pub struct GuardedHttp { /* private fields */ }Expand description
The HTTP side of delivery: a client plus the address policy it was built for, so the two can’t drift apart. Build it once per process and keep it (the job context, the web settings page).
The client uses the guarded DNS resolver under Public (private and internal addresses are
dropped from answers), never follows redirects, ignores proxy settings and times out after
10 seconds. AllowPrivate (self-hosted) resolves normally.
Implementations§
Source§impl GuardedHttp
impl GuardedHttp
Sourcepub fn new(policy: AddressPolicy) -> Result<GuardedHttp, Error>
pub fn new(policy: AddressPolicy) -> Result<GuardedHttp, Error>
Resolves names through the system resolver.
Sourcepub fn with_lookup<L: Lookup>(
policy: AddressPolicy,
lookup: L,
) -> Result<GuardedHttp, Error>
pub fn with_lookup<L: Lookup>( policy: AddressPolicy, lookup: L, ) -> Result<GuardedHttp, Error>
GuardedHttp::new with another resolver (tests resolve names to chosen addresses).
pub fn policy(&self) -> AddressPolicy
Sourcepub async fn validate_target(
&self,
kind: ChannelKind,
url: &str,
) -> Result<Url, TargetError>
pub async fn validate_target( &self, kind: ChannelKind, url: &str, ) -> Result<Url, TargetError>
Checks a URL a user wants to save as a channel target: Slack must be
https://hooks.slack.com/..., Discord https://discord.com/api/webhooks/... (or
discordapp.com), a webhook any https URL (plain http only under AllowPrivate).
Then the address guard: IP literals are checked, and under Public a host name is
resolved and refused when it only resolves to private or internal addresses (or doesn’t
resolve at all). The same guard runs again at delivery.