HORIZON HASKELLDocslts/ghc-9.10.xc74966e2026-09-27Search names, modules, packages, or :: a typeCtrl K

GHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27

Modulehttp2-tls-0.4.5Haskell2010

Network.HTTP2.TLS.Client

Running an HTTP/2 client over TLS.

  • 6 types
  • 28 values
  • Packagehttp2-tls-0.4.5
  • Exports34
  • LanguageHaskell2010
  • LicenceBSD-3-Clause
  • SourceClient.hs

Runners

7 declarations
typetype HostName = String
#

Either a host name e.g., "haskell.org" or a numeric host address string consisting of a dotted decimal IPv4 address or an IPv6 address e.g., "192.168.0.1".

newtypenewtype PortNumber
#

Port number. Use the Num instance (i.e. use a literal) to create a PortNumber value.

Example6 expressions
1 :: PortNumber1read "1" :: PortNumber1show (12345 :: PortNumber)"12345"50000 < (51000 :: PortNumber)True50000 < (52000 :: PortNumber)True50000 + (10000 :: PortNumber)60000
Instances10Bounded, Enum, Eq, Integral, Num, Ord, …

Generalized API

Default authority

When we connect to a server, we can distinguish between three names, all of which may be different:

  1. The HostName, used for the DNS lookup to get the server's IP

  2. The HTTP2 :authority pseudo-header

  3. The TLS SNI (Server Name Indicator). This is different from (2) only in exceptional circumstances, see settingsServerNameOverride.

In most cases, however, all three names are identical, and so the default Authority is simply equal to the ServerName.

Settings

17 declarations
valuesettingsKeyLogger :: Settings -> String -> IO ()
#

Key logger (TLS and H2)

Applications may wish to set this depending on the SSLKEYLOGFILE environment variable.

Default: do nothing.

How many pushed responses are contained in the cache (H2 and H2c)

Example1 expression
settingsCacheLimits defaultSettings64

Server name override (H2)

By default, the server name (for TLS SNI) is set based on the Network.HTTP2.Client.authority, corresponding to the HTTP2 :authority pseudo-header. In rare circumstances these two values should be different (for example in the case of domain fronting); settingsServerNameOverride can be used to give SNI a different value than :authority.

Try to use 0-RTT (H2 and TLS)

This is only supported for tls >= 2.0.

Example1 expression
settingsUseEarlyData defaultSettingsFalse

Rate limits

Maximum number of pings allowed per second (CVE-2019-9512)

Example1 expression
settingsPingRateLimit defaultSettings10

Maximum number of settings frames allowed per second (CVE-2019-9515)

Example1 expression
settingsSettingsRateLimit defaultSettings4

Maximum number of reset frames allowed per second (CVE-2023-44487)

Example1 expression
settingsRstRateLimit4