Files
node/server/http/allowed_hosts.go
Hanzo AI c3b398bc7b json: migrate every encoding/json import to json/v2 (go-json-experiment)
External (HTTP / JSON-RPC) is the only place JSON is legitimate. Every
existing encoding/json import in node/ moves to github.com/go-json-experiment/json
(v2 root, not the v1 sub-package). NewEncoder/NewDecoder rewrite to
MarshalWrite/UnmarshalRead. MarshalIndent rewrites to Marshal with
jsontext.WithIndent. json.RawMessage rewrites to jsontext.Value.
*json.SyntaxError rewrites to *jsontext.SyntacticError.

81 files migrated. LLM.md captures the rule + v1->v2 delta table.

Known v2 semantic deltas surfaced by existing tests (followups, not regressions):
- [N]byte fields with no MarshalJSON now marshal as base64 string (v1 marshalled
  as JSON array of byte numbers). Affects vms/platformvm/txs/*_test.go fixtures
  with embedded BLS proofOfPossession.
- time.Duration has no v2 default representation; configs that wire-format
  Duration as nanoseconds (vms/{xvm,platformvm}/config, config/spec) need to
  switch to string-form Duration or carry an explicit option. v2 root does not
  re-export FormatDurationAsNano.
- v2 enforces strict UTF-8 (vms/chainadapter/messaging fixture has non-UTF-8).
- json.MarshalWrite does not append a trailing '\n' (v1 NewEncoder.Encode did);
  service/auth/auth_test.go expectation updated.
- nil []byte round-trips to empty (not nil); config_test deep-equal fixtures
  surface this.

All affected sites are at the API boundary; ZAP wire envelope already covers
the internal data paths (state, P2P, consensus, MPC, threshold). Internal
JSON sites that should move to ZAP next (separate work):
- vms/da/store.go            (DA blob/cert storage as JSON)
- vms/platformvm/airdrop     (airdrop claims as JSON in db)
- vms/chainadapter/appchain  (SQLite materializer schema/data blobs)
- vms/chainadapter/messaging (conversation codec)
- staking/kms.go             (KMS HTTP client — external technically, leave)
- utils/{bimap,ips}          (small marshaler shims — low priority)
2026-06-06 22:26:02 -07:00

89 lines
2.1 KiB
Go

// Copyright (C) 2019-2025, Lux Industries Inc. All rights reserved.
// See the file LICENSE for licensing terms.
package server
import (
"net"
"net/http"
"strings"
"github.com/go-json-experiment/json"
"github.com/luxfi/math/set"
)
const wildcard = "*"
var _ http.Handler = (*allowedHostsHandler)(nil)
func filterInvalidHosts(
handler http.Handler,
allowed []string,
) http.Handler {
s := make(set.Set[string])
for _, host := range allowed {
if host == wildcard {
// wildcards match all hostnames, so just return the base handler
return handler
}
s.Add(strings.ToLower(host))
}
return &allowedHostsHandler{
handler: handler,
hosts: s,
}
}
// allowedHostsHandler is an implementation of http.Handler that validates the
// http host header of incoming requests. This can prevent DNS rebinding attacks
// which do not utilize CORS-headers. Http request host headers are validated
// against a whitelist to determine whether the request should be dropped or
// not.
type allowedHostsHandler struct {
handler http.Handler
hosts set.Set[string]
}
func (a *allowedHostsHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
// if the host header is missing we can serve this request because dns
// rebinding attacks rely on this header
if r.Host == "" {
a.handler.ServeHTTP(w, r)
return
}
host, _, err := net.SplitHostPort(r.Host)
if err != nil {
// either invalid (too many colons) or no port specified
host = r.Host
}
if ipAddr := net.ParseIP(host); ipAddr != nil {
// accept requests from ips
a.handler.ServeHTTP(w, r)
return
}
// a specific hostname - we need to check the whitelist to see if we should
// accept this r
if a.hosts.Contains(strings.ToLower(host)) {
a.handler.ServeHTTP(w, r)
return
}
// Return error as JSON
w.Header().Set("Content-Type", "application/json")
w.WriteHeader(http.StatusForbidden)
_ = json.MarshalWrite(w, map[string]interface{}{
"jsonrpc": "2.0",
"error": map[string]interface{}{
"code": -32001,
"message": "invalid host specified",
"data": map[string]string{"host": host},
},
"id": nil,
})
}