basalt / webhooks/src / resolveAndValidate
Function: resolveAndValidate()
> resolveAndValidate(rawUrl, options?): Promise<ValidatedTarget>
Defined in: webhooks/src/ssrf.ts:278
Resolves a delivery URL and validates it against SSRF: a disallowed scheme, a port outside the port policy (see isPortAllowed), or a host that is — or resolves to — a private, loopback, link-local (incl. 169.254.169.254), CGNAT, ULA or reserved address is refused. Resolves the hostname once and checks every returned address (so a name pointed at an internal IP is caught), then returns the validated addresses and the single address the caller must pin the connection to.
Pinning closes the DNS-rebind TOCTOU: because the transport connects to pinned (not by re-resolving the hostname), a hostile authoritative DNS that returned a public IP here can't hand the socket an internal IP at connect time. See pinnedLookup and the deliverer's transport.
Parameters
rawUrl
string
options?
SsrfGuardOptions = {}
Returns
Promise<ValidatedTarget>