|
7 | 7 |
|
8 | 8 | import { writeFileSync, existsSync, mkdirSync, copyFileSync } from 'node:fs'; |
9 | 9 | import { join } from 'node:path'; |
10 | | -import { read, log, templatesDir } from '../util.js'; |
| 10 | +import { bakeSiteUuid, read, log, templatesDir } from '../util.js'; |
11 | 11 | import type { Adapter, WireOptions, WireResult, VerifyResult } from '../types.js'; |
12 | 12 |
|
13 | 13 | const CLIENT_TUNNEL = [ |
@@ -133,40 +133,6 @@ function scaffold(cwd: string, opts: WireOptions): string[] { |
133 | 133 | return changed; |
134 | 134 | } |
135 | 135 |
|
136 | | -// Bake the site UUID from .patchstackrc.json (written by `scan`) into the scaffolded guard, so the |
137 | | -// deployed Worker calls the live Pulse rules API with zero user config. Left as the inert |
138 | | -// placeholder when the app hasn't been scanned yet or the file can't be read. Returns whether it baked. |
139 | | -function bakeSiteUuid(cwd: string): boolean { |
140 | | - const rc = join(cwd, '.patchstackrc.json'); |
141 | | - if (!existsSync(rc)) { |
142 | | - log('no .patchstackrc.json — guard uses PATCHSTACK_SITE_UUID env or the bundled fallback'); |
143 | | - return false; |
144 | | - } |
145 | | - let uuid: string | undefined; |
146 | | - try { |
147 | | - uuid = JSON.parse(read(rc)).siteUuid; |
148 | | - } catch { |
149 | | - log('.patchstackrc.json unreadable — skipping site-UUID bake'); |
150 | | - return false; |
151 | | - } |
152 | | - // Guard on UUID format so a malformed value falls through to the inert placeholder rather than |
153 | | - // baking junk into a TS string literal (broken build / replace-token hazards). |
154 | | - if (!uuid || !/^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$/i.test(uuid)) { |
155 | | - log('.patchstackrc.json siteUuid missing or malformed — guard uses PATCHSTACK_SITE_UUID env or the bundled fallback'); |
156 | | - return false; |
157 | | - } |
158 | | - const p = join(cwd, GUARD_FILE); |
159 | | - if (!existsSync(p)) return false; |
160 | | - const s = read(p); |
161 | | - if (!s.includes('__PATCHSTACK_SITE_UUID__')) { |
162 | | - log('guard.ts site UUID already baked'); |
163 | | - return false; |
164 | | - } |
165 | | - writeFileSync(p, s.replace('__PATCHSTACK_SITE_UUID__', uuid)); |
166 | | - log('baked site UUID into guard.ts — live rules from the Patchstack API'); |
167 | | - return true; |
168 | | -} |
169 | | - |
170 | 136 | function patchClient(cwd: string): boolean { |
171 | 137 | const p = join(cwd, 'src/integrations/supabase/client.ts'); |
172 | 138 | const s = read(p); |
@@ -238,7 +204,7 @@ function wire(cwd: string, opts: WireOptions): WireResult { |
238 | 204 | const changed = scaffold(cwd, opts); |
239 | 205 | // In demo mode, keep the local sample rules active — don't bake a site UUID (which would make |
240 | 206 | // the guard fetch live Pulse rules instead of the bundled demo set). |
241 | | - if (!opts.demo && bakeSiteUuid(cwd)) changed.push(GUARD_FILE); |
| 207 | + if (!opts.demo && bakeSiteUuid(cwd, GUARD_FILE)) changed.push(GUARD_FILE); |
242 | 208 | if (patchClient(cwd)) changed.push('src/integrations/supabase/client.ts'); |
243 | 209 | if (patchStart(cwd)) changed.push('src/start.ts'); |
244 | 210 | log( |
|
0 commit comments