Skip to content

Commit

Permalink
fix(NET-760): check for private network range
Browse files Browse the repository at this point in the history
  • Loading branch information
Aceix committed Dec 11, 2023
1 parent 530dbdc commit 20f9b4f
Showing 1 changed file with 35 additions and 0 deletions.
35 changes: 35 additions & 0 deletions controllers/network.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ import (
"encoding/json"
"errors"
"fmt"
"net"
"net/http"
"strings"

Expand Down Expand Up @@ -246,6 +247,40 @@ func createNetwork(w http.ResponseWriter, r *http.Request) {
return
}

// validate address ranges: must be private
if network.AddressRange != "" {
_, ipNet, err := net.ParseCIDR(network.AddressRange)
if err != nil {
logger.Log(0, r.Header.Get("user"), "failed to create network: ",
err.Error())
logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
return
}
if !ipNet.IP.IsPrivate() {
err := errors.New("address range must be private")
logger.Log(0, r.Header.Get("user"), "failed to create network: ",
err.Error())
logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
return
}
}
if network.AddressRange6 != "" {
_, ipNet, err := net.ParseCIDR(network.AddressRange6)
if err != nil {
logger.Log(0, r.Header.Get("user"), "failed to create network: ",
err.Error())
logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
return
}
if !ipNet.IP.IsPrivate() {
err := errors.New("address range must be private")
logger.Log(0, r.Header.Get("user"), "failed to create network: ",
err.Error())
logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
return
}
}

network, err = logic.CreateNetwork(network)
if err != nil {
logger.Log(0, r.Header.Get("user"), "failed to create network: ",
Expand Down

0 comments on commit 20f9b4f

Please sign in to comment.