requireAPIKeyForBind rejects a non-loopback bind address that has no API key. An empty or unspecified host binds each interface, and that counts as non-loopback.
(address, apiKey string)
| 18 | // API key. An empty or unspecified host binds each interface, and that |
| 19 | // counts as non-loopback. |
| 20 | func requireAPIKeyForBind(address, apiKey string) error { |
| 21 | if apiKey != "" { |
| 22 | return nil |
| 23 | } |
| 24 | host := address |
| 25 | if h, _, err := net.SplitHostPort(address); err == nil { |
| 26 | host = h |
| 27 | } |
| 28 | if host == "localhost" { |
| 29 | return nil |
| 30 | } |
| 31 | if ip := net.ParseIP(host); ip != nil && ip.IsLoopback() { |
| 32 | return nil |
| 33 | } |
| 34 | return fmt.Errorf(i18n.T("server_api_key_required"), address) |
| 35 | } |
| 36 | |
| 37 | // APIKeyMiddleware validates API key for protected endpoints. |
| 38 | // Swagger documentation endpoints (/swagger/*) are exempt from authentication |