Skip to Content [alt-c]
In reply to Preventing Server Side Request Forgery in Golang
Looking at smokescreen src code i wondered if the is isPublicIPAddress you linked to be safely replaced by by a some std lib method calls. e.g. https://go.dev/play/p/oz2CNqT-2Sr
smokescreen reference: https://github.com/stripe/smokescreen/blob/8c0fa26edf63f35d5632ba7682d78ff07a306819/pkg/smokescreen/smokescreen.go#L168
I will validate it against your shared isPublicIPAddress next, but figured it may be worth to share it here.
Reply
Your comment will be public. To contact me privately, email me. Please keep your comment polite, on-topic, and comprehensible. Your comment may be held for moderation before being published.
Your Name: (Optional; will be published)
Your Email Address: (Optional; will not be published)
Your Website: (Optional; will be published)
>
monospaced
Post a Reply
Your comment will be public. To contact me privately, email me. Please keep your comment polite, on-topic, and comprehensible. Your comment may be held for moderation before being published.