Files
spa-server/CHANGELOG.md
T
Rene Nochebuena b73b9ee022 feat: per-file Cache-Control, navigation-scoped SPA fallback, nosniff, non-root image; v1.7.0
- Cache-Control per file: no-cache for index.html + service workers, immutable 1y for
  content-hashed assets, 1h for the rest (Vite/CRA/Angular). Closes the stale-release
  trap at the HTTP layer that the v1.6.0 image fix closed at the container layer.
- SPA fallback scoped to navigation: a missing asset (path w/ extension) or a non-HTML
  Accept now returns 404 instead of index.html (no more HTML-as-JS 'Unexpected token <').
- X-Content-Type-Options: nosniff on every response.
- Image runs as a non-root 'spa' user.
- README: caching table, fallback contract, and the Angular dist/<project>/browser/ note.
2026-08-18 17:55:56 -06:00

4.4 KiB

Changelog — einherjar/spa-server

All notable changes to this module are documented here. Format follows Keep a Changelog. This module adheres to Semantic Versioning.


[1.7.0] — 2026-08-14

Minor — HTTP behaviour: caching, a strict SPA fallback, security headers, and a non-root image.

Added

  • Per-file Cache-Control. index.html and service-worker files (ngsw.json, ngsw-worker.js, sw.js, service-worker.js, safety-worker.js, workbox-*.js) are no-cache; content-hashed assets are public, max-age=31536000, immutable; everything else is public, max-age=3600. Correct for Vite, CRA and Angular output. Closes, at the HTTP layer, the same stale-release trap the v1.6.0 image fix closed at the container layer.
  • X-Content-Type-Options: nosniff on every response.
  • Non-root container. The image adds an unprivileged spa user and runs as it — a static binary serving read-only files on :8080 needs no privilege.

Changed

  • The index.html fallback is now scoped to navigation requests. A path that does not resolve to a file is served index.html only when it has no file extension and the client accepts HTML (text/html / */*). A missing asset (/main.js) or a typed non-HTML client now gets 404 instead of index.html, so a broken deploy fails loudly rather than shipping the SPA shell as JavaScript (Unexpected token '<').
  • Bumped einherjar dependencies to v1.7.0.

Docs

  • README documents the caching table and the navigation-scoped fallback, and notes that Angular must COPY dist/<project>/browser/ (not dist/) — the application builder nests index.html under browser/.

[1.6.0] — 2026-08-14

Minor — coordinated framework release (lockstep versioning). No changes to this module's own API.

Fixed

  • Dropped VOLUME ["/srv/www"] from the base image. The declaration created an anonymous volume at the SPA root that docker compose up reuses across container recreation, so a rebuild silently kept serving the previous bundle (up -d --build exited 0 while shipping the old build; on a PWA the stale ngsw.json then poisoned the service-worker cache). Consumers could not un-declare an inherited VOLUME and were stuck with --renew-anon-volumes forever. Removing it makes the headline COPY dist/ /srv/www/ case deterministic, and the runtime bind-mount case (-v /path:/srv/www) is unaffected. The v1.6.0 image was rebuilt and re-pushed with this fix. Consumers with an already-poisoned anonymous volume need a one-time -V (or docker volume rm) to shed it.

Changed

  • Bumped einherjar dependencies to v1.6.0. The framework-wide change in this release is web's new httputil.Bind / httputil.BindEmpty request-binding adapters.

[1.5.0] — 2026-08-09

Minor — coordinated framework version alignment. No code or API changes in this module.

Changed

  • Bumped contracts, core to v1.5.0.

[1.4.0] — 2026-08-09

Minor — coordinated framework release: dependency refresh + lockstep version alignment.

Changed

  • Refreshed dependencies to their latest minor/patch where available.
  • Bumped contracts, core to v1.4.0.

[1.3.0] — 2026-08-08

Minor — coordinated framework version alignment. No code or API changes in this module.

Changed

  • Bumped contracts, core to v1.3.0.

[1.2.0] — 2026-08-08

Minor — coordinated framework version alignment. No code or API changes in this module.

Changed

  • Bumped contracts, core to v1.2.0.

[1.1.3] — 2026-08-08

Patch — coordinated framework version alignment.

Changed

  • Bumped einherjar dependencies (`contracts`, `core`) to v1.1.3. No code or API changes.## [1.1.2] — 2026-08-08

Patch — coordinated framework version alignment.

Changed

  • Bumped einherjar dependencies (contracts, core) to v1.1.2. No code or API changes.

[1.1.1] — 2026-08-07

Patch — coordinated framework version alignment.

Changed

  • Bumped einherjar dependencies (contracts, core) to v1.1.1. No code or API changes.

[1.1.0] — 2026-08-07

Patch — coordinated framework version alignment.

Changed

  • Bumped einherjar dependencies (contracts, core) to v1.1.0.

[1.0.0] — 2026-05-28

Initial release. See the README for the full API and the v1.0.0 git tag for the source.