hostpolicy

package
v0.1.7 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: MIT Imports: 13 Imported by: 0

Documentation

Overview

Package hostpolicy gates all content on resolved alternate hosts. Compose it outside every application wrapper; it neither provisions tenants nor grants CMS access. Credentials are owner supplied and stored only as bcrypt hashes.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func CanonicalURL

func CanonicalURL(primary string, path *url.URL) string

CanonicalURL is intended for callers that need a safe public canonical hint.

func ParseTrustedProxies

func ParseTrustedProxies(raw string) ([]netip.Prefix, error)

ParseTrustedProxies accepts explicit CIDRs only; never trust forwarded host.

Types

type Config

type Config struct {
	AdminHost, PlatformHost string
	Policies                map[string]Policy
	Resolve                 func(context.Context, string) (Tenant, bool)
	TrustedProxies          []netip.Prefix
	Transport               TransportMode
}

type Gate

type Gate struct {
	// contains filtered or unexported fields
}

func New

func New(cfg Config, next http.Handler) (*Gate, error)

func (*Gate) ServeHTTP

func (g *Gate) ServeHTTP(w http.ResponseWriter, r *http.Request)

type Policy

type Policy struct {
	Primary         string   `json:"primary"`
	RedirectAliases []string `json:"redirect_aliases"`
	PasswordHash    string   `json:"-"`
}

type Tenant

type Tenant struct {
	ID         int64
	Slug, Kind string
}

type TransportMode

type TransportMode string

TransportMode describes the deployment's HTTPS boundary, never client input.

const (
	TransportStrict           TransportMode = "strict"
	TransportAppPlatformHTTPS TransportMode = "app-platform-https"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL