ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Server.Pipeline.Origin

Description

Resolve metadata origins with their credential posture and typed outcomes. Private reads forward the caller's credential without caching. Public reads are anonymous. Explicit access refusals remain distinct for the packument pipeline, and an origin that answered 404 stays distinct from one that could not be read.

Synopsis

A resolved contribution

data Contribution Source #

A parsed contribution with opaque source bytes and a digest for the derived validator.

Constructors

Contribution 

Fields

fingerprintPiece :: Contribution -> (Provenance, ContentDigest, [(Text, [EntryKey])]) Source #

Scope surviving versions and exact artifact coordinates to their source digest and provenance.

The per-origin outcome

data OriginResult Source #

One origin's contribution, access refusal, identity mismatch, or absence.

Constructors

OriginResolved Manifest

A packument that decoded and whose self-reported name matched the request.

OriginAuthorisationFailure Int

An explicit upstream access refusal, retaining its 401 or 403.

OriginNameMismatch

An invalid package identity, contributing a 502 when no valid origin remains.

OriginNotFound

The origin answered 404, so it holds no such package. It degrades to no contribution.

OriginUnresolved

The origin was not read: unreachable, faulting, or undecodable. It degrades to no contribution.

OriginAbsent

An unconfigured origin contributes neither metadata nor an availability failure.

data OriginMiss Source #

Distinguish a settled absence from an unread origin that a retry may resolve.

Constructors

MissAbsent

The origin holds no such package, or the mount configures no such origin.

MissUnresolved

The origin was not read, so nothing yet says whether it holds the package.

Instances

Instances details
Show OriginMiss Source # 
Instance details

Defined in Ecluse.Core.Server.Pipeline.Origin

Eq OriginMiss Source # 
Instance details

Defined in Ecluse.Core.Server.Pipeline.Origin

originManifest :: OriginResult -> Maybe Manifest Source #

The resolved manifest an origin contributed, if any.

originMiss :: OriginResult -> Maybe OriginMiss Source #

The miss an origin yielded, or Nothing when it contributed a document or an explicit refusal.

Fetching the two origins

fetchPrivateOrigin :: PackumentDeps -> ServeRuntime -> MemoryTicket -> Maybe ClientCredential -> PackageName -> Handler OriginResult Source #

Resolve the private origin uncached with the caller's credential, retaining explicit access refusals.

fetchPublicOrigin :: PackumentDeps -> ServeRuntime -> MemoryTicket -> PackageName -> Handler OriginResult Source #

Resolve the public (gated, anonymous) upstream origin through the metadata cache, keyed by the origin's base URL as its Source.

preparePublicMetadata :: ServeRuntime -> PackumentDeps -> PackageName -> Version -> Handler (PreparedStore MetadataError VersionRead) Source #

Pin a public local value without starting remote work.

withPrivateMetadataClient :: ServeRuntime -> PackumentDeps -> RegistryUrl -> Maybe ClientCredential -> (MetadataClient -> IO a) -> Handler a Source #

Bypass shared caching so the private upstream authorises each caller's credential.

One origin's coordinates

mountOrigin :: PackumentDeps -> Manager -> RegistryUrl -> Maybe ClientCredential -> OriginClient Source #

Build an origin with the mount's response bound and the caller-selected manager and credential.