- http/auth.wo: auth_header (scheme split, case-insensitive, RFC 9110),
bearer_token, basic_credentials (first-colon split, RFC 7617),
pure-.wo base64_decode (RFC 4648, strict padding), ct_eq constant-time
compare (no early exit, both Basic fields always compared)
- req.principal: the blessed "who is this" slot, "" until authenticated;
Middleware.before now takes mut req so auth can write it
- BearerAuth { token, principal } and BasicAuth { user, pass, realm }
middlewares; BasicAuth answers the WWW-Authenticate challenge; policy
(routes/users/secrets) stays app-side on the exposed fns
- web-app dogfoods BearerAuth; its hand-rolled Auth class deleted
- probe matrix 26/26 (RFC 4648 vectors, rfc7617 pair, pass-with-colon,
bad padding/chars/length, deny paths, challenge header) release+ASan
- gate grows 16 -> 17: wrong bearer token answers 401 over the wire
- README: auth bullet + the core CHECKLIST (done / candidate / parked
behind 8-11 by design); story 16 + board record the landing
- all gates green: web-app 17/0, oop-e2e 89/0, deps-accept 8/0,
log-watcher 7/0, employee 8/0, woc-test green
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
70 lines
2.3 KiB
Text
70 lines
2.3 KiB
Text
-- router/router.wo — the handler model and the route table.
|
|
--
|
|
-- No function values in this language, by doctrine — so a handler is a
|
|
-- CLASS satisfying the Handler interface (its fields are the closure
|
|
-- substitute), dispatched structurally (ICALL). A class missing `handle`
|
|
-- is a compile error (WO-E205). Middleware is its own interface because
|
|
-- the signature differs: `before` returns `?Resp` — nil means continue,
|
|
-- a Resp short-circuits (401 gates, redirects).
|
|
|
|
pub interface Handler {
|
|
fn handle(req: Req) -> Resp
|
|
}
|
|
|
|
-- `mut req`: middleware may WRITE the request — auth attaches the
|
|
-- authenticated principal (req.principal) for downstream handlers.
|
|
pub interface Middleware {
|
|
fn before(mut req: Req) -> ?Resp
|
|
}
|
|
|
|
-- One route: method + pattern + the handler value. Built with a ctor
|
|
-- literal at the registration site (`Route { method: "GET", pattern:
|
|
-- "/products/:id", h: ProductShow {} }`) — the exact ownership shape the
|
|
-- conformance corpus pins (run/container-owned-move).
|
|
pub class Route {
|
|
method: Text
|
|
pattern: Text
|
|
h: Handler
|
|
}
|
|
|
|
-- Middleware wrapper record, same shape as Route for the same reason.
|
|
pub class Mw {
|
|
m: Middleware
|
|
}
|
|
|
|
-- Request-line logging, the one middleware every framework ships: method +
|
|
-- path to stderr, never short-circuits. `pad` is the record-class ctor
|
|
-- convention (every stateless handler carries one Int field).
|
|
pub class Logging {
|
|
pad: Int
|
|
fn before(mut req: Req) -> ?Resp {
|
|
print_err("${req.method} ${req.path}");
|
|
return nil;
|
|
}
|
|
}
|
|
|
|
-- Does `pattern` match `path`? Fills `params` with :name captures.
|
|
-- Segments split on '/', empties dropped (so "/a//b" == "/a/b" and the
|
|
-- root "/" is the empty segment list). First mismatch wins; a :segment
|
|
-- captures anything non-empty.
|
|
pub fn route_match(pattern: Text, path: Text, mut params: map<Text, Text>) -> Bool {
|
|
let ps = split(pattern, "/");
|
|
let xs = split(path, "/");
|
|
let psegs: multi Text = [];
|
|
for s in ps { if s != "" { push(psegs, s); } }
|
|
let xsegs: multi Text = [];
|
|
for s in xs { if s != "" { push(xsegs, s); } }
|
|
if len(psegs) != len(xsegs) { return false; }
|
|
let i = 0;
|
|
while i < len(psegs) {
|
|
let p = psegs[i];
|
|
let x = xsegs[i];
|
|
if starts_with(p, ":") {
|
|
params[substr(p, 1, len(p) - 1)] = x;
|
|
} else {
|
|
if p != x { return false; }
|
|
}
|
|
i = i + 1;
|
|
}
|
|
return true;
|
|
}
|