Skip to content

IsValidRemoteURL only blocks literal localhost/127.0.0.1 — misses [::1], 127.0.0.0/8, 0.0.0.0, and private/link-local addresses #1465

Description

@rajanpanth

IsValidRemoteURL (internal/validators/utils.go) is meant to reject remote URLs pointing at local/internal hosts ("stricter than packages - no localhost allowed"). The current host check is:

hostname := u.Hostname()
if hostname == "localhost" || hostname == "127.0.0.1" || strings.HasSuffix(hostname, ".localhost") {
return false
}
Because it compares string literals, it only catches localhost, 127.0.0.1, and *.localhost. These all currently pass validation:

IPv6 loopback: https://[::1]/
Rest of 127.0.0.0/8: https://127.0.0.2/
Unspecified: https://0.0.0.0/, https://[::]/
IPv4-mapped loopback: https://[::ffff:127.0.0.1]/
RFC1918 / link-local: https://10.0.0.1/, https://192.168.1.1/, https://169.254.169.254/
So a published server entry can register a remote URL pointing at loopback/internal addresses despite the intended restriction. This is also inconsistent with the codebase's own handling elsewhere (the auth domain-verification dialer already blocks these ranges, and validateRealmURL blocks 0.0.0.0/::).

Happy to send a PR that resolves the host with net.ParseIP and rejects loopback/unspecified/private/link-local addresses.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions