Skip to content

Decides the BasicHTTP location and its front (ADR-0002 Amendment) - #137

Merged
johnnyt merged 1 commit into
mainfrom
sr-xgi8-basichttp-location-record
Sep 30, 2026
Merged

johnnyt merged 1 commit into
mainfrom
sr-xgi8-basichttp-location-record

Conversation

@johnnyt

@johnnyt johnnyt commented Sep 30, 2026

Copy link
Copy Markdown
Member

Adds an Amendment at proposed to ADR-0002 (addressing) that decides where a durable execution's BasicHTTP location comes from and what the front that answers at it does. It is the record half of sr-xgi8. This repo's rule is that the record merges before the code, so this PR carries the record alone. The code PR comes later and cites it.

The location's shape and the front's authentication were ruled by the operator, 2026-09-30: an unguessable, rotatable per-execution token minted by the router, never the bare execution id; the front authenticates nothing beyond possession; a location is a bearer capability. The rest is decided by this Amendment:

  • The token: 32 random bytes as unpadded URL-safe base64. It is stored in a new locations table created by StatifierRouter.Migrations.V04, keyed by the address row with ON DELETE CASCADE and unique on the token. It is minted on the :if_absent insert that wins, and only when the new :basichttp key is set. An always_new execution has no location. The token is a table and not a column, so a host that does not use BasicHTTP needs no migration.
  • Rotation: StatifierRouter.BasicHTTP.rotate_location/2 replaces the token, after which the old one answers 404. The execution's own _ioprocessors entry is written once, at start, by statifier, so it keeps the old location. The record says so plainly.
  • Resolution: token -> location row -> address row -> StatifierRouter.Delivery.deliver_event/4 under the plan name basichttp with create: :never. This is never a route: ADR-0005 decision 1 is unchanged, and a URL in a route target stays refused. basichttp is reserved as a binding id only on a configuration that sets the new key.
  • The location string: StatifierRouter.BasicHTTP is a router-owned processor whose ioprocessors_entry/2 builds base_url/token from a per-create registration option. It hands deliver/3, cancel/2 and perform/2 to Statifier.Send.BasicHTTP unchanged. It uses statifier 2.10.0's public API only.
  • The front: StatifierRouter.BasicHTTP.Front.handle/3 and response/1, Plug-shaped with no process. Deduplication is per execution on the scxml-send-key header. The status table is 204 / 404 / 405 / 400 / 500.
  • The bearer-capability statement the docs will carry.

Gate. This is a docs-only change under docs/adr/. It touches no gated path (lib/, test/, config/, mix.exs, mix.lock, corpus/, README.md), so there is no local gate to run. CI runs regardless. No changelog fragment: ADRs are on changelog.d/README.md's "do not" side.

Direction check (in-turn). Every claim about code was verified at bb292c8 on main:

  • StatifierRouter.Delivery's private create_options/1 and insert_or_existing/4, and the moduledoc's statement that deliver_event/4 does not take dropped: unmatched_event
  • StatifierRouter.Config.new/1's refusal of unknown keys
  • StatifierRouter.Addresses.by_execution/2
  • StatifierRouter.Schema.Address

statifier claims were verified at its v2.10.0 tag:

  • Statifier.Send.BasicHTTP.ioprocessors_entry/2 and decode/1's request keys
  • the Statifier.Evaluator.SystemVariables moduledoc's "once, when the session starts, and nowhere else", with SystemVariables.initial/3 as the only caller of Types.session_entry!/3
  • Statifier.MachineState.new/2's generated sess_ default
  • Statifier.Send.Types.from_send_types/1 taking {module, opts}, and its entry check accepting %{}
  • st-ADR-0075, decisions 1, 3, 5 and 9, and its send-key Amendment

statifier_persistence 0.18.0 create/4 passing initialize: to Interpreter.initialize/2 was also verified. Cites are by module and function anchor, never by line. git diff origin/main -- docs/adr/ shows zero removed lines.

Provenance. The Amendment heading carries the bead id, as the other Amendments in this file do.

Adds an Amendment at proposed to ADR-0002: a durable execution's
BasicHTTP location is a 256-bit token the router mints and stores in a
new locations table (V04), one per address row; rotate_location/2
replaces it and the old token answers 404; the front resolves a token
to its address row and delivers through Delivery.deliver_event/4 under
the name basichttp, deduplicating on the scxml-send-key header per
execution; a router-owned processor writes base_url/token into
_ioprocessors from a per-create registration option. A location is a
bearer capability. No route rule changes.

Refs: sr-xgi8
@johnnyt
johnnyt merged commit 8600d6f into main Sep 30, 2026
1 check passed
@johnnyt
johnnyt deleted the sr-xgi8-basichttp-location-record branch September 30, 2026 16:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant