Files
VoiceStudio/backend/core/spa_inject.py
T
Palash DebnathandClaude Opus 4.8 1b08c03da9 fix(docker): runtime API-base override so served deployments reach the backend (#174)
Docker users reported Settings -> Engines failing with 'Failed to load engines:
Failed to fetch'. Two problems: (1) the two API-base resolvers diverged
(client.ts honored VITE_API_URL; apiBase.ts honored VITE_OMNIVOICE_API), and
the docs documented VITE_OMNIVOICE_API -- which the Engines request path
ignored; (2) VITE_* is inlined at BUILD time, so a prebuilt ghcr.io image has
no working runtime override at all for reverse-proxy / split-origin deploys.

- backend: when OMNIVOICE_PUBLIC_API_BASE is set, inject it into index.html as
  window.__OMNIVOICE_API_BASE__ (core/spa_inject.py; validated to a plain
  http(s) URL so it can't break out of the <script>). Unset (default) ->
  StaticFiles serves index.html untouched (same-origin, zero overhead).
- frontend: both resolvers (client.ts _resolveApiBase + utils/apiBase.ts) now
  read the runtime global FIRST, then VITE_OMNIVOICE_API/VITE_API_URL, then
  fall through to same-origin. client.ts also strips trailing slashes and
  recognises __TAURI_INTERNALS__ (parity with apiBase.ts/external.ts).
- docs: docker.md + troubleshooting.md document OMNIVOICE_PUBLIC_API_BASE as the
  runtime override that works on the prebuilt image (the old VITE_OMNIVOICE_API
  docker run -e example never worked -- build-time inlining).
- tests: spa_inject helpers (inject + URL validation/breakout); resolver
  precedence for the runtime global + VITE_OMNIVOICE_API in both test files.

Default same-origin behavior is unchanged on every platform; override is opt-in.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-05-30 20:54:49 +05:30

36 lines
1.4 KiB
Python

"""Runtime API-base injection for the served SPA (Docker / reverse-proxy).
`VITE_*` vars are inlined at build time, so a prebuilt image cannot take an
API-base override from `docker run -e`. When `OMNIVOICE_PUBLIC_API_BASE` is set,
the backend injects it into `index.html` as `window.__OMNIVOICE_API_BASE__`,
which the SPA's API resolver reads first. These helpers are pure so they can be
unit-tested without booting the app.
"""
from __future__ import annotations
import json
import re
# Operator-controlled value, but validate to a plain http(s) URL with no
# whitespace, quotes, or angle brackets so it can never break out of the
# injected <script> element.
_URL_RE = re.compile(r"^https?://[^\s<>\"']+$")
def is_valid_public_api_base(value: str) -> bool:
"""True if `value` is a safe http(s) URL we can inject into HTML."""
return bool(value) and bool(_URL_RE.match(value))
def inject_api_base(html_doc: str, api_base: str) -> str:
"""Insert `window.__OMNIVOICE_API_BASE__` right after the SPA's <head>.
`api_base` is JSON-encoded (neutralising quotes); the caller is expected to
have validated it via `is_valid_public_api_base` first. Falls back to
prepending the snippet if the document has no <head>.
"""
snippet = f"<script>window.__OMNIVOICE_API_BASE__={json.dumps(api_base)};</script>"
if "<head>" in html_doc:
return html_doc.replace("<head>", "<head>" + snippet, 1)
return snippet + html_doc