netguard

package
v1.122.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package netguard restricts outbound HTTP connections to publicly routable destinations.

Index

Constants

This section is empty.

Variables

View Source
var ErrBlockedTarget = errors.New("blocked outbound request")

ErrBlockedTarget is returned when a request is refused because its destination is not publicly routable.

View Source
var Transport = sync.OnceValue(func() *http.Transport {
	return RestrictTransport(nil)
})

Transport returns a process-wide transport that only connects to publicly routable destinations, so that its connections are pooled and reused across requests. See RestrictTransport.

Functions

func IsPubliclyRoutable

func IsPubliclyRoutable(ip net.IP) bool

IsPubliclyRoutable reports whether ip is an address on the public internet.

func NewHTTPClient

func NewHTTPClient(timeout time.Duration) *http.Client

NewHTTPClient returns a client that only connects to publicly routable destinations, backed by Transport.

func RestrictTransport

func RestrictTransport(t *http.Transport) *http.Transport

RestrictTransport makes t connect to publicly routable destinations only: loopback, private ranges, link-local addresses (where cloud metadata services live) and the IPv6 transition ranges that embed an IPv4 address are all refused with ErrBlockedTarget.

It also drops any proxy, which would otherwise be the only address the transport connects to and would leave the destination unchecked.

t is modified in place and returned. A nil t starts from a clone of http.DefaultTransport.

Types

type DialFunc

type DialFunc func(ctx context.Context, network, addr string) (net.Conn, error)

DialFunc opens a connection to addr, in the form of net.Dialer.DialContext.

func PublicOnlyDialContext

func PublicOnlyDialContext(resolve ResolveFunc, dial DialFunc) DialFunc

PublicOnlyDialContext wraps dial so that a connection is only made to a publicly routable address.

The check runs here, at dial time, rather than against the URL, for two reasons. It sees the address the connection will actually use, so a host name that resolves to an allowed address for a check and to a blocked one for the connection cannot slip through: the dial targets the very IP that was validated. And because every redirect hop opens its own connection, the whole chain is covered, not just the URL the caller supplied.

type ResolveFunc

type ResolveFunc func(ctx context.Context, host string) ([]net.IPAddr, error)

ResolveFunc resolves a host name into the addresses it points to.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL