[WP03 · SubStep 03.00] Fix www connection through canonical host routing - #16
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The connection example opened through
www.arcforges.comused that origin for/api, but onlyarcforges.com/api/*belongs to Cloud. The www Web catchall therefore served the page without a working API path.This implements the existing canonical-host requirement: an importless Web Worker issues HTTP 308 from the exact www hostname to HTTPS apex before static assets, preserving path/query. Apex requests and responses pass unchanged through ASSETS. Existing DNS/domain/route bindings, the Cloud API, CSP and the client redirect guard remain unchanged. Pages already open on www need a reload after deployment.
The private Worker is copied into the same sealed candidate and deployed without rebundling. Its source bytes, candidate membership and Worker-first configuration are verified. Append-only browser profile r6 and admission r2 retain the complete previous browser graph, templates, legal inputs, package identities and SBOM expectations; there are no dependency upgrades. The large new JSON files retain the required immutable predecessor history. Design ownership is clarified by ArcForges/ArcForges-Design#59.
Validation and review:
CI finding resolved: the first run passed Linux/Windows source checks, offline tests and CodeQL but reported eight secret-scan matches. All eight are unchanged public-source checksum lines already covered by exact r5 exceptions. Independent review approved adding only r6 to that anchored profile-path condition; scanner rules and exact hash patterns remain unchanged. Final CI runs on the corrected head.