What changed, and why it matters
This commit adds a new helper method to check whether a web address points to the same computer (a 'loopback' address like 127.0.0.1 or localhost). It is purely a utility addition with tests and does not change any existing behavior or fix a known bug on its own.
No security action required for this commit in isolation. If future commits use isLoopbackUrl for access-control decisions, review that the method's behavior (no DNS resolution, treating all non-localhost hostnames as non-loopback) matches the intended security policy.
Security signals we found
No strong security signals were identified.
Evidence from the diff
The patch introduces NetworkUtils.isLoopbackUrl(String) in monero-java. It parses a URL, strips IPv6 brackets, and returns true if the host is ‘localhost’, an IPv4 address in 127.0.0.0/8, or the IPv6 ::1 address. It swallows exceptions and returns false for unparseable input. A unit test covers positive and negative cases. No callers of the new method are added in this commit, and no security issue is described in the commit message or diff.
Changed components
src/main/java/monero/common/NetworkUtils.javasrc/test/java/TestNetworkUtils.javaInspect captured patch +41 / −0
diff --git a/src/main/java/monero/common/NetworkUtils.java b/src/main/java/monero/common/NetworkUtils.java
index 042433e..2ded09c 100644
--- a/src/main/java/monero/common/NetworkUtils.java
+++ b/src/main/java/monero/common/NetworkUtils.java
@@ -207,6 +207,27 @@ public class NetworkUtils {
}
}
+ /**
+ * Determine if the given URL's host is a loopback address (e.g. "127.0.0.1", "::1" or "localhost").
+ *
+ * Recognizes the entire IPv4 loopback range (127.0.0.0/8), the IPv6 loopback
+ * address (::1) and the conventional "localhost" alias. Hostnames other than
+ * "localhost" are treated as non-loopback; no DNS resolution is performed.
+ *
+ * @param url is the URL to check (scheme optional)
+ * @return true if the host is a loopback address, false otherwise or if it cannot be parsed
+ */
+ public static boolean isLoopbackUrl(String url) {
+ try {
+ String host = stripIpv6Brackets(parseUri(url).getHost());
+ if (host == null) return false;
+ if (LOCALHOST.equalsIgnoreCase(host)) return true;
+ return isLiteralIp(host) && toInetAddress(host).isLoopbackAddress();
+ } catch (Exception e) {
+ return false;
+ }
+ }
+
/**
* Determine if the given URI's host is local or a private (non-routable) IP address.
*
diff --git a/src/test/java/TestNetworkUtils.java b/src/test/java/TestNetworkUtils.java
index 62df15b..d97332d 100644
--- a/src/test/java/TestNetworkUtils.java
+++ b/src/test/java/TestNetworkUtils.java
@@ -123,6 +123,26 @@ public class TestNetworkUtils {
assertFalse(NetworkUtils.isLocalHost("[fe80::1]:18081"));
}
+ @Test
+ public void testIsLoopbackUrl() {
+ assertTrue(NetworkUtils.isLoopbackUrl("localhost"));
+ assertTrue(NetworkUtils.isLoopbackUrl("LOCALHOST"));
+ assertTrue(NetworkUtils.isLoopbackUrl("127.0.0.1"));
+ assertTrue(NetworkUtils.isLoopbackUrl("127.0.0.1:18081"));
+ assertTrue(NetworkUtils.isLoopbackUrl("http://127.0.0.1:18081"));
+ assertTrue(NetworkUtils.isLoopbackUrl("127.5.6.7")); // entire 127.0.0.0/8 range is loopback
+ assertTrue(NetworkUtils.isLoopbackUrl("::1"));
+ assertTrue(NetworkUtils.isLoopbackUrl("[::1]:18081"));
+ assertTrue(NetworkUtils.isLoopbackUrl("http://[::1]:18081"));
+ assertFalse(NetworkUtils.isLoopbackUrl(null));
+ assertFalse(NetworkUtils.isLoopbackUrl(""));
+ assertFalse(NetworkUtils.isLoopbackUrl("example.com"));
+ assertFalse(NetworkUtils.isLoopbackUrl("http://192.168.1.1:18081"));
+ assertFalse(NetworkUtils.isLoopbackUrl("8.8.8.8"));
+ assertFalse(NetworkUtils.isLoopbackUrl("[fe80::1]:18081"));
+ assertFalse(NetworkUtils.isLoopbackUrl("[2607:3c40:1900:33e0::1]:18089"));
+ }
+
@Test
public void testIsPrivateIp() {
// loopback / localhost
Why this scored 12/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.