Skip to content

fix(governance): serve /static assets on the :8090 console - #21

Merged
NetworkTheoryAppliedResearchInstitute merged 1 commit into
mainfrom
fix/governance-static
Jul 14, 2026
Merged

NetworkTheoryAppliedResearchInstitute merged 1 commit into
mainfrom
fix/governance-static

Conversation

@NetworkTheoryAppliedResearchInstitute

Copy link
Copy Markdown
Contributor

Found live 2026-07-14: opening the governance console (127.0.0.1:8090) in a browser showed what looked like "no UI". The pages themselves rendered fine (200) — but the admin templates reference /static/css/portal.css and the brand mark, and the governance mux registered no /static/ route, so the stylesheet 404'd and every page displayed as bare unstyled HTML.

Fix

  • ConfigureConsole derives a static dir beside the templates dir (templatesDir/../static — the same web/ layout the portal serves at internal/portal/server.go:353) and a new GET /static/ route serves it with the portal's exact StripPrefix+FileServer idiom.
  • POST-only server (no ConfigureConsole): the route 404s — harmless, alongside the unwired console pages' own 500 "template not found".
  • Configure-time os.Stat warning when the derived static dir is missing, so a trimmed deployment layout can't silently reproduce the unstyled-console symptom (adversarial-review finding).
  • Governance separation unchanged: the route sits on the same loopback-bound, loopback-source-guarded mux as everything else on :8090.

Review

Ran a 3-lens adversarial panel (security / correctness / house-discipline) over the diff before opening this PR: no blockers. Security traced the loopback guard over the new route and refuted traversal/symlink/public-reachability (http.Dir roots through path.Clean; the coordinator key lives in env/process memory, unreachable from the served tree). Correctness verified the path derivation for both the launcher's absolute Windows path and the tests' relative path, Windows registry MIME types for .css/.svg on the deployment host, and Go 1.22+ ServeMux subtree semantics. Two nits adopted: the configure-time stat warning, and comment precision (static 404 vs pages' 500). One nit deliberately not taken: scoping the served tree below web/static — parity with the portal's idiom won (read-only, loopback-only, serves only already-public assets).

Tests

TestAdminConsole_StaticAssets_ServedWhenConfigured (200 + design tokens), TestAdminConsole_Static404WhenUnconfigured, TestAdminConsole_StaticRejectsNonLoopbackSource (403). Full internal/api package green.

No launcher/env change needed — GOVERNANCE_TEMPLATES_DIR already points at web/templates. Deployment step after merge: rebuild C:\SoHoLINK-governance\governance.exe from main and restart the host process.

Author does not self-merge — for review.

The admin console GET pages reference /static/css/portal.css and the
brand mark, but the governance mux registered no /static route, so every
console page rendered as bare unstyled HTML (found live 2026-07-14: the
browser showed what looked like "no UI"; the pages themselves were 200).

ConfigureConsole now derives a static dir beside the templates dir
(templatesDir/../static — the same web/ layout the portal serves,
internal/portal/server.go) and a new GET /static/ route serves it via
the portal's exact StripPrefix+FileServer idiom. On a POST-only server
(ConfigureConsole not called) the route 404s — harmless, alongside the
unwired console pages' own 500 "template not found". The route sits on
the same loopback-bound, loopback-source-guarded mux as everything else
on :8090; governance separation is unchanged.

ConfigureConsole also warns at configure time when the derived static
dir is missing — without that, the only symptom of a trimmed deployment
layout is per-request 404s and a silently unstyled console, the exact
regression class this fixes (adversarial-review finding).

Three tests: 200 + design tokens when configured, 404 when
unconfigured, 403 from a non-loopback source.

No launcher/env change needed: GOVERNANCE_TEMPLATES_DIR already points
at web/templates, so the derived static dir lands on web/static.

Signed-off-by: Jodson Graves <info@ntari.org>
@NetworkTheoryAppliedResearchInstitute
NetworkTheoryAppliedResearchInstitute merged commit 63ee4cd into main Jul 14, 2026
7 checks passed
@NetworkTheoryAppliedResearchInstitute
NetworkTheoryAppliedResearchInstitute deleted the fix/governance-static branch July 14, 2026 15:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant