FluxFlow.Components.Http
2.0.0
See the version list below for details.
dotnet add package FluxFlow.Components.Http --version 2.0.0
NuGet\Install-Package FluxFlow.Components.Http -Version 2.0.0
<PackageReference Include="FluxFlow.Components.Http" Version="2.0.0" />
<PackageVersion Include="FluxFlow.Components.Http" Version="2.0.0" />
<PackageReference Include="FluxFlow.Components.Http" />
paket add FluxFlow.Components.Http --version 2.0.0
#r "nuget: FluxFlow.Components.Http, 2.0.0"
#:package FluxFlow.Components.Http@2.0.0
#addin nuget:?package=FluxFlow.Components.Http&version=2.0.0
#tool nuget:?package=FluxFlow.Components.Http&version=2.0.0
FluxFlow.Components.Http
Reusable HTTP request components for FluxFlow.
Nodes
| Node type | Shape | Purpose |
|---|---|---|
http.client |
resource | Owns the HTTP sender lifecycle (base URL, host allow-list, redirects, timeout, pooling). Request nodes reference it by name. |
http.request |
Input → Output, Errors |
Sends HTTP requests through a borrowed client and emits typed responses or request errors. |
Register both node types once:
registry.RegisterHttpComponents();
Client resource
The http.client node owns the sender. It is a resource: http.request does
not build its own client, it borrows the established sender from an
http.client by name. Transport and security settings live on the client.
{
"type": "http.client",
"name": "internal-api",
"baseUrl": "https://api.internal.example",
"defaultTimeoutMilliseconds": 100000,
"followRedirects": true,
"restrictToBaseUrlOrigin": true,
"allowedHosts": [ "api.internal.example", ".internal.example" ],
"pooledConnectionLifetimeSeconds": 300,
"maxConnectionsPerServer": 20,
"defaultHeaders": { "x-api-key": "..." }
}
http.request requires a client that names an http.client resource. The
reference is mandatory; there is no inline transport configuration on the
request node.
{
"type": "http.request",
"name": "call-api",
"client": "internal-api",
"maxResponseBodyBytes": 1048576,
"treatNonSuccessStatusAsError": false,
"boundedCapacity": 128
}
http.request consumes HttpRequestInput values and emits
HttpResponseOutput values. Network, timeout, cancellation, invalid URL, and
body size failures are emitted through HttpErrorOutput on the Errors port.
The node continues processing later messages after a per-message failure.
Non-success status codes do not fault the node. Responses are emitted with
Success = false. When treatNonSuccessStatusAsError is enabled, the response
is still emitted and a matching error item is also emitted.
Connecting (host-driven)
Connecting is an explicit host decision: there is no auto-connect or lazy
connect. StartAsync on the client is a no-op. The host establishes and tears
down the sender through IHttpClientHandle:
await client.ConnectAsync(cancellationToken);
// ... run the graph ...
await client.DisconnectAsync(cancellationToken);
http.request borrows the established sender at call-time and never builds or
disposes it. A request sent before the client is connected is reported per
message on the Errors port rather than faulting the node.
Security
A host that processes untrusted message URLs should restrict where requests can
go on the http.client, because defaultHeaders (often credentials) are
attached to every request:
allowedHosts(default empty = allow all): when non-empty, the resolved absolute URL host must match one entry. Entries match case-insensitively, either exactly or as a leading-dot suffix such as.internal.example.restrictToBaseUrlOrigin(defaultfalse): whentrue, absolute message URLs must match thebaseUrlscheme, host, and port.
Violations are reported per message through the Errors port with kind
UrlNotAllowed and the message is dropped. Header names and values containing
CR, LF, or NUL characters are also rejected per message before the request is
sent.
Runtime Timing
Responses and request errors use the package clock for timestamps and elapsed
milliseconds. The package uses System.TimeProvider (default
TimeProvider.System); there is no bespoke HTTP clock interface. Hosts and
tests can provide a deterministic TimeProvider through registration:
registry.RegisterHttpComponents(options => options
.UseClock(httpClock));
Sender Ownership
The http.client resource builds a default pooled sender from its options.
Hosts that need custom authentication, tracing, proxy settings, or test doubles
can provide IHttpRequestSenderFactory through registration:
registry.RegisterHttpComponents(options => options
.UseClock(httpClock)
.UseRequestSenderFactory(myFactory));
The sender factory receives the resolved client handle and configured clock.
The http.client resource disposes senders it creates through the configured
factory.
Design Metadata
This package exposes a package-owned IComponentDesignMetadataProvider for its
node types. Hosts can compose it through ComponentDesignMetadataCatalog to
populate palettes, editors, validation views, and documentation without
duplicating package descriptors.
Composition Guidance
Use this package as one part of a host-composed graph. See Component Composition for recommended host boundaries, package boundaries, and extraction timing.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net10.0
- FluxFlow.Components.Designer (>= 1.0.1)
- FluxFlow.Engine (>= 1.3.0)
-
net8.0
- FluxFlow.Components.Designer (>= 1.0.1)
- FluxFlow.Engine (>= 1.3.0)
- System.Threading.Tasks.Dataflow (>= 9.0.4)
NuGet packages (2)
Showing the top 2 NuGet packages that depend on FluxFlow.Components.Http:
| Package | Downloads |
|---|---|
|
FluxFlow.Components.Http.AspNetCore
ASP.NET Core HTTP trigger adapter for FluxFlow: maps an endpoint's HttpContext onto the request/reply bridge so an inbound request flows into a graph and the correlated response is written back. The only FluxFlow package that references ASP.NET Core. |
|
|
FluxFlow.Components.Http.Composition
Canonical HTTP FlowContent/result registration and Designer metadata over host-owned keyed HttpClient resources. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 7.0.0-rc.1 | 84 | 9/5/2026 |
| 6.0.0 | 231 | 8/3/2026 |
| 3.0.2 | 146 | 7/3/2026 |
| 3.0.1 | 207 | 7/2/2026 |
| 3.0.0 | 148 | 6/19/2026 |
| 2.0.0 | 137 | 6/18/2026 |
| 1.2.1 | 120 | 6/15/2026 |
| 1.2.0 | 419 | 6/12/2026 |
| 1.1.0 | 118 | 6/5/2026 |
| 1.0.0 | 117 | 6/4/2026 |
| 0.2.0-alpha.1 | 246 | 6/2/2026 |
| 0.1.1-alpha.1 | 91 | 6/2/2026 |
| 0.1.0-alpha.1 | 101 | 6/1/2026 |
2.0 preview: the node's static Create(RuntimeNodeFactoryContext …) factory moves into a dedicated internal *NodeFactory class, removing the public static Create from the node type (breaking). Node registration, options, ports, JSON shape, and runtime behavior are unchanged. Replaces the bespoke IHttpClock abstraction with System.TimeProvider (UseClock now takes a TimeProvider; the old clock interface/implementation are removed). Introduces a separate http.client resource component that owns the client configuration (base URL, allowed hosts, redirect policy, timeout, pooling); http.request now references it by a required client name and no longer carries client-level config. For now the client holds configuration only — no HttpClient is established, so http.request reports a not-connected result until a later connect step. Adds an explicit, host-driven connect lifecycle: http.client now exposes ConnectAsync/DisconnectAsync (plus a State and a lock-free TryGetSender), owning the pooled HttpClient/sender built via a new client-scoped sender context; http.request borrows the sender when connected and reports not-connected otherwise, never connecting or disposing. The allowed-hosts/redirect SSRF guard is preserved (per-request validation plus AllowAutoRedirect disabled under a guard). No auto-connect.