From 5dea19d9950518887be7eb14696f600ee023dbbd Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Sun, 16 Aug 2026 20:57:52 +0200 Subject: fix(hub): serve the SPA under a fingerprint of what it is MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `Cache-Control: no-cache` requires a browser to revalidate, but it only binds one that asks. A browser that cached app.js before that header existed applies heuristic freshness instead — a fraction of the file's age, which for a file dated weeks ago is days — and never asks. It then runs an old player against a new node. That cost most of a session. A phone kept a player without the read-ahead bound and filled the browser's buffer ceiling at 106 MB, the exact symptom the bound had been written to remove, for an hour after the bounded player went live. A fix that is written, tested, deployed and served, and still not what runs, is indistinguishable from a fix that does not work. The whole module graph now lives under `/a//`. A path prefix rather than a query string, because relative imports inherit it: `app.js` reaching for `./i18n.js` gets the build it was written against, and never a mixture of two — which does not render a stale page, it fails to link. The URL changes with the content, so those may be cached hard. `sw.js` stays at the root. Its scope is its own path, and under the prefix it would no longer control the pages whose downloads it exists to intercept. --- packages/meshbay-hub/src/meshbay_hub/app.py | 31 ++++++++++++++++++++++++++++- 1 file changed, 30 insertions(+), 1 deletion(-) (limited to 'packages/meshbay-hub/src/meshbay_hub/app.py') diff --git a/packages/meshbay-hub/src/meshbay_hub/app.py b/packages/meshbay-hub/src/meshbay_hub/app.py index 6240785..423ad03 100644 --- a/packages/meshbay-hub/src/meshbay_hub/app.py +++ b/packages/meshbay-hub/src/meshbay_hub/app.py @@ -35,7 +35,7 @@ from meshbay_hub.api.relay import router as relay_router from meshbay_hub.api.signaling import router as signaling_router from meshbay_hub.api.admin import router as admin_router from meshbay_hub.api.notifications import router as notifications_router -from meshbay_hub.api.webapp import router as webapp_router, STATIC_DIR +from meshbay_hub.api.webapp import router as webapp_router, STATIC_DIR, ASSET_V from meshbay_hub.api.middleware import limiter @@ -145,6 +145,35 @@ def create_app(cfg: HubConfig | None = None) -> FastAPI: response.headers.setdefault("Cache-Control", "no-cache") return response + class VersionedStatics(StaticFiles): + """The same files under a URL that changes when they do. + + `no-cache` above only binds a browser that asks. One that cached the SPA + before that header existed applies heuristic freshness and does not ask + at all, so it runs an old player against a new node — a fix that is + deployed, served, and not running, which looks exactly like a fix that + does not work. Measured: a phone kept a player without the read-ahead + bound and filled the browser's buffer ceiling at 106 MB, while the + server had been serving the bounded one for an hour. + + Serving the graph under /a// solves it for every file at + once, because relative imports inherit the prefix: `app.js` reaching for + `./i18n.js` gets the version it was built against, and never a mixture. + The URL changes with the content, so these may be cached hard. + """ + + async def get_response(self, path, scope): + response = await super().get_response(path, scope) + response.headers["Cache-Control"] = ( + "public, max-age=31536000, immutable") + return response + + # Before "/", which would otherwise swallow it. + app.mount(f"/a/{ASSET_V}", VersionedStatics(directory=STATIC_DIR), + name="static-versioned") + # Still served unversioned: sw.js must stay at the root or its scope stops + # covering the pages it intercepts downloads for, and old bookmarks of + # /style.css and the like should not 404. app.mount("/", RevalidatingStatics(directory=STATIC_DIR), name="static") return app -- cgit v1.2.3