/
parameter_ip.go
102 lines (79 loc) · 1.93 KB
/
parameter_ip.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
package config
import (
"context"
"errors"
"fmt"
"net"
"github.com/9seconds/chore/internal/network"
)
const ParameterIP = "ip"
var (
errInvalidIP = errors.New("invalid IP address")
errNotInAllowedSubnets = errors.New("cannot find address in allowed subnets")
)
type paramIP struct {
baseParameter
resolve bool
allowedSubnets []*net.IPNet
forbiddenSubnets []*net.IPNet
}
func (p paramIP) Type() string {
return ParameterIP
}
func (p paramIP) Validate(ctx context.Context, value string) error {
addr := net.ParseIP(value)
if addr == nil {
return errInvalidIP
}
for _, subnet := range p.forbiddenSubnets {
if subnet.Contains(addr) {
return fmt.Errorf("address blacklisted in %s", subnet)
}
}
found := true
for _, subnet := range p.allowedSubnets {
found = false
if subnet.Contains(addr) {
found = true
break
}
}
if !found {
return errNotInAllowedSubnets
}
if p.resolve {
if _, err := network.DNSResolver.LookupAddr(ctx, addr.String()); err != nil {
return fmt.Errorf("cannot do reverse lookup: %w", err)
}
}
return nil
}
func NewIP(description string, required bool, spec map[string]string) (Parameter, error) {
param := paramIP{
baseParameter: baseParameter{
required: required,
description: description,
specification: spec,
},
}
for _, v := range parseCSV(spec["allowed_subnets"]) {
_, subnet, err := net.ParseCIDR(v)
if err != nil {
return nil, fmt.Errorf("%s is incorrect subnet: %w", v, err)
}
param.allowedSubnets = append(param.allowedSubnets, subnet)
}
for _, v := range parseCSV(spec["forbidden_subnets"]) {
_, subnet, err := net.ParseCIDR(v)
if err != nil {
return nil, fmt.Errorf("%s is incorrect subnet: %w", v, err)
}
param.forbiddenSubnets = append(param.forbiddenSubnets, subnet)
}
if resolve, err := parseBool(spec, "resolve"); err == nil {
param.resolve = resolve
} else {
return nil, err
}
return param, nil
}