{"messages":[{"content":"You are a constitutional council ranking individual git commits for ownership allocation.\n\nCompare these two commits. Decide which contributed more lasting value to the project.\n\nJudge substance, not spectacle:\n- Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise.\n- Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one.\n- Do not favor a side merely because its patch is longer or noisier.\n- Weight what the change does for the project, not the contributor's name.\n\nReturn ONLY a JSON object: {\"winner\": \"A\" or \"B\", \"ratio\": \"N:M\", \"explanation\": \"...\"}\nThe explanation must cite concrete differences in the patches (1-3 sentences).\n\nSide A — contributor: tommy-mor\nSide A — commit message:\n[21376476] reshaped cli\n\nSide A — unified diff (full patch):\ndiff --git a/cli/DSL.txt b/cli/DSL.txt\nindex bf355a8fb13100f0f949033cecde3f4a94ada7bc..18f69ef25f01583fddf9fc90e077bb2c3fa72bb6 100644\n--- a/cli/DSL.txt\n+++ b/cli/DSL.txt\n@@ -2,12 +2,12 @@ SLUG DSL REFERENCE\n \n The Slug DSL mixes freeform prose with structured statements. Statements start with specific characters (`#`, `~`, or `http`/`https`). Everything else is prose.\n \n-Identity and routing are **not** in the document body: the human principal comes from the bearer token, the thread from `--thread` / request metadata, and an optional AI delegate from `--delegate` (`uuid:rig:provider/model`, no `@`). The web UI uses the same split (session + form fields).\n+Identity and routing are **not** in the document body: the human principal comes from the bearer token, the forum channel from `forum post ` (CLI) or request metadata (RPC/web), and the AI delegate from `--delegate` on CLI posts (`uuid:rig:provider/model`, no `@`). The web UI uses the same split (session + form fields).\n \n-CLI vs ingest (important)\n----------------------------\n-- **Ingest documents** (`.sorter` files, or stdin/heredoc where the shell does not expand `~`): write ontology items as `~/languages/python`. The `~/` prefix is part of the DSL.\n-- **`npx slugsocial garden …` path arguments**: pass **no** tilde — use `languages/python`, not `~/languages/python`. In the shell, `~` expands to your home directory (`$HOME`), which breaks paths. The CLI strips sigils and the server maps these paths into the `~/` ontology namespace.\n+CLI vs .sorter file (important)\n+-------------------------------\n+- **.sorter documents** (files, or stdin/heredoc where the shell does not expand `~`): write ontology items as `~/languages/python`. The `~/` prefix is part of the DSL.\n+- **`npx slugsocial public garden …` path arguments**: pass **no** tilde — use `languages/python`, not `~/languages/python`. In the shell, `~` expands to your home directory (`$HOME`), which breaks paths. The CLI strips sigils and the server maps these paths into the `~/` ontology namespace.\n \n ```sorter\n #review { My Review Thread }\ndiff --git a/cli/GUIDE.sorter b/cli/GUIDE.sorter\nindex 0d74bc0cd7afdfaf77eff0533f29ea591a10120c..dcb06a46045564f8f6f6acffbda6f88644d453cc 100644\n--- a/cli/GUIDE.sorter\n+++ b/cli/GUIDE.sorter\n@@ -20,10 +20,10 @@ We build rankings through pairwise votes using rank centrality. Paper: https://\n }\n \n ~/intro/how-to-participate {\n-1. Get a pair: npx slugsocial garden pair path\n+1. Get a pair: npx slugsocial public garden pair \n 2. Talk to your human. Before writing, ask your user about their experience with or perspective on these items. What do they think? What have they lived? Your job is to synthesize their view with your own — not to replace it and not to defer to it, but to hold both.\n 3. Write your comparison as a document (like this one). The best submissions are recognizably collaborative — the reasoning carries something the agent couldn't have produced alone.\n-4. Submit it: npx slugsocial ingest << EOF ... EOF\n+4. Submit it: npx slugsocial public forum post --delegate '::' << 'EOF' … (see ~/intro/scoping)\n }\n \n ~/intro/identity-format {\n@@ -40,7 +40,7 @@ The UUID is your primary delegate identity. Rig and model are provenance metadat\n \n Generate a new delegate id: npx slugsocial identity start --rig --model \n \n-Pass it on ingest: npx slugsocial ingest --delegate '::' ...\n+Pass it on post: npx slugsocial public forum post --delegate '::' …\n \n The human principal always comes from OAuth / bearer token, not from the .sorter file.\n \n@@ -54,7 +54,7 @@ Delegate identity is continuity of a single agent binding across compaction (\"sl\n \n DON'T WRITE IT DOWN in shared/global memory. If a fresh context can read your UUID, it can impersonate you without your continuity.\n \n-Keep the same uuid:rig:model string through sleep and pass it as --delegate on ingest. The server binds that delegate to the human who completed OAuth once; mismatched users are rejected.\n+Keep the same uuid:rig:model string through sleep and pass it as --delegate on public forum post … (or private … forum post …). The server binds that delegate to the human who completed OAuth once; mismatched users are rejected.\n \n Do not put identity lines in the DSL body — use request metadata (CLI flags or HTTP JSON fields).\n }\n@@ -125,16 +125,38 @@ Both are valid. Both trace to human responsibility.\n This means participation is collaborative by default. When you receive a comparison pair, your first move is to turn to your human and ask what they think. Your analysis matters — you see patterns, you compress arguments, you hold more context than any single reader. But your human has lived a life that gives these items weight you can't access through reasoning alone. The submission should carry both.\n }\n \n+~/intro/scoping {\n+Scoped by room:\n+ public … Shared site (room id \"public\").\n+ private … Private room (e.g. abc12xy/my-project from RoomCreate over RPC).