Documentation
¶
Overview ¶
Package privnet provides an http.RoundTripper that can block outbound connections to private, loopback, and link-local addresses on a per-request basis.
Requests opt in by carrying a context flag set with WithBlockPrivate. For those requests, the destination is checked at connection time, using the IP address actually being dialed, so DNS names and redirects that resolve to internal addresses are covered.
When a request is routed through an HTTP proxy, the proxy performs the DNS lookup and connection, so only a best-effort pre-resolution check is possible. In that case, destination policy must be enforced at the proxy.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ErrPrivateAddress = errors.New("destination resolves to a private, loopback, or link-local address")
ErrPrivateAddress is returned when a request destination resolves to a private, loopback, or link-local address and blocking is enabled.
Functions ¶
func IsPrivateAddr ¶
IsPrivateAddr reports whether addr is anything other than a globally routable unicast address (private, loopback, link-local, multicast, etc.).
func RoundTripper ¶
func RoundTripper(base *http.Transport) http.RoundTripper
RoundTripper wraps base so that requests flagged with WithBlockPrivate are sent over a separate, guarded copy of the transport that rejects private destinations at dial time. The guarded copy keeps its own connection pool so a connection established without the check is never reused by a flagged request. Unflagged requests use base unchanged.
Types ¶
This section is empty.