From 0bece1f8e7133bcdb137a79f2d79746d8d1e56d2 Mon Sep 17 00:00:00 2001 From: Hong Minhee Date: Fri, 9 Oct 2026 08:07:24 +0900 Subject: [PATCH] Remove DNS from mocked WebFinger lookups The WebFinger unit test mocked HTTP responses but still resolved the public hostnames through the SSRF guard. Skip that guard for these mocked lookups so external DNS latency cannot exhaust Bun's timeout. Retain both alias assertions and fetch restoration. A temporary DNS-failure harness fails before the patch and passes with zero DNS calls afterward. The CLI suite passes on Deno, Node.js, and Bun. Note the option rename needed when merging into 2.4 or later. Fixes https://github.com/fedify-dev/fedify/issues/1273 Changelog: none Assisted-by: Codex:gpt-6.1-sol Assisted-by: Claude Code:claude-opus-5-5 --- packages/cli/src/webfinger/mod.test.ts | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/packages/cli/src/webfinger/mod.test.ts b/packages/cli/src/webfinger/mod.test.ts index fedca199f..3e9ab8ca2 100644 --- a/packages/cli/src/webfinger/mod.test.ts +++ b/packages/cli/src/webfinger/mod.test.ts @@ -136,7 +136,10 @@ test("Test lookupSingleWebFinger", async (): Promise => { try { const results = await Array.fromAsync( RESOURCES, - (resource) => lookupSingleWebFinger({ resource }), + // HTTP responses are mocked, so skip the SSRF guard's external DNS lookup. + // TODO: Use allowPrivateAddresses when merging into 2.4-maintenance or later. + (resource) => + lookupSingleWebFinger({ resource, allowPrivateAddress: true }), ); const aliases = results.map((w) => w?.aliases?.[0]);