basalt / webhooks/src / WebhookUrlBlockedError
Class: WebhookUrlBlockedError
Defined in: webhooks/src/ssrf.ts:12
Thrown when a delivery URL points somewhere we refuse to send (SSRF guard).
The message never contains a DNS-resolved address — echoing it would turn the guard into an internal-DNS oracle (register db.internal, read back its IP). The offending resolved address is kept on resolvedAddress for server-side logging only; never forward it to whoever configured the URL.
Extends
Error
Constructors
Constructor
> new WebhookUrlBlockedError(url, reason, detail?): WebhookUrlBlockedError
Defined in: webhooks/src/ssrf.ts:22
Parameters
url
string
reason
string
detail?
dnsDerived?
boolean
resolvedAddress?
string
Returns
WebhookUrlBlockedError
Overrides
Error.constructor
Properties
dnsDerived
> readonly dnsDerived: boolean
Defined in: webhooks/src/ssrf.ts:20
True when the verdict came from resolving the hostname (did not resolve / resolves to a private address). Such reasons reveal internal DNS, so the deliverer reports them outward with one indistinguishable generic message.
resolvedAddress
> readonly resolvedAddress: string | undefined
Defined in: webhooks/src/ssrf.ts:14
The resolved (private/reserved) address that caused the block, when DNS produced one. Server-side only.