Skip to main content

SID-TRANS-04 — SSRF-Protected HTTP Client

PropertyValue
Statusverified
Ownerplatform
Categorytechnical
CSF Functionprotect
GroupTransport Security Controls

Description

SafeHTTPClient blocks: private IP ranges, cloud metadata endpoints (169.254.169.254), DNS rebinding, non-HTTPS connections. Host allowlisting supported. Response body size limits: 10MB general, 1MB JWKS/discovery, 64KB errors.

Components

  • Trust Service (AuthZEN)
  • Wallet Backend (Go)

Source References

Audit Findings

FindingSeverityStatus
EN-P-7 — Partial hardening and error handlingmediumresolved
ISO-T-8 — Partial network securitymediumopen