Skip to content

Migrate utility layer to HTTP types (PR 11)#623

Merged
prk-Jr merged 118 commits intomainfrom
feature/edgezero-pr11-utility-layer-migration-v2
May 9, 2026
Merged

Migrate utility layer to HTTP types (PR 11)#623
prk-Jr merged 118 commits intomainfrom
feature/edgezero-pr11-utility-layer-migration-v2

Conversation

@prk-Jr
Copy link
Copy Markdown
Collaborator

@prk-Jr prk-Jr commented Apr 8, 2026

Summary

  • Migrate the PR11 utility layer off direct fastly::Request/fastly::Response usage so core helpers can operate on http::{Request, Response} and edgezero_core::Body.
  • Add a temporary compat bridge at Fastly boundaries so handlers and integrations can keep working while later migration PRs move the remaining call stack.
  • Lock in the migration with focused compat tests and a guard test that prevents the migrated utility modules from drifting back to Fastly request/response types.

Changes

File Change
Cargo.toml Add the workspace mime dependency used by migrated HTTP response helpers.
Cargo.lock Record the new mime dependency.
crates/trusted-server-adapter-fastly/src/main.rs Route forwarded-header sanitization and basic-auth response conversion through the new compat boundary.
crates/trusted-server-core/Cargo.toml Add the core crate's mime workspace dependency.
crates/trusted-server-core/src/auction/endpoints.rs Convert auction utility calls to use the HTTP request compat bridge for EC ID and consent handling.
crates/trusted-server-core/src/auth.rs Migrate basic-auth enforcement to http::Request/Response and update tests to HTTP builders.
crates/trusted-server-core/src/compat.rs Add Fastly-to-HTTP request/response conversions plus temporary Fastly boundary shims for headers, cookies, and EC cookie handling.
crates/trusted-server-core/src/consent/extraction.rs Migrate consent signal extraction to http::Request<EdgeBody>.
crates/trusted-server-core/src/consent/mod.rs Move consent pipeline input types and tests onto HTTP request types.
crates/trusted-server-core/src/cookies.rs Migrate cookie parsing/forwarding and EC cookie response helpers to HTTP request/response types; document and test target Cookie append semantics.
crates/trusted-server-core/src/edge_cookie.rs Add HTTP request EC ID helpers so migrated callers can reuse an existing HTTP request without rebuilding Fastly headers.
crates/trusted-server-core/src/http_util.rs Migrate request/response helpers to HTTP types, preserve duplicate headers, and keep request-info logic on ClientInfo.
crates/trusted-server-core/src/integrations/lockr.rs Use Fastly compat shims for header/cookie forwarding at the integration boundary.
crates/trusted-server-core/src/integrations/permutive.rs Use Fastly compat shims for custom-header forwarding at the integration boundary.
crates/trusted-server-core/src/integrations/prebid.rs Bridge request-info construction and cookie forwarding through compat conversions.
crates/trusted-server-core/src/integrations/registry.rs Use compat conversions for EC ID generation and EC cookie response handling.
crates/trusted-server-core/src/lib.rs Export the compat module and add migration guard tests.
crates/trusted-server-core/src/migration_guards.rs Add a regression test preventing migrated utility modules from reintroducing direct Fastly request/response types.
crates/trusted-server-core/src/publisher.rs Route TSJS serving, request-info extraction, consent handling, and EC cookie writes through compat conversions.
crates/trusted-server-core/src/request_signing/endpoints.rs Switch JSON content-type constants to mime::APPLICATION_JSON.

