Files
wyucandClaude Opus 5.5 44ad72beba fix(persistence): serve the course library without the agent runtime; exit on invalid boot config
* fix(persistence): serve the course library without the agent runtime

The course library and folder routes (/api/stages/** and /api/folders/**)
gated on isAgentRuntimeConfigured(), so a deployment with server persistence
(DATABASE_URL set, client built with NEXT_PUBLIC_PERSISTENCE=1) but the agent
runtime off answered 404 there: the home library showed an empty,
"persistence unavailable" list and folder creation failed, although imports
persisted.

These routes only need the persistence provider and the owner-bound document
store, so they now gate on isServerPersistenceConfigured(). Agent features
(/api/agent/**, /api/skills/**, /api/materials/**) keep the runtime gate, and
without a DATABASE_URL every route still answers 404.

GET /api/agent/runtime also reports `persistence`; `enabled` and
`runtimeEnabled` are unchanged and the workbench entry still keys on
`enabled`.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(boot): exit the server when boot validation refuses the configuration

Next.js logs a throw from the instrumentation register() hook as "Failed to
prepare server" but keeps listening and answers every request with 500, so a
refused configuration (malformed asset quota, pending TTL or owner lock
waits, PERSISTENCE_SHARED_OWNER_ID without ACCESS_CODE, the removed
OWNER_AUTHENTICATOR / TRUSTED_PROXY_* variables, invalid owner auth or host
hook registrations) left a process that looked alive and served nothing.

The fatal validations now run in one validateBootConfiguration() step. When
it throws, register() calls exitOnInvalidBootConfiguration(), which prints
one "[boot] Invalid server configuration" line carrying the original message,
waits for stderr to flush, and exits with code 1. The wrapper lives in its own
module so tests stub it (or process.exit) and still assert the thrown error.
register() already returns before any validation on the Edge runtime, and
warnings (unset ACCESS_CODE, model-routing checks) never exit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* docs: document library gating and exit on invalid boot configuration

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(boot): tell refused configuration apart from other startup failures

Every throw from the boot validation step was printed as "Invalid server
configuration" with its message only, so a startup failure that has nothing
to do with settings (a module missing from a standalone build, a bug in
startup code, a host registration call that throws) sent operators looking
for a bad environment variable.

Each fatal configuration check now runs through runConfigurationCheck(),
which marks what it throws as an InvalidBootConfigurationError with the same
message. exitOnBootFailure() (renamed from exitOnInvalidBootConfiguration)
keeps the one-line message for those, and prints anything else as
"[boot] Server startup failed" with its stack and cause. Both exit with
code 1.

The README (EN and zh) and CHANGELOG now list exactly the settings the boot
validation refuses, adding OWNER_CLAIM_TRIGGER, the ASSET_S3_BUCKET conflict
with a registered byte store and the sharedTeamAuthMethod() placement rule.
Also fixes a stray comment marker in feature-flags.ts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 17:03:36 +08:00
..