No description
  • TypeScript 99.4%
  • Shell 0.3%
  • HTML 0.1%
  • Dockerfile 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Max Katz-Christy 73a05f1438
All checks were successful
Build and Deploy / build (push) Successful in 35s
Vulnerability scan / vuln-scan (push) Successful in 9s
chore(release): bump version 0.6.0 -> 0.6.1
2026-10-01 00:41:58 +02:00
.forgejo/workflows ci: check out from the public Forgejo URL in the vuln scan 2026-09-30 20:01:18 +02:00
.githooks chore(vendor): re-vendor feed-download and bump the route engine SHAs 2026-09-12 12:33:02 +02:00
.github/workflows ci: add osv-scanner vulnerability gate on GitHub and Forgejo Actions 2026-09-30 19:49:45 +02:00
public feat: repo scaffold and the vendor spine 2026-08-20 03:08:15 +02:00
reference feat(spec): import the GTFS-realtime spec as typed data 2026-08-21 17:02:29 +02:00
scripts ci: add osv-scanner vulnerability gate on GitHub and Forgejo Actions 2026-09-30 19:49:45 +02:00
src fix: load the maplibre worker from a Vite-built URL 2026-10-01 00:14:49 +02:00
.cz.toml chore(release): bump version 0.6.0 -> 0.6.1 2026-10-01 00:41:58 +02:00
.dockerignore chore: add .dockerignore 2026-09-22 13:59:11 +02:00
.gitignore chore: gitignore CURRENT_PLAN.md 2026-09-12 12:40:34 +02:00
CHANGELOG.md chore(release): bump version 0.6.0 -> 0.6.1 2026-10-01 00:41:58 +02:00
CLAUDE.md fix(ui): drop the help cursor from tooltip triggers 2026-09-26 10:04:16 +02:00
Dockerfile feat: repo scaffold and the vendor spine 2026-08-20 03:08:15 +02:00
LICENSE.txt chore: relicense under AGPL-3.0 2026-08-27 15:35:02 +02:00
nginx.conf feat: repo scaffold and the vendor spine 2026-08-20 03:08:15 +02:00
package.json ci: add osv-scanner vulnerability gate on GitHub and Forgejo Actions 2026-09-30 19:49:45 +02:00
pnpm-lock.yaml chore(deps): bump interlocking to v4.0.0 from GitHub, maplibre-gl to ^6 2026-09-30 19:27:24 +02:00
pnpm-workspace.yaml feat: repo scaffold and the vendor spine 2026-08-20 03:08:15 +02:00
postcss.config.js feat: repo scaffold and the vendor spine 2026-08-20 03:08:15 +02:00
README.md feat(account): add sign-out, and drop the vite dev server 2026-09-14 02:02:55 +02:00
TODO.md chore(release): add the commitizen config and prune the closed shared-UI TODOs 2026-09-14 01:17:55 +02:00
tsconfig.json chore(deps): bump interlocking to v4.0.0 from GitHub, maplibre-gl to ^6 2026-09-30 19:27:24 +02:00
VENDORED.md refactor: build the shell on interlocking's shared modules 2026-09-25 00:07:49 +02:00
vite.config.ts refactor: consume the 35 shared modules from interlocking 2026-09-16 00:54:05 +02:00

yard-master

Map-first manager for gtfs.zone feeds, trackers and tracker assignments. Deployed at manage.rt.gtfs.zone, behind oauth2-proxy.

A static Vite/TypeScript/daisyUI app. MapLibre fills the view, a resizable right panel browses the object hierarchy, and every object has an editable properties page. It reads and writes cafe-car's authenticated JSON API at /api/* on the same hostname, so there is no CORS and no token handling: the session cookie oauth2-proxy already set is the whole auth story.

Replaces cafe-car's SQLAdmin interface.

pnpm install
pnpm dev          # watch build into dist/, which the :4180 stack serves
pnpm typecheck
pnpm build
pnpm vendor:check # diff vendored files against coloring-book / test-track
pnpm check-rt-spec     # diff src/gtfs-rt-spec against reference/
pnpm check-alert-enums # hold the alert enums to cafe-car's alert_enums.py
pnpm check             # typecheck plus both of the above

One local door

The music-student stack's http://localhost:4180, where a production build of this app is served by nginx behind the real oauth2-proxy and /api reaches cafe-car on the same origin. Build into the dist/ it bind-mounts:

VITE_RT_BASE=http://localhost:8000 pnpm build --watch

There is no vite dev server. Anything auth-shaped is only real behind the proxy: session expiry, the cookie, the CSRF header on a write, SSE staying open, signing out. A server forging the X-Auth-Request-* headers cannot fail the way production does, so it would only ever hand out a verdict worth ignoring.

VITE_RT_BASE is what points a path-only feed URL at the local feed server. A watch build is a production build, so CONFIG.RT_BASE's dev branch never fires and without the variable the app resolves against rt.gtfs.zone.

See CURRENT_PLAN.md for the build-out plan.