Closes

Closes #492

Test plan

  • cargo test --workspace
  • cargo clippy --workspace --all-targets --all-features -- -D warnings
  • cargo fmt --all -- --check
  • JS tests: cd crates/js/lib && npx vitest run
  • JS format: cd crates/js/lib && npm run format
  • Docs format: cd docs && npm run format
  • WASM build: cargo build --package trusted-server-adapter-fastly --release --target wasm32-wasip1
  • Manual testing via fastly compute serve
  • Other: focused Rust verification with cargo test --package trusted-server-core compat -- --nocapture, cargo test --package trusted-server-core http_util -- --nocapture, cargo test --package trusted-server-core request_signing -- --nocapture, and cargo test --package trusted-server-core migration_guards -- --nocapture
  • Other: local cd crates/js/lib && npx vitest run currently fails before test execution with ERR_REQUIRE_ESM in html-encoding-sniffer -> @exodus/bytes/encoding-lite.js; leaving CI to capture the current JS environment issue.

Hardening note

This PR does not add any new config-derived regex or pattern compilation paths. Basic auth still surfaces invalid enabled handler regex configuration as an error rather than panicking, covered by auth::tests::returns_error_for_invalid_handler_regex_without_panicking alongside the existing settings startup validation tests.

Checklist

  • Changes follow CLAUDE.md conventions
  • No unwrap() in production code — use expect("should ...")
  • Uses project logging macros (not println!)
  • New code has tests
  • No secrets or credentials committed

prk-Jr and others added 30 commits March 18, 2026 16:54
Rename crates/common → crates/trusted-server-core and crates/fastly →
crates/trusted-server-adapter-fastly following the EdgeZero naming
convention. Add EdgeZero workspace dependencies pinned to rev 170b74b.
Update all references across docs, CI workflows, scripts, agent files,
and configuration.
Introduces trusted-server-core::platform with PlatformConfigStore,
PlatformSecretStore, PlatformKvStore, PlatformBackend, PlatformHttpClient,
and PlatformGeo traits alongside ClientInfo, PlatformError, and
RuntimeServices. Wires the Fastly adapter implementations and threads
RuntimeServices into route_request. Moves GeoInfo to platform/types as
platform-neutral data and adds geo_from_fastly for field mapping.
- Defer KV store opening: replace early error return with a local
  UnavailableKvStore fallback so routes that do not need synthetic ID
  access succeed when the KV store is missing or temporarily unavailable
- Use ConfigStore::try_open + try_get and SecretStore::try_get throughout
  FastlyPlatformConfigStore and FastlyPlatformSecretStore to honour the
  Result contract instead of panicking on open/lookup failure
- Encapsulate RuntimeServices service fields as pub(crate) with public
  getter methods (config_store, secret_store, backend, http_client, geo)
  and a pub new() constructor; adapter updated to use new()
- Reference #487 in FastlyPlatformHttpClient stub (PR 6 implements it)
- Remove unused KvPage re-export from platform/mod.rs
- Use super::KvHandle shorthand in RuntimeServices::kv_handle()
- Split fastly_storage.rs into storage/{config_store,secret_store,api_client,mod}.rs
- Add PlatformConfigStore read path via FastlyPlatformConfigStore::get using ConfigStore::try_open/try_get
- Add PlatformError::NotImplemented variant; stub write methods on FastlyPlatformConfigStore and FastlyPlatformSecretStore
- Add StoreName/StoreId newtypes with From<String>, From<&str>, AsRef<str>
- Add UnavailableKvStore to core platform module
- Add RuntimeServicesBuilder replacing 7-arg constructor
- Migrate get_active_jwks and handle_trusted_server_discovery to use &RuntimeServices
- Update call sites in signing.rs, rotation.rs, main.rs
- Add success-path test for handle_trusted_server_discovery using StubJwksConfigStore
- Fix test_parse_cookies_to_jar_empty typo (was emtpy)
- Make StoreName and StoreId inner fields private; From/AsRef provide all
  needed construction and access
- Add #[deprecated] to GeoInfo::from_request with #[allow(deprecated)] at
  the three legacy call sites to track migration progress
- Enumerate the six platform traits in the platform module doc comment
- Extract backend_config_from_spec helper to remove duplicate BackendConfig
  construction in predict_name and ensure
- Replace .into_iter().collect() with .to_vec() on secret plaintext bytes
- Remove unused bytes dependency from trusted-server-adapter-fastly
- Add comment on SecretStore::open clarifying it already returns Result
  (unlike ConfigStore::open which panics)
prk-Jr added 7 commits April 15, 2026 12:06
- Revert proxy.rs merge artifact: restore per-request allowed_domains
  at both redirect_is_permitted call sites; remove dead_code allow and
  stale comment — integration proxies defaulting to &[] get open mode
  again as documented
- Drop unused trusted-server-js dep from adapter Cargo.toml
- Fix check_response: gate body read behind error branch so 2xx paths
  do not buffer and discard the response body
- Remove self-referential SECRET_UPSERT_METHOD test
- Reorder write-cost doc so outbound HTTPS round-trip leads; handle-open
  caching noted as negligible
- Refactor make_request to take fastly::http::Method; drop string match
  and unreachable arm; remove SECRET_UPSERT_METHOD const
- Add SigningStoreIds named struct in endpoints.rs; update both call
  sites to destructure by name
Copy link
Copy Markdown
Collaborator

