Skip to main content

Module web

Module web 

Source
Expand description

The web UI, embedded at build time (see build.rs) and served by isb serve on its TCP listener.

  • Files come from a table compiled into the binary, so nothing is read from disk and a request path can never reach the filesystem.
  • Any other GET that is not an API path gets index.html, so the UI’s client-side routes (/login, /account, …) load on a refresh.
  • It never answers the API: /api/..., /mcp, /healthz, /orgs/<org>/mcp and /orgs/<org>/api/... are left to the server (a 404 when nothing else claims them), so a typo in an API path is an API error, not a page.
  • Vite names its bundles by content hash, so /assets/* is cached for a year; index.html is no-store, so a new binary’s UI loads at once.
  • Every page carries a strict Content-Security-Policy (scripts only from this origin, no inline scripts, fetches only to this origin), and refuses framing.

Constants§

BUILT
Whether this binary carries the real UI (else a page saying it was not built).
CSP
Scripts and styles from this origin only, no inline script, fetches and event streams to this origin only, no plugins, no framing. Inline styles are allowed: the UI’s dialog and toast components inject <style> elements at runtime, and a style cannot run code.

Functions§

is_api_path
Paths the UI must never answer: they belong to the API, even when nothing serves them.
routes
The routes for the embedded UI.
serve
Answer req from assets, or None to leave it to the server.