Documentation
¶
Overview ¶
Package post is the one POST the alert channels and Claude triage make, as the SDK makes it with fetch (alerts/shared.ts): the URL cleaned and read as fetch reads it, only http and https, headers checked as fetch checks them, one ten second deadline for the whole request, a redirect refused rather than followed, at most 1 MiB of an answer read, and an error that names only the URL's origin, with every secret the caller holds cut out of a quoted answer before it is cut to 200 characters.
Index ¶
- Constants
- Variables
- func Clean(raw string) string
- func Cut(text string, max int) string
- func ErrorBody(text string, secrets ...string) string
- func Headers(list []Header) (http.Header, error)
- func Origin(raw string) string
- func Postable(raw string) (string, error)
- func Refused(provider, rawURL string, resp Response, secrets ...string) error
- func Text(data []byte) string
- type Header
- type Response
- func Do(ctx context.Context, client *http.Client, rawURL string, headers []Header, ...) (Response, error)
- func DoWithin(ctx context.Context, timeout time.Duration, client *http.Client, rawURL string, ...) (Response, error)
- func Post(ctx context.Context, client *http.Client, provider, rawURL string, ...) (Response, error)
Constants ¶
const ErrorBodyMax = 200
ErrorBodyMax is how much of an answer's body goes into an error.
const MaxBody = 1 << 20
MaxBody is how much of an answer is read. A channel quotes 200 characters of a refusal, and a compressed answer from a broken or hostile endpoint could otherwise decode to far more than a process has.
Variables ¶
var ErrTimeout error = timeoutError{}
ErrTimeout is fetch's error for a request past its deadline. It is a context.DeadlineExceeded, so an app telling a channel's timeout from its refusal can ask errors.Is(err, context.DeadlineExceeded).
var Timeout = 10 * time.Second
Timeout is how long one request may take, connecting, sending and reading the answer, as the SDK's AbortSignal.timeout(10_000). A variable only so tests can wait less.
Functions ¶
func Clean ¶
Clean is a URL as the URL parser (and so fetch) reads it: characters U+0000 to U+0020 around it dropped, and every tab, CR and LF inside it removed (a pasted webhook URL often ends in a newline).
func Cut ¶
Cut is at most max UTF-16 code units of text, never half a surrogate pair (shared.ts's cut).
func ErrorBody ¶
ErrorBody is the start of an error body: every secret of four or more characters cut out of a prefix long enough to hold one that starts inside the first ErrorBodyMax characters, and only then cut to that length, so no part of a secret survives at the edge.
func Headers ¶
Headers are the headers as a request sends them: each name an HTTP token, each value without the spaces, tabs and line breaks around it, as fetch sends it. A name that is not a token, or a value with a line break or NUL inside, is refused, as fetch refuses them, so no header can add another; the error names the header, never its value, which may be a credential. Two headers whose names differ only in case are both sent, as fetch appends them.
func Origin ¶
Origin is new URL(url).origin: the scheme, host and port only, a port that is the scheme's own left out. A URL's path or query can hold a credential, so an error names only this.
func Postable ¶
Postable is the URL, cleaned, once it is one a channel can post to: http or https with a host. Refused without quoting it, since a webhook URL's path is its credential: "not ftp:" for another scheme with a host, "not this URL" for anything else (no scheme, no host, a space or control character left inside it, or a user name and password, which fetch refuses to send).
Types ¶
type Header ¶
type Header struct{ Name, Value string }
Header is one request header. The channels keep them in the SDK's order.
type Response ¶
Response is an answer: its status and as much of its body as was read, as response.text() reads it (UTF-8, U+FFFD for bytes that are not, no byte order mark). A body the deadline cut short is "".
func Do ¶
func Do(ctx context.Context, client *http.Client, rawURL string, headers []Header, body string) (Response, error)
Do posts body to rawURL through client (nil for the default: Go's default transport, which verifies TLS) and returns the answer, whatever its status. The client is used as a copy that never follows a redirect. An error is a request that could not be made or had no answer: the URL refused (Postable), a header refused (Headers), ErrTimeout past the deadline, the caller's context ending, or the transport's own error, which names no more of the URL than its origin.
func DoWithin ¶
func DoWithin(ctx context.Context, timeout time.Duration, client *http.Client, rawURL string, headers []Header, body string) (Response, error)
DoWithin is Do with a deadline of its own in place of Timeout.