Defines canonical URL checks for text scanners and for application code that is about to make a network request. The policy can also validate resolved IP addresses and redirect targets supplied by the network executor.
Usage
url_policy(
allowed_schemes = "https",
allowed_hosts = NULL,
blocked_hosts = c("localhost", "localhost.localdomain"),
allow_userinfo = FALSE,
allow_idn = FALSE,
block_private = TRUE,
max_redirects = 0L,
show_stats = FALSE
)Arguments
- allowed_schemes
Allowed schemes.
- allowed_hosts
Optional exact host allowlist.
- blocked_hosts
Exact blocked hosts. Subdomains are also blocked.
- allow_userinfo
Whether
user:password@hostauthorities are allowed.- allow_idn
Whether non-ASCII and punycode host names are allowed.
- block_private
Whether loopback, link-local, and private IP targets are blocked, including executor-supplied DNS results.
- max_redirects
Maximum redirect targets accepted by
scan_url_target().- show_stats
Show construction time and available usage metrics.
Examples
policy <- url_policy(allowed_hosts = "api.example.com")
scan_url_target("https://api.example.com/v1", policy)
#> llmshieldr report
#> action: allow
#> risk_score: 0.000
#> findings: 0
