put every http sidecar on the proxy factory

createSidecarProxy arrived with the wallet but nothing else moved onto it, so five sidecars
still carried their own copy of the same two files: a sidecar-server.ts that remembered a
port announced as `<name>:server`, and a router.ts that forwarded the subpath. Byte for
byte identical once the app name was normalised away — which is exactly what the factory's
own header said it existed to end.

headscale, transmission, invoiceshelf, slskd and music are now wallet-shaped: create the
proxy, export the router and the URL getter. 386 lines deleted against 163 added, and the
five feature directories go from ~70 lines each to ~18.

Two deviations were real and moved INTO the factory rather than being dropped, because both
are HTTP concerns rather than app knowledge:

- Range and If-None-Match are now forwarded for every sidecar. music needed both (seeking,
  and ETag revalidation returning a cheap 304 instead of a cover image) and slskd needed
  Range. Forwarding them everywhere costs nothing and removes the reason to hand-roll.
- timeoutSeconds, used only by music at 1800. A from-scratch reindex holds the proxied
  connection open for minutes with no bytes flowing, which the 60s idle timeout would drop.
  It applies to the whole prefix — the proxy must not know which of a sidecar's routes are
  slow.

The five side-effect imports in hono.ts are gone with them: the port listener now registers
when createSidecarProxy runs inside the router this file already imports. Vault keeps its
hand-rolled pair and its side-effect import — it is off-limits by standing instruction, and
is the one sidecar this commit deliberately does not touch.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-31 11:46:29 +00:00
co-authored by Claude Opus 5
parent 7129cd82e6
commit aaf0161620
13 changed files with 100 additions and 362 deletions
+13 -46
View File
@@ -1,50 +1,17 @@
import { createRouter } from '../../create-router';
import { getTransmissionServerUrl } from './sidecar-server';
import { createSidecarProxy } from '../../sidecar/create-proxy';
// Thin reverse-proxy for /api/transmission/*. The platform's ONLY job here is AUTH + FORWARDING: this router
// mounts under the protected /api tree (userMiddleware upstream authenticates the owner), then forwards the
// subpath + query + body to the officer-transmission sidecar, which OWNS the Transmission contract and holds
// the daemon credentials.
// /api/transmission/* — auth, then forward to officer-transmission. No routes of its own and no transmission knowledge:
// this file must never grow app logic.
//
// A catch-all with no routes of its own. The sidecar exposes only Officer-owned routes under /_officer/,
// because Transmission's RPC is a single POST endpoint guarded by a rotating CSRF token — proxying it raw
// would push the handshake into the browser. The full contract is documented at the top of
// src/servers/sidecar/transmission/index.ts. It is opaque from here: this file must never grow Transmission
// logic.
// The sidecar owns the Transmission RPC contract, including its session-id handshake, and holds the
// credentials. The platform knows none of it.
export const transmissionRouter = createRouter();
const PREFIX = '/api/transmission';
transmissionRouter.all('/*', async (ctx) => {
const baseUrl = getTransmissionServerUrl();
if (!baseUrl) return ctx.text('transmission sidecar not available', 503);
const url = new URL(ctx.req.url);
const subpath = url.pathname.slice(PREFIX.length) || '/';
const target = `${baseUrl}${subpath}${url.search}`;
const method = ctx.req.method;
const headers: Record<string, string> = {};
const contentType = ctx.req.header('content-type');
if (contentType) headers['Content-Type'] = contentType;
// Forward the authenticated user id so the sidecar can serve its Officer-owned routes. The sidecar binds
// loopback only, so this header is trusted.
headers['X-Officer-User'] = String(ctx.get('user').id);
const hasBody = method !== 'GET' && method !== 'HEAD';
let upstream: Response;
try {
upstream = await fetch(target, {
method,
headers,
body: hasBody ? await ctx.req.arrayBuffer() : undefined,
});
} catch (err) {
console.error('[transmission] proxy fetch failed', { target, error: String(err) });
return ctx.text('transmission sidecar unreachable', 502);
}
return new Response(upstream.body, { status: upstream.status, headers: new Headers(upstream.headers) });
const proxy = createSidecarProxy({
name: 'transmission',
prefix: '/api/transmission',
});
export const transmissionRouter = proxy.router;
/** Base URL of the sidecar's HTTP server, or null if it hasn't reported in yet. */
export const getTransmissionServerUrl = proxy.getHttpUrl;
@@ -1,19 +0,0 @@
import * as sidecar from '@@/sidecar-registry';
// The officer-transmission sidecar starts its HTTP server on a random loopback port and reports it here on
// connect. We remember it so `/api/transmission/*` always forwards to the current sidecar. The platform
// holds NO knowledge of Transmission itself — not its URL, and not its credentials.
let serverPort: number | null = null;
sidecar.on('transmission:server', (msg) => {
const port = (msg as { port?: number }).port;
if (typeof port !== 'number') return;
serverPort = port;
console.log(`[transmission] sidecar registered on port ${port}`);
});
/** Base URL of the sidecar's HTTP server, or null if the sidecar hasn't reported in yet. */
export function getTransmissionServerUrl(): string | null {
return serverPort ? `http://127.0.0.1:${serverPort}` : null;
}