Skip to content

feat(server): CORS, ws subprotocol auth and --web-dir; GPL-3.0-only - #75

Merged
devproje merged 1 commit into
masterfrom
feat/server-web-client
Sep 21, 2026
Merged

devproje merged 1 commit into
masterfrom
feat/server-web-client

Conversation

@devproje

@devproje devproje commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Summary

Server side of a separate web/desktop client, plus a relicense.

  • --cors-origin (repeatable): preflight is answered before the key check and only for listed origins. Nothing is allowed by default.
  • /ws also accepts the key as a bearer.<key> subprotocol, so a browser can authenticate without the key appearing in a URL or in gin's request log. REST ignores it.
  • --web-dir: serves a built client at / with an index.html fallback. It never shadows /api or /ws.
  • NewAppServer takes an Options struct.
  • ./configure writes config.mk (PREFIX, BINDIR); the Makefile includes it.

Relicense

Every SPDX header and the wording in README, CONTRIBUTING, COPYRIGHT and the PR template change from GPL-3.0-or-later to GPL-3.0-only. This is most of the file count (156 one-line header changes); the functional change is confined to server/, cli/serve.go, configure and the Makefile.

The license text in LICENSE is unchanged. Git history has commits from the maintainer and dependabot only, so no outside contributor's or-later grant is affected.

Test plan

  • make fmt vet and go test ./... pass
  • Preflight from an allowed origin returns 204 with the CORS headers; a disallowed origin gets none
  • /ws connects with bearer.<key> and rejects a wrong key with 401; the key does not appear in the server log
  • --web-dir serves /, static files and SPA paths; /api/unknown and non-GET requests return 404
  • Try it from the separate client against a real gateway

Server:
- --cors-origin (repeatable) answers preflight before the key check and only
  for the listed origins; nothing is allowed by default
- /ws also accepts the key as a bearer.<key> subprotocol, so a browser can
  authenticate without putting it in the URL; REST ignores it
- --web-dir serves a built client at / with an index.html fallback and never
  shadows /api or /ws
- NewAppServer takes an Options struct

Build: add ./configure, which writes config.mk (PREFIX, BINDIR), and include it
from the Makefile.

License: switch every SPDX header and the README, CONTRIBUTING, COPYRIGHT and
PR template wording from GPL-3.0-or-later to GPL-3.0-only.
@devproje
devproje merged commit 0933136 into master Sep 21, 2026
3 checks passed
@devproje
devproje deleted the feat/server-web-client branch September 21, 2026 11:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant