fix(security): patch SSRF in federation node import and restrict its access

This commit is contained in:
sagitchu
2026-04-17 11:52:08 +08:00
parent 5503d146e6
commit 5e2580bd45
4 changed files with 14 additions and 1 deletions
@@ -5,6 +5,7 @@ import (
"fmt"
"net"
"net/http"
"net/url"
"sort"
"strconv"
"strings"
@@ -636,6 +637,16 @@ func (h *Handler) nodeImport(w http.ResponseWriter, r *http.Request) {
return
}
rUrl, err := url.Parse(req.RemoteURL)
if err != nil || (rUrl.Scheme != "http" && rUrl.Scheme != "https") {
response.WriteJSON(w, response.ErrDefault("Invalid Remote URL format"))
return
}
if err := IsSafeRemoteAddr(rUrl.Host); err != nil {
response.WriteJSON(w, response.Err(403, "禁止将远程节点地址设置为内部网络或保留地址"))
return
}
domainCfg, _ := h.repo.GetConfigByName("panel_domain")
localDomain := ""
if domainCfg != nil {