gitoriaLog in with ident

gitoria

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Branchmain4f47843egate: ticket links use the tickets short URL (/<slug>/<n>, tickets#25)mremain/lib/api.hl

6.3 KB

  1. // lib/api.hl — THE FUNCTION ROUTES (project.hl wires them): thin wrappers — check the request and the session, call the
  2. // topic, answer. The plumbing (JSON / Markdown / plain answers, redirects, the ssh guard, `?next=`) is lib/api-helpers.hl.
  3. // /api/repos, /api/repos/:slug the public reads (repos.hl; Accept: text/markdown → the Markdown read view)
  4. // /login/callback the login button's return (users.hl)
  5. // /settings/connect, /settings/connected connecting a repo to a tickets project (tickets.hl)
  6. // /__git/keys, /__git/access what the sshd container asks (sshkeys.hl, repos.hl)
  7. // (The git protocol's routes are lib/transport.hl gitTransport.)
  8. // A route that WRITES THE SESSION gets the request and the framework's session store BY REFERENCE (`&req`, `&sessions`,
  9. // from project.hl): copied into a second call, the session inside `req` would be a copy too and the write would be lost.
  10. import { Response } from 'hl:http1'
  11. import { randomBytes } from 'hl:crypto'
  12. import { NL } from './util.hl'
  13. import { userOfLoginCode } from './users.hl'
  14. import { repoRows, repoRow, repoBySlug, ownsRepo, mayPush } from './repos.hl'
  15. import { slugError, repoDocument, listDocument } from './repos-helpers.hl'
  16. import { connectHref, finishConnect } from './tickets.hl'
  17. import { keyLine } from './sshkeys.hl'
  18. import { fail, wantsMarkdown, markdownReply, textReply, goTo, sshGuard, repoOfRequest, safeNext } from './api-helpers.hl'
  19. // ---- the API: reads are public (creating a repo is a web action for now) ------------------------
  20. static apiRepos = (route, req) => {
  21. if (req.method != 'GET') { return fail(405, 'GET only') }
  22. rows = repoRows()
  23. if (wantsMarkdown(req)) { return markdownReply(listDocument(rows)) }
  24. return { repos = rows }
  25. }
  26. static apiRepo = (route, req) => {
  27. if (req.method != 'GET') { return fail(405, 'GET only') }
  28. row = repoRow(route.params.slug)
  29. if (row == null) { return fail(404, 'no such repository') }
  30. if (wantsMarkdown(req)) { return markdownReply(repoDocument(row)) }
  31. return row
  32. }
  33. // ---- THE LOGIN BUTTON'S RETURN (ident README "How apps use ident") ----------------------------
  34. // ident sends the browser back with ?ident_code= (and our ?next=); the code is exchanged here (users.hl userOfLoginCode),
  35. // the user goes into THIS browser's session (`req.session`, the cookie's — hybriel #11; minted when it brought none),
  36. // then → `?next=` (api-helpers.hl safeNext). A FAILED LOGIN is a page (components/loginfailed.hl): the reason is parked
  37. // in the session, then → /login/failed.
  38. static loginFailed = (&req, &sessions, why) => {
  39. let s = req.session
  40. fresh = s == null
  41. if (fresh) { s = sessions.mint() }
  42. s.data.loginError = why
  43. sessions.save(s)
  44. res = new Response('login failed: ' + why, { status = 302 headers = { 'Location' = '/login/failed' 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  45. if (fresh) { res.headers['Set-Cookie'] = sessions.cookieHeader(s.id) }
  46. return res
  47. }
  48. static loginCallback = (route, &req, &sessions) => {
  49. if (req.method != 'GET') { return loginFailed(&req, &sessions, 'GET only') }
  50. q = req.query != null ? req.query : {}
  51. code = q.ident_code
  52. if (code == null || code == '') { return loginFailed(&req, &sessions, 'ident sent no login code') }
  53. x = userOfLoginCode(code)
  54. if (x.error != null) { return loginFailed(&req, &sessions, x.error) }
  55. let s = req.session
  56. fresh = s == null
  57. if (fresh) { s = sessions.mint() }
  58. s.user = { id = x.user.id }
  59. s.data.tag = randomBytes(16)
  60. s.data.loginError = null
  61. sessions.save(s)
  62. res = new Response('logged in', { status = 302 headers = { 'Location' = safeNext(q.next) 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  63. if (fresh) { res.headers['Set-Cookie'] = sessions.cookieHeader(s.id) }
  64. return res
  65. }
  66. // ---- CONNECT A REPO TO A TICKETS PROJECT (gitoria#18; tickets.hl, components/settings.hl) ----------------------------
  67. // /settings/connect: the owner's click → a fresh nonce parked in the session (bound to the repo) → tickets' /connect.
  68. // /settings/connected: tickets' return with ?code&state → tickets.hl finishConnect (nonce, exchange, key stored per
  69. // repo) → back to /settings. A failure is a note on the settings page.
  70. static connectStart = (route, &req, &sessions) => {
  71. if (req.method != 'GET') { return fail(405, 'GET only') }
  72. repo = repoOfRequest(req)
  73. if (repo == null) { return fail(404, 'no such repository') }
  74. s = req.session
  75. if (s == null || !ownsRepo(repo.slug, s)) { return goTo('/settings') }
  76. nonce = randomBytes(16)
  77. s.data.connectState = repo.slug + '.' + nonce
  78. s.data.connectNote = null
  79. sessions.save(s)
  80. return goTo(connectHref(repo.slug, nonce))
  81. }
  82. static connectBack = (route, &req, &sessions) => {
  83. if (req.method != 'GET') { return fail(405, 'GET only') }
  84. repo = repoOfRequest(req)
  85. if (repo == null) { return fail(404, 'no such repository') }
  86. s = req.session
  87. if (s == null || !ownsRepo(repo.slug, s)) { return goTo('/settings') }
  88. q = req.query != null ? req.query : {}
  89. want = s.data.connectState
  90. s.data.connectState = null
  91. note = finishConnect(repo.slug, want, q)
  92. s.data.connectNote = note == '' ? null : note
  93. sessions.save(s)
  94. return goTo('/settings')
  95. }
  96. // ---- WHAT THE SSHD CONTAINER ASKS (ticket gitoria#7; docker/sshd) — only with the shared secret (api-helpers.hl sshGuard)
  97. // GET /__git/keys?type=<ssh-ed25519>&key=<base64> sshd AuthorizedKeysCommand: the authorized_keys line for a known key
  98. // (sshkeys.hl keyLine), empty for an unknown one
  99. // GET /__git/access?user=<id>&slug=<slug>&write=0|1 gitoria-shell before it starts git: `ok` or 403. Read = every repo (public);
  100. // write = the repo's owner only (repos.hl mayPush — the same rule as the token on HTTPS, transport.hl)
  101. static gitKeys = (route, req) => {
  102. no = sshGuard(req)
  103. if (no != null) { return no }
  104. q = req.query != null ? req.query : {}
  105. return textReply(200, keyLine(q.type, q.key))
  106. }
  107. static gitAccess = (route, req) => {
  108. no = sshGuard(req)
  109. if (no != null) { return no }
  110. q = req.query != null ? req.query : {}
  111. slug = q.slug
  112. if (slug == null || hlTypeName(slug) != 'String' || slugError(slug) != null) { return textReply(404, 'no such repository' + NL) }
  113. repo = repoBySlug(slug)
  114. if (repo == null) { return textReply(404, 'no such repository' + NL) }
  115. if (q.write == '1' && !mayPush(q.user, repo)) { return textReply(403, 'only the owner of this repository can push to it' + NL) }
  116. return textReply(200, 'ok' + NL)
  117. }

