API: utils/ssrf

better-web-search-mcp


better-web-search-mcp / utils/ssrf

utils/ssrf#

Classes#

BlockedUrlError#

Defined in: src/utils/ssrf.ts:21

A URL rejected because it does not point at a public internet host.

Extends#

  • Error

Constructors#

Constructor#

new BlockedUrlError(url, reason): BlockedUrlError

Defined in: src/utils/ssrf.ts:25

Parameters#
ParameterType
urlstring
reasonstring
Returns#

BlockedUrlError

Overrides#

Error.constructor

Properties#

PropertyModifierTypeDescriptionInherited fromDefined in
cause?publicunknown-Error.causenode_modules/typescript/lib/lib.es2022.error.d.ts:26
messagepublicstring-Error.messagenode_modules/typescript/lib/lib.es5.d.ts:1077
namepublicstring-Error.namenode_modules/typescript/lib/lib.es5.d.ts:1076
stack?publicstring-Error.stacknode_modules/typescript/lib/lib.es5.d.ts:1078
urlreadonlystringThe URL that was rejected.-src/utils/ssrf.ts:23
stackTraceLimitstaticnumberThe Error.stackTraceLimit property specifies the number of stack frames collected by a stack trace (whether generated by new Error().stack or Error.captureStackTrace(obj)). The default value is 10 but may be set to any valid JavaScript number. Changes will affect any stack trace captured after the value has been changed. If set to a non-number value, or set to a negative number, stack traces will not capture any frames.Error.stackTraceLimitnode_modules/@types/node/globals.d.ts:68

Methods#

captureStackTrace()#

static captureStackTrace(targetObject, constructorOpt?): void

Defined in: node_modules/@types/node/globals.d.ts:52

Creates a .stack property on targetObject, which when accessed returns a string representing the location in the code at which Error.captureStackTrace() was called.

const myObject = {};
Error.captureStackTrace(myObject);
myObject.stack;  // Similar to `new Error().stack`

The first line of the trace will be prefixed with ${myObject.name}: ${myObject.message}.

The optional constructorOpt argument accepts a function. If given, all frames above constructorOpt, including constructorOpt, will be omitted from the generated stack trace.

The constructorOpt argument is useful for hiding implementation details of error generation from the user. For instance:

function a() {
  b();
}

function b() {
  c();
}

function c() {
  // Create an error without stack trace to avoid calculating the stack trace twice.
  const { stackTraceLimit } = Error;
  Error.stackTraceLimit = 0;
  const error = new Error();
  Error.stackTraceLimit = stackTraceLimit;

  // Capture the stack trace above function b
  Error.captureStackTrace(error, b); // Neither function c, nor b is included in the stack trace
  throw error;
}

a();
Parameters#
ParameterType
targetObjectobject
constructorOpt?Function
Returns#

void

Inherited from#

Error.captureStackTrace

prepareStackTrace()#

static prepareStackTrace(err, stackTraces): any

Defined in: node_modules/@types/node/globals.d.ts:56

Parameters#
ParameterType
errError
stackTracesCallSite[]
Returns#

any

See#

https://v8.dev/docs/stack-trace-api#customizing-stack-traces

Inherited from#

Error.prepareStackTrace

Interfaces#

SsrfDeps#

Defined in: src/utils/ssrf.ts:125

Injectable DNS resolution so tests need no network.

Properties#

PropertyTypeDescriptionDefined in
resolve?(hostname) => Promise<string[]>Resolve a hostname to one or more IP addresses.src/utils/ssrf.ts:127

Functions#

assertPublicUrl()#

assertPublicUrl(url, deps?): Promise<void>

Defined in: src/utils/ssrf.ts:145

Throw BlockedUrlError unless url points at a public host.

Every address the hostname resolves to must be public: a name with both a public and a private record is rejected, since which one the fetch uses is not ours to choose.

Parameters#

ParameterTypeDescription
urlstringThe URL to validate.
depsSsrfDepsInjectable DNS resolution for tests.

Returns#

Promise<void>


isBlockedAddress()#

isBlockedAddress(address): boolean

Defined in: src/utils/ssrf.ts:112

Whether a resolved IP address must not be fetched.

Parameters#

ParameterType
addressstring

Returns#

boolean


isBlockedIpv4()#

isBlockedIpv4(address): boolean

Defined in: src/utils/ssrf.ts:74

Whether an IPv4 address falls inside a blocked range.

Parameters#

ParameterType
addressstring

Returns#

boolean


isBlockedIpv6()#

isBlockedIpv6(address): boolean

Defined in: src/utils/ssrf.ts:94

Whether an IPv6 address is loopback, unspecified, or otherwise non-public.

Parameters#

ParameterType
addressstring

Returns#

boolean