Skip to content

[WP03 · SubStep 03.00] Fix www connection through canonical host routing - #16

Merged
deku2026 merged 3 commits into
mainfrom
wp03-00-www-canonical
Sep 22, 2026
Merged

deku2026 merged 3 commits into
mainfrom
wp03-00-www-canonical

Conversation

@deku2026

@deku2026 deku2026 commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

The connection example opened through www.arcforges.com used that origin for /api, but only arcforges.com/api/* belongs to Cloud. The www Web catchall therefore served the page without a working API path.

This implements the existing canonical-host requirement: an importless Web Worker issues HTTP 308 from the exact www hostname to HTTPS apex before static assets, preserving path/query. Apex requests and responses pass unchanged through ASSETS. Existing DNS/domain/route bindings, the Cloud API, CSP and the client redirect guard remain unchanged. Pages already open on www need a reload after deployment.

The private Worker is copied into the same sealed candidate and deployed without rebundling. Its source bytes, candidate membership and Worker-first configuration are verified. Append-only browser profile r6 and admission r2 retain the complete previous browser graph, templates, legal inputs, package identities and SBOM expectations; there are no dependency upgrades. The large new JSON files retain the required immutable predecessor history. Design ownership is clarified by ArcForges/ArcForges-Design#59.

Validation and review:

  • Independent review covered routing, fixed destination, asset passthrough, candidate boundaries, tests and docs. The finding that JS bypassed Biome was fixed by including the Worker explicitly.
  • One local Node Request/Response navigation and apex fallback check passed without network. Formatting, whitespace, source-provenance and dependency-admission checks passed using existing local tools.
  • Added targeted offline regression tests for redirects, host boundaries, method/path/query handling, original asset passthrough, required routing configuration and private-script substitution.
  • The local Node/npm do not match the repository pins; the offline restore stopped at its engine guard. No toolchain was installed and no full local build or workerd/browser/live Cloud test is claimed. Existing pinned Windows/Linux CI performs applicable source/static/offline/security and candidate checks.
  • No workflow expansion or public asset downloads. Merge only after the final review and all applicable checks are green; main promotes the sealed candidate through the existing deployment job.

CI finding resolved: the first run passed Linux/Windows source checks, offline tests and CodeQL but reported eight secret-scan matches. All eight are unchanged public-source checksum lines already covered by exact r5 exceptions. Independent review approved adding only r6 to that anchored profile-path condition; scanner rules and exact hash patterns remain unchanged. Final CI runs on the corrected head.

@deku2026
deku2026 merged commit 120f209 into main Sep 22, 2026
10 checks passed
@deku2026
deku2026 deleted the wp03-00-www-canonical branch September 22, 2026 10:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant