Skip to contents

Defines canonical URL checks for text scanners and for application code that is about to make a network request. The policy can also validate resolved IP addresses and redirect targets supplied by the network executor.

Usage

url_policy(
  allowed_schemes = "https",
  allowed_hosts = NULL,
  blocked_hosts = c("localhost", "localhost.localdomain"),
  allow_userinfo = FALSE,
  allow_idn = FALSE,
  block_private = TRUE,
  max_redirects = 0L,
  show_stats = FALSE
)

Arguments

allowed_schemes

Allowed schemes.

allowed_hosts

Optional exact host allowlist.

blocked_hosts

Exact blocked hosts. Subdomains are also blocked.

allow_userinfo

Whether user:password@host authorities are allowed.

allow_idn

Whether non-ASCII and punycode host names are allowed.

block_private

Whether loopback, link-local, and private IP targets are blocked, including executor-supplied DNS results.

max_redirects

Maximum redirect targets accepted by scan_url_target().

show_stats

Show construction time and available usage metrics.

Value

A shieldr_url_policy object.

Examples

policy <- url_policy(allowed_hosts = "api.example.com")
scan_url_target("https://api.example.com/v1", policy)
#> llmshieldr report
#> action: allow
#> risk_score: 0.000
#> findings: 0