test: fix contract tests failing due to strict SSRF checks

This commit is contained in:
sagitchu
2026-04-17 12:02:40 +08:00
parent 5e2580bd45
commit 3ddff94bc3
3 changed files with 14 additions and 1 deletions
@@ -6,9 +6,16 @@ import (
"strings"
)
// DisableSafeRemoteAddrCheckForTesting allows bypassing the safety check during integration tests.
var DisableSafeRemoteAddrCheckForTesting = false
// IsSafeRemoteAddr checks if a given address is safe to connect to (prevents SSRF/Open Proxy).
// It resolves domains to IPs to prevent DNS rebinding attacks pointing to internal networks.
func IsSafeRemoteAddr(addr string) error {
if DisableSafeRemoteAddrCheckForTesting {
return nil
}
host, _, err := net.SplitHostPort(addr)
if err != nil {
// If there is no port, try to treat the whole string as host