From 6426912946270bb02e7b94508008edf8f949d993 Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Thu, 1 Oct 2026 09:49:58 +0200 Subject: fix(node): link previews connect to the address they checked, without blocking The name is resolved off the event loop and every answer checked; the socket is then opened to that IP literal through a pinned httpcore backend, TLS still verifying the certificate for the name, and no proxy from the environment. A name that answers clean and then with a LAN address no longer gets a request sent there, and a slow name no longer stalls the node (F-12). Co-Authored-By: Claude Opus 5.5 --- packages/meshbay-node/src/meshbay_node/transport/webrtc/chat.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'packages/meshbay-node/src/meshbay_node/transport/webrtc/chat.py') diff --git a/packages/meshbay-node/src/meshbay_node/transport/webrtc/chat.py b/packages/meshbay-node/src/meshbay_node/transport/webrtc/chat.py index 26ec27c..5ef153e 100644 --- a/packages/meshbay-node/src/meshbay_node/transport/webrtc/chat.py +++ b/packages/meshbay-node/src/meshbay_node/transport/webrtc/chat.py @@ -598,7 +598,7 @@ class ChatMixin: the client asks, the node produces on demand, the asking device caches — nothing durable here). - `linkpreview.safe_url` is the SSRF gate: the URL a *member* chose + `linkpreview.check_url` is the SSRF gate: the URL a *member* chose decides an outbound request from the operator's machine, so http(s) only and the resolved address must be globally routable. Failure of any kind — blocked, unreachable, not HTML, nothing worth showing — -- cgit v1.2.3