{"messages":[{"content":"You are a constitutional council ranking individual git commits for ownership allocation.\n\nCompare these two commits. Decide which contributed more lasting value to the project.\n\nJudge substance, not spectacle:\n- Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise.\n- Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one.\n- Do not favor a side merely because its patch is longer or noisier.\n- Weight what the change does for the project, not the contributor's name.\n\nReturn ONLY a JSON object: {\"winner\": \"A\" or \"B\", \"ratio\": \"N:M\", \"explanation\": \"...\"}\nThe explanation must cite concrete differences in the patches (1-3 sentences).\n\nSide A — contributor: tommy-mor\nSide A — commit message:\n[6120bd96] fix redirect urls for custom hosts and deploy from staging\n\nUse HOSTNAME and window.location.origin instead of hardcoded staging.sorter.social, and trigger fly deploys on pushes to staging.\n\nCo-authored-by: Cursor \n\nSide A — unified diff (full patch):\ndiff --git a/.github/workflows/fly-deploy.yml b/.github/workflows/fly-deploy.yml\nindex 3e693915fe6f99a5c2221b2921bf8ebc305180fc..5e11e5c312f62bed34d8cc68bd4a5538f52476b9 100644\n--- a/.github/workflows/fly-deploy.yml\n+++ b/.github/workflows/fly-deploy.yml\n@@ -3,11 +3,11 @@ name: deploy to fly.io\n on:\n push:\n branches:\n- - main\n+ - staging\n workflow_dispatch:\n \n concurrency:\n- group: fly-deploy-main\n+ group: fly-deploy-staging\n cancel-in-progress: true\n \n jobs:\ndiff --git a/borter/src/app/linear.clj b/borter/src/app/linear.clj\nindex f77d8a974e0cf05f9c33233bb625bdb190d2007b..5ef0e34cf1d543826675c6facb66aec079b40561 100644\n--- a/borter/src/app/linear.clj\n+++ b/borter/src/app/linear.clj\n@@ -6,6 +6,7 @@\n [ring.util.response :as response]\n [app.database :as db]\n [app.permissions :as perms]\n+ [app.util :as util]\n [honey.sql.helpers :as h]\n [sluj.core :refer [sluj]]))\n \n@@ -13,9 +14,7 @@\n (def client-secret (System/getenv \"BORTER_LINEAR_CLIENT_SECRET\"))\n \n (defn get-hostname []\n- (case (.getCanonicalHostName (java.net.InetAddress/getLocalHost))\n- \"sorter.social\" \"https://sorter.social/api/linear/callback\"\n- \"http://localhost:3000/api/linear/callback\"))\n+ (str (util/get-base-url) \"/api/linear/callback\"))\n \n (defn code->token [code]\n (def code code)\ndiff --git a/borter/src/app/login.clj b/borter/src/app/login.clj\nindex 5d545db9bef7765ba8b3fe7d00261c8ce84e9e1a..86817f8e94bc174e5b108859cc0b342953ab7acb 100644\n--- a/borter/src/app/login.clj\n+++ b/borter/src/app/login.clj\n@@ -1,6 +1,7 @@\n (ns app.login\n (:require [crypto.password.bcrypt :as password]\n [app.database :as db]\n+ [app.util :as util]\n [honey.sql.helpers :as h]\n [hato.client :as hc]\n [clojure.data.json :as json]\n@@ -12,10 +13,7 @@\n (def environment (or (System/getenv \"ENVIRONMENT\") \"development\"))\n \n (defn get-base-url []\n- (case environment\n- \"production\" \"https://sorter.social\"\n- \"staging\" \"https://staging.sorter.social\"\n- \"development\" \"http://localhost:3000\")) ; fallback for development\n+ (util/get-base-url))\n \n (defn create-email-content\n \"Creates a standardized email structure with customizable content\"\ndiff --git a/borter/src/app/oauth.clj b/borter/src/app/oauth.clj\nindex 1166f2ee30c9e813840711c72d1ad8f1c62e1ffe..2cd0c62f1fe267f7f5f725a97bc3ba0d0889517f 