osasukev57-venn opened a new pull request, #4386:
URL: https://github.com/apache/hertzbeat/pull/4386

   ## What changes were proposed in this pull request?
   
   Fixes #4383
   
   Add SSRF protection for user-configured webhook/notification URLs.
   
   ### Changes
   
   1. **New `InternalUrlValidator` utility** in `hertzbeat-common-core`:
      - Restricts URL scheme to `http` / `https`
      - Resolves the host and rejects loopback / link-local / RFC-1918 / ULA / 
reserved addresses
      - Checks all resolved IPs (DNS may return multiple)
      - Fails closed on DNS resolution failure
   
   2. **Apply validation before sending** in three notify handlers:
      - `WebHookAlertNotifyHandlerImpl` — user-supplied `hookUrl`
      - `GotifyAlertNotifyHandlerImpl` — configured `gotifyWebhookUrl`
      - `NtfyAlertNotifyHandlerImpl` — user-configured `ntfyServerUrl`
   
   3. **Unit tests** covering loopback, private, link-local, ULA, reserved, and 
public addresses.
   
   ### Why is this needed?
   
   User-supplied webhook URLs were only checked for non-blank, allowing 
server-side requests to internal services (e.g. cloud metadata 
`169.254.169.254`, localhost APIs). ASF security assessed this as hardening 
under the trusted-user model, not a vulnerability.
   
   ### How was this patch tested?
   
   - Unit tests for `InternalUrlValidator` (30+ cases)
   - Code review: all three handlers now call `InternalUrlValidator.validate()` 
before `restTemplate.postForEntity()`
   
   ### Note on redirects
   
   This PR adds pre-flight URL validation. Redirect-time re-validation can be 
added in a follow-up via a custom `ClientHttpRequestFactory` if maintainers 
request it.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to