Skip to main content

Module exports

Module exports 

Source
Expand description

Declarative export-adapter delivery (#156, slice 6b).

On a scheduler event, every installed export adapter subscribed to it has the host render its own break stats (CSV/JSON) and deliver them to the adapter’s consent-fixed destination: a local file, or an HTTP POST — the only path in the app that sends data off the machine. The plugin runs no code and cannot influence the destination (fixed in the signed manifest, shown in full in the consent dialog).

Delivery is fire-and-forget on a spawned task so it never blocks the scheduler tick, and bounded (payload cap + HTTP timeout + no redirects) so a slow or hostile endpoint can’t stall or redirect it. Any failure is logged, never surfaced — a broken sink must not break breaks.

Constants§

HTTP_TIMEOUT 🔒
Timeout for the whole HTTP delivery, so a hung endpoint can’t pin the task.
MAX_EXPORT_BYTES 🔒
Hard cap on a rendered payload. Generous for a break-stats log; bounds the write/POST so an ever-growing event history can’t produce an unbounded request.

Functions§

deliver_on_event
Fire-and-forget: deliver the current break stats to every export adapter subscribed to event. Snapshots the configs under the registry lock, then renders + delivers off the lock on a spawned task. No subscribers → no work (and no file read).
deliver_one 🔒
Deliver one rendered payload to its configured sink. Over-cap payloads are dropped; all failures are logged, never propagated.
post 🔒
POST payload to the adapter’s URL. A fresh client per call with a hard timeout and redirects disabled — a redirect could bounce the data to a different host than the one the user consented to.
render_stats 🔒
Render the logged events in the requested format. Pure.
run_delivery 🔒
The delivery body, split from the spawn wrapper so it’s directly awaitable in tests. Snapshots subscribers under the lock, then renders + delivers off it.