diff --git a/go-backend/internal/http/handler/federation.go b/go-backend/internal/http/handler/federation.go index 2e76e97..0067bb6 100644 --- a/go-backend/internal/http/handler/federation.go +++ b/go-backend/internal/http/handler/federation.go @@ -650,7 +650,7 @@ func (h *Handler) nodeImport(w http.ResponseWriter, r *http.Request) { return } if err := IsSafeRemoteAddr(rURL.Host); err != nil { - response.WriteJSON(w, response.Err(403, "禁止将远程节点地址设置为内部网络或保留地址")) + response.WriteJSON(w, response.Err(403, "禁止将远程节点地址设置为内部网络")) return } diff --git a/go-backend/internal/http/handler/mutations.go b/go-backend/internal/http/handler/mutations.go index 1ae8c80..b622d4a 100644 --- a/go-backend/internal/http/handler/mutations.go +++ b/go-backend/internal/http/handler/mutations.go @@ -1726,7 +1726,7 @@ func (h *Handler) forwardCreate(w http.ResponseWriter, r *http.Request) { } if roleID != 0 { if err := IsSafeRemoteAddr(remoteAddr); err != nil { - response.WriteJSON(w, response.Err(403, "禁止将目标地址设置为内部网络或保留地址")) + response.WriteJSON(w, response.Err(403, "禁止将目标地址设置为内部网络")) return } if speedIDVal, ok := req["speedId"]; ok && speedIDVal != nil { @@ -1850,7 +1850,7 @@ func (h *Handler) forwardUpdate(w http.ResponseWriter, r *http.Request) { } if actorRole != 0 { if err := IsSafeRemoteAddr(remoteAddr); err != nil { - response.WriteJSON(w, response.Err(403, "禁止将目标地址设置为内部网络或保留地址")) + response.WriteJSON(w, response.Err(403, "禁止将目标地址设置为内部网络")) return } } diff --git a/go-backend/internal/http/handler/security_utils.go b/go-backend/internal/http/handler/security_utils.go index d121389..7132fa7 100644 --- a/go-backend/internal/http/handler/security_utils.go +++ b/go-backend/internal/http/handler/security_utils.go @@ -31,8 +31,8 @@ func IsSafeRemoteAddr(addr string) error { } for _, ip := range ips { - if ip.IsLoopback() || ip.IsPrivate() || ip.IsLinkLocalUnicast() || ip.IsLinkLocalMulticast() || ip.IsUnspecified() || ip.IsMulticast() { - return fmt.Errorf("address resolves to internal or reserved IP: %s", ip.String()) + if ip.IsLoopback() || ip.IsPrivate() { + return fmt.Errorf("address resolves to internal IP: %s", ip.String()) } }