| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Registry.Request
Description
Ecosystem-agnostic request mechanics: the outbound finaliser, the credential presentation,
and URL parsing into a typed UrlFormationError. An adapter supplies only its own protocol facts.
parseRequestEither seals what it parses, so an adapter cannot obtain an unsealed Request
from this module at all.
Synopsis
- sealRequest :: Request -> Request
- finaliseRequest :: (Request -> Request) -> Request -> Request
- data CredentialMapping
- credentialMapping :: (RequestHeaders -> Maybe ClientCredential) -> HeaderName -> (ClientCredential -> ByteString) -> CredentialMapping
- credentialRecover :: CredentialMapping -> RequestHeaders -> Maybe ClientCredential
- attachCredential :: CredentialMapping -> Maybe ClientCredential -> Request -> Request
- authorizationUnder :: Text -> RequestHeaders -> Maybe Text
- artifactRequestByUrl :: CredentialMapping -> Maybe ClientCredential -> Text -> Either UrlFormationError Request
- joinPath :: Text -> Text -> Either UrlFormationError Text
- parseRequestEither :: Text -> Either UrlFormationError Request
Request finalisation
sealRequest :: Request -> Request Source #
Seal the outbound invariants onto a request, idempotently. A followed redirect could re-send a credential cross-host or steer an anonymous fetch past the host allowlist.
finaliseRequest :: (Request -> Request) -> Request -> Request Source #
Apply the ecosystem's injected credential attach, then seal the result through
sealRequest. The attach runs first, so it cannot reopen redirect following.
Credential presentation
data CredentialMapping Source #
One ecosystem's credential presentation, recovered as a value so an attach re-encodes rather than replaying a header. The constructor is hidden, so no adapter spells its own attach point.
credentialMapping :: (RequestHeaders -> Maybe ClientCredential) -> HeaderName -> (ClientCredential -> ByteString) -> CredentialMapping Source #
Declare an ecosystem's credential presentation. The constructor is hidden, so this is the
only way to build a CredentialMapping.
credentialRecover :: CredentialMapping -> RequestHeaders -> Maybe ClientCredential Source #
Nothing for a request carrying none in this ecosystem's form, which the edge gate
denies rather than half-reading. The compare is over the secret half alone.
attachCredential :: CredentialMapping -> Maybe ClientCredential -> Request -> Request Source #
Attach a credential to an outbound request under the mapping's own header, then finalise it
through finaliseRequest. A Nothing attaches no header, and the seal still applies.
authorizationUnder :: Text -> RequestHeaders -> Maybe Text Source #
The first Authorization header's remainder when it carries scheme (compared without
case), with the separating spaces dropped. Another scheme or no header yields Nothing.
Request building
artifactRequestByUrl :: CredentialMapping -> Maybe ClientCredential -> Text -> Either UrlFormationError Request Source #
Build the artifact GET at the URL a projection preserved from upstream. Non-decompressing,
so the bytes the served integrity digest is paired with are never gunzipped.
parseRequestEither :: Text -> Either UrlFormationError Request Source #
Parse a URL into the sealed request every adapter builds from (sealRequest). The URL comes
from configuration and an already-safe name, so a parse failure here is a configuration fault.