ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Registry.Npm.Publish

Description

npm mirror publication through Ecluse.Core.Registry.Publish, plus identity extraction for the first-party publish guard. Published SRI retains all alternatives at its strongest algorithm, matching the worker's verification contract. The published version object keeps what the author wrote and strips what the public registry issued about itself, and a plan whose version object is not an npm object is refused rather than reduced.

Synopsis

Documentation

npmPublishCodec :: PublishCodec Source #

Probe an abbreviated packument and publish verified bytes with their strongest SRI alternatives.

publishRequest :: Text -> Maybe ClientCredential -> PackageName -> ByteString -> Either UrlFormationError Request Source #

Build the publish request with its credential, failing when the URL cannot be formed.

npmPublishDocument Source #

Arguments

:: PackageName 
-> PublishPlan 
-> Text

The tarball's filename: the _attachments key and tarball file segment.

-> Maybe Text

The dist.integrity SRI string, if known (e.g. "sha512-...").

-> Maybe Text

The dist.shasum (SHA-1, hex), if known.

-> ByteString

The verified tarball bytes.

-> Either PublishFault ByteString 

Assemble one version from the plan's metadata, under local authority for the name, version, and verified dist fields. The declared latest is the plan's: a registry left to choose can retag.

declaredNames :: LByteString -> [Text] Source #

Read _id, name and each version's name for the anti-shadowing guard. An undecodable body declares nothing.

npmPublishAllowed :: [Scope] -> PackageName -> Bool Source #

Require an exact configured scope, refusing unscoped names and scope prefixes.