ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Registry.Request

Description

Ecosystem-agnostic request mechanics: the outbound finaliser, the credential presentation, and URL parsing into a typed UrlFormationError. An adapter supplies only its own protocol facts.

parseRequestEither seals what it parses, so an adapter cannot obtain an unsealed Request from this module at all.

Synopsis

Request finalisation

sealRequest :: Request -> Request Source #

Seal the outbound invariants onto a request, idempotently. A followed redirect could re-send a credential cross-host or steer an anonymous fetch past the host allowlist.

finaliseRequest :: (Request -> Request) -> Request -> Request Source #

Apply the ecosystem's injected credential attach, then seal the result through sealRequest. The attach runs first, so it cannot reopen redirect following.

Credential presentation

data CredentialMapping Source #

One ecosystem's credential presentation, recovered as a value so an attach re-encodes rather than replaying a header. The constructor is hidden, so no adapter spells its own attach point.

credentialMapping :: (RequestHeaders -> Maybe ClientCredential) -> HeaderName -> (ClientCredential -> ByteString) -> CredentialMapping Source #

Declare an ecosystem's credential presentation. The constructor is hidden, so this is the only way to build a CredentialMapping.

credentialRecover :: CredentialMapping -> RequestHeaders -> Maybe ClientCredential Source #

Nothing for a request carrying none in this ecosystem's form, which the edge gate denies rather than half-reading. The compare is over the secret half alone.

attachCredential :: CredentialMapping -> Maybe ClientCredential -> Request -> Request Source #

Attach a credential to an outbound request under the mapping's own header, then finalise it through finaliseRequest. A Nothing attaches no header, and the seal still applies.

authorizationUnder :: Text -> RequestHeaders -> Maybe Text Source #

The first Authorization header's remainder when it carries scheme (compared without case), with the separating spaces dropped. Another scheme or no header yields Nothing.

Request building

artifactRequestByUrl :: CredentialMapping -> Maybe ClientCredential -> Text -> Either UrlFormationError Request Source #

Build the artifact GET at the URL a projection preserved from upstream. Non-decompressing, so the bytes the served integrity digest is paired with are never gunzipped.

parseRequestEither :: Text -> Either UrlFormationError Request Source #

Parse a URL into the sealed request every adapter builds from (sealRequest). The URL comes from configuration and an already-safe name, so a parse failure here is a configuration fault.