The bare catch {} swallowed the ApiError thrown by the private-IP
checks, defeating the entire DNS-based SSRF protection. Now catches
and re-throws ApiError so security rejections propagate correctly;
only DNS-lookup failures fall through.
The bare catch {} swallowed the ApiError thrown by the private-IP
checks, defeating the entire DNS-based SSRF protection. Now catches
and re-throws ApiError so security rejections propagate correctly;
only DNS-lookup failures fall through.