HostSiteConfig host.site-config@1

Generated at from openvibe-contracts v0.84.0 and openvibe-sdk v0.26.0.

Version
1.0.0
Owner
host
Visibility
first-party
Status
active
Compatibility
backward
Schema
https://openvibe.network/contracts/host/site-config.v1.json

host.site-config@1: one Host site's serving configuration (plan T12 J3). headers are applied to every response of the site before the platform's own, which always win; the platform's security, routing, caching, scope and transport headers (Content-Security-Policy, Strict-Transport-Security, Set-Cookie, Cache-Control, Content-Type, Location, Service-Worker-Allowed, Alt-Svc and the rest of Host's reserved list) and every X-Forwarded-* header are refused. redirects are local paths only (no scheme, host, protocol-relative URL, backslash or control character, also after percent-decoding). spa serves /index.html for an extensionless path that has no file. A site with no configuration answers { headers: {}, redirects: [], spa: false }.

Fields

FieldTypeRequiredDescriptionConstraints
headersobjectyes
redirectsarray of objectyes
  • maxItems 200
  • items: no other fields
redirects[].fromstringyes
  • pattern ^/(?!/)
  • maxLength 1024
redirects[].tostringyes
  • pattern ^/(?!/)
  • maxLength 1024
redirects[].statusenumyes
  • one of 301, 302, 307, 308
spabooleanyes

Examples

From the contract's own test fixtures: valid ones validate, rejected ones must fail.

Valid: configured
{
  "headers": {
    "X-Frame-Options": "DENY",
    "Access-Control-Allow-Origin": "*"
  },
  "redirects": [
    {
      "from": "/old",
      "to": "/new",
      "status": 301
    }
  ],
  "spa": true
}
Valid: defaults
{
  "headers": {},
  "redirects": [],
  "spa": false
}
Rejected: protocol-relative
{
  "headers": {},
  "redirects": [
    {
      "from": "/a",
      "to": "//evil.example/",
      "status": 301
    }
  ],
  "spa": false
}

Validate

const contracts = require('openvibe-contracts');
contracts.validate('host.site-config@1', value);   // { valid, errors: [{ path, message }] }