mirror of
https://github.com/InvoiceShelf/InvoiceShelf.git
synced 2026-08-04 15:12:12 +00:00
* fix: allow Gotenberg to reach private/Docker-internal hosts (Issue #688) The SSRF guard introduced in #664/#671 correctly blocks arbitrary private URLs, but also prevents legitimate use-cases where Gotenberg runs alongside InvoiceShelf in a Docker Compose network (e.g. the default http://pdf:3000 service name resolves to a private IP). Add a `gotenberg_allow_private_host` setting (env: GOTENBERG_ALLOW_PRIVATE_HOST, default false) that: - skips PrivateNetworkGuard in GotenbergPdfDriver - skips PublicHttpUrl validation in PDFConfigurationRequest - exposes a clearly-warned toggle in the admin PDF settings UI - is persisted to the settings table and loaded via AppConfigProvider A disabled guard is safe for controlled private networks (Docker Compose, LAN); it must never be enabled for untrusted hosts. The UI surfaces a prominent warning to communicate this constraint. Closes #688 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * refactor(gotenberg): scope the private-host exemption to a declared host Reshapes the escape hatch from a boolean admin setting into an environment-declared host allowlist. The driver streams the upstream response body back as the PDF, so a mis-set Gotenberg host is full-response SSRF — pointed at a link-local metadata endpoint it returns cloud credentials. A blanket "allow private" switch left that reachable: gotenberg_host stays editable from the admin UI, so any install that enabled the switch to run a sidecar could have the host repointed at an internal service. The population the flag existed to serve was exactly the population it failed to protect. GOTENBERG_ALLOWED_PRIVATE_HOST now names the single host that may skip the guard. Only that exact value is exempt; every other private target stays blocked. GotenbergHostPolicy owns the comparison so the save-time rule and the runtime driver guard cannot drift, and normalises case, trailing slash and surrounding whitespace on both sides. Being env-only also drops the settings-table key, the AppConfigProvider branch and the whole admin UI surface — the toggle there could not be switched on in any case, since BaseSwitchSection has no slot and was passed no v-model, so the child BaseSwitch was discarded and the value never changed from false. Restores the gotenberg_margins validation rule, which the previous revision replaced rather than added alongside. Tests cover both directions, including that declaring one private host does not exempt another; sabotaging the policy to always exempt fails 16 of the 22. Co-authored-by: csoscd <csoscd@users.noreply.github.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> Co-authored-by: Darko Gjorgjijoski <dg@darkog.com> Co-authored-by: csoscd <csoscd@users.noreply.github.com>
84 lines
2.7 KiB
PHP
84 lines
2.7 KiB
PHP
<?php
|
|
|
|
namespace App\Support\Pdf;
|
|
|
|
use App\Support\Net\PrivateNetworkGuard;
|
|
|
|
/**
|
|
* Decides whether a Gotenberg host is exempt from {@see PrivateNetworkGuard}.
|
|
*
|
|
* Gotenberg is normally deployed as a sidecar on a private network — the shipped
|
|
* default host is `http://pdf:3000` — which the SSRF guard rejects. The exemption
|
|
* is declared in the environment and names the single host it trusts:
|
|
*
|
|
* GOTENBERG_ALLOWED_PRIVATE_HOST=http://pdf:3000
|
|
*
|
|
* It is deliberately NOT a boolean and deliberately not settable from the admin UI.
|
|
* `gotenberg_host` itself stays editable by any super admin, and the driver returns
|
|
* the upstream response body verbatim as the PDF — so a blanket "allow private"
|
|
* switch would let that setting be repointed at a link-local metadata endpoint and
|
|
* read back the response. Matching one declared host keeps the sidecar working while
|
|
* every other private target stays blocked.
|
|
*
|
|
* Both the save-time validation rule and the runtime driver guard call this, so the
|
|
* two layers cannot drift apart.
|
|
*/
|
|
class GotenbergHostPolicy
|
|
{
|
|
/**
|
|
* Whether the given host is the operator-declared Gotenberg host, and may
|
|
* therefore skip the private-network check.
|
|
*/
|
|
public static function isExemptFromPrivateNetworkGuard(?string $host): bool
|
|
{
|
|
$allowed = config('pdf.connections.gotenberg.allowed_private_host');
|
|
|
|
if (! is_string($allowed) || ! is_string($host)) {
|
|
return false;
|
|
}
|
|
|
|
$allowed = self::normalize($allowed);
|
|
$host = self::normalize($host);
|
|
|
|
// An unset or unparseable allowlist never exempts anything.
|
|
return $allowed !== null && $allowed === $host;
|
|
}
|
|
|
|
/**
|
|
* Reduce a URL to scheme://host[:port][/path] with casing and any trailing
|
|
* slash removed, so `HTTP://PDF:3000/` and `http://pdf:3000` compare equal.
|
|
*
|
|
* Returns null when the value is empty or carries no scheme and host.
|
|
*/
|
|
private static function normalize(string $url): ?string
|
|
{
|
|
$url = trim($url);
|
|
|
|
if ($url === '') {
|
|
return null;
|
|
}
|
|
|
|
$parts = parse_url($url);
|
|
|
|
if ($parts === false || ! isset($parts['scheme'], $parts['host'])) {
|
|
return null;
|
|
}
|
|
|
|
// parse_url keeps IPv6 literals bracketed; strip them on both sides so the
|
|
// comparison is consistent.
|
|
$host = strtolower(trim($parts['host'], '[]'));
|
|
|
|
if ($host === '') {
|
|
return null;
|
|
}
|
|
|
|
return sprintf(
|
|
'%s://%s%s%s',
|
|
strtolower($parts['scheme']),
|
|
$host,
|
|
isset($parts['port']) ? ':'.$parts['port'] : '',
|
|
rtrim($parts['path'] ?? '', '/'),
|
|
);
|
|
}
|
|
}
|