ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Package.Hash

Description

The integrity vocabulary shared by admission, merge, and worker verification.

Synopsis

Hashes

data Hash Source #

An artifact digest validated by mkHash. Record updates must preserve its encoding and length.

Instances

Instances details
Show Hash Source # 
Instance details

Defined in Ecluse.Core.Package.Hash

Methods

showsPrec :: Int -> Hash -> ShowS #

show :: Hash -> String #

showList :: [Hash] -> ShowS #

Eq Hash Source # 
Instance details

Defined in Ecluse.Core.Package.Hash

Methods

(==) :: Hash -> Hash -> Bool #

(/=) :: Hash -> Hash -> Bool #

hashAlg :: Hash -> HashAlg Source #

The algorithm the digest was computed with.

hashValue :: Hash -> Text Source #

The digest itself, in the algorithm's wire encoding (e.g. hex, or the single sha512-… component for SRI).

canonicalHashValue :: Hash -> Maybe Text Source #

Lowercase hex for comparison, or Nothing if a record update introduced an invalid digest. The original hashValue remains unchanged.

mkHash :: HashAlg -> Text -> Either Text Hash Source #

Validate encoding and digest length, preserving the wire spelling. Strength is a separate admission decision.

mkSriHashes :: Text -> Either Text (NonEmpty Hash) Source #

Split SRI components, rejecting the whole string when empty or when any component is malformed.

data HashAlg Source #

A hash algorithm an integrity digest is computed with. The Ord instance is integrity authority, not constructor order: SRI < MD5 < SHA1 < SHA256 < SHA384 < Blake2b < SHA512.

Constructors

SHA1 
SHA256 
SHA384 
SHA512 
MD5 
Blake2b 
SRI

One Subresource-Integrity component. mkSriHashes splits whitespace-separated components.

Instances

Instances details
Generic HashAlg Source # 
Instance details

Defined in Ecluse.Core.Package.Hash

Associated Types

type Rep HashAlg 
Instance details

Defined in Ecluse.Core.Package.Hash

type Rep HashAlg = D1 ('MetaData "HashAlg" "Ecluse.Core.Package.Hash" "ecluse-0.4.0-inplace-ecluse-core" 'False) ((C1 ('MetaCons "SHA1" 'PrefixI 'False) (U1 :: Type -> Type) :+: (C1 ('MetaCons "SHA256" 'PrefixI 'False) (U1 :: Type -> Type) :+: C1 ('MetaCons "SHA384" 'PrefixI 'False) (U1 :: Type -> Type))) :+: ((C1 ('MetaCons "SHA512" 'PrefixI 'False) (U1 :: Type -> Type) :+: C1 ('MetaCons "MD5" 'PrefixI 'False) (U1 :: Type -> Type)) :+: (C1 ('MetaCons "Blake2b" 'PrefixI 'False) (U1 :: Type -> Type) :+: C1 ('MetaCons "SRI" 'PrefixI 'False) (U1 :: Type -> Type))))

Methods

from :: HashAlg -> Rep HashAlg x #

to :: Rep HashAlg x -> HashAlg #

Show HashAlg Source # 
Instance details

Defined in Ecluse.Core.Package.Hash

Eq HashAlg Source # 
Instance details

Defined in Ecluse.Core.Package.Hash

Methods

(==) :: HashAlg -> HashAlg -> Bool #

(/=) :: HashAlg -> HashAlg -> Bool #

Ord HashAlg Source # 
Instance details

Defined in Ecluse.Core.Package.Hash

Universe HashAlg Source # 
Instance details

Defined in Ecluse.Core.Package.Hash

Methods

universe :: [HashAlg] #

type Rep HashAlg Source # 
Instance details

Defined in Ecluse.Core.Package.Hash

type Rep HashAlg = D1 ('MetaData "HashAlg" "Ecluse.Core.Package.Hash" "ecluse-0.4.0-inplace-ecluse-core" 'False) ((C1 ('MetaCons "SHA1" 'PrefixI 'False) (U1 :: Type -> Type) :+: (C1 ('MetaCons "SHA256" 'PrefixI 'False) (U1 :: Type -> Type) :+: C1 ('MetaCons "SHA384" 'PrefixI 'False) (U1 :: Type -> Type))) :+: ((C1 ('MetaCons "SHA512" 'PrefixI 'False) (U1 :: Type -> Type) :+: C1 ('MetaCons "MD5" 'PrefixI 'False) (U1 :: Type -> Type)) :+: (C1 ('MetaCons "Blake2b" 'PrefixI 'False) (U1 :: Type -> Type) :+: C1 ('MetaCons "SRI" 'PrefixI 'False) (U1 :: Type -> Type))))

Algorithm vocabulary

renderHashAlg :: HashAlg -> Text Source #

The canonical lowercase name, also used in configuration and error text.

parseHashAlg :: Text -> Either Text HashAlg Source #

Parse canonical names and single-dash aliases, ignoring case and surrounding whitespace. SRI is not selectable.

sriPrefix :: Text -> Text Source #

The token before the first dash. Without a dash, the entire string is the prefix.

sriBody :: Text -> Text Source #

The body after the first dash, or empty text when there is no dash.

sriAlgorithm :: Text -> Maybe HashAlg Source #

Resolve an SRI prefix. An unsupported prefix asserts no algorithm and clears no integrity floor.

Digest computation

computeDigest :: HashAlg -> Maybe (LByteString -> ByteString) Source #

Digest computation for verifiable algorithms. MD5 cannot prove integrity, and SRI must first resolve its algorithm.

isComputable :: HashAlg -> Bool Source #

Whether the worker can compute and verify the algorithm.

Wire encodings of digest bytes

hexDigestText :: ByteString -> Text Source #

The lowercase hex a non-SRI digest is compared and reported in.

base64DigestText :: ByteString -> Text Source #

The base64 body an SRI component carries after its algorithm prefix.