For better SSRF prevention, we should consider enforcing shared requirements/limitations for all outbound HTTP traffic Flagsmith's backend produces, such as:
- resolve first
- reject private, loopback, link-local and CGNAT ranges
- refuse redirects
We must understand which of the above should apply to which of the calls we make, and come up with a policy shared by all urlopen calls in the codebase.
For better SSRF prevention, we should consider enforcing shared requirements/limitations for all outbound HTTP traffic Flagsmith's backend produces, such as:
We must understand which of the above should apply to which of the calls we make, and come up with a policy shared by all
urlopencalls in the codebase.