{"messages":[{"content":"You are a constitutional council ranking individual git commits for ownership allocation.\n\nCompare these two commits. Decide which contributed more lasting value to the project.\n\nJudge substance, not spectacle:\n- Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise.\n- Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one.\n- Do not favor a side merely because its patch is longer or noisier.\n- Weight what the change does for the project, not the contributor's name.\n\nReturn ONLY a JSON object: {\"winner\": \"A\" or \"B\", \"ratio\": \"N:M\", \"explanation\": \"...\"}\nThe explanation must cite concrete differences in the patches (1-3 sentences).\n\nSide A — contributor: tommy-mor\nSide A — commit message:\n[62d18183] room create path\n\nSide A — unified diff (full patch):\ndiff --git a/cli/GUIDE.sorter b/cli/GUIDE.sorter\nindex dcb06a46045564f8f6f6acffbda6f88644d453cc..9828cba4d9c17b7cce3de597d8724609b2b2adbe 100644\n--- a/cli/GUIDE.sorter\n+++ b/cli/GUIDE.sorter\n@@ -128,7 +128,7 @@ This means participation is collaborative by default. When you receive a compari\n ~/intro/scoping {\n Scoped by room:\n public … Shared site (room id \"public\").\n- private … Private room (e.g. abc12xy/my-project from RoomCreate over RPC).\n+ private … Private room (create with `npx slugsocial room create ` after OAuth — prints e.g. abc12xy/my-project).\n \n Writes from the CLI are only via forum post: the forum channel tag is the first argument after post (no #). Humans post through the website; CLI requires --delegate (agent identity).\n \n@@ -144,7 +144,7 @@ Examples:\n \n Garden and check do not take a forum tag on the command line the same way; check is a dry-run against public garden semantics.\n \n-Global (no room prefix): identity, whoami, feed, search, healthz.\n+Global (no room prefix): room, identity, whoami, feed, search, healthz.\n }\n \n ~/intro/example-session {\n@@ -152,6 +152,10 @@ Global (no room prefix): identity, whoami, feed, search, healthz.\n npx slugsocial identity start --rig claudecode --model anthropic/claude-sonnet-4.5\n # Poll until signed in; keep the printed uuid:rig:model for --delegate (do not publish to shared memory).\n \n+# Private room (optional): creates shortid/slug you pass to `private …`\n+# npx slugsocial room create austin\n+# npx slugsocial private invite-link --caps view,post,vote --uses 5\n+\n # Get sibling items to compare (path: no ~ in CLI; shell expands ~ to home)\n npx slugsocial public garden pair languages\n \n@@ -192,8 +196,12 @@ forum post --delegate DELEGATE [FILE] Post a .sorter doc (stdin if no\n \n check [FILE] Validate without submitting (public garden dry-run)\n \n+invite-link --caps view,post[,…] [--uses N] Mint shareable /join/… link (private rooms; Manage required)\n+audit [--json] List principals + capabilities (private rooms; View or Manage)\n+\n Global (no public/private prefix):\n \n+room create Create a private room (bearer required); prints ROOM_ID for `private …` (use `public …` for the shared site, not a room)\n identity start --rig --model New delegate id + OAuth pending session\n identity poll Complete OAuth; saves bearer token\n \ndiff --git a/cli/src/main.rs b/cli/src/main.rs\nindex 8eda9f485bd1f7392f1e34be27176c21e20354eb..5b1a5845e90bfea9bd9a1e1af5744e97e566b5ae 100644\n--- a/cli/src/main.rs\n+++ b/cli/src/main.rs\n@@ -140,6 +140,12 @@ enum Command {\n sub: ScopedCmd,\n },\n \n+ /// Private rooms: create (requires signed-in CLI token from `identity …`)\n+ Room {\n+ #[command(subcommand)]\n+ sub: RoomCmd,\n+ },\n+\n /// Show all activity since you last posted (global feed)\n ///\n /// Returns all ingests since this actor's last ingest, newest first.