mirror of
https://github.com/AmruthPillai/Reactive-Resume.git
synced 2026-07-24 08:54:05 +10:00
Squashed commit of the following:
commit b2b0470a1d9267d042ec0ac66523c6635bf5b199
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 13:13:38 2026 +0200
chore: update .gitignore to include .vite-hooks and modify pnpm-lock.yaml for dependencies
commit d28fadb5cd8706c874e616102878b4a394ec84c1
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 13:08:04 2026 +0200
fix: remove timestamp conflict guard
commit c6998d9dbab19d09d3c8054feef1d2e4117555eb
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 12:11:51 2026 +0200
chore(release): v5.1.5
commit f33d168711804880e1f12e88d24290aae16cc258
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:58:35 2026 +0200
revert: compose.yml
commit d961e6535811a10c335525fb33a08d03e737278d
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:58:08 2026 +0200
refactor(agent): replace 'revert' terminology with 'restore' for clarity, resolves #3086
commit 17f351171be218e33f01c469d95e4164d4c8dc57
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 11:10:41 2026 +0200
refactor(pdf): simplify sidebar section filtering and update summary feature logic
commit d55179b9d76879e3204de185e8b53fadd0a107ed
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:53:37 2026 +0200
chore: update pnpm-lock.yaml and turbo.json
commit 7cade6980e1a04352536bd44ef773f338c4ef599
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:38:30 2026 +0200
fix(polyfill): add tested polyfill for Map Upsert methods
commit 26d175bb9c53d93225d1e907678445252c13d660
Merge: 1cf33dc6c 5b1297fa2
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:23:29 2026 +0200
Merge remote-tracking branch 'origin/main' into feat/explore-hono-orpc-migration
# Conflicts:
# packages/api/src/services/agent-url.ts
# packages/runtime-externals/package.json
commit 1cf33dc6c9d81735730ad656e16dab6501c6d6a1
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Tue May 19 09:22:12 2026 +0200
chore: preserve branch changes before main sync
commit b380a4b00fdbcdd81ff4f8ef72b330fd027ccda5
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Mon May 18 07:50:28 2026 +0200
chore: lot of fixes for monorepo migration
commit 8fcf0ec64e1c29572ebaff494338368bfcf75760
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 13:57:17 2026 +0200
chore: update knip version and refine web app routing with new SEO endpoints
commit 234e68086ff15610a93877354c98e2c020364533
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 12:10:06 2026 +0200
refactor(auth): update OAuth routes to include API prefix and remove unused schema endpoint
commit 91c84b9a8496b0ce21d71cae9f8b2a027638c9ac
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:54:29 2026 +0200
chore: update dependencies and enhance PWA metadata in web app
commit 150117d4a5a9dd6cd92c64891aad8cae90f6a7af
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:12:35 2026 +0200
docs: revise manifest-only pwa testing scope
commit 6b939a55661aec9dd8122b184e4b60a5c7325fb5
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:11:33 2026 +0200
docs: add manifest-only pwa design
commit 1422e1fc96c400948b273210a1067251087d15d4
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:05:04 2026 +0200
chore(dev): simplify server proxy config
commit bc2ff5a9f6fda41e6c40333c8f163aa23a6c5e48
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:04:50 2026 +0200
docs: add unsafe oauth redirect plan
commit 445359ebe9b96c1515bf1c4c3f73ba8a8448ec12
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 11:04:34 2026 +0200
feat(auth): add unsafe oauth redirect flag
commit 73fffdd24598e56b2793f7657919bc794835892e
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:55:02 2026 +0200
docs: design unsafe oauth redirect flag
commit c0066aa19c15fc8a4c8e5179ed49889c117519f4
