feat(14-04): fetchguard.IsPrivateAddr exposes the dial guard's address classification
The golem SSRF guard checks a URL's resolved addresses before it connects, as PHP's SSRFGuard does, with the same table the dial guard uses.
This commit is contained in:
@@ -32,6 +32,16 @@ var (
|
||||
sixToFourPrefix = netip.MustParsePrefix("2002::/16")
|
||||
)
|
||||
|
||||
// IsPrivateAddr reports whether addr is not a public address: private,
|
||||
// loopback, link-local, carrier-grade NAT, documentation, multicast,
|
||||
// unspecified or another reserved IPv4 or IPv6 range, including IPv4
|
||||
// embedded in NAT64 and 6to4 addresses. An invalid address counts as
|
||||
// private. It is the classification the dial guard applies, for callers
|
||||
// that check a resolved address before they connect.
|
||||
func IsPrivateAddr(addr netip.Addr) bool {
|
||||
return isReservedOrPrivate(addr)
|
||||
}
|
||||
|
||||
// isReservedOrPrivate classifies addr against the PHP private/loopback/
|
||||
// reserved/CGNAT table, including IPv4 embedded in supported IPv6 transition
|
||||
// formats.
|
||||
|
||||
Reference in New Issue
Block a user