docs: reconcile authenticated SSR production state
This commit is contained in:
1 parent
498c2fa242
commit
ca12cc88da
7 files changed
+101
-38
No files matched your search
@@ -1,6 +1,8 @@
|
||||
# Data Flow
|
||||
|
||||
## Primary Flows
|
||||
## Local Full-Stack Flows
|
||||
|
||||
These repository flows remain available for local development and do not establish which Service currently owns a path in the live production cluster.
|
||||
|
||||
| Flow | Source | Destination | Notes |
|
||||
|---|---|---|---|
|
||||
@@ -11,12 +13,12 @@
|
||||
|
||||
## Approved Target Flows
|
||||
|
||||
The Go implementation for these flows is merged into `main` under `backend/`; they become active on the first production deployment, which routes `/api`, `/uploads`, and `/generated-results` to Go from day one:
|
||||
The Go implementation and desired ACK routing for these flows are present in the repository. Production is already online, but its exact live Service ownership has not been confirmed from cluster configuration or logs:
|
||||
|
||||
| Flow | Source | Destination | Required behavior |
|
||||
|---|---|---|---|
|
||||
| Browser UI | Browser | Same-origin Ingress -> Next.js or Go by path | Preserve current URLs; avoid cross-origin Cookie/CORS changes. |
|
||||
| SSR identity/data | Next.js | Internal Go HTTP Interface | Forward Cookie and origin; Go remains the sole authorization authority. |
|
||||
| SSR identity | Next.js `getOptionalAuthSession()` | Internal Go `GET /api/auth/me` | Implemented in `498c2fa` when `ZHINIAN_GO_INTERNAL_BASE_URL` is configured: forward only enumerated `zhinian_session` Cookie chunks, use no-store transport, strictly validate authenticated/anonymous response shape and identity binding, and fail closed on bridge errors. No unrelated Cookie or origin forwarding. Without the URL, local full-stack mode keeps direct-store authorization. The live revision does not yet contain this fix. |
|
||||
| Backend persistence | Go Modules | PostgreSQL Adapter -> RDS | Parameterized queries and transactions; fail closed in production. |
|
||||
| Task execution | Embedded Go WorkerLoop | RDS claim -> provider -> OSS -> RDS -> Webhook | Bounded concurrency, recoverable leases, one owner for external side effects. |
|
||||
| Asset lifecycle | Go Assets | OSS plus RDS metadata | Shared storage required before horizontal scaling. |
|
||||
@@ -32,10 +34,13 @@ The Go implementation for these flows is merged into `main` under `backend/`; th
|
||||
|
||||
- Alibaba Cloud RDS PostgreSQL via its internal endpoint and verified TLS CA.
|
||||
- Alibaba Cloud ACK resources under `deploy/ack/`.
|
||||
- Live production at `https://nianxxaigc.nianxx.cn`; public `/api/ready` has returned HTTP 200 with PostgreSQL configured, without proving the owning Service.
|
||||
- Internal Worker HTTP endpoint is cluster-internal and blocked from public Ingress routing.
|
||||
|
||||
The internal Worker HTTP endpoint remains part of the local-development implementation only; production never deploys the Node Worker and uses the embedded Go WorkerLoop from the first rollout.
|
||||
The accepted production topology uses the embedded Go WorkerLoop rather than the local-development Node Worker. The exact live workload set remains to be confirmed from the cluster.
|
||||
|
||||
The SSR identity bridge and ACK internal URL are merged but not yet deployed. The current live revision produces a production RSC error for authenticated `/create`; the repair rollout must deploy `498c2fa` and verify the flow with an authenticated smoke test.
|
||||
|
||||
## Last Updated
|
||||
|
||||
2026-08-14
|
||||
2026-08-16
|
||||
Reference in new issue
Block a user