Show upgrade_endpoint and the https-only client in the storage design

storage.md's BackendProvider listing and its notes predated #65: the
trait gained upgrade_endpoint (core/dr-sync/src/provider.rs:95), run at
launch by AccountStore::upgrade_endpoints to move an http:// account to
https:// with its keyring entry, and the Nextcloud client refuses plain
http below every URL it sends (adade27, ea31791, 5569a06). The listing
gains the method and a note says why it is not normalise_endpoint again.
This commit is contained in:
2026-09-26 07:49:39 -04:00
parent 9e099a07ab
commit 35d0696b66
+13
View File
@@ -195,6 +195,7 @@ pub trait BackendProvider: Send + Sync {
fn endpoint_placeholder(&self) -> &'static str;
fn sign_in(&self) -> SignIn;
fn normalise_endpoint(&self, input: &str) -> Result<String, String>;
fn upgrade_endpoint(&self, stored: &str) -> Option<String>; // defaulted: None
fn account_for(&self, endpoint: &str) -> Result<Account, RemoteError>; // defaulted
fn connect(&self, conn: &Connection) -> Result<Box<dyn RemoteBackend>, RemoteError>;
}
@@ -215,6 +216,18 @@ pub enum SignIn {
Nextcloud provider upgrades `http://` to `https://` here (`NFR-SEC-3`); the
folder provider canonicalises the path, so two spellings of one directory do
not become two accounts indexing the same photographs.
- **`upgrade_endpoint` is for accounts already saved,** and is not a second
call to `normalise_endpoint`: the folder provider's needs the path to exist,
so running it on every launch would fail a library on an unplugged disk.
`AccountStore::upgrade_endpoints` runs it at launch; only Nextcloud answers,
rewriting an `http://` account an older build saved to `https://`
(#65). The keyring entry is filed under the endpoint, so the secret is
copied across before the record changes, and a move that would change
`namespace()` is refused rather than performed. Below both, the Nextcloud
client sets `https_only`, so no URL it sends — a typed one, the login flow's
poll endpoint, a redirect — can carry the app password in the clear, and
the login flow keeps the address the user typed rather than the server's
idea of its own URL.
- **`connect` is synchronous and cheap.** It validates configuration and builds
a client; it does not talk to the remote. Workers call it per task.
- **`SignIn` is a shape, not a method.** It would be tidier to expose