noggin

HTTP(S) provider

The HTTP(S) provider loads a noggin from a remote URL. It's read-only by design: there's no portable, authenticated write protocol that fits every server, so the provider rejects every apply(ops) with code: 'read-only'. Hosts use this to display shared noggins (GitHub-hosted YAML files, raw URLs) without giving the user a misleading "I can edit this" experience.

At a glance

Schemeshttps://, http://
Module@noggin/engine/providers/http
PersistentSource-controlled (whoever owns the URL)
Read-onlyYes — apply() always rejects
AuthNone — only public URLs (or whatever the runtime's fetch allows)
Runs inNode (≥18), browsers, Deno — anywhere with fetch

When to use

Use this when you want to read a noggin that lives somewhere else — a sample noggin on GitHub, a teammate's URL, a snapshot from a CI artifact. The desktop app's "Open from URL…" picker drives this provider; so does any host that wants to preview a noggin without copying it locally.

If you need to mutate the remote noggin, sync it back to a file first (download → edit → push) or use a different backend behind a custom provider.

Quick start

import { openNoggin } from '@noggin/engine';
import '@noggin/engine/providers/http';

const noggin = await openNoggin('https://example.com/sample.yaml');

console.log(noggin.items.map((i) => i.title));
console.log(noggin.readOnly); // true

await noggin.dispose();

Or directly:

import { openHttpNoggin } from '@noggin/engine/providers/http';

const noggin = await openHttpNoggin(
  'https://raw.githubusercontent.com/dornstein/noggin/main/docs/site/playground/sample.yaml',
);

The provider fetches whatever URL you give it. It doesn't rewrite or massage the input — host UIs that want to translate friendly forms (a github.com/.../blob/... URL into the raw. equivalent, a bare hostname into https://...) do that at the picker boundary before calling openNoggin.

Read-only contract

Every mutation rejects with NogginError({ code: 'read-only' }). Including the bound shortcuts:

await noggin.push({ title: 'nope' });
// → NogginError: code 'read-only', "remote noggin is read-only"

The returned noggin also carries a readOnly: true flag. UI code should read it and disable mutation affordances preemptively rather than waiting for an error round-trip:

{!noggin.readOnly && <AddButton onClick={...} />}

Behaviour

Error codes you might see

CodeWhen
http-fetch-failedThe fetch threw (network down, DNS, CORS in a browser)
http-errorThe server replied with a non-2xx status
http-invalid-yamlThe body parsed as something that wasn't a valid noggin document (e.g. HTML)
schema-version-mismatchThe document declares an unknown schemaVersion
read-onlyAny apply() call

Security notes