feat(14-04): fetchguard.IsPrivateAddr exposes the dial guard's address classification

The golem SSRF guard checks a URL's resolved addresses before it connects,
as PHP's SSRFGuard does, with the same table the dial guard uses.
This commit is contained in:
Jakub Zych
2026-10-03 22:49:19 +02:00
parent f519261da6
commit 7c2c43359f
5 changed files with 55 additions and 0 deletions

View File

@@ -61,6 +61,18 @@ fmt.Println(fetchguard.Defaults())
// 10485760 10s
```
Code that has to judge a resolved address itself, before it connects, uses the same classification through `fetchguard.IsPrivateAddr`:
```go src=modules/fetchguard/example_test.go#ExampleIsPrivateAddr
for _, ip := range []string{"8.8.8.8", "10.0.0.7", "::ffff:127.0.0.1"} {
fmt.Println(ip, fetchguard.IsPrivateAddr(netip.MustParseAddr(ip)))
}
// Output:
// 8.8.8.8 false
// 10.0.0.7 true
// ::ffff:127.0.0.1 true
```
A failure is always a `fetchguard.Error` with one `fetchguard.Reason` from a closed set, so a handler can map it to a stable API error code. A host outside the allow list is reported as `invalid_url`, as the example shows.
## Responses and limits