You are a constitutional council ranking individual git commits for ownership allocation. Compare these two commits. Decide which contributed more lasting value to the project. Judge substance, not spectacle: - Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise. - Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one. - Do not favor a side merely because its patch is longer or noisier. - Weight what the change does for the project, not the contributor's name. Return ONLY a JSON object: {"winner": "A" or "B", "ratio": "N:M", "explanation": "..."} The explanation must cite concrete differences in the patches (1-3 sentences). Side A — contributor: tommy-mor Side A — commit message: [4e327784] deploy live constitution dashboard Expose auditable progress and event streaming, configure the production roots and runtime, and make tested main-branch commits the deployment authority. Co-authored-by: Cursor Side A — unified diff (full patch): diff --git a/.dockerignore b/.dockerignore new file mode 100644 index 0000000000000000000000000000000000000000..c9d63a722beba0a0297fc853089332c460ab78dd --- /dev/null +++ b/.dockerignore @@ -0,0 +1,7 @@ +.git +.venv +.hypothesis +__pycache__ +tests +*.json +*.bsp diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml new file mode 100644 index 0000000000000000000000000000000000000000..76dcdf82d53177c1e47d86b23a54523239d232a6 --- /dev/null +++ b/.github/workflows/deploy.yml @@ -0,0 +1,49 @@ +name: Test and deploy + +on: + push: + branches: [main] + +concurrency: + group: production + cancel-in-progress: false + +permissions: + contents: read + +jobs: + test: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - uses: astral-sh/setup-uv@v6 + with: + enable-cache: true + + - name: Run Python tests + run: uv run pytest -q + + - name: Install Babashka + run: | + curl -fsSL https://raw.githubusercontent.com/babashka/babashka/master/install \ + | sudo bash -s -- --dir /usr/local/bin + + - name: Run process integration tests + run: bb TEST.sh + + deploy: + needs: test + runs-on: ubuntu-latest + environment: + name: production + url: https://token.slug.social + steps: + - uses: actions/checkout@v4 + + - uses: superfly/flyctl-actions/setup-flyctl@master + + - name: Deploy to Fly + run: flyctl deploy --remote-only + env: + FLY_API_TOKEN: ${{ secrets.FLY_API_TOKEN }} diff --git a/Dockerfile b/Dockerfile new file mode 100644 index 0000000000000000000000000000000000000000..c9a5c00782371c19ad5ab5c58cf6f5a8ffec0141 --- /dev/null +++ b/Dockerfile @@ -0,0 +1,17 @@ +FROM ghcr.io/astral-sh/uv:python3.11-bookworm-slim + +RUN apt-get update \ + && apt-get install -y --no-install-recommends git ca-certificates \ + && rm -rf /var/lib/apt/lists/* + +WORKDIR /app +COPY pyproject.toml uv.lock ./ +RUN uv sync --frozen --no-install-project + +COPY constitution.py ./ + +ENV PATH="/app/.venv/bin:${PATH}" \ + PYTHONUNBUFFERED="1" + +EXPOSE 8080 +CMD ["python", "constitution.py"] diff --git a/constitution.py b/constitution.py index 4bee9f83663ab7fb36db95129b92b64b4ef57258..a58257e1881b21d1d6fa8e68a3faa222e4f661ef 100644 --- a/constitution.py +++ b/constitution.py @@ -24,12 +24,12 @@ A daily GitHub Action backs up the JSONL ledger to the same repo. Run: uv run constitution.py """ -from decimal import Decimal, getcontext +from decimal import Decimal, getcontext, DefaultContext from datetime import datetime, timezone from fastapi import FastAPI, Request, Response from fastapi.responses import PlainTextResponse, HTMLResponse from starlette.middleware.sessions import SessionMiddleware -import