Files
oikos/web/node_modules/enhanced-resolve/lib/RestrictionsPlugin.js
dtoro d4d99a7473
Some checks failed
ci / build-test (push) Has been cancelled
ci / docker-build (push) Has been cancelled
feat: Phase 1 — extract the client (web SPA + desktop) to dtoro/oikos-web
Problem: the hexagonal refactor churns the backend tree for nine more
phases; the UI delivery stack (web/ SPA, cmd/desktop Wails wrapper,
compose/web image) must move to its own repo first so doc/layout
rewrites land once on a backend-only tree.

Change:
- New repo git.hubris.network/dtoro/oikos-web (v0.33.0): web/, desktop/
  (updateURL repointed to oikos-web releases), compose/, own CI (web +
  desktop jobs), own deploy script (CI-green gate, TOCTOU guard,
  version-tagged images, prune-to-3), own webhook receiver on :9798 +
  launchd unit, own compose project publishing the same 8091:80.
- Cutover executed on mac-mini in order: oikos stack's web service
  stopped+removed, oikos-web project brought up on 8091; outer Caddy
  untouched (targets the published port) — serving + Authentik flow +
  /wails 404 quirk verified post-cutover.
- Stripped from oikos: web/, cmd/desktop/, compose/web/, desktop CI
  workflow, ci.yml web job, Makefile ui/desktop/desktop-package/install
  targets, the compose web service, oikos-web from deploy.sh's fallback
  prune list; wails + go-keyring dropped from go.mod, vendor synced.
- README / CONTRIBUTING / AGENTS.md / .agents dev+operations docs now
  point at the new repo; mbse + mascot design docs carry a path note.

Risk: production SPA serving depends on the new pipeline now; rollback
is versioned-image re-up of the old web service from a pre-split
checkout (port 8091). Desktop builds installed before the split still
check dtoro/oikos releases — one manual reinstall, noted in the
oikos-web release notes.

Verification: go vet, make test (race), make generate-check, golangci
(no new findings; baseline down 400→365); post-cutover curls —
localhost:8091 200, /wails/runtime.js 404, outer Caddy 302 Authentik.
2026-08-15 22:27:52 +02:00

87 lines
2.4 KiB
JavaScript

/*
MIT License http://www.opensource.org/licenses/mit-license.php
Author Ivan Kopeykin @vankop
*/
"use strict";
const { isInside, normalize } = require("./util/path");
/** @typedef {import("./Resolver")} Resolver */
/** @typedef {import("./Resolver").ResolveStepHook} ResolveStepHook */
/**
* @typedef {object} PathRestriction
* @property {"path"} type type of the restriction
* @property {string} rule normalized path the request has to be inside of
*/
/**
* @typedef {object} RegExpRestriction
* @property {"regexp"} type type of the restriction
* @property {RegExp} rule pattern the request has to match
*/
/** @typedef {PathRestriction | RegExpRestriction} Restriction */
module.exports = class RestrictionsPlugin {
/**
* @param {string | ResolveStepHook} source source
* @param {Set<string | RegExp>} restrictions restrictions
*/
constructor(source, restrictions) {
this.source = source;
this.restrictions = restrictions;
// Restrictions never change, so bringing them into the shape requests
// arrive in is done once here instead of on every request.
/** @type {Restriction[]} */
this._restrictions = [];
for (const rule of restrictions) {
this._restrictions.push(
typeof rule === "string"
? { type: "path", rule: normalize(rule) }
: { type: "regexp", rule },
);
}
}
/**
* @param {Resolver} resolver the resolver
* @returns {void}
*/
apply(resolver) {
resolver
.getHook(this.source)
.tapAsync("RestrictionsPlugin", (request, resolveContext, callback) => {
if (typeof request.path === "string") {
const { path } = request;
for (const restriction of this._restrictions) {
if (restriction.type === "path") {
if (isInside(restriction.rule, path)) continue;
if (resolveContext.log) {
resolveContext.log(
`${path} is not inside of the restriction ${restriction.rule}`,
);
}
} else {
if (restriction.rule.test(path)) continue;
if (resolveContext.log) {
resolveContext.log(
`${path} doesn't match the restriction ${restriction.rule}`,
);
}
}
// Target existed (FileExistsPlugin already passed) but is
// outside the jail; signal ExportsFieldPlugin to fall back.
if (request.__restrictionsMarker) {
request.__restrictionsMarker.blocked = true;
}
return callback(null, null);
}
}
callback();
});
}
};