Files
coolify/app/Providers/AppServiceProvider.php
T
Andras BacsaiandClaude Opus 5.5 e17b15f5f1 fix(sources): allow private networks for self-hosted Git sources
Since GitHub App and GitLab API calls use the outbound URL guard,
GitHub Enterprise or GitLab on a private network failed with "Webhook
URL resolved to an unsafe IP address" unless an admin allow-listed it.

On self-hosted instances, Git source URLs and requests now allow
private (RFC 1918), CGNAT (100.64/10, Tailscale), and IPv6 unique local
addresses, plus internal hostnames such as .internal, .local, and
container names. Loopback, localhost, link-local (cloud metadata),
0.0.0.0, and other reserved targets stay blocked. Redirects stay off
and DNS stays pinned. Coolify Cloud and all other outbound URLs keep
the strict rules.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:52:01 +02:00

135 lines
4.1 KiB
PHP

<?php
namespace App\Providers;
use App\Auth\Oidc\OidcDiscoveryService;
use App\Auth\Oidc\OidcTokenValidator;
use App\Auth\Oidc\Socialite\OidcProvider;
use App\Models\PersonalAccessToken;
use App\Rules\SafeExternalUrl;
use Illuminate\Database\Eloquent\Model;
use Illuminate\Support\Facades\App;
use Illuminate\Support\Facades\DB;
use Illuminate\Support\Facades\Http;
use Illuminate\Support\Facades\Queue;
use Illuminate\Support\Once;
use Illuminate\Support\ServiceProvider;
use Illuminate\Validation\Rules\Password;
use Laravel\Sanctum\Sanctum;
use Laravel\Socialite\Contracts\Factory as SocialiteFactory;
use Stripe\StripeClient;
class AppServiceProvider extends ServiceProvider
{
public function register(): void
{
$this->app->bind(StripeClient::class, fn () => new StripeClient(config('subscription.stripe_api_key')));
}
public function boot(): void
{
$this->configureCommands();
$this->configureModels();
$this->configurePasswords();
$this->configureSanctumModel();
$this->configureGitHubHttp();
$this->configureGitLabHttp();
$this->configureOidcSocialite();
$this->configureQueue();
}
/**
* Queue workers are long-running processes, so once() values (e.g. instanceSettings())
* would stay stale across jobs. Flush them before each job, like a fresh web request.
*/
private function configureQueue(): void
{
Queue::before(fn () => Once::flush());
}
private function configureCommands(): void
{
if (App::isProduction()) {
DB::prohibitDestructiveCommands();
}
}
private function configureModels(): void
{
// Disabled because it's causing issues with the application
// Model::shouldBeStrict();
}
private function configurePasswords(): void
{
Password::defaults(function () {
return App::isProduction()
? Password::min(8)
->mixedCase()
->letters()
->numbers()
->symbols()
->uncompromised()
: Password::min(8)->letters();
});
}
private function configureSanctumModel(): void
{
Sanctum::usePersonalAccessTokenModel(PersonalAccessToken::class);
}
private function configureOidcSocialite(): void
{
if (! $this->app->bound(SocialiteFactory::class)) {
return;
}
$this->app->make(SocialiteFactory::class)->extend('oidc', function ($app) {
return new OidcProvider(
$app['request'],
$app->make(OidcDiscoveryService::class),
$app->make(OidcTokenValidator::class),
'',
'',
'',
);
});
}
private function configureGitHubHttp(): void
{
Http::macro('GitSource', function (string $url) {
return Http::withOptions(SafeExternalUrl::httpClientOptions(
$url,
allowPrivateNetworks: SafeExternalUrl::gitSourcesMayUsePrivateNetworks(),
));
});
Http::macro('GitHub', function (string $api_url, ?string $github_access_token = null) {
if ($github_access_token) {
return Http::GitSource($api_url)->withHeaders([
'X-GitHub-Api-Version' => '2022-11-28',
'Accept' => 'application/vnd.github.v3+json',
'Authorization' => "Bearer $github_access_token",
])->baseUrl($api_url);
} else {
return Http::GitSource($api_url)->withHeaders([
'Accept' => 'application/vnd.github.v3+json',
])->baseUrl($api_url);
}
});
}
private function configureGitLabHttp(): void
{
Http::macro('GitLab', function (string $api_url, ?string $access_token = null) {
$client = Http::GitSource($api_url)->withHeaders([
'Accept' => 'application/json',
])->baseUrl($api_url);
return $access_token ? $client->withToken($access_token) : $client;
});
}
}