webserve

package
v0.15.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 13, 2026 License: MIT Imports: 2 Imported by: 0

Documentation

Overview

Package webserve centralizes the production HTTP-serving conventions shared by the deepwork web services — the standalone terminal (net/http) and the pro host (Gin): the standard security-header set and content-hash-aware cache headers for Vite SPA builds. One source of truth so the two services can't drift on what "production-correct headers" means. The primitives operate on a bare http.Header, so a net/http middleware and a Gin middleware can both drive them without reimplementing the policy.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func AssetCacheControl

func AssetCacheControl(urlPath string) string

AssetCacheControl returns the Cache-Control for a path served from a Vite build: content- hashed assets/* are immutable (cached a year), the shell (index.html, sw.js, manifest, icons) is no-cache so a new build is picked up on the next load. A stale index.html would pin the previous build's asset hashes and silently block updates — hence the split.

func IsHTTPS

func IsHTTPS(r *http.Request) bool

IsHTTPS reports whether r reached the server over TLS, directly or via a trusted proxy.

func SPACSP

func SPACSP(frameSrc string) string

SPACSP builds a Content-Security-Policy for a Vite SPA that talks only to its own origin (same-origin API + WebSocket). frameSrc sets the frame-src directive — "'none'" when the app embeds nothing, "'self'" when it embeds same-origin iframes (e.g. rendered artifacts); empty defaults to "'none'". style-src keeps 'unsafe-inline' because Vue's :style bindings emit inline style attributes; script-src stays strict 'self' (Vite emits no inline script).

Types

type Config

type Config struct {
	// CSP is the Content-Security-Policy value; empty omits the header. It is caller-supplied
	// because it legitimately differs per app: the terminal frames nothing (frame-src 'none'),
	// while pro embeds same-origin artifact iframes (frame-src 'self'). Build one with SPACSP.
	CSP string
	// FrameOptions is the X-Frame-Options value (e.g. "DENY", "SAMEORIGIN"); empty omits it.
	FrameOptions string
	// HSTS emits Strict-Transport-Security, but only on requests that reached us over HTTPS
	// (direct TLS or a trusted proxy's X-Forwarded-Proto) — never on a plain-HTTP LAN listener.
	HSTS bool
}

Config selects the response-specific security headers. The always-on headers (X-Content-Type-Options, Referrer-Policy, Permissions-Policy) need no configuration.

func (Config) Middleware

func (c Config) Middleware(next http.Handler) http.Handler

Middleware wraps next, applying SetSecurity to every response. HTTPS is detected from r.TLS or a trusted X-Forwarded-Proto=https (set by the tunnel / reverse proxy).

func (Config) SetSecurity

func (c Config) SetSecurity(h http.Header, https bool)

SetSecurity writes the configured security headers onto h. https reports whether the request arrived over TLS. This is the SSOT primitive both the net/http middleware and a Gin middleware call, so neither reimplements the set.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL