mirror of
https://github.com/Sagit-chu/flvx.git
synced 2026-09-28 07:36:38 +08:00
fix(backend): allow setting reserved ip addresses as target
Only forbid internal networks (loopback and private ips), removing restrictions on reserved addresses like multicast or unspecified.
This commit is contained in:
@@ -650,7 +650,7 @@ func (h *Handler) nodeImport(w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
if err := IsSafeRemoteAddr(rURL.Host); err != nil {
|
||||
response.WriteJSON(w, response.Err(403, "禁止将远程节点地址设置为内部网络或保留地址"))
|
||||
response.WriteJSON(w, response.Err(403, "禁止将远程节点地址设置为内部网络"))
|
||||
return
|
||||
}
|
||||
|
||||
|
||||
@@ -1726,7 +1726,7 @@ func (h *Handler) forwardCreate(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
if roleID != 0 {
|
||||
if err := IsSafeRemoteAddr(remoteAddr); err != nil {
|
||||
response.WriteJSON(w, response.Err(403, "禁止将目标地址设置为内部网络或保留地址"))
|
||||
response.WriteJSON(w, response.Err(403, "禁止将目标地址设置为内部网络"))
|
||||
return
|
||||
}
|
||||
if speedIDVal, ok := req["speedId"]; ok && speedIDVal != nil {
|
||||
@@ -1850,7 +1850,7 @@ func (h *Handler) forwardUpdate(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
if actorRole != 0 {
|
||||
if err := IsSafeRemoteAddr(remoteAddr); err != nil {
|
||||
response.WriteJSON(w, response.Err(403, "禁止将目标地址设置为内部网络或保留地址"))
|
||||
response.WriteJSON(w, response.Err(403, "禁止将目标地址设置为内部网络"))
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
@@ -31,8 +31,8 @@ func IsSafeRemoteAddr(addr string) error {
|
||||
}
|
||||
|
||||
for _, ip := range ips {
|
||||
if ip.IsLoopback() || ip.IsPrivate() || ip.IsLinkLocalUnicast() || ip.IsLinkLocalMulticast() || ip.IsUnspecified() || ip.IsMulticast() {
|
||||
return fmt.Errorf("address resolves to internal or reserved IP: %s", ip.String())
|
||||
if ip.IsLoopback() || ip.IsPrivate() {
|
||||
return fmt.Errorf("address resolves to internal IP: %s", ip.String())
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user