Files
InvoiceShelf/config/pdf.php
T
Darko Gjorgjijoski 4d6ece6230 fix(gotenberg): allow a declared private host past the SSRF guard (#700)
Backport of InvoiceShelf/InvoiceShelf#691 to 2.x, for the reporter of
#688 who is on 2.4.1.

The guard added in the 2.4.0 security round rejects private addresses,
which includes the shipped default host `http://pdf:3000` and every
Docker Compose sidecar deployment. So the guard rejects its own default
and Gotenberg cannot be configured at all on the standard setup — a
usability regression introduced by a security patch, which is why this
lands during the 2.x feature freeze.

GOTENBERG_ALLOWED_PRIVATE_HOST names the single host that may skip the
check. It is deliberately not a boolean and not settable from the admin
UI: the driver streams the upstream response body back as the PDF, so a
blanket "allow private" switch would let gotenberg_host be repointed at
a link-local metadata endpoint and the response read back. Naming one
host keeps the sidecar working while every other private target stays
blocked.

GotenbergHostPolicy owns the comparison so the save-time rule and the
runtime driver guard cannot drift, normalising case, trailing slash and
surrounding whitespace on both sides.

Note this differs from 3.x in one respect: SafeRemoteUrl rejects hosts
that do not resolve, where 3.x's PrivateNetworkGuard lets them through.
That behaviour is unchanged here — a typo'd host is still refused at save
time on 2.x, which is the friendlier outcome.
2026-07-29 11:46:53 +02:00

47 lines
1.6 KiB
PHP

<?php
return [
/*
|--------------------------------------------------------------------------
| Default PDF Driver
|--------------------------------------------------------------------------
| Here you may specify which of the PDF drivers below you wish to use as
| your default driver for all PDF generation.
|
*/
'driver' => env('PDF_DRIVER', 'dompdf'),
/*
|--------------------------------------------------------------------------
| PDF Connections
|--------------------------------------------------------------------------
|
| Here are each of the connections setup for your application. Example
| configuration has been included, but you may add as many connections as
| you would like.
|
*/
'connections' => [
'dompdf' => [],
'gotenberg' => [
'host' => env('GOTENBERG_HOST', 'http://pdf:3000'),
'papersize' => env('GOTENBERG_PAPERSIZE', '210mm 297mm'),
/*
* Gotenberg usually runs as a sidecar on a private network, which the
* SSRF guard rejects. Name that one host here to exempt it — e.g.
* GOTENBERG_ALLOWED_PRIVATE_HOST=http://pdf:3000. Only this exact value
* is exempt; the guard still blocks every other private target, so the
* host setting cannot be repointed at an internal service. No default:
* the `host` fallback above must never be trusted implicitly.
*/
'allowed_private_host' => env('GOTENBERG_ALLOWED_PRIVATE_HOST'),
],
],
];