Server-Side Request Forgery against internal services.
01
01
Understand the problem
nodejssecurityssrfnetworking
02
02
Attempt it yourself
Sketch your approach before reading the solution — that's what interviews test.
Stuck? AI Nudge Available
Get a conceptual hint to guide your logic without spoiling the final implementation.
03
03
Study the solution
The solution is waiting
Give it an honest attempt first — then compare your thinking with the full walkthrough.
04
04
Read the code
Validate the resolved IP before fetching
import dns from 'node:dns/promises';
import net from 'node:net';
async function safeFetch(rawUrl) {
const url = new URL(rawUrl);
if (!['http:', 'https:'].includes(url.protocol)) throw new Error('bad scheme');
const { address } = await dns.lookup(url.hostname);
// reject private / loopback / link-local
if (isPrivate(address)) throw new Error('blocked internal address');
return fetch(url, { redirect: 'error' }); // no silent redirects
}05
05
Join the discussion
Discussion (0)
Sign in to join the discussion.
No responses yet. Be the first to share what you think.