Say how to allow a refused private target address (closes #398)
check / check (push) Failing after 16m43s

Adding or editing an http or slack target whose address is private or
reserved was refused with no hint that the refusal is deliberate or
that it can be lifted. The refusal now adds that such addresses are
refused by default and that the server's ALLOWED_EGRESS_CIDRS setting
allows named networks, naming the README section "Allowing egress to
your own network". Link-local and cloud metadata refusals, which no
setting can lift, are unchanged.

The delivery package's blocked-address error is exported so the
handler can tell this refusal from the others.

Model: opus-5-5
This commit is contained in:
clawbot
2026-10-01 20:49:22 +00:00
committed by sneak
parent 9d29baaa2d
commit 1b83d25c80
3 changed files with 116 additions and 7 deletions
+4 -2
View File
@@ -25,7 +25,9 @@ var (
errNoIPs = errors.New(
"hostname resolved to no IP addresses",
)
errBlockedIP = errors.New(
// ErrBlockedIP reports an address the default blocklist
// refuses, one that ALLOWED_EGRESS_CIDRS can open.
ErrBlockedIP = errors.New(
"blocked private, reserved or cloud metadata address",
)
errBlockedMetadata = errors.New(
@@ -340,7 +342,7 @@ func (g *Guard) checkIP(ip net.IP) error {
if isBlockedIP(ip) {
return fmt.Errorf(
"target IP %s: %w", ip, errBlockedIP,
"target IP %s: %w", ip, ErrBlockedIP,
)
}