mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
* refactor: Extract shared cooldown helpers to package-level functions * feat: Add PyPI cooldown handler with PEP 691 file parsing * feat: Add PyPI cooldown file stripping logic * feat: Implement PyPI cooldown HandleMetadataRequest with PEP 691 filtering * feat: Wire PyPI cooldown into pypi_registry interceptor * update headers for no cache * fix: Strip conditional GET headers to prevent 304 bypass in cooldown handlers pip and npm clients cache Simple API / registry responses with ETags. On subsequent requests they send If-None-Match, which causes the server to return 304 Not Modified with no body. The cooldown response modifier received an empty body, failed to parse it, and failed-open — letting the client use its stale cached (unfiltered) response. Fix: delete If-None-Match and If-Modified-Since from the request before forwarding, forcing a full 200 response so the modifier always has a body to filter. Also removes the Content-Type guard from the PyPI modifier (the empty Content-Type on 304 responses was a symptom of the same root cause) and replaces Cache-Control: no-cache with the more targeted header deletion. * docs: Add PyPI cooldown limitation for pip < 22.3 to dependency-cooldown docs
49 lines
1.5 KiB
Go
49 lines
1.5 KiB
Go
package interceptors
|
|
|
|
import "time"
|
|
|
|
// cooldownIsWithinWindow reports whether a version published at publishDate is still
|
|
// within the cooldown window of cooldownDays. Returns withinCooldown, daysSincePublish,
|
|
// and daysRemaining.
|
|
func cooldownIsWithinWindow(publishDate time.Time, cooldownDays int) (withinCooldown bool, daysSincePublish int, daysRemaining int) {
|
|
daysSincePublish = int(time.Since(publishDate).Hours() / 24)
|
|
if daysSincePublish < 0 {
|
|
daysSincePublish = 0
|
|
}
|
|
daysRemaining = cooldownDays - daysSincePublish
|
|
if daysRemaining < 0 {
|
|
daysRemaining = 0
|
|
}
|
|
return daysSincePublish < cooldownDays, daysSincePublish, daysRemaining
|
|
}
|
|
|
|
// cooldownOldestVersion returns the version with the earliest publish date.
|
|
// When all versions are in cooldown, this is the one closest to exiting the window.
|
|
func cooldownOldestVersion(dates map[string]time.Time) (string, time.Time) {
|
|
var oldest string
|
|
var oldestTime time.Time
|
|
for version, publishDate := range dates {
|
|
if oldestTime.IsZero() || publishDate.Before(oldestTime) {
|
|
oldest = version
|
|
oldestTime = publishDate
|
|
}
|
|
}
|
|
return oldest, oldestTime
|
|
}
|
|
|
|
// cooldownLatestEligibleVersion returns the most recently published version not in tooNew.
|
|
func cooldownLatestEligibleVersion(dates map[string]time.Time, tooNew map[string]bool) string {
|
|
var latest string
|
|
var latestTime time.Time
|
|
for version, publishDate := range dates {
|
|
if tooNew[version] {
|
|
continue
|
|
}
|
|
if publishDate.After(latestTime) {
|
|
latest = version
|
|
latestTime = publishDate
|
|
}
|
|
}
|
|
return latest
|
|
}
|