writeonce/docs/examples/web-app
shoney.arickathil 82713e4010 feat: framework v1 slice 2 — the remaining ledger, ten items
- After seam: interface After + Aw + use_after; dispatch funnels every
  response (handler/short-circuit/404/405) through the after chain;
  the WS 101 sentinel skips it (never serialized)
- http/secure.wo: SecurityHeaders (nosniff/DENY/referrer; HSTS stays
  at the TLS proxy), Cors (preflight 204 before + origin stamp after,
  one class both halves), HostAllow (421), client_ip (XFF parsing —
  peer VERIFY stays story 35)
- http/nego.wo: accepts() (exact, type/*, */*; q stripped not ranked),
  etag_for (quoted base64 sha256), with_etag (If-None-Match -> 304)
- router: *rest wildcard (last segment, empty rest matches), Group
  (prefix + routes + group middleware) + Gmw prefix-scoped entries,
  App.mount; new App fields carry defaults so standing ctor literals
  keep compiling
- Req grows ctx bag; parse rejects duplicate Content-Length (400,
  RFC 9112 §6.3)
- web-app exercises all of it; gate grows 26 -> 38 checks (wildcards,
  group+ctx, etag+304, 406/200 negotiation, sec headers, 421,
  preflight+origin stamp, dup-CL 400)
- ledger rows flipped; dep graph section 3 grown (slice-2 done nodes,
  crypto gate cleared, cookie/CSRF/session/webhook/JWT now ready)
- merges: chat-ws-lifecycle (digests for ETag; WS + lifecycle ride
  along) + site-sample (second consumer gate); battery 13/13

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-23 06:45:51 +02:00
..
main.wo feat: framework v1 slice 2 — the remaining ledger, ten items 2026-08-23 06:45:51 +02:00
README.md feat(examples): framework skeleton + web-app scaffold (iter 16 Task 1) 2026-08-19 19:43:19 +02:00
types.wo feat: iterations 19 + 17 — Float/Bytes scalars (.wob v5), library kind + internal/ 2026-08-20 19:24:15 +02:00
wo.toml feat: web-app storefront + dep-relative use resolution (iter 16 Task 4) 2026-08-19 19:56:18 +02:00

web-app — the storefront sample

A small store: Product/Order as @table classes, JSON routes, one auth middleware — built on writeonce-framework, which it imports through [deps] (iteration 15). This app is iteration 16's acceptance workload: just web-app runs the whole chain — fetch → lock → build → serve → curl matrix → restart persistence → SIGTERM.

Routes

Route What
GET /products list (JSON array)
GET /products/:id one product or 404
POST /products create from a JSON body (name, price, stock); 400 on malformed JSON; 409 on a duplicate name (@unique)
POST /orders create (product, qty); FK checked
DELETE /products/:id 409 while orders reference it (FK restrict), 200 after

Every request needs authorization: Bearer <token> (the auth middleware); the token comes from the WA_TOKEN env var.

Run

woc .                       # fetches deps, builds target/web-app
WA_TOKEN=secret WO_DATA=./data ./target/web-app 8080

TLS / HTTP2

None here, deliberately: deploy behind nginx/caddy — the proxy terminates TLS+ALPN and speaks h2 to browsers while this backend serves HTTP/1.1 keep-alive. Sketch:

server {
  listen 443 ssl;
  http2 on;
  location / {
    proxy_pass http://127.0.0.1:8080;
    proxy_http_version 1.1;
    proxy_set_header Connection "";
  }
}