resolvedHostAllowed resolves host and applies checkWebIP to every address. Literal IPs were already handled by validateWebTarget; a resolution failure fails closed (the request is blocked).
(host string)
| 422 | // address. Literal IPs were already handled by validateWebTarget; a |
| 423 | // resolution failure fails closed (the request is blocked). |
| 424 | func resolvedHostAllowed(host string) bool { |
| 425 | if net.ParseIP(host) != nil { |
| 426 | return true |
| 427 | } |
| 428 | |
| 429 | hostVerdicts.mu.Lock() |
| 430 | if v, ok := hostVerdicts.entries[host]; ok && time.Now().Before(v.expires) { |
| 431 | hostVerdicts.mu.Unlock() |
| 432 | return v.allowed |
| 433 | } |
| 434 | hostVerdicts.mu.Unlock() |
| 435 | |
| 436 | allowed := resolveAndCheckHost(host) |
| 437 | |
| 438 | hostVerdicts.mu.Lock() |
| 439 | if len(hostVerdicts.entries) >= ssrfVerdictMaxEntries { |
| 440 | hostVerdicts.entries = map[string]hostVerdict{} |
| 441 | } |
| 442 | hostVerdicts.entries[host] = hostVerdict{allowed: allowed, expires: time.Now().Add(ssrfVerdictTTL)} |
| 443 | hostVerdicts.mu.Unlock() |
| 444 | return allowed |
| 445 | } |
| 446 | |
| 447 | func resolveAndCheckHost(host string) bool { |
| 448 | ips, err := net.LookupIP(host) |