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:22:04 2026 +0200
chore: update translation source paths
commit 9033da082418d252aafd6c2eed72f71f014be3d9
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 10:09:25 2026 +0200
refactor(arch): react spa + hono migration
commit 6f27936c11bda895977dc63ee550c3346d4ce24b
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Fri May 15 01:10:47 2026 +0200
docs: add docker nightly tagging design
commit ecc1fd9a88a0ee1dca2f1977dfc17f74527fe1da
Author: Amruth Pillai <im.amruth@gmail.com>
Date: Thu May 14 20:05:44 2026 +0200
feat: migrate to hono spa server
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
import z from "zod";
|
||||
import { resumeDataSchema } from "@reactive-resume/schema/resume/data";
|
||||
|
||||
export function handleSchemaJson() {
|
||||
const resumeDataJSONSchema = z.toJSONSchema(resumeDataSchema);
|
||||
|
||||
return Response.json(resumeDataJSONSchema, {
|
||||
status: 200,
|
||||
headers: {
|
||||
"Content-Type": "application/schema+json; charset=utf-8",
|
||||
"Cache-Control": "public, max-age=86400, immutable",
|
||||
"Surrogate-Control": "max-age=86400",
|
||||
"X-Content-Type-Options": "nosniff",
|
||||
"X-Robots-Tag": "index, follow",
|
||||
ETag: __APP_VERSION__,
|
||||
Vary: "Accept",
|
||||
},
|
||||
});
|
||||
}
|
||||
@@ -0,0 +1,68 @@
|
||||
import { describe, expect, it, vi } from "vitest";
|
||||
|
||||
vi.mock("@reactive-resume/env/server", () => ({
|
||||
env: {
|
||||
APP_URL: "https://app.example.com/",
|
||||
},
|
||||
}));
|
||||
|
||||
const { handleLlms, handleRobots, handleSitemap } = await import("./seo");
|
||||
|
||||
describe("SEO static endpoints", () => {
|
||||
it("generates robots.txt from the normalized app URL", async () => {
|
||||
const response = handleRobots();
|
||||
const text = await response.text();
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.headers.get("Content-Type")).toBe("text/plain; charset=UTF-8");
|
||||
expect(text).toContain("User-agent: *");
|
||||
expect(text).toContain("Allow: /");
|
||||
expect(text).toContain("Disallow: /api/rpc");
|
||||
expect(text).toContain("Disallow: /api/auth");
|
||||
expect(text).toContain("Disallow: /mcp");
|
||||
expect(text).toContain("Disallow: /.well-known");
|
||||
expect(text).toContain("Sitemap: https://app.example.com/sitemap.xml");
|
||||
expect(text).toContain("Sitemap: https://docs.rxresu.me/sitemap.xml");
|
||||
expect(text).not.toMatch(/GPTBot|ClaudeBot|PerplexityBot|CCBot|ChatGPT-User/);
|
||||
});
|
||||
|
||||
it("generates an app-domain-only sitemap", async () => {
|
||||
const response = handleSitemap();
|
||||
const text = await response.text();
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.headers.get("Content-Type")).toBe("application/xml; charset=UTF-8");
|
||||
expect(text).toContain("<loc>https://app.example.com/</loc>");
|
||||
expect(text).not.toContain("docs.rxresu.me");
|
||||
expect(text).not.toContain("/auth");
|
||||
expect(text).not.toContain("/dashboard");
|
||||
expect(text).not.toContain("/builder");
|
||||
expect(text).not.toContain("/templates");
|
||||
expect(text).not.toContain("/schema.json");
|
||||
});
|
||||
|
||||
it("generates a lightweight llms.txt product index", async () => {
|
||||
const response = handleLlms();
|
||||
const text = await response.text();
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.headers.get("Content-Type")).toBe("text/plain; charset=UTF-8");
|
||||
expect(text).toContain("# Reactive Resume");
|
||||
expect(text).toContain("- Product: https://app.example.com");
|
||||
expect(text).toContain("- Documentation: https://docs.rxresu.me");
|
||||
expect(text).toContain("- Documentation sitemap: https://docs.rxresu.me/sitemap.xml");
|
||||
expect(text).toContain("- Documentation llms.txt: https://docs.rxresu.me/llms.txt");
|
||||
expect(text).toContain("- API documentation: https://docs.rxresu.me/api-reference");
|
||||
expect(text).toContain("- Resume schema: https://app.example.com/schema.json");
|
||||
expect(text).toContain("- MCP documentation: https://docs.rxresu.me/guides/using-the-mcp-server");
|
||||
expect(text).toContain("- OpenAPI specification: https://app.example.com/api/openapi/spec.json");
|
||||
});
|
||||
|
||||
it("returns headers without a body for HEAD responses", async () => {
|
||||
const response = handleLlms({ head: true });
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.headers.get("Content-Type")).toBe("text/plain; charset=UTF-8");
|
||||
expect(await response.text()).toBe("");
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,75 @@
|
||||
import { env } from "@reactive-resume/env/server";
|
||||
|
||||
const DOCS_URL = "https://docs.rxresu.me";
|
||||
|
||||
type StaticSeoOptions = {
|
||||
head?: boolean;
|
||||
};
|
||||
|
||||
function appUrl() {
|
||||
return env.APP_URL.replace(/\/+$/, "");
|
||||
}
|
||||
|
||||
function textResponse(body: string, options: StaticSeoOptions = {}) {
|
||||
return new Response(options.head ? null : body, {
|
||||
headers: { "Content-Type": "text/plain; charset=UTF-8" },
|
||||
});
|
||||
}
|
||||
|
||||
export function handleRobots(options?: StaticSeoOptions) {
|
||||
const baseUrl = appUrl();
|
||||
const body = [
|
||||
"User-agent: *",
|
||||
"Allow: /",
|
||||
"Disallow: /api/rpc",
|
||||
"Disallow: /api/auth",
|
||||
"Disallow: /mcp",
|
||||
"Disallow: /.well-known",
|
||||
"",
|
||||
`Sitemap: ${baseUrl}/sitemap.xml`,
|
||||
`Sitemap: ${DOCS_URL}/sitemap.xml`,
|
||||
"",
|
||||
].join("\n");
|
||||
|
||||
return textResponse(body, options);
|
||||
}
|
||||
|
||||
export function handleSitemap(options?: StaticSeoOptions) {
|
||||
const baseUrl = appUrl();
|
||||
const body = [
|
||||
'<?xml version="1.0" encoding="UTF-8"?>',
|
||||
'<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">',
|
||||
" <url>",
|
||||
` <loc>${baseUrl}/</loc>`,
|
||||
" </url>",
|
||||
"</urlset>",
|
||||
"",
|
||||
].join("\n");
|
||||
|
||||
return new Response(options?.head ? null : body, {
|
||||
headers: { "Content-Type": "application/xml; charset=UTF-8" },
|
||||
});
|
||||
}
|
||||
|
||||
export function handleLlms(options?: StaticSeoOptions) {
|
||||
const baseUrl = appUrl();
|
||||
const body = [
|
||||
"# Reactive Resume",
|
||||
"",
|
||||
"Reactive Resume is an open-source resume builder for creating, managing, and exporting resumes.",
|
||||
"",
|
||||
"## Links",
|
||||
"",
|
||||
`- Product: ${baseUrl}`,
|
||||
`- Documentation: ${DOCS_URL}`,
|
||||
`- Documentation sitemap: ${DOCS_URL}/sitemap.xml`,
|
||||
`- Documentation llms.txt: ${DOCS_URL}/llms.txt`,
|
||||
`- API documentation: ${DOCS_URL}/api-reference`,
|
||||
`- Resume schema: ${baseUrl}/schema.json`,
|
||||
`- MCP documentation: ${DOCS_URL}/guides/using-the-mcp-server`,
|
||||
`- OpenAPI specification: ${baseUrl}/api/openapi/spec.json`,
|
||||
"",
|
||||
].join("\n");
|
||||
|
||||
return textResponse(body, options);
|
||||
}
|
||||
@@ -0,0 +1,52 @@
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
const readMock = vi.fn();
|
||||
|
||||
vi.mock("@reactive-resume/api/features/storage", () => ({
|
||||
getStorageService: () => ({
|
||||
read: readMock,
|
||||
}),
|
||||
}));
|
||||
|
||||
vi.mock("@reactive-resume/env/server", () => ({
|
||||
env: {
|
||||
APP_URL: "https://example.com",
|
||||
},
|
||||
}));
|
||||
|
||||
const { handleUpload } = await import("./uploads");
|
||||
|
||||
describe("handleUpload", () => {
|
||||
beforeEach(() => {
|
||||
readMock.mockReset();
|
||||
});
|
||||
|
||||
it("serves public upload keys", async () => {
|
||||
readMock.mockResolvedValueOnce({
|
||||
data: new TextEncoder().encode("image"),
|
||||
size: 5,
|
||||
contentType: "image/jpeg",
|
||||
});
|
||||
|
||||
const response = await handleUpload(new Request("https://example.com/api/uploads/user-1/pictures/photo.jpeg"));
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(readMock).toHaveBeenCalledWith("uploads/user-1/pictures/photo.jpeg");
|
||||
expect(response.headers.get("Content-Type")).toBe("image/jpeg");
|
||||
});
|
||||
|
||||
it("does not serve private agent attachment keys through the public uploads route", async () => {
|
||||
readMock.mockResolvedValueOnce({
|
||||
data: new TextEncoder().encode("secret"),
|
||||
size: 6,
|
||||
contentType: "text/plain",
|
||||
});
|
||||
|
||||
const response = await handleUpload(
|
||||
new Request("https://example.com/api/uploads/user-1/agent/thread-1/attachment.txt"),
|
||||
);
|
||||
|
||||
expect(response.status).toBe(404);
|
||||
expect(readMock).not.toHaveBeenCalled();
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,160 @@
|
||||
import { createHash } from "node:crypto";
|
||||
import { basename, extname, normalize } from "node:path";
|
||||
import { getStorageService } from "@reactive-resume/api/features/storage";
|
||||
import { env } from "@reactive-resume/env/server";
|
||||
|
||||
export async function handleUpload(request: Request) {
|
||||
const { userId, filePath } = parseRouteParams(request.url);
|
||||
|
||||
if (!userId || !filePath) return new Response("Bad Request", { status: 400 });
|
||||
|
||||
if (!isValidPath(userId) || !isValidPathSegments(filePath)) return new Response("Forbidden", { status: 403 });
|
||||
if (isPrivateUploadPath(filePath)) return new Response("Not Found", { status: 404 });
|
||||
|
||||
const storageService = getStorageService();
|
||||
const key = `uploads/${userId}/${filePath}`;
|
||||
const storedFile = await storageService.read(key);
|
||||
if (!storedFile) return new Response("Not Found", { status: 404 });
|
||||
|
||||
const filename = filePath.split("/").pop() ?? filePath;
|
||||
const ext = extname(filename).toLowerCase();
|
||||
const contentType = storedFile.contentType ?? inferContentTypeFromExtension(ext);
|
||||
const etag = createEtag(storedFile);
|
||||
|
||||
if (isNotModified(request.headers, etag)) return makeNotModifiedResponse(etag);
|
||||
|
||||
const shouldForceDownload = [".pdf"].includes(ext);
|
||||
const headers = buildResponseHeaders({
|
||||
filename,
|
||||
storedFile,
|
||||
contentType,
|
||||
etag,
|
||||
shouldForceDownload,
|
||||
});
|
||||
|
||||
const buffer = toArrayBuffer(storedFile.data);
|
||||
|
||||
return new Response(buffer, { headers });
|
||||
}
|
||||
|
||||
function inferContentTypeFromExtension(ext: string): string {
|
||||
switch (ext) {
|
||||
case ".webp":
|
||||
return "image/webp";
|
||||
case ".png":
|
||||
return "image/png";
|
||||
case ".jpg":
|
||||
case ".jpeg":
|
||||
return "image/jpeg";
|
||||
case ".gif":
|
||||
return "image/gif";
|
||||
case ".pdf":
|
||||
return "application/pdf";
|
||||
default:
|
||||
return "application/octet-stream";
|
||||
}
|
||||
}
|
||||
|
||||
function parseRouteParams(url: string): { userId: string | undefined; filePath: string | undefined } {
|
||||
const pathname = new URL(url).pathname;
|
||||
const [, pathAfterUploads] = pathname.split("/uploads/");
|
||||
if (!pathAfterUploads) return { userId: undefined, filePath: undefined };
|
||||
const firstSlashIndex = pathAfterUploads.indexOf("/");
|
||||
|
||||
if (firstSlashIndex === -1) {
|
||||
return { userId: pathAfterUploads, filePath: undefined };
|
||||
}
|
||||
|
||||
const userId = pathAfterUploads.slice(0, firstSlashIndex);
|
||||
const filePath = pathAfterUploads.slice(firstSlashIndex + 1);
|
||||
|
||||
return { userId, filePath: filePath || undefined };
|
||||
}
|
||||
|
||||
function isValidPath(segment: string): boolean {
|
||||
const normalized = normalize(segment).replace(/^(\.\.(\/|\\|$))+/, "");
|
||||
|
||||
return normalized === segment;
|
||||
}
|
||||
|
||||
function isValidPathSegments(path: string): boolean {
|
||||
const segments = path.split("/");
|
||||
|
||||
return segments.every((segment) => isValidPath(segment));
|
||||
}
|
||||
|
||||
function isPrivateUploadPath(path: string): boolean {
|
||||
return path.split("/")[0] === "agent";
|
||||
}
|
||||
|
||||
function isNotModified(headers: Headers, etag: string): boolean {
|
||||
const ifNoneMatch = headers.get("If-None-Match");
|
||||
const candidates = ifNoneMatch?.split(",").map((s) => s.trim()) ?? [];
|
||||
|
||||
return candidates.includes(etag);
|
||||
}
|
||||
|
||||
function makeNotModifiedResponse(etag: string): Response {
|
||||
return new Response(null, {
|
||||
status: 304,
|
||||
headers: { ETag: etag, "Cache-Control": "public, max-age=31536000, immutable" },
|
||||
});
|
||||
}
|
||||
|
||||
type BuildResponseHeaderArgs = {
|
||||
filename: string;
|
||||
storedFile: { size: number };
|
||||
contentType: string;
|
||||
etag: string;
|
||||
shouldForceDownload: boolean;
|
||||
};
|
||||
|
||||
function buildResponseHeaders({
|
||||
filename,
|
||||
storedFile,
|
||||
contentType,
|
||||
etag,
|
||||
shouldForceDownload,
|
||||
}: BuildResponseHeaderArgs): Headers {
|
||||
const headers = new Headers();
|
||||
|
||||
headers.set("Content-Type", shouldForceDownload ? "application/octet-stream" : contentType);
|
||||
headers.set("Content-Length", storedFile.size.toString());
|
||||
|
||||
if (shouldForceDownload) {
|
||||
headers.set("Content-Disposition", `attachment; filename="${encodeURIComponent(basename(filename))}"`);
|
||||
}
|
||||
|
||||
headers.set("Cache-Control", "public, max-age=31536000, immutable");
|
||||
headers.set("ETag", etag);
|
||||
headers.set("X-Content-Type-Options", "nosniff");
|
||||
headers.set("X-Robots-Tag", "noindex, nofollow");
|
||||
headers.set("Cross-Origin-Resource-Policy", "same-site");
|
||||
headers.set("Referrer-Policy", "strict-origin-when-cross-origin");
|
||||
headers.set("X-Frame-Options", "DENY");
|
||||
headers.set("X-Download-Options", "noopen");
|
||||
headers.set("Access-Control-Allow-Origin", env.APP_URL);
|
||||
|
||||
return headers;
|
||||
}
|
||||
|
||||
function toArrayBuffer(data: Uint8Array): ArrayBuffer {
|
||||
return data.byteOffset === 0 && data.byteLength === data.buffer.byteLength
|
||||
? (data.buffer as ArrayBuffer)
|
||||
: (data.slice().buffer as ArrayBuffer);
|
||||
}
|
||||
|
||||
function createEtag(storedFile: { data: Uint8Array; size: number; etag?: string }): string {
|
||||
if (storedFile.etag) {
|
||||
const tag = storedFile.etag.trim();
|
||||
|
||||
if (tag.startsWith("W/") || tag.startsWith('"')) {
|
||||
return tag;
|
||||
}
|
||||
return `"${tag}"`;
|
||||
}
|
||||
|
||||
const hash = createHash("sha256").update(storedFile.data).digest("hex");
|
||||
|
||||
return `"${storedFile.size}-${hash}"`;
|
||||
}
|
||||
@@ -0,0 +1,106 @@
|
||||
import fs from "node:fs/promises";
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
vi.mock("node:fs", () => ({
|
||||
existsSync: vi.fn(() => true),
|
||||
}));
|
||||
|
||||
vi.mock("node:fs/promises", () => ({
|
||||
default: {
|
||||
readFile: vi.fn(),
|
||||
},
|
||||
}));
|
||||
|
||||
vi.mock("@hono/node-server/serve-static", () => ({
|
||||
serveStatic: vi.fn(() => vi.fn()),
|
||||
}));
|
||||
|
||||
const { handleWebApp, handleWebAppHead } = await import("./web");
|
||||
|
||||
describe("web app fallback classification", () => {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
vi.mocked(fs.readFile).mockResolvedValue("<html>app</html>");
|
||||
});
|
||||
|
||||
