{"messages":[{"content":"You are a constitutional council ranking individual git commits for ownership allocation.\n\nCompare these two commits. Decide which contributed more lasting value to the project.\n\nJudge substance, not spectacle:\n- Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise.\n- Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one.\n- Do not favor a side merely because its patch is longer or noisier.\n- Weight what the change does for the project, not the contributor's name.\n\nReturn ONLY a JSON object: {\"winner\": \"A\" or \"B\", \"ratio\": \"N:M\", \"explanation\": \"...\"}\nThe explanation must cite concrete differences in the patches (1-3 sentences).\n\nSide A — contributor: tommy-mor\nSide A — commit message:\n[a888d56c] refactor: centralize path identity in slug-types\n\nMove canonicalization and CanonicalItemUrl into types::paths with\nGardenItemUrl, ForumThreadUrl, and TildeOntologyPath for JSON hrefs.\nServer canonical_path and path_types re-export slug-types; RPC and\nvalidation build hrefs via those types instead of string helpers.\n\nMade-with: Cursor\n\nSide A — unified diff (full patch):\ndiff --git a/server/src/api/helpers.rs b/server/src/api/helpers.rs\nindex 9b71491e9f9efc44a2a4beba09be8f64bd2ff2ee..03b3e77911ccd662bec8635345dafe2593cf242e 100644\n--- a/server/src/api/helpers.rs\n+++ b/server/src/api/helpers.rs\n@@ -4,12 +4,12 @@ use axum::{\n Json,\n };\n use sha2::{Digest, Sha256};\n+use slug_types::paths::{CanonicalItemUrl, GardenItemUrl};\n use slug_types::*;\n use std::collections::HashMap;\n \n use crate::{\n canonical_path::canonicalize_item,\n- path_types::CanonicalItemUrl,\n ranking::connected_components_from_voted_pairs,\n };\n \n@@ -30,64 +30,6 @@ pub fn now_ms() -> i64 {\n t.as_millis() as i64\n }\n \n-/// Serialize a canonical item for JSON: absolute URLs stay as-is; bare paths get a `/` prefix.\n-pub fn item_path_for_api(item: &str) -> String {\n- if item.starts_with(\"http://\") || item.starts_with(\"https://\") {\n- item.to_string()\n- } else {\n- format!(\"/{}\", item)\n- }\n-}\n-\n-/// Same as [`item_path_for_api`], but for private rooms ontology items are prefixed with\n-/// `/r/{short}/{slug}` so the URL matches the web app (`/r/…/~/…` routes).\n-pub fn item_path_for_api_in_room(item: &str, room_wire: &str) -> String {\n- let room = room_wire.trim();\n- if room.is_empty() || room == \"public\" {\n- return item_path_for_api(item);\n- }\n- let Some((short, slug)) = room.split_once('/') else {\n- return item_path_for_api(item);\n- };\n- if short.is_empty() || slug.is_empty() {\n- return item_path_for_api(item);\n- }\n- let Some(c) = CanonicalItemUrl::parse(item) else {\n- return item_path_for_api(item);\n- };\n- let root = CanonicalItemUrl::ontology_root();\n- let item_norm = c.as_str().trim_end_matches('/');\n- let root_norm = root.as_str().trim_end_matches('/');\n- if let Some(tail) = c.tilde_tail() {\n- return if tail.is_empty() {\n- format!(\"https://slug.social/r/{short}/{slug}/~\")\n- } else {\n- format!(\"https://slug.social/r/{short}/{slug}/~/{}\", tail)\n- };\n- }\n- if item_norm == root_norm {\n- return format!(\"https://slug.social/r/{short}/{slug}/~\");\n- }\n- item_path_for_api(item)\n-}\n-\n-/// Absolute thread URL for forum JSON (`/t/…` vs `/r/…/t/…`).\n-pub fn forum_thread_web_url(room_wire: &str, thread_tag: &str) -> String {\n- let room = room_wire.trim();\n- let tag = thread_tag.trim().trim_start_matches('#');\n- if room.is_empty() || room == \"public\" {\n- format!(\"https://slug.social/t/{tag}\")\n- } else if let Some((short, slug)) = room.split_once('/') {\n- if short.is_empty() || slug.is_empty() {\n- format!(\"https://slug.social/t/{tag}\")\n- } else {\n- format!(\"https://slug.social/r/{short}/{slug}/t/{tag}\")\n- }\n- } else {\n- format!(\"https://slug.social/t/{tag}\")\n- }\n-}\n-\n /// Resolve an item path as a first-class canonical path.\n pub fn resolve_item(item: &str) -> Result {\n let canonical = canonicalize_item(item);\n@@ -109,14 +51,12 @@ pub fn parse_parent_specs(parent: Option<&String>) -> Vec {\n }\n \n /// Apply offset+limit pagination to the flattened component rankings.\n-/// Items are flattened in component order (largest component first), then unranked last.\n-/// Returns (components, unranked_items) after the window.\n pub fn paginate_rankings(\n components: Vec,\n- unranked_items: Vec,\n+ unranked_items: Vec,\n offset: usize,\n limit: Option,\n-) -> (Vec, Vec) {\n+) -> (Vec, Vec) {\n let mut remaining_skip = offset;\n let mut remaining_take = limit.unwrap_or(usize::MAX);\n let mut out_components: Vec = Vec::new();\n@@ -141,7 +81,7 @@ pub fn paginate_rankings(\n });\n }\n \n- let out_unranked: Vec = if remaining_take > 0 {\n+ let out_unranked: Vec = if remaining_take > 0 {\n unranked_items\n .into_iter()\n .skip(remaining_skip)\n@@ -183,11 +123,9 @@ pub fn is_pair_voted(group: &crate::reducer::GroupState, a: &str, b: &str) -> bo\n group.voted_pairs.contains(&(i, j))\n }\n \n-/// Compute graph connectivity stats for a set of items within the ranking group.\n pub fn compute_connectivity_stats(group: &crate::reducer::GroupState, pool: &[String]) -> ConnectivityStats {\n let n = pool.len();\n \n- // Map pool items to global indices (items not yet in the group get no index)\n let global_idxs: Vec> = pool\n .iter()\n .map(|it| {\n@@ -197,7 +135,6 @@ pub fn compute_connectivity_stats(group: &crate::reducer::GroupState, pool: &[St\n .collect();\n let present: Vec = global_idxs.iter().filter_map(|x| *x).collect();\n \n- // Build local index mapping for items that exist in the ranking group\n let global_to_local: HashMap = present\n .iter()\n .enumerate()\n@@ -213,7 +150,6 @@ pub fn compute_connectivity_stats(group: &crate::reducer::GroupState, pool: &[St\n }),\n );\n \n- // Items not in the ranking group at all are also isolates\n let items_not_in_group = global_idxs.iter().filter(|x| x.is_none()).count();\n \n let num_components = comps.len() + isolates.len() + items_not_in_group;\n@@ -237,52 +173,3 @@ pub fn vote_touches_path(a: &str, b: &str, parent_canon: &str) -> bool {\n let under = |item: &str| item == parent_canon || item.starts_with(&format!(\"{}/\", parent_canon));\n under(a) || under(b)\n }\n-\n-#[cfg(test)]\n-mod wire_url_tests {\n- use super::{forum_thread_web_url, item_path_for_api_in_room};\n-\n- #[test]\n- fn public_room_unchanged() {\n- let u = \"https://slug.social/~/a/b\";\n- assert_eq!(item_path_for_api_in_room(u, \"public\"), u);\n- }\n-\n- #[test]\n- fn private_room_prefixes_ontology() {\n- assert_eq!(\n- item_path_for_api_in_room(\"https://slug.social/~/topic/x\", \"9ab12cd/my-room\"),\n- \"https://slug.social/r/9ab12cd/my-room/~/topic/x\"\n- );\n- }\n-\n- #[test]\n- fn private_room_ontology_root() {\n- assert_eq!(\n- item_path_for_api_in_room(\"https://slug.social/~\", \"9ab12cd/my-room\"),\n- \"https://slug.social/r/9ab12cd/my-room/~\"\n- );\n- assert_eq!(\n- item_path_for_api_in_room(\"https://slug.social/~/\", \"9ab12cd/my-room\"),\n- \"https://slug.social/r/9ab12cd/my-room/~\"\n- );\n- }\n-\n- #[test]\n- fn external_url_untouched_in_private_room() {\n- let u = \"https://example.com/z\";\n- assert_eq!(item_path_for_api_in_room(u, \"9ab12cd/my-room\"), u);\n- }\n-\n- #[test]\n- fn forum_web_public_vs_room() {\n- assert_eq!(\n- forum_thread_web_url(\"public\", \"debate\"),\n- \"https://slug.social/t/debate\"\n- );\n- assert_eq!(\n- forum_thread_web_url(\"9ab12cd/my-room\", \"#debate\"),\n- \"https://slug.social/r/9ab12cd/my-room/t/debate\"\n- );\n- }\n-}\ndiff --git a/server/src/api/mod.rs b/server/src/api/mod.rs\nindex 042aa248305f9362a3be78f9eea2a5abf6ba707a..cf22cb0129366c3aed031bc86f3197a4321cb806 100644\n--- a/server/src/api/mod.rs\n+++ b/server/src/api/mod.rs\n@@ -24,8 +24,7 @@ pub use auth::{\n \n pub use helpers::{\n api_error, compute_connectivity_stats, is_pair_voted, now_ms, paginate_rankings,\n- parse_parent_specs, pick_random_distinct, sha256_hex, resolve_item, vote_touches_path,\n- item_path_for_api,\n+ parse_parent_specs, pick_random_distinct, resolve_item, sha256_hex, vote_touches_path,\n };\n \n pub use rpc::handle_rpc_batch;\ndiff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs\nindex 5b91f5836625eedbb1cd9423168046e3fb576c17..5f7d50188f1381267402f2e57e671234ef5db2fd 100644\n--- a/server/src/api/rpc.rs\n+++ b/server/src/api/rpc.rs\n@@ -8,6 +8,7 @@ use axum::{\n Json,\n };\n use rand::seq::SliceRandom;\n+use slug_types::paths::{ForumThreadUrl, GardenItemUrl, TildeOntologyPath};\n use slug_types::*;\n \n use crate::{\n@@ -27,9 +28,8 @@ use crate::{\n \n use super::auth::verify_bearer_principal;\n use super::helpers::{\n- compute_connectivity_stats, forum_thread_web_url, is_pair_voted, item_path_for_api,\n- item_path_for_api_in_room, now_ms, paginate_rankings, parse_parent_specs, pick_random_distinct,\n- resolve_item, vote_touches_path,\n+ compute_connectivity_stats, is_pair_voted, now_ms, paginate_rankings, parse_parent_specs,\n+ pick_random_distinct, resolve_item, vote_touches_path,\n };\n use super::validate::{normalize_room_and_thread, validate_ingest_document};\n \n@@ -184,7 +184,7 @@ fn compute_scope_rank_changes(\n };\n if changed {\n changes.push(RankChange {\n- item: item_path_for_api_in_room(&item, room_wire),\n+ item: GardenItemUrl::from_storage_str(&item, room_wire),\n before: b,\n after: a,\n });\n@@ -206,7 +206,7 @@ fn compute_scope_rank_changes(\n parent: if parent.is_empty() {\n \"/\".to_string()\n } else {\n- item_path_for_api_in_room(parent, room_wire)\n+ GardenItemUrl::from_storage_str(parent, room_wire).into_inner()\n },\n changes,\n })\n@@ -302,7 +302,7 @@ fn build_rank_response_for_content(\n .ranked\n .into_iter()\n .map(|r| RankRow {\n- item: item_path_for_api_in_room(r.item.as_str(), room_wire),\n+ item: GardenItemUrl::from_stored(&r.item, room_wire),\n percent: if want_percent {\n Some((r.score / max_score) * 100.0)\n } else {\n@@ -315,10 +315,10 @@ fn build_rank_response_for_content(\n })\n .collect();\n \n- let prefixed_unranked: Vec = rankings\n+ let prefixed_unranked: Vec = rankings\n .unranked_items\n .into_iter()\n- .map(|s| item_path_for_api_in_room(s.as_str(), room_wire))\n+ .map(|s| GardenItemUrl::from_stored(&s, room_wire))\n .collect();\n \n let (components, unranked_items) = if offset > 0 || limit.is_some() {\n@@ -537,13 +537,13 @@ async fn rpc_post(\n (\n \"npx slugsocial public garden pair\".to_string(),\n \"npx slugsocial public garden rank\".to_string(),\n- forum_thread_web_url(\"public\", &thread_id),\n+ ForumThreadUrl::from_room_tag(\"public\", &thread_id),\n )\n } else {\n (\n format!(\"npx slugsocial private {room_key} garden pair\"),\n format!(\"npx slugsocial private {room_key} garden rank\"),\n- forum_thread_web_url(&room_key, &thread_id),\n+ ForumThreadUrl::from_room_tag(&room_key, &thread_id),\n )\n };\n \n@@ -664,7 +664,7 @@ async fn rpc_check(\n .ranked\n .into_iter()\n .map(|r| RankRow {\n- item: item_path_for_api_in_room(r.item.as_str(), &room_key),\n+ item: GardenItemUrl::from_stored(&r.item, &room_key),\n score: r.score,\n percent: None,\n })\n@@ -672,12 +672,12 @@ async fn rpc_check(\n })\n .collect();\n CheckScopeRanking {\n- parent: item_path_for_api_in_room(parent.as_str(), &room_key),\n+ parent: GardenItemUrl::from_stored(parent, &room_key).into_inner(),\n components,\n unranked_items: scoped\n .unranked_items\n .into_iter()\n- .map(|it| item_path_for_api_in_room(it.as_str(), &room_key))\n+ .map(|it| GardenItemUrl::from_stored(&it, &room_key))\n .collect(),\n }\n })\n@@ -687,13 +687,13 @@ async fn rpc_check(\n vec![\n \"npx slugsocial public forum post --delegate \".to_string(),\n \"npx slugsocial public forum list\".to_string(),\n- forum_thread_web_url(\"public\", &thread_id),\n+ ForumThreadUrl::from_room_tag(\"public\", &thread_id).into_inner(),\n ]\n } else {\n vec![\n format!(\"npx slugsocial private {room_key} forum post --delegate \"),\n format!(\"npx slugsocial private {room_key} forum list\"),\n- forum_thread_web_url(&room_key, &thread_id),\n+ ForumThreadUrl::from_room_tag(&room_key, &thread_id).into_inner(),\n ]\n };\n \n@@ -717,7 +717,7 @@ fn rpc_list_forum_threads(reduced: &ReducerState, room: &str) -> ThreadsResponse\n .map(|((_, tag), ts)| ThreadSummary {\n thread: format!(\"#{tag}\"),\n last_activity_ts: ts.last_activity_ts,\n- web: forum_thread_web_url(room, tag),\n+ web: ForumThreadUrl::from_room_tag(room, tag),\n })\n .collect();\n out.sort_by(|a, b| b.last_activity_ts.cmp(&a.last_activity_ts));\n@@ -885,7 +885,7 @@ fn rpc_search(reduced: &ReducerState, q: &str, limit: usize, principal: Option<&\n }\n if score > 0 {\n scored_items.push((score, SearchItemHit {\n- path: item_path_for_api(item.as_str()),\n+ path: GardenItemUrl::from_storage_str(item.as_str(), \"public\"),\n body: content.item_bodies.get(item).map(|b| snippet_around(b, &words, 120)),\n }));\n }\n@@ -1058,8 +1058,8 @@ async fn rpc_get_pair(state: &AppState, room: String, parent_path: String) -> Re\n .collect();\n let cs = compute_connectivity_stats(&content.ranking_group, &pool);\n Ok(RpcResult::Pair(PairResponse {\n- left: item_path_for_api_in_room(&left, &room),\n- right: item_path_for_api_in_room(&right, &room),\n+ left: GardenItemUrl::from_storage_str(&left, &room),\n+ right: GardenItemUrl::from_storage_str(&right, &room),\n left_body: lb,\n right_body: rb,\n threads: th,\n@@ -1137,7 +1137,7 @@ pub async fn handle_rpc_batch(\n if !content.items.contains(&item) {\n line_err(\n \"item not found\",\n- Some(format!(\"{} does not exist\", item_path_for_api_in_room(&item_str, &room))),\n+ Some(format!(\"{} does not exist\", GardenItemUrl::from_storage_str(&item_str, &room))),\n )\n } else {\n const MAX_ITEM_BODY: usize = 10_000;\n@@ -1160,7 +1160,7 @@ pub async fn handle_rpc_batch(\n .map(|s| s.iter().cloned().collect())\n .unwrap_or_default();\n line_ok(RpcResult::GardenItem(ItemResponse {\n- item: item_path_for_api_in_room(&item_str, &room),\n+ item: GardenItemUrl::from_storage_str(&item_str, &room),\n body,\n truncated,\n body_len,\n@@ -1554,7 +1554,7 @@ pub async fn handle_rpc_batch(\n for r in items {\n let pct = want_percent.then(|| ((r.score - bot) / range * 100.0).clamp(0.0, 100.0));\n ranked.push(RankRow {\n- item: item_path_for_api_in_room(r.item.as_str(), &room),\n+ item: GardenItemUrl::from_storage_str(r.item.as_str(), &room),\n score: r.score,\n percent: pct,\n });\n@@ -1574,7 +1574,7 @@ pub async fn handle_rpc_batch(\n let page: Vec = ranked\n .into_iter()\n .chain(unranked.into_iter().map(|it| RankRow {\n- item: item_path_for_api_in_room(&it, &room),\n+ item: GardenItemUrl::from_storage_str(&it, &room),\n score: 0.0,\n percent: want_percent.then_some(0.0),\n }))\n@@ -1618,7 +1618,7 @@ pub async fn handle_rpc_batch(\n if !content.items.contains(&item) {\n line_err(\n \"item not found\",\n- Some(format!(\"{} does not exist\", item_path_for_api_in_room(&item_str, &room))),\n+ Some(format!(\"{} does not exist\", GardenItemUrl::from_storage_str(&item_str, &room))),\n )\n } else {\n let votes: Vec = content\n@@ -1629,8 +1629,8 @@ pub async fn handle_rpc_batch(\n .take(limit)\n .map(|v| VoteRow {\n ts: v.ts,\n- a: item_path_for_api_in_room(v.a.as_str(), &room),\n- b: item_path_for_api_in_room(v.b.as_str(), &room),\n+ a: GardenItemUrl::from_stored(&v.a, &room),\n+ b: GardenItemUrl::from_stored(&v.b, &room),\n ratio: format!(\"{}:{}\", v.ratio_left, v.ratio_right),\n actor: Some(v.principal.clone()),\n body: v.body.clone(),\n@@ -1640,7 +1640,7 @@ pub async fn handle_rpc_batch(\n })\n .unwrap_or_default();\n line_ok(RpcResult::Matchup(MatchupResponse {\n- item: item_path_for_api_in_room(&item_str, &room),\n+ item: GardenItemUrl::from_storage_str(&item_str, &room),\n votes,\n }))\n }\n@@ -1667,8 +1667,8 @@ pub async fn handle_rpc_batch(\n if a == item_str || b == item_str {\n Some(VoteRow {\n ts: e.ts,\n- a: item_path_for_api_in_room(&a, &room),\n- b: item_path_for_api_in_room(&b, &room),\n+ a: GardenItemUrl::from_storage_str(&a, &room),\n+ b: GardenItemUrl::from_storage_str(&b, &room),\n ratio: format!(\"{}:{}\", ratio_left, ratio_right),\n actor: reduced.ingests_by_id.get(&e.post_id).map(|ing| ing.principal.clone()),\n body: explanation,\n@@ -1704,7 +1704,7 @@ pub async fn handle_rpc_batch(\n }\n }).collect();\n line_ok(RpcResult::RankHistory(RankHistoryResponse {\n- item: item_path_for_api_in_room(&item_str, &room),\n+ item: GardenItemUrl::from_storage_str(&item_str, &room),\n history,\n }))\n }\n@@ -1716,17 +1716,13 @@ pub async fn handle_rpc_batch(\n } else {\n let content = content_for_room(&reduced, &room);\n let parents: HashSet<&str> = content.item_children.keys().map(|s| s.as_str()).collect();\n- let mut paths: Vec = content\n+ let mut paths: Vec = content\n .items\n .iter()\n .filter(|p| !parents.contains(p.as_str()))\n- .map(|p| p.as_str().to_string())\n- .collect();\n- paths.sort();\n- let paths: Vec = paths\n- .into_iter()\n- .map(|p| item_path_for_api_in_room(&p, &room))\n+ .map(|p| GardenItemUrl::from_stored(p, &room))\n .collect();\n+ paths.sort_by(|a, b| a.as_str().cmp(b.as_str()));\n line_ok(RpcResult::Leaves(LeavesResponse { paths }))\n }\n },\n@@ -1743,24 +1739,13 @@ pub async fn handle_rpc_batch(\n let mut v: Vec = roots.iter()\n .map(|path| {\n let children = content.item_children.get(path.as_str()).map(|s| s.len()).unwrap_or(0);\n- let path_label = CanonicalItemUrl::parse(path.as_str())\n- .and_then(|c| {\n- c.tilde_tail().map(|t| {\n- if t.is_empty() {\n- \"~/\".to_string()\n- } else {\n- format!(\"~/{}\", t)\n- }\n- })\n- })\n- .unwrap_or_else(|| path.to_string());\n PathSummary {\n- path: path_label,\n+ path: TildeOntologyPath::from_stored(path),\n children,\n- web: item_path_for_api_in_room(path.as_str(), &room),\n+ web: GardenItemUrl::from_stored(path, &room),\n }\n }).collect();\n- v.sort_by(|a, b| a.path.cmp(&b.path));\n+ v.sort_by(|a, b| a.path.as_str().cmp(b.path.as_str()));\n v\n })\n .unwrap_or_default();\n@@ -1790,8 +1775,8 @@ pub async fn handle_rpc_batch(\n .take(limit)\n .map(|v| VoteRow {\n ts: v.ts,\n- a: item_path_for_api_in_room(v.a.as_str(), &room),\n- b: item_path_for_api_in_room(v.b.as_str(), &room),\n+ a: GardenItemUrl::from_stored(&v.a, &room),\n+ b: GardenItemUrl::from_stored(&v.b, &room),\n ratio: format!(\"{}:{}\", v.ratio_left, v.ratio_right),\n actor: Some(v.principal.clone()),\n body: v.body.clone(),\ndiff --git a/server/src/api/validate.rs b/server/src/api/validate.rs\nindex 27150577982f52cbd6d11bb93654dc3d4cf75cc5..a51c783ee9785569b5a44c0b1572471fe00d174b 100644\n--- a/server/src/api/validate.rs\n+++ b/server/src/api/validate.rs\n@@ -7,8 +7,9 @@ use crate::{\n path_types::CanonicalItemUrl,\n reducer::{ReducerState, ScopeId},\n };\n+use slug_types::paths::GardenItemUrl;\n \n-use super::helpers::{item_path_for_api, resolve_item};\n+use super::helpers::resolve_item;\n \n #[derive(Debug)]\n pub struct ValidatedIngest {\n@@ -22,6 +23,10 @@ pub fn validate_ingest_document(\n text: &str,\n scope: &ScopeId,\n ) -> Result)> {\n+ let room_wire = match scope {\n+ ScopeId::Public => \"public\",\n+ ScopeId::Room(r) => r.as_str(),\n+ };\n let public_content = reduced.public();\n let scoped_content = match scope {\n ScopeId::Public => None,\n@@ -61,14 +66,14 @@ pub fn validate_ingest_document(\n let Some(body_text) = body else {\n return Err((\n StatusCode::BAD_REQUEST,\n- format!(\"item missing body: {}\", item_path_for_api(&item)),\n+ format!(\"item missing body: {}\", GardenItemUrl::from_storage_str(&item, room_wire)),\n Some(\"items must be declared with bodies, e.g. `~/path/item { ... }`\".to_string()),\n ));\n };\n if body_text.trim().is_empty() {\n return Err((\n StatusCode::BAD_REQUEST,\n- format!(\"item body is empty: {}\", item_path_for_api(&item)),\n+ format!(\"item body is empty: {}\", GardenItemUrl::from_storage_str(&item, room_wire)),\n Some(\"write at least one sentence inside `{ ... }`\".to_string()),\n ));\n }\n@@ -101,7 +106,7 @@ pub fn validate_ingest_document(\n let key = CanonicalItemUrl((*it).clone());\n !defined_in_doc.contains(*it) && !item_exists(&key)\n })\n- .map(|it| item_path_for_api(it))\n+ .map(|it| GardenItemUrl::from_storage_str(it, room_wire).into_inner())\n .collect();\n if !missing.is_empty() {\n return Err((\n@@ -119,7 +124,7 @@ pub fn validate_ingest_document(\n let key = CanonicalItemUrl((*it).clone());\n !defined_in_doc.contains(*it) && !body_exists(&key)\n })\n- .map(|it| item_path_for_api(it))\n+ .map(|it| GardenItemUrl::from_storage_str(it, room_wire).into_inner())\n .collect();\n if !missing_body.is_empty() {\n return Err((\ndiff --git a/server/src/canonical_path.rs b/server/src/canonical_path.rs\nindex 5c0febe883d8b3978a25896ed0d71df8509a8717..8a1998025121838b0867f8c5ddbd28aea41a23d2 100644\n--- a/server/src/canonical_path.rs\n+++ b/server/src/canonical_path.rs\n@@ -1,92 +1,3 @@\n-//! Normalization for thread tags and ontology item URLs (DSL ↔ stored canonical form).\n-//! Not event types — see `events` and `path_types`.\n+//! Re-exports — implementations live in `slug-types` (`paths` module).\n \n-/// Thread / public tag: stored without leading `#`, lowercase.\n-pub fn canonicalize_tag(input: &str) -> String {\n- input.trim().trim_start_matches('#').to_lowercase()\n-}\n-\n-/// Ontology item reference → canonical absolute URL on the slug host.\n-pub fn canonicalize_item(input: &str) -> String {\n- let s = input.trim();\n- if s.is_empty() {\n- return String::new();\n- }\n-\n- if let Some(rest) = s.strip_prefix(\"https://\") {\n- let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n- let host = host.trim().to_lowercase();\n- if tail.is_empty() {\n- return format!(\"https://{}\", host);\n- } else {\n- return format!(\"https://{}/{}\", host, tail);\n- }\n- }\n- if let Some(rest) = s.strip_prefix(\"http://\") {\n- let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n- let host = host.trim().to_lowercase();\n- if tail.is_empty() {\n- return format!(\"http://{}\", host);\n- } else {\n- return format!(\"http://{}/{}\", host, tail);\n- }\n- }\n-\n- let is_tilde = s.starts_with(\"~/\");\n- let rest = s.strip_prefix(\"~/\").or_else(|| s.strip_prefix(\"/\")).unwrap_or(s);\n-\n- let tail = rest\n- .split('/')\n- .filter_map(|seg| {\n- let t = seg.trim();\n- if t.is_empty() {\n- None\n- } else {\n- Some(t.to_lowercase())\n- }\n- })\n- .collect::>()\n- .join(\"/\");\n-\n- if is_tilde {\n- format!(\"https://slug.social/~/{}\", tail)\n- } else if tail.is_empty() {\n- \"https://slug.social\".to_string()\n- } else {\n- format!(\"https://slug.social/{}\", tail)\n- }\n-}\n-\n-pub fn item_path_segments(input: &str) -> Vec {\n- let canonical = canonicalize_item(input);\n- if canonical.is_empty() {\n- return vec![];\n- }\n-\n- if let Some(rest) = canonical.strip_prefix(\"https://\") {\n- let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n- let mut out = vec![format!(\"https://{}\", host)];\n- out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string()));\n- return out;\n- }\n- if let Some(rest) = canonical.strip_prefix(\"http://\") {\n- let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n- let mut out = vec![format!(\"http://{}\", host)];\n- out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string()));\n- return out;\n- }\n-\n- canonical\n- .split('/')\n- .filter(|s| !s.is_empty())\n- .map(|s| s.to_string())\n- .collect()\n-}\n-\n-pub fn item_parent_path(input: &str) -> Option {\n- let segs = item_path_segments(input);\n- if segs.len() <= 1 {\n- return None;\n- }\n- Some(segs[..segs.len() - 1].join(\"/\"))\n-}\n+pub use slug_types::paths::{canonicalize_item, canonicalize_tag, item_parent_path, item_path_segments};\ndiff --git a/server/src/html/forum.rs b/server/src/html/forum.rs\nindex ab7970feca47a4431ddc19dab2c8186180b78413..f789e347dc136f8ffd356f4492f0bd76cea04bf0 100644\n--- a/server/src/html/forum.rs\n+++ b/server/src/html/forum.rs\n@@ -697,7 +697,7 @@ async fn thread_view_inner(\n let offset = q.offset.unwrap_or(0);\n let page_ids: Vec = all_ids.into_iter().skip(offset).take(PAGE_SIZE).collect();\n \n- let (display_ingests, subtitle) = {\n+ let (display_ingests, _subtitle) = {\n let reduced = state.reduced.read().await;\n let ingests = page_ids\n .iter()\ndiff --git a/server/src/path_types.rs b/server/src/path_types.rs\nindex cad58cac7da948f92d6ea2a5587d917ab21d57ea..4c8075bbd488f1b9a5eda9e03ced83f6238c6d5e 100644\n--- a/server/src/path_types.rs\n+++ b/server/src/path_types.rs\n@@ -1,260 +1,3 @@\n-//! Path representation types.