Feature request: opt-in block_internal_urls egress filter for the library layer
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 45/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- docker, playwright, python
- 領域
- backend, networking, security
調査の方向性
Read crawl4ai/async_crawler_strategy.py and trace the HTTP path through AsyncHTTPCrawlerStrategy._handle_http() and the browser path through browser_manager.py to Playwright goto(). Then compare validate_url_destination and resolve_and_pin in deploy/docker/utils.py and egress_broker.py; the work is done when one shared opt-in filter covers DNS resolution, redirects, and both egress paths without fetching blocked destinations.
索引モデルが issue の本文から書いたものです。
説明
Thanks for following up from the email thread, @ntohidi.
Quick correction on my side: the issue body initially only contained a literal file path — I mistakenly relied on @path expansion with gh api, which doesn't expand files (that's a curl / --body-file flag). Pasting the real content here.
Alignment
We're aligned on the classification. The library is a user agent invoked by a trusted caller, so destination filtering should stay opt-in, and the SSRF trust boundary remains at the Docker API server where egress_broker.py already enforces it. The agentic / LLM-chosen-URL case is the scenario that justifies exposing the same primitives to library callers.
Proposed design
- Flag:
block_internal_urls: bool(defaultFalse, opt-in). Set per-crawl so callers who embed Crawl4AI in an agent can opt in without a global change. - Chokepoint: a single host-validation call inserted right after the existing scheme allow-list check in
AsyncCrawlerStrategy.crawl()(crawl4ai/async_crawler_strategy.py). It must cover both egress paths:- HTTP path:
AsyncHTTPCrawlerStrategy._handle_http()(aiohttp) - Browser path:
browser_manager.py→ Playwrightgoto()
- HTTP path:
- Logic reuse: port the existing
validate_url_destination+resolve_and_pin(DNS pinning) + per-hop redirect revalidation fromdeploy/docker/utils.py/egress_broker.pyinto a shared helper (e.g.crawl4ai/url_safety.py) so the library and the Docker server share one implementation — no duplicated trust logic. - Blocked ranges: loopback (
127.0.0.0/8,::1), private (10/8,172.16/12,192.168/16,fc00::/7), link-local (169.254/16incl. cloud metadata169.254.169.254,fe80::/10), and0.0.0.0/8. The resolved IP must be checked after DNS (pin) and after every redirect hop (revalidate) to prevent DNS-rebinding / redirect-to-internal bypasses. - Behavior on block: raise a
BlockedURLexception (or return a failedCrawlResultwith a clear error) rather than fetching.
Open questions (happy to match maintainer preference)
- Flag name —
block_internal_urlsvsdeny_private_destinationsvsegress_filter? - Where the chokepoint sits — shared base
crawl()vs per-strategy hooks? - Browser redirect following — should the redirect revalidation also cover hops taken by Playwright
goto, or only the initial URL?
I'd be happy to draft the PR implementing this once we settle the surface.
- 主要言語
- Python
- スター
- 84.5k
- フォーク
- 8.7k
- 平均マージ
- 3日 20時間
- マージ済み PR(30日)
- 15
環境構築
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
unclecode/crawl4ai のほかの issue
-
🐞 Bug 🩺 Needs Triage
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
unclecode/crawl4ai#2319 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
[Bug]: Reusing BFSDeepCrawlStrategy leaks the previous crawl's max_pages budget into a fresh runオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
unclecode/crawl4ai#2309 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 84/100
unclecode/crawl4ai#2147 · コメント 3 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
unclecode/crawl4ai#2123 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
🐞 Bug 🩺 Needs Triage
難易度 4/5 3〜5日 初心者へのやさしさ 55/100
メンテナーはふだん 1 日以内に返信
unclecode/crawl4ai の issue をすべて見る
似ている issue
-
bug server
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
sportsdataverse/sportsdataverse-py#641 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
googleapis/google-cloud-python#18532 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信