@aram356 aram356 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

PR introduces compat.rs as a temporary Fastly↔http bridge and migrates six utility modules (auth, cookies, synthetic, http_util, consent/extraction, consent/mod) off fastly::Request/fastly::Response. Prior approvals (2026-04-14) predate the latest commit ae402ff (2026-04-15), which renamed from_fastly_request_reffrom_fastly_headers_ref, dropped a redundant case check in copy_fastly_custom_headers, and switched forward_cookie_header to get_all + append. The round-2 fixes for duplicate-header preservation are clean, but a few concerns remain — notably a new runtime-panic surface at the edge and unused compat helpers that arrived before their callers.

Blocking

🔧 wrench

  • New edge-wide panic surface on URL parsing: compat::build_http_request calls .parse().expect(...) on every bridged request. http::Uri is stricter than Fastly's internal url::Url, so a URL Fastly accepts but http::Uri rejects panics the entire edge handler before auth can run. Previously enforce_basic_auth used req.get_path() with no re-parse. (crates/trusted-server-core/src/compat.rs:14-31)

Non-blocking

🤔 thinking

  • Redundant compat conversion on the prebid hot path: request_bids (prebid.rs:1012) and to_openrtb (prebid.rs:713) both convert the same context.request in the same auction flow — pull up once and thread through.

♻️ refactor

  • Three compat functions ship without callers: from_fastly_request, to_fastly_request, and from_fastly_response are only referenced from their own tests. CLAUDE.md says "Don't design for hypothetical future requirements. No half-finished implementations either." Ship in the PR that uses them. (crates/trusted-server-core/src/compat.rs:40, 61, 90)

🌱 seedling / 📌 out of scope / ⛏ nitpick

  • 📌 Redundant conversion at the auction boundary: acknowledged by TODO at auction/formats.rs:93-95; accepted cost of incremental migration.
  • 🌱 sanitize_fastly_forwarded_headers get-then-remove: remove_header is idempotent; the get_header guard exists only for the debug log. (compat.rs:129-136)
  • forward_cookie_header panics on HeaderValue::from_str: fires only on already-validated input, but a try_from + skip keeps failure local to the function. (cookies.rs:156-186)

CI Status

  • fmt: PASS
  • clippy: PASS
  • rust tests: PASS (841/841)
  • browser integration / integration / artifacts (GitHub Actions): PASS

Comment thread crates/trusted-server-core/src/compat.rs Outdated
Comment thread crates/trusted-server-core/src/integrations/prebid.rs Outdated
Comment thread crates/trusted-server-core/src/compat.rs Outdated
Comment thread crates/trusted-server-core/src/auction/formats.rs Outdated
Comment thread crates/trusted-server-core/src/compat.rs
Comment thread crates/trusted-server-core/src/cookies.rs Outdated
prk-Jr and others added 7 commits April 25, 2026 19:37
…into feature/edgezero-pr10-abstract-logging-initialization
…into feature/edgezero-pr11-utility-layer-migration-v2

