mirror of
https://github.com/truewhile/MeBox.git
synced 2026-10-04 12:36:37 +08:00
优化,排查项目问题
This commit is contained in:
@@ -35,13 +35,18 @@ func isPrivateHost(host string) bool {
|
||||
if host == "" {
|
||||
return true
|
||||
}
|
||||
ip := net.ParseIP(host)
|
||||
if ip != nil {
|
||||
return ip.IsLoopback() || ip.IsPrivate() || ip.IsLinkLocalUnicast() || ip.IsLinkLocalMulticast() || ip.IsUnspecified()
|
||||
if ip := net.ParseIP(host); ip != nil {
|
||||
return isPrivateIP(ip)
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
// isPrivateIP 判定单个 IP 是否属于回环/私网/链路本地/未指定地址。
|
||||
func isPrivateIP(ip net.IP) bool {
|
||||
return ip.IsLoopback() || ip.IsPrivate() || ip.IsLinkLocalUnicast() ||
|
||||
ip.IsLinkLocalMulticast() || ip.IsUnspecified()
|
||||
}
|
||||
|
||||
// isAllowedLocalPath restricts local file reads to known-safe roots.
|
||||
func (p *ImageProxy) isAllowedLocalPath(abs string) bool {
|
||||
roots := []string{p.cfg.App.DataDir, p.cfg.Cache.CacheDir, p.cfg.Media.MoviesDir, p.cfg.Media.TVDir, p.cfg.Media.AnimeDir}
|
||||
|
||||
Reference in New Issue
Block a user