Add cargo sparse registry remote type #132

Merged
benvin merged 1 commits from benvin/remote-cargo into master 2026-10-09 21:44:18 +11:00
Member

Rust crate builds (rpmbuilder CI) fetch from crates.io directly because artifactapi has no Cargo remote type.

  • add cargo package type proxying the sparse registry protocol (RFC 2789)
  • synthesize config.json so dl points crate downloads back at the remote
  • treat index files as mutable and crates/*/*.crate as immutable, fetched from static.crates.io for crates.io
  • add a ~/.cargo/config.toml usage snippet to the UI and a cargo e2e caching case
Rust crate builds (rpmbuilder CI) fetch from crates.io directly because artifactapi has no Cargo remote type. - add `cargo` package type proxying the sparse registry protocol (RFC 2789) - synthesize `config.json` so `dl` points crate downloads back at the remote - treat index files as mutable and `crates/*/*.crate` as immutable, fetched from static.crates.io for crates.io - add a `~/.cargo/config.toml` usage snippet to the UI and a cargo e2e caching case
unkin-agent added 1 commit 2026-10-09 19:35:15 +11:00
Add cargo sparse registry remote type
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
66da315cd9
Author
Member
  • nit: internal/provider/cargo/cargo.go:75 — config.json is built from r.Host / X-Forwarded-Proto (proxy.go:89, shared with other providers); a client can only poison its own response, but with no TLS-terminator header dl becomes http:// → set Cache-Control: no-store on this response, and document that the ingress must send X-Forwarded-Proto.
  • nit: internal/provider/cargo/cargo.go:37 — crates/../x.crate is classified Immutable and, on crates.io, rerouted to static.crates.io with .. unsanitised (engine does no path cleaning) → reject paths containing .. segments in isCrate/UpstreamURL, with a test.
  • nit: internal/api/v1/proxy.go:handleProxyHead — HEAD config.json skips ServeRemote and hits upstream config.json (dl points at static.crates.io) → low risk, but either call ServeRemote on HEAD or note it.
  • nit: ui/src/components/UsageInstructions.tsx (cargo case) — shown for local repos too, but locals have no cargo support → guard with !isLocal or drop the Locals.tsx colour entry.
- nit: internal/provider/cargo/cargo.go:75 — config.json is built from r.Host / X-Forwarded-Proto (proxy.go:89, shared with other providers); a client can only poison its own response, but with no TLS-terminator header `dl` becomes http:// → set `Cache-Control: no-store` on this response, and document that the ingress must send X-Forwarded-Proto. - nit: internal/provider/cargo/cargo.go:37 — `crates/../x.crate` is classified Immutable and, on crates.io, rerouted to static.crates.io with `..` unsanitised (engine does no path cleaning) → reject paths containing `..` segments in isCrate/UpstreamURL, with a test. - nit: internal/api/v1/proxy.go:handleProxyHead — HEAD config.json skips ServeRemote and hits upstream config.json (dl points at static.crates.io) → low risk, but either call ServeRemote on HEAD or note it. - nit: ui/src/components/UsageInstructions.tsx (cargo case) — shown for local repos too, but locals have no cargo support → guard with !isLocal or drop the Locals.tsx colour entry.
benvin merged commit 80368986bb into master 2026-10-09 21:44:18 +11:00
benvin deleted branch benvin/remote-cargo 2026-10-09 21:44:20 +11:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unkin/artifactapi#132