pub struct SecurityPolicy { /* private fields */ }Expand description
Validates tool invocations against security constraints: path restrictions,
blocked commands, .git protection, and NAVI private storage.
Implementations§
Source§impl SecurityPolicy
impl SecurityPolicy
Sourcepub fn new(
project_root: PathBuf,
data_dir: PathBuf,
config: SecurityConfig,
) -> Result<Self>
pub fn new( project_root: PathBuf, data_dir: PathBuf, config: SecurityConfig, ) -> Result<Self>
Creates a new policy from the project root, data directory, and security config.
Sourcepub fn with_write_scope(self, scope: WritePathScope) -> Self
pub fn with_write_scope(self, scope: WritePathScope) -> Self
Returns a clone with a workflow worker write-path scope applied.
Sourcepub fn set_plan_mode(&self, active: bool, plan_file: Option<PathBuf>)
pub fn set_plan_mode(&self, active: bool, plan_file: Option<PathBuf>)
Enable/disable plan mode and set the only writable plan markdown path. Shared across policy clones via interior mutability.
Sourcepub fn plan_mode_active(&self) -> bool
pub fn plan_mode_active(&self) -> bool
Whether plan mode is currently active on this policy.
Sourcepub fn plan_file_path(&self) -> Option<PathBuf>
pub fn plan_file_path(&self) -> Option<PathBuf>
Absolute path of the session plan file (if set).
Sourcepub fn validate_path(&self, path: &Path, write: bool) -> SecurityDecision
pub fn validate_path(&self, path: &Path, write: bool) -> SecurityDecision
Validates a file path, checking project restrictions, .git protection,
and NAVI private storage.
Sourcepub fn validate_patch(&self, patch: &PatchProposal) -> SecurityDecision
pub fn validate_patch(&self, patch: &PatchProposal) -> SecurityDecision
Validates all paths in a patch proposal.
Sourcepub fn validate_command(&self, program: &str) -> SecurityDecision
pub fn validate_command(&self, program: &str) -> SecurityDecision
Validates a command against the blocked-commands list, guarded-commands list, and approval config.
Sourcepub fn validate_plugin_path(&self, path: &Path) -> SecurityDecision
pub fn validate_plugin_path(&self, path: &Path) -> SecurityDecision
Validates a plugin library path, requiring approval unless external plugins are explicitly allowed.
Sourcepub fn validate_mcp_server(&self, server_id: &str) -> SecurityDecision
pub fn validate_mcp_server(&self, server_id: &str) -> SecurityDecision
Validates an MCP server id against the configured allowlist.
When allowlist is non-empty, only server ids present in the list
are allowed. An empty allowlist permits all MCP servers.
Sourcepub fn validate_tool_invocation(
&self,
definition: &ToolDefinition,
invocation: &ToolInvocation,
) -> SecurityDecision
pub fn validate_tool_invocation( &self, definition: &ToolDefinition, invocation: &ToolInvocation, ) -> SecurityDecision
Validates a tool invocation by dispatching to the appropriate validator based on tool kind.
Sourcepub fn post_execution_effect_check(
&self,
tool_name: &str,
paths: &[PathBuf],
_command: Option<&str>,
) -> PostDecision
pub fn post_execution_effect_check( &self, tool_name: &str, paths: &[PathBuf], _command: Option<&str>, ) -> PostDecision
Performs a post-execution effect check on the paths touched by a tool.
Analyses created, modified, and deleted paths through the
EffectAnalyzer and produces a PostDecision that the harness
can act on (allow, ask, deny, or roll back).
tool_name is used for contextual messaging. paths are the filesystem
paths the tool reported touching. command is the shell command string,
if any (used for context, not analysed here).
Sourcepub fn project_root(&self) -> &Path
pub fn project_root(&self) -> &Path
Returns the normalized project root used as the execution sandbox.
Sourcepub fn paths_restricted_to_project(&self) -> bool
pub fn paths_restricted_to_project(&self) -> bool
Whether file-tool paths must stay inside the project root.
Always enforced in PermissionMode::Restricted. Outside Restricted,
only the explicit restrict_paths_to_project config flag applies (default
off), so AcceptEdits / Auto / YOLO keep agent agency unless the user
opts into a project jail.
Sourcepub fn config(&self) -> &SecurityConfig
pub fn config(&self) -> &SecurityConfig
Returns a reference to the security configuration.
Sourcepub fn set_config(&mut self, config: SecurityConfig)
pub fn set_config(&mut self, config: SecurityConfig)
Replaces the security configuration used by subsequent validations.
Sourcepub fn data_dir(&self) -> &Path
pub fn data_dir(&self) -> &Path
Returns the NAVI data directory used for persistent storage (sessions, memory, plans, credentials, logs).
Sourcepub fn resolve_project_path(&self, path: &Path) -> PathBuf
pub fn resolve_project_path(&self, path: &Path) -> PathBuf
Resolves relative tool paths against the project root instead of the process CWD. This keeps SDK/ACP embeddings from accidentally reading or writing outside the requested project when NAVI is launched elsewhere.
Sourcepub fn write_scope(&self) -> Option<&WritePathScope>
pub fn write_scope(&self) -> Option<&WritePathScope>
Returns the optional workflow write-path scope, if any.
Sourcepub fn normalize_invocation_paths(
&self,
invocation: &ToolInvocation,
) -> ToolInvocation
pub fn normalize_invocation_paths( &self, invocation: &ToolInvocation, ) -> ToolInvocation
Returns a copy of the invocation with security-visible path fields made absolute under the project root.
Sourcepub fn is_path_denied(&self, path: &Path) -> bool
pub fn is_path_denied(&self, path: &Path) -> bool
Check if a path matches any entry in the deny list.
Supports:
- Directory name prefixes:
"node_modules"matchesnode_modules/foo/bar.js - Glob patterns:
"*.log"matchesdebug.log - Exact path suffixes:
"package-lock.json"matchesfoo/package-lock.json
Sourcepub fn filter_denied_lines(&self, text: &str) -> String
pub fn filter_denied_lines(&self, text: &str) -> String
Filter text output by removing lines that reference denied paths.
Used by grep and fs_browser to prevent denied path references from entering the LLM context.
Trait Implementations§
Source§impl Clone for SecurityPolicy
impl Clone for SecurityPolicy
Auto Trait Implementations§
impl Freeze for SecurityPolicy
impl RefUnwindSafe for SecurityPolicy
impl Send for SecurityPolicy
impl Sync for SecurityPolicy
impl Unpin for SecurityPolicy
impl UnsafeUnpin for SecurityPolicy
impl UnwindSafe for SecurityPolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more