Latihan 1: SSRF (Server-Side Request Forgery) — Security

Latihan 1 dari materi SSRF (Server-Side Request Forgery) di Security — praktek dengan editor kode interaktif, test case otomatis, dan hint terpandu. Langsung jalan di browser.

Buat fungsi isUrlSafeForFetch(url, allowlist) yang menentukan apakah sebuah URL aman untuk di-fetch oleh server.

Aturan:

  1. URL harus parse-able sebagai URL valid, kalau parsing gagal, return false
  2. Protocol harus https:, selain itu return false (tolak http:, file:, gopher:, dll)
  3. Hostname harus ada di allowlist (array string, case-insensitive), kalau tidak, return false
  4. Jika semua lolos, return true

Contoh:

const ok = ["images.cdn.com", "storage.googleapis.com"];
isUrlSafeForFetch("https://images.cdn.com/pic.jpg", ok) // true
isUrlSafeForFetch("http://images.cdn.com/pic.jpg", ok) // false (http)
isUrlSafeForFetch("https://evil.com/x", ok) // false (not in allowlist)
isUrlSafeForFetch("file:///etc/passwd", ok) // false
isUrlSafeForFetch("bukan-url", ok) // false

Hint