HttpDownloader: add option to prevent access to private network (#11895)
parent
83212118cb
commit
d36cd30d11
|
@ -23,13 +23,14 @@ use Composer\Util\AuthHelper;
|
||||||
use Composer\Util\Url;
|
use Composer\Util\Url;
|
||||||
use Composer\Util\HttpDownloader;
|
use Composer\Util\HttpDownloader;
|
||||||
use React\Promise\Promise;
|
use React\Promise\Promise;
|
||||||
|
use Symfony\Component\HttpFoundation\IpUtils;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* @internal
|
* @internal
|
||||||
* @author Jordi Boggiano <j.boggiano@seld.be>
|
* @author Jordi Boggiano <j.boggiano@seld.be>
|
||||||
* @author Nicolas Grekas <p@tchwork.com>
|
* @author Nicolas Grekas <p@tchwork.com>
|
||||||
* @phpstan-type Attributes array{retryAuthFailure: bool, redirects: int<0, max>, retries: int<0, max>, storeAuth: 'prompt'|bool, ipResolve: 4|6|null}
|
* @phpstan-type Attributes array{retryAuthFailure: bool, redirects: int<0, max>, retries: int<0, max>, storeAuth: 'prompt'|bool, ipResolve: 4|6|null}
|
||||||
* @phpstan-type Job array{url: non-empty-string, origin: string, attributes: Attributes, options: mixed[], progress: mixed[], curlHandle: \CurlHandle, filename: string|null, headerHandle: resource, bodyHandle: resource, resolve: callable, reject: callable}
|
* @phpstan-type Job array{url: non-empty-string, origin: string, attributes: Attributes, options: mixed[], progress: mixed[], curlHandle: \CurlHandle, filename: string|null, headerHandle: resource, bodyHandle: resource, resolve: callable, reject: callable, primaryIp: string}
|
||||||
*/
|
*/
|
||||||
class CurlDownloader
|
class CurlDownloader
|
||||||
{
|
{
|
||||||
|
@ -279,6 +280,7 @@ class CurlDownloader
|
||||||
'bodyHandle' => $bodyHandle,
|
'bodyHandle' => $bodyHandle,
|
||||||
'resolve' => $resolve,
|
'resolve' => $resolve,
|
||||||
'reject' => $reject,
|
'reject' => $reject,
|
||||||
|
'primaryIp' => '',
|
||||||
];
|
];
|
||||||
|
|
||||||
$usingProxy = $proxy->getFormattedUrl(' using proxy (%s)');
|
$usingProxy = $proxy->getFormattedUrl(' using proxy (%s)');
|
||||||
|
@ -505,6 +507,18 @@ class CurlDownloader
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (isset($progress['primary_ip']) && $progress['primary_ip'] !== $this->jobs[$i]['primaryIp']) {
|
||||||
|
if (
|
||||||
|
isset($this->jobs[$i]['options']['prevent_ip_access_callable']) &&
|
||||||
|
is_callable($this->jobs[$i]['options']['prevent_ip_access_callable']) &&
|
||||||
|
$this->jobs[$i]['options']['prevent_ip_access_callable']($progress['primary_ip'])
|
||||||
|
) {
|
||||||
|
throw new TransportException(sprintf('IP "%s" is blocked for "%s".', $progress['primary_ip'], $progress['url']));
|
||||||
|
}
|
||||||
|
|
||||||
|
$this->jobs[$i]['primaryIp'] = (string) $progress['primary_ip'];
|
||||||
|
}
|
||||||
|
|
||||||
// TODO progress
|
// TODO progress
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
|
@ -249,6 +249,10 @@ class RemoteFilesystem
|
||||||
|
|
||||||
$origFileUrl = $fileUrl;
|
$origFileUrl = $fileUrl;
|
||||||
|
|
||||||
|
if (isset($options['prevent_ip_access_callable'])) {
|
||||||
|
throw new \RuntimeException("RemoteFilesystem doesn't support the 'prevent_ip_access_callable' config.");
|
||||||
|
}
|
||||||
|
|
||||||
if (isset($options['gitlab-token'])) {
|
if (isset($options['gitlab-token'])) {
|
||||||
$fileUrl .= (false === strpos($fileUrl, '?') ? '?' : '&') . 'access_token='.$options['gitlab-token'];
|
$fileUrl .= (false === strpos($fileUrl, '?') ? '?' : '&') . 'access_token='.$options['gitlab-token'];
|
||||||
unset($options['gitlab-token']);
|
unset($options['gitlab-token']);
|
||||||
|
|
Loading…
Reference in New Issue