feat: blocked_networks config and extended SSRF ranges (closes #67)
check / check (push) Successful in 2m28s
check / check (push) Successful in 2m28s
Add a blocked_networks config key: a list of CIDRs parsed with net/netip, added to (not replacing) the built-in SSRF blocklist. An invalid CIDR aborts startup naming the key and the offending value. Extend the built-in blocklist to CGNAT 100.64.0.0/10, IETF protocol assignments 192.0.0.0/24, benchmark 198.18.0.0/15, and NAT64 64:ff9b::/96, unmapping IPv4-mapped IPv6 so the IPv4 ranges are caught in both forms. Enforcement stays in the dial-time re-resolution (dialSSRFSafe), which now also consults the operator-supplied prefixes, so the DNS-rebinding window remains closed. Model: opus-4-8
This commit is contained in:
@@ -22,6 +22,15 @@ allowlist_hosts:
|
||||
- github.com
|
||||
- user-images.githubusercontent.com
|
||||
|
||||
# Additional CIDR ranges to refuse when fetching upstream, extending the
|
||||
# SSRF protection. These are added to the always-enforced built-in ranges
|
||||
# (loopback, RFC 1918 private, link-local, CGNAT, benchmark, NAT64, and
|
||||
# similar), never replacing them. Each entry must be a valid CIDR in IPv4
|
||||
# or IPv6 form; an invalid entry aborts startup.
|
||||
# blocked_networks:
|
||||
# - 100.64.0.0/10
|
||||
# - 2001:db8::/32
|
||||
|
||||
# Allow HTTP upstream (only for testing, always use HTTPS in production)
|
||||
allow_http: false
|
||||
|
||||
|
||||
Reference in New Issue
Block a user