feat: complete remaining Go backend modules

This commit is contained in:
zn-admin committed 2026-08-14 00:02:43 +08:00
1 parent cea2751dc5
commit aef5a97165
145 files changed
+18376 -199

No files matched your search

+39
View File
@@ -10,9 +10,40 @@ import (
"net/url"
)
var errRemotePolicyRequired = errors.New("remote fetcher requires a bounded client and destination policy")
type HTTPRemoteFetcher struct {
client *http.Client
maxBytes int64
policy DestinationPolicy
}
// DestinationPolicy is the injectable outbound-network policy seam.
type DestinationPolicy interface {
Validate(context.Context, *url.URL) error
}
// NewPolicyHTTPRemoteFetcher preserves the existing constructor while offering
// production composition a fail-closed destination-policy seam.
func NewPolicyHTTPRemoteFetcher(client *http.Client, maxBytes int64, policy DestinationPolicy) (*HTTPRemoteFetcher, error) {
if client == nil || client.Timeout <= 0 || policy == nil {
return nil, errRemotePolicyRequired
}
base := *client
previousRedirect := base.CheckRedirect
base.CheckRedirect = func(req *http.Request, via []*http.Request) error {
if len(via) >= 10 {
return errors.New("stopped after 10 redirects")
}
if err := policy.Validate(req.Context(), req.URL); err != nil {
return err
}
if previousRedirect != nil {
return previousRedirect(req, via)
}
return nil
}
return &HTTPRemoteFetcher{client: &base, maxBytes: maxBytes, policy: policy}, nil
}
func NewHTTPRemoteFetcher(client *http.Client, maxBytes int64) *HTTPRemoteFetcher {
@@ -40,6 +71,14 @@ func (f *HTTPRemoteFetcher) Fetch(ctx context.Context, rawURL string) (Blob, err
if err != nil || (u.Scheme != "http" && u.Scheme != "https") || u.Host == "" {
return Blob{}, ErrRemoteProtocol
}
if u.User != nil {
return Blob{}, ErrRemoteProtocol
}
if f.policy != nil {
if err := f.policy.Validate(ctx, u); err != nil {
return Blob{}, err
}
}
req, err := http.NewRequestWithContext(ctx, http.MethodGet, u.String(), nil)
if err != nil {
return Blob{}, err