#!/bin/sh set -eu cd "$(dirname "$0")/.." policy=frontend/src/api/backend-url-policy.json corpus=frontend/src/api/backend-url-cases.json assert_policy() { value=$1 expected=$2 if BACKEND_URL_POLICY_FILE="$policy" ./docker/validate-backend-url.sh "$value"; then actual=true else actual=false fi if [ "$actual" != "$expected" ]; then echo "browser URL policy mismatch for $value: expected $expected" >&2 exit 1 fi } assert_policy /api true assert_policy /datamart-builder/api false assert_policy http://localhost:8787 false assert_policy https://api.example.test/v1 false if rg -n '^ARG VITE_(BASE|BACKEND_URL)' docker/frontend.Dockerfile; then echo "frontend image must not expose deployment-specific Vite build arguments" >&2 exit 1 fi if ! rg -Fx 'ENV VITE_BASE=/ VITE_BACKEND_URL=/api' docker/frontend.Dockerfile >/dev/null; then echo "frontend image must build the fixed / assets and /api browser contract" >&2 exit 1 fi if rg -n 'datamart-builder' frontend/src/api/runtime-config.ts frontend/src/api/backend-url-policy.json docker/nginx.conf.template docker/frontend-entrypoint.sh docker/frontend.Dockerfile; then echo "active frontend routing still assumes a portal prefix" >&2 exit 1 fi jq -c '.[]' "$corpus" | while IFS= read -r case_json; do value=$(printf '%s' "$case_json" | jq -r '.value') valid=$(printf '%s' "$case_json" | jq -r '.valid') if BACKEND_URL_POLICY_FILE="$policy" ./docker/validate-backend-url.sh "$value"; then actual=true else actual=false fi if [ "$actual" != "$valid" ]; then echo "shell policy mismatch for BACKEND_BASE_URL=$value: expected $valid" >&2 exit 1 fi done echo "shell canonical URL corpus: ok"