mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-10-04 21:22:07 +03:00
fix(server): apply the outbound address policy to remote cert pinning
The remote certificate fetch now dials through the same netsafe guard as the REALITY target scan. A private or loopback endpoint is refused unless the request carries allowPrivate; the inbound form asks the operator to confirm and retries with the opt-in.
This commit is contained in:
@@ -7797,6 +7797,10 @@
|
||||
"server": {
|
||||
"type": "string",
|
||||
"description": "Remote server as domain or domain:port (default port 443), e.g. cloudflare-dns.com."
|
||||
},
|
||||
"allowPrivate": {
|
||||
"type": "boolean",
|
||||
"description": "Ping a private/internal/loopback server (LAN, Docker service name). Default false (SSRF guard blocks it and the error response sets obj.privateTarget=true)."
|
||||
}
|
||||
},
|
||||
"required": [
|
||||
|
||||
Reference in New Issue
Block a user