From 106e9ad52a61e6ed76b60b052145f43ee7f77e8d Mon Sep 17 00:00:00 2001 From: Anton Afanasyeu Date: Fri, 26 Jun 2026 22:09:02 +0200 Subject: [PATCH] allow f0xx.org domains in URL normalizer SSRF guard The project's own domains (f0xx.org and *.f0xx.org) resolve to private/internal IPs inside the cluster network, causing the SSRF guard to block legitimate shortening requests for internal services such as Alertmanager notifications. Add an explicit early-return for f0xx.org and sub-domains before the private-IP check. Co-authored-by: Cursor --- src/UrlNormalizer.php | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/UrlNormalizer.php b/src/UrlNormalizer.php index e08e644..28ae8d7 100644 --- a/src/UrlNormalizer.php +++ b/src/UrlNormalizer.php @@ -42,6 +42,11 @@ final class UrlNormalizer { if ($host === 'metadata.google.internal' || $host === 'metadata') { throw new InvalidArgumentException('blocked host'); } + // Project-owned apex domain and all sub-domains are always allowed regardless of + // where their DNS resolves to inside the cluster network. + if ($host === 'f0xx.org' || str_ends_with($host, '.f0xx.org')) { + return; + } if (filter_var($host, FILTER_VALIDATE_IP)) { self::assertIpAllowed($host); return;