Say how to allow a refused private target address (closes #398)
check / check (push) Failing after 16m43s
check / check (push) Failing after 16m43s
Adding or editing an http or slack target whose address is private or reserved was refused with no hint that the refusal is deliberate or that it can be lifted. The refusal now adds that such addresses are refused by default and that the server's ALLOWED_EGRESS_CIDRS setting allows named networks, naming the README section "Allowing egress to your own network". Link-local and cloud metadata refusals, which no setting can lift, are unchanged. The delivery package's blocked-address error is exported so the handler can tell this refusal from the others. Model: opus-5-5
This commit is contained in:
@@ -25,7 +25,9 @@ var (
|
||||
errNoIPs = errors.New(
|
||||
"hostname resolved to no IP addresses",
|
||||
)
|
||||
errBlockedIP = errors.New(
|
||||
// ErrBlockedIP reports an address the default blocklist
|
||||
// refuses, one that ALLOWED_EGRESS_CIDRS can open.
|
||||
ErrBlockedIP = errors.New(
|
||||
"blocked private, reserved or cloud metadata address",
|
||||
)
|
||||
errBlockedMetadata = errors.New(
|
||||
@@ -340,7 +342,7 @@ func (g *Guard) checkIP(ip net.IP) error {
|
||||
|
||||
if isBlockedIP(ip) {
|
||||
return fmt.Errorf(
|
||||
"target IP %s: %w", ip, errBlockedIP,
|
||||
"target IP %s: %w", ip, ErrBlockedIP,
|
||||
)
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user