| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Package.Hash
Description
The integrity vocabulary shared by admission, merge, and worker verification.
Synopsis
- data Hash
- hashAlg :: Hash -> HashAlg
- hashValue :: Hash -> Text
- canonicalHashValue :: Hash -> Maybe Text
- mkHash :: HashAlg -> Text -> Either Text Hash
- mkSriHashes :: Text -> Either Text (NonEmpty Hash)
- data HashAlg
- renderHashAlg :: HashAlg -> Text
- parseHashAlg :: Text -> Either Text HashAlg
- sriPrefix :: Text -> Text
- sriBody :: Text -> Text
- sriAlgorithm :: Text -> Maybe HashAlg
- computeDigest :: HashAlg -> Maybe (LByteString -> ByteString)
- isComputable :: HashAlg -> Bool
- hexDigestText :: ByteString -> Text
- base64DigestText :: ByteString -> Text
Hashes
An artifact digest validated by mkHash. Record updates must preserve its encoding and length.
hashValue :: Hash -> Text Source #
The digest itself, in the algorithm's wire encoding (e.g. hex, or the
single sha512-… component for SRI).
mkHash :: HashAlg -> Text -> Either Text Hash Source #
Validate encoding and digest length, preserving the wire spelling. Strength is a separate admission decision.
mkSriHashes :: Text -> Either Text (NonEmpty Hash) Source #
Split SRI components, rejecting the whole string when empty or when any component is malformed.
A hash algorithm an integrity digest is computed with. The Ord instance is integrity
authority, not constructor order: SRI < MD5 < SHA1 < SHA256 < SHA384 < Blake2b < SHA512.
Constructors
| SHA1 | |
| SHA256 | |
| SHA384 | |
| SHA512 | |
| MD5 | |
| Blake2b | |
| SRI | One Subresource-Integrity component. |
Instances
Algorithm vocabulary
renderHashAlg :: HashAlg -> Text Source #
The canonical lowercase name, also used in configuration and error text.
parseHashAlg :: Text -> Either Text HashAlg Source #
Parse canonical names and single-dash aliases, ignoring case and surrounding whitespace. SRI is not selectable.
sriPrefix :: Text -> Text Source #
The token before the first dash. Without a dash, the entire string is the prefix.
sriAlgorithm :: Text -> Maybe HashAlg Source #
Resolve an SRI prefix. An unsupported prefix asserts no algorithm and clears no integrity floor.
Digest computation
computeDigest :: HashAlg -> Maybe (LByteString -> ByteString) Source #
Digest computation for verifiable algorithms. MD5 cannot prove integrity, and SRI must first resolve its algorithm.
isComputable :: HashAlg -> Bool Source #
Whether the worker can compute and verify the algorithm.
Wire encodings of digest bytes
hexDigestText :: ByteString -> Text Source #
The lowercase hex a non-SRI digest is compared and reported in.
base64DigestText :: ByteString -> Text Source #
The base64 body an SRI component carries after its algorithm prefix.