aboutsummaryrefslogtreecommitdiff
path: root/internal/route
diff options
context:
space:
mode:
authorMichael Rowley <michaellrowley@protonmail.com>2022-03-08 03:34:53 +0000
committerGitHub <noreply@github.com>2022-03-08 11:34:53 +0800
commit242deca524dbf922bfb08dadd65455164b9e663e (patch)
treeb8110c947dba99cf3e8115219a440f79f19bcc14 /internal/route
parentbb19f52c05e212b9358f9efaa897120dbdf9d0ab (diff)
security: fix SSRF in repository migration (#6812)
Co-authored-by: Joe Chen <jc@unknwon.io>
Diffstat (limited to 'internal/route')
-rw-r--r--internal/route/repo/webhook.go20
-rw-r--r--internal/route/repo/webhook_test.go19
2 files changed, 2 insertions, 37 deletions
diff --git a/internal/route/repo/webhook.go b/internal/route/repo/webhook.go
index 43148822..77696bbc 100644
--- a/internal/route/repo/webhook.go
+++ b/internal/route/repo/webhook.go
@@ -20,6 +20,7 @@ import (
"gogs.io/gogs/internal/db"
"gogs.io/gogs/internal/db/errors"
"gogs.io/gogs/internal/form"
+ "gogs.io/gogs/internal/netutil"
)
const (
@@ -118,23 +119,6 @@ func WebhooksNew(c *context.Context, orCtx *orgRepoContext) {
c.Success(orCtx.TmplNew)
}
-var localHostnames = []string{
- "localhost",
- "127.0.0.1",
- "::1",
- "0:0:0:0:0:0:0:1",
-}
-
-// isLocalHostname returns true if given hostname is a known local address.
-func isLocalHostname(hostname string) bool {
- for _, local := range localHostnames {
- if hostname == local {
- return true
- }
- }
- return false
-}
-
func validateWebhook(actor *db.User, l macaron.Locale, w *db.Webhook) (field, msg string, ok bool) {
if !actor.IsAdmin {
// 🚨 SECURITY: Local addresses must not be allowed by non-admins to prevent SSRF,
@@ -144,7 +128,7 @@ func validateWebhook(actor *db.User, l macaron.Locale, w *db.Webhook) (field, ms
return "PayloadURL", l.Tr("repo.settings.webhook.err_cannot_parse_payload_url", err), false
}
- if isLocalHostname(payloadURL.Hostname()) {
+ if netutil.IsLocalHostname(payloadURL.Hostname()) {
return "PayloadURL", l.Tr("repo.settings.webhook.err_cannot_use_local_addresses"), false
}
}
diff --git a/internal/route/repo/webhook_test.go b/internal/route/repo/webhook_test.go
index 182c6eed..d10a6fcc 100644
--- a/internal/route/repo/webhook_test.go
+++ b/internal/route/repo/webhook_test.go
@@ -13,25 +13,6 @@ import (
"gogs.io/gogs/internal/mocks"
)
-func Test_isLocalHostname(t *testing.T) {
- tests := []struct {
- hostname string
- want bool
- }{
- {hostname: "localhost", want: true},
- {hostname: "127.0.0.1", want: true},
- {hostname: "::1", want: true},
- {hostname: "0:0:0:0:0:0:0:1", want: true},
-
- {hostname: "gogs.io", want: false},
- }
- for _, test := range tests {
- t.Run("", func(t *testing.T) {
- assert.Equal(t, test.want, isLocalHostname(test.hostname))
- })
- }
-}
-
func Test_validateWebhook(t *testing.T) {
l := &mocks.Locale{
MockLang: "en",