writeonce/docs/examples/web-app
shoney.arickathil 296efb52ed docs(db2-ephemeral): databasev2 2 closes — task 6a contract, forks 1–7, the README sweep
- story 02: `status: done`, `review_pending` (forks 1–7 auto-approved for
  autonomy); progress rows 6a ✅, 6b ➡ databasev2 5 Phase A, 7 `a310496`;
  5c/5d rows cite the `dev` hashes (the pre-merge ones were unreachable);
  task 6a's Given/When/Then met; Info records the seven forks (sentinel over
  `:memory:`, its rules, the refusal contract, startup-only, the budget
  leaves for 5, library-owned tables bind consumers, the v8 table bit);
  History keeps the first cut that refused every class-bearing program
- database/src/CODE-LOGIC.md: "Startup refusal + WO_EPHEMERAL" — contract,
  hatch, table bit, measured blast radius, deferred items, proof; the
  dispatcher paragraph no longer says a failed commit un-applies the row
  (fatal since databasev2 4 part A; WO_T_IO unreachable from a write path)
- residency spec + plan: task 6 items annotated with the 2026-09-09
  decisions; the byte budget marked moved to databasev2 5
- README, seven example READMEs and four guides carry the one-line rule
  (durable default refuses without WO_DATA; WO_EPHEMERAL=1; durable:
  false); shop's RAM-only command sets the sentinel

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
(cherry picked from commit 2c3531998124042fe736388e8b926abda3841194)
2026-09-15 01:16:24 +02:00
..
main.wo refactor(porch): name the web framework porch, fix the wo.toml identifier claim 2026-08-26 19:36:34 +02:00
README.md docs(db2-ephemeral): databasev2 2 closes — task 6a contract, forks 1–7, the README sweep 2026-09-15 01:16:24 +02:00
types.wo feat: iterations 19 + 17 — Float/Bytes scalars (.wob v5), library kind + internal/ 2026-08-20 19:24:15 +02:00
wo.toml refactor(porch): name the web framework porch, fix the wo.toml identifier claim 2026-08-26 19:36:34 +02:00

web-app — the storefront sample

A small store: Product/Order as @table classes, JSON routes, one auth middleware — built on porch, which it imports through [deps] (iteration 15). This app is iteration 16's acceptance workload: just web-app runs the whole chain — fetch → lock → build → serve → curl matrix → restart persistence → SIGTERM.

Routes

Route What
GET /products list (JSON array)
GET /products/:id one product or 404
POST /products create from a JSON body (name, price, stock); 400 on malformed JSON; 409 on a duplicate name (@unique)
POST /orders create (product, qty); FK checked
DELETE /products/:id 409 while orders reference it (FK restrict), 200 after

Every request needs authorization: Bearer <token> (the auth middleware); the token comes from the WA_TOKEN env var.

Run

woc .                       # fetches deps, builds target/web-app
WA_TOKEN=secret WO_DATA=./data ./target/web-app 8080

A program with any durable table (the default) refuses to start without WO_DATA; WO_EPHEMERAL=1 opts into a RAM-only run, @table(durable: false) opts a table out.

TLS / HTTP2

This sample runs plaintext behind nginx/caddy — the proxy terminates TLS+ALPN and speaks h2 to browsers while this backend serves HTTP/1.1 keep-alive. The runtime itself can now terminate TLS 1.3 (net.accept_tls, runtime-v2 9, 2026-09-09; see docs/examples/tls-server), so the proxy is a deployment choice here, not a requirement — HTTP/2 is the remaining reason to keep it. Sketch:

server {
  listen 443 ssl;
  http2 on;
  location / {
    proxy_pass http://127.0.0.1:8080;
    proxy_http_version 1.1;
    proxy_set_header Connection "";
  }
}