Add $axios to the VM sandbox with a request interceptor that blocks
non-http(s) URLs and common SSRF targets (localhost, private IPs,
link-local, and cloud metadata hosts). require('axios') and import
axios resolve to the same screened instance so scripts cannot bypass
URL screening.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
14 lines
348 B
JavaScript
14 lines
348 B
JavaScript
export default async function ntfy(ctx) {
|
|
log.info({ ctx }, "ntfy");
|
|
const headers = {}
|
|
|
|
if(ctx.data?.title) {
|
|
headers.Title = ctx.data.title
|
|
}
|
|
|
|
await $axios.post(ctx.config?.url || "https://ntfy.sh/scrunner", ctx.data?.message || "Hello from scrunner", {
|
|
headers: headers
|
|
})
|
|
return {sent: "true"}
|
|
}
|