Skip to content

static

tit.server.static

Serve the UI bundle at / (SPA fallback) or a minimal status page.

The bundle directory is checked on every request so a bundle built after the server started is picked up without a restart. Non-/api, non-/ws, non-/auth paths fall back to index.html; the bundle directory is a jail (resolved paths must stay inside it). The status page is unauthenticated, so it discloses nothing about the runtime.

resolve_static_file

resolve_static_file(static_dir: str, path: str) -> Path | None

File under static_dir for path, or None (missing / escapes the jail).

Source code in tit/server/static.py
def resolve_static_file(static_dir: str, path: str) -> Path | None:
    """File under *static_dir* for *path*, or ``None`` (missing / escapes the jail)."""
    root = os.path.realpath(static_dir)
    candidate = os.path.realpath(os.path.join(root, path or "index.html"))
    if candidate == root:
        return Path(root) if os.path.isfile(root) else None
    if candidate.startswith(root.rstrip(os.sep) + os.sep):
        return Path(candidate) if os.path.isfile(candidate) else None
    return None