1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
//! The guarded outbound transport this crate receives from its composing
//! process.
//!
//! Every trusted-side fetch in [`crate::proxy`] — the paid `paid_fetch` path
//! and the non-paying `web_fetch` path — rides a transport that validates the
//! destination and pins the connection to the address that validation
//! resolved. This crate builds no such transport. It names the shape it needs
//! here and takes an implementation from the process that composes it, so the
//! destination policy, the DNS pin, and the redirect and timeout guards all
//! belong to one composition root instead of to this component.
//!
//! This seam covers the FETCH of the merchant URL, and nothing else. The
//! chain transports are separate, and this crate does not receive those.
//! `PaymentsConfig::resolve_client` (reached from [`crate::proxy::fulfill`])
//! resolves a settlement client per call from the caller's own delegated key,
//! and `PaymentsConfig::resolve_keychain_status` opens a one-shot RPC read.
//! Both build their own transport inside `polyc-payments-client`.
//! `arch-capabilities.toml`'s standing allowance SA-01 records exactly that,
//! against PRV-25 — see docs/decisions/0026-payments-settlement-client-standing-allowance.md.
//!
//! Reading the body is separate: `polyc_capped_body::read_capped_text` caps
//! it, and needs no transport.
//!
//! `polyc-control-plane` implements this over the shared guarded egress
//! client. A test binary composes its own implementation the same way.
use Duration;
/// Why the guarded transport produced no client for a destination.
/// The guarded outbound HTTP transport a proxied fetch rides.
///
/// One implementation serves both fetch paths. The paid path takes the
/// transport's own default request budget; the non-paying path asks for a
/// shorter one. Neither path chooses the destination policy, the redirect
/// behavior, or the connect timeout — those belong to the implementation.
/// `Debug` is required so a composing struct that holds one can still derive
/// it; an implementation prints its own destination policy, never a URL.