All checks were successful
Sync infra to hosts / sync-beta (push) Successful in 13s
Sync infra to hosts / sync-prod (push) Successful in 12s
secrets-guard / encrypted (push) Successful in 7s
shell-lint / shellcheck (push) Successful in 8s
Build + push frontend image (Forgejo registry) / build-push (push) Successful in 53s
Deploy frontend to beta VPS / deploy (push) Successful in 1m16s
secrets-guard / encrypted (pull_request) Successful in 5s
shell-lint / shellcheck (pull_request) Successful in 6s
Ports frontend/ (Jinja2/FastAPI, ~1180 LOC) to Go with html/template. No climate math, no DB, no auth -- every route fetches from the backend's /content/* API. Verified with a golden-HTML diff, not just unit tests: both the Python original and the Go rewrite were run against the same committed fixtures and every route compared byte-for-byte, confirmed programmatically. That process caught defects unit tests alone missed, since map[string]any has no compile-time field check: - Render-context keys were snake_case throughout while the templates read PascalCase fields. A missing map key doesn't error, it silently renders empty -- title, meta description, canonical URL, OpenGraph tags, and the homepage's entire ranked list were blank on every page despite every route returning 200. Fixed by renaming every key to match each template's own documented field contract, and passing API structs straight through wherever their fields already matched (removes a whole layer of future drift risk). - Three pages 500'd: ToolHref needed a composed href, not a bare "lat,lon" fragment; the records table needed the raw API struct. - JSON-LD was double-encoded: <script type="application/ld+json"> is JAVASCRIPT context to html/template's escaper regardless of the script's type attribute, so template.HTML gets re-escaped as a quoted JS string. Needed template.JS. The glossary term page's JSON-LD was never built at all -- added. - html/template silently strips literal HTML and JS comments from parsed output (verified in isolation) -- both need a FuncMap function returning template.HTML/template.JS to survive. Packaging: 187MB -> 22.6MB. Two defects caught before reaching a host: the Swarm stack's entrypoint override with no explicit command drops the image's CMD entirely (every deploy would have exited 127), and COPY --chown by name fails under the classic Docker builder on Alpine. Both fixed. go build/vet/test -race clean; docker build passes its embedded test step under both BuildKit and the classic builder; shellcheck 0 findings.
119 lines
4.5 KiB
Go
119 lines
4.5 KiB
Go
package content
|
|
|
|
import (
|
|
"net/http"
|
|
"strings"
|
|
)
|
|
|
|
// RobotsTxt is the port of content.py's robots_txt — the body is built the
|
|
// same way, byte for byte.
|
|
func (h *Handlers) RobotsTxt(w http.ResponseWriter, r *http.Request) {
|
|
base := h.cfg.Base
|
|
baseURL := origin(r) + base
|
|
body := "User-agent: *\n" +
|
|
"Allow: /\n" +
|
|
"Disallow: " + base + "/api/\n" +
|
|
"Disallow: " + base + "/alerts\n" +
|
|
"Sitemap: " + baseURL + "/sitemap.xml\n"
|
|
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
|
|
w.Write([]byte(body))
|
|
}
|
|
|
|
// SitemapXML is the port of content.py's sitemap_xml: one <url> line per
|
|
// backend sitemap entry, <lastmod> pinned to the per-process boot date.
|
|
// ~2.35 MB and crawled repeatedly — the short Cache-Control saves every
|
|
// crawler hit within the window a full Sitemap() call plus the string build,
|
|
// on top of the response body itself (the backend client's TTL cache absorbs
|
|
// the rest).
|
|
func (h *Handlers) SitemapXML(w http.ResponseWriter, r *http.Request) {
|
|
baseURL := origin(r) + h.cfg.Base
|
|
entries, err := h.api.Sitemap()
|
|
if err != nil {
|
|
h.apiError(w, err)
|
|
return
|
|
}
|
|
var b strings.Builder
|
|
b.WriteString(`<?xml version="1.0" encoding="UTF-8"?>` + "\n")
|
|
b.WriteString(`<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">`)
|
|
for _, e := range entries {
|
|
b.WriteString("\n<url><loc>")
|
|
b.WriteString(baseURL)
|
|
b.WriteString(e.Path)
|
|
b.WriteString("</loc><lastmod>")
|
|
b.WriteString(h.bootDate)
|
|
b.WriteString("</lastmod><changefreq>")
|
|
b.WriteString(e.Changefreq)
|
|
b.WriteString("</changefreq><priority>")
|
|
b.WriteString(e.Priority)
|
|
b.WriteString("</priority></url>")
|
|
}
|
|
b.WriteString("\n</urlset>")
|
|
w.Header().Set("Content-Type", "application/xml")
|
|
w.Header().Set("Cache-Control", "public, max-age=300")
|
|
w.Write([]byte(b.String()))
|
|
}
|
|
|
|
// registerIndexNow wires the IndexNow key file. IndexNow verification works
|
|
// by serving a file at /<key>.txt — the key isn't just response *content*,
|
|
// it's baked into the route *path*, which the mux needs at registration
|
|
// time. That used to mean an eager, unretried key fetch at boot — so if the
|
|
// backend was unreachable (down, mid-restart, a network blip) the frontend
|
|
// would never finish booting at all. That's exactly the coupling the
|
|
// repo-split removed: frontend and backend deploy asynchronously, so
|
|
// "backend happens to be briefly unreachable" must be a normal, survivable
|
|
// condition at frontend boot, not a crash.
|
|
//
|
|
// So: try the eager fetch once (preserving the plain static route for the
|
|
// overwhelmingly common case where the backend IS reachable at boot). If it
|
|
// fails, log a warning and fall back to a route that lazily (re)fetches the
|
|
// key on each request via the client's TTL cache — once the backend comes
|
|
// back up the correct key starts being served automatically, no frontend
|
|
// restart required, and no request ever gets a permanently wrong/empty key.
|
|
//
|
|
// Mux mechanics differ from Starlette here: Go's patterns cannot express the
|
|
// Python's "/{token}.txt" suffix wildcard, so the lazy fallback claims the
|
|
// whole single-segment slot ({BASE}/{token}) and forwards anything that
|
|
// isn't a .txt request to the static file server it displaced (explicit page
|
|
// routes still win on specificity).
|
|
func (h *Handlers) registerIndexNow(mux *http.ServeMux, static http.Handler) {
|
|
base := h.cfg.Base
|
|
key, err := h.api.IndexNowKey()
|
|
if err == nil {
|
|
mux.HandleFunc("GET "+base+"/"+key+".txt", func(w http.ResponseWriter, r *http.Request) {
|
|
writeKey(w, key)
|
|
})
|
|
return
|
|
}
|
|
h.log.Printf("indexnow_key fetch failed at boot (backend unreachable?) -- "+
|
|
"continuing boot without it; falling back to lazy per-request lookup at "+
|
|
"/<key>.txt so the frontend doesn't depend on backend liveness to start up: %v", err)
|
|
|
|
mux.HandleFunc("GET "+base+"/{token}", func(w http.ResponseWriter, r *http.Request) {
|
|
token := r.PathValue("token")
|
|
if !strings.HasSuffix(token, ".txt") {
|
|
// Not a key-file request: this pattern displaced the static
|
|
// subtree for single-segment paths, so hand it back.
|
|
if static != nil {
|
|
static.ServeHTTP(w, r)
|
|
return
|
|
}
|
|
http.NotFound(w, r)
|
|
return
|
|
}
|
|
key, err := h.api.IndexNowKey()
|
|
if err != nil {
|
|
writeDetail(w, http.StatusServiceUnavailable, "backend unavailable")
|
|
return
|
|
}
|
|
if strings.TrimSuffix(token, ".txt") != key {
|
|
writeDetail(w, http.StatusNotFound, "Not Found")
|
|
return
|
|
}
|
|
writeKey(w, key)
|
|
})
|
|
}
|
|
|
|
func writeKey(w http.ResponseWriter, key string) {
|
|
w.Header().Set("Content-Type", "text/plain; charset=utf-8")
|
|
w.Write([]byte(key + "\n"))
|
|
}
|