4734b99bea6dfd10e60a910ab9a3889604d27739
The security docs claimed the in-browser SSRF filter (context.route/ routeWebSocket) re-applies "the same filtering" as the pre-fetch DNS check. That's inaccurate for hostnames: the browser-level filter only blocks literal private IPs and localhost/.local/.internal suffixes — it never re-resolves hostnames, so a same-hostname DNS-rebind (public IP on first resolve, private IP on a later request from inside browserless) is not closed at that layer. Correct the wording in the design spec and TECHNICAL.md, and add a prominent note to both the spec's deploy section and the plan's deploy notes: before flipping TOOLBOX_VISIBLE on prod, harden the browserless container's network egress (block 169.254.0.0/16 and RFC1918 ranges via host firewall or a dedicated internal docker network) to close the residual at the network layer. Also note that per-user limits currently count only successful generations — failed renders are uncapped, a bounded self-DoS risk worth a follow-up.
This is a Next.js project bootstrapped with create-next-app.
Getting Started
First, run the development server:
npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev
Open http://localhost:3000 with your browser to see the result.
You can start editing the page by modifying app/page.tsx. The page auto-updates as you edit the file.
This project uses next/font to automatically optimize and load Geist, a new font family for Vercel.
Learn More
To learn more about Next.js, take a look at the following resources:
- Next.js Documentation - learn about Next.js features and API.
- Learn Next.js - an interactive Next.js tutorial.
You can check out the Next.js GitHub repository - your feedback and contributions are welcome!
Deploy on Vercel
The easiest way to deploy your Next.js app is to use the Vercel Platform from the creators of Next.js.
Check out our Next.js deployment documentation for more details.
Description
Languages
TypeScript
54.2%
HTML
43.9%
Shell
0.5%
CSS
0.5%
PLpgSQL
0.5%
Other
0.4%