namespace w4c_workflows.Services.Security;
///
/// Operator policy for outbound HTTP issued by workflow nodes. Bound from the
/// Nodes:Egress configuration section. The defaults are fail-closed:
/// private, loopback, link-local and other reserved ranges are denied unless an
/// operator explicitly opts in through or
/// .
///
public sealed class EgressPolicyOptions
{
/// Configuration section this policy binds from.
public const string SectionName = "Nodes:Egress";
///
/// Permit requests whose target resolves into a private or reserved range.
/// Leave false in hosted environments; opt in per host instead.
///
public bool AllowPrivateNetworks { get; set; }
///
/// Schemes a node may target. Anything outside the list is rejected, which
/// keeps file/gopher/data URIs out of the HTTP executor entirely.
///
public string[] AllowedSchemes { get; set; } = ["https", "http"];
///
/// Explicit allow-list of hosts that bypass the address-range checks (for
/// example a documented internal API). Supports an exact host and a
/// *.example.com suffix wildcard.
///
public string[] AllowedHosts { get; set; } = [];
/// Explicit deny-list of hosts; a match always blocks the request.
public string[] BlockedHosts { get; set; } = [];
///
/// Hard ceiling for redirects a single node invocation may follow. A
/// workflow can ask for fewer, never more.
///
public int MaxRedirects { get; set; } = 5;
}