ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Security.Limits

Description

Response bounds for the data plane: what an upstream may make the proxy hold, walk, or wait on.

A Limits budget bounds the algorithmic-complexity and stalling DoS a hostile or compromised upstream can inflict. Every limit fails closed: a breach yields Left, never a truncated or partial result.

Synopsis

Response bounds

data Limits Source #

Byte ceilings by operation, structural metadata backstops, and the upstream progress floor.

Constructors

Limits 

Fields

Instances

Instances details
Show Limits Source # 
Instance details

Defined in Ecluse.Core.Security.Limits

Eq Limits Source # 
Instance details

Defined in Ecluse.Core.Security.Limits

Methods

(==) :: Limits -> Limits -> Bool #

(/=) :: Limits -> Limits -> Bool #

defaultLimits :: Limits Source #

Generous bounded metadata input, with publish and mirror caps resolved separately by composition.

data BodyLimit Source #

The selected body role and its byte ceiling, shared by reads and failures.

Constructors

MetadataBodyLimit Int

Metadata and registry control responses.

PublishRequestBodyLimit Int

Inbound first-party publish requests.

MirrorArtifactBodyLimit Int

Artifacts buffered by the mirror worker.

Instances

Instances details
Show BodyLimit Source # 
Instance details

Defined in Ecluse.Core.Security.Limits

Eq BodyLimit Source # 
Instance details

Defined in Ecluse.Core.Security.Limits

bodyLimitBytes :: BodyLimit -> Int Source #

The selected ceiling in bytes, before decoding or projection.

data LimitError Source #

Which Limits ceiling a response exceeded.

Constructors

BodyTooLarge BodyLimit

The selected body role exceeded its configured byte ceiling.

TooManyVersions Int Int

More than maxVersionCount versions. Carries the count seen and the ceiling.

TooManyArtifacts Int Int

More than maxArtifactCount artifacts across the versions, then the ceiling.

TooDeeplyNested Int

JSON nesting exceeded maxNestingDepth. Carries the ceiling.

Instances

Instances details
Show LimitError Source # 
Instance details

Defined in Ecluse.Core.Security.Limits

Eq LimitError Source # 
Instance details

Defined in Ecluse.Core.Security.Limits

boundedRead :: Monad m => BodyLimit -> m ByteString -> m (Either LimitError (Int, ByteString)) Source #

Return the consumed byte count and body. An empty chunk ends the read, and an overstep refuses it whole.

checkVersionCountOf :: Limits -> Int -> Either LimitError () Source #

The same ceiling over a bare count, for a caller that knows how many versions a document carries without projecting it, as the selective decoders do while they skip entries.

checkArtifactCount :: Limits -> PackageInfo -> Either LimitError PackageInfo Source #

Reject a parsed document carrying more than maxArtifactCount artifacts across all its versions. Adapters check version counts before applying the artifact ceiling.

Upstream progress

data ProgressFloor Source #

A progress window, the body bytes a transfer must move within it, and the serve-path cap the window must stay below. The private constructor keeps the three consistent.

data ProgressFloorError Source #

Why a window and a byte count make no ProgressFloor.

Constructors

WindowNotPositive

The window is zero or negative.

WindowNotBelowServeCap

The window is not below the serve-path cap, so the floor could never fire before the cap.

MinBytesNotPositive

The byte count is zero or negative.

mkProgressFloor :: NominalDiffTime -> NominalDiffTime -> Int -> Either (NonEmpty ProgressFloorError) ProgressFloor Source #

The floor for a serve-path cap, a window, and a byte count, in that order, with every refusal.

floorWindowMicros :: ProgressFloor -> Int Source #

The waiting time, in microseconds, within which a transfer must move floorMinBytes.

floorMinBytes :: ProgressFloor -> Int Source #

The body bytes a transfer must move within each window.

floorServeCapMicros :: ProgressFloor -> Int Source #

How long one serve-path exchange may run, in microseconds.

requestTimeoutSeconds :: Int Source #

The front door's per-request timeout, in seconds. Generous enough for a large packument fetch, bounded so a stuck upstream cannot pin a handler indefinitely.

serveCapMarginSeconds :: Int Source #

Seconds the serve-path cap leaves under the request timeout for admission waits and the work around an exchange.

serveCapSeconds :: Int Source #

How long one serve-path upstream exchange may run, in seconds: the request timeout less its margin.