Documentation
¶
Overview ¶
Package webhooks provides bounded, engine-scoped HTTP webhook ingress. It routes exact request bytes to an engine-owned verifier and acceptor but deliberately does not parse, persist, deduplicate, or enqueue deliveries.
Index ¶
Constants ¶
const ( DefaultMaxBodyBytes int64 = 256 * 1024 DefaultHandlerTimeout = 5 * time.Second DefaultMaxConcurrentBodyReads = 64 MaxResponseBodyBytes = 64 * 1024 )
const ( OutcomeAccepted = "accepted" OutcomeRejected = "rejected" OutcomeFailed = "failed" )
Variables ¶
Functions ¶
Types ¶
type AcceptFunc ¶
AcceptFunc captures the verified, engine-owned source identity and performs durable acceptance. A verifier must return it only after authenticating the exact request bytes.
type AdmitFunc ¶
AdmitFunc performs a cheap check before Soro reads the request body. It may reject abusive traffic but cannot authenticate a delivery; Verify still owns provider authentication over the exact body bytes.
type Definition ¶
type Definition struct {
Name string
Path string
ContentTypes []string
MaxBodyBytes int64
Timeout time.Duration
Admit AdmitFunc
Verify VerifyFunc
}
Definition declares one POST endpoint relative to an engine's API mount. Zero limits use the package defaults.
type Metadata ¶
type Metadata struct {
Method string
URL *url.URL
Host string
Header http.Header
PathValues map[string]string
RemoteAddr string
ReceivedAt time.Time
}
Metadata is the detached request metadata available before Soro reads the body. It is suitable for cheap per-address or per-path admission checks. Path values are routing hints only and must not be trusted as source identity.
type Observation ¶
type Observer ¶
type Observer func(context.Context, Observation)
type Registry ¶
type Registry struct {
// contains filtered or unexported fields
}
Registry owns webhook routes installed on a host HTTP mux.
type Request ¶
type Request struct {
Method string
URL *url.URL
Host string
Header http.Header
Body []byte
PathValues map[string]string
RemoteAddr string
ReceivedAt time.Time
}
Request is the detached transport evidence supplied to an engine. Body is the exact bounded byte sequence read from the HTTP request; Soro does not decompress or parse it before verification.
type Scope ¶
type Scope struct {
// contains filtered or unexported fields
}
func (*Scope) Register ¶
func (scope *Scope) Register(definition Definition) error
type VerifyFunc ¶
type VerifyFunc func(context.Context, Request) (AcceptFunc, error)
VerifyFunc authenticates a request and returns the only function allowed to accept it. This keeps provider-specific identities and secrets inside the owning engine without an untyped shared claims container.