scopedhttps

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package scopedhttps constructs HTTPS clients confined to explicitly approved private-network endpoints.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func NewClient

func NewClient(ctx context.Context, endpointCAs map[string][]byte) (*http.Client, error)

NewClient constructs an HTTPS-only client restricted to endpoints, one scoped connection-pool lifecycle for every endpoint in endpointCAs. Each endpoint must resolve to a private address at construction and at every dial. endpointCAs maps each approved HTTPS endpoint URL to the exact CA PEM bundle trusted for THAT endpoint's own host:port authority -- never a shared/unioned pool, and never merged with a DIFFERENT authority that happens to share a hostname on another port. Two endpoints on different authorities, each supplying its own CA, are kept isolated: a certificate presented for authority B is verified ONLY against B's own pool, never against A's, so a compromised or overly permissive CA configured for one endpoint can never authenticate a connection to another.

func NewSingleIssuerClient

func NewSingleIssuerClient(ctx context.Context, endpoints []string, trustedCAPEM []byte) (*http.Client, error)

NewSingleIssuerClient is NewClient's convenience form for the common case of one issuer's own endpoints (e.g. its discovery document and JWKS URI) all trusting the SAME CA bundle.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL