fix editor

This commit is contained in:
Your Name 2026-08-22 11:29:04 -04:00
parent 3a7031e462
commit f6bde50ce3
6 changed files with 305 additions and 50 deletions

View file

@ -32,9 +32,9 @@ if (!structure) {
const structureId = String(structure.id);
bliss("update-settings", structureId, "--route-prefix", "/_bliss");
let state = json("structure", structureId);
if (!state.dbs.some((db) => String(db.id) === "0" && db.alias === "bliss")) {
bliss("attach-db", structureId, "0", "bliss");
}
// No db is attached: the editor reads structure sources through the /plumbing
// API (owner-checked), not by mounting the prime db — which is no longer
// attachable to other structures anyway.
const templates = [
["inspector/slideout", "slideout.eta"],

View file

@ -1,7 +1,14 @@
function handler(req, res) {
const sql = require("db")("bliss").sql;
const kind = "route";
const artifact = sql.prepare("SELECT * FROM routes WHERE id = ?").get(req.params.id);
if (!artifact) return res.status(404).send("Route not found");
res.render("inspector/artifact_editor", { kind, artifact });
// Read a route's source through the plumbing API rather than mounting the prime
// db directly. The prime db is no longer attachable to other structures, and
// going through /plumbing means this read is owner-checked: forwarding the
// caller's session cookie, plumbing 404s any route in a structure they can't
// see, so the live editor can only open what the user is already allowed to edit.
async function handler(req, res) {
const base = `${req.protocol}://${req.get("host")}`;
const response = await fetch(`${base}/plumbing/routes/${req.params.id}`, {
headers: { cookie: req.headers.cookie || "" },
});
if (!response.ok) return res.status(response.status).send("Route not found");
const artifact = await response.json();
res.render("inspector/artifact_editor", { kind: "route", artifact });
}

View file

@ -1,7 +1,13 @@
function handler(req, res) {
const sql = require("db")("bliss").sql;
const kind = "template";
const artifact = sql.prepare("SELECT * FROM templates WHERE id = ?").get(req.params.id);
if (!artifact) return res.status(404).send("Template not found");
res.render("inspector/artifact_editor", { kind, artifact });
// Read a template's source through the plumbing API rather than mounting the
// prime db directly (see route-editor.js for the why). Forwarding the caller's
// session cookie keeps the read owner-checked: plumbing 404s any template in a
// structure the user can't see.
async function handler(req, res) {
const base = `${req.protocol}://${req.get("host")}`;
const response = await fetch(`${base}/plumbing/templates/${req.params.id}`, {
headers: { cookie: req.headers.cookie || "" },
});
if (!response.ok) return res.status(response.status).send("Template not found");
const artifact = await response.json();
res.render("inspector/artifact_editor", { kind: "template", artifact });
}