Go's MIME table has no .webmanifest entry, so http.FileServer sniffed the PWA web app manifest as text/plain. mime.AddExtensionType at package load makes TypeByExtension authoritative. A correctness nit (the manifest spec parses by content and nosniff does not reject manifests), but a PWA server should label its manifest correctly.
4.8 KiB
Changelog — einherjar/spa-server
All notable changes to this module are documented here. Format follows Keep a Changelog. This module adheres to Semantic Versioning.
[1.7.1] — 2026-08-14
Patch — correct MIME types for PWA assets.
Fixed
- Register
application/manifest+jsonfor.webmanifest(plusimage/webpandimage/avif) at startup. Without it, Go's content sniffing served the PWA web app manifest astext/plain. Nothing broke in practice — the manifest spec parses by content, andnosniffdoes not reject manifests — but a PWA-focused server should label its manifest correctly.
[1.7.0] — 2026-08-14
Minor — HTTP behaviour: caching, a strict SPA fallback, security headers, and a non-root image.
Added
- Per-file
Cache-Control.index.htmland service-worker files (ngsw.json,ngsw-worker.js,sw.js,service-worker.js,safety-worker.js,workbox-*.js) areno-cache; content-hashed assets arepublic, max-age=31536000, immutable; everything else ispublic, max-age=3600. Correct for Vite, CRA and Angular output. Closes, at the HTTP layer, the same stale-release trap the v1.6.0 image fix closed at the container layer. X-Content-Type-Options: nosniffon every response.- Non-root container. The image adds an unprivileged
spauser and runs as it — a static binary serving read-only files on:8080needs no privilege.
Changed
- The
index.htmlfallback is now scoped to navigation requests. A path that does not resolve to a file is servedindex.htmlonly when it has no file extension and the client accepts HTML (text/html/*/*). A missing asset (/main.js) or a typed non-HTML client now gets 404 instead ofindex.html, so a broken deploy fails loudly rather than shipping the SPA shell as JavaScript (Unexpected token '<'). - Bumped einherjar dependencies to v1.7.0.
Docs
- README documents the caching table and the navigation-scoped fallback, and notes that Angular
must
COPY dist/<project>/browser/(notdist/) — the application builder nestsindex.htmlunderbrowser/.
[1.6.0] — 2026-08-14
Minor — coordinated framework release (lockstep versioning). No changes to this module's own API.
Fixed
- Dropped
VOLUME ["/srv/www"]from the base image. The declaration created an anonymous volume at the SPA root thatdocker compose upreuses across container recreation, so a rebuild silently kept serving the previous bundle (up -d --buildexited 0 while shipping the old build; on a PWA the stalengsw.jsonthen poisoned the service-worker cache). Consumers could not un-declare an inheritedVOLUMEand were stuck with--renew-anon-volumesforever. Removing it makes the headlineCOPY dist/ /srv/www/case deterministic, and the runtime bind-mount case (-v /path:/srv/www) is unaffected. Thev1.6.0image was rebuilt and re-pushed with this fix. Consumers with an already-poisoned anonymous volume need a one-time-V(ordocker volume rm) to shed it.
Changed
- Bumped einherjar dependencies to v1.6.0. The framework-wide change in this release is
web's newhttputil.Bind/httputil.BindEmptyrequest-binding adapters.
[1.5.0] — 2026-08-09
Minor — coordinated framework version alignment. No code or API changes in this module.
Changed
- Bumped
contracts,coreto v1.5.0.
[1.4.0] — 2026-08-09
Minor — coordinated framework release: dependency refresh + lockstep version alignment.
Changed
- Refreshed dependencies to their latest minor/patch where available.
- Bumped
contracts,coreto v1.4.0.
[1.3.0] — 2026-08-08
Minor — coordinated framework version alignment. No code or API changes in this module.
Changed
- Bumped
contracts,coreto v1.3.0.
[1.2.0] — 2026-08-08
Minor — coordinated framework version alignment. No code or API changes in this module.
Changed
- Bumped
contracts,coreto v1.2.0.
[1.1.3] — 2026-08-08
Patch — coordinated framework version alignment.
Changed
- Bumped einherjar dependencies (`contracts`, `core`) to v1.1.3. No code or API changes.## [1.1.2] — 2026-08-08
Patch — coordinated framework version alignment.
Changed
- Bumped einherjar dependencies (
contracts,core) to v1.1.2. No code or API changes.
[1.1.1] — 2026-08-07
Patch — coordinated framework version alignment.
Changed
- Bumped einherjar dependencies (
contracts,core) to v1.1.1. No code or API changes.
[1.1.0] — 2026-08-07
Patch — coordinated framework version alignment.
Changed
- Bumped einherjar dependencies (
contracts,core) to v1.1.0.
[1.0.0] — 2026-05-28
Initial release. See the README for the full API and the v1.0.0 git tag for the source.