Renamed the Web package as Infrastructure (#25)
This PR contains the work done to rename the _Web_ package as _Infrastructure_, to provide a clear naming and purpose to this particular package within the project. To provide further details about the work: * Infrastructure * Asset fingerprinting: an FNV-1a token derived from the static files directory, appended as ?v= to asset URLs so deploys bust caches; pre-rendered pages also revalidate via weak ETags. * New middlewares: fixed-window RateLimitMiddleware (per-client budgets keyed by trusted X-Forwarded-For or remote address) and VaryMiddleware (Accept-Encoding on every response); SecurityHeadersMiddleware now also stamps error responses. * Auto-generated HEAD endpoints, cache max-age configuration, and Docker build/Compose refinements. * Protocols and scaffolding: Asset/AssetExtension, the Page protocol (viewport, stylesheets, scripts, versioned URLs), and LocalizedRequestContext. * Rate limiter's counter store swapped from an actor to a Mutex (no executor hop per request) with amortized batch eviction instead of O(n²) scans under client floods. * FingerprintAssets reports unreadable files to a logger instead of silently producing a token that never busts their cache. Reviewed-on: rock-n-code/loud-amsterdam#25 Co-authored-by: Javier Cicchelli <javier@rock-n-code.com> Co-committed-by: Javier Cicchelli <javier@rock-n-code.com>
This commit is contained in:
@@ -0,0 +1,47 @@
|
||||
import Foundation
|
||||
|
||||
/// Hashes bytes with the FNV-1a 64-bit algorithm.
|
||||
///
|
||||
/// The hash is stable across processes and platforms, which `Hasher` deliberately is not, so it
|
||||
/// suits values that must agree between instances and survive restarts: the asset version token
|
||||
/// (``FingerprintAssets``) and the entity tags of the pre-rendered pages (`CachedHTMLResponse`).
|
||||
/// It is not cryptographic — a collision only risks serving a stale cached asset, not security.
|
||||
struct FNV1aHash {
|
||||
|
||||
// MARK: Properties
|
||||
|
||||
/// The running hash value.
|
||||
private var hash: UInt64
|
||||
|
||||
// MARK: Initializers
|
||||
|
||||
/// Creates a hasher at the FNV-1a offset basis.
|
||||
init() {
|
||||
self.hash = 0xcbf2_9ce4_8422_2325
|
||||
}
|
||||
|
||||
// MARK: Computed
|
||||
|
||||
/// The hash of everything combined so far, as a fixed-width, 16-character hexadecimal token.
|
||||
///
|
||||
/// Reading it does not consume the running hash: more bytes can be combined afterwards.
|
||||
var digest: String {
|
||||
String(
|
||||
format: "%016llx",
|
||||
hash
|
||||
)
|
||||
}
|
||||
|
||||
// MARK: Functions
|
||||
|
||||
/// Folds the given bytes into the hash.
|
||||
/// - Parameter bytes: the bytes to fold in.
|
||||
mutating func combine(
|
||||
_ bytes: some Sequence<UInt8>
|
||||
) {
|
||||
for byte in bytes {
|
||||
hash = (hash ^ UInt64(byte)) &* 0x100_0000_01b3
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
Reference in New Issue
Block a user