aboutsummaryrefslogtreecommitdiff
path: root/webmentions_ssg/url_security.py
diff options
context:
space:
mode:
authorDennis Fink2026-08-19 19:49:55 +0200
committerDennis Fink2026-08-19 19:49:55 +0200
commitd0e245d63e014d268310976fc45429f08d2cbbe9 (patch)
treeef2e96570723190baf02f05c2c4644a19ff1af78 /webmentions_ssg/url_security.py
parentd4a03623544aac0ce911d8471ff4b033bc3255e1 (diff)
downloadwebmentions-ssg-d0e245d63e014d268310976fc45429f08d2cbbe9.tar.gz
webmentions-ssg-d0e245d63e014d268310976fc45429f08d2cbbe9.zip
refactor(core): improve typing and test coverage
Restructure database and user CLI commands, make passwords write-only model properties, and use the UTC datetime constant throughout the application. Add PEP 287-style documentation and expand receiver, scanner, sender, and URL security tests to cover error paths and edge cases.
Diffstat (limited to 'webmentions_ssg/url_security.py')
-rw-r--r--webmentions_ssg/url_security.py15
1 files changed, 14 insertions, 1 deletions
diff --git a/webmentions_ssg/url_security.py b/webmentions_ssg/url_security.py
index 51c037a..9cd261e 100644
--- a/webmentions_ssg/url_security.py
+++ b/webmentions_ssg/url_security.py
@@ -10,6 +10,14 @@ class AddressResolutionError(Exception):
def is_public_url(url: str) -> bool:
+ """
+ Check whether a URL resolves exclusively to public IP addresses.
+
+ :param url: URL whose hostname should be resolved.
+ :return: Whether all resolved addresses are globally routable.
+ :raises ValueError: If the URL does not contain a hostname.
+ :raises AddressResolutionError: If the hostname cannot be resolved.
+ """
hostname = urlsplit(url).hostname
if hostname is None:
@@ -30,7 +38,12 @@ def is_public_url(url: str) -> bool:
def is_http_url(url: str) -> bool:
- """Return whether a URL is an absolute HTTP or HTTPS URL."""
+ """
+ Check whether a URL is an absolute HTTP or HTTPS URL.
+
+ :param url: URL to validate.
+ :return: Whether the URL uses HTTP or HTTPS and contains a hostname.
+ """
try:
parsed = urlsplit(url)
except ValueError: