fix(sandbox): allow localhost in axios URL screening
Self-hosted automation targets often run on localhost or loopback addresses, so keep blocking private/metadata hosts but stop blocking localhost, 127.x.x.x, and .localhost names. Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
This commit is contained in:
@@ -188,15 +188,6 @@ function createConsole(logger) {
|
|||||||
|
|
||||||
function isBlockedHostname(hostname) {
|
function isBlockedHostname(hostname) {
|
||||||
const host = hostname.toLowerCase().replace(/\.$/, "");
|
const host = hostname.toLowerCase().replace(/\.$/, "");
|
||||||
if (
|
|
||||||
host === "localhost" ||
|
|
||||||
host === "0.0.0.0" ||
|
|
||||||
host === "[::]" ||
|
|
||||||
host === "[::1]" ||
|
|
||||||
host.endsWith(".localhost")
|
|
||||||
) {
|
|
||||||
return true;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (host === "metadata.google.internal" || host === "metadata.goog") {
|
if (host === "metadata.google.internal" || host === "metadata.goog") {
|
||||||
return true;
|
return true;
|
||||||
@@ -214,7 +205,6 @@ function isBlockedHostname(hostname) {
|
|||||||
|
|
||||||
const [a, b] = octets;
|
const [a, b] = octets;
|
||||||
if (a === 10) return true;
|
if (a === 10) return true;
|
||||||
if (a === 127) return true;
|
|
||||||
if (a === 0) return true;
|
if (a === 0) return true;
|
||||||
if (a === 169 && b === 254) return true;
|
if (a === 169 && b === 254) return true;
|
||||||
if (a === 172 && b >= 16 && b <= 31) return true;
|
if (a === 172 && b >= 16 && b <= 31) return true;
|
||||||
|
|||||||
Reference in New Issue
Block a user