Skip to main content

SecurityPolicy

Struct SecurityPolicy 

Source
pub struct SecurityPolicy { /* private fields */ }
Expand description

Validates tool invocations against security constraints: path restrictions, blocked commands, .git protection, and NAVI private storage.

Implementations§

Source§

impl SecurityPolicy

Source

pub fn new( project_root: PathBuf, data_dir: PathBuf, config: SecurityConfig, ) -> Result<Self>

Creates a new policy from the project root, data directory, and security config.

Source

pub fn with_write_scope(self, scope: WritePathScope) -> Self

Returns a clone with a workflow worker write-path scope applied.

Source

pub fn set_plan_mode(&self, active: bool, plan_file: Option<PathBuf>)

Enable/disable plan mode and set the only writable plan markdown path. Shared across policy clones via interior mutability.

Source

pub fn plan_mode_active(&self) -> bool

Whether plan mode is currently active on this policy.

Source

pub fn plan_file_path(&self) -> Option<PathBuf>

Absolute path of the session plan file (if set).

Source

pub fn validate_path(&self, path: &Path, write: bool) -> SecurityDecision

Validates a file path, checking project restrictions, .git protection, and NAVI private storage.

Source

pub fn validate_patch(&self, patch: &PatchProposal) -> SecurityDecision

Validates all paths in a patch proposal.

Source

pub fn validate_command(&self, program: &str) -> SecurityDecision

Validates a command against the blocked-commands list, guarded-commands list, and approval config.

Source

pub fn validate_plugin_path(&self, path: &Path) -> SecurityDecision

Validates a plugin library path, requiring approval unless external plugins are explicitly allowed.

Source

pub fn validate_mcp_server(&self, server_id: &str) -> SecurityDecision

Validates an MCP server id against the configured allowlist.

When allowlist is non-empty, only server ids present in the list are allowed. An empty allowlist permits all MCP servers.

Source

pub fn validate_tool_invocation( &self, definition: &ToolDefinition, invocation: &ToolInvocation, ) -> SecurityDecision

Validates a tool invocation by dispatching to the appropriate validator based on tool kind.

Source

pub fn post_execution_effect_check( &self, tool_name: &str, paths: &[PathBuf], _command: Option<&str>, ) -> PostDecision

Performs a post-execution effect check on the paths touched by a tool.

Analyses created, modified, and deleted paths through the EffectAnalyzer and produces a PostDecision that the harness can act on (allow, ask, deny, or roll back).

tool_name is used for contextual messaging. paths are the filesystem paths the tool reported touching. command is the shell command string, if any (used for context, not analysed here).

Source

pub fn project_root(&self) -> &Path

Returns the normalized project root used as the execution sandbox.

Source

pub fn paths_restricted_to_project(&self) -> bool

Whether file-tool paths must stay inside the project root.

Always enforced in PermissionMode::Restricted. Outside Restricted, only the explicit restrict_paths_to_project config flag applies (default off), so AcceptEdits / Auto / YOLO keep agent agency unless the user opts into a project jail.

Source

pub fn config(&self) -> &SecurityConfig

Returns a reference to the security configuration.

Source

pub fn set_config(&mut self, config: SecurityConfig)

Replaces the security configuration used by subsequent validations.

Source

pub fn data_dir(&self) -> &Path

Returns the NAVI data directory used for persistent storage (sessions, memory, plans, credentials, logs).

Source

pub fn resolve_project_path(&self, path: &Path) -> PathBuf

Resolves relative tool paths against the project root instead of the process CWD. This keeps SDK/ACP embeddings from accidentally reading or writing outside the requested project when NAVI is launched elsewhere.

Source

pub fn write_scope(&self) -> Option<&WritePathScope>

Returns the optional workflow write-path scope, if any.

Source

pub fn normalize_invocation_paths( &self, invocation: &ToolInvocation, ) -> ToolInvocation

Returns a copy of the invocation with security-visible path fields made absolute under the project root.

Source

pub fn is_path_denied(&self, path: &Path) -> bool

Check if a path matches any entry in the deny list.

Supports:

  • Directory name prefixes: "node_modules" matches node_modules/foo/bar.js
  • Glob patterns: "*.log" matches debug.log
  • Exact path suffixes: "package-lock.json" matches foo/package-lock.json
Source

pub fn filter_denied_lines(&self, text: &str) -> String

Filter text output by removing lines that reference denied paths.

Used by grep and fs_browser to prevent denied path references from entering the LLM context.

Trait Implementations§

Source§

impl Clone for SecurityPolicy

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SecurityPolicy

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> MaybeSend for T

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more