feat(14-04): fetchguard.IsPrivateAddr exposes the dial guard's address classification

The golem SSRF guard checks a URL's resolved addresses before it connects,
as PHP's SSRFGuard does, with the same table the dial guard uses.
This commit is contained in:
Jakub Zych
2026-10-03 22:49:19 +02:00
parent f519261da6
commit 7c2c43359f
5 changed files with 55 additions and 0 deletions

View File

@@ -176,3 +176,23 @@ func TestIsReservedOrPrivateIgnoresZone(t *testing.T) {
}
}
}
func TestIsPrivateAddr(t *testing.T) {
for ip, want := range map[string]bool{
"127.0.0.1": true,
"169.254.169.254": true,
"10.1.2.3": true,
"::1": true,
"fd12:3456:789a::1": true,
"64:ff9b::a00:1": true,
"8.8.8.8": false,
"2001:4860:4860::8888": false,
} {
if got := IsPrivateAddr(netip.MustParseAddr(ip)); got != want {
t.Errorf("IsPrivateAddr(%s) = %v, want %v", ip, got, want)
}
}
if !IsPrivateAddr(netip.Addr{}) {
t.Error("an invalid address must count as private")
}
}