From 337b56ec1b5ff91c3e79964c5d8382b02f81c98b Mon Sep 17 00:00:00 2001 From: Cole Speelman Date: Thu, 3 Sep 2026 10:05:17 -0400 Subject: [PATCH] docs: publish Web Foundations module landing --- CHANGELOG.md | 12 ++ LICENSE | 375 ++++++++++++++++++++++++++++++++++ LICENSES.md | 4 + README.md | 182 ++++++++++------- doc.go | 65 ++++++ docs/GETTING_STARTED.md | 2 +- docs/MODULES.md | 2 +- example_test.go | 51 +++++ scripts/public-snapshot.allow | 3 + 9 files changed, 620 insertions(+), 76 deletions(-) create mode 100644 LICENSE create mode 100644 doc.go create mode 100644 example_test.go diff --git a/CHANGELOG.md b/CHANGELOG.md index 15c1eeb..660c98c 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,18 @@ # Changelog +## v0.1.0-preview.9 — 2026-09-03 + +- Add a documented root package and executable composition example so the + module landing page presents its purpose, package-selection guidance, + security model, and `net/http` integration rather than only a directory + index. +- Add the repository's default MPL-2.0 licence at the conventional root path + so Go package tooling can identify the library licence while preserving the + existing file-level exceptions for starters and operational machinery. +- Rework the public README around progressive adoption, explicit design + promises, package selection, assurance gates, and canonical project links. + ## v0.1.0-preview.8 — 2026-08-28 - Preserve `http.Hijacker` through the request-evidence middleware so audited, diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..64a3d0b --- /dev/null +++ b/LICENSE @@ -0,0 +1,375 @@ +SPDX-License-Identifier: MPL-2.0 + +Mozilla Public License Version 2.0 +================================== + +1. Definitions +-------------- + +1.1. "Contributor" + means each individual or legal entity that creates, contributes to + the creation of, or owns Covered Software. + +1.2. "Contributor Version" + means the combination of the Contributions of others (if any) used + by a Contributor and that particular Contributor's Contribution. + +1.3. "Contribution" + means Covered Software of a particular Contributor. + +1.4. "Covered Software" + means Source Code Form to which the initial Contributor has attached + the notice in Exhibit A, the Executable Form of such Source Code + Form, and Modifications of such Source Code Form, in each case + including portions thereof. + +1.5. "Incompatible With Secondary Licenses" + means + + (a) that the initial Contributor has attached the notice described + in Exhibit B to the Covered Software; or + + (b) that the Covered Software was made available under the terms of + version 1.1 or earlier of the License, but not also under the + terms of a Secondary License. + +1.6. "Executable Form" + means any form of the work other than Source Code Form. + +1.7. "Larger Work" + means a work that combines Covered Software with other material, in + a separate file or files, that is not Covered Software. + +1.8. "License" + means this document. + +1.9. "Licensable" + means having the right to grant, to the maximum extent possible, + whether at the time of the initial grant or subsequently, any and + all of the rights conveyed by this License. + +1.10. "Modifications" + means any of the following: + + (a) any file in Source Code Form that results from an addition to, + deletion from, or modification of the contents of Covered + Software; or + + (b) any new file in Source Code Form that contains any Covered + Software. + +1.11. "Patent Claims" of a Contributor + means any patent claim(s), including without limitation, method, + process, and apparatus claims, in any patent Licensable by such + Contributor that would be infringed, but for the grant of the + License, by the making, using, selling, offering for sale, having + made, import, or transfer of either its Contributions or its + Contributor Version. + +1.12. "Secondary License" + means either the GNU General Public License, Version 2.0, the GNU + Lesser General Public License, Version 2.1, the GNU Affero General + Public License, Version 3.0, or any later versions of those + licenses. + +1.13. "Source Code Form" + means the form of the work preferred for making modifications. + +1.14. "You" (or "Your") + means an individual or a legal entity exercising rights under this + License. For legal entities, "You" includes any entity that + controls, is controlled by, or is under common control with You. For + purposes of this definition, "control" means (a) the power, direct + or indirect, to cause the direction or management of such entity, + whether by contract or otherwise, or (b) ownership of more than + fifty percent (50%) of the outstanding shares or beneficial + ownership of such entity. + +2. License Grants and Conditions +-------------------------------- + +2.1. Grants + +Each Contributor hereby grants You a world-wide, royalty-free, +non-exclusive license: + +(a) under intellectual property rights (other than patent or trademark) + Licensable by such Contributor to use, reproduce, make available, + modify, display, perform, distribute, and otherwise exploit its + Contributions, either on an unmodified basis, with Modifications, or + as part of a Larger Work; and + +(b) under Patent Claims of such Contributor to make, use, sell, offer + for sale, have made, import, and otherwise transfer either its + Contributions or its Contributor Version. + +2.2. Effective Date + +The licenses granted in Section 2.1 with respect to any Contribution +become effective for each Contribution on the date the Contributor first +distributes such Contribution. + +2.3. Limitations on Grant Scope + +The licenses granted in this Section 2 are the only rights granted under +this License. No additional rights or licenses will be implied from the +distribution or licensing of Covered Software under this License. +Notwithstanding Section 2.1(b) above, no patent license is granted by a +Contributor: + +(a) for any code that a Contributor has removed from Covered Software; + or + +(b) for infringements caused by: (i) Your and any other third party's + modifications of Covered Software, or (ii) the combination of its + Contributions with other software (except as part of its Contributor + Version); or + +(c) under Patent Claims infringed by Covered Software in the absence of + its Contributions. + +This License does not grant any rights in the trademarks, service marks, +or logos of any Contributor (except as may be necessary to comply with +the notice requirements in Section 3.4). + +2.4. Subsequent Licenses + +No Contributor makes additional grants as a result of Your choice to +distribute the Covered Software under a subsequent version of this +License (see Section 10.2) or under the terms of a Secondary License (if +permitted under the terms of Section 3.3). + +2.5. Representation + +Each Contributor represents that the Contributor believes its +Contributions are its original creation(s) or it has sufficient rights +to grant the rights to its Contributions conveyed by this License. + +2.6. Fair Use + +This License is not intended to limit any rights You have under +applicable copyright doctrines of fair use, fair dealing, or other +equivalents. + +2.7. Conditions + +Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted +in Section 2.1. + +3. Responsibilities +------------------- + +3.1. Distribution of Source Form + +All distribution of Covered Software in Source Code Form, including any +Modifications that You create or to which You contribute, must be under +the terms of this License. You must inform recipients that the Source +Code Form of the Covered Software is governed by the terms of this +License, and how they can obtain a copy of this License. You may not +attempt to alter or restrict the recipients' rights in the Source Code +Form. + +3.2. Distribution of Executable Form + +If You distribute Covered Software in Executable Form then: + +(a) such Covered Software must also be made available in Source Code + Form, as described in Section 3.1, and You must inform recipients of + the Executable Form how they can obtain a copy of such Source Code + Form by reasonable means in a timely manner, at a charge no more + than the cost of distribution to the recipient; and + +(b) You may distribute such Executable Form under the terms of this + License, or sublicense it under different terms, provided that the + license for the Executable Form does not attempt to limit or alter + the recipients' rights in the Source Code Form under this License. + +3.3. Distribution of a Larger Work + +You may create and distribute a Larger Work under terms of Your choice, +provided that You also comply with the requirements of this License for +the Covered Software. If the Larger Work is a combination of Covered +Software with a work governed by one or more Secondary Licenses, and the +Covered Software is