writeonce/docs/examples/web-app/README.md
shoney.arickathil ad1ad8361c docs(audit): fix stale docs against the code (TLS, net.connect, RNG, lang-41); jarvis deps
Code is the source of truth; these claims no longer matched runtime/src:

- "net.connect does not exist" — landed 2026-09-07 (id 110); net.connect_tls /
  read_tls / write_tls (115-117) + net.accept_tls (118), WO_B_MAX 118. Fixed
  in jarvis 00-story (problem statement + architecture + out-of-scope), porch
  00-story (proxy middleware row), rv2 7 (push-collector fork), 00-code-review
- "TLS: none / proxy-mandated forever" — retired by rv2 9 (in-process TLS both
  directions). Fixed in porch + web-app + site example READMEs (proxy is now a
  deployment choice; HSTS row), 00-code-review
- "no RNG anywhere in the runtime" — imprecise: the runtime has a getrandom(2)
  source since rv2 9 (TLS ephemerals), but nothing exposes it to .wo yet.
  Fixed in CODE-LOGIC (digests), lang 34, porch 2, status lang-39 row
- "porch 9 blocked on language 41" — lang 41 fixed 63065ff. Fixed in porch 1,
  jarvis 00-story, status NEXT PLAN, dependency graph (L41 done, P9 ready)
- dependency graph §7 rewritten: the runtime side is done; jarvis 1 waits only
  on porch (developer's porch-first order). Adds jarvis 1's dependency table +
  the build order that satisfies it
- 00-code-review: a dated 2026-09-09 re-verification appended (record kept)
- site README lives in the writeonce-site submodule: committed there, pointer
  bumped here

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
(cherry picked from commit f1049dd9b7c7770da28bcabfc1cb1324621e7ee6)
2026-09-15 01:16:13 +02:00

44 lines
1.6 KiB
Markdown

# web-app — the storefront sample
A small store: `Product`/`Order` as `@table` classes, JSON routes, one auth
middleware — built on [`porch`](../porch/), which
it imports **through `[deps]`** (iteration 15). This app is iteration 16's
acceptance workload: `just web-app` runs the whole chain — fetch → lock →
build → serve → curl matrix → restart persistence → SIGTERM.
## Routes
| Route | What |
| --- | --- |
| `GET /products` | list (JSON array) |
| `GET /products/:id` | one product or 404 |
| `POST /products` | create from a JSON body (`name`, `price`, `stock`); 400 on malformed JSON; 409 on a duplicate name (`@unique`) |
| `POST /orders` | create (`product`, `qty`); FK checked |
| `DELETE /products/:id` | 409 while orders reference it (FK restrict), 200 after |
Every request needs `authorization: Bearer <token>` (the auth middleware);
the token comes from the `WA_TOKEN` env var.
## Run
woc . # fetches deps, builds target/web-app
WA_TOKEN=secret WO_DATA=./data ./target/web-app 8080
## TLS / HTTP2
This sample runs plaintext behind nginx/caddy — the proxy terminates TLS+ALPN
and speaks h2 to browsers while this backend serves HTTP/1.1 keep-alive. The
runtime itself can now terminate TLS 1.3 (`net.accept_tls`, runtime-v2 9,
2026-09-09; see `docs/examples/tls-server`), so the proxy is a deployment
choice here, not a requirement — HTTP/2 is the remaining reason to keep it.
Sketch:
server {
listen 443 ssl;
http2 on;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_http_version 1.1;
proxy_set_header Connection "";
}
}