readonly

package
v1.261010.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 10, 2026 License: MIT Imports: 8 Imported by: 0

Documentation

Overview

Package readonly implements the global read-only mode that refuses every mutating request before it leaves the process.

Read-only mode is enabled by the ASC_READ_ONLY environment variable or the root --read-only flag. It is enforced at the transport layer of each Apple-facing client (App Store Connect API, App Store Connect web session, Developer Portal, Apple Ads, StoreKit) rather than per command, so a session that sets it cannot write even through commands that were never taught about the mode. Either source only enables the mode; neither can disable the other.

Index

Constants

View Source
const (
	// EnvVar enables read-only mode when set to a truthy value (1/true/yes/on).
	EnvVar = "ASC_READ_ONLY"
	// FlagName is the root flag that enables read-only mode for one invocation.
	FlagName = "read-only"
)

Variables

View Source
var ErrRefused = errors.New("read-only mode refused a mutating request")

ErrRefused is the sentinel matched by errors.Is for every refusal raised by read-only mode.

Functions

func Check

func Check(ctx context.Context, method, target string) error

Check returns a *RefusedError when read-only mode is enabled and the request would mutate remote state. Requests marked with WithReadIntent pass.

func Enabled

func Enabled() bool

Enabled reports whether read-only mode is active from either source.

func HasReadIntent

func HasReadIntent(ctx context.Context) bool

HasReadIntent reports whether ctx was marked by WithReadIntent.

func IsMutatingMethod

func IsMutatingMethod(method string) bool

IsMutatingMethod reports whether an HTTP method can change remote state. An empty method is treated as GET, matching net/http.

func SetFlagEnabled

func SetFlagEnabled(enabled bool)

SetFlagEnabled records whether the root --read-only flag was passed. The root command resets it on every bind so one parse cannot leak into the next.

func Source

func Source() string

Source names the mechanism that enabled read-only mode for diagnostics.

func Target

func Target(rawURL string) string

Target renders a request URL for refusal diagnostics without its query string, so signed upload URLs and filters never reach stderr.

func WithReadIntent

func WithReadIntent(ctx context.Context) context.Context

WithReadIntent marks ctx as carrying a request that only reads data even though it is transported with a mutating method, such as Apple Ads selector queries or Developer Portal proxied GETs. Callers must only mark requests whose server-side effect is a read.

Types

type RefusedError

type RefusedError struct {
	Source string
	Method string
	Target string
}

RefusedError is returned when read-only mode blocks a mutating request.

func (*RefusedError) Error

func (e *RefusedError) Error() string

func (*RefusedError) Is

func (e *RefusedError) Is(target error) bool

Is reports ErrRefused so callers can classify wrapped refusals.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL