httpclient

package
v0.8.4 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: Apache-2.0 Imports: 9 Imported by: 0

Documentation

Overview

Package httpclient is the outbound HTTP wrapper that forwards the correlation ID from request context as X-Correlation-Id on every call.

All outbound HTTP MUST go through this package's Client. The forbidigo lint rule rejects raw uses of http.DefaultClient and http.NewRequest + stdlib http.Client.Do in foundation/business code.

Spec: specs/system/correlation.spec.yaml AC-14, AC-15, AC-16.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func BlockedHost

func BlockedHost(host string) bool

BlockedHost rejects targets that are non-public by name — literal IPs and obvious loopback names — before DNS resolution. The dial-time GuardedDialControl re-checks the resolved IP (defeats DNS rebinding).

func BlockedIP

func BlockedIP(ip net.IP) bool

BlockedIP reports whether ip is in a range that outbound requests to operator- or IdP-supplied URLs must not reach (SSRF). Covers loopback, RFC1918 private, RFC6598 CGNAT, link-local (including the 169.254.169.254 cloud-metadata endpoint), and the unspecified address. IPv4-mapped IPv6 forms are unwrapped before checking. A nil/unparseable ip is blocked (fail closed).

func GuardedDialControl

func GuardedDialControl(_, address string, _ syscall.RawConn) error

GuardedDialControl runs after DNS resolution with the concrete dial address and blocks the connection if the resolved IP is non-public. Wire it into a net.Dialer.Control so a hostname that resolves (or rebinds) to internal space cannot be reached.

func NewGuardedHTTPClient

func NewGuardedHTTPClient(timeout time.Duration) *http.Client

NewGuardedHTTPClient returns a *http.Client that refuses to dial non-public addresses (SSRF guard) and pins TLS >= 1.2. Use for outbound calls to operator- or IdP-supplied URLs (webhooks, OIDC discovery/JWKS).

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client wraps net/http.Client with correlation forwarding. Use NewClient to construct one; the zero value is usable but lacks sensible timeouts.

func NewClient

func NewClient() *Client

NewClient returns a Client with conservative defaults: 30-second total timeout, transport pooling enabled. Callers requiring different timeouts construct directly via WithInner.

func NewGuardedClient

func NewGuardedClient(timeout time.Duration) *Client

NewGuardedClient wraps NewGuardedHTTPClient in the correlation-forwarding Client. Use for outbound calls to untrusted URLs that should still carry the correlation ID (the OIDC flow).

func WithInner

func WithInner(inner *http.Client) *Client

WithInner wraps a caller-supplied http.Client. Useful for tests, custom transports (TLS configs), or short-timeout health checks.

func (*Client) Do

func (c *Client) Do(req *http.Request) (*http.Response, error)

Do sends the request, forwarding the correlation ID from req.Context() as X-Correlation-Id. If the caller has already set the header (e.g., they explicitly want a different value), Do leaves it alone.

func (*Client) Get

func (c *Client) Get(ctx context.Context, url string) (*http.Response, error)

Get is a convenience matching http.Client.Get's contract. Builds a GET request from ctx + url and forwards through Do.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL