ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Package.Filter

Description

Ecosystem-independent listing decisions and artifact-location admission. Adapters replay the surviving versions and files onto their raw documents. Ecluse.Core.Package.Filter.Internal holds the per-artifact location check.

Synopsis

Rule-filter plan

data FilterPlan Source #

The filtering decisions for one public packument, for the adapter to replay onto the raw upstream Value. It carries only decisions, never a finished, re-serialisable document.

Constructors

FilterPlan 

Fields

  • fpSurvivors :: Set Text

    The surviving version keys (the raw infoVersions keys): exactly those the rules engine approved. Empty when no version survived.

  • fpDecisions :: [Decision]

    Every version's Decision, admitted ones included, in version-key order so the adapter can zip them back onto the same-ordered versions. Feeds the no-survivors status and denial body.

Instances

Instances details
Show FilterPlan Source # 
Instance details

Defined in Ecluse.Core.Package.Filter

Eq FilterPlan Source # 
Instance details

Defined in Ecluse.Core.Package.Filter

filterPlanFromDecisions :: Map Text Decision -> FilterPlan Source #

Build a FilterPlan from per-version Decisions already taken. A version survives iff its decision is Admitted, so an undecided one drops fail-closed.

restrictToSurvivors :: Set Text -> PackageInfo -> PackageInfo Source #

Restrict a PackageInfo to the surviving version keys, pruning dist-tags to targets that survive. mergePackuments treats the result as already gated.

Served-location enforcement

enforceArtifactLocations :: AllowedHostPorts -> Text -> PackageInfo -> PackageInfo Source #

Drop artifacts with refused filenames, schemes, or authorities, and versions left with none. Retain drop records for operator reporting.

enforceArtifactLocationsOf :: AllowedHostPorts -> Text -> PackageDetails -> Maybe PackageDetails Source #

The single-version form of enforceArtifactLocations, for the selective decode path. Nothing means no artifact of the version survived, so the version drops.