feat(14-04): fetchguard.IsPrivateAddr exposes the dial guard's address classification
The golem SSRF guard checks a URL's resolved addresses before it connects, as PHP's SSRFGuard does, with the same table the dial guard uses.
This commit is contained in:
@@ -6,6 +6,7 @@ import (
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/netip"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
@@ -94,3 +95,13 @@ func ExampleClient_PostJSON() {
|
||||
// Output:
|
||||
// 201 {"id":42}
|
||||
}
|
||||
|
||||
func ExampleIsPrivateAddr() {
|
||||
for _, ip := range []string{"8.8.8.8", "10.0.0.7", "::ffff:127.0.0.1"} {
|
||||
fmt.Println(ip, fetchguard.IsPrivateAddr(netip.MustParseAddr(ip)))
|
||||
}
|
||||
// Output:
|
||||
// 8.8.8.8 false
|
||||
// 10.0.0.7 true
|
||||
// ::ffff:127.0.0.1 true
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user