gitoriaLog in with ident

notes

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit2149e9022149e902notes mission 002 (4/4): code order — README file map + same-output test, STATUS, LOG, report; tests/letcount.py, tests/realdata-baseline.mjs, tests/realdata-compare.pymre2149e902/lib/api.hl

4.6 KB

  1. // lib/api.hl — THE FUNCTION ROUTES (notes mission 002, code order): thin wrappers — check the input and the session,
  2. // call the topic (lib/notes.hl, lib/users.hl), answer.
  3. //
  4. // THE LOGIN BUTTON'S RETURN (ident README "How apps use ident"): /login/callback?ident_code=&next= → the user
  5. // (lib/users.hl userOfLoginCode) → the session is signed in → back to `next` (lib/api-helpers.hl safePath). A FAILED
  6. // LOGIN is a page (components/loginfailed.hl): the reason is parked in the session, then → /login/failed.
  7. // These two write the session: project.hl hands them the request and the session store BY REFERENCE (&req, &sessions);
  8. // a by-value copy would lose the write (tickets mission 010, gitoria mission 002).
  9. //
  10. // THE SYNC API (ticket notes#2): what the browser's offline copy talks to. JSON, the session cookie is the login.
  11. // GET /api/me → { user } (an opaque id of the signed-in user, or null)
  12. // GET /api/notes → { notes: [{ id, edited, gone }] } every note of the user, tombstones included
  13. // GET /api/notes?id=<id> → { id, text, edited, created }
  14. // POST /api/notes { op: 'save', id, local, text, base, at } → { id, edited, text, copy? }
  15. // POST /api/notes { op: 'delete', id, base } → { ok } | { kept, id, edited, text }
  16. // Invalid JSON is refused by lib/jsoncheck.hl before JSON.parse sees it (hybriel #6); unknown/mistyped fields → 400.
  17. import { Response } from 'hl:http1'
  18. import { randomBytes } from 'hl:crypto'
  19. import { userOfLoginCode, userIdOfSession } from './users.hl'
  20. import { metaRows, noteView, pushNote, removeNote } from './notes.hl'
  21. import { jsonErrorAt } from './jsoncheck.hl'
  22. import { reply, isText, isTime, safePath } from './api-helpers.hl'
  23. static loginFailed = (&req, &sessions, why) => {
  24. let s = req.session
  25. fresh = s == null
  26. if (fresh) { s = sessions.mint() }
  27. s.data.loginError = why
  28. sessions.save(s)
  29. res = new Response('login failed: ' + why, { status = 302 headers = { 'Location' = '/login/failed' 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  30. if (fresh) { res.headers['Set-Cookie'] = sessions.cookieHeader(s.id) }
  31. return res
  32. }
  33. // the function route gets the cookie's session as req.session (hybriel #11); none yet → minted here
  34. static loginCallback = (route, &req, &sessions) => {
  35. if (req.method != 'GET') { return loginFailed(&req, &sessions, 'GET only') }
  36. q = req.query != null ? req.query : {}
  37. code = q.ident_code
  38. if (code == null || code == '') { return loginFailed(&req, &sessions, 'ident sent no login code') }
  39. x = userOfLoginCode(code)
  40. if (x.error != null) { return loginFailed(&req, &sessions, x.error) }
  41. let s = req.session
  42. fresh = s == null
  43. if (fresh) { s = sessions.mint() }
  44. s.user = { id = x.user.id }
  45. s.data.tag = randomBytes(16)
  46. s.data.loginError = null
  47. sessions.save(s)
  48. res = new Response('logged in', { status = 302 headers = { 'Location' = safePath(q.next) 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  49. if (fresh) { res.headers['Set-Cookie'] = sessions.cookieHeader(s.id) }
  50. return res
  51. }
  52. static apiMe = (route, req) => {
  53. u = userIdOfSession(req.session)
  54. return reply(200, { user = u })
  55. }
  56. static apiNotes = (route, req) => {
  57. u = userIdOfSession(req.session)
  58. if (u == null) { return reply(401, { error = 'log in with ident first' }) }
  59. q = req.query != null ? req.query : {}
  60. if (req.method == 'GET') {
  61. if (q.id != null) {
  62. v = noteView(u, q.id)
  63. if (v == null) { return reply(404, { error = 'no such note' }) }
  64. return reply(200, v)
  65. }
  66. return reply(200, { notes = metaRows(u) })
  67. }
  68. if (req.method != 'POST') { return reply(405, { error = 'GET or POST only' }) }
  69. if (req.body == null || req.body == '') { return reply(400, { error = 'a JSON body is needed' }) }
  70. at = jsonErrorAt(req.body)
  71. if (at >= 0) { return reply(400, { error = 'invalid JSON at character ' + at }) }
  72. b = JSON.parse(req.body)
  73. if (b == null || hlTypeName(b) != 'Hybrid') { return reply(400, { error = 'the body must be a JSON object' }) }
  74. if (b.op == 'save') {
  75. if (!isText(b.id) || !isText(b.local) || !isText(b.text) || !isTime(b.base) || !isTime(b.at)) { return reply(400, { error = 'save needs id, local, text (strings) and base, at (numbers)' }) }
  76. if (b.local.length > 64 || b.id.length > 64) { return reply(400, { error = 'id / local too long' }) }
  77. r = pushNote(u, b.id, b.local, b.text, b.base, b.at)
  78. if (r.error != null) { return reply(400, r) }
  79. return reply(200, r)
  80. }
  81. if (b.op == 'delete') {
  82. if (!isText(b.id) || !isTime(b.base)) { return reply(400, { error = 'delete needs id (string) and base (number)' }) }
  83. return reply(200, removeNote(u, b.id, b.base))
  84. }
  85. return reply(400, { error = "op must be 'save' or 'delete'" })
  86. }