not Incompatible With Secondary Licenses, this +License permits You to additionally distribute such Covered Software +under the terms of such Secondary License(s), so that the recipient of +the Larger Work may, at their option, further distribute the Covered +Software under the terms of either this License or such Secondary +License(s). + +3.4. Notices + +You may not remove or alter the substance of any license notices +(including copyright notices, patent notices, disclaimers of warranty, +or limitations of liability) contained within the Source Code Form of +the Covered Software, except that You may alter any license notices to +the extent required to remedy known factual inaccuracies. + +3.5. Application of Additional Terms + +You may choose to offer, and to charge a fee for, warranty, support, +indemnity or liability obligations to one or more recipients of Covered +Software. However, You may do so only on Your own behalf, and not on +behalf of any Contributor. You must make it absolutely clear that any +such warranty, support, indemnity, or liability obligation is offered by +You alone, and You hereby agree to indemnify every Contributor for any +liability incurred by such Contributor as a result of warranty, support, +indemnity or liability terms You offer. You may include additional +disclaimers of warranty and limitations of liability specific to any +jurisdiction. + +4. Inability to Comply Due to Statute or Regulation +--------------------------------------------------- + +If it is impossible for You to comply with any of the terms of this +License with respect to some or all of the Covered Software due to +statute, judicial order, or regulation then You must: (a) comply with +the terms of this License to the maximum extent possible; and (b) +describe the limitations and the code they affect. Such description must +be placed in a text file included with all distributions of the Covered +Software under this License. Except to the extent prohibited by statute +or regulation, such description must be sufficiently detailed for a +recipient of ordinary skill to be able to understand it. + +5. Termination +-------------- + +5.1. The rights granted under this License will terminate automatically +if You fail to comply with any of its terms. However, if You become +compliant, then the rights granted under this License from a particular +Contributor are reinstated (a) provisionally, unless and until such +Contributor explicitly and finally terminates Your grants, and (b) on an +ongoing basis, if such Contributor fails to notify You of the +non-compliance by some reasonable means prior to 60 days after You have +come back into compliance. Moreover, Your grants from a particular +Contributor are reinstated on an ongoing basis if such Contributor +notifies You of the non-compliance by some reasonable means, this is the +first time You have received notice of non-compliance with this License +from such Contributor, and You become compliant prior to 30 days after +Your receipt of the notice. + +5.2. If You initiate litigation against any entity by asserting a patent +infringement claim (excluding declaratory judgment actions, +counter-claims, and cross-claims) alleging that a Contributor Version +directly or indirectly infringes any patent, then the rights granted to +You by any and all Contributors for the Covered Software under Section +2.1 of this License shall terminate. + +5.3. In the event of termination under Sections 5.1 or 5.2 above, all +end user license agreements (excluding distributors and resellers) which +have been validly granted by You or Your distributors under this License +prior to termination shall survive termination. + +************************************************************************ +* * +* 6. Disclaimer of Warranty * +* ------------------------- * +* * +* Covered Software is provided under this License on an "as is" * +* basis, without warranty of any kind, either expressed, implied, or * +* statutory, including, without limitation, warranties that the * +* Covered Software is free of defects, merchantable, fit for a * +* particular purpose or non-infringing. The entire risk as to the * +* quality and performance of the Covered Software is with You. * +* Should any Covered Software prove defective in any respect, You * +* (not any Contributor) assume the cost of any necessary servicing, * +* repair, or correction. This disclaimer of warranty constitutes an * +* essential part of this License. No use of any Covered Software is * +* authorized under this License except under this disclaimer. * +* * +************************************************************************ + +************************************************************************ +* * +* 7. Limitation of Liability * +* -------------------------- * +* * +* Under no circumstances and under no legal theory, whether tort * +* (including negligence), contract, or otherwise, shall any * +* Contributor, or anyone who distributes Covered Software as * +* permitted above, be liable to You for any direct, indirect, * +* special, incidental, or consequential damages of any character * +* including, without limitation, damages for lost profits, loss of * +* goodwill, work stoppage, computer failure or malfunction, or any * +* and all other commercial damages or losses, even if such party * +* shall have been informed of the possibility of such damages. This * +* limitation of liability shall not apply to liability for death or * +* personal injury resulting from such party's negligence to the * +* extent applicable law prohibits such limitation. Some * +* jurisdictions do not allow the exclusion or limitation of * +* incidental or consequential damages, so this exclusion and * +* limitation may not apply to You. * +* * +************************************************************************ + +8. Litigation +------------- + +Any litigation relating to this License may be brought only in the +courts of a jurisdiction where the defendant maintains its principal +place of business and such litigation shall be governed by laws of that +jurisdiction, without reference to its conflict-of-law provisions. +Nothing in this Section shall prevent a party's ability to bring +cross-claims or counter-claims. + +9. Miscellaneous +---------------- + +This License represents the complete agreement concerning the subject +matter hereof. If any provision of this License is held to be +unenforceable, such provision shall be reformed only to the extent +necessary to make it enforceable. Any law or regulation which provides +that the language of a contract shall be construed against the drafter +shall not be used to construe this License against a Contributor. + +10. Versions of the License +--------------------------- + +10.1. New Versions + +Mozilla Foundation is the license steward. Except as provided in Section +10.3, no one other than the license steward has the right to modify or +publish new versions of this License. Each version will be given a +distinguishing version number. + +10.2. Effect of New Versions + +You may distribute the Covered Software under the terms of the version +of the License under which You originally received the Covered Software, +or under the terms of any subsequent version published by the license +steward. + +10.3. Modified Versions + +If you create software not governed by this License, and you want to +create a new license for such software, you may create and use a +modified version of this License if you rename the license and remove +any references to the name of the license steward (except to note that +such modified license differs from this License). + +10.4. Distributing Source Code Form that is Incompatible With Secondary +Licenses + +If You choose to distribute Source Code Form that is Incompatible With +Secondary Licenses under the terms of this version of the License, the +notice described in Exhibit B of this License must be attached. + +Exhibit A - Source Code Form License Notice +------------------------------------------- + + This Source Code Form is subject to the terms of the Mozilla Public + License, v. 2.0. If a copy of the MPL was not distributed with this + file, You can obtain one at http://mozilla.org/MPL/2.0/. + +If it is not possible or desirable to put the notice in a particular +file, then You may include the notice in a location (such as a LICENSE +file in a relevant directory) where a recipient would be likely to look +for such a notice. + +You may add additional accurate notices of copyright ownership. + +Exhibit B - "Incompatible With Secondary Licenses" Notice +--------------------------------------------------------- + + This Source Code Form is "Incompatible With Secondary Licenses", as + defined by the Mozilla Public License, v. 2.0. diff --git a/LICENSES.md b/LICENSES.md index 23eaaab..336f6ec 100644 --- a/LICENSES.md +++ b/LICENSES.md @@ -14,3 +14,7 @@ fails closed on missing or misplaced identifiers. Full texts are in `LICENSES/`. Combining these MPL-covered packages with an application does not change the licence of the application's own files; changes to covered files remain subject to the MPL. This summary is not legal advice. + +The root [`LICENSE`](LICENSE) contains the default MPL-2.0 text for package +indexers and repository tooling. More specific file-level SPDX identifiers in +the paths above remain authoritative. diff --git a/README.md b/README.md index af425be..bdf47b3 100644 --- a/README.md +++ b/README.md @@ -2,106 +2,140 @@ # Gamertan Web Foundations -> Status: `v0.1.0-preview.8` public preview. APIs may change before a stable -> release; Linux is the maintained release platform. +[![Go Reference](https://pkg.go.dev/badge/gamertan.com/web.svg)](https://pkg.go.dev/gamertan.com/web) +[![Verify](https://gitea.speelman.ca/gamertan/web/actions/workflows/verify.yml/badge.svg?branch=main)](https://gitea.speelman.ca/gamertan/web/actions?workflow=verify.yml) -Small, composable Go packages for the unglamorous boundaries of a careful web -application: request identity, structured request logs, browser security, -passwords, passkeys, sessions, permissions, SQLite persistence, and private -analytics. +**Security-conscious building blocks for ordinary `net/http` applications.** -This is a toolkit, not an application framework. Your application keeps its -router, HTTP policy, HTML, authorization decisions, cache behavior, and -deployment. Each package works with `net/http` and can be adopted independently. +Web Foundations provides small, composable Go packages for the unglamorous +boundaries of a careful web application: request identity, structured request +evidence, browser security, authentication, passkeys, permissions, +organizations, SQLite persistence, abuse controls, and private analytics. -The first preview targets modest Linux servers, local files, SQLite, and normal -Go binaries. It requires no Redis, message broker, hosted identity provider, -telemetry service, or JavaScript framework. +It is a toolkit, not an application framework. Your application keeps its +router, handlers, HTML, authorization decisions, cache behavior, and +deployment. Adopt one boundary at a time; Go compiles and links only the +packages you import. + +> **Public preview:** `v0.1.0-preview.9`. APIs may change before a stable +> release. Linux is the maintained release platform. + +## Why Web Foundations? + +| Design promise | What it means in an application | +| --- | --- | +| `net/http` native | Keep the standard router or any compatible router; there is no framework lifecycle. | +| Explicit security boundaries | Trusted proxies, sensitive log fields, browser origins, and scoped authority are configured deliberately. | +| Bounded and fail-closed | Untrusted inputs are size-limited, and security-critical configuration or storage failures do not quietly weaken policy. | +| Storage-neutral core | Interfaces separate identity and access policy from the optional no-CGO SQLite adapter. | +| Self-hosted by default | No Redis, message broker, hosted identity provider, telemetry service, or JavaScript framework is required. | + +## Start with one boundary + +| Application need | Begin with | +| --- | --- | +| Request IDs and trustworthy client addresses | [`requestmeta`](requestmeta) | +| Bounded structured request evidence | [`requestmeta`](requestmeta) + [`requestlog`](requestlog) | +| Browser and HTTP security primitives | [`websec`](websec) | +| Users, credentials, permissions, and sessions | [`auth`](auth) + [`authhttp`](authhttp) | +| Passkey-only authentication | [`authwebauthn`](authwebauthn) | +| Private SQLite persistence | [`authsqlite`](authsqlite) | +| Organizations, teams, and invitations | [`organizations`](organizations) | +| Organization-scoped roles and temporary access | [`access`](access) | +| Application-classified request abuse | [`abuse`](abuse) | +| Disposable request-log summaries | [`analytics`](analytics) | + +The [getting-started guide](docs/GETTING_STARTED.md) explains what each package +owns—and, just as importantly, what remains application policy. ## Install -Pin the preview in an application module, then import only the packages that -application needs: +Pin the preview in an application module: ```bash -go get gamertan.com/web@v0.1.0-preview.8 +go get gamertan.com/web@v0.1.0-preview.9 go mod verify ``` -An application may also name the first package it intends to adopt: +An application may name the first package it intends to adopt: ```bash -go get gamertan.com/web/requestmeta@v0.1.0-preview.8 +go get gamertan.com/web/requestmeta@v0.1.0-preview.9 ``` -The version belongs to the `gamertan.com/web` module. Go compiles and links -only the packages the application imports. See the [getting-started guide](docs/GETTING_STARTED.md) -and [module-boundary policy](docs/MODULES.md) before choosing a first slice. +The version belongs to the `gamertan.com/web` module. See the +[module-boundary policy](docs/MODULES.md) before selecting a first slice. -Canonical source, issues, security policy, and release notes live on -[Gamertan Gitea](https://gitea.speelman.ca/gamertan/web). GitHub is a read-only -discovery snapshot rather than a second release origin. +## Compose a request path -Linux is the required and supported release platform. WSL may be used as a -Linux development environment. Native Windows is not a release gate or support -promise; downstream users may evaluate the ordinary Go packages elsewhere -without turning that portability into a maintained compatibility claim. +Build middleware from the application outward. The request metadata resolver +is outermost so every package inside it observes the same request identity: -## Packages +```text +request + └─ requestmeta ─ websec ─ requestlog ─ your router and handlers +``` -- [`requestmeta`](requestmeta): trusted-proxy resolution, HTTPS/origin metadata, - and request IDs. -- [`requestlog`](requestlog): bounded versioned records, middleware, sinks, and - private JSONL. -- [`websec`](websec): headers, origin checks, CSRF, redirects, body limits, and - rate limits. -- [`abuse`](abuse): application-classified request abuse with pluggable persistence. -- [`auth`](auth), [`authhttp`](authhttp), and [`authsqlite`](authsqlite): - passwords, forced first-login rotation, local administrative recovery, - session revocation, platform-level permissions, cookies, and a no-CGO SQLite - adapter. -- [`authwebauthn`](authwebauthn): passkey-only registration, discoverable - login, fresh-operation approval, local recovery tokens, and an ES256-first - WebAuthn policy. See the [passkey integration guide](docs/PASSKEYS.md). -- [`organizations`](organizations) and [`access`](access): organizations, - teams, invitations, resource hierarchy, scoped roles, and audited temporary - access without turning platform operation into tenant-data access. -- [`analytics`](analytics): safe and sensitive aggregate projections over request - records. +```go +var handler http.Handler = router +handler = requestlog.Middleware(sink, logPolicy)(handler) +handler = websec.Headers(headerPolicy)(handler) +handler = resolver.Middleware(handler) +``` -The copyable starter under `starters/basic` demonstrates the packages without -turning them into a router or template system. +The copyable [`starters/basic`](starters/basic) server demonstrates that +composition with loopback binding, graceful shutdown, and optional private +JSONL logging. + +## Identity and access + +- [`auth`](auth) defines storage-neutral users, password credentials, opaque + sessions, platform permissions, and audit events. +- [`authhttp`](authhttp) connects those sessions to secure browser cookies and + request context without owning login routes or pages. +- [`authwebauthn`](authwebauthn) provides discoverable passkey login, + passkey-only enrollment, fresh-operation approval, and bounded recovery. +- [`organizations`](organizations) and [`access`](access) keep platform + operation separate from organization-data authority while supporting teams, + invitations, scoped roles, and audited temporary access. + +See the [passkey integration guide](docs/PASSKEYS.md) and +[organization/access model](docs/ORGANIZATIONS.md) before exposing account or +administration routes. + +## Security and assurance + +Client addresses are accepted from forwarding headers only when the immediate +peer and every skipped proxy are explicitly trusted. Sensitive request fields +are off by default. Cryptographic entropy failures fail closed. Logs and +account databases remain private application data and never belong in source +releases. + +Every change is checked with formatting, tests, the race detector, vet, +dependency policy, licence policy, public-snapshot allowlisting, and a +reproducible starter build. Scheduled assurance adds vulnerability scanning and +bounded fuzz campaigns. + +Read [SECURITY.md](SECURITY.md), the [threat model](docs/THREAT_MODEL.md), +[adoption contract](docs/ADOPTION.md), and +[dependency boundary](docs/DEPENDENCIES.md) before production adoption. ## HTML and templates Web Foundations deliberately does not provide a template language. Sandwich Hime is the preferred companion for Gamertan applications that want HTML-first, -typed, ahead-of-time Go templates. The two projects remain independently -usable: this module does not import the `sando` runtime, and Sandwich Hime does -not own middleware, authentication, logging, routing, or deployment. +typed, ahead-of-time Go templates. The projects remain independently usable. -See [HTML with Sandwich Hime](docs/SANDWICH_HIME.md), then follow the official -[first site tutorial](https://sandwichhime.com/docs/tutorial/) and -[application integration tutorial](https://sandwichhime.com/docs/tutorial/application/). +See [HTML with Sandwich Hime](docs/SANDWICH_HIME.md) and the official +[first-site tutorial](https://sandwichhime.com/docs/tutorial/). -## Security boundary +## Source, support, and licensing -Client addresses are accepted from forwarding headers only when the immediate -peer and every skipped proxy are explicitly trusted. Sensitive request fields -are off by default. Cryptographic entropy failures fail closed. Logs and account -databases remain private application data and never belong in source releases. +Canonical source, issues, security policy, and release notes live on +[Speelman Forge](https://gitea.speelman.ca/gamertan/web). GitHub is a read-only +discovery snapshot rather than a second release origin. -See [SECURITY.md](SECURITY.md), [docs/THREAT_MODEL.md](docs/THREAT_MODEL.md), -the [application adoption contract](docs/ADOPTION.md), and -[docs/SERVICES_ROADMAP.md](docs/SERVICES_ROADMAP.md). - -## Licensing - -This is a multi-license repository with exact file-level SPDX identifiers: - -- embeddable packages and adapters: MPL-2.0; -- future standalone network services and operational machinery: AGPL-3.0-only; -- starters, examples, and reusable configuration: 0BSD. - -See [LICENSES.md](LICENSES.md). No standalone auth or logging server is included -in this preview. +The libraries and adapters are MPL-2.0. Starters and reusable examples are +0BSD. Future standalone services and operational machinery are +AGPL-3.0-only. Exact file-level SPDX identifiers remain authoritative; see the +[licensing map](LICENSES.md) and [third-party notices](THIRD_PARTY_NOTICES.md). diff --git a/doc.go b/doc.go new file mode 100644 index 0000000..4280174 --- /dev/null +++ b/doc.go @@ -0,0 +1,65 @@ +// SPDX-License-Identifier: MPL-2.0 + +// Package web is the documentation root for Gamertan Web Foundations. +// +// Web Foundations is a collection of small, composable Go packages for the +// security-sensitive edges of a web application: request identity, structured +// request evidence, browser security, authentication, passkeys, permissions, +// organizations, SQLite persistence, abuse controls, and private analytics. +// +// It is a toolkit rather than an application framework. Applications keep +// their router, handlers, HTML, authorization decisions, deployment, and +// operational policy. Packages use net/http and can be adopted independently. +// No Redis, message broker, hosted identity provider, telemetry service, or +// JavaScript framework is required. +// +// # Choose a first boundary +// +// Start with the smallest package that owns the boundary you need: +// +// - [requestmeta] resolves request IDs, client addresses, and trusted-proxy +// metadata once for downstream security and logging. +// - [requestlog] records bounded, versioned request observations with +// sensitive fields disabled by default. +// - [websec] supplies HTTP headers, same-origin checks, CSRF protection, +// redirects, body limits, and rate limits. +// - [auth], [authhttp], [authwebauthn], and [authsqlite] provide +// storage-neutral identity, secure browser sessions, passkeys, and an +// optional no-CGO SQLite adapter. +// - [organizations] and [access] model organizations, teams, invitations, +// scoped roles, and audited temporary access. +// - [abuse] applies application-classified request-abuse decisions. +// - [analytics] creates