Skip to main content

HttpEgressContract

Struct HttpEgressContract 

Source
pub struct HttpEgressContract {
    pub tenant_egress_namespace: String,
    pub allowed_schemes: BTreeSet<String>,
    pub allowed_authority_set: BTreeSet<String>,
    pub deny_loopback: bool,
    pub deny_link_local: bool,
    pub deny_ipv6_ula: bool,
    pub max_redirect_chain: u8,
    pub max_response_bytes: u64,
}
Expand description

Typed egress policy that must be declared before substrate HTTP egress.

Fields§

§tenant_egress_namespace: String

Tenant-scoped namespace used by callers to bind egress receipts and deployment policy to one authority domain.

§allowed_schemes: BTreeSet<String>

Lowercase HTTP URL schemes allowed by this contract: http or https.

§allowed_authority_set: BTreeSet<String>

Exact normalized URL authorities allowed by this contract.

Domain authorities are lowercase. IPv6 authorities use brackets, for example [2001:db8::10]:443.

§deny_loopback: bool

Reject loopback address literals and localhost names even if an authority entry was configured.

§deny_link_local: bool

Reject IPv4 and IPv6 link-local address literals.

§deny_ipv6_ula: bool

Reject IPv6 unique-local address literals.

§max_redirect_chain: u8

Maximum redirect hop count accepted for a request chain.

§max_response_bytes: u64

Maximum response bytes accepted before the substrate must abort.

Implementations§

Source§

impl HttpEgressContract

Source

pub fn enforce_required( contract: Option<&HttpEgressContract>, target_url: &str, redirect_chain_len: u8, observed_response_bytes: Option<u64>, ) -> Result<ValidatedHttpEgressTarget, HttpEgressError>

Enforce a required contract. None is a fail-closed denial.

Source

pub fn enforce_attempt( &self, target_url: &str, redirect_chain_len: u8, observed_response_bytes: Option<u64>, ) -> Result<ValidatedHttpEgressTarget, HttpEgressError>

Enforce target, redirect, and optional response-size bounds.

Source

pub fn enforce_url( &self, target_url: &str, redirect_chain_len: u8, ) -> Result<ValidatedHttpEgressTarget, HttpEgressError>

Enforce target URL and redirect hop constraints.

Source

pub fn enforce_url_with_dns( &self, target_url: &str, redirect_chain_len: u8, ) -> Result<ValidatedHttpEgressTarget, HttpEgressError>

Enforce target URL, redirect hop constraints, and DNS safety.

Literal IPs and localhost names are enforced directly. Domain names are resolved here and every resolved IP is checked against the address-class policy before the caller opens a socket.

Source

pub fn enforce_response_bytes( &self, observed: u64, ) -> Result<(), HttpEgressError>

Enforce the response-byte ceiling after headers or streaming counters expose the observed size.

Source

pub fn validate(&self) -> Result<(), HttpEgressError>

Validate the contract shape before use.

Source

pub fn prepare(&self) -> Result<PreparedHttpEgressContract, HttpEgressError>

Validate this raw contract and return an immutable enforcement handle.

Source

pub fn validate_dispatchable_with_pinned_dns( &self, ) -> Result<(), HttpEgressError>

Validate that this contract can be used by the reqwest-backed dispatcher whose resolver enforces address-class policy at connect time.

Source

pub fn enforce_resolved_ip( &self, host: &str, address: IpAddr, ) -> Result<(), HttpEgressError>

Enforce address-class denials after a domain has resolved to an IP.

Source§

impl HttpEgressContract

Source

pub fn permissive_for_tests(authority: &str) -> HttpEgressContract

Construct a permissive contract suitable for tests that exercise a wiremock or other local loopback HTTP server. Production code MUST NOT use this; production always builds a contract from tenant-scoped substrate config.

Loopback, link-local and IPv6 ULA denials are disabled so wiremock’s 127.0.0.1:<port> URL is accepted. Authority allow-list is wildcard per allowed_authority_set semantics: caller supplies the wiremock authority. Schemes default to http and https.

Trait Implementations§

Source§

impl Clone for HttpEgressContract

Source§

fn clone(&self) -> HttpEgressContract

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for HttpEgressContract

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result<(), Error>

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for HttpEgressContract

Source§

fn deserialize<__D>( __deserializer: __D, ) -> Result<HttpEgressContract, <__D as Deserializer<'de>>::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Eq for HttpEgressContract

Source§

impl PartialEq for HttpEgressContract

Source§

fn eq(&self, other: &HttpEgressContract) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl Serialize for HttpEgressContract

Source§

fn serialize<__S>( &self, __serializer: __S, ) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more
Source§

impl StructuralPartialEq for HttpEgressContract

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more