Documentation
¶
Overview ¶
Package netguard restricts outbound HTTP connections to publicly routable destinations.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ErrBlockedTarget = errors.New("blocked outbound request")
ErrBlockedTarget is returned when a request is refused because its destination is not publicly routable.
var Transport = sync.OnceValue(func() *http.Transport { return RestrictTransport(nil) })
Transport returns a process-wide transport that only connects to publicly routable destinations, so that its connections are pooled and reused across requests. See RestrictTransport.
Functions ¶
func IsPubliclyRoutable ¶
IsPubliclyRoutable reports whether ip is an address on the public internet.
func NewHTTPClient ¶
NewHTTPClient returns a client that only connects to publicly routable destinations, backed by Transport.
func RestrictTransport ¶
RestrictTransport makes t connect to publicly routable destinations only: loopback, private ranges, link-local addresses (where cloud metadata services live) and the IPv6 transition ranges that embed an IPv4 address are all refused with ErrBlockedTarget.
It also drops any proxy, which would otherwise be the only address the transport connects to and would leave the destination unchecked.
t is modified in place and returned. A nil t starts from a clone of http.DefaultTransport.
Types ¶
type DialFunc ¶
DialFunc opens a connection to addr, in the form of net.Dialer.DialContext.
func PublicOnlyDialContext ¶
func PublicOnlyDialContext(resolve ResolveFunc, dial DialFunc) DialFunc
PublicOnlyDialContext wraps dial so that a connection is only made to a publicly routable address.
The check runs here, at dial time, rather than against the URL, for two reasons. It sees the address the connection will actually use, so a host name that resolves to an allowed address for a check and to a blocked one for the connection cannot slip through: the dial targets the very IP that was validated. And because every redirect hop opens its own connection, the whole chain is covered, not just the URL the caller supplied.