import mimetypes import os from pathlib import Path from fastapi import FastAPI from fastapi.middleware.cors import CORSMiddleware from fastapi.staticfiles import StaticFiles from starlette.exceptions import HTTPException as StarletteHTTPException from .database import engine from .limits import BodySizeLimitMiddleware from .migrations import bootstrap from .routers import ( adventures, backups, chat, debug, scenarios, settings, story_cards, ) from .seed import seed_public_scenarios bootstrap(engine) seed_public_scenarios(engine) # Production serves the SPA same-origin, so CORS only matters for the Vite dev # server; AIDND_CORS_ORIGINS overrides for any other cross-origin setup. # # A wildcard is refused rather than honoured. This API is unauthenticated by # design and bound to loopback, so its only protection from a page the user # happens to have open in another tab is the same-origin policy. `*` would hand # every site on the Internet a write handle on the local campaign database. If the # value is wrong the app refuses to start, because a permissive CORS policy that # nobody notices is worse than one that fails loudly. CORS_ORIGINS = [ o.strip() for o in os.environ.get("AIDND_CORS_ORIGINS", "").split(",") if o.strip() ] or ["http://localhost:5173", "http://127.0.0.1:5173"] if any(o == "*" or o.strip() == "*" for o in CORS_ORIGINS): raise RuntimeError( "AIDND_CORS_ORIGINS must not contain '*'. The storyteller API is " "unauthenticated and loopback-bound; a wildcard origin would let any " "web page read and rewrite every campaign. List the exact origins " "instead." ) app = FastAPI( title="Adventure Storyteller", docs_url="/docs", redoc_url=None, openapi_url="/openapi.json", ) app.add_middleware( CORSMiddleware, allow_origins=CORS_ORIGINS, allow_methods=["*"], allow_headers=["*"], ) app.add_middleware(BodySizeLimitMiddleware) class SecurityHeadersMiddleware: """Standard hardening headers on every response. Pure ASGI (wraps `send`) so SSE streams pass through unbuffered. The CSP allows exactly what the SPA uses, and that is now same-origin and nothing else: scripts, styles, fonts, images and XHR/SSE all resolve to the app itself. The fonts used to come from Google, which made an Internet request on every page load; they are self-hosted under /fonts/ instead (frontend/tools/vendor_fonts.py), so `font-src 'self'` covers them and the two remote hosts are gone from the policy. `'unsafe-inline'` stays on `style-src` because React writes inline `style` attributes. It is deliberately absent from `script-src`. """ _HEADERS = [ (b"x-content-type-options", b"nosniff"), (b"referrer-policy", b"same-origin"), (b"x-frame-options", b"DENY"), ( b"content-security-policy", b"default-src 'self'; " b"script-src 'self'; " b"style-src 'self' 'unsafe-inline'; " b"font-src 'self'; " b"img-src 'self' data:; " b"connect-src 'self'; " b"object-src 'none'; " b"base-uri 'none'; " b"form-action 'self'; " b"frame-ancestors 'none'", ), ] def __init__(self, app): self.app = app async def __call__(self, scope, receive, send): if scope["type"] != "http": return await self.app(scope, receive, send) async def send_with_headers(message): if message["type"] == "http.response.start": message.setdefault("headers", []) message["headers"] = list(message["headers"]) + self._HEADERS await send(message) await self.app(scope, receive, send_with_headers) app.add_middleware(SecurityHeadersMiddleware) app.include_router(scenarios.router) app.include_router(adventures.router) app.include_router(story_cards.router) app.include_router(settings.router) # M9: a verified copy of the whole database, taken while the app is running. app.include_router(backups.router) app.include_router(chat.router) app.include_router(debug.router) @app.get("/api/health") def health(): return {"ok": True} # In production, serve the built frontend (frontend/dist) as static files. class SPAStaticFiles(StaticFiles): """Serve index.html for unknown paths so client-side routes (/play/3) survive a page reload. API routes are matched before this mount, and an unmatched one 404s rather than falling through to the page.""" async def get_response(self, path, scope): try: response = await super().get_response(path, scope) except StarletteHTTPException as exc: if exc.status_code != 404: raise return await self._fallback(path, scope) if response.status_code == 404: return await self._fallback(path, scope) return response async def _fallback(self, path, scope): # The mount is a catch-all, so an /api path no router claims — a typo, # or an endpoint this build removed — used to come back as the SPA's # HTML with status 200, and a client asking for JSON parsed a web page # instead of seeing that the route is not there. if path == "api" or path.startswith("api/"): raise StarletteHTTPException(status_code=404) return await super().get_response("index.html", scope) # Python's mimetypes table has no entry for woff2 on a slim Debian image, so # StaticFiles served the self-hosted fonts as application/octet-stream. Browsers # take them anyway — a @font-face src carries its own format() hint — but the # honest type costs one line. mimetypes.add_type("font/woff2", ".woff2") mimetypes.add_type("font/woff", ".woff") frontend_dist = Path(__file__).resolve().parent.parent.parent / "frontend" / "dist" if frontend_dist.is_dir(): app.mount("/", SPAStaticFiles(directory=frontend_dist, html=True), name="frontend")