[sup] Same-origin deployment: static artifact in ACM docroot, <Location> CSP, acm-ui link
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 35/100
- Issue 类型
- 功能
- 描述清晰度
- 基本清楚
- 活跃度
- 冷清
- 技术栈
- typescript
调研方向
首先阅读此仓库中关于 artifact/build 的讨论,然后检查 acm's distrib/build.sh 和 vhost 配置,以及 acm-ui 的 cluster/explore 页面。在三个仓库之间确定 artifact 交付和 CSP 方案,同时检查 release.yml 和 docker.yml 是否存在意外的公开发布路径。/sql/ artifact、cookie-auth 流程、CSP、具体文件路径、上下文链接和发布保护措施满足列出的验收检查后,即视为完成。
由索引模型根据 Issue 内容生成。
描述
Part of #352. Reworked: same-origin static deployment into ACM, not a public release tag.
Our SPA ships as a static file in the altinity/acm image docroot, served same-origin at a concrete path (e.g. /sql/), opened in a new tab from acm-ui.
Our repo (altinity-sql-browser)
- Build the artifact so it runs under ACM (see CSP below): either keep the single inline-
<script>file and rely on a scoped ACM<Location>CSP, or add a build mode emitting external JS from'self'(no inline/eval). - Select ACM cookie-auth mode at runtime (URL context) rather than a separate bundle if practical.
- Decide artifact delivery to ACM: committed asset, pinned GitHub release download, or built in acm-ui's pipeline.
acm repo (backend/distrib)
distrib/build.sh: place our built file into the docroot / tar (/var/www/html/sql/…).- vhost: add a
<Location /sql/>CSP block (mirror the existing/api/CSP:'self' 'unsafe-inline' 'unsafe-eval' *.gstatic.com data:). Needed because the strict page CSP blocks our inline bundle. - Serve as a real file at a concrete path (
FallbackResource /index.htmlwould otherwise return the Angular shell).
acm-ui repo
- Add a link on the cluster/explore page →
/sql/?cluster=<id>&node=<n>(target=_blank).
Do NOT
—vX.Y.Z-suptagrelease.ymlfires onv*anddocker.ymlonv*.*.*(+latest); a-suptag would enter public GitHub Release / Helm / Dockerlatest. Deployment here is via the ACM image, not this repo's public tags.
Acceptance
- Artifact served same-origin at
/sql/; cookie auth works end-to-end in the console. -
<Location /sql/>CSP allows the app; page loads with no CSP violations. - Concrete-path file (not swallowed by
FallbackResource). - acm-ui link opens the new tab with cluster/node context.
- No public-release/Helm/Docker path is triggered by this work.
- 主要语言
- TypeScript
- 星标
- 8
- 派生
- 2
- 平均合并
- 1 小时 17 分钟
- 30 天内合并 PR
- 3
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
Altinity/altinity-sql-browser 的其他 Issue
-
inbox
难度 2/5 1-3 小时 新手友好度 76/100
Altinity/altinity-sql-browser#605 ·
维护者通常 1 天内回复
-
inbox
难度 2/5 1-3 小时 新手友好度 78/100
Altinity/altinity-sql-browser#509 ·
维护者通常 1 天内回复
-
inbox
难度 2/5 1-3 小时 新手友好度 78/100
Altinity/altinity-sql-browser#489 ·
维护者通常 1 天内回复
-
flamegraph未关闭enhancement
难度 5/5 一周以上 新手友好度 25/100
Altinity/altinity-sql-browser#684 ·
维护者通常 1 天内回复
-
bug
难度 4/5 3-5 天 新手友好度 68/100
Altinity/altinity-sql-browser#680 · 2 条评论 ·
维护者通常 1 天内回复
查看 Altinity/altinity-sql-browser 的全部 Issue
相似的 Issue
-
难度 1/5 1 小时以内 新手友好度 72/100
betagouv/mon-entreprise#4699 ·
维护者通常 3 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 82/100
jaegertracing/jaeger-ui#4547 · 3 条评论 ·
维护者通常 1 天内回复
-
ai-driven-qa
难度 2/5 1-3 小时 新手友好度 84/100
linagora/twake-calendar-frontend#1467 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 78/100
need4deed-org/sdk#267 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 84/100
auth0/universal-login#414 ·
维护者通常 1 天内回复