ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Registry.Npm.Request

Description

Request shaping and URL building for the npm data plane, composed over the ecosystem-agnostic mechanics in Ecluse.Core.Registry.Request (the outbound seal, URL parsing, the path join, the opaque-artifact request core).

Three of npm's protocol facts are load-bearing here. Metadata comes in two forms chosen by Accept, a scoped name travels as the single segment @scope%2Fname, and an artifact request must not decompress in flight, because the client verifies the relayed bytes against the packument's dist.integrity.

Synopsis

Content negotiation

data MetadataForm Source #

Which of npm's two metadata documents to request, selected by the Accept header.

Constructors

Abbreviated

The install view (application/vnd.npm.install-v1+json), which drops the time map.

Full

The full packument (application/json), the only form carrying the time map.

The ecosystem's artifact hosts

npmArtifactHosts :: [Text] Source #

npm's canonical artifact hosts: none, because a registry serves its own tarball bytes. The gate and the projection read this one list, so an artifact authority means one thing on both.

Request building

metadataRequest :: Text -> Maybe ClientCredential -> MetadataForm -> PackageName -> Either UrlFormationError Request Source #

Build the metadata GET request for a package at {baseUrl}/{encoded-name}. It asks for gzip, because a popular packument is megabytes.

artifactRequestByFile :: Text -> Maybe ClientCredential -> PackageName -> Text -> Either UrlFormationError Request Source #

Build the artifact GET at {baseUrl}{encoded-pkg}-/{filename}. It addresses the tarball by the filename the client requested, so a registry with its own tarball naming still resolves.

artifactRequestByUrl :: Maybe ClientCredential -> Text -> Either UrlFormationError Request Source #

Build npm's artifact GET for the absolute url the projection preserved from the upstream's dist.tarball, under npm's credential presentation.

artifactFileUrl :: Text -> PackageName -> Text -> Either UrlFormationError Text Source #

The artifact URL {baseUrl}/{encoded-name}/-/{encoded-filename}, with filename percent-encoded as one component so a once-decoded escape cannot reach the upstream raw.

Shared internals

jsonPutRequest :: Maybe ClientCredential -> Text -> ByteString -> Either UrlFormationError Request Source #

Build the JSON PUT at url carrying document, under the injected credential. An npm registry answers 415 unless the body declares application/json.