Browse Source
Wire SsrfSafeAddressResolverGroup only when SSRF protection is enabled. Remove "SSRF protection" prefix from error messages to avoid exposing internal security mechanisms to users. Add 11 new tests covering isHostnameAllowed, one-arg validateUri, allow-list case-insensitivity, cloud metadata/loopback overrides, CIDR boundaries, IPv6 unique local, whitespace parsing, allow-list replacement, and blocked hostname override.pull/15253/head
3 changed files with 9 additions and 6 deletions
Loading…
Reference in new issue