checkCommand method
Checks every command the commandLine would run.
Returns the first denial in left-to-right segment order, or CubePolicyDecision.allowed when every segment passes.
Implementation
CubePolicyDecision checkCommand(String commandLine) {
for (final segment in _splitSegments(commandLine)) {
final words = _commandWords(segment);
if (words.isEmpty) continue;
final toolDecision = _checkToolPolicy(words);
if (!toolDecision.allowed) return toolDecision;
final networkDecision = _checkNetworkPolicy(words);
if (!networkDecision.allowed) return networkDecision;
final redirectDecision = _checkRedirects(segment);
if (!redirectDecision.allowed) return redirectDecision;
}
return const CubePolicyDecision.allowed();
}