From 8350bef3e3baea6042ed3780a054cc65707e9f8d Mon Sep 17 00:00:00 2001 From: Dennis Fink Date: Mon, 10 Aug 2026 19:36:49 +0200 Subject: fix(receiver): prevent requests to non-public addresses Resolve source hostnames before fetching and reject addresses that are not globally routable to prevent SSRF against local or private services. Repeat the check for every HTTP request so redirects cannot bypass the initial source validation. Treat DNS resolution failures during verification as temporary fetch errors. --- tests/test_url_security.py | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 tests/test_url_security.py (limited to 'tests/test_url_security.py') diff --git a/tests/test_url_security.py b/tests/test_url_security.py new file mode 100644 index 0000000..fba6d7d --- /dev/null +++ b/tests/test_url_security.py @@ -0,0 +1,42 @@ +import pytest + +from webmentions_ssg.url_security import ( + NonPublicAddressError, + ensure_public_url, +) + + +class FakeAnswers: + def __init__(self, *addresses: str): + self._addresses = addresses + + def addresses(self): + return iter(self._addresses) + + +@pytest.mark.parametrize( + ("url", "resolved_addresses"), + [ + ("http://127.0.0.1/", ["127.0.0.1"]), + ("http://127.0.0.1:8080/test", ["127.0.0.1"]), + ("http://[::1]/", ["::1"]), + ("http://10.0.0.1/", ["10.0.0.1"]), + ("http://172.16.0.1/", ["172.16.0.1"]), + ("http://192.168.1.1/", ["192.168.1.1"]), + ("http://169.254.169.254/", ["169.254.169.254"]), + ("http://localhost/", ["127.0.0.1", "::1"]), + ("http://internal.example/", ["192.168.1.10"]), + ], +) +def test_ensure_public_url_rejects_non_public_addresses( + monkeypatch: pytest.MonkeyPatch, + url: str, + resolved_addresses: list[str], +) -> None: + monkeypatch.setattr( + "webmentions_ssg.url_security.dns.resolver.resolve_name", + lambda hostname: FakeAnswers(*resolved_addresses), + ) + + with pytest.raises(NonPublicAddressError): + ensure_public_url(url) -- cgit v1.3.1