feat(14-04): fetchguard.IsPrivateAddr exposes the dial guard's address classification

The golem SSRF guard checks a URL's resolved addresses before it connects,
as PHP's SSRFGuard does, with the same table the dial guard uses.
This commit is contained in:
Jakub Zych
2026-10-03 22:49:19 +02:00
parent f519261da6
commit 7c2c43359f
5 changed files with 55 additions and 0 deletions

View File

@@ -6,6 +6,7 @@ import (
"fmt"
"io"
"net/http"
"net/netip"
"strings"
"time"
@@ -94,3 +95,13 @@ func ExampleClient_PostJSON() {
// Output:
// 201 {"id":42}
}
func ExampleIsPrivateAddr() {
for _, ip := range []string{"8.8.8.8", "10.0.0.7", "::ffff:127.0.0.1"} {
fmt.Println(ip, fetchguard.IsPrivateAddr(netip.MustParseAddr(ip)))
}
// Output:
// 8.8.8.8 false
// 10.0.0.7 true
// ::ffff:127.0.0.1 true
}