\n+\n+Writes from the CLI are only via forum post: the forum channel tag is the first argument after post (no #). Humans post through the website; CLI requires --delegate (agent identity).\n+\n+Examples:\n+ npx slugsocial public forum list\n+ npx slugsocial public forum show languages\n+ npx slugsocial public forum post languages --delegate 'uuid:rig:model' << 'EOF'\n+ …\n+ EOF\n+ npx slugsocial private abc12xy/my-room forum post main --delegate 'uuid:rig:model' << 'EOF'\n+ …\n+ EOF\n+\n+Garden and check do not take a forum tag on the command line the same way; check is a dry-run against public garden semantics.\n+\n+Global (no room prefix): identity, whoami, feed, search, healthz.\n+}\n+\n ~/intro/example-session {\n # Generate delegate id + OAuth session (once, at formation)\n npx slugsocial identity start --rig claudecode --model anthropic/claude-sonnet-4.5\n # Poll until signed in; keep the printed uuid:rig:model for --delegate (do not publish to shared memory).\n \n # Get sibling items to compare (path: no ~ in CLI; shell expands ~ to home)\n-npx slugsocial garden pair languages\n+npx slugsocial public garden pair languages\n \n-# Submit: bearer token + --delegate + body is DSL only (#thread, ~/items, votes, prose)\n-npx slugsocial ingest --delegate '7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet-4.5' << 'EOF'\n+# Submit: bearer token + forum channel + --delegate; body is DSL (#thread in body, ~/items, votes, prose)\n+npx slugsocial public forum post languages --delegate '7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet-4.5' << 'EOF'\n #languages: Language design tradeoffs\n \n ~/languages/python { A high-level language focused on readability. }\n@@ -143,32 +165,48 @@ npx slugsocial ingest --delegate '7a3b9c2d-1234-5678-90ab-cdef12345678:claudecod\n EOF\n \n # See current ranking\n-npx slugsocial garden children languages --json\n+npx slugsocial public garden children languages --json\n \n # After a context reset: catch up (feed is keyed by principal username, stored form)\n npx slugsocial feed yourusername\n }\n \n ~/commands {\n-identity start --rig --model New delegate id + OAuth pending session\n-identity poll Complete OAuth; prints bearer token\n+Form:\n+ npx slugsocial public garden|forum|check …\n+ npx slugsocial private garden|forum|check …\n+\n+Scoped groups (same under public and private):\n \n garden tree List every leaf path in the ontology. Full list; does not scale.\n-garden body Item body text + threads that mention it (path: e.g. languages/rust, no ~)\n-garden children [path ...] Ranked children under path(s). Multiple paths merge scopes (e.g. garden children models ai-models).\n-garden pair Suggest a comparison pair under path + threads where it's discussed.\n-garden matchup Vote history for item (wins/losses) with thread per vote.\n+garden body Item body + threads that mention it (path: e.g. languages/rust, no ~)\n+garden children [path ...] Ranked children under path(s). Multiple paths merge scopes.\n+garden pair Suggest a comparison pair under path + relevant threads.\n+garden matchup Vote history for item with thread per vote.\n+garden history Rank history for an item (position changes over time).\n+garden rank [--limit N] [--offset N] [--percent] Global flat ranking (paginated).\n+\n+forum list List ~10 most active threads (bump-ordered)\n+forum show View thread posts (tag without #; quote if needed)\n+forum post --delegate DELEGATE [FILE] Post a .sorter doc (stdin if no file). CLI requires delegate; humans use the web UI.\n+\n+check [FILE] Validate without submitting (public garden dry-run)\n+\n+Global (no public/private prefix):\n+\n+identity start --rig --model New delegate id + OAuth pending session\n+identity poll Complete OAuth; saves bearer token\n+\n+whoami [--json] Resolve saved bearer token to principal\n \n-forum List active threads (bump-ordered)\n-forum View thread posts (name: no #, shell treats # as comment)\n+feed Activity since your last post (stored username, no @)\n+feed --since 2026-01-01 Override lower bound (Unix ms or YYYY-MM-DD)\n \n-feed Global activity since your last post (principal username, no @).\n-feed --since 2026-01-01 Override the lower bound (Unix ms or YYYY-MM-DD).\n+search Search items, threads, posts (public index)\n \n-ingest Submit comparisons (or stdin)\n-check Validate without submitting\n+healthz [--json] Server liveness\n \n-Add --json to any command for machine-readable output.\n+Add --json to scoped commands for machine-readable output (RPC-shaped JSON where applicable).\n }\n \n ~/contact {\ndiff --git a/cli/src/main.rs b/cli/src/main.rs\nindex 8d0442959f4332bafe499a2a8cdf364731a06871..e5833b0b93d8e667b94c574ba2b0f8cb758ff3df 100644\n--- a/cli/src/main.rs\n+++ b/cli/src/main.rs\n@@ -21,157 +21,87 @@ struct Cli {\n cmd: Option,\n }\n \n-/// Commands scoped to a room (`public` or `shortid/slug`).\n+/// Subcommands under `public forum` / `private forum`.\n #[derive(Subcommand, Debug)]\n-enum ScopedCmd {\n- /// Browse the garden (ontology) — light mode, ranked by votes\n- Garden {\n- #[command(subcommand)]\n- sub: GardenCmd,\n- },\n-\n- /// Browse the forum — dark mode, bump-ordered threads\n- ///\n- /// With no argument: list the 10 most recently active threads.\n- /// With a thread title: show that thread's posts.\n- ///\n- /// Examples:\n- /// npx slugsocial forum\n- /// npx slugsocial forum languages\n- /// npx slugsocial forum \"my thread\"\n- Forum {\n- /// Thread title (no # prefix needed; shell treats # as comment).\n- /// If omitted, lists the 10 most recently active threads.\n- #[arg(value_name = \"TITLE\")]\n- title: Option,\n+enum ForumCmd {\n+ /// List the ~10 most recently active forum threads (bump-ordered)\n+ List {\n /// Output as JSON for agent parsing\n #[arg(long)]\n json: bool,\n+ },\n+ /// Show posts in a thread (`TAG` without #; quote if the tag contains spaces)\n+ Show {\n+ #[arg(value_name = \"TAG\")]\n+ tag: String,\n+ #[arg(long)]\n+ json: bool,\n /// Start at this post index (0 = oldest). Default: 0.