bounded, disposable projections from requestlog +// records without becoming a telemetry service. +// +// # Compose with net/http +// +// Middleware is wrapped from the application outward. A request metadata +// resolver should be outermost so packages inside it agree about request +// identity. The package example shows a complete, executable composition. +// A copyable server with graceful shutdown and optional private JSONL logging +// is available in the repository's starters/basic directory. +// +// # Security model +// +// Untrusted values are bounded before storage or aggregation. Forwarding +// headers affect identity only through explicitly trusted proxies. Sensitive +// request fields require field-by-field opt-in. Security-relevant +// configuration and persistence failures fail closed rather than silently +// weakening policy. +// +// This root package intentionally exports no runtime API. Applications import +// only the subpackages they use. +// +// [abuse]: https://pkg.go.dev/gamertan.com/web/abuse +// [access]: https://pkg.go.dev/gamertan.com/web/access +// [analytics]: https://pkg.go.dev/gamertan.com/web/analytics +// [auth]: https://pkg.go.dev/gamertan.com/web/auth +// [authhttp]: https://pkg.go.dev/gamertan.com/web/authhttp +// [authsqlite]: https://pkg.go.dev/gamertan.com/web/authsqlite +// [authwebauthn]: https://pkg.go.dev/gamertan.com/web/authwebauthn +// [organizations]: https://pkg.go.dev/gamertan.com/web/organizations +// [requestlog]: https://pkg.go.dev/gamertan.com/web/requestlog +// [requestmeta]: https://pkg.go.dev/gamertan.com/web/requestmeta +// [websec]: https://pkg.go.dev/gamertan.com/web/websec +package web diff --git a/docs/GETTING_STARTED.md b/docs/GETTING_STARTED.md index fff63b4..b375399 100644 --- a/docs/GETTING_STARTED.md +++ b/docs/GETTING_STARTED.md @@ -25,7 +25,7 @@ The packages are ordinary Go imports. Pin the current preview and verify its module checksum: ```bash -go get gamertan.com/web/requestmeta@v0.1.0-preview.6 +go get gamertan.com/web/requestmeta@v0.1.0-preview.9 go mod verify ``` diff --git a/docs/MODULES.md b/docs/MODULES.md index ba0fc49..b98022f 100644 --- a/docs/MODULES.md +++ b/docs/MODULES.md @@ -18,7 +18,7 @@ import "gamertan.com/web/requestmeta" and request the containing module at an exact version: ```bash -go get gamertan.com/web/requestmeta@v0.1.0-preview.6 +go get gamertan.com/web/requestmeta@v0.1.0-preview.9 ``` Only imported packages are compiled and linked. The packages nevertheless diff --git a/example_test.go b/example_test.go new file mode 100644 index 0000000..8a3d20f --- /dev/null +++ b/example_test.go @@ -0,0 +1,51 @@ +// SPDX-License-Identifier: MPL-2.0 + +package web_test + +import ( + "fmt" + "net/http" + "net/http/httptest" + + "gamertan.com/web/requestlog" + "gamertan.com/web/requestmeta" + "gamertan.com/web/websec" +) + +func Example() { + resolver, err := requestmeta.New(requestmeta.Config{}) + if err != nil { + panic(err) + } + + router := http.NewServeMux() + router.HandleFunc("GET /", func(response http.ResponseWriter, _ *http.Request) { + response.WriteHeader(http.StatusNoContent) + }) + + var handler http.Handler = router + handler = requestlog.Middleware(nil, requestlog.Policy{ + Route: func(*http.Request) string { return "home" }, + })(handler) + handler = websec.Headers(func(*http.Request) websec.HeaderPolicy { + return websec.HeaderPolicy{ + ContentSecurityPolicy: "default-src 'none'; frame-ancestors 'none'", + ReferrerPolicy: "no-referrer", + FrameOptions: "DENY", + } + })(handler) + handler = resolver.Middleware(handler) + + request := httptest.NewRequest(http.MethodGet, "https://example.test/", nil) + request.RemoteAddr = "192.0.2.10:43120" + response := httptest.NewRecorder() + handler.ServeHTTP(response, request) + + fmt.Println(response.Code) + fmt.Println(response.Header().Get("X-Request-ID") != "") + fmt.Println(response.Header().Get("X-Content-Type-Options")) + // Output: + // 204 + // true + // nosniff +} diff --git a/scripts/public-snapshot.allow b/scripts/public-snapshot.allow index 2f453f1..e473d29 100644 --- a/scripts/public-snapshot.allow +++ b/scripts/public-snapshot.allow @@ -6,6 +6,7 @@ .gitignore CHANGELOG.md CONTRIBUTING.md +LICENSE LICENSES.md LICENSES/0BSD.txt LICENSES/AGPL-3.0-only.txt @@ -53,6 +54,8 @@ docs/PUBLIC_SNAPSHOT.md docs/SANDWICH_HIME.md docs/SERVICES_ROADMAP.md docs/THREAT_MODEL.md +doc.go +example_test.go go.mod go.sum requestlog/jsonl.go