checkCommand method

CubePolicyDecision checkCommand(
  1. String commandLine
)

Checks every command the commandLine would run.

Returns the first denial in left-to-right segment order, or CubePolicyDecision.allowed when every segment passes.

Implementation

CubePolicyDecision checkCommand(String commandLine) {
  for (final segment in _splitSegments(commandLine)) {
    final words = _commandWords(segment);
    if (words.isEmpty) continue;
    final toolDecision = _checkToolPolicy(words);
    if (!toolDecision.allowed) return toolDecision;
    final networkDecision = _checkNetworkPolicy(words);
    if (!networkDecision.allowed) return networkDecision;
    final redirectDecision = _checkRedirects(segment);
    if (!redirectDecision.allowed) return redirectDecision;
  }
  return const CubePolicyDecision.allowed();
}