Decides the BasicHTTP location and its front (ADR-0002 Amendment) - #137
Merged
Merged
Conversation
Adds an Amendment at proposed to ADR-0002: a durable execution's BasicHTTP location is a 256-bit token the router mints and stores in a new locations table (V04), one per address row; rotate_location/2 replaces it and the old token answers 404; the front resolves a token to its address row and delivers through Delivery.deliver_event/4 under the name basichttp, deduplicating on the scxml-send-key header per execution; a router-owned processor writes base_url/token into _ioprocessors from a per-create registration option. A location is a bearer capability. No route rule changes. Refs: sr-xgi8
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds an Amendment at
proposedto ADR-0002 (addressing) that decides where a durable execution's BasicHTTP location comes from and what the front that answers at it does. It is the record half of sr-xgi8. This repo's rule is that the record merges before the code, so this PR carries the record alone. The code PR comes later and cites it.The location's shape and the front's authentication were ruled by the operator, 2026-09-30: an unguessable, rotatable per-execution token minted by the router, never the bare execution id; the front authenticates nothing beyond possession; a location is a bearer capability. The rest is decided by this Amendment:
locationstable created byStatifierRouter.Migrations.V04, keyed by the address row withON DELETE CASCADEand unique on the token. It is minted on the:if_absentinsert that wins, and only when the new:basichttpkey is set. Analways_newexecution has no location. The token is a table and not a column, so a host that does not use BasicHTTP needs no migration.StatifierRouter.BasicHTTP.rotate_location/2replaces the token, after which the old one answers 404. The execution's own_ioprocessorsentry is written once, at start, by statifier, so it keeps the old location. The record says so plainly.StatifierRouter.Delivery.deliver_event/4under the plan namebasichttpwithcreate: :never. This is never a route: ADR-0005 decision 1 is unchanged, and a URL in a route target stays refused.basichttpis reserved as a binding id only on a configuration that sets the new key.StatifierRouter.BasicHTTPis a router-owned processor whoseioprocessors_entry/2buildsbase_url/tokenfrom a per-create registration option. It handsdeliver/3,cancel/2andperform/2toStatifier.Send.BasicHTTPunchanged. It uses statifier 2.10.0's public API only.StatifierRouter.BasicHTTP.Front.handle/3andresponse/1, Plug-shaped with no process. Deduplication is per execution on thescxml-send-keyheader. The status table is 204 / 404 / 405 / 400 / 500.Gate. This is a docs-only change under
docs/adr/. It touches no gated path (lib/,test/,config/,mix.exs,mix.lock,corpus/,README.md), so there is no local gate to run. CI runs regardless. No changelog fragment: ADRs are onchangelog.d/README.md's "do not" side.Direction check (in-turn). Every claim about code was verified at
bb292c8onmain:StatifierRouter.Delivery's privatecreate_options/1andinsert_or_existing/4, and the moduledoc's statement thatdeliver_event/4does not takedropped: unmatched_eventStatifierRouter.Config.new/1's refusal of unknown keysStatifierRouter.Addresses.by_execution/2StatifierRouter.Schema.Addressstatifier claims were verified at its
v2.10.0tag:Statifier.Send.BasicHTTP.ioprocessors_entry/2anddecode/1's request keysStatifier.Evaluator.SystemVariablesmoduledoc's "once, when the session starts, and nowhere else", withSystemVariables.initial/3as the only caller ofTypes.session_entry!/3Statifier.MachineState.new/2's generatedsess_defaultStatifier.Send.Types.from_send_types/1taking{module, opts}, and its entry check accepting%{}statifier_persistence 0.18.0
create/4passinginitialize:toInterpreter.initialize/2was also verified. Cites are by module and function anchor, never by line.git diff origin/main -- docs/adr/shows zero removed lines.Provenance. The Amendment heading carries the bead id, as the other Amendments in this file do.