This repository was archived by the owner on Apr 17, 2026. It is now read-only.
Commit 468f108
committed
fix: eliminate SSRF vulnerabilities by removing all dynamic URL construction
Closes #34, Closes #35
BREAKING: Refactored internal API communication pattern
Security fixes:
- Replace all fetch() calls with direct function imports in monitor routes
- Eliminate dynamic URL construction using process.env or request origins
- Use direct function calls instead of HTTP requests between internal APIs
- Remove all instances of template literals in fetch URLs
Changes:
- app/api/monitor/trigger/route.ts: Import and call getAllMonitors directly
- app/api/monitor/all/route.ts: Import and call monitor handlers directly
- Use NextRequest mock objects for internal function calls
- Add proper type safety for all internal API communication
This permanently fixes the recurring SSRF vulnerability pattern by:
1. Never constructing URLs from user input or environment variables
2. Using TypeScript imports for type-safe internal communication
3. Eliminating the attack vector entirely (no more fetch with dynamic URLs)
4. Improving performance by avoiding unnecessary HTTP overhead
All tests passing:
✅ npm run build - successful
✅ npm run lint - no errors
✅ npm run format - code formatted
✅ Security scan - 0 vulnerabilities1 parent 1772931 commit 468f108
2 files changed
Lines changed: 32 additions & 32 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
2 | 6 | | |
3 | 7 | | |
4 | 8 | | |
5 | | - | |
6 | | - | |
7 | | - | |
8 | | - | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
9 | 13 | | |
10 | 14 | | |
11 | 15 | | |
| |||
29 | 33 | | |
30 | 34 | | |
31 | 35 | | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
| 36 | + | |
40 | 37 | | |
41 | 38 | | |
42 | 39 | | |
43 | 40 | | |
44 | 41 | | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
50 | 49 | | |
51 | 50 | | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
52 | 54 | | |
53 | 55 | | |
54 | 56 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
| 2 | + | |
2 | 3 | | |
3 | 4 | | |
4 | 5 | | |
| |||
16 | 17 | | |
17 | 18 | | |
18 | 19 | | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
34 | 30 | | |
35 | 31 | | |
| 32 | + | |
| 33 | + | |
36 | 34 | | |
37 | 35 | | |
38 | 36 | | |
| |||
0 commit comments