diff options
| author | Dennis Fink | 2026-08-10 19:36:49 +0200 |
|---|---|---|
| committer | Dennis Fink | 2026-08-10 19:36:49 +0200 |
| commit | 8350bef3e3baea6042ed3780a054cc65707e9f8d (patch) | |
| tree | 81ab5f102045f53d23f89e22a41b2f6a2eef9b52 /webmentions_ssg/url_security.py | |
| parent | afcdb411882a6c157c3b5008e1c633d3e40cd984 (diff) | |
| download | webmentions-ssg-8350bef3e3baea6042ed3780a054cc65707e9f8d.tar.gz webmentions-ssg-8350bef3e3baea6042ed3780a054cc65707e9f8d.zip | |
fix(receiver): prevent requests to non-public addresses
Resolve source hostnames before fetching and reject addresses that are
not globally routable to prevent SSRF against local or private services.
Repeat the check for every HTTP request so redirects cannot bypass the
initial source validation. Treat DNS resolution failures during
verification as temporary fetch errors.
Diffstat (limited to '')
| -rw-r--r-- | webmentions_ssg/url_security.py | 37 |
1 files changed, 37 insertions, 0 deletions
diff --git a/webmentions_ssg/url_security.py b/webmentions_ssg/url_security.py new file mode 100644 index 0000000..ce5d700 --- /dev/null +++ b/webmentions_ssg/url_security.py @@ -0,0 +1,37 @@ +import ipaddress +from urllib.parse import urlsplit + +import dns.exception +import dns.resolver + + +class AddressResolutionError(Exception): + pass + + +class NonPublicAddressError(Exception): + pass + + +def ensure_public_url(url: str) -> None: + hostname = urlsplit(url).hostname + + if hostname is None: + raise NonPublicAddressError("URL has no hostname") + + try: + answers = dns.resolver.resolve_name(hostname) + except dns.exception.DNSException as exc: + raise AddressResolutionError( + f"Could not resolve hostname {hostname!r}" + ) from exc + + addresses = {ipaddress.ip_address(address) for address in answers.addresses()} + + if not addresses: + raise AddressResolutionError(f"Hostname {hostname!r} did not resolve") + + if any(not address.is_global for address in addresses): + raise NonPublicAddressError( + f"Hostname {hostname!r} resolves to a non-public address" + ) |