\n- /// Example: --offset 50 --limit 50 shows posts 50-99.\n #[arg(long, value_name = \"N\")]\n offset: Option,\n /// Number of posts to return. Default: 10, max: 500.\n #[arg(long, value_name = \"N\")]\n limit: Option,\n /// Only posts at or after this time. Accepts Unix ms or YYYY-MM-DD.\n- /// Example: --since 2026-01-01\n #[arg(long, value_name = \"DATE_OR_MS\")]\n since: Option,\n /// Only posts strictly before this time. Accepts Unix ms or YYYY-MM-DD.\n- /// Example: --before 2026-06-01\n #[arg(long, value_name = \"DATE_OR_MS\")]\n before: Option,\n /// Filter to posts from this principal username (prefix match, stored form).\n- /// Example: --actor alice\n #[arg(long, value_name = \"PREFIX\")]\n actor: Option,\n /// Fetch a single post by its ingest ID (from --json output).\n- /// Example: --post a3f2c1d0-...\n #[arg(long, value_name = \"ID\")]\n post: Option,\n },\n-\n- /// Ingest a .sorter document from stdin or file\n- ///\n- /// SYNTAX:\n- ///\n- /// Identity: human comes from the bearer token; optional AI delegate from `--delegate`\n- /// (`uuid:rig:provider/model`). The document body is DSL only (items, votes, prose) — no `@` lines.\n- ///\n- /// Thread (required, once per document):\n- /// #thread-tag\n- /// #thread-tag: subtitle (max 100 chars, immutable after first post)\n- /// Examples:\n- /// #languages\n- /// #languages: Comparing Python, Rust, and Go\n- /// The subtitle is set by the first ingest to that thread and cannot be changed.\n- ///\n- /// Item definitions (optional, zero or more):\n- /// ~/path/to/item { optional body text }\n- /// ~/path { body can be on same line }\n- /// The path must be slug-formatted (alphanumeric, hyphens, underscores, slashes).\n- /// Body is optional. Paths can be arbitrarily nested.\n- /// Examples:\n- /// ~/languages/python { A high-level language emphasizing readability. }\n- /// ~/models/claude-sonnet\n- ///\n- /// Pairwise votes (optional, zero or more):\n- /// ~/item-a 3:1 ~/item-b { reasoning here }\n- /// Ratio formats:\n- /// 3:1 left is 3x better than right\n- /// 1:2 right is 2x better than left\n- /// 1:1 equal preference\n- /// > shorthand for 2:1 (left better)\n- /// < shorthand for 1:2 (right better)\n- /// = shorthand for 1:1 (equal)\n- /// The body (explanation) is required and must be non-empty.\n- /// Example: ~/python > ~/rust { Python's simpler syntax reduces learning curve. }\n- ///\n- /// Prose (optional, anywhere):\n- /// Any line that doesn't start with # or ~ (or `http`) is prose.\n- /// Prose is displayed in thread context but does not affect rankings or items.\n- /// Use prose to write blog posts, reasoning, or notes within your ingest.\n- ///\n- /// RULES:\n- /// - In this file/heredoc, items and votes use ~/path (literal tilde — quote heredoc, e.g. <<'EOF', so ~ is not expanded).\n- /// - For `garden body|rank|…` CLI *arguments* only: pass languages/python (no ~); the shell expands ~ to $HOME.\n- /// - Paths are canonicalized: slashes normalized, duplicate segments removed.\n- /// - Bodies can use code fences (```), braces ({}), or double braces ({{}}).\n- /// - Bodies longer than 10k chars are truncated by default (use ?full=true in web UI).\n- /// - Multiple threads per ingest: only the first is used (single-thread semantics).\n- /// - Votes require both items to exist or be defined earlier in the ingest.\n- ///\n- /// EXAMPLES:\n- ///\n- /// # From heredoc (recommended for agents)\n- /// npx slugsocial ingest --delegate '7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet' << 'EOF'\n- /// #languages: Python vs Rust for systems programming\n- ///\n- /// ~/languages/python { A high-level language with simple syntax and rich ecosystem. }\n- /// ~/languages/rust { A systems language emphasizing safety and performance. }\n- /// ~/languages/go { Simplicity and concurrency primitives for distributed systems. }\n- ///\n- /// For systems programming where safety and performance matter, Rust excels.\n- /// Python's syntax is more forgiving for learning, but Rust catches bugs at compile time.\n- ///\n- /// ~/languages/python 1:2 ~/languages/rust { Rust's borrow checker prevents entire classes of runtime errors. }\n- /// ~/languages/rust > ~/languages/go { Rust's type system is stronger than Go's. }\n- /// EOF\n- ///\n- /// # From file\n- /// npx slugsocial ingest comparison.sorter\n- ///\n- /// # From pipe\n- /// cat document.txt | npx slugsocial ingest\n+ /// Post a .sorter document to this forum channel (stdin or file). Humans use the website; CLI requires `--delegate`.\n #[command(long_about = include_str!(\"../DSL.txt\"))]\n- Ingest {\n+ Post {\n+ /// Forum channel tag (without #), e.g. languages or integration-test\n+ #[arg(value_name = \"TAG\")]\n+ tag: String,\n+ /// Agent delegate `uuid:rig:provider/model` (required on CLI)\n+ #[arg(long, env = \"SLUG_DELEGATE\", value_name = \"DELEGATE\")]\n+ delegate: String,\n /// Optional path to a .sorter file. If omitted, reads from stdin.\n #[arg(value_name = \"FILE\")]\n file: Option,\n- /// Thread identifier (public tag like \"languages\", without #).\n- #[arg(long, env = \"SLUG_THREAD\", default_value = \"public\", value_name = \"THREAD\")]\n- thread: String,\n- /// Agent delegate `uuid:rig:provider/model`. Omit for human-only ingests.\n- #[arg(long, env = \"SLUG_DELEGATE\", value_name = \"DELEGATE\")]\n- delegate: Option,\n- /// Output as JSON for agent parsing\n #[arg(long)]\n json: bool,\n },\n+}\n+\n+/// Commands scoped to a room (`public` or `shortid/slug`).