- After seam: interface After + Aw + use_after; dispatch funnels every response (handler/short-circuit/404/405) through the after chain; the WS 101 sentinel skips it (never serialized) - http/secure.wo: SecurityHeaders (nosniff/DENY/referrer; HSTS stays at the TLS proxy), Cors (preflight 204 before + origin stamp after, one class both halves), HostAllow (421), client_ip (XFF parsing — peer VERIFY stays story 35) - http/nego.wo: accepts() (exact, type/*, */*; q stripped not ranked), etag_for (quoted base64 sha256), with_etag (If-None-Match -> 304) - router: *rest wildcard (last segment, empty rest matches), Group (prefix + routes + group middleware) + Gmw prefix-scoped entries, App.mount; new App fields carry defaults so standing ctor literals keep compiling - Req grows ctx bag; parse rejects duplicate Content-Length (400, RFC 9112 §6.3) - web-app exercises all of it; gate grows 26 -> 38 checks (wildcards, group+ctx, etag+304, 406/200 negotiation, sec headers, 421, preflight+origin stamp, dup-CL 400) - ledger rows flipped; dep graph section 3 grown (slice-2 done nodes, crypto gate cleared, cookie/CSRF/session/webhook/JWT now ready) - merges: chat-ws-lifecycle (digests for ETag; WS + lifecycle ride along) + site-sample (second consumer gate); battery 13/13 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
76 lines
No EOL
3 KiB
Text
76 lines
No EOL
3 KiB
Text
-- http/secure.wo — framework v1 slice 2: the security middlewares and the
|
|
-- trusted-proxy parsing helper. Mechanism here, POLICY in the app — the
|
|
-- same split http/auth.wo keeps. The classes satisfy router's Middleware/
|
|
-- After interfaces STRUCTURALLY at the registration site — no import here.
|
|
|
|
-- The response headers every deployment wants and nobody remembers.
|
|
-- HSTS is deliberately absent: TLS terminates at the proxy (the
|
|
-- framework's standing decision), so Strict-Transport-Security belongs
|
|
-- in the proxy config next to the certificates.
|
|
pub class SecurityHeaders {
|
|
pad: Int
|
|
fn after(req: Req, mut r: Resp) {
|
|
r.headers["x-content-type-options"] = "nosniff";
|
|
r.headers["x-frame-options"] = "DENY";
|
|
r.headers["referrer-policy"] = "strict-origin-when-cross-origin";
|
|
}
|
|
}
|
|
|
|
-- CORS, both halves in one class: `before` answers the OPTIONS preflight
|
|
-- (204 with the allow set), `after` stamps Access-Control-Allow-Origin on
|
|
-- every response to a request that carried an Origin. Register it twice —
|
|
-- once as Mw, once as Aw — the structural interfaces make one value
|
|
-- satisfy both. allow_origin is the policy knob ("*" or one origin).
|
|
pub class Cors {
|
|
allow_origin: Text
|
|
|
|
fn before(mut req: Req) -> ?Resp {
|
|
if req.method != "OPTIONS" { return nil; }
|
|
let origin = req.headers["origin"];
|
|
if origin == nil { return nil; }
|
|
let want = req.headers["access-control-request-method"];
|
|
if want == nil { return nil; }
|
|
let h: map<Text, Text> = {};
|
|
h["access-control-allow-origin"] = self.allow_origin;
|
|
h["access-control-allow-methods"] = "GET, POST, PUT, DELETE, OPTIONS";
|
|
h["access-control-allow-headers"] = "authorization, content-type";
|
|
h["access-control-max-age"] = "600";
|
|
return Resp { status: 204, headers: h, body: "" };
|
|
}
|
|
|
|
fn after(req: Req, mut r: Resp) {
|
|
let origin = req.headers["origin"];
|
|
if origin != nil {
|
|
r.headers["access-control-allow-origin"] = self.allow_origin;
|
|
}
|
|
}
|
|
}
|
|
|
|
-- Host validation: a request whose Host header is missing or not the
|
|
-- one this app serves answers 421 (misdirected request) before any
|
|
-- route runs. Port suffixes count as part of the host on purpose —
|
|
-- behind the proxy the forwarded Host is exactly one known value.
|
|
pub class HostAllow {
|
|
host: Text
|
|
fn before(mut req: Req) -> ?Resp {
|
|
let got = req.headers["host"];
|
|
if got != nil {
|
|
if trim(got) == self.host { return nil; }
|
|
}
|
|
let h: map<Text, Text> = {};
|
|
h["content-type"] = "application/json";
|
|
return Resp { status: 421, headers: h, body: "{\"error\":\"misdirected request\"}" };
|
|
}
|
|
}
|
|
|
|
-- The PARSING half of trusted-proxy client identity: the left-most
|
|
-- X-Forwarded-For entry, trimmed; "" when absent. VERIFYING that the
|
|
-- peer actually is the trusted proxy needs a peer-address runtime seam —
|
|
-- story 35's, not this slice's.
|
|
pub fn client_ip(req: Req) -> Text {
|
|
let xff = req.headers["x-forwarded-for"];
|
|
if xff == nil { return ""; }
|
|
let parts = split("${xff}", ",");
|
|
if len(parts) == 0 { return ""; }
|
|
return trim(parts[0]);
|
|
} |