Expand description
Same-origin reverse proxy for the dev server (R513-F10, W207 Gap #1).
The dashboard E2E (Option B) serves a static SPA bundle and a separate
cheers auth service on different loopback ports. A browser fetch from the
SPA’s origin to another port is cross-origin — and cheers-axum ships no
CORS layer (W207 §“Decision 3”). The fix the spec picked is a same-origin
reverse proxy: the static server forwards a few path prefixes (/auth/*,
/dev/*, /api/*) to the backing service ports, so the browser only ever
talks to its own origin — no preflight, no Access-Control-*, no cheers
change.
The prefix→backend map is emitted by the camp at SPA-service spawn (beside
the served config.json) and handed to the server with --proxy-map. The
map carries the server-internal ephemeral ports; the SPA’s config.json
carries only the same-origin path prefixes, so the bundle stays
port-oblivious.
Forwarding is path-preserving (no prefix strip): /auth/magic-link/verify
reaches the backend as /auth/magic-link/verify. cheers mounts its routes at
their natural paths (/auth/* under the auth router, /dev/last-magic-link
and /health at root), so a prefix map of {"/auth": …, "/dev": …} reaches
all of them unchanged. Bodies are buffered (auth/api payloads are small
JSON); streaming is unnecessary here and keeps the hop simple.
Structs§
- Proxy
Map - An ordered set of
prefix → backend base URLproxy routes. Matching is longest-prefix-first, so a more specific/auth/admincan shadow a broader/authif both are present. - Proxy
State - Shared proxy state: the route map plus a single reusable HTTP client. Held in
the server state and cloned (cheaply — both are
Arc-backed) per request.