gitoriaLog in with ident

gitoria

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Main branchmain4f47843egate: ticket links use the tickets short URL (/<slug>/<n>, tickets#25)mremain/lib/users.hl

6.5 KB

  1. // lib/users.hl — WHO MAY CREATE (ticket gitoria#6; CONCEPT.md "login via ident"). Reading is public;
  2. // creating a repo needs a login through ident. Login is ident's LOGIN BUTTON flow (ident README
  3. // "How apps use ident", way 2): <ident>/login?key=&return=<public url>/login/callback → ?ident_code=
  4. // → the server exchanges it (key + secret) for the per-app identity id. Way 3, the IDENTITY SELECTOR
  5. // (gitoria#14, ident README "The identity selector"), sits beside the button; ident checks its caller's origin
  6. // against the app's registered origins, and a repo address (<slug>.<domain>) is not one — so the selector shows
  7. // on the main address only (login.js) and the button works from every address (it returns through the main one).
  8. //
  9. // usersTable pk @id index !identity { identity, name, created } storage/mpackdb/users.db
  10. // identity = what ident's exchange answers: the identity's public SHORT id since ident#23 (`a68sz`; old 32-hex per-app
  11. // ids are rewritten once by tools/migrate-short-ids.hl) — stays SERVER SIDE, never sent to a page.
  12. // name = the display name asked once at the first login ('' until chosen); it is what
  13. // a repo shows as its owner.
  14. // The session (hl:web) carries `user = { id = <users @id> }` only.
  15. //
  16. // Config (environment, or `.env` beside project.hl — never read or printed by workers):
  17. // IDENT_URL, IDENT_EXCHANGE_URL, IDENT_API_KEY, IDENT_API_SECRET as in tickets
  18. // (GITORIA_PUBLIC_URL and GITORIA_STORAGE: lib/util.hl)
  19. import { MPackDB } from 'hl:mpackdb'
  20. import { now } from 'hl:time'
  21. import { fetch } from 'hl:fetch'
  22. import { envOr, storageDir, publicUrl, scheme, hostPort, firstOf, plainError, isHex } from './util.hl'
  23. static identUrl = envOr('IDENT_URL', 'https://ident.worldapi.org')
  24. static identExchangeUrl = envOr('IDENT_EXCHANGE_URL', identUrl)
  25. static identKey = envOr('IDENT_API_KEY', '')
  26. static identSecret = envOr('IDENT_API_SECRET', '')
  27. static usersTable = new MPackDB(file = storageDir + '/users.db', primaryKey = '@id', indexes = ['!identity'])
  28. static selectorScript = identUrl + '/selector.js'
  29. static callbackUrl = publicUrl.replaceAll('/', '') == '' ? '' : scheme + '://' + hostPort + '/login/callback'
  30. static loginHref = identUrl + '/login?key=' + identKey + '&return=' + encodeURIComponent(callbackUrl)
  31. // an identity id as ident answers it: its public SHORT ID since ident#23 (5 characters like `a68sz`: 2-9 and a-z),
  32. // before that the old per-app id (32 hex) — lower case letters and digits, at most 64 (mission 039; isHex refused `a68sz`)
  33. static isIdentId = (s) => {
  34. if (s == null || hlTypeName(s) != 'String' || s.length == 0 || s.length > 64) { return false }
  35. let i = 0
  36. while (i < s.length) {
  37. let c = s.charCodeAt(i)
  38. if (!((c >= 48 && c <= 57) || (c >= 97 && c <= 122))) { return false }
  39. i = i + 1
  40. }
  41. return true
  42. }
  43. // THE EXCHANGE: POST <ident>/api/exchange { key, secret, code } → { identity } | { error }
  44. // (a failed fetch is an `Error` event, absorbed by project.hl's `on Error`; the fetch then yields null)
  45. static exchangeCode = (code) => {
  46. if (identKey == '' || identSecret == '') { return { error = 'login is not set up on this server (IDENT_API_KEY / IDENT_API_SECRET missing)' } }
  47. if (!isHex(code, 200)) { return { error = 'that is not an ident login code' } }
  48. r = fetch(identExchangeUrl + '/api/exchange', { method = 'POST' json = { key = identKey secret = identSecret code = code } headers = { 'user-agent' = 'gitoria.worldapi.org (ident exchange)' } timeoutMs = 10000 })
  49. if (r == null || r.status == null || r.status == 0) { return { error = 'ident did not answer' } }
  50. j = r.status == 200 ? r.json() : null
  51. if (j == null || j.identity == null || !isIdentId(j.identity)) {
  52. let why = ''
  53. if (r.status != 200) {
  54. e = r.json()
  55. why = e != null && e.error != null ? ': ' + e.error : ''
  56. }
  57. return { error = 'ident refused the login (' + r.status + why + ')' }
  58. }
  59. return { identity = j.identity }
  60. }
  61. // ---- users --------------------------------------------------------------------------------
  62. // a face's trailing `session` is always the server's since hybriel #16 (a peer's extra argument is refused)
  63. static userRecord = (userId) => {
  64. if (userId == null || hlTypeName(userId) != 'String' || userId == '') { return null }
  65. return usersTable.fetch(userId)
  66. }
  67. // the user of an identity id, made at its first login (name '' = not chosen yet)
  68. static ensureUser = (identity) => {
  69. u = firstOf(usersTable.find('identity', identity))
  70. if (u != null) { return u }
  71. id = usersTable.put({ identity = identity name = '' created = now() })
  72. if (id == null) { return null }
  73. return usersTable.fetch(id)
  74. }
  75. // what a page may know about a user: NEVER the identity id
  76. static userInfo = (u) => { return { name = u.name named = u.name != '' } }
  77. static userOfSession = (session) => {
  78. if (session == null || session.user == null) { return null }
  79. return userRecord(session.user.id)
  80. }
  81. static infoOfSession = (session) => {
  82. u = userOfSession(session)
  83. return u == null ? null : userInfo(u)
  84. }
  85. // the display name of an owner, 'someone' for a user without one
  86. static nameOfUser = (userId) => {
  87. u = userRecord(userId)
  88. if (u == null || u.name == '') { return 'someone' }
  89. return u.name
  90. }
  91. // the display name: 1–60 characters, one line, asked ONCE
  92. static setUserName = (userId, name) => {
  93. u = userRecord(userId)
  94. if (u == null) { return { error = 'not logged in' } }
  95. if (u.name != '') { return { error = 'your display name is already set' } }
  96. bad = plainError(name, 60, 'the display name')
  97. if (bad != null) { return { error = bad } }
  98. n = name.trim()
  99. if (n == '') { return { error = 'the display name must not be empty' } }
  100. usersTable.update(u.id, { id = u.id identity = u.identity name = n created = u.created })
  101. after = usersTable.fetch(u.id)
  102. if (after == null || after.name != n) { return { error = 'could not store the name: ' + usersTable.lastError() } }
  103. return { user = after }
  104. }
  105. // A LOGIN (the login button's return, lib/api.hl loginCallback, and the selector's face gitoriaLogin, components/main.hl):
  106. // ident's one-time code → { user } (made at the first login) or { error }. The caller puts the user into the session.
  107. static userOfLoginCode = (code) => {
  108. x = exchangeCode(code)
  109. if (x.error != null) { return { error = x.error } }
  110. u = ensureUser(x.identity)
  111. if (u == null) { return { error = 'could not store the user' } }
  112. return { user = u }
  113. }
  114. // the random tag of a session's login (session.data.tag, set at login): `gitoriaSignedIn` / `gitoriaSignedOut` reach the
  115. // tabs of the session that carries it (project.hl audience)
  116. static tagOf = (session) => { return session != null && session.data != null ? session.data.tag : null }

Branches

Latest commits

  • 4f47843egate: ticket links use the tickets short URL (/<slug>/<n>, tickets#25)mre
  • 86605446mission 002 (code order) 4/4: README file map + import order + 'Same output' test + gate run with a tickets HEAD copy, STATUS (entry, lessons), LOG, report; tests/realdata-baseline.mjs + realdata-compare.py (a cleanup answers the same on live data: pages, modules, API, git over HTTPS and SSH, faces), tests/letcount.pymre
  • cc7bf7bamission 002 (code order) 3/4: let only where a variable is reassigned or re-bound in a loop body (289 lets → plain declarations; 213 left: 125 reassigned, 88 loop-bound; no member/import/param clash). gates 200/0, 46/0, 44/0; real-data reads + writes identical (browser modules: var → const only)mre
  • 090a20c6mission 002 (code order) 2/4: one lib/ file per topic — git.hl split into git (calls, branches, init, temp folder) / homepage / code / pulls / releases (+ git-helpers: paths, ids, |||PR/|||RL markers); repos-helpers, tickets-helpers, transport-helpers; util.hl = localtime + env, storage dir, addresses, lists, text checks, one newest-first sort (was 3 copies); the function routes out of project.hl into lib/api.hl (thin; plumbing in api-helpers.hl), sshgate.hl folded into api.hl + sshkeys.hl keyLine + repos.hl mayPush; 'Make main' and the merge answer out of the faces (code.hl makeMain, pulls.hl pullsView), one login helper (users.hl userOfLoginCode); project.hl is the map. Session-writing routes get &req + &server.sessions. gates 200/0, 46/0, 44/0; real-data identical except /login/failed now shows the parked reason for a browser that already had a session (the old copy-of-req lost it)mre
  • 110c2799mission 002 (code order) 1/4: .hl files out of the root — lib/ (api, git, localtime, markdown, repos, sshgate, sshkeys, tickets, tokens, transport, users), components/styles.hl; jsoncheck.hl removed (imported nowhere); import paths only. gates 200/0, 46/0, 44/0; real-data reads + writes identicalmre
  • fdfb4b1bgitoria: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 200/0, 46/0, 44/0mre
  • 5b46ac84antcolony#40: LOG.md — missions 069/072 are antcolony missions (report paths on Byrodin)mre
  • 5602ff41gitoria: Hybriel master 190aa11d (fc838894 GC correctness, #127 mountKids by reference, #126, #48) — tracker README flat; gates 200/0, 46/0, 44/0mre
  • e85eaf01gitoria: 069 round 2 — hybriel 1a096ad3 not adopted (Markdown SSR still grows); browser gate waits for the server-side logout before restartmre
  • 09ce4f3fgitoria: mission 069 re-vendor hybriel 8efba065 stopped (big SSR pages grow + slow down); lambda audit clean; old vendor keptmre
  • 3dc43108antcolony#40: mission references point to the moved missionsmre
  • 8d9450fdantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 205d5fe4gitoria: Hybriel master ff51cf46; ssh keys/tokens no double rows (session sync); gates follow #20mre
  • 9b27cb26gitoria#21: installable app (manifest, service worker, offline start page), own iconmre
  • 68dcb603deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • e2deed6dgitoria#20: "Add code" only on the Code page of an empty repository, no collapsiblemre
  • 8bb97ffddeploy.sh: never send .git or .gitignore to Byrodinmre
  • fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mre
  • 4a2d7125initial commitmre