docs: integrate static frontend architecture
This commit is contained in:
1 parent
b14b4fced7
commit
bb50d06d1d
13 files changed
+243
-82
No files matched your search
@@ -4,30 +4,33 @@
|
||||
|
||||
| Path | Responsibility | Owner Notes |
|
||||
|---|---|---|
|
||||
| `lib/server/database.ts` | Server-only PostgreSQL Pool, TLS, queries, transactions, readiness | Only deep database transport boundary for runtime stores. |
|
||||
| `lib/server/{data-store,account-store,billing-store}.ts` | Domain persistence with PostgreSQL/local implementations | Preserve exported interfaces for callers. |
|
||||
| `database/migrations/` | Immutable versioned PostgreSQL schema changes | Executed manually for the first deployment (0001 initial schema, 0002 generation lifecycle fencing); the Node runner and Job manifest are retained but not part of the deployment path. |
|
||||
| `scripts/postgres-client.mjs` | Validated database configuration for Node operations scripts | Shared by migration/bootstrap/import scripts. |
|
||||
| `deploy/ack/` | ACK deployment resources and secret/config templates | Desired production split topology; the `498c2fa` Web configuration is pending rollout, and the migration Job manifest is deprecated (manual SQL). |
|
||||
| `app/api/ready/route.ts` | Database/schema/privilege readiness endpoint | Separate from process-level liveness. |
|
||||
| `lib/server/auth/current-user.ts` | In revision `498c2fa`, resolves the current SSR user through internal Go `/api/auth/me` when `ZHINIAN_GO_INTERNAL_BASE_URL` is set; otherwise uses the local direct-store authorization path | Sends only enumerated `zhinian_session` chunks, validates the Go response and identity binding strictly, and fails closed on bridge errors. The fixed revision is not yet live. |
|
||||
| `backend/cmd/zhinian-api` | Go application entrypoint, configuration, HTTP server composition, readiness | Locally runnable and targeted by checked-in ACK routing; exact live request ownership remains unverified. |
|
||||
| `backend/internal/*` | ADR-003 deep modules and adapters, 18 packages: `identity`, `administration`, `assets`, `billing`, `usage`, `jobs`, `providers`, `webhook`, `httpapi`, `publicapi`, `application`, `orchestration`, `postgres`, `localstore`, `logging`, `settings`, `templates`, `prompt` | Merged; production is online, but the deployed revision and live routing do not yet reflect the `498c2fa` repair configuration. |
|
||||
| `app/**`, `components/**` | Statically exportable pages and browser UI | No Route Handlers, Middleware, server auth imports, or request-time page dependencies. |
|
||||
| `components/browser-auth.tsx` | Browser identity context and presentation guards | Consumes validated same-origin state; guards are UX only. |
|
||||
| `lib/client/browser-auth.ts` | Deep browser/Go auth Interface | Owns `GET /api/auth/me` parsing plus safe return-path validation. |
|
||||
| `next.config.ts`, `Dockerfile`, `deploy/nginx.conf` | Static export and production Web runtime | Build emits `out/`; unprivileged Nginx serves files and rejects Go-owned paths when reached directly. |
|
||||
| `database/migrations/` | Immutable versioned PostgreSQL schema changes | Executed manually/through dedicated operator CI; no migration Job reuses Web. |
|
||||
| `deploy/ack/` | Seven ACK manifests plus Secret template | Static Web + Go topology; Web has no runtime config/Secret and Go owns the session Secret. |
|
||||
| `backend/cmd/zhinian-api` | Go application entrypoint, configuration, HTTP server composition, health/readiness | Sole runtime API owner targeted by checked-in Ingress. |
|
||||
| `backend/internal/*` | ADR-003 deep modules and adapters, 18 packages: `identity`, `administration`, `assets`, `billing`, `usage`, `jobs`, `providers`, `webhook`, `httpapi`, `publicapi`, `application`, `orchestration`, `postgres`, `localstore`, `logging`, `settings`, `templates`, `prompt` | Implemented in `b14b4fc`; publication of immutable images and rollout of the static Web + Go revision remain pending. |
|
||||
| `contracts/**/*.json` | Language-neutral HTTP/Cookie/auth/jobs/billing/storage/webhook contract fixtures | Shared acceptance source for TypeScript and Go consumers. |
|
||||
|
||||
## Dependency Direction
|
||||
|
||||
- Routes and services depend on store interfaces; stores depend on the shared database adapter; the adapter does not depend on domain stores.
|
||||
- Worker depends on the internal Web HTTP API, not the database module.
|
||||
- Go modules depend on the PostgreSQL transport and storage/provider adapters; `httpapi`/`publicapi` depend on deep modules, never the reverse.
|
||||
- Static pages/components depend on `lib/client/browser-auth.ts` and relative
|
||||
same-origin HTTP paths; they never depend on `lib/server`.
|
||||
- Go `httpapi`/`publicapi` depend on deep business Modules; Modules depend on
|
||||
PostgreSQL/storage/provider Adapters, never on Web or HTTP presentation.
|
||||
- The embedded WorkerLoop uses Go application/Module seams and PostgreSQL
|
||||
claims; there is no Node-to-Web internal tick dependency.
|
||||
|
||||
## Approved Target Module Map
|
||||
|
||||
The target below is implemented in the repository. The first production deployment has occurred; the `498c2fa` repair rollout and confirmation of the live cluster shape remain pending:
|
||||
The target below is implemented in `b14b4fc`; image publication, ACK rollout,
|
||||
and confirmation of the live cluster shape remain pending:
|
||||
|
||||
| Target Module | Go package | Implementation notes |
|
||||
|---|---|---|
|
||||
| Next.js frontend | `lib/server/auth/current-user.ts` | In `498c2fa`, production SSR forwards only enumerated signed session Cookie chunks to Go `/api/auth/me`; the live revision does not yet contain this fix. Local full-stack mode uses direct stores when the internal Go URL is absent. |
|
||||
| Static frontend | `components/browser-auth.tsx`, `lib/client/browser-auth.ts` | Browser calls same-origin Go `/api/auth/me`; no SSR bridge, request Cookie parsing, internal Go URL, or server fallback. |
|
||||
| Go Identity | `internal/identity` | Login/logout/session/password/authorization; preserves the signed chunked Cookie and per-request account/organization/sessionVersion validation. |
|
||||
| Go Administration | `internal/administration` | Organizations, accounts, settings visibility, logs, administrative usage; enforces super-admin and organization-admin rules. |
|
||||
| Go Assets | `internal/assets` | Register/upload/list/get/delete/download; uses object-storage Adapter; preserves owner-scoped 404 and storage metadata. |
|
||||
@@ -45,7 +48,10 @@ Real internal seams are PostgreSQL transport, object storage, generation provide
|
||||
- Account authentication/password transactions and billing wallet idempotency.
|
||||
- ACK Secrets, RDS CA mounting, Ingress protection for internal Worker routes, and pool connection budgeting.
|
||||
- `backend/internal/{postgres,jobs,billing}`: claim and wallet correctness across Go replica scaling until WorkerLoop concurrency is deliberate.
|
||||
- Live request-path ownership and deployed workload revisions must be confirmed from ACK configuration or logs; do not infer them from the public endpoint alone.
|
||||
- Static Web image construction/container startup still needs CI smoke evidence.
|
||||
- Go `emptyDir` file state is lost on Pod replacement when OSS is absent.
|
||||
- Live request-path ownership and deployed workload revisions must be confirmed
|
||||
from ACK configuration or logs; do not infer them from a public endpoint.
|
||||
|
||||
## Last Updated
|
||||
|
||||
|
||||
Reference in new issue
Block a user