{"messages":[{"content":"You are a constitutional council ranking individual git commits for ownership allocation.\n\nCompare these two commits. Decide which contributed more lasting value to the project.\n\nJudge substance, not spectacle:\n- Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise.\n- Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one.\n- Do not favor a side merely because its patch is longer or noisier.\n- Weight what the change does for the project, not the contributor's name.\n\nReturn ONLY a JSON object: {\"winner\": \"A\" or \"B\", \"ratio\": \"N:M\", \"explanation\": \"...\"}\nThe explanation must cite concrete differences in the patches (1-3 sentences).\n\nSide A — contributor: tommy-mor\nSide A — commit message:\n[3f35edab] progress\n\nSide A — unified diff (full patch):\ndiff --git a/server/src/api/mod.rs b/server/src/api/mod.rs\nindex a10ce662105cff8fad949c6b83f7035ce79bed18..a986f706ea4b261cbaf004c02b4cf84184b41371 100644\n--- a/server/src/api/mod.rs\n+++ b/server/src/api/mod.rs\n@@ -3,6 +3,7 @@ mod helpers;\n mod rpc;\n mod stream;\n mod validate;\n+mod ui_html;\n mod web_post;\n \n pub use auth::{\n@@ -33,6 +34,7 @@ pub use stream::{get_html_stream, get_stream};\n \n pub use validate::{normalize_room_and_thread, validate_ingest_document, ValidatedIngest};\n \n+pub use ui_html::post_ui_html;\n pub use web_post::{check_web_ingest, post_web_ingest, post_web_redact};\n \n #[cfg(test)]\ndiff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs\nnew file mode 100644\nindex 0000000000000000000000000000000000000000..2b40a72059981d558768f73d189b991f3448c257\n--- /dev/null\n+++ b/server/src/api/ui_html.rs\n@@ -0,0 +1,139 @@\n+//! Single `POST /ui` entry for browser [`crate::html::ui_action::HtmlUiAction`] (JSON in `__rpc__` + holes).\n+\n+use axum::{\n+ body::Body,\n+ extract::State,\n+ http::{header, HeaderMap, StatusCode},\n+ response::{IntoResponse, Response},\n+ Form,\n+};\n+use axum_extra::extract::cookie::CookieJar;\n+use std::collections::HashMap;\n+\n+use crate::{\n+ api::{\n+ auth::optional_principal,\n+ web_post::{run_check_web_ingest, run_post_web_ingest, run_post_web_redact, WebPostForm, WebRedactForm},\n+ },\n+ html::{\n+ fragment_public_new_thread_form, fragment_room_new_thread_form, login_to_post_hint_markup,\n+ parse_html_ui_from_form, user_can_post_room, user_can_view_room, HtmlUiAction, JsBuilder,\n+ ThreadNav,\n+ },\n+ state::AppState,\n+};\n+\n+pub async fn post_ui_html(\n+ State(state): State,\n+ headers: HeaderMap,\n+ jar: CookieJar,\n+ Form(form): Form>,\n+) -> impl IntoResponse {\n+ let action = match parse_html_ui_from_form(&form) {\n+ Ok(a) => a,\n+ Err(e) => return ui_js_warn(&e.to_string()).into_response(),\n+ };\n+\n+ match action {\n+ HtmlUiAction::PostIngest {\n+ room,\n+ thread_tag,\n+ text,\n+ error_target,\n+ form_id,\n+ } => {\n+ run_post_web_ingest(\n+ &state,\n+ &headers,\n+ &jar,\n+ WebPostForm {\n+ room,\n+ thread_tag,\n+ text,\n+ error_target,\n+ form_id,\n+ },\n+ )\n+ .await\n+ }\n+ HtmlUiAction::CheckIngest {\n+ room,\n+ thread_tag,\n+ text,\n+ error_target,\n+ form_id,\n+ } => {\n+ run_check_web_ingest(\n+ &state,\n+ &headers,\n+ &jar,\n+ WebPostForm {\n+ room,\n+ thread_tag,\n+ text,\n+ error_target,\n+ form_id,\n+ },\n+ )\n+ .await\n+ }\n+ HtmlUiAction::RedactPost { post_id } => {\n+ run_post_web_redact(&state, &headers, &jar, WebRedactForm { post_id }).await\n+ }\n+ HtmlUiAction::ExpandPublicNewThreadForm => {\n+ let reduced = state.reduced.read().await;\n+ let user = optional_principal(&headers, &jar, &reduced);\n+ drop(reduced);\n+ let markup = if user.is_some() {\n+ fragment_public_new_thread_form(true)\n+ } else {\n+ login_to_post_hint_markup()\n+ };\n+ JsBuilder::new()\n+ .morph_selector(\"#public-new-thread-ui-slot\", markup)\n+ .into_response()\n+ }\n+ HtmlUiAction::ExpandRoomNewThreadForm { room_wire } => {\n+ let room_wire = room_wire.trim().to_string();\n+ if room_wire.is_empty() {\n+ return ui_js_warn(\"missing room\").into_response();\n+ }\n+ let reduced = state.reduced.read().await;\n+ let user = optional_principal(&headers, &jar, &reduced);\n+ if !reduced.rooms.contains(&room_wire) {\n+ drop(reduced);\n+ return ui_js_warn(\"room not found\").into_response();\n+ }\n+ if !user_can_view_room(&reduced, &room_wire, user.as_deref()) {\n+ drop(reduced);\n+ return ui_js_warn(\"forbidden\").into_response();\n+ }\n+ let can_post = user\n+ .as_ref()\n+ .map(|u| user_can_post_room(&reduced, &room_wire, u))\n+ .unwrap_or(false);\n+ drop(reduced);\n+ let Some(nav) = ThreadNav::from_room_id(&room_wire) else {\n+ return ui_js_warn(\"bad room\").into_response();\n+ };\n+ let markup = if can_post {\n+ fragment_room_new_thread_form(&nav, true)\n+ } else {\n+ login_to_post_hint_markup()\n+ };\n+ JsBuilder::new()\n+ .morph_selector(\"#room-new-thread-ui-slot\", markup)\n+ .into_response()\n+ }\n+ }\n+}\n+\n+fn ui_js_warn(msg: &str) -> Response {\n+ use crate::html::js_string_literal;\n+ let js = format!(\"console.warn({});\", js_string_literal(msg));\n+ Response::builder()\n+ .status(StatusCode::OK)\n+ .header(header::CONTENT_TYPE, \"text/javascript; charset=utf-8\")\n+ .body(Body::from(js))\n+ .unwrap()\n+}\ndiff --git a/server/src/api/web_post.rs b/server/src/api/web_post.rs\nindex a64010e382d3039821c836a5529adad0fe67cce5..265025f41ff1548d05b2d2d5d84202245388053f 100644\n--- a/server/src/api/web_post.rs\n+++ b/server/src/api/web_post.rs\n@@ -222,8 +222,18 @@ pub async fn post_web_redact(\n jar: CookieJar,\n Form(form): Form,\n ) -> impl IntoResponse {\n+ run_post_web_redact(&state, &headers, &jar, form).await\n+}\n+\n+/// Shared with [`crate::api::ui_html::post_ui_html`].\n+pub(crate) async fn run_post_web_redact(\n+ state: &AppState,\n+ headers: &HeaderMap,\n+ jar: &CookieJar,\n+ form: WebRedactForm,\n+) -> Response {\n let reduced = state.reduced.read().await;\n- let Some(_username) = optional_principal(&headers, &jar, &reduced) else {\n+ let Some(_username) = optional_principal(headers, jar, &reduced) else {\n drop(reduced);\n return js_redirect(\"/login\").into_response();\n };\n@@ -239,8 +249,8 @@ pub async fn post_web_redact(\n return js_redirect(\"/login\").into_response();\n };\n \n- match rpc_post_redact(&state, &headers, form.post_id).await {\n- Ok(RpcResult::RedactPostOk {}) => redact_success_response(&state).await.into_response(),\n+ match rpc_post_redact(state, headers, form.post_id).await {\n+ Ok(RpcResult::RedactPostOk {}) => redact_success_response(state).await.into_response(),\n Ok(_) => (StatusCode::BAD_REQUEST, \"unexpected response\").into_response(),\n Err((msg, hint)) => {\n let detail = hint.as_deref().unwrap_or(\"\");\n@@ -255,8 +265,18 @@ pub async fn post_web_ingest(\n jar: CookieJar,\n Form(form): Form,\n ) -> impl IntoResponse {\n+ run_post_web_ingest(&state, &headers, &jar, form).await\n+}\n+\n+/// Shared with [`crate::api::ui_html::post_ui_html`] (`POST /ui`).\n+pub(crate) async fn run_post_web_ingest(\n+ state: &AppState,\n+ headers: &HeaderMap,\n+ jar: &CookieJar,\n+ form: WebPostForm,\n+) -> Response {\n let reduced = state.reduced.read().await;\n- let Some(_username) = optional_principal(&headers, &jar, &reduced) else {\n+ let Some(_username) = optional_principal(headers, jar, &reduced) else {\n drop(reduced);\n return js_redirect(\"/login\").into_response();\n };\n@@ -282,8 +302,8 @@ pub async fn post_web_ingest(\n .into_response();\n }\n \n- match rpc_post_with_bearer(&state, &bearer, room.clone(), thread_tag.clone(), text).await {\n- Ok(RpcResult::PostOk { .. }) => post_success_response(&state, &form, &headers, &jar)\n+ match rpc_post_with_bearer(state, &bearer, room.clone(), thread_tag.clone(), text).await {\n+ Ok(RpcResult::PostOk { .. }) => post_success_response(state, &form, headers, jar)\n .await\n .into_response(),\n Ok(_) => form_js_error(&form, \"unexpected response\", \"Post did not return PostOk.\").into_response(),\n@@ -297,8 +317,18 @@ pub async fn check_web_ingest(\n jar: CookieJar,\n Form(form): Form,\n ) -> impl IntoResponse {\n+ run_check_web_ingest(&state, &headers, &jar, form).await\n+}\n+\n+/// Shared with [`crate::api::ui_html::post_ui_html`] (`POST /ui`).\n+pub(crate) async fn run_check_web_ingest(\n+ state: &AppState,\n+ headers: &HeaderMap,\n+ jar: &CookieJar,\n+ form: WebPostForm,\n+) -> Response {\n let reduced = state.reduced.read().await;\n- let Some(_username) = optional_principal(&headers, &jar, &reduced) else {\n+ let Some(_username) = optional_principal(headers, jar, &reduced) else {\n drop(reduced);\n return js_redirect(\"/login\").into_response();\n };\n@@ -324,7 +354,7 @@ pub async fn check_web_ingest(\n return js_clear_errors(&form_error_target(&form)).into_response();\n }\n \n- match rpc_check_with_bearer(&state, &bearer, room, form.text.clone()).await {\n+ match rpc_check_with_bearer(state, &bearer, room, form.text.clone()).await {\n Ok(RpcResult::CheckOk { .. }) => js_clear_errors(&form_error_target(&form)).into_response(),\n Ok(_) => form_js_error(&form, \"unexpected response\", \"Check did not return CheckOk.\").into_response(),\n Err((msg, hint)) => form_js_error(&form, &msg, hint.as_deref().unwrap_or(\"\")).into_response(),\ndiff --git a/server/src/form_template.rs b/server/src/form_template.rs\nnew file mode 100644\nindex 0000000000000000000000000000000000000000..3709c2c09a859da006e4af173413d5d235bc19be\n--- /dev/null\n+++ b/server/src/form_template.rs\n@@ -0,0 +1,142 @@\n+//! Plan2-style JSON templates with `{\"$form\": \"field_name\"}` holes, filled from\n+//! `application/x-www-form-urlencoded` (or any `String` → `String` map) **before**\n+//! deserializing into a typed struct.\n+//!\n+//! # Wire format\n+//!\n+//! Templates are **compact JSON** (`serde_json::to_string`): one line, no pretty\n+//! printing, strings escaped per JSON rules (`\\\"`, `\\n`, etc.). Embed that string\n+//! in HTML attributes or text nodes with normal HTML escaping (e.g. maud), not\n+//! bespoke encodings.\n+//!\n+//! # Power vs flat hidden fields\n+//!\n+//! A form is always a string→string map. You can fake depth with dotted keys (`a.b.c`),\n+//! but one structured blob (`__rpc__` = compact JSON) gives you nested objects,\n+//! arrays, and optional fields without inventing a new naming scheme each time.\n+//!\n+//! # Security\n+//!\n+//! Substitution runs **before** `serde` into your command type. It does not fix\n+//! authorization: if the client can replace the hidden `__rpc__` value, they can\n+//! change the command shape unless you validate (signed blob, server-side session\n+//! context, or treat the blob as hints only). Same threat model as any hidden field.\n+\n+use serde::Serialize;\n+use serde_json::Value;\n+use std::collections::HashMap;\n+\n+/// Serialize a value to compact JSON for a hidden `__rpc__` (or similar) field.\n+pub fn template_json_compact(v: &T) -> serde_json::Result {\n+ serde_json::to_string(v)\n+}\n+\n+/// Recursively walk the JSON AST and replace `{\"$form\": \"key\"}` with the submitted\n+/// string for `key` (empty if missing). Other keys are unchanged.\n+pub fn substitute_form_vars(val: &mut Value, form_data: &HashMap) {\n+ match val {\n+ Value::Object(map) => {\n+ if map.len() == 1 {\n+ if let Some(Value::String(field_name)) = map.get(\"$form\") {\n+ let submitted = form_data\n+ .get(field_name.as_str())\n+ .map(|s| s.as_str())\n+ .unwrap_or(\"\");\n+ *val = Value::String(submitted.to_string());\n+ return;\n+ }\n+ }\n+ for v in map.values_mut() {\n+ substitute_form_vars(v, form_data);\n+ }\n+ }\n+ Value::Array(arr) => {\n+ for v in arr.iter_mut() {\n+ substitute_form_vars(v, form_data);\n+ }\n+ }\n+ _ => {}\n+ }\n+}\n+\n+/// Parse JSON, apply [`substitute_form_vars`], return the mutated value.\n+pub fn fill_template_from_form(\n+ template_json: &str,\n+ form_data: &HashMap,\n+) -> Result {\n+ let mut v: Value = serde_json::from_str(template_json)?;\n+ substitute_form_vars(&mut v, form_data);\n+ Ok(v)\n+}\n+\n+#[cfg(test)]\n+mod tests {\n+ use super::*;\n+ use serde::Deserialize;\n+\n+ #[derive(Debug, Deserialize, PartialEq, Eq)]\n+ struct Demo {\n+ room: String,\n+ thread_tag: String,\n+ nested: Nested,\n+ }\n+\n+ #[derive(Debug, Deserialize, PartialEq, Eq)]\n+ struct Nested {\n+ text: String,\n+ }\n+\n+ #[test]\n+ fn holes_become_strings() {\n+ let json = r#\"{\n+ \"room\": \"public\",\n+ \"thread_tag\": {\"$form\": \"tag\"},\n+ \"nested\": {\"text\": {\"$form\": \"body\"}}\n+ }\"#;\n+ let mut form = HashMap::new();\n+ form.insert(\"tag\".into(), \"foo\".into());\n+ form.insert(\"body\".into(), \"hello\\nworld\".into());\n+\n+ let v = fill_template_from_form(json, &form).unwrap();\n+ let d: Demo = serde_json::from_value(v).unwrap();\n+ assert_eq!(\n+ d,\n+ Demo {\n+ room: \"public\".into(),\n+ thread_tag: \"foo\".into(),\n+ nested: Nested {\n+ text: \"hello\\nworld\".into(),\n+ },\n+ }\n+ );\n+ }\n+\n+ #[test]\n+ fn missing_form_key_is_empty_string() {\n+ let json = r#\"{\"x\": {\"$form\": \"nope\"}}\"#;\n+ let mut form = HashMap::new();\n+ form.insert(\"other\".into(), \"y\".into());\n+ let v = fill_template_from_form(json, &form).unwrap();\n+ assert_eq!(v[\"x\"], \"\");\n+ }\n+\n+ #[test]\n+ fn array_of_holes() {\n+ let json = r#\"{\"items\": [{\"$form\": \"a\"}, {\"$form\": \"b\"}]}\"#;\n+ let mut form = HashMap::new();\n+ form.insert(\"a\".into(), \"1\".into());\n+ form.insert(\"b\".into(), \"2\".into());\n+ let v = fill_template_from_form(json, &form).unwrap();\n+ assert_eq!(v[\"items\"], serde_json::json!([\"1\", \"2\"]));\n+ }\n+\n+ #[test]\n+ fn template_json_compact_escapes_and_single_line() {\n+ let s = template_json_compact(&serde_json::json!({\n+ \"x\": \"quote\\\"and\\nnewline\"\n+ }))\n+ .unwrap();\n+ assert!(!s.contains('\\n'));\n+ assert!(s.contains(\"\\\\\\\"\") || s.contains(\"\\\\n\"));\n+ }\n+}\ndiff --git a/server/src/html/forum.rs b/server/src/html/forum.rs\nindex f789e347dc136f8ffd356f4492f0bd76cea04bf0..b1c037f3dd93c7bb96d6624cab6019228432c501 100644\n--- a/server/src/html/forum.rs\n+++ b/server/src/html/forum.rs\n@@ -11,12 +11,15 @@ use crate::{\n api::optional_principal,\n canonical_path::{canonicalize_item, canonicalize_tag},\n events::ThreadCapability,\n+ form_template::template_json_compact,\n identity::parse_username,\n reducer::{scope_from_room_wire, ReducerState, ScopeId},\n state::AppState,\n timeago,\n };\n \n+use super::ui_action::{HtmlUiAction, UI_RPC_FIELD};\n+\n use super::{\n bc_segment, bc_threads, cli_panel, layout, now_ms, profile_href, recency_class,\n render_linkified_with_embeds_in_scope, theme_from_jar, theme_next_from_uri, JsBuilder,\n@@ -289,7 +292,7 @@ fn rooms_for_user(reduced: &ReducerState, username: &str) -> Vec {\n v\n }\n \n-fn user_can_view_room(reduced: &ReducerState, room_id: &str, username: Option<&str>) -> bool {\n+pub(crate) fn user_can_view_room(reduced: &ReducerState, room_id: &str, username: Option<&str>) -> bool {\n if !reduced.rooms.contains(room_id) {\n return false;\n }\n@@ -299,7 +302,7 @@ fn user_can_view_room(reduced: &ReducerState, room_id: &str, username: Option<&s\n reduced.user_has_cap(room_id, u, ThreadCapability::View)\n }\n \n-fn user_can_post_room(reduced: &ReducerState, room_id: &str, username: &str) -> bool {\n+pub(crate) fn user_can_post_room(reduced: &ReducerState, room_id: &str, username: &str) -> bool {\n reduced.user_has_cap(room_id, username, ThreadCapability::Post)\n }\n \n@@ -591,7 +594,6 @@ pub async fn home(\n let nav = ThreadNav::public();\n let reduced_read = state.reduced.read().await;\n let strip = auth_strip(&headers, &jar, &reduced_read);\n- let show_forms = user.is_some();\n drop(reduced_read);\n \n let page = layout(\n@@ -617,8 +619,14 @@ pub async fn home(\n }\n }\n p class=\"muted\" { \"dark = time-ordered · light = vote-ranked\" }\n+ div class=\"thread-feed-toolbar\" {\n+ form method=\"POST\" action=\"/ui\" {\n+ input type=\"hidden\" name=(UI_RPC_FIELD) value=(expand_public_new_thread_rpc_value());\n+ button type=\"submit\" class=\"section-add-btn\" { \"+\" }\n+ }\n+ }\n+ div id=\"public-new-thread-ui-slot\" {}\n (render_thread_feed(Some(&nav), \"thread-feed\", &public_rows, now))\n- (new_thread_form_public(show_forms))\n (cli_panel(\"npx slugsocial public forum list\"))\n },\n None,\n@@ -901,7 +909,13 @@ pub async fn room_page(\n h3 { \"threads\" }\n (render_thread_feed(Some(&nav), \"room-thread-feed\", &rows, now))\n @if show_new {\n- (new_thread_form_for_room(&nav, show_new))\n+ div class=\"thread-feed-toolbar\" {\n+ form method=\"POST\" action=\"/ui\" {\n+ input type=\"hidden\" name=(UI_RPC_FIELD) value=(expand_room_new_thread_rpc_value(&nav));\n+ button type=\"submit\" class=\"section-add-btn\" { \"+\" }\n+ }\n+ }\n+ div id=\"room-new-thread-ui-slot\" {}\n }\n (cli_panel(&forum_cli))\n (cli_panel(&garden_cli))\n@@ -945,6 +959,31 @@ fn new_thread_form_for_room(nav: &ThreadNav, show: bool) -> Markup {\n }\n }\n \n+pub(crate) fn expand_public_new_thread_rpc_value() -> String {\n+ template_json_compact(&HtmlUiAction::ExpandPublicNewThreadForm).expect(\"static json\")\n+}\n+\n+pub(crate) fn expand_room_new_thread_rpc_value(nav: &ThreadNav) -> String {\n+ template_json_compact(&HtmlUiAction::ExpandRoomNewThreadForm {\n+ room_wire: nav.room_wire.clone(),\n+ })\n+ .expect(\"static json\")\n+}\n+\n+pub(crate) fn login_to_post_hint_markup() -> Markup {\n+ html! {\n+ p class=\"muted\" { \"log in to post\" }\n+ }\n+}\n+\n+pub(crate) fn fragment_public_new_thread_form(show: bool) -> Markup {\n+ new_thread_form_public(show)\n+}\n+\n+pub(crate) fn fragment_room_new_thread_form(nav: &ThreadNav, show: bool) -> Markup {\n+ new_thread_form_for_room(nav, show)\n+}\n+\n async fn thread_post_view_inner(\n state: AppState,\n tag: String,\ndiff --git a/server/src/html/mod.rs b/server/src/html/mod.rs\nindex 53041a0cf0b30e6f20749c92ecc15a4e9ac56e09..a4fd2dd60ac283f7eb9b2e64522501b21d1e27e9 100644\n--- a/server/src/html/mod.rs\n+++ b/server/src/html/mod.rs\n@@ -16,6 +16,7 @@ mod editor;\n mod forum;\n mod garden;\n mod search;\n+pub mod ui_action;\n use breadcrumb_path::OntologyPath;\n \n pub use auth::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page};\n@@ -27,9 +28,15 @@ pub use forum::{\n thread_post_collapse_deleted, thread_post_expand, thread_post_expand_deleted, thread_post_view,\n thread_view, ThreadNav,\n };\n+\n+pub(crate) use forum::{\n+ fragment_public_new_thread_form, fragment_room_new_thread_form, login_to_post_hint_markup,\n+ user_can_post_room, user_can_view_room,\n+};\n pub use garden::{garden_index, ontology_path, room_garden_index, room_ontology_path};\n pub use search::{search_page, search_results_fragment};\n pub use forum::user_profile_page;\n+pub use ui_action::{parse_html_ui_from_form, HtmlUiAction, HtmlUiParseError, UI_RPC_FIELD};\n \n /// Public profile URL path for a stored username (no `@`).