- http/auth.wo: auth_header (scheme split, case-insensitive, RFC 9110),
bearer_token, basic_credentials (first-colon split, RFC 7617),
pure-.wo base64_decode (RFC 4648, strict padding), ct_eq constant-time
compare (no early exit, both Basic fields always compared)
- req.principal: the blessed "who is this" slot, "" until authenticated;
Middleware.before now takes mut req so auth can write it
- BearerAuth { token, principal } and BasicAuth { user, pass, realm }
middlewares; BasicAuth answers the WWW-Authenticate challenge; policy
(routes/users/secrets) stays app-side on the exposed fns
- web-app dogfoods BearerAuth; its hand-rolled Auth class deleted
- probe matrix 26/26 (RFC 4648 vectors, rfc7617 pair, pass-with-colon,
bad padding/chars/length, deny paths, challenge header) release+ASan
- gate grows 16 -> 17: wrong bearer token answers 401 over the wire
- README: auth bullet + the core CHECKLIST (done / candidate / parked
behind 8-11 by design); story 16 + board record the landing
- all gates green: web-app 17/0, oop-e2e 89/0, deps-accept 8/0,
log-watcher 7/0, employee 8/0, woc-test green
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
||
|---|---|---|
| .. | ||
| main.wo | ||
| README.md | ||
| types.wo | ||
| wo.toml | ||
web-app — the storefront sample
A small store: Product/Order as @table classes, JSON routes, one auth
middleware — built on writeonce-framework, which
it imports through [deps] (iteration 15). This app is iteration 16's
acceptance workload: just web-app runs the whole chain — fetch → lock →
build → serve → curl matrix → restart persistence → SIGTERM.
Routes
| Route | What |
|---|---|
GET /products |
list (JSON array) |
GET /products/:id |
one product or 404 |
POST /products |
create from a JSON body (name, price, stock); 400 on malformed JSON; 409 on a duplicate name (@unique) |
POST /orders |
create (product, qty); FK checked |
DELETE /products/:id |
409 while orders reference it (FK restrict), 200 after |
Every request needs authorization: Bearer <token> (the auth middleware);
the token comes from the WA_TOKEN env var.
Run
woc . # fetches deps, builds target/web-app
WA_TOKEN=secret WO_DATA=./data ./target/web-app 8080
TLS / HTTP2
None here, deliberately: deploy behind nginx/caddy — the proxy terminates TLS+ALPN and speaks h2 to browsers while this backend serves HTTP/1.1 keep-alive. Sketch:
server {
listen 443 ssl;
http2 on;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_http_version 1.1;
proxy_set_header Connection "";
}
}