Skip to content

calternal_plugin::outbound

Validate and pin public endpoints used by Plugin provider clients.

Provider URLs can change DNS answers between validation and connection. Resolve each host once, reject the whole answer set if any address is not public, and let the caller pin its HTTP client to this validated set. This outbound boundary supports the shared Integration setup flow (#407, DESIGN §49).

Source: crates/calternal-plugin/src/outbound.rs

pub enum ResolvePublicEndpointError

A safe error category for provider endpoint resolution (#407, DESIGN §49).

Variants

  • InvalidEndpoint
  • BlockedAddress
  • Dns
  • Timeout

Implements: Clone, Copy, Debug, Eq, PartialEq, std::fmt::Display, std::error::Error

Source: crates/calternal-plugin/src/outbound.rs:21

pub fn is_public_ip(address: IpAddr) -> bool

Apply the shared global-unicast boundary to literal metadata assets too (#1151, DESIGN §53).

Source: crates/calternal-plugin/src/outbound.rs:96

pub async fn resolve_public_endpoint(
host: &str,
port: u16,
) -> Result<Vec<SocketAddr>, ResolvePublicEndpointError>

Resolve a provider host and return only validated public socket addresses. Callers must pin network clients to the returned addresses. The function rejects mixed public/private DNS answers and bounds both time and answer count so an attacker-controlled domain cannot cause unbounded work. Integration setup relies on this pinned endpoint boundary (#407, DESIGN §49).

Source: crates/calternal-plugin/src/outbound.rs:46