Documentation
¶
Overview ¶
Package localio owns safe local artifact publication shared by product shortcuts. Remote names and URLs are always treated as untrusted input.
Index ¶
- func ReadTextInput(spec string, stdin io.Reader, maxBytes int64) (string, error)
- func ResolveOutputPath(baseDir, output, rawURL, preferredName string) (string, string, error)
- func SafeFilename(preferredName, rawURL string) string
- func SecureHTTPClient() *http.Client
- func SetSecureDownloadDialTargetForTest(fixtureAddr string)
- func ValidateDownloadURL(rawURL string) (*url.URL, error)
- func ValidateOutput(output string) error
- type DownloadOptions
- type DownloadResult
- type PublishBytesOptions
- type UploadResult
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ReadTextInput ¶ added in v1.0.58
ReadTextInput resolves a literal, "-" stdin, or @workspace-relative file. File symlinks must resolve inside the current working directory and all input forms are bounded to prevent accidental unbounded memory use.
func ResolveOutputPath ¶
func SafeFilename ¶
SafeFilename selects a portable basename from a preferred server name or URL.
func SecureHTTPClient ¶ added in v1.0.60
SecureHTTPClient returns a download client enforcing the same URL policy and redirect hygiene as Download. Product shortcuts that own their local-file workflow (e.g. chat message resources) share it so download URL trust decisions stay in one place.
func SetSecureDownloadDialTargetForTest ¶ added in v1.0.60
func SetSecureDownloadDialTargetForTest(fixtureAddr string)
SetSecureDownloadDialTargetForTest reroutes every secure download dial to fixtureAddr. Subprocess e2e tests use it to serve platform download hosts from a loopback TLS fixture: TLS SNI and certificate verification still run against the real host name, and the production client keeps Proxy disabled. Production code must not call this.
func ValidateDownloadURL ¶
ValidateDownloadURL accepts HTTPS download URLs on any host and port, IP literals included — mirroring the official GUI client, which applies no client-side SSRF interception to downloads. Only userinfo URLs stay rejected; TLS hostname verification in secureHTTPClient pins the connection to the requested host and redirects are re-validated per hop.
func ValidateOutput ¶
ValidateOutput rejects absolute paths and portable `..` escapes.
Types ¶
type DownloadOptions ¶
type DownloadOptions struct {
ExpectedSize *int64 // When supplied, validate downloaded bytes before publication.
Overwrite bool // Explicit opt-in; defaults retain no-clobber semantics.
BaseDir string
Output string
PreferredName string
Headers map[string]string
}
DownloadOptions controls safe, atomic publication beneath BaseDir.
type DownloadResult ¶
type DownloadResult struct {
SHA256 string // Hash of successfully downloaded bytes; empty for local publication.
AbsolutePath string
RelativePath string
SizeBytes int64
}
DownloadResult describes the published local artifact.
func Download ¶
func Download(ctx context.Context, rawURL string, opts DownloadOptions) (DownloadResult, error)
Download validates a platform-owned HTTPS URL, resolves a workspace-relative output path without following symlink escapes, streams into a sibling temp file, fsyncs it, and atomically publishes the completed file.
func PublishBytes ¶ added in v1.0.58
func PublishBytes(payload []byte, opts PublishBytesOptions) (DownloadResult, error)
PublishBytes writes an in-memory artifact through the same symlink-safe, fsync and atomic no-clobber path used by remote downloads.
type PublishBytesOptions ¶ added in v1.0.58
type PublishBytesOptions struct {
BaseDir string
Output string
PreferredName string
MaxBytes int64
}
PublishBytesOptions controls safe no-clobber publication beneath BaseDir.
type UploadResult ¶ added in v1.0.58
UploadResult records only non-sensitive transfer facts. The signed URL is deliberately never returned.
func PutFile ¶ added in v1.0.58
PutFile uploads a regular local file to an exact trusted pre-signed HTTPS endpoint. Redirects are rejected so file bytes and credentials cannot move to a second origin. Transient failures reuse the same verified open file so a path replacement cannot change the bytes sent by a later attempt.