Author SHA1 Message Date
sneak 9b7ba5150b Name each embedded static file so a missing Alpine.js fails the build (closes #166)
check / check (push) Waiting to run
static/static.go embedded the css and js directories, which match
whatever is present, so a build that skipped make assets produced a
binary whose pages had no Alpine.js. It now names the four files the
pages load, so a missing one is a compile error naming it.
css/input.css, the Tailwind source that no page loads, is no longer
embedded or served.

Both lint stages now extract Alpine.js before linting, since the
static package no longer compiles without it.

Model: opus-5-5
2026-10-02 17:49:57 +00:00
4 changed files with 13 additions and 3 deletions
+1
View File
@@ -25,6 +25,7 @@ COPY . .
# would need a docker daemon inside the build. Keep these steps in step with
# Dockerfile.lint, including --network=none (see its header for why).
RUN make fmt-check
RUN script/assets
RUN --network=none golangci-lint config verify --config .golangci.yml
RUN --network=none golangci-lint run --config .golangci.yml --build-tags browser ./...
+4
View File
@@ -31,6 +31,10 @@ FROM deps AS lint
COPY . .
# static/static.go embeds the Alpine.js file this extracts from 3p/; without
# it the static package does not compile and cannot be linted.
RUN script/assets
# `run` silently ignores config keys it does not recognize, so a typo would
# disable a setting without a word. `config verify` is what catches that.
RUN --network=none golangci-lint config verify --config .golangci.yml
+3 -1
View File
@@ -1348,7 +1348,9 @@ apply. The directory is `3p/` rather than `vendor/` because Go treats a root
where `go:embed` picks it up. `script/test`, `make build` and `make dev` run
it first, and the Dockerfile builds through `make test` and `make build`, so
nothing downloads Alpine.js. The extracted file is not committed, and
`.dockerignore` keeps any host copy out of the build context.
`.dockerignore` keeps any host copy out of the build context. `static/static.go`
names every file it embeds, so a build that skips the extraction, such as a
bare `go build`, fails with an error naming `js/alpine.min.js`.
To move to a new version: download
`https://registry.npmjs.org/@alpinejs/csp/-/csp-<version>.tgz`, check it against
+5 -2
View File
@@ -5,7 +5,10 @@ import (
"embed"
)
// Static holds the embedded CSS and JavaScript files for the web UI.
// Static holds the CSS and JavaScript files the web UI's pages load. They
// are named one by one so that a missing js/alpine.min.js, which make
// assets extracts and git does not track, fails the build instead of
// leaving the pages without Alpine.js.
//
//go:embed css js
//go:embed css/tailwind.css css/style.css js/app.js js/alpine.min.js
var Static embed.FS