| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Security.Egress
Description
The egress posture for registry traffic: https-only by construction.
Every outbound registry URL is a RegistryUrl, so a plain-HTTP target cannot be represented
and a non-https configured upstream fails closed at boot.
Endpoint authentication
TLS certificate validation, not a resolved-IP pin, is the boundary: an attacker who steers a
name to an internal address cannot make it present a CA-trusted certificate for that host. The
host allowlist (isAllowedUpstreamHost), the literal internal-range block,
and the redirectCount = 0 every request carries are complementary controls owned elsewhere.
Synopsis
- data RegistryUrl
- mkRegistryUrl :: Text -> Either Text RegistryUrl
- mkConfiguredRegistryUrl :: Text -> Either Text RegistryUrl
- registryUrlText :: RegistryUrl -> Text
- resolveTarballUrl :: Text -> Text -> Either Text RegistryUrl
The https-only egress URL
data RegistryUrl Source #
An outbound registry-egress URL, https by construction and stored with surrounding whitespace trimmed. A plain-HTTP registry target cannot be represented in a running system.
Instances
| Show RegistryUrl Source # | |
Defined in Ecluse.Core.Security.Egress.Internal Methods showsPrec :: Int -> RegistryUrl -> ShowS # show :: RegistryUrl -> String # showList :: [RegistryUrl] -> ShowS # | |
| Eq RegistryUrl Source # | |
Defined in Ecluse.Core.Security.Egress.Internal | |
| Ord RegistryUrl Source # | |
Defined in Ecluse.Core.Security.Egress.Internal Methods compare :: RegistryUrl -> RegistryUrl -> Ordering # (<) :: RegistryUrl -> RegistryUrl -> Bool # (<=) :: RegistryUrl -> RegistryUrl -> Bool # (>) :: RegistryUrl -> RegistryUrl -> Bool # (>=) :: RegistryUrl -> RegistryUrl -> Bool # max :: RegistryUrl -> RegistryUrl -> RegistryUrl # min :: RegistryUrl -> RegistryUrl -> RegistryUrl # | |
mkRegistryUrl :: Text -> Either Text RegistryUrl Source #
Build a RegistryUrl, accepting only an https:// URL, matched case-insensitively. The
configuration layer fails closed at boot on the Left reason, which quotes the offending value.
>>>mkRegistryUrl "https://registry.npmjs.org"Right (RegistryUrl "https://registry.npmjs.org")
>>>mkRegistryUrl "http://registry.npmjs.org"Left "registry URL must use https (got http://registry.npmjs.org)"
mkConfiguredRegistryUrl :: Text -> Either Text RegistryUrl Source #
Build a RegistryUrl for an operator-configured endpoint. refuseCredentialMaterial
runs before mkRegistryUrl, which quotes what it rejects.
>>>mkConfiguredRegistryUrl "https://registry.npmjs.org"Right (RegistryUrl "https://registry.npmjs.org")
>>>mkConfiguredRegistryUrl "https://deploy:hunter2@registry.npmjs.org"Left "registry URL must not carry userinfo (a credential belongs in its own configuration key)"
registryUrlText :: RegistryUrl -> Text Source #
The underlying URL text.
Packument dist.tarball normalisation
resolveTarballUrl :: Text -> Text -> Either Text RegistryUrl Source #
Resolve a packument's dist.tarball under the https-only posture: plaintext upgrades
to https only on its own host. A refusal names the authority, since the URL can carry a credential.