Safely performing external HTTP requests (avoiding SSRF)

Thank you, this is exactly what I was looking for. I was preoccupied with Finch and didn’t spend enough time looking through Req’s APIs. In hindsight it makes sense that Req starts the pool itself.

Following redirects is desirable in many cases. It would probably be better for Req to support this IP filtering pattern natively. I’ll see about writing a proposal for that.