Files
InvoiceShelf/.env.example
T
Darko Gjorgjijoski 4d6ece6230 fix(gotenberg): allow a declared private host past the SSRF guard (#700)
Backport of InvoiceShelf/InvoiceShelf#691 to 2.x, for the reporter of
#688 who is on 2.4.1.

The guard added in the 2.4.0 security round rejects private addresses,
which includes the shipped default host `http://pdf:3000` and every
Docker Compose sidecar deployment. So the guard rejects its own default
and Gotenberg cannot be configured at all on the standard setup — a
usability regression introduced by a security patch, which is why this
lands during the 2.x feature freeze.

GOTENBERG_ALLOWED_PRIVATE_HOST names the single host that may skip the
check. It is deliberately not a boolean and not settable from the admin
UI: the driver streams the upstream response body back as the PDF, so a
blanket "allow private" switch would let gotenberg_host be repointed at
a link-local metadata endpoint and the response read back. Naming one
host keeps the sidecar working while every other private target stays
blocked.

GotenbergHostPolicy owns the comparison so the save-time rule and the
runtime driver guard cannot drift, normalising case, trailing slash and
surrounding whitespace on both sides.

Note this differs from 3.x in one respect: SafeRemoteUrl rejects hosts
that do not resolve, where 3.x's PrivateNetworkGuard lets them through.
That behaviour is unchanged here — a typo'd host is still refused at save
time on 2.x, which is the friendlier outcome.
2026-07-29 11:46:53 +02:00

35 lines
1018 B
Bash

APP_ENV=production
APP_DEBUG=false
APP_KEY=base64:kgk/4DW1vEVy7aEvet5FPp5un6PIGe/so8H0mvoUtW0=
APP_NAME="InvoiceShelf"
APP_TIMEZONE=UTC
APP_URL=
APP_LOCALE=en
DB_CONNECTION=sqlite
DB_HOST=
DB_PORT=
DB_DATABASE=
DB_USERNAME=
DB_PASSWORD=
SESSION_DOMAIN=null
SANCTUM_STATEFUL_DOMAIN=
TRUSTED_PROXIES="*"
# Dompdf: keep false so untrusted HTML in PDF notes cannot trigger outbound requests (SSRF).
# Set true only if you fully trust all PDF HTML and need remote images/CSS.
DOMPDF_ENABLE_REMOTE=false
# Gotenberg (optional alternative PDF driver; the default is dompdf).
# PDF_DRIVER=gotenberg
# GOTENBERG_HOST=http://pdf:3000
# GOTENBERG_PAPERSIZE="210mm 297mm"
#
# Gotenberg is normally a sidecar on a private network, which the SSRF guard
# rejects. Name that one host to exempt it — and only it. Every other private
# target stays blocked, so the host cannot later be repointed at an internal
# service. Leave unset unless you actually run Gotenberg privately.
# GOTENBERG_ALLOWED_PRIVATE_HOST=http://pdf:3000