JustBash.Network (JustBash v0.4.0)
View SourceShared network policy enforcement for sandbox HTTP commands (curl, wget).
Enforces the caller's network configuration:
- Enabled gate — network must be explicitly enabled.
- Scheme enforcement — only
https://by default;http://requires the caller to setallow_insecure: true. - Allow-list — each host is checked against the configured patterns.
An empty list blocks everything;
:allpermits any host. - Redirect validation — every redirect target is re-checked against the
same policy. The HTTP library's built-in redirect following is disabled so
that a
301 → http://evil.comcannot bypass the allow-list.
Summary
Functions
Follows redirects manually, re-validating each target against the network policy.
Extracts the location header from a response headers map.
Validates that url is permitted under bash's network config.
Functions
@spec follow_redirects( JustBash.t(), map(), String.t(), (map() -> {:ok, map()} | {:error, map()}), (integer(), map() -> map()) ) :: {:response, map()} | {:error, map()}
Follows redirects manually, re-validating each target against the network policy.
request_fn is called with the current request map and must return
{:ok, response} or {:error, error}.
on_redirect is called as on_redirect.(status, request) and must return
the updated request map. Curl uses this to adjust the HTTP method on 303/307/308;
wget uses the default (identity) since it only issues GET requests.
Returns:
{:response, response}— terminal HTTP response (not a redirect, or redirect without a Location header){:error, error}— transport failure or network policy violation
Extracts the location header from a response headers map.
@spec validate_access(JustBash.t(), String.t(), String.t()) :: :ok | {:error, String.t()}
Validates that url is permitted under bash's network config.
Returns :ok or {:error, message}. The command_name (e.g. "curl") is
included in error messages for user-facing output.