gitoriaLog in with ident

gitoria

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Main branchmain4f47843egate: ticket links use the tickets short URL (/<slug>/<n>, tickets#25)mremain/lib/tokens.hl

3.0 KB

  1. // lib/tokens.hl — ACCESS TOKENS for git over HTTPS (ticket gitoria#7; docs/git-backend.md "Credentials"). A developer's
  2. // git client cannot do the ident login, so a logged-in user makes a token here and gives it to git as the PASSWORD
  3. // (the user name is ignored). Git's HTTP Basic login is not deprecated by git itself; GitHub's ban on account
  4. // passwords is GitHub's. Only the sha256 of a token is stored: the token is shown ONCE, at its creation.
  5. // tokensTable pk @id index !hash, user { user (users @id), name, hash, created } storage/mpackdb/tokens.db
  6. // A token is `gtr_` + 40 hex characters from the kernel's random source (160 bits — the fast sha256 is enough).
  7. import { MPackDB } from 'hl:mpackdb'
  8. import { now } from 'hl:time'
  9. import { randomBytes, sha256 } from 'hl:crypto'
  10. import { storageDir, countOfList, firstOf, plainError, isHex, newestFirst, localStamp } from './util.hl'
  11. import { userRecord } from './users.hl'
  12. static tokensTable = new MPackDB(file = storageDir + '/tokens.db', primaryKey = '@id', indexes = ['!hash', 'user'])
  13. static maxTokens = 20
  14. static rowOfToken = (t) => { return { id = t.id name = t.name created = localStamp(t.created) createdMs = t.created } }
  15. // a user's tokens, newest first — never the token itself, only what identifies it to the owner
  16. static tokenRows = (userId) => {
  17. out = []
  18. all = tokensTable.find('user', userId)
  19. if (countOfList(all) == 0) { return out }
  20. for (t of all) { out.push(rowOfToken(t)) }
  21. return newestFirst(out)
  22. }
  23. // a new token: { token (the secret, this once), row } or { error }
  24. static createToken = (userId, name) => {
  25. u = userRecord(userId)
  26. if (u == null) { return { error = 'log in with ident (top right) first' } }
  27. n = name == null ? '' : ('' + name).trim()
  28. bad = plainError(n, 60, 'the token name')
  29. if (bad != null) { return { error = bad } }
  30. if (n == '') { return { error = 'give the token a name (for example the computer it is for)' } }
  31. if (countOfList(tokensTable.find('user', u.id)) >= maxTokens) { return { error = 'you have ' + maxTokens + ' tokens already — remove one first' } }
  32. secret = 'gtr_' + randomBytes(20, 'hex')
  33. id = tokensTable.put({ user = u.id name = n hash = sha256(secret) created = now() })
  34. if (id == null) { return { error = 'could not store the token: ' + tokensTable.lastError() } }
  35. return { token = secret row = rowOfToken(tokensTable.fetch(id)) }
  36. }
  37. // remove one of the user's own tokens
  38. static revokeToken = (userId, tokenId) => {
  39. if (userId == null || tokenId == null || hlTypeName(tokenId) != 'String') { return { error = 'no such token' } }
  40. t = tokensTable.fetch(tokenId)
  41. if (t == null || t.user != userId) { return { error = 'no such token' } }
  42. tokensTable.delete(tokenId)
  43. return { ok = true }
  44. }
  45. // the user a token belongs to (users @id) or null; anything that is not shaped like a token is null without a lookup
  46. static userOfToken = (secret) => {
  47. if (secret == null || hlTypeName(secret) != 'String' || secret.length != 44 || !secret.startsWith('gtr_') || !isHex(secret.slice(4), 40)) { return null }
  48. t = firstOf(tokensTable.find('hash', sha256(secret)))
  49. return t == null ? null : t.user
  50. }

Branches

Latest commits

  • 4f47843egate: ticket links use the tickets short URL (/<slug>/<n>, tickets#25)mre
  • 86605446mission 002 (code order) 4/4: README file map + import order + 'Same output' test + gate run with a tickets HEAD copy, STATUS (entry, lessons), LOG, report; tests/realdata-baseline.mjs + realdata-compare.py (a cleanup answers the same on live data: pages, modules, API, git over HTTPS and SSH, faces), tests/letcount.pymre
  • cc7bf7bamission 002 (code order) 3/4: let only where a variable is reassigned or re-bound in a loop body (289 lets → plain declarations; 213 left: 125 reassigned, 88 loop-bound; no member/import/param clash). gates 200/0, 46/0, 44/0; real-data reads + writes identical (browser modules: var → const only)mre
  • 090a20c6mission 002 (code order) 2/4: one lib/ file per topic — git.hl split into git (calls, branches, init, temp folder) / homepage / code / pulls / releases (+ git-helpers: paths, ids, |||PR/|||RL markers); repos-helpers, tickets-helpers, transport-helpers; util.hl = localtime + env, storage dir, addresses, lists, text checks, one newest-first sort (was 3 copies); the function routes out of project.hl into lib/api.hl (thin; plumbing in api-helpers.hl), sshgate.hl folded into api.hl + sshkeys.hl keyLine + repos.hl mayPush; 'Make main' and the merge answer out of the faces (code.hl makeMain, pulls.hl pullsView), one login helper (users.hl userOfLoginCode); project.hl is the map. Session-writing routes get &req + &server.sessions. gates 200/0, 46/0, 44/0; real-data identical except /login/failed now shows the parked reason for a browser that already had a session (the old copy-of-req lost it)mre
  • 110c2799mission 002 (code order) 1/4: .hl files out of the root — lib/ (api, git, localtime, markdown, repos, sshgate, sshkeys, tickets, tokens, transport, users), components/styles.hl; jsoncheck.hl removed (imported nowhere); import paths only. gates 200/0, 46/0, 44/0; real-data reads + writes identicalmre
  • fdfb4b1bgitoria: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 200/0, 46/0, 44/0mre
  • 5b46ac84antcolony#40: LOG.md — missions 069/072 are antcolony missions (report paths on Byrodin)mre
  • 5602ff41gitoria: Hybriel master 190aa11d (fc838894 GC correctness, #127 mountKids by reference, #126, #48) — tracker README flat; gates 200/0, 46/0, 44/0mre
  • e85eaf01gitoria: 069 round 2 — hybriel 1a096ad3 not adopted (Markdown SSR still grows); browser gate waits for the server-side logout before restartmre
  • 09ce4f3fgitoria: mission 069 re-vendor hybriel 8efba065 stopped (big SSR pages grow + slow down); lambda audit clean; old vendor keptmre
  • 3dc43108antcolony#40: mission references point to the moved missionsmre
  • 8d9450fdantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 205d5fe4gitoria: Hybriel master ff51cf46; ssh keys/tokens no double rows (session sync); gates follow #20mre
  • 9b27cb26gitoria#21: installable app (manifest, service worker, offline start page), own iconmre
  • 68dcb603deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • e2deed6dgitoria#20: "Add code" only on the Code page of an empty repository, no collapsiblemre
  • 8bb97ffddeploy.sh: never send .git or .gitignore to Byrodinmre
  • fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mre
  • 4a2d7125initial commitmre