web

package
v0.182.6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 6, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package web embeds the built Cockpit application so the loopback daemon serves it with no Node runtime and no network.

dist/ is the production build of this directory's Angular project. It is git-ignored except for dist/.gitkeep, which exists because go:embed refuses a directory that is not there, so a wb built from a clean clone compiles and Handler serves a one-line page naming the build command.

Index

Constants

View Source
const MountPath = "/cockpit/"

MountPath is where the application is served.

Variables

View Source
var Dist embed.FS

Dist holds every file the Cockpit build emitted, or only .gitkeep in a clone where the build has never run.

Functions

func AcceptsGzip added in v0.175.0

func AcceptsGzip(values []string) bool

AcceptsGzip reports whether the Accept-Encoding header values allow gzip: an explicit gzip entry decides (a quality of zero refuses it), and only without one does `*` (again unless its quality is zero). Parameters are read case-insensitively and only `q` counts; an unreadable quality is ignored.

func FreshPolicy

func FreshPolicy() string

FreshPolicy is PolicyFor with a new random nonce, for a response the application handler does not write: it is what lets the code that answers ahead of Handler carry the same policy shape.

func Handler

func Handler() http.Handler

Handler serves the embedded application under MountPath, or the one-line not-built page when none is embedded. Mount it at MountPath; the prefix is stripped here so the caller does not have to.

Every response carries the strict Content-Security-Policy, set here after any outer middleware so it is the policy the browser receives. The entry document gets a fresh random style nonce in the policy and in its markup.

func HandlerFor

func HandlerFor(files fs.FS) http.Handler

HandlerFor is Handler over an injectable tree, so the built and not-built pages are both testable in a checkout that has only one of them.

Only GET and HEAD are answered. A missing path whose extension is one this handler has a content type for is a missing asset and gets 404, never HTML; any other missing path, with or without a dot, is a client-side route and gets the entry document. The entry document, the fallback and the not-built page are sent no-cache so a new wb binary's application is never masked by a stale one.

func PolicyFor

func PolicyFor(nonce string) string

PolicyFor is the content security policy of every response under MountPath. Scripts come only from the daemon's own origin: no unsafe-inline, no unsafe-eval. Styles come from the own origin plus the response's nonce, which covers the style elements Angular injects at run time; style attributes in markup are not allowed. Images come only from the own origin (no data: URL, no foreign origin), so content that names an image elsewhere makes no request. Framing is limited to the own origin.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL