MCPcopy Create free account
hub / github.com/UsefulSoftwareCo/executor / guardFetch

Function guardFetch

packages/core/sdk/src/hosted-http-client.ts:222–260  ·  view source on GitHub ↗
(
  underlying: typeof globalThis.fetch,
  options: HostedHttpClientOptions,
)

Source from the content-addressed store, hash-verified

220};
221
222const guardFetch = (
223 underlying: typeof globalThis.fetch,
224 options: HostedHttpClientOptions,
225): typeof globalThis.fetch =>
226 (async (input, init) => {
227 const guardOptions = {
228 ...options,
229 resolveHostname: options.resolveHostname ?? resolveHostnameWithNodeDns,
230 };
231 const maxRedirects = options.maxRedirects ?? 10;
232 let current: Parameters<typeof globalThis.fetch>[0] | URL = input;
233 let currentInit = init;
234 for (let redirects = 0; redirects <= maxRedirects; redirects++) {
235 const url = current instanceof Request ? current.url : String(current);
236 await Effect.runPromise(validateHostedOutboundUrl(url, guardOptions));
237 const response = await underlying(current, {
238 ...currentInit,
239 redirect: "manual",
240 });
241 if (
242 response.status >= 300 &&
243 response.status < 400 &&
244 response.headers.has("location") &&
245 redirects < maxRedirects
246 ) {
247 const next = new URL(response.headers.get("location")!, url);
248 // Cross-origin redirects are followed (the loop re-validates every
249 // hop), but credentials minted for the original origin must not leak
250 // to the redirect target — same as fetch/curl behavior.
251 if (next.origin !== new URL(url).origin) {
252 currentInit = stripCredentialHeaders(currentInit);
253 }
254 current = next.toString();
255 continue;
256 }
257 return response;
258 }
259 return await underlying(current, { ...currentInit, redirect: "manual" });
260 }) as typeof globalThis.fetch;
261
262export const makeHostedFetch = (options: HostedHttpClientOptions = {}): typeof globalThis.fetch =>
263 // oxlint-disable-next-line executor/no-raw-fetch -- boundary: exposes a guarded Fetch API adapter for libraries that require fetch

Callers 2

makeHostedFetchFunction · 0.85

Calls 4

stripCredentialHeadersFunction · 0.85
toStringMethod · 0.80
getMethod · 0.65

Tested by

no test coverage detected