Skip to content

Server: do not serve /h/{n} from the mountable app #142

Description

@jvdd

Problem

GET /h/{n} is a route of flexviz.app, so every app that mounts FlexViz serves it, including mount_into(), a Streamlit st.App mount, and Dash or Gradio. The route reads .flexviz/history.jsonl in the working folder of the process (flexviz/server.py, history_view).

Repro: in a folder where flexviz history add <url> ran, mount FlexViz in a FastAPI app with no source registered. GET /flexviz/h/1 returns 200, and the page holds the recorded spec: figure titles, column names, and selections. When the recorded source is also registered, the page also shows its data.

/h/N exists for the agent loop. A web app that embeds a dashboard does not need it. Authentication in front of the web app does not help, because each signed-in user can still read the history. #141 adds a warning to the web apps guide. The agent guide's safety notes already say not to serve a public dashboard from such a folder.

Proposal

Register /h/{n} only where the agent loop starts the server: in run_server(), which flexviz serve and show() call. app and mount_into() then serve only the stateless routes.

This affects one documented recipe. The skill's recipe for a derived column (flexviz/skills/flexviz-explore/SKILL.md, step "2. Serve the file") runs uvicorn.run(app, ...) directly. It would lose /h/N unless it calls run_server(). That needs run_server() (or a small wrapper) in the public API. A side benefit is that the recipe then also gets the loopback Host check, which it skips today.

Alternatives:

Done when

  • A mounted or embedded app answers 404 on /h/{n}.
  • flexviz serve and show() still serve /h/N, and the agent loop tests pass.
  • The skill's derived-column recipe starts the server through the public entry point.
  • CHANGELOG, Architecture.md, and the agent and web apps guides describe the change.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions