pub struct NetworkPolicy {
pub allow_hosts: Vec<String>,
pub allow_classes: Vec<AddressClass>,
pub allowed_schemes: Vec<String>,
pub allow_request: Option<AllowCallback>,
pub hard_block_link_local: bool,
pub unrestricted: bool,
pub resolver: Option<Resolver>,
/* private fields */
}Expand description
Typed SSRF/host policy. See the module docs for defaults.
Fields§
§allow_hosts: Vec<String>Hosts (exact, case-insensitive) allowed even when their address class is blocked.
allow_classes: Vec<AddressClass>Address classes allowed for every host (e.g. Loopback for local dev servers).
allowed_schemes: Vec<String>Lowercase schemes that may be requested. Default ["http", "https"].
allow_request: Option<AllowCallback>Called for every checked request; see PolicyDecision.
hard_block_link_local: boolLink-local and metadata destinations cannot be allowed (default true).
unrestricted: boolDisable every check (trusted callers only).
resolver: Option<Resolver>Replaces the system resolver (offline tests, pinned DNS, split-horizon setups).
Implementations§
Source§impl NetworkPolicy
impl NetworkPolicy
Sourcepub fn unrestricted() -> Self
pub fn unrestricted() -> Self
Policy with every check off.
pub fn allow_host(self, host: impl Into<String>) -> Self
pub fn allow_class(self, class: AddressClass) -> Self
pub fn allow_scheme(self, scheme: impl Into<String>) -> Self
pub fn hard_block_link_local(self, on: bool) -> Self
pub fn with_resolver( self, f: impl Fn(&str) -> Vec<IpAddr> + Send + Sync + 'static, ) -> Self
Sourcepub fn allow_with<D: Into<PolicyDecision>>(
self,
f: impl Fn(&BrowserRequest) -> D + Send + Sync + 'static,
) -> Self
pub fn allow_with<D: Into<PolicyDecision>>( self, f: impl Fn(&BrowserRequest) -> D + Send + Sync + 'static, ) -> Self
Per-request callback. Returning bool works too: true allows,
false defers to the defaults.
Trait Implementations§
Source§impl Clone for NetworkPolicy
impl Clone for NetworkPolicy
Source§impl Debug for NetworkPolicy
impl Debug for NetworkPolicy
Auto Trait Implementations§
impl !RefUnwindSafe for NetworkPolicy
impl !UnwindSafe for NetworkPolicy
impl Freeze for NetworkPolicy
impl Send for NetworkPolicy
impl Sync for NetworkPolicy
impl Unpin for NetworkPolicy
impl UnsafeUnpin for NetworkPolicy
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more