Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[sup] Same-origin deployment: static artifact in ACM docroot, <Location> CSP, acm-ui link

Open
#357 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Quiet
Tech stack
typescript

Research direction

Start by reading the artifact/build discussion in this repository, then inspect acm's distrib/build.sh and vhost configuration and acm-ui's cluster/explore page. Resolve the artifact delivery and CSP approach across the three repositories, while checking release.yml and docker.yml for unintended public-release paths. Done means the /sql/ artifact, cookie-auth flow, CSP, concrete file path, contextual link, and release safeguards satisfy the listed acceptance checks.

Written by the indexing model from the issue text.

Description

enhancement sup

Part of #352. Reworked: same-origin static deployment into ACM, not a public release tag.

Our SPA ships as a static file in the altinity/acm image docroot, served same-origin at a concrete path (e.g. /sql/), opened in a new tab from acm-ui.

Our repo (altinity-sql-browser)

  • Build the artifact so it runs under ACM (see CSP below): either keep the single inline-<script> file and rely on a scoped ACM <Location> CSP, or add a build mode emitting external JS from 'self' (no inline/eval).
  • Select ACM cookie-auth mode at runtime (URL context) rather than a separate bundle if practical.
  • Decide artifact delivery to ACM: committed asset, pinned GitHub release download, or built in acm-ui's pipeline.

acm repo (backend/distrib)

  • distrib/build.sh: place our built file into the docroot / tar (/var/www/html/sql/…).
  • vhost: add a <Location /sql/> CSP block (mirror the existing /api/ CSP: 'self' 'unsafe-inline' 'unsafe-eval' *.gstatic.com data:). Needed because the strict page CSP blocks our inline bundle.
  • Serve as a real file at a concrete path (FallbackResource /index.html would otherwise return the Angular shell).

acm-ui repo

  • Add a link on the cluster/explore page → /sql/?cluster=<id>&node=<n> (target=_blank).

Do NOT

  • vX.Y.Z-sup tagrelease.yml fires on v* and docker.yml on v*.*.* (+latest); a -sup tag would enter public GitHub Release / Helm / Docker latest. Deployment here is via the ACM image, not this repo's public tags.

Acceptance

  • Artifact served same-origin at /sql/; cookie auth works end-to-end in the console.
  • <Location /sql/> CSP allows the app; page loads with no CSP violations.
  • Concrete-path file (not swallowed by FallbackResource).
  • acm-ui link opens the new tab with cluster/node context.
  • No public-release/Helm/Docker path is triggered by this work.
Dominant language
TypeScript
Stars
8
Forks
2
Avg merge
1h 34m
Merged PRs (30d)
6

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Altinity/altinity-sql-browser

All issues in Altinity/altinity-sql-browser

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.