100644\n--- a/borter/src/app/oauth.clj\n+++ b/borter/src/app/oauth.clj\n@@ -3,6 +3,7 @@\n [clojure.data.json :as json]\n [hato.client :as hc]\n [app.database :as db]\n+ [app.util :as util]\n [honey.sql.helpers :as h]\n [ring.util.codec :as codec])\n (:import [java.util Base64]))\n@@ -13,12 +14,7 @@\n encoded-bytes))\n \n (defn get-hostname []\n- (let [env (System/getenv \"ENVIRONMENT\")]\n- (println \"Current environment:\" env)\n- (case env\n- \"production\" \"https://sorter.social\"\n- \"staging\" \"https://staging.sorter.social\"\n- \"http://localhost:3000\")))\n+ (util/get-base-url))\n \n (defn get-origin-hostname [req]\n (let [origin (get-in req [:headers \"origin\"])\ndiff --git a/borter/src/app/spotify.clj b/borter/src/app/spotify.clj\nindex 3e11713119141812fa2707ec956fb7ed612ee69a..b38d734351a1d4f1e142d93d4435ffe7bd20c02d 100644\n--- a/borter/src/app/spotify.clj\n+++ b/borter/src/app/spotify.clj\n@@ -1,5 +1,6 @@\n (ns app.spotify\n (:require [app.oauth :as oauth]\n+ [app.util :as util]\n [hato.client :as hc]\n [clojure.data.json :as json]\n [ring.util.codec :as codec]\n@@ -47,10 +48,7 @@\n \n \n (defn get-hostname []\n- (case (System/getenv \"ENVIRONMENT\")\n- \"production\" \"https://sorter.social\"\n- \"staging\" \"https://staging.sorter.social\"\n- \"http://localhost:3000\"))\n+ (util/get-base-url))\n \n (defn create-spotify-tag\n \"Creates a tag for a Spotify entity (artist, album, track) if it doesn't exist\"\ndiff --git a/borter/src/app/twitter.clj b/borter/src/app/twitter.clj\nindex ef7b18fa1fcb82bb944b3035ffed44499181237f..b9a3fdccc15d13918a4d11d8c0443de94fd172b4 100644\n--- a/borter/src/app/twitter.clj\n+++ b/borter/src/app/twitter.clj\n@@ -1,6 +1,7 @@\n (ns app.twitter\n (:require [app.database :as db]\n [app.permissions :as perms]\n+ [app.util :as util]\n [honey.sql.helpers :as h]\n [hato.client :as hc]\n [clojure.data.json :as json]\n@@ -37,9 +38,7 @@\n (clojure.string/join \"&\" (map (fn [[k v]] (str (name k) \"=\" v)) params)))\n \n (defn get-hostname []\n- (case (.getCanonicalHostName (java.net.InetAddress/getLocalHost))\n- \"sorter.isnt.online\" \"https://sorter.isnt.online/api/twitter/callback\"\n- \"http://localhost:3000/api/twitter/callback\"))\n+ (str (util/get-base-url) \"/api/twitter/callback\"))\n \n (defn encode-b64 [s]\n (.encodeToString (java.util.Base64/getEncoder) (.getBytes s)))\ndiff --git a/borter/src/app/util.clj b/borter/src/app/util.clj\nindex 384a64306c84aa8288ec44cd5de57edc248a826d..6a8aa0875accb28dc81bf57e645e3961b0a3ace5 100644\n--- a/borter/src/app/util.clj\n+++ b/borter/src/app/util.clj\n@@ -2,6 +2,18 @@\n (:require [clojure.string :as string])\n (:import [java.net URLEncoder]))\n \n+(defn get-base-url\n+ \"Public site base URL for redirects and oauth callbacks.\"\n+ []\n+ (if-let [hostname (not-empty (System/getenv \"HOSTNAME\"))]\n+ (if (string/starts-with? hostname \"http\")\n+ (string/replace hostname #\"/$\" \"\")\n+ (str \"https://\" (string/replace hostname #\"/$\" \"\")))\n+ (case (or (System/getenv \"ENVIRONMENT\") \"development\")\n+ \"production\" \"https://sorter.social\"\n+ \"staging\" \"https://staging.sorter.social\"\n+ \"http://localhost:3000\")))\n+\n (defn urlencode-params [params]\n (clojure.string/join \"&\" (map (fn [[k v]] (str k \"=\" (URLEncoder/encode (str v) \"UTF-8\"))) params)))\n \ndiff --git a/borter/src/app/youtube.clj b/borter/src/app/youtube.clj\nindex 647ef7c6d4f2503a63a7c074d46dc815b2a23547..fc9a2f5ed516692f19e06b4c0221f510547cf8c0 100644\n--- a/borter/src/app/youtube.clj\n+++ b/borter/src/app/youtube.clj\n@@ -6,6 +6,7 @@\n [ring.util.response :as response]\n [app.database :as db]\n [app.permissions :as perms]\n+ [app.util :as util]\n [honey.sql.helpers :as h]\n [sluj.core :refer [sluj]]))\n \n@@ -32,9 +33,7 @@\n :body (json/read-str {:key-fn keyword})))\n \n (defn get-hostname []\n- (case (.getCanonicalHostName (java.net.InetAddress/getLocalHost))\n- \"localhost\" \"http://localhost:3000/api/youtube/callback\"\n- \"https://sorter.isnt.online/api/youtube/callback\"))\n+ (str (util/get-base-url) \"/api/youtube/callback\"))\n \n \n \ndiff --git a/forter/src/utils/authUtils.js b/forter/src/utils/authUtils.js\nindex 145e5db7ad6f7a6439d68c63beb4d07d31b2de08..98ed7fa671f9887f44dc1479d85569951eb4773e 100644\n--- a/forter/src/utils/authUtils.js\n+++ b/forter/src/utils/authUtils.js\n@@ -5,8 +5,11 @@ import { current_session, fetchSession } from \"../session\";\n let lastSyncTime = 0;\n const SYNC_THROTTLE_MS = 5000; // Only sync once every 5 seconds\n \n-// Get base URL based on Vite's mode\n+// Get base URL based on current origin, with build-mode fallbacks for SSR/build\n const getBaseUrl = () => {\n+ if (typeof window !== 'undefined' && window.location?.origin) {\n+ return window.location.origin;\n+ }\n switch (import.meta.env.MODE) {\n case 'production':\n return 'https://sorter.social';\n\n\nSide B — contributor: tommy-mor\nSide B — commit message:\n[6b6eb0c3] Auth form: poem JS morphs form innerHTML on response; no redirect\n\n- post_choose_username returns HTML fragments instead of redirects:\n success → auth_signed_in_fragment (\"you're signed in — return to your agent\")\n error → choose_username_error_fragment (form re-rendered with error inline)\n- Poem JS now reads response body; if non-empty, morphs form innerHTML with it\n (existing ingest forms return empty body, so they're unaffected)\n- auth.rs: keep full layout() with poem JS — revert to single layout\n- auth-success CSS class added to both themes\n\nCo-Authored-By: Claude Sonnet 4.6 (1M context) \n\nSide B — unified diff (full patch):\ndiff --git a/server/src/api/auth.rs b/server/src/api/auth.rs\nindex c1194f79fd89fb47fe6b425b494a0ffa667abb2d..cb0faa29b834931e2c2b2f5c174c875e2e2e9346 100644\n--- a/server/src/api/auth.rs\n+++ b/server/src/api/auth.rs\n@@ -16,7 +16,7 @@ use crate::{\n canonicalize_username, validate_agent_format, validate_username,\n Event, TokenIssued, UserRegistered,\n },\n- html::{auth_complete_page, choose_username_page},\n+ html::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page},\n state::{AppState, PendingSession},\n };\n \n@@ -274,8 +274,6 @@ pub async fn post_choose_username(\n return api_error(StatusCode::BAD_REQUEST, \"invalid agent format\", Some(msg)).into_response();\n }\n \n- let public_url = std::env::var(\"SLUG_PUBLIC_URL\").unwrap_or_else(|_| \"http://127.0.0.1:8080\".to_string());\n-\n let reduced_arc = state.reduced.clone();\n let reduced = reduced_arc.read().await;\n let provider_key = (provider.to_lowercase(), provider_id.clone());\n@@ -284,11 +282,7 @@ pub async fn post_choose_username(\n }\n if reduced.users_by_provider.values().any(|u| u == &canonicalize_username(&form.username)) {\n drop(reduced);\n- return Redirect::to(&format!