feat(mcpedia): Phase 4 — operability + correctness hardening
Reinterpreted from the plan's YAGNI 'Scale-out' (OpenSearch/object-storage /multi-tenant deferred at KB scale). Phase 4 = make the Phase 3 async + revision system correct, secure, observable, deployable. - T1 (correctness bug): restoreRevision now rebuilds semantic chunks via new @mcpedia/core reindexChunks(slug) so semantic/hybrid search stay consistent after a restore (previously document_chunks held the NEW body while documents.body held the restored OLD body -> stale search). - T2 (security): /hooks/* git-sync webhooks now require x-webhook-secret header matching WEBHOOK_SECRET (401 otherwise); API fails fast at startup if unset. Added WEBHOOK_SECRET to @mcpedia/config + .env.example; set real secret in .env. - T3 (UX): web doc page shows a History panel (revision no/reason/date/length) with per-revision Restore; app/api/revisions/restore/route.ts calls restoreRevision + revalidatePath (server-component only, no client JS). - T4: listRevisions gains offset paging; summary never includes body. - T5 (ops): deploy/mcpedia-api.service + deploy/mcpedia-worker.service systemd units (Restart=on-failure, EnvironmentFile=.env). Not auto-enabled on host. Verified against live imrnes Redis + Postgres: turbo typecheck+build green; restore-rebuilds-chunks (marker present -> gone after restore); webhook 401/200; web restore route redirects to doc + reverts body; revisions API returns summary (no body); systemd-analyze verify passes.
This commit is contained in:
+19
-1
@@ -5,22 +5,40 @@ import { db } from "@mcpedia/db";
|
||||
import { appRouter } from "./router";
|
||||
import type { Context } from "./trpc";
|
||||
import { enqueueIndexDoc, enqueueFullIndex } from "@mcpedia/queue";
|
||||
import { WEBHOOK_SECRET } from "@mcpedia/config";
|
||||
|
||||
// Fail fast: never expose an open git-sync endpoint. If the operator hasn't
|
||||
// set WEBHOOK_SECRET, refuse to start rather than run an unauthenticated hook.
|
||||
if (!WEBHOOK_SECRET) {
|
||||
throw new Error(
|
||||
"WEBHOOK_SECRET is not set — /hooks/* would be open. Set it (see .env.example) before starting the API.",
|
||||
);
|
||||
}
|
||||
|
||||
const app = new Hono();
|
||||
|
||||
// Health check.
|
||||
// Health check (no auth — safe to expose).
|
||||
app.get("/health", (c) => c.json({ ok: true }));
|
||||
|
||||
// Shared guard for the git-sync webhooks: require `x-webhook-secret` header to
|
||||
// match the configured secret. Reject anything else with 401.
|
||||
function assertWebhookAuth(c: { req: { header: (k: string) => string | undefined } }): boolean {
|
||||
const provided = c.req.header("x-webhook-secret");
|
||||
return provided != null && provided === WEBHOOK_SECRET;
|
||||
}
|
||||
|
||||
// --- Phase 3: Git synchronization hook ---
|
||||
// POST /hooks/reindex -> enqueue a full-corpus reindex (git push webhook)
|
||||
// POST /hooks/index?slug=... -> enqueue a single document reindex
|
||||
// Returns the created job id(s). The worker processes them asynchronously.
|
||||
app.post("/hooks/reindex", async (c) => {
|
||||
if (!assertWebhookAuth(c)) return c.json({ ok: false, error: "unauthorized" }, 401);
|
||||
const job = await enqueueFullIndex("git-push");
|
||||
return c.json({ ok: true, jobId: job.id, kind: "full" });
|
||||
});
|
||||
|
||||
app.post("/hooks/index", async (c) => {
|
||||
if (!assertWebhookAuth(c)) return c.json({ ok: false, error: "unauthorized" }, 401);
|
||||
const slug = c.req.query("slug");
|
||||
if (!slug) return c.json({ ok: false, error: "slug query param required" }, 400);
|
||||
// slug is the relative path without extension, e.g. docs/websocket/contract
|
||||
|
||||
Reference in New Issue
Block a user