\n-//!\n-//! The codebase currently treats item identifiers as strings in a few different\n-//! encodings:\n-//! - user/DSL input like `~/a/b`\n-//! - canonical item URLs like `https://slug.social/~/a/b`\n-//! - relative paths within a rooted tree view (e.g. `llms/openai` under a root)\n-//!\n-//! This module adds lightweight newtypes so code can be explicit about what it\n-//! expects without changing core storage formats.\n-//!\n-//! **Storage vs wire:** [`CanonicalItemUrl`] values are shared across scopes\n-//! (`https://slug.social/~/…`); which [`crate::reducer::ContentState`] they live in\n-//! is determined by scope, not by embedding the room id in the string. For JSON/RPC\n-//! and browser links in a private room, use [`crate::api::helpers::item_path_for_api_in_room`]\n-//! so ontology items become `https://slug.social/r/{short}/{slug}/~/…`.\n+//! Re-exports — implementations live in `slug-types` (`paths` module).\n \n-use std::borrow::Borrow;\n-use std::fmt;\n-\n-use serde::{Deserialize, Serialize};\n-\n-use crate::canonical_path::canonicalize_item;\n-\n-/// Canonical item identifier as produced by `canonical_path::canonicalize_item`.\n-///\n-/// In practice this is usually:\n-/// - `https://slug.social/~/...` for ontology items, or\n-/// - `https://...` / `http://...` for URL items.\n-#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n-pub struct CanonicalItemUrl(pub String);\n-\n-impl CanonicalItemUrl {\n- pub fn parse(input: &str) -> Option {\n- let c = canonicalize_item(input);\n- if c.is_empty() {\n- None\n- } else {\n- Some(Self(c))\n- }\n- }\n-\n- pub fn as_str(&self) -> &str {\n- &self.0\n- }\n-\n- /// Returns the `~/...` tail for ontology items (`https://slug.social/~/...`).\n- pub fn tilde_tail(&self) -> Option<&str> {\n- self.0.strip_prefix(\"https://slug.social/~/\")\n- }\n-\n- /// Returns the final non-empty `/`-separated segment of the path.\n- ///\n- /// `https://slug.social/~/a/b/c` → `\"c\"`\n- /// `https://slug.social/~/a` → `\"a\"`\n- pub fn last_segment(&self) -> &str {\n- self.0\n- .rsplit('/')\n- .find(|s| !s.is_empty())\n- .unwrap_or(self.0.as_str())\n- }\n-\n- /// The ontology root key as stored in `item_children`: `\"https://slug.social/~\"`.\n- /// Use this (not `parse(\"~/\")`) when looking up top-level children.\n- pub fn ontology_root() -> Self {\n- Self(\"https://slug.social/~\".to_string())\n- }\n-\n- /// Returns the parent of this canonical item URL by stripping the last\n- /// path segment, or `None` if there is no parent (already at root).\n- ///\n- /// `https://slug.social/~/a/b/c` → `Some(\"https://slug.social/~/a/b\")`\n- /// `https://slug.social/~/a` → `Some(\"https://slug.social/~\")`\n- /// `https://slug.social/~/` → `None` (tilde root)\n- pub fn parent(&self) -> Option {\n- // tilde_tail() is None for non-ontology URLs and \"\" for the root ~/\n- if self.tilde_tail().map(|t| t.is_empty()).unwrap_or(true) {\n- return None;\n- }\n- // Strip everything from the last '/' onwards.\n- let last_slash = self.0.rfind('/')?;\n- let parent_str = &self.0[..last_slash];\n- if parent_str.is_empty() {\n- None\n- } else {\n- Some(Self(parent_str.to_string()))\n- }\n- }\n-\n- /// Segments of an ontology path suitable for breadcrumb rendering.\n- /// Strips the `https://slug.social` prefix and returns the `~/…` parts.\n- ///\n- /// `https://slug.social/~/a/b` → `[\"~\", \"a\", \"b\"]`\n- /// `https://slug.social/~/` → `[\"~\"]`\n- pub fn tilde_segments(&self) -> Vec<&str> {\n- match self.tilde_tail() {\n- Some(tail) if !tail.is_empty() => {\n- std::iter::once(\"~\")\n- .chain(tail.split('/').filter(|s| !s.is_empty()))\n- .collect()\n- }\n- Some(_) => vec![\"~\"],\n- None => vec![],\n- }\n- }\n-}\n-\n-impl fmt::Display for CanonicalItemUrl {\n- fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n- self.0.fmt(f)\n- }\n-}\n-\n-/// Allow `HashMap` to be searched by `&str`.\n-impl Borrow for CanonicalItemUrl {\n- fn borrow(&self) -> &str {\n- &self.0\n- }\n-}\n-\n-impl PartialEq for CanonicalItemUrl {\n- fn eq(&self, other: &str) -> bool {\n- self.0 == other\n- }\n-}\n-\n-impl PartialEq<&str> for CanonicalItemUrl {\n- fn eq(&self, other: &&str) -> bool {\n- self.0 == *other\n- }\n-}\n-\n-impl PartialEq for CanonicalItemUrl {\n- fn eq(&self, other: &String) -> bool {\n- &self.0 == other\n- }\n-}\n-\n-/// A `~/...` input path (as used in the DSL and UX).\n-///\n-/// This is not canonicalized; it is a presentation/input form.\n-#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n-pub struct TildePath(pub String);\n-\n-impl TildePath {\n- pub fn new(input: &str) -> Option {\n- let s = input.trim();\n- if s.starts_with(\"~/\") && s.len() > 2 {\n- Some(Self(s.to_string()))\n- } else if s == \"~/\" {\n- Some(Self(\"~/\".to_string()))\n- } else {\n- None\n- }\n- }\n-\n- pub fn as_str(&self) -> &str {\n- &self.0\n- }\n-\n- pub fn canonicalize(&self) -> Option {\n- CanonicalItemUrl::parse(&self.0)\n- }\n-}\n-\n-impl fmt::Display for TildePath {\n- fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n- self.0.fmt(f)\n- }\n-}\n-\n-/// A path relative to a chosen root in a tree UI.\n-///\n-/// This is intended for compact state encodings (blobs). It must be joined to a\n-/// root `CanonicalItemUrl` (typically an ontology root) to become a full item.\n-#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n-pub struct RelativePath(pub String);\n-\n-impl RelativePath {\n- pub fn new(input: &str) -> Option {\n- let s = input.trim().trim_matches('/');\n- if s.is_empty() {\n- Some(Self(String::new()))\n- } else {\n- // Keep this permissive: the DSL parser is the main gatekeeper.\n- Some(Self(s.to_string()))\n- }\n- }\n-\n- pub fn as_str(&self) -> &str {\n- &self.0\n- }\n-\n- /// Join this relative path under a canonical ontology root\n- /// (`https://slug.social/~/...`) to form a canonical item URL.\n- pub fn join_under_ontology_root(&self, root: &CanonicalItemUrl) -> Option {\n- let base = root.tilde_tail()?;\n- // base is the tail after https://slug.social/~/, e.g. \"models\" or \"models/llms\"\n- let joined = if base.is_empty() {\n- if self.0.is_empty() {\n- \"~/\".to_string()\n- } else {\n- format!(\"~/{}\", self.0)\n- }\n- } else if self.0.is_empty() {\n- format!(\"~/{}\", base)\n- } else {\n- format!(\"~/{}/{}\", base.trim_end_matches('/'), self.0)\n- };\n- CanonicalItemUrl::parse(&joined)\n- }\n-}\n-\n-impl fmt::Display for RelativePath {\n- fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n- self.0.fmt(f)\n- }\n-}\n-\n-\n-#[cfg(test)]\n-mod tests {\n- use super::*;\n-\n- #[test]\n- fn canonical_parent_deep() {\n- let c = CanonicalItemUrl::parse(\"~/a/b/c\").unwrap();\n- assert_eq!(c.parent().unwrap().as_str(), \"https://slug.social/~/a/b\");\n- }\n-\n- #[test]\n- fn canonical_parent_one_level() {\n- let c = CanonicalItemUrl::parse(\"~/a\").unwrap();\n- assert_eq!(c.parent().unwrap().as_str(), \"https://slug.social/~\");\n- }\n-\n- #[test]\n- fn canonical_parent_root_is_none() {\n- let root = CanonicalItemUrl::parse(\"~/\").unwrap();\n- assert!(root.parent().is_none());\n- }\n-\n- #[test]\n- fn tilde_segments_deep() {\n- let c = CanonicalItemUrl::parse(\"~/a/b\").unwrap();\n- assert_eq!(c.tilde_segments(), vec![\"~\", \"a\", \"b\"]);\n- }\n-\n- #[test]\n- fn tilde_segments_root() {\n- let c = CanonicalItemUrl::parse(\"~/\").unwrap();\n- assert_eq!(c.tilde_segments(), vec![\"~\"]);\n- }\n-\n- #[test]\n- fn tilde_segments_non_ontology_is_empty() {\n- let c = CanonicalItemUrl::parse(\"https://example.com/foo\").unwrap();\n- assert_eq!(c.tilde_segments(), Vec::<&str>::new());\n- }\n-}\n+pub use slug_types::paths::{CanonicalItemUrl, RelativePath, TildePath};\ndiff --git a/types/src/lib.rs b/types/src/lib.rs\nindex c1cde3b783d03b02783385b5f07659fb112aae3e..5fc867bf2af84c2ca63fa1cdd03413110ad784a3 100644\n--- a/types/src/lib.rs\n+++ b/types/src/lib.rs\n@@ -1,7 +1,13 @@\n use serde::{Deserialize, Serialize};\n \n+pub mod paths;\n pub mod timeago;\n \n+pub use paths::{\n+ canonicalize_item, canonicalize_tag, item_parent_path, item_path_segments, CanonicalItemUrl,\n+ ForumThreadUrl, GardenItemUrl, RelativePath, TildeOntologyPath, TildePath,\n+};\n+\n #[derive(Debug, Serialize, Deserialize)]\n pub struct ApiError {\n pub ok: bool,\n@@ -12,7 +18,7 @@ pub struct ApiError {\n \n #[derive(Debug, Clone, Serialize, Deserialize)]\n pub struct RankRow {\n- pub item: String,\n+ pub item: GardenItemUrl,\n pub score: f64,\n /// Normalized score as a percentage of the top item (0–100). Present when ?percent=true.\n #[serde(skip_serializing_if = \"Option::is_none\")]\n@@ -43,7 +49,7 @@ pub struct RankComponent {\n #[derive(Debug, Serialize, Deserialize)]\n pub struct RankResponse {\n pub components: Vec,\n- pub unranked_items: Vec,\n+ pub unranked_items: Vec,\n }\n \n /// Graph connectivity stats for a scope, returned with pair suggestions.\n@@ -63,8 +69,8 @@ pub struct ConnectivityStats {\n \n #[derive(Debug, Serialize, Deserialize)]\n pub struct PairResponse {\n- pub left: String,\n- pub right: String,\n+ pub left: GardenItemUrl,\n+ pub right: GardenItemUrl,\n pub left_body: Option,\n pub right_body: Option,\n /// Thread tags that discuss either item (connective tissue to forum).\n@@ -79,7 +85,7 @@ pub struct PairResponse {\n pub struct NextMoves {\n pub pair: String,\n pub rank: String,\n- pub web: String,\n+ pub web: ForumThreadUrl,\n }\n \n #[derive(Debug, Serialize, Deserialize)]\n@@ -90,14 +96,14 @@ pub struct PathsResponse {\n /// Leaf items only (no children). For search / \"full path list\" — does not scale, works for now.\n #[derive(Debug, Serialize, Deserialize)]\n pub struct LeavesResponse {\n- pub paths: Vec,\n+ pub paths: Vec,\n }\n \n #[derive(Debug, Serialize, Deserialize)]\n pub struct PathSummary {\n- pub path: String,\n+ pub path: TildeOntologyPath,\n pub children: usize,\n- pub web: String,\n+ pub web: GardenItemUrl,\n }\n \n #[derive(Debug, Clone, Serialize, Deserialize)]\n@@ -109,7 +115,7 @@ pub struct ThreadsResponse {\n pub struct ThreadSummary {\n pub thread: String,\n pub last_activity_ts: i64,\n- pub web: String,\n+ pub web: ForumThreadUrl,\n }\n \n #[derive(Debug, Serialize, Deserialize)]\n@@ -178,7 +184,7 @@ pub struct IngestRow {\n \n #[derive(Debug, Serialize, Deserialize)]\n pub struct ItemResponse {\n- pub item: String,\n+ pub item: GardenItemUrl,\n pub body: Option,\n /// True when the body was truncated due to size. Fetch with `?full=true` for the complete body.\n #[serde(default, skip_serializing_if = \"std::ops::Not::not\")]\n@@ -201,15 +207,15 @@ pub struct RecentVotesResponse {\n /// Vote history for one item (matchup: wins/losses + thread per vote).\n #[derive(Debug, Serialize, Deserialize)]\n pub struct MatchupResponse {\n- pub item: String,\n+ pub item: GardenItemUrl,\n pub votes: Vec,\n }\n \n #[derive(Debug, Clone, Serialize, Deserialize)]\n pub struct VoteRow {\n pub ts: i64,\n- pub a: String,\n- pub b: String,\n+ pub a: GardenItemUrl,\n+ pub b: GardenItemUrl,\n pub ratio: String,\n /// Principal username when present (stored form, no `@`).\n pub actor: Option,\n@@ -510,7 +516,7 @@ pub struct RankPosition {\n /// How one item's rank changed after a vote.\n #[derive(Debug, Clone, Serialize, Deserialize)]\n pub struct RankChange {\n- pub item: String,\n+ pub item: GardenItemUrl,\n /// Position before the vote. None = was unranked (no voted connections in this scope).\n pub before: Option,\n /// Position after the vote. None = became unranked (e.g. component split, unlikely).\n@@ -544,7 +550,7 @@ pub struct CheckScopeRanking {\n /// Parent scope path (e.g. \"/models\" or \"/\" for root).\n pub parent: String,\n pub components: Vec,\n- pub unranked_items: Vec,\n+ pub unranked_items: Vec,\n }\n \n #[derive(Debug, Serialize, Deserialize)]\n@@ -567,7 +573,7 @@ pub struct SearchResponse {\n \n #[derive(Debug, Serialize, Deserialize)]\n pub struct SearchItemHit {\n- pub path: String,\n+ pub path: GardenItemUrl,\n #[serde(skip_serializing_if = \"Option::is_none\")]\n pub body: Option,\n }\n@@ -614,7 +620,7 @@ pub struct RankHistoryRow {\n \n #[derive(Debug, Serialize, Deserialize)]\n pub struct RankHistoryResponse {\n- pub item: String,\n+ pub item: GardenItemUrl,\n pub history: Vec,\n }\n \ndiff --git a/types/src/paths.rs b/types/src/paths.rs\nnew file mode 100644\nindex 0000000000000000000000000000000000000000..2950a7502255927583fbacdfd2adb700f0b0c221\n--- /dev/null\n+++ b/types/src/paths.rs\n@@ -0,0 +1,498 @@\n+//! Canonical paths, storage ids, and JSON href newtypes. All normalization and\n+//! room-aware URL rules for items live here.