fix(http-client): validate public addresses at connect time (#2341)

This commit is contained in:
Hampus
2026-09-02 17:22:37 +02:00
committed by GitHub
parent 32dcd5ed1c
commit bcd95b2af9
4 changed files with 75 additions and 5 deletions
+17 -2
View File
@@ -83,6 +83,7 @@ function createFetchInit(
headers: Record<string, string>,
body: string | undefined,
signal: AbortSignal,
dispatcher: NonNullable<RequestInit['dispatcher']> | undefined,
): RequestInit {
return {
method,
@@ -90,9 +91,16 @@ function createFetchInit(
body,
signal,
redirect: 'manual',
...(dispatcher ? {dispatcher} : {}),
};
}
function resolveRequestUrlPolicyDispatcher(
requestUrlPolicy: RequestUrlPolicy | undefined,
): NonNullable<RequestInit['dispatcher']> | undefined {
return (requestUrlPolicy as {dispatcher?: NonNullable<RequestInit['dispatcher']>} | undefined)?.dispatcher;
}
function isRedirectStatus(status: number): boolean {
return REDIRECT_STATUS_CODES.includes(status as (typeof REDIRECT_STATUS_CODES)[number]);
}
@@ -142,11 +150,15 @@ async function fetchWithRedirects(
let currentMethod: HttpMethod = method;
let currentBody = body;
let currentHeaders = {...headers};
const dispatcher = resolveRequestUrlPolicyDispatcher(requestUrlPolicy);
await validateRequestUrlPolicy(requestUrlPolicy, currentUrl, {
phase: 'initial',
redirectCount: 0,
});
let response = await fetch(currentUrl.href, createFetchInit(currentMethod, currentHeaders, currentBody, signal));
let response = await fetch(
currentUrl.href,
createFetchInit(currentMethod, currentHeaders, currentBody, signal, dispatcher),
);
let redirectCount = 0;
while (isRedirectStatus(response.status)) {
if (redirectCount >= maxRedirects) {
@@ -174,7 +186,10 @@ async function fetchWithRedirects(
previousUrl: previousUrl.href,
});
currentUrl = nextUrl;
response = await fetch(currentUrl.href, createFetchInit(currentMethod, currentHeaders, currentBody, signal));
response = await fetch(
currentUrl.href,
createFetchInit(currentMethod, currentHeaders, currentBody, signal, dispatcher),
);
redirectCount = nextRedirectCount;
}
return response;