Branches

  • mainmain branch

Latest commits

  • 4f47843egate: ticket links use the tickets short URL (/<slug>/<n>, tickets#25)mre
  • 86605446mission 002 (code order) 4/4: README file map + import order + 'Same output' test + gate run with a tickets HEAD copy, STATUS (entry, lessons), LOG, report; tests/realdata-baseline.mjs + realdata-compare.py (a cleanup answers the same on live data: pages, modules, API, git over HTTPS and SSH, faces), tests/letcount.pymre
  • cc7bf7bamission 002 (code order) 3/4: let only where a variable is reassigned or re-bound in a loop body (289 lets → plain declarations; 213 left: 125 reassigned, 88 loop-bound; no member/import/param clash). gates 200/0, 46/0, 44/0; real-data reads + writes identical (browser modules: var → const only)mre
  • 090a20c6mission 002 (code order) 2/4: one lib/ file per topic — git.hl split into git (calls, branches, init, temp folder) / homepage / code / pulls / releases (+ git-helpers: paths, ids, |||PR/|||RL markers); repos-helpers, tickets-helpers, transport-helpers; util.hl = localtime + env, storage dir, addresses, lists, text checks, one newest-first sort (was 3 copies); the function routes out of project.hl into lib/api.hl (thin; plumbing in api-helpers.hl), sshgate.hl folded into api.hl + sshkeys.hl keyLine + repos.hl mayPush; 'Make main' and the merge answer out of the faces (code.hl makeMain, pulls.hl pullsView), one login helper (users.hl userOfLoginCode); project.hl is the map. Session-writing routes get &req + &server.sessions. gates 200/0, 46/0, 44/0; real-data identical except /login/failed now shows the parked reason for a browser that already had a session (the old copy-of-req lost it)mre
  • 110c2799mission 002 (code order) 1/4: .hl files out of the root — lib/ (api, git, localtime, markdown, repos, sshgate, sshkeys, tickets, tokens, transport, users), components/styles.hl; jsoncheck.hl removed (imported nowhere); import paths only. gates 200/0, 46/0, 44/0; real-data reads + writes identicalmre
  • fdfb4b1bgitoria: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 200/0, 46/0, 44/0mre
  • 5b46ac84antcolony#40: LOG.md — missions 069/072 are antcolony missions (report paths on Byrodin)mre
  • 5602ff41gitoria: Hybriel master 190aa11d (fc838894 GC correctness, #127 mountKids by reference, #126, #48) — tracker README flat; gates 200/0, 46/0, 44/0mre
  • e85eaf01gitoria: 069 round 2 — hybriel 1a096ad3 not adopted (Markdown SSR still grows); browser gate waits for the server-side logout before restartmre
  • 09ce4f3fgitoria: mission 069 re-vendor hybriel 8efba065 stopped (big SSR pages grow + slow down); lambda audit clean; old vendor keptmre
  • 3dc43108antcolony#40: mission references point to the moved missionsmre
  • 8d9450fdantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 205d5fe4gitoria: Hybriel master ff51cf46; ssh keys/tokens no double rows (session sync); gates follow #20mre
  • 9b27cb26gitoria#21: installable app (manifest, service worker, offline start page), own iconmre
  • 68dcb603deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • e2deed6dgitoria#20: "Add code" only on the Code page of an empty repository, no collapsiblemre
  • 8bb97ffddeploy.sh: never send .git or .gitignore to Byrodinmre
  • fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mre
  • 4a2d7125initial commitmre