docs: reconcile authenticated SSR production state
This commit is contained in:
1 parent
498c2fa242
commit
ca12cc88da
7 files changed
+101
-38
No files matched your search
@@ -13,10 +13,11 @@ This file is the integrated default-branch snapshot. Feature tasks record progre
|
||||
- `f10cdd9` (record of completed task `20260812-architecture-task-breakdown-a83f61c2`)
|
||||
- `ff055c9` (config-driven super-admin bootstrap in the Go backend, task `20260814-go-bootstrap-admin-6e2b7d9c`)
|
||||
- `4a8f2d5` (Go workload deployment artifacts and split Ingress routing, task `20260814-go-deploy-artifacts-2a5f8e1d`)
|
||||
- `498c2fa` (authenticated Next.js SSR-to-Go identity bridge and ACK Web internal Go URL, task `20260816-fix-authenticated-ssr-6c3f8a21`)
|
||||
|
||||
## Current Focus
|
||||
|
||||
ADR-003's Go modular-monolith backend is implemented and merged into `main` under `backend/` (`cmd/zhinian-api`, 18 `internal/` packages, 24 contract fixtures, migration 0002). There is no production instance of this application yet: the **first production deployment** will run the ADR-003 split topology directly — Next.js serves pages/static/SSR, Go owns `/api`, `/uploads`, and `/generated-results` — so there is no legacy cutover, no Node Worker drain, and no legacy production session compatibility to preserve. Next.js route handlers remain in the repository for local development only. The production schema is initialized by manually executing the versioned SQL files; the ACK migration Job is not part of the deployment path.
|
||||
The first production deployment is live at `https://nianxxaigc.nianxx.cn`. Its deployed revision does not yet include `498c2fa`: authenticated `/create` currently triggers a production RSC error, while the public `/api/ready` endpoint has been observed returning HTTP 200 with PostgreSQL configured. The repository now contains the authenticated Next.js SSR-to-Go identity bridge in `lib/server/auth/current-user.ts`; when `ZHINIAN_GO_INTERNAL_BASE_URL` is configured it refreshes identity through internal Go `/api/auth/me`, and without that environment variable local Next.js full-stack development retains the direct-store path. Current work is the production repair rollout: publish the updated Web image and ACK configuration, then complete an authenticated `/create` smoke test. The exact live Service owner for each request path remains unverified until confirmed from cluster configuration or logs.
|
||||
|
||||
## Recently Completed
|
||||
|
||||
@@ -28,31 +29,32 @@ ADR-003's Go modular-monolith backend is implemented and merged into `main` unde
|
||||
- 2026-08-14: Added config-driven first-super-administrator bootstrap to the Go backend (task `20260814-go-bootstrap-admin-6e2b7d9c`).
|
||||
- 2026-08-14: Recorded the first-deployment model: no production cutover, manual schema initialization without the migration Job pod (task `20260814-deploy-model-reconcile-9b4c2e7f`).
|
||||
- 2026-08-14: Built the Go workload deployment artifacts: `backend/Dockerfile`, `deploy/ack/go-api.yaml`, split-path Ingress routing, non-root/read-only-filesystem workload config, and updated manifest assertions (task `20260814-go-deploy-artifacts-2a5f8e1d`).
|
||||
- 2026-08-16: Implemented authenticated production SSR identity refresh through Go `/api/auth/me`, forwarding only enumerated `zhinian_session` chunks, strictly validating the response, preserving the local direct-store path when the internal URL is absent, and keeping the updated ACK Web configuration database-free (task `20260816-fix-authenticated-ssr-6c3f8a21`, commit `498c2fa`; not yet deployed).
|
||||
|
||||
## In Progress
|
||||
|
||||
- None.
|
||||
- Release `498c2fa` to the existing production environment and verify authenticated `/create` SSR; the live revision still exhibits the RSC failure.
|
||||
|
||||
## Next Recommended Steps
|
||||
|
||||
1. Build and push the `zhinian-go-api` image from `backend/Dockerfile`, then validate all manifests with `kubectl apply --dry-run=server` on the target ACK cluster.
|
||||
2. Initialize the production schema by manually executing `database/migrations/0001_initial_schema.sql` then `0002_generation_lifecycle_fencing.sql` as the migration role, then apply the application-role grants (tables plus the two concurrency functions).
|
||||
3. Configure `ZHINIAN_BOOTSTRAP_ADMIN_*` on the first Go startup; the process creates the first super administrator exactly once.
|
||||
4. Validate against non-production RDS (real application role, verified-CA TLS), real OSS, provider credentials, and external Webhooks before the first production rollout.
|
||||
5. Confirm the public `/api/v1` compatibility promise for external consumers.
|
||||
1. Build and push the updated Web image containing `498c2fa`, and validate the updated ACK configuration with a server-side dry run on the production cluster.
|
||||
2. Apply the updated Web image and ACK configuration without assuming the current live Service ownership beyond what cluster configuration and logs confirm.
|
||||
3. Smoke-test an authenticated request to `/create`, confirming the production RSC error is resolved and SSR refreshes the user through internal Go `/api/auth/me`.
|
||||
4. Recheck public `/api/ready` after the rollout; it currently returns HTTP 200 with PostgreSQL configured.
|
||||
5. Continue real RDS/OSS/provider/Webhook validation and confirm the public `/api/v1` compatibility promise for external consumers.
|
||||
|
||||
## Open Questions / Blockers
|
||||
|
||||
- Target RDS PostgreSQL version, connection budget, endpoint, TLS enforcement, CA bundle, database roles, and ACK network policy remain deployment inputs.
|
||||
- Canonical memory does not yet record the live RDS PostgreSQL version, connection budget, endpoint, TLS/CA details, database roles, ACK network policy, or confirmed request-path Service ownership.
|
||||
- Real OSS bucket/credential configuration is still needed for shared asset storage.
|
||||
- Public `/api/v1` support promises for external consumers need explicit confirmation.
|
||||
|
||||
## Risky Areas
|
||||
|
||||
- Database grants and least-privilege roles must be tested against the actual RDS instance before the first rollout.
|
||||
- Database grants and least-privilege roles still require documented validation against the live RDS instance.
|
||||
- The current image runs as root; moving to a non-root user requires an explicit writable-path ownership design.
|
||||
- The Go code is contract-tested but has never run against real provider, OSS, RDS, and Webhook traffic; parity gaps can only surface under real dependencies.
|
||||
- Real provider, OSS, RDS, and Webhook coverage is not fully documented; do not infer which live workload owns those paths without cluster evidence.
|
||||
|
||||
## Last Updated
|
||||
|
||||
2026-08-14
|
||||
2026-08-16
|
||||
@@ -16,6 +16,8 @@
|
||||
| 2026-08-14 | `20260814-deploy-model-reconcile-9b4c2e7f` | Recorded the first-deployment model (split topology from day one, manual SQL schema initialization, config-driven bootstrap) across canonical memory and deployment docs. | Current state, decisions (DEP-001), architecture, commitments, deployment docs |
|
||||
| 2026-08-14 | `20260814-go-bootstrap-admin-6e2b7d9c` | Config-driven first-super-administrator bootstrap in the Go backend. | Task record, backend README |
|
||||
| 2026-08-14 | `20260814-go-deploy-artifacts-2a5f8e1d` | Go workload deployment artifacts: `backend/Dockerfile`, `deploy/ack/go-api.yaml`, split-path Ingress, database-free Web workload, updated manifest assertions. | Task record, deployment docs, READMEs |
|
||||
| 2026-08-16 | `20260816-fix-authenticated-ssr-6c3f8a21` | Revision `498c2fa` implements authenticated SSR identity refresh through internal Go `/api/auth/me` using only enumerated session Cookie chunks; strict response validation, local direct-store behavior, and a database-free ACK Web configuration are preserved. The task performed no live deployment. | Task record |
|
||||
| 2026-08-16 | `20260816-integrate-auth-ssr-9d7e4c2a` | Serialized integration of source commit `498c2fa` and canonical reconciliation for the authenticated SSR-to-Go identity bridge. No live deployment was performed. | Current state, task history, system overview, module map, data flow, commitments |
|
||||
|
||||
## Notes
|
||||
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
# Task: Integrate authenticated SSR fix into main
|
||||
|
||||
## Identity
|
||||
|
||||
- Task ID: 20260816-integrate-auth-ssr-9d7e4c2a
|
||||
- Mode: Integration
|
||||
- Branch: codex/20260816-integrate-auth-ssr-9d7e4c2a-integrate-auth-ssr
|
||||
- Worktree: D:\Datas\OthersProjects\NianAIGC-integrate-auth-ssr-9d7e4c2a
|
||||
- Base commit: 498c2fa2423abb1706f92f27ef7c1e71fc7345ca
|
||||
- Owner: codex
|
||||
- Status: In Progress
|
||||
|
||||
## Scope
|
||||
|
||||
- Integrate completed feature commit `498c2fa` (`20260816-fix-authenticated-ssr-6c3f8a21`) into `main` without mixing unrelated ready or planning tasks.
