- rename the two libraries: writeonce-framework -> writeonce-serve
(`use serve`), wo-html -> writeonce-view (`use view`). Names say the
ROLE now; every sample, script, gate and live doc follows
- stories/specs/plans keep the old names: they are dated records, and
both library READMEs carry a "renamed 2026-08-25" note
- serve/http/files.wo: StaticFiles { dir, max_bytes } — traversal
refused not normalised, extension content types, attachment
disposition for archives. Lifted out of the shop, which had said in
a comment that it belonged in the framework
- shop drops its private copy and mounts the framework's
- site: /dl/*path over $WO_DIST (default ./dist), 16 MiB ceiling
- /install gains supported systems — Linux x86-64, glibc >= 2.38,
not musl — read off `file` and the binaries' GLIBC_ symbol
versions, not off a wish list; plus GitHub release as primary,
/dl as mirror, and the sha256 verify step
- site-accept: 17 -> 21 checks (supported systems, gzip download with
a binary-safe probe, checksum, /dl traversal 404)
Verified on 192.168.0.165: the real 960,820-byte tarball downloads
as application/gzip and its sha256 matches the published digest.
Gates: oop-accept MET, site 21/0, web-app 46/0, fibers 10/0,
db-actor 8/0; shop rebuilt and its /assets served by the framework.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
41 lines
1.4 KiB
Markdown
41 lines
1.4 KiB
Markdown
# web-app — the storefront sample
|
|
|
|
A small store: `Product`/`Order` as `@table` classes, JSON routes, one auth
|
|
middleware — built on [`writeonce-serve`](../writeonce-serve/), which
|
|
it imports **through `[deps]`** (iteration 15). This app is iteration 16's
|
|
acceptance workload: `just web-app` runs the whole chain — fetch → lock →
|
|
build → serve → curl matrix → restart persistence → SIGTERM.
|
|
|
|
## Routes
|
|
|
|
| Route | What |
|
|
| --- | --- |
|
|
| `GET /products` | list (JSON array) |
|
|
| `GET /products/:id` | one product or 404 |
|
|
| `POST /products` | create from a JSON body (`name`, `price`, `stock`); 400 on malformed JSON; 409 on a duplicate name (`@unique`) |
|
|
| `POST /orders` | create (`product`, `qty`); FK checked |
|
|
| `DELETE /products/:id` | 409 while orders reference it (FK restrict), 200 after |
|
|
|
|
Every request needs `authorization: Bearer <token>` (the auth middleware);
|
|
the token comes from the `WA_TOKEN` env var.
|
|
|
|
## Run
|
|
|
|
woc . # fetches deps, builds target/web-app
|
|
WA_TOKEN=secret WO_DATA=./data ./target/web-app 8080
|
|
|
|
## TLS / HTTP2
|
|
|
|
None here, deliberately: deploy behind nginx/caddy — the proxy terminates
|
|
TLS+ALPN and speaks h2 to browsers while this backend serves HTTP/1.1
|
|
keep-alive. Sketch:
|
|
|
|
server {
|
|
listen 443 ssl;
|
|
http2 on;
|
|
location / {
|
|
proxy_pass http://127.0.0.1:8080;
|
|
proxy_http_version 1.1;
|
|
proxy_set_header Connection "";
|
|
}
|
|
}
|