Register the chi routes as flat absolute paths (httpBase+"/slots" …)
instead of a nested r.Route mount: the wasm host forwards the full
original path with no prefix strip, so the nested mount's RoutePath
rebasing never matched and 404'd the entire HTTP surface.
Declare allowed_hosts = ["api.cal.com"] so the ADR-0023 install consent
dialog asks the admin to grant egress; without it every Cal.com call was
denied at runtime (ABI_ERROR_CODE_EGRESS_DENIED, no egress grant).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The v2.0.5 captchaEnabled editor toggle (fe5d117) changed web/src but never
rebuilt the committed web/dist. Rebuild so the shipped bundle matches source.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Convert the bundled backend/internal/plugins/calcomblock package into a
standalone reactor-mode wasm plugin, dropping every git.dev.alexdunmow.com/block/cms
import (forbidden in standalone plugins):
- package calcomblock -> package main; add wasip1 main.go with
wasmguest.Serve(Registration). go.mod module
git.dev.alexdunmow.com/block/calcomblock, block/core v0.18.2, no replace
directives.
- Settings persistence: replace the pool-backed poolQuerier (direct SQL against
the public-schema `settings` table, which a sandboxed plugin role cannot read)
with capabilityQuerier over the SDK settings.Settings / settings.Updater
capabilities. GetSiteTimezone now resolves via GetSiteSettings host-side.
- Vendor the small CMS-internal helpers the plugin used into internal/helpers
(GetRealIP, StartCleanupLoop, MaskSecret, GetStringOr, the PluginSettingsQuerier
settings helpers, PluginCrypto for tests) and internal/db (minimal Setting /
UpsertSettingParams), each with a provenance header.
- Inline the captcha widget: vendor blocks.CaptchaWidget as a local
CaptchaWidget templ (captcha_widget.templ) and regenerate templ; drop the
block/cms/blocks import from booking.templ.
- blockConfig (server-authoritative captcha requirement via a
page_block_snapshots scan) has no wasm-ABI capability, so it is left nil:
honeypot + per-IP rate limit still apply. Documented as a follow-up.
- web: @block-ninja/ui workspace:* -> ^0.1.0 registry version; eslint.config.js
repointed at ../../../cms/web/eslint.config.js; rebuild web/dist.
- Rewrite CLAUDE.md for the standalone wasm reality; add .gitignore.
Full test suite preserved and passing; builds to calcomblock-2.0.0.bnp;
check-safety passes.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>