INNER CODE UNIT · Python
_ip_blocked
tiliondev/fortress · mcp/server.py:64
def _ip_blocked(ip_str: str) -> bool:
import ipaddress
try:
ip = ipaddress.ip_address(ip_str)
except ValueError:
return False
# normalise IPv4-mapped IPv6 (::ffff:169.254.169.254) to the v4 checks
if getattr(ip, "ipv4_mapped", None) is not None:
ip = ip.ipv4_mapped
return (ip.is_private or ip.is_loopback or ip.is_link_local
or ip.is_reserved or ip.is_multicast or ip.is_unspecified)
async def _check_url(url: str) -> None:
"""SSRF guard for the local MCP: refuse localhost / private / cloud-metadata
targets unless the operator opts in with TILION_ALLOW_PRIVATE_EGRESS=1.
DNS resolution goes through the event loop's ASYNC resolver — a blocking