Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 
 
 
 
 
 
 
 
 

README.md

@linkforty/og-node

Node fetcher for @linkforty/og-core, hardened for the position it is usually deployed in: a public, unauthenticated endpoint that accepts a URL from a stranger and fetches it server-side.

import { inspect } from '@linkforty/og-core';
import { createNodeFetcher } from '@linkforty/og-node';

const result = await inspect(url, { fetcher: createNodeFetcher() });

What it refuses

  • any protocol other than http and https
  • hostnames resolving to loopback, private, link-local, unique-local, unspecified, or IPv4-mapped forms of the same
  • redirects into any of the above — the address check re-runs on every hop, because a first-URL-only check is defeated by any open redirect
  • more than maxHops redirects (default 5)
  • responses beyond maxBytes (default 512KB) or timeoutMs (default 8s)

It forwards no cookies, credentials or headers from the calling request.

Known limitation

DNS rebinding between resolution and fetch is not closed. The impact is bounded to a single truncated GET body, and closing it properly requires pinning the resolved IP and overriding the TLS SNI host. This is a considered trade-off, not an oversight — see the note in src/fetcher.ts.

MIT