feat(14-04): fetchguard.IsPrivateAddr exposes the dial guard's address classification
The golem SSRF guard checks a URL's resolved addresses before it connects, as PHP's SSRFGuard does, with the same table the dial guard uses.
This commit is contained in:
@@ -176,3 +176,23 @@ func TestIsReservedOrPrivateIgnoresZone(t *testing.T) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestIsPrivateAddr(t *testing.T) {
|
||||
for ip, want := range map[string]bool{
|
||||
"127.0.0.1": true,
|
||||
"169.254.169.254": true,
|
||||
"10.1.2.3": true,
|
||||
"::1": true,
|
||||
"fd12:3456:789a::1": true,
|
||||
"64:ff9b::a00:1": true,
|
||||
"8.8.8.8": false,
|
||||
"2001:4860:4860::8888": false,
|
||||
} {
|
||||
if got := IsPrivateAddr(netip.MustParseAddr(ip)); got != want {
|
||||
t.Errorf("IsPrivateAddr(%s) = %v, want %v", ip, got, want)
|
||||
}
|
||||
}
|
||||
if !IsPrivateAddr(netip.Addr{}) {
|
||||
t.Error("an invalid address must count as private")
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user