ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Server.Pipeline.Shared

Description

Shared authentication, admission shedding, and refusal handling. Route handlers keep their own response formats while sharing these policy decisions.

Synopsis

Edge authentication

edgeTokenMatches :: Maybe Secret -> Maybe ClientCredential -> Bool Source #

Match the configured inbound secret without content-dependent early exit. An unconfigured edge is open.

unauthorisedMessage :: Text Source #

Report edge authentication failure without disclosing either token.

privateAuthorisationRefusal :: Maybe HelpMessage -> Refusal Source #

The fixed refusal shared by private metadata and artifact access failures.

Admission shed

withMetadataAdmission :: MonadUnliftIO m => ServeRuntime -> m received -> (MemoryTicket -> m a) -> (a -> m received) -> m received Source #

Run metadata work behind the memory gate and then the CPU gate, and answer its result after both release. A shed at either gate answers with shed, counted once.

shedStatus :: Status Source #

Use 503 to report server admission capacity, without implying a client rate limit.

shedMessage :: Text Source #

The body every read-path shed answers with, so the three handlers say one thing.

shedRetryAfter :: Header Source #

The shed retry delay, rounded down to whole seconds from admissionWaitMicros.

retryAfterHeaders :: Maybe RetryAfter -> ResponseHeaders Source #

Emit Retry-After only when a decision supplies a delay.

First-party refusals

firstPartyRule :: RuleName Source #

The rule a first-party refusal names, so the read pipelines label one denial series rather than two spellings of the same refusal.

Integrity-floor rejections