ARTEX 현재 시스템 문서
전체 문서
이 페이지 목차

HTTP server·SSE·Web UI 모듈

Go http.ServeMux가 261개 API operation을 등록하고 /api/*에 CORS와 JWT wrapper를 적용한 뒤, 나머지 경로에는 embedded Next.js static export를 제공한다. Web client는 web/src/lib/api.ts의 fetch helper와 여러 SSE 경로로 같은 API를 소비한다. Operation 전수는 API 독립 진입, source provider는 58개 handler group, request/response는 semantic schema를 본다.

Router와 middleware

Router와 middleware · 관계

이 대상이 사용하는 구현·계약·의존 · 2개

이 대상을 사용하는 기능·모듈·계약 · 1개

전체 관계 3개 · 종류 선택·관계도

/api/*

auth/* or health

valid JWT

missing/invalid

other

HTTP request

path

CORS

requireAuth

public handler

API ServeMux

JSON 401

embedded static UI handler

JSON/file response

SSE stream

그림 크게 보기
Mermaid 원문
flowchart TD
  Request[HTTP request] --> Root{path}
  Root -->|/api/*| CORS[CORS]
  CORS --> Auth[requireAuth]
  Auth -->|auth/* or health| Public[public handler]
  Auth -->|valid JWT| Mux[API ServeMux]
  Auth -->|missing/invalid| E401[JSON 401]
  Root -->|other| UI[embedded static UI handler]
  Mux --> JSON[JSON/file response]
  Mux --> SSE[SSE stream]

  click Auth "../security-boundaries.md#auth-boundary" "인증 경계"
  click Mux "../contracts/http-ui.md#route-families" "API 영역"
  click UI "#ui-routes" "UI route"

/api/auth/*와 /api/health는 wrapper 예외다. change-password는 예외 route 안에서 token과 현재 password를 직접 검증한다. 그 외 /api/*는 Bearer, artex_token cookie 또는 query token 중 하나를 읽는다. UI static file 자체는 공개이며 데이터 권한은 API가 강제한다. Router Auth

응답과 후속 완료

응답과 후속 완료 · 관계

이 대상이 사용하는 구현·계약·의존 · 1개

이 대상을 사용하는 기능·모듈·계약 · 2개

전체 관계 3개 · 종류 선택·관계도
응답 형태 의미 추가 확인
일반 2xx JSON 해당 handler의 동기 단계 완료 background engine/worker/external delivery가 남는지 operation별 확인
archive/action queue 응답 persistent job 접수 archive state/phase/progress/error
task create response task row/runtime launch 요청 admission queue, goal decomposition, engine 상태
chat/message response session 실행 경로의 handler 결과 activity/terminal/cancel 상태
SSE open stream 연결과 cursor 전달 최종 event/재연결·gap 처리
file/download server가 bytes를 전송 client 저장·외부 제출 완료는 아님
update apply/rollback stage/restart protocol 시작 supervisor relaunch와 settle/rollback

SSE cursor와 인증

SSE cursor와 인증 · 관계

이 대상이 사용하는 구현·계약·의존 · 1개

전체 관계 1개 · 종류 선택·관계도

Activity, logs, update, side-question event 등은 장기 HTTP stream을 사용한다. frontend EventSource는 이 네 경로에 query token을 붙이며 reverse proxy buffering을 꺼야 실시간 event가 보인다. 서버 extractToken의 query fallback은 SSE 외 보호 API에도 적용된다. History endpoint와 cursor를 함께 사용해 reconnect gap을 채우는 경로가 있고, UI의 현재 화면 auto-refresh가 서버 event 보존 전체를 대신하지 않는다. Activity stream

Query token은 URL/access log/referrer 노출 가능성이 있어 HTTPS와 log redaction이 필요하다. Same-origin production과 cross-origin development의 CORS/cookie 동작을 구분한다.

Next.js 사용자 영역

Next.js 사용자 영역 · 관계

이 대상이 사용하는 구현·계약·의존 · 1개

전체 관계 1개 · 종류 선택·관계도
UI 영역 주요 route 소비 API/상태
setup/login /setup, /login auth status/init/login, local token
dashboard /dashboard stats, token usage, recent task/activity
tasks /function/tasks, detail task CRUD/control, goals/constraints, sessions, graph, coverage, archive
findings /function/findings finding groups/tree/detail/retest/evidence/export
assets /function/assets assets, companies/scope, ScopeSentry sync
traffic /function/traffic exchange filters/detail/body/delete
chat /chat conversations/messages/side questions/uploads
agents/tools/skills/MCP system pages runtime catalog, prompts, visibility, triggers
LLM/settings system pages profiles/pool/retry/search/proxy/update/config
intercept/asset intercept system pages rules, pending/history/execution/judge
notifications/logs/records system pages channel/delivery, logs, LLM records/usage

화면 route는 API operation이나 authorization boundary가 아니다. 같은 API를 다른 화면과 agent tool이 소비할 수 있고, UI에 노출되지 않은 route도 등록돼 있다. 27개 page.tsx entry와 화면별 wrapper/API/SSE/state/error 소비는 프런트엔드 소비 지도가 소유한다. Web API client Web layout

Client token·cache·navigation

Client token·cache·navigation · 관계

이 대상이 사용하는 구현·계약·의존 · 1개

전체 관계 1개 · 종류 선택·관계도

Frontend auth helper는 token을 localStorage와 JavaScript-readable cookie에 저장한다. API helper가 Authorization header를 구성하고, SSE는 필요할 때 query token을 사용한다. Cookie에는 HttpOnly를 적용할 수 없고 Secure 여부도 배포 경로에 따라 달라져 XSS·HTTP 배포 위험을 고려해야 한다. Web auth

Task detail의 polling/SSE, finding/traffic pagination, graph UI의 local expansion은 view state다. 서버 DB state와 충돌하면 새 fetch/stream cursor를 기준으로 다시 확인해야 한다.

Code-first API 계약의 한계

저장소에는 OpenAPI/GraphQL/proto 명세가 없다. 실제 등록 route, inline request struct, DTO/JSON marshal, handler error branch와 web client type이 계약 원본이다. API 전수 참조는 등록 261개를, 요청·응답 semantic 참조는 field와 직접 variant를 모두 목적지로 제공한다. 다음은 P/U 표시와 원본 대조가 필요하다.

실패 조건

상위 영역: ARTEX 현재 시스템 지도

전체로 돌아가기 · Markdown 원본

검색을 열면 색인을 읽습니다.

등록한 문서 본문에서 검색합니다.