add public icon route + forwarded proxy trust; SPEC/AGENTS docs

This commit is contained in:
proitlab committed 2026-08-16 20:58:38 +07:00
1 parent e737cd0b63
commit bc8021825a
4 files changed
+23 -6

No files matched your search

+2 -1
View File
@@ -3,7 +3,7 @@
Project conventions and operational gotchas for agents working in this repo.
## Layout
- `app/main.py` — FastAPI app: public endpoints `GET /api/getTokenInfo`, `GET /api/version/android`, `GET /img/token/<filename>`; mounts `/static`; startup calls `db.init_db()`.
- `app/main.py` — FastAPI app: public endpoints `GET /api/getTokenInfo`, `GET /api/version/android`, `GET /img/token/<filename>` + `GET /public/img/token/<filename>` (alias, seed iconUrl path); mounts `/static`; startup calls `db.init_db()`.
- `app/admin.py` — sqladmin panel: `TokenAdmin` (custom WTForms form, `on_model_change`), `VersionAdmin`, `create_admin(app)`. Upload icons saved under `app/static/icons/token/` with `iconUrl = {IDRS_PUBLIC_URL}/img/token/<filename>`.
- `app/models.py` — SQLAlchemy `Token`/`Version`, engine, `SessionLocal`, `ICON_DIR`, `DB_PATH` (env `IDRS_DB_PATH`).
- `app/db.py` — seed from `tokenList.json`/`versionAndroid.json` (once, empty DB only).
@@ -26,6 +26,7 @@ Project conventions and operational gotchas for agents working in this repo.
- Deploy (Swarm): `docker stack deploy -c docker-compose.yml idrs` — service `idrs-api`, traefik labels (Host `idrs.databisnis.id`, `entrypoints=websecure`, `certresolver=letsencrypt`), constraint `node.hostname != server2U`, external overlay `traefik-net` (must pre-exist on manager), `env_file: .env`.
- NFS bind mounts: `/mnt/nfs/server5.saltis.id/data/idrs/data` → `/app/data` (DB), `/mnt/nfs/server5.saltis.id/data/idrs/static` → `/app/app/static` (icons live at `<static>/icons/`; `icons/` subdir auto-created on first upload).
- MUST use a single uvicorn worker (in-memory starlette sessions → `--workers >1` breaks login).
- Behind traefik, uvicorn must trust the proxy scheme or admin assets come out `http://` and the panel is unstyled (mixed content): stack env sets `FORWARDED_ALLOW_IPS=*`.
- DB + uploaded icons persist in the volumes across container recreate; code changes need an image rebuild + re-push.
## Verification