Skip to content

basalt / webhooks/src / resolveAndValidate

Function: resolveAndValidate() ​

> resolveAndValidate(rawUrl, options?): Promise<ValidatedTarget>

Defined in: webhooks/src/ssrf.ts:278

Resolves a delivery URL and validates it against SSRF: a disallowed scheme, a port outside the port policy (see isPortAllowed), or a host that is — or resolves to — a private, loopback, link-local (incl. 169.254.169.254), CGNAT, ULA or reserved address is refused. Resolves the hostname once and checks every returned address (so a name pointed at an internal IP is caught), then returns the validated addresses and the single address the caller must pin the connection to.

Pinning closes the DNS-rebind TOCTOU: because the transport connects to pinned (not by re-resolving the hostname), a hostile authoritative DNS that returned a public IP here can't hand the socket an internal IP at connect time. See pinnedLookup and the deliverer's transport.

Parameters ​

rawUrl ​

string

options? ​

SsrfGuardOptions = {}

Returns ​

Promise<ValidatedTarget>

Released under the MIT License.