Add Sycamore/WASM frontend and restructure into server/ + web/

Repo is now a monorepo:

- server/: the kaya backend, unchanged in behaviour, plus:
  - GET /api/me for SPA session detection
  - last_move recorded on every play and broadcast in the game state, so
    clients can show who played which card the moment they play it
  - legal_moves per hand card for the player on turn (rules stay
    server-side)
  - static catch-all route serving the compiled SPA with index.html
    fallback; Tortoise context now bound only for /api/* requests
  - configurable OIDC post-login/logout redirects for dev against trunk
- web/: Sycamore 0.9 + WASM frontend (trunk): login via the OIDC flow,
  lobby (create match / join by code), live game page over websocket with
  card images (CC0 woodcut napoletane deck), capture picker, move banner,
  game-over overlay, match history and leaderboard pages
- server/Dockerfile gains a rust+trunk stage building web/dist; the single
  app image serves the SPA; compose builds from the repo root with
  overridable ports/OIDC env

Verified end-to-end against the compose stack: four OIDC logins, game
creation, three joins by code, websocket play with broadcasts to all
players and out-of-turn rejection. 51 backend tests, mypy and cargo tests
all green.
This commit is contained in:
2026-09-16 13:20:05 +08:00
parent e9ddb82e9a
commit 96a95d74b6
104 changed files with 151484 additions and 236 deletions
+13 -7
View File
@@ -28,7 +28,7 @@ services:
# Derived image baking dev/mockoauth/config.json in (see
# dev/mockoauth/Dockerfile) — a bind mount would not work against
# containerized docker daemons.
build: ./dev/mockoauth
build: ./server/dev/mockoauth
environment:
SERVER_PORT: "8180"
LOG_LEVEL: INFO
@@ -63,7 +63,9 @@ services:
# One-shot: applies pending aerich migrations before the app starts
# (build cache makes the second build of the same Dockerfile instant).
db-migrate:
build: .
build:
context: .
dockerfile: server/Dockerfile
# aerich reads [tool.aerich] from /app/pyproject.toml (default config
# file) and finds migrations in ./migrations relative to working_dir.
working_dir: /app
@@ -75,7 +77,9 @@ services:
condition: service_healthy
scopa:
build: .
build:
context: .
dockerfile: server/Dockerfile
depends_on:
postgres:
condition: service_healthy
@@ -87,15 +91,17 @@ services:
condition: service_healthy
environment:
DATABASE_URL: postgres://scopa:scopa@postgres:5432/scopa
OIDC_ISSUER: http://mockoauth:8180/scopa
# By default the app and browsers reach the mock IdP under the same
# name (see README /etc/hosts note); override OIDC_ISSUER and
# OIDC_REDIRECT_URI to use a real provider or a different host port.
OIDC_ISSUER: ${OIDC_ISSUER:-http://mockoauth:8180/scopa}
# The mock OIDC server does not validate clients: any id/secret works.
OIDC_CLIENT_ID: scopa
OIDC_CLIENT_SECRET: ${OIDC_CLIENT_SECRET:-dev-secret}
# Browser-facing callback: the app is published on host port 8080.
OIDC_REDIRECT_URI: http://localhost:8080/auth/callback
OIDC_REDIRECT_URI: ${OIDC_REDIRECT_URI:-http://localhost:8080/auth/callback}
REDIS_URL: redis://redis:6379/0
ports:
- "127.0.0.1:8080:8080"
- "127.0.0.1:${APP_PORT:-8080}:8080"
volumes:
pgdata: