docs(outbound): document the allow-list bypass on every allow-list flag and terminate the example patterns

This commit is contained in:
Julien Neuhart
2026-09-04 19:55:57 +02:00
parent 201e80b9d7
commit 4de9b0f68b
8 changed files with 49 additions and 10 deletions

View File

@@ -589,7 +589,7 @@ Feature: /forms/chromium/convert/url
@chromium-ssrf
Scenario: POST /forms/chromium/convert/url (Redirect to a non-allow-listed address is re-filtered)
Given I have a Gotenberg container with the following environment variable(s):
| CHROMIUM_ALLOW_LIST | ^https?://host.docker.internal.* |
| CHROMIUM_ALLOW_LIST | ^https?://host\.docker\.internal(:[0-9]+)?/ |
Given I have a static server
When I make a "POST" request to Gotenberg at the "/forms/chromium/convert/url" endpoint with the following form data and header(s):
| url | http://host.docker.internal:%d/redirect-to-private | field |