Skip to main content

guarded_post_form

Function guarded_post_form 

Source
pub async fn guarded_post_form(
    client: &Client,
    url: &str,
    extra_headers: &[(HeaderName, HeaderValue)],
    params: &[(&str, &str)],
) -> Result<Response>
Expand description

POST a form-encoded body to a user-influenced URL through the SSRF guard.

The OAuth counterpart to guarded_post_json: PAR, token exchange and refresh are all application/x-www-form-urlencoded. It matters more here than anywhere else that the guard applies — these are the requests that carry the client assertion and the authorization code, so an issuer URL that resolves to loopback or RFC1918 has to fail closed before the credential leaves the process.

Redirects are refused for the same reason as guarded_post_json, and more acutely: a 307 would re-send the assertion and code to the new host.