Safe Haskell | None |
---|---|
Language | Haskell98 |
A fast, light-weight HTTP server handler for WAI.
Note on slowloris timeouts: to prevent slowloris attacks, timeouts are used at various points in request receiving and response sending. One interesting corner case is partial request body consumption; in that case, Warp's timeout handling is still in effect, and the timeout will not be triggered again. Therefore, it is recommended that once you start consuming the request body, you either:
- consume the entire body promptly
- call the
pauseTimeout
function
For more information, see https://github.com/yesodweb/wai/issues/351.
- run :: Port -> Application -> IO ()
- runEnv :: Port -> Application -> IO ()
- runSettings :: Settings -> Application -> IO ()
- runSettingsSocket :: Settings -> Socket -> Application -> IO ()
- runSettingsConnection :: Settings -> IO (Connection, SockAddr) -> Application -> IO ()
- runSettingsConnectionMaker :: Settings -> IO (IO Connection, SockAddr) -> Application -> IO ()
- runSettingsConnectionMakerSecure :: Settings -> IO (IO (Connection, Transport), SockAddr) -> Application -> IO ()
- data Settings
- defaultSettings :: Settings
- setPort :: Int -> Settings -> Settings
- setHost :: HostPreference -> Settings -> Settings
- setOnException :: (Maybe Request -> SomeException -> IO ()) -> Settings -> Settings
- setOnExceptionResponse :: (SomeException -> Response) -> Settings -> Settings
- setOnOpen :: (SockAddr -> IO Bool) -> Settings -> Settings
- setOnClose :: (SockAddr -> IO ()) -> Settings -> Settings
- setTimeout :: Int -> Settings -> Settings
- setManager :: Manager -> Settings -> Settings
- setFdCacheDuration :: Int -> Settings -> Settings
- setBeforeMainLoop :: IO () -> Settings -> Settings
- setNoParsePath :: Bool -> Settings -> Settings
- setInstallShutdownHandler :: (IO () -> IO ()) -> Settings -> Settings
- setServerName :: ByteString -> Settings -> Settings
- setMaximumBodyFlush :: Maybe Int -> Settings -> Settings
- setFork :: (((forall a. IO a -> IO a) -> IO ()) -> IO ()) -> Settings -> Settings
- setProxyProtocolNone :: Settings -> Settings
- setProxyProtocolRequired :: Settings -> Settings
- setProxyProtocolOptional :: Settings -> Settings
- getPort :: Settings -> Int
- getHost :: Settings -> HostPreference
- settingsPort :: Settings -> Int
- settingsHost :: Settings -> HostPreference
- settingsOnException :: Settings -> Maybe Request -> SomeException -> IO ()
- settingsOnExceptionResponse :: Settings -> SomeException -> Response
- settingsOnOpen :: Settings -> SockAddr -> IO Bool
- settingsOnClose :: Settings -> SockAddr -> IO ()
- settingsTimeout :: Settings -> Int
- settingsManager :: Settings -> Maybe Manager
- settingsFdCacheDuration :: Settings -> Int
- settingsBeforeMainLoop :: Settings -> IO ()
- settingsNoParsePath :: Settings -> Bool
- exceptionResponseForDebug :: SomeException -> Response
- defaultShouldDisplayException :: SomeException -> Bool
- data Transport
- data HostPreference :: *
- type Port = Int
- data InvalidRequest
- data ConnSendFileOverride
- pauseTimeout :: Request -> IO ()
- data Connection = Connection {
- connSendMany :: [ByteString] -> IO ()
- connSendAll :: ByteString -> IO ()
- connSendFile :: FilePath -> Integer -> Integer -> IO () -> [ByteString] -> IO ()
- connClose :: IO ()
- connRecv :: IO ByteString
- connReadBuffer :: Buffer
- connWriteBuffer :: Buffer
- connBufferSize :: BufSize
- connSendFileOverride :: ConnSendFileOverride
- socketConnection :: Socket -> IO Connection
- warpVersion :: String
- data InternalInfo = InternalInfo {}
- type HeaderValue = ByteString
- type IndexedHeader = Array Int (Maybe HeaderValue)
- requestMaxIndex :: Int
- module Network.Wai.Handler.Warp.Timeout
- withFdCache :: Int -> (Maybe MutableFdCache -> IO a) -> IO a
- getFd :: MutableFdCache -> FilePath -> IO (Fd, Refresh)
- type MutableFdCache = Reaper FdCache (Hash, FdEntry)
- type Refresh = IO ()
- withDateCache :: (DateCache -> IO a) -> IO a
- getDate :: DateCache -> IO GMTDate
- type DateCache = IO GMTDate
- type GMTDate = ByteString
- recvRequest :: Settings -> Connection -> InternalInfo -> SockAddr -> Source -> IO (Request, Maybe (IORef Int), IndexedHeader, IO ByteString)
- sendResponse :: ByteString -> Connection -> InternalInfo -> Request -> IndexedHeader -> IO ByteString -> Response -> IO Bool
Run a Warp server
run :: Port -> Application -> IO () Source
Run an Application
on the given port. This calls runSettings
with
defaultSettings
.
