feat(server): CORS, ws subprotocol auth and --web-dir; GPL-3.0-only - #75
Merged
Merged
Conversation
Server: - --cors-origin (repeatable) answers preflight before the key check and only for the listed origins; nothing is allowed by default - /ws also accepts the key as a bearer.<key> subprotocol, so a browser can authenticate without putting it in the URL; REST ignores it - --web-dir serves a built client at / with an index.html fallback and never shadows /api or /ws - NewAppServer takes an Options struct Build: add ./configure, which writes config.mk (PREFIX, BINDIR), and include it from the Makefile. License: switch every SPDX header and the README, CONTRIBUTING, COPYRIGHT and PR template wording from GPL-3.0-or-later to GPL-3.0-only.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Server side of a separate web/desktop client, plus a relicense.
--cors-origin(repeatable): preflight is answered before the key check and only for listed origins. Nothing is allowed by default./wsalso accepts the key as abearer.<key>subprotocol, so a browser can authenticate without the key appearing in a URL or in gin's request log. REST ignores it.--web-dir: serves a built client at/with anindex.htmlfallback. It never shadows/apior/ws.NewAppServertakes anOptionsstruct../configurewritesconfig.mk(PREFIX,BINDIR); the Makefile includes it.Relicense
Every SPDX header and the wording in README, CONTRIBUTING, COPYRIGHT and the PR template change from
GPL-3.0-or-latertoGPL-3.0-only. This is most of the file count (156 one-line header changes); the functional change is confined toserver/,cli/serve.go,configureand the Makefile.The license text in
LICENSEis unchanged. Git history has commits from the maintainer and dependabot only, so no outside contributor'sor-latergrant is affected.Test plan
make fmt vetandgo test ./...pass/wsconnects withbearer.<key>and rejects a wrong key with 401; the key does not appear in the server log--web-dirserves/, static files and SPA paths;/api/unknownand non-GET requests return 404