Documentation
¶
Overview ¶
Package httpserver provides the shared Gin HTTP surface used by Candace services. Applications register routes; this package owns the behavior that must remain identical across service binaries.
Index ¶
- Constants
- func EncodeEvent[Data any](writer io.Writer, identifier string, data Data) error
- func EventStream(context *gin.Context, step func(writer io.Writer) bool)
- func EventStreamHeaders() gin.HandlerFunc
- func NewEngine(service string, options ...EngineOption) *gin.Engine
- func NewStreamingServer(address string, handler http.Handler) *http.Server
- func Probe(ctx context.Context, target string) error
- func Recovery(service string) gin.HandlerFunc
- func RequestLogger(service string) gin.HandlerFunc
- func Serve(ctx context.Context, server *http.Server) error
- func StrictBrowserSecurity() gin.HandlerFunc
- func ValidateOpenAPIRequests(document *openapi3.T, options openapi3filter.Options, ...) (gin.HandlerFunc, error)
- type EngineOption
Constants ¶
const BrowserContentSecurityPolicy = "default-src 'none'; " +
"script-src 'self'; " +
"style-src 'self'; " +
"connect-src 'self'; " +
"img-src 'self' data:; " +
"object-src 'none'; " +
"base-uri 'none'; " +
"form-action 'none'; " +
"frame-ancestors 'none'"
BrowserContentSecurityPolicy permits only the same-origin assets and socket needed by a server-rendered Candace page.
Variables ¶
This section is empty.
Functions ¶
func EncodeEvent ¶
EncodeEvent writes one server-sent-event frame. It is gin-contrib/sse's encoder, named here so a streaming handler depends on this package alone. Data is a type parameter rather than any so the caller's frame type is carried to this boundary and erased exactly once, where the third-party encoder's own interface{} field demands it (CS-7).
func EventStream ¶
EventStream writes the server-sent-event headers and then runs step until it returns false or the client hangs up. gin's Stream owns the flush-per-step and client-gone loop; step writes frames, for which EncodeEvent is the encoder.
func EventStreamHeaders ¶
func EventStreamHeaders() gin.HandlerFunc
EventStreamHeaders is the middleware form: mount it on a route group and every response in that group is a server-sent-event stream. Handlers that stream from inside a generated wrapper use EventStream instead.
func NewEngine ¶
func NewEngine(service string, options ...EngineOption) *gin.Engine
NewEngine returns a quiet production Gin engine with explicit 404/405 behavior and panic recovery through core.Logger.
func NewStreamingServer ¶
NewStreamingServer returns the canonical server shape for long-lived SSE or WebSocket responses. It deliberately leaves ReadTimeout and WriteTimeout unset; ReadHeaderTimeout still bounds the unauthenticated request phase.
func Recovery ¶
func Recovery(service string) gin.HandlerFunc
Recovery converts a panic into a 500 response and records it with the shared logger. It deliberately does not include Gin's default text logger.
func RequestLogger ¶
func RequestLogger(service string) gin.HandlerFunc
RequestLogger assigns or preserves a request ID and emits one structured log event after the request completes.
func Serve ¶
Serve runs server until it fails or ctx is canceled, then performs a bounded graceful shutdown and waits for the listener goroutine to exit.
func StrictBrowserSecurity ¶
func StrictBrowserSecurity() gin.HandlerFunc
StrictBrowserSecurity applies the shared browser-facing response policy.
func ValidateOpenAPIRequests ¶
func ValidateOpenAPIRequests(document *openapi3.T, options openapi3filter.Options, onError func(context *gin.Context, message string, statusCode int)) (gin.HandlerFunc, error)
ValidateOpenAPIRequests adapts kin-openapi validation to a caller-owned Gin router. Callers own authentication options and the validation error response. The returned middleware must be scoped to routes declared in the contract.
Types ¶
type EngineOption ¶
type EngineOption func(config *engineConfig)
EngineOption enables optional shared middleware.
func WithRequestLogging ¶
func WithRequestLogging() EngineOption
WithRequestLogging adds structured completion logs and request IDs.
func WithStrictBrowserSecurity ¶
func WithStrictBrowserSecurity() EngineOption
WithStrictBrowserSecurity applies the shared locked-down browser policy.