feat: custom routing — bind scripts to your own URLs
Scripts can now answer at user-chosen paths (e.g. /greet, /greet/:name,
/webhooks/*), on user-chosen hosts (strict or *.example.com wildcards),
on user-chosen methods. The internal /api/v1/execute/{id} endpoint
stays as the always-available ID-based bypass.
Routing rules (decided in design with the user; see chat history):
Path kinds:
exact /greet literal
prefix /greet/* strict-subtree; stored as "/greet/";
does NOT match bare /greet (add an
exact route for that case)
param /users/:id :name captures one whole segment;
mid-segment colons are rejected;
{name} is reserved for a future SDK
Host kinds:
any no Host header constraint
strict sub.example.com literal match (case-insensitive)
wildcard *.example.com suffix match; multi-level subdomains OK
Within-kind uniqueness:
two routes of the same kind that could match the same request
conflict at config time. Algorithm (orchestrator_core::routing::
conflict):
exact: literal equality
prefix: literal equality (longer-prefix coexists; longer wins
at request time)
param: same segment count + same literals at every
literal-vs-literal position (the user's example:
:id vs :userId at same shape is a conflict)
Request-time precedence:
exact > param > prefix
among non-exact: more leading-literal segments wins
tie: param > prefix (more constrained)
within prefix: longest matching prefix wins
host bucket: strict > wildcard (longer suffix) > any; fall through
to less specific buckets when path doesn't match
Reserved path prefixes: /api/, /admin/, /healthz, /version
Routes that look invalid at config time return 422 with the precise
parse error; conflicting routes return 409 with the conflicting route
in the body (so the dashboard can render the conflict inline).
What landed:
* 0003_routes.sql — routes table (host_kind, host, host_param_name,
path_kind, path, method, script_id) with UNIQUE index on the
literal binding tuple. Schema 2 → 3.
* shared::Route / HostKind / PathKind — flat storage shape that
crosses wire boundaries cleanly.
* orchestrator_core::routing — four sub-modules, all unit-tested:
pattern.rs (16 tests) parse + validate + display
conflict.rs (12 tests) within-kind overlap predicate
matcher.rs (12 tests) runtime dispatch (specificity-aware)
table.rs Arc<RwLock<Vec<CompiledRoute>>>
shared by manager (writes) and
orchestrator (reads); atomic replace
after each admin write
* manager-core::route_admin — five new admin endpoints under
/api/v1/admin:
POST /scripts/{id}/routes create
GET /scripts/{id}/routes list per script
DELETE /routes/{route_id} delete (refreshes table)
POST /routes:check pre-flight conflict check
(powers the dashboard's
live conflict warning)
POST /routes:match synthetic URL → matched
route + extracted params
(powers the dashboard's
match-preview tool)
Stored path strings stay raw (user-typed); normalization
happens only in the in-memory CompiledRoute so re-parses are
idempotent.
* orchestrator_core::api::user_routes_router — fallback handler
mounted in picloud after the system routes. Reads Host /
method / path / query from the request, dispatches via the
table, builds an ExecRequest with params/query/rest filled,
calls the executor, writes to the log sink. 10 MiB body cap.
* executor-core::ctx (SDK 1.0 → 1.1) — adds
ctx.request.params (map of named-param captures)
ctx.request.query (parsed query string)
ctx.request.rest (suffix for prefix routes; "" otherwise)
All three are always present (empty when not applicable) so
scripts can read them unconditionally.
* picloud::build_app — now async; loads routes at startup,
populates the shared table, mounts route_admin_router under
/api/v1/admin alongside the script CRUD, and the user-routes
fallback at the app root.
* caddy/Caddyfile + Caddyfile.prod widened: anything not
/healthz, /version, /api/v1/admin/*, /api/v1/execute/*,
/api/* (404 sunset), or /admin/* (dashboard) → picloud.
* Dashboard moves to /admin/* via SvelteKit paths.base. Its
internal Caddy strips the prefix and serves with SPA fallback.
All in-app links use $app/paths. The dashboard URL is now
http://localhost:8000/admin/ — one-time break for the new
URL freedom users gained.
* PICLOUD_PUBLIC_BASE_URL env var, exposed via /version so the
dashboard renders full URLs for routes regardless of the
operator's external port / TLS setup.
* memory_limit_mb stays in the schema, still v1.3+ advisory.
