betterwithage commited on
Commit
78d0e50
·
verified ·
1 Parent(s): aa3154d

chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)

Browse files

Automated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): (none)
Deleted (gone from the repo + Dockerfile COPY set): tests/test_zero_cdn_guard.py

Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.

Files changed (1) hide show
  1. tests/test_zero_cdn_guard.py +0 -108
tests/test_zero_cdn_guard.py DELETED
@@ -1,108 +0,0 @@
1
- """
2
- test_zero_cdn_guard.py — DEV-WIRE-A (2026-06-09)
3
-
4
- Doctrine guard: the operator console + every vendored JS asset MUST be 0 runtime CDN.
5
- All third-party libraries are vendored in-image under static-vendor/ and referenced with
6
- relative `<script src="/vendor/...">` tags only. This test FAILS the build if any banned
7
- CDN host string appears in a served HTML or JS file, or if any <script>/<link> references
8
- an absolute http(s) origin.
9
-
10
- ADDITIVE + SAFE: this only ADDS a gate; it never weakens an existing one.
11
- """
12
- import re
13
- import pathlib
14
-
15
- ROOT = pathlib.Path(__file__).resolve().parent.parent
16
-
17
- # Banned runtime-CDN host fragments (case-insensitive). A real vendored 0-CDN build
18
- # must not contain any of these inside a served HTML/JS file.
19
- BANNED = [
20
- "cdn.jsdelivr.net", "unpkg.com", "cdnjs.cloudflare.com", "cdn.skypack.dev",
21
- "esm.sh", "ajax.googleapis.com", "fonts.googleapis.com", "fonts.gstatic.com",
22
- "code.jquery.com", "stackpath.bootstrapcdn.com", "maxcdn.bootstrapcdn.com",
23
- "d3js.org/d3", "threejs.org/build", "cdn.plot.ly",
24
- ]
25
-
26
- # Files that are SERVED to the browser and therefore must be 0-CDN.
27
- # 2026-06-14 (DEV-WIRE-A, additive): extended to the routed surfaces QA Team A's
28
- # full-tab walk had to catch by hand — /nemo, /estate-hologram (web/*.html baked &
29
- # served via _ptg_serve FileResponse) and /chaski (pages/chaski.html FileResponse).
30
- # These are individually named (NOT web/*.html) so unrouted build artifacts such as
31
- # web/console.html / web/operator.html are deliberately not pulled into the gate.
32
- SERVED_GLOBS = [
33
- "pages/console.html",
34
- "pages/chaski.html",
35
- "console/*.html",
36
- "web/nemo.html",
37
- "web/estate-hologram.html",
38
- "static-vendor/*.js",
39
- "static-vendor/*.css",
40
- ]
41
-
42
- # Absolute external ASSET loads are forbidden in served HTML: <script src="http(s)://...">
43
- # and stylesheet <link ... href="http(s)://...">. Plain <a href> navigation links to our
44
- # own HF Space / canonical origin are NOT asset loads and are allowed.
45
- EXT_SCRIPT = re.compile(r'<script\b[^>]*\bsrc\s*=\s*["\']https?://', re.IGNORECASE)
46
- EXT_STYLESHEET = re.compile(r'<link\b[^>]*\bhref\s*=\s*["\']https?://[^>]*>', re.IGNORECASE)
47
-
48
-
49
- def _served_files():
50
- out = []
51
- for g in SERVED_GLOBS:
52
- out.extend(sorted(ROOT.glob(g)))
53
- return out
54
-
55
-
56
- def test_no_banned_cdn_host_in_served_files():
57
- offenders = []
58
- for f in _served_files():
59
- try:
60
- txt = f.read_text(errors="ignore")
61
- except Exception:
62
- continue
63
- low = txt.lower()
64
- for host in BANNED:
65
- if host in low:
66
- offenders.append(f"{f.relative_to(ROOT)} :: {host}")
67
- assert not offenders, "Runtime-CDN host string(s) found in served files:\n" + "\n".join(offenders)
68
-
69
-
70
- def test_no_absolute_external_asset_load_in_html():
71
- """No <script src=http(s)> or external stylesheet <link href=http(s)>. Navigation
72
- <a href> links to our own origin are allowed (not asset loads)."""
73
- offenders = []
74
- for f in _served_files():
75
- if f.suffix.lower() != ".html":
76
- continue
77
- try:
78
- txt = f.read_text(errors="ignore")
79
- except Exception:
80
- continue
81
- for rx, kind in ((EXT_SCRIPT, "script"), (EXT_STYLESHEET, "stylesheet")):
82
- for m in rx.finditer(txt):
83
- # a <link> is only an asset load if it is rel=stylesheet/preload/modulepreload
84
- tag = m.group(0).lower()
85
- if kind == "stylesheet" and not re.search(r'rel\s*=\s*["\']?(stylesheet|preload|modulepreload)', tag):
86
- continue
87
- snippet = txt[max(0, m.start() - 10):m.start() + 70].replace("\n", " ")
88
- offenders.append(f"{f.relative_to(ROOT)} :: [{kind}] …{snippet}…")
89
- assert not offenders, "Absolute external asset load in served HTML (must be relative, 0-CDN):\n" + "\n".join(offenders)
90
-
91
-
92
- def test_anvaka_vendor_files_present_and_real():
93
- """The vendored anvaka graph stack must exist in-image and be real JS (not LFS/404)."""
94
- required = [
95
- "static-vendor/ngraph.graph.min.js",
96
- "static-vendor/ngraph.forcelayout.min.js",
97
- "static-vendor/ngraph.path.min.js",
98
- "static-vendor/panzoom.min.js",
99
- "static-vendor/vivagraph.min.js",
100
- "static-vendor/ngraph.events.umd.js",
101
- ]
102
- for rel in required:
103
- f = ROOT / rel
104
- assert f.is_file(), f"missing vendored lib: {rel}"
105
- head = f.read_bytes()[:80].lstrip()
106
- # LFS pointer files start with 'version https://git-lfs'; real JS never does.
107
- assert not head.startswith(b"version https://git-lfs"), f"{rel} is an LFS pointer, not real JS"
108
- assert f.stat().st_size > 1500, f"{rel} suspiciously small ({f.stat().st_size} bytes)"