Documentation
¶
Overview ¶
Package hubaddress holds the one rule for an address a machine credential is sent to, and the proxy policy of a client that sends one. It is a leaf package so that both internal/remotestate (remote.url) and internal/sessionmove (session_move.targets.<machine>.http.url) apply the same rule; internal/remotestate imports internal/sessionmove through internal/worktrees, so the rule cannot live in either of them.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var Proxy = ProxyFrom(http.ProxyFromEnvironment)
Proxy is the proxy policy of a client that sends a machine credential.
Functions ¶
func IsLoopbackHost ¶
IsLoopbackHost reports whether host is exactly "localhost" or a loopback IP address. The name is matched in lower case only (callers lower-case first): Go's own exemption of loopback hosts from proxying is case-sensitive, so an address is always used in lower case (Origin) and never proxied (ProxyFrom).
func Origin ¶
Origin is raw as the origin a request is built on: trimmed, with the scheme and host in lower case and no trailing slash. It is meant for an address that passed Valid.
func ProxyFrom ¶
func ProxyFrom(environment func(*http.Request) (*url.URL, error)) func(*http.Request) (*url.URL, error)
ProxyFrom is the policy over environment, the function that says which proxy the environment names for a request. A request that is not https, or that is for a loopback host, is never proxied: an http request through a proxy is sent to it whole, Authorization header included. An https request follows the environment, because it passes through a proxy as a CONNECT tunnel that does not see the header.
func Valid ¶
Valid reports whether raw is an origin a bearer credential may be sent to: an https origin, or an http origin only on a loopback host, with no user information, no query (not even an empty one), no fragment and no path beyond an optional single "/". There is no base path: the routes a credential is sent to are fixed paths on the origin.
Plain http is refused except on a loopback host because the credential travels in the Authorization header of every request, and a loopback origin is the one case with no network to intercept it. Even there the credential goes to whatever process listens on that local port (a tunnel's local end included), so https is the better choice wherever it is available.
Types ¶
This section is empty.