Repository navigation
fix(governance): serve /static assets on the :8090 console - #21
Merged
NetworkTheoryAppliedResearchInstitute merged 1 commit intoJul 14, 2026
Merged
Conversation
The admin console GET pages reference /static/css/portal.css and the brand mark, but the governance mux registered no /static route, so every console page rendered as bare unstyled HTML (found live 2026-07-14: the browser showed what looked like "no UI"; the pages themselves were 200). ConfigureConsole now derives a static dir beside the templates dir (templatesDir/../static — the same web/ layout the portal serves, internal/portal/server.go) and a new GET /static/ route serves it via the portal's exact StripPrefix+FileServer idiom. On a POST-only server (ConfigureConsole not called) the route 404s — harmless, alongside the unwired console pages' own 500 "template not found". The route sits on the same loopback-bound, loopback-source-guarded mux as everything else on :8090; governance separation is unchanged. ConfigureConsole also warns at configure time when the derived static dir is missing — without that, the only symptom of a trimmed deployment layout is per-request 404s and a silently unstyled console, the exact regression class this fixes (adversarial-review finding). Three tests: 200 + design tokens when configured, 404 when unconfigured, 403 from a non-loopback source. No launcher/env change needed: GOVERNANCE_TEMPLATES_DIR already points at web/templates, so the derived static dir lands on web/static. Signed-off-by: Jodson Graves <info@ntari.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Found live 2026-07-14: opening the governance console (127.0.0.1:8090) in a browser showed what looked like "no UI". The pages themselves rendered fine (200) — but the admin templates reference
/static/css/portal.cssand the brand mark, and the governance mux registered no/static/route, so the stylesheet 404'd and every page displayed as bare unstyled HTML.Fix
ConfigureConsolederives a static dir beside the templates dir (templatesDir/../static— the sameweb/layout the portal serves atinternal/portal/server.go:353) and a newGET /static/route serves it with the portal's exactStripPrefix+FileServeridiom.ConfigureConsole): the route 404s — harmless, alongside the unwired console pages' own 500 "template not found".os.Statwarning when the derived static dir is missing, so a trimmed deployment layout can't silently reproduce the unstyled-console symptom (adversarial-review finding).Review
Ran a 3-lens adversarial panel (security / correctness / house-discipline) over the diff before opening this PR: no blockers. Security traced the loopback guard over the new route and refuted traversal/symlink/public-reachability (
http.Dirroots throughpath.Clean; the coordinator key lives in env/process memory, unreachable from the served tree). Correctness verified the path derivation for both the launcher's absolute Windows path and the tests' relative path, Windows registry MIME types for.css/.svgon the deployment host, and Go 1.22+ServeMuxsubtree semantics. Two nits adopted: the configure-time stat warning, and comment precision (static 404 vs pages' 500). One nit deliberately not taken: scoping the served tree belowweb/static— parity with the portal's idiom won (read-only, loopback-only, serves only already-public assets).Tests
TestAdminConsole_StaticAssets_ServedWhenConfigured(200 + design tokens),TestAdminConsole_Static404WhenUnconfigured,TestAdminConsole_StaticRejectsNonLoopbackSource(403). Fullinternal/apipackage green.No launcher/env change needed —
GOVERNANCE_TEMPLATES_DIRalready points atweb/templates. Deployment step after merge: rebuildC:\SoHoLINK-governance\governance.exefrom main and restart the host process.Author does not self-merge — for review.