Skip to main content

Module net

Module net 

Source
Expand description

Outbound connections held to an address policy (notifications, and whatever else dials an address an org member chose).

A notification target is chosen by an org member, so it must not become a way into the host’s own network (SSRF). Every destination is resolved here, every address it resolves to is checked, and the connection is made to one of those checked addresses (never re-resolved, so DNS rebinding cannot swap in another), and the connected peer is checked once more. Redirects are never followed. Loopback, private, link-local, CGNAT and other non-public ranges are refused unless the platform admin allows private targets server-wide.

Error messages name the host, never the URL: a webhook URL’s path is a credential (Slack, Discord), as is a Telegram bot token.

Structs§

Net
Where and how outbound connections may go.
Request
An HTTP POST.
Response
What came back.
SendError
A failed send: what went wrong, and whether trying again may help.
Target
A parsed http(s)://host[:port]/path URL.

Constants§

IO_TIMEOUT
How long connecting, and each read or write, may take.

Functions§

check_ip
Why an address may not be reached: Err(reason). Some ranges are never reachable (unspecified, multicast, broadcast); the rest of the non-public ranges only with allow_private.
connect
Connect to one of a host’s checked addresses, and check the peer.
default_tls
A TLS client config on ring with the webpki (Mozilla) roots.
hmac_sha256_hex
HMAC-SHA256 of body under key, as lowercase hex.
parse_inet_aton
Read a host the way inet_aton (and so getaddrinfo) does: one to four parts, each decimal, octal (leading 0) or hex (0x). 2130706433, 0x7f000001, 0177.1 and 127.1 are all 127.0.0.1.
parse_url
Parse a webhook URL. The error never repeats the URL.
post
POST once. Never follows a redirect: a 3xx is a failure like a 4xx.
resolve
Resolve a host and check every address: all must pass, so a name with one public and one private record is refused.
tls
Wrap a connected stream in TLS to host.
tls_with_roots
A TLS client config trusting exactly roots.