mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
feat: Add PyPI dependency cooldown support (#221)
* refactor: Extract shared cooldown helpers to package-level functions * feat: Add PyPI cooldown handler with PEP 691 file parsing * feat: Add PyPI cooldown file stripping logic * feat: Implement PyPI cooldown HandleMetadataRequest with PEP 691 filtering * feat: Wire PyPI cooldown into pypi_registry interceptor * update headers for no cache * fix: Strip conditional GET headers to prevent 304 bypass in cooldown handlers pip and npm clients cache Simple API / registry responses with ETags. On subsequent requests they send If-None-Match, which causes the server to return 304 Not Modified with no body. The cooldown response modifier received an empty body, failed to parse it, and failed-open — letting the client use its stale cached (unfiltered) response. Fix: delete If-None-Match and If-Modified-Since from the request before forwarding, forcing a full 200 response so the modifier always has a body to filter. Also removes the Content-Type guard from the PyPI modifier (the empty Content-Type on 304 responses was a symptom of the same root cause) and replaces Cache-Control: no-cache with the more targeted header deletion. * docs: Add PyPI cooldown limitation for pip < 22.3 to dependency-cooldown docs
This commit is contained in:
@@ -0,0 +1,48 @@
|
||||
package interceptors
|
||||
|
||||
import "time"
|
||||
|
||||
// cooldownIsWithinWindow reports whether a version published at publishDate is still
|
||||
// within the cooldown window of cooldownDays. Returns withinCooldown, daysSincePublish,
|
||||
// and daysRemaining.
|
||||
func cooldownIsWithinWindow(publishDate time.Time, cooldownDays int) (withinCooldown bool, daysSincePublish int, daysRemaining int) {
|
||||
daysSincePublish = int(time.Since(publishDate).Hours() / 24)
|
||||
if daysSincePublish < 0 {
|
||||
daysSincePublish = 0
|
||||
}
|
||||
daysRemaining = cooldownDays - daysSincePublish
|
||||
if daysRemaining < 0 {
|
||||
daysRemaining = 0
|
||||
}
|
||||
return daysSincePublish < cooldownDays, daysSincePublish, daysRemaining
|
||||
}
|
||||
|
||||
// cooldownOldestVersion returns the version with the earliest publish date.
|
||||
// When all versions are in cooldown, this is the one closest to exiting the window.
|
||||
func cooldownOldestVersion(dates map[string]time.Time) (string, time.Time) {
|
||||
var oldest string
|
||||
var oldestTime time.Time
|
||||
for version, publishDate := range dates {
|
||||
if oldestTime.IsZero() || publishDate.Before(oldestTime) {
|
||||
oldest = version
|
||||
oldestTime = publishDate
|
||||
}
|
||||
}
|
||||
return oldest, oldestTime
|
||||
}
|
||||
|
||||
// cooldownLatestEligibleVersion returns the most recently published version not in tooNew.
|
||||
func cooldownLatestEligibleVersion(dates map[string]time.Time, tooNew map[string]bool) string {
|
||||
var latest string
|
||||
var latestTime time.Time
|
||||
for version, publishDate := range dates {
|
||||
if tooNew[version] {
|
||||
continue
|
||||
}
|
||||
if publishDate.After(latestTime) {
|
||||
latest = version
|
||||
latestTime = publishDate
|
||||
}
|
||||
}
|
||||
return latest
|
||||
}
|
||||
Reference in New Issue
Block a user