Class Cidr

java.lang.Object
org.frontcache.core.Cidr

public final class Cidr extends Object
An address block, compared on raw address bytes so v4 and v6 never match each other. Lived inside ClientIpResolver as a package-private nested class until a second caller appeared in another package (the client-ip: rule predicate, shared by guard rules and bots.conf - see docs/archive/dynamic-bots-classification-proposal.md). Promoted rather than copied: one definition of "is this address inside that block", so a fix reaches both callers. Never throws. An address or block that cannot be parsed is null, and every caller treats null as "undecidable", not as "matches".
  • Method Details

    • parse

      public static Cidr parse(String text)
      Parameters:
      text - an address (203.0.113.7, 2001:db8::1) or a block (10.0.0.0/8). A bare address is a single-host block.
      Returns:
      the block, or null when the text is not one
    • contains

      public boolean contains(InetAddress address)
    • contains

      public boolean contains(String addressLiteral)
      Parameters:
      text - an address literal, as it turns up in remoteAddr and forwarding headers
      Returns:
      the address, or null when the text is not an IP literal
    • parseAddress

      public static InetAddress parseAddress(String text)
      Parses an address literal only - never a host name, so this can never trigger a DNS lookup on the request thread from attacker-controlled input. Tolerates the forms that turn up in remoteAddr and forwarding headers: bracketed IPv6, a trailing port, an IPv6 zone id.
      Returns:
      the address, or null if the text is not an IP literal
    • toString

      public String toString()
      Overrides:
      toString in class Object