feat(14-04): fetchguard.IsPrivateAddr exposes the dial guard's address classification

The golem SSRF guard checks a URL's resolved addresses before it connects,
as PHP's SSRFGuard does, with the same table the dial guard uses.
This commit is contained in:
Jakub Zych
2026-10-03 22:49:19 +02:00
parent f519261da6
commit 7c2c43359f
5 changed files with 55 additions and 0 deletions

View File

@@ -32,6 +32,16 @@ var (
sixToFourPrefix = netip.MustParsePrefix("2002::/16")
)
// IsPrivateAddr reports whether addr is not a public address: private,
// loopback, link-local, carrier-grade NAT, documentation, multicast,
// unspecified or another reserved IPv4 or IPv6 range, including IPv4
// embedded in NAT64 and 6to4 addresses. An invalid address counts as
// private. It is the classification the dial guard applies, for callers
// that check a resolved address before they connect.
func IsPrivateAddr(addr netip.Addr) bool {
return isReservedOrPrivate(addr)
}
// isReservedOrPrivate classifies addr against the PHP private/loopback/
// reserved/CGNAT table, including IPv4 embedded in supported IPv6 transition
// formats.