Implement authenticated alert receipt acknowledgments and audit delivery
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e6f1-443f-7783-9920-a16b2ffc467f
This commit is contained in:
parent
67283b66c2
commit
e7282e493d
25 changed files with 1881 additions and 0 deletions
46
scripts/telemetry_http.py
Normal file
46
scripts/telemetry_http.py
Normal file
|
|
@ -0,0 +1,46 @@
|
|||
"""Bounded HTTP transport; endpoint configuration is never supplied by callers."""
|
||||
import json
|
||||
from http.client import HTTPException
|
||||
from urllib.error import HTTPError, URLError
|
||||
from urllib.parse import urlsplit
|
||||
from urllib.request import HTTPRedirectHandler, ProxyHandler, Request, build_opener
|
||||
|
||||
|
||||
def origin(value, internal=False):
|
||||
p = urlsplit(value)
|
||||
local = p.hostname in ('127.0.0.1', '::1') or (p.hostname or '').endswith(('.svc', '.svc.cluster.local'))
|
||||
if (p.scheme != 'https' and not (internal and local and p.scheme == 'http')
|
||||
or not p.hostname or p.username or p.password or p.path or p.query or p.fragment
|
||||
or any(c.isspace() for c in value)):
|
||||
raise ValueError('invalid fixed origin')
|
||||
return value
|
||||
|
||||
|
||||
class NoRedirect(HTTPRedirectHandler):
|
||||
def redirect_request(self, *args, **kwargs):
|
||||
return None
|
||||
|
||||
|
||||
class Transport:
|
||||
def __init__(self):
|
||||
self.opener = build_opener(ProxyHandler({}), NoRedirect())
|
||||
|
||||
def request(self, method, url, body=None, headers=None):
|
||||
try:
|
||||
try:
|
||||
response = self.opener.open(Request(url, data=body, headers=headers or {}, method=method), timeout=5)
|
||||
except HTTPError as error:
|
||||
response = error
|
||||
with response:
|
||||
status = response.code
|
||||
if status >= 300:
|
||||
return status, {}
|
||||
raw = response.read(262145)
|
||||
if len(raw) > 262144:
|
||||
raise ValueError()
|
||||
data = json.loads(raw)
|
||||
if not isinstance(data, dict):
|
||||
raise ValueError()
|
||||
return status, data
|
||||
except (OSError, URLError, HTTPException, ValueError, UnicodeError):
|
||||
raise OSError('upstream unavailable or invalid') from None
|
||||
Loading…
Add table
Add a link
Reference in a new issue