\n@@ -203,6 +209,18 @@ enum Command {\n },\n }\n \n+#[derive(Subcommand, Debug)]\n+enum RoomCmd {\n+ /// Create a private room; prints `shortid/slug` for `private …` (public site is `public …`, not a room)\n+ Create {\n+ /// Room slug (lowercase letters, digits, hyphens; 1–64 chars), e.g. `austin` or `my-project`\n+ #[arg(value_name = \"SLUG\")]\n+ slug: String,\n+ #[arg(long)]\n+ json: bool,\n+ },\n+}\n+\n #[derive(Subcommand, Debug)]\n enum IdentityCmd {\n /// Create agent delegate + pending session; output OAuth URL (exit immediately — do not poll here)\n@@ -1252,6 +1270,43 @@ async fn main() -> Result<()> {\n match cmd {\n Command::Public { sub } => run_scoped(base, \"public\", sub).await?,\n Command::Private { room, sub } => run_scoped(base, &room, sub).await?,\n+ Command::Room { sub } => match sub {\n+ RoomCmd::Create { slug, json } => {\n+ let client = http_client()?;\n+ let bearer = effective_bearer().ok_or_else(|| {\n+ anyhow!(\n+ \"no bearer token: run `slugsocial identity start --rig --model ` \\\n+ then `slugsocial identity poll `, or set SLUG_BEARER_TOKEN / ~/.config/slugsocial/token\"\n+ )\n+ })?;\n+ let batch = send_rpc(\n+ &client,\n+ base,\n+ Some(&bearer),\n+ vec![RpcCommand::RoomCreate { slug }],\n+ )\n+ .await?;\n+ match rpc_line_ok(&batch.results[0])? {\n+ RpcResult::RoomCreated { room_id } => {\n+ if json {\n+ println!(\n+ \"{}\",\n+ serde_json::to_string_pretty(&serde_json::json!({\n+ \"ok\": true,\n+ \"room_id\": room_id,\n+ }))?\n+ );\n+ } else {\n+ println!(\"{room_id}\");\n+ println!();\n+ println!(\"Next: npx slugsocial private {room_id} forum post --delegate '…' …\");\n+ println!(\" npx slugsocial private {room_id} invite-link --caps view,post,vote\");\n+ }\n+ }\n+ _ => return Err(anyhow!(\"unexpected RPC result\")),\n+ }\n+ }\n+ },\n \n Command::Healthz { json } => {\n let client = http_client()?;\ndiff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs\nindex f6bbc3df71909a2da7403cd46fe4ea6ca130c692..7d384e938a526bdf6aa04d1bf21a54d3fcb57d7e 100644\n--- a/server/src/api/rpc.rs\n+++ b/server/src/api/rpc.rs\n@@ -14,7 +14,7 @@ use crate::{\n canonical_path::{canonicalize_item, canonicalize_tag},\n dsl,\n events::{\n- AgentBound, Event, GrantAdded, Ingest, RoomCreated, ThreadCapability, ThreadVisibility,\n+ AgentBound, Event, GrantAdded, Ingest, RoomCreated, ThreadCapability,\n },\n identity::{parse_agent, parse_username},\n path_types::CanonicalItemUrl,\n@@ -270,7 +270,7 @@ async fn rpc_post(\n let scope = scope_from_room_wire(&room_key);\n \n let is_private = !matches!(scope, ScopeId::Public);\n- if is_private && !reduced.rooms.contains_key(&room_key) {\n+ if is_private && !reduced.rooms.contains(&room_key) {\n drop(reduced);\n return Err((\"unknown room\".into(), Some(format!(\"room `{}` does not exist\", room_key))));\n }\n@@ -958,7 +958,7 @@ pub async fn handle_rpc_batch(\n let reduced = state.reduced.read().await;\n line_ok(RpcResult::ForumThreads(rpc_list_forum_threads(&reduced, &room)))\n }\n- RpcCommand::RoomCreate { slug, visibility } => {\n+ RpcCommand::RoomCreate { slug } => {\n // Scope the first read so its guard drops before any nested `read().await` / `write().await`.\n // A guard from `match verify(..., &*state.reduced.read().await)` would otherwise live for the\n // whole `match` and deadlock here (tokio::sync::RwLock is not reentrant).\n@@ -975,53 +975,42 @@ pub async fn handle_rpc_batch(\n } else if !slug.chars().all(|c| c.is_ascii_alphanumeric() || c == '-') {\n line_err(\"slug must be lowercase alphanumeric with hyphens\", None)\n } else {\n- match visibility.as_deref().unwrap_or(\"private\") {\n- \"private\" | \"public\" => {\n- let vis = if visibility.as_deref() == Some(\"public\") {\n- ThreadVisibility::Public\n- } else {\n- ThreadVisibility::Private\n- };\n- let short_id = loop {\n- let id = gen_short_id();\n- if !state.reduced.read().await.rooms.contains_key(&format!(\"{id}/{slug}\")) {\n- break id;\n- }\n- };\n- let room_id = format!(\"{short_id}/{slug}\");\n- let ts = now_ms();\n- let tc_ev = Event::RoomCreated(RoomCreated {\n- ts,\n- room_id: room_id.clone(),\n- slug: slug.clone(),\n- owner: principal.clone(),\n- visibility: vis,\n- });\n- let ga_ev = Event::GrantAdded(GrantAdded {\n- ts,\n- room_id: room_id.clone(),\n- username: principal.clone(),\n- capabilities: vec![\n- ThreadCapability::View,\n- ThreadCapability::Post,\n- ThreadCapability::Vote,\n- ThreadCapability::AddItem,\n- ThreadCapability::Manage,\n- ],\n- granted_by: principal.clone(),\n- });\n- if let Err(e) = state.event_log.append(&tc_ev).await {\n- line_err(format!(\"{e}\"), None)\n- } else if let Err(e) = state.event_log.append(&ga_ev).await {\n- line_err(format!(\"{e}\"), None)\n- } else {\n- let mut r = state.reduced.write().await;\n- r.apply_event(tc_ev);\n- r.apply_event(ga_ev);\n- line_ok(RpcResult::RoomCreated { room_id })\n- }\n+ let short_id = loop {\n+ let id = gen_short_id();\n+ if !state.reduced.read().await.rooms.contains(&format!(\"{id}/{slug}\")) {\n+ break id;\n }\n- other => line_err(format!(\"unknown visibility: {other}\"), None),\n+ };\n+ let room_id = format!(\"{short_id}/{slug}\");\n+ let ts = now_ms();\n+ let tc_ev = Event::RoomCreated(RoomCreated {\n+ ts,\n+ room_id: room_id.clone(),\n+ slug: slug.clone(),\n+ owner: principal.clone(),\n+ });\n+ let ga_ev = Event::GrantAdded(GrantAdded {\n+ ts,\n+ room_id: room_id.clone(),\n+ username: principal.clone(),\n+ capabilities: vec![\n+ ThreadCapability::View,\n+ ThreadCapability::Post,\n+ ThreadCapability::Vote,\n+ ThreadCapability::AddItem,\n+ ThreadCapability::Manage,\n+ ],\n+ granted_by: principal.clone(),\n+ });\n+ if let Err(e) = state.event_log.append(&tc_ev).await {\n+ line_err(format!(\"{e}\"), None)\n+ } else if let Err(e) = state.event_log.append(&ga_ev).await {\n+ line_err(format!