Commit bb00376
committed
fix(egress): judge IP literals synchronously and match every IPv4 spelling
Two more from review, both verified with probes first.
The deferral added last round applied to every liftable refusal whenever an IP
range was configured — literals included. A literal has already been judged
against its own address, so a lookup can add nothing, and deferring accepted
literals outside every configured range: with only `10.0.0.0/8` allowlisted,
`https://192.168.1.1` came back valid. It now defers hostnames only.
`matchesRangeAllowlist` compared the raw parsed address, so a resolver answering
with `::a00:1` — which is 10.0.0.1 — was refused by a `10.0.0.0/8` entry. It
over-blocks rather than under-blocks, but an allowlisted destination became
unreachable depending on what DNS returned. `canonicalAddress` already existed
for the metadata comparison and simply was not used here.
Folding needed a carve-out the metadata path did not: `::` and `::1` are the
unspecified and loopback addresses, not an IPv4 carried inside IPv6. Folding
`::1` to `0.0.0.1` would have let a `0.0.0.0/8` entry match loopback and stopped
`::1/128` matching it. Both directions are pinned by tests, alongside the four
spellings an IPv4 range must accept.1 parent 0a50b90 commit bb00376
4 files changed
Lines changed: 62 additions & 4 deletions
File tree
- apps/sim/lib/core/security
- packages/security/src
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
473 | 473 | | |
474 | 474 | | |
475 | 475 | | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
476 | 492 | | |
477 | 493 | | |
478 | 494 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
| 3 | + | |
3 | 4 | | |
4 | 5 | | |
5 | 6 | | |
| |||
521 | 522 | | |
522 | 523 | | |
523 | 524 | | |
524 | | - | |
| 525 | + | |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
| 530 | + | |
| 531 | + | |
| 532 | + | |
| 533 | + | |
525 | 534 | | |
526 | 535 | | |
527 | 536 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
155 | 155 | | |
156 | 156 | | |
157 | 157 | | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
158 | 185 | | |
159 | 186 | | |
160 | 187 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
245 | 245 | | |
246 | 246 | | |
247 | 247 | | |
248 | | - | |
249 | | - | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
250 | 252 | | |
251 | 253 | | |
252 | 254 | | |
| |||
268 | 270 | | |
269 | 271 | | |
270 | 272 | | |
271 | | - | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
272 | 278 | | |
273 | 279 | | |
274 | 280 | | |
| |||
0 commit comments