Class: Portage::Ucp::Rack::ManifestEndpoint

Inherits:
Object
  • Object
show all
Defined in:
lib/portage/ucp/rack/manifest_endpoint.rb

Overview

Rack app serving GET /.well-known/ucp — the signed UCP discovery document. Mount it however suits the consumer's app (in-process or standalone, §7.3); this gem makes no assumption about host framework or process model.

Instance Method Summary collapse

Constructor Details

#initialize(manifest:, allow_insecure: false) ⇒ ManifestEndpoint

Returns a new instance of ManifestEndpoint.

Parameters:

  • allow_insecure (Boolean) (defaults to: false) —

    TLS termination is the consumer's job (§9), so by default this refuses to serve payment-handler declarations over plaintext HTTP rather than silently leaking them. Set true only for local development over http://localhost.



15
16
17
18
# File 'lib/portage/ucp/rack/manifest_endpoint.rb', line 15

def initialize(manifest:, allow_insecure: false)
  @manifest = manifest
  @allow_insecure = allow_insecure
end

Instance Method Details

#call(env) ⇒ Object



20
21
22
23
24
25
26
27
28
# File 'lib/portage/ucp/rack/manifest_endpoint.rb', line 20

def call(env)
  request = ::Rack::Request.new(env)
  return not_found unless request.get?

  payload = @manifest.to_h
  return insecure_rejected if payment_handlers_over_plaintext?(payload, request)

  [200, { "content-type" => "application/json" }, [JSON.generate(payload)]]
end