headscale leaves the platform. 45 files move to plugins/offscale/ and the
platform stops knowing it exists.
api/router.ts the thin auth-gated proxy, now at /api/offscale
sidecar/ 18 files, the whole headscale contract and its admin keys
db/ schema + queries, offscale_servers
web/ 26 files as panels and a layout — no screen, per the rule
removed from the platform: the hono mount, the `headscale` capability, the
App.tsx route pair, the screen and its barrel, the AppRegistry spread, the
officerdev re-exports, the dock tile, the page-title rule, and both database
barrels. tsgo is clean and nothing references it.
the imports tell the story of what the plugin↔host API actually is. the sidecar
takes @@/sidecar/protocol, @@/sidecar/connect, @@/data-path and
@@/officer-url.mjs; the queries take officerdb/db and officerdb/crypto; the
schema takes officerdb/auth/schema for the one reference a plugin may make; the
web half takes useClient, copyToClipboard, WorkspaceView and TerminalView from
the officerdev barrel. all of it resolves because a plugin lives inside the repo
— no publishing, no version negotiation.
AND IT FOUND A REAL BUG IN THE INSTALLER. createSidecarProxy learns its port
from a one-shot `<name>:server` event and subscribes when the plugin's router is
first imported — at mount. install started the sidecar BEFORE mounting, so the
announcement fired into a void: process online, routes mounted, every request
answering `503 sidecar not available` until something forced a reconnect. it
would have hit every plugin with an http sidecar. `example` never caught it
because it has no listener to announce.
install and enable now mount before starting; disable still unmounts before
stopping. neither direction leaves a mounted route in front of a sidecar that
cannot be reached.
verified live: /api/offscale/_officer/servers answers {"servers":[]}, /offscale
and /offscale/nodes serve, the old /api/headscale is 404, the offscale
capability is registered from the manifest, and officer-offscale is online.
757 pass, same 10 pre-existing failures.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
21 lines
1.0 KiB
TypeScript
21 lines
1.0 KiB
TypeScript
import { getActiveHeadscaleCredentials } from '../db/queries';
|
|
import { createClient, type HeadscaleClient } from './client';
|
|
|
|
// Every domain route acts on the ACTIVE server — the one the owner selected in the servers section. That
|
|
// choice lives in Postgres (one row, enforced by a partial unique index), not in a request parameter, so
|
|
// no client can act on a server the owner isn't currently looking at by guessing an id.
|
|
|
|
/**
|
|
* The client for the active server, or a ready-to-send 409 when there isn't one.
|
|
*
|
|
* 409 rather than 404: the route exists and the request was well-formed, the account just has no server
|
|
* selected yet. The UI maps it to "pick a server", which is a different message from "that node is gone".
|
|
*/
|
|
export async function activeClient(userId: number): Promise<HeadscaleClient | Response> {
|
|
const creds = await getActiveHeadscaleCredentials(userId);
|
|
if (!creds) {
|
|
return Response.json({ error: 'no active Headscale server', code: 'no_active_server' }, { status: 409 });
|
|
}
|
|
return createClient(creds);
|
|
}
|