MCPcopy Create free account
hub / github.com/diillson/chatcli / resolvedHostAllowed

Function resolvedHostAllowed

cli/plugins/webfetch_render.go:424–445  ·  view source on GitHub ↗

resolvedHostAllowed resolves host and applies checkWebIP to every address. Literal IPs were already handled by validateWebTarget; a resolution failure fails closed (the request is blocked).

(host string)

Source from the content-addressed store, hash-verified

422// address. Literal IPs were already handled by validateWebTarget; a
423// resolution failure fails closed (the request is blocked).
424func resolvedHostAllowed(host string) bool {
425 if net.ParseIP(host) != nil {
426 return true
427 }
428
429 hostVerdicts.mu.Lock()
430 if v, ok := hostVerdicts.entries[host]; ok && time.Now().Before(v.expires) {
431 hostVerdicts.mu.Unlock()
432 return v.allowed
433 }
434 hostVerdicts.mu.Unlock()
435
436 allowed := resolveAndCheckHost(host)
437
438 hostVerdicts.mu.Lock()
439 if len(hostVerdicts.entries) >= ssrfVerdictMaxEntries {
440 hostVerdicts.entries = map[string]hostVerdict{}
441 }
442 hostVerdicts.entries[host] = hostVerdict{allowed: allowed, expires: time.Now().Add(ssrfVerdictTTL)}
443 hostVerdicts.mu.Unlock()
444 return allowed
445}
446
447func resolveAndCheckHost(host string) bool {
448 ips, err := net.LookupIP(host)

Calls 4

resolveAndCheckHostFunction · 0.85
LockMethod · 0.80
UnlockMethod · 0.80
AddMethod · 0.80