# ── build the WebAssembly client ────────────────────────────────────────────
# emsdk 4.0.x or newer is REQUIRED, not merely preferred: the client is built
# with -sUSE_SDL=3 and the SDL3 port does not exist in older Emscripten. On
# 3.1.61 the ports directory contains sdl2* only, and the build dies with
# "SDL3/SDL.h file not found" partway through.
#
# Pinned to BUILDPLATFORM, not TARGETPLATFORM. WebAssembly is architecture
# independent, so this stage should run ONCE on the builder's own arch no
# matter how many platforms the final image targets. Without the pin, a
# multi-arch build would run this entire toolchain under qemu for arm64, which
# is both pointless and extremely slow, and would fail outright: the protoc
# release fetched below is a linux-x86_64 binary.
FROM --platform=$BUILDPLATFORM emscripten/emsdk:4.0.15 AS build

# protoc must be a 21.x release to match the protobuf v21.12 runtime that
# CMakeLists.txt fetches. Distro packages are the trap here: Ubuntu 22.04
# ships 3.12.4, which generates headers the v21.12 runtime rejects with
# "generated by an older version of protoc". Pin the release binary instead
# of trusting apt.
ARG PROTOC_VERSION=21.12
RUN apt-get update \
 && apt-get install -y --no-install-recommends unzip curl ca-certificates \
 && curl -fsSL -o /tmp/protoc.zip \
      "https://github.com/protocolbuffers/protobuf/releases/download/v${PROTOC_VERSION}/protoc-${PROTOC_VERSION}-linux-x86_64.zip" \
 && unzip -q /tmp/protoc.zip -d /usr/local \
 && rm /tmp/protoc.zip \
 && rm -rf /var/lib/apt/lists/* \
 && protoc --version

WORKDIR /src
COPY . .

RUN mkdir -p build && cd build \
 && emcmake cmake -DCMAKE_BUILD_TYPE=Release .. \
 && emmake make -j"$(nproc)" c_based_trader_client

# Four artifacts, not three. index.data holds the fonts preloaded via
# --preload-file (CMakeLists.txt), and the app renders nothing without it.
RUN cd build && test -f index.html && test -f index.js \
 && test -f index.wasm && test -f index.data

# Load the runtime config before the Emscripten glue. Injecting straight
# after <head> guarantees it runs before any script the shell emits, so
# window.__EDGEDEPTH_WS_URL__ is set by the time main() reads it.
RUN cd build \
 && sed -i 's|<head>|<head>\n<script src="edgedepth-config.js"></script>|' index.html \
 && grep -q 'edgedepth-config.js' index.html

# ── serve ───────────────────────────────────────────────────────────────────
FROM nginx:1.27-alpine

COPY docker/nginx.conf /etc/nginx/conf.d/default.conf
COPY docker/entrypoint.sh /usr/local/bin/entrypoint.sh
RUN chmod +x /usr/local/bin/entrypoint.sh

COPY --from=build /src/build/index.html  /usr/share/nginx/html/
COPY --from=build /src/build/index.js    /usr/share/nginx/html/
COPY --from=build /src/build/index.wasm  /usr/share/nginx/html/
COPY --from=build /src/build/index.data  /usr/share/nginx/html/
# shell.html references this, so omitting it makes the browser fetch a missing
# file. nginx sets COOP and COEP itself, making the worker redundant here, but
# it is the fallback that keeps the app working behind a reverse proxy that
# strips those headers.
COPY --from=build /src/build/coi-serviceworker.js /usr/share/nginx/html/

EXPOSE 8080

ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
CMD ["nginx", "-g", "daemon off;"]
