gitoria
All repositories: gitoria
3.8 KB
// lib/api-helpers.hl — the plumbing of the function routes (lib/api.hl): JSON / Markdown / plain answers, redirects,// the guard of the internal ssh routes, the repo of a request's host, where a login may return to. Statics only.import { Response } from 'hl:http1'import { NL, scheme, hostPort, slugOfHost } from './util.hl'import { slugError } from './repos-helpers.hl'import { repoBySlug } from './repos.hl'import { sshSecret, sshEnabled } from './sshkeys.hl'static jsonHeaders = { 'Content-Type' = 'application/json; charset=utf-8' }static reply = (status, value) => {return new Response(JSON.stringify(value), { status = status headers = jsonHeaders })}static fail = (status, message) => { return reply(status, { error = message }) }// THE MARKDOWN READ VIEW: `Accept: text/markdown` (for LLM readers)static wantsMarkdown = (req) => {a = req.headers['accept']return a != null && hlTypeName(a) == 'String' && a.includes('text/markdown')}static markdownReply = (text) => {return new Response(text, { status = 200 headers = { 'Content-Type' = 'text/markdown; charset=utf-8' } })}// a plain-text answer of the internal ssh routesstatic textReply = (status, text) => {return new Response(text, { status = status headers = { 'Content-Type' = 'text/plain; charset=utf-8' 'Cache-Control' = 'no-store' } })}static goTo = (where) => {return new Response('redirect', { status = 302 headers = { 'Location' = where 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })}// THE INTERNAL SSH ROUTES' GUARD (docker/sshd asks them): null when the caller may ask, else the refusing answer. Without// GITORIA_SSH_SECRET they do not exist (404); every call needs `X-Gitoria-Secret` = that secret, and a request that came// through the public proxy (it carries X-Forwarded-For / X-Real-IP) is refused.static sshGuard = (req) => {if (!sshEnabled) { return textReply(404, 'not found' + NL) }if (req.method != 'GET') { return textReply(405, 'GET only' + NL) }if (req.headers['x-forwarded-for'] != null || req.headers['x-real-ip'] != null) { return textReply(403, 'internal only' + NL) }given = req.headers['x-gitoria-secret']if (given == null || hlTypeName(given) != 'String' || given != sshSecret) { return textReply(403, 'wrong secret' + NL) }return null}// the repo of a request's host (a repo address), or nullstatic repoOfRequest = (req) => {h = req.headers['host']slug = slugOfHost(h == null ? '' : h.split(':')[0])return slug == '' || slugError(slug) != null ? null : repoBySlug(slug)}// BACK TO THE PAGE after a login: /login.js puts `?next=` into the button's return URL at the click. Only a same-origin PATH// goes (one `/`, URL-safe characters, ≤ 500) — or a full URL of THIS system: <scheme>://<label>.<host>// with a valid, non-reserved repo label and such a path. Anything else → `/`.static nextChars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-._~/?&=%+,;@!$()*:'static nextPath = (want) => {if (want == null || hlTypeName(want) != 'String' || want == '' || want.length > 500) { return '/' }if (want.slice(0, 1) != '/' || want.slice(0, 2) == '//' || want.slice(0, 7) == '/login/') { return '/' }let i = 0while (i < want.length) {if (!nextChars.includes(want[i])) { return '/' }i = i + 1}return want}static safeNext = (want) => {if (want == null || hlTypeName(want) != 'String' || want.length > 500) { return '/' }prefix = scheme + '://'if (!want.startsWith(prefix)) { return nextPath(want) }rest = want.slice(prefix.length)slash = rest.indexOf('/')hp = slash < 0 ? rest : rest.slice(0, slash)path = slash < 0 ? '/' : rest.slice(slash)dot = hp.indexOf('.')if (dot < 1 || hp.slice(dot + 1) != hostPort || slugError(hp.slice(0, dot)) != null) { return '/' }p = nextPath(path)if (p == '/' && path != '/') { return '/' }return prefix + hp + p}
Branches
- mainmain branch
Latest commits
- 4f47843egate: ticket links use the tickets short URL (/<slug>/<n>, tickets#25)mre
- 86605446mission 002 (code order) 4/4: README file map + import order + 'Same output' test + gate run with a tickets HEAD copy, STATUS (entry, lessons), LOG, report; tests/realdata-baseline.mjs + realdata-compare.py (a cleanup answers the same on live data: pages, modules, API, git over HTTPS and SSH, faces), tests/letcount.pymre
- cc7bf7bamission 002 (code order) 3/4: let only where a variable is reassigned or re-bound in a loop body (289 lets → plain declarations; 213 left: 125 reassigned, 88 loop-bound; no member/import/param clash). gates 200/0, 46/0, 44/0; real-data reads + writes identical (browser modules: var → const only)mre
- 090a20c6mission 002 (code order) 2/4: one lib/ file per topic — git.hl split into git (calls, branches, init, temp folder) / homepage / code / pulls / releases (+ git-helpers: paths, ids, |||PR/|||RL markers); repos-helpers, tickets-helpers, transport-helpers; util.hl = localtime + env, storage dir, addresses, lists, text checks, one newest-first sort (was 3 copies); the function routes out of project.hl into lib/api.hl (thin; plumbing in api-helpers.hl), sshgate.hl folded into api.hl + sshkeys.hl keyLine + repos.hl mayPush; 'Make main' and the merge answer out of the faces (code.hl makeMain, pulls.hl pullsView), one login helper (users.hl userOfLoginCode); project.hl is the map. Session-writing routes get &req + &server.sessions. gates 200/0, 46/0, 44/0; real-data identical except /login/failed now shows the parked reason for a browser that already had a session (the old copy-of-req lost it)mre
- 110c2799mission 002 (code order) 1/4: .hl files out of the root — lib/ (api, git, localtime, markdown, repos, sshgate, sshkeys, tickets, tokens, transport, users), components/styles.hl; jsoncheck.hl removed (imported nowhere); import paths only. gates 200/0, 46/0, 44/0; real-data reads + writes identicalmre
- fdfb4b1bgitoria: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 200/0, 46/0, 44/0mre
- 5b46ac84antcolony#40: LOG.md — missions 069/072 are antcolony missions (report paths on Byrodin)mre
- 5602ff41gitoria: Hybriel master 190aa11d (fc838894 GC correctness, #127 mountKids by reference, #126, #48) — tracker README flat; gates 200/0, 46/0, 44/0mre
- e85eaf01gitoria: 069 round 2 — hybriel 1a096ad3 not adopted (Markdown SSR still grows); browser gate waits for the server-side logout before restartmre
- 09ce4f3fgitoria: mission 069 re-vendor hybriel 8efba065 stopped (big SSR pages grow + slow down); lambda audit clean; old vendor keptmre
- 3dc43108antcolony#40: mission references point to the moved missionsmre
- 8d9450fdantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
- 205d5fe4gitoria: Hybriel master ff51cf46; ssh keys/tokens no double rows (session sync); gates follow #20mre
- 9b27cb26gitoria#21: installable app (manifest, service worker, offline start page), own iconmre
- 68dcb603deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
- e2deed6dgitoria#20: "Add code" only on the Code page of an empty repository, no collapsiblemre
- 8bb97ffddeploy.sh: never send .git or .gitignore to Byrodinmre
- fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mre
- 4a2d7125initial commitmre