fix(server): apply the outbound address policy to remote cert pinning

The remote certificate fetch now dials through the same netsafe guard
as the REALITY target scan. A private or loopback endpoint is refused
unless the request carries allowPrivate; the inbound form asks the
operator to confirm and retries with the opt-in.
This commit is contained in:
MHSanaei
2026-10-03 13:20:00 +02:00
parent d31465e37b
commit ede275e4dc
8 changed files with 87 additions and 8 deletions
+4
View File
@@ -7797,6 +7797,10 @@
"server": {
"type": "string",
"description": "Remote server as domain or domain:port (default port 443), e.g. cloudflare-dns.com."
},
"allowPrivate": {
"type": "boolean",
"description": "Ping a private/internal/loopback server (LAN, Docker service name). Default false (SSRF guard blocks it and the error response sets obj.privateTarget=true)."
}
},
"required": [