aboutsummaryrefslogtreecommitdiff
path: root/webmentions_ssg/url_security.py
diff options
context:
space:
mode:
authorDennis Fink2026-08-15 20:54:53 +0200
committerDennis Fink2026-08-15 20:54:53 +0200
commite0f65d7ff582b32f1c7b5508bba8cda807aaae5f (patch)
tree6693b9fc259bf642e0392b4d8920fbca7ffd6dda /webmentions_ssg/url_security.py
parentb3e12b975064f0873bdb4d2834cae75925387d6b (diff)
downloadwebmentions-ssg-e0f65d7ff582b32f1c7b5508bba8cda807aaae5f.tar.gz
webmentions-ssg-e0f65d7ff582b32f1c7b5508bba8cda807aaae5f.zip
feat(sender): add outgoing Webmention pipeline
Scan generated h-entry documents for Webmention targets and track source revisions and delivery state in the database. Discover target endpoints, send Webmentions asynchronously, and reconcile updated, removed, restored, and deleted sources across scans. Add authenticated views for inspecting sent Webmentions and make the scanner schedule configurable.
Diffstat (limited to '')
-rw-r--r--webmentions_ssg/url_security.py28
1 files changed, 15 insertions, 13 deletions
diff --git a/webmentions_ssg/url_security.py b/webmentions_ssg/url_security.py
index ce5d700..51c037a 100644
--- a/webmentions_ssg/url_security.py
+++ b/webmentions_ssg/url_security.py
@@ -9,15 +9,11 @@ class AddressResolutionError(Exception):
pass
-class NonPublicAddressError(Exception):
- pass
-
-
-def ensure_public_url(url: str) -> None:
+def is_public_url(url: str) -> bool:
hostname = urlsplit(url).hostname
if hostname is None:
- raise NonPublicAddressError("URL has no hostname")
+ raise ValueError("No hostname was specified")
try:
answers = dns.resolver.resolve_name(hostname)
@@ -25,13 +21,19 @@ def ensure_public_url(url: str) -> None:
raise AddressResolutionError(
f"Could not resolve hostname {hostname!r}"
) from exc
+ else:
+ for address in answers.addresses():
+ if not ipaddress.ip_address(address).is_global:
+ return False
- addresses = {ipaddress.ip_address(address) for address in answers.addresses()}
+ return True
- if not addresses:
- raise AddressResolutionError(f"Hostname {hostname!r} did not resolve")
- if any(not address.is_global for address in addresses):
- raise NonPublicAddressError(
- f"Hostname {hostname!r} resolves to a non-public address"
- )
+def is_http_url(url: str) -> bool:
+ """Return whether a URL is an absolute HTTP or HTTPS URL."""
+ try:
+ parsed = urlsplit(url)
+ except ValueError:
+ return False
+
+ return parsed.scheme.lower() in {"http", "https"} and parsed.hostname is not None