OutboundHostValidatorOptions interface

Configuration for the shared outbound-host allowlist.

Properties

enabled

Enables allowlist enforcement. Defaults to false.

hosts

Additional exact hosts or host suffixes to allow. An entry matches a request host when the host equals the entry or is a subdomain of it (e.g. contoso.com matches contoso.com and files.contoso.com). A leading *. is accepted and ignored (treated as a suffix). Ports and paths are ignored if provided.

includeDefaultMicrosoftHosts

Indicates whether the built-in list of Microsoft first-party hosts (Bot Connector, Graph, SharePoint, Azure Blob/AMS) is included when enforcement is enabled. Defaults to true.

Property Details

enabled

Enables allowlist enforcement. Defaults to false.

enabled?: boolean

Property Value

boolean

hosts

Additional exact hosts or host suffixes to allow. An entry matches a request host when the host equals the entry or is a subdomain of it (e.g. contoso.com matches contoso.com and files.contoso.com). A leading *. is accepted and ignored (treated as a suffix). Ports and paths are ignored if provided.

hosts?: readonly string[]

Property Value

readonly string[]

includeDefaultMicrosoftHosts

Indicates whether the built-in list of Microsoft first-party hosts (Bot Connector, Graph, SharePoint, Azure Blob/AMS) is included when enforcement is enabled. Defaults to true.

includeDefaultMicrosoftHosts?: boolean

Property Value

boolean