{"messages":[{"content":"You are a constitutional council ranking individual git commits for ownership allocation.\n\nCompare these two commits. Decide which contributed more lasting value to the project.\n\nJudge substance, not spectacle:\n- Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise.\n- Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one.\n- Do not favor a side merely because its patch is longer or noisier.\n- Weight what the change does for the project, not the contributor's name.\n\nReturn ONLY a JSON object: {\"winner\": \"A\" or \"B\", \"ratio\": \"N:M\", \"explanation\": \"...\"}\nThe explanation must cite concrete differences in the patches (1-3 sentences).\n\nSide A — contributor: tommy-mor\nSide A — commit message:\n[075d4d37] Fix OAuth test mocks so Clojure E2E auth flows work again.\n\nHttpServer handlers were crashing on query parsing and token POSTs, which broke Playwright login; also read alias/history via real CSS selectors.\n\nCo-authored-by: Cursor \n\nSide A — unified diff (full patch):\ndiff --git a/test/auth_login.clj b/test/auth_login.clj\nindex 6f2f00d7aa7340e63d1ac465b0a2234cec7a983f..aa63b66ccb2471b710ba3d168d0461252b39fc10 100644\n--- a/test/auth_login.clj\n+++ b/test/auth_login.clj\n@@ -14,27 +14,27 @@\n (defn- type-alias! [pg text]\n (page/evaluate pg\n (.replace\n- \"(() => { const i = document.getElementById('alias-input'); const f = document.getElementById('alias-check-form'); if (!i || !f) return;\n+ \"(() => { const i = document.getElementById('alias-input'); const f = document.getElementById('alias-check-form'); if (!i || !f) return Promise.resolve('missing-form');\n i.value = __TEXT__;\n const cf = document.getElementById('alias-claim-field'); if (cf) cf.value = i.value;\n return fetch(f.action, { method: 'POST', credentials: 'same-origin',\n headers: { 'Content-Type': 'application/x-www-form-urlencoded' },\n body: new URLSearchParams(new FormData(f)).toString() })\n .then(function (r) { return r.text(); })\n- .then(function (t) { eval(t); }); })()\"\n+ .then(function (t) { eval(t); return document.getElementById('alias-status')?.textContent || ''; }); })()\"\n \"__TEXT__\"\n- (pr-str text)))\n- (Thread/sleep 400))\n+ (pr-str text))))\n \n-(defn- element-text [pg test-id]\n+(defn- element-text [pg selector]\n (let [raw (page/evaluate pg\n- (str \"document.querySelector('[data-testid=\\\"\" test-id \"\\\"]')?.textContent || ''\"))]\n+ (str \"document.querySelector(\" (pr-str selector) \")?.textContent || ''\"))]\n (when (string? raw) (str/trim raw))))\n \n (defn- wait-for-text [pg test-id text timeout-ms]\n- (let [deadline (+ (System/currentTimeMillis) timeout-ms)]\n+ (let [deadline (+ (System/currentTimeMillis) timeout-ms)\n+ selector (str \"[data-testid=\\\"\" test-id \"\\\"]\")]\n (loop []\n- (let [got (or (element-text pg test-id) \"\")]\n+ (let [got (or (element-text pg selector) \"\")]\n (cond\n (= got text) got\n (< (System/currentTimeMillis) deadline) (do (Thread/sleep 200) (recur))\ndiff --git