You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Upstream fetches go through registries' dial gate which refuses connections to loopback and link-local addresses.
This currently makes using a deliberately-internal upstream impossible.
This PR exposes registries' new per-host opt-out in config:
Started rebasing this onto main but hit a structural blocker: Server.Start now builds its own safehttp client (to layer auth and access-log transports) and injects it via fetch.WithHTTPClient, which replaces the fetcher's default transport. fetch.WithAllowPrivateHosts only affects that default transport, so on current main the allowlist would be loaded from config and then never consulted. safehttp.Options only has blanket AllowPrivate, no per-host list.
Opened git-pkgs/registries#67 to add per-host allowlisting to safehttp.Options. Once that's in a tagged release the rebase is straightforward: pass safehttp.Options{AllowPrivateHosts: s.cfg.Upstream.AllowPrivateHosts} at the safehttp.New call and drop the fetch.WithAllowPrivateHosts option. The config, docs, and env-var parts of this PR carry over as-is (env parsing needs restating in the new setEnvString-style LoadFromEnv).
Converting back to draft until the registries change lands.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Depends on git-pkgs/registries#51.
Upstream fetches go through registries' dial gate which refuses connections to loopback and link-local addresses.
This currently makes using a deliberately-internal upstream impossible.
This PR exposes registries' new per-host opt-out in config:
or
PROXY_UPSTREAM_ALLOW_PRIVATE_HOSTS=host1,host2(comma-separated).