package ohttp

  1. Overview
  2. Docs
Oblivious HTTP (RFC 9458) for OCaml

Install

dune-project
 Dependency

Authors

Maintainers

Sources

v0.1.2.tar.gz
md5=6a31dba01d9ee06d1b0115516439d8b0
sha512=c2739c32cf8d44b36ca565052f6b14feaf99a029115e8d94dcd469bd363f7dacd8e401a4ca07c0a3555f0fe5572a37516b489ddd945ee9acae4ceafc29e7dadb

doc/ohttp/Ohttp/Client/index.html

Module Ohttp.ClientSource

The client's side of an exchange (RFC 9458 Sections 4.3 and 4.4).

  let* encapsulated, context = Client.encapsulate ~rng config request in
  (* POST [encapsulated] to the relay as message/ohttp-req, and read the
     message/ohttp-res that comes back. *)
  let* response = Client.decapsulate context encapsulated_response in

Requests and responses are byte strings: Binary HTTP messages from Bhttp unless the application has agreed on something else.

Sourcetype response_context

What opens the response to one request. It holds a secret of that exchange and nothing of the HPKE context, so it is immutable and can be kept for as long as a response is awaited.

Sourceval encapsulate : rng:Mirage_crypto_rng.g -> ?labels:Encapsulation.labels -> ?preference:Suite.symmetric list -> Key_config.t -> string -> (string * response_context, Error.t) result

encapsulate ~rng config request is an Encapsulated Request for the gateway that published config, and the context for its response. Every call sets up a fresh HPKE context, as RFC 9458 Section 6.1 requires.

The algorithms are chosen by Key_config.select with preference. labels defaults to Encapsulation.bhttp_labels.

How an HPKE sender context is established. encapsulate uses Hpke.Rfc9180.setup_base_sender ~rng.

Sourceval encapsulate_with : setup:sender_setup -> ?labels:Encapsulation.labels -> ?preference:Suite.symmetric list -> Key_config.t -> string -> (string * response_context, Error.t) result

As encapsulate, with the HPKE sender context set up by setup. Only the hpke package can build a sender context, so setup cannot weaken the exchange unless it comes from hpke.for_testing, whose deterministic senders reproduce published test vectors.

Sourceval decapsulate : response_context -> string -> (string, Error.t) result

decapsulate context encapsulated_response is the response, or Error.t.Decapsulation_failed if it is not the gateway's answer to the request that produced context.