runEnv :: Port -> Application -> IO () Source
Run an Application
on the port present in the PORT
environment variable
Uses the Port
given when the variable is unset.
Since 3.0.9
runSettings :: Settings -> Application -> IO () Source
Run an Application
with the given Settings
.
runSettingsSocket :: Settings -> Socket -> Application -> IO () Source
Same as runSettings
, but uses a user-supplied socket instead of opening
one. This allows the user to provide, for example, Unix named socket, which
can be used when reverse HTTP proxying into your application.
Note that the settingsPort
will still be passed to Application
s via the
serverPort
record.
When the listen socket in the second argument is closed, all live connections are gracefully shut down.
runSettingsConnection :: Settings -> IO (Connection, SockAddr) -> Application -> IO () Source
Allows you to provide a function which will return a Connection
. In
cases where creating the Connection
can be expensive, this allows the
expensive computations to be performed in a separate thread instead of the
main server loop.
Since 1.3.5
runSettingsConnectionMaker :: Settings -> IO (IO Connection, SockAddr) -> Application -> IO () Source
runSettingsConnectionMakerSecure :: Settings -> IO (IO (Connection, Transport), SockAddr) -> Application -> IO () Source
Allows you to provide a function which will return a function
which will return Connection
.
Since 2.1.4
Settings
Various Warp server settings. This is purposely kept as an abstract data
type so that new settings can be added without breaking backwards
compatibility. In order to create a Settings
value, use defaultSettings
and the various 'set' functions to modify individual fields. For example:
setTimeout 20 defaultSettings
defaultSettings :: Settings Source
The default settings for the Warp server. See the individual settings for the default value.
Setters
setHost :: HostPreference -> Settings -> Settings Source
Interface to bind to. Default value: HostIPv4
Since 2.1.0
setOnException :: (Maybe Request -> SomeException -> IO ()) -> Settings -> Settings Source
What to do with exceptions thrown by either the application or server.
Default: ignore server-generated exceptions (see InvalidRequest
) and print
application-generated exceptions to stderr.
Since 2.1.0
setOnExceptionResponse :: (SomeException -> Response) -> Settings -> Settings Source
A function to create a Response
when an exception occurs.
Default: 500, text/plain, "Something went wrong"
Since 2.1.0
setOnClose :: (SockAddr -> IO ()) -> Settings -> Settings Source
What to do when a connection is closed. Default: do nothing.
Since 2.1.0
setTimeout :: Int -> Settings -> Settings Source
Timeout value in seconds. Default value: 30
Since 2.1.0
setManager :: Manager -> Settings -> Settings Source
Use an existing timeout manager instead of spawning a new one. If used,
settingsTimeout
is ignored.
Since 2.1.0
setFdCacheDuration :: Int -> Settings -> Settings Source
Cache duration time of file descriptors in seconds. 0 means that the cache mechanism is not used.
The FD cache is an optimization that is useful for servers dealing with static files. However, if files are being modified, it can cause incorrect results in some cases. Therefore, we disable it by default. If you know that your files will be static or you prefer performance to file consistency, it's recommended to turn this on; a reasonable value for those cases is 10. Enabling this cache results in drastic performance improvement for file transfers.
Default value: since 3.0.13, default value is 0, was previously 10
setBeforeMainLoop :: IO () -> Settings -> Settings Source
Code to run after the listening socket is ready but before entering the main event loop. Useful for signaling to tests that they can start running, or to drop permissions after binding to a restricted port.
Default: do nothing.
Since 2.1.0
setNoParsePath :: Bool -> Settings -> Settings Source
Perform no parsing on the rawPathInfo.
This is useful for writing HTTP proxies.
Default: False
Since 2.1.0
setInstallShutdownHandler :: (IO () -> IO ()) -> Settings -> Settings Source
A code to install shutdown handler.
For instance, this code should set up a UNIX signal handler. The handler should call the first argument, which close the listen socket, at shutdown.
Default: does not install any code.
