JustBash.Network (JustBash v0.4.0)

View Source

Shared network policy enforcement for sandbox HTTP commands (curl, wget).

Enforces the caller's network configuration:

  • Enabled gate — network must be explicitly enabled.
  • Scheme enforcement — only https:// by default; http:// requires the caller to set allow_insecure: true.
  • Allow-list — each host is checked against the configured patterns. An empty list blocks everything; :all permits any host.
  • Redirect validation — every redirect target is re-checked against the same policy. The HTTP library's built-in redirect following is disabled so that a 301 → http://evil.com cannot bypass the allow-list.

Summary

Functions

Follows redirects manually, re-validating each target against the network policy.

Extracts the location header from a response headers map.

Validates that url is permitted under bash's network config.

Functions

follow_redirects(bash, request, command_name, request_fn, on_redirect \\ &identity_redirect/2)

@spec follow_redirects(
  JustBash.t(),
  map(),
  String.t(),
  (map() -> {:ok, map()} | {:error, map()}),
  (integer(), map() -> map())
) :: {:response, map()} | {:error, map()}

Follows redirects manually, re-validating each target against the network policy.

request_fn is called with the current request map and must return {:ok, response} or {:error, error}.

on_redirect is called as on_redirect.(status, request) and must return the updated request map. Curl uses this to adjust the HTTP method on 303/307/308; wget uses the default (identity) since it only issues GET requests.

Returns:

  • {:response, response} — terminal HTTP response (not a redirect, or redirect without a Location header)
  • {:error, error} — transport failure or network policy violation

get_location_header(headers)

@spec get_location_header(map() | term()) :: String.t() | nil

Extracts the location header from a response headers map.

validate_access(bash, url, command_name)

@spec validate_access(JustBash.t(), String.t(), String.t()) ::
  :ok | {:error, String.t()}

Validates that url is permitted under bash's network config.

Returns :ok or {:error, message}. The command_name (e.g. "curl") is included in error messages for user-facing output.