hubaddress

package
v0.175.6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: Apache-2.0 Imports: 4 Imported by: 0

Documentation

Overview

Package hubaddress holds the one rule for an address a machine credential is sent to, and the proxy policy of a client that sends one. It is a leaf package so that both internal/remotestate (remote.url) and internal/sessionmove (session_move.targets.<machine>.http.url) apply the same rule; internal/remotestate imports internal/sessionmove through internal/worktrees, so the rule cannot live in either of them.

Index

Constants

This section is empty.

Variables

Proxy is the proxy policy of a client that sends a machine credential.

Functions

func IsLoopbackHost

func IsLoopbackHost(host string) bool

IsLoopbackHost reports whether host is exactly "localhost" or a loopback IP address. The name is matched in lower case only (callers lower-case first): Go's own exemption of loopback hosts from proxying is case-sensitive, so an address is always used in lower case (Origin) and never proxied (ProxyFrom).

func Origin

func Origin(raw string) string

Origin is raw as the origin a request is built on: trimmed, with the scheme and host in lower case and no trailing slash. It is meant for an address that passed Valid.

func ProxyFrom

func ProxyFrom(environment func(*http.Request) (*url.URL, error)) func(*http.Request) (*url.URL, error)

ProxyFrom is the policy over environment, the function that says which proxy the environment names for a request. A request that is not https, or that is for a loopback host, is never proxied: an http request through a proxy is sent to it whole, Authorization header included. An https request follows the environment, because it passes through a proxy as a CONNECT tunnel that does not see the header.

func Valid

func Valid(raw string) bool

Valid reports whether raw is an origin a bearer credential may be sent to: an https origin, or an http origin only on a loopback host, with no user information, no query (not even an empty one), no fragment and no path beyond an optional single "/". There is no base path: the routes a credential is sent to are fixed paths on the origin.

Plain http is refused except on a loopback host because the credential travels in the Authorization header of every request, and a loopback origin is the one case with no network to intercept it. Even there the credential goes to whatever process listens on that local port (a tunnel's local end included), so https is the better choice wherever it is available.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL