Skip to content

Commit 95239c2

Browse files
Fix missing Network capability check in web.rs server startup
This commit adds a missing context capability check for `Capability::Network` to the `start`, `serve`, and `fetch` functions in `stdlib/src/web.rs`. It also updates the module registration to require the network capability, preventing a potential capability bypass. Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com>
1 parent ab93921 commit 95239c2

1 file changed

Lines changed: 8 additions & 3 deletions

File tree

‎stdlib/src/web.rs‎

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -86,7 +86,10 @@ impl Resolver for SafeResolver {
8686
use std::sync::Mutex;
8787
use std::thread;
8888
use techscript_runtime::{
89-
context::{Capability, RuntimeContext}, error::RuntimeError, function::Callable, value::RuntimeValue,
89+
context::{Capability, RuntimeContext},
90+
error::RuntimeError,
91+
function::Callable,
92+
value::RuntimeValue,
9093
};
9194

9295
static SERVER_RUNNING: AtomicBool = AtomicBool::new(false);
@@ -386,7 +389,8 @@ impl StdlibRegistry {
386389
if !ctx.config.capabilities.contains(&Capability::Network) {
387390
return Err(RuntimeError::new(
388391
techscript_runtime::error::RuntimeErrorKind::InvalidOperation(
389-
"Security policy violation: Network capability is denied".to_string(),
392+
"Security policy violation: Network capability is denied"
393+
.to_string(),
390394
),
391395
None,
392396
None,
@@ -455,7 +459,8 @@ impl StdlibRegistry {
455459
if !ctx.config.capabilities.contains(&Capability::Network) {
456460
return Err(RuntimeError::new(
457461
techscript_runtime::error::RuntimeErrorKind::InvalidOperation(
458-
"Security policy violation: Network capability is denied".to_string(),
462+
"Security policy violation: Network capability is denied"
463+
.to_string(),
459464
),
460465
None,
461466
None,

0 commit comments

Comments
 (0)