micro--go-micro
013e6be76b
govulncheck / govulncheck (push) Has been cancelled
Harness (E2E) / Harnesses (mock LLM) (push) Has been cancelled
Harness (E2E) / Provider harnesses (live LLM conformance) (push) Has been cancelled
Lint / golangci-lint (push) Has been cancelled
Run Tests / Unit Tests (push) Has been cancelled
Run Tests / Etcd Integration Tests (push) Has been cancelled
The A2A gateway's push-notification flow (tasks/pushNotificationConfig/set → deliverPush) POSTed task state to a caller-supplied URL via the default HTTP client, so an untrusted A2A caller could aim the gateway at internal addresses (loopback, link-local cloud metadata, RFC1918) it would otherwise never reach — a server-side request forgery vector (#4129). Add a default SSRF-safe policy: only http/https callbacks whose host does not resolve to a loopback, private, link-local, multicast, or unspecified address. It's enforced when the config is set (caller gets a clear rejection, nothing stored) and again at delivery, and the delivery client re-checks the resolved IP at dial time so a name that passes validation can't be rebound to an internal address before connect. Operators that need a trusted in-cluster receiver set Options.AllowPushURL (gateway) or a2a.WithPushURLPolicy (embedded handlers) to own the policy; that path skips the built-in private-IP dial guard by design. Tests cover blocked/allowed URLs, the dial-time guard, set-time rejection, default-deny delivery, and the operator override. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CmdEY7pYmV5zzwCjNJ4ykL