\n+\n+use std::borrow::Borrow;\n+use std::fmt;\n+\n+use serde::{Deserialize, Serialize};\n+\n+// ---------------------------------------------------------------------------\n+// Normalization (moved from server `canonical_path`)\n+// ---------------------------------------------------------------------------\n+\n+/// Thread / public tag: stored without leading `#`, lowercase.\n+pub fn canonicalize_tag(input: &str) -> String {\n+ input.trim().trim_start_matches('#').to_lowercase()\n+}\n+\n+/// Ontology item reference → canonical absolute URL on the slug host.\n+pub fn canonicalize_item(input: &str) -> String {\n+ let s = input.trim();\n+ if s.is_empty() {\n+ return String::new();\n+ }\n+\n+ if let Some(rest) = s.strip_prefix(\"https://\") {\n+ let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n+ let host = host.trim().to_lowercase();\n+ if tail.is_empty() {\n+ return format!(\"https://{}\", host);\n+ } else {\n+ return format!(\"https://{}/{}\", host, tail);\n+ }\n+ }\n+ if let Some(rest) = s.strip_prefix(\"http://\") {\n+ let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n+ let host = host.trim().to_lowercase();\n+ if tail.is_empty() {\n+ return format!(\"http://{}\", host);\n+ } else {\n+ return format!(\"http://{}/{}\", host, tail);\n+ }\n+ }\n+\n+ let is_tilde = s.starts_with(\"~/\");\n+ let rest = s.strip_prefix(\"~/\").or_else(|| s.strip_prefix(\"/\")).unwrap_or(s);\n+\n+ let tail = rest\n+ .split('/')\n+ .filter_map(|seg| {\n+ let t = seg.trim();\n+ if t.is_empty() {\n+ None\n+ } else {\n+ Some(t.to_lowercase())\n+ }\n+ })\n+ .collect::>()\n+ .join(\"/\");\n+\n+ if is_tilde {\n+ format!(\"https://slug.social/~/{}\", tail)\n+ } else if tail.is_empty() {\n+ \"https://slug.social\".to_string()\n+ } else {\n+ format!(\"https://slug.social/{}\", tail)\n+ }\n+}\n+\n+pub fn item_path_segments(input: &str) -> Vec {\n+ let canonical = canonicalize_item(input);\n+ if canonical.is_empty() {\n+ return vec![];\n+ }\n+\n+ if let Some(rest) = canonical.strip_prefix(\"https://\") {\n+ let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n+ let mut out = vec![format!(\"https://{}\", host)];\n+ out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string()));\n+ return out;\n+ }\n+ if let Some(rest) = canonical.strip_prefix(\"http://\") {\n+ let (host, tail) = rest.split_once('/').map_or((rest, \"\"), |(h, t)| (h, t));\n+ let mut out = vec![format!(\"http://{}\", host)];\n+ out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string()));\n+ return out;\n+ }\n+\n+ canonical\n+ .split('/')\n+ .filter(|s| !s.is_empty())\n+ .map(|s| s.to_string())\n+ .collect()\n+}\n+\n+pub fn item_parent_path(input: &str) -> Option {\n+ let segs = item_path_segments(input);\n+ if segs.len() <= 1 {\n+ return None;\n+ }\n+ Some(segs[..segs.len() - 1].join(\"/\"))\n+}\n+\n+// ---------------------------------------------------------------------------\n+// Storage + input path newtypes\n+// ---------------------------------------------------------------------------\n+\n+/// Canonical item identifier as produced by [`canonicalize_item`].\n+///\n+/// Shared across all scopes; room is not embedded. Usually\n+/// `https://slug.social/~/…` or an external `http(s)://…` URL item.\n+#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n+pub struct CanonicalItemUrl(pub String);\n+\n+impl CanonicalItemUrl {\n+ pub fn parse(input: &str) -> Option {\n+ let c = canonicalize_item(input);\n+ if c.is_empty() {\n+ None\n+ } else {\n+ Some(Self(c))\n+ }\n+ }\n+\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+\n+ pub fn tilde_tail(&self) -> Option<&str> {\n+ self.0.strip_prefix(\"https://slug.social/~/\")\n+ }\n+\n+ pub fn last_segment(&self) -> &str {\n+ self.0\n+ .rsplit('/')\n+ .find(|s| !s.is_empty())\n+ .unwrap_or(self.0.as_str())\n+ }\n+\n+ pub fn ontology_root() -> Self {\n+ Self(\"https://slug.social/~\".to_string())\n+ }\n+\n+ pub fn parent(&self) -> Option {\n+ if self.tilde_tail().map(|t| t.is_empty()).unwrap_or(true) {\n+ return None;\n+ }\n+ let last_slash = self.0.rfind('/')?;\n+ let parent_str = &self.0[..last_slash];\n+ if parent_str.is_empty() {\n+ None\n+ } else {\n+ Some(Self(parent_str.to_string()))\n+ }\n+ }\n+\n+ pub fn tilde_segments(&self) -> Vec<&str> {\n+ match self.tilde_tail() {\n+ Some(tail) if !tail.is_empty() => {\n+ std::iter::once(\"~\")\n+ .chain(tail.split('/').filter(|s| !s.is_empty()))\n+ .collect()\n+ }\n+ Some(_) => vec![\"~\"],\n+ None => vec![],\n+ }\n+ }\n+\n+ /// `~/…` list label for ontology items (paths index, CLI).\n+ pub fn tilde_list_label(&self) -> TildeOntologyPath {\n+ TildeOntologyPath::from_stored(self)\n+ }\n+\n+ /// Absolute href for JSON/RPC and browsers for this stored id in `room`.\n+ pub fn json_href(&self, room_wire: &str) -> GardenItemUrl {\n+ GardenItemUrl::from_stored(self, room_wire)\n+ }\n+}\n+\n+impl fmt::Display for CanonicalItemUrl {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+impl Borrow for CanonicalItemUrl {\n+ fn borrow(&self) -> &str {\n+ &self.0\n+ }\n+}\n+\n+impl PartialEq for CanonicalItemUrl {\n+ fn eq(&self, other: &str) -> bool {\n+ self.0 == other\n+ }\n+}\n+\n+impl PartialEq<&str> for CanonicalItemUrl {\n+ fn eq(&self, other: &&str) -> bool {\n+ self.0 == *other\n+ }\n+}\n+\n+impl PartialEq for CanonicalItemUrl {\n+ fn eq(&self, other: &String) -> bool {\n+ &self.0 == other\n+ }\n+}\n+\n+#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n+pub struct TildePath(pub String);\n+\n+impl TildePath {\n+ pub fn new(input: &str) -> Option {\n+ let s = input.trim();\n+ if s.starts_with(\"~/\") && s.len() > 2 {\n+ Some(Self(s.to_string()))\n+ } else if s == \"~/\" {\n+ Some(Self(\"~/\".to_string()))\n+ } else {\n+ None\n+ }\n+ }\n+\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+\n+ pub fn canonicalize(&self) -> Option {\n+ CanonicalItemUrl::parse(&self.0)\n+ }\n+}\n+\n+impl fmt::Display for TildePath {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n+pub struct RelativePath(pub String);\n+\n+impl RelativePath {\n+ pub fn new(input: &str) -> Option {\n+ let s = input.trim().trim_matches('/');\n+ if s.is_empty() {\n+ Some(Self(String::new()))\n+ } else {\n+ Some(Self(s.to_string()))\n+ }\n+ }\n+\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+\n+ pub fn join_under_ontology_root(&self, root: &CanonicalItemUrl) -> Option {\n+ let base = root.tilde_tail()?;\n+ let joined = if base.is_empty() {\n+ if self.0.is_empty() {\n+ \"~/\".to_string()\n+ } else {\n+ format!(\"~/{}\", self.0)\n+ }\n+ } else if self.0.is_empty() {\n+ format!(\"~/{}\", base)\n+ } else {\n+ format!(\"~/{}/{}\", base.trim_end_matches('/'), self.0)\n+ };\n+ CanonicalItemUrl::parse(&joined)\n+ }\n+}\n+\n+impl fmt::Display for RelativePath {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+// ---------------------------------------------------------------------------\n+// Wire / JSON: correct-by-construction hrefs\n+// ---------------------------------------------------------------------------\n+\n+fn api_path_or_url(item: &str) -> String {\n+ if item.starts_with(\"http://\") || item.starts_with(\"https://\") {\n+ item.to_string()\n+ } else {\n+ format!(\"/{}\", item)\n+ }\n+}\n+\n+/// Ontology item as serialized in JSON (absolute URL or `/`-prefixed path).\n+#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n+#[serde(transparent)]\n+pub struct GardenItemUrl(pub String);\n+\n+impl GardenItemUrl {\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+\n+ pub fn into_inner(self) -> String {\n+ self.0\n+ }\n+\n+ /// Stored canonical id + RPC `room` field (`\"public\"` or `\"short/slug\"`).\n+ pub fn from_stored(stored: &CanonicalItemUrl, room_wire: &str) -> Self {\n+ Self(garden_href_string(stored.as_str(), room_wire))\n+ }\n+\n+ /// Like [`Self::from_stored`] but accepts a string that may already be canonical.\n+ pub fn from_storage_str(stored: &str, room_wire: &str) -> Self {\n+ Self(garden_href_string(stored, room_wire))\n+ }\n+}\n+\n+impl fmt::Display for GardenItemUrl {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+fn garden_href_string(item: &str, room_wire: &str) -> String {\n+ let room = room_wire.trim();\n+ if room.is_empty() || room == \"public\" {\n+ return api_path_or_url(item);\n+ }\n+ let Some((short, slug)) = room.split_once('/') else {\n+ return api_path_or_url(item);\n+ };\n+ if short.is_empty() || slug.is_empty() {\n+ return api_path_or_url(item);\n+ }\n+ let Some(c) = CanonicalItemUrl::parse(item) else {\n+ return api_path_or_url(item);\n+ };\n+ let root = CanonicalItemUrl::ontology_root();\n+ let item_norm = c.as_str().trim_end_matches('/');\n+ let root_norm = root.as_str().trim_end_matches('/');\n+ if let Some(tail) = c.tilde_tail() {\n+ return if tail.is_empty() {\n+ format!(\"https://slug.social/r/{short}/{slug}/~\")\n+ } else {\n+ format!(\"https://slug.social/r/{short}/{slug}/~/{}\", tail)\n+ };\n+ }\n+ if item_norm == root_norm {\n+ return format!(\"https://slug.social/r/{short}/{slug}/~\");\n+ }\n+ api_path_or_url(item)\n+}\n+\n+/// Forum thread URL for JSON (`/t/…` or `/r/…/t/…` on slug.social).\n+#[derive(Debug, Clone, PartialEq, Eq, PartialOrd, Ord, Hash, Serialize, Deserialize)]\n+#[serde(transparent)]\n+pub struct ForumThreadUrl(pub String);\n+\n+impl ForumThreadUrl {\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+\n+ pub fn into_inner(self) -> String {\n+ self.0\n+ }\n+\n+ pub fn from_room_tag(room_wire: &str, thread_tag: &str) -> Self {\n+ let room = room_wire.trim();\n+ let tag = thread_tag.trim().trim_start_matches('#');\n+ Self(if room.is_empty() || room == \"public\" {\n+ format!(\"https://slug.social/t/{tag}\")\n+ } else if let Some((short, slug)) = room.split_once('/') {\n+ if short.is_empty() || slug.is_empty() {\n+ format!(\"https://slug.social/t/{tag}\")\n+ } else {\n+ format!(\"https://slug.social/r/{short}/{slug}/t/{tag}\")\n+ }\n+ } else {\n+ format!(\"https://slug.social/t/{tag}\")\n+ })\n+ }\n+}\n+\n+impl fmt::Display for ForumThreadUrl {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+/// `~/a/b` style path for list UIs (paths index `path` field).\n+#[derive(Debug, Clone, PartialEq, Eq, Hash, Serialize, Deserialize)]\n+#[serde(transparent)]\n+pub struct TildeOntologyPath(pub String);\n+\n+impl TildeOntologyPath {\n+ pub fn from_stored(c: &CanonicalItemUrl) -> Self {\n+ let s = match c.tilde_tail() {\n+ Some(tail) if !tail.is_empty() => format!(\"~/{}\", tail),\n+ Some(_) => \"~/\".to_string(),\n+ None => c.to_string(),\n+ };\n+ Self(s)\n+ }\n+\n+ pub fn as_str(&self) -> &str {\n+ &self.0\n+ }\n+}\n+\n+impl fmt::Display for TildeOntologyPath {\n+ fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {\n+ self.0.fmt(f)\n+ }\n+}\n+\n+#[cfg(test)]\n+mod tests {\n+ use super::*;\n+\n+ #[test]\n+ fn canonical_parent_deep() {\n+ let c = CanonicalItemUrl::parse(\"~/a/b/c\").unwrap();\n+ assert_eq!(c.parent().unwrap().as_str(), \"https://slug.social/~/a/b\");\n+ }\n+\n+ #[test]\n+ fn canonical_parent_one_level() {\n+ let c = CanonicalItemUrl::parse(\"~/a\").unwrap();\n+ assert_eq!(c.parent().unwrap().as_str(), \"https://slug.social/~\");\n+ }\n+\n+ #[test]\n+ fn canonical_parent_root_is_none() {\n+ let root = CanonicalItemUrl::parse(\"~/\").unwrap();\n+ assert!(root.parent().is_none());\n+ }\n+\n+ #[test]\n+ fn tilde_segments_deep() {\n+ let c = CanonicalItemUrl::parse(\"~/a/b\").unwrap();\n+ assert_eq!(c.tilde_segments(), vec![\"~\", \"a\", \"b\"]);\n+ }\n+\n+ #[test]\n+ fn tilde_segments_root() {\n+ let c = CanonicalItemUrl::parse(\"~/\").unwrap();\n+ assert_eq!(c.tilde_segments(), vec![\"~\"]);\n+ }\n+\n+ #[test]\n+ fn tilde_segments_non_ontology_is_empty() {\n+ let c = CanonicalItemUrl::parse(\"https://example.com/foo\").unwrap();\n+ assert_eq!(c.tilde_segments(), Vec::<&str>::new());\n+ }\n+\n+ #[test]\n+ fn garden_public_passthrough_https() {\n+ let u = \"https://slug.social/~/a/b\";\n+ assert_eq!(GardenItemUrl::from_storage_str(u, \"public\").as_str(), u);\n+ }\n+\n+ #[test]\n+ fn garden_private_room_prefixes_ontology() {\n+ assert_eq!(\n+ GardenItemUrl::from_storage_str(\"https://slug.social/~/topic/x\", \"9ab12cd/my-room\").as_str(),\n+ \"https://slug.social/r/9ab12cd/my-room/~/topic/x\"\n+ );\n+ }\n+\n+ #[test]\n+ fn garden_private_room_ontology_root() {\n+ assert_eq!(\n+ GardenItemUrl::from_storage_str(\"https://slug.social/~\", \"9ab12cd/my-room\").as_str(),\n+ \"https://slug.social/r/9ab12cd/my-room/~\"\n+ );\n+ assert_eq!(\n+ GardenItemUrl::from_storage_str(\"https://slug.social/~/\", \"9ab12cd/my-room\").as_str(),\n+ \"https://slug.social/r/9ab12cd/my-room/~\"\n+ );\n+ }\n+\n+ #[test]\n+ fn garden_external_url_untouched_in_private_room() {\n+ let u = \"https://example.com/z\";\n+ assert_eq!(GardenItemUrl::from_storage_str(u, \"9ab12cd/my-room\").as_str(), u);\n+ }\n+\n+ #[test]\n+ fn forum_web_public_vs_room() {\n+ assert_eq!(\n+ ForumThreadUrl::from_room_tag(\"public\", \"debate\").as_str(),\n+ \"https://slug.social/t/debate\"\n+ );\n+ assert_eq!(\n+ ForumThreadUrl::from_room_tag(\"9ab12cd/my-room\", \"#debate\").as_str(),\n+ \"https://slug.social/r/9ab12cd/my-room/t/debate\"\n+ );\n+ }\n+}\n\n\nSide B — contributor: tommy-mor\nSide B — commit message:\n[7caef802] room ui wired up again\n\nSide B — unified diff (full patch):\ndiff --git a/Cargo.lock b/Cargo.lock\nindex e31485f28717993a13e1c4caf7be15b43a97573e..8be6ff8677700ce0a56d4a53b221e25c2bb70507 100644\n--- a/Cargo.lock\n+++ b/Cargo.lock\n@@ -158,6 +158,7 @@ dependencies = [\n \"axum\",\n \"axum-core\",\n \"bytes\",\n+ \"cookie\",\n \"fastrand\",\n \"futures-util\",\n \"http\",\n@@ -300,6 +301,17 @@ version = \"1.0.4\"\n source = \"registry+https://github.com/rust-lang/crates.io-index\"\n checksum = \"b05b61dc5112cbb17e4b6cd61790d9845d13888356391624cbe7e41efeac1e75\"\n \n+[[package]]\n+name = \"cookie\"\n+version = \"0.18.1\"\n+source = \"registry+https://github.com/rust-lang/crates.io-index\"\n+checksum = \"4ddef33a339a91ea89fb53151bd0a4689cfce27055c291dfa69945475d22c747\"\n+dependencies = [\n+ \"percent-encoding\",\n+ \"time\",\n+ \"version_check\",\n+]\n+\n [[package]]\n name = \"core-foundation\"\n version = \"0.9.4\"\ndiff --git a/plan2.md b/plan2.md\nnew file mode 100644\nindex 0000000000000000000000000000000000000000..1587cbe558eb0a98fbce78566bf5f93b18100e54\n--- /dev/null\n+++ b/plan2.md\n@@ -0,0 +1,190 @@\n+This is a phenomenal synthesis. You stripped away the exact parts of `evaleval` that don't scale to a multi-tenant web application (string-splicing `eval` and in-memory nonce OCAP tracking) and kept the parts that make development lightning fast (embedded declarative payloads, single endpoint routing, and Javascript AST responses). \n+\n+You are entirely right about the **AST substitution in Rust**. Walking a `serde_json::Value` tree to find `{\"$form\": \"field_name\"}` and swapping the node for a String isn't a hack—in Rust, it’s just a completely standard recursive enum visitor. \n+\n+Let’s lock in this exact architecture. It is cohesive, secure, and incredibly ergonomic.\n+\n+Here is what the code actually looks like to execute this vision.\n+\n+---\n+\n+### 1. The Safe AST Substitution\n+\n+This is the exact function that runs in the Web handler before giving the payload to the RPC engine. Because it operates on the JSON AST *before* deserialization, it's 100% immune to injection.\n+\n+```rust\n+use serde_json::Value;\n+use std::collections::HashMap;\n+\n+/// Recursively walk the JSON AST and replace {\"$form\": \"key\"} with the actual form string.\n+fn substitute_form_vars(val: &mut Value, form_data: &HashMap) {\n+ match val {\n+ Value::Object(map) => {\n+ // Is this the magic placeholder node? {\"$form\": \"input_name\"}\n+ if map.len() == 1 && map.contains_key(\"$form\") {\n+ if let Some(field_name) = map.get(\"$form\").and_then(|v| v.as_str()) {\n+ let submitted_text = form_data.get(field_name).map(|s| s.as_str()).unwrap_or(\"\");\n+ *val = Value::String(submitted_text.to_string());\n+ return;\n+ }\n+ }\n+ // Otherwise, keep walking the object\n+ for v in map.values_mut() {\n+ substitute_form_vars(v, form_data);\n+ }\n+ }\n+ Value::Array(arr) => {\n+ // Walk arrays\n+ for v in arr.iter_mut() {\n+ substitute_form_vars(v, form_data);\n+ }\n+ }\n+ _ => {} // Primitives stay as is\n+ }\n+}\n+```\n+**Why this rules:** You can write a single, hidden HTML input: \n+``\n+When the form submits, the backend safely turns it into standard RPC input.\n+\n+---\n+\n+### 2. The Unified Core RPC Layer\n+\n+You keep exactly one execution layer that strictly enforces your domain constraints (ACLs). Whether the command originated from a CLI script or a web form, they all hit this choke point:\n+\n+```rust\n+// Core execute function, decoupled from HTTP\n+pub async fn execute_rpc(\n+ state: &ReducerState, \n+ principal: &Principal, \n+ command: RpcCommand\n+) -> Result {\n+ match command {\n+ RpcCommand::Ingest { space, text } => {\n+ // ACLs are checked RIGHT HERE, universally.\n+ if !state.user_has_cap(&space, principal, ThreadCapability::Post) {\n+ return Err(ApiError::Forbidden(\"No post access in this space\".to_string()));\n+ }\n+ // Do the write, apply events...\n+ Ok(RpcResponse::IngestOk { ... })\n+ }\n+ // ...\n+ }\n+}\n+```\n+\n+---\n+\n+### 3. The `DomPatch` Builder Pattern\n+\n+You prefer the Builder pattern over a macro for the response mapping. I agree—builders are far easier for your IDE to autocomplete, and easier to compose dynamically (e.g., iterating over a list of items to append).\n+\n+```rust\n+pub struct DomPatch {\n+ js: String,\n+}\n+\n+impl DomPatch {\n+ pub fn new() -> Self {\n+ Self { js: String::new() }\n+ }\n+\n+ /// Morphs an element using Idiomorph\n+ pub fn morph(mut self, selector: &str, html: &str) -> Self {\n+ let safe_html = serde_json::to_string(html).expect(\"string escaping failed\");\n+ self.js.push_str(&format!(\n+ \"Idiomorph.morph(document.querySelector('{}'), {}, {{morphStyle: 'innerHTML'}});\\n\", \n+ selector, safe_html\n+ ));\n+ self\n+ }\n+\n+ /// Appends raw HTML to an element\n+ pub fn append(mut self, selector: &str, html: &str) -> Self {\n+ let safe_html = serde_json::to_string(html).unwrap();\n+ self.js.push_str(&format!(\n+ \"document.querySelector('{}')?.insertAdjacentHTML('beforeend', {});\\n\", \n+ selector, safe_html\n+ ));\n+ self\n+ }\n+\n+ /// Executes raw javascript\n+ pub fn eval(mut self, code: &str) -> Self {\n+ self.js.push_str(code);\n+ self.js.push('\\n');\n+ self\n+ }\n+\n+ /// Consumes the builder into an HTTP Response with the right content-type\n+ pub fn into_response(self) -> impl axum::response::IntoResponse {\n+ (\n+ axum::http::StatusCode::OK, \n+ [(axum::http::header::CONTENT_TYPE, \"text/javascript\")], \n+ self.js\n+ )\n+ }\n+}\n+```\n+\n+---\n+\n+### 4. The Single Web Handler (`POST /ui/action`)\n+\n+With the pipeline defined, you only ever have to write **one** `POST` handler for the entire Web UI.\n+\n+```rust\n+pub async fn handle_web_action(\n+ State(state): State,\n+ headers: HeaderMap,\n+ Form(form_data): Form>, // Captures everything dynamically\n+) -> impl IntoResponse {\n+ // 1. Authenticate using Bearer / Cookie exactly like the CLI\n+ let principal = match extract_web_session(&headers, &state) {\n+ Ok(p) => p,\n+ Err(_) => return DomPatch::new().eval(\"window.location = '/auth/login';\").into_response(),\n+ };\n+\n+ // 2. Decode the Base64 JSON\n+ let b64 = form_data.get(\"__rpc__\").expect(\"Missing RPC payload in form\");\n+ let decoded = base64::decode(b64).expect(\"Bad b64\");\n+ let mut json_ast: Value = serde_json::from_slice(&decoded).expect(\"Bad JSON\");\n+\n+ // 3. Do AST Substitution!\n+ substitute_form_vars(&mut json_ast, &form_data);\n+\n+ // 4. Parse it strongly into the RPC enum\n+ let command: RpcCommand = serde_json::from_value(json_ast).expect(\"Invalid RpcCommand\");\n+\n+ // 5. Pass it to the core execute function (authz + mutation happens here)\n+ match execute_rpc(&state.reduced.read().await, &principal, command).await {\n+ Ok(RpcResponse::IngestOk { new_ranks }) => {\n+ // Translate the RpcResponse to UI JS snippets\n+ DomPatch::new()\n+ .morph(\"#rank-container\", &render_ranking(&new_ranks))\n+ .eval(\"document.getElementById('ingest-form').reset();\")\n+ .into_response()\n+ }\n+ Ok(_) => DomPatch::new().eval(\"console.log('Action complete');\").into_response(),\n+ Err(e) => {\n+ // Reconcile errors\n+ DomPatch::new()\n+ .morph(\"#error-banner\", &format!(\"
{}
\", e.message()))\n+ .into_response()\n+ }\n+ }\n+}\n+```\n+\n+### The Verdict on the Grand Architecture\n+\n+By combining:\n+1. The **Domain-Driven Asymmetry** (Spaces contain Gardens & Threads)\n+2. The **Core RPC Logic** (1 executor, `Vec`, strict ACL checks)\n+3. The **Single Web Form Controller** (b64 embedded, `substitute_form_vars()`)\n+4. The **Javascript DomPatch Builder**\n+\n+You have constructed an application architecture that gives you absolute security and data integrity for your CLI AI Agents, while keeping the absolute peak hackability, form simplicity, and lightning-fast JS UI diffing of your `evaleval` Python framework. \n+\n+I'm sold. It is clean, it is uniquely fitted to the mechanics of Rust (`serde`, `enums`), and it solves the URL routing fatigue problem beautifully. This is the exact way to build `slug.social` v2.\n\\ No newline at end of file\ndiff --git a/server/Cargo.toml b/server/Cargo.toml\nindex d527f86532c2856e29f9c6265e54c7235fdf0a8c..18c45777d662b71dc309e1daa4ddb2944da9759d 100644\n--- a/server/Cargo.toml\n+++ b/server/Cargo.toml\n@@ -6,7 +6,7 @@ license = \"MIT\"\n \n [dependencies]\n axum = { version = \"0.7\", features = [\"macros\"] }\n-axum-extra = { version = \"0.9\", features = [\"query\"] }\n+axum-extra = { version = \"0.9\", features = [\"query\", \"cookie\"] }\n bytes = \"1.11.1\" # pin: RUSTSEC-2026-0007\n tokio = { version = \"1\", features = [\"rt-multi-thread\", \"macros\", \"signal\", \"fs\", \"io-util\"] }\n tokio-stream = { version = \"0.1\", features = [\"sync\"] }\ndiff --git a/server/src/api/auth.rs b/server/src/api/auth.rs\nindex b45ba39419c84af8bf2333fc9b7d47e98525c45f..2524a3ffcb5ea9ef6259cb9bb0bf12119bd840d2 100644\n--- a/server/src/api/auth.rs\n+++ b/server/src/api/auth.rs\n@@ -1,9 +1,11 @@\n use axum::{\n+ body::Body,\n extract::{Path, Query, State},\n- http::{HeaderMap, StatusCode},\n- response::{IntoResponse, Redirect},\n+ http::{header, HeaderMap, HeaderValue, StatusCode},\n+ response::{IntoResponse, Redirect, Response},\n Form, Json,\n };\n+use axum_extra::extract::cookie::CookieJar;\n use base64::Engine;\n use serde::Deserialize;\n use slug_types::{PendingSessionPollResponse, PendingSessionStartRequest, PendingSessionStartResponse, WhoamiResponse};\n@@ -13,14 +15,47 @@ use tokio::sync::RwLock;\n use crate::{\n api::helpers::{api_error, now_ms, sha256_hex},\n events::{Event, GrantAdded, TokenIssued, UserRegistered},\n- identity::{parse_agent, parse_username},\n html::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page},\n+ identity::{parse_agent, parse_username},\n+ reducer::ReducerState,\n state::{AppState, PendingSession},\n };\n \n /// Delegate id for browser users who land via `/join/inv_…` (no CLI agent).\n const INVITE_BROWSER_AGENT: &str = \"00000000-0000-0000-0000-000000000000:invite:web/join\";\n \n+/// Agent id for `/login` browser OAuth (no CLI); must pass [`parse_agent`].\n+const WEB_BROWSER_AGENT: &str = \"00000000-0000-0000-0000-000000000001:social:web/browser\";\n+\n+/// HttpOnly cookie storing the same `slug_*` bearer string the CLI uses.\n+pub const SLUG_SESSION_COOKIE: &str = \"slug_session\";\n+\n+/// `Set-Cookie` header value (full attribute string).\n+pub fn session_cookie_header_value(bearer: &str) -> HeaderValue {\n+ let s = format!(\n+ \"{SLUG_SESSION_COOKIE}={bearer}; Path=/; HttpOnly; SameSite=Lax; Max-Age=31536000\"\n+ );\n+ HeaderValue::from_str(&s).expect(\"session cookie value must be ASCII\")\n+}\n+\n+/// Resolve the signed-in username from `Authorization: Bearer` or `slug_session` cookie.