Skip to main content

mkit_server/scanner_retrieval/
mod.rs

1//! Private raw-pack retrieval for synchronous scanners (SPEC-SERVER ยง11.4).
2//! Capabilities authorize only open ticket-bound bytes; public serving is unrelated.
3mod config;
4pub(crate) mod service;
5#[cfg(all(test, feature = "remote-hooks"))]
6mod tests;
7#[cfg(feature = "remote-hooks")]
8mod token;
9#[cfg(feature = "remote-hooks")]
10pub(crate) use token::Claims;
11
12pub use config::{ConfigError, RetrievalConfig};
13pub use service::{RetrievalResponse, validate_config};
14#[cfg(feature = "remote-hooks")]
15pub use token::{Assignment, PackGrant};
16
17/// Exact private POST path; auth v2 signs this procedure and the request body.
18pub const PATH: &str = "/_mkit/scanner/pack";
19/// Bound the complete signed request, including its capability.
20pub const MAX_REQUEST_BYTES: usize = 16_384;
21/// Maximum returned range, or entire pack when no range is requested.
22pub const MAX_RESPONSE_BYTES: usize = 1 << 20;
23/// Shared bound for denial, ticket and blob operations; adapter work has headroom.
24pub const MAX_CALLS: u32 = 8_500;
25/// Small retrieval margin after the hook timeout.
26pub const MARGIN_MS: u64 = 1_000;
27/// Longest capability validity; hook timeout is at most five minutes.
28pub const MAX_LIFETIME_MS: u64 = 301_000;