Skip to main content

Module validate

Module validate 

Source
Expand description

Challenge validation as queued work.

POST /chall/{id} claims a challenge and enqueues one of these rows; the job runner performs the outbound check. Validation reaches out to an address the client named — over DNS, HTTP or TLS, to a host that may simply not answer — so running it inside the request held an admission permit for the length of challenge.timeout_ms and coupled that budget to server.request_timeout_ms. RFC 8555 §7.1.6 already has the state this needs: a challenge “transitions to the processing state when the client responds to the challenge”, and §8.2 pairs that with a Retry-After.

One handler over every profile, the SignerRevokeJob shape: a row names its challenge, the challenge walks up to its order, and the order names the profile whose validators and notifier decide it. The registry refuses a second handler for one kind, so one per profile could not be registered anyway.

Structs§

ChallengeValidateJob
Performs a claimed challenge validation and records its answer.

Constants§

CHALLENGE_VALIDATE_KIND
The jobs.kind one challenge validation is queued under.

Functions§

challenge_validate_spec
The row asking a worker to validate the challenge claim_challenge just claimed.