package ohttp

  1. Overview
  2. Docs

Module Service.ClientSource

A client: sends an Encapsulated Request to a relay, and opens the Encapsulated Response that comes back.

Sourceval key_configs : status:int -> headers:(string * string) list -> string -> (Key_config.t list, Error.t) result

The key configurations in the answer to a GET sent with Http_binding.Client.key_config_request_headers.

Key configurations must be fetched in a way that authenticates the gateway, and the same ones must be given to every client (RFC 9458 Sections 6.1 and 7): that is up to the application, and not something that a GET shows.

Sourcetype exchange

A request that has been sent, and what is needed to open its response.

Sourceval start : rng:Mirage_crypto_rng.g -> ?preference:Suite.symmetric list -> ?framing:Bhttp.Framing.t -> ?padding:int -> ?now:float -> Key_config.t -> Bhttp.Request.t -> (request * exchange, Error.t) result

The POST to send to the relay for request, and the exchange that opens its response.

With now, in seconds since the epoch, the request carries a date field for that time, in place of any it had. A gateway that checks for replay may refuse a request without one (Replay), and tells a client whose date is too far from its clock what its time is: see finish.

The other arguments are those of Http_message.encapsulate_request.

Sourcetype outcome =
  1. | Response of Bhttp.Response.t
    (*

    The gateway's answer.

    *)
  2. | Retry of request * exchange
    (*

    The gateway refused the date of the request, and said what its time is. Send this POST in place of the first: the same request, encapsulated anew, with the gateway's time as its date (RFC 9458 Section 6.5). It is given at most once for each call of start, and only when it had now.

    *)
Sourceval finish : exchange -> status:int -> headers:(string * string) list -> string -> (outcome, Error.t) result

What the relay's answer means. An answer that is not a 200 of type message/ohttp-res is an error: it was not sealed by the gateway, and its content deserves no trust (see Http_binding.Client.check_response).