feat(hub): migrate database admin pages to SPA (database-admin)

- scaffold hub/database-admin as SvelteKit 2 + Svelte 5 static SPA
  with aurora/glass visual style (paths.base='/database')
- add lib/{api,session,org}.ts + Aurora.svelte component
- add routes: root redirect, /admin login page, /dashboard (OWNER/ADMIN only)
- backend: replace server-rendered HTML routes with /database/config JSON endpoint
- add hub/src/database/static.ts to serve SPA under /database/*
- wire registerDatabaseSpa into plugin.ts
- exempt /database/* from silo rate-limit (same treatment as /admin/*)
- add database:dev + database:build npm scripts; update deploy scripts
- update hub/src/database/README.md

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-23 21:51:53 +08:00
parent 5df1900ca8
commit 12628c9233
30 changed files with 3546 additions and 247 deletions
+13 -4
View File
@@ -2,8 +2,8 @@
* Silo-wide HTTP request rate limit (ADR-0022 `requestRate`).
*
* Counts dynamic traffic only: APIs, auth, and other application handlers.
* Static SPA assets and the org-admin HTML shell are exempt so a single page
* load (dozens of `/_app/*` chunks + favicon) does not exhaust the minute budget.
* Static SPA assets and the admin HTML shells are exempt so a single page load
* (dozens of `/_app/*` chunks + favicon) does not exhaust the minute budget.
*/
/** Paths that must not consume the silo HTTP request-rate budget. */
@@ -12,12 +12,21 @@ export function isSiloHttpRateLimitExempt(url: string): boolean {
if (path === "/api/healthz") return true;
// SvelteKit build output and top-level static files (see admin/static.ts).
// admin-web SvelteKit build output at the root, and top-level static files
// (see admin/static.ts).
if (path === "/_app" || path.startsWith("/_app/")) return true;
if (path === "/favicon.ico" || path === "/favicon.svg" || path === "/robots.txt") return true;
// SPA index shell for client-side routes (not an API).
// database-admin SvelteKit build output, served under /database (base path;
// see database/static.ts).
if (path === "/database/_app" || path.startsWith("/database/_app/")) return true;
if (path === "/database/favicon.svg" || path === "/database/robots.txt") return true;
// SPA index shells for client-side routes (not APIs). The /database/* shell is
// blanket-exempt like /admin/* since client routes are unknowable up front;
// this also covers the once-per-load /database/config bootstrap.
if (path === "/admin" || path.startsWith("/admin/")) return true;
if (path === "/database" || path.startsWith("/database/")) return true;
return false;
}