earlydata

package
v0.0.26 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: MIT Imports: 2 Imported by: 0

README

Early Data Middleware

What it does

Detects and controls TLS 0-RTT early data requests to prevent replay-sensitive operations from being executed unsafely.

How to implement

package main

import (
	"github.com/oarkflow/fh"
	"github.com/oarkflow/fh/mw/earlydata"
)

func main() {
	app := fh.New()
	app.Use(earlydata.New(earlydata.Config{}))

	app.Get("/", func(c fh.Ctx) error {
		return c.Status(fh.StatusOK).SendString("ok")
	})
}

Impact

Protects unsafe operations from replay risks. May reject requests marked as early data.

Ordering guidance

Run before handlers for unsafe methods and before idempotency-sensitive operations.

Production considerations

Only allow early data for safe, idempotent operations. Document behavior behind TLS terminators/CDNs.

Documentation

Overview

Package earlydata protects non-idempotent requests replayed as TLS early data.

Index

Constants

This section is empty.

Variables

View Source
var DefaultConfig = Config{
	AllowMethods:            []string{"GET", "HEAD", "OPTIONS", "TRACE"},
	AllowWithIdempotencyKey: false,
	IdempotencyHeader:       "Idempotency-Key",
}

Functions

func New

func New(config ...Config) fh.HandlerFunc

Types

type Config

type Config struct {
	AllowMethods            []string
	AllowWithIdempotencyKey bool
	IdempotencyHeader       string
	Next                    func(fh.Ctx) bool
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL