Conversation
Expose the configured Express application as StorageServer.app and make port optional outside start(). Add preRpcMiddleware, run on POST / after authentication, rate limiting and payment and before JSON-RPC dispatch, and publicRoutes to drop the unauthenticated GET routes. Defaults are unchanged.
|
Contributor
Author
|
Closing for now: running StorageServer standalone is enough for our deployment. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



What changed
StorageServerin@bsv/wallet-toolboxcan be mounted inside a host Express application.StorageServer.appis public. A host mounts it withhostApp.use('/storage', server.app)instead of callingstart().portis optional and only required bystart(), which now throwsWERR_INVALID_PARAMETERwithout it.preRpcMiddleware?: RequestHandler[]runs onPOST /after authentication, the authenticated rate limit and (whenmonetizeis set) payment, immediately before JSON-RPC dispatch. Handlers seereq.authand the parsed body; a handler that responds stops the call before dispatch. It does not run on the action batch upload routes.publicRoutes?: boolean(defaulttrue) controls the unauthenticatedGET /,/robots.txtand/healthzroutes.With none of the new options set, the route stack is the same as before.
Why a host needs it
A host that serves wallet storage next to its own authenticated routes needs one listener, its own health and info routes, and a per-identity check (for example a storage quota) between authentication and dispatch.
AuthFetchsends the BRC-104 handshake to the origin's/.well-known/auth, so under a sub-path the host answers the handshake with its own auth middleware, using the same wallet and the existingsessionManageroption shared with the storage server. The README section covers this, including mount order relative to the host's auth middleware and body parsers.Version
Minor: new public options and a public field.
@bsv/wallet-toolbox,-clientand-mobilemove from the unpublished 2.14.5 to 2.15.0 in step, with the release notes, CHANGELOG, generated facts and baselines updated. StorageServer is only in the Node entry point; client and mobile bytes are unchanged. #719 (StorageKnex on Postgres) makes the same 2.14.5 → 2.15.0 bump; whichever merges second merges its notes into the 2.15.0 entries.docs/storage.mdis updated for the StorageServer entries only; a fullpnpm docrun also rewrites unrelated sections and is left out.Tests
New
src/storage/remoting/__test/StorageServerMount.test.ts(SQLiteStorageKnex):/storagein a host app whose auth middleware handles the handshake with a sharedSessionManager;StorageClientcallsmakeAvailableandfindOrInsertUserthrough the mountpublicRoutes: falseremoves the GET routes; defaults keep themstart()withoutportthrowspreRpcMiddlewarehandler is not reached by an unauthenticated POST, seesreq.auth.identityKeyand the method when authenticated, returns 507 without dispatching, and lets dispatch proceed when it callsnext()Local results
pnpm lint, toolboxpnpm lint, toolboxpnpm typecheck: passpnpm format:check: passpnpm health:check: pass (0 contract findings)npx jest --testPathIgnorePatterns='man.test.ts|live.test.ts|bench.test.ts|client/test|mobile/test' --watchman=false: 287/287 suites, 3115 passed, 1 skippedNo dependency or lockfile change. Nothing published.