Class A2aAllowlistPolicy

java.lang.Object
com.xebialabs.xlrelease.a2a.gateway.A2aAllowlistPolicy

public final class A2aAllowlistPolicy extends Object
The one implementation of the A2A agent allowlist, shared by every component that sends a byte to a caller-influenced URL: the outbound gateway (agent calls) and the push-notification sender (webhook POSTs registered by external callers — the classic SSRF vector, closed by requiring webhook targets to sit on the same allowlist as the agents themselves).

URL-structural matching, never a raw string prefix: scheme, host and effective port must match an entry exactly (so agents.example.com.evil.io, agents.example.com@evil.io and an unexpected port all fail), and an entry's path — if it has one — must be a whole-segment prefix of the target's path. An empty allowlist refuses everything: secure by default.

  • Method Details

    • isAllowlisted

      public static boolean isAllowlisted(String url)