\n+pub fn optional_principal(headers: &HeaderMap, jar: &CookieJar, reduced: &ReducerState) -> Option {\n+ if let Ok(u) = verify_bearer_principal(headers, reduced) {\n+ return Some(u);\n+ }\n+ let c = jar.get(SLUG_SESSION_COOKIE)?;\n+ verify_token(reduced, c.value()).ok()\n+}\n+\n+fn redirect_with_session_cookie(public_url: &str, path_and_query: &str, bearer: &str) -> Response {\n+ Response::builder()\n+ .status(StatusCode::TEMPORARY_REDIRECT)\n+ .header(header::LOCATION, format!(\"{public_url}{path_and_query}\"))\n+ .header(header::SET_COOKIE, session_cookie_header_value(bearer))\n+ .body(Body::empty())\n+ .unwrap()\n+}\n+\n async fn apply_invite_redemption(state: &AppState, invite_token: &str, grantee_username: &str) -> Result<(), String> {\n let now = now_ms();\n let ga = {\n@@ -306,8 +341,9 @@ pub async fn get_auth_callback(Query(q): Query, State(state):\n tracing::warn!(error = %e, \"invite redemption skipped after oauth\");\n }\n }\n+ let cookie_bearer = bearer.clone();\n s.complete = Some((username, bearer));\n- return Redirect::temporary(&format!(\"{public_url}/auth/complete\")).into_response();\n+ return redirect_with_session_cookie(&public_url, \"/\", &cookie_bearer).into_response();\n }\n }\n \n@@ -418,7 +454,47 @@ pub async fn post_choose_username(\n s.complete = Some((canon_user.clone(), bearer.clone()));\n }\n \n- auth_signed_in_fragment().into_response()\n+ Response::builder()\n+ .status(StatusCode::OK)\n+ .header(header::CONTENT_TYPE, \"text/html; charset=utf-8\")\n+ .header(header::SET_COOKIE, session_cookie_header_value(&bearer))\n+ .body(Body::from(auth_signed_in_fragment().into_string()))\n+ .unwrap()\n+ .into_response()\n+}\n+\n+/// Start a browser-only OAuth flow (no CLI polling). Sets session cookie on success.\n+pub async fn get_web_login(State(state): State) -> impl IntoResponse {\n+ let session = format!(\"p_{}\", uuid::Uuid::new_v4().simple());\n+ let s = PendingSession {\n+ agent: WEB_BROWSER_AGENT.to_string(),\n+ created_ts: now_ms(),\n+ provider: None,\n+ provider_id: None,\n+ redeem_invite: None,\n+ complete: None,\n+ };\n+ state.pending_sessions.write().await.insert(session.clone(), s);\n+ let public_url = std::env::var(\"SLUG_PUBLIC_URL\").unwrap_or_else(|_| \"http://127.0.0.1:8080\".to_string());\n+ Redirect::temporary(&format!(\n+ \"{public_url}/auth/login?session={}\",\n+ urlencoding::encode(&session)\n+ ))\n+ .into_response()\n+}\n+\n+pub async fn get_logout() -> impl IntoResponse {\n+ let clear = format!(\"{SLUG_SESSION_COOKIE}=; Path=/; HttpOnly; SameSite=Lax; Max-Age=0\");\n+ Response::builder()\n+ .status(StatusCode::TEMPORARY_REDIRECT)\n+ .header(header::LOCATION, \"/\")\n+ .header(\n+ header::SET_COOKIE,\n+ HeaderValue::from_str(&clear).expect(\"static cookie clears\"),\n+ )\n+ .body(Body::empty())\n+ .unwrap()\n+ .into_response()\n }\n \n pub async fn post_pending_session(\ndiff --git a/server/src/api/mod.rs b/server/src/api/mod.rs\nindex cb031aecebad1107dfa2898a98fb6084b28ba6e9..5320345a33bbb7b5ab769696a31f70347d019c3e 100644\n--- a/server/src/api/mod.rs\n+++ b/server/src/api/mod.rs\n@@ -1,7 +1,9 @@\n mod auth;\n mod helpers;\n mod rpc;\n+mod stream;\n mod validate;\n+mod web_post;\n \n pub use auth::{\n get_join_invite,\n@@ -13,6 +15,11 @@ pub use auth::{\n get_auth_callback,\n get_auth_complete,\n get_choose_username,\n+ get_web_login,\n+ get_logout,\n+ optional_principal,\n+ session_cookie_header_value,\n+ SLUG_SESSION_COOKIE,\n };\n \n pub use helpers::{\n@@ -23,8 +30,12 @@ pub use helpers::{\n \n pub use rpc::handle_rpc_batch;\n \n+pub use stream::{get_html_stream, get_stream};\n+\n pub use validate::{normalize_room_and_thread, validate_ingest_document, ValidatedIngest};\n \n+pub use web_post::post_web_ingest;\n+\n #[cfg(test)]\n mod tests {\n use super::*;\ndiff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs\nindex 7d384e938a526bdf6aa04d1bf21a54d3fcb57d7e..231bf7381cf804144efd0521970b72dd8ffd4213 100644\n--- a/server/src/api/rpc.rs\n+++ b/server/src/api/rpc.rs\n@@ -407,6 +407,22 @@ async fn rpc_post(\n })\n }\n \n+/// Post forum content using a raw bearer token (CLI `Authorization` header or browser session cookie).\n+pub async fn rpc_post_with_bearer(\n+ state: &AppState,\n+ bearer_token: &str,\n+ room: String,\n+ thread_tag: String,\n+ text: String,\n+) -> Result {\n+ use axum::http::{header, HeaderMap, HeaderValue};\n+ let mut headers = HeaderMap::new();\n+ let hv = HeaderValue::from_str(&format!(\"Bearer {bearer_token}\"))\n+ .map_err(|_| (\"invalid session token\".into(), None))?;\n+ headers.insert(header::AUTHORIZATION, hv);\n+ rpc_post(state, &headers, room, thread_tag, None, text, false).await\n+}\n+\n async fn rpc_check(\n state: &AppState,\n _room: String,\ndiff --git a/server/src/api/web_post.rs b/server/src/api/web_post.rs\nnew file mode 100644\nindex 0000000000000000000000000000000000000000..d7a5780c02281a60d29f27d17b291d6df5580606\n--- /dev/null\n+++ b/server/src/api/web_post.rs\n@@ -0,0 +1,107 @@\n+use axum::{\n+ extract::State,\n+ http::{HeaderMap, StatusCode},\n+ response::{Html, IntoResponse, Redirect},\n+ Form,\n+};\n+use axum_extra::extract::cookie::CookieJar;\n+use serde::Deserialize;\n+use slug_types::RpcResult;\n+\n+use crate::{\n+ api::{\n+ auth::{optional_principal, SLUG_SESSION_COOKIE},\n+ rpc::rpc_post_with_bearer,\n+ },\n+ canonical_path::canonicalize_tag,\n+ html::layout,\n+ state::AppState,\n+};\n+\n+#[derive(Debug, Deserialize)]\n+pub struct WebPostForm {\n+ pub room: String,\n+ pub thread_tag: String,\n+ pub text: String,\n+}\n+\n+fn post_redirect_location(room: &str, thread_tag: &str) -> String {\n+ let tag = canonicalize_tag(thread_tag);\n+ if room.trim() == \"public\" {\n+ format!(\"/t/{tag}\")\n+ } else {\n+ let room = room.trim();\n+ let Some((a, b)) = room.split_once('/') else {\n+ return \"/\".to_string();\n+ };\n+ format!(\"/r/{a}/{b}/{tag}\")\n+ }\n+}\n+\n+pub async fn post_web_ingest(\n+ State(state): State,\n+ headers: HeaderMap,\n+ jar: CookieJar,\n+ Form(form): Form,\n+) -> impl IntoResponse {\n+ let reduced = state.reduced.read().await;\n+ let Some(username) = optional_principal(&headers, &jar, &reduced) else {\n+ drop(reduced);\n+ return Redirect::temporary(\"/login\").into_response();\n+ };\n+\n+ let bearer = headers\n+ .get(axum::http::header::AUTHORIZATION)\n+ .and_then(|v| v.to_str().ok())\n+ .and_then(|s| s.strip_prefix(\"Bearer \").map(|t| t.trim().to_string()))\n+ .or_else(|| jar.get(SLUG_SESSION_COOKIE).map(|c| c.value().to_string()));\n+\n+ drop(reduced);\n+\n+ let Some(bearer) = bearer else {\n+ return Redirect::temporary(\"/login\").into_response();\n+ };\n+\n+ let room = form.room.trim().to_string();\n+ let thread_tag = form.thread_tag.trim().to_string();\n+ let text = form.text.clone();\n+\n+ if text.trim().is_empty() {\n+ return error_page(\n+ \"empty post\",\n+ \"Write something in the text area (DSL / prose).\",\n+ &username,\n+ )\n+ .into_response();\n+ }\n+\n+ match rpc_post_with_bearer(&state, &bearer, room.clone(), thread_tag.clone(), text).await {\n+ Ok(RpcResult::PostOk { .. }) => {\n+ Redirect::to(&post_redirect_location(&room, &thread_tag)).into_response()\n+ }\n+ Ok(_) => error_page(\"unexpected response\", \"Post did not return PostOk.\", &username).into_response(),\n+ Err((msg, hint)) => error_page(\n+ &msg,\n+ hint.as_deref().unwrap_or(\"\"),\n+ &username,\n+ )\n+ .into_response(),\n+ }\n+}\n+\n+fn error_page(title: &str, detail: &str, user: &str) -> impl IntoResponse {\n+ use maud::html;\n+ let body = html! {\n+ nav class=\"breadcrumb\" {\n+ a href=\"/\" { \"slug.social\" }\n+ }\n+ h1 { \"could not post\" }\n+ p { (title) }\n+ @if !detail.is_empty() {\n+ pre class=\"muted\" { (detail) }\n+ }\n+ p class=\"muted\" { \"signed in as @\" (user) \" · \" a href=\"/\" { \"home\" } }\n+ };\n+ let page = layout(\"post error — slug.social\", \"view-thread\", body, None);\n+ (StatusCode::BAD_REQUEST, Html(page.into_string()))\n+}\ndiff --git a/server/src/html/forum.rs b/server/src/html/forum.rs\nindex 228a120065dbacd8a308ba6e8bfc6ab111877c4b..8dfcd6b23a18e1571c4f0b3b60c865fa8f576f2f 100644\n--- a/server/src/html/forum.rs\n+++ b/server/src/html/forum.rs\n@@ -1,21 +1,24 @@\n use axum::{\n extract::{Path, Query, State},\n- http::{header, StatusCode},\n+ http::{header, HeaderMap, StatusCode},\n response::{Html, IntoResponse, Response},\n };\n-use serde::Deserialize;\n+use axum_extra::extract::cookie::CookieJar;\n use maud::{html, Markup};\n+use serde::Deserialize;\n \n use crate::{\n+ api::optional_principal,\n canonical_path::canonicalize_tag,\n+ events::ThreadCapability,\n reducer::{ReducerState, ScopeId},\n state::AppState,\n timeago,\n };\n \n use super::{\n- authorship_address, bc_threads, cli_panel, layout, now_ms,\n- recency_class, render_linkified_with_embeds,\n+ authorship_address, bc_segment, bc_threads, cli_panel, layout, now_ms, recency_class,\n+ render_linkified_with_embeds,\n };\n \n #[derive(Clone)]\n@@ -26,17 +29,72 @@ struct ThreadRow {\n ingests: usize,\n }\n \n-/// Collect thread rows from reducer state (unsorted).\n-fn collect_thread_rows(reduced: &ReducerState, now: i64) -> Vec {\n+/// URL prefix for thread pages: public `/t/…` or room `/r/{short}/{slug}/…`.\n+#[derive(Clone)]\n+pub struct ThreadNav {\n+ pub room_wire: String,\n+ scope: ScopeId,\n+ path_prefix: String,\n+}\n+\n+impl ThreadNav {\n+ pub fn public() -> Self {\n+ Self {\n+ room_wire: \"public\".into(),\n+ scope: ScopeId::Public,\n+ path_prefix: \"/t\".into(),\n+ }\n+ }\n+\n+ /// `room_id` wire form `shortid/slug`.\n+ pub fn from_room_id(room_id: &str) -> Option {\n+ let (short, slug) = room_id.split_once('/')?;\n+ if short.is_empty() || slug.is_empty() {\n+ return None;\n+ }\n+ Some(Self {\n+ room_wire: room_id.to_string(),\n+ scope: ScopeId::Room(room_id.to_string()),\n+ path_prefix: format!(\"/r/{short}/{slug}\"),\n+ })\n+ }\n+\n+ fn scope(&self) -> ScopeId {\n+ self.scope.clone()\n+ }\n+\n+ fn thread_url(&self, tag: &str) -> String {\n+ format!(\"{}/{}\", self.path_prefix, tag)\n+ }\n+\n+ fn thread_page_url(&self, tag: &str, offset: usize) -> String {\n+ let base = self.thread_url(tag);\n+ if offset == 0 {\n+ base\n+ } else {\n+ format!(\"{base}?offset={offset}\")\n+ }\n+ }\n+\n+ fn post_url(&self, tag: &str, idx: usize) -> String {\n+ format!(\"{}/{}/{}\", self.path_prefix, tag, idx)\n+ }\n+\n+ fn expand_url(&self, tag: &str, idx: usize) -> String {\n+ format!(\"{}/{}/{}/expand\", self.path_prefix, tag, idx)\n+ }\n+}\n+\n+fn collect_thread_rows_for_scope(reduced: &ReducerState, scope: &ScopeId, now: i64) -> Vec {\n let _ = now;\n reduced\n .forum_threads\n .iter()\n- .filter(|((scope, _), _)| scope == &ScopeId::Public)\n+ .filter(|((s, _), _)| s == scope)\n .map(|((_, tag), thread)| {\n let ingests = reduced\n .ingests_by_scope_thread\n- .get(&(ScopeId::Public, tag.clone()))\n+ .get(&(scope.clone(), tag.clone()))\n .map(|q| q.len())\n .unwrap_or(0);\n ThreadRow {\n@@ -49,16 +107,46 @@ fn collect_thread_rows(reduced: &ReducerState, now: i64) -> Vec {\n .collect()\n }\n \n-/// Render the thread feed div (id=\"thread-feed\"). Used by both index() and SSE broadcast.\n-fn render_thread_feed(rows: &[ThreadRow], now: i64) -> Markup {\n+fn rooms_for_user(reduced: &ReducerState, username: &str) -> Vec {\n+ let mut v: Vec = reduced\n+ .grants\n+ .iter()\n+ .filter(|(rid, m)| reduced.rooms.contains(*rid) && m.contains_key(username))\n+ .map(|(rid, _)| rid.clone())\n+ .collect();\n+ v.sort();\n+ v\n+}\n+\n+fn user_can_view_room(reduced: &ReducerState, room_id: &str, username: Option<&str>) -> bool {\n+ if !reduced.rooms.contains(room_id) {\n+ return false;\n+ }\n+ let Some(u) = username else {\n+ return false;\n+ };\n+ reduced.user_has_cap(room_id, u, ThreadCapability::View)\n+ || reduced.user_has_cap(room_id, u, ThreadCapability::Post)\n+ || reduced.user_has_cap(room_id, u, ThreadCapability::Manage)\n+}\n+\n+fn user_can_post_room(reduced: &ReducerState, room_id: &str, username: &str) -> bool {\n+ reduced.user_has_cap(room_id, username, ThreadCapability::Post)\n+}\n+\n+/// `feed_id` is e.g. `thread-feed` (public bump list, SSE) or `room-thread-feed`.