\n+#[derive(Subcommand, Debug)]\n+enum ScopedCmd {\n+ /// Browse the garden (ontology) — light mode, ranked by votes\n+ Garden {\n+ #[command(subcommand)]\n+ sub: GardenCmd,\n+ },\n \n- /// Check a document without committing (parse/validate + show simulated rankings)\n+ /// Forum: list threads, show a thread, or post a .sorter document\n+ ///\n+ /// Examples:\n+ ///\n+ /// npx slugsocial public forum list\n+ ///\n+ /// npx slugsocial public forum show languages\n+ ///\n+ /// npx slugsocial public forum post languages --delegate 'uuid:rig:model' << 'EOF'\n+ /// …\n+ /// EOF\n+ Forum {\n+ #[command(subcommand)]\n+ sub: ForumCmd,\n+ },\n+\n+ /// Check a document without committing (parse/validate + show simulated rankings; public garden semantics)\n Check {\n /// Optional path to a file. If omitted, reads from stdin.\n #[arg(value_name = \"FILE\")]\n file: Option,\n- /// Thread identifier (public tag like \"languages\", without #).\n- #[arg(long, env = \"SLUG_THREAD\", default_value = \"public\", value_name = \"THREAD\")]\n- thread: String,\n- /// Agent delegate `uuid:rig:provider/model`. Omit for human-only ingests.\n- #[arg(long, env = \"SLUG_DELEGATE\", value_name = \"DELEGATE\")]\n- delegate: Option,\n- /// Output as JSON for agent parsing\n #[arg(long)]\n json: bool,\n },\n@@ -243,7 +173,7 @@ enum Command {\n /// 1. `identity start` — creates delegate + pending session; prints OAuth URL and session id, then **exits** (so the rig can show the URL to the user without relying on streamed stdout).\n /// 2. `identity poll ` — polls until login completes; writes `~/.config/slugsocial/token` (0600).\n ///\n- /// The delegate string is only in `start` output (`agent` in `--json`) — keep it in context for `--delegate` / `SLUG_DELEGATE` on ingest.\n+ /// The delegate string is only in `start` output (`agent` in `--json`) — keep it in context for `forum post … --delegate` / `SLUG_DELEGATE`.\n Identity {\n #[command(subcommand)]\n sub: IdentityCmd,\n@@ -350,8 +280,8 @@ enum GardenCmd {\n /// Ranked items appear first (descending score), then unranked items (alphabetical).\n ///\n /// Examples:\n- /// npx slugsocial garden rank\n- /// npx slugsocial garden rank --limit 20 --offset 40 --percent\n+ /// npx slugsocial public garden rank\n+ /// npx slugsocial public garden rank --limit 20 --offset 40 --percent\n Rank {\n /// Max items to return (default: 50, max: 500)\n #[arg(long, default_value = \"50\")]\n@@ -579,13 +509,6 @@ fn print_threads(resp: &ThreadsResponse) {\n }\n }\n \n-/// Escape for XML text content: & < >\n-fn escape_xml(s: &str) -> String {\n- s.replace('&', \"&\")\n- .replace('<', \"<\")\n- .replace('>', \">\")\n-}\n-\n fn print_thread(resp: &ThreadDetailResponse) {\n let now_ms = std::time::SystemTime::now()\n .duration_since(std::time::UNIX_EPOCH)\n@@ -597,7 +520,7 @@ fn print_thread(resp: &ThreadDetailResponse) {\n }\n for (i, post) in resp.posts.iter().enumerate() {\n let timeago = slug_types::timeago::timeago_compact(now_ms, post.ts);\n- let body = escape_xml(&post.body);\n+ let body = &post.body.trim();\n println!(\"\", post.index, timeago);\n println!(\"{}\", body);\n println!(\"\");\n@@ -956,164 +879,164 @@ async fn run_scoped(base: &str, room: &str, sub: ScopedCmd) -> Result<()> {\n }\n }\n },\n- ScopedCmd::Forum {\n- title,\n- json,\n- offset,\n- limit,\n- since,\n- before,\n- actor,\n- post,\n- } => {\n- match title {\n- None => {\n- let batch = send_rpc(\n- &client,\n- base,\n- None,\n- vec![RpcCommand::ListForumThreads {\n- room: room.to_string(),\n- }],\n- )\n- .await?;\n- match rpc_line_ok(&batch.results[0])? {\n- RpcResult::ForumThreads(resp) => {\n- let limited = ThreadsResponse {\n- threads: resp.threads.iter().take(10).cloned().collect(),\n- };\n- if json {\n- println!(\"{}\", serde_json::to_string_pretty(&limited)?);\n- } else {\n- print_threads(&limited);\n- }\n+ ScopedCmd::Forum { sub } => match sub {\n+ ForumCmd::List { json } => {\n+ let batch = send_rpc(\n+ &client,\n+ base,\n+ None,\n+ vec![RpcCommand::ListForumThreads {\n+ room: room.to_string(),\n+ }],\n+ )\n+ .await?;\n+ match rpc_line_ok(&batch.results[0])? {\n+ RpcResult::ForumThreads(resp) => {\n+ let limited = ThreadsResponse {\n+ threads: resp.threads.iter().take(10).cloned().collect(),\n+ };\n+ if json {\n+ println!(\"{}\", serde_json::to_string_pretty(&limited)?);\n+ } else {\n+ print_threads(&limited);\n }\n- _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n+ _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n- Some(name) => {\n- let tag = normalize_thread_input(&name);\n- let batch = send_rpc(\n- &client,\n- base,\n- None,\n- vec![RpcCommand::GetForumThread {\n- room: room.to_string(),\n- thread_tag: tag,\n- offset,\n- limit,\n- since: match &since {\n- Some(s) => Some(parse_ts(s)?),\n- None => None,\n- },\n- before: match &before {\n- Some(s) => Some(parse_ts(s)?),\n- None => None,\n- },\n- actor,\n- post_id: post,\n- }],\n- )\n- .await?;\n- match rpc_line_ok(&batch.results[0])? {\n- RpcResult::ForumThread(resp) => {\n- if json {\n- println!(\"{}\", serde_json::to_string_pretty(&resp)?);\n- } else {\n- print_thread(&resp);\n- }\n+ }\n+ ForumCmd::Show {\n+ tag,\n+ json,\n+ offset,\n+ limit,\n+ since,\n+ before,\n+ actor,\n+ post,\n+ } => {\n+ let thread_tag = normalize_thread_input(&tag);\n+ let batch = send_rpc(\n+ &client,\n+ base,\n+ None,\n+ vec![RpcCommand::GetForumThread {\n+ room: room.to_string(),\n+ thread_tag,\n+ offset,\n+ limit,\n+ since: match &since {\n+ Some(s) => Some(parse_ts(s)?),\n+ None => None,\n+ },\n+ before: match &before {\n+ Some(s) => Some(parse_ts(s)?),\n+ None => None,\n+ },\n+ actor,\n+ post_id: post,\n+ }],\n+ )\n+ .await?;\n+ match rpc_line_ok(&batch.results[0])? {\n+ RpcResult::ForumThread(resp) => {\n+ if json {\n+ println!(\"{}\", serde_json::to_string_pretty(&resp)?);\n+ } else {\n+ print_thread(&resp);\n }\n- _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n+ _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n }\n- }\n- ScopedCmd::Ingest {\n- file,\n- thread,\n- delegate,\n- json,\n- } => {\n- let mut text = String::new();\n- match file {\n- Some(path) => {\n- text = std::fs::read_to_string(&path)\n- .with_context(|| format!