fix: harden workspace registry deployment

This commit is contained in:
2026-08-04 07:42:35 +02:00
parent f71feecaea
commit 802b564200
11 changed files with 132 additions and 14 deletions
+6 -3
View File
@@ -32,6 +32,8 @@ export function sessionRoutes(
workspaceRegistry: WorkspaceRegistry;
/** Local-only guard: probe DWH reachability before creating a session (run-stack.sh). */
dwhPrecheck?: boolean;
/** Explicit loopback-only compatibility path for old clients that send `workspace`. */
legacyWorkspaceMode?: boolean;
},
) {
const lifecycleTails = new Map<string, Promise<void>>();
@@ -267,9 +269,10 @@ export function sessionRoutes(
try { s = await d.getSettings(principal); } catch { return storageFailure(reply); }
const runner = runnerFor(principal);
// `workspace` was the legacy request field before browser-local registry preferences.
// It opts a pre-registry caller into the existing installation-default config only; modern
// `workspaceId` and saved preferences must continue to resolve an immutable snapshot.
const legacyWorkspaceRequest = typeof b.workspace === "string" && b.workspace.length > 0;
// It is available only through the explicit loopback-only compatibility mode; every normal
// new session must resolve and pin an immutable registry revision.
const legacyWorkspaceRequest = d.legacyWorkspaceMode
&& typeof b.workspace === "string" && b.workspace.length > 0;
const requestedWorkspaceId = b.workspaceId ?? (legacyWorkspaceRequest ? undefined : s.workspace);
if (!requestedWorkspaceId && !legacyWorkspaceRequest) {
return reply.code(409).send({