calternal_plugin::raster_transport
One bounded transport for public images, Mail fonts and Notes page metadata (#766, #726, #1151; DESIGN §§9, 21, 45, 53). Each redirect is resolved and pinned. No ambient proxy, cookies or Referer leave the Instance. The global FIFO limits active reads and queued requests; callers retain their own authorization, image decoding and cache policy.
Consumer contract (#759, mailhtml-726)
Section titled “Consumer contract (#759, mailhtml-726)”Use image_url(&str) -> Result<Url, StatusCode> for URL admission, then
fetch_image(Url) -> Result<(&'static str, Vec<u8>), StatusCode> for the read.
The read repeats admission and applies the same rules to each redirect.
Success returns a matching declared MIME type and raster signature, with at
most MAX_BYTES buffered bytes. It does not prove that an image decodes or
has useful dimensions; Mail keeps its still-image and dimension checks.
Notes calls fetch_html(Url) and gets the final URL plus at most 256 KiB of
uncompressed HTML. Encoded and non-HTML responses are refused. It shares
the same admission queue and total deadline; the caller reads only head
metadata and owns its URL cache. Neither response is stored in Markdown.
BAD_REQUEST rejects URL input, NOT_FOUND refuses a destination or response,
TOO_MANY_REQUESTS marks temporary admission failure, and
SERVICE_UNAVAILABLE marks the total read deadline. Callers can retry the
last two within their own finite window. Never retry at the remote origin
from a browser. Dropping the read future releases both admission permits.
Authentication, session cancellation, persistence and account cache limits
remain the caller’s responsibility. These public signatures are shared with
mailhtml-726; keep them stable when changing transport internals.
Source: crates/calternal-plugin/src/raster_transport.rs
Functions
Section titled “Functions”fetch_font
Section titled “fetch_font”pub async fn fetch_font(url: Url) -> Result<(&'static str, Vec<u8>), StatusCode>Mail font prefetch uses the same admission, pinning, redirects and privacy policy (#726). Only bounded WOFF and OpenType containers are returned; browsers validate their OpenType tables.
Source: crates/calternal-plugin/src/raster_transport.rs:73
fetch_html
Section titled “fetch_html”pub async fn fetch_html(url: Url) -> Result<(Url, Vec<u8>), StatusCode>Fetch a small HTML document through the same pinned, credential-free public transport (#1151). Only HTML bytes are returned; callers must parse bounded document metadata, never page content.
Source: crates/calternal-plugin/src/raster_transport.rs:85
fetch_image
Section titled “fetch_image”pub async fn fetch_image(url: Url) -> Result<(&'static str, Vec<u8>), StatusCode>Fetch one raster with bounded admission and a total transport deadline (#759 F3). Admission failures are temporary; browser consumers retry on the Instance origin.
Source: crates/calternal-plugin/src/raster_transport.rs:61
font_type
Section titled “font_type”pub fn font_type(bytes: &[u8]) -> Option<&'static str>Validate font container size and expanded size before embedding sender bytes (#726). WOFF/WOFF2 and OpenType tables declare at most 4 MiB of expanded tables and 256 table entries. SVG fonts and system-font probes are never accepted.
Source: crates/calternal-plugin/src/raster_transport.rs:205
image_url
Section titled “image_url”pub fn image_url(value: &str) -> Result<Url, StatusCode>Only ordinary HTTP(S) image URLs are admitted; credentials and unusual ports are refused (#766).
Source: crates/calternal-plugin/src/raster_transport.rs:288
raster_type
Section titled “raster_type”pub fn raster_type(bytes: &[u8]) -> Option<&'static str>Active formats such as SVG never reach the browser; declared type must match raster bytes (#766).
Source: crates/calternal-plugin/src/raster_transport.rs:423
tracking_host
Section titled “tracking_host”pub fn tracking_host(host: &str) -> boolDrop known image-only measurement services before any request (#726). Shared transport applies this rule on every redirect, including Notes loads.
Source: crates/calternal-plugin/src/raster_transport.rs:271
Constants
Section titled “Constants”HTML_MAX_BYTES
Section titled “HTML_MAX_BYTES”pub const HTML_MAX_BYTES: usizeBound HTML metadata reads before parsing, independent of the source page size (#1151).
Source: crates/calternal-plugin/src/raster_transport.rs:38
MAX_BYTES
Section titled “MAX_BYTES”pub const MAX_BYTES: usizeMaximum buffered raster response, shared across Notes and Mail (#759/#726).