Refuse image requests whose Referer is on referer_blocklist (closes #90)
A new setting, referer_blocklist (PIXA_REFERER_BLOCKLIST), lists hosts written and matched as allowlist_hosts are, with the same matcher and the same entry check; a bad entry aborts startup naming the setting and the entry. Both image routes check the Referer first and answer 403 with the JSON error, so a blocked request fetches nothing and is refused whether or not the image is cached. No Referer, or one that does not parse as a URL with a host, is served; README.md and config.example.yml say this makes the list easy to get around. The CIDR-list entry reader is renamed listEntries now that host lists use it too. Model: opus-5-5
This commit is contained in:
@@ -53,6 +53,16 @@ allowlist_hosts:
|
||||
- github.com
|
||||
- user-images.githubusercontent.com
|
||||
|
||||
# Hosts whose pages may not show pixa's images, written as for
|
||||
# allowlist_hosts. A request to /v1/image/ or /v1/e/ whose Referer header
|
||||
# names one of them is answered 403 before anything is fetched, even when
|
||||
# the image is cached. A request with no Referer, or one that does not
|
||||
# parse, is served, so a site whose pages send no Referer is not stopped.
|
||||
# An entry that is not a host aborts startup. (default: none)
|
||||
# referer_blocklist:
|
||||
# - leech.example
|
||||
# - .hotlinker.example
|
||||
|
||||
# Additional CIDR ranges to refuse when fetching upstream, extending the
|
||||
# SSRF protection. These are added to the always-enforced built-in ranges
|
||||
# (loopback, RFC 1918 private, link-local, CGNAT, benchmark, NAT64, and
|
||||
|
||||
Reference in New Issue
Block a user