basalt / webhooks/src / SsrfGuardOptions
Interface: SsrfGuardOptions
Defined in: webhooks/src/ssrf.ts:225
Properties
allowedPorts?
> optional allowedPorts?: "any" | readonly number[]
Defined in: webhooks/src/ssrf.ts:240
Permitted destination ports. An array allows exactly those ports; 'any' turns the port policy off. Default: 80, 443, and every port from 1024 up except DEFAULT_BLOCKED_PORTS (databases, caches, brokers, control planes, proxies). See isPortAllowed.
allowedSchemes?
> optional allowedSchemes?: string[]
Defined in: webhooks/src/ssrf.ts:233
Permitted URL schemes. Default ['https:', 'http:'].
allowPrivateHosts?
> optional allowPrivateHosts?: boolean
Defined in: webhooks/src/ssrf.ts:231
Escape hatch for trusted self-hosted setups delivering to internal hosts. Skips the address checks and pinning — not the port policy (allowedPorts), which applies to internal hosts all the more.
lookup?
> optional lookup?: (host) => Promise<object[]>
Defined in: webhooks/src/ssrf.ts:242
Injected resolver (tests). Default dns.lookup(host, { all: true }).
Parameters
host
string
Returns
Promise<object[]>