Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
var SafeHttpTransport *http.Transport
SafeHttpTransport is a http.Transport that must be used as transport for HTTP clients that fetch URLs influenced by other parties, e.g. OpenID4VCI issuer/wallet endpoints and OAuth endpoints resolved from DID documents. It carries the strict-mode SSRF dial guard (see denyNonPublicAddr). It is deliberately NOT installed on http.DefaultTransport: PKI CRL fetching and external crypto storage clients may legitimately target non-public addresses.
var StrictMode bool
StrictMode is a flag that can be set to true to enable strict mode for the HTTP client.
Functions ¶
func SetAllowedNonPublicCIDRs ¶
SetAllowedNonPublicCIDRs parses the given CIDR strings and replaces the set of non-public networks that strict mode permits. It returns an error on the first invalid CIDR, leaving the previous value unchanged.
func SetDeniedCIDRs ¶
SetDeniedCIDRs parses the given CIDR strings and replaces the operator-configured part of the denied networks; the built-in cloud metadata prefixes are always retained. It returns an error on the first invalid CIDR, leaving the previous value unchanged.
Types ¶
This section is empty.