package fetchguard_test import ( "context" "errors" "fmt" "time" "git.golem15.com/golem15/summercms/modules/fetchguard" ) func ExampleFetch() { ctx := context.Background() // Only the application's image host, at most 5 MiB within 5 seconds. images := fetchguard.Policy{ Mode: fetchguard.AllowHostsMode, AllowHosts: []string{"images.example.com"}, MaxBytes: 5 << 20, Timeout: 5 * time.Second, } // Any public host, for a URL a user pasted. public := fetchguard.Policy{Mode: fetchguard.PublicOnlyMode} for _, c := range []struct { url string policy fetchguard.Policy }{ {"http://images.example.com/cover.jpg", images}, {"https://cdn.attacker.example/cover.jpg", images}, {"https://127.0.0.1/admin", public}, {"https://169.254.169.254/latest/meta-data/", public}, {"https://[::ffff:10.0.0.1]/", public}, {"https://%zz", public}, } { // The last argument is the application's config (app.Config), for // limits the policy leaves at zero; nil uses the framework defaults. _, err := fetchguard.Fetch(ctx, c.url, c.policy, nil) var fe *fetchguard.Error if errors.As(err, &fe) { fmt.Println(fe.Reason, c.url) } } fmt.Println(fetchguard.Defaults()) // Output: // scheme http://images.example.com/cover.jpg // invalid_url https://cdn.attacker.example/cover.jpg // private_ip https://127.0.0.1/admin // private_ip https://169.254.169.254/latest/meta-data/ // private_ip https://[::ffff:10.0.0.1]/ // invalid_url https://%zz // 10485760 10s }