Show upgrade_endpoint and the https-only client in the storage design
storage.md's BackendProvider listing and its notes predated #65: the trait gained upgrade_endpoint (core/dr-sync/src/provider.rs:95), run at launch by AccountStore::upgrade_endpoints to move an http:// account to https:// with its keyring entry, and the Nextcloud client refuses plain http below every URL it sends (adade27,ea31791,5569a06). The listing gains the method and a note says why it is not normalise_endpoint again.
This commit is contained in:
@@ -195,6 +195,7 @@ pub trait BackendProvider: Send + Sync {
|
||||
fn endpoint_placeholder(&self) -> &'static str;
|
||||
fn sign_in(&self) -> SignIn;
|
||||
fn normalise_endpoint(&self, input: &str) -> Result<String, String>;
|
||||
fn upgrade_endpoint(&self, stored: &str) -> Option<String>; // defaulted: None
|
||||
fn account_for(&self, endpoint: &str) -> Result<Account, RemoteError>; // defaulted
|
||||
fn connect(&self, conn: &Connection) -> Result<Box<dyn RemoteBackend>, RemoteError>;
|
||||
}
|
||||
@@ -215,6 +216,18 @@ pub enum SignIn {
|
||||
Nextcloud provider upgrades `http://` to `https://` here (`NFR-SEC-3`); the
|
||||
folder provider canonicalises the path, so two spellings of one directory do
|
||||
not become two accounts indexing the same photographs.
|
||||
- **`upgrade_endpoint` is for accounts already saved,** and is not a second
|
||||
call to `normalise_endpoint`: the folder provider's needs the path to exist,
|
||||
so running it on every launch would fail a library on an unplugged disk.
|
||||
`AccountStore::upgrade_endpoints` runs it at launch; only Nextcloud answers,
|
||||
rewriting an `http://` account an older build saved to `https://`
|
||||
(#65). The keyring entry is filed under the endpoint, so the secret is
|
||||
copied across before the record changes, and a move that would change
|
||||
`namespace()` is refused rather than performed. Below both, the Nextcloud
|
||||
client sets `https_only`, so no URL it sends — a typed one, the login flow's
|
||||
poll endpoint, a redirect — can carry the app password in the clear, and
|
||||
the login flow keeps the address the user typed rather than the server's
|
||||
idea of its own URL.
|
||||
- **`connect` is synchronous and cheap.** It validates configuration and builds
|
||||
a client; it does not talk to the remote. Workers call it per task.
|
||||
- **`SignIn` is a shape, not a method.** It would be tidier to expose
|
||||
|
||||
Reference in New Issue
Block a user