Sync-Kern:
- internal/sync/hlc.go: Hybrid Logical Clock (wall_ms<<16|counter)
Tick/Now/After, global mutex, strikt monoton + kausal korrekt
- internal/sync/hlc_test.go: Unit-Tests (monoton, kausal, keine Duplikate)
Store-Schicht:
- internal/store/opstore.go: AppendOps idempotent via UNIQUE(client_id,
client_seq) ON CONFLICT DO NOTHING; LWW-Projektion (list_create/
rename/delete, item_add/update/remove) in derselben Transaktion;
PullOps mit Cursor (seq > since, 500er Pages)
- internal/store/liststore.go: CreateList / GetLists / GetList
- internal/store/itemstore.go: GetItems (nicht-gelöschte Items)
- internal/store/suggeststore.go: Search (pg_trgm + LIKE-fallback, 10)
HTTP-Handler:
- internal/httpapi/lists.go: GET/POST /api/lists, GET /api/lists/{id}
- internal/httpapi/ops.go: POST /api/lists/{id}/ops (Push),
GET /api/lists/{id}/ops (Pull ?since=)
- internal/httpapi/suggest.go: GET /api/suggestions?q=
- internal/httpapi/api.go: alle Routen verdrahtet (RequireAuth)
Deployment:
- deploy/Caddyfile.behind-proxy: auto_https off, trusted_proxies
- deploy/Caddyfile: X-Forwarded-Proto hinzugefügt, Kommentar aktualisiert
- deploy/docker-compose.yml: CADDY_HTTP_PORT + CADDY_HTTPS_PORT
- deploy/.env.example: Caddy-Port-Variablen dokumentiert
go build ./... && go vet ./... && go test ./... ✅
HLC-Tests: monoton, kausal, keine Duplikate ✅
AGENTS.md: Phase C vollständig ✅
41 lines
1.2 KiB
Text
41 lines
1.2 KiB
Text
# Caddyfile for mitbringsl – behind external reverse proxy mode.
|
||
#
|
||
# Use this when your own reverse proxy (nginx, Traefik, etc.) handles TLS
|
||
# termination and routes traffic to Caddy over plain HTTP on the internal
|
||
# Docker network.
|
||
#
|
||
# In docker-compose.yml, mount this file instead of the default Caddyfile:
|
||
# volumes:
|
||
# - ./Caddyfile.behind-proxy:/etc/caddy/Caddyfile:ro
|
||
#
|
||
# Your external proxy should set:
|
||
# X-Forwarded-For <client-ip>
|
||
# X-Forwarded-Proto https
|
||
# Host <your-domain>
|
||
{
|
||
# Disable auto-HTTPS – TLS is handled by the outer proxy.
|
||
auto_https off
|
||
}
|
||
|
||
:80 {
|
||
# Trust the private-network upstream so X-Forwarded-* headers are accepted.
|
||
# Change to a specific IP/CIDR if your proxy has a fixed address.
|
||
trusted_proxies private_ranges
|
||
|
||
reverse_proxy backend:8080 {
|
||
# Forward the real client IP to the backend.
|
||
header_up X-Real-IP {http.request.header.X-Forwarded-For}
|
||
header_up X-Forwarded-For {http.request.header.X-Forwarded-For}
|
||
header_up X-Forwarded-Proto {http.request.header.X-Forwarded-Proto}
|
||
}
|
||
|
||
# Enforce a sensible request body size limit.
|
||
request_body {
|
||
max_size 2MB
|
||
}
|
||
|
||
log {
|
||
output stdout
|
||
format console
|
||
}
|
||
}
|