feat(sandbox): expose screened $axios in script context
Add $axios to the VM sandbox with a request interceptor that blocks
non-http(s) URLs and common SSRF targets (localhost, private IPs,
link-local, and cloud metadata hosts). require('axios') and import
axios resolve to the same screened instance so scripts cannot bypass
URL screening.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
This commit is contained in:
+2
-3
@@ -1,5 +1,4 @@
|
||||
import axios from "axios";
|
||||
export default function ntfy(ctx) {
|
||||
export default async function ntfy(ctx) {
|
||||
log.info({ ctx }, "ntfy");
|
||||
const headers = {}
|
||||
|
||||
@@ -7,7 +6,7 @@ export default function ntfy(ctx) {
|
||||
headers.Title = ctx.data.title
|
||||
}
|
||||
|
||||
axios.post(ctx.config?.url || "https://ntfy.sh/scrunner", ctx.data?.message || "Hello from scrunner", {
|
||||
await $axios.post(ctx.config?.url || "https://ntfy.sh/scrunner", ctx.data?.message || "Hello from scrunner", {
|
||||
headers: headers
|
||||
})
|
||||
return {sent: "true"}
|
||||
|
||||
Reference in New Issue
Block a user