SSRF Protection

Description:

Input validation for AI provider URLs prevents Server-Side Request Forgery attacks. Users can only connect to allowed AI providers.

Problem it solves:

Custom AI endpoints could be exploited to make the server access internal resources or malicious URLs.

Key features:

  • URL validation and sanitization

  • Blocked private IP ranges

  • Allowed domain whitelisting

  • Protocol restrictions (HTTPS only)

Please authenticate to join the conversation.

Upvoters
Status

Completed

Board
πŸ’‘

Feature Request

Date

About 1 month ago

Author

Code Cora Team

Subscribe to post

Get notified by email when there are changes.