Skip to content

Reject unsupported document URL schemes with private addresses allowed #1292

Description

@dahlia

allowPrivateAddress is intended to allow private network addresses, but also skips protocol validation in both built-in document loaders. Non-HTTP URLs reach the runtime's fetch implementation, producing runtime-dependent failures; in #1291, these failures become retryable inbox errors.

At 3f5ca6f (2.4.3 development checkout), Deno 2.9.7 on macOS 27.0.1 reproduces this with:

import { getDocumentLoader } from "@fedify/vocab-runtime";

await getDocumentLoader({ allowPrivateAddress: true })(
  "ftp://example.com/collection",
);

Expected: reject the unsupported scheme with UrlError before fetching, regardless of allowPrivateAddress.

Actual: TypeError: Url scheme 'ftp' not supported from runtime fetch. A file: URL also reaches runtime fetch. The same validation gap applies to redirect and alternate document targets, and to getAuthenticatedDocumentLoader() in @fedify/fedify.

#1291 adds HTTP(S) scheme checks independently of private-address validation. This issue also tracks the backport. Both loaders in 2.0-maintenance also skip validatePublicUrl() when private addresses are allowed. Determine the oldest affected maintenance branch before preparing the backport. Carry over #1291's regression tests for direct and redirected URLs with private addresses allowed, and retain HTTP(S) private-address support.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

Fields

Priority

None yet

Effort

None yet

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions