diff --git a/src/channels/web/CLAUDE.md b/src/channels/web/CLAUDE.md index 1e18514ce5f..ad22b5567b9 100644 --- a/src/channels/web/CLAUDE.md +++ b/src/channels/web/CLAUDE.md @@ -12,9 +12,9 @@ Browser-facing HTTP API and SSE/WebSocket real-time streaming. Axum-based, singl | `platform/state.rs` | `GatewayState`, `RateLimiter`, `PerUserRateLimiter`, `WorkspacePool`, `FrontendHtmlCache`, `FrontendCacheKey`, `ActiveConfigSnapshot`, `PromptQueue`, `RoutineEngineSlot`. Canonical home for shared gateway state. | | `platform/static_files.rs` | CSP directive set + `BASE_CSP_HEADER` (single source of truth), frontend HTML bundle assembly (`build_frontend_html`), and the unauthenticated static handlers: `/`, `/style.css`, `/app.js`, `/theme.css`, `/favicon.ico`, `/i18n/*`, `/admin*`, `/api/health`, plus the authenticated `/projects/{id}/...` file-serving routes. | | `types.rs` | Request/response DTOs and `SseEvent` enum (source of truth for SSE contract) | -| `sse.rs` | `SseManager` — broadcast channel that fans out `SseEvent` to all connected SSE clients | -| `ws.rs` | WebSocket handler (`handle_ws_connection`) + `WsConnectionTracker` | -| `auth.rs` | Bearer token middleware (`Authorization: Bearer `) | +| `platform/sse.rs` | `SseManager` — broadcast channel that fans out `SseEvent` to all connected SSE clients. Re-exported as `channels::web::sse` for backward compat. | +| `platform/ws.rs` | WebSocket handler (`handle_ws_connection`) + `WsConnectionTracker`. Re-exported as `channels::web::ws`. | +| `platform/auth.rs` | Bearer token middleware (`Authorization: Bearer `) + DB-token + OIDC extractors. Re-exported as `channels::web::auth`. | | `log_layer.rs` | Tracing layer that tees log lines to the `/api/logs/events` SSE stream | | `handlers/` | Feature handler functions split by domain: `auth`, `chat`, `engine`, `extensions`, `frontend`, `jobs`, `llm`, `memory`, `routines`, `secrets`, `settings`, `skills`, `system_prompt`, `tokens`, `tool_policy`, `users`, `webhooks`. Targeted for migration into `features//` per ironclaw#2599. | | `openai_compat.rs` | OpenAI-compatible proxy (`/v1/chat/completions`, `/v1/models`) | diff --git a/src/channels/web/mod.rs b/src/channels/web/mod.rs index 33e6490cb52..d8d8f3ababc 100644 --- a/src/channels/web/mod.rs +++ b/src/channels/web/mod.rs @@ -14,19 +14,25 @@ //! ◄── GET / ───────────────── Static HTML/CSS/JS //! ``` -pub mod auth; pub(crate) mod handlers; pub mod log_layer; pub mod oauth; pub(crate) mod onboarding; pub mod openai_compat; -pub(crate) mod platform; +pub mod platform; pub mod responses_api; pub mod server; -pub mod sse; pub mod types; pub(crate) mod util; -pub mod ws; + +// Backward-compat re-exports for the ironclaw#2599 migration. The auth, +// SSE, and WebSocket modules moved to `platform::*` in stage 3; every +// existing `crate::channels::web::{auth,sse,ws}::...` call site +// continues to resolve via these re-exports until a follow-up PR +// updates them directly. +pub use platform::auth; +pub use platform::sse; +pub use platform::ws; /// Test helpers for gateway integration tests. /// diff --git a/src/channels/web/auth.rs b/src/channels/web/platform/auth.rs similarity index 100% rename from src/channels/web/auth.rs rename to src/channels/web/platform/auth.rs diff --git a/src/channels/web/platform/mod.rs b/src/channels/web/platform/mod.rs index 00b42a14fb4..51e792bb200 100644 --- a/src/channels/web/platform/mod.rs +++ b/src/channels/web/platform/mod.rs @@ -1,22 +1,24 @@ //! Platform layer for the web gateway. //! -//! This submodule holds the gateway's transport and framing concerns: shared -//! state, the Axum route composition, static asset serving, and (in later -//! stages of ironclaw#2599) auth / SSE / WS. +//! This submodule holds the gateway's transport and framing concerns: +//! shared state, the Axum route composition, static asset serving, bearer +//! / OIDC auth, and the SSE / WebSocket broadcast fan-out. //! //! **Dependency direction.** Feature handlers (under `handlers/` today, //! `features//` later) depend on platform types (`GatewayState`, -//! rate limiters, auth extractors). Platform *submodules* do **not** -//! reach back into feature handlers — with the single, intentional -//! exception of [`router`], which is the composition point. The router -//! imports every feature handler it registers; that is its job. The -//! "no back-edges" rule enforced by future CI (ironclaw#2599 stage 5) -//! applies to `platform/state.rs`, `platform/static_files.rs`, and the -//! auth/SSE/WS modules once they move here — not to `router`, whose -//! whole purpose is to wire features onto the transport. +//! rate limiters, auth extractors, `SseManager`, `WsConnectionTracker`). +//! Platform *submodules* do **not** reach back into feature handlers — +//! with the single, intentional exception of [`router`], which is the +//! composition point. The router imports every feature handler it +//! registers; that is its job. The "no back-edges" rule enforced by +//! future CI (ironclaw#2599 stage 5) applies to every platform module +//! except `router`. //! //! See `src/channels/web/CLAUDE.md` for the staged migration plan. +pub mod auth; pub mod router; +pub mod sse; pub mod state; pub mod static_files; +pub mod ws; diff --git a/src/channels/web/sse.rs b/src/channels/web/platform/sse.rs similarity index 100% rename from src/channels/web/sse.rs rename to src/channels/web/platform/sse.rs diff --git a/src/channels/web/ws.rs b/src/channels/web/platform/ws.rs similarity index 100% rename from src/channels/web/ws.rs rename to src/channels/web/platform/ws.rs