proxy

package
v1.833.292 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0 Imports: 12 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

View Source
var (
	DefaultHttpClient *http.Client
	ProxyHttpClient   *http.Client
)
View Source
var ErrBlocked = errors.New("proxy: refused to dial a non-public address")

ErrBlocked reports a URL that resolved to an address this package refuses to dial. It is distinguishable from a site that was merely down, because a log line that cannot tell the two apart makes an attack look like an outage.

View Source
var Public = &http.Client{
	Timeout:   publicTimeout,
	Transport: guarded(),
	CheckRedirect: func(req *http.Request, via []*http.Request) error {
		if len(via) >= maxRedirects {
			return fmt.Errorf("proxy: stopped after %d redirects", maxRedirects)
		}

		if s := req.URL.Scheme; s != "http" && s != "https" {
			return fmt.Errorf("%w: redirect to scheme %q", ErrBlocked, s)
		}
		return nil
	},
}

Public is the client for a URL chosen by whoever wrote the request. This process runs inside the cluster, where in-namespace service names resolve and 169.254.169.254 hands out credentials to anyone who asks, so an unrestricted GET on a caller-supplied URL is a credential read, not a fetch.

The address check is in the DIALER. A hostname checked before the request is resolved again by the transport, and a name that answers differently the second time walks through the gap between the two lookups; dialing is the one moment the real destination is known. Redirects re-enter the same dialer, so a public URL that redirects to 169.254.169.254 is refused at the hop that matters.

Functions

func GetHttpClient

func GetHttpClient(url string) *http.Client

GetHttpClient answers the client a URL should be fetched with, and always answers one.

The two package clients are filled by InitHttpClient at boot, so anything running before that line got nil and dereferenced it — a panic rather than a request. Three tests already worked around it by calling InitHttpClient themselves, which is the ordering problem stated out loud.

The fallback is http.DefaultClient, which is what the non-proxy path resolves to anyway; a deployment that configured a proxy still gets it, because by then InitHttpClient has run.

func InitHttpClient

func InitHttpClient()

func Local added in v1.833.53

func Local(url string) *http.Client

Local returns the client to use for a base URL, or nil to take the verifying default. A non-nil result accepts any certificate and is returned ONLY for this machine, where a model server's certificate is self-signed because nobody issues one for 127.0.0.1. Anything that does not clearly name this machine — a look-alike host, an unparseable URL — is remote and verifies.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL