Problem
assertPublicUrl validates the current DNS answers, but the subsequent built-in fetch performs its own DNS resolution. A hostile hostname could change from a public address during validation to a private address during connection.
Acceptance criteria
- The HTTP/TLS connection uses an address from the validated DNS result.
- Redirect destinations are resolved, validated, and pinned independently.
- The connected socket address is rejected if it is non-public.
- Automated tests simulate DNS rebinding without depending on external network access.
npm run ci passes.
Problem
assertPublicUrlvalidates the current DNS answers, but the subsequent built-infetchperforms its own DNS resolution. A hostile hostname could change from a public address during validation to a private address during connection.Acceptance criteria
npm run cipasses.