/** * Spec C1 LoopbackEnforcer — two-check enforcement against DNS rebinding: * (a) IP-level: socket remote address must be loopback (127/8 or ::1) * (b) Host/Origin header: must be localhost / 127.0.0.1 / [::1] * * The IP check defends against external network access; the header check * defends against rebinding attacks where a malicious site resolves a * controlled hostname to 127.0.0.1. */ /** * Returns true iff the given address string refers to the loopback interface. * Accepts all forms Node's socket layer surfaces: * - IPv4 loopback (any 127.0.0.0/8 address): 127.0.0.1, 127.0.1.1, etc. * - IPv6 loopback: ::1 * - IPv4-mapped IPv6 loopback: ::ffff:127.0.0.1 * - Hostname: localhost */ export declare function isLoopbackAddress(addr: string | undefined): boolean; /** * Returns true iff the request should be rejected because the socket * remote address is not loopback. */ export declare function shouldRejectNonLoopback(remoteAddress: string | undefined): boolean; /** * Validates the Host (or Origin) header against a small allowlist. * Strips any port suffix before comparing. */ export declare function isAllowedHostHeader(host: string | undefined): boolean; //# sourceMappingURL=loopback-enforcer.d.ts.map