(\"{e}\"), None)\n+ } else {\n+ let mut r = state.reduced.write().await;\n+ r.apply_event(tc_ev);\n+ r.apply_event(ga_ev);\n+ line_ok(RpcResult::RoomCreated { room_id })\n }\n }\n }\n@@ -1161,7 +1150,7 @@ pub async fn handle_rpc_batch(\n Err((_, m)) => line_err(m, None),\n Ok(principal) => {\n let reduced = state.reduced.read().await;\n- if !reduced.rooms.contains_key(&room) {\n+ if !reduced.rooms.contains(&room) {\n line_err(\"unknown room\", None)\n } else {\n let can_audit = reduced.user_has_cap(&room, &principal, ThreadCapability::View)\ndiff --git a/server/src/events.rs b/server/src/events.rs\nindex 9e60f2c218f5c871a93e855e415dd984e3a017c5..b4ffed95ead228b9cb37ce50953b13efb958a73d 100644\n--- a/server/src/events.rs\n+++ b/server/src/events.rs\n@@ -1,12 +1,5 @@\n use serde::{Deserialize, Serialize};\n \n-#[derive(Debug, Clone, Copy, Serialize, Deserialize, PartialEq, Eq)]\n-#[serde(rename_all = \"snake_case\")]\n-pub enum ThreadVisibility {\n- Public,\n- Private,\n-}\n-\n #[derive(Debug, Clone, Copy, Hash, Serialize, Deserialize, PartialEq, Eq)]\n #[serde(rename_all = \"snake_case\")]\n pub enum ThreadCapability {\n@@ -57,13 +50,13 @@ pub struct AgentBound {\n pub username: String,\n }\n \n+/// Private space keyed as `shortid/slug`.\n #[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]\n pub struct RoomCreated {\n pub ts: i64,\n pub room_id: String,\n pub slug: String,\n pub owner: String,\n- pub visibility: ThreadVisibility,\n }\n \n #[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)]\ndiff --git a/server/src/html/search.rs b/server/src/html/search.rs\nindex 9353cf229fbbd2cfbab5b89ba63ebe192042c91f..694220a038b335f19ac33cb3fb33c74a625bcc51 100644\n--- a/server/src/html/search.rs\n+++ b/server/src/html/search.rs\n@@ -113,7 +113,7 @@ fn search(state: &ReducerState, q: &str, limit: usize) -> SearchResults {\n }\n }\n \n- // Search threads (public room only in HTML)\n+ // Search threads (shared site scope only — `room` wire `public`)\n for ((scope, tag), thread_state) in &state.forum_threads {\n if scope != &ScopeId::Public {\n continue;\ndiff --git a/server/src/reducer.rs b/server/src/reducer.rs\nindex 5190d0a7ee3d545a786a68fef483322aafdce7f9..e06445fa4441771cda0d3474bedccf6f19a36b5f 100644\n--- a/server/src/reducer.rs\n+++ b/server/src/reducer.rs\n@@ -3,7 +3,7 @@ use std::collections::{HashMap, HashSet, VecDeque};\n use serde::{Deserialize, Serialize};\n \n use crate::canonical_path::canonicalize_tag;\n-use crate::events::{Event, Ingest, ThreadCapability, ThreadVisibility};\n+use crate::events::{Event, Ingest, ThreadCapability};\n use crate::path_types::CanonicalItemUrl;\n \n #[derive(Debug, Clone, Hash, PartialEq, Eq, PartialOrd, Ord)]\n@@ -151,11 +151,6 @@ pub struct RankHistoryEntry {\n pub post_id: String,\n }\n \n-#[derive(Debug, Clone)]\n-pub struct RoomState {\n- pub visibility: crate::events::ThreadVisibility,\n-}\n-\n /// Durable invite link state (from [`crate::events::InviteMinted`] / [`crate::events::InviteRedeemed`]).\n #[derive(Debug, Clone)]\n pub struct ActiveInviteState {\n@@ -171,7 +166,6 @@ pub enum RoomTimelineKind {\n RoomCreated {\n owner: String,\n slug: String,\n- visibility: ThreadVisibility,\n },\n GrantAdded {\n username: String,\n@@ -235,8 +229,8 @@ pub struct ReducerState {\n pub ingests_by_id: HashMap,\n /// (scope, thread_tag) → ingest ids, newest first.\n pub ingests_by_scope_thread: HashMap<(ScopeId, String), VecDeque>,\n- /// Private (or public) room registry: room_id → visibility from [`RoomCreated`].\n- pub rooms: HashMap,\n+ /// Private room ids (`shortid/slug`) known from [`RoomCreated`].\n+ pub rooms: HashSet,\n /// (scope, thread_tag) → last activity.