feat: add combined frontend and API Docker deployment
This commit is contained in:
1 parent
0b2588e09c
commit
a5f1236d44
12 files changed
+429
-2
No files matched your search
@@ -5,7 +5,7 @@
|
||||
"dev": "node scripts/dev.cjs",
|
||||
"build": "tsc",
|
||||
"typecheck": "tsc --noEmit",
|
||||
"test": "tsx --test --test-concurrency=1 test/calculation.test.ts test/update.test.ts test/zip.test.ts test/metals.test.ts ../web/test/i18n.test.ts test/account-deletion.test.ts test/mcp-hosts.test.ts test/mcp-http.test.ts test/network.test.ts ../web/test/quick-entry.test.ts ../web/test/net-worth-chart.test.ts ../web/test/login-preferences.test.ts",
|
||||
"test": "tsx --test --test-concurrency=1 test/calculation.test.ts test/update.test.ts test/zip.test.ts test/metals.test.ts ../web/test/i18n.test.ts test/account-deletion.test.ts test/mcp-hosts.test.ts test/mcp-http.test.ts test/network.test.ts test/web.test.ts ../web/test/quick-entry.test.ts ../web/test/net-worth-chart.test.ts ../web/test/login-preferences.test.ts",
|
||||
"db:generate": "prisma generate",
|
||||
"db:migrate": "node scripts/database.cjs deploy",
|
||||
"db:status": "node scripts/database.cjs status",
|
||||
|
||||
@@ -26,6 +26,7 @@ import { AgentOperations } from './mcp/operations';
|
||||
import { AgentFiles } from './mcp/files';
|
||||
import { AgentTransport } from './mcp/transport';
|
||||
import { AgentManagementController } from './mcp/management';
|
||||
import { installWeb } from './web';
|
||||
@Catch()
|
||||
class SafeErrors implements ExceptionFilter {
|
||||
catch(error: unknown, host: ArgumentsHost) {
|
||||
@@ -132,6 +133,7 @@ async function bootstrap() {
|
||||
app.get(AgentTransport).install(app.getHttpAdapter().getInstance());
|
||||
app.useGlobalFilters(new SafeErrors());
|
||||
setupOpenApi(app);
|
||||
installWeb(app.getHttpAdapter().getInstance());
|
||||
app.enableShutdownHooks();
|
||||
await app.listen(Number(process.env.PORT || 3100), network.apiHost);
|
||||
console.log('WorthPath API ready');
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
import { existsSync } from 'node:fs';
|
||||
import { join } from 'node:path';
|
||||
import { Express, static as serveStatic } from 'express';
|
||||
|
||||
/** Serve only the current Vite assets and page entries; leave service routes to Nest/OAuth. */
|
||||
export function installWeb(app: Express, directory = join(__dirname, '../public')) {
|
||||
const index = join(directory, 'index.html');
|
||||
if (!existsSync(index)) return false;
|
||||
|
||||
app.use('/assets', serveStatic(join(directory, 'assets'), { index: false, redirect: false }));
|
||||
const pages = new Set(['/', '/agent/authorize', '/agent/operation']);
|
||||
app.use((req, res, next) => {
|
||||
if (!['GET', 'HEAD'].includes(req.method) || !pages.has(req.path)) return next();
|
||||
res.setHeader('Cache-Control', 'no-store');
|
||||
res.sendFile(index, (error) => {
|
||||
if (error) next(error);
|
||||
});
|
||||
});
|
||||
return true;
|
||||
}
|
||||
@@ -0,0 +1,80 @@
|
||||
import { test } from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
import express from 'express';
|
||||
import { mkdtemp, mkdir, writeFile, rm } from 'node:fs/promises';
|
||||
import { tmpdir } from 'node:os';
|
||||
import { join } from 'node:path';
|
||||
import { AddressInfo } from 'node:net';
|
||||
import { installWeb } from '../src/web';
|
||||
|
||||
test('combined web serves pages/assets without swallowing API, MCP, OAuth or missing assets', async () => {
|
||||
const dir = await mkdtemp(join(tmpdir(), 'worthpath-web-'));
|
||||
const app = express();
|
||||
let server: ReturnType<typeof app.listen> | undefined;
|
||||
try {
|
||||
assert.equal(installWeb(app, join(dir, 'missing')), false);
|
||||
await mkdir(join(dir, 'assets'));
|
||||
await writeFile(join(dir, 'index.html'), '<html>WorthPath test page</html>');
|
||||
await writeFile(join(dir, 'assets', 'app.js'), 'window.worthpath = true;');
|
||||
assert.equal(installWeb(app, dir), true);
|
||||
// Register downstream service routes to detect accidental web interception.
|
||||
for (const path of [
|
||||
'/api/probe',
|
||||
'/mcp',
|
||||
'/authorize',
|
||||
'/token',
|
||||
'/register',
|
||||
'/revoke',
|
||||
'/.well-known/oauth-authorization-server',
|
||||
]) {
|
||||
app.all(path, (_req, res) => res.status(401).json({ service: path }));
|
||||
}
|
||||
app.use((_req, res) => res.status(404).json({ missing: true }));
|
||||
server = app.listen(0, '127.0.0.1');
|
||||
await new Promise<void>((resolve) => server!.once('listening', resolve));
|
||||
const base = `http://127.0.0.1:${(server.address() as AddressInfo).port}`;
|
||||
for (const path of [
|
||||
'/',
|
||||
'/?agent_operation=test',
|
||||
'/agent/authorize?agent_authorization=test',
|
||||
'/agent/operation',
|
||||
]) {
|
||||
const result = await fetch(base + path);
|
||||
assert.equal(result.status, 200);
|
||||
assert.match(result.headers.get('content-type') || '', /text\/html/);
|
||||
assert.equal(result.headers.get('cache-control'), 'no-store');
|
||||
assert.match(await result.text(), /WorthPath test page/);
|
||||
}
|
||||
const head = await fetch(base + '/', { method: 'HEAD' });
|
||||
assert.equal(head.status, 200);
|
||||
assert.equal(await head.text(), '');
|
||||
assert.match(await (await fetch(base + '/assets/app.js')).text(), /window.worthpath/);
|
||||
for (const path of ['/assets/missing.js', '/api/unknown', '/unknown']) {
|
||||
assert.equal((await fetch(base + path)).status, 404);
|
||||
}
|
||||
assert.equal((await fetch(base + '/', { method: 'POST' })).status, 404);
|
||||
for (const path of [
|
||||
'/api/probe',
|
||||
'/mcp',
|
||||
'/authorize',
|
||||
'/token',
|
||||
'/register',
|
||||
'/revoke',
|
||||
'/.well-known/oauth-authorization-server',
|
||||
]) {
|
||||
for (const method of ['GET', 'POST']) {
|
||||
const result = await fetch(base + path, { method });
|
||||
assert.equal(result.status, 401);
|
||||
assert.deepEqual(await result.json(), { service: path });
|
||||
}
|
||||
}
|
||||
} finally {
|
||||
if (server) {
|
||||
server.closeAllConnections();
|
||||
await new Promise<void>((resolve, reject) =>
|
||||
server!.close((error) => (error ? reject(error) : resolve())),
|
||||
);
|
||||
}
|
||||
await rm(dir, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
Reference in new issue
Block a user