Refuse host entries that are not a host name or an IP address
check / check (push) Failing after 2s

An entry of allowlist_hosts or referer_blocklist that is neither a host
name (letters, digits, hyphens and dots, with at most one leading dot)
nor an IP address now aborts startup naming the setting and the entry,
so a `*.` wildcard or a port no longer loads and silently matches
nothing. README.md, config.example.yml and the TODO.md entry now say the
Referer check comes before the signature, the cache and the upstream
fetch, since maintenance mode answers first; config.example.yml says
the list does not cover the login and generator pages.

Model: opus-5-5
This commit is contained in:
2026-10-04 19:04:34 +00:00
parent a31dbcb70a
commit b3e744a744
4 changed files with 51 additions and 42 deletions
+3 -1
View File
@@ -46,6 +46,8 @@ signing_key: "CHANGE_ME_generate_with_openssl_rand_base64_32"
# Hosts that don't require signatures (default: none)
# Use "." prefix for wildcard subdomain matching (e.g., ".example.com" matches "cdn.example.com")
# An entry that is neither a host name nor an IP address (IPv6 without
# brackets), such as one with a port or a "*." wildcard, aborts startup.
allowlist_hosts:
- s3.sneak.cloud
- static.sneak.cloud
@@ -58,7 +60,7 @@ allowlist_hosts:
# names one of them is answered 403 before anything is fetched, even when
# the image is cached. A request with no Referer, or one that does not
# parse, is served, so a site whose pages send no Referer is not stopped.
# An entry that is not a host aborts startup. (default: none)
# The login and generator pages are not covered. (default: none)
# referer_blocklist:
# - leech.example
# - .hotlinker.example