Expand description
The web UI, embedded at build time (see build.rs) and served by
isb serve on its TCP listener.
- Files come from a table compiled into the binary, so nothing is read from disk and a request path can never reach the filesystem.
- Any other GET that is not an API path gets
index.html, so the UI’s client-side routes (/login,/account, …) load on a refresh. - It never answers the API:
/api/...,/mcp,/healthz,/orgs/<org>/mcpand/orgs/<org>/api/...are left to the server (a 404 when nothing else claims them), so a typo in an API path is an API error, not a page. - Vite names its bundles by content hash, so
/assets/*is cached for a year;index.htmlisno-store, so a new binary’s UI loads at once. - Every page carries a strict Content-Security-Policy (scripts only from this origin, no inline scripts, fetches only to this origin), and refuses framing.
Constants§
- BUILT
- Whether this binary carries the real UI (else a page saying it was not built).
- CSP
- Scripts and styles from this origin only, no inline script, fetches and
event streams to this origin only, no plugins, no framing. Inline
styles are allowed: the UI’s dialog and toast components inject
<style>elements at runtime, and a style cannot run code.
Functions§
- is_
api_ path - Paths the UI must never answer: they belong to the API, even when nothing serves them.
- routes
- The routes for the embedded UI.
- serve
- Answer
reqfromassets, orNoneto leave it to the server.