DenylistService class

Operator-controlled content denylist service.

Supports CID strings, multihash strings, and BadBits-style compact lists. The service is default-off: it only blocks requests when the operator explicitly enables it via SecurityConfig.enableDenylist.

Constructors

DenylistService(SecurityConfig _config, MetricsCollector _metrics, {String? storagePath, Client? httpClient})
Creates a denylist service from security configuration and metrics.

Properties

configuredEnabled → bool
Returns whether the operator has enabled the denylist in configuration.
no setter
defaultAction → String
Returns the configured default action: "block" or "log".
no setter
hashCode → int
The hash code for this object.
no setterinherited
isEnabled → bool
Returns whether the denylist is enabled and contains entries.
no setter
length → int
Returns the number of loaded entries (CIDs + multihashes).
no setter
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited

Methods

block(CID cid) → void
Adds a single CID to the in-memory denylist.
blockCidString(String cidStr) → void
Adds a CID string to the in-memory denylist.
clear() → void
Clears all in-memory denylist entries.
getAuditLog() → List<DenylistAuditEvent>
Returns a copy of the audit log, oldest first.
getStats() → DenylistStats
Returns the current denylist statistics.
isBlocked(CID cid) → bool
Returns true if the CID is blocked.
isBlockedByCidString(String cidStr) → bool
Returns true if the CID string is blocked.
isBlockedByMultihash(String multihash) → bool
Returns true if the multihash string is blocked.
isBlockedPath(String path) → bool
Returns true if the path contains a blocked CID or IPNS name.
loadCompactBytes(Uint8List bytes) → void
Loads a compact BadBits-style denylist from raw bytes.
loadFromPath(String path) → Future<void>
Loads the denylist from a local file path.
loadFromUrl(String url) → Future<void>
Loads the denylist from an HTTP(S) URL.
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
recordHit(String cidOrMultihash, {required String source, String? reason}) → String
Records a denylist hit and returns the action that should be taken.
refresh() → Future<void>
Refreshes the denylist from the configured source.
start() → Future<void>
Starts the service, loads the initial denylist, and schedules refreshes.
stop() → Future<void>
Stops the service and cancels the refresh timer.
toString() → String
A string representation of this object.
inherited
unblock(CID cid) → void
Removes a CID from the in-memory denylist.
unblockCidString(String cidStr) → void
Removes a CID string from the in-memory denylist.

Operators

operator ==(Object other) → bool
The equality operator.
inherited