feat(14-01): fetchguard client covers PUT, multipart, bearer and a trusted mode

- TrustedMode (declared after PublicOnlyMode) lifts the scheme, host and dial checks for Client only
- PutJSON, PostMultipart with FormField/FormFile, Bearer
- tests for modes, redirects, multipart order, body cap and the scheme guard
- README, root modules row and outbound HTTP docs describe the client and its test seam
This commit is contained in:
Jakub Zych
2026-10-03 19:42:37 +02:00
parent 93b7142059
commit e6a67134d1
10 changed files with 543 additions and 38 deletions

View File

@@ -9,13 +9,25 @@ import (
"git.golem15.com/golem15/summercms/modules/compass"
)
// Mode selects host-allow-list vs any-public-host. The private/loopback/
// reserved IP block is always on regardless of Mode (D-11).
// Mode selects host-allow-list vs any-public-host. In AllowHostsMode and
// PublicOnlyMode the URL must be https and the private/loopback/reserved IP
// block runs at dial time (D-11). TrustedMode lifts both, for Client only.
type Mode int
const (
// AllowHostsMode accepts only hosts listed in Policy.AllowHosts (exact or
// dotted-suffix match).
AllowHostsMode Mode = iota
// PublicOnlyMode accepts any host that resolves to a public address.
PublicOnlyMode
// TrustedMode is for endpoints an operator configured in Go code or admin
// settings, for example a model server on the local network. A Client in
// this mode accepts http and https, checks no host list and runs no dial
// guard; the response body is still capped and redirects are still never
// followed. Never use it for a URL a user or a third party supplied. Only
// Go code that builds the Policy can choose it; Fetch ignores it and
// guards as PublicOnlyMode.
TrustedMode
)
// Reason is the closed set of Fetch failure reasons, matching PHP's