| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Server.Pipeline.Origin
Description
Resolve metadata origins with their credential posture and typed outcomes. Private reads forward the caller's credential without caching. Public reads are anonymous. Explicit access refusals remain distinct for the packument pipeline, and an origin that answered 404 stays distinct from one that could not be read.
Synopsis
- data Contribution = Contribution {}
- fingerprintPiece :: Contribution -> (Provenance, ContentDigest, [(Text, [EntryKey])])
- data OriginResult
- data OriginMiss
- originManifest :: OriginResult -> Maybe Manifest
- originMiss :: OriginResult -> Maybe OriginMiss
- fetchPrivateOrigin :: PackumentDeps -> ServeRuntime -> MemoryTicket -> Maybe ClientCredential -> PackageName -> Handler OriginResult
- fetchPublicOrigin :: PackumentDeps -> ServeRuntime -> MemoryTicket -> PackageName -> Handler OriginResult
- preparePublicMetadata :: ServeRuntime -> PackumentDeps -> PackageName -> Version -> Handler (PreparedStore MetadataError VersionRead)
- withPrivateMetadataClient :: ServeRuntime -> PackumentDeps -> RegistryUrl -> Maybe ClientCredential -> (MetadataClient -> IO a) -> Handler a
- mountOrigin :: PackumentDeps -> Manager -> RegistryUrl -> Maybe ClientCredential -> OriginClient
A resolved contribution
data Contribution Source #
A parsed contribution with opaque source bytes and a digest for the derived validator.
Constructors
| Contribution | |
Fields
| |
fingerprintPiece :: Contribution -> (Provenance, ContentDigest, [(Text, [EntryKey])]) Source #
Scope surviving versions and exact artifact coordinates to their source digest and provenance.
The per-origin outcome
data OriginResult Source #
One origin's contribution, access refusal, identity mismatch, or absence.
Constructors
| OriginResolved Manifest | A packument that decoded and whose self-reported name matched the request. |
| OriginAuthorisationFailure Int | An explicit upstream access refusal, retaining its 401 or 403. |
| OriginNameMismatch | An invalid package identity, contributing a 502 when no valid origin remains. |
| OriginNotFound | The origin answered 404, so it holds no such package. It degrades to no contribution. |
| OriginUnresolved | The origin was not read: unreachable, faulting, or undecodable. It degrades to no contribution. |
| OriginAbsent | An unconfigured origin contributes neither metadata nor an availability failure. |
data OriginMiss Source #
Distinguish a settled absence from an unread origin that a retry may resolve.
Constructors
| MissAbsent | The origin holds no such package, or the mount configures no such origin. |
| MissUnresolved | The origin was not read, so nothing yet says whether it holds the package. |
Instances
| Show OriginMiss Source # | |
Defined in Ecluse.Core.Server.Pipeline.Origin Methods showsPrec :: Int -> OriginMiss -> ShowS # show :: OriginMiss -> String # showList :: [OriginMiss] -> ShowS # | |
| Eq OriginMiss Source # | |
Defined in Ecluse.Core.Server.Pipeline.Origin | |
originManifest :: OriginResult -> Maybe Manifest Source #
The resolved manifest an origin contributed, if any.
originMiss :: OriginResult -> Maybe OriginMiss Source #
The miss an origin yielded, or Nothing when it contributed a document or an explicit refusal.
Fetching the two origins
fetchPrivateOrigin :: PackumentDeps -> ServeRuntime -> MemoryTicket -> Maybe ClientCredential -> PackageName -> Handler OriginResult Source #
Resolve the private origin uncached with the caller's credential, retaining explicit access refusals.
fetchPublicOrigin :: PackumentDeps -> ServeRuntime -> MemoryTicket -> PackageName -> Handler OriginResult Source #
Resolve the public (gated, anonymous) upstream origin through the metadata cache, keyed by the origin's base URL as its Source.
preparePublicMetadata :: ServeRuntime -> PackumentDeps -> PackageName -> Version -> Handler (PreparedStore MetadataError VersionRead) Source #
Pin a public local value without starting remote work.
withPrivateMetadataClient :: ServeRuntime -> PackumentDeps -> RegistryUrl -> Maybe ClientCredential -> (MetadataClient -> IO a) -> Handler a Source #
Bypass shared caching so the private upstream authorises each caller's credential.
One origin's coordinates
mountOrigin :: PackumentDeps -> Manager -> RegistryUrl -> Maybe ClientCredential -> OriginClient Source #
Build an origin with the mount's response bound and the caller-selected manager and credential.