Show upgrade_endpoint and the https-only client in the storage design

storage.md's BackendProvider listing and its notes predated #65: the
trait gained upgrade_endpoint (core/dr-sync/src/provider.rs:95), run at
launch by AccountStore::upgrade_endpoints to move an http:// account to
https:// with its keyring entry, and the Nextcloud client refuses plain
http below every URL it sends (adade27, ea31791, 5569a06). The listing
gains the method and a note says why it is not normalise_endpoint again.
This commit is contained in:
2026-09-26 07:49:39 -04:00
parent 9e099a07ab
commit 35d0696b66
+13
View File
@@ -195,6 +195,7 @@ pub trait BackendProvider: Send + Sync {
fn endpoint_placeholder(&self) -> &'static str; fn endpoint_placeholder(&self) -> &'static str;
fn sign_in(&self) -> SignIn; fn sign_in(&self) -> SignIn;
fn normalise_endpoint(&self, input: &str) -> Result<String, String>; fn normalise_endpoint(&self, input: &str) -> Result<String, String>;
fn upgrade_endpoint(&self, stored: &str) -> Option<String>; // defaulted: None
fn account_for(&self, endpoint: &str) -> Result<Account, RemoteError>; // defaulted fn account_for(&self, endpoint: &str) -> Result<Account, RemoteError>; // defaulted
fn connect(&self, conn: &Connection) -> Result<Box<dyn RemoteBackend>, RemoteError>; fn connect(&self, conn: &Connection) -> Result<Box<dyn RemoteBackend>, RemoteError>;
} }
@@ -215,6 +216,18 @@ pub enum SignIn {
Nextcloud provider upgrades `http://` to `https://` here (`NFR-SEC-3`); the Nextcloud provider upgrades `http://` to `https://` here (`NFR-SEC-3`); the
folder provider canonicalises the path, so two spellings of one directory do folder provider canonicalises the path, so two spellings of one directory do
not become two accounts indexing the same photographs. not become two accounts indexing the same photographs.
- **`upgrade_endpoint` is for accounts already saved,** and is not a second
call to `normalise_endpoint`: the folder provider's needs the path to exist,
so running it on every launch would fail a library on an unplugged disk.
`AccountStore::upgrade_endpoints` runs it at launch; only Nextcloud answers,
rewriting an `http://` account an older build saved to `https://`
(#65). The keyring entry is filed under the endpoint, so the secret is
copied across before the record changes, and a move that would change
`namespace()` is refused rather than performed. Below both, the Nextcloud
client sets `https_only`, so no URL it sends — a typed one, the login flow's
poll endpoint, a redirect — can carry the app password in the clear, and
the login flow keeps the address the user typed rather than the server's
idea of its own URL.
- **`connect` is synchronous and cheap.** It validates configuration and builds - **`connect` is synchronous and cheap.** It validates configuration and builds
a client; it does not talk to the remote. Workers call it per task. a client; it does not talk to the remote. Workers call it per task.
- **`SignIn` is a shape, not a method.** It would be tidier to expose - **`SignIn` is a shape, not a method.** It would be tidier to expose