Rewrite the backend in Go #6
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "refactor/go-rewrite"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Closes #4. Closes #2.
The image was 305 MB, almost all of it the Node runtime. This replaces the Express server with a Go binary that carries the dashboard inside it: 29.8 MB.
The routes, the
data/layout and the JWT are unchanged, so the database, the assets and the tokens already handed out all carry over. Migrations run offPRAGMA user_version, and the first one is a no-op on a database drizzle made. Two dependencies:modernc.org/sqlitebecause a cgo driver needs a C cross compiler, andgolang-jwtbecause a hand written verifier can miss the algorithm confusion check. The router isnet/http.Checked against the old server
Node on :4000 and Go on :4001, both reading a copy of the production
data/. Manifests are byte identical for iOS and Android, headers included. A token Node signed verifies on Go and the other way round. ThenoUpdateAvailabledirective, the old-client 404s, the asset bytes and content types, the traversal blocking and the login limiter all match request for request.Fixed, not carried over
upload_dateholds whole seconds, so uploads inside one second tie. The old server kept the wrong updates and served a stale manifest. Every ordering now breaks the tie on the rowid.archive/ziphas no zip slip guard, so every entry name is checked to stay below the update directory.MAX_UPLOAD_BYTEScaps an upload route that took an archive of any size./apiin development and the server sends the dashboard in production, so every request was already same origin.bareed --backupcopies the database withVACUUM INTO. The backup script on the server snapshotted it withbetter-sqlite3through node, which this image does not carry.Still to verify
A real device, which is the only thing that proves the protocol end to end. And this PR itself: the runner has no Go, so this is the first run of
actions/setup-go.