allowPrivateAddress is intended to allow private network addresses, but also skips protocol validation in both built-in document loaders. Non-HTTP URLs reach the runtime's fetch implementation, producing runtime-dependent failures; in #1291, these failures become retryable inbox errors.
At 3f5ca6f (2.4.3 development checkout), Deno 2.9.7 on macOS 27.0.1 reproduces this with:
import { getDocumentLoader } from "@fedify/vocab-runtime";
await getDocumentLoader({ allowPrivateAddress: true })(
"ftp://example.com/collection",
);
Expected: reject the unsupported scheme with UrlError before fetching, regardless of allowPrivateAddress.
Actual: TypeError: Url scheme 'ftp' not supported from runtime fetch. A file: URL also reaches runtime fetch. The same validation gap applies to redirect and alternate document targets, and to getAuthenticatedDocumentLoader() in @fedify/fedify.
#1291 adds HTTP(S) scheme checks independently of private-address validation. This issue also tracks the backport. Both loaders in 2.0-maintenance also skip validatePublicUrl() when private addresses are allowed. Determine the oldest affected maintenance branch before preparing the backport. Carry over #1291's regression tests for direct and redirected URLs with private addresses allowed, and retain HTTP(S) private-address support.
allowPrivateAddressis intended to allow private network addresses, but also skips protocol validation in both built-in document loaders. Non-HTTP URLs reach the runtime's fetch implementation, producing runtime-dependent failures; in #1291, these failures become retryable inbox errors.At 3f5ca6f (2.4.3 development checkout), Deno 2.9.7 on macOS 27.0.1 reproduces this with:
Expected: reject the unsupported scheme with
UrlErrorbefore fetching, regardless ofallowPrivateAddress.Actual:
TypeError: Url scheme 'ftp' not supportedfrom runtime fetch. Afile:URL also reaches runtime fetch. The same validation gap applies to redirect and alternate document targets, and togetAuthenticatedDocumentLoader()in@fedify/fedify.#1291 adds HTTP(S) scheme checks independently of private-address validation. This issue also tracks the backport. Both loaders in
2.0-maintenancealso skipvalidatePublicUrl()when private addresses are allowed. Determine the oldest affected maintenance branch before preparing the backport. Carry over #1291's regression tests for direct and redirected URLs with private addresses allowed, and retain HTTP(S) private-address support.