Files
calendar/packages/lib/zod/ssrfSafeUrl.ts
T
e2119879ae refactor: apply biome formatting to packages/sms, prisma, emails, lib (#27880)
* refactor: apply biome formatting to small packages + packages/lib

Format packages/sms, packages/prisma, packages/platform/libraries,
packages/platform/examples, packages/platform/types, packages/emails,
and packages/lib.

Excludes packages/platform/examples/base/src/pages/[bookingUid].tsx
due to pre-existing lint errors.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* revert: remove packages/platform formatting changes

Revert biome formatting for packages/platform as requested.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-13 07:39:01 -03:00

39 lines
1.4 KiB
TypeScript

import type { z } from "zod";
import { z as zod } from "zod";
import { validateUrlForSSRFSync } from "../ssrfProtection";
const SSRF_ERROR = "URL is not allowed for security reasons";
const ssrfRefineOptions: { message: string } = { message: SSRF_ERROR };
// Validates URL for SSRF, allowing null/undefined/empty to pass through
const validateSsrfUrl = (url: string | null | undefined): boolean => {
if (url == null || url === "") return true;
return validateUrlForSSRFSync(url).isValid;
};
/**
* Zod schema for validating user-provided URLs before server-side fetching
* Applies synchronous SSRF checks only (no DNS resolution)
*/
export const ssrfSafeUrlSchema: z.ZodEffects<z.ZodString, string, string> = zod
.string()
.refine((url) => validateUrlForSSRFSync(url).isValid, ssrfRefineOptions);
// Optional nullable variant for update schemas
export const optionalSsrfSafeUrlSchema: z.ZodEffects<
z.ZodOptional<z.ZodNullable<z.ZodString>>,
string | null | undefined,
string | null | undefined
> = zod.string().nullable().optional().refine(validateSsrfUrl, ssrfRefineOptions);
// Optional variant for webhook edit schemas (non-nullable, rejects empty string)
export const optionalSsrfSafeUrlSchemaNotNullable: z.ZodEffects<
z.ZodOptional<z.ZodString>,
string | undefined,
string | undefined
> = zod
.string()
.optional()
.refine((url) => url === undefined || validateUrlForSSRFSync(url).isValid, ssrfRefineOptions);