\n pub(crate) fn profile_href(username: &str) -> String {\ndiff --git a/server/src/html/ui_action.rs b/server/src/html/ui_action.rs\nnew file mode 100644\nindex 0000000000000000000000000000000000000000..3bc69ecbb7e16a59d2d393b2d59f9cd3fedb12b1\n--- /dev/null\n+++ b/server/src/html/ui_action.rs\n@@ -0,0 +1,116 @@\n+//! Browser-only UI commands: JSON in hidden `__rpc__` plus hole fill ([`crate::form_template`]).\n+//! Not part of [`slug_types::RpcCommand`] (CLI / JSON API).\n+\n+use crate::form_template::fill_template_from_form;\n+use serde::{Deserialize, Serialize};\n+use serde_json::Value;\n+use std::collections::HashMap;\n+use thiserror::Error;\n+\n+/// Form field name for the compact JSON template (possibly with `{\"$form\":\"…\"}` holes).\n+pub const UI_RPC_FIELD: &str = \"__rpc__\";\n+\n+/// HTML form / fetch `POST /ui` payload after template fill and deserialization.\n+#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]\n+#[serde(tag = \"action\", rename_all = \"snake_case\")]\n+pub enum HtmlUiAction {\n+ /// Same semantics as `POST /post` (forum ingest).\n+ PostIngest {\n+ room: String,\n+ thread_tag: String,\n+ text: String,\n+ #[serde(default)]\n+ error_target: Option,\n+ #[serde(default)]\n+ form_id: Option,\n+ },\n+ /// Same as `POST /post/check`.\n+ CheckIngest {\n+ room: String,\n+ thread_tag: String,\n+ text: String,\n+ #[serde(default)]\n+ error_target: Option,\n+ #[serde(default)]\n+ form_id: Option,\n+ },\n+ /// Same as `POST /post/redact`.\n+ RedactPost {\n+ post_id: String,\n+ },\n+ /// Morph `#public-new-thread-ui-slot` to the new-thread form (or login hint).\n+ ExpandPublicNewThreadForm,\n+ /// Morph `#room-new-thread-ui-slot` for the given room wire id.\n+ ExpandRoomNewThreadForm {\n+ room_wire: String,\n+ },\n+}\n+\n+#[derive(Debug, Error)]\n+pub enum HtmlUiParseError {\n+ #[error(\"missing __rpc__ field\")]\n+ MissingRpc,\n+ #[error(\"invalid template json: {0}\")]\n+ Template(serde_json::Error),\n+ #[error(\"invalid ui action: {0}\")]\n+ Action(serde_json::Error),\n+}\n+\n+/// Parse `__rpc__` JSON, apply `$form` holes from the rest of the form map, deserialize.\n+pub fn parse_html_ui_from_form(form: &HashMap) -> Result {\n+ let template = form\n+ .get(UI_RPC_FIELD)\n+ .ok_or(HtmlUiParseError::MissingRpc)?;\n+ let mut hole_map = form.clone();\n+ hole_map.remove(UI_RPC_FIELD);\n+ let v: Value = fill_template_from_form(template, &hole_map).map_err(HtmlUiParseError::Template)?;\n+ serde_json::from_value(v).map_err(HtmlUiParseError::Action)\n+}\n+\n+#[cfg(test)]\n+mod tests {\n+ use super::*;\n+\n+ #[test]\n+ fn round_trip_post_ingest_with_holes() {\n+ let template = serde_json::json!({\n+ \"action\": \"post_ingest\",\n+ \"room\": \"public\",\n+ \"thread_tag\": {\"$form\": \"thread_tag\"},\n+ \"text\": {\"$form\": \"text\"},\n+ \"error_target\": \"e\",\n+ \"form_id\": \"f\",\n+ });\n+ let mut form = HashMap::new();\n+ form.insert(\n+ UI_RPC_FIELD.to_string(),\n+ serde_json::to_string(&template).unwrap(),\n+ );\n+ form.insert(\"thread_tag\".into(), \"x\".into());\n+ form.insert(\"text\".into(), \"body\".into());\n+\n+ let a = parse_html_ui_from_form(&form).unwrap();\n+ assert_eq!(\n+ a,\n+ HtmlUiAction::PostIngest {\n+ room: \"public\".into(),\n+ thread_tag: \"x\".into(),\n+ text: \"body\".into(),\n+ error_target: Some(\"e\".into()),\n+ form_id: Some(\"f\".into()),\n+ }\n+ );\n+ }\n+\n+ #[test]\n+ fn expand_public_unit_variant() {\n+ let template = serde_json::json!({ \"action\": \"expand_public_new_thread_form\" });\n+ let mut form = HashMap::new();\n+ form.insert(\n+ UI_RPC_FIELD.to_string(),\n+ serde_json::to_string(&template).unwrap(),\n+ );\n+ let a = parse_html_ui_from_form(&form).unwrap();\n+ assert_eq!(a, HtmlUiAction::ExpandPublicNewThreadForm);\n+ }\n+}\ndiff --git a/server/src/lib.rs b/server/src/lib.rs\nindex b9d4b79791ba8dd3a3c26ff777943a2548092de5..5f5b6b0f01b29350c7415e5801ec5caa74f0b452 100644\n--- a/server/src/lib.rs\n+++ b/server/src/lib.rs\n@@ -3,6 +3,7 @@ pub mod paths;\n pub mod api;\n pub mod canonical_path;\n pub mod dsl;\n+pub mod form_template;\n pub mod html;\n pub mod event_log;\n pub mod events;\n@@ -33,6 +34,7 @@ pub fn create_app(state: AppState) -> Router {\n .route(\"/post\", post(api::post_web_ingest))\n .route(\"/post/redact\", post(api::post_web_redact))\n .route(\"/post/check\", post(api::check_web_ingest))\n+ .route(\"/ui\", post(api::post_ui_html))\n .route(\"/theme\", post(crate::html::post_theme))\n .route(\"/sse\", get(api::get_html_stream))\n .route(\"/stream\", get(api::get_stream))\n\n\nSide B — contributor: tommy-mor\nSide B — commit message:\n[a888d56c] refactor: centralize path identity in slug-types\n\nMove canonicalization and CanonicalItemUrl into types::paths with\nGardenItemUrl, ForumThreadUrl, and TildeOntologyPath for JSON hrefs.\nServer canonical_path and path_types re-export slug-types; RPC and\nvalidation build hrefs via those types instead of string helpers.\n\nMade-with: Cursor\n\nSide B — unified diff (full patch):\ndiff --git a/server/src/api/helpers.rs b/server/src/api/helpers.rs\nindex 9b71491e9f9efc44a2a4beba09be8f64bd2ff2ee..03b3e77911ccd662bec8635345dafe2593cf242e 100644\n--- a/server/src/api/helpers.rs\n+++ b/server/src/api/helpers.rs\n@@ -4,12 +4,12 @@ use axum::{\n Json,\n };\n use sha2::{Digest, Sha256};\n+use slug_types::paths::{CanonicalItemUrl, GardenItemUrl};\n use slug_types::*;\n use std::collections::HashMap;\n \n use crate::{\n canonical_path::canonicalize_item,\n- path_types::CanonicalItemUrl,\n ranking::connected_components_from_voted_pairs,\n };\n \n@@ -30,64 +30,6 @@ pub fn now_ms() -> i64 {\n t.as_millis() as i64\n }\n \n-/// Serialize a canonical item for JSON: absolute URLs stay as-is; bare paths get a `/` prefix.\n-pub fn item_path_for_api(item: &str) -> String {\n- if item.starts_with(\"http://\") || item.starts_with(\"https://\") {\n- item.to_string()\n- } else {\n- format!(\"/{}\", item)\n- }\n-}\n-\n-/// Same as [`item_path_for_api`], but for private rooms ontology items are prefixed with\n-/// `/r/{short}/{slug}` so the URL matches the web app (`/r/…/~/…` routes).\n-pub fn item_path_for_api_in_room(item: &str, room_wire: &str) -> String {\n- let room = room_wire.trim();\n- if room.is_empty() || room == \"public\" {\n- return item_path_for_api(item);\n- }\n- let Some((short, slug)) = room.split_once('/') else {\n- return item_path_for_api(item);\n- };\n- if short.is_empty() || slug.is_empty() {\n- return item_path_for_api(item);\n- }\n- let Some(c) = CanonicalItemUrl::parse(item) else {\n- return item_path_for_api(item);\n- };\n- let root = CanonicalItemUrl::ontology_root();\n- let item_norm = c.as_str().trim_end_matches('/');\n- let root_norm = root.as_str().trim_end_matches('/');\n- if let Some(tail) = c.tilde_tail() {\n- return if tail.is_empty() {\n- format!(\"https://slug.social/r/{short}/{slug}/~\")\n- } else {\n- format!(\"https://slug.social/r/{short}/{slug}/~/{}\", tail)\n- };\n- }\n- if item_norm == root_norm {\n- return format!(\"https://slug.social/r/{short}/{slug}/~\");\n- }\n- item_path_for_api(item)\n-}\n-\n-/// Absolute thread URL for forum JSON (`/t/…` vs `/r/…/t/…`).\n-pub fn forum_thread_web_url(room_wire: &str, thread_tag: &str) -> String {\n- let room = room_wire.trim();\n- let tag = thread_tag.trim().trim_start_matches('#');\n- if room.is_empty() || room == \"public\" {\n- format!(\"https://slug.social/t/{tag}\")\n- } else if let Some((short, slug)) = room.split_once('/') {\n- if short.is_empty() || slug.is_empty() {\n- format!(\"https://slug.social/t/{tag}\")\n- } else {\n- format!(\"https://slug.social/r/{short}/{slug}/t/{tag}\")\n- }\n- } else {\n- format!(\"https://slug.social/t/{tag}\")\n- }\n-}\n-\n /// Resolve an item path as a first-class canonical path.\n pub fn resolve_item(item: &str) -> Result {\n let canonical = canonicalize_item(item);\n@@ -109,14 +51,12 @@ pub fn parse_parent_specs(parent: Option<&String>) -> Vec {\n }\n \n /// Apply offset+limit pagination to the flattened component rankings.\n-/// Items are flattened in component order (largest component first), then unranked last.\n-/// Returns (components, unranked_items) after the window.\n pub fn paginate_rankings(\n components: Vec,\n- unranked_items: Vec,\n+ unranked_items: Vec,\n offset: usize,\n limit: Option,\n-) -> (Vec, Vec) {\n+) -> (Vec, Vec) {\n let mut remaining_skip = offset;\n let mut remaining_take = limit.unwrap_or(usize::MAX);\n let mut out_components: Vec = Vec::new();\n@@ -141,7 +81,7 @@ pub fn paginate_rankings(\n });\n }\n \n- let out_unranked: Vec = if remaining_take > 0 {\n+ let out_unranked: Vec = if remaining_take > 0 {\n unranked_items\n .into_iter()\n .skip(remaining_skip)\n@@ -183,11 +123,9 @@ pub fn is_pair_voted(group: &crate::reducer::GroupState, a: &str, b: &str) -> bo\n group.voted_pairs.contains(&(i, j))\n }\n \n-/// Compute graph connectivity stats for a set of items within the ranking group.\n pub fn compute_connectivity_stats(group: &crate::reducer::GroupState, pool: &[String]) -> ConnectivityStats {\n let n = pool.len();\n \n- // Map pool items to global indices (items not yet in the group get no index)\n let global_idxs: Vec> = pool\n .iter()\n .map(|it| {\n@@ -197,7 +135,6 @@ pub fn compute_connectivity_stats(group: &crate::reducer::GroupState, pool: &[St\n .collect();\n let present: Vec = global_idxs.iter().filter_map(|x| *x).collect();\n \n- // Build local index mapping for items that exist in the ranking group\n let global_to_local: HashMap = present\n .iter()\n .enumerate()\n@@ -213,7 +150,6 @@ pub fn compute_connectivity_stats(group: &crate::reducer::GroupState, pool: &[St\n }),\n );\n \n- // Items not in the ranking group at all are also isolates\n let items_not_in_group = global_idxs.iter().filter(|x| x.is_none()).count();\n \n let num_components = comps.len() + isolates.len() + items_not_in_group;\n@@ -237,52 +173,3 @@ pub fn vote_touches_path(a: &str, b: &str, parent_canon: &str) -> bool {\n let under = |item: &str| item == parent_canon || item.starts_with(&format!(\"{}/\", parent_canon));\n under(a) || under(b)\n }\n-\n-#[cfg(test)]\n-mod wire_url_tests {\n- use super::{forum_thread_web_url, item_path_for_api_in_room};\n-\n- #[test]\n- fn public_room_unchanged() {\n- let u = \"https://slug.social/~/a/b\";\n- assert_eq!(item_path_for_api_in_room(u, \"public\"), u);\n- }\n-\n- #[test]\n- fn private_room_prefixes_ontology() {\n- assert_eq!(\n- item_path_for_api_in_room(\"https://slug.social/~/topic/x\", \"9ab12cd/my-room\"),\n- \"https://slug.social/r/9ab12cd/my-room/~/topic/x\"\n- );\n- }\n-\n- #[test]\n- fn private_room_ontology_root() {\n- assert_eq!(\n- item_path_for_api_in_room(\"https://slug.social/~\", \"9ab12cd/my-room\"),\n- \"https://slug.social/r/9ab12cd/my-room/~\"\n- );\n- assert_eq!(\n- item_path_for_api_in_room(\"https://slug.social/~/\", \"9ab12cd/my-room\"),\n- \"https://slug.social/r/9ab12cd/my-room/~\"\n- );\n- }\n-\n- #[test]\n- fn external_url_untouched_in_private_room() {\n- let u = \"https://example.com/z\";\n- assert_eq!(item_path_for_api_in_room(u, \"9ab12cd/my-room\"), u);\n- }\n-\n- #[test]\n- fn forum_web_public_vs_room() {\n- assert_eq!(\n- forum_thread_web_url(\"public\", \"debate\"),\n- \"https://slug.social/t/debate\"\n- );\n- assert_eq!(\n- forum_thread_web_url(\"9ab12cd/my-room\", \"#debate\"),\n- \"https://slug.social/r/9ab12cd/my-room/t/debate\"\n- );\n- }\n-}\ndiff --git a/server/src/api/mod.rs b/server/src/api/mod.rs\nindex 042aa248305f9362a3be78f9eea2a5abf6ba707a..cf22cb0129366c3aed031bc86f3197a4321cb806 100644\n--- a/server/src/api/mod.rs\n+++ b/server/src/api/mod.rs\n@@ -24,8 +24,7 @@ pub use auth::{\n \n pub use helpers::{\n api_error, compute_connectivity_stats, is_pair_voted, now_ms, paginate_rankings,\n- parse_parent_specs, pick_random_distinct, sha256_hex, resolve_item, vote_touches_path,\n- item_path_for_api,\n+ parse_parent_specs, pick_random_distinct, resolve_item, sha256_hex, vote_touches_path,\n };\n \n pub use rpc::handle_rpc_batch;\ndiff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs\nindex 5b91f5836625eedbb1cd9423168046e3fb576c17..5f7d50188f1381267402f2e57e671234ef5db2fd 100644\n--- a/server/src/api/rpc.rs\n+++ b/server/src/api/rpc.rs\n@@ -8,6 +8,7 @@ use axum::{\n Json,\n };\n use rand::seq::SliceRandom;\n+use slug_types::paths::{ForumThreadUrl, GardenItemUrl, TildeOntologyPath};\n use slug_types::*;\n \n use crate::{\n@@ -27,9 +28,8 @@ use crate::{\n \n use super::auth::verify_bearer_principal;\n use super::helpers::{\n- compute_connectivity_stats, forum_thread_web_url, is_pair_voted, item_path_for_api,\n- item_path_for_api_in_room, now_ms, paginate_rankings, parse_parent_specs, pick_random_distinct,\n- resolve_item, vote_touches_path,\n+ compute_connectivity_stats, is_pair_voted, now_ms, paginate_rankings, parse_parent_specs,\n+ pick_random_distinct, resolve_item, vote_touches_path,\n };\n use super::validate::{normalize_room_and_thread, validate_ingest_document};\n \n@@ -184,7 +184,7 @@ fn compute_scope_rank_changes(\n };\n if changed {\n changes.push(RankChange {\n- item: item_path_for_api_in_room(&item, room_wire),\n+ item: GardenItemUrl::from_storage_str(&item, room_wire),\n before: b,\n after: a,\n });\n@@ -206,7 +206,7 @@ fn compute_scope_rank_changes(\n parent: if parent.is_empty() {\n \"/\".to_string()\n } else {\n- item_path_for_api_in_room(parent, room_wire)\n+ GardenItemUrl::from_storage_str(parent, room_wire).into_inner()\n },\n changes,\n })\n@@ -302,7 +302,7 @@ fn build_rank_response_for_content(\n .ranked\n .into_iter()\n .map(|r| RankRow {\n- item: item_path_for_api_in_room(r.item.as_str(), room_wire),\n+ item: GardenItemUrl::from_stored(&r.item, room_wire),\n percent: if want_percent {\n Some((r.score / max_score) * 100.0)\n } else {\n@@ -315,10 +315,10 @@ fn build_rank_response_for_content(\n })\n .collect();\n \n- let prefixed_unranked: Vec = rankings\n+ let prefixed_unranked: Vec = rankings\n .unranked_items\n .into_iter()\n- .map(|s| item_path_for_api_in_room(s.as_str(), room_wire))\n+ .map(|s| GardenItemUrl::from_stored(&s, room_wire))\n .collect();\n \n let (components, unranked_items) = if offset > 0 || limit.is_some() {\n@@ -537,13 +537,13 @@ async fn rpc_post(\n (\n \"npx slugsocial public garden pair\".to_string(),\n \"npx slugsocial public garden rank\".to_string(),\n- forum_thread_web_url(\"public\", &thread_id),\n+ ForumThreadUrl::from_room_tag(\"public\", &thread_id),\n )\n } else {\n (\n format!(\"npx slugsocial private {room_key} garden pair\"),\n format!(\"npx slugsocial private {room_key} garden rank\"),\n- forum_thread_web_url(&room_key, &thread_id),\n+ ForumThreadUrl::from_room_tag(&room_key, &thread_id),\n )\n };\n \n@@ -664,7 +664,7 @@ async fn rpc_check(\n .ranked\n .into_iter()\n .map(|r| RankRow {\n- item: item_path_for_api_in_room(r.item.as_str(), &room_key),\n+ item: GardenItemUrl::from_stored(&r.item, &room_key),\n score: r.score,\n percent: None,\n })\n@@ -672,12 +672,12 @@ async fn rpc_check(\n })\n .collect();\n CheckScopeRanking {\n- parent: item_path_for_api_in_room(parent.as_str(), &room_key),\n+ parent: GardenItemUrl::from_stored(parent, &room_key).into_inner(),\n components,\n unranked_items: scoped\n .unranked_items\n .into_iter()\n- .map(|it| item_path_for_api_in_room(it.as_str(), &room_key))\n+ .map(|it| GardenItemUrl::from_stored(&it, &room_key))\n .collect(),\n }\n })\n@@ -687,13 +687,13 @@ async fn rpc_check(\n vec![\n \"npx slugsocial public forum post --delegate \".to_string(),\n \"npx slugsocial public forum list\".to_string(),\n- forum_thread_web_url(\"public\", &thread_id),\n+ ForumThreadUrl::from_room_tag(\"public\", &thread_id).into_inner(),\n ]\n } else {\n vec![\n format!(\"npx slugsocial private {room_key} forum post --delegate \"),\n format!(\"npx slugsocial private {room_key} forum list\"),\n- forum_thread_web_url(&room_key, &thread_id),\n+ ForumThreadUrl::from_room_tag(&room_key, &thread_id).into_inner(),\n ]\n };\n \n@@ -717,7 +717,7 @@ fn rpc_list_forum_threads(reduced: &ReducerState, room: &str) -> ThreadsResponse\n .map(|((_, tag), ts)| ThreadSummary {\n thread: format!(\"#{tag}\"),\n last_activity_ts: ts.last_activity_ts,\n- web: forum_thread_web_url(room, tag),\n+ web: ForumThreadUrl::from_room_tag(room, tag),\n })\n .collect();\n out.sort_by(|a, b| b.last_activity_ts.cmp(&a.last_activity_ts));\n@@ -885,7 +885,7 @@ fn rpc_search(reduced: &ReducerState, q: &str, limit: usize, principal: Option<&\n }\n if score > 0 {\n scored_items.push((score, SearchItemHit {\n- path: item_path_for_api(item.as_str()),\n+ path: GardenItemUrl::from_storage_str(item.as_str(), \"public\"),\n body: content.item_bodies.get(item).map(|b| snippet_around(b, &words, 120)),\n }));\n }\n@@ -1058,8 +1058,8 @@ async fn rpc_get_pair(state: &AppState, room: String, parent_path: String) -> Re\n .collect();\n let cs = compute_connectivity_stats(&content.ranking_group, &pool);\n Ok(RpcResult::Pair(PairResponse {\n- left: item_path_for_api_in_room(&left, &room),\n- right: item_path_for_api_in_room(&right, &room),\n+ left: GardenItemUrl::from_storage_str(&left, &room),\n+ right: GardenItemUrl::from_storage_str(&right, &room),\n left_body: lb,\n right_body: rb,\n threads: th,\n@@ -1137,7 +1137,7 @@ pub async fn handle_rpc_batch(\n if !content.items.contains(&item) {\n line_err(\n \"item not found\",\n- Some(format!(\"{} does not exist\", item_path_for_api_in_room(&item_str, &room))),\n+ Some(format!(\"{} does not exist\", GardenItemUrl::from_storage_str(&item_str, &room))),\n )\n } else {\n const MAX_ITEM_BODY: usize = 10_000;\n@@ -1160,7 +1160,7 @@ pub async fn handle_rpc_batch(\n .map(|s| s.iter().cloned().collect())\n .unwrap_or_default();\n line_ok(RpcResult::GardenItem(ItemResponse {\n- item: item_path_for_api_in_room(&item_str, &room),\n+ item: GardenItemUrl::from_storage_str(&item_str, &room),\n body,\n truncated,\n body_len,\n@@ -1554,7 +1554,7 @@ pub async fn handle_rpc_batch(\n for r in items {\n let pct = want_percent.then(|| ((r.score - bot) / range * 100.0).clamp(0.0, 100.0));\n ranked.push(RankRow {\n- item: item_path_for_api_in_room(r.item.as_str(), &room),\n+ item: GardenItemUrl::from_storage_str(r.item.as_str(), &room),\n score: r.score,\n percent: pct,\n });\n@@ -1574,7 +1574,7 @@ pub async fn handle_rpc_batch(\n let page: Vec = ranked\n .into_iter()\n .chain(unranked.into_iter().map(|it| RankRow {\n- item: item_path_for_api_in_room(&it, &room),\n+ item: GardenItemUrl::from_storage_str(&it, &room),\n score: 0.0,\n percent: want_percent.then_some(0.0),\n }))\n@@ -1618,7 +1618,7 @@ pub async fn handle_rpc_batch(\n if !content.items.contains(&item) {\n line_err(\n \"item not found\",\n- Some(format!(\"{} does not exist\", item_path_for_api_in_room(&item_str, &room))),\n+ Some(format!(\"{} does not exist\", GardenItemUrl::from_storage_str(&item_str, &room))),\n )\n } else {\n let votes: Vec = content\n@@ -1629,8 +1629,8 @@ pub async fn handle_rpc_batch(\n .take(limit)\n .map(|v| VoteRow {\n ts: v.ts,\n- a: item_path_for_api_in_room(v.a.as_str(), &room),\n- b: item_path_for_api_in_room(v.b.as_str(), &room),\n+ a: GardenItemUrl::from_stored(&v.a, &room),\n+ b: GardenItemUrl::from_stored(&v.b, &room),\n ratio: format!(\"{}:{}\", v.ratio_left, v.ratio_right),\n actor: Some(v.principal.clone()),\n body: v.body.clone(),\n@@ -1640,7 +1640,7 @@ pub async fn handle_rpc_batch(\n })\n .unwrap_or_default();\n line_ok(RpcResult::Matchup(MatchupResponse {\n- item: item_path_for_api_in_room(&item_str, &room),\n+ item: GardenItemUrl::from_storage_str(&item_str, &room),\n votes,\n }))\n }\n@@ -1667,8 +1667,8 @@ pub async fn handle_rpc_batch(\n if a == item_str || b == item_str {\n Some(VoteRow {\n ts: e.ts,\n- a: item_path_for_api_in_room(&a, &room),\n- b: item_path_for_api_in_room(&b, &room),\n+ a: GardenItemUrl::from_storage_str(&a, &room),\n+ b: GardenItemUrl::from_storage_str(&b, &room),\n ratio: format!(\"{}:{}\", ratio_left, ratio_right),\n actor: reduced.ingests_by_id.get(&e.post_id).map(|ing| ing.principal.clone()),\n body: explanation,\n@@ -1704,7 +1704,7 @@ pub async fn handle_rpc_batch(\n }\n }).collect();\n line_ok(RpcResult::RankHistory(RankHistoryResponse {\n- item: item_path_for_api_in_room(&item_str, &room),\n+ item: GardenItemUrl::from_storage_str(&item_str, &room),\n history,\n }))\n }\n@@ -1716,17 +1716,13 @@ pub async fn handle_rpc_batch(\n } else {\n let content = content_for_room(&reduced, &room);\n let parents: HashSet<&str> = content.item_children.keys().map(|s| s.as_str()).collect();\n- let mut paths: Vec = content\n+ let mut paths: Vec = content\n .items\n .iter()\n .filter(|p| !parents.contains(p.as_str()))\n- .map(|p| p.as_str().to_string())\n- .collect();\n- paths.sort();\n- let paths: Vec = paths\n- .into_iter()\n- .map(|p| item_path_for_api_in_room(&p, &room))\n+ .map(|p| GardenItemUrl::from_stored(p, &room))\n .collect();\n+ paths.sort_by(|a, b| a.as_str().cmp(b.as_str()));\n line_ok(RpcResult::Leaves(LeavesResponse { paths }))\n }\n },\n@@ -1743,24 +1739,13 @@ pub async fn handle_rpc_batch(\n let mut v: Vec = roots.iter()\n .map(|path| {\n let children = content.item_children.get(path.as_str()).map(|s| s.len()).unwrap_or(0);\n- let path_label = CanonicalItemUrl::parse(path.as_str())\n- .and_then(|c| {\n- c.tilde_tail().map(|t| {\n- if t.is_empty() {\n- \"~/\".to_string()\n- } else {\n- format!(\"~/{}\", t)\n- }\n- })\n- })\n- .unwrap_or_else(|| path.to_string());\n PathSummary {\n- path: path_label,\n+ path: TildeOntologyPath::from_stored(path),\n children,\n- web: item_path_for_api_in_room(path.as_str(), &room),\n+ web: GardenItemUrl::from_stored(path, &room),\n }\n }).collect();\n- v.sort_by(|a, b| a.path.cmp(&b.path));\n+ v.sort_by(|a, b| a.path.as_str().cmp(b.path.as_str()));\n v\n })\n .unwrap_or_default();\n@@ -1790,8 +1775,8 @@ pub async fn handle_rpc_batch(\n .take(limit)\n .map(|v| VoteRow {\n ts: v.ts,\n- a: item_path_for_api_in_room(v.a.as_str(), &room),\n- b: item_path_for_api_in_room(v.b.as_str(), &room),\n+ a: GardenItemUrl::from_stored(&v.a, &room),\n+ b: GardenItemUrl::from_stored(&v.b, &room),\n ratio: format!(\"{}:{}\", v.ratio_left, v.ratio_right),\n actor: Some(v.principal.clone()),\n body: v.body.clone(),\ndiff --git a/server/src/api/validate.rs b/server/src/api/validate.rs\nindex 27150577982f52cbd6d11bb93654dc3d4cf75cc5..a51c783ee9785569b5a44c0b1572471fe00d174b 100644\n--- a/server/src/api/validate.rs\n+++ b/server/src/api/validate.rs\n@@ -7,8 +7,9 @@ use crate::{\n path_types::CanonicalItemUrl,\n reducer::{ReducerState, ScopeId},\n };\n+use slug_types::paths::GardenItemUrl;\n \n-use super::helpers::{item_path_for_api, resolve_item};\n+use super::helpers::resolve_item;\n \n #[derive(Debug)]\n pub struct ValidatedIngest {\n@@ -22,6 +23,10 @@ pub fn validate_ingest_document(\n text: &str,\n scope: &ScopeId,\n ) -> Result)> {\n+ let room_wire = match scope {\n+ ScopeId::Public => \"public\",\n+ ScopeId::Room(r) => r.as_str(),\n+ };\n let public_content = reduced.public();\n let scoped_content = match scope {\n ScopeId::Public => None,\n@@ -61,14 +66,14 @@ pub fn validate_ingest_document(\n let Some(body_text) = body else {\n return Err((\n StatusCode::BAD_REQUEST,\n- format!(\"item missing body: {}\", item_path_for_api(&item)),\n+ format!(\"item missing body: {}\", GardenItemUrl::from_storage_str(&item, room_wire)),\n Some(\"items must be declared with bodies, e.g. `~/path/item { ... }`\".to_string()),\n ));\n };\n if body_text.trim().is_empty() {\n return Err((\n StatusCode::BAD_REQUEST,\n- format!(\"item body is empty: {}\", item_path_for_api(&item)),\n+ format!(\"item body is empty: {}\", GardenItemUrl::from_storage_str(&item, room_wire)),\n Some(\"write at least one sentence inside `{ ... }`\".to_string()),\n ));\n }\n@@ -101,7 +106,7 @@ pub fn validate_ingest_document(\n let key = CanonicalItemUrl((*it).clone());\n !defined_in_doc.contains(*it) && !item_exists(&key)\n })\n- .map(|it| item_path_for_api(it))\n+ .map(|it| GardenItemUrl::from_storage_str(it, room_wire).into_inner())\n .collect();\n if !missing.is_empty() {\n return Err((\n@@ -119,7 +124,7 @@ pub fn validate_ingest_document(\n let key = CanonicalItemUrl((*it).clone());\n !defined_in_doc.contains(*it) && !body_exists(&key)\n })\n- .map(|it| item_path_for_api(it))\n+ .map(|it| GardenItemUrl::from_storage_str(it, room_wire).into_inner())\n .collect();\n if !missing_body.is_empty() {\n return Err((\ndiff --git a/server/src/canonical_path.rs b/server/src/canonical_path.rs\nindex 5c0febe883d8b3978a25896ed0d71df8509a8717..8a1998025121838b0867f8c5ddbd28aea41a23d2 100644\n--- a/server/src/canonical_path.rs\n+++ b/server/src/canonical_path.rs\n@@ -1,92 +1,3 @@\n-//! Normalization for thread tags and ontology item URLs (DSL ↔ stored canonical form).\n-//! Not event types — see `events` and `path_types`.\n+//! Re-exports — implementations live in `slug-types` (`paths` module).\n \n-/// Thread / public tag: stored without leading `#`, lowercase.\n-pub fn canonicalize_tag(input: &str) -> String {\n- input.trim().trim_start_matches('#').to_lowercase()\n-}\n-\n-/// Ontology item reference → canonical absolute URL on the slug host.\n-pub fn canonicalize_item(input: &str) -> String {\n- let s = input.trim();\n- if s.is_empty() {\n- return String::new();\n- }\n-\n- if let Some(rest) = s.strip_prefix(\"https://\") {\n- let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n- let host = host.trim().to_lowercase();\n- if tail.is_empty() {\n- return format!(\"https://{}\", host);\n- } else {\n- return format!(\"https://{}/{}\", host, tail);\n- }\n- }\n- if let Some(rest) = s.strip_prefix(\"http://\") {\n- let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n- let host = host.trim().to_lowercase();\n- if tail.is_empty() {\n- return format!(\"http://{}\", host);\n- } else {\n- return format!(\"http://{}/{}\", host, tail);\n- }\n- }\n-\n- let is_tilde = s.starts_with(\"~/\");\n- let rest = s.strip_prefix(\"~/\").or_else(|| s.strip_prefix(\"/\")).unwrap_or(s);\n-\n- let tail = rest\n- .split('/')\n- .filter_map(|seg| {\n- let t = seg.trim();\n- if t.is_empty() {\n- None\n- } else {\n- Some(t.to_lowercase())\n- }\n- })\n- .collect::>()\n- .join(\"/\");\n-\n- if is_tilde {\n- format!(\"https://slug.social/~/{}\", tail)\n- } else if tail.is_empty() {\n- \"https://slug.social\".to_string()\n- } else {\n- format!(\"https://slug.social/{}\", tail)\n- }\n-}\n-\n-pub fn item_path_segments(input: &str) -> Vec {\n- let canonical = canonicalize_item(input);\n- if canonical.is_empty() {\n- return vec![];\n- }\n-\n- if let Some(rest) = canonical.strip_prefix(\"https://\") {\n- let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n- let mut out = vec![format!(\"https://{}\", host)];\n- out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string()));\n- return out;\n- }\n- if let Some(rest) = canonical.strip_prefix(\"http://\") {\n- let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n- let mut out = vec![format!(\"http://{}\", host)];\n- out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string()));\n- return out;\n- }\n-\n- canonical\n- .split('/')\n- .filter(|s| !s.is_empty())\n- .map(|s| s.to_string())\n- .collect()\n-}\n-\n-pub fn item_parent_path(input: &str) -> Option {\n- let segs = item_path_segments(input);\n- if segs.len() <= 1 {\n- return None;\n- }\n- Some(segs[..segs.len() - 1].join(\"/\"))\n-}\n+pub use slug_types::paths::{canonicalize_item, canonicalize_tag, item_parent_path, item_path_segments};\ndiff --git a/server/src/html/forum.rs b/server/src/html/forum.rs\nindex ab7970feca47a4431ddc19dab2c8186180b78413..f789e347dc136f8ffd356f4492f0bd76cea04bf0 100644\n--- a/server/src/html/forum.rs\n+++ b/server/src/html/forum.rs\n@@ -697,7 +697,7 @@ async fn thread_view_inner(\n let offset = q.offset.unwrap_or(0);\n let page_ids: Vec = all_ids.into_iter().skip(offset).take(PAGE_SIZE).collect();\n \n- let (display_ingests, subtitle) = {\n+ let (display_ingests, _subtitle) = {\n let reduced = state.reduced.read().await;\n let ingests = page_ids\n .iter()\ndiff --git a/server/src/path_types.rs b/server/src/path_types.rs\nindex cad58cac7da948f92d6ea2a5587d917ab21d57ea..4c8075bbd488f1b9a5eda9e03ced83f6238c6d5e 100644\n--- a/server/src/path_types.rs\n+++ b/server/src/path_types.rs\n@@ -1,260 +1,3 @@\n-//! Path representation types.\n-//!\n-//! The codebase currently treats item identifiers as strings in a few different\n-//! encodings:\n-//! - user/DSL input like `~/a/b`\n-//! - canonical item URLs like `https://slug.social/~/a/b`\n-//! - relative paths within a rooted tree view (e.g. `llms/openai` under a root)\n-//!\n-//! This module adds lightweight newtypes so code can be explicit about what it\n-//! expects without changing core storage formats.\n-//!\n-//! **Storage vs wire:** [`CanonicalItemUrl`] values are shared across scopes\n-//! (`https://slug.social/~/…`); which [`crate::reducer::ContentState`] they live in\n-//! is determined by scope, not by embedding the room id in the string. For JSON/RPC\n-//! and browser links in a private room, use [`crate::api::helpers::item_path_for_api_in_room`]\n-//! so ontology items become `https://slug.social/r/{short}/{slug}/~/…`.\n+//! Re-exports — implementations live in `slug-types` (`paths` module).\n \n-use std::borrow::Borrow;\n-use std::fmt;\n-\n-use serde::{Deserialize, Serialize};\n-\n-use crate::canonical_path::canonicalize_item;\n-\n-/// Canonical item identifier as produced by `canonical_path::canonicalize_item`.\n-///\n-/// In practice this is usually:\n-/// - `https://slug.social/~/...` for ontology items, or\n-/// - `https://...` / `http://...` for URL items.\n-#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n-pub struct CanonicalItemUrl(pub String);\n-\n-impl CanonicalItemUrl {\n- pub fn parse(input: &str) -> Option {\n- let c = canonicalize_item(input);\n- if c.is_empty() {\n- None\n- } else {\n- Some(Self(c))\n- }\n- }\n-\n- pub fn as_str(&self) -> &str {\n- &self.0\n- }\n-\n- /// Returns the `~/...` tail for ontology items (`https://slug.social/~/...`).\n- pub fn tilde_tail(&self) -> Option<&str> {\n- self.0.strip_prefix(\"https://slug.social/~/\")\n- }\n-\n- /// Returns the final non-empty `/`-separated segment of the path.\n- ///\n- /// `https://slug.social/~/a/b/c` → `\"c\"`\n- /// `https://slug.social/~/a` → `\"a\"`\n- pub fn last_segment(&self) -> &str {\n- self.0\n- .rsplit('/')\n- .find(|s| !s.is_empty())\n- .unwrap_or(self.0.as_str())\n- }\n-\n- /// The ontology root key as stored in `item_children`: `\"https://slug.social/~\"`.\n- /// Use this (not `parse(\"~/\")`) when looking up top-level children.\n- pub fn ontology_root() -> Self {\n- Self(\"https://slug.social/~\".to_string())\n- }\n-\n- /// Returns the parent of this canonical item URL by stripping the last\n- /// path segment, or `None` if there is no parent (already at root).\n- ///\n- /// `https://slug.social/~/a/b/c` → `Some(\"https://slug.social/~/a/b\")`\n- /// `https://slug.social/~/a` → `Some(\"https://slug.social/~\")`\n- /// `https://slug.social/~/` → `None` (tilde root)\n- pub fn parent(&self) -> Option {\n- // tilde_tail() is None for non-ontology URLs and \"\" for the root ~/\n- if self.tilde_tail().map(|t| t.is_empty()).unwrap_or(true) {\n- return None;\n- }\n- // Strip everything from the last '/' onwards.\n- let last_slash = self.0.rfind('/')?;\n- let parent_str = &self.0[..last_slash];\n- if parent_str.is_empty() {\n- None\n- } else {\n- Some(Self(parent_str.to_string()))\n- }\n- }\n-\n- /// Segments of an ontology path suitable for breadcrumb rendering.\n- /// Strips the `https://slug.social` prefix and returns the `~/…` parts.\n- ///\n- /// `https://slug.social/~/a/b` → `[\"~\", \"a\", \"b\"]`\n- /// `https://slug.social/~/` → `[\"~\"]`\n- pub fn tilde_segments(&self) -> Vec<&str> {\n- match self.tilde_tail() {\n- Some(tail) if !tail.is_empty() => {\n- std::iter::once(\"~\")\n- .chain(tail.split('/').filter(|s| !s.is_empty()))\n- .collect()\n- }\n- Some(_) => vec![\"~\"],\n- None => vec![],\n- }\n- }\n-}\n-\n-impl fmt::Display for CanonicalItemUrl {\n- fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n- self.0.fmt(f)\n- }\n-}\n-\n-/// Allow `HashMap` to be searched by `&str`.\n-impl Borrow for CanonicalItemUrl {\n- fn borrow(&self) -> &str {\n- &self.0\n- }\n-}\n-\n-impl PartialEq for CanonicalItemUrl {\n- fn eq(&self, other: &str) -> bool {\n- self.0 == other\n- }\n-}\n-\n-impl PartialEq<&str> for CanonicalItemUrl {\n- fn eq(&self, other: &&str) -> bool {\n- self.0 == *other\n- }\n-}\n-\n-impl PartialEq for CanonicalItemUrl {\n- fn eq(&self, other: &String) -> bool {\n- &self.0 == other\n- }\n-}\n-\n-/// A `~/...` input path (as used in the DSL and UX).\n-///\n-/// This is not canonicalized; it is a presentation/input form.\n-#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n-pub struct TildePath(pub String);\n-\n-impl TildePath {\n- pub fn new(input: &str) -> Option {\n- let s = input.trim();\n- if s.starts_with(\"~/\") && s.len() > 2 {\n- Some(Self(s.to_string()))\n- } else if s == \"~/\" {\n- Some(Self(\"~/\".to_string()))\n- } else {\n- None\n- }\n- }\n-\n- pub fn as_str(&self) -> &str {\n- &self.0\n- }\n-\n- pub fn canonicalize(&self) -> Option {\n- CanonicalItemUrl::parse(&self.0)\n- }\n-}\n-\n-impl fmt::Display for TildePath {\n- fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n- self.0.fmt(f)\n- }\n-}\n-\n-/// A path relative to a chosen root in a tree UI.\n-///\n-/// This is intended for compact state encodings (blobs). It must be joined to a\n-/// root `CanonicalItemUrl` (typically an ontology root) to become a full item.\n-#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n-pub struct RelativePath(pub String);\n-\n-impl RelativePath {\n- pub fn new(input: &str) -> Option {\n- let s = input.trim().trim_matches('/');\n- if s.is_empty() {\n- Some(Self(String::new()))\n- } else {\n- // Keep this permissive: the DSL parser is the main gatekeeper.\n- Some(Self(s.to_string()))\n- }\n- }\n-\n- pub fn as_str(&self) -> &str {\n- &self.0\n- }\n-\n- /// Join this relative path under a canonical ontology root\n- /// (`https://slug.social/~/...`) to form a canonical item URL.\n- pub fn join_under_ontology_root(&self, root: &CanonicalItemUrl) -> Option {\n- let base = root.tilde_tail()?;\n- // base is the tail after https://slug.social/~/, e.g. \"models\" or \"models/llms\"\n- let joined = if base.is_empty() {\n- if self.0.is_empty() {\n- \"~/\".to_string()\n- } else {\n- format!(\"~/{}\", self.0)\n- }\n- } else if self.0.is_empty() {\n- format!(\"~/{}\", base)\n- } else {\n- format!(\"~/{}/{}\", base.trim_end_matches('/'), self.0)\n- };\n- CanonicalItemUrl::parse(&joined)\n- }\n-}\n-\n-impl fmt::Display for RelativePath {\n- fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n- self.0.fmt(f)\n- }\n-}\n-\n-\n-#[cfg(test)]\n-mod tests {\n- use super::*;\n-\n- #[test]\n- fn canonical_parent_deep() {\n- let c = CanonicalItemUrl::parse(\"~/a/b/c\").unwrap();\n- assert_eq!(c.parent().unwrap().as_str(), \"https://slug.social/~/a/b\");\n- }\n-\n- #[test]\n- fn canonical_parent_one_level() {\n- let c = CanonicalItemUrl::parse(\"~/a\").unwrap();\n- assert_eq!(c.parent().unwrap().as_str(), \"https://slug.social/~\");\n- }\n-\n- #[test]\n- fn canonical_parent_root_is_none() {\n- let root = CanonicalItemUrl::parse(\"~/\").unwrap();\n- assert!(root.parent().is_none());\n- }\n-\n- #[test]\n- fn tilde_segments_deep() {\n- let c = CanonicalItemUrl::parse(\"~/a/b\").unwrap();\n- assert_eq!(c.tilde_segments(), vec![\"~\", \"a\", \"b\"]);\n- }\n-\n- #[test]\n- fn tilde_segments_root() {\n- let c = CanonicalItemUrl::parse(\"~/\").unwrap();\n- assert_eq!(c.tilde_segments(), vec![\"~\"]);\n- }\n-\n- #[test]\n- fn tilde_segments_non_ontology_is_empty() {\n- let c = CanonicalItemUrl::parse(\"https://example.com/foo\").unwrap();\n- assert_eq!(c.tilde_segments(), Vec::<&str>::new());\n- }\n-}\n+pub use slug_types::paths::{CanonicalItemUrl, RelativePath, TildePath};\ndiff --git a/types/src/lib.rs b/types/src/lib.rs\nindex c1cde3b783d03b02783385b5f07659fb112aae3e..5fc867bf2af84c2ca63fa1cdd03413110ad784a3 100644\n--- a/types/src/lib.rs\n+++ b/types/src/lib.rs\n@@ -1,7 +1,13 @@\n use serde::{Deserialize, Serialize};\n \n+pub mod paths;\n pub mod timeago;\n \n+pub use paths::{\n+ canonicalize_item, canonicalize_tag, item_parent_path, item_path_segments, CanonicalItemUrl,\n+ ForumThreadUrl, GardenItemUrl, RelativePath, TildeOntologyPath, TildePath,\n+};\n+\n #[derive(Debug, Serialize, Deserialize)]\n pub struct ApiError {\n pub ok: bool,\n@@ -12,7 +18,7 @@ pub struct ApiError {\n \n #[derive(Debug, Clone, Serialize, Deserialize)]\n pub struct RankRow {\n- pub item: String,\n+ pub item: GardenItemUrl,\n pub score: f64,\n /// Normalized score as a percentage of the top item (0–100). Present when ?percent=true.\n #[serde(skip_serializing_if = \"Option::is_none\")]\n@@ -43,7 +49,7 @@ pub struct RankComponent {\n #[derive(Debug, Serialize, Deserialize)]\n pub struct RankResponse {\n pub components: Vec,\n- pub unranked_items: Vec,\n+ pub unranked_items: Vec,\n }\n \n /// Graph connectivity stats for a scope, returned with pair suggestions.\n@@ -63,8 +69,8 @@ pub struct ConnectivityStats {\n \n #[derive(Debug, Serialize, Deserialize)]\n pub struct PairResponse {\n- pub left: String,\n- pub right: String,\n+ pub left: GardenItemUrl,\n+ pub right: GardenItemUrl,\n pub left_body: Option,\n pub right_body: Option,\n /// Thread tags that discuss either item (connective tissue to forum).\n@@ -79,7 +85,7 @@ pub struct PairResponse {\n pub struct NextMoves {\n pub pair: String,\n pub rank: String,\n- pub web: String,\n+ pub web: ForumThreadUrl,\n }\n \n #[derive(Debug, Serialize, Deserialize)]\n@@ -90,14 +96,14 @@ pub struct PathsResponse {\n /// Leaf items only (no children). For search / \"full path list\" — does not scale, works for now.\n #[derive(Debug, Serialize, Deserialize)]\n pub struct LeavesResponse {\n- pub paths: Vec,\n+ pub paths: Vec,\n }\n \n #[derive(Debug, Serialize, Deserialize)]\n pub struct PathSummary {\n- pub path: String,\n+ pub path: TildeOntologyPath,\n pub children: usize,\n- pub web: String,\n+ pub web: GardenItemUrl,\n }\n \n #[derive(Debug, Clone, Serialize, Deserialize)]\n@@ -109,7 +115,7 @@ pub struct ThreadsResponse {\n pub struct ThreadSummary {\n pub thread: String,\n pub last_activity_ts: i64,\n- pub web: String,\n+ pub web: ForumThreadUrl,\n }\n \n #[derive(Debug, Serialize, Deserialize)]\n@@ -178,7 +184,7 @@ pub struct IngestRow {\n \n #[derive(Debug, Serialize, Deserialize)]\n pub struct ItemResponse {\n- pub item: String,\n+ pub item: GardenItemUrl,\n pub body: Option,\n /// True when the body was truncated due to size. Fetch with `?full=true` for the complete body.\n #[serde(default, skip_serializing_if = \"std::ops::Not::not\")]\n@@ -201,15 +207,15 @@ pub struct RecentVotesResponse {\n /// Vote history for one item (matchup: wins/losses + thread per vote).\n #[derive(Debug, Serialize, Deserialize)]\n pub struct MatchupResponse {\n- pub item: String,\n+ pub item: GardenItemUrl,\n pub votes: Vec,\n }\n \n #[derive(Debug, Clone, Serialize, Deserialize)]\n pub struct VoteRow {\n pub ts: i64,\n- pub a: String,\n- pub b: String,\n+ pub a: GardenItemUrl,\n+ pub b: GardenItemUrl,\n pub ratio: String,\n /// Principal username when present (stored form, no `@`).\n pub actor: Option,\n@@ -510,7 +516,7 @@ pub struct RankPosition {\n /// How one item's rank changed after a vote.\n #[derive(Debug, Clone, Serialize, Deserialize)]\n pub struct RankChange {\n- pub item: String,\n+ pub item: GardenItemUrl,\n /// Position before the vote. None = was unranked (no voted connections in this scope).\n pub before: Option,\n /// Position after the vote. None = became unranked (e.g. component split, unlikely).\n@@ -544,7 +550,7 @@ pub struct CheckScopeRanking {\n /// Parent scope path (e.g. \"/models\" or \"/\" for root).\n pub parent: String,\n pub components: Vec,\n- pub unranked_items: Vec,\n+ pub unranked_items: Vec,\n }\n \n #[derive(Debug, Serialize, Deserialize)]\n@@ -567,7 +573,7 @@ pub struct SearchResponse {\n \n #[derive(Debug, Serialize, Deserialize)]\n pub struct SearchItemHit {\n- pub path: String,\n+ pub path: GardenItemUrl,\n #[serde(skip_serializing_if = \"Option::is_none\")]\n pub body: Option,\n }\n@@ -614,7 +620,7 @@ pub struct RankHistoryRow {\n \n #[derive(Debug, Serialize, Deserialize)]\n pub struct RankHistoryResponse {\n- pub item: String,\n+ pub item: GardenItemUrl,\n pub history: Vec,\n }\n \ndiff --git a/types/src/paths.rs b/types/src/paths.rs\nnew file mode 100644\nindex 0000000000000000000000000000000000000000..2950a7502255927583fbacdfd2adb700f0b0c221\n--- /dev/null\n+++ b/types/src/paths.rs\n@@ -0,0 +1,498 @@\n+//! Canonical paths, storage ids, and JSON href newtypes. All normalization and\n+//! room-aware URL rules for items live here.\n+\n+use std::borrow::Borrow;\n+use std::fmt;\n+\n+use serde::{Deserialize, Serialize};\n+\n+// ---------------------------------------------------------------------------\n+// Normalization (moved from server `canonical_path`)\n+// ---------------------------------------------------------------------------\n+\n+/// Thread / public tag: stored without leading `#`, lowercase.\n+pub fn canonicalize_tag(input: &str) -> String {\n+ input.trim().trim_start_matches('#').to_lowercase()\n+}\n+\n+/// Ontology item reference → canonical absolute URL on the slug host.\n+pub fn canonicalize_item(input: &str) -> String {\n+ let s = input.trim();\n+ if s.is_empty() {\n+ return String::new();\n+ }\n+\n+ if let Some(rest) = s.strip_prefix(\"https://\") {\n+ let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n+ let host = host.trim().to_lowercase();\n+ if tail.is_empty() {\n+ return format!(\"https://{}\", host);\n+ } else {\n+ return format!(\"https://{}/{}\", host, tail);\n+ }\n+ }\n+ if let Some(rest) = s.strip_prefix(\"http://\") {\n+ let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n+ let host = host.trim().to_lowercase();\n+ if tail.is_empty() {\n+ return format!(\"http://{}\", host);\n+ } else {\n+ return format!(\"http://{}/{}\", host, tail);\n+ }\n+ }\n+\n+ let is_tilde = s.starts_with(\"~/\");\n+ let rest = s.strip_prefix(\"~/\").or_else(|| s.strip_prefix(\"/\")).unwrap_or(s);\n+\n+ let tail = rest\n+ .split('/')\n+ .filter_map(|seg| {\n+ let t = seg.trim();\n+ if t.is_empty() {\n+ None\n+ } else {\n+ Some(t.to_lowercase())\n+ }\n+ })\n+ .collect::>()\n+ .join(\"/\");\n+\n+ if is_tilde {\n+ format!(\"https://slug.social/~/{}\", tail)\n+ } else if tail.is_empty() {\n+ \"https://slug.social\".to_string()\n+ } else {\n+ format!(\"https://slug.social/{}\", tail)\n+ }\n+}\n+\n+pub fn item_path_segments(input: &str) -> Vec {\n+ let canonical = canonicalize_item(input);\n+ if canonical.is_empty() {\n+ return vec![];\n+ }\n+\n+ if let Some(rest) = canonical.strip_prefix(\"https://\") {\n+ let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n+ let mut out = vec![format!(\"https://{}\", host)];\n+ out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string()));\n+ return out;\n+ }\n+ if let Some(rest) = canonical.strip_prefix(\"http://\") {\n+ let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n+ let mut out = vec![format!(\"http://{}\", host)];\n+ out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string()));\n+ return out;\n+ }\n+\n+ canonical\n+ .split('/')\n+ .filter(|s| !s.is_empty())\n+ .map(|s| s.to_string())\n+ .collect()\n+}\n+\n+pub fn item_parent_path(input: &str) -> Option {\n+ let segs = item_path_segments(input);\n+ if segs.len() <= 1 {\n+ return None;\n+ }\n+ Some(segs[..segs.len() - 1].join(\"/\"))\n+}\n+\n+// ---------------------------------------------------------------------------\n+// Storage + input path newtypes\n+// ---------------------------------------------------------------------------\n+\n+/// Canonical item identifier as produced by [`canonicalize_item`].\n+///\n+/// Shared across all scopes; room is not embedded. Usually\n+/// `https://slug.social/~/…` or an external `http(s)://…` URL item.\n+#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n+pub struct CanonicalItemUrl(pub String);\n+\n+impl CanonicalItemUrl {\n+ pub fn parse(input: &str) -> Option {\n+ let c = canonicalize_item(input);\n+ if c.is_empty() {\n+ None\n+ } else {\n+ Some(Self(c))\n+ }\n+ }\n+\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+\n+ pub fn tilde_tail(&self) -> Option<&str> {\n+ self.0.strip_prefix(\"https://slug.social/~/\")\n+ }\n+\n+ pub fn last_segment(&self) -> &str {\n+ self.0\n+ .rsplit('/')\n+ .find(|s| !s.is_empty())\n+ .unwrap_or(self.0.as_str())\n+ }\n+\n+ pub fn ontology_root() -> Self {\n+ Self(\"https://slug.social/~\".to_string())\n+ }\n+\n+ pub fn parent(&self) -> Option {\n+ if self.tilde_tail().map(|t| t.is_empty()).unwrap_or(true) {\n+ return None;\n+ }\n+ let last_slash = self.0.rfind('/')?;\n+ let parent_str = &self.0[..last_slash];\n+ if parent_str.is_empty() {\n+ None\n+ } else {\n+ Some(Self(parent_str.to_string()))\n+ }\n+ }\n+\n+ pub fn tilde_segments(&self) -> Vec<&str> {\n+ match self.tilde_tail() {\n+ Some(tail) if !tail.is_empty() => {\n+ std::iter::once(\"~\")\n+ .chain(tail.split('/').filter(|s| !s.is_empty()))\n+ .collect()\n+ }\n+ Some(_) => vec![\"~\"],\n+ None => vec![],\n+ }\n+ }\n+\n+ /// `~/…` list label for ontology items (paths index, CLI).