Files
container/Sources/Services/ContainerAPIService/Client/RequestScheme.swift
T
Noah Thornton e3c49803a0 Move to TOML configuration for defaults (#1425)
- Discussion topic #1336.
- This change migrates away from using `UserDefaults`,
  instead providing a TOML configuration mechanism for
  user configurable settings. All existing system property
  settings keys are supported in the new configuration
  file. However, users will have to migrate any settings
  they have configured in the `UserDefaults` into TOML
  for these settings to take effect.
- Breaking changes:
  * `container system property get` is removed in favor of
    users directly utilizing `container system property list --format toml | jq<>`.
  * `container system property set` is removed since the TOML
    configuration is effectively immutable during the lifetime of the
    `container` daemon. Uses can edit the TOML they have in their home
    directory, however no changes will take effect until the daemon is
    restarted via `container system stop && container system start`
* `container system property list --format table` is removed as
    generating tabular format is non-trivial and the new TOML format is
    intended to be human readable
2026-05-04 12:04:24 -07:00

98 lines
3.4 KiB
Swift

//===----------------------------------------------------------------------===//
// Copyright © 2026 Apple Inc. and the container project authors.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// https://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
//===----------------------------------------------------------------------===//
import ContainerizationError
import ContainerizationExtras
/// The URL scheme to be used for a HTTP request.
public enum RequestScheme: String, Sendable {
private static let defaultDomain = "test"
case http = "http"
case https = "https"
case auto = "auto"
public init(_ rawValue: String) throws {
switch rawValue {
case RequestScheme.http.rawValue:
self = .http
case RequestScheme.https.rawValue:
self = .https
case RequestScheme.auto.rawValue:
self = .auto
default:
throw ContainerizationError(.invalidArgument, message: "unsupported scheme \(rawValue)")
}
}
/// Returns the prescribed protocol to use while making a HTTP request to a webserver
/// - Parameter host: The domain or IP address of the webserver
/// - Parameter internalDnsDomain: The DNS domain used for container name resolution
/// - Returns: RequestScheme
public func schemeFor(host: String, internalDnsDomain: String?) throws -> Self {
guard host.count > 0 else {
throw ContainerizationError(.invalidArgument, message: "host cannot be empty")
}
switch self {
case .http, .https:
return self
case .auto:
return Self.isInternalHost(host: host, internalDnsDomain: internalDnsDomain) ? .http : .https
}
}
/// Checks if the given `host` string is a private IP address
/// or a domain typically reachable only on the local system.
public static func isInternalHost(host: String, internalDnsDomain: String?) -> Bool {
// The localhost hostname is private.
if host == "localhost" {
return true
}
// If hostname uses the provided DNS domain, treat it as private.
if let internalDnsDomain {
if host.hasSuffix(".\(internalDnsDomain)") {
return true
}
}
// If it's any other hostname and not an IP address, it's not private access.
guard let ipv4Address = try? IPv4Address(host) else {
return false
}
let ipv4Value = ipv4Address.value
// 10.0.0.0/8 and 127.0.0.0/8 are private CIDRs.
if (ipv4Value & 0xff00_0000 == 0x0a00_0000) || (ipv4Value & 0xff00_0000 == 0x7f00_0000) {
return true
}
// 192.168.0.0/16 is a private CIDR.
if ipv4Value & 0xffff_0000 == 0xc0a8_0000 {
return true
}
// 172.16.0.0/12 is a private CIDR.
if ipv4Value & 0xfff0_0000 == 0xac10_0000 {
return true
}
return false
}
}