@oreefy/http
v1.0.0
Published
Edge-compatible, standardized HTTP handler for secure inter-service communication across Oreefy ecosystem.
Downloads
195
Maintainers
Readme
@oreefy/http
Edge-compatible, standardized HTTP handler for secure inter-service communication across Oreefy ecosystem.
@oreefy/http is a library built for the Oreefy ecosystem. The package is officially developed, maintained, and fully controlled by Oreefy, ensuring long-term stability, consistency, and compatibility across the ecosystem.
Required Capabilities
- JavaScript / TypeScript
- Web Crypto API (
crypto) @oreefy/jwev1.0.0
API Reference
import { http } from "@oreefy/http";
http.request();
http.receive();
http.response();// Crypto params from @oreefy/jwe are required for
// http.request(), http.receive() and http.response().
interface Crypto {
secret: string; // A 64-character hexadecimal secret representing a 256-bit AES key.
issuer?: string; // Optional issuer value authenticated as AES-GCM AAD.
audience?: string; // Optional audience value authenticated as AES-GCM AAD.
subject?: string; // Optional subject value authenticated as AES-GCM AAD.
}http.request()
Sends an encrypted HTTP POST request to a destination endpoint. The plaintext is encrypted using JWE before transmission. You can also attach files, which will be sent as multipart/form-data along with the encrypted ciphertext.
import { http } from "@oreefy/http";
interface Options extends Crypto {
endpoint: string | URL; // The destination URL for the request.
plaintext: string; // You must stringify your data before sending via http.request().
files?: Record<string, Blob>; // Optional files to include with the request.
authorize?: string; // A custom authorization code. This must be the same in http.receive().
}
const response = await http.request(options); // Promise<string | null>Notes:
- If the request succeeds (HTTP 200), the decrypted plaintext from the response is returned.
- On any failure (network error, invalid status, decryption failure, etc.), the method returns null.
- Default values:
authorize = "@oreefy/http",subject = "request",issuer = "@oreefy/http", audience ="@oreefy/http". - The encrypted payload expires after 100 seconds.
http.receive()
Receives and validates an incoming encrypted request. It checks the required Oreefy headers and authorization value, then decrypts the payload. Supports both plain text and multipart/form-data (when files are present).
import { http } from "@oreefy/http";
interface Options extends Crypto {
request: Request; // Standard Web Request API object.
authorize?: string; // A custom authorization code. This must be the same as in http.request().
}
const data = await http.receive(options); // Promise<{ plaintext: string | null; files: Record<string, Blob | undefined> }>Notes:
- Returns
{ plaintext: null, files: {} }if header validation fails, authorization does not match, or decryption fails. - When files are present, they are extracted from the form data and returned in the
filesobject. - Default values:
authorize = "@oreefy/http",subject = "request",issuer = "@oreefy/http",audience = "@oreefy/http".
http.response()
Creates an encrypted HTTP response. The plaintext is encrypted using JWE and returned as a standard Response object with status 200.
import { http } from "@oreefy/http";
interface Options extends Crypto {
plaintext: string; // You must stringify your data before sending via http.response().
}
await http.response(options); // Promise<Response>Notes:
- On success, returns a
Responsewith the encrypted ciphertext and status200. - On failure, returns a
Responsewith status500and a generic error message. - Default values:
subject = "request",issuer = "@oreefy/http",audience = "@oreefy/http". - The encrypted payload expires after 100 seconds.
About Oreefy
Oreefy is an affordable business ecosystem designed for small to enterprise businesses. Oreefy provides essential software you need for your modern business within a single ecosystem. It will save you significant time, effort, and money.
License
MIT © Oreefy
