- rename the two libraries: writeonce-framework -> writeonce-serve
(`use serve`), wo-html -> writeonce-view (`use view`). Names say the
ROLE now; every sample, script, gate and live doc follows
- stories/specs/plans keep the old names: they are dated records, and
both library READMEs carry a "renamed 2026-08-25" note
- serve/http/files.wo: StaticFiles { dir, max_bytes } — traversal
refused not normalised, extension content types, attachment
disposition for archives. Lifted out of the shop, which had said in
a comment that it belonged in the framework
- shop drops its private copy and mounts the framework's
- site: /dl/*path over $WO_DIST (default ./dist), 16 MiB ceiling
- /install gains supported systems — Linux x86-64, glibc >= 2.38,
not musl — read off `file` and the binaries' GLIBC_ symbol
versions, not off a wish list; plus GitHub release as primary,
/dl as mirror, and the sha256 verify step
- site-accept: 17 -> 21 checks (supported systems, gzip download with
a binary-safe probe, checksum, /dl traversal 404)
Verified on 192.168.0.165: the real 960,820-byte tarball downloads
as application/gzip and its sha256 matches the published digest.
Gates: oop-accept MET, site 21/0, web-app 46/0, fibers 10/0,
db-actor 8/0; shop rebuilt and its /assets served by the framework.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
28 lines
1.3 KiB
Text
28 lines
1.3 KiB
Text
-- http/form.wo — the public body-inspection surface: what media type a
|
|
-- request carries, and form-encoded bodies as decoded pairs.
|
|
--
|
|
-- PUBLIC by design (iteration 17). It sits here rather than in
|
|
-- `internal/parse.wo` with the rest of the parsing code because these two
|
|
-- functions are exactly what a consuming app calls; the decoders they lean on
|
|
-- stay behind the privacy line. `use internal` is legal INSIDE the library —
|
|
-- the boundary is consumer-only.
|
|
use internal
|
|
|
|
-- The request's media type: the content-type header lowercased with any
|
|
-- parameters ("; charset=...") stripped; "" when the header is absent.
|
|
pub fn media_type(req: Req) -> Text {
|
|
let ct = req.headers["content-type"];
|
|
if ct == nil { return ""; }
|
|
let semi = index_of(ct, ";");
|
|
if semi >= 0 { return to_lower(trim(substr(ct, 0, semi))); }
|
|
return to_lower(trim("${ct}"));
|
|
}
|
|
|
|
-- Form-encoded body -> decoded pairs ('+' as space, %XX), the body-parsing
|
|
-- hook for application/x-www-form-urlencoded. nil when the content-type
|
|
-- says the body is something else — a JSON body is not silently misread
|
|
-- as one giant form key.
|
|
pub fn form_values(req: Req) -> ?map<Text, Text> {
|
|
if media_type(req) != "application/x-www-form-urlencoded" { return nil; }
|
|
return parse_query(req.body);
|
|
}
|