\n+fn render_thread_feed(nav: Option<&ThreadNav>, feed_id: &str, rows: &[ThreadRow], now: i64) -> Markup {\n html! {\n- div id=\"thread-feed\" {\n+ div id=(feed_id) {\n @if rows.is_empty() {\n p class=\"muted\" { \"no threads yet\" }\n } @else {\n ul class=\"thread-feed\" {\n @for r in rows {\n- @let thread_href = format!(\"/t/{}\", r.tag);\n+ @let thread_href = nav\n+ .as_ref()\n+ .map(|n| n.thread_url(&r.tag))\n+ .unwrap_or_else(|| format!(\"/t/{}\", r.tag));\n @let hover = timeago::rfc3339_utc(r.last_ts);\n @let ago = timeago::timeago(now, r.last_ts);\n @let age_cls = recency_class(now, r.last_ts);\n@@ -83,36 +171,148 @@ fn render_thread_feed(rows: &[ThreadRow], now: i64) -> Markup {\n }\n }\n \n+fn auth_strip(\n+ headers: &HeaderMap,\n+ jar: &CookieJar,\n+ reduced: &ReducerState,\n+) -> Markup {\n+ match optional_principal(headers, jar, reduced) {\n+ Some(u) => html! {\n+ p class=\"muted auth-strip\" {\n+ \"@\" (u)\n+ \" · \"\n+ a href=\"/logout\" { \"log out\" }\n+ }\n+ },\n+ None => html! {\n+ p class=\"muted auth-strip\" {\n+ a href=\"/login\" { \"log in\" }\n+ }\n+ },\n+ }\n+}\n+\n+fn bc_room(nav: &ThreadNav, room_slug: &str, thread_tag: Option<&str>) -> Markup {\n+ html! {\n+ a href=\"/\" { \"slug.social\" }\n+ @if let Some(t) = thread_tag {\n+ (bc_segment(\n+ &format!(\"r / {room_slug}\"),\n+ &nav.path_prefix,\n+ false,\n+ ))\n+ (bc_segment(&format!(\"#{t}\"), &nav.thread_url(t), true))\n+ } @else {\n+ (bc_segment(\n+ &format!(\"r / {room_slug}\"),\n+ &nav.path_prefix,\n+ true,\n+ ))\n+ }\n+ }\n+}\n+\n+fn compose_form(nav: &ThreadNav, thread_tag: &str, show: bool) -> Markup {\n+ if !show {\n+ return html! {};\n+ }\n+ html! {\n+ section class=\"compose\" {\n+ h3 { \"reply\" }\n+ p class=\"muted\" { \"Uses the same ingest DSL as the CLI. You must be logged in.\" }\n+ form method=\"POST\" action=\"/post\" {\n+ input type=\"hidden\" name=\"room\" value=(nav.room_wire.clone());\n+ input type=\"hidden\" name=\"thread_tag\" value=(thread_tag);\n+ textarea name=\"text\" rows=\"8\" cols=\"80\" placeholder=\"prose or ~/items and votes…\" {}\n+ p {\n+ button type=\"submit\" { \"post\" }\n+ }\n+ }\n+ }\n+ }\n+}\n+\n+fn new_thread_form_public(show: bool) -> Markup {\n+ if !show {\n+ return html! {};\n+ }\n+ html! {\n+ section class=\"compose\" {\n+ h3 { \"new public thread\" }\n+ p class=\"muted\" { \"Set thread tag and body. Example: start with a title line or use the CLI-shaped DSL.\" }\n+ form method=\"POST\" action=\"/post\" {\n+ input type=\"hidden\" name=\"room\" value=\"public\";\n+ label for=\"new-thread-tag\" { \"thread tag\" }\n+ input type=\"text\" id=\"new-thread-tag\" name=\"thread_tag\" pattern=\"[a-z0-9_\\\\-]{1,64}\" placeholder=\"my-topic\";\n+ label for=\"new-thread-text\" { \"text\" }\n+ textarea id=\"new-thread-text\" name=\"text\" rows=\"6\" placeholder=\"#my-topic\\n\\nYour first post…\" {}\n+ p { button type=\"submit\" { \"create / post\" } }\n+ }\n+ }\n+ }\n+}\n \n-/// Returns the current thread feed HTML fragment for SSE broadcast.\n-/// selector: `#thread-feed`\n+/// Returns the current public thread feed HTML fragment for SSE (`#thread-feed`).\n pub async fn thread_feed_html(state: &AppState) -> String {\n let now = now_ms();\n+ let nav = ThreadNav::public();\n let mut rows = {\n let reduced = state.reduced.read().await;\n- collect_thread_rows(&reduced, now)\n+ collect_thread_rows_for_scope(&reduced, &ScopeId::Public, now)\n };\n rows.sort_by(|a, b| b.last_ts.cmp(&a.last_ts));\n- render_thread_feed(&rows, now).into_string()\n+ render_thread_feed(Some(&nav), \"thread-feed\", &rows, now).into_string()\n }\n \n-pub async fn index(State(state): State) -> impl IntoResponse {\n+/// Home: private rooms (signed-in), then public bump-ordered threads.\n+pub async fn home(\n+ State(state): State,\n+ headers: HeaderMap,\n+ jar: CookieJar,\n+) -> impl IntoResponse {\n let now = now_ms();\n- let mut rows: Vec = {\n- let reduced = state.reduced.read().await;\n- collect_thread_rows(&reduced, now)\n- };\n- // Bump order: most recently active first.\n- rows.sort_by(|a, b| b.last_ts.cmp(&a.last_ts));\n+ let reduced = state.reduced.read().await;\n+ let user = optional_principal(&headers, &jar, &reduced);\n+ let room_ids = user\n+ .as_ref()\n+ .map(|u| rooms_for_user(&reduced, u))\n+ .unwrap_or_default();\n+ let mut public_rows = collect_thread_rows_for_scope(&reduced, &ScopeId::Public, now);\n+ drop(reduced);\n+ public_rows.sort_by(|a, b| b.last_ts.cmp(&a.last_ts));\n+\n+ let nav = ThreadNav::public();\n+ let reduced_read = state.reduced.read().await;\n+ let strip = auth_strip(&headers, &jar, &reduced_read);\n+ let show_forms = user.is_some();\n+ drop(reduced_read);\n \n let page = layout(\n \"slug.social\",\n \"view-thread\",\n html! {\n+ (strip)\n nav class=\"breadcrumb\" { (bc_threads(None)) }\n+ @if !room_ids.is_empty() {\n+ h2 { \"your rooms\" }\n+ ul class=\"thread-feed\" {\n+ @for rid in &room_ids {\n+ @if let Some(nav_r) = ThreadNav::from_room_id(rid) {\n+ @let slug = if let Some((_, s)) = rid.split_once('/') { s } else { rid.as_str() };\n+ li {\n+ a href=(nav_r.path_prefix) {\n+ (slug)\n+ span class=\"muted\" { \" · \" (rid) }\n+ }\n+ }\n+ }\n+ }\n+ }\n+ }\n+ h2 { \"public threads\" }\n p class=\"muted\" { \"dark = time-ordered · light = vote-ranked\" }\n- h2 { \"threads\" }\n- (render_thread_feed(&rows, now))\n+ (render_thread_feed(Some(&nav), \"thread-feed\", &public_rows, now))\n+ (new_thread_form_public(show_forms))\n (cli_panel(\"npx slugsocial forum\"))\n },\n None,\n@@ -127,9 +327,13 @@ pub struct ThreadViewQuery {\n \n const PAGE_SIZE: usize = 10;\n \n-fn render_thread_paginator(tag: &str, offset: usize, total: usize, top: bool) -> Markup {\n+fn render_thread_paginator(nav: &ThreadNav, tag: &str, offset: usize, total: usize, top: bool) -> Markup {\n let newer_offset = offset.checked_add(PAGE_SIZE).filter(|&o| o < total);\n- let older_offset = if offset > 0 { Some(offset.saturating_sub(PAGE_SIZE)) } else { None };\n+ let older_offset = if offset > 0 {\n+ Some(offset.saturating_sub(PAGE_SIZE))\n+ } else {\n+ None\n+ };\n let latest_offset = total.saturating_sub(PAGE_SIZE);\n let on_latest = offset >= latest_offset;\n let (id, scroll_href, scroll_label) = if top {\n@@ -141,7 +345,7 @@ fn render_thread_paginator(tag: &str, offset: usize, total: usize, top: bool) ->\n div class=\"thread-paginator\" id=(id) {\n a href=(scroll_href) class=\"post-nav-btn\" { (scroll_label) }\n @if let Some(o) = older_offset {\n- a href=(format!(\"/t/{tag}?offset={o}\")) class=\"post-nav-btn\" { \"← older\" }\n+ a href=(nav.thread_page_url(tag, o)) class=\"post-nav-btn\" { \"← older\" }\n } @else {\n span class=\"post-nav-btn disabled\" { \"← older\" }\n }\n@@ -149,37 +353,38 @@ fn render_thread_paginator(tag: &str, offset: usize, total: usize, top: bool) ->\n (offset + 1) \"–\" (total.min(offset + PAGE_SIZE)) \" / \" (total)\n }\n @if let Some(o) = newer_offset {\n- a href=(format!(\"/t/{tag}?offset={o}\")) class=\"post-nav-btn\" { \"newer →\" }\n+ a href=(nav.thread_page_url(tag, o)) class=\"post-nav-btn\" { \"newer →\" }\n } @else {\n span class=\"post-nav-btn disabled\" { \"newer →\" }\n }\n @if !on_latest {\n- a href=(format!(\"/t/{tag}?offset={latest_offset}\")) class=\"post-nav-btn\" { \"latest\" }\n+ a href=(nav.thread_page_url(tag, latest_offset)) class=\"post-nav-btn\" { \"latest\" }\n }\n }\n }\n }\n \n-/// Thread view — `/t/:tag` — dark, paginated.\n-pub async fn thread_view(\n- State(state): State,\n- Path(tag): Path,\n- Query(q): Query,\n+async fn thread_view_inner(\n+ state: AppState,\n+ tag: String,\n+ q: ThreadViewQuery,\n+ nav: ThreadNav,\n+ headers: HeaderMap,\n+ jar: CookieJar,\n ) -> impl IntoResponse {\n let tag = canonicalize_tag(&tag);\n+ let scope = nav.scope();\n \n- // Newest-first queue → chronological for the page.\n let all_ids: Vec = {\n let reduced = state.reduced.read().await;\n reduced\n .ingests_by_scope_thread\n- .get(&(ScopeId::Public, tag.clone()))\n+ .get(&(scope.clone(), tag.clone()))\n .map(|q| q.iter().rev().cloned().collect())\n .unwrap_or_default()\n };\n \n let total = all_ids.len();\n- // Default: first page (oldest posts first, like a book).\n let offset = q.offset.unwrap_or(0);\n let page_ids: Vec = all_ids.into_iter().skip(offset).take(PAGE_SIZE).collect();\n \n@@ -189,18 +394,49 @@ pub async fn thread_view(\n .iter()\n .filter_map(|id| reduced.ingests_by_id.get(id).cloned())\n .collect::>();\n- let subtitle: Option = None;\n- (ingests, subtitle)\n+ (ingests, None::)\n+ };\n+\n+ let reduced = state.reduced.read().await;\n+ let user = optional_principal(&headers, &jar, &reduced);\n+ let sc = nav.scope();\n+ let show_compose = match &sc {\n+ ScopeId::Public => user.is_some(),\n+ ScopeId::Room(rid) => user\n+ .as_ref()\n+ .map(|u| user_can_post_room(&reduced, rid, u))\n+ .unwrap_or(false),\n };\n+ let strip = auth_strip(&headers, &jar, &reduced);\n+ drop(reduced);\n \n let now = now_ms();\n- let paginator_top = render_thread_paginator(&tag, offset, total, true);\n- let paginator_bot = render_thread_paginator(&tag, offset, total, false);\n+ let paginator_top = render_thread_paginator(&nav, &tag, offset, total, true);\n+ let paginator_bot = render_thread_paginator(&nav, &tag, offset, total, false);\n+\n+ let bc: Markup = match &sc {\n+ ScopeId::Public => bc_threads(Some(&tag)),\n+ ScopeId::Room(rid) => {\n+ let slug = if let Some((_, s)) = rid.split_once('/') {\n+ s\n+ } else {\n+ rid.as_str()\n+ };\n+ bc_room(&nav, slug, Some(&tag))\n+ }\n+ };\n+\n+ let cli = match &sc {\n+ ScopeId::Public => format!(\"npx slugsocial forum {tag}\"),\n+ ScopeId::Room(r) => format!(\"npx slugsocial private {r} forum {tag}\"),\n+ };\n+\n let page = layout(\n &format!(\"#{tag}\"),\n \"view-thread\",\n html! {\n- nav class=\"breadcrumb\" { (bc_threads(Some(&tag))) }\n+ (strip)\n+ nav class=\"breadcrumb\" { (bc) }\n h2 { \"#\" (tag) @if let Some(sub) = &subtitle { \": \" (sub) } }\n p class=\"muted\" { \"top=oldest · bottom=newest\" }\n @if display_ingests.is_empty() {\n@@ -209,7 +445,7 @@ pub async fn thread_view(\n (paginator_top)\n @for (i, ing) in display_ingests.iter().enumerate() {\n @let post_idx = offset + i;\n- @let post_href = format!(\"/t/{tag}/{post_idx}\");\n+ @let post_href = nav.post_url(&tag, post_idx);\n @let hover = timeago::rfc3339_utc(ing.ts);\n @let ago = timeago::timeago(now, ing.ts);\n @let truncated = ing.raw.len() > 2000;\n@@ -222,8 +458,9 @@ pub async fn thread_view(\n }\n (render_linkified_with_embeds(display_body))\n @if truncated {\n+ @let exp = nav.expand_url(&tag, post_idx);\n a href=\"#\" class=\"show-full-link\"\n- onclick=(format!(\"fetch('/t/{tag}/{post_idx}/expand').then(r=>r.text()).then(eval);return false\")) {\n+ onclick=(format!(\"fetch('{exp}').then(r=>r.text()).then(eval);return false\")) {\n \"[show full post]\"\n }\n }\n@@ -231,34 +468,171 @@ pub async fn thread_view(\n }\n (paginator_bot)\n }\n- (cli_panel(&format!(\"npx slugsocial forum {tag}\")))\n+ (compose_form(&nav, &tag, show_compose))\n+ (cli_panel(&cli))\n },\n None,\n );\n Html(page.into_string()).into_response()\n }\n \n-/// Single-post view — `/t/:tag/:index` — shows one ingest at full length.\n-pub async fn thread_post_view(\n+/// Thread view — `/t/:tag`\n+pub async fn thread_view(\n State(state): State,\n- Path((tag, index_str)): Path<(String, String)>,\n+ Path(tag): Path,\n+ Query(q): Query,\n+ headers: HeaderMap,\n+ jar: CookieJar,\n ) -> impl IntoResponse {\n- let tag = canonicalize_tag(&tag);\n+ thread_view_inner(state, tag, q, ThreadNav::public(), headers, jar).await\n+}\n+\n+/// Room thread — `/r/:short/:slug/:tag`\n+pub async fn room_thread_view(\n+ State(state): State,\n+ Path((room_short, room_slug, tag)): Path<(String, String, String)>,\n+ Query(q): Query,\n+ headers: HeaderMap,\n+ jar: CookieJar,\n+) -> impl IntoResponse {\n+ let room_id = format!(\"{room_short}/{room_slug}\");\n+ let reduced = state.reduced.read().await;\n+ let user = optional_principal(&headers, &jar, &reduced);\n+ if !user_can_view_room(&reduced, &room_id, user.as_deref()) {\n+ drop(reduced);\n+ return room_forbidden_page().into_response();\n+ }\n+ drop(reduced);\n+ let Some(nav) = ThreadNav::from_room_id(&room_id) else {\n+ return (StatusCode::NOT_FOUND, \"bad room path\").into_response();\n+ };\n+ thread_view_inner(state, tag, q, nav, headers, jar)\n+ .await\n+ .into_response()\n+}\n+\n+fn room_forbidden_page() -> impl IntoResponse {\n+ let body = html! {\n+ nav class=\"breadcrumb\" { a href=\"/\" { \"slug.social\" } }\n+ h1 { \"private room\" }\n+ p { \"Log in with an account that has been granted access to this room.