Skip to main content
IronClaw implements strict network controls to ensure WASM tools can only access approved API endpoints with proper rate limiting and size constraints.

Security Model

WASM tools have zero network access by default. HTTP capability must be:
  1. Explicitly granted via capabilities file
  2. Allowlisted to specific hosts and paths
  3. Rate limited to prevent abuse
  4. Size constrained for requests and responses
  5. HTTPS-only (no plaintext HTTP)

HTTP Request Flow

Endpoint Allowlisting

The first and most critical defense: WASM tools can only make HTTP requests to explicitly approved endpoints.

Allowlist Configuration

Defined in *.capabilities.json:

EndpointPattern Structure

From src/tools/wasm/capabilities.rs:172-200:

Validation Logic

From src/tools/wasm/allowlist.rs:74-164:

Host Matching

Exact Match

Matches:
  • ✓ https://api.openai.com/v1/chat
  • ❌ https://openai.com/v1/chat (different host)
  • ❌ https://api.openai.com.evil.com (suffix attack)

Wildcard Subdomain

Matches:
  • ✓ https://api.example.com/data
  • ✓ https://staging.example.com/data
  • ❌ https://example.com/data (no subdomain)
  • ❌ https://api.example.com.evil.com (suffix attack blocked)

Case-Insensitive

Matches:
  • ✓ https://api.openai.com
  • ✓ https://API.OPENAI.COM
  • ✓ https://Api.OpenAi.Com
All hosts normalized to lowercase before matching.

Path Prefix Matching

With Prefix

Matches:
  • ✓ https://api.github.com/repos/owner/repo
  • ✓ https://api.github.com/repos/owner/repo/issues
  • ❌ https://api.github.com/users/username
  • ❌ https://api.github.com/user/repos (different prefix)

Without Prefix

Matches:
  • ✓ https://httpbin.org/get
  • ✓ https://httpbin.org/post
  • ✓ https://httpbin.org/anything/goes/here
All paths allowed when path_prefix is null.

Method Filtering

Specific Methods

Allows:
  • ✓ GET requests
  • ✓ POST requests
  • ❌ PUT requests
  • ❌ DELETE requests

All Methods

Allows:
  • ✓ GET, POST, PUT, DELETE, PATCH, HEAD, OPTIONS, etc.
Empty methods array means all methods allowed.

Security Edge Cases

Userinfo in URL (Blocked)

Blocked to prevent:
  • Credential leakage in URLs
  • Host confusion attacks (https://trusted@evil.com)
From src/tools/wasm/allowlist.rs:174-198:

Path Normalization

All paths normalized before matching:
Prevents path traversal bypasses.

IPv6 Addresses

Brackets stripped before matching:
  • [2001:db8::1] → 2001:db8::1

Rate Limiting

Per-tool request limits prevent abuse and runaway costs.

Rate Limit Configuration

From src/tools/wasm/capabilities.rs:
Capabilities file:

Rate Limiter Implementation

Slidding window algorithm:

Rate Limit Errors

WASM receives:

Size Limits

Prevent memory exhaustion and exfiltration via large payloads.

Request Size Limits

Validation:

Response Size Limits

Prevents:
  • Memory exhaustion: Large responses filling WASM memory
  • Cost overruns: Downloading massive files
  • Exfiltration: Uploading huge datasets

HTTPS Enforcement

Plaintext HTTP is blocked by default.
Attempts:
For local development/testing only:
Never disable HTTPS in production.

Timeout Controls

Prevent hanging requests.
Enforced via reqwest:
After timeout:

Complete Example: OpenAI Integration

Capabilities File

Allowed Request

Validation flow:
  1. ✓ Host api.openai.com in allowlist
  2. ✓ Path /v1/chat/completions matches prefix /v1/
  3. ✓ Method POST is allowed
  4. ✓ Scheme is https
  5. ✓ No secrets leaked in request
  6. ✓ Rate limit not exceeded
  7. ✓ Request body < 512 KB
  8. ✓ Credential injected: Authorization: Bearer sk-...
  9. ✓ HTTP request executed
  10. ✓ Response body < 1 MB
  11. ✓ No secrets in response
  12. ✓ Response returned to WASM

Denied Requests

Wrong Host

❌ Denied: HostNotAllowed("evil.com")

Wrong Path

❌ Denied: PathNotAllowed { host: "api.openai.com", path: "/admin/users" }

Wrong Method

❌ Denied: MethodNotAllowed { method: "DELETE", host: "api.openai.com" }

Insecure Scheme

❌ Denied: InsecureScheme("http")

Rate Limit Exceeded

❌ After 20 requests in 1 minute: RateLimitExceeded(PerMinute)

Request Too Large

❌ Denied: RequestTooLarge { size: 10000000, limit: 524288 }

Monitoring and Logging

All network activity is logged:

Allowed Requests

Denied Requests

Rate Limit Hits

Secret Leaks Blocked

Enable debug logging:

Best Practices

For Tool Authors

  1. Request minimal access
  1. Use specific methods
  1. Set conservative limits
  1. Handle rate limits gracefully

For System Administrators

  1. Audit allowlists regularly
  1. Monitor denied requests
  1. Set resource limits per tool
  1. Use different limits for different tools

Network Security Checklist

  • Allowlist contains only necessary hosts
  • Path prefixes are as specific as possible
  • HTTP methods are restricted (not empty array)
  • HTTPS is enforced (don’t call .allow_http())
  • Rate limits are appropriate for use case
  • Request/response sizes are reasonable
  • Timeout is not too long (default 30s is good)
  • Credentials are only for allowed hosts
  • Logs are monitored for denied requests
  • Capabilities are reviewed before deploying tools

Source Code References

See Also