Skip to content

basalt / webhooks/src / SsrfGuardOptions

Interface: SsrfGuardOptions ​

Defined in: webhooks/src/ssrf.ts:225

Properties ​

allowedPorts? ​

> optional allowedPorts?: "any" | readonly number[]

Defined in: webhooks/src/ssrf.ts:240

Permitted destination ports. An array allows exactly those ports; 'any' turns the port policy off. Default: 80, 443, and every port from 1024 up except DEFAULT_BLOCKED_PORTS (databases, caches, brokers, control planes, proxies). See isPortAllowed.


allowedSchemes? ​

> optional allowedSchemes?: string[]

Defined in: webhooks/src/ssrf.ts:233

Permitted URL schemes. Default ['https:', 'http:'].


allowPrivateHosts? ​

> optional allowPrivateHosts?: boolean

Defined in: webhooks/src/ssrf.ts:231

Escape hatch for trusted self-hosted setups delivering to internal hosts. Skips the address checks and pinning — not the port policy (allowedPorts), which applies to internal hosts all the more.


lookup? ​

> optional lookup?: (host) => Promise<object[]>

Defined in: webhooks/src/ssrf.ts:242

Injected resolver (tests). Default dns.lookup(host, { all: true }).

Parameters ​

host ​

string

Returns ​

Promise<object[]>

Released under the MIT License.