mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix(coderd): block SSRF in MCP OAuth2 discovery and client registration (#27989)
This commit is contained in:
@@ -13,6 +13,7 @@ import (
|
||||
"math"
|
||||
"net/http"
|
||||
httppprof "net/http/pprof"
|
||||
"net/netip"
|
||||
"net/url"
|
||||
"path/filepath"
|
||||
"regexp"
|
||||
@@ -261,6 +262,13 @@ type Options struct {
|
||||
SSHConfig codersdk.SSHConfigResponse
|
||||
|
||||
HTTPClient *http.Client
|
||||
// MCPOAuth2DiscoveryAllowedIPRanges exempts IP ranges from the
|
||||
// SSRF guard applied to MCP OAuth2 metadata discovery and dynamic
|
||||
// client registration, which refuse private/internal destinations
|
||||
// by default. This is a seam for tests, which serve their mock MCP
|
||||
// servers on loopback; there is intentionally no user-facing
|
||||
// configuration for it.
|
||||
MCPOAuth2DiscoveryAllowedIPRanges []netip.Prefix
|
||||
// ChatStreamPartsDialer dials remote chat stream parts.
|
||||
// Set by enterprise for HA deployments. Nil uses chatd's local
|
||||
// in-process channel dialer.
|
||||
|
||||
Reference in New Issue
Block a user