- rename the two libraries: writeonce-framework -> writeonce-serve
(`use serve`), wo-html -> writeonce-view (`use view`). Names say the
ROLE now; every sample, script, gate and live doc follows
- stories/specs/plans keep the old names: they are dated records, and
both library READMEs carry a "renamed 2026-08-25" note
- serve/http/files.wo: StaticFiles { dir, max_bytes } — traversal
refused not normalised, extension content types, attachment
disposition for archives. Lifted out of the shop, which had said in
a comment that it belonged in the framework
- shop drops its private copy and mounts the framework's
- site: /dl/*path over $WO_DIST (default ./dist), 16 MiB ceiling
- /install gains supported systems — Linux x86-64, glibc >= 2.38,
not musl — read off `file` and the binaries' GLIBC_ symbol
versions, not off a wish list; plus GitHub release as primary,
/dl as mirror, and the sha256 verify step
- site-accept: 17 -> 21 checks (supported systems, gzip download with
a binary-safe probe, checksum, /dl traversal 404)
Verified on 192.168.0.165: the real 960,820-byte tarball downloads
as application/gzip and its sha256 matches the published digest.
Gates: oop-accept MET, site 21/0, web-app 46/0, fibers 10/0,
db-actor 8/0; shop rebuilt and its /assets served by the framework.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
49 lines
No EOL
1.8 KiB
Text
49 lines
No EOL
1.8 KiB
Text
-- http/nego.wo — framework v1 slice 2: response-side content negotiation
|
|
-- and ETag / conditional requests (the crypto slice's first ledger
|
|
-- consumer beyond the WS handshake).
|
|
|
|
-- Does the request accept this media type? Absent Accept = yes (RFC 9110
|
|
-- §12.5.1: no header means anything goes). Matching is exact, type/*,
|
|
-- or */*; q-values are stripped, not ranked — v1 answers CAN I send
|
|
-- this, not WHICH ONE is best (a ranking negotiation waits for an app
|
|
-- that serves alternates).
|
|
pub fn accepts(req: Req, mtype: Text) -> Bool {
|
|
let acc = req.headers["accept"];
|
|
if acc == nil { return true; }
|
|
let slash = index_of(mtype, "/");
|
|
let major = mtype;
|
|
if slash >= 0 { major = substr(mtype, 0, slash); }
|
|
for part in split(to_lower("${acc}"), ",") {
|
|
let item = trim(part);
|
|
let semi = index_of(item, ";");
|
|
if semi >= 0 { item = trim(substr(item, 0, semi)); }
|
|
if item == mtype { return true; }
|
|
if item == "*/*" { return true; }
|
|
if item == "${major}/*" { return true; }
|
|
}
|
|
return false;
|
|
}
|
|
|
|
-- A strong ETag for a body: quoted base64 of its SHA-256. Deterministic,
|
|
-- content-addressed — two identical bodies share one tag across
|
|
-- restarts and shards.
|
|
pub fn etag_for(body: Text) -> Text {
|
|
return "\"${base64_encode(sha256(bytes_of_text(body)))}\"";
|
|
}
|
|
|
|
-- Stamp the response's ETag and collapse it to 304 when the request's
|
|
-- If-None-Match already has it. The 304 keeps the etag header and
|
|
-- drops the body (RFC 9110 §15.4.5). Call it last in a handler:
|
|
-- return with_etag(req, ok_json(body));
|
|
pub fn with_etag(req: Req, take r: Resp) -> Resp {
|
|
let tag = etag_for(r.body);
|
|
r.headers["etag"] = tag;
|
|
let inm = req.headers["if-none-match"];
|
|
if inm != nil {
|
|
if trim(inm) == tag {
|
|
r.status = 304;
|
|
r.body = "";
|
|
}
|
|
}
|
|
return r;
|
|
} |