Skip to content

feat: add packages/spa as React Router v7 + Vite SPA sample - #61

Merged
koh110 merged 21 commits into
mainfrom
feature/spa-sample
Sep 18, 2026
Merged

koh110 merged 21 commits into
mainfrom
feature/spa-sample

Conversation

@koh110

@koh110 koh110 commented Sep 15, 2026 •

Copy link
Copy Markdown
Owner
  • add packages/spa as a React Router v7 + Vite ssr:false SPA sample
  • browser fetches same-origin GET /api/user with credentials: 'include'
  • SPA runtime is static-only: no Node application server, API proxy, BFF, or cookie-to-Authorization adapter in the package
  • build outputs static assets to dist/public; local start uses Vite preview only
  • deployment environment provides same-origin /api/user and SPA fallback; nginx example documented
  • existing Authorization-only API can be adapted by nginx / ingress / BFF outside the SPA package
  • extract the existing schema-driven typed HTTP client to shared/src/api-client so Next.js and SPA use the same implementation
  • SPA api.client.ts is only a browser wrapper that adds credentials: 'include'; endpoint-specific loading stays separate
  • deterministic dark dashboard UI with loading/success/empty/failure states
  • CI covers format/lint/typecheck/build/test

Closes limit-monitor reference SPA sample request.

- separate workspace alongside Next.js client
- ssr:false, Node built-in HTTP static server
- server-side /api/user proxy (API_URI + API_TOKEN never exposed to browser)
- loopback-only, exact Host/Origin validation, raw path parsing, O_NOFOLLOW symlink protection
- 5s absolute deadline, decoded body ≤1MiB (with genuine gzip streamed test at limit boundaries + immediate abort)
- redirect rejection, client-disconnect/shutdown cancellation, runtime validation + sanitized errors
- deterministic dark dashboard UI (connection status, cards, meter-like user list, 4 states, responsive)
- full CI (ci-spa.yml + updated ci-client.yml), lint/tsc/build/test pass
- Vite dependency split (root vite-plus override + scoped @react-router/dev / vite-node)
- spec + 6 rounds qualified code review (Blocking/Major=0, all prior M-00x closed)

Closes limit-monitor reference SPA sample request.
Base: 8987d19
@koh110
koh110 force-pushed the feature/spa-sample branch 2 times, most recently from 6b1d663 to 3991385 Compare September 18, 2026 05:13
@koh110
koh110 merged commit 47d4322 into main Sep 18, 2026
9 checks passed
@koh110
koh110 deleted the feature/spa-sample branch September 18, 2026 05:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant