gitoriaLog in with ident

notes

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Branchmain2149e902notes mission 002 (4/4): code order — README file map + same-output test, STATUS, LOG, report; tests/letcount.py, tests/realdata-baseline.mjs, tests/realdata-compare.pymremain/lib/users.hl

4.7 KB

  1. // lib/users.hl — WHO OWNS NOTES (ticket notes#1; CONCEPT.md "login via ident"). Login is ident's LOGIN BUTTON flow
  2. // (ident README "How apps use ident", way 2): <ident>/login?key=&return=<public url>/login/callback → ?ident_code=
  3. // → the server exchanges it (key + secret) for the per-app identity id. Way 3, the IDENTITY SELECTOR, sits beside the
  4. // button (login.js hands its code to the shell).
  5. //
  6. // usersTable pk @id index !identity { identity, created } storage/mpackdb/users.db
  7. // identity = what ident's exchange answers: the identity's public SHORT id since ident#23 (`a68sz`; old 32-hex per-app
  8. // ids are rewritten once by tools/migrate-short-ids.hl) — stays SERVER SIDE, never sent to a page.
  9. // The session (hl:web) carries `user = { id = <users @id> }` and `data.tag` (the login's random tag, tagOf) only.
  10. // No display name: notes are private. Both logins (lib/api.hl loginCallback, the face notesLogin in components/main.hl)
  11. // go through userOfLoginCode; they write the session themselves.
  12. //
  13. // Config (environment, or `.env` beside project.hl — never read or printed by workers):
  14. // IDENT_URL, IDENT_EXCHANGE_URL, IDENT_API_KEY, IDENT_API_SECRET as in gitoria
  15. // NOTES_PUBLIC_URL the app's address, default https://notes.worldapi.org
  16. // NOTES_STORAGE table directory, default ./storage/mpackdb (lib/util.hl storageDir)
  17. import { MPackDB } from 'hl:mpackdb'
  18. import { now } from 'hl:time'
  19. import { fetch } from 'hl:fetch'
  20. import { envOr, storageDir, firstOf, isHex, isIdentId } from './util.hl'
  21. static identUrl = envOr('IDENT_URL', 'https://ident.worldapi.org')
  22. static identExchangeUrl = envOr('IDENT_EXCHANGE_URL', identUrl)
  23. static identKey = envOr('IDENT_API_KEY', '')
  24. static identSecret = envOr('IDENT_API_SECRET', '')
  25. static publicUrl = envOr('NOTES_PUBLIC_URL', 'https://notes.worldapi.org')
  26. static usersTable = new MPackDB(file = storageDir + '/users.db', primaryKey = '@id', indexes = ['!identity'])
  27. static selectorScript = identUrl + '/selector.js'
  28. static callbackUrl = publicUrl.replaceAll('/', '') == '' ? '' : publicUrl + '/login/callback'
  29. static loginHref = identUrl + '/login?key=' + identKey + '&return=' + encodeURIComponent(callbackUrl)
  30. // THE EXCHANGE: POST <ident>/api/exchange { key, secret, code } → { identity } | { error }
  31. // (a failed fetch is an `Error` event, absorbed by project.hl's `on Error`; the fetch then yields null)
  32. static exchangeCode = (code) => {
  33. if (identKey == '' || identSecret == '') { return { error = 'login is not set up on this server (IDENT_API_KEY / IDENT_API_SECRET missing)' } }
  34. if (!isHex(code, 200)) { return { error = 'that is not an ident login code' } }
  35. r = fetch(identExchangeUrl + '/api/exchange', { method = 'POST' json = { key = identKey secret = identSecret code = code } headers = { 'user-agent' = 'notes.worldapi.org (ident exchange)' } timeoutMs = 10000 })
  36. if (r == null || r.status == null || r.status == 0) { return { error = 'ident did not answer' } }
  37. j = r.status == 200 ? r.json() : null
  38. if (j == null || j.identity == null || !isIdentId(j.identity)) {
  39. let why = ''
  40. if (r.status != 200) {
  41. e = r.json()
  42. why = e != null && e.error != null ? ': ' + e.error : ''
  43. }
  44. return { error = 'ident refused the login (' + r.status + why + ')' }
  45. }
  46. return { identity = j.identity }
  47. }
  48. // ---- users --------------------------------------------------------------------------------
  49. // a face's trailing `session` is always the server's since hybriel #16 (a peer's extra argument is refused)
  50. static userRecord = (userId) => {
  51. if (userId == null || hlTypeName(userId) != 'String' || userId == '') { return null }
  52. return usersTable.fetch(userId)
  53. }
  54. // the user of an identity id, made at its first login
  55. static ensureUser = (identity) => {
  56. u = firstOf(usersTable.find('identity', identity))
  57. if (u != null) { return u }
  58. id = usersTable.put({ identity = identity created = now() })
  59. if (id == null) { return null }
  60. return usersTable.fetch(id)
  61. }
  62. // A LOGIN CODE (the button's ?ident_code= or the selector's) → { user } (made at the first login) | { error }
  63. static userOfLoginCode = (code) => {
  64. x = exchangeCode(code)
  65. if (x.error != null) { return { error = x.error } }
  66. u = ensureUser(x.identity)
  67. if (u == null) { return { error = 'could not store the user' } }
  68. return { user = u }
  69. }
  70. static userOfSession = (session) => {
  71. if (session == null || session.user == null) { return null }
  72. return userRecord(session.user.id)
  73. }
  74. // the users @id of a session, or null (a page may know it: it is not the identity id)
  75. static userIdOfSession = (session) => {
  76. u = userOfSession(session)
  77. return u == null ? null : u.id
  78. }
  79. // the random tag of a session's login (project.hl audience: the login state reaches the tabs of that one session)
  80. static tagOf = (session) => { return session != null && session.data != null ? session.data.tag : null }