a/test/support/mock_oauth.clj b/test/support/mock_oauth.clj\nindex 5ba7e9be3cf6d2226648e9609a09ed45f306930f..333fe08d56cb06bac2a338cad1c73894d54c4495 100644\n--- a/test/support/mock_oauth.clj\n+++ b/test/support/mock_oauth.clj\n@@ -7,7 +7,7 @@\n (defn- query-param [query key]\n (when query\n (some (fn [pair]\n- (let [[k v] (str/split pair \"=\" 2)]\n+ (let [[k v] (str/split pair #\"=\" 2)]\n (when (= k key)\n (URLDecoder/decode (or v \"\") \"UTF-8\"))))\n (str/split query #\"&\"))))\n@@ -31,11 +31,11 @@\n \n (defn- send-redirect [^HttpExchange ex location]\n (.set (.getResponseHeaders ex) \"Location\" location)\n- (.sendResponseHeaders ex 302 -1)\n+ (.sendResponseHeaders ex 302 0)\n (.close (.getResponseBody ex)))\n \n (defn- read-form [^HttpExchange ex]\n- (let [body (slurp (.getInputStream ex))]\n+ (let [body (slurp (.getRequestBody ex))]\n {:code (query-param body \"code\")\n :grant (query-param body \"grant_type\")}))\n \n@@ -45,7 +45,7 @@\n (str/replace #\"^[Bb]earer \" \"\")))\n \n (defn- parse-token-user [token]\n- (when (str/starts-with? token \"mock:\")\n+ (when (and token (str/starts-with? token \"mock:\"))\n (parse-mock-user (subs token 5))))\n \n (defn- authorize-redirect [exchange query]\n@@ -55,7 +55,7 @@\n user (parse-mock-user mock-user)\n code (str \"mock:\" (:id user) \":\" (:login user))\n loc (str redirect-uri \"?code=\" (java.net.URLEncoder/encode code \"UTF-8\")\n- \"&state=\" (java.net.URLEncoder/encode state \"UTF-8\"))]\n+ \"&state=\" (java.net.URLEncoder/encode (or state \"\") \"UTF-8\"))]\n (send-redirect exchange loc)))\n \n (defn start-mock-oauth\n@@ -65,49 +65,56 @@\n handler\n (proxy [HttpHandler] []\n (handle [^HttpExchange exchange]\n- (let [uri (.getRequestURI exchange)\n- path (.getPath uri)\n- query (.getQuery uri)\n- method (.getRequestMethod exchange)]\n- (cond\n- ;; GitHub authorize\n- (str/ends-with? path \"/login/oauth/authorize\")\n- (authorize-redirect exchange query)\n+ (try\n+ (let [uri (.getRequestURI exchange)\n+ path (.getPath uri)\n+ query (.getQuery uri)\n+ method (.getRequestMethod exchange)]\n+ (cond\n+ ;; GitHub authorize\n+ (str/ends-with? path \"/login/oauth/authorize\")\n+ (authorize-redirect exchange query)\n \n- ;; Reddit authorize\n- (str/ends-with? path \"/api/v1/authorize\")\n- (authorize-redirect exchange query)\n+ ;; Reddit authorize\n+ (str/ends-with? path \"/api/v1/authorize\")\n+ (authorize-redirect exchange query)\n \n- ;; GitHub token\n- (and (= method \"POST\") (str/ends-with? path \"/login/oauth/access_token\"))\n- (let [code (or (:code (read-form exchange)) \"mock:1002:newbie\")]\n- (send-json exchange 200 (str \"{\\\"access_token\\\":\\\"\" code \"\\\",\\\"token_type\\\":\\\"bearer\\\"}\")))\n+ ;; GitHub token\n+ (and (= method \"POST\") (str/ends-with? path \"/login/oauth/access_token\"))\n+ (let [code (or (:code (read-form exchange)) \"mock:1002:newbie\")]\n+ (send-json exchange 200 (str \"{\\\"access_token\\\":\\\"\" code \"\\\",\\\"token_type\\\":\\\"bearer\\\"}\")))\n \n- ;; Reddit token (client_credentials for import + authorization_code for login)\n- (and (= method \"POST\") (str/ends-with? path \"/api/v1/access_token\"))\n- (let [form (read-form exchange)\n- grant (or (:grant form) \"\")\n- code (or (:code form) \"mock:t2_test:redditor\")]\n- (if (= grant \"client_credentials\")\n- (send-json exchange 200 \"{\\\"access_token\\\":\\\"app-token\\\",\\\"token_type\\\":\\\"bearer\\\",\\\"expires_in\\\":3600}\")\n- (send-json exchange 200 (str \"{\\\"access_token\\\":\\\"\" code \"\\\",\\\"token_type\\\":\\\"bearer\\\",\\\"expires_in\\\":3600}\"))))\n+ ;; Reddit token (client_credentials for import + authorization_code for login)\n+ (and (= method \"POST\") (str/ends-with? path \"/api/v1/access_token\"))\n+ (let [form (read-form exchange)\n+ grant (or (:grant form) \"\")\n+ code (or (:code form) \"mock:t2_test:redditor\")]\n+ (if (= grant \"client_credentials\")\n+ (send-json exchange 200 \"{\\\"access_token\\\":\\\"app-token\\\",\\\"token_type\\\":\\\"bearer\\\",\\\"expires_in\\\":3600}\")\n+ (send-json exchange 200 (str \"{\\\"access_token\\\":\\\"\" code \"\\\",\\\"token_type\\\":\\\"bearer\\\",\\\"expires_in\\\":3600}\"))))\n \n- ;; GitHub user\n- (= path \"/user\")\n- (let [token (bearer-token exchange)\n- user (or (parse-token-user token) {:id \"1002\" :login \"newbie\" :numeric? true})]\n- (send-json exchange 200\n- (str \"{\\\"id\\\":\" (:id user) \",\\\"login\\\":\\\"\" (:login user) \"\\\"}\")))\n+ ;; GitHub user\n+ (= path \"/user\")\n+ (let [token (bearer-token exchange)\n+ user (or (parse-token-user token) {:id \"1002\" :login \"newbie\" :numeric? true})]\n+ (send-json exchange 200\n+ (str \"{\\\"id\\\":\" (:id user) \",\\\"login\\\":\\\"\" (:login user) \"\\\"}\")))\n \n- ;; Reddit /api/v1/me\n- (str/ends-with? path \"/api/v1/me\")\n- (let [token (bearer-token exchange)\n- user (or (parse-token-user token) {:id \"t2_test\" :login \"redditor\"})]\n- (send-json exchange 200\n- (str \"{\\\"id\\\":\\\"\" (:id user) \"\\\",\\\"name\\\":\\\"\" (:login user) \"\\\"}\")))\n+ ;; Reddit /api/v1/me\n+ (str/ends-with? path \"/api/v1/me\")\n+ (let [token (bearer-token exchange)\n+ user (or (parse-token-user token) {:id \"t2_test\" :login \"redditor\"})]\n+ (send-json exchange 200\n+ (str \"{\\\"id\\\":\\\"\" (:id user) \"\\\",\\\"name\\\":\\\"\" (:login user) \"\\\"}\")))\n \n- :else\n- (send-json exchange 404 \"{\\\"error\\\":\\\"not found\\\"}\")))))]\n+ :else\n+ (send-json exchange 404 \"{\\\"error\\\":\\\"not found\\\"}\")))\n+ (catch Throwable t\n+ (binding [*out* *err*]\n+ (println \"mock-oauth handler error:\" t))\n+ (try\n+ (send-json exchange 500 \"{\\\"error\\\":\\\"mock-oauth internal\\\"}\")\n+ (catch Throwable _))))))]\n (.createContext server \"/\" handler)\n (.setExecutor server nil)\n (.start server)\ndiff --git a/test/support/mock_reddit.clj b/test/support/mock_reddit.clj\nindex a630cf0938722193e9af88382d60e777ff371be4..faa27945b6394363914c853627a0bad1e819a5f9 100644\n--- a/test/support/mock_reddit.clj\n+++ b/test/support/mock_reddit.clj\n@@ -12,7 +12,7 @@\n (defn- query-param [query key]\n (when query\n (some (fn [pair]\n- (let [[k v] (str/split pair \"=\" 2)]\n+ (let [[k v] (str/split pair #\"=\" 2)]\n (when (= k key)\n (URLDecoder/decode (or v \"\") \"UTF-8\"))))\n (str/split query #\"&\"))))\n@@ -34,11 +34,11 @@\n \n (defn- send-redirect [^HttpExchange ex location]\n (.set (.getResponseHeaders ex) \"Location\" location)\n- (.sendResponseHeaders ex 302 -1)\n+ (.sendResponseHeaders ex 302 0)\n (.close (.getResponseBody ex)))\n \n (defn- read-form [^HttpExchange ex]\n- (let [body (slurp (.getInputStream ex))]\n+ (let [body (slurp (.getRequestBody ex))]\n {:code (query-param body \"code\")\n :grant (query-param body \"grant_type\")}))\n \n@@ -48,7 +48,7 @@\n (str/replace #\"^[Bb]earer \" \"\")))\n \n (defn- parse-token-user [token]\n- (when (str/starts-with? token \"mock:\")\n+ (when (and token (str/starts-with? token \"mock:\"))\n (parse-mock-user (subs token 5))))\n \n (defn start-mock-reddit\n@@ -72,7 +72,7 @@\n user (parse-mock-user (query-param query \"mock_user\"))\n code (str \"mock:\" (:id user) \":\" (:login user))\n loc (str redirect-uri \"?code=\" (java.net.URLEncoder/encode code \"UTF-8\")\n- \"&state=\" (java.net.URLEncoder/encode state \"UTF-8\"))]\n+ \"&state=\" (java.net.URLEncoder/encode (or state \"\") \"UTF-8\"))]\n (send-redirect exchange loc))\n \n (and (= method \"POST\") (str/ends-with? path \"/api/v1/access_token\"))\n\n\nSide B — contributor: tommy-mor\nSide B — commit message:\n[6120bd96] fix redirect urls for custom hosts and deploy from staging\n\nUse HOSTNAME and window.location.origin instead of hardcoded staging.sorter.social, and trigger fly deploys on pushes to staging.\n\nCo-authored-by: Cursor \n\nSide B — unified diff (full patch):\ndiff --git a/.github/workflows/fly-deploy.yml b/.github/workflows/fly-deploy.yml\nindex 3e693915fe6f99a5c2221b2921bf8ebc305180fc..5e11e5c312f62bed34d8cc68bd4a5538f52476b9 100644\n--- a/.github/workflows/fly-deploy.yml\n+++ b/.github/workflows/fly-deploy.yml\n@@ -3,11 +3,11 @@ name: deploy to fly.io\n on:\n push:\n branches:\n- - main\n+ - staging\n workflow_dispatch:\n \n concurrency:\n- group: fly-deploy-main\n+ group: fly-deploy-staging\n cancel-in-progress: true\n \n jobs:\ndiff --git a/borter/src/app/linear.clj b/borter/src/app/linear.clj\nindex f77d8a974e0cf05f9c33233bb625bdb190d2007b..5ef0e34cf1d543826675c6facb66aec079b40561 100644\n--- a/borter/src/app/linear.clj\n+++ b/borter/src/app/linear.clj\n@@ -6,6 +6,7 @@\n [ring.util.response :as response]\n [app.database :as db]\n [app.permissions :as perms]\n+ [app.util :as util]\n [honey.sql.helpers :as h]\n [sluj.core :refer [sluj]]))\n \n@@ -13,9 +14,7 @@\n (def client-secret (System/getenv \"BORTER_LINEAR_CLIENT_SECRET\"))\n \n (defn get-hostname []\n- (case (.getCanonicalHostName (java.net.InetAddress/getLocalHost))\n- \"sorter.social\" \"https://sorter.social/api/linear/callback\"\n- \"http://localhost:3000/api/linear/callback\"))\n+ (str (util/get-base-url) \"/api/linear/callback\"))\n \n (defn code->token [code]\n (def code code)\ndiff --git a/borter/src/app/login.clj b/borter/src/app/login.clj\nindex 5d545db9bef7765ba8b3fe7d00261c8ce84e9e1a..86817f8e94bc174e5b108859cc0b342953ab7acb 100644\n--- a/borter/src/app/login.clj\n+++ b/borter/src/app/login.clj\n@@ -1,6 +1,7 @@\n (ns app.login\n (:require [crypto.password.bcrypt :as password]\n [app.database :as db]\n+ [app.util :as util]\n [honey.sql.helpers :as h]\n [hato.client :as hc]\n [clojure.data.json :as json]\n@@ -12,10 +13,7 @@\n (def environment (or (System/getenv \"ENVIRONMENT\") \"development\"))\n \n (defn get-base-url []\n- (case environment\n- \"production\" \"https://sorter.social\"\n- \"staging\" \"https://staging.sorter.social\"\n- \"development\" \"http://localhost:3000\")) ; fallback for development\n+ (util/get-base-url))\n \n (defn create-email-content\n \"Creates a standardized email structure with customizable content\"\ndiff --git a/borter/src/app/oauth.clj b/borter/src/app/oauth.clj\nindex 1166f2ee30c9e813840711c72d1ad8f1c62e1ffe..2cd0c62f1fe267f7f5f725a97bc3ba0d0889517f 100644\n--- a/borter/src/app/oauth.clj\n+++ b/borter/src/app/oauth.clj\n@@ -3,6 +3,7 @@\n [clojure.data.json :as json]\n [hato.client :as hc]\n [app.database :as db]\n+ [app.util :as util]\n [honey.sql.helpers :as h]\n [ring.util.codec :as codec])\n (:import [java.util Base64]))\n@@ -13,12 +14,7 @@\n encoded-bytes))\n \n (defn get-hostname []\n- (let [env (System/getenv \"ENVIRONMENT\")]\n- (println \"Current environment:\" env)\n- (case env\n- \"production\" \"https://sorter.social\"\n- \"staging\" \"https://staging.sorter.social\"\n- \"http://localhost:3000\")))\n+ (util/get-base-url))\n \n (defn get-origin-hostname [req]\n (let [origin (get-in req [:headers \"origin\"])\ndiff --git a/borter/src/app/spotify.clj b/borter/src/app/spotify.clj\nindex 3e11713119141812fa2707ec956fb7ed612ee69a..b38d734351a1d4f1e142d93d4435ffe7bd20c02d 100644\n--- a/borter/src/app/spotify.clj\n+++ b/borter/src/app/spotify.clj\n@@ -1,5 +1,6 @@\n (ns app.spotify\n (:require [app.oauth :as oauth]\n+ [app.util :as util]\n [hato.client :as hc]\n [clojure.data.json :as json]\n [ring.util.codec :as codec]\n@@ -47,10 +48,7 @@\n \n \n (defn get-hostname []\n- (case (System/getenv \"ENVIRONMENT\")\n- \"production\" \"https://sorter.social\"\n- \"staging\" \"https://staging.sorter.social\"\n- \"http://localhost:3000\"))\n+ (util/get-base-url))\n \n (defn create-spotify-tag\n \"Creates a tag for a Spotify entity (artist, album, track) if it doesn't exist\"\ndiff --git a/borter/src/app/twitter.clj b/borter/src/app/twitter.clj\nindex ef7b18fa1fcb82bb944b3035ffed44499181237f..b9a3fdccc15d13918a4d11d8c0443de94fd172b4 100644\n--- a/borter/src/app/twitter.clj\n+++ b/borter/src/app/twitter.clj\n@@ -1,6 +1,7 @@\n (ns app.twitter\n (:require [app.database :as db]\n [app.permissions :as perms]\n+ [app.util :as util]\n [honey.sql.helpers :as h]\n [hato.client :as hc]\n [clojure.data.json :as json]\n@@ -37,9 +38,7 @@\n (clojure.string/join \"&\" (map (fn [[k v]] (str (name k) \"=\" v)) params)))\n \n (defn get-hostname []\n- (case (.getCanonicalHostName (java.net.InetAddress/getLocalHost))\n- \"sorter.isnt.online\" \"https://sorter.isnt.online/api/twitter/callback\"\n- \"http://localhost:3000/api/twitter/callback\"))\n+ (str (util/get-base-url) \"/api/twitter/callback\"))\n \n (defn encode-b64 [s]\n (.encodeToString (java.util.Base64/getEncoder) (.getBytes s)))\ndiff --git a/borter/src/app/util.clj b/borter/src/app/util.clj\nindex 384a64306c84aa8288ec44cd5de57edc248a826d..6a8aa0875accb28dc81bf57e645e3961b0a3ace5 100644\n--- a/borter/src/app/util.clj\n+++ b/borter/src/app/util.clj\n@@ -2,6 +2,18 @@\n (:require [clojure.string :as string])\n (:import [java.net URLEncoder]))\n \n+(defn get-base-url\n+ \"Public site base URL for redirects and oauth callbacks.\"\n+ []\n+ (if-let [hostname (not-empty (System/getenv \"HOSTNAME\"))]\n+ (if (string/starts-with? hostname \"http\")\n+ (string/replace hostname #\"/$\" \"\")\n+ (str \"https://\" (string/replace hostname #\"/$\" \"\")))\n+ (case (or (System/getenv \"ENVIRONMENT\") \"development\")\n+ \"production\" \"https://sorter.social\"\n+ \"staging\" \"https://staging.sorter.social\"\n+ \"http://localhost:3000\")))\n+\n (defn urlencode-params [params]\n (clojure.string/join \"&\" (map (fn [[k v]] (str k \"=\" (URLEncoder/encode (str v) \"UTF-8\"))) params)))\n \ndiff --git a/borter/src/app/youtube.clj b/borter/src/app/youtube.clj\nindex 647ef7c6d4f2503a63a7c074d46dc815b2a23547..fc9a2f5ed516692f19e06b4c0221f510547cf8c0 100644\n--- a/borter/src/app/youtube.clj\n+++ b/borter/src/app/youtube.clj\n@@ -6,6 +6,7 @@\n [ring.util.response :as response]\n [app.database :as db]\n [app.permissions :as perms]\n+ [app.util :as util]\n [honey.sql.helpers :as h]\n [sluj.core :refer [sluj]]))\n \n@@ -32,9 +33,7 @@\n :body (json/read-str {:key-fn keyword})))\n \n (defn get-hostname []\n- (case (.getCanonicalHostName (java.net.InetAddress/getLocalHost))\n- \"localhost\" \"http://localhost:3000/api/youtube/callback\"\n- \"https://sorter.isnt.online/api/youtube/callback\"))\n+ (str (util/get-base-url) \"/api/youtube/callback\"))\n \n \n \ndiff --git a/forter/src/utils/authUtils.js b/forter/src/utils/authUtils.js\nindex 145e5db7ad6f7a6439d68c63beb4d07d31b2de08..98ed7fa671f9887f44dc1479d85569951eb4773e 100644\n--- a/forter/src/utils/authUtils.js\n+++ b/forter/src/utils/authUtils.js\n@@ -5,8 +5,11 @@ import { current_session, fetchSession } from \"../session\";\n let lastSyncTime = 0;\n const SYNC_THROTTLE_MS = 5000; // Only sync once every 5 seconds\n \n-// Get base URL based on Vite's mode\n+// Get base URL based on current origin, with build-mode fallbacks for SSR/build\n const getBaseUrl = () => {\n+ if (typeof window !== 'undefined' && window.location?.origin) {\n+ return window.location.origin;\n+ }\n switch (import.meta.env.MODE) {\n case 'production':\n return 'https://sorter.social';\n","role":"user"}],"model":"openai/gpt-chat-latest"}