ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Security.Egress

Description

The egress posture for registry traffic: https-only by construction.

Every outbound registry URL is a RegistryUrl, so a plain-HTTP target cannot be represented and a non-https configured upstream fails closed at boot.

Endpoint authentication

TLS certificate validation, not a resolved-IP pin, is the boundary: an attacker who steers a name to an internal address cannot make it present a CA-trusted certificate for that host. The host allowlist (isAllowedUpstreamHost), the literal internal-range block, and the redirectCount = 0 every request carries are complementary controls owned elsewhere.

Synopsis

The https-only egress URL

data RegistryUrl Source #

An outbound registry-egress URL, https by construction and stored with surrounding whitespace trimmed. A plain-HTTP registry target cannot be represented in a running system.

mkRegistryUrl :: Text -> Either Text RegistryUrl Source #

Build a RegistryUrl, accepting only an https:// URL, matched case-insensitively. The configuration layer fails closed at boot on the Left reason, which quotes the offending value.

>>> mkRegistryUrl "https://registry.npmjs.org"
Right (RegistryUrl "https://registry.npmjs.org")
>>> mkRegistryUrl "http://registry.npmjs.org"
Left "registry URL must use https (got http://registry.npmjs.org)"

mkConfiguredRegistryUrl :: Text -> Either Text RegistryUrl Source #

Build a RegistryUrl for an operator-configured endpoint. refuseCredentialMaterial runs before mkRegistryUrl, which quotes what it rejects.

>>> mkConfiguredRegistryUrl "https://registry.npmjs.org"
Right (RegistryUrl "https://registry.npmjs.org")
>>> mkConfiguredRegistryUrl "https://deploy:hunter2@registry.npmjs.org"
Left "registry URL must not carry userinfo (a credential belongs in its own configuration key)"

registryUrlText :: RegistryUrl -> Text Source #

The underlying URL text.

Packument dist.tarball normalisation

resolveTarballUrl :: Text -> Text -> Either Text RegistryUrl Source #

Resolve a packument's dist.tarball under the https-only posture: plaintext upgrades to https only on its own host. A refusal names the authority, since the URL can carry a credential.