mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 05:27:48 +00:00
block local and private IPs on host header
This commit is contained in:
@@ -29,6 +29,7 @@ import {
|
|||||||
TRevokeOciAuthDTO,
|
TRevokeOciAuthDTO,
|
||||||
TUpdateOciAuthDTO
|
TUpdateOciAuthDTO
|
||||||
} from "./identity-oci-auth-types";
|
} from "./identity-oci-auth-types";
|
||||||
|
import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator";
|
||||||
|
|
||||||
type TIdentityOciAuthServiceFactoryDep = {
|
type TIdentityOciAuthServiceFactoryDep = {
|
||||||
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create" | "delete">;
|
||||||
@@ -55,7 +56,7 @@ export const identityOciAuthServiceFactory = ({
|
|||||||
|
|
||||||
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId: identityOciAuth.identityId });
|
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId: identityOciAuth.identityId });
|
||||||
|
|
||||||
// TODO(andrey): Validate inputs
|
await blockLocalAndPrivateIpAddresses(headers.host);
|
||||||
|
|
||||||
const { data } = await request.get<TOciGetUserResponse>(`https://${headers.host}/20160918/users/${userOcid}`, {
|
const { data } = await request.get<TOciGetUserResponse>(`https://${headers.host}/20160918/users/${userOcid}`, {
|
||||||
headers
|
headers
|
||||||
|
|||||||
Reference in New Issue
Block a user