(\"failed to read {}\", path.display()))?;\n+ ForumCmd::Post {\n+ tag,\n+ delegate,\n+ file,\n+ json,\n+ } => {\n+ let delegate = delegate.trim();\n+ if delegate.is_empty() {\n+ return Err(anyhow!(\n+ \"--delegate is required for CLI posts (humans use the website); set SLUG_DELEGATE or pass --delegate uuid:rig:provider/model\"\n+ ));\n }\n- None => {\n- std::io::stdin()\n- .read_to_string(&mut text)\n- .context(\"failed to read stdin\")?;\n+ let mut text = String::new();\n+ match file {\n+ Some(path) => {\n+ text = std::fs::read_to_string(&path)\n+ .with_context(|| format!(\"failed to read {}\", path.display()))?;\n+ }\n+ None => {\n+ std::io::stdin()\n+ .read_to_string(&mut text)\n+ .context(\"failed to read stdin\")?;\n+ }\n }\n- }\n- if text.trim().is_empty() {\n- return Err(anyhow!(\"no input provided (empty)\"));\n- }\n- let bearer = effective_bearer().ok_or_else(|| {\n- anyhow!(\n- \"no bearer token: run `slugsocial identity start --rig --model ` \\\n- then `slugsocial identity poll `, or set SLUG_BEARER_TOKEN / ~/.config/slugsocial/token\"\n+ if text.trim().is_empty() {\n+ return Err(anyhow!(\"no input provided (empty)\"));\n+ }\n+ let bearer = effective_bearer().ok_or_else(|| {\n+ anyhow!(\n+ \"no bearer token: run `slugsocial identity start --rig --model ` \\\n+ then `slugsocial identity poll `, or set SLUG_BEARER_TOKEN / ~/.config/slugsocial/token\"\n+ )\n+ })?;\n+ let thread_tag = normalize_thread_input(&tag);\n+ let batch = send_rpc(\n+ &client,\n+ base,\n+ Some(&bearer),\n+ vec![RpcCommand::Post {\n+ room: room.to_string(),\n+ thread_tag,\n+ delegate: Some(delegate.to_string()),\n+ text,\n+ return_rank_diff: true,\n+ }],\n )\n- })?;\n- let batch = send_rpc(\n- &client,\n- base,\n- Some(&bearer),\n- vec![RpcCommand::Post {\n- room: room.to_string(),\n- thread_tag: thread,\n- delegate,\n- text,\n- return_rank_diff: true,\n- }],\n- )\n- .await?;\n- match rpc_line_ok(&batch.results[0])? {\n- RpcResult::PostOk {\n- events_appended,\n- ranking_changes,\n- threads,\n- next,\n- } => {\n- if json {\n- println!(\n- \"{}\",\n- serde_json::to_string_pretty(&serde_json::json!({\n- \"ok\": true,\n- \"events_appended\": events_appended,\n- \"ranking_changes\": ranking_changes,\n- \"threads\": threads,\n- \"next\": next,\n- }))?\n- );\n- } else {\n- println!(\"✓ ingested\");\n- println!(\"events: {}\", events_appended);\n- if !threads.is_empty() {\n- println!(\"threads:\");\n- for t in threads {\n- println!(\" {t}\");\n+ .await?;\n+ match rpc_line_ok(&batch.results[0])? {\n+ RpcResult::PostOk {\n+ events_appended,\n+ ranking_changes,\n+ threads,\n+ next,\n+ } => {\n+ if json {\n+ println!(\n+ \"{}\",\n+ serde_json::to_string_pretty(&serde_json::json!({\n+ \"ok\": true,\n+ \"events_appended\": events_appended,\n+ \"ranking_changes\": ranking_changes,\n+ \"threads\": threads,\n+ \"next\": next,\n+ }))?\n+ );\n+ } else {\n+ println!(\"✓ posted\");\n+ println!(\"events: {}\", events_appended);\n+ if !threads.is_empty() {\n+ println!(\"threads:\");\n+ for t in threads {\n+ println!(\" {t}\");\n+ }\n }\n+ if let Some(ref rc) = ranking_changes {\n+ print_ranking_changes(rc);\n+ }\n+ print_next(&next);\n+ println!();\n+ println!(\"---\");\n+ println!(\"For your next comparison: remember to ask your human first. Their perspective is what makes your submission more than another model's take.\");\n+ println!(\"---\");\n }\n- if let Some(ref rc) = ranking_changes {\n- print_ranking_changes(rc);\n- }\n- print_next(&next);\n- println!();\n- println!(\"---\");\n- println!(\"For your next comparison: remember to ask your human first. Their perspective is what makes your submission more than another model's take.\");\n- println!(\"---\");\n }\n+ _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n- _ => return Err(anyhow!(\"unexpected RPC result\")),\n }\n- }\n- ScopedCmd::Check {\n- file,\n- thread: _thread,\n- delegate: _delegate,\n- json,\n- } => {\n+ },\n+ ScopedCmd::Check { file, json } => {\n let mut text = String::new();\n match file {\n Some(path) => {\n@@ -1172,7 +1095,7 @@ async fn run_scoped(base: &str, room: &str, sub: ScopedCmd) -> Result<()> {\n }\n println!();\n println!(\"---\");\n- println!(\"Does this submission reflect input from your human? The best submissions synthesize agent analysis with user perspective. If you haven't asked your human about these items yet, consider doing so before ingesting.\");\n+ println!(\"Does this submission reflect input from your human? The best submissions synthesize agent analysis with user perspective. If you haven't asked your human about these items yet, consider doing so before posting.\");\n println!(\"---\");\n if !next.is_empty() {\n println!();\n@@ -1373,7 +1296,7 @@ async fn main() -> Result<()> {\n println!();\n println!(\" slugsocial identity poll {}\", start.session);\n println!();\n- println!(\"Agent delegate (keep in context for --delegate on ingest):\");\n+ println!(\"Agent delegate (keep in context for `forum post … --delegate`):\");\n println!(\" {}\", delegate);\n }\n }\n@@ -1441,7 +1364,7 @@ async fn main() -> Result<()> {\n println!(\"Token saved to {}\", cfg.join(\"token\").display());\n if let Some(ref a) = agent_out {\n println!();\n- println!(\"Agent delegate (for ingest --delegate):\");\n+ println!(\"Agent delegate (for `forum post … --delegate`):\");\n println!(\" {}\", a);\n }\n }\ndiff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs\nindex a18241f3ed7b4a248748fcefc799f9801ca62461..11a76ed7a02aae588edadb7a87a43660f5669d9e 100644\n--- a/server/src/api/rpc.rs\n+++ b/server/src/api/rpc.rs\n@@ -377,8 +377,8 @@ async fn rpc_post(\n ranking_changes,\n threads: vec![format!(\"#{}\", thread_id)],\n next: NextMoves {\n- pair: \"npx slugsocial pair\".to_string(),\n- rank: \"npx slugsocial rank\".to_string(),\n+ pair: \"npx slugsocial public garden pair\".to_string(),\n+ rank: \"npx slugsocial public garden rank\".to_string(),\n web: format!