osasukev57-venn commented on PR #4386:
URL: https://github.com/apache/hertzbeat/pull/4386#issuecomment-5970643338

   Thanks for the thorough review, @zqr10159. I've addressed all three points:
   
   **1. Allowlist / configurable policy (compatibility)**
   Added `alerter.internal-url-allowlist` (default empty = strict mode). It 
accepts exact host names and `*.example.com` wildcard subdomains. Allowlisted 
hosts bypass the internal-address check *without* DNS resolution, so operators 
can explicitly retain self-hosted Gotify/Ntfy/generic webhook endpoints under 
the trusted-user model. Documented in `application.yml` with examples.
   
   **2. Deterministic handler tests**
   All handler tests now run against the allowlist, so no real DNS resolution 
happens and results don't depend on the CI network:
   - Gotify/Ntfy/WebHook success tests: test hosts are allowlisted (localhost, 
ntfy.example.com, etc.)
   - New rejection tests: localhost without allowlist → `AlertNoticeException` 
before any HTTP call
   - New allowlist-policy tests: internal endpoint permitted once allowlisted
   - `InternalUrlValidatorTest`: exact-host, wildcard-subdomain (apex NOT 
matched), empty/null allowlist cases
   
   Local results: `InternalUrlValidatorTest` 41/41, WebHook 9/9, Gotify 3/3, 
Ntfy 19/19 — 0 failures. Also compiled `hertzbeat-manager` successfully (JDK 
25).
   
   **3. Redirects**
   Instead of validating each redirect target, I disabled redirects for these 
outbound notification requests: new `notificationRestTemplate` bean (JDK 
HttpClient with `Redirect.NEVER`) in `RestTemplateConfig`, used by all three 
handlers. A redirect response now surfaces as a normal response the handler 
treats as failure, so the SSRF guard cannot be bypassed mid-request.
   
   Happy to adjust anything else.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to