(\n- \"{public_url}/auth/choose-username?session={}&error={}\",\n- urlencoding::encode(&form.session),\n- urlencoding::encode(\"that username is taken — try another\"),\n- )).into_response();\n+ return choose_username_error_fragment(&form.session, \"that username is taken — try another\").into_response();\n }\n drop(reduced);\n \n@@ -324,7 +318,7 @@ pub async fn post_choose_username(\n s.complete = Some((canon_user.clone(), bearer.clone()));\n }\n \n- Redirect::to(&format!(\"{public_url}/auth/complete\")).into_response()\n+ auth_signed_in_fragment().into_response()\n }\n \n pub async fn post_pending_session(\ndiff --git a/server/src/html/auth.rs b/server/src/html/auth.rs\nindex 40b1ef30a6c1d4063aa2d8e9c93df8972df4b27c..0a14bdbfb66c65d1bd09993ffd4a7bb6f2fe041e 100644\n--- a/server/src/html/auth.rs\n+++ b/server/src/html/auth.rs\n@@ -1,20 +1,25 @@\n-use maud::{html, Markup, DOCTYPE};\n+use maud::{html, Markup};\n \n-/// Minimal layout for auth pages — no JS interceptor, real form navigation works.\n-fn auth_layout(title: &str, body: Markup) -> Markup {\n+fn form_inner(session: &str, error: Option<&str>) -> Markup {\n html! {\n- (DOCTYPE)\n- html {\n- head {\n- meta charset=\"utf-8\";\n- meta name=\"viewport\" content=\"width=device-width, initial-scale=1\";\n- title { (title) }\n- link rel=\"stylesheet\" href=\"/static/theme_default.css\";\n- }\n- body class=\"view-auth\" {\n- (body)\n- }\n+ input type=\"hidden\" name=\"session\" value=(session);\n+ label for=\"username\" { \"username\" }\n+ input\n+ type=\"text\"\n+ id=\"username\"\n+ name=\"username\"\n+ placeholder=\"e.g. alice\"\n+ pattern=\"[a-z0-9_\\\\-]{1,32}\"\n+ maxlength=\"32\"\n+ autocomplete=\"off\"\n+ autofocus;\n+ p.auth-hint {\n+ \"lowercase · alphanumeric · hyphens · underscores · max 32\"\n }\n+ @if let Some(msg) = error {\n+ p.auth-error { (msg) }\n+ }\n+ button type=\"submit\" { \"continue\" }\n }\n }\n \n@@ -28,27 +33,23 @@ pub fn choose_username_page(session: &str, error: Option<&str>) -> Markup {\n h1 { \"choose a username\" }\n p { \"pick a handle for slug.social.\" }\n form.auth-form method=\"POST\" action=\"/auth/choose-username\" {\n- input type=\"hidden\" name=\"session\" value=(session);\n- label for=\"username\" { \"username\" }\n- input\n- type=\"text\"\n- id=\"username\"\n- name=\"username\"\n- placeholder=\"e.g. alice\"\n- pattern=\"[a-z0-9_\\\\-]{1,32}\"\n- maxlength=\"32\"\n- autocomplete=\"off\"\n- autofocus;\n- p.auth-hint {\n- \"lowercase · alphanumeric · hyphens · underscores · max 32\"\n- }\n- @if let Some(msg) = error {\n- p.auth-error { (msg) }\n- }\n- button type=\"submit\" { \"continue\" }\n+ (form_inner(session, error))\n }\n };\n- auth_layout(\"join — slug.social\", body)\n+ super::layout(\"join — slug.social\", \"view-auth\", body, None)\n+}\n+\n+/// Fragment returned to the poem JS on error — replaces the form's innerHTML.\n+pub fn choose_username_error_fragment(session: &str, error: &str) -> Markup {\n+ form_inner(session, Some(error))\n+}\n+\n+/// Fragment returned to the poem JS on success — replaces the form's innerHTML.\n+pub fn auth_signed_in_fragment() -> Markup {\n+ html! {\n+ p.auth-success { \"you're signed in — return to your agent.\" }\n+ p.auth-hint { \"you can close this tab.\" }\n+ }\n }\n \n pub fn auth_complete_page() -> Markup {\n@@ -62,5 +63,5 @@ pub fn auth_complete_page() -> Markup {\n p { \"Return to your terminal — your agent is polling and will collect your token automatically.