writeonce/docs/examples/web-app/README.md
shoney.arickathil 47a920f19a feat(serve+view): file serving, downloads, supported systems; rename
- rename the two libraries: writeonce-framework -> writeonce-serve
  (`use serve`), wo-html -> writeonce-view (`use view`). Names say the
  ROLE now; every sample, script, gate and live doc follows
- stories/specs/plans keep the old names: they are dated records, and
  both library READMEs carry a "renamed 2026-08-25" note
- serve/http/files.wo: StaticFiles { dir, max_bytes } — traversal
  refused not normalised, extension content types, attachment
  disposition for archives. Lifted out of the shop, which had said in
  a comment that it belonged in the framework
- shop drops its private copy and mounts the framework's
- site: /dl/*path over $WO_DIST (default ./dist), 16 MiB ceiling
- /install gains supported systems — Linux x86-64, glibc >= 2.38,
  not musl — read off `file` and the binaries' GLIBC_ symbol
  versions, not off a wish list; plus GitHub release as primary,
  /dl as mirror, and the sha256 verify step
- site-accept: 17 -> 21 checks (supported systems, gzip download with
  a binary-safe probe, checksum, /dl traversal 404)

Verified on 192.168.0.165: the real 960,820-byte tarball downloads
as application/gzip and its sha256 matches the published digest.

Gates: oop-accept MET, site 21/0, web-app 46/0, fibers 10/0,
db-actor 8/0; shop rebuilt and its /assets served by the framework.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-25 04:41:00 +02:00

1.4 KiB

web-app — the storefront sample

A small store: Product/Order as @table classes, JSON routes, one auth middleware — built on writeonce-serve, which it imports through [deps] (iteration 15). This app is iteration 16's acceptance workload: just web-app runs the whole chain — fetch → lock → build → serve → curl matrix → restart persistence → SIGTERM.

Routes

Route What
GET /products list (JSON array)
GET /products/:id one product or 404
POST /products create from a JSON body (name, price, stock); 400 on malformed JSON; 409 on a duplicate name (@unique)
POST /orders create (product, qty); FK checked
DELETE /products/:id 409 while orders reference it (FK restrict), 200 after

Every request needs authorization: Bearer <token> (the auth middleware); the token comes from the WA_TOKEN env var.

Run

woc .                       # fetches deps, builds target/web-app
WA_TOKEN=secret WO_DATA=./data ./target/web-app 8080

TLS / HTTP2

None here, deliberately: deploy behind nginx/caddy — the proxy terminates TLS+ALPN and speaks h2 to browsers while this backend serves HTTP/1.1 keep-alive. Sketch:

server {
  listen 443 ssl;
  http2 on;
  location / {
    proxy_pass http://127.0.0.1:8080;
    proxy_http_version 1.1;
    proxy_set_header Connection "";
  }
}