Node fetcher for @linkforty/og-core, hardened for the position it
is usually deployed in: a public, unauthenticated endpoint that accepts a URL
from a stranger and fetches it server-side.
import { inspect } from '@linkforty/og-core';
import { createNodeFetcher } from '@linkforty/og-node';
const result = await inspect(url, { fetcher: createNodeFetcher() });- any protocol other than
httpandhttps - hostnames resolving to loopback, private, link-local, unique-local, unspecified, or IPv4-mapped forms of the same
- redirects into any of the above — the address check re-runs on every hop, because a first-URL-only check is defeated by any open redirect
- more than
maxHopsredirects (default 5) - responses beyond
maxBytes(default 512KB) ortimeoutMs(default 8s)
It forwards no cookies, credentials or headers from the calling request.
DNS rebinding between resolution and fetch is not closed. The impact is bounded
to a single truncated GET body, and closing it properly requires pinning the
resolved IP and overriding the TLS SNI host. This is a considered trade-off, not
an oversight — see the note in src/fetcher.ts.
MIT