|
||||
- Reconcile canonical project memory with the now-implemented Next.js SSR-to-Go identity boundary and database-free production Web workload.
|
||||
- Re-run repository and project-document gates, complete read-only review, and advance the reviewed integration commit to `main`.
|
||||
|
||||
## Intent And Constraints
|
||||
|
||||
- Use the serialized Integration Gate and this dedicated worktree; do not mutate the occupied `main` worktree before a separately owned final fast-forward step.
|
||||
- Integrate only the authenticated SSR fix and necessary canonical-memory reconciliation; the source task record remains read-only in this task baseline.
|
||||
- Preserve accepted ADR-003 and DEP-001 semantics: production Next.js serves pages/SSR and calls Go over internal HTTP; Go owns database-backed authorization and the Web workload receives no database credentials.
|
||||
- Treat the diagnosis promotion candidate as satisfied by the public-seam regression suite and retain a durable deployment commitment for authenticated SSR smoke testing.
|
||||
- Do not merge the unrelated provider-settings or other ready task branches.
|
||||
|
||||
## Outcome
|
||||
|
||||
- Completed feature commit `498c2fa` is the verified baseline of this Integration Gate; its source task record remains unchanged.
|
||||
- The user confirmed that `https://nianxxaigc.nianxx.cn` is the production environment and that the currently running revision is the first deployment. Canonical memory is therefore being reconciled as a live production remediation, not as a future first deployment.
|
||||
- Canonical current state, task history, system overview, module map, data flow, and commitments now describe the implemented production SSR-to-Go identity bridge, database-free Web workload, local direct-store fallback, and required authenticated `/create` rollout smoke test.
|
||||
- No unrelated ready/planning task branch was merged. Creating the reviewed integration documentation commit and advancing it to `main` remain the final steps.
|
||||
|
||||
## Verification
|
||||
|
||||
- Source feature final `sol_reviewer`: PASS for Standards and Spec.
|
||||
- `cmd /c npm.cmd test` — 58 files and 183 tests passed on commit `498c2fa` in this integration worktree.
|
||||
- `cmd /c npx.cmd tsc --noEmit --incremental false` — passed.
|
||||
- `cmd /c npm.cmd run deploy:check` — `ACK manifest assertions passed (9 files)`.
|
||||
- `cmd /c npm.cmd run build` — Next.js 15.5.18 production build passed; `/create` remains dynamically server-rendered.
|
||||
- Canonical-memory reconciliation ran `git diff --check` successfully and touched only the six authorized canonical files.
|
||||
- `uv run python .../check_project_docs.py` — passed in the correctly based integration worktree.
|
||||
- `uv run python .../check_doc_drift.py --task-id 20260816-integrate-auth-ssr-9d7e4c2a` — passed; only this integration task record and authorized canonical documents changed relative to `498c2fa`.
|
||||
|
||||
## Follow-ups
|
||||
|
||||
- Build and publish the updated Web image, apply the checked-in ACK configuration, and complete the open authenticated `/create` smoke-test commitment before declaring the production remediation complete.
|
||||
|
||||
## Promotion Candidates
|
||||
|
||||
- None. This integration applies the already accepted ADR-003/DEP-001 boundary and records the remaining deployment verification obligation.
|
||||
Reference in new issue
Block a user