Skip to main content

Module http_objects

Module http_objects 

Source
Expand description

Runtime-agnostic HTTP object serving (SPEC-HTTP-OBJECTS; WP-4.12, R-169).

crate::pipeline::Pipeline::serve_http_object takes the raw escaped path, query and headers of a GET, HEAD or OPTIONS request and returns a complete HttpObjectResponse: no http crate, no runtime. A binding (WP-4.16) mounts it, adds CORS and streams the body.

The http-objects feature is off by default. Native embedders and the Paid Workers launch can opt in through their adapter features and mount configuration. The handler requires indexed mode and PipelineConfig::http_objects.

The pieces: route is the §2 parser, range the conditional and byte-range rules, resolve published resolution and the byte source (extracted objects held by this repository, else its own pack entry), reach the reachability proof, body the length-enforcing body, and seams the hooks for admission (4.13), proofs (4.14b), tokens (4.15), mounting (4.16) and takedown (5.9a).

Re-exports§

pub use reach::Reachability;
pub use reach::TtlReachability;
pub use route::BadUrl;
pub use route::ParsedUrl;
pub use route::Query;
pub use route::RepoPrefix;
pub use route::Target;
pub use route::is_http_object_path;
pub use route::parse;
pub use seams::AdmitDecision;
pub use seams::AdmitRequest;
pub use seams::Admitted;
pub use seams::HttpAdmission;
pub use seams::HttpSeams;
pub use seams::NoAdmission;
pub use seams::NoTakedown;
pub use seams::NoTokens;
pub use seams::PreparedProof;
pub use seams::ProofServer;
pub use seams::ProofSource;
pub use seams::TakedownGate;
pub use seams::TakedownVerdict;
pub use seams::TokenGate;
pub use seams::UnsupportedProofs;

Modules§

mount
Read-only mount policy shared by the native and Workers adapters.
range
Conditional requests and ordinary byte ranges (SPEC-HTTP-OBJECTS §5.1). Pure functions over header text; proofs never reach them.
reach
Reachability for id URLs (SPEC-HTTP-OBJECTS §4, D2): a member id is served only when a published ref reaches it. The default is a bounded breadth-first walk from the published refs with a positive-result cache; Reachability is the seam a maintained reachable set (WP-5.3a) will replace it behind.
route
The SPEC-HTTP-OBJECTS §2 URL grammar. Pure and URL-only: every failure is a 400 that depends on the request text and the route grammar alone, never on stored state (§2, §3 step 3).
seams
The hand-off points later work packages fill. Every default is inert: no tokens, no admission, no takedown, and proofs answer 416.

Structs§

HttpObjectRequest
One request as a binding presents it. raw_path and raw_query are exactly as received (still escaped, no leading ?): framework decoding must not reinterpret delimiters (§2). Neither is ever logged.
HttpObjectResponse
A complete response. Header names are static; values never carry request text verbatim. Filenames are derived and fully percent-encoded outside RFC 5987 attr-char, with a sanitized ASCII fallback, preventing injection.
HttpObjectsConfig
Limits of opt-in HTTP object serving.
HttpReadRuntime
Runtime services required to retain read settlement after cancellation. Native adapters use tasks; Worker adapters must use the request’s wait_until lifetime. A spawner must run accepted work to completion.
RedactedQuery
An escaped query whose contents are available only to the URL parser. Debug and Display always redact it, including when formatted on its own.

Enums§

HttpBody
A response body. Stream carries its exact length: the stream errors instead of yielding more or fewer bytes.

Constants§

DEFAULT_MAX_INLINE_OBJECT_BYTES
Default HttpObjectsConfig::max_inline_object_bytes: 64 MiB.
METRIC_HTTP_INLINE_CAPPED
Counter: an object without an extracted copy exceeded max_inline_object_bytes and answered 503.
METRIC_HTTP_REACH_CAPPED
Counter: ref enumeration or a reachability walk hit its row, page or decode budget and answered the uniform 404.

Functions§

body_with_hook
body with hook attached: a stream is wrapped, an in-memory body becomes a one-piece stream so the hook still fires when it is consumed.
exact_body
Wrap a backend stream so it yields exactly len bytes or fails, reporting its end to hook. Backend errors are logged and redacted to a fixed message.

Type Aliases§

EndHook
Called once when a body ends, with the bytes sent and how it ended (WP-4.13’s ReadServed{bytes} and Aborted(INTERNAL) hook). A body dropped before its end reports canceled.
HttpHeaderValues
Header lookup safe to retain across a native response future.