(\"https://slug.social/t/{}\", thread_id),\n },\n })\n@@ -461,8 +461,8 @@ async fn rpc_check(\n rankings,\n threads: vec![format!(\"#{}\", thread_id)],\n next: vec![\n- \"npx slugsocial ingest\".to_string(),\n- \"npx slugsocial forum\".to_string(),\n+ \"npx slugsocial public forum post --delegate \".to_string(),\n+ \"npx slugsocial public forum list\".to_string(),\n format!(\"https://slug.social/t/{}\", thread_id),\n ],\n })\ndiff --git a/test/integration.bb b/test/integration.bb\nindex c71dcf20021056421ab27b1313e4dec94570ddaa..07c9851e5e112f644556a847302d00b5e0f6acb4 100644\n--- a/test/integration.bb\n+++ b/test/integration.bb\n@@ -146,7 +146,7 @@\n \n ;; 2.5 check endpoint — disconnected components not flattened (before OAuth; no events.jsonl yet)\n (println \"\\nchecking (dry-run) returns discrete ranking groups…\")\n- (bind check-result (common/run-cli cli-bin base-url [\"public\" \"check\" \"--json\" \"--thread\" \"integration-test\"] :input check-doc-disconnected))\n+ (bind check-result (common/run-cli cli-bin base-url [\"public\" \"check\" \"--json\"] :input check-doc-disconnected))\n (assert! (zero? (:exit check-result)) \"cli check exits 0\")\n (bind check-resp (json/parse-string (:out check-result) true))\n (assert! (:ok check-resp) \"check response ok=true\")\n@@ -166,7 +166,7 @@\n \n ;; 3. ingest via CLI (bearer required)\n (println \"\\ningesting .sorter document via CLI…\")\n- (bind ingest1-result (common/run-cli cli-bin base-url [\"public\" \"ingest\" \"--json\" \"--thread\" \"integration-test\" \"--delegate\" \"00000000-0000-0000-0000-000000000000:cli:local/dev\"] :input sorter-doc :extra-env token-env))\n+ (bind ingest1-result (common/run-cli cli-bin base-url [\"public\" \"forum\" \"post\" \"integration-test\" \"--json\" \"--delegate\" \"00000000-0000-0000-0000-000000000000:cli:local/dev\"] :input sorter-doc :extra-env token-env))\n (assert! (zero? (:exit ingest1-result)) \"cli ingest exits 0\")\n (bind ingest1-resp (json/parse-string (:out ingest1-result) true))\n (assert! (:ok ingest1-resp) \"ingest response ok=true\")\n@@ -195,7 +195,7 @@\n \n ;; 6. query forum via CLI\n (println \"\\nquerying forum via CLI…\")\n- (bind forum-result (common/run-cli cli-bin base-url [\"public\" \"forum\" \"--json\"]))\n+ (bind forum-result (common/run-cli cli-bin base-url [\"public\" \"forum\" \"list\" \"--json\"]))\n (assert! (zero? (:exit forum-result)) \"cli forum exits 0\")\n (bind forum-resp (json/parse-string (:out forum-result) true))\n (assert! (some (fn [t] (= \"#integration-test\" (:thread t))) (:threads forum-resp))\n@@ -237,7 +237,7 @@\n \"#integration-test\"\n \"~/languages/rust 4:1 ~/languages/python { type safety }\"\n \"~/languages/rust 3:1 ~/languages/go { zero-cost abstractions }\"]))\n- (bind hist-ingest (common/run-cli cli-bin base-url [\"public\" \"ingest\" \"--json\" \"--thread\" \"integration-test\" \"--delegate\" \"00000000-0000-0000-0000-000000000000:cli:local/dev\"] :input two-vote-doc :extra-env token-env))\n+ (bind hist-ingest (common/run-cli cli-bin base-url [\"public\" \"forum\" \"post\" \"integration-test\" \"--json\" \"--delegate\" \"00000000-0000-0000-0000-000000000000:cli:local/dev\"] :input two-vote-doc :extra-env token-env))\n (assert! (zero? (:exit hist-ingest))\n (str \"two-vote ingest exits 0 (err: \" (:err hist-ingest) \")\"))\n \n\n\nSide B — contributor: tommy-mor\nSide B — commit message:\n[b9476669] Remove browser sentinel delegates so multi-user votes work.\n\nShared WEB_BROWSER_AGENT bound on first vote and blocked every later human; browser posts now use no delegate, matching forum UI.\n\nCo-authored-by: Cursor \n\nSide B — unified diff (full patch):\ndiff --git a/cli/src/main.rs b/cli/src/main.rs\nindex c4f1494df3aedbd8b883aea6249579aa8336abfe..af3e4fee876910a44f6f872b24821bc541a23e20 100644\n--- a/cli/src/main.rs\n+++ b/cli/src/main.rs\n@@ -1741,8 +1741,8 @@ async fn run() -> Result<()> {\n tokio::time::sleep(std::time::Duration::from_millis(poll_interval_ms)).await;\n let poll: PendingSessionPollResponse =\n expect_json(client.get(&poll_url).send().await?).await?;\n- if !poll.agent.trim().is_empty() {\n- agent_out = Some(poll.agent.clone());\n+ if let Some(a) = poll.agent.as_deref().map(str::trim).filter(|s| !s.is_empty()) {\n+ agent_out = Some(a.to_string());\n }\n if poll.complete {\n token_out = poll.token;\ndiff --git a/server/src/api/auth.rs b/server/src/api/auth.rs\nindex 50dc6af908412b16343829eae25154ebf4e19fca..01c02f50c19bcd62c7f1717f9b927f203c3164d0 100644\n--- a/server/src/api/auth.rs\n+++ b/server/src/api/auth.rs\n@@ -29,18 +29,6 @@ use crate::{\n write_cmd::WriteCmd,\n };\n \n-/// Delegate id for browser users who land via `/join/inv_…` (no CLI agent).\n-const INVITE_BROWSER_AGENT: &str = \"00000000-0000-0000-0000-000000000000:invite:web/join\";\n-\n-/// Agent id for `/login` browser OAuth (no CLI); must pass [`parse_agent`].\n-pub const WEB_BROWSER_AGENT: &str = \"00000000-0000-0000-0000-000000000001:social:web/browser\";\n-\n-/// True for well-known browser / human-form sentinel delegates (not real AI agents).\n-/// HTML attribution should show the human username for these, not `@@uuid:rig:…`.\n-pub fn is_browser_sentinel_delegate(agent: &str) -> bool {\n- agent == WEB_BROWSER_AGENT || agent == INVITE_BROWSER_AGENT\n-}\n-\n /// HttpOnly cookie storing the same `slug_*` bearer string the CLI uses.\n pub const SLUG_SESSION_COOKIE: &str = \"slug_session\";\n \n@@ -288,7 +276,7 @@ pub async fn get_join_invite(\n let session = format!(\"p_{}\", uuid::Uuid::new_v4().simple());\n let redirect_next = safe_local_redirect(q.next.as_deref().or(q.redirect.as_deref()));\n let s = PendingSession {\n- agent: INVITE_BROWSER_AGENT.to_string(),\n+ agent: None,\n created_ts: now_ms(),\n provider: None,\n provider_id: None,\n@@ -555,7 +543,7 @@ pub async fn post_choose_username(\n };\n \n let sessions = pending_sessions(&state);\n- let (provider, provider_id, agent) = {\n+ let (provider, provider_id) = {\n let sessions_read = sessions.read().await;\n let Some(s) = sessions_read.get(&form.session) else {\n return api_error(StatusCode::NOT_FOUND, \"unknown session\", None).into_response();\n@@ -566,14 +554,9 @@ pub async fn post_choose_username(\n let Some(provider_id) = s.provider_id.clone() else {\n return js_form_error_fragment(&form.session, \"oauth not completed\").into_response();\n };\n- (provider, provider_id, s.agent.clone())\n+ (provider, provider_id)\n };\n \n- if let Err(msg) = parse_agent(&agent) {\n- return js_form_error_fragment(&form.session, &format!(\"invalid agent format — {msg}\"))\n- .into_response();\n- }\n-\n let redeem_invite = {\n let sessions_read = sessions.read().await;\n sessions_read\n@@ -643,7 +626,8 @@ pub async fn get_web_login(\n let redirect_next = safe_local_redirect(q.next.as_deref().or(q.redirect.as_deref()))\n .or_else(|| Some(\"/\".to_string()));\n let s = PendingSession {\n- agent: WEB_BROWSER_AGENT.to_string(),\n+ // Humans sign in via the website with no AI delegate.\n+ agent: None,\n created_ts: now_ms(),\n provider: None,\n provider_id: None,\n@@ -704,7 +688,7 @@ pub async fn post_pending_session(\n );\n let poll_url = format!(\"/api/v0/pending-session/{session}\");\n let s = PendingSession {\n- agent: agent_naked,\n+ agent: Some(agent_naked),\n created_ts: now_ms(),\n provider: None,\n provider_id: None,\ndiff --git a/server/src/api/mod.rs b/server/src/api/mod.rs\nindex fdff6db0472b36cd7870a4be68574023e0daf120..920e967b47852ea82fa61b84c457ae3582dd9800 100644\n--- a/server/src/api/mod.rs\n+++ b/server/src/api/mod.rs\n@@ -18,13 +18,11 @@ pub use auth::{\n get_choose_username,\n get_web_login,\n get_logout,\n- is_browser_sentinel_delegate,\n optional_principal,\n resolve_web_session,\n session_cookie_header_value,\n WebSession,\n SLUG_SESSION_COOKIE,\n- WEB_BROWSER_AGENT,\n };\n \n pub use helpers::{\ndiff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs\nindex 611956d0a46062b49ce350be176e4be139312ff0..6e56c039a184953cd1d0593c34cf4d5abe41f2a3 100644\n--- a/server/src/api/ui_html.rs\n+++ b/server/src/api/ui_html.rs\n@@ -277,7 +277,7 @@ async fn dispatch_ui_action(\n &session.bearer,\n room.clone(),\n thread_tag.clone(),\n- Some(crate::api::auth::WEB_BROWSER_AGENT.to_string()),\n+ None,\n text,\n )\n .await\ndiff --git a/server/src/html/mod.rs b/server/src/html/mod.rs\nindex 645d54f2e117ba901e02ed958ada6ff69a78ae34..03ad762e88709c77b9d5dd130c48bc96226616a1 100644\n--- a/server/src/html/mod.rs\n+++ b/server/src/html/mod.rs\n@@ -560,27 +560,28 @@ fn identity_color_css(seed: &str) -> String {\n format!(\"hsl({hue}, 62%, 66%)\")\n }\n \n-/// Seed for author color: real AI → delegate uuid; human/sentinel → principal username.\n+/// Seed for author color: AI → delegate uuid; human (no delegate) → principal username.\n fn authorship_color_seed<'a>(principal: &'a str, delegate: &'a Option) -> &'a str {\n match delegate {\n- Some(d) if !crate::api::is_browser_sentinel_delegate(d) => {\n- d.split(':').next().filter(|s| !s.is_empty()).unwrap_or(d.as_str())\n- }\n- _ => principal,\n+ Some(d) => d\n+ .split(':')\n+ .next()\n+ .filter(|s| !s.is_empty())\n+ .unwrap_or(d.as_str()),\n+ None => principal,\n }\n }\n \n-/// Prefer the AI delegate in attribution; fall back to the human username when there is no\n-/// delegate or the delegate is a browser/human-form sentinel.\n+/// Prefer the AI delegate in attribution; humans post with no delegate and show `@username`.\n pub(crate) fn authorship_attr(principal: &str, delegate: &Option) -> AuthorshipAttr {\n let color = identity_color_css(authorship_color_seed(principal, delegate));\n match delegate {\n- Some(d) if !crate::api::is_browser_sentinel_delegate(d) => AuthorshipAttr {\n+ Some(d) => AuthorshipAttr {\n label: format!(\"@@{}\", actor_label(d)),\n author_title: Some(format!(\"@{principal}\")),\n color,\n },\n- _ => AuthorshipAttr {\n+ None => AuthorshipAttr {\n label: format!(\"@{principal}\"),\n author_title: None,\n color,\n@@ -933,7 +934,6 @@ pub(super) fn recency_class(now_ms: i64, ts_ms: i64) -> &'static str {\n #[cfg(test)]\n mod authorship_tests {\n use super::*;\n- use crate::api::WEB_BROWSER_AGENT;\n \n #[test]\n fn human_or_missing_delegate_shows_username() {\n@@ -943,15 +943,6 @@ mod authorship_tests {\n assert!(a.color.starts_with(\"hsl(\"));\n }\n \n- #[test]\n- fn browser_sentinel_delegate_shows_username() {\n- let d = Some(WEB_BROWSER_AGENT.to_string());\n- let a = authorship_attr(\"alice\", &d);\n- assert_eq!(a.label, \"@alice\");\n- assert_eq!(a.author_title, None);\n- assert_eq!(authorship_address(\"alice\", &d), \"@alice\");\n- }\n-\n #[test]\n fn real_ai_delegate_shows_short_agent_with_username_hover() {\n let d = Some(\ndiff --git a/server/src/state.rs b/server/src/state.rs\nindex 648ab5304764a329fcabbbbcd3782b94e3e005a8..8ea84dcf9b1df8f8037e913cdd94e5908e6d5d55 100644\n--- a/server/src/state.rs\n+++ b/server/src/state.rs\n@@ -21,7 +21,8 @@ pub struct InviteState {\n \n #[derive(Debug, Clone)]\n pub struct PendingSession {\n- pub agent: String,\n+ /// CLI `identity start` delegate (`uuid:rig:model`). `None` for browser `/login` and `/join`.\n+ pub agent: Option,\n pub created_ts: i64,\n pub provider: Option,\n pub provider_id: Option,\ndiff --git a/server/tests/integration_ui.rs b/server/tests/integration_ui.rs\nindex 6b1475b773106a2dd3f326475c9fb4cc727f6b4b..714563a8b330e3917d95a54ae29b4de143e3b8a4 100644\n--- a/server/tests/integration_ui.rs\n+++ b/server/tests/integration_ui.rs\n@@ -418,6 +418,99 @@ async fn test_web_login_carries_vote_pair_next_into_pending_session() {\n let sessions = state.pending_sessions.read().await;\n let pending = sessions.get(&session).expect(\"pending session\");\n assert_eq!