Skip to content

security: pin validated DNS addresses during URL fetch #4

Description

@fly1d

Problem

assertPublicUrl validates the current DNS answers, but the subsequent built-in fetch performs its own DNS resolution. A hostile hostname could change from a public address during validation to a private address during connection.

Acceptance criteria

  • The HTTP/TLS connection uses an address from the validated DNS result.
  • Redirect destinations are resolved, validated, and pinned independently.
  • The connected socket address is rejected if it is non-public.
  • Automated tests simulate DNS rebinding without depending on external network access.
  • npm run ci passes.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions