pub fn widening_suggestions(host: &str) -> Vec<(String, &'static str)>Expand description
Widening suggestions for a refused host, most specific first (#443).
The = help: block used to name only the hop that was just refused, so
a publisher whose PDF sits behind www.x.org -> pubs.x.org cost the
user one edit-run cycle per hop. Naming the registrable domain too ends
it in one.
It is also the policy-consistent suggestion. The built-in allowlist is
written almost entirely as registrable-domain wildcards
(*.springer.com, *.wiley.com, *.aps.org), and ADR-0027’s stated
mitigation for widening the trusted surface is exactly that they are
“bounded registrable-domain wildcards”. Suggesting a bare FQDN was both
more work for the user and narrower than the convention the project
applies to itself. The apex is offered alongside the wildcard because a
single-suffix wildcard does not match it — the reason the built-in list
already carries both forms for doaj.org, arxiv.org and friends.
Conservative by construction: a suggestion is emitted only when the
derived parent is clearly registrable. Getting this exactly right needs
the public suffix list, and a wrong guess here is not cosmetic — it
would invite the user to trust *.co.uk.
Moved here from doiget-cli in #459 so the MCP and batch --json
surfaces get the same suggestions as the CLI rather than a second
implementation of them.