fix(security): patch SSRF in federation node import and restrict its access

This commit is contained in:
sagitchu
2026-04-17 11:52:08 +08:00
parent 5503d146e6
commit 5e2580bd45
4 changed files with 14 additions and 1 deletions
Submodule .worktrees/feat-dash-rule-adapter added at 8a6aacc45b
Submodule .worktrees/non-dash-release added at 608fbf74de
@@ -5,6 +5,7 @@ import (
"fmt"
"net"
"net/http"
"net/url"
"sort"
"strconv"
"strings"
@@ -636,6 +637,16 @@ func (h *Handler) nodeImport(w http.ResponseWriter, r *http.Request) {
return
}
rUrl, err := url.Parse(req.RemoteURL)
if err != nil || (rUrl.Scheme != "http" && rUrl.Scheme != "https") {
response.WriteJSON(w, response.ErrDefault("Invalid Remote URL format"))
return
}
if err := IsSafeRemoteAddr(rUrl.Host); err != nil {
response.WriteJSON(w, response.Err(403, "禁止将远程节点地址设置为内部网络或保留地址"))
return
}
domainCfg, _ := h.repo.GetConfigByName("panel_domain")
localDomain := ""
if domainCfg != nil {
+1 -1
View File
@@ -109,7 +109,7 @@ func requiresAdmin(path string) bool {
return true
}
if strings.HasPrefix(path, "/api/v1/federation/share/") {
if strings.HasPrefix(path, "/api/v1/federation/share/") || strings.HasPrefix(path, "/api/v1/federation/node/") {
return true
}