FluxFlow.Components.Http 2.0.0

There is a newer version of this package available.
See the version list below for details.
dotnet add package FluxFlow.Components.Http --version 2.0.0
                    
NuGet\Install-Package FluxFlow.Components.Http -Version 2.0.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="FluxFlow.Components.Http" Version="2.0.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="FluxFlow.Components.Http" Version="2.0.0" />
                    
Directory.Packages.props
<PackageReference Include="FluxFlow.Components.Http" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add FluxFlow.Components.Http --version 2.0.0
                    
#r "nuget: FluxFlow.Components.Http, 2.0.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package FluxFlow.Components.Http@2.0.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=FluxFlow.Components.Http&version=2.0.0
                    
Install as a Cake Addin
#tool nuget:?package=FluxFlow.Components.Http&version=2.0.0
                    
Install as a Cake Tool

FluxFlow.Components.Http

Reusable HTTP request components for FluxFlow.

Nodes

Node type Shape Purpose
http.client resource Owns the HTTP sender lifecycle (base URL, host allow-list, redirects, timeout, pooling). Request nodes reference it by name.
http.request InputOutput, Errors Sends HTTP requests through a borrowed client and emits typed responses or request errors.

Register both node types once:

registry.RegisterHttpComponents();

Client resource

The http.client node owns the sender. It is a resource: http.request does not build its own client, it borrows the established sender from an http.client by name. Transport and security settings live on the client.

{
  "type": "http.client",
  "name": "internal-api",
  "baseUrl": "https://api.internal.example",
  "defaultTimeoutMilliseconds": 100000,
  "followRedirects": true,
  "restrictToBaseUrlOrigin": true,
  "allowedHosts": [ "api.internal.example", ".internal.example" ],
  "pooledConnectionLifetimeSeconds": 300,
  "maxConnectionsPerServer": 20,
  "defaultHeaders": { "x-api-key": "..." }
}

http.request requires a client that names an http.client resource. The reference is mandatory; there is no inline transport configuration on the request node.

{
  "type": "http.request",
  "name": "call-api",
  "client": "internal-api",
  "maxResponseBodyBytes": 1048576,
  "treatNonSuccessStatusAsError": false,
  "boundedCapacity": 128
}

http.request consumes HttpRequestInput values and emits HttpResponseOutput values. Network, timeout, cancellation, invalid URL, and body size failures are emitted through HttpErrorOutput on the Errors port. The node continues processing later messages after a per-message failure.

Non-success status codes do not fault the node. Responses are emitted with Success = false. When treatNonSuccessStatusAsError is enabled, the response is still emitted and a matching error item is also emitted.

Connecting (host-driven)

Connecting is an explicit host decision: there is no auto-connect or lazy connect. StartAsync on the client is a no-op. The host establishes and tears down the sender through IHttpClientHandle:

await client.ConnectAsync(cancellationToken);
// ... run the graph ...
await client.DisconnectAsync(cancellationToken);

http.request borrows the established sender at call-time and never builds or disposes it. A request sent before the client is connected is reported per message on the Errors port rather than faulting the node.

Security

A host that processes untrusted message URLs should restrict where requests can go on the http.client, because defaultHeaders (often credentials) are attached to every request:

  • allowedHosts (default empty = allow all): when non-empty, the resolved absolute URL host must match one entry. Entries match case-insensitively, either exactly or as a leading-dot suffix such as .internal.example.
  • restrictToBaseUrlOrigin (default false): when true, absolute message URLs must match the baseUrl scheme, host, and port.

Violations are reported per message through the Errors port with kind UrlNotAllowed and the message is dropped. Header names and values containing CR, LF, or NUL characters are also rejected per message before the request is sent.

Runtime Timing

Responses and request errors use the package clock for timestamps and elapsed milliseconds. The package uses System.TimeProvider (default TimeProvider.System); there is no bespoke HTTP clock interface. Hosts and tests can provide a deterministic TimeProvider through registration:

registry.RegisterHttpComponents(options => options
    .UseClock(httpClock));

Sender Ownership

The http.client resource builds a default pooled sender from its options. Hosts that need custom authentication, tracing, proxy settings, or test doubles can provide IHttpRequestSenderFactory through registration:

registry.RegisterHttpComponents(options => options
    .UseClock(httpClock)
    .UseRequestSenderFactory(myFactory));

The sender factory receives the resolved client handle and configured clock. The http.client resource disposes senders it creates through the configured factory.

Design Metadata

This package exposes a package-owned IComponentDesignMetadataProvider for its node types. Hosts can compose it through ComponentDesignMetadataCatalog to populate palettes, editors, validation views, and documentation without duplicating package descriptors.

Composition Guidance

Use this package as one part of a host-composed graph. See Component Composition for recommended host boundaries, package boundaries, and extraction timing.

Product Compatible and additional computed target framework versions.
.NET net8.0 is compatible.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages (2)

Showing the top 2 NuGet packages that depend on FluxFlow.Components.Http:

Package Downloads
FluxFlow.Components.Http.AspNetCore

ASP.NET Core HTTP trigger adapter for FluxFlow: maps an endpoint's HttpContext onto the request/reply bridge so an inbound request flows into a graph and the correlated response is written back. The only FluxFlow package that references ASP.NET Core.

FluxFlow.Components.Http.Composition

Canonical HTTP FlowContent/result registration and Designer metadata over host-owned keyed HttpClient resources.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
7.0.0-rc.1 84 9/5/2026
6.0.0 231 8/3/2026
3.0.2 146 7/3/2026
3.0.1 207 7/2/2026
3.0.0 148 6/19/2026
2.0.0 137 6/18/2026
1.2.1 120 6/15/2026
1.2.0 419 6/12/2026
1.1.0 118 6/5/2026
1.0.0 117 6/4/2026
0.2.0-alpha.1 246 6/2/2026
0.1.1-alpha.1 91 6/2/2026
0.1.0-alpha.1 101 6/1/2026

2.0 preview: the node's static Create(RuntimeNodeFactoryContext …) factory moves into a dedicated internal *NodeFactory class, removing the public static Create from the node type (breaking). Node registration, options, ports, JSON shape, and runtime behavior are unchanged. Replaces the bespoke IHttpClock abstraction with System.TimeProvider (UseClock now takes a TimeProvider; the old clock interface/implementation are removed). Introduces a separate http.client resource component that owns the client configuration (base URL, allowed hosts, redirect policy, timeout, pooling); http.request now references it by a required client name and no longer carries client-level config. For now the client holds configuration only — no HttpClient is established, so http.request reports a not-connected result until a later connect step. Adds an explicit, host-driven connect lifecycle: http.client now exposes ConnectAsync/DisconnectAsync (plus a State and a lock-free TryGetSender), owning the pooled HttpClient/sender built via a new client-scoped sender context; http.request borrows the sender when connected and reports not-connected otherwise, never connecting or disposing. The allowed-hosts/redirect SSRF guard is preserved (per-request validation plus AllowAutoRedirect disabled under a guard). No auto-connect.