hardBackend

What is SSRF and how do you mitigate it in a Node.js backend?

829 views
01

Understand the problem

Server-Side Request Forgery against internal services.

nodejssecurityssrfnetworking
02

Attempt it yourself

Sketch your approach before reading the solution — that's what interviews test.

Stuck? AI Nudge Available

Get a conceptual hint to guide your logic without spoiling the final implementation.

03

Study the solution

The solution is waiting

Give it an honest attempt first — then compare your thinking with the full walkthrough.

04

Read the code

Validate the resolved IP before fetching
import dns from 'node:dns/promises';
import net from 'node:net';

async function safeFetch(rawUrl) {
  const url = new URL(rawUrl);
  if (!['http:', 'https:'].includes(url.protocol)) throw new Error('bad scheme');
  const { address } = await dns.lookup(url.hostname);
  // reject private / loopback / link-local
  if (isPrivate(address)) throw new Error('blocked internal address');
  return fetch(url, { redirect: 'error' });   // no silent redirects
}
05

Join the discussion

Discussion (0)

Sign in to join the discussion.

No responses yet. Be the first to share what you think.