mirror of
https://github.com/InvoiceShelf/InvoiceShelf.git
synced 2026-08-04 15:12:12 +00:00
* fix: allow Gotenberg to reach private/Docker-internal hosts (Issue #688) The SSRF guard introduced in #664/#671 correctly blocks arbitrary private URLs, but also prevents legitimate use-cases where Gotenberg runs alongside InvoiceShelf in a Docker Compose network (e.g. the default http://pdf:3000 service name resolves to a private IP). Add a `gotenberg_allow_private_host` setting (env: GOTENBERG_ALLOW_PRIVATE_HOST, default false) that: - skips PrivateNetworkGuard in GotenbergPdfDriver - skips PublicHttpUrl validation in PDFConfigurationRequest - exposes a clearly-warned toggle in the admin PDF settings UI - is persisted to the settings table and loaded via AppConfigProvider A disabled guard is safe for controlled private networks (Docker Compose, LAN); it must never be enabled for untrusted hosts. The UI surfaces a prominent warning to communicate this constraint. Closes #688 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * refactor(gotenberg): scope the private-host exemption to a declared host Reshapes the escape hatch from a boolean admin setting into an environment-declared host allowlist. The driver streams the upstream response body back as the PDF, so a mis-set Gotenberg host is full-response SSRF — pointed at a link-local metadata endpoint it returns cloud credentials. A blanket "allow private" switch left that reachable: gotenberg_host stays editable from the admin UI, so any install that enabled the switch to run a sidecar could have the host repointed at an internal service. The population the flag existed to serve was exactly the population it failed to protect. GOTENBERG_ALLOWED_PRIVATE_HOST now names the single host that may skip the guard. Only that exact value is exempt; every other private target stays blocked. GotenbergHostPolicy owns the comparison so the save-time rule and the runtime driver guard cannot drift, and normalises case, trailing slash and surrounding whitespace on both sides. Being env-only also drops the settings-table key, the AppConfigProvider branch and the whole admin UI surface — the toggle there could not be switched on in any case, since BaseSwitchSection has no slot and was passed no v-model, so the child BaseSwitch was discarded and the value never changed from false. Restores the gotenberg_margins validation rule, which the previous revision replaced rather than added alongside. Tests cover both directions, including that declaring one private host does not exempt another; sabotaging the policy to always exempt fails 16 of the 22. Co-authored-by: csoscd <csoscd@users.noreply.github.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Darko Gjorgjijoski <dg@darkog.com> Co-authored-by: csoscd <csoscd@users.noreply.github.com>
77 lines
2.3 KiB
PHP
77 lines
2.3 KiB
PHP
<?php
|
|
|
|
namespace App\Http\Requests;
|
|
|
|
use App\Rules\PublicHttpUrl;
|
|
use App\Support\Pdf\GotenbergHostPolicy;
|
|
use Illuminate\Foundation\Http\FormRequest;
|
|
use Illuminate\Validation\Rule;
|
|
|
|
class PDFConfigurationRequest extends FormRequest
|
|
{
|
|
/**
|
|
* Determine if the user is authorized to make this request.
|
|
*/
|
|
public function authorize(): bool
|
|
{
|
|
return true;
|
|
}
|
|
|
|
/**
|
|
* Get the validation rules that apply to the request.
|
|
*/
|
|
public function rules(): array
|
|
{
|
|
switch ($this->get('pdf_driver')) {
|
|
case 'dompdf':
|
|
return [
|
|
'pdf_driver' => [
|
|
'required',
|
|
'string',
|
|
],
|
|
];
|
|
|
|
case 'gotenberg':
|
|
// The operator-declared Gotenberg host skips the private-network
|
|
// check; anything else is still held to it. See GotenbergHostPolicy.
|
|
$isDeclaredHost = GotenbergHostPolicy::isExemptFromPrivateNetworkGuard(
|
|
$this->input('gotenberg_host')
|
|
);
|
|
|
|
return [
|
|
'pdf_driver' => [
|
|
'required',
|
|
'string',
|
|
],
|
|
'gotenberg_host' => [
|
|
'required',
|
|
'url',
|
|
Rule::when(! $isDeclaredHost, [new PublicHttpUrl]),
|
|
],
|
|
'gotenberg_papersize' => [
|
|
'required',
|
|
'string',
|
|
function ($attribute, $value, $fail) {
|
|
$reg = "/^\d+(pt|px|pc|mm|cm|in) \d+(pt|px|pc|mm|cm|in)$/";
|
|
if (! preg_match($reg, $value)) {
|
|
$fail('Invalid papersize, must be in format "210mm 297mm". Accepts: pt,px,pc,mm,cm,in');
|
|
}
|
|
},
|
|
],
|
|
'gotenberg_margins' => [
|
|
'nullable',
|
|
'string',
|
|
],
|
|
];
|
|
|
|
default:
|
|
return [
|
|
'pdf_driver' => [
|
|
'required',
|
|
'string',
|
|
],
|
|
];
|
|
}
|
|
}
|
|
}
|