Revalidate Docs / Revalidate Docs (push) Failing after 2s
E2E CI / Check Duplicate Run (push) Failing after 5s
Test CI / Check Duplicate Run (push) Failing after 6s
E2E CI / Test Web App (push) Has been skipped
Test CI / Test Packages (push) Has been skipped
Test CI / Test App (shard 1/3) (push) Has been skipped
Test CI / Test App (shard 2/3) (push) Has been skipped
Test CI / Test App (shard 3/3) (push) Has been skipped
Test CI / Test Desktop App (push) Has been skipped
🔄 Branch Synchronization / sync-branches (push) Failing after 11s
Test CI / Test Database (push) Has been skipped
Test CI / Merge and Upload App Coverage (push) Has been skipped
Database Schema Visualization CI / build (push) Failing after 4m14s
34 lines
893 B
TypeScript
34 lines
893 B
TypeScript
/**
|
|
* Browser version of SSRF-safe fetch
|
|
* In browser environments, we simply use the native fetch API
|
|
* as SSRF attacks are not applicable in client-side code
|
|
*/
|
|
|
|
/**
|
|
* Options for per-call SSRF configuration overrides
|
|
* (ignored in browser - kept for API parity with server version)
|
|
*/
|
|
export interface SSRFOptions {
|
|
/** List of IP addresses to allow */
|
|
allowIPAddressList?: string[];
|
|
/** Whether to allow private/local IP addresses */
|
|
allowPrivateIPAddress?: boolean;
|
|
}
|
|
|
|
/**
|
|
* Browser-safe fetch implementation
|
|
* Uses native fetch API in browser environments
|
|
* @param url - The URL to fetch
|
|
* @param options - Standard fetch options
|
|
* @param _ssrfOptions - Ignored in browser (kept for API parity)
|
|
*/
|
|
export const ssrfSafeFetch = async (
|
|
url: string,
|
|
|
|
options?: RequestInit,
|
|
|
|
_ssrfOptions?: SSRFOptions,
|
|
): Promise<Response> => {
|
|
return fetch(url, options);
|
|
};
|