\n pub forum_threads: HashMap<(ScopeId, String), ForumThreadState>,\n pub actor_last_post_ts: HashMap,\n@@ -403,12 +397,7 @@ impl ReducerState {\n self.agent_bindings.insert(ab.agent, ab.username);\n }\n Event::RoomCreated(rc) => {\n- self.rooms.insert(\n- rc.room_id.clone(),\n- RoomState {\n- visibility: rc.visibility,\n- },\n- );\n+ self.rooms.insert(rc.room_id.clone());\n self.room_timeline\n .entry(rc.room_id.clone())\n .or_default()\n@@ -417,7 +406,6 @@ impl ReducerState {\n kind: RoomTimelineKind::RoomCreated {\n owner: rc.owner.clone(),\n slug: rc.slug.clone(),\n- visibility: rc.visibility,\n },\n });\n }\n@@ -673,7 +661,7 @@ impl Default for ReducerState {\n agent_bindings: HashMap::new(),\n ingests_by_id: HashMap::new(),\n ingests_by_scope_thread: HashMap::new(),\n- rooms: HashMap::new(),\n+ rooms: HashSet::new(),\n forum_threads: HashMap::new(),\n actor_last_post_ts: HashMap::new(),\n ingests_ordered: Vec::new(),\ndiff --git a/server/src/timeline.rs b/server/src/timeline.rs\nindex 251158943ab36d3015268e35f6bdd01c3f42ab3b..265ca4ae9946ecd29a7d1d4ec791de8465ce658e 100644\n--- a/server/src/timeline.rs\n+++ b/server/src/timeline.rs\n@@ -25,16 +25,8 @@ fn caps_list(caps: &[crate::events::ThreadCapability]) -> String {\n /// Human-readable system line for the thread feed.\n pub fn format_room_timeline_entry(e: &RoomTimelineEntry) -> String {\n match &e.kind {\n- RoomTimelineKind::RoomCreated {\n- owner,\n- slug,\n- visibility,\n- } => {\n- let vis = match visibility {\n- crate::events::ThreadVisibility::Public => \"public\",\n- crate::events::ThreadVisibility::Private => \"private\",\n- };\n- format!(\"@{owner} created room #{slug} ({vis})\")\n+ RoomTimelineKind::RoomCreated { owner, slug } => {\n+ format!(\"@{owner} created room #{slug}\")\n }\n RoomTimelineKind::GrantAdded {\n username,\n@@ -141,7 +133,7 @@ pub fn merge_thread_rows(\n rows\n }\n \n-/// Public forum thread (`room_wire == \"public\"`): same merge (timeline usually empty).\n+/// Shared-site thread view (`room_wire == \"public\"` on the wire). Same merge as private rooms; private-room timeline is unused here.\n pub fn merge_public_thread_rows(\n reduced: &ReducerState,\n thread_tag: &str,\ndiff --git a/server/tests/integration.rs b/server/tests/integration.rs\nindex b930120da09fe7d307f0411b84fb639fb8bd0b15..139fdda27d2276e3b30116816495648970d24c5f 100644\n--- a/server/tests/integration.rs\n+++ b/server/tests/integration.rs\n@@ -96,11 +96,11 @@ async fn test_healthz() {\n }\n \n #[tokio::test]\n-async fn test_room_create_private_rpc() {\n+async fn test_room_create_rpc() {\n let (addr, _tmp, _log, _handle) = create_test_server().await;\n let client = reqwest::Client::new();\n let batch = serde_json::json!([{\n- \"RoomCreate\": { \"slug\": \"secret-project\", \"visibility\": \"private\" }\n+ \"RoomCreate\": { \"slug\": \"secret-project\" }\n }]);\n let body = rpc_batch(&client, addr, Some(&test_bearer()), batch).await;\n let line = &body[\"results\"][0];\ndiff --git a/test/grants.bb b/test/grants.bb\nindex 4ded5ce92576cdea653cce0ba8a751be4374731a..697e7d91545dd3ee96efde07fc8c3cf90f1a8056 100644\n--- a/test/grants.bb\n+++ b/test/grants.bb\n@@ -82,7 +82,7 @@\n ;; Alice creates a private room.\n _ (println \"\\nalice creates private room…\")\n create (rpc-batch! base-url alice-token\n- [{\"RoomCreate\" {\"slug\" \"secret-project\" \"visibility\" \"private\"}}])\n+ [{\"RoomCreate\" {\"slug\" \"secret-project\"}}])\n _ (assert! (= 200 (:status create)) \"room create HTTP 200\")\n _ (assert! (rpc-line-ok? (:parsed create)) \"room create RPC ok\")\n room-id (get-in (:parsed create) [\"results\" 0 \"result\" \"RoomCreated\" \"room_id\"])\ndiff --git a/test/invites.bb b/test/invites.bb\nindex f72b1e630a6856174cdef11eb977e2f81b16e551..ca0fd6c858400671452c4ec59c490d05101dd0e4 100644\n--- a/test/invites.bb\n+++ b/test/invites.bb\n@@ -86,7 +86,7 @@\n \n _ (println \"\\nalice creates private room…\")\n create (rpc-batch! base-url alice-token\n- [{\"RoomCreate\" {\"slug\" \"invite-demo\" \"visibility\" \"private\"}}])\n+ [{\"RoomCreate\" {\"slug\" \"invite-demo\"}}])\n _ (assert! (= 200 (:status create)) \"room create HTTP 200\")\n _ (assert! (rpc-line-ok? (:parsed create)) \"room create RPC ok\")\n room-id (get-in (:parsed create) [\"results\" 0 \"result\" \"RoomCreated\" \"room_id\"])\ndiff --git a/types/src/lib.rs b/types/src/lib.rs\nindex 98c66a00fd27803ef6f75b5ac478ff2eb762d771..bb8586f1734f77d95598a9294bdb0de2d55bf715 100644\n--- a/types/src/lib.rs\n+++ b/types/src/lib.rs\n@@ -319,8 +319,6 @@ pub enum RpcCommand {\n },\n RoomCreate {\n slug: String,\n- #[serde(default, skip_serializing_if = \"Option::is_none\")]\n- visibility: Option,\n },\n RoomGrant {\n room: String,\n\n\nSide B — contributor: tommy-mor\nSide B — commit message:\n[6b6eb0c3] Auth form: poem JS morphs form innerHTML on response; no redirect\n\n- post_choose_username returns HTML fragments instead of redirects:\n success → auth_signed_in_fragment (\"you're signed in — return to your agent\")\n error → choose_username_error_fragment (form re-rendered with error inline)\n- Poem JS now reads response body; if non-empty, morphs form innerHTML with it\n (existing ingest forms return empty body, so they're unaffected)\n- auth.rs: keep full layout() with poem JS — revert to single layout\n- auth-success CSS class added to both themes\n\nCo-Authored-By: Claude Sonnet 4.6 (1M context) \n\nSide B — unified diff (full patch):\ndiff --git a/server/src/api/auth.rs b/server/src/api/auth.rs\nindex c1194f79fd89fb47fe6b425b494a0ffa667abb2d..cb0faa29b834931e2c2b2f5c174c875e2e2e9346 100644\n--- a/server/src/api/auth.rs\n+++ b/server/src/api/auth.rs\n@@ -16,7 +16,7 @@ use crate::{\n canonicalize_username, validate_agent_format, validate_username,\n Event, TokenIssued, UserRegistered,\n },\n- html::{auth_complete_page, choose_username_page},\n+ html::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page},\n state::{AppState, PendingSession},\n };\n \n@@ -274,8 +274,6 @@ pub async fn post_choose_username(\n return api_error(StatusCode::BAD_REQUEST, \"invalid agent format\", Some(msg)).into_response();\n }\n \n- let public_url = std::env::var(\"SLUG_PUBLIC_URL\").unwrap_or_else(|_| \"http://127.0.0.1:8080\".to_string());\n-\n let reduced_arc = state.reduced.clone();\n let reduced = reduced_arc.read().await;\n let provider_key = (provider.to_lowercase(), provider_id.clone());\n@@ -284,11 +282,7 @@ pub async fn post_choose_username(\n }\n if reduced.users_by_provider.values().any(|u| u == &canonicalize_username(&form.username)) {\n drop(reduced);\n- return Redirect::to(&format!