Build and Push Containers / build-and-push (push) Successful in 1m50s
One env var (BOR_APP_NAME, default "Brain of Reese") now drives the app's
display name everywhere (TODO.md L12 — owner ask: "a way to customize the
name for 'Brain of'. Should be an env var."). The existing app_name setting
is the source of truth (phase locked decision — no new variable, no rename);
with the variable unset the app is byte-identical to before.
Endpoint (A10 public/stateless, no secrets):
GET /api/config → exactly {app_name, version} (app/api/config.py, the
health.py pattern; registered before the static mount). Integration tests:
anonymous 200, default values, a Settings override follows, key set is
exactly two keys — no other setting may leak in later.
Frontend brand layer (A11 — runtime fetch, static templates stay static):
assets/brand.js — a CLASSIC script, first on all six pages, so its top
level runs at parse time: window.BOR_BRAND = "Brain of Reese"
synchronously (the default renders immediately, no blank flash), then a
no-store fetch of /api/config applies the name — document.title (global
replace), every .brand-text (a name starting "Brain of " keeps the bold
split Brain of <strong>rest</strong>, any other name renders plain; the
operator-controlled name is HTML-escaped before innerHTML), a TreeWalker
over text nodes (script/style rejected — page source never rewritten),
and the aria-label/placeholder/meta-content attributes. Fetch failure
keeps the default + console.warn (the loadHealth house style).
app.js (status labels, typing label, elapsed-hint aria, tool labels) and
document.js (viewer titles) read window.BOR_BRAND at CALL time via
brand() — a label set after the fetch lands carries the configured name.
Containerfile: esbuild minify line for brand.js (classic, like markdown.js);
the phase-33 ?v= cache-busting picks the new asset ref up automatically.
E2E (A16 — one story, one file, isolated): test_configurable_brand.py boots
a SECOND app instance (same DB/mock-LLM/admin-auth env block, port APP_PORT+1,
BOR_APP_NAME="Brain of Testy") — the shared conftest server keeps the
default name so every other suite's title/label assertions stay untouched —
and asserts /api/config on both instances, the index title/brand/greeting/
#messages aria-label, the sources + login page titles, and one pre-token
chat turn (think out loud marker) whose #send-status reads "Brain of Testy
is thinking"; the no-op regression pins the shared server's default bytes.
Docs: .env.example App section + README configuration reference — what it
affects (titles, header brand, status labels, aria text), the default, the
bold-split rendering rule.
Gates: 695 unit+integration passed, app/ coverage 99% (>90%), story E2E
green in isolation (two consecutive runs), brand-string suites (smoke,
shared header, header consistency, chat persistence) green, ruff + pyright
clean.
92 lines
3.5 KiB
Python
92 lines
3.5 KiB
Python
"""Brain of Reese — application entrypoint.
|
|
|
|
Boots logging + conditional debugpy, then creates the FastAPI app:
|
|
API routes first (so they win over the catch-all), and the static frontend
|
|
mounted last. No CDN: everything the browser needs is served by this
|
|
process from local files (see PLAN §UI/UX — No External Dependencies).
|
|
|
|
Phase 16 (A10 revised): before anything is served, admin auth must be
|
|
configured (fail-loud), and the app wraps every route in Starlette's
|
|
SessionMiddleware — a signed ``bor_session`` cookie is the only session
|
|
state in the system.
|
|
"""
|
|
from __future__ import annotations
|
|
|
|
import logging
|
|
from pathlib import Path
|
|
|
|
from fastapi import FastAPI
|
|
from fastapi.staticfiles import StaticFiles
|
|
from starlette.middleware.sessions import SessionMiddleware
|
|
|
|
from app.api.auth import router as auth_router
|
|
from app.api.chat import router as chat_router
|
|
from app.api.config import router as config_router
|
|
from app.api.docs import router as docs_router
|
|
from app.api.git_sources import router as git_sources_router
|
|
from app.api.health import router as health_router
|
|
from app.api.steering import router as steering_router
|
|
from app.api.suggestions import router as suggestions_router
|
|
from app.api.sync import router as sync_router
|
|
from app.config import get_settings
|
|
from app.core.auth import ensure_admin_configured
|
|
from app.core.caching import configure_caching
|
|
from app.core.debugging import configure_debugging
|
|
from app.core.logging import configure_logging
|
|
|
|
configure_logging()
|
|
configure_debugging()
|
|
|
|
settings = get_settings()
|
|
logger = logging.getLogger("app")
|
|
|
|
|
|
def create_app() -> FastAPI:
|
|
# Fail loud BEFORE serving anything (phase 16): missing
|
|
# BOR_ADMIN_PASSWORD / BOR_SESSION_SECRET raises at boot, naming the
|
|
# variable(s) — the app never starts in a half-authenticated state.
|
|
ensure_admin_configured(settings)
|
|
|
|
app = FastAPI(title=settings.app_name, version=settings.app_version)
|
|
|
|
# Signed single-admin session cookie (Starlette middleware, itsdangerous
|
|
# signer — no server-side store, no new services). Homelab HTTP: same_site
|
|
# is "lax" and https_only stays off (documented in the README).
|
|
app.add_middleware(
|
|
SessionMiddleware,
|
|
secret_key=settings.session_secret,
|
|
session_cookie=settings.session_cookie,
|
|
max_age=settings.session_max_age,
|
|
same_site="lax",
|
|
https_only=False,
|
|
)
|
|
|
|
# API routes first so they take precedence over the catch-all static mount.
|
|
app.include_router(health_router, prefix="/api")
|
|
app.include_router(config_router, prefix="/api")
|
|
app.include_router(auth_router, prefix="/api")
|
|
app.include_router(suggestions_router, prefix="/api")
|
|
app.include_router(docs_router, prefix="/api")
|
|
app.include_router(git_sources_router, prefix="/api")
|
|
app.include_router(chat_router, prefix="/api")
|
|
app.include_router(steering_router, prefix="/api")
|
|
app.include_router(sync_router, prefix="/api")
|
|
|
|
# Cache busting (phase 33): the five HTML pages revalidate (no-cache)
|
|
# with ?v=<token> asset refs; /assets/* becomes immutable for a year.
|
|
# Added after the session middleware, so it wraps the whole app
|
|
# (including the static catch-all below); /api/* — the SSE chat
|
|
# stream in particular — passes through untouched.
|
|
configure_caching(app)
|
|
|
|
static_dir = Path(settings.static_dir).resolve()
|
|
if static_dir.is_dir():
|
|
app.mount("/", StaticFiles(directory=static_dir, html=True), name="static")
|
|
else:
|
|
logger.warning("static dir %s not found — serving API only", static_dir)
|
|
|
|
return app
|
|
|
|
|
|
app = create_app()
|