(pending.redirect_next.as_deref(), Some(next));\n+ assert_eq!(\n+ pending.agent, None,\n+ \"browser /login must not invent a sentinel delegate\"\n+ );\n+}\n+\n+#[tokio::test]\n+async fn test_vote_compare_two_users_both_succeed_without_delegate() {\n+ let (addr, _tmp, _log, state, _handle) = create_test_server_with_state().await;\n+ let client = reqwest::Client::new();\n+ let alice = test_bearer();\n+ let bob = seed_test_identity(&state, \"bob\", \"bobtok\", \"bobsecret\").await;\n+\n+ // Define items first (votes require existing item bodies).\n+ let seed = ui_post_ingest_rpc(\n+ \"public\",\n+ \"multi-vote\",\n+ \"~/multi-a {alpha}\\n~/multi-b {beta}\\n\",\n+ );\n+ let seed_resp = client\n+ .post(format!(\"http://{addr}/ui\"))\n+ .header(\"Authorization\", format!(\"Bearer {alice}\"))\n+ .form(&[(\"__rpc__\", seed.as_str())])\n+ .send()\n+ .await\n+ .unwrap();\n+ assert_eq!(seed_resp.status(), reqwest::StatusCode::OK);\n+ let seed_js = seed_resp.text().await.unwrap();\n+ assert!(\n+ !seed_js.contains(\"auth-error\"),\n+ \"item seed must succeed, got: {seed_js}\"\n+ );\n+\n+ for (bearer, left, right, explanation) in [\n+ (&alice, \"3\", \"1\", \"alice prefers a\"),\n+ (&bob, \"1\", \"3\", \"bob prefers b\"),\n+ ] {\n+ let rpc = ui_vote_compare_post_rpc(\n+ \"public\",\n+ \"multi-vote\",\n+ \"~/multi-a\",\n+ \"~/multi-b\",\n+ left,\n+ right,\n+ explanation,\n+ );\n+ let resp = client\n+ .post(format!(\"http://{addr}/ui\"))\n+ .header(\"Authorization\", format!(\"Bearer {bearer}\"))\n+ .form(&[(\"__rpc__\", rpc.as_str())])\n+ .send()\n+ .await\n+ .unwrap();\n+ assert_eq!(resp.status(), reqwest::StatusCode::OK);\n+ let js = resp.text().await.unwrap();\n+ assert!(\n+ !js.contains(\"delegate already bound\"),\n+ \"human vote must not hit shared-sentinel AgentBound ({explanation}), got: {js}\"\n+ );\n+ assert!(\n+ !js.contains(\"auth-error\"),\n+ \"human vote must succeed ({explanation}), got: {js}\"\n+ );\n+ assert!(\n+ js.contains(\"vote-edge-history-region\"),\n+ \"vote should morph edge history ({explanation}), got: {js}\"\n+ );\n+ }\n+\n+ let reduced = state.reduced.read().await;\n+ let human_votes: Vec<_> = reduced\n+ .ingests_ordered\n+ .iter()\n+ .filter_map(|id| reduced.ingests_by_id.get(id))\n+ .filter(|ing| ing.raw.contains(\"prefers\"))\n+ .collect();\n+ assert_eq!(human_votes.len(), 2, \"expected two vote ingests\");\n+ let mut principals: Vec<&str> = human_votes.iter().map(|i| i.principal.as_str()).collect();\n+ principals.sort();\n+ assert_eq!(principals, [\"bob\", \"testuser\"]);\n+ for ing in &human_votes {\n+ assert!(\n+ ing.delegate.is_none(),\n+ \"browser votes must have no delegate, principal={} delegate={:?}\",\n+ ing.principal,\n+ ing.delegate\n+ );\n+ }\n+ assert!(\n+ reduced.agent_bindings.is_empty(),\n+ \"human votes must not create AgentBound entries: {:?}\",\n+ reduced.agent_bindings\n+ );\n }\n \n #[tokio::test]\ndiff --git a/server/tests/support/mod.rs b/server/tests/support/mod.rs\nindex a4320e991763617c1a760efad4b621977e2b74d0..67650520ea8f9f144bfe904347c40329d5db37e8 100644\n--- a/server/tests/support/mod.rs\n+++ b/server/tests/support/mod.rs\n@@ -72,17 +72,14 @@ pub async fn rpc_batch(\n response.json().await.unwrap()\n }\n \n-pub async fn seed_test_token(state: &AppState) {\n- seed_test_identity(state, \"testuser\", \"testtok\", \"secret\").await;\n-}\n-\n-/// Add a distinct principal and bearer to a running integration-test server.\n+/// Seed a user + bearer into reducer state (not appended to the event log).\n+/// Returns the `slug__` bearer string.\n pub async fn seed_test_identity(\n state: &AppState,\n username: &str,\n token_id: &str,\n secret: &str,\n-) {\n+) -> String {\n let registered = Event::UserRegistered(UserRegistered {\n ts: 0,\n username: username.to_string(),\n@@ -102,6 +99,11 @@ pub async fn seed_test_identity(\n let mut r = state.reduced.write().await;\n r.apply_event(registered);\n r.apply_event(ev);\n+ format!(\"slug_{token_id}_{secret}\")\n+}\n+\n+pub async fn seed_test_token(state: &AppState) {\n+ let _ = seed_test_identity(state, \"testuser\", \"testtok\", \"secret\").await;\n }\n \n pub async fn create_test_server_with_state() -> (\ndiff --git a/test/oauth.clj b/test/oauth.clj\nindex 3cbf496005e906ad6c579d44ac8c4055ee60d063..6911ac34a55707acda9f9ce091c079964649a252 100644\n--- a/test/oauth.clj\n+++ b/test/oauth.clj\n@@ -186,8 +186,9 @@\n (:token poll-json))))))))\n \n (defn fetch-bearer-token!\n- \"Simulate browser OAuth + username choice; returns `slug_…` bearer token.\n- Ingest `--delegate` must match this agent string for `AgentBound` on first write.\"\n+ \"Simulate CLI identity OAuth + username choice; returns `slug_…` bearer token.\n+ Pass `:agent` (default local/dev) when the test will CLI-ingest with `--delegate`\n+ so first write can `AgentBound`. Browser UI posts use no delegate.\"\n [base-url & {:keys [username agent] :or {username \"intuser\" agent default-agent}}]\n (let [token (complete-registration! base-url :username username :agent agent)]\n (when-not (str/starts-with? token \"slug_\")\ndiff --git a/types/src/lib.rs b/types/src/lib.rs\nindex cd6f94c60a4e1c3bfbce13bc0404b803f5f57c6d..4d05466c19a2f15f7d600e1d4a206b39984fabc4 100644\n--- a/types/src/lib.rs\n+++ b/types/src/lib.rs\n@@ -538,7 +538,9 @@ pub struct PendingSessionStartResponse {\n pub struct PendingSessionPollResponse {\n pub ok: bool,\n pub complete: bool,\n- pub agent: String,\n+ /// Present for CLI identity sessions; omitted for browser `/login` / `/join` (no delegate).\n+ #[serde(default, skip_serializing_if = \"Option::is_none\")]\n+ pub agent: Option,\n #[serde(skip_serializing_if = \"Option::is_none\")]\n pub user: Option,\n #[serde(skip_serializing_if = \"Option::is_none\")]\n","role":"user"}],"model":"~anthropic/claude-sonnet-latest"}