package ohttp

  1. Overview
  2. Docs

Module Service.GatewaySource

A gateway: serves its key configurations, and answers each Encapsulated Request with an Encapsulated Response.

Sourcetype t
Sourceval create : rng:Mirage_crypto_rng.g -> ?replay:Replay.t -> ?checks_replay:(Bhttp.Request.t -> bool) -> ?framing:Bhttp.Framing.t -> ?padding:int -> ?max_request_size:int -> ?max_in_flight:int -> Gateway.t -> t

A gateway with the keys of a Ohttp.Gateway.t.

With replay, every request for which checks_replay holds is checked with Replay.check, and a rejected one is answered, sealed, with Replay.rejection_response. checks_replay holds for every request by default; a gateway that trusts its targets to be idempotent for some requests, such as GET, can leave those out (RFC 9458 Section 6.5).

rng seals the responses, which framing and padding shape as with Http_message.encapsulate_response.

The gateway reads Encapsulated Requests of at most max_request_size bytes, and handles at most max_in_flight of them at once. The defaults are default_max_request_size and default_max_in_flight. Raises Invalid_argument unless both are positive. What a gateway reads from a target is limited where it is read: see the forward functions of the adapters.

Sourceval max_request_size : t -> int
Sourceval admit : t -> bool

As Relay.admit, for the requests that a gateway receives.

Sourceval release : t -> unit
Sourceval key_configs : t -> response

The answer to a GET of Http_binding.well_known_gateway_path: the key configurations, in the application/ohttp-keys format.

Sourcetype step =
  1. | Respond of response
    (*

    The answer to give, which needs nothing from a target.

    *)
  2. | Forward of Bhttp.Request.t * Bhttp.Response.t -> response
    (*

    The request to answer, and what seals its answer. The gateway gets a response for the request, from a target or of its own making, and gives what the function returns for it. A request that cannot be answered, because no target is known for its authority or none answers, is answered with a response of the gateway's making too, such as a 403, 502, or 504, and sealed like any other (RFC 9458 Section 5).

    *)
Sourceval target : targets:(string * string) list -> Bhttp.Request.t -> (string, Bhttp.Response.t) result

target ~targets request is the URI to which a gateway sends request. targets maps each authority that the gateway serves to the URI at which it reaches that target, such as "http://127.0.0.1:8000", and the request's path is appended to it.

A request for any other authority is answered with a 403, and one whose path does not start with "/" with a 400: a gateway that sent requests wherever its clients asked would be an open proxy.

Sourceval receive : t -> now:float -> meth:string -> headers:(string * string) list -> string -> step

receive gateway ~now ~meth ~headers content is the step for a request to the gateway's resource. now is the time in seconds since the epoch, for the replay check.

A request whose encapsulation cannot be removed is answered in the clear with Http_binding.Gateway.error_response, and so is one longer than max_request_size, with a 413. An adapter refuses that one as it reads it; the check here is for those that do not. Once it is removed, every answer is sealed: a request that does not decode, that expects 100-continue, or that fails the replay check is answered with a Respond whose content is an Encapsulated Response.