Skip to content

Add CURLOPT_RESOLVE and safer following of HTTP redirections - #76

Merged
Alkarex merged 5 commits into
freshrssfrom
CURLOPT_RESOLVE
May 26, 2026
Merged

Add CURLOPT_RESOLVE and safer following of HTTP redirections#76
Alkarex merged 5 commits into
freshrssfrom
CURLOPT_RESOLVE

Conversation

@Alkarex

Copy link
Copy Markdown
Member

Related to:
* FreshRSS/FreshRSS#8400
Fixes upstream:
* simplepie#968
Co-authored-by: Inverle <inverle@proton.me>
Comment threadsrc/File.php Outdated
@Alkarex
Alkarex merged commit 843cc8b into freshrssMay 26, 2026
20 checks passed
@Alkarex
Alkarex deleted the CURLOPT_RESOLVE branch May 26, 2026 20:31
Alkarex added a commit to Inverle/FreshRSS that referenced this pull request May 26, 2026
Alkarex added a commit that referenced this pull request Jun 27, 2026
…-origin) (#78)
* Improve SimplePie redirects (POST to GET, remove authentication cross-origin)
Follow-up of #76FreshRSS/FreshRSS#8400
* PHP 7.2+ compatibility
* Normalize URLs to lowercase when parsing
* Fix wrong URL printed in error message
* Same logic for fsockopen
* Also unset `CURLOPT_USERPWD` during redirects
* Add infinite redirects for the `fsockopen()` path too
* Draft rework CURLOPT_FOLLOWLOCATION
* A bit of documentation
* Minor doc
* Move curl_close
* composer run fix
---------
Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr>
Alkarex added a commit to FreshRSS/FreshRSS that referenced this pull request Jun 28, 2026
* Add SSRF mitigations using `filter_var` and `CURLOPT_RESOLVE`
The idea is to prevent FreshRSS from sending any HTTP requests to internal services, except for the ones that are explicitly allowed in the config.
Based on https://github.com/moodle/moodle/blob/6e82b46a480826d1a85394d9e5087f7d82d1dd52/lib/filelib.php#L3818 and https://github.com/symfony/symfony/blob/8.1/src/Symfony/Component/HttpClient/NoPrivateNetworkHttpClient.phpFreshRSS/simplepie#76FreshRSS/simplepie#78
* Add allowlist setting in Web UI
* make readme
* Update app/i18n/fr/admin.php
Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr>
* make readme again
* make readme
* Further work
Still WIP and needs testing etc.
* Readd previous if check for domain combination allowlist
* Turn POST to GET after redirect
* Improve
* Update config.default.php
Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr>
* make readme
* Skip SSRF check if `CURLOPT_PROXY` is set
* make readme
* Fix `!empty()` mistake
* Respect max redirects feed option when fetching with `httpGet()`
* Respect max redirects during SimplePie fetching + fix bypass
bypass fix: `CURLOPT_FOLLOWLOCATION` was moved below so that emulated redirects are enforced.
* Avoid FreshRSS and Minz code in SimplePie
#8400 (comment)
* Corrected hook code
* phpdoc wrong return type
* Add CIDR support in allowlist
* Implement simple DNS caching
* Suppress `dns_get_record()` warnings
* A bit of proof-reading
* Minor typo
* Fix proxy logic
* Fix HTTP POST redirect logic
* Proofread checkCIDR
Add fixes for several situations
* Remove credentials from URL in logs
* Ensure `CURLOPT_FOLLOWLOCATION` is `false` by setting it at the end
* Fix codesniffer long line
* Fix potential bypass due to wrong return value
If there were no records returned by `dns_get_record()`, no overrides to `CURLOPT_RESOLVE` would get passed,
and a potential bypass could occur, when cURL would try to resolve the domain by itself.
* Put the URL at the end in logs
* Add documentation and environment variable support
* make readme
* Fix wrong behavior in case of IP
* Fix duplicate selector in CSS
* Minor type check change
* i18n fr, en
* Minor type check change
* Fix whitespace i18n fr
* make fix-all
* Fix `$ips_ok` not being returned after domain records were cached
* make readme
* PHPStan fix
* make readme
* Minor syntax in SimplePie
* Only return `null` if no allowed IPs were found
* Add wildcard *, help message
* Consistent docs with help message
* i18n: pl
* SimplePie compatibility PHP 7.2
* make fix-all
* Sync SimplePie
* FreshRSS/simplepie#76
* 💥 Breaking change in the Changelog
* Document `INTERNAL_HOST_ALLOWLIST` in Docker docs
* Remove `Cookie` and `Authorization` headers in `httpGet()` during cross-origin redirect
* Minor whitespace
And same comment convention than below
* Remove authentication headers and change POST to GET on redirect in SimplePie
* Remove .local in Docker example
* Fill in default ports when comparing URL origins
* Remove .local from other places than the Docker example
* Rewrite WebSub subscribe to use `httpGet()`
* make fix-all
* Also unset `CURLOPT_USERPWD` during redirects
* phpcs fix
* Always unset `CURLOPT_FOLLOWLOCATION`
* Bump SimplePie
FreshRSS/simplepie#78
* Update logic for CURLOPT_FOLLOWLOCATION
* Fix PHPStan
* Changelog fix security section
* Update most common RSS Bridge case
https://hub.docker.com/r/rssbridge/rss-bridge
* Replace misleading 127.0.0.1:8080 example for Docker
This does not make sense for a Docker container
---------
Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr>
Alkarex added a commit that referenced this pull request Jul 23, 2026
* Allow restricting `CURLOPT_PROXY` with `get_curl_resolve_info()`
Follow-up of #76FreshRSS/FreshRSS#8950
* Fix wrong for_proxy value returned from `get_curl_resolve_info()`
* Minor CURLPROXY_HTTP
* Implement suggestion
* A few more fixes
---------
Co-authored-by: Alexandre Alapetite <alexandre@alapetite.fr>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Alkarex@Inverle