# Changelog — einherjar/spa-server All notable changes to this module are documented here. Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/). This module adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). --- ## [1.7.1] — 2026-08-14 Patch — correct MIME types for PWA assets. ### Fixed - Register `application/manifest+json` for `.webmanifest` (plus `image/webp` and `image/avif`) at startup. Without it, Go's content sniffing served the PWA web app manifest as `text/plain`. Nothing broke in practice — the manifest spec parses by content, and `nosniff` does not reject manifests — but a PWA-focused server should label its manifest correctly. ## [1.7.0] — 2026-08-14 Minor — HTTP behaviour: caching, a strict SPA fallback, security headers, and a non-root image. ### Added - **Per-file `Cache-Control`.** `index.html` and service-worker files (`ngsw.json`, `ngsw-worker.js`, `sw.js`, `service-worker.js`, `safety-worker.js`, `workbox-*.js`) are `no-cache`; content-hashed assets are `public, max-age=31536000, immutable`; everything else is `public, max-age=3600`. Correct for Vite, CRA and Angular output. Closes, at the HTTP layer, the same stale-release trap the v1.6.0 image fix closed at the container layer. - **`X-Content-Type-Options: nosniff`** on every response. - **Non-root container.** The image adds an unprivileged `spa` user and runs as it — a static binary serving read-only files on `:8080` needs no privilege. ### Changed - **The `index.html` fallback is now scoped to navigation requests.** A path that does not resolve to a file is served `index.html` only when it has no file extension and the client accepts HTML (`text/html` / `*/*`). A missing asset (`/main.js`) or a typed non-HTML client now gets **404** instead of `index.html`, so a broken deploy fails loudly rather than shipping the SPA shell as JavaScript (`Unexpected token '<'`). - Bumped einherjar dependencies to v1.7.0. ### Docs - README documents the caching table and the navigation-scoped fallback, and notes that **Angular** must `COPY dist//browser/` (not `dist/`) — the application builder nests `index.html` under `browser/`. ## [1.6.0] — 2026-08-14 Minor — coordinated framework release (lockstep versioning). No changes to this module's own API. ### Fixed - **Dropped `VOLUME ["/srv/www"]` from the base image.** The declaration created an anonymous volume at the SPA root that `docker compose up` reuses across container recreation, so a rebuild silently kept serving the previous bundle (`up -d --build` exited 0 while shipping the old build; on a PWA the stale `ngsw.json` then poisoned the service-worker cache). Consumers could not un-declare an inherited `VOLUME` and were stuck with `--renew-anon-volumes` forever. Removing it makes the headline `COPY dist/ /srv/www/` case deterministic, and the runtime bind-mount case (`-v /path:/srv/www`) is unaffected. *The `v1.6.0` image was rebuilt and re-pushed with this fix.* Consumers with an already-poisoned anonymous volume need a one-time `-V` (or `docker volume rm`) to shed it. ### Changed - Bumped einherjar dependencies to v1.6.0. The framework-wide change in this release is `web`'s new `httputil.Bind` / `httputil.BindEmpty` request-binding adapters. ## [1.5.0] — 2026-08-09 Minor — coordinated framework version alignment. No code or API changes in this module. ### Changed - Bumped `contracts`, `core` to v1.5.0. ## [1.4.0] — 2026-08-09 Minor — coordinated framework release: dependency refresh + lockstep version alignment. ### Changed - Refreshed dependencies to their latest minor/patch where available. - Bumped `contracts`, `core` to v1.4.0. ## [1.3.0] — 2026-08-08 Minor — coordinated framework version alignment. No code or API changes in this module. ### Changed - Bumped `contracts`, `core` to v1.3.0. ## [1.2.0] — 2026-08-08 Minor — coordinated framework version alignment. No code or API changes in this module. ### Changed - Bumped `contracts`, `core` to v1.2.0. ## [1.1.3] — 2026-08-08 Patch — coordinated framework version alignment. ### Changed - Bumped einherjar dependencies (\`contracts\`, \`core\`) to v1.1.3. No code or API changes.## [1.1.2] — 2026-08-08 Patch — coordinated framework version alignment. ### Changed - Bumped einherjar dependencies (`contracts`, `core`) to v1.1.2. No code or API changes. ## [1.1.1] — 2026-08-07 Patch — coordinated framework version alignment. ### Changed - Bumped einherjar dependencies (`contracts`, `core`) to v1.1.1. No code or API changes. ## [1.1.0] — 2026-08-07 Patch — coordinated framework version alignment. ### Changed - Bumped einherjar dependencies (`contracts`, `core`) to v1.1.0. ## [1.0.0] — 2026-05-28 Initial release. See the README for the full API and the `v1.0.0` git tag for the source.