it("serves the shell for the root app route without noindex", async () => {
|
||||
const response = await handleWebApp(new Request("https://example.com/"));
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.headers.get("Content-Type")).toBe("text/html; charset=UTF-8");
|
||||
expect(response.headers.get("X-Robots-Tag")).toBeNull();
|
||||
expect(await response.text()).toBe("<html>app</html>");
|
||||
});
|
||||
|
||||
it.each([
|
||||
"/auth/login",
|
||||
"/dashboard",
|
||||
"/builder/resume-1",
|
||||
"/agent",
|
||||
"/templates",
|
||||
"/templates/azurill.pdf",
|
||||
])("serves noindex shell for known app prefix %s", async (pathname) => {
|
||||
const response = await handleWebApp(new Request(`https://example.com${pathname}`));
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.headers.get("Content-Type")).toBe("text/html; charset=UTF-8");
|
||||
expect(response.headers.get("X-Robots-Tag")).toBe("noindex, follow");
|
||||
expect(await response.text()).toBe("<html>app</html>");
|
||||
});
|
||||
|
||||
it("serves noindex shell for public resume shaped routes", async () => {
|
||||
const response = await handleWebApp(new Request("https://example.com/alice/resume"));
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.headers.get("X-Robots-Tag")).toBe("noindex, follow");
|
||||
expect(await response.text()).toBe("<html>app</html>");
|
||||
});
|
||||
|
||||
it("returns noindex 404 for unknown non-asset routes", async () => {
|
||||
const response = await handleWebApp(new Request("https://example.com/unknown/extra/path"));
|
||||
|
||||
expect(response.status).toBe(404);
|
||||
expect(response.headers.get("Content-Type")).toBe("text/plain; charset=UTF-8");
|
||||
expect(response.headers.get("X-Robots-Tag")).toBe("noindex, nofollow");
|
||||
expect(await response.text()).toBe("Not Found");
|
||||
expect(fs.readFile).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it.each([
|
||||
"/api/foo",
|
||||
"/mcp/foo",
|
||||
"/uploads/foo",
|
||||
])("does not treat reserved two-segment path %s as a public resume", async (pathname) => {
|
||||
const response = await handleWebApp(new Request(`https://example.com${pathname}`));
|
||||
|
||||
expect(response.status).toBe(404);
|
||||
expect(response.headers.get("Content-Type")).toBe("text/plain; charset=UTF-8");
|
||||
expect(response.headers.get("X-Robots-Tag")).toBe("noindex, nofollow");
|
||||
expect(await response.text()).toBe("Not Found");
|
||||
expect(fs.readFile).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it("returns plain 404 for missing asset-looking paths", async () => {
|
||||
const response = await handleWebApp(new Request("https://example.com/assets/missing.css"));
|
||||
|
||||
expect(response.status).toBe(404);
|
||||
expect(response.headers.get("X-Robots-Tag")).toBeNull();
|
||||
expect(await response.text()).toBe("Not Found");
|
||||
expect(fs.readFile).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it("mirrors fallback status and headers for HEAD without a body", async () => {
|
||||
const knownResponse = handleWebAppHead(new Request("https://example.com/dashboard"));
|
||||
const unknownResponse = handleWebAppHead(new Request("https://example.com/unknown/extra/path"));
|
||||
|
||||
expect(knownResponse.status).toBe(200);
|
||||
expect(knownResponse.headers.get("Content-Type")).toBe("text/html; charset=UTF-8");
|
||||
expect(knownResponse.headers.get("X-Robots-Tag")).toBe("noindex, follow");
|
||||
expect(await knownResponse.text()).toBe("");
|
||||
|
||||
expect(unknownResponse.status).toBe(404);
|
||||
expect(unknownResponse.headers.get("Content-Type")).toBe("text/plain; charset=UTF-8");
|
||||
expect(unknownResponse.headers.get("X-Robots-Tag")).toBe("noindex, nofollow");
|
||||
expect(await unknownResponse.text()).toBe("");
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,96 @@
|
||||
import { existsSync } from "node:fs";
|
||||
import fs from "node:fs/promises";
|
||||
import { fileURLToPath } from "node:url";
|
||||
import { serveStatic } from "@hono/node-server/serve-static";
|
||||
|
||||
function resolveWebDistPath() {
|
||||
const candidates = [
|
||||
// Source layout: apps/server/src/static/web.ts -> apps/web/dist
|
||||
fileURLToPath(new URL("../../../web/dist", import.meta.url)),
|
||||
// Bundled layout: apps/server/dist/index.mjs -> apps/web/dist
|
||||
fileURLToPath(new URL("../../web/dist", import.meta.url)),
|
||||
];
|
||||
const [fallback] = candidates;
|
||||
if (!fallback) throw new Error("Could not resolve web dist path");
|
||||
|
||||
return candidates.find((candidate) => existsSync(candidate)) ?? fallback;
|
||||
}
|
||||
|
||||
const staticRoot = resolveWebDistPath();
|
||||
const indexHtmlPath = `${staticRoot}/index.html`;
|
||||
const noindexShellPrefixes = ["/auth", "/dashboard", "/builder", "/agent", "/templates"];
|
||||
const reservedPublicResumeSegments = new Set([
|
||||
"api",
|
||||
"mcp",
|
||||
".well-known",
|
||||
"uploads",
|
||||
"auth",
|
||||
"dashboard",
|
||||
"builder",
|
||||
"agent",
|
||||
"templates",
|
||||
]);
|
||||
|
||||
export const serveWebDistStatic = serveStatic({ root: staticRoot });
|
||||
|
||||
function isAssetPath(pathname: string): boolean {
|
||||
return pathname.split("/").pop()?.includes(".") ?? false;
|
||||
}
|
||||
|
||||
function getPathSegments(pathname: string) {
|
||||
return pathname.split("/").filter(Boolean);
|
||||
}
|
||||
|
||||
function isNoindexShellPath(pathname: string): boolean {
|
||||
return noindexShellPrefixes.some((prefix) => pathname === prefix || pathname.startsWith(`${prefix}/`));
|
||||
}
|
||||
|
||||
function isPublicResumePath(pathname: string): boolean {
|
||||
const segments = getPathSegments(pathname);
|
||||
const [firstSegment] = segments;
|
||||
|
||||
return segments.length === 2 && firstSegment !== undefined && !reservedPublicResumeSegments.has(firstSegment);
|
||||
}
|
||||
|
||||
function getFallbackResponseHeaders(pathname: string) {
|
||||
if (pathname === "/") return { "Content-Type": "text/html; charset=UTF-8" };
|
||||
if (isNoindexShellPath(pathname) || isPublicResumePath(pathname)) {
|
||||
return {
|
||||
"Content-Type": "text/html; charset=UTF-8",
|
||||
"X-Robots-Tag": "noindex, follow",
|
||||
};
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
function notFoundResponse(options: { head?: boolean; noindex?: boolean } = {}) {
|
||||
const headers = new Headers({ "Content-Type": "text/plain; charset=UTF-8" });
|
||||
if (options.noindex) headers.set("X-Robots-Tag", "noindex, nofollow");
|
||||
|
||||
return new Response(options.head ? null : "Not Found", {
|
||||
status: 404,
|
||||
headers,
|
||||
});
|
||||
}
|
||||
|
||||
export async function handleWebApp(request: Request) {
|
||||
const pathname = new URL(request.url).pathname;
|
||||
if (!isNoindexShellPath(pathname) && isAssetPath(pathname)) return new Response("Not Found", { status: 404 });
|
||||
|
||||
const headers = getFallbackResponseHeaders(pathname);
|
||||
if (!headers) return notFoundResponse({ noindex: true });
|
||||
|
||||
const html = await fs.readFile(indexHtmlPath, "utf-8");
|
||||
return new Response(html, { headers });
|
||||
}
|
||||
|
||||
export function handleWebAppHead(request: Request) {
|
||||
const pathname = new URL(request.url).pathname;
|
||||
if (!isNoindexShellPath(pathname) && isAssetPath(pathname)) return new Response(null, { status: 404 });
|
||||
|
||||
const headers = getFallbackResponseHeaders(pathname);
|
||||
if (!headers) return notFoundResponse({ head: true, noindex: true });
|
||||
|
||||
return new Response(null, { status: 200, headers });
|
||||
}
|
||||
Reference in New Issue
Block a user