remote

package
v0.5.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: MIT Imports: 10 Imported by: 0

Documentation

Index

Constants

View Source
const (
	DefaultMaxRedirects     = 5
	DefaultMaxResponseBytes = 10 << 20
	DefaultRequestTimeout   = 30 * time.Second
	DefaultDialTimeout      = 5 * time.Second
	DefaultTLSHandshake     = 5 * time.Second
	DefaultResponseHeader   = 10 * time.Second
	DefaultIdleConnTimeout  = 30 * time.Second
	DefaultExpectContinue   = time.Second
)

Variables

View Source
var (
	ErrHTTPSRequired     = errors.New("only HTTPS URLs are allowed")
	ErrUnsafeDestination = errors.New("destination address is not public")
	ErrTooManyRedirects  = errors.New("redirect limit exceeded")
	ErrResponseTooLarge  = errors.New("response body exceeds configured limit")
)

Functions

func IsAllowedAddress

func IsAllowedAddress(address netip.Addr) bool

IsAllowedAddress reports whether an address is suitable for a remote HTTPS asset.

func NewClient

func NewClient(config Config) (*http.Client, error)

NewClient is a convenience constructor for NewPolicy(config).Client().

Types

type Config

type Config struct {
	MaxRedirects          int
	MaxResponseBytes      int64
	RequestTimeout        time.Duration
	DialTimeout           time.Duration
	TLSHandshakeTimeout   time.Duration
	ResponseHeaderTimeout time.Duration
	IdleConnTimeout       time.Duration
	ExpectContinueTimeout time.Duration
	Resolver              Resolver
	DialContext           DialContextFunc
}

Config controls outbound HTTPS policy limits. Zero values select secure defaults.

type DialContextFunc

type DialContextFunc func(ctx context.Context, network, address string) (net.Conn, error)

DialContextFunc is compatible with net.Dialer.DialContext.

type Policy

type Policy struct {
	// contains filtered or unexported fields
}

Policy validates remote asset requests and owns its security-configured transport.

func NewPolicy

func NewPolicy(config Config) (*Policy, error)

NewPolicy builds a credentialless HTTPS client policy with DNS-aware destination checks.

func (*Policy) Client

func (p *Policy) Client() *http.Client

Client returns an HTTP client using this policy. The underlying transport is safe for concurrent use.

func (*Policy) CloseIdleConnections

func (p *Policy) CloseIdleConnections()

CloseIdleConnections closes connections retained by this policy's transport.

func (*Policy) ValidateURL

func (p *Policy) ValidateURL(ctx context.Context, target *url.URL) error

ValidateURL resolves and validates an HTTPS URL without sending a request.

type Resolver

type Resolver interface {
	LookupNetIP(ctx context.Context, network, host string) ([]netip.Addr, error)
}

Resolver is the DNS operation required by Policy.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL