identity_header_guard
Captures request headers matching a configured prefix into filter_metadata and removes them from the upstream request.
On this page
Captures request headers matching a configured prefix into filter_metadata and removes them from the upstream request.
Configuration Notes
A client that sets x-tenant-username: admin directly is indistinguishable from a gateway that set it legitimately unless this filter strips the headers first. Place it early in the pipeline — before any filter that reads identity from request headers.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
prefix | string | yes | Case-insensitive header name prefix to capture and strip. |
metadata_namespace | string | no | Metadata namespace for captured headers. Headers are stored as {namespace}.{header_name}. |
Example
filter: identity_header_guard
prefix: "x-tenant-"
metadata_namespace: "identity"