View raw

1 (** The web tier: routing, authentication, sessions, and CSRF. Functorized over 2 the repository so tests drive it with an in-memory store while production 3 uses SQLite. *) 4 5 module Make (R : Hito_app.Repository.S) (_ : Hito_app.Password_hash.S) : sig 6 type t 7 8 val make : 9 repo:R.t -> 10 ?now:(unit -> Recovery.timestamp) -> 11 ?registration_open:bool -> 12 unit -> 13 t 14 (** [registration_open] exposes the public [/register] routes and the sign-in 15 page's Register link. Defaults to [false]: the deployment runs on 16 pre-seeded accounts until public sign-up returns. *) 17 18 val routes : t -> Dream.route list 19 (** The route table. Session and CSRF middleware are applied per handler. Wrap 20 with {!Dream.sql_sessions} or {!Dream.memory_sessions} and a secret at the 21 top level. *) 22 23 val error_handler : Dream.error_handler 24 (** Renders a branded page for every failure Dream routes here, including 25 unmatched paths and [5xx] responses. Pass to {!Dream.run} 26 [~error_handler]. It leaks no server-supplied string. *) 27 end 28