This PR contains the work done to rename the _Web_ package as _Infrastructure_, to provide a clear naming and purpose to this particular package within the project. To provide further details about the work: * Infrastructure * Asset fingerprinting: an FNV-1a token derived from the static files directory, appended as ?v= to asset URLs so deploys bust caches; pre-rendered pages also revalidate via weak ETags. * New middlewares: fixed-window RateLimitMiddleware (per-client budgets keyed by trusted X-Forwarded-For or remote address) and VaryMiddleware (Accept-Encoding on every response); SecurityHeadersMiddleware now also stamps error responses. * Auto-generated HEAD endpoints, cache max-age configuration, and Docker build/Compose refinements. * Protocols and scaffolding: Asset/AssetExtension, the Page protocol (viewport, stylesheets, scripts, versioned URLs), and LocalizedRequestContext. * Rate limiter's counter store swapped from an actor to a Mutex (no executor hop per request) with amortized batch eviction instead of O(n²) scans under client floods. * FingerprintAssets reports unreadable files to a logger instead of silently producing a token that never busts their cache. Reviewed-on: rock-n-code/loud-amsterdam#25 Co-authored-by: Javier Cicchelli <javier@rock-n-code.com> Co-committed-by: Javier Cicchelli <javier@rock-n-code.com>
85 lines
5.1 KiB
Swift
85 lines
5.1 KiB
Swift
import Configuration
|
|
|
|
extension ConfigKey {
|
|
/// A namespace for the static files cache configuration keys.
|
|
public enum Cache {
|
|
/// The configuration key for the max-age, in seconds, applied to fingerprinted assets (CSS, JavaScript) and fonts.
|
|
public static let maxAgeAsset: ConfigKey = "cache.maxAge.asset"
|
|
/// The configuration key for the max-age, in seconds, applied to unversioned text-based static files (e.g. plain text).
|
|
public static let maxAgeText: ConfigKey = "cache.maxAge.text"
|
|
/// The configuration key for the max-age, in seconds, applied to image static files (ICO, PNG, SVG).
|
|
public static let maxAgeImage: ConfigKey = "cache.maxAge.image"
|
|
/// The configuration key for the max-age, in seconds, applied to all other static files (e.g. the web manifest).
|
|
public static let maxAgeDefault: ConfigKey = "cache.maxAge.default"
|
|
}
|
|
/// A namespace for the response compression configuration keys.
|
|
public enum Compression {
|
|
/// The configuration key for the minimum response body size, in bytes, before compression is applied.
|
|
public static let minResponseSize: ConfigKey = "compression.minimumResponseSize"
|
|
}
|
|
/// A namespace for the persistence configuration keys.
|
|
public enum Database {
|
|
/// The configuration key selecting migrate-and-exit mode (run migrations, then exit) instead of serving.
|
|
public static let migrate: ConfigKey = "database.migrate"
|
|
/// The configuration key for the persistence driver (`inMemory` or `mysql`).
|
|
public static let driver: ConfigKey = "database.driver"
|
|
/// The configuration key for the MySQL/MariaDB host.
|
|
public static let host: ConfigKey = "database.host"
|
|
/// The configuration key for the MySQL/MariaDB port.
|
|
public static let port: ConfigKey = "database.port"
|
|
/// The configuration key for the database name.
|
|
public static let name: ConfigKey = "database.name"
|
|
/// The configuration key for the database username.
|
|
public static let username: ConfigKey = "database.username"
|
|
/// The configuration key for the database password.
|
|
public static let password: ConfigKey = "database.password"
|
|
/// The configuration key for the TLS posture used when connecting (`off`, `prefer`, or `require`).
|
|
public static let tls: ConfigKey = "database.tls"
|
|
/// The configuration key for the maximum pooled connections per event loop.
|
|
public static let poolMaxPerEventLoop: ConfigKey = "database.pool.maxPerEventLoop"
|
|
}
|
|
/// A namespace for the HTTP server configuration keys.
|
|
public enum HTTP {
|
|
/// The configuration key for the host the server binds to.
|
|
public static let host: ConfigKey = "http.host"
|
|
/// The configuration key for the port the server listens on.
|
|
public static let port: ConfigKey = "http.port"
|
|
/// The configuration key for the server's name.
|
|
public static let serverName: ConfigKey = "http.serverName"
|
|
}
|
|
/// A namespace for the logging configuration keys.
|
|
public enum Log {
|
|
/// The configuration key for the minimum log level.
|
|
public static let level: ConfigKey = "log.level"
|
|
}
|
|
/// A namespace for the rate limit configuration keys.
|
|
public enum RateLimit {
|
|
/// The configuration key for the number of requests admitted per client per window.
|
|
public static let limit: ConfigKey = "rateLimit.limit"
|
|
/// The configuration key for the window length, in seconds.
|
|
public static let window: ConfigKey = "rateLimit.window"
|
|
/// The configuration key for keying clients by the first `X-Forwarded-For` entry (enable only behind a trusted proxy).
|
|
public static let trustForwardedFor: ConfigKey = "rateLimit.trustForwardedFor"
|
|
}
|
|
/// A namespace for the path configuration keys.
|
|
public enum Path {
|
|
/// The configuration key for the directory the static files are served from.
|
|
public static let staticFiles: ConfigKey = "path.staticFiles"
|
|
}
|
|
/// A namespace for the security headers configuration keys.
|
|
public enum Security {
|
|
/// The configuration key for the `Content-Security-Policy` header value.
|
|
public static let contentSecurityPolicy: ConfigKey = "security.contentSecurityPolicy"
|
|
/// The configuration key for the `X-Content-Type-Options` header value.
|
|
public static let contentTypeOptions: ConfigKey = "security.contentTypeOptions"
|
|
/// The configuration key for the `X-Frame-Options` header value.
|
|
public static let frameOptions: ConfigKey = "security.frameOptions"
|
|
/// The configuration key for the `Referrer-Policy` header value.
|
|
public static let referrerPolicy: ConfigKey = "security.referrerPolicy"
|
|
/// The configuration key for the `Permissions-Policy` header value.
|
|
public static let permissionsPolicy: ConfigKey = "security.permissionsPolicy"
|
|
/// The configuration key for the `Strict-Transport-Security` header value (omitted when unset).
|
|
public static let strictTransportSecurity: ConfigKey = "security.strictTransportSecurity"
|
|
}
|
|
}
|