ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Worker.Integrity

Description

Verify artifact bytes before publication into the trusted mirror. The gate uses current metadata from admission, never digests from the queue. SRI components at the strongest algorithm are alternatives. A weaker digest cannot rescue a mismatch, because that would permit substitution through a broken hash.

Synopsis

Documentation

data IntegrityResult Source #

Whether fetched bytes may enter the mirror, with a refusal detail for the operator.

Constructors

IntegrityVerified

The bytes matched the selected digest or one of its SRI alternatives.

IntegrityMismatch Text

The selected digest mismatched or its algorithm cannot be computed.

verifyIntegrity :: NonEmpty Hash -> ByteString -> IntegrityResult Source #

Verify the strongest selected digest, allowing only its same-algorithm SRI alternatives. A weaker match or an uncomputable selected algorithm never permits publication.