Class UrlDownloads

java.lang.Object
io.github.intisy.gradle.github.impl.download.UrlDownloads
All Implemented Interfaces:
Downloads

public final class UrlDownloads extends Object implements Downloads
Downloads a jar from an arbitrary HTTP(S) URL, caching it under a directory keyed by a hash of jarUrl, and verifying an optional expected SHA-256 of the downloaded content.
Implementation Note:
Header values are user secrets, and a URL can carry one too (a presigned or ?token= URL, or https://user:token@host/...). This class never writes a header value anywhere but the outgoing Request, and every log line and exception message that names jarUrl runs it through UrlRedaction.redact(java.lang.String) first, stripping userinfo and the query string. The cache file name is a hash of jarUrl alone (via UrlDigest), never the URL itself. A redirect is followed per RedirectPolicyInterceptor: same-host keeps the caller's headers, cross-host strips them, and https-to-http is refused.
  • Constructor Details

    • UrlDownloads

      public UrlDownloads(okhttp3.OkHttpClient httpClient, GitHubLogger logger, File cacheDir)
      Parameters:
      httpClient - issues the download request; injected so tests can intercept it without a real network call. OkHttp's own redirect-following is always disabled and replaced with RedirectPolicyInterceptor on top of whatever httpClient was configured with, so the caller's client need not already disable it.
      logger - receives diagnostic output.
      cacheDir - the directory downloaded jars are cached under, keyed by a hash of the URL.
  • Method Details

    • download

      public File download(String jarUrl, Map<String,String> headers, String sha256) throws IOException
      Specified by:
      download in interface Downloads
      Parameters:
      jarUrl - the exact URL to download from.
      headers - request headers (for example, an auth token) to send with the download; may be null or empty.
      sha256 - the expected SHA-256 of the downloaded jar, hex-encoded, or null to skip integrity verification.
      Returns:
      the cached jar for jarUrl, downloaded only when not already cached.
      Throws:
      IOException - if the download fails, or the downloaded content does not match sha256.