Altinity / Altinity/altinity-sql-browser
[sup] Same-origin deployment: static artifact in ACM docroot, <Location> CSP, acm-ui link
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 8
- Forks
- 2
- Avg merge
- 1h 34m
- Merged PRs (30d)
- 6
Description
Part of #352. Reworked: same-origin static deployment into ACM, not a public release tag.
Our SPA ships as a static file in the altinity/acm image docroot, served same-origin at a concrete path (e.g. /sql/), opened in a new tab from acm-ui.
Our repo (altinity-sql-browser)
- Build the artifact so it runs under ACM (see CSP below): either keep the single inline-
<script>file and rely on a scoped ACM<Location>CSP, or add a build mode emitting external JS from'self'(no inline/eval). - Select ACM cookie-auth mode at runtime (URL context) rather than a separate bundle if practical.
- Decide artifact delivery to ACM: committed asset, pinned GitHub release download, or built in acm-ui's pipeline.
acm repo (backend/distrib)
distrib/build.sh: place our built file into the docroot / tar (/var/www/html/sql/…).- vhost: add a
<Location /sql/>CSP block (mirror the existing/api/CSP:'self' 'unsafe-inline' 'unsafe-eval' *.gstatic.com data:). Needed because the strict page CSP blocks our inline bundle. - Serve as a real file at a concrete path (
FallbackResource /index.htmlwould otherwise return the Angular shell).
acm-ui repo
- Add a link on the cluster/explore page →
/sql/?cluster=<id>&node=<n>(target=_blank).
Do NOT
—vX.Y.Z-suptagrelease.ymlfires onv*anddocker.ymlonv*.*.*(+latest); a-suptag would enter public GitHub Release / Helm / Dockerlatest. Deployment here is via the ACM image, not this repo's public tags.
Acceptance
- Artifact served same-origin at
/sql/; cookie auth works end-to-end in the console. -
<Location /sql/>CSP allows the app; page loads with no CSP violations. - Concrete-path file (not swallowed by
FallbackResource). - acm-ui link opens the new tab with cluster/node context.
- No public-release/Helm/Docker path is triggered by this work.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reading the artifact/build discussion in this repository, then inspect acm's distrib/build.sh and vhost configuration and acm-ui's cluster/explore page. Resolve the artifact delivery and CSP approach across the three repositories, while checking release.yml and docker.yml for unintended public-release paths. Done means the /sql/ artifact, cookie-auth flow, CSP, concrete file path, contextual link, and release safeguards satisfy the listed acceptance checks.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- backend, devops, frontend
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100