Merge pull request #3510 from Infisical/internal-ip-check-fix

fix(external-connections): Use Hostname for Blocking Internal IPs DNS Resolve
This commit is contained in:
Scott Wilson
2025-04-29 12:37:46 -07:00
committed by GitHub
+4 -4
View File
@@ -15,13 +15,13 @@ export const blockLocalAndPrivateIpAddresses = async (url: string) => {
const validUrl = new URL(url); const validUrl = new URL(url);
const inputHostIps: string[] = []; const inputHostIps: string[] = [];
if (isIPv4(validUrl.host)) { if (isIPv4(validUrl.hostname)) {
inputHostIps.push(validUrl.host); inputHostIps.push(validUrl.hostname);
} else { } else {
if (validUrl.host === "localhost" || validUrl.host === "host.docker.internal") { if (validUrl.hostname === "localhost" || validUrl.hostname === "host.docker.internal") {
throw new BadRequestError({ message: "Local IPs not allowed as URL" }); throw new BadRequestError({ message: "Local IPs not allowed as URL" });
} }
const resolvedIps = await dns.resolve4(validUrl.host); const resolvedIps = await dns.resolve4(validUrl.hostname);
inputHostIps.push(...resolvedIps); inputHostIps.push(...resolvedIps);
} }
const isInternalIp = inputHostIps.some((el) => isPrivateIp(el)); const isInternalIp = inputHostIps.some((el) => isPrivateIp(el));