feat(14-04): fetchguard.IsPrivateAddr exposes the dial guard's address classification
The golem SSRF guard checks a URL's resolved addresses before it connects, as PHP's SSRFGuard does, with the same table the dial guard uses.
This commit is contained in:
@@ -61,6 +61,18 @@ fmt.Println(fetchguard.Defaults())
|
||||
// 10485760 10s
|
||||
```
|
||||
|
||||
Code that has to judge a resolved address itself, before it connects, uses the same classification through `fetchguard.IsPrivateAddr`:
|
||||
|
||||
```go src=modules/fetchguard/example_test.go#ExampleIsPrivateAddr
|
||||
for _, ip := range []string{"8.8.8.8", "10.0.0.7", "::ffff:127.0.0.1"} {
|
||||
fmt.Println(ip, fetchguard.IsPrivateAddr(netip.MustParseAddr(ip)))
|
||||
}
|
||||
// Output:
|
||||
// 8.8.8.8 false
|
||||
// 10.0.0.7 true
|
||||
// ::ffff:127.0.0.1 true
|
||||
```
|
||||
|
||||
A failure is always a `fetchguard.Error` with one `fetchguard.Reason` from a closed set, so a handler can map it to a stable API error code. A host outside the allow list is reported as `invalid_url`, as the example shows.
|
||||
|
||||
## Responses and limits
|
||||
|
||||
Reference in New Issue
Block a user