Split out of #1053. That issue is now SRI and version only, fixed by #1060.
/docs loads swagger-ui's CSS and JS from cdnjs. On an air-gapped or LAN-only install the page stays blank. The rest of the web UI is embedded with go:embed, so /docs is the only page that needs internet access.
Bundling swagger-ui-dist was turned down in #114 because of binary size (about 1.5 MB gzipped), and so were build tags. This proposal needs neither.
Proposal: an optional setting for where /docs loads the swagger-ui assets from, e.g. GOTIFY_SERVER_SWAGGERUIURL / server.swaggeruiurl in config.yml. It defaults to the current cdnjs path. docs/ui.go would put the setting in front of the three filenames and keep the same integrity hashes. A local mirror would then have to serve byte-identical files for the pinned version, so a changed or wrong-version mirror fails closed rather than running in the app origin.
- No change to binary size or default behaviour.
- An offline user runs something like
npm pack swagger-ui-dist@<pinned> once, hosts the three files on any internal static server (or a reverse proxy path) and sets the URL.
- About ten lines in
docs/ui.go plus a config field.
Workaround until then: /swagger still serves the spec JSON, so an offline Swagger/OpenAPI viewer can load it directly.
If you're open to it I can send the PR or just close this if its still off the table.
Split out of #1053. That issue is now SRI and version only, fixed by #1060.
/docsloads swagger-ui's CSS and JS from cdnjs. On an air-gapped or LAN-only install the page stays blank. The rest of the web UI is embedded withgo:embed, so/docsis the only page that needs internet access.Bundling swagger-ui-dist was turned down in #114 because of binary size (about 1.5 MB gzipped), and so were build tags. This proposal needs neither.
Proposal: an optional setting for where
/docsloads the swagger-ui assets from, e.g.GOTIFY_SERVER_SWAGGERUIURL/server.swaggeruiurlinconfig.yml. It defaults to the current cdnjs path.docs/ui.gowould put the setting in front of the three filenames and keep the sameintegrityhashes. A local mirror would then have to serve byte-identical files for the pinned version, so a changed or wrong-version mirror fails closed rather than running in the app origin.npm pack swagger-ui-dist@<pinned>once, hosts the three files on any internal static server (or a reverse proxy path) and sets the URL.docs/ui.goplus a config field.Workaround until then:
/swaggerstill serves the spec JSON, so an offline Swagger/OpenAPI viewer can load it directly.If you're open to it I can send the PR or just close this if its still off the table.