json, time, os, asyncio, httpx, pathlib, subprocess, hashlib, re, fcntl +import json, time, os, asyncio, httpx, pathlib, subprocess, hashlib, re, fcntl, base64 import sympy as sp # type: ignore[reportMissingImports] from tenacity import retry, retry_if_exception, stop_after_attempt, wait_exponential from evaleval import ( @@ -37,6 +37,7 @@ from evaleval import ( exec_event, One, Two, Three, Selector, MORPH, PREPEND, ) +DefaultContext.prec = 50 getcontext().prec = 50 app = FastAPI() @@ -129,14 +130,47 @@ OPENROUTER_BASE_URL = os.environ.get("OPENROUTER_BASE_URL", "https://openrouter. # using the exact same source; their normalized values are committed to every # discovery event. DEFAULT_REPOSITORIES = [ + { + "id": "constitution", + "url": "https://github.com/sortersocial/constitution.git", + "refs": ["refs/heads/**"], + }, { "id": "slug", - "url": "https://github.com/tommy-mor/slug.git", + "url": "https://github.com/sortersocial/slug.git", + "refs": ["refs/heads/**"], + }, + { + "id": "sorter", + "url": "https://github.com/sorterisntonline/sorter.git", + "refs": ["refs/heads/**"], + }, + { + "id": "sorter2", + "url": "https://github.com/sortersocial/sorter2.git", + "refs": ["refs/heads/**"], + }, + { + "id": "sorter-oldest", + "url": "https://github.com/tommy-mor/sorter.git", "refs": ["refs/heads/**"], }, ] DEFAULT_CONTRIBUTORS = { "tommy-mor": ["thmorriss@gmail.com"], + "christopher-whitman": [ + "chris@cwwhitman.com", + "7566903+cwwhitman@users.noreply.github.com", + ], + "jake-chvatal": [ + "jake+github@uln.industries", + "jakechvatal@gmail.com", + "jake@isnt.online", + ], + "lara": ["me@lara.lv"], + "nat-reid": ["nathanielreid@gmail.com"], + "zod": ["jason.p.mcel@gmail.com", "me@zod.tf"], + "jovan": ["jovan@slug.social", "jovan@getcivicai.com"], } REPOSITORIES = json.loads( @@ -147,6 +181,7 @@ CONTRIBUTORS = json.loads( ) GIT_MIRROR_DIR = pathlib.Path(os.environ.get("GIT_MIRROR_DIR", "/data/git")) GIT_TIMEOUT_SECONDS = int(os.environ.get("GIT_TIMEOUT_SECONDS", "120")) +GITHUB_TOKEN = os.environ.get("GITHUB_TOKEN", "") # Council model IDs: slug.social garden rank under this parent (bodies = OpenRouter URLs), then top-up from OpenRouter list. SLUG_SOCIAL_BASE_URL = os.environ.get("SLUG_SOCIAL_BASE_URL", "https://slug.social").rstrip("/") @@ -661,20 +696,30 @@ def _git(repo: pathlib.Path | None, *args: str, input_bytes: bytes | None = None if repo is not None: command += ["-C", str(repo)] command += list(args) + git_env = { + **os.environ, + "GIT_CONFIG_NOSYSTEM": "1", + "GIT_CONFIG_GLOBAL": os.devnull, + "GIT_NO_REPLACE_OBJECTS": "1", + "LC_ALL": "C", + "TZ": "UTC", + } + if GITHUB_TOKEN: + credential = base64.b64encode( + f"x-access-token:{GITHUB_TOKEN}".encode() + ).decode() + git_env.update({ + "GIT_CONFIG_COUNT": "1", + "GIT_CONFIG_KEY_0": "http.https://github.com/.extraHeader", + "GIT_CONFIG_VALUE_0": f"Authorization: Basic {credential}", + }) try: result = subprocess.run( command, input=input_bytes, stdout=subprocess.PIPE, stderr=subprocess.PIPE, - env={ - **os.environ, - "GIT_CONFIG_NOSYSTEM": "1", - "GIT_CONFIG_GLOBAL": os.devnull, - "GIT_NO_REPLACE_OBJECTS": "1", - "LC_ALL": "C", - "TZ": "UTC", - }, + env=git_env, timeout=GIT_TIMEOUT_SECONDS, check=False, ) @@ -844,9 +889,15 @@ def _build_discovery(epoch_n: int, boundary_ms: int, events: list) -> GitDiscove canonical_location = min( locations[qualified_oid], key=lambda x: (x[0], x[1]) ) + # One commit may be reachable from dozens of refs in the same mirror. + # Verify its object once per repository, not once per source ref. + object_locations = { + (str(m), raw_oid): (m, raw_oid) + for _, _, m, raw_oid in locations[qualified_oid] + } object_hashes = { hashlib.sha256(_git(m, "cat-file", "commit", raw_oid)).hexdigest() - for _, _, m, raw_oid in locations[qualified_oid] + for m, raw_oid in object_locations.values() } if len(object_hashes) != 1: raise RuntimeError(f"conflicting Git objects share OID {qualified_oid}") @@ -994,11 +1045,55 @@ async def discover_repositories(epoch_n: int, boundary_ms: int) -> GitDiscovery: SSE_CLIENTS = [] +AUDIT_HISTORY = [] +AUDIT_SEQUENCE = 0 +PROCESS_STATE = { + "running": False, + "phase": "idle", + "progress": 100, + "message": "Waiting for the next epoch", +} + + +def _sse_event(event_name: str, payload: dict) -> str: + return ( + f"event: {event_name}\n" + f"data: {json.dumps(payload, separators=(',', ':'))}\n\n" + ) + + +async def broadcast_audit( + kind: str, + message: str, + *, + progress: int | None = None, + phase: str | None = None, +) -> dict: + global AUDIT_SEQUENCE + AUDIT_SEQUENCE += 1 + if progress is not None: + PROCESS_STATE["progress"] = max(0, min(100, int(progress))) + if phase is not None: + PROCESS_STATE["phase"] = phase + PROCESS_STATE["message"] = message + payload = { + "id": AUDIT_SEQUENCE, + "timestamp_ms": int(time.time() * 1000), + "kind": kind, + "message": message, + **PROCESS_STATE, + } + AUDIT_HISTORY.append(payload) + del AUDIT_HISTORY[:-200] + wire = _sse_event("audit", payload) + for queue in list(SSE_CLIENTS): + await queue.put(wire) + return payload async def broadcast_js(js: str): """Send a JS snippet to all connected SSE clients.""" - for queue in SSE_CLIENTS: + for queue in list(SSE_CLIENTS): await queue.put(js) @@ -1006,10 +1101,29 @@ async def rank_commits(commits: list[dict]): if not commits: return {}, [] - models = await fetch_top_models(n=3) contributors = sorted(set(c["contributor"] for c in commits)) - if len(contributors) > 1 and not models: + if len(contributors) == 1: + await broadcast_audit( + "ranking", + f"Only {contributors[0]} is eligible; rank is 1.0", + progress=90, + phase="finalizing", + ) + return {contributors[0]: Decimal("1")}, [] + if not (OPENROUTER_API_KEY or "").strip(): + raise RuntimeError( + "OPENROUTER_API_KEY is required when multiple contributors need ranking" + ) + + models = await fetch_top_models(n=3) + if not models: raise RuntimeError("no council models available for contributor ranking") + await broadcast_audit( + "council", + f"Council selected: {', '.join(models)}", + progress=35, + phase="ranking", + ) await broadcast_js(exec_event(Three[Selector("#emission-log")][PREPEND][ ["div.log-council", f"Council: {', '.join(models)} — {len(commits)} commits"] ])) @@ -1035,6 +1149,11 @@ async def rank_commits(commits: list[dict]): async def compare_fn(i, j): a1, a2 = authors[i], authors[j] + await broadcast_audit( + "comparison", + f"Comparing {a1} with {a2}", + phase="ranking", + ) await broadcast_js(exec_event(Three[Selector("#emission-status")][MORPH][ ["div#emission-status", f"Comparing {a1} vs {a2}…"] ])) @@ -1050,6 +1169,11 @@ async def rank_commits(commits: list[dict]): if winner_weight <= 0 or loser_weight <= 0: raise ValueError("ratio weights must be positive") results.append((w, l, winner_weight, loser_weight)) + await broadcast_audit( + "vote", + f"{model}: {authors[w]} over {authors[l]} ({result['ratio']})", + phase="ranking", + ) await broadcast_js(exec_event(Three[Selector("#emission-log")][PREPEND][ ["div.log-vote", ["span.model", model], " — ", @@ -1059,6 +1183,11 @@ async def rank_commits(commits: list[dict]): ] ])) except Exception as e: + await broadcast_audit( + "error", + f"{model} failed: {e}", + phase="error", + ) await broadcast_js(exec_event(Three[Selector("#emission-log")][PREPEND][ ["div.log-error", f"⚠ {model}: {e}"] ])) @@ -1068,8 +1197,13 @@ async def rank_commits(commits: list[dict]): async def progress_fn(ev): if ev["phase"] == "spanning_tree": label = f"Spanning tree: {ev['step']}/{ev['total']}" + percent = 35 + round(35 * ev["step"] / max(ev["total"], 1)) else: label = f"Zip pass {ev['pass']}: {ev['step']}/{ev['total']}" + percent = 70 + round(20 * ev["step"] / max(ev["total"], 1)) + await broadcast_audit( + "progress", label, progress=percent, phase="ranking" + ) await broadcast_js(exec_event(Three[Selector("#emission-status")][MORPH][ ["div#emission-status", label] ])) @@ -1083,6 +1217,12 @@ async def rank_commits(commits: list[dict]): scores = rank_centrality(pairs) ranking = {authors[i]: Decimal(str(scores[i])) for i in range(len(authors))} ranking_rows = sorted(ranking.items(), key=lambda x: x[1], reverse=True) + await broadcast_audit( + "ranking", + "Ranking: " + ", ".join(f"{a} {s:.4f}" for a, s in ranking_rows), + progress=90, + phase="finalizing", + ) await broadcast_js(exec_event(Three[Selector("#emission-log")][PREPEND][ ["div.log-ranking", ["b", "Ranking: "], @@ -1104,11 +1244,33 @@ def pool_remaining(events: list) -> Decimal: async def run_emission(epoch_n, boundary_ms): + PROCESS_STATE["running"] = True + await broadcast_audit( + "start", + f"Epoch {epoch_n} emission started", + progress=2, + phase="starting", + ) await broadcast_js(exec_event(Three[Selector("#emission-log")][PREPEND][ ["div.log-start", f"⚡ Epoch {epoch_n} emission started"] ])) + await broadcast_audit( + "discovery", + "Fetching configured repositories and snapshotting refs", + progress=8, + phase="discovery", + ) discovery = await discover_repositories(epoch_n, boundary_ms) + await broadcast_audit( + "discovery", + ( + f"Discovered {len(discovery.observations)} new commits; " + f"{len(discovery.commits)} are eligible" + ), + progress=30, + phase="discovery", + ) ranking, models = await rank_commits(discovery.commits) def make_emission(events): @@ -1146,6 +1308,13 @@ async def run_emission(epoch_n, boundary_ms): entry = await store.atomic(make_emission) if entry: + PROCESS_STATE["running"] = False + await broadcast_audit( + "complete", + f"Epoch {entry.epoch} complete; emitted {entry.total_emitted} SLG", + progress=100, + phase="idle", + ) await broadcast_js(exec_event(Three[Selector("#emission-log")][PREPEND][ ["div.log-amount", f"Pool {entry.pool_before} → emit {entry.total_emitted} → {entry.pool_after}"] @@ -1189,13 +1358,24 @@ async def distribute_usdc(holdings, treasury_balance): async def epoch_loop(): while True: epoch_n, current_start, next_boundary = current_epoch() + processed = {e.epoch for e in store.read() if isinstance(e, Emission)} + if epoch_n >= 0 and epoch_n not in processed: + try: + await run_emission(epoch_n, current_start) + except Exception as exc: + PROCESS_STATE["running"] = False + await broadcast_audit( + "error", + f"Epoch {epoch_n} failed: {exc}; retrying in 60 seconds", + phase="error", + ) + print(f"epoch {epoch_n} emission failed: {exc}", flush=True) + await asyncio.sleep(60) + continue + now = int(time.time() * 1000) wait_ms = next_boundary - now - if wait_ms <= 0: - processed = {e.epoch for e in store.read() if isinstance(e, Emission)} - if epoch_n not in processed and epoch_n >= 0: - await run_emission(epoch_n, current_start) await asyncio.sleep(60) elif wait_ms < 86_400_000: await broadcast_js(exec_event(Three[Selector("#emission-status")][MORPH][ @@ -1243,6 +1423,36 @@ async def get_ranking(): return {"ranking": latest.ranking, "epoch": latest.epoch} +@app.get("/api/status") +async def get_status(): + events = store.read() + discoveries = [e for e in events if isinstance(e, GitDiscovery)] + emissions = [e for e in events if isinstance(e, Emission)] + return { + **PROCESS_STATE, + "epoch": current_epoch()[0], + "openrouter_configured": bool((OPENROUTER_API_KEY or "").strip()), + "sse_clients": len(SSE_CLIENTS), + "latest_discovery": ( + { + "epoch": discoveries[-1].epoch, + "snapshot_id": discoveries[-1].snapshot_id, + "observations": len(discoveries[-1].observations), + "eligible_commits": len(discoveries[-1].commits), + } + if discoveries else None + ), + "latest_emission": ( + { + "epoch": emissions[-1].epoch, + "total_emitted": emissions[-1].total_emitted, + "ranking": emissions[-1].ranking, + } + if emissions else None + ), + } + + @app.get("/api/contributor/{github_username}") async def get_contributor(github_username: str): history = [ @@ -1306,13 +1516,6 @@ async def test_emit(): # =========================================================================== # §9. SSE — live audit stream of the pairwise voting process -# -# TODO: the /sse emission audit page needs a real SSE-driven UI. votes arrive -# incrementally during rank_commits(), and the client should show a live -# progress bar and per-vote results as they stream in. this requires a -# dedicated page that connects to /sse and updates the DOM on each event -# (council, comparing, vote, ranking, emission_complete). defer until we -# have playwright tests to cover it — the incremental rendering is fiddly. # =========================================================================== @app.get("/sse") @@ -1322,6 +1525,13 @@ async def sse_stream(request: Request): async def generate(): try: + yield _sse_event("audit", { + "id": AUDIT_SEQUENCE, + "timestamp_ms": int(time.time() * 1000), + "kind": "connection", + "message": f"Connected to epoch {current_epoch()[0]}", + **PROCESS_STATE, + }) yield exec_event(Three[Selector("#emission-status")][MORPH][ ["div#emission-status", f"Connected — epoch {current_epoch()[0]}"] ]) @@ -1334,10 +1544,15 @@ async def sse_stream(request: Request): except asyncio.TimeoutError: yield ": keepalive\n\n" finally: - SSE_CLIENTS.remove(queue) + if queue in SSE_CLIENTS: + SSE_CLIENTS.remove(queue) from starlette.responses import StreamingResponse - return StreamingResponse(generate(), media_type="text/event-stream") + return StreamingResponse( + generate(), + media_type="text/event-stream", + headers={"Cache-Control": "no-cache", "X-Accel-Buffering": "no"}, + ) # =========================================================================== @@ -1359,6 +1574,7 @@ def _page(title: str, body: list) -> HTMLResponse: ["meta", {"charset": "utf-8"}], ["meta", {"name": "viewport", "content": "width=device-width, initial-scale=1"}], ["title", title], + ["style", RawContent(_WATCH_CSS)], ], ["body", body, @@ -1367,6 +1583,387 @@ def _page(title: str, body: list) -> HTMLResponse: ])) +_WATCH_CSS = """ +/* ================================================================ + ZIGGURAT — bevel-first dark theme + --spread (0→1) controls bevel depth. 0 = flat. 1 = full relief. + Light source: top-left. Shadow: bottom-right. + Platforms nest. Each level is raised. Nothing is rounded. + ================================================================ */ + +:root { + color-scheme: dark; + --spread: 1; + + --g0: #080808; + --g1: #131313; + --g2: #1c1c1c; + --g3: #252525; + --g4: #2e2e2e; + --g5: #383838; + + --hi: #5e5e5e; + --lo: #050505; + --bv: calc(var(--spread) * 4px + 1px); + --bv-lg: calc(var(--spread) * 6px + 2px); + + --signal: #f0f0f0; + --prose: #c2c2c2; + --ui: #888; + --meta: #4a4a4a; + --link: #8899ee; + --code-fg: #c8dda0; + + --font-prose: "Iowan Old Style", "Palatino Linotype", Palatino, "Book Antiqua", Georgia, serif; + --font-ui: system-ui, -apple-system, sans-serif; + --font-code: ui-monospace, "Cascadia Code", "SF Mono", Menlo, monospace; +} + +*, *::before, *::after { box-sizing: border-box; } +html, body { margin: 0; padding: 0; } + +body { + background: var(--g0); + color: var(--prose); + font-family: var(--font-ui); + font-size: 14px; + line-height: 1.6; + margin: 0 auto; + max-width: 560px; + min-height: 100vh; + padding: 0 16px 48px; +} +main { width: 100%; padding: 18px 0 48px; } + +h1, h2, h3 { + color: var(--signal); + font-size: 11px; + font-weight: bold; + letter-spacing: 0.12em; + margin: 14px 0 6px; + text-transform: uppercase; +} +a { color: var(--link); text-decoration: none; } +a:hover { color: var(--signal); } +.eyebrow { + background: var(--g2); + border: var(--bv) solid; + border-color: var(--hi) var(--lo) var(--lo) var(--hi); + color: var(--ui); + font-size: 11px; + letter-spacing: 0.12em; + padding: 4px 10px; + text-transform: uppercase; + width: fit-content; +} + +/* Every dashboard section is a raised platform. */ +.panel { + background: var(--g2); + border: var(--bv-lg) solid; + border-color: var(--hi) var(--lo) var(--lo) var(--hi); + margin: 8px 0; + padding: 10px; + width: 100%; +} +.status-row { + align-items: center; + display: flex; + flex-wrap: wrap; + gap: 8px; + justify-content: space-between; +} +#process-status { color: var(--signal); font-family: var(--font-code); font-weight: bold; } +.badge { + align-items: center; + background: var(--g3); + border: var(--bv) solid; + border-color: var(--hi) var(--lo) var(--lo) var(--hi); + color: var(--ui); + display: inline-flex; + font-size: 11px; + gap: 7px; + padding: 3px 8px; +} +.dot { background: var(--meta); height: 8px; width: 8px; } +.live .dot { background: #7acc7a; } +.warn .dot { background: #cc9955; } + +/* The progress track is inset; its signal is raised inside it. */ +.progress-shell { + background: var(--g1); + border: var(--bv-lg) solid; + border-color: var(--lo) var(--hi) var(--hi) var(--lo); + height: 58px; + margin: 14px 0 10px; + overflow: hidden; + position: relative; +} +#progress-fill { + background: var(--link); + border: var(--bv) solid; + border-color: var(--hi) var(--lo) var(--lo) var(--hi); + height: 100%; + transition: width .35s steps(8, end); + width: 0; +} +#progress-label { + color: var(--signal); + display: grid; + font-family: var(--font-code); + font-size: 18px; + font-weight: bold; + inset: 0; + place-items: center; + position: absolute; + text-shadow: 1px 1px var(--lo); +} + +.controls { align-items: center; display: flex; flex-wrap: wrap; gap: 8px; } +button { + background: var(--g5); + border: var(--bv) solid; + border-color: var(--hi) var(--lo) var(--lo) var(--hi); + color: var(--signal); + cursor: pointer; + font: inherit; + font-size: 12px; + padding: 4px 10px; +} +button:hover { background: #404040; } +button:active { + background: var(--g4); + border-color: var(--lo) var(--hi) var(--hi) var(--lo); + transform: translate(1px, 1px); +} +button:disabled { cursor: default; opacity: .4; } +.note { color: var(--meta); font-size: 11px; margin: 4px 0; } + +.feed-head { align-items: baseline; display: flex; justify-content: space-between; } +#audit-feed { + background: var(--g1); + border: var(--bv) solid; + border-color: var(--lo) var(--hi) var(--hi) var(--lo); + display: flex; + flex-direction: column; + gap: 5px; + margin-top: 8px; + padding: 6px; +} +.event { + background: var(--g3); + border: var(--bv) solid; + border-color: var(--hi) var(--lo) var(--lo) var(--hi); + display: grid; + gap: 6px; + grid-template-columns: 82px 88px 1fr; + padding: 5px 8px; +} +.event[data-kind="error"] { border-left-color: #cc5555; } +.event[data-kind="complete"], .event[data-kind="ranking"] { border-left-color: #7acc7a; } +.event[data-kind="vote"] { border-left-color: var(--link); } +.event time, .event-kind { color: var(--meta); font-family: var(--font-code); font-size: 10px; } +.event-kind { text-transform: uppercase; } +.event-message { color: var(--prose); font-family: var(--font-prose); } + +code { + background: var(--g1); + border: 2px solid; + border-color: var(--lo) var(--hi) var(--hi) var(--lo); + color: var(--code-fg); + font-family: var(--font-code); + font-size: 12px; + padding: 1px 4px; +} + +@media (max-width: 520px) { + .event { grid-template-columns: 72px 1fr; } + .event-message { grid-column: 1 / -1; } +} +""" + + +def _watch_initial_state() -> dict: + events = store.read() + feed = [] + for event_ in events[-40:]: + if isinstance(event_, GitDiscovery): + feed.append({ + "id": f"discovery-{event_.snapshot_id}", + "timestamp_ms": event_.timestamp_ms, + "kind": "discovery", + "message": ( + f"Epoch {event_.epoch}: observed {len(event_.observations)} commits; " + f"{len(event_.commits)} eligible" + ), + }) + elif isinstance(event_, Emission): + feed.append({ + "id": f"emission-{event_.epoch}", + "timestamp_ms": event_.timestamp_ms, + "kind": "complete", + "message": ( + f"Epoch {event_.epoch}: emitted {event_.total_emitted} SLG; " + f"ranking {event_.ranking}" + ), + }) + feed.extend(AUDIT_HISTORY) + return { + "process": dict(PROCESS_STATE), + "openrouter_configured": bool((OPENROUTER_API_KEY or "").strip()), + "epoch": current_epoch()[0], + "feed": feed[-200:], + } + + +_WATCH_JS = """ +const initial = __INITIAL__; +const feed = document.querySelector('#audit-feed'); +const processStatus = document.querySelector('#process-status'); +const connection = document.querySelector('#connection-status'); +const fill = document.querySelector('#progress-fill'); +const progressLabel = document.querySelector('#progress-label'); +const play = document.querySelector('#play'); +const pause = document.querySelector('#pause'); +const seen = new Set(); +let source = null; + +function setProgress(value) { + const n = Math.max(0, Math.min(100, Number(value ?? 0))); + fill.style.width = `${n}%`; + progressLabel.textContent = `${Math.round(n)}%`; + document.querySelector('.progress-shell').setAttribute('aria-valuenow', String(n)); +} + +function addEvent(event) { + const id = String(event.id); + if (seen.has(id)) return; + seen.add(id); + const row = document.createElement('div'); + row.className = 'event'; + row.dataset.kind = event.kind || 'event'; + const when = document.createElement('time'); + when.dateTime = new Date(event.timestamp_ms).toISOString(); + when.textContent = new Date(event.timestamp_ms).toLocaleTimeString(); + const kind = document.createElement('span'); + kind.className = 'event-kind'; + kind.textContent = event.kind || 'event'; + const message = document.createElement('span'); + message.className = 'event-message'; + message.textContent = event.message; + row.append(when, kind, message); + feed.prepend(row); + while (feed.children.length > 200) feed.lastElementChild.remove(); +} + +function applyