Phase 4: move catalog controllers and routes into WarpEngine

- update, files and the 6 /api catalog controllers now live in the engine on
  a new WarpEngine::ApiController base (same rescue/mime behavior as host)
- engine routes serve /update, /file/*path, /api/software*, /api/builds*,
  /api/image/:id, /api/download at unchanged public paths via the root mount;
  host routes keep only TTG endpoints (events, members, wiki, rss, swagger)
- /update secret comes from WarpEngine.config.update_secret and an
  unconfigured secret now rejects every request (previously an empty
  UPDATE_SECRET env accepted empty secrets)
- apipie-rails is an engine dependency (DSL in engine controllers); dummy app
  configures apipie with validation off, mirroring the host
- engine request specs: catalog controller specs moved from host plus new
  /update auth contract spec

Verified: engine suite 53 green, host suite 6 green, /api/software and
/api/builds byte-identical to baselines, /update 401/400 behavior intact,
admin and TTG endpoints OK.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-04 19:09:11 +02:00
co-authored by Claude Fable 5
parent 0dc3cebc14
commit b79a73d62d
28 changed files with 349 additions and 234 deletions
+1
View File
@@ -2,6 +2,7 @@ PATH
remote: ../libs/ruby/warp_engine
specs:
warp_engine (0.1.0)
apipie-rails
blueprinter
rails (>= 8.0)
rubyzip (~> 2.3)