Documentation
¶
Overview ¶
Package localio owns safe local artifact publication shared by product shortcuts. Remote names and URLs are always treated as untrusted input.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ResolveOutputPath ¶
func SafeFilename ¶
SafeFilename selects a portable basename from a preferred server name or URL.
func ValidateDownloadURL ¶
ValidateDownloadURL accepts only public DingTalk and Aliyun OSS HTTPS hosts.
func ValidateOutput ¶
ValidateOutput rejects absolute paths and portable `..` escapes.
Types ¶
type DownloadOptions ¶
type DownloadOptions struct {
BaseDir string
Output string
PreferredName string
Headers map[string]string
}
DownloadOptions controls safe, atomic publication beneath BaseDir.
type DownloadResult ¶
DownloadResult describes the published local artifact.
func Download ¶
func Download(ctx context.Context, rawURL string, opts DownloadOptions) (DownloadResult, error)
Download validates a platform-owned HTTPS URL, resolves a workspace-relative output path without following symlink escapes, streams into a sibling temp file, fsyncs it, and atomically publishes the completed file.