Skip to main content

isPrivateAddress

@forge/monorepo


@forge/monorepo / backend/src / isPrivateAddress

Function: isPrivateAddress()

isPrivateAddress(address): boolean

Defined in: backend/src/toolkit/ssrf.ts:126

The SSRF-hardened fetch, shared — REQ-055 (#237), tasks #238 and #239.

It was written for tools-scrape and lives here because tools-browser needs the same implementation rather than a second copy: a browser navigating to 169.254.169.254 is the same hole as a fetch doing it, and two copies of an address classifier is how one of them ends up missing the IPv6-mapped forms.

Not a replacement for mcp/egress.ts, which is deliberately stricter. That one denies every IPv6 literal unless explicitly allowed, which is right for an MCP endpoint an operator configures once and wrong for scraping the open web, where a great many real sites are v6-only. They differ because the questions differ, and merging them would mean picking one answer for both.

Parameters

address

string

Returns

boolean