Decide before a client's networking layer is written (#11, #12); expensive to retrofit after ten screens.
/api/v1/cmd is argv-over-POST. Every read is a POST returning a JSON envelope, which means no ETags, no conditional requests, no HTTP caching, no CDN, and nothing an OS-level URL cache can help with. On a phone that is a real cost: every screen revisit is a full round trip on whatever network the user has.
Options:
a) Keep argv RPC as the only surface. The client caches in its own store and revalidates by polling. Simplest server, most client work, no conditional-request savings.
b) Add a thin GET layer for reads over the same handlers — /api/v1/read? argv=... or a small set of resource paths — returning the same envelopes with ETag and Cache-Control, honouring If-None-Match. Writes stay POST argv. Preserves 'one registry, no drift': the GET layer dispatches the same commands, it does not reimplement them.
Recommendation: (b), scoped to commands already marked ReadOnly, with the ETag derived from the response body hash. That keeps the invariant that every capability exists over SSH and the API never grows its own semantics, while giving a mobile client conditional requests.
closed by commit 65ba14e8f6 by cmc: httpd: GET /api/v1/read for conditional reads
2026-08-27 04:09 UTC