Files
spa-server/CHANGELOG.md
T
Rene Nochebuena d6665047d8 fix(mime): register application/manifest+json for .webmanifest (+ webp/avif); v1.7.1
Go's MIME table has no .webmanifest entry, so http.FileServer sniffed the PWA web
app manifest as text/plain. mime.AddExtensionType at package load makes TypeByExtension
authoritative. A correctness nit (the manifest spec parses by content and nosniff does
not reject manifests), but a PWA server should label its manifest correctly.
2026-08-18 18:43:55 -06:00

137 lines
4.8 KiB
Markdown

# Changelog — einherjar/spa-server
All notable changes to this module are documented here.
Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
This module adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
---
## [1.7.1] — 2026-08-14
Patch — correct MIME types for PWA assets.
### Fixed
- Register `application/manifest+json` for `.webmanifest` (plus `image/webp` and `image/avif`) at
startup. Without it, Go's content sniffing served the PWA web app manifest as `text/plain`.
Nothing broke in practice — the manifest spec parses by content, and `nosniff` does not reject
manifests — but a PWA-focused server should label its manifest correctly.
## [1.7.0] — 2026-08-14
Minor — HTTP behaviour: caching, a strict SPA fallback, security headers, and a non-root image.
### Added
- **Per-file `Cache-Control`.** `index.html` and service-worker files (`ngsw.json`, `ngsw-worker.js`,
`sw.js`, `service-worker.js`, `safety-worker.js`, `workbox-*.js`) are `no-cache`; content-hashed
assets are `public, max-age=31536000, immutable`; everything else is `public, max-age=3600`.
Correct for Vite, CRA and Angular output. Closes, at the HTTP layer, the same stale-release trap
the v1.6.0 image fix closed at the container layer.
- **`X-Content-Type-Options: nosniff`** on every response.
- **Non-root container.** The image adds an unprivileged `spa` user and runs as it — a static binary
serving read-only files on `:8080` needs no privilege.
### Changed
- **The `index.html` fallback is now scoped to navigation requests.** A path that does not resolve to
a file is served `index.html` only when it has no file extension and the client accepts HTML
(`text/html` / `*/*`). A missing asset (`/main.js`) or a typed non-HTML client now gets **404**
instead of `index.html`, so a broken deploy fails loudly rather than shipping the SPA shell as
JavaScript (`Unexpected token '<'`).
- Bumped einherjar dependencies to v1.7.0.
### Docs
- README documents the caching table and the navigation-scoped fallback, and notes that **Angular**
must `COPY dist/<project>/browser/` (not `dist/`) — the application builder nests `index.html`
under `browser/`.
## [1.6.0] — 2026-08-14
Minor — coordinated framework release (lockstep versioning). No changes to this module's own API.
### Fixed
- **Dropped `VOLUME ["/srv/www"]` from the base image.** The declaration created an anonymous
volume at the SPA root that `docker compose up` reuses across container recreation, so a
rebuild silently kept serving the previous bundle (`up -d --build` exited 0 while shipping the
old build; on a PWA the stale `ngsw.json` then poisoned the service-worker cache). Consumers
could not un-declare an inherited `VOLUME` and were stuck with `--renew-anon-volumes` forever.
Removing it makes the headline `COPY dist/ /srv/www/` case deterministic, and the runtime
bind-mount case (`-v /path:/srv/www`) is unaffected. *The `v1.6.0` image was rebuilt and
re-pushed with this fix.* Consumers with an already-poisoned anonymous volume need a one-time
`-V` (or `docker volume rm`) to shed it.
### Changed
- Bumped einherjar dependencies to v1.6.0. The framework-wide change in this release is
`web`'s new `httputil.Bind` / `httputil.BindEmpty` request-binding adapters.
## [1.5.0] — 2026-08-09
Minor — coordinated framework version alignment. No code or API changes in this module.
### Changed
- Bumped `contracts`, `core` to v1.5.0.
## [1.4.0] — 2026-08-09
Minor — coordinated framework release: dependency refresh + lockstep version alignment.
### Changed
- Refreshed dependencies to their latest minor/patch where available.
- Bumped `contracts`, `core` to v1.4.0.
## [1.3.0] — 2026-08-08
Minor — coordinated framework version alignment. No code or API changes in this module.
### Changed
- Bumped `contracts`, `core` to v1.3.0.
## [1.2.0] — 2026-08-08
Minor — coordinated framework version alignment. No code or API changes in this module.
### Changed
- Bumped `contracts`, `core` to v1.2.0.
## [1.1.3] — 2026-08-08
Patch — coordinated framework version alignment.
### Changed
- Bumped einherjar dependencies (\`contracts\`, \`core\`) to v1.1.3. No code or API changes.## [1.1.2] — 2026-08-08
Patch — coordinated framework version alignment.
### Changed
- Bumped einherjar dependencies (`contracts`, `core`) to v1.1.2. No code or API changes.
## [1.1.1] — 2026-08-07
Patch — coordinated framework version alignment.
### Changed
- Bumped einherjar dependencies (`contracts`, `core`) to v1.1.1. No code or API changes.
## [1.1.0] — 2026-08-07
Patch — coordinated framework version alignment.
### Changed
- Bumped einherjar dependencies (`contracts`, `core`) to v1.1.0.
## [1.0.0] — 2026-05-28
Initial release. See the README for the full API and the `v1.0.0` git tag for the source.