Skip to content

Architecture

Leonard Ramminger edited this page Aug 31, 2026 · 1 revision

Architecture

Data flow

YAML profile
    -> yaml_parser -> ApiDefinition
ApiDefinition -> profile_store (install) -> Protobuf .pb / bytes
Protobuf bytes -> profile_store (load) -> ApiDefinition
ApiDefinition -> call_engine -> PreparedHttpRequest
PreparedHttpRequest -> YcallrClient (reqwest) or YcallrWasmClient (fetch)

Runtime loads compiled protobuf only. YAML is parsed at install or compile time.

Module map

Path Responsibility
profile_store.rs compile_yaml_str, install_profile, load_installed_profile, load_from_proto_bytes
yaml_parser.rs Parse YAML (validate() at ingest; parse_yaml_for_client() at install)
models/ Domain types: ApiDefinition, Command, auth, body, responses
models/validation.rs URL, auth refs, body rules, env names, SSRF checks
compiler/ YAML and Protobuf via prost
call_engine/ Request prep: templates, env, auth, query, body, response messages (no HTTP I/O)
client/ YcallrClient builder and reqwest execution
ffi.rs C bindings (ycallr.h)
wasm.rs WASM bindings and browser fetch client

Cargo features

Feature Enables
yaml (default) YAML parsing
protobuf (default) Protobuf serialization
call-engine Shared request preparation
client HTTP client (reqwest; enables call-engine)
ffi C FFI (client + yaml + protobuf)
wasm WebAssembly bindings
test-utils Mock client and test helpers

Default features: yaml, protobuf. Use --all-features for full CI parity.

Validation split

  • validate() at YAML or protobuf ingest: blocks loopback, private IPv4, link-local IPv6, metadata hosts.
  • validate_for_client() at client build: allows loopback for local or mock testing.
  • FFI ycallr_set_base_url() overrides the base URL at runtime without re-validation.

HTTP client behavior

Redirects are disabled (Policy::none) to reduce SSRF risk.

Clone this wiki locally