Resolve conflicts by adopting PR10's ec_id naming throughout. cookies.rs
set_ec_cookie/expire_ec_cookie retain Response<EdgeBody> types to satisfy
migration_guards; Fastly-typed callers route through compat bridge. Remove
synthetic.rs (deleted in PR10) and its migration_guards entry.
cookies.rs set_ec_cookie/expire_ec_cookie now take Response<EdgeBody> to
satisfy the migration_guards invariant. registry.rs and publisher.rs call
the Fastly-typed equivalents in compat instead. Remove synthetic.rs entry
from migration_guards (file deleted in PR10).
…into feature/edgezero-pr11-utility-layer-migration-v2
@prk-Jr prk-Jr requested a review from aram356 April 27, 2026 14:08
Copy link
Copy Markdown
Collaborator

@aram356 aram356 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

PR 11 of the EdgeZero migration: lifts the utility layer (auth, cookies, http_util, consent) off fastly::{Request, Response} onto http::{Request, Response}<EdgeBody>, with a compat bridge module that lets non-migrated callers keep working. The shape of the migration is sound and the new migration_guards test is a strong regression backstop. The principal concerns are CI (clippy fails when run against main) and a migrated-but-untested code path that will silently change behavior in the next PR.

Blocking

🔧 wrench

  • Clippy fails: cookies::set_ec_cookie missing # Panics (crates/trusted-server-core/src/cookies.rs:258)
  • Clippy fails: cookies::expire_ec_cookie missing # Panics (crates/trusted-server-core/src/cookies.rs:277)
  • Migrated cookies::forward_cookie_header has no callers and no tests — semantics diverge from compat::forward_fastly_cookie_header (get_all vs first-only) (crates/trusted-server-core/src/cookies.rs:152)

CI didn't catch the clippy regressions because format.yml only triggers on PRs whose base is main. PR 623's base is the PR 10 feature branch, so the clippy + fmt gate was bypassed entirely.

Non-blocking

🤔 thinking

  • compat is pub mod compat — exposed as public API despite being PR 15 removal scaffolding (crates/trusted-server-core/src/lib.rs:38)
  • from_fastly_headers_ref # Panics doc is inaccurate — claims URL parse panics but uses unwrap_or_else fallback (crates/trusted-server-core/src/compat.rs:46)
  • to_fastly_response silently truncates EdgeBody::Stream — latent risk as more callers migrate (crates/trusted-server-core/src/compat.rs:65)

♻️ refactor

  • compat::expire_fastly_synthetic_cookie hardcodes cookie attributes instead of reusing cookies::ec_cookie_attributes — DRY drift on security-sensitive code (crates/trusted-server-core/src/compat.rs:145)
  • compat uses old "synthetic" naming instead of "ec" — inconsistent with the recent EC rename (crates/trusted-server-core/src/compat.rs:118)

⛏ nitpick

  • from_fastly_headers_ref URI fallback to "/" swallows malformed URLs silently — at minimum log a warning (crates/trusted-server-core/src/compat.rs:17)

👍 praise

  • migration_guards.rs — concise regression test with well-justified limitations
  • PrebidAuctionProvider::to_openrtb request_info refactor — single source of truth, real readability win

CI Status

  • fmt: PASS (cargo fmt --all -- --check)
  • clippy: FAIL — 2 errors (missing_panics_doc on set_ec_cookie / expire_ec_cookie), bypassed by base branch routing
  • rust tests: PASS (cargo test --workspace)
  • integration tests (GitHub Actions): PASS (3/3)

Comment thread crates/trusted-server-core/src/cookies.rs
Comment thread crates/trusted-server-core/src/cookies.rs
Comment thread crates/trusted-server-core/src/cookies.rs
Comment thread crates/trusted-server-core/src/lib.rs
Comment thread crates/trusted-server-core/src/compat.rs
Comment thread crates/trusted-server-core/src/compat.rs Outdated
Comment thread crates/trusted-server-core/src/compat.rs
Comment thread crates/trusted-server-core/src/compat.rs Outdated
Comment thread crates/trusted-server-core/src/migration_guards.rs
Comment thread crates/trusted-server-core/src/integrations/prebid.rs
@prk-Jr prk-Jr changed the base branch from feature/edgezero-pr10-abstract-logging-initialization to main April 30, 2026 02:18
@prk-Jr prk-Jr requested a review from aram356 May 3, 2026 15:54
Copy link
Copy Markdown
Collaborator

@aram356 aram356 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

PR 11 of the EdgeZero migration: lifts six utility modules (auth, cookies, http_util, consent/extraction, consent/mod, plus the JSON content-type in request_signing/endpoints) off fastly::{Request, Response} onto http::{Request, Response}<EdgeBody> with a compat bridge for non-migrated callers. CI is green across all 13 jobs and clippy is clean against main locally. All blocking findings from the prior CHANGES_REQUESTED reviews are resolved — set_ec_cookie/expire_ec_cookie panics docs added, forward_cookie_header now has dedicated tests for the multi-Cookie and non-UTF-8 paths, and the *_synthetic_cookie*_ec_cookie rename keeps the EC terminology consistent. Filing non-blocking observations only; a clean approve will follow.

Non-blocking

🤔 thinking

  • forward_cookie_header source/target divergence: source-side get_all vs get_header is tested, but target-side append vs set is unflagged and would change behavior for any future caller that seeds to with a pre-existing Cookie header (crates/trusted-server-core/src/cookies.rs:169).
  • TSJS path allocates the response body twice through the serve_static_with_etagcompat::to_fastly_response round-trip; disappears in PR 13/14 (crates/trusted-server-core/src/publisher.rs:140).

🌱 seedling

  • Double http::Request build per request in handle_publisher_request and handle_auction — both build http_req explicitly, then pass &req (fastly) to get_or_generate_ec_id, which rebuilds it inside get_ec_id (crates/trusted-server-core/src/edge_cookie.rs:120).
  • compat::set_fastly_ec_cookie duplicates the validate-then-build control flow of cookies::set_ec_cookie. A cookies::try_build_ec_cookie_value helper would dedupe both append-paths (crates/trusted-server-core/src/compat.rs:156).

📝 note

  • PR description "Changes" table is out of sync with the diff: lists auction/formats.rs, integrations/testlight.rs, proxy.rs, synthetic.rs which aren't in git diff main...HEAD (folded into PR 9/10 merges). Update before merge for accuracy.

👍 praise

  • All 9 prior findings addressed correctly — panics docs, EC rename, attribute reuse, #[doc(hidden)], debug_assert! on stream truncation, URI parse warning, plus comprehensive tests for the divergent code paths.
  • migration_guards ban list extension to fastly::mime::APPLICATION_JSON keeps the regression net tight (crates/trusted-server-core/src/migration_guards.rs:42).
  • PrebidAuctionProvider::to_openrtb request_info refactor — lifts RequestInfo::from_request to prepare_request, eliminating a duplicate construction (crates/trusted-server-core/src/integrations/prebid.rs:1007).

CI Status

  • fmt: PASS
  • clippy: PASS (verified locally with --workspace --all-targets --all-features -- -D warnings)
  • rust tests: PASS
  • vitest: PASS
  • browser integration tests: PASS
  • format-typescript / format-docs: PASS

Comment thread crates/trusted-server-core/src/cookies.rs
Comment thread crates/trusted-server-core/src/publisher.rs
Comment thread crates/trusted-server-core/src/edge_cookie.rs Outdated
Comment thread crates/trusted-server-core/src/compat.rs
Comment thread crates/trusted-server-core/src/migration_guards.rs
Comment thread crates/trusted-server-core/src/cookies.rs
Comment thread crates/trusted-server-core/src/integrations/prebid.rs
@prk-Jr prk-Jr merged commit f275aba into main May 9, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Utility layer type migration + compat adapter

3 participants