Branches

  • mainmain branch

Latest commits

  • 2149e902notes mission 002 (4/4): code order — README file map + same-output test, STATUS, LOG, report; tests/letcount.py, tests/realdata-baseline.mjs, tests/realdata-compare.pymre
  • 47db4fc1notes mission 002 (3/4): code order — let only where reassigned (58 dropped; 34 left: 19 reassigned, 15 loop-bound); gates 50/0 + 18/0, live-data run = step 2mre
  • 3f8cb383notes mission 002 (2/4): code order — topics, map, thin wrappers: lib/util.hl, lib/notes(-helpers).hl, lib/users.hl (+userOfLoginCode, tagOf), lib/api(-helpers).hl; project.hl = map; login routes take &req/&sessions (failed-login reason now kept); dead notes#1 functions removed; gates 50/0 + 18/0mre
  • 8cda5412notes mission 002 (1/4): code order — files moved: lib/notes.hl, lib/users.hl, lib/jsoncheck.hl, components/styles.hl (imports only); gates 50/0 + 18/0, live-data run identicalmre
  • 47dad68bnotes: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 50/0 + 18/0mre
  • a4a2b2aeantcolony#40: tracker missions moved too — references to them in missions/reports/LOG.md updatedmre
  • 3dea0ef2notes: Hybriel master 190aa11d (fc838894 GC correctness, #126 closure scopes, #127); gate 50/0mre
  • e27c7d71notes: Hybriel master 8efba065 (#126 GC by bytes, #48 lambda params copy; audit: nothing to fix; gate 50/0)mre
  • 124613b6antcolony#40: mission references point to the moved missionsmre
  • 1ca2f34dantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 2bebebdanotes: Hybriel master ff51cf46 (re-vendor round)mre
  • 3eff126dnotes#3: installable app (manifest + own icon/favicon; notes' own sw.js kept)mre
  • 9883c540deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • eee693b8deploy.sh: never send .git or .gitignore to Byrodinmre
  • c8904061State of 2026-09-27, before the move to gitoriamre