Documentation
¶
Overview ¶
Package scopedhttps constructs HTTPS clients confined to explicitly approved private-network endpoints.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func NewClient ¶
NewClient constructs an HTTPS-only client restricted to endpoints, one scoped connection-pool lifecycle for every endpoint in endpointCAs. Each endpoint must resolve to a private address at construction and at every dial. endpointCAs maps each approved HTTPS endpoint URL to the exact CA PEM bundle trusted for THAT endpoint's own host:port authority -- never a shared/unioned pool, and never merged with a DIFFERENT authority that happens to share a hostname on another port. Two endpoints on different authorities, each supplying its own CA, are kept isolated: a certificate presented for authority B is verified ONLY against B's own pool, never against A's, so a compromised or overly permissive CA configured for one endpoint can never authenticate a connection to another.
func NewSingleIssuerClient ¶
func NewSingleIssuerClient(ctx context.Context, endpoints []string, trustedCAPEM []byte) (*http.Client, error)
NewSingleIssuerClient is NewClient's convenience form for the common case of one issuer's own endpoints (e.g. its discovery document and JWKS URI) all trusting the SAME CA bundle.
Types ¶
This section is empty.