# `SSL.QUIC`
[🔗](https://github.com/gsmlg-dev/http_fetch/blob/v0.16.7/apps/ex_ssl/lib/ssl/quic.ex#L1)

Caller-owned TLS 1.3 certificate handshake for QUIC CRYPTO streams.

Feed only new contiguous handshake bytes at the level reported by `info/1`.
Process returned actions in list order. Emitted bytes are committed to the
caller's reliable send queue; retransmission reuses them without another TLS
call. This API implements no sockets, records, QUIC packets or HANDSHAKE_DONE.
See `docs/QUIC_TLS_INTERFACE.md` for the ownership and authentication boundary.

# `action`

```elixir
@type action() ::
  SSL.QUIC.Secret.t()
  | {:emit, level(), binary()}
  | {:peer_transport_parameters, binary(), :unverified | :authenticated}
  | {:peer_authenticated, :server}
  | {:negotiated_alpn, binary()}
  | :handshake_complete
  | {:error, SSL.QUIC.Error.t()}
```

# `level`

```elixir
@type level() :: :initial | :handshake | :application
```

# `result`

```elixir
@type result() ::
  {:ok, state(), [action()]} | {:error, SSL.QUIC.Error.t(), state(), [action()]}
```

# `state`

```elixir
@opaque state()
```

# `abort`

```elixir
@spec abort(state(), atom()) :: state()
```

# `capabilities`

```elixir
@spec capabilities() :: %{
  cipher_suites: [any()],
  groups: [map()],
  hello_retry_request: true,
  quic_packet_protection: false,
  resumption: false,
  roles: %{client: map(), server: map()},
  server_mtls: false,
  signatures: [map()],
  tls_records: false,
  tls_versions: [772, ...],
  zero_rtt: false
}
```

# `feed`

```elixir
@spec feed(state(), level(), binary()) :: result()
```

# `info`

```elixir
@spec info(state()) :: map()
```

# `new`

```elixir
@spec new(:client | :server, keyword()) ::
  {:ok, state(), [action()]} | {:error, SSL.QUIC.Error.t()}
```

---

*Consult [api-reference.md](api-reference.md) for complete listing*
