@@ -86,7 +86,10 @@ impl Resolver for SafeResolver {
8686use std:: sync:: Mutex ;
8787use std:: thread;
8888use techscript_runtime:: {
89- context:: RuntimeContext , error:: RuntimeError , function:: Callable , value:: RuntimeValue ,
89+ context:: { Capability , RuntimeContext } ,
90+ error:: RuntimeError ,
91+ function:: Callable ,
92+ value:: RuntimeValue ,
9093} ;
9194
9295static SERVER_RUNNING : AtomicBool = AtomicBool :: new ( false ) ;
@@ -382,7 +385,17 @@ impl StdlibRegistry {
382385 Rc :: new ( StdFunction {
383386 name : "start" . to_string ( ) ,
384387 arity : 2 ,
385- callback : |_ctx, args| {
388+ callback : |ctx, args| {
389+ if !ctx. config . capabilities . contains ( & Capability :: Network ) {
390+ return Err ( RuntimeError :: new (
391+ techscript_runtime:: error:: RuntimeErrorKind :: InvalidOperation (
392+ "Security policy violation: Network capability is denied"
393+ . to_string ( ) ,
394+ ) ,
395+ None ,
396+ None ,
397+ ) ) ;
398+ }
386399 let port = args[ 0 ] . try_into_int ( ) . map_err ( |e| {
387400 RuntimeError :: new (
388401 techscript_runtime:: error:: RuntimeErrorKind :: InvalidOperation (
@@ -442,7 +455,17 @@ impl StdlibRegistry {
442455 Rc :: new ( StdFunction {
443456 name : "serve" . to_string ( ) ,
444457 arity : 1 ,
445- callback : |_ctx, args| {
458+ callback : |ctx, args| {
459+ if !ctx. config . capabilities . contains ( & Capability :: Network ) {
460+ return Err ( RuntimeError :: new (
461+ techscript_runtime:: error:: RuntimeErrorKind :: InvalidOperation (
462+ "Security policy violation: Network capability is denied"
463+ . to_string ( ) ,
464+ ) ,
465+ None ,
466+ None ,
467+ ) ) ;
468+ }
446469 let port = args[ 0 ] . try_into_int ( ) . map_err ( |e| {
447470 RuntimeError :: new (
448471 techscript_runtime:: error:: RuntimeErrorKind :: InvalidOperation (
@@ -511,7 +534,16 @@ impl StdlibRegistry {
511534 Rc :: new ( StdFunction {
512535 name : "fetch" . to_string ( ) ,
513536 arity : 1 ,
514- callback : |_ctx, args| {
537+ callback : |ctx, args| {
538+ if !ctx. config . capabilities . contains ( & Capability :: Network ) {
539+ return Err ( RuntimeError :: new (
540+ techscript_runtime:: error:: RuntimeErrorKind :: InvalidOperation (
541+ "Security policy violation: Network capability is denied" . to_string ( ) ,
542+ ) ,
543+ None ,
544+ None ,
545+ ) ) ;
546+ }
515547 let url = args[ 0 ] . to_string ( ) ;
516548
517549 if !is_safe_url ( & url) {
@@ -592,7 +624,7 @@ impl StdlibRegistry {
592624 name : "std.web" . to_string ( ) ,
593625 version : "1.0.0" . to_string ( ) ,
594626 exports,
595- required_capabilities : Vec :: new ( ) ,
627+ required_capabilities : vec ! [ Capability :: Network ] ,
596628 } ,
597629 ) ;
598630 }
0 commit comments