gitoria
All repositories: gitoria
6.6 KB
// lib/users.hl — WHO MAY CREATE (ticket gitoria#6; CONCEPT.md "login via ident"). Reading is public;// creating a repo needs a login through ident. Login is ident's LOGIN BUTTON flow (ident README// "How apps use ident", way 2): <ident>/login?key=&return=<public url>/login/callback → ?ident_code=// → the server exchanges it (key + secret) for the per-app identity id. Way 3, the IDENTITY SELECTOR// (gitoria#14, ident README "The identity selector"), sits beside the button; ident checks its caller's origin// against the app's registered origins, and a repo address (<slug>.<domain>) is not one — so the selector shows// on the main address only (login.js) and the button works from every address (it returns through the main one).//// usersTable pk @id index !identity { identity, name, created } storage/mpackdb/users.db// identity = what ident's exchange answers: the identity's public SHORT id since ident#23 (`a68sz`; old 32-hex per-app// ids are rewritten once by tools/migrate-short-ids.hl) — stays SERVER SIDE, never sent to a page.// name = the display name asked once at the first login ('' until chosen); it is what// a repo shows as its owner.// The session (hl:web) carries `user = { id = <users @id> }` only.//// Config (environment, or `.env` beside project.hl — never read or printed by workers):// IDENT_URL, IDENT_EXCHANGE_URL, IDENT_API_KEY, IDENT_API_SECRET as in tickets// (GITORIA_PUBLIC_URL and GITORIA_STORAGE: lib/util.hl)import { MPackDB } from 'hl:mpackdb'import { now } from 'hl:time'import { fetch } from 'hl:fetch'import { envOr, storageDir, publicUrl, scheme, hostPort, firstOf, plainError, isHex } from './util.hl'static identUrl = envOr('IDENT_URL', 'https://ident.worldapi.org')static identExchangeUrl = envOr('IDENT_EXCHANGE_URL', identUrl)static identKey = envOr('IDENT_API_KEY', '')static identSecret = envOr('IDENT_API_SECRET', '')static usersTable = new MPackDB(file = storageDir + '/users.db', primaryKey = '@id', indexes = ['!identity'])static selectorScript = identUrl + '/selector.js'static callbackUrl = publicUrl.replaceAll('/', '') == '' ? '' : scheme + '://' + hostPort + '/login/callback'static loginHref = identUrl + '/login?key=' + identKey + '&return=' + encodeURIComponent(callbackUrl)// an identity id as ident answers it: its public SHORT ID since ident#23 (5 characters like `a68sz`: 2-9 and a-z),// before that the old per-app id (32 hex) — lower case letters and digits, at most 64 (mission 039; isHex refused `a68sz`)static isIdentId = (s) => {if (s == null || hlTypeName(s) != 'String' || s.length == 0 || s.length > 64) { return false }let i = 0while (i < s.length) {let c = s.charCodeAt(i)if (!((c >= 48 && c <= 57) || (c >= 97 && c <= 122))) { return false }i = i + 1}return true}// THE EXCHANGE: POST <ident>/api/exchange { key, secret, code } → { identity } | { error }// (a failed fetch is an `Error` event, absorbed by project.hl's `on Error`; the fetch then yields null)static exchangeCode = (code) => {if (identKey == '' || identSecret == '') { return { error = 'login is not set up on this server (IDENT_API_KEY / IDENT_API_SECRET missing)' } }if (!isHex(code, 200)) { return { error = 'that is not an ident login code' } }let r = fetch(identExchangeUrl + '/api/exchange', { method = 'POST' json = { key = identKey secret = identSecret code = code } headers = { 'user-agent' = 'gitoria.worldapi.org (ident exchange)' } timeoutMs = 10000 })if (r == null || r.status == null || r.status == 0) { return { error = 'ident did not answer' } }let j = r.status == 200 ? r.json() : nullif (j == null || j.identity == null || !isIdentId(j.identity)) {let why = ''if (r.status != 200) {let e = r.json()why = e != null && e.error != null ? ': ' + e.error : ''}return { error = 'ident refused the login (' + r.status + why + ')' }}return { identity = j.identity }}// ---- users --------------------------------------------------------------------------------// a face's trailing `session` is always the server's since hybriel #16 (a peer's extra argument is refused)static userRecord = (userId) => {if (userId == null || hlTypeName(userId) != 'String' || userId == '') { return null }return usersTable.fetch(userId)}// the user of an identity id, made at its first login (name '' = not chosen yet)static ensureUser = (identity) => {let u = firstOf(usersTable.find('identity', identity))if (u != null) { return u }let id = usersTable.put({ identity = identity name = '' created = now() })if (id == null) { return null }return usersTable.fetch(id)}// what a page may know about a