Branches

Latest commits

  • 2149e902notes mission 002 (4/4): code order — README file map + same-output test, STATUS, LOG, report; tests/letcount.py, tests/realdata-baseline.mjs, tests/realdata-compare.pymre
  • 47db4fc1notes mission 002 (3/4): code order — let only where reassigned (58 dropped; 34 left: 19 reassigned, 15 loop-bound); gates 50/0 + 18/0, live-data run = step 2mre
  • 3f8cb383notes mission 002 (2/4): code order — topics, map, thin wrappers: lib/util.hl, lib/notes(-helpers).hl, lib/users.hl (+userOfLoginCode, tagOf), lib/api(-helpers).hl; project.hl = map; login routes take &req/&sessions (failed-login reason now kept); dead notes#1 functions removed; gates 50/0 + 18/0mre
  • 8cda5412notes mission 002 (1/4): code order — files moved: lib/notes.hl, lib/users.hl, lib/jsoncheck.hl, components/styles.hl (imports only); gates 50/0 + 18/0, live-data run identicalmre
  • 47dad68bnotes: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 50/0 + 18/0mre
  • a4a2b2aeantcolony#40: tracker missions moved too — references to them in missions/reports/LOG.md updatedmre
  • 3dea0ef2notes: Hybriel master 190aa11d (fc838894 GC correctness, #126 closure scopes, #127); gate 50/0mre
  • e27c7d71notes: Hybriel master 8efba065 (#126 GC by bytes, #48 lambda params copy; audit: nothing to fix; gate 50/0)mre
  • 124613b6antcolony#40: mission references point to the moved missionsmre
  • 1ca2f34dantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 2bebebdanotes: Hybriel master ff51cf46 (re-vendor round)mre
  • 3eff126dnotes#3: installable app (manifest + own icon/favicon; notes' own sw.js kept)mre
  • 9883c540deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • eee693b8deploy.sh: never send .git or .gitignore to Byrodinmre
  • c8904061State of 2026-09-27, before the move to gitoriamre