Skip to main content

PushSender

Struct PushSender 

Source
pub struct PushSender { /* private fields */ }
Expand description

Delivers notifications, under the controls in the module docs.

Implementations§

Source§

impl PushSender

Source

pub const DEFAULT_TIMEOUT: Duration

The spec recommends 10–30 seconds; a webhook that needs longer is doing work it should not be doing on our thread.

Source

pub fn new(policy: PushPolicy) -> Self

Source

pub fn for_operator_destinations(destinations: &[Destination]) -> Self

A sender for destinations the deployment configured.

Takes no PushPolicy, because a host allowlist answers may this caller name this host? and there is no caller: the URL comes from the deployment’s own configuration, written by whoever would have written the allowlist. HTTPS and the public-address check are lifted for the same reason — an in-cluster collector on plaintext HTTP at a private address is the ordinary shape here, and it is the only shape the inward-facing case has.

This is not an off switch for push. It cannot deliver to a caller-registered webhook at all: Outbox owns the rows this serves, the A2A worker owns the others, and the two id namespaces do not overlap.

§Why it takes the destinations

For the signing keys of whichever of them called Destination::signed_with, which live here and not in the stored registration: a caller’s bearer token has to be persisted because the request that carried it is over, while an operator’s signing key is this deployment’s own configuration, read at every start — persisting it would put a forge-anything key in a row per run per destination and freeze rotation at admission. Taking them as an argument rather than offering a .signing(..) setter is the difference between a control you can forget and one you cannot: a destination configured to be signed whose sender was built without it would deliver unsigned, and nothing downstream could notice, because a receiver’s own refusal is the only place a missing signature shows up. Pass Outbox::destinations, which is the list that was actually registered.

Source

pub const fn allow_plaintext_loopback(self) -> Self

Permit http:// to a webhook on this machine. testkit only.

The A2A conformance kit’s webhook receiver is an http://localhost:PORT server, because a kit cannot mint a public TLS endpoint for a run on a laptop. Both of this crate’s address controls refuse that, correctly — and the consequence was that the kit’s ten push MUSTs could not run at all, so the one surface where an untrusted party names an address this plane connects to had no outside-authority evidence behind it. Ten unrunnable rows is a worse answer than one named exception.

What this does not lift is the part that is the actual control: the operator’s host grant still has to name the host, the task-level authorization still runs, the cursor still advances only on 2xx, and every non-loopback destination is judged exactly as before — a plaintext URL to a public host stays refused with the flag set, which is the half that keeps this from being an off switch.

It cannot exist in a production build: the field is cfg(testkit), and testkit is documented as never belonging in one.

Source

pub const fn timeout(self, d: Duration) -> Self

Source

pub const fn policy(&self) -> &PushPolicy

The grant this sender enforces, so a registration can be checked against the same policy that will later be checked at delivery.

Trait Implementations§

Source§

impl Clone for PushSender

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for PushSender

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl PushTransport for PushSender

Source§

fn validate(&self, config: &PushConfig) -> Result<(), PushError>

Source§

fn deliver<'life0, 'life1, 'life2, 'async_trait>( &'life0 self, config: &'life1 PushConfig, message: &'life2 PushMessage, at: u64, ) -> Pin<Box<dyn Future<Output = Result<Delivered, PushError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait,

POST one message. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<Unshared, Shared> IntoShared<Shared> for Unshared
where Shared: FromUnshared<Unshared>,

Source§

fn into_shared(self) -> Shared

Creates a shared type from an unshared type.
Source§

impl<T> MaybeSend for T
where T: Send,

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more