- rename the two libraries: writeonce-framework -> writeonce-serve
(`use serve`), wo-html -> writeonce-view (`use view`). Names say the
ROLE now; every sample, script, gate and live doc follows
- stories/specs/plans keep the old names: they are dated records, and
both library READMEs carry a "renamed 2026-08-25" note
- serve/http/files.wo: StaticFiles { dir, max_bytes } — traversal
refused not normalised, extension content types, attachment
disposition for archives. Lifted out of the shop, which had said in
a comment that it belonged in the framework
- shop drops its private copy and mounts the framework's
- site: /dl/*path over $WO_DIST (default ./dist), 16 MiB ceiling
- /install gains supported systems — Linux x86-64, glibc >= 2.38,
not musl — read off `file` and the binaries' GLIBC_ symbol
versions, not off a wish list; plus GitHub release as primary,
/dl as mirror, and the sha256 verify step
- site-accept: 17 -> 21 checks (supported systems, gzip download with
a binary-safe probe, checksum, /dl traversal 404)
Verified on 192.168.0.165: the real 960,820-byte tarball downloads
as application/gzip and its sha256 matches the published digest.
Gates: oop-accept MET, site 21/0, web-app 46/0, fibers 10/0,
db-actor 8/0; shop rebuilt and its /assets served by the framework.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
33 lines
1.2 KiB
Text
33 lines
1.2 KiB
Text
-- admin.controller.wo — POST /admin/ch/:slug: title/body update,
|
|
-- form-encoded, bearer-gated. Mechanism (bearer_token, constant-time
|
|
-- ct_eq) is the framework's; POLICY — which routes, which token — is
|
|
-- this app's, right here. No rendering: the answer is a redirect.
|
|
use serve/http
|
|
|
|
pub class AdminEdit {
|
|
token: Text
|
|
|
|
fn handle(req: Req) -> Resp {
|
|
let got = bearer_token(req);
|
|
if got == nil { return unauthorized(); }
|
|
if ct_eq("${got}", self.token) == false { return unauthorized(); }
|
|
let slug = req.params["slug"];
|
|
if slug == nil { return not_found(); }
|
|
let hits = from c in Chapter where c.slug == slug take 1 select c;
|
|
if len(hits) == 0 { return not_found(); }
|
|
let f = form_values(req);
|
|
if f == nil { return bad_request("body must be form-encoded (title, body)"); }
|
|
let title = f["title"];
|
|
let body = f["body"];
|
|
if title == nil and body == nil { return bad_request("nothing to update"); }
|
|
if title != nil {
|
|
let t = trim("${title}");
|
|
if t == "" { return bad_request("title must not be empty"); }
|
|
hits[0].title = t;
|
|
}
|
|
if body != nil {
|
|
hits[0].body = "${body}";
|
|
}
|
|
return redirect("/ch/${slug}");
|
|
}
|
|
}
|