Verified live through Caddy:
/version → schema 3, sdk 1.1, public_base_url
GET /admin/ → 200, dashboard HTML containing "PiCloud"
POST /api/v1/admin/scripts → 201
POST .../scripts/{id}/routes (path=/greet/:name) → 201
GET /greet/alice?lang=en → 200 {"name":"alice","q":"en"}
POST conflicting route → 409 with conflicting_route body
POST /admin/foo route → 422 "reserved"
POST /api/v1/admin/routes:match → matched + params extracted
GET /unbound-path → 404 JSON
Tests:
* 40 routing unit tests (pattern + conflict + matcher tables)
* 14 executor-core unit tests (one new for ctx.request.params/
query/rest exposure)
* 32 integration tests (10 new for routing CRUD + dispatch +
conflict + reserved + specificity tie-break + match preview +
delete invalidation + /version returns public_base_url)
* default cargo test --workspace stays green; opt-in via
DATABASE_URL + --include-ignored for the integration suite
Bumps: schema 2 → 3; SDK 1.0 → 1.1; product 0.3.0 → 0.4.0.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -8,6 +8,7 @@ pub mod error;
|
||||
pub mod execution_log;
|
||||
pub mod ids;
|
||||
pub mod log_sink;
|
||||
pub mod route;
|
||||
pub mod sandbox;
|
||||
pub mod script;
|
||||
pub mod validator;
|
||||
@@ -17,6 +18,7 @@ pub use error::Error;
|
||||
pub use execution_log::{ExecutionLog, ExecutionStatus};
|
||||
pub use ids::{ExecutionId, RequestId, ScriptId};
|
||||
pub use log_sink::{ExecutionLogSink, LogSinkError};
|
||||
pub use route::{HostKind, PathKind, Route};
|
||||
pub use sandbox::ScriptSandbox;
|
||||
pub use script::Script;
|
||||
pub use validator::{ScriptValidator, ValidationError};
|
||||
|
||||
60
crates/shared/src/route.rs
Normal file
60
crates/shared/src/route.rs
Normal file
@@ -0,0 +1,60 @@
|
||||
//! Route binding: which `(host, method, path)` tuples invoke a given
|
||||
//! script. The storage shape (this file) is intentionally flat — the
|
||||
//! orchestrator parses these into typed `HostPattern` / `PathPattern`
|
||||
//! values for matching, and reconstructs strings for display.
|
||||
|
||||
use chrono::{DateTime, Utc};
|
||||
use serde::{Deserialize, Serialize};
|
||||
use uuid::Uuid;
|
||||
|
||||
use crate::ScriptId;
|
||||
|
||||
#[derive(Debug, Clone, Copy, Serialize, Deserialize, PartialEq, Eq)]
|
||||
#[serde(rename_all = "lowercase")]
|
||||
pub enum HostKind {
|
||||
/// Matches any host header.
|
||||
Any,
|
||||
/// Exact hostname match: `sub.example.com`.
|
||||
Strict,
|
||||
/// Wildcard suffix match: `*.example.com` matches any subdomain of
|
||||
/// `example.com`. Capture name is reserved for the future
|
||||
/// `{name}.example.com` syntax (currently always None on writes).
|
||||
Wildcard,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Copy, Serialize, Deserialize, PartialEq, Eq)]
|
||||
#[serde(rename_all = "lowercase")]
|
||||
pub enum PathKind {
|
||||
/// Literal string equality: `/greet` matches only `/greet`.
|
||||
Exact,
|
||||
/// Strict-subtree match. Stored as the prefix including the trailing
|
||||
/// slash; `/greet/*` is stored as path "/greet/" and matches
|
||||
/// `/greet/x` but not `/greet` itself (which would need its own
|
||||
/// exact route).
|
||||
Prefix,
|
||||
/// Named-parameter pattern: `/greet/:name` where each `:foo` consumes
|
||||
/// exactly one segment and captures it into `ctx.request.params.foo`.
|
||||
Param,
|
||||
}
|
||||
|
||||
#[derive(Debug, Clone, Serialize, Deserialize)]
|
||||
pub struct Route {
|
||||
pub id: Uuid,
|
||||
pub script_id: ScriptId,
|
||||
|
||||
pub host_kind: HostKind,
|
||||
/// For `Any`: empty string. For `Strict`: full hostname. For
|
||||
/// `Wildcard`: the suffix after the leading `*.` (e.g. `example.com`).
|
||||
pub host: String,
|
||||
pub host_param_name: Option<String>,
|
||||
|
||||
pub path_kind: PathKind,
|
||||
/// Raw path as the user typed it. For `Prefix`, normalized to end
|
||||
/// with `/` (the trailing `*` is dropped on write).
|
||||
pub path: String,
|
||||
|
||||
/// `None` = any method.
|
||||
pub method: Option<String>,
|
||||
|
||||
pub created_at: DateTime<Utc>,
|
||||
}
|
||||
@@ -12,11 +12,14 @@ pub const PRODUCT_VERSION: &str = env!("CARGO_PKG_VERSION");
|
||||
|
||||
/// Rhai SDK version, in `"major.minor"` form. Scripts read this from
|
||||
/// `ctx.sdk_version` for feature detection. Bump rules:
|
||||
/// * patch (`1.0.x`): doc-only, no script-observable change
|
||||
/// * patch (`1.x.0`): doc-only, no script-observable change
|
||||
/// * minor (`1.0 → 1.1`): added functions / fields; existing
|
||||
/// scripts must still run unchanged
|
||||
/// * major (`1 → 2`): removed, renamed, retyped, restricted
|
||||
pub const SDK_VERSION: &str = "1.0";
|
||||
///
|
||||
/// 1.1 additions: `ctx.request.params`, `ctx.request.query`,
|
||||
/// `ctx.request.rest`.
|
||||
pub const SDK_VERSION: &str = "1.1";
|
||||
|
||||
/// HTTP API major version. Appears in URL paths as `/api/v{N}/...`.
|
||||
/// Bump (new integer + new URL prefix) when the request/response
|
||||
|
||||
Reference in New Issue
Block a user