Since 3.0.1
setServerName :: ByteString -> Settings -> Settings Source
Default server name if application does not set one.
Since 3.0.2
setMaximumBodyFlush :: Maybe Int -> Settings -> Settings Source
The maximum number of bytes to flush from an unconsumed request body.
By default, Warp does not flush the request body so that, if a large body is
present, the connection is simply terminated instead of wasting time and
bandwidth on transmitting it. However, some clients do not deal with that
situation well. You can either change this setting to Nothing
to flush the
entire body in all cases, or in your application ensure that you always
consume the entire request body.
Default: 8192 bytes.
Since 3.0.3
setFork :: (((forall a. IO a -> IO a) -> IO ()) -> IO ()) -> Settings -> Settings Source
Code to fork a new thread to accept a connection.
This may be useful if you need OS bound threads, or if you wish to develop an alternative threading model.
Default: void . forkIOWithUnmask
Since 3.0.4
setProxyProtocolNone :: Settings -> Settings Source
Do not use the PROXY protocol.
Since 3.0.5
setProxyProtocolRequired :: Settings -> Settings Source
Require PROXY header.
This is for cases where a "dumb" TCP/SSL proxy is being used, which cannot
add an X-Forwarded-For
HTTP header field but has enabled support for the
PROXY protocol.
See http://www.haproxy.org/download/1.5/doc/proxy-protocol.txt and http://docs.aws.amazon.com/ElasticLoadBalancing/latest/DeveloperGuide/TerminologyandKeyConcepts.html#proxy-protocol.
Only the human-readable header format (version 1) is supported. The binary header format (version 2) is not supported.
Since 3.0.5
setProxyProtocolOptional :: Settings -> Settings Source
Use the PROXY header if it exists, but also accept
connections without the header. See setProxyProtocolRequired
.
WARNING: This is contrary to the PROXY protocol specification and using it can indicate a security problem with your architecture if the web server is directly accessable to the public, since it would allow easy IP address spoofing. However, it can be useful in some cases, such as if a load balancer health check uses regular HTTP without the PROXY header, but proxied connections do include the PROXY header.
Since 3.0.5
Getters
getHost :: Settings -> HostPreference Source
Get the interface to bind to.
Since 2.1.1
Accessors
Note: these accessors are deprecated, please use the set
versions instead.
settingsPort :: Settings -> Int Source
Deprecated: Use setPort instead
Port to listen on. Default value: 3000
settingsHost :: Settings -> HostPreference Source
Deprecated: Use setHost instead
Default value: HostIPv4
settingsOnException :: Settings -> Maybe Request -> SomeException -> IO () Source
Deprecated: Use setOnException instead
What to do with exceptions thrown by either the application or server. Default: ignore server-generated exceptions (see InvalidRequest
) and print application-generated applications to stderr.
settingsOnExceptionResponse :: Settings -> SomeException -> Response Source
Deprecated: Use setOnExceptionResponse instead
A function to create Response
when an exception occurs.
Default: 500, text/plain, "Something went wrong"
Since 2.0.3
settingsOnClose :: Settings -> SockAddr -> IO () Source
Deprecated: Use setOnClose instead
What to do when a connection is close. Default: do nothing.
settingsTimeout :: Settings -> Int Source
Deprecated: Use setTimeout instead
Timeout value in seconds. Default value: 30
settingsManager :: Settings -> Maybe Manager Source
Deprecated: Use setManager instead
Use an existing timeout manager instead of spawning a new one. If used, settingsTimeout
is ignored. Default is Nothing
settingsFdCacheDuration :: Settings -> Int Source
Deprecated: Use setFdCacheDuration instead
Cache duration time of file descriptors in seconds. 0 means that the cache mechanism is not used. Default value: 0
settingsBeforeMainLoop :: Settings -> IO () Source
Deprecated: Use setBeforeMainLoop instead
Code to run after the listening socket is ready but before entering the main event loop. Useful for signaling to tests that they can start running, or to drop permissions after binding to a restricted port.
Default: do nothing.
Since 1.3.6
settingsNoParsePath :: Settings -> Bool Source
Deprecated: Use setNoParsePath instead
Perform no parsing on the rawPathInfo.
This is useful for writing HTTP proxies.
Default: False
Since 2.0.3
Debugging
exceptionResponseForDebug :: SomeException -> Response Source
Default implementation of settingsOnExceptionResponse
for the debugging purpose. 500, text/plain, a showed exception.
defaultShouldDisplayException :: SomeException -> Bool Source
Apply the logic provided by defaultExceptionHandler
to determine if an
exception should be shown or not. The goal is to hide exceptions which occur
under the normal course of the web server running.
Since 2.1.3
Data types
What kind of transport is used for this connection?
TCP | Plain channel: TCP |
TLS | Encrypted channel: TLS or SSL |
|
data HostPreference :: *
Which host to bind.
Note: The IsString
instance recognizes the following special values:
*
meansHostAny
*4
meansHostIPv4
!4
meansHostIPv4Only
*6
meansHostIPv6
!6
meansHostIPv6Only
Any other values is treated as a hostname. As an example, to bind to the IPv4 local host only, use "127.0.0.1".
data InvalidRequest Source
Error types for bad Request
.
data ConnSendFileOverride Source
Whether or not ConnSendFileOverride
in Connection
can be
overridden. This is a kind of hack to keep the signature of
Connection
clean.
NotOverride | Don't override |
Override Socket | Override with this |
Per-request utilities
pauseTimeout :: Request -> IO () Source
Explicitly pause the slowloris timeout.
This is useful for cases where you partially consume a request body. For more information, see https://github.com/yesodweb/wai/issues/351
Since 3.0.10
Connection
data Connection Source
Data type to manipulate IO actions for connections.
Connection | |
|
socketConnection :: Socket -> IO Connection Source
Default action value for Connection
.
Internal
Version
The version of Warp.
Data types
data InternalInfo Source
Internal information.
type HeaderValue = ByteString Source
The type for header value used with HeaderName
.
type IndexedHeader = Array Int (Maybe HeaderValue) Source
Array for a set of HTTP headers.
The size for IndexedHeader
for HTTP Request.
From 0 to this corresponds to "Content-Length", "Transfer-Encoding",
"Expect", "Connection", "Range", and "Host".
Time out manager
File descriptor cache
withFdCache :: Int -> (Maybe MutableFdCache -> IO a) -> IO a Source
Creating MutableFdCache
and executing the action in the second
argument. The first argument is a cache duration in second.
type MutableFdCache = Reaper FdCache (Hash, FdEntry) Source
Mutable Fd cacher.
Date
type GMTDate = ByteString Source
The type of the Date header value.
Request and response
:: Settings | |
-> Connection | |
-> InternalInfo | |
-> SockAddr | Peer's address. |
-> Source | Where HTTP request comes from. |
-> IO (Request, Maybe (IORef Int), IndexedHeader, IO ByteString) |
|
Receiving a HTTP request from Connection
and parsing its header
to create Request
.
:: ByteString | default server value |
-> Connection | |
-> InternalInfo | |
-> Request | HTTP request. |
-> IndexedHeader | Indexed header of HTTP request. |
-> IO ByteString | source from client, for raw response |
-> Response | HTTP response including status code and response header. |
-> IO Bool | Returing True if the connection is persistent. |
Sending a HTTP response to Connection
according to Response
.
Applications/middlewares MUST specify a proper ResponseHeaders
.
so that inconsistency does not happen.
No header is deleted by this function.
Especially, Applications/middlewares MUST take care of Content-Length, Content-Range, and Transfer-Encoding because they are inserted, when necessary, regardless they already exist. This function does not insert Content-Encoding. It's middleware's responsibility.
The Date and Server header is added if not exist in HTTP response header.
There are three basic APIs to create Response
:
responseFile
::Status
->ResponseHeaders
->FilePath
->Maybe
FilePart
->Response
- HTTP response body is sent by sendfile() for GET method.
HTTP response body is not sent by HEAD method.
Applications are categorized into simple and sophisticated.
Simple applications should specify
Nothing
toMaybe
FilePart
. The size of the specified file is obtained by disk access. Then Range is handled. Sophisticated applications should specifyJust
toMaybe
FilePart
. They should treat Range (and If-Range) by themselves. In both cases, Content-Length and Content-Range (if necessary) are automatically added into the HTTP response header. If Content-Length and Content-Range exist in the HTTP response header, they would cause inconsistency. Status is also changed to 206 (Partial Content) if necessary. responseBuilder
::Status
->ResponseHeaders
->Builder
->Response
- HTTP response body is created from
Builder
. Transfer-Encoding: chunked is used in HTTP/1.1. responseStream
::Status
->ResponseHeaders
->StreamingBody
->Response
- HTTP response body is created from
Builder
. Transfer-Encoding: chunked is used in HTTP/1.1. responseRaw
:: (IO
ByteString
-> (ByteString
->IO
()) ->IO
()) ->Response
->Response
- No header is added and no Transfer-Encoding: is applied.