bridgy-fed icon indicating copy to clipboard operation
bridgy-fed copied to clipboard

prevent SSRF in ATProto, Nostr websocket connections

Open snarfed opened this issue 2 months ago • 0 comments

Need to block localhost domains, GCP internal domains, internal IP ranges, non-wss schemes, etc.

https://owasp.org/www-community/attacks/Server_Side_Request_Forgery https://cheatsheetseries.owasp.org/cheatsheets/Server_Side_Request_Forgery_Prevention_Cheat_Sheet.html

snarfed avatar Oct 15 '25 17:10 snarfed