archivebox.core.views
Module Contents
Classes
Admin-only handoff that lets a snap host mint its own replay cookie. |
|
Serve snapshots by the new URL scheme: / |
|
Serve snapshot directory contents on |
|
Serve snapshot directory contents on a one-domain replay path. |
|
Serve responses from the most recent snapshot when using |
|
Serve original-domain replay content on a one-domain replay path. |
|
Keep browsing responsive while the same small server is archiving. |
|
A Django view that renders plain text “OK” for service discovery tools |
Functions
Only allow same-snap relative replay paths; grants must never redirect off-host. |
|
A replay cookie is not its own auth source; it must point at a live admin session. |
|
Resolve a declared output path and its exact historical fallbacks. |
|
Render an explicit plugin full template as a trusted preview wrapper. |
|
Serve the existing card template from the snapshot origin, not web.*. |
|
Data
API
- archivebox.core.views._files_index_target(snapshot: archivebox.core.models.Snapshot, archivefile: str | None) str[source]
- archivebox.core.views._find_snapshot_by_ref(snapshot_ref: str) archivebox.core.models.Snapshot | None[source]
- archivebox.core.views._replay_cookie_name(snapshot: archivebox.core.models.Snapshot) str[source]
- archivebox.core.views._clean_replay_next(path: str | None) str[source]
Only allow same-snap relative replay paths; grants must never redirect off-host.
- archivebox.core.views._replay_payload_is_valid(payload: dict, snapshot: archivebox.core.models.Snapshot) bool[source]
A replay cookie is not its own auth source; it must point at a live admin session.
Replayed pages can execute hostile JS, so admin cookies stay host-only on admin.. The snap host gets only this host-only HttpOnly cookie, and every request checks that the original Django session still exists and still belongs to an active staff user. Logout, session expiry, user deletion/deactivation, or password auth-hash rotation all make the replay cookie inert without needing admin. to delete a cookie on snap-*.
- archivebox.core.views._has_replay_cookie(request: django.http.HttpRequest, snapshot: archivebox.core.models.Snapshot) bool[source]
- archivebox.core.views._private_snapshot_auth_redirect(request: django.http.HttpRequest, snapshot: archivebox.core.models.Snapshot, path: str = '', *, preserve_query: bool = True)[source]
- archivebox.core.views._replay_auth_response(request: django.http.HttpRequest, snapshot: archivebox.core.models.Snapshot)[source]
- class archivebox.core.views.SnapshotReplayAuthView[source]
Bases:
django.views.ViewAdmin-only handoff that lets a snap host mint its own replay cookie.
admin.* cannot set a host-only cookie for snap-* (browsers forbid that), and widening the real Django session cookie to .archivebox.localhost would let XSS in replayed pages hit the admin UI. Instead admin. proves the user is logged in with a short URL grant, then snap-* validates it and sets a snap-host-only cookie.
- class archivebox.core.views.SnapshotView[source]
Bases:
django.views.View- static find_snapshots_for_url(path: str, *, allow_fallback: bool = True)[source]
Return a queryset of snapshots matching a URL-ish path. URL only — never tries ID matching.
Use
find_snapshots_for_idseparately if you also want to match by snapshot UUID.
- static find_snapshots_for_id(slug: str)[source]
Return a queryset of snapshots matching a (possibly truncated) UUID via prefix or suffix.
Strips non-hex characters from
slug(so input with or without hyphens both work). Requires at least 8 hex chars — shorter inputs return an empty queryset to avoid scanning the entire snapshots table on too-broad matches.
- class archivebox.core.views.SnapshotPathView[source]
Bases:
django.views.ViewServe snapshots by the new URL scheme: /
/ / / /…
- archivebox.core.views._resolve_archiveresult_relpath(snapshot: archivebox.core.models.Snapshot, rel_path: str) tuple[str, archivebox.core.models.ArchiveResult | None, tuple[str, ...]][source]
Resolve a declared output path and its exact historical fallbacks.
- archivebox.core.views._plugin_full_preview_response(request: django.http.HttpRequest, snapshot: archivebox.core.models.Snapshot, rel_path: str, result: archivebox.core.models.ArchiveResult | None) django.http.HttpResponse | None[source]
Render an explicit plugin full template as a trusted preview wrapper.
- archivebox.core.views._plugin_card_document_response(request: django.http.HttpRequest, snapshot: archivebox.core.models.Snapshot, result_id: str) django.http.HttpResponse[source]
Serve the existing card template from the snapshot origin, not web.*.
srcdoc and inline card scripts inherit the containing page’s origin. This frame route gives them same-origin access to this snapshot’s saved files without opening CORS on raw archives or sharing the admin session cookie. The parent web page receives only the one-bit login hint; delete buttons navigate to admin.* for a real authenticated confirmation.
- archivebox.core.views._visible_response_snapshots_for_domain(request: django.http.HttpRequest, domain: str) list[archivebox.core.models.Snapshot][source]
- archivebox.core.views._latest_response_match(snapshots: list[archivebox.core.models.Snapshot], domain: str, rel_path: str) tuple[archivebox.core.models.Snapshot, pathlib.Path, pathlib.Path] | None[source]
- archivebox.core.views._latest_responses_root(snapshots: list[archivebox.core.models.Snapshot], domain: str) tuple[archivebox.core.models.Snapshot, pathlib.Path] | None[source]
- archivebox.core.views._original_request_url(domain: str, path: str = '', query_string: str = '') str[source]
- archivebox.core.views._serve_responses_path(request, responses_root: pathlib.Path, rel_path: str, show_indexes: bool)[source]
- archivebox.core.views._build_snapshot_replay_response(request: django.http.HttpRequest, snapshot: archivebox.core.models.Snapshot, path: str = '')[source]
- archivebox.core.views._serve_snapshot_replay(request: django.http.HttpRequest, snapshot: archivebox.core.models.Snapshot, path: str = '')[source]
- archivebox.core.views._serve_original_domain_replay(request: django.http.HttpRequest, domain: str, path: str = '')[source]
- class archivebox.core.views.SnapshotHostView[source]
Bases:
django.views.ViewServe snapshot directory contents on
.<listen_host>/ .
- class archivebox.core.views.SnapshotReplayView[source]
Bases:
django.views.ViewServe snapshot directory contents on a one-domain replay path.
- class archivebox.core.views.OriginalDomainHostView[source]
Bases:
django.views.ViewServe responses from the most recent snapshot when using
.<listen_host>/ .
- class archivebox.core.views.OriginalDomainReplayView[source]
Bases:
django.views.ViewServe original-domain replay content on a one-domain replay path.
- class archivebox.core.views.PublicIndexView[source]
Bases:
django.views.generic.list.ListViewKeep browsing responsive while the same small server is archiving.
Performance takes priority over perfect initial totals: on a 1 vCPU / 1 GB host with hundreds of thousands of snapshots, even an indexed count can consume the entire roughly 0.5-0.7 second page-load budget. Benchmark with the runner active, since it shares the CPU, memory, and SQLite database.
The unfiltered list therefore renders rows first and accepts missing/stale display totals. A later ordinary reload can show the background-cached count; do not restore a synchronous COUNT or add polling just to fill it in.
- _ordered_public_page_from_order_index(*, page_number: int, page_size: int) list[archivebox.core.models.Snapshot][source]
- class archivebox.core.views.AddView[source]
Bases:
django.contrib.auth.mixins.UserPassesTestMixin,django.views.generic.FormView- _get_custom_config_overrides(form: archivebox.core.forms.AddLinkForm) dict[source]
- _create_crawl_from_form(form, *, created_by_id=None) archivebox.crawls.models.Crawl[source]
- class archivebox.core.views.HealthCheckView[source]
Bases:
django.views.ViewA Django view that renders plain text “OK” for service discovery tools