namespace w4c_workflows.Services.Security; /// /// Operator policy for outbound HTTP issued by workflow nodes. Bound from the /// Nodes:Egress configuration section. The defaults are fail-closed: /// private, loopback, link-local and other reserved ranges are denied unless an /// operator explicitly opts in through or /// . /// public sealed class EgressPolicyOptions { /// Configuration section this policy binds from. public const string SectionName = "Nodes:Egress"; /// /// Permit requests whose target resolves into a private or reserved range. /// Leave false in hosted environments; opt in per host instead. /// public bool AllowPrivateNetworks { get; set; } /// /// Schemes a node may target. Anything outside the list is rejected, which /// keeps file/gopher/data URIs out of the HTTP executor entirely. /// public string[] AllowedSchemes { get; set; } = ["https", "http"]; /// /// Explicit allow-list of hosts that bypass the address-range checks (for /// example a documented internal API). Supports an exact host and a /// *.example.com suffix wildcard. /// public string[] AllowedHosts { get; set; } = []; /// Explicit deny-list of hosts; a match always blocks the request. public string[] BlockedHosts { get; set; } = []; /// /// Hard ceiling for redirects a single node invocation may follow. A /// workflow can ask for fewer, never more. /// public int MaxRedirects { get; set; } = 5; }