fix(docker): harden frontend runtime config
This commit is contained in:
@@ -55,3 +55,28 @@ Implemented and verified runtime-configured frontend packaging.
|
||||
this task.
|
||||
- `.superpowers/sdd/progress.md` was already modified by the orchestrator and was intentionally
|
||||
excluded from this task's commit.
|
||||
|
||||
## P1 review fixes
|
||||
|
||||
Follow-up commit work addressed both review findings:
|
||||
|
||||
- Runtime configuration is now produced with `jq -cn --arg`, so `BACKEND_BASE_URL` is encoded
|
||||
by a real JSON serializer rather than interpolated into JavaScript by `sed`.
|
||||
- The image includes `frontend-config-smoke`, which strips only the fixed assignment wrapper,
|
||||
parses the remaining JSON with `jq`, requires exactly the `backendBaseUrl` key, and compares
|
||||
the decoded value to the environment input.
|
||||
- The hostile smoke passed with quotes, backslashes, a literal newline, ampersand, pipe, and
|
||||
`"; globalThis.PWNED=true; //` in the value. A breakout would leave non-JSON trailing input
|
||||
and fail parsing.
|
||||
- Added `joinBackendPath`, shared by API fetch and EventSource creation. It removes duplicate
|
||||
boundary slashes for relative and absolute bases while keeping empty and `/` bases rooted.
|
||||
|
||||
Follow-up verification:
|
||||
|
||||
- RED: six join cases failed with `joinBackendPath is not a function` before implementation.
|
||||
- Targeted: runtime config, API client, and EventSource suites — 14 tests passed.
|
||||
- Full frontend gate — exit 0 (40 test files, 191 tests, TypeScript, Vite build).
|
||||
- Rebuilt `thothii-frontend:test` successfully.
|
||||
- Hostile config image smoke — `frontend runtime config smoke: ok`.
|
||||
- Rebuilt two-container smoke — default `/api` config, proxied `/api/health`, SPA fallback,
|
||||
and SSE-safe nginx directives all passed.
|
||||
|
||||
Reference in New Issue
Block a user