Problem: the hexagonal refactor churns the backend tree for nine more phases; the UI delivery stack (web/ SPA, cmd/desktop Wails wrapper, compose/web image) must move to its own repo first so doc/layout rewrites land once on a backend-only tree. Change: - New repo git.hubris.network/dtoro/oikos-web (v0.33.0): web/, desktop/ (updateURL repointed to oikos-web releases), compose/, own CI (web + desktop jobs), own deploy script (CI-green gate, TOCTOU guard, version-tagged images, prune-to-3), own webhook receiver on :9798 + launchd unit, own compose project publishing the same 8091:80. - Cutover executed on mac-mini in order: oikos stack's web service stopped+removed, oikos-web project brought up on 8091; outer Caddy untouched (targets the published port) — serving + Authentik flow + /wails 404 quirk verified post-cutover. - Stripped from oikos: web/, cmd/desktop/, compose/web/, desktop CI workflow, ci.yml web job, Makefile ui/desktop/desktop-package/install targets, the compose web service, oikos-web from deploy.sh's fallback prune list; wails + go-keyring dropped from go.mod, vendor synced. - README / CONTRIBUTING / AGENTS.md / .agents dev+operations docs now point at the new repo; mbse + mascot design docs carry a path note. Risk: production SPA serving depends on the new pipeline now; rollback is versioned-image re-up of the old web service from a pre-split checkout (port 8091). Desktop builds installed before the split still check dtoro/oikos releases — one manual reinstall, noted in the oikos-web release notes. Verification: go vet, make test (race), make generate-check, golangci (no new findings; baseline down 400→365); post-cutover curls — localhost:8091 200, /wails/runtime.js 404, outer Caddy 302 Authentik.
95 lines
2.5 KiB
JSON
95 lines
2.5 KiB
JSON
{
|
|
"$schema": "http://json-schema.org/draft-07/schema#",
|
|
"$id": "https://raw.githubusercontent.com/ajv-validator/ajv/master/lib/refs/json-schema-secure.json#",
|
|
"title": "Meta-schema for the security assessment of JSON Schemas",
|
|
"description": "If a JSON Schema fails validation against this meta-schema, it may be unsafe to validate untrusted data",
|
|
"definitions": {
|
|
"schemaArray": {
|
|
"type": "array",
|
|
"minItems": 1,
|
|
"items": {"$ref": "#"}
|
|
}
|
|
},
|
|
"dependencies": {
|
|
"patternProperties": {
|
|
"description": "prevent slow validation of large property names",
|
|
"required": ["propertyNames"],
|
|
"properties": {
|
|
"propertyNames": {
|
|
"required": ["maxLength"]
|
|
}
|
|
}
|
|
},
|
|
"uniqueItems": {
|
|
"description": "prevent slow validation of large non-scalar arrays",
|
|
"if": {
|
|
"properties": {
|
|
"uniqueItems": {"const": true},
|
|
"items": {
|
|
"properties": {
|
|
"type": {
|
|
"anyOf": [
|
|
{
|
|
"enum": ["object", "array"]
|
|
},
|
|
{
|
|
"type": "array",
|
|
"contains": {"enum": ["object", "array"]}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"then": {
|
|
"required": ["maxItems"]
|
|
}
|
|
},
|
|
"pattern": {
|
|
"description": "prevent slow pattern matching of large strings",
|
|
"required": ["maxLength"]
|
|
},
|
|
"format": {
|
|
"description": "prevent slow format validation of large strings",
|
|
"required": ["maxLength"]
|
|
}
|
|
},
|
|
"properties": {
|
|
"additionalItems": {"$ref": "#"},
|
|
"additionalProperties": {"$ref": "#"},
|
|
"dependencies": {
|
|
"additionalProperties": {
|
|
"anyOf": [
|
|
{"type": "array"},
|
|
{"$ref": "#"}
|
|
]
|
|
}
|
|
},
|
|
"items": {
|
|
"anyOf": [
|
|
{"$ref": "#"},
|
|
{"$ref": "#/definitions/schemaArray"}
|
|
]
|
|
},
|
|
"definitions": {
|
|
"additionalProperties": {"$ref": "#"}
|
|
},
|
|
"patternProperties": {
|
|
"additionalProperties": {"$ref": "#"}
|
|
},
|
|
"properties": {
|
|
"additionalProperties": {"$ref": "#"}
|
|
},
|
|
"if": {"$ref": "#"},
|
|
"then": {"$ref": "#"},
|
|
"else": {"$ref": "#"},
|
|
"allOf": {"$ref": "#/definitions/schemaArray"},
|
|
"anyOf": {"$ref": "#/definitions/schemaArray"},
|
|
"oneOf": {"$ref": "#/definitions/schemaArray"},
|
|
"not": {"$ref": "#"},
|
|
"contains": {"$ref": "#"},
|
|
"propertyNames": {"$ref": "#"}
|
|
}
|
|
}
|