\" }\n+ p { a href=\"/login\" { \"log in\" } \" · \" a href=\"/\" { \"home\" } }\n+ };\n+ let page = layout(\"private room — slug.social\", \"view-thread\", body, None);\n+ (StatusCode::FORBIDDEN, Html(page.into_string()))\n+}\n+\n+/// Private room index — `/r/:short/:slug`\n+pub async fn room_page(\n+ State(state): State,\n+ Path((room_short, room_slug)): Path<(String, String)>,\n+ headers: HeaderMap,\n+ jar: CookieJar,\n+) -> impl IntoResponse {\n+ let room_id = format!(\"{room_short}/{room_slug}\");\n let now = now_ms();\n+ let reduced = state.reduced.read().await;\n+ if !reduced.rooms.contains(&room_id) {\n+ drop(reduced);\n+ return (StatusCode::NOT_FOUND, \"room not found\").into_response();\n+ }\n+ let user = optional_principal(&headers, &jar, &reduced);\n+ if !user_can_view_room(&reduced, &room_id, user.as_deref()) {\n+ drop(reduced);\n+ return room_forbidden_page().into_response();\n+ }\n+ let scope = ScopeId::Room(room_id.clone());\n+ let mut rows = collect_thread_rows_for_scope(&reduced, &scope, now);\n+ let strip = auth_strip(&headers, &jar, &reduced);\n+ let show_new = user\n+ .as_ref()\n+ .map(|u| user_can_post_room(&reduced, &room_id, u))\n+ .unwrap_or(false);\n+ drop(reduced);\n+ rows.sort_by(|a, b| b.last_ts.cmp(&a.last_ts));\n+\n+ let Some(nav) = ThreadNav::from_room_id(&room_id) else {\n+ return (StatusCode::NOT_FOUND, \"room not found\").into_response();\n+ };\n+ let slug_display = room_slug.as_str();\n+ let cli = format!(\"npx slugsocial private {room_id} forum\");\n+\n+ let page = layout(\n+ &format!(\"room {slug_display} — slug.social\"),\n+ \"view-thread\",\n+ html! {\n+ (strip)\n+ nav class=\"breadcrumb\" { (bc_room(&nav, slug_display, None)) }\n+ h2 { (slug_display) }\n+ p class=\"muted\" { (room_id) }\n+ h3 { \"threads\" }\n+ (render_thread_feed(Some(&nav), \"room-thread-feed\", &rows, now))\n+ @if show_new {\n+ (new_thread_form_for_room(&nav, show_new))\n+ }\n+ (cli_panel(&cli))\n+ },\n+ None,\n+ );\n+ Html(page.into_string()).into_response()\n+}\n+\n+fn new_thread_form_for_room(nav: &ThreadNav, show: bool) -> Markup {\n+ if !show {\n+ return html! {};\n+ }\n+ html! {\n+ section class=\"compose\" {\n+ h3 { \"new thread in this room\" }\n+ form method=\"POST\" action=\"/post\" {\n+ input type=\"hidden\" name=\"room\" value=(nav.room_wire.clone());\n+ label for=\"room-new-tag\" { \"thread tag\" }\n+ input type=\"text\" id=\"room-new-tag\" name=\"thread_tag\" pattern=\"[a-z0-9_\\\\-]{1,64}\" required;\n+ textarea name=\"text\" rows=\"6\" placeholder=\"First post body…\" required {}\n+ p { button type=\"submit\" { \"post\" } }\n+ }\n+ }\n+ }\n+}\n+\n+async fn thread_post_view_inner(\n+ state: AppState,\n+ tag: String,\n+ index_str: String,\n+ nav: ThreadNav,\n+) -> impl IntoResponse {\n+ let tag = canonicalize_tag(&tag);\n let index: usize = index_str.parse().unwrap_or(0);\n+ let scope = nav.scope();\n+ let now = now_ms();\n let (ing, subtitle) = {\n let reduced = state.reduced.read().await;\n- let ing = reduced.ingests_by_scope_thread.get(&(ScopeId::Public, tag.clone()))\n+ let ing = reduced\n+ .ingests_by_scope_thread\n+ .get(&(scope.clone(), tag.clone()))\n .and_then(|q| q.iter().rev().nth(index))\n .and_then(|id| reduced.ingests_by_id.get(id).cloned());\n- let subtitle: Option = None;\n- (ing, subtitle)\n+ (ing, None::)\n };\n+\n+ let sc = nav.scope();\n+ let bc: Markup = match &sc {\n+ ScopeId::Public => bc_threads(Some(&tag)),\n+ ScopeId::Room(rid) => {\n+ let slug = if let Some((_, s)) = rid.split_once('/') {\n+ s\n+ } else {\n+ rid.as_str()\n+ };\n+ bc_room(&nav, slug, Some(&tag))\n+ }\n+ };\n+\n let page = layout(\n &format!(\"#{tag} / post #{index}\"),\n \"view-thread\",\n html! {\n- nav class=\"breadcrumb\" { (bc_threads(Some(&tag))) }\n+ nav class=\"breadcrumb\" { (bc) }\n h2 { \"#\" (tag) @if let Some(sub) = &subtitle { \": \" (sub) } \" / post #\" (index) }\n @if let Some(ing) = ing {\n @let hover = timeago::rfc3339_utc(ing.ts);\n@@ -280,21 +654,51 @@ pub async fn thread_post_view(\n Html(page.into_string()).into_response()\n }\n \n-/// Inline expand handler — `/t/:tag/:id/expand`\n-/// Returns a JS snippet that morphs the truncated post into its full version.\n-pub async fn thread_post_expand(\n+pub async fn thread_post_view(\n State(state): State,\n Path((tag, index_str)): Path<(String, String)>,\n+) -> impl IntoResponse {\n+ thread_post_view_inner(state, tag, index_str, ThreadNav::public()).await\n+}\n+\n+pub async fn room_thread_post_view(\n+ State(state): State,\n+ Path((room_short, room_slug, tag, index_str)): Path<(String, String, String, String)>,\n+ headers: HeaderMap,\n+ jar: CookieJar,\n+) -> impl IntoResponse {\n+ let room_id = format!(\"{room_short}/{room_slug}\");\n+ let reduced = state.reduced.read().await;\n+ let user = optional_principal(&headers, &jar, &reduced);\n+ if !user_can_view_room(&reduced, &room_id, user.as_deref()) {\n+ drop(reduced);\n+ return room_forbidden_page().into_response();\n+ }\n+ drop(reduced);\n+ let Some(nav) = ThreadNav::from_room_id(&room_id) else {\n+ return (StatusCode::NOT_FOUND, \"bad room path\").into_response();\n+ };\n+ thread_post_view_inner(state, tag, index_str, nav)\n+ .await\n+ .into_response()\n+}\n+\n+async fn thread_post_expand_inner(\n+ state: AppState,\n+ tag: String,\n+ index_str: String,\n+ nav: ThreadNav,\n ) -> impl IntoResponse {\n let tag = canonicalize_tag(&tag);\n let index: usize = index_str.parse().unwrap_or(0);\n let now = now_ms();\n+ let scope = nav.scope();\n \n let ing = {\n let reduced = state.reduced.read().await;\n reduced\n .ingests_by_scope_thread\n- .get(&(ScopeId::Public, tag.clone()))\n+ .get(&(scope.clone(), tag.clone()))\n .and_then(|q| q.iter().rev().nth(index))\n .and_then(|id| reduced.ingests_by_id.get(id).cloned())\n };\n@@ -303,7 +707,7 @@ pub async fn thread_post_expand(\n return (StatusCode::NOT_FOUND, \"post not found\").into_response();\n };\n \n- let post_href = format!(\"/t/{tag}/{index}\");\n+ let post_href = nav.post_url(&tag, index);\n let hover = timeago::rfc3339_utc(ing.ts);\n let ago = timeago::timeago(now, ing.ts);\n \n@@ -319,7 +723,6 @@ pub async fn thread_post_expand(\n };\n \n let full_html_str = full_html.into_string();\n- // Escape backticks and backslashes for JS template literal\n let escaped = full_html_str\n .replace('\\\\', \"\\\\\\\\\")\n .replace('`', \"\\\\`\")\n@@ -334,7 +737,36 @@ pub async fn thread_post_expand(\n Response::builder()\n .status(StatusCode::OK)\n .header(header::CONTENT_TYPE, \"text/javascript; charset=utf-8\")\n- .body(js)\n+ .body(axum::body::Body::from(js))\n .unwrap()\n .into_response()\n }\n+\n+pub async fn thread_post_expand(\n+ State(state): State,\n+ Path((tag, index_str)): Path<(String, String)>,\n+) -> impl IntoResponse {\n+ thread_post_expand_inner(state, tag, index_str, ThreadNav::public()).await\n+}\n+\n+pub async fn room_thread_post_expand(\n+ State(state): State,\n+ Path((room_short, room_slug, tag, index_str)): Path<(String, String, String, String)>,\n+ headers: HeaderMap,\n+ jar: CookieJar,\n+) -> impl IntoResponse {\n+ let room_id = format!(\"{room_short}/{room_slug}\");\n+ let reduced = state.reduced.read().await;\n+ let user = optional_principal(&headers, &jar, &reduced);\n+ if !user_can_view_room(&reduced, &room_id, user.as_deref()) {\n+ drop(reduced);\n+ return (StatusCode::FORBIDDEN, \"forbidden\").into_response();\n+ }\n+ drop(reduced);\n+ let Some(nav) = ThreadNav::from_room_id(&room_id) else {\n+ return (StatusCode::NOT_FOUND, \"not found\").into_response();\n+ };\n+ thread_post_expand_inner(state, tag, index_str, nav)\n+ .await\n+ .into_response()\n+}\ndiff --git a/server/src/html/mod.rs b/server/src/html/mod.rs\nindex 9c5af9654c7010d2cdb100e4cf63ba63e77c8c57..26e86124aae7cd878c92e1dc927e19d9fd2feaba 100644\n--- a/server/src/html/mod.rs\n+++ b/server/src/html/mod.rs\n@@ -16,7 +16,10 @@ use breadcrumb_path::OntologyPath;\n \n pub use auth::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page};\n pub use editor::{editor_check, editor_page};\n-pub use forum::{index, thread_feed_html, thread_post_expand, thread_post_view, thread_view};\n+pub use forum::{\n+ home, room_page, room_thread_post_expand, room_thread_post_view, room_thread_view, thread_feed_html,\n+ thread_post_expand, thread_post_view, thread_view,\n+};\n pub use garden::{garden_index, ontology_path};\n pub use search::{search_page, search_results_fragment};\n \ndiff --git a/server/src/lib.rs b/server/src/lib.rs\nindex bf2f73d4d0f26a357961e88c52c3b4f72626af81..b074cc31b94f23d1d566513392d7da3c02653c97 100644\n--- a/server/src/lib.rs\n+++ b/server/src/lib.rs\n@@ -16,7 +16,7 @@ pub mod state;\n pub mod timeago;\n \n use axum::Router;\n-use axum::routing::post;\n+use axum::routing::{get, post};\n use tower_http::trace::TraceLayer;\n \n use crate::state::AppState;\n@@ -25,17 +25,48 @@ pub use reducer::ReducerState;\n \n pub fn create_app(state: AppState) -> Router {\n Router::new()\n- .route(\"/healthz\", axum::routing::get(|| async { \"ok\" }))\n- .route(\"/static/:filename\", axum::routing::get(crate::html::serve_theme_css))\n- .route(\"/join/:token\", axum::routing::get(api::get_join_invite))\n- .route(\"/auth/login\", axum::routing::get(api::get_auth_login))\n- .route(\"/auth/callback\", axum::routing::get(api::get_auth_callback))\n- .route(\"/auth/complete\", axum::routing::get(api::get_auth_complete))\n- .route(\"/auth/choose-username\", axum::routing::get(api::get_choose_username))\n- .route(\"/auth/choose-username\", axum::routing::post(api::post_choose_username))\n- .route(\"/api/v0/pending-session\", axum::routing::post(api::post_pending_session))\n- .route(\"/api/v0/pending-session/:id\", axum::routing::get(api::get_pending_session))\n- .route(\"/api/v0/whoami\", axum::routing::get(api::get_whoami))\n+ .route(\"/healthz\", get(|| async { \"ok\" }))\n+ .route(\"/static/:filename\", get(crate::html::serve_theme_css))\n+ .route(\"/\", get(crate::html::home))\n+ .route(\"/login\", get(api::get_web_login))\n+ .route(\"/logout\", get(api::get_logout))\n+ .route(\"/post\", post(api::post_web_ingest))\n+ .route(\"/sse\", get(api::get_html_stream))\n+ .route(\"/stream\", get(api::get_stream))\n+ .route(\"/search\", get(crate::html::search_page))\n+ .route(\"/search/results\", get(crate::html::search_results_fragment))\n+ .route(\"/try\", get(crate::html::editor_page))\n+ .route(\"/try/check\", post(crate::html::editor_check))\n+ .route(\"/~\", get(crate::html::garden_index))\n+ .route(\"/~/*path\", get(crate::html::ontology_path))\n+ .route(\n+ \"/t/:tag/:index/expand\",\n+ get(crate::html::thread_post_expand),\n+ )\n+ .route(\"/t/:tag/:index\", get(crate::html::thread_post_view))\n+ .route(\"/t/:tag\", get(crate::html::thread_view))\n+ .route(\n+ \"/r/:room_short/:room_slug/:thread_tag/:index/expand\",\n+ get(crate::html::room_thread_post_expand),\n+ )\n+ .route(\n+ \"/r/:room_short/:room_slug/:thread_tag/:index\",\n+ get(crate::html::room_thread_post_view),\n+ )\n+ .route(\n+ \"/r/:room_short/:room_slug/:thread_tag\",\n+ get(crate::html::room_thread_view),\n+ )\n+ .route(\"/r/:room_short/:room_slug\", get(crate::html::room_page))\n+ .route(\"/join/:token\", get(api::get_join_invite))\n+ .route(\"/auth/login\", get(api::get_auth_login))\n+ .route(\"/auth/callback\", get(api::get_auth_callback))\n+ .route(\"/auth/complete\", get(api::get_auth_complete))\n+ .route(\"/auth/choose-username\", get(api::get_choose_username))\n+ .route(\"/auth/choose-username\", post(api::post_choose_username))\n+ .route(\"/api/v0/pending-session\", post(api::post_pending_session))\n+ .route(\"/api/v0/pending-session/:id\", get(api::get_pending_session))\n+ .route(\"/api/v0/whoami\", get(api::get_whoami))\n .route(\"/api/v0/rpc\", post(api::handle_rpc_batch))\n .with_state(state)\n .layer(TraceLayer::new_for_http())\n","role":"user"}],"model":"~x-ai/grok-latest"}