gitoriaLog in with ident

gitoria

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit4a2d71254a2d7125initial commitmre4a2d7125/STATUS.md

10.9 KB

  1. # gitoria.worldapi.org — status
  2. ## Built
  3. - **Push and pull over SSH** (gitoria#7, 2026-09-25, second worker): `docker/sshd` (sshd container: `AuthorizedKeysCommand` → app, forced command `gitoria-shell`, host keys volume),
  4. `sshkeys.hl` + `components/sshkeys.hl` (SSH keys page: paste public key, `ssh-keygen -l` check, list, remove), `sshgate.hl` (`/__git/keys`, `/__git/access`, secret + no proxy),
  5. ssh commands in the "add code" box (`repohead.hl`), service `gitoria-sshd` in `docker-compose.yml`, `openssh-client` in the Dockerfile. Gate `node tests/ssh.mjs`: **44 checks green**
  6. with the real sshd container + real ssh/git (needs docker); `push.mjs` 46 and `browser.mjs` 149 still green. Not deployed. **Deploy needs** (README "Git over SSH"): `GITORIA_SSH_SECRET`
  7. in `.env`, firewall port (2222), DNS-only record for the ssh host (Cloudflare proxy carries no ssh), rebuild both images. SSH is hidden on the site until the secret is set.
  8. Not built (not decided): private repos, collaborators, protected branches, size limits.
  9. - **Push and pull over HTTPS + "Add code" box** (gitoria#7, 2026-09-25): `transport.hl` (smart-HTTP clone/fetch/push with `git upload-pack|receive-pack
  10. --stateless-rpc`, body via temp files, protocol v0/v1/v2, gzip requests), `tokens.hl` + `components/tokens.hl` (access tokens: shown once, sha256 stored,
  11. list/remove, on the main address), the box in `components/repohead.hl` (clone command, new/existing-project commands, open while the repo is empty),
  12. `git.hl isEmptyNow`, routes in `project.hl`, `styles.hl`. Read is public; only the owner's token may push. Gate `node tests/push.mjs`: **46 checks
  13. green** (real git: clone empty, push refused without / with wrong / another user's token, owner pushes a 4 MB pack, clone, gzip fetch with 300 local commits,
  14. pull, v0/v2, removed token stops at once, odd requests, layout 390/1280); `node tests/browser.mjs` still 149 green. Not deployed. **SSH: see the next entry.** Not built: collaborators / private repos / protected branches (not decided), SSH keys page.
  15. Deploy needs: nginx `client_max_body_size` (500m) and default request buffering on the `*.gitoria` vhost (README "Push and pull"); the Dockerfile has git, gzip, base64 (debian).
  16. Found: hl:http1 gives `body = null` for a chunked request (hence the proxy note); hybriel has no base64 decoder (the Basic header is decoded with `base64 -d`).
  17. - **Every repo view its own server-rendered page** (gitoria#16, mission 033, 2026-09-25): `components/index.hl` (`/`: list.hl on the
  18. main address, readme.hl on a repo address), `code.hl` / `branch.hl` / `commit.hl` (+ `codebrowser.hl`), `pulls.hl`, `releases.hl`,
  19. `tickets.hl`, `repohead.hl`, `loginfailed.hl` (was `htmlPage`). The repo comes from `host = null` (hybriel#74), git is read with
  20. hl:proc `run()` (hybriel#80, `git.hl` `*Now`): README, file list/file, branch, commit, pulls, releases and tickets are in the FIRST
  21. HTML, no "Loading". Gone: `components/home.hl`, `/host.js` (+ route), the hidden #hostslug/#loading inputs, `gitoriaOpen`,
  22. `gitoriaDocs/Code/Pulls/Releases` and their pushed answers; `?next=` moved into `login.js`. The rest of `/code/*path` etc. is the
  23. page member `path` (hybriel#81). Gate `node tests/browser.mjs`: **149 checks green**, incl. hybriel#43 (a code view in another tab
  24. keeps its elements through a login + logout) and NAVIGATION LOGGED IN in Chrome AND a real Firefox 155 (`tests/firefox.mjs`, BiDi):
  25. button login on a repo address, Readme → Code → Releases → Pulls → Tickets → Code → folder, an empty owned repo, and (Chrome) with
  26. the socket closed — no full page load anywhere. Not deployed.