\" }\n p.auth-hint { \"You can close this tab.\" }\n };\n- auth_layout(\"signed in — slug.social\", body)\n+ super::layout(\"signed in — slug.social\", \"view-auth\", body, None)\n }\ndiff --git a/server/src/html/mod.rs b/server/src/html/mod.rs\nindex 2f16d701962d703db0c859bb586dfc08ec385690..8b48a25cce79f0eefc7e29849e1a667cae4c7986 100644\n--- a/server/src/html/mod.rs\n+++ b/server/src/html/mod.rs\n@@ -15,7 +15,7 @@ mod search;\n mod tree;\n use breadcrumb_path::OntologyPath;\n \n-pub use auth::{auth_complete_page, choose_username_page};\n+pub use auth::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page};\n pub use editor::{editor_check, editor_page};\n pub use forum::{index, thread_feed_html, thread_post_expand, thread_post_view, thread_view};\n pub use garden::{garden_index, ontology_path};\n@@ -114,6 +114,8 @@ script { (maud::PreEscaped(r#\"\n });\n \n // Poem: intercept POST forms, send via fetch, await SSE for DOM update.\n+ // If the response body is non-empty HTML, morph the form's innerHTML with it\n+ // (used for inline feedback without a page reload, e.g. auth forms).\n document.addEventListener('submit', async (e) => {\n const f = e.target;\n if (!f || f.tagName !== 'FORM') return;\n@@ -121,14 +123,19 @@ script { (maud::PreEscaped(r#\"\n e.preventDefault();\n const btn = f.querySelector('button[type=\"submit\"], input[type=\"submit\"]');\n if (btn) { btn.disabled = true; btn.textContent = '…'; }\n- await fetch(f.action, {\n+ const resp = await fetch(f.action, {\n method: 'POST',\n body: new URLSearchParams(new FormData(f)),\n headers: { 'Content-Type': 'application/x-www-form-urlencoded' },\n credentials: 'same-origin',\n });\n- if (btn) { btn.disabled = false; btn.textContent = 'submit'; }\n- f.reset();\n+ const html = await resp.text();\n+ if (html && html.trim()) {\n+ Idiomorph.morph(f, html, {morphStyle: 'innerHTML'});\n+ } else {\n+ if (btn) { btn.disabled = false; btn.textContent = 'submit'; }\n+ f.reset();\n+ }\n });\n \n // Search: debounced fetch + idiomorph.\ndiff --git a/server/static/theme_default.css b/server/static/theme_default.css\nindex 9e71574da4bed3a0116c347610636780678bd1af..a1d8d1765a7812191edc579125facf1694554c2c 100644\n--- a/server/static/theme_default.css\n+++ b/server/static/theme_default.css\n@@ -250,6 +250,11 @@ p.auth-error {\n font-size: 12px;\n margin: 4px 0 0;\n }\n+p.auth-success {\n+ color: var(--signal);\n+ font-size: 13px;\n+ margin: 4px 0 0;\n+}\n \n /* ----------------------------------------------------------------\n BUTTONS — raised, press on :active\ndiff --git a/server/static/theme_retro.css b/server/static/theme_retro.css\nindex dc9fa4654f529eb1843557fb580cf3982da46901..8ed8fd88efab32b36bd66cf200aa182219b0a8b5 100644\n--- a/server/static/theme_retro.css\n+++ b/server/static/theme_retro.css\n@@ -32,6 +32,7 @@ input[type=\"text\"] {\n input[type=\"text\"]:focus { border-color: #00ff41; }\n p.auth-hint { color: #555; font-family: monospace; font-size: 0.75rem; margin: 0; }\n p.auth-error { color: #ff4444; font-family: monospace; font-size: 0.8rem; margin: 0; }\n+p.auth-success { color: #00ff41; font-family: monospace; font-size: 0.8rem; margin: 0; }\n \n /* Ingest form (poem pattern) */\n .ingest-form-wrap { margin-top: 1.5rem; }\n","role":"user"}],"model":"openai/gpt-chat-latest"}