Don't allow wildcard suffix domain rules that look like an address range rule
This commit is contained in:
@@ -2,6 +2,7 @@ package endpoints
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"errors"
|
||||||
"regexp"
|
"regexp"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
@@ -17,7 +18,12 @@ const (
|
|||||||
domainMatchTypeContains
|
domainMatchTypeContains
|
||||||
)
|
)
|
||||||
|
|
||||||
var allowedDomainChars = regexp.MustCompile(`^[a-z0-9\.-]+$`)
|
var (
|
||||||
|
allowedDomainChars = regexp.MustCompile(`^[a-z0-9\.-]+$`)
|
||||||
|
|
||||||
|
// looksLikeAnIP matches domains that look like an IP address.
|
||||||
|
looksLikeAnIP = regexp.MustCompile(`^[0-9\.:]+$`)
|
||||||
|
)
|
||||||
|
|
||||||
// EndpointDomain matches domains.
|
// EndpointDomain matches domains.
|
||||||
type EndpointDomain struct {
|
type EndpointDomain struct {
|
||||||
@@ -122,6 +128,12 @@ func parseTypeDomain(fields []string) (Endpoint, error) {
|
|||||||
return nil, nil
|
return nil, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Do not accept domains that look like an IP address and have a suffix wildcard.
|
||||||
|
// This is confusing, because it looks like an IP Netmask matching rule.
|
||||||
|
if looksLikeAnIP.MatchString(ep.Domain) {
|
||||||
|
return nil, errors.New("use CIDR notation (eg. 10.0.0.0/24) for matching ip address ranges")
|
||||||
|
}
|
||||||
|
|
||||||
case strings.HasPrefix(domain, "*"):
|
case strings.HasPrefix(domain, "*"):
|
||||||
ep.MatchType = domainMatchTypeSuffix
|
ep.MatchType = domainMatchTypeSuffix
|
||||||
ep.Domain = strings.TrimPrefix(domain, "*")
|
ep.Domain = strings.TrimPrefix(domain, "*")
|
||||||
|
|||||||
Reference in New Issue
Block a user