mirror of
https://github.com/InvoiceShelf/InvoiceShelf.git
synced 2026-09-06 15:14:13 +00:00
Backport of InvoiceShelf/InvoiceShelf#691 to 2.x, for the reporter of #688 who is on 2.4.1. The guard added in the 2.4.0 security round rejects private addresses, which includes the shipped default host `http://pdf:3000` and every Docker Compose sidecar deployment. So the guard rejects its own default and Gotenberg cannot be configured at all on the standard setup — a usability regression introduced by a security patch, which is why this lands during the 2.x feature freeze. GOTENBERG_ALLOWED_PRIVATE_HOST names the single host that may skip the check. It is deliberately not a boolean and not settable from the admin UI: the driver streams the upstream response body back as the PDF, so a blanket "allow private" switch would let gotenberg_host be repointed at a link-local metadata endpoint and the response read back. Naming one host keeps the sidecar working while every other private target stays blocked. GotenbergHostPolicy owns the comparison so the save-time rule and the runtime driver guard cannot drift, normalising case, trailing slash and surrounding whitespace on both sides. Note this differs from 3.x in one respect: SafeRemoteUrl rejects hosts that do not resolve, where 3.x's PrivateNetworkGuard lets them through. That behaviour is unchanged here — a typo'd host is still refused at save time on 2.x, which is the friendlier outcome.
47 lines
1.6 KiB
PHP
47 lines
1.6 KiB
PHP
<?php
|
|
|
|
return [
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| Default PDF Driver
|
|
|--------------------------------------------------------------------------
|
|
| Here you may specify which of the PDF drivers below you wish to use as
|
|
| your default driver for all PDF generation.
|
|
|
|
|
*/
|
|
|
|
'driver' => env('PDF_DRIVER', 'dompdf'),
|
|
|
|
/*
|
|
|--------------------------------------------------------------------------
|
|
| PDF Connections
|
|
|--------------------------------------------------------------------------
|
|
|
|
|
| Here are each of the connections setup for your application. Example
|
|
| configuration has been included, but you may add as many connections as
|
|
| you would like.
|
|
|
|
|
*/
|
|
'connections' => [
|
|
|
|
'dompdf' => [],
|
|
|
|
'gotenberg' => [
|
|
'host' => env('GOTENBERG_HOST', 'http://pdf:3000'),
|
|
'papersize' => env('GOTENBERG_PAPERSIZE', '210mm 297mm'),
|
|
|
|
/*
|
|
* Gotenberg usually runs as a sidecar on a private network, which the
|
|
* SSRF guard rejects. Name that one host here to exempt it — e.g.
|
|
* GOTENBERG_ALLOWED_PRIVATE_HOST=http://pdf:3000. Only this exact value
|
|
* is exempt; the guard still blocks every other private target, so the
|
|
* host setting cannot be repointed at an internal service. No default:
|
|
* the `host` fallback above must never be trusted implicitly.
|
|
*/
|
|
'allowed_private_host' => env('GOTENBERG_ALLOWED_PRIVATE_HOST'),
|
|
],
|
|
],
|
|
|
|
];
|