fix(webhook): guard deliveries against loopback and link-local SSRF #27
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!27
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/webhook-ssrf-guards"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Webhook deliveries used
http.DefaultClient: redirects followed, no IP validation, DNS-rebinding-prone. Now:Controlhook (after DNS, before connect — rebinding-safe): loopback, link-local (including 169.254.169.254 metadata), unspecified, and multicast are refused, each with a named reason.validateTargetURLapplies the same IP-class check at create/update time (best-effort resolve, 2s timeout) so admins get an immediateInvalidArgumentnaming the class instead of silent delivery failures.AllowLoopbackWebhooks(off in production) keeps the integration harness's 127.0.0.1 receivers working;make test-integrationpasses.Fixes #14
🤖 Generated with Claude Code
19727211ab4f429d671c