Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

[sup] Same-origin deployment: static artifact in ACM docroot, <Location> CSP, acm-ui link

未关闭
#357 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
35/100
Issue 类型
功能
描述清晰度
基本清楚
活跃度
冷清
技术栈
typescript

调研方向

首先阅读此仓库中关于 artifact/build 的讨论,然后检查 acm's distrib/build.sh 和 vhost 配置,以及 acm-ui 的 cluster/explore 页面。在三个仓库之间确定 artifact 交付和 CSP 方案,同时检查 release.yml 和 docker.yml 是否存在意外的公开发布路径。/sql/ artifact、cookie-auth 流程、CSP、具体文件路径、上下文链接和发布保护措施满足列出的验收检查后,即视为完成。

由索引模型根据 Issue 内容生成。

描述

enhancement sup

Part of #352. Reworked: same-origin static deployment into ACM, not a public release tag.

Our SPA ships as a static file in the altinity/acm image docroot, served same-origin at a concrete path (e.g. /sql/), opened in a new tab from acm-ui.

Our repo (altinity-sql-browser)

  • Build the artifact so it runs under ACM (see CSP below): either keep the single inline-<script> file and rely on a scoped ACM <Location> CSP, or add a build mode emitting external JS from 'self' (no inline/eval).
  • Select ACM cookie-auth mode at runtime (URL context) rather than a separate bundle if practical.
  • Decide artifact delivery to ACM: committed asset, pinned GitHub release download, or built in acm-ui's pipeline.

acm repo (backend/distrib)

  • distrib/build.sh: place our built file into the docroot / tar (/var/www/html/sql/…).
  • vhost: add a <Location /sql/> CSP block (mirror the existing /api/ CSP: 'self' 'unsafe-inline' 'unsafe-eval' *.gstatic.com data:). Needed because the strict page CSP blocks our inline bundle.
  • Serve as a real file at a concrete path (FallbackResource /index.html would otherwise return the Angular shell).

acm-ui repo

  • Add a link on the cluster/explore page → /sql/?cluster=<id>&node=<n> (target=_blank).

Do NOT

  • vX.Y.Z-sup tag — release.yml fires on v* and docker.yml on v*.*.* (+latest); a -sup tag would enter public GitHub Release / Helm / Docker latest. Deployment here is via the ACM image, not this repo's public tags.

Acceptance

  • Artifact served same-origin at /sql/; cookie auth works end-to-end in the console.
  • <Location /sql/> CSP allows the app; page loads with no CSP violations.
  • Concrete-path file (not swallowed by FallbackResource).
  • acm-ui link opens the new tab with cluster/node context.
  • No public-release/Helm/Docker path is triggered by this work.
主要语言
TypeScript
星标
8
派生
2
平均合并
1 小时 17 分钟
30 天内合并 PR
3

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

Altinity/altinity-sql-browser 的其他 Issue

查看 Altinity/altinity-sql-browser 的全部 Issue

相似的 Issue

更多 TypeScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。