module Ecluse.Core.Security.Egress (
RegistryUrl,
mkRegistryUrl,
mkConfiguredRegistryUrl,
registryUrlText,
resolveTarballUrl,
) where
import Data.Text qualified as T
import Ecluse.Core.Security (authorityLabel, hostAddress)
import Ecluse.Core.Security.Egress.Internal (RegistryUrl, mkConfiguredRegistryUrl, mkRegistryUrl, registryUrlText)
import Ecluse.Core.Text (httpPrefix, httpsPrefix, isPrefixOfLowered, lowerPrefixChars)
resolveTarballUrl :: Text -> Text -> Either Text RegistryUrl
resolveTarballUrl :: Text -> Text -> Either Text RegistryUrl
resolveTarballUrl Text
upstreamHost Text
url
| LowerPrefix -> Text -> Bool
isPrefixOfLowered LowerPrefix
httpsPrefix Text
url = Text -> Either Text RegistryUrl
mkRegistryUrl Text
url
| LowerPrefix -> Text -> Bool
isPrefixOfLowered LowerPrefix
httpPrefix Text
url =
if Text -> Text
hostAddress Text
url Text -> Text -> Bool
forall a. Eq a => a -> a -> Bool
== Text
upstreamHost
then Text -> Either Text RegistryUrl
mkRegistryUrl (Text
"https://" Text -> Text -> Text
forall a. Semigroup a => a -> a -> a
<> Int -> Text -> Text
T.drop (LowerPrefix -> Int
lowerPrefixChars LowerPrefix
httpPrefix) Text
url)
else Text -> Either Text RegistryUrl
forall a b. a -> Either a b
Left (Text
"dist.tarball is http on a host other than the upstream registry: " Text -> Text -> Text
forall a. Semigroup a => a -> a -> a
<> Text -> Text
authorityLabel Text
url)
| Bool
otherwise = Text -> Either Text RegistryUrl
forall a b. a -> Either a b
Left (Text
"dist.tarball is not an https URL: " Text -> Text -> Text
forall a. Semigroup a => a -> a -> a
<> Text -> Text
authorityLabel Text
url)