feat: Phase 1 — extract the client (web SPA + desktop) to dtoro/oikos-web
Problem: the hexagonal refactor churns the backend tree for nine more phases; the UI delivery stack (web/ SPA, cmd/desktop Wails wrapper, compose/web image) must move to its own repo first so doc/layout rewrites land once on a backend-only tree. Change: - New repo git.hubris.network/dtoro/oikos-web (v0.33.0): web/, desktop/ (updateURL repointed to oikos-web releases), compose/, own CI (web + desktop jobs), own deploy script (CI-green gate, TOCTOU guard, version-tagged images, prune-to-3), own webhook receiver on :9798 + launchd unit, own compose project publishing the same 8091:80. - Cutover executed on mac-mini in order: oikos stack's web service stopped+removed, oikos-web project brought up on 8091; outer Caddy untouched (targets the published port) — serving + Authentik flow + /wails 404 quirk verified post-cutover. - Stripped from oikos: web/, cmd/desktop/, compose/web/, desktop CI workflow, ci.yml web job, Makefile ui/desktop/desktop-package/install targets, the compose web service, oikos-web from deploy.sh's fallback prune list; wails + go-keyring dropped from go.mod, vendor synced. - README / CONTRIBUTING / AGENTS.md / .agents dev+operations docs now point at the new repo; mbse + mascot design docs carry a path note. Risk: production SPA serving depends on the new pipeline now; rollback is versioned-image re-up of the old web service from a pre-split checkout (port 8091). Desktop builds installed before the split still check dtoro/oikos releases — one manual reinstall, noted in the oikos-web release notes. Verification: go vet, make test (race), make generate-check, golangci (no new findings; baseline down 400→365); post-cutover curls — localhost:8091 200, /wails/runtime.js 404, outer Caddy 302 Authentik.
This commit is contained in:
85
web/node_modules/eslint-plugin-svelte/lib/rules/no-target-blank.js
generated
vendored
Normal file
85
web/node_modules/eslint-plugin-svelte/lib/rules/no-target-blank.js
generated
vendored
Normal file
@@ -0,0 +1,85 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
const utils_1 = require("../utils");
|
||||
const ast_utils_1 = require("../utils/ast-utils");
|
||||
/** Checks wether the given attr node is target="_blank" */
|
||||
function isTargetBlank(node) {
|
||||
return node.key.name === 'target' && (0, ast_utils_1.getStaticAttributeValue)(node) === '_blank';
|
||||
}
|
||||
/** Checks wether the given element node has secure rel="..." */
|
||||
function hasSecureRel(node, allowReferrer) {
|
||||
const attr = (0, ast_utils_1.findAttribute)(node, 'rel');
|
||||
if (attr) {
|
||||
const tags = [];
|
||||
for (const value of attr.value) {
|
||||
if (value.type === 'SvelteLiteral') {
|
||||
tags.push(...value.value.toLowerCase().split(' '));
|
||||
}
|
||||
}
|
||||
return tags && tags.includes('noopener') && (allowReferrer || tags.includes('noreferrer'));
|
||||
}
|
||||
return false;
|
||||
}
|
||||
/** Checks wether the given element node has external link */
|
||||
function hasExternalLink(node) {
|
||||
return node.attributes.some((attr) => attr.type === 'SvelteAttribute' &&
|
||||
attr.key.name === 'href' &&
|
||||
attr.value.length >= 1 &&
|
||||
attr.value[0].type === 'SvelteLiteral' &&
|
||||
/^(?:\w+:|\/\/)/.test(attr.value[0].value));
|
||||
}
|
||||
/** Checks wether the given element node has dynamic link */
|
||||
function hasDynamicLink(node) {
|
||||
const attr = (0, ast_utils_1.findAttribute)(node, 'href');
|
||||
if (attr) {
|
||||
return attr.value.some((v) => v.type === 'SvelteMustacheTag');
|
||||
}
|
||||
return Boolean((0, ast_utils_1.findShorthandAttribute)(node, 'href')) || Boolean((0, ast_utils_1.findBindDirective)(node, 'href'));
|
||||
}
|
||||
exports.default = (0, utils_1.createRule)('no-target-blank', {
|
||||
meta: {
|
||||
docs: {
|
||||
description: 'disallow `target="_blank"` attribute without `rel="noopener noreferrer"`',
|
||||
category: 'Security Vulnerability',
|
||||
recommended: false
|
||||
},
|
||||
schema: [
|
||||
{
|
||||
type: 'object',
|
||||
properties: {
|
||||
allowReferrer: {
|
||||
type: 'boolean'
|
||||
},
|
||||
enforceDynamicLinks: {
|
||||
enum: ['always', 'never']
|
||||
}
|
||||
},
|
||||
additionalProperties: false
|
||||
}
|
||||
],
|
||||
messages: {
|
||||
disallow: 'Using target="_blank" without rel="noopener noreferrer" is a security risk.'
|
||||
},
|
||||
type: 'problem'
|
||||
},
|
||||
create(context) {
|
||||
const configuration = context.options[0] || {};
|
||||
const allowReferrer = Boolean(configuration.allowReferrer) || false;
|
||||
const enforceDynamicLinks = configuration.enforceDynamicLinks || 'always';
|
||||
return {
|
||||
SvelteAttribute(node) {
|
||||
if (!isTargetBlank(node) || hasSecureRel(node.parent, allowReferrer)) {
|
||||
return;
|
||||
}
|
||||
const hasDangerHref = hasExternalLink(node.parent) ||
|
||||
(enforceDynamicLinks === 'always' && hasDynamicLink(node.parent));
|
||||
if (hasDangerHref) {
|
||||
context.report({
|
||||
node,
|
||||
message: 'Using target="_blank" without rel="noopener noreferrer" is a security risk.'
|
||||
});
|
||||
}
|
||||
}
|
||||
};
|
||||
}
|
||||
});
|
||||
Reference in New Issue
Block a user