Class: URLCanonicalize::Destination
- Inherits:
-
Object
- Object
- URLCanonicalize::Destination
- Defined in:
- lib/url_canonicalize/destination.rb
Overview
Resolves a URI to an address that is permitted by the fetch security policy
Constant Summary collapse
- FORBIDDEN_IPV4_RANGES =
%w[ 0.0.0.0/8 10.0.0.0/8 100.64.0.0/10 127.0.0.0/8 169.254.0.0/16 172.16.0.0/12 192.0.0.0/24 192.0.2.0/24 192.88.99.0/24 192.168.0.0/16 198.18.0.0/15 198.51.100.0/24 203.0.113.0/24 224.0.0.0/4 240.0.0.0/4 ].map { |range| IPAddr.new(range) }.freeze
- ALLOCATED_IPV6_RANGES =
Fail closed: only prefixes in IANA's IPv6 Global Unicast Address Space registry are accepted.
%w[ 2001:200::/23 2001:400::/23 2001:600::/23 2001:800::/22 2001:c00::/23 2001:e00::/23 2001:1200::/23 2001:1400::/22 2001:1800::/23 2001:1a00::/23 2001:1c00::/22 2001:2000::/19 2001:4000::/23 2001:4200::/23 2001:4400::/23 2001:4600::/23 2001:4800::/23 2001:4a00::/23 2001:4c00::/23 2001:5000::/20 2001:8000::/19 2001:a000::/20 2001:b000::/20 2003::/18 2400::/12 2410::/12 2600::/12 2610::/23 2620::/23 2630::/12 2800::/12 2a00::/12 2a10::/12 2c00::/12 ].map { |range| IPAddr.new(range) }.freeze
- FORBIDDEN_IPV6_RANGES =
%w[ 2001::/23 2001:db8::/32 2002::/16 ].map { |range| IPAddr.new(range) }.freeze
Class Method Summary collapse
Class Method Details
.resolve(uri, options) ⇒ Object
72 73 74 75 76 77 |
# File 'lib/url_canonicalize/destination.rb', line 72 def resolve(uri, ) validate!(uri, ) addresses = resolve_addresses(uri) validate_addresses!(uri, addresses, ) addresses.first end |
.validate!(uri, options) ⇒ Object
79 80 81 82 83 84 |
# File 'lib/url_canonicalize/destination.rb', line 79 def validate!(uri, ) raise URLCanonicalize::Exception::Security, 'URLs containing userinfo are not allowed' if uri.userinfo return if [:allowed_ports].include?(uri.port) raise URLCanonicalize::Exception::Security, "Port #{uri.port} is not allowed" end |