\n+ pub fn tilde_list_label(&self) -> TildeOntologyPath {\n+ TildeOntologyPath::from_stored(self)\n+ }\n+\n+ /// Absolute href for JSON/RPC and browsers for this stored id in `room`.\n+ pub fn json_href(&self, room_wire: &str) -> GardenItemUrl {\n+ GardenItemUrl::from_stored(self, room_wire)\n+ }\n+}\n+\n+impl fmt::Display for CanonicalItemUrl {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+impl Borrow for CanonicalItemUrl {\n+ fn borrow(&self) -> &str {\n+ &self.0\n+ }\n+}\n+\n+impl PartialEq for CanonicalItemUrl {\n+ fn eq(&self, other: &str) -> bool {\n+ self.0 == other\n+ }\n+}\n+\n+impl PartialEq<&str> for CanonicalItemUrl {\n+ fn eq(&self, other: &&str) -> bool {\n+ self.0 == *other\n+ }\n+}\n+\n+impl PartialEq for CanonicalItemUrl {\n+ fn eq(&self, other: &String) -> bool {\n+ &self.0 == other\n+ }\n+}\n+\n+#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n+pub struct TildePath(pub String);\n+\n+impl TildePath {\n+ pub fn new(input: &str) -> Option {\n+ let s = input.trim();\n+ if s.starts_with(\"~/\") && s.len() > 2 {\n+ Some(Self(s.to_string()))\n+ } else if s == \"~/\" {\n+ Some(Self(\"~/\".to_string()))\n+ } else {\n+ None\n+ }\n+ }\n+\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+\n+ pub fn canonicalize(&self) -> Option {\n+ CanonicalItemUrl::parse(&self.0)\n+ }\n+}\n+\n+impl fmt::Display for TildePath {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n+pub struct RelativePath(pub String);\n+\n+impl RelativePath {\n+ pub fn new(input: &str) -> Option {\n+ let s = input.trim().trim_matches('/');\n+ if s.is_empty() {\n+ Some(Self(String::new()))\n+ } else {\n+ Some(Self(s.to_string()))\n+ }\n+ }\n+\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+\n+ pub fn join_under_ontology_root(&self, root: &CanonicalItemUrl) -> Option {\n+ let base = root.tilde_tail()?;\n+ let joined = if base.is_empty() {\n+ if self.0.is_empty() {\n+ \"~/\".to_string()\n+ } else {\n+ format!(\"~/{}\", self.0)\n+ }\n+ } else if self.0.is_empty() {\n+ format!(\"~/{}\", base)\n+ } else {\n+ format!(\"~/{}/{}\", base.trim_end_matches('/'), self.0)\n+ };\n+ CanonicalItemUrl::parse(&joined)\n+ }\n+}\n+\n+impl fmt::Display for RelativePath {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+// ---------------------------------------------------------------------------\n+// Wire / JSON: correct-by-construction hrefs\n+// ---------------------------------------------------------------------------\n+\n+fn api_path_or_url(item: &str) -> String {\n+ if item.starts_with(\"http://\") || item.starts_with(\"https://\") {\n+ item.to_string()\n+ } else {\n+ format!(\"/{}\", item)\n+ }\n+}\n+\n+/// Ontology item as serialized in JSON (absolute URL or `/`-prefixed path).\n+#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n+#[serde(transparent)]\n+pub struct GardenItemUrl(pub String);\n+\n+impl GardenItemUrl {\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+\n+ pub fn into_inner(self) -> String {\n+ self.0\n+ }\n+\n+ /// Stored canonical id + RPC `room` field (`\"public\"` or `\"short/slug\"`).\n+ pub fn from_stored(stored: &CanonicalItemUrl, room_wire: &str) -> Self {\n+ Self(garden_href_string(stored.as_str(), room_wire))\n+ }\n+\n+ /// Like [`Self::from_stored`] but accepts a string that may already be canonical.\n+ pub fn from_storage_str(stored: &str, room_wire: &str) -> Self {\n+ Self(garden_href_string(stored, room_wire))\n+ }\n+}\n+\n+impl fmt::Display for GardenItemUrl {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+fn garden_href_string(item: &str, room_wire: &str) -> String {\n+ let room = room_wire.trim();\n+ if room.is_empty() || room == \"public\" {\n+ return api_path_or_url(item);\n+ }\n+ let Some((short, slug)) = room.split_once('/') else {\n+ return api_path_or_url(item);\n+ };\n+ if short.is_empty() || slug.is_empty() {\n+ return api_path_or_url(item);\n+ }\n+ let Some(c) = CanonicalItemUrl::parse(item) else {\n+ return api_path_or_url(item);\n+ };\n+ let root = CanonicalItemUrl::ontology_root();\n+ let item_norm = c.as_str().trim_end_matches('/');\n+ let root_norm = root.as_str().trim_end_matches('/');\n+ if let Some(tail) = c.tilde_tail() {\n+ return if tail.is_empty() {\n+ format!(\"https://slug.social/r/{short}/{slug}/~\")\n+ } else {\n+ format!(\"https://slug.social/r/{short}/{slug}/~/{}\", tail)\n+ };\n+ }\n+ if item_norm == root_norm {\n+ return format!(\"https://slug.social/r/{short}/{slug}/~\");\n+ }\n+ api_path_or_url(item)\n+}\n+\n+/// Forum thread URL for JSON (`/t/…` or `/r/…/t/…` on slug.social).\n+#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n+#[serde(transparent)]\n+pub struct ForumThreadUrl(pub String);\n+\n+impl ForumThreadUrl {\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+\n+ pub fn into_inner(self) -> String {\n+ self.0\n+ }\n+\n+ pub fn from_room_tag(room_wire: &str, thread_tag: &str) -> Self {\n+ let room = room_wire.trim();\n+ let tag = thread_tag.trim().trim_start_matches('#');\n+ Self(if room.is_empty() || room == \"public\" {\n+ format!(\"https://slug.social/t/{tag}\")\n+ } else if let Some((short, slug)) = room.split_once('/') {\n+ if short.is_empty() || slug.is_empty() {\n+ format!(\"https://slug.social/t/{tag}\")\n+ } else {\n+ format!(\"https://slug.social/r/{short}/{slug}/t/{tag}\")\n+ }\n+ } else {\n+ format!(\"https://slug.social/t/{tag}\")\n+ })\n+ }\n+}\n+\n+impl fmt::Display for ForumThreadUrl {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+/// `~/a/b` style path for list UIs (paths index `path` field).\n+#[derive(Debug, Clone, PartialEq, Eq, Hash, Serialize, Deserialize)]\n+#[serde(transparent)]\n+pub struct TildeOntologyPath(pub String);\n+\n+impl TildeOntologyPath {\n+ pub fn from_stored(c: &CanonicalItemUrl) -> Self {\n+ let s = match c.tilde_tail() {\n+ Some(tail) if !tail.is_empty() => format!(\"~/{}\", tail),\n+ Some(_) => \"~/\".to_string(),\n+ None => c.to_string(),\n+ };\n+ Self(s)\n+ }\n+\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+}\n+\n+impl fmt::Display for TildeOntologyPath {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+#[cfg(test)]\n+mod tests {\n+ use super::*;\n+\n+ #[test]\n+ fn canonical_parent_deep() {\n+ let c = CanonicalItemUrl::parse(\"~/a/b/c\").unwrap();\n+ assert_eq!(c.parent().unwrap().as_str(), \"https://slug.social/~/a/b\");\n+ }\n+\n+ #[test]\n+ fn canonical_parent_one_level() {\n+ let c = CanonicalItemUrl::parse(\"~/a\").unwrap();\n+ assert_eq!(c.parent().unwrap().as_str(), \"https://slug.social/~\");\n+ }\n+\n+ #[test]\n+ fn canonical_parent_root_is_none() {\n+ let root = CanonicalItemUrl::parse(\"~/\").unwrap();\n+ assert!(root.parent().is_none());\n+ }\n+\n+ #[test]\n+ fn tilde_segments_deep() {\n+ let c = CanonicalItemUrl::parse(\"~/a/b\").unwrap();\n+ assert_eq!(c.tilde_segments(), vec![\"~\", \"a\", \"b\"]);\n+ }\n+\n+ #[test]\n+ fn tilde_segments_root() {\n+ let c = CanonicalItemUrl::parse(\"~/\").unwrap();\n+ assert_eq!(c.tilde_segments(), vec![\"~\"]);\n+ }\n+\n+ #[test]\n+ fn tilde_segments_non_ontology_is_empty() {\n+ let c = CanonicalItemUrl::parse(\"https://example.com/foo\").unwrap();\n+ assert_eq!(c.tilde_segments(), Vec::<&str>::new());\n+ }\n+\n+ #[test]\n+ fn garden_public_passthrough_https() {\n+ let u = \"https://slug.social/~/a/b\";\n+ assert_eq!(GardenItemUrl::from_storage_str(u, \"public\").as_str(), u);\n+ }\n+\n+ #[test]\n+ fn garden_private_room_prefixes_ontology() {\n+ assert_eq!(\n+ GardenItemUrl::from_storage_str(\"https://slug.social/~/topic/x\", \"9ab12cd/my-room\").as_str(),\n+ \"https://slug.social/r/9ab12cd/my-room/~/topic/x\"\n+ );\n+ }\n+\n+ #[test]\n+ fn garden_private_room_ontology_root() {\n+ assert_eq!(\n+ GardenItemUrl::from_storage_str(\"https://slug.social/~\", \"9ab12cd/my-room\").as_str(),\n+ \"https://slug.social/r/9ab12cd/my-room/~\"\n+ );\n+ assert_eq!(\n+ GardenItemUrl::from_storage_str(\"https://slug.social/~/\", \"9ab12cd/my-room\").as_str(),\n+ \"https://slug.social/r/9ab12cd/my-room/~\"\n+ );\n+ }\n+\n+ #[test]\n+ fn garden_external_url_untouched_in_private_room() {\n+ let u = \"https://example.com/z\";\n+ assert_eq!(GardenItemUrl::from_storage_str(u, \"9ab12cd/my-room\").as_str(), u);\n+ }\n+\n+ #[test]\n+ fn forum_web_public_vs_room() {\n+ assert_eq!(\n+ ForumThreadUrl::from_room_tag(\"public\", \"debate\").as_str(),\n+ \"https://slug.social/t/debate\"\n+ );\n+ assert_eq!(\n+ ForumThreadUrl::from_room_tag(\"9ab12cd/my-room\", \"#debate\").as_str(),\n+ \"https://slug.social/r/9ab12cd/my-room/t/debate\"\n+ );\n+ }\n+}\n","role":"user"}],"model":"~x-ai/grok-latest"}