Saltar al contenido
Esta página aún no está traducida.

SecureUriValidator Class

Default ISecureUriValidator implementation: applies the scheme allow-list and the internal-hostname / private-or-reserved IP-literal rules from SecureHttpFetchOptions.

C#
public class SecureUriValidator : Abblix.Oidc.Server.Features.SecureHttpFetch.ISecureUriValidator

Inheritance System.Object → SecureUriValidator

Implements ISecureUriValidator

Remarks

A configuration that lifts the scheme restriction is reported once, when this singleton is created, under this type's own log category. A report rather than a refusal, because an empty list is a statement a deployment may mean; the category makes the message separately silenceable the same way Abblix.Oidc.Server.Features.SecureHttpFetch.SsrfGuardWatch's is.

Constructors

SecureUriValidator(IOptions<SecureHttpFetchOptions>, ILogger<SecureUriValidator>) Constructor

Creates the validator and reports a lifted scheme restriction, once, when the configuration states one.

C#
public SecureUriValidator(Microsoft.Extensions.Options.IOptions<Abblix.Oidc.Server.Features.SecureHttpFetch.SecureHttpFetchOptions> options, Microsoft.Extensions.Logging.ILogger<Abblix.Oidc.Server.Features.SecureHttpFetch.SecureUriValidator>? logger=null);

Parameters

options Microsoft.Extensions.Options.IOptions<SecureHttpFetchOptions>

The fetch policy this validator enforces.

logger Microsoft.Extensions.Logging.ILogger<SecureUriValidator>

Carries the one-time report; absent in hosts that build the validator by hand, where there is nowhere to report to.

Methods

SecureUriValidator.IsAllowedDestination(Uri, Uri[]) Method

Reports whether a URI is one of the destinations named in AllowedDestinations.

C#
public static bool IsAllowedDestination(System.Uri uri, System.Uri[]? allowedDestinations);

Parameters

uri System.Uri

The URI about to be reached.

allowedDestinations System.Uri[]

The configured permissions, which may be absent.

Returns

System.Boolean
true when the URI matches one of them.

Remarks

Static because two separate refusals have to honour the same permission: the synchronous policy below, and the DNS re-resolution in SsrfValidatingHttpMessageHandler. A permission honoured by only one of them passes validation and then dies at the request - which reads as a working allow-list in every test of this class, and fails only against a live service.

An entry with no path of its own (/) matches the whole origin; an entry carrying a path matches that path exactly. Comparison of scheme and host ignores case as RFC 3986 Section 6.2.2.1 requires, while the path is compared as written, because the same section leaves it case-sensitive.

SecureUriValidator.IsInternalHostname(string) Method

Checks if a hostname appears to be internal or non-public.

C#
public static bool IsInternalHostname(string hostname);

Parameters

hostname System.String

Returns

System.Boolean

Remarks

The rules live in PrivateNetworks, where every package that must refuse such an address reads them, so a name added there takes effect here too. The wording of this member is kept as shipped: it is public, and a rename would break a host that calls it for nothing but a synonym.

SecureUriValidator.IsPrivateOrReservedAddress(IPAddress) Method

Checks if an IP address is private, loopback, link-local, or otherwise reserved.

C#
public static bool IsPrivateOrReservedAddress(System.Net.IPAddress address);

Parameters

address System.Net.IPAddress

Returns

System.Boolean

Remarks

Delegates to PrivateNetworks for the same reason as the hostname rules above.

SecureUriValidator.Validate(Uri) Method

Validates a URI against the configured SSRF policy without resolving DNS.

C#
public string? Validate(System.Uri uri);

Parameters

uri System.Uri

The URI to validate.

Implements Validate(Uri)

Returns

System.String
null when the URI is allowed; otherwise a human-readable reason for the rejection.