# Graphify Security Measures: How They Prevent Path Traversal and URL Redirects

> Discover how Graphify security measures prevent path traversal and URL redirects. Learn about URL validation, SSRF guarding, and directory confinement for robust protection.

- Repository: [Graphify Labs/graphify](https://github.com/Graphify-Labs/graphify)
- Tags: security-measures
- Published: 2026-07-15

---

**Graphify blocks path traversal and unsafe URL redirects through four layered defenses in [`graphify/security.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/security.py): strict URL validation with IP filtering, SSRF-guarded HTTP connections, redirect re-validation, and filesystem path confinement to the `graphify-out` directory.**

The Graphify-Labs/graphify repository implements rigorous security measures to prevent path traversal and URL redirect attacks. By centralizing protection logic in [`graphify/security.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/security.py), the library ensures that every file operation stays within designated boundaries and every external request undergoes validation against Server-Side Request Forgery (SSRF) vectors. These defenses work together to secure the knowledge-graph generation process against common web application vulnerabilities.

## URL Validation and IP Filtering

Every incoming URL passes through `validate_url()` before processing. This function enforces two critical checks: scheme validation and IP address filtering.

First, the function accepts only `http` and `https` schemes, rejecting any URL using `file`, `ftp`, or other dangerous protocols. Second, it resolves the hostname and passes the resulting IP to `_ip_is_blocked()`, which filters out private, reserved, and cloud-metadata IP addresses. According to the source code at lines 103-112 in [`graphify/security.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/security.py), this prevents attackers from using URLs to access internal services or cloud instance metadata endpoints.

## SSRF-Protected HTTP Connections

To eliminate DNS rebinding attacks, Graphify implements custom connection classes that resolve and validate the host IP exactly once. The `_SSRFGuardedHTTPConnection` and `_SSRFGuardedHTTPSConnection` classes (lines 80-102) use `_resolve_and_validate()` to perform a single DNS lookup, verify the IP against blocklists, and then connect directly to that validated IP address.

This design prevents a second DNS resolution during the actual connection phase, closing the window where an attacker might swap a legitimate DNS record for a malicious internal IP after validation.

## Redirect Re-Validation

Graphify treats every HTTP redirect as a potential attack vector. The bespoke `_NoFileRedirectHandler` class extends `urllib.request.HTTPRedirectHandler` to intercept redirect responses.

Before following any redirect, the `redirect_request()` method calls `validate_url()` on the new target URL (lines 31-34). This ensures that even if an initial URL passes validation, subsequent redirects to file schemes, private IPs, or other restricted destinations are blocked immediately.

## Filesystem Path Confinement

The `validate_graph_path()` function enforces strict path confinement to prevent directory traversal attacks. Any file path that Graphify reads or writes must remain inside the `graphify-out` directory (or a user-supplied base path defined in [`graphify/paths.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/paths.py)).

As implemented at lines 15-25 in [`graphify/security.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/security.py), the function resolves the absolute path, confirms the base directory exists, and uses `relative_to` to verify the resolved path is a descendant of the allowed base. If the check fails, the function raises a `ValueError`, blocking attempts to access files outside the sandbox such as [`../outside/secret.txt`](https://github.com/Graphify-Labs/graphify/blob/main/../outside/secret.txt).

## Implementation Examples

The following code demonstrates how to use Graphify's security functions in your application:

```python
from graphify.security import validate_graph_path, safe_fetch

# Prevent path traversal

try:
    # Only files inside graphify-out are allowed

    safe_path = validate_graph_path("../outside/secret.txt")
except ValueError as e:
    print("Blocked traversal:", e)

# Safe fetching with redirect guard

try:
    # Redirects will be re-validated; private IPs are rejected

    html = safe_fetch("https://example.com")
except Exception as e:
    print("Fetch blocked:", e)

```

## Summary

- **URL Validation**: The `validate_url()` function in [`graphify/security.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/security.py) (lines 103-112) blocks non-HTTP schemes and private IP ranges using `_ip_is_blocked()`.
- **SSRF Protection**: Custom `_SSRFGuardedHTTPConnection` classes (lines 80-102) prevent DNS rebinding by resolving and validating IPs once before connecting.
- **Redirect Security**: The `_NoFileRedirectHandler` re-validates every redirect target via `validate_url()` (lines 31-34) to stop open redirects.
- **Path Confinement**: `validate_graph_path()` (lines 15-25) ensures all file operations stay within the `graphify-out` directory, raising `ValueError` on traversal attempts.

## Frequently Asked Questions

### How does Graphify prevent path traversal attacks?

Graphify prevents path traversal through the `validate_graph_path()` function in [`graphify/security.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/security.py). This function resolves any provided path to its absolute form and verifies it is a descendant of the designated `graphify-out` base directory using `relative_to`. If the path attempts to escape the sandbox (e.g., using `../` sequences), the function raises a `ValueError` before any file operation occurs.

### What mechanism protects against unsafe URL redirects in Graphify?

Graphify protects against unsafe redirects using the `_NoFileRedirectHandler` class, which overrides the standard HTTP redirect handler. Before following any redirect, the `redirect_request()` method re-validates the new URL through `validate_url()` (lines 31-34). This blocks redirects to file schemes, internal IP addresses, or other restricted destinations that could enable SSRF attacks.

### How does Graphify defend against Server-Side Request Forgery (SSRF)?

Graphify implements multi-layered SSRF defense: first, `validate_url()` filters out private and reserved IP ranges; second, custom `_SSRFGuardedHTTPConnection` and `_SSRFGuardedHTTPSConnection` classes (lines 80-102) resolve DNS once and connect directly to the validated IP, preventing DNS rebinding attacks; third, all redirect targets undergo re-validation to ensure chains of requests remain safe.

### Can I configure the base directory for path validation?

Yes. While `validate_graph_path()` defaults to the `graphify-out` directory defined in [`graphify/paths.py`](https://github.com/Graphify-Labs/graphify/blob/main/graphify/paths.py), you can specify a custom base directory when calling the function. The security logic remains the same: the function resolves the absolute path and confirms it falls within the specified base using `relative_to`, ensuring path traversal protection regardless of the base directory chosen.