- docs/examples/writeonce-serve -> docs/examples/porch (git mv, history kept); `[deps]` key and import are now `porch` / `porch/http` / `porch/router` - name history preserved on the library README, not rewritten into dated records: writeonce-framework -> writeonce-serve (08-25) -> porch (08-26). Stories, specs, plans and the audit reports keep the older name by the repo's own convention; only live docs and every path link were rewritten - left alone deliberately: `internal/serve.wo`, `pub fn serve`, `serve_conn`, `app.serve(...)` — those are functions, not the module name - web-app/wo.toml comment corrected: it claimed hyphens are not identifier characters and named a key this file never used. lexer.ml's `is_ident_cont` DOES accept `-` (an internal dash is part of the identifier, which is why binary minus needs spaces), so a hyphenated key would be legal too - site now teaches the name: package card, the two-deps chapter and the handlers-are-classes chapter say `porch`; site-accept asserted the old /packages/serve route and caught the rename, as a gate should - gates: web-app 46/0, site 21/0, deps-accept 8/0, oop-e2e 116/0, linkcheck 0 broken / 0 anchors; porch typechecks entry-less as kind=library Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
33 lines
1.2 KiB
Text
33 lines
1.2 KiB
Text
-- admin.controller.wo — POST /admin/ch/:slug: title/body update,
|
|
-- form-encoded, bearer-gated. Mechanism (bearer_token, constant-time
|
|
-- ct_eq) is the framework's; POLICY — which routes, which token — is
|
|
-- this app's, right here. No rendering: the answer is a redirect.
|
|
use porch/http
|
|
|
|
pub class AdminEdit {
|
|
token: Text
|
|
|
|
fn handle(req: Req) -> Resp {
|
|
let got = bearer_token(req);
|
|
if got == nil { return unauthorized(); }
|
|
if ct_eq("${got}", self.token) == false { return unauthorized(); }
|
|
let slug = req.params["slug"];
|
|
if slug == nil { return not_found(); }
|
|
let hits = from c in Chapter where c.slug == slug take 1 select c;
|
|
if len(hits) == 0 { return not_found(); }
|
|
let f = form_values(req);
|
|
if f == nil { return bad_request("body must be form-encoded (title, body)"); }
|
|
let title = f["title"];
|
|
let body = f["body"];
|
|
if title == nil and body == nil { return bad_request("nothing to update"); }
|
|
if title != nil {
|
|
let t = trim("${title}");
|
|
if t == "" { return bad_request("title must not be empty"); }
|
|
hits[0].title = t;
|
|
}
|
|
if body != nil {
|
|
hits[0].body = "${body}";
|
|
}
|
|
return redirect("/ch/${slug}");
|
|
}
|
|
}
|