Offscale was the first plugin extracted and it was done before we knew what "extracted" meant. Music, done last, is the standard. This brings offscale to it. ── The rebrand ── The plugin was `offscale` to the platform and `headscale` to itself: sidecar name and handles, the port announcement, the API proxy name, the React components, every hook, the react-query keys, the panel ids and appTypes, and the Postgres table. Now all of those say offscale. The line drawn, and it is deliberate: OffScale is Officer's tooling layer, and Headscale is the server it manages. So every IDENTIFIER is offscale, while a message like `headscale unreachable`, the `headscale apikeys create` hint and the ACL assistant's prompt still say Headscale — because they are talking about the remote server, and renaming them would make the code lie about what it reached. 495 occurrences became 180, and the 180 are all of that second kind. ── The live bug this uncovered ── `headscaleSectionPath` built links to `/headscale/<section>`. The shell has no such route — plugin routes come from `plugin.route`, which is `/offscale` — and it redirects unknown paths to the home page. So every section link in the nav, the console and the server picker silently went home. The extraction moved the route and left the link builder behind. Also live: ServersView told the user to run `pm2 start ecosystem.config.cjs --only officer-headscale`, a process that has not existed since the sidecar was renamed. ── The correctness fix music already had ── api/router.ts hardcoded `prefix: '/api/offscale'`. The proxy strips `prefix.length` characters, so a literal is correct only for a first-party publisher; published by anyone else this mounts at `/api/p/<publisher>/offscale` and forwards the wrong subpath. Derived from `mountPrefix()` now, as music does. ── The rest ── - assets/icon.png — the OffScale artwork, 256px to match music's. The tile stops being a glyph badge. - First tests: 21 of them, over the version floor and the protobuf normalisers. Those are the two places a Headscale release actually breaks this, and they had no coverage at all. `meetsFloor` has a real trap pinned now — comparing minor first would refuse 1.0 as older than 0.29. - OFFSCALE_API.md — the contract was a 45-line comment inside sidecar/index.ts, which is not linkable and not published. Now a document, as MUSIC_API.md is. - web/panels.ts re-exported three components. A plugin cannot export components; that was residue of the platform importing them before extraction. - Comments pointed at src/servers/api/headscale/ and src/servers/sidecar/headscale/, neither of which has existed since the extraction. The crypto purpose moved headscale → offscale too, and the secret-store row was renamed rather than left to create a fresh key — the material is preserved, so this is reversible. Free to do only because offscale_servers had 0 rows; with one stored API key it would have been a migration.
80 lines
3.7 KiB
TypeScript
80 lines
3.7 KiB
TypeScript
import { useMutation, useQuery, useQueryClient } from '@tanstack/react-query';
|
|
import { useClient } from 'hooks/useClient';
|
|
import type { OffscalePolicy } from './shared';
|
|
import { POLICY_READ_ONLY, POLICY_REJECTED } from './shared';
|
|
|
|
// The active server's ACL policy. One document, one query, one mutation — the interesting part is entirely
|
|
// in how a failed save is classified, because the two failures need opposite reactions from the owner:
|
|
// "your document is wrong, here is where" versus "this server does not accept written policies at all".
|
|
|
|
const POLICY_KEY = ['offscale', 'policy'] as const;
|
|
const PATH = '/offscale/_officer/policy';
|
|
|
|
/** What a rejected save means. `rejected` carries Headscale's own message; `readOnly` ends the editing. */
|
|
export type PolicySaveFailure = { kind: 'rejected' | 'readOnly' | 'unknown'; message: string };
|
|
|
|
/** useClient throws `{status, message}` with the raw body text — dig the sidecar's `{error, code}` out. */
|
|
export function policySaveFailure(err: unknown): PolicySaveFailure {
|
|
const raw = (err as { message?: unknown } | null)?.message;
|
|
if (typeof raw !== 'string' || !raw) return { kind: 'unknown', message: 'The policy could not be saved' };
|
|
|
|
try {
|
|
const parsed = JSON.parse(raw) as { error?: unknown; code?: unknown };
|
|
const message = typeof parsed.error === 'string' && parsed.error ? parsed.error : 'The policy could not be saved';
|
|
if (parsed.code === POLICY_READ_ONLY) return { kind: 'readOnly', message };
|
|
if (parsed.code === POLICY_REJECTED) return { kind: 'rejected', message };
|
|
return { kind: 'unknown', message };
|
|
} catch {
|
|
return { kind: 'unknown', message: raw.slice(0, 300) };
|
|
}
|
|
}
|
|
|
|
/** What the assistant proposes. Never saved by the hook — PolicyView puts it in the draft. */
|
|
export type PolicyProposal = { explanation: string; policy: string };
|
|
|
|
/** The assistant's failures are all one sentence to the owner; only the sidecar's `error` field is useful. */
|
|
export function assistFailure(err: unknown): string {
|
|
const raw = (err as { message?: unknown } | null)?.message;
|
|
if (typeof raw !== 'string' || !raw) return 'The assistant could not be reached';
|
|
try {
|
|
const parsed = JSON.parse(raw) as { error?: unknown };
|
|
return typeof parsed.error === 'string' && parsed.error ? parsed.error : 'The assistant could not be reached';
|
|
} catch {
|
|
return raw.slice(0, 300);
|
|
}
|
|
}
|
|
|
|
/**
|
|
* Ask for a revised policy in English. Separate from `useOffscalePolicy` because it is a different kind of
|
|
* thing: no cache, no query key, nothing to invalidate — one request, one answer, discarded on reload.
|
|
*/
|
|
export function useOffscalePolicyAssist() {
|
|
const { post } = useClient();
|
|
return useMutation({
|
|
mutationFn: (input: { prompt: string; policy: string }) => post<PolicyProposal>(`${PATH}/assist`, input),
|
|
});
|
|
}
|
|
|
|
export function useOffscalePolicy() {
|
|
const { get, put } = useClient();
|
|
const qc = useQueryClient();
|
|
|
|
const query = useQuery({
|
|
queryKey: POLICY_KEY,
|
|
queryFn: () => get<OffscalePolicy>(PATH),
|
|
// No polling and a long staleTime: this is a document someone is editing. A background refetch that
|
|
// replaced the textarea under a half-written rule would be the worst thing this screen could do.
|
|
staleTime: 5 * 60_000,
|
|
refetchOnWindowFocus: false,
|
|
});
|
|
|
|
const save = useMutation({
|
|
mutationFn: (policy: string) => put<OffscalePolicy>(PATH, { policy }),
|
|
// Seed the cache from the response rather than invalidating: a refetch here would race the editor's
|
|
// own state and could show the pre-save document for a frame.
|
|
onSuccess: (data) => qc.setQueryData(POLICY_KEY, data),
|
|
});
|
|
|
|
return { policy: query.data ?? null, isLoading: query.isLoading, error: query.error, refetch: query.refetch, save };
|
|
}
|