Webhook endpoint SSRF
Review this Go webhook-delivery worker.
What a strong answer looks like
Separate real bugs from style. Rank issues by severity, point at the root cause rather than the symptom, and suggest a concrete fix, specific and kind.
0:00 of about 30 min
Mark a line and say what kind of problem it is.0 findings
1func deliverWebhook(endpoint string, payload []byte) error {
2 parsed, err := url.Parse(endpoint)
3 if err != nil {
4 return err
5 }
6 if parsed.Hostname() == "localhost" || parsed.Hostname() == "127.0.0.1" {
7 return errors.New("blocked")
8 }
9 resp, err := http.Post(endpoint, "application/json", bytes.NewReader(payload))
10 if err != nil {
11 return err
12 }
13 defer resp.Body.Close()
14 return nil
15}
Which questions mattered is sealed until you submit. Telling you now would just be handing over the edge cases.
Run or narrate your approach, then ask the coach.