INNER CODE UNIT · Python

_ip_blocked

tiliondev/fortress · mcp/server.py:64

def _ip_blocked(ip_str: str) -> bool:
    import ipaddress
    try:
        ip = ipaddress.ip_address(ip_str)
    except ValueError:
        return False
    # normalise IPv4-mapped IPv6 (::ffff:169.254.169.254) to the v4 checks
    if getattr(ip, "ipv4_mapped", None) is not None:
        ip = ip.ipv4_mapped
    return (ip.is_private or ip.is_loopback or ip.is_link_local
            or ip.is_reserved or ip.is_multicast or ip.is_unspecified)


async def _check_url(url: str) -> None:
    """SSRF guard for the local MCP: refuse localhost / private / cloud-metadata
    targets unless the operator opts in with TILION_ALLOW_PRIVATE_EGRESS=1.

    DNS resolution goes through the event loop's ASYNC resolver — a blocking

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…