Skip to content

calternal_plugin::raster_transport

One bounded transport for public images, Mail fonts and Notes page metadata (#766, #726, #1151; DESIGN §§9, 21, 45, 53). Each redirect is resolved and pinned. No ambient proxy, cookies or Referer leave the Instance. The global FIFO limits active reads and queued requests; callers retain their own authorization, image decoding and cache policy.

Use image_url(&str) -> Result<Url, StatusCode> for URL admission, then fetch_image(Url) -> Result<(&'static str, Vec<u8>), StatusCode> for the read. The read repeats admission and applies the same rules to each redirect. Success returns a matching declared MIME type and raster signature, with at most MAX_BYTES buffered bytes. It does not prove that an image decodes or has useful dimensions; Mail keeps its still-image and dimension checks.

Notes calls fetch_html(Url) and gets the final URL plus at most 256 KiB of uncompressed HTML. Encoded and non-HTML responses are refused. It shares the same admission queue and total deadline; the caller reads only head metadata and owns its URL cache. Neither response is stored in Markdown.

BAD_REQUEST rejects URL input, NOT_FOUND refuses a destination or response, TOO_MANY_REQUESTS marks temporary admission failure, and SERVICE_UNAVAILABLE marks the total read deadline. Callers can retry the last two within their own finite window. Never retry at the remote origin from a browser. Dropping the read future releases both admission permits. Authentication, session cancellation, persistence and account cache limits remain the caller’s responsibility. These public signatures are shared with mailhtml-726; keep them stable when changing transport internals.

Source: crates/calternal-plugin/src/raster_transport.rs

pub async fn fetch_font(url: Url) -> Result<(&'static str, Vec<u8>), StatusCode>

Mail font prefetch uses the same admission, pinning, redirects and privacy policy (#726). Only bounded WOFF and OpenType containers are returned; browsers validate their OpenType tables.

Source: crates/calternal-plugin/src/raster_transport.rs:73

pub async fn fetch_html(url: Url) -> Result<(Url, Vec<u8>), StatusCode>

Fetch a small HTML document through the same pinned, credential-free public transport (#1151). Only HTML bytes are returned; callers must parse bounded document metadata, never page content.

Source: crates/calternal-plugin/src/raster_transport.rs:85

pub async fn fetch_image(url: Url) -> Result<(&'static str, Vec<u8>), StatusCode>

Fetch one raster with bounded admission and a total transport deadline (#759 F3). Admission failures are temporary; browser consumers retry on the Instance origin.

Source: crates/calternal-plugin/src/raster_transport.rs:61

pub fn font_type(bytes: &[u8]) -> Option<&'static str>

Validate font container size and expanded size before embedding sender bytes (#726). WOFF/WOFF2 and OpenType tables declare at most 4 MiB of expanded tables and 256 table entries. SVG fonts and system-font probes are never accepted.

Source: crates/calternal-plugin/src/raster_transport.rs:205

pub fn image_url(value: &str) -> Result<Url, StatusCode>

Only ordinary HTTP(S) image URLs are admitted; credentials and unusual ports are refused (#766).

Source: crates/calternal-plugin/src/raster_transport.rs:288

pub fn raster_type(bytes: &[u8]) -> Option<&'static str>

Active formats such as SVG never reach the browser; declared type must match raster bytes (#766).

Source: crates/calternal-plugin/src/raster_transport.rs:423

pub fn tracking_host(host: &str) -> bool

Drop known image-only measurement services before any request (#726). Shared transport applies this rule on every redirect, including Notes loads.

Source: crates/calternal-plugin/src/raster_transport.rs:271

pub const HTML_MAX_BYTES: usize

Bound HTML metadata reads before parsing, independent of the source page size (#1151).

Source: crates/calternal-plugin/src/raster_transport.rs:38

pub const MAX_BYTES: usize

Maximum buffered raster response, shared across Notes and Mail (#759/#726).

Source: crates/calternal-plugin/src/raster_transport.rs:36