| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Package.Filter
Description
Ecosystem-independent listing decisions and artifact-location admission. Adapters replay the surviving versions and files onto their raw documents. Ecluse.Core.Package.Filter.Internal holds the per-artifact location check.
Synopsis
- data FilterPlan = FilterPlan {
- fpSurvivors :: Set Text
- fpDecisions :: [Decision]
- filterPlanFromDecisions :: Map Text Decision -> FilterPlan
- restrictToSurvivors :: Set Text -> PackageInfo -> PackageInfo
- enforceArtifactLocations :: AllowedHostPorts -> Text -> PackageInfo -> PackageInfo
- enforceArtifactLocationsOf :: AllowedHostPorts -> Text -> PackageDetails -> Maybe PackageDetails
Rule-filter plan
data FilterPlan Source #
The filtering decisions for one public packument, for the adapter to replay onto the raw
upstream Value. It carries only decisions, never a finished, re-serialisable document.
Constructors
| FilterPlan | |
Fields
| |
Instances
| Show FilterPlan Source # | |
Defined in Ecluse.Core.Package.Filter Methods showsPrec :: Int -> FilterPlan -> ShowS # show :: FilterPlan -> String # showList :: [FilterPlan] -> ShowS # | |
| Eq FilterPlan Source # | |
Defined in Ecluse.Core.Package.Filter | |
filterPlanFromDecisions :: Map Text Decision -> FilterPlan Source #
Build a FilterPlan from per-version Decisions already taken. A version survives iff its
decision is Admitted, so an undecided one drops fail-closed.
restrictToSurvivors :: Set Text -> PackageInfo -> PackageInfo Source #
Restrict a PackageInfo to the surviving version keys, pruning dist-tags to targets
that survive. mergePackuments treats the result as already gated.
Served-location enforcement
enforceArtifactLocations :: AllowedHostPorts -> Text -> PackageInfo -> PackageInfo Source #
Drop artifacts with refused filenames, schemes, or authorities, and versions left with none. Retain drop records for operator reporting.
enforceArtifactLocationsOf :: AllowedHostPorts -> Text -> PackageDetails -> Maybe PackageDetails Source #
The single-version form of enforceArtifactLocations, for the selective decode path.
Nothing means no artifact of the version survived, so the version drops.