Resolve each candidate image/page/stylesheet URL and refuse loopback, RFC1918, link-local (cloud-metadata), reserved, multicast, and unspecified targets before fetching; re-validate on every redirect hop via a custom opener. URLs originate from external search-result content, so this closes the operator server fetching internal services. |
||
|---|---|---|
| .. | ||
| operator_gui | ||
| rights_filter | ||