feat(proxy): add a read-only dashboard at /_slp/ #17
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/dashboard"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What
A read-only status page at
/_slp/for a person: what SLP is doing, how it is configured, and what it has been up to lately.retry,aggregate,expect/gating, backend or edition, plus version, listen address, uptime, logging, and the allow list.The SLP version is in the tab title, beside the heading, and in the settings. The page refreshes every 5 seconds, pauses while text is selected, and works as a snapshot without scripts.
Access
X-Forwarded-For,X-Real-IP, andForwarded; one that does not parse is a refusal.curl localhost:8080/_slp/on the SLP host is a 404 until127.0.0.0/8is added.allowlist is a startup error.What it does not show
?debugrule).X-Request-Id; a request matching no route is "unknown model", not the name.GET-only, served under a content security policy with no inline script or style.
Worth a look in review
/_slp/there or turn the dashboard off.config.Routeandproxy.RoutegainEditionOf.slp_requests_totallabel is unchanged.Testing
go vetandgo test -race ./...pass. New tests cover the allow-list table (including forged and unparseable forwarding headers), refusal being indistinguishable from a disabled dashboard, and a leak test that drives marked secrets through the proxy and asserts none reach the page. Also run against fake backends and checked in headless Chromium at desktop, dark, and phone widths; not yet run against a real deployment behind Caddy.🤖 Generated with Claude Code
Automated review by pr-reviewer v0.52.3 | Safety Check | Ministral 3 Instruct | tracking id
r-bf3ec8-12f727This is an AI-generated review and may contain mistakes.
Status: ❌ Failed
This review couldn't be completed: that model isn't loaded on the inference service right now, and no alternate model was able to review it either. Consider splitting this PR into smaller changes. Tracking id
r-bf3ec8-12f727.Comment
@pr-reviewer-bot retryto try again.