summaryrefslogtreecommitdiff
path: root/lib/gitlab/url_blockers/url_whitelist.rb
blob: a0cfcbc49a3f0f9ca2b48d024782175b883a0430 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
# frozen_string_literal: true

module Gitlab
  module UrlBlockers
    class UrlWhitelist
      class << self
        def ip_whitelisted?(ip_string)
          return false if ip_string.blank?

          ip_whitelist, _ = outbound_local_requests_whitelist_arrays
          ip_obj = Gitlab::Utils.string_to_ip_object(ip_string)

          ip_whitelist.any? { |ip| ip.include?(ip_obj) }
        end

        def domain_whitelisted?(domain_string)
          return false if domain_string.blank?

          _, domain_whitelist = outbound_local_requests_whitelist_arrays

          domain_whitelist.include?(domain_string)
        end

        private

        attr_reader :ip_whitelist, :domain_whitelist

        # We cannot use Gitlab::CurrentSettings as ApplicationSetting itself
        # calls this class. This ends up in a cycle where
        # Gitlab::CurrentSettings creates an ApplicationSetting which then
        # calls this method.
        #
        # See https://gitlab.com/gitlab-org/gitlab-ee/issues/9833
        def outbound_local_requests_whitelist_arrays
          return [[], []] unless ApplicationSetting.current

          ApplicationSetting.current.outbound_local_requests_whitelist_arrays
        end
      end
    end
  end
end