Historique des commits

Auteur SHA1 Message Date
  Frédéric Guillot c896bafdaa fix(urllib): reject backslashes in relative path validation il y a 1 mois
  Frédéric Guillot 4cd9dd6af7 refactor(validator): replace IsValidURL with urllib.IsAbsoluteURL il y a 3 mois
  Frédéric Guillot c166f80b58 fix: block RFC 6598 shared address space as non-public il y a 3 mois
  Frédéric Guillot fe2bfb27cf fix(fetcher): avoid possible SSRF TOCTOU/DNS-rebinding in private network check il y a 4 mois
  Frédéric Guillot f9b756ecf8 feat: add SSRF protection for integration HTTP clients il y a 4 mois
  Frédéric Guillot bb05b25530 refactor(urllib): replace AbsoluteURL and GetAbsoluteURL il y a 5 mois
  Frédéric Guillot 6c83e8c477 feat(mediaproxy): disallow the media proxy to fetch resources on private networks il y a 6 mois
  Frédéric Guillot 76df99f3a3 fix: only relative path should allowed for redirectURL parameter il y a 8 mois
  Frédéric Guillot e5d9f2f5a0 Rename internal url package to avoid overlap with net/url il y a 2 ans