  27. **Open — the creator's full page loads in Firefox 155 are NOT reproduced**: locally logged in (Chrome + Firefox) and on the LIVE site
  28. signed out (Firefox, h3 via Cloudflare, also with the socket closed) the marker survives. Not tested: live + logged in (it would
  29. write a user into live data). Found on the way: hl:web never reconnects a closed WebSocket (`client.hl` `close` → `socket = null`,
  30. no retry): after Cloudflare's ~100 s idle close every emit rides POST and live pushes (new repo, new ticket, login in another tab)
  31. no longer arrive — a hybriel ticket candidate.
  32. - **Hybriel re-vendored from master 2fbfe195** (mission 033; edf27bc1 → 6ae171af → 2fbfe195): binary sha256 `2a3c2b02…b565`
  33. (ReleaseFast from `git archive`), plugins core crypto data fetch fs http http1 mpackdb proc time **web** (every import `'hl:web'`).
  34. Older copies in `.scratch/pre-033/`, `pre-033b/`, `pre-033d/`. **No local patch left**: the cookie Domain is `sessionDomain`
  35. (#44) in project.hl. Dropped earlier: patches for #34/#39, HL_HOST listener (#24), `server.sessions.cookie` (#10), `realSession()`
  36. (#16), URL encoders (#14), `sessions.resolve` in the callback (#11). Master refuses `if (!x)` in a View → `noSource` for pulls.
  37. - **Identity selector** (gitoria#14, 2026-09-25): ident's `<ident-selector>` in the header beside "Log in with ident", like tickets
  38. (`components/main.hl` face `gitoriaLogin`, `login.js`, `users.hl selectorScript`, `styles.hl`, route `/login.js`). Gate `node tests/browser.mjs`:
  39. 122 checks green (choose identity → logged in without reload, logout resets it, hidden on a repo address, button unchanged). The gate now
  40. serves ident as `ident.gitoria.test` (same site as gitoria.test, else ident's Lax cookie never reaches the selector's fetch). Not deployed.
  41. - **Releases from commit messages** (gitoria#12, 2026-09-25): `/releases` of a repo address lists them (`git.hl` `parseRelease`, `releases`,
  42. `components/home.hl`, face `gitoriaReleases`, pushed `releasesReady`). Gate `node tests/browser.mjs`: 116 checks green (patch / `med` / `mj` /
  43. by-hand versions counted up, newest first, marker inside text / bad version / repeated version / other branch ignored, HTML as text,
  44. empty repo, forged face, 390/1280px). Not deployed. Not built: real git tags, downloadable archives, release notes page, API.
  45. - **Pull requests from commit messages** (gitoria#11, 2026-09-24): `/pulls` of a repo address lists them (`git.hl` `parsePull`, `pulls`,
  46. `components/home.hl`, face `gitoriaPulls`, pushed `pullsReady`). Gate `node tests/browser.mjs`: 108 checks green (marker parsing,
  47. target `|||PR|branch] `, merged vs open, missing target, one per source branch, HTML as text, empty repo, forged face, 390/1280px).
  48. Not deployed. Not built: merging in gitoria (open question to the creator), a PR page with diff/comments, PR numbers, API, a settings page
  49. for the default target (the repo's main branch is used).
  50. - **Tickets inside a repo** (gitoria#10, 2026-09-24): `/tickets` of a repo address lists the tickets of its project in tickets.worldapi.org
  51. (`<slug>.<host>`), any named user opens one (gitoria's own API token; the text says who), the first ticket creates the project there.
  52. `tickets.hl`, `components/home.hl`, `git.hl parseView`, `tests/ticketskit.mjs`. Gate `node tests/browser.mjs`: 99 checks green (own tickets
  53. copy: 404 → first ticket creates the project, text as text, live to another viewer, ticket made in tickets shows on reload, forged
  54. session refused, tickets down message, 390/1280px). Not deployed: needs `GITORIA_TICKETS_TOKEN` in `.env` (README "Tickets").
  55. Not built: ticket text/comments inside gitoria, real author in tickets (tickets has no act-on-behalf).
  56. - **Browse code** (gitoria#9, 2026-09-24): `/code`, `/branch/<name>`, `/commit/<id>` (+ a path), `git.hl` `browse`, `components/home.hl`, `host.js`,
  57. `repos.hl` (`branch` field, `setMainBranch`), routes in `project.hl`. Gate `node tests/browser.mjs`: 79 checks green (main branch tree,
  58. folder/file/crumbs, old commit incl. short id, branch with a slash, binary file, unknown branch/commit/path messages, empty repo,
  59. "Make main" for the owner only, homepage follows the setting, 390/1280px). Not deployed. Not built: API / Markdown read view of code,
  60. commit diff, syntax highlighting. Found: hl:proc lines cannot carry non-UTF-8 bytes (breaks the socket) — files are checked with
  61. `git grep` first; a non-UTF-8 author name / branch name is not handled.
  62. - **Repo homepage from README and $docs** (gitoria#8, 2026-09-24): `git.hl`, `markdown.hl`, `components/markdown.hl`, `components/home.hl`;
  63. repo creation makes a bare git repo. Gate `node tests/browser.mjs`: 54 checks green (README as HTML incl. table/quote/rule/code,
  64. unsafe HTML and `javascript:` links stay text, `$docs` replaces README, empty repo message, 390/1280px). Not deployed:
  65. the Dockerfile now installs `git`; repos created before this have no bare repo yet (they show "no README.md yet").
  66. Not built: Markdown read view of the homepage in the API, images in Markdown, per-repo branch setting (#9).
  67. - **Repos with their own address** (gitoria#6, 2026-09-24): the app (`project.hl`, `components/`, `repos.hl`, `users.hl`),
  68. README "How a repo gets its address". Gate `node tests/browser.mjs`: 46 checks green (create, refusals, unique slug, live
  69. list, `<slug>.gitoria.test` pages, login from a repo address, shared cookie, restart, 390/1280px). Not deployed.
  70. Not built: git data (#7), homepage (#8), code browsing (#9), tickets (#10), pulls (#11), releases (#12), API creation, settings.
  71. ## Research done
  72. - [`docs/differ-from-custom-ide.md`](docs/differ-from-custom-ide.md) — gitoria#2: whether to reuse
  73. custom-ide's diff/editor (CodeJar-based) as a Hybriel component. Verdict: the diff **algorithm**
  74. (`lineDiff.js`, pure, no DOM) is directly reusable as a native Hybriel module; the CodeJar-based
  75. editing **surface** is real engineering (~3,400 LOC total, not "simple") and a native rewrite is blocked on
  76. open webex tickets (hybriel#31/#32/#33/#17/#41). Final plan (see Decision below): native Hybriel only,
  77. no JS-asset interim.
  78. - [`docs/git-backend.md`](docs/git-backend.md) — gitoria#5: how to use git from Hybriel. Verdict: the `git`
  79. binary, no `hl:git` library plugin (libgit2 has no server side). Reads via `hl:proc`; HTTPS clone/push
  80. served by Hybriel itself (`git upload-pack|receive-pack --stateless-rpc` through hl:proc stdin/binary, after
  81. hybriel#42); only SSH needs a small sshd container. Tested: byte-exact blobs, upload-pack over stdin, hl:http1
  82. byte-safe bodies. Full endpoint (#7) and SSH not run.
  83. ## Decision (gitoria#4, rejected 2026-09-24)
  84. Embedding custom-ide's JS bundle is **not** wanted. Editor and differ are built natively in Hybriel as
  85. shared components in layouts.worldapi.org (as ticket #2 said). Not started: the native port; the editing
  86. surface is blocked on hybriel#31/#32/#33/#17.
  87. Note: `DECISIONS.md` is generated by the librarian and still says "no decisions recorded yet"; it does not yet hold this decision.
  88. - **How to get code in, said where the creator looks** (gitoria#8 sent back 2026-09-25: "no description how i get a repo in at the /code page"): the "Add code to this repository" box (gitoria#7, `repohead.hl`, open while the repo is empty) was built but not yet deployed when the creator tested. The empty messages of the Readme and Code views now point to it (`components/readme.hl`, `git.hl`). Gate `node tests/browser.mjs`: 149 green. Needs the gitoria#7 deploy.

Branches

Latest commits

  • 4a2d7125initial commitmre