxy_mode = True is under the [options] section in odoo.conf.
  2. Restart the Odoo service (sudo systemctl restart odoo).
  3. Verify Nginx configuration (sudo nginx -t).
  4. Reload the Nginx service (sudo systemctl reload nginx).
  5. Check Nginx access logs to confirm it sees the real client IP.
  6. Try logging into Odoo again and check the Odoo logs.

Avatar
Discard

Hi, How about using the `set_real_ip_from` directive to solve this?
Here's the documentation:
https://nginx.org/en/docs/http/ngx_http_realip_module.html#set_real_ip_from

Best regards,

Related Posts Replies Views Activity
2
Sep 24
3334
0
Jul 24
1400
1
May 24
4346
2
May 24
15677
1
Jul 23
5307