Class A2aAllowlistPolicy
java.lang.Object
com.xebialabs.xlrelease.a2a.gateway.A2aAllowlistPolicy
The one implementation of the A2A agent allowlist, shared by every component that sends a byte
to a caller-influenced URL: the outbound gateway (agent calls) and the push-notification sender
(webhook POSTs registered by external callers — the classic SSRF vector, closed by requiring
webhook targets to sit on the same allowlist as the agents themselves).
URL-structural matching, never a raw string prefix: scheme, host and effective port must
match an entry exactly (so agents.example.com.evil.io, agents.example.com@evil.io
and an unexpected port all fail), and an entry's path — if it has one — must be a whole-segment
prefix of the target's path. An empty allowlist refuses everything: secure by default.
-
Method Summary
-
Method Details
-
isAllowlisted
-