Problem
GET /h/{n} is a route of flexviz.app, so every app that mounts FlexViz serves it, including mount_into(), a Streamlit st.App mount, and Dash or Gradio. The route reads .flexviz/history.jsonl in the working folder of the process (flexviz/server.py, history_view).
Repro: in a folder where flexviz history add <url> ran, mount FlexViz in a FastAPI app with no source registered. GET /flexviz/h/1 returns 200, and the page holds the recorded spec: figure titles, column names, and selections. When the recorded source is also registered, the page also shows its data.
/h/N exists for the agent loop. A web app that embeds a dashboard does not need it. Authentication in front of the web app does not help, because each signed-in user can still read the history. #141 adds a warning to the web apps guide. The agent guide's safety notes already say not to serve a public dashboard from such a folder.
Proposal
Register /h/{n} only where the agent loop starts the server: in run_server(), which flexviz serve and show() call. app and mount_into() then serve only the stateless routes.
This affects one documented recipe. The skill's recipe for a derived column (flexviz/skills/flexviz-explore/SKILL.md, step "2. Serve the file") runs uvicorn.run(app, ...) directly. It would lose /h/N unless it calls run_server(). That needs run_server() (or a small wrapper) in the public API. A side benefit is that the recipe then also gets the loopback Host check, which it skips today.
Alternatives:
Done when
- A mounted or embedded
app answers 404 on /h/{n}.
flexviz serve and show() still serve /h/N, and the agent loop tests pass.
- The skill's derived-column recipe starts the server through the public entry point.
- CHANGELOG, Architecture.md, and the agent and web apps guides describe the change.
Problem
GET /h/{n}is a route offlexviz.app, so every app that mounts FlexViz serves it, includingmount_into(), a Streamlitst.Appmount, and Dash or Gradio. The route reads.flexviz/history.jsonlin the working folder of the process (flexviz/server.py,history_view).Repro: in a folder where
flexviz history add <url>ran, mount FlexViz in a FastAPI app with no source registered.GET /flexviz/h/1returns 200, and the page holds the recorded spec: figure titles, column names, and selections. When the recorded source is also registered, the page also shows its data./h/Nexists for the agent loop. A web app that embeds a dashboard does not need it. Authentication in front of the web app does not help, because each signed-in user can still read the history. #141 adds a warning to the web apps guide. The agent guide's safety notes already say not to serve a public dashboard from such a folder.Proposal
Register
/h/{n}only where the agent loop starts the server: inrun_server(), whichflexviz serveandshow()call.appandmount_into()then serve only the stateless routes.This affects one documented recipe. The skill's recipe for a derived column (
flexviz/skills/flexviz-explore/SKILL.md, step "2. Serve the file") runsuvicorn.run(app, ...)directly. It would lose/h/Nunless it callsrun_server(). That needsrun_server()(or a small wrapper) in the public API. A side benefit is that the recipe then also gets the loopbackHostcheck, which it skips today.Alternatives:
appand add an opt-out tomount_into(). This adds API surface, and a directuvicorn.run(app)would still serve history.Done when
appanswers 404 on/h/{n}.flexviz serveandshow()still serve/h/N, and the agent loop tests pass.