Skip to main content

Module http

Module http 

Source
Expand description

The Streamable HTTP transport, and everything that stands in front of it.

Stdio has one client, reached over a pipe the operating system already decided who may open. HTTP has none of that: anything that can reach the socket can try, and a browser on the same machine can be made to try by a page the operator never visited. So the transport is the small part of this module and the checks are the rest.

What has to be true before a request reaches the handler, in the order it is asked:

  1. The Host header names something on the allow-list. Loopback, plus this node’s own tailnet names read from status at startup, plus whatever the operator added. This is what stops DNS rebinding: a page that resolves evil.example to 127.0.0.1 reaches the socket and arrives with the wrong Host.
  2. There is no Origin, or the Origin is on its own allow-list. A request carrying one came from a page, and a page is not a client this server has any reason to serve unless the operator said so.
  3. The caller’s address is under its rate limit.
  4. The bearer token matches, compared in constant time.

The body limit is the one check that is not here: rmcp’s transport reads the body, so rmcp’s transport is what caps it. See MAX_BODY_BYTES.

GET /health skips all four: it exists to be reachable by something that holds no credential, which is the whole point of a health check.

A token is optional on loopback and required everywhere else. Binding to an address other than loopback without one refuses to start, and --http-no-auth is the only way past that — a flag rather than an omission, so that serving an unauthenticated tailnet address is something an operator did rather than something that happened.

Structs§

Caller
Who is calling, as far as this server can tell.
Guard
Everything the checks need, built once at startup.

Enums§

Refusal
Why a request was refused.

Constants§

DEFAULT_BIND
Where --http listens when it is given no address.
HEALTH_PATH
The path that answers without a token.
MAX_BODY_BYTES
The largest request body accepted.
MCP_PATH
The path the MCP transport is served at.
RATE_BURST
How many requests one address may make in RATE_WINDOW.
RATE_WINDOW
The window the burst is counted over.

Functions§

router
Build the router: the health check, the transport, and the checks in front.
serve
Build the transport, the checks, and the listener, and serve until stopped.