user: NEVER the identity idstatic userInfo = (u) => { return { name = u.name named = u.name != '' } }static userOfSession = (session) => {if (session == null || session.user == null) { return null }return userRecord(session.user.id)}static infoOfSession = (session) => {let u = userOfSession(session)return u == null ? null : userInfo(u)}// the display name of an owner, 'someone' for a user without onestatic nameOfUser = (userId) => {let u = userRecord(userId)if (u == null || u.name == '') { return 'someone' }return u.name}// the display name: 1–60 characters, one line, asked ONCEstatic setUserName = (userId, name) => {let u = userRecord(userId)if (u == null) { return { error = 'not logged in' } }if (u.name != '') { return { error = 'your display name is already set' } }let bad = plainError(name, 60, 'the display name')if (bad != null) { return { error = bad } }let n = name.trim()if (n == '') { return { error = 'the display name must not be empty' } }usersTable.update(u.id, { id = u.id identity = u.identity name = n created = u.created })let after = usersTable.fetch(u.id)if (after == null || after.name != n) { return { error = 'could not store the name: ' + usersTable.lastError() } }return { user = after }}// A LOGIN (the login button's return, lib/api.hl loginCallback, and the selector's face gitoriaLogin, components/main.hl):// ident's one-time code → { user } (made at the first login) or { error }. The caller puts the user into the session.static userOfLoginCode = (code) => {let x = exchangeCode(code)if (x.error != null) { return { error = x.error } }let u = ensureUser(x.identity)if (u == null) { return { error = 'could not store the user' } }return { user = u }}// the random tag of a session's login (session.data.tag, set at login): `gitoriaSignedIn` / `gitoriaSignedOut` reach the// tabs of the session that carries it (project.hl audience)static tagOf = (session) => { return session != null && session.data != null ? session.data.tag : null }
Branches
- mainmain branch
Latest commits
- 090a20c6mission 002 (code order) 2/4: one lib/ file per topic — git.hl split into git (calls, branches, init, temp folder) / homepage / code / pulls / releases (+ git-helpers: paths, ids, |||PR/|||RL markers); repos-helpers, tickets-helpers, transport-helpers; util.hl = localtime + env, storage dir, addresses, lists, text checks, one newest-first sort (was 3 copies); the function routes out of project.hl into lib/api.hl (thin; plumbing in api-helpers.hl), sshgate.hl folded into api.hl + sshkeys.hl keyLine + repos.hl mayPush; 'Make main' and the merge answer out of the faces (code.hl makeMain, pulls.hl pullsView), one login helper (users.hl userOfLoginCode); project.hl is the map. Session-writing routes get &req + &server.sessions. gates 200/0, 46/0, 44/0; real-data identical except /login/failed now shows the parked reason for a browser that already had a session (the old copy-of-req lost it)mre
- 110c2799mission 002 (code order) 1/4: .hl files out of the root — lib/ (api, git, localtime, markdown, repos, sshgate, sshkeys, tickets, tokens, transport, users), components/styles.hl; jsoncheck.hl removed (imported nowhere); import paths only. gates 200/0, 46/0, 44/0; real-data reads + writes identicalmre
- fdfb4b1bgitoria: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 200/0, 46/0, 44/0mre
- 5b46ac84antcolony#40: LOG.md — missions 069/072 are antcolony missions (report paths on Byrodin)mre
- 5602ff41gitoria: Hybriel master 190aa11d (fc838894 GC correctness, #127 mountKids by reference, #126, #48) — tracker README flat; gates 200/0, 46/0, 44/0mre
- e85eaf01gitoria: 069 round 2 — hybriel 1a096ad3 not adopted (Markdown SSR still grows); browser gate waits for the server-side logout before restartmre
- 09ce4f3fgitoria: mission 069 re-vendor hybriel 8efba065 stopped (big SSR pages grow + slow down); lambda audit clean; old vendor keptmre
- 3dc43108antcolony#40: mission references point to the moved missionsmre
- 8d9450fdantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
- 205d5fe4gitoria: Hybriel master ff51cf46; ssh keys/tokens no double rows (session sync); gates follow #20mre
- 9b27cb26gitoria#21: installable app (manifest, service worker, offline start page), own iconmre
- 68dcb603deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
- e2deed6dgitoria#20: "Add code" only on the Code page of an empty repository, no collapsiblemre
- 8bb97ffddeploy.sh: never send .git or .gitignore to Byrodinmre
- fd981932State of 2026-09-27; bin/ no longer tracked (Hybriel commit is in README)mre
- 4a2d7125initial commitmre