SSRF protection
SSRF protection stops users from making your server fetch addresses they shouldn't reach, such as http://192.168.1.1/admin or the cloud metadata service at http://169.254.169.254/. It applies when the server loads remote content referenced in files it converts, such as HTML, SVG and office documents. Setting system.disableSanitize: true turns these checks off. URL to PDF ignores these settings.
Configure SSRF protection in Settings → Server → Sign-in & security → HTML URL Security, or under system.html.urlSecurity.
Warning
URL to PDF is off by default because of these risks (Enable URL to PDF in Settings → Server → Advanced → Feature Flags, or system.enableUrlToPDF). Only turn it on for internal use.
Settings#
| Setting | Default | What it does |
|---|---|---|
enabled |
true |
Turn SSRF protection on or off. |
level |
MEDIUM |
OFF, MEDIUM or MAX (see below). |
allowedDomains |
[] |
Domains to allow (see below). |
blockedDomains |
[] |
Extra domains to block in MEDIUM (see below). |
internalTlds |
.local, .internal, .corp, .home |
Domain endings treated as internal. |
blockPrivateNetworks |
true |
Block private ranges (10.x, 172.16-31.x, 192.168.x). |
blockLocalhost |
true |
Block 127.x and ::1. |
blockLinkLocal |
true |
Block 169.254.x and fe80::. |
blockCloudMetadata |
true |
Block cloud provider metadata addresses. |
yaml
system:
html:
urlSecurity:
enabled: true
level: MEDIUM
allowedDomains: []
blockedDomains: []bash
SYSTEM_HTML_URLSECURITY_ENABLED=true
SYSTEM_HTML_URLSECURITY_LEVEL=MEDIUM
SYSTEM_HTML_URLSECURITY_ALLOWEDDOMAINS= # comma-separated
SYSTEM_HTML_URLSECURITY_BLOCKEDDOMAINS= # comma-separatedProtection levels#
MEDIUM(default) blocks private IPs, localhost, cloud metadata and internal domain endings, and allows the public internet.MAXonly allows domains listed inallowedDomains.OFFdoes no checks. Use it only if your network blocks these requests elsewhere.
Allow and block lists#
allowedDomains: inMEDIUM, a non-empty list restricts access to those domains and their subdomains, and the otherMEDIUMchecks still apply. It doesn't keep the rest of the internet open. InMAX, a host must match an entry exactly, so list each subdomain.blockedDomains: only used inMEDIUM, with exact matching. Blockingexample.comdoesn't blocksub.example.com.