paperclipai/paperclip · error · Error

networkAllowlist[ ] must be a hostname, hostname:port, or…

Error message

networkAllowlist[${index}] must be a hostname, hostname:port, or origin URL.

What it means

parseNetworkAllowlistEntry could not parse the entry as a URL/hostname:port/origin (it had a path, credentials, or was malformed), so the allowlist rule is rejected.

Solutions

  1. Use a hostname, hostname:port, or origin URL for networkAllowlist[${index}].
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/adapter-utils/src/local-process-sandbox.ts:134 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of paperclipai/paperclip@120ae5428f (2026-08-18). Data as JSON: /api/errors/86d3631dc99cd9f4. Report an issue: GitHub.

Appendix: source

Thrown at packages/adapter-utils/src/local-process-sandbox.ts:134

  const realCommand = await fs.realpath(command).catch(() => command);
  paths.add(await nearestPackageRoot(realCommand));
  return Array.from(paths);
}

function parseNetworkAllowlistEntry(entry: string, index: number): NetworkAllowlistRule {
  const trimmed = entry.trim();
  if (!trimmed) throw new Error(`networkAllowlist[${index}] must not be empty.`);
  let hostname: string;
  let port: string | null;
  try {
    const parsed = new URL(trimmed.includes("://") ? trimmed : `https://${trimmed}`);
    if (parsed.username || parsed.password || parsed.pathname !== "/" || parsed.search || parsed.hash) {
      throw new Error("path");
    }
    hostname = parsed.hostname.toLowerCase();
    port = parsed.port || null;
  } catch {
    throw new Error(`networkAllowlist[${index}] must be a hostname, hostname:port, or origin URL.`);
  }
  if (!hostname || hostname === "*" || hostname.startsWith("*.")) {
    throw new Error(`networkAllowlist[${index}] must use an exact hostname; wildcards are not supported.`);
  }
  return { hostname, port };
}

export function parseLocalProcessNetworkAllowlist(value: unknown): string[] {
  if (!Array.isArray(value)) return [];
  return value.map((entry, index) => {
    if (typeof entry !== "string") throw new Error(`networkAllowlist[${index}] must be a string.`);
    const rule = parseNetworkAllowlistEntry(entry, index);
    return rule.port ? `${rule.hostname}:${rule.port}` : rule.hostname;
  });
}

export function parseLocalProcessNetworkScope(value: unknown): LocalProcessNetworkScope | null {
  if (value == null || value === "") return null;

View on GitHub (pinned to 120ae5428f)