calternal_plugin::outbound
Validate and pin public endpoints used by Plugin provider clients.
Provider URLs can change DNS answers between validation and connection. Resolve each host once, reject the whole answer set if any address is not public, and let the caller pin its HTTP client to this validated set. This outbound boundary supports the shared Integration setup flow (#407, DESIGN §49).
Source: crates/calternal-plugin/src/outbound.rs
ResolvePublicEndpointError
Section titled “ResolvePublicEndpointError”pub enum ResolvePublicEndpointErrorA safe error category for provider endpoint resolution (#407, DESIGN §49).
Variants
InvalidEndpointBlockedAddressDnsTimeout
Implements: Clone, Copy, Debug, Eq, PartialEq, std::fmt::Display, std::error::Error
Source: crates/calternal-plugin/src/outbound.rs:21
Functions
Section titled “Functions”is_public_ip
Section titled “is_public_ip”pub fn is_public_ip(address: IpAddr) -> boolApply the shared global-unicast boundary to literal metadata assets too (#1151, DESIGN §53).
Source: crates/calternal-plugin/src/outbound.rs:96
resolve_public_endpoint
Section titled “resolve_public_endpoint”pub async fn resolve_public_endpoint( host: &str, port: u16,) -> Result<Vec<SocketAddr>, ResolvePublicEndpointError>Resolve a provider host and return only validated public socket addresses. Callers must pin network clients to the returned addresses. The function rejects mixed public/private DNS answers and bounds both time and answer count so an attacker-controlled domain cannot cause unbounded work. Integration setup relies on this pinned endpoint boundary (#407, DESIGN §49).