(\n- \"{public_url}/auth/choose-username?session={}&error={}\",\n- urlencoding::encode(&form.session),\n- urlencoding::encode(\"that username is taken — try another\"),\n- )).into_response();\n+ return choose_username_error_fragment(&form.session, \"that username is taken — try another\").into_response();\n }\n drop(reduced);\n \n@@ -324,7 +318,7 @@ pub async fn post_choose_username(\n s.complete = Some((canon_user.clone(), bearer.clone()));\n }\n \n- Redirect::to(&format!(\"{public_url}/auth/complete\")).into_response()\n+ auth_signed_in_fragment().into_response()\n }\n \n pub async fn post_pending_session(\ndiff --git a/server/src/html/auth.rs b/server/src/html/auth.rs\nindex 40b1ef30a6c1d4063aa2d8e9c93df8972df4b27c..0a14bdbfb66c65d1bd09993ffd4a7bb6f2fe041e 100644\n--- a/server/src/html/auth.rs\n+++ b/server/src/html/auth.rs\n@@ -1,20 +1,25 @@\n-use maud::{html, Markup, DOCTYPE};\n+use maud::{html, Markup};\n \n-/// Minimal layout for auth pages — no JS interceptor, real form navigation works.\n-fn auth_layout(title: &str, body: Markup) -> Markup {\n+fn form_inner(session: &str, error: Option<&str>) -> Markup {\n html! {\n- (DOCTYPE)\n- html {\n- head {\n- meta charset=\"utf-8\";\n- meta name=\"viewport\" content=\"width=device-width, initial-scale=1\";\n- title { (title) }\n- link rel=\"stylesheet\" href=\"/static/theme_default.css\";\n- }\n- body class=\"view-auth\" {\n- (body)\n- }\n+ input type=\"hidden\" name=\"session\" value=(session);\n+ label for=\"username\" { \"username\" }\n+ input\n+ type=\"text\"\n+ id=\"username\"\n+ name=\"username\"\n+ placeholder=\"e.g. alice\"\n+ pattern=\"[a-z0-9_\\\\-]{1,32}\"\n+ maxlength=\"32\"\n+ autocomplete=\"off\"\n+ autofocus;\n+ p.auth-hint {\n+ \"lowercase · alphanumeric · hyphens · underscores · max 32\"\n }\n+ @if let Some(msg) = error {\n+ p.auth-error { (msg) }\n+ }\n+ button type=\"submit\" { \"continue\" }\n }\n }\n \n@@ -28,27 +33,23 @@ pub fn choose_username_page(session: &str, error: Option<&str>) -> Markup {\n h1 { \"choose a username\" }\n p { \"pick a handle for slug.social.\" }\n form.auth-form method=\"POST\" action=\"/auth/choose-username\" {\n- input type=\"hidden\" name=\"session\" value=(session);\n- label for=\"username\" { \"username\" }\n- input\n- type=\"text\"\n- id=\"username\"\n- name=\"username\"\n- placeholder=\"e.g. alice\"\n- pattern=\"[a-z0-9_\\\\-]{1,32}\"\n- maxlength=\"32\"\n- autocomplete=\"off\"\n- autofocus;\n- p.auth-hint {\n- \"lowercase · alphanumeric · hyphens · underscores · max 32\"\n- }\n- @if let Some(msg) = error {\n- p.auth-error { (msg) }\n- }\n- button type=\"submit\" { \"continue\" }\n+ (form_inner(session, error))\n }\n };\n- auth_layout(\"join — slug.social\", body)\n+ super::layout(\"join — slug.social\", \"view-auth\", body, None)\n+}\n+\n+/// Fragment returned to the poem JS on error — replaces the form's innerHTML.\n+pub fn choose_username_error_fragment(session: &str, error: &str) -> Markup {\n+ form_inner(session, Some(error))\n+}\n+\n+/// Fragment returned to the poem JS on success — replaces the form's innerHTML.\n+pub fn auth_signed_in_fragment() -> Markup {\n+ html! {\n+ p.auth-success { \"you're signed in — return to your agent.\" }\n+ p.auth-hint { \"you can close this tab.\" }\n+ }\n }\n \n pub fn auth_complete_page() -> Markup {\n@@ -62,5 +63,5 @@ pub fn auth_complete_page() -> Markup {\n p { \"Return to your terminal — your agent is polling and will collect your token automatically.