Spaces:
Running
Running
chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)
Browse filesAutomated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): a11oy_canonical_domain.py
Deleted (gone from the repo + Dockerfile COPY set): (none)
Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.
- a11oy_canonical_domain.py +22 -10
a11oy_canonical_domain.py
CHANGED
|
@@ -5,20 +5,32 @@
|
|
| 5 |
a11oy_canonical_domain.py — make a-11-oy.com the single canonical host.
|
| 6 |
|
| 7 |
a11oy.net is SUNSET. This installs an app-level 301 redirect so any request whose
|
| 8 |
-
Host header is a11oy.net
|
| 9 |
-
|
| 10 |
-
|
| 11 |
-
|
| 12 |
-
|
| 13 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 14 |
receipt, signs nothing, and touches no state (provenance rule: never sign on a read
|
| 15 |
path). Doctrine-safe: try/except-guarded register(app).
|
| 16 |
"""
|
| 17 |
|
| 18 |
CANONICAL_HOST = "a-11-oy.com"
|
| 19 |
|
| 20 |
-
#
|
| 21 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 22 |
|
| 23 |
|
| 24 |
def register(app):
|
|
@@ -28,7 +40,7 @@ def register(app):
|
|
| 28 |
@app.middleware("http")
|
| 29 |
async def _canonical_host_redirect(request, call_next):
|
| 30 |
host = (request.headers.get("host") or "").split(":")[0].lower()
|
| 31 |
-
if host
|
| 32 |
target = f"https://{CANONICAL_HOST}{request.url.path}"
|
| 33 |
if request.url.query:
|
| 34 |
target = f"{target}?{request.url.query}"
|
|
@@ -36,4 +48,4 @@ def register(app):
|
|
| 36 |
return RedirectResponse(url=target, status_code=301)
|
| 37 |
return await call_next(request)
|
| 38 |
|
| 39 |
-
return [f"301 {
|
|
|
|
| 5 |
a11oy_canonical_domain.py — make a-11-oy.com the single canonical host.
|
| 6 |
|
| 7 |
a11oy.net is SUNSET. This installs an app-level 301 redirect so any request whose
|
| 8 |
+
Host header is on the a11oy.net domain — the apex (a11oy.net), www, OR ANY
|
| 9 |
+
subdomain (*.a11oy.net) — is permanently redirected to the same path+query on
|
| 10 |
+
https://a-11-oy.com. The canonical HF Space host (szlholdings-a11oy.hf.space),
|
| 11 |
+
localhost, and a-11-oy.com itself are passed through untouched, so the app keeps
|
| 12 |
+
working on its origin while the public URL converges.
|
| 13 |
+
|
| 14 |
+
Doctrine ("No a11oy.net on user surfaces"): matching only the apex + www left a
|
| 15 |
+
real gap — any OTHER a11oy.net host (e.g. app.a11oy.net, a stray CNAME) fell
|
| 16 |
+
through and SERVED user surfaces on .net. The match is host-suffix based so no
|
| 17 |
+
a11oy.net host can serve user content; every one of them is redirect-only.
|
| 18 |
+
|
| 19 |
+
This is a READ-PATH-SAFE redirect: it is a pure 301 Location response, mints no
|
| 20 |
receipt, signs nothing, and touches no state (provenance rule: never sign on a read
|
| 21 |
path). Doctrine-safe: try/except-guarded register(app).
|
| 22 |
"""
|
| 23 |
|
| 24 |
CANONICAL_HOST = "a-11-oy.com"
|
| 25 |
|
| 26 |
+
# The sunset domain. Any host that IS this apex or ends with ".<apex>" (i.e. any
|
| 27 |
+
# subdomain) is redirect-only and must never serve a user surface.
|
| 28 |
+
SUNSET_DOMAIN = "a11oy.net"
|
| 29 |
+
|
| 30 |
+
|
| 31 |
+
def _is_sunset_host(host: str) -> bool:
|
| 32 |
+
"""True if `host` is the a11oy.net apex or any of its subdomains."""
|
| 33 |
+
return host == SUNSET_DOMAIN or host.endswith("." + SUNSET_DOMAIN)
|
| 34 |
|
| 35 |
|
| 36 |
def register(app):
|
|
|
|
| 40 |
@app.middleware("http")
|
| 41 |
async def _canonical_host_redirect(request, call_next):
|
| 42 |
host = (request.headers.get("host") or "").split(":")[0].lower()
|
| 43 |
+
if _is_sunset_host(host):
|
| 44 |
target = f"https://{CANONICAL_HOST}{request.url.path}"
|
| 45 |
if request.url.query:
|
| 46 |
target = f"{target}?{request.url.query}"
|
|
|
|
| 48 |
return RedirectResponse(url=target, status_code=301)
|
| 49 |
return await call_next(request)
|
| 50 |
|
| 51 |
+
return [f"301 {SUNSET_DOMAIN} (+ *.{SUNSET_DOMAIN}) -> https://{CANONICAL_HOST}"]
|