privnet

package
v0.35.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 15, 2026 License: Apache-2.0 Imports: 8 Imported by: 0

Documentation

Overview

Package privnet provides an http.RoundTripper that can block outbound connections to private, loopback, and link-local addresses on a per-request basis.

Requests opt in by carrying a context flag set with WithBlockPrivate. For those requests, the destination is checked at connection time, using the IP address actually being dialed, so DNS names and redirects that resolve to internal addresses are covered.

When a request is routed through an HTTP proxy, the proxy performs the DNS lookup and connection, so only a best-effort pre-resolution check is possible. In that case, destination policy must be enforced at the proxy.

Index

Constants

This section is empty.

Variables

View Source
var ErrPrivateAddress = errors.New("destination resolves to a private, loopback, or link-local address")

ErrPrivateAddress is returned when a request destination resolves to a private, loopback, or link-local address and blocking is enabled.

Functions

func IsPrivateAddr

func IsPrivateAddr(addr netip.Addr) bool

IsPrivateAddr reports whether addr is anything other than a globally routable unicast address (private, loopback, link-local, multicast, etc.).

func RoundTripper

func RoundTripper(base *http.Transport) http.RoundTripper

RoundTripper wraps base so that requests flagged with WithBlockPrivate are sent over a separate, guarded copy of the transport that rejects private destinations at dial time. The guarded copy keeps its own connection pool so a connection established without the check is never reused by a flagged request. Unflagged requests use base unchanged.

func WithBlockPrivate

func WithBlockPrivate(ctx context.Context) context.Context

WithBlockPrivate returns a context that causes requests made with it to be rejected if the destination is a private, loopback, or link-local address.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL