Security Model
WASM tools have zero network access by default. HTTP capability must be:- Explicitly granted via capabilities file
- Allowlisted to specific hosts and paths
- Rate limited to prevent abuse
- Size constrained for requests and responses
- HTTPS-only (no plaintext HTTP)
HTTP Request Flow
Endpoint Allowlisting
The first and most critical defense: WASM tools can only make HTTP requests to explicitly approved endpoints.Allowlist Configuration
Defined in*.capabilities.json:
EndpointPattern Structure
From src/tools/wasm/capabilities.rs:172-200:Validation Logic
From src/tools/wasm/allowlist.rs:74-164:Host Matching
Exact Match
- ✓
https://api.openai.com/v1/chat - ❌
https://openai.com/v1/chat(different host) - ❌
https://api.openai.com.evil.com(suffix attack)
Wildcard Subdomain
- ✓
https://api.example.com/data - ✓
https://staging.example.com/data - ❌
https://example.com/data(no subdomain) - ❌
https://api.example.com.evil.com(suffix attack blocked)
Case-Insensitive
- ✓
https://api.openai.com - ✓
https://API.OPENAI.COM - ✓
https://Api.OpenAi.Com
Path Prefix Matching
With Prefix
- ✓
https://api.github.com/repos/owner/repo - ✓
https://api.github.com/repos/owner/repo/issues - ❌
https://api.github.com/users/username - ❌
https://api.github.com/user/repos(different prefix)
Without Prefix
- ✓
https://httpbin.org/get - ✓
https://httpbin.org/post - ✓
https://httpbin.org/anything/goes/here
path_prefix is null.
Method Filtering
Specific Methods
- ✓ GET requests
- ✓ POST requests
- ❌ PUT requests
- ❌ DELETE requests
All Methods
- ✓ GET, POST, PUT, DELETE, PATCH, HEAD, OPTIONS, etc.
methods array means all methods allowed.
Security Edge Cases
Userinfo in URL (Blocked)
- Credential leakage in URLs
- Host confusion attacks (
https://trusted@evil.com)
Path Normalization
All paths normalized before matching:IPv6 Addresses
[2001:db8::1]→2001:db8::1
Rate Limiting
Per-tool request limits prevent abuse and runaway costs.Rate Limit Configuration
From src/tools/wasm/capabilities.rs:Rate Limiter Implementation
Slidding window algorithm:Rate Limit Errors
Size Limits
Prevent memory exhaustion and exfiltration via large payloads.Request Size Limits
Response Size Limits
- Memory exhaustion: Large responses filling WASM memory
- Cost overruns: Downloading massive files
- Exfiltration: Uploading huge datasets
HTTPS Enforcement
Plaintext HTTP is blocked by default.Disable HTTPS Requirement (Not Recommended)
For local development/testing only:Timeout Controls
Prevent hanging requests.reqwest:
Complete Example: OpenAI Integration
Capabilities File
Allowed Request
- ✓ Host
api.openai.comin allowlist - ✓ Path
/v1/chat/completionsmatches prefix/v1/ - ✓ Method
POSTis allowed - ✓ Scheme is
https - ✓ No secrets leaked in request
- ✓ Rate limit not exceeded
- ✓ Request body < 512 KB
- ✓ Credential injected:
Authorization: Bearer sk-... - ✓ HTTP request executed
- ✓ Response body < 1 MB
- ✓ No secrets in response
- ✓ Response returned to WASM
Denied Requests
Wrong Host
HostNotAllowed("evil.com")
Wrong Path
PathNotAllowed { host: "api.openai.com", path: "/admin/users" }
Wrong Method
MethodNotAllowed { method: "DELETE", host: "api.openai.com" }
Insecure Scheme
InsecureScheme("http")
Rate Limit Exceeded
RateLimitExceeded(PerMinute)
Request Too Large
RequestTooLarge { size: 10000000, limit: 524288 }
Monitoring and Logging
All network activity is logged:Allowed Requests
Denied Requests
Rate Limit Hits
Secret Leaks Blocked
Best Practices
For Tool Authors
- Request minimal access
- Use specific methods
- Set conservative limits
- Handle rate limits gracefully
For System Administrators
- Audit allowlists regularly
- Monitor denied requests
- Set resource limits per tool
- Use different limits for different tools
Network Security Checklist
- Allowlist contains only necessary hosts
- Path prefixes are as specific as possible
- HTTP methods are restricted (not empty array)
- HTTPS is enforced (don’t call
.allow_http()) - Rate limits are appropriate for use case
- Request/response sizes are reasonable
- Timeout is not too long (default 30s is good)
- Credentials are only for allowed hosts
- Logs are monitored for denied requests
- Capabilities are reviewed before deploying tools
Source Code References
- Allowlist validator: src/tools/wasm/allowlist.rs:74-164
- HTTP capability: src/tools/wasm/capabilities.rs:102-169
- Endpoint patterns: src/tools/wasm/capabilities.rs:172-200
- Rate limiter: src/tools/wasm/rate_limiter.rs
- URL parsing: src/tools/wasm/allowlist.rs:174-198
See Also
- Security Overview - Complete security architecture
- WASM Sandbox - HTTP capability configuration
- Credential Management - Secret injection at boundary
- Prompt Injection Defense - External content safety