A feature that imports an image, previews a link, or reads a document from a URL makes a network request from the application's infrastructure. The destination is selected through user input, but the connection originates from a server with its own network position.
Server-side request forgery, or SSRF, becomes possible when that feature can reach destinations outside its intended scope. The review needs to examine how the application validates and executes the request, including what happens after a redirect.
Validate the destination the server will reach
OWASP's SSRF guidance discusses allowlists, URL parsing, address validation, redirects, and network-layer controls. It distinguishes integrations with known destinations from features that legitimately retrieve broader internet content. The SSRF prevention guidance explains these design choices.
An illustrative product imports supplier logos from approved storage domains. That narrow purpose permits a different destination policy from a general web-preview service. The business requirement determines which connections the feature needs, rather than an unrestricted fetch function determining the requirement.
Redirects and DNS can change the effective destination
A URL's first hostname may not be the final endpoint. Redirect handling can move the request, while DNS resolution determines the address actually contacted. Validation and connection logic need to use a consistent interpretation and enforce policy across the request path.
Network controls provide another boundary. A fetch worker can be restricted from reaching internal services and cloud metadata endpoints even if application-level validation has a defect. Record the actual outbound rules and any proxy that changes the connection path.
Test with controlled endpoints
Use endpoints owned for testing to return ordinary content, a redirect, a slow response, and a response larger than the supported limit. Include an agreed internal test destination that contains no sensitive information. The objective is to observe whether the feature follows its destination and resource policy.
Do not probe unrelated third-party infrastructure or retrieve real metadata credentials as a demonstration. A controlled marker endpoint can establish whether a prohibited connection occurred while keeping the test bounded and reproducible.
Review the response as untrusted content
Fetching a permitted URL does not make the returned file safe to parse or display. The importer still needs content-type handling, size limits, timeouts, and controls appropriate to its parser and rendering destination. A link-preview service can also expose response data through logs or cached previews.
An assessment can connect the user-supplied URL to the validated destination, actual connection, response processing, and final display. That trace helps engineering locate a failure precisely. It also gives the product owner a clear definition of which imports are supported and how rejected or unavailable destinations appear to users.
Sources
OWASP API7: Server Side Request Forgery. The supplier-logo importer is illustrative.