package assets import ( "net/http" "time" "git.nianxx.cn/wangxuming/NianAIGC/backend/internal/webhook" ) // PublicDestinationPolicy reuses the backend's public-network validation and // DNS-pinned dialing policy for provider asset downloads. type PublicDestinationPolicy = webhook.PublicDestinationValidator func NewPublicDestinationPolicy(resolver webhook.IPResolver, dialer webhook.ContextDialer) *PublicDestinationPolicy { return webhook.NewPublicDestinationPolicy(resolver, dialer) } // NewPublicHTTPRemoteFetcher is the production construction seam. Its // transport resolves and validates immediately before dialing the selected IP. func NewPublicHTTPRemoteFetcher(timeout time.Duration, maxBytes int64, policy *PublicDestinationPolicy) (*HTTPRemoteFetcher, error) { if policy == nil { return nil, errRemotePolicyRequired } transport := http.DefaultTransport.(*http.Transport).Clone() transport.Proxy = nil transport.DialContext = policy.DialContext return NewPolicyHTTPRemoteFetcher(&http.Client{Timeout: timeout, Transport: transport}, maxBytes, policy) }