\" }\n p.auth-hint { \"You can close this tab.\" }\n };\n- auth_layout(\"signed in — slug.social\", body)\n+ super::layout(\"signed in — slug.social\", \"view-auth\", body, None)\n }\ndiff --git a/server/src/html/mod.rs b/server/src/html/mod.rs\nindex 2f16d701962d703db0c859bb586dfc08ec385690..8b48a25cce79f0eefc7e29849e1a667cae4c7986 100644\n--- a/server/src/html/mod.rs\n+++ b/server/src/html/mod.rs\n@@ -15,7 +15,7 @@ mod search;\n mod tree;\n use breadcrumb_path::OntologyPath;\n \n-pub use auth::{auth_complete_page, choose_username_page};\n+pub use auth::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page};\n pub use editor::{editor_check, editor_page};\n pub use forum::{index, thread_feed_html, thread_post_expand, thread_post_view, thread_view};\n pub use garden::{garden_index, ontology_path};\n@@ -114,6 +114,8 @@ script { (maud::PreEscaped(r#\"\n });\n \n // Poem: intercept POST forms, send via fetch, await SSE for DOM update.\n+ // If the response body is non-empty HTML, morph the form's innerHTML with it\n+ // (used for inline feedback without a page reload, e.g. auth forms).\n document.addEventListener('submit', async (e) => {\n const f = e.target;\n if (!f || f.tagName !== 'FORM') return;\n@@ -121,14 +123,19 @@ script { (maud::PreEscaped(r#\"\n e.preventDefault();\n const btn = f.querySelector('button[type=\"submit\"], input[type=\"submit\"]');\n if (btn) { btn.disabled = true; btn.textContent = '…'; }\n- await fetch(f.action, {\n+ const resp = await fetch(f.action, {\n method: 'POST',\n body: new URLSearchParams(new FormData(f)),\n headers: { 'Content-Type': 'application/x-www-form-urlencoded' },\n credentials: 'same-origin',\n });\n- if (btn) { btn.disabled = false; btn.textContent = 'submit'; }\n- f.reset();\n+ const html = await resp.text();\n+ if (html && html.trim()) {\n+ Idiomorph.morph(f, html, {morphStyle: 'innerHTML'});\n+ } else {\n+ if (btn) { btn.disabled = false; btn.textContent = 'submit'; }\n+ f.reset();\n+ }\n });\n \n // Search: debounced fetch + idiomorph.\ndiff --git a/server/static/theme_default.css b/server/static/theme_default.css\nindex 9e71574da4bed3a0116c347610636780678bd1af..a1d8d1765a7812191edc579125facf1694554c2c 100644\n--- a/server/static/theme_default.css\n+++ b/server/static/theme_default.css\n@@ -250,6 +250,11 @@ p.auth-error {\n font-size: 12px;\n margin: 4px 0 0;\n }\n+p.auth-success {\n+ color: var(--signal);\n+ font-size: 13px;\n+ margin: 4px 0 0;\n+}\n \n /* ----------------------------------------------------------------\n BUTTONS — raised, press on :active\ndiff --git a/server/static/theme_retro.css b/server/static/theme_retro.css\nindex dc9fa4654f529eb1843557fb580cf3982da46901..8ed8fd88efab32b36bd66cf200aa182219b0a8b5 100644\n--- a/server/static/theme_retro.css\n+++ b/server/static/theme_retro.css\n@@ -32,6 +32,7 @@ input[type=\"text\"] {\n input[type=\"text\"]:focus { border-color: #00ff41; }\n p.auth-hint { color: #555; font-family: monospace; font-size: 0.75rem; margin: 0; }\n p.auth-error { color: #ff4444; font-family: monospace; font-size: 0.8rem; margin: 0; }\n+p.auth-success { color: #00ff41; font-family: monospace; font-size: 0.8rem; margin: 0; }\n \n /* Ingest form (poem pattern) */\n .ingest-form-wrap { margin-top: 1.5rem; }\n","role":"user"}],"model":"~anthropic/claude-sonnet-latest"}