curl keeps only the last CURLOPT_RESOLVE entry for a given host and
port, so passing one entry per address meant a host with both IPv6 and
IPv4 addresses was only ever tried on the last one. A server reachable
on just the other address (e.g. listening only on ::1) failed to
connect. Pass all the addresses in a single entry instead, which curl
has supported since 7.59.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
set_safe_mode(true) refuses anything but http and https, refuses hosts
that resolve to loopback, private, link-local or reserved addresses,
pins curl to the addresses that were checked (no DNS rebinding), and
follows redirects one hop at a time so each is checked, dropping
credentials when a redirect changes origin. Hosts or ranges can be
allowed explicitly for development servers.
Off by default. Adds a PHPUnit suite.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>