mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-26 09:52:11 +03:00
Webhooks hardcoded parseAndValidatePublicUrl, which blocks any RFC1918/loopback host — breaking self-hosted setups that legitimately point webhooks at internal services (n8n, Home Assistant, a LAN box). Provider URLs already had an opt-in (OMNIROUTE_ALLOW_PRIVATE_PROVIDER_URLS); webhooks now reuse it. - outboundUrlGuard: add parseAndValidateWebhookUrl — gates the private-host check on arePrivateProviderUrlsAllowed() (default OFF); protocol + embedded-credential checks stay unconditional. - swap all webhook call sites (create/update/test/validate-url + dispatcher x2) to it. Regression test: tests/unit/webhook-private-optin-3269.test.ts (RED before, GREEN after); existing webhook SSRF/dispatcher suites stay green (33/33).