Merge pull request #16986 from jmhbnz/prevent-member-add-ssrf

Disable following redirects when checking peer urls
This commit is contained in:
Benjamin Wang 2023-11-21 10:07:48 +00:00 committed by GitHub
commit 7c0a09b81e
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -240,6 +240,9 @@ func getVersion(lg *zap.Logger, m *membership.Member, rt http.RoundTripper, time
cc := &http.Client{
Transport: rt,
Timeout: timeout,
CheckRedirect: func(req *http.Request, via []*http.Request) error {
return http.ErrUseLastResponse
},
}
var (
err error