You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Plugin outbound requests need cloudflare-dns.com reachable: worth documenting?
#3910
When EmDash runs where network egress is limited to an allow list (a container sandbox, a corporate network), every plugin ctx.http.fetch fails with "Could not resolve hostname: DoH lookup failed: 403", even for hosts in the plugin's allowedHosts. Allowing cloudflare-dns.com as well fixes it, with no code change.
The SSRF guard resolves the target through DNS over HTTPS against a hard-coded endpoint (DEFAULT_DOH_URL = "https://cloudflare-dns.com/dns-query" in src/security/ssrf.ts). setDefaultDnsResolver exists, but it is not exposed as configuration.
Would it make sense to mention this dependency in the plugin capabilities or deployment docs, so operators of restricted networks know to allow it? Is a configurable resolver (a DoH URL, or the platform resolver on Node) something you would consider?
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
When EmDash runs where network egress is limited to an allow list (a container sandbox, a corporate network), every plugin
ctx.http.fetchfails with "Could not resolve hostname: DoH lookup failed: 403", even for hosts in the plugin'sallowedHosts. Allowingcloudflare-dns.comas well fixes it, with no code change.The SSRF guard resolves the target through DNS over HTTPS against a hard-coded endpoint (
DEFAULT_DOH_URL = "https://cloudflare-dns.com/dns-query"insrc/security/ssrf.ts).setDefaultDnsResolverexists, but it is not exposed as configuration.Would it make sense to mention this dependency in the plugin capabilities or deployment docs, so operators of restricted networks know to allow it? Is a configurable resolver (a DoH URL, or the platform resolver on Node) something you would consider?
All reactions