project-nomad/admin/app/services
chriscrosstalk cdf6c00d4c
feat: support gated downloads for self-hosted curated content (#1172)
Adds an optional `auth: 'nomad_app_key'` discriminator to curated manifest
resources so a curated collection tier can carry content we host ourselves,
gated to official release builds. Without this, only Creator Packs could use
the entitlement Worker; curated tier installs always downloaded
unauthenticated.

No behaviour change for any existing manifest entry: absent `auth` means
unauthenticated, exactly as today.

- `auth` declared on both the type and the VineJS validator. It has to be on
  the validator or VineJS strips it silently on fetch, and the gated download
  would then go out with no header and 401 for everyone. A dedicated spec
  guards that regression.
- Gated resources are pinned to their manifest URL (resolveZimDownload skips
  the catalog comparison) and excluded from catalog update checks, so a
  resource-id collision cannot let a third-party mirror overwrite our content.
  Consequence, commented rather than implied: gated content does not
  auto-update; new versions ship via the manifest.
- 401/403 on a download now reports that an official build is required instead
  of a raw axios status, which is what a fork build will hit.
- The pure `isGatedResource` predicate is deliberately split from the
  env-reading header builder: importing `#start/env` into
  zim_download_resolution triggers env validation at import time and breaks its
  unit tests.

Reuses CREATOR_PACKS_APP_KEY rather than minting a second secret — the question
it answers ("is this an official build?") is identical for both content types.

Verified end to end on a test server: `auth` survives validation into the
cached spec, the Bearer header attaches to only the gated resource, the file
lands byte-exact with an installed_resources row and a Kiwix library entry, and
an entry with a gated URL but no `auth` field fails with the intended message.

No catalog entry is included here. Manifests are fetched live from `main`, so a
gated entry must not merge until this ships and is adopted — pre-`auth` builds
strip the field and 401.

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-04 03:39:55 +00:00
..
app_auto_update_service.ts feat(supply-depot): opt-in automatic updates for installed apps 2026-06-23 04:46:52 +00:00
auto_update_service.ts feat(supply-depot): opt-in automatic updates for installed apps 2026-06-23 04:46:52 +00:00
benchmark_service.ts fix(benchmark): don't block submission when the AI host is this machine (#1166) 2026-08-04 03:39:55 +00:00
benchmark_telemetry.ts feat(benchmark): end-of-run score reveal + NVIDIA GPU-util overlay (#1087) 2026-08-04 03:37:40 +00:00
chat_service.ts fix(chat): prefer selected model for suggestions, fall back to smallest 2026-06-23 04:47:00 +00:00
collection_manifest_service.ts feat: support gated downloads for self-hosted curated content (#1172) 2026-08-04 03:39:55 +00:00
collection_update_service.ts feat: support gated downloads for self-hosted curated content (#1172) 2026-08-04 03:39:55 +00:00
condition_service.ts Add offline FDA drug reference (labels, interaction view, conditions, remedies) (#1040) 2026-08-04 03:38:33 +00:00
container_registry_service.ts fix(updates): resolve relative registry pagination URL so tag listing doesn't crash (#945) 2026-06-23 04:46:59 +00:00
content_auto_update_service.ts Add offline FDA drug reference (labels, interaction view, conditions, remedies) (#1040) 2026-08-04 03:38:33 +00:00
countries_service.ts feat(Maps): regional map downloads via go-pmtiles extract (#780) 2026-05-20 10:16:00 -07:00
creator_pack_service.ts feat(creator-packs): gated per-creator video packs, offline via Kiwix (#1106) 2026-08-04 03:38:27 +00:00
custom_app_guard.ts feat: supply depot 2026-06-23 04:46:45 +00:00
docker_service.ts fix(amd): coerce gfx1103 (780M) to HSA_OVERRIDE 11.0.0 so it stays on GPU (#1134) 2026-08-04 03:38:36 +00:00
docs_service.ts docs: update in-app docs for v1.33 Supply Depot + auto-updates 2026-06-23 04:47:04 +00:00
download_service.ts Add offline FDA drug reference (labels, interaction view, conditions, remedies) (#1040) 2026-08-04 03:38:33 +00:00
drug_reference_service.ts Add offline FDA drug reference (labels, interaction view, conditions, remedies) (#1040) 2026-08-04 03:38:33 +00:00
kiwix_catalog_service.ts feat(content): opt-in automatic updates for installed ZIM & map content 2026-06-23 04:47:01 +00:00
kiwix_library_service.ts fix(kiwix): self-heal a missing or corrupt library XML on startup 2026-06-23 04:46:56 +00:00
map_service.ts fix(maps): warn when world basemap missing instead of silent grey map (#1104) 2026-08-04 03:38:29 +00:00
nomad_md_service.ts feat(AI): nomad.md for custom instructions (#1127) 2026-08-04 03:38:33 +00:00
ollama_service.ts feat(AI): per-model thinking toggle with global default (off) (#1079) 2026-08-04 03:38:29 +00:00
queue_service.ts fix(queue): share one ioredis connection across BullMQ queues and workers (#1009) 2026-06-23 04:47:08 +00:00
rag_service.ts fix(rag): stop re-creating payload indexes on every embedded document (#1135) 2026-08-04 03:38:36 +00:00
system_service.ts feat(debug-info): add storage, docker, GPU health, and auto-update diagnostics (#1102) 2026-08-04 03:37:36 +00:00
system_update_service.ts feat(system): add opt-in automatic updates for the core NOMAD app 2026-06-23 04:46:51 +00:00
zim_extraction_service.ts chore(KB): filter non-content sections + render tables in ZIM extraction (#1044) 2026-08-04 03:37:30 +00:00
zim_service.ts feat: support gated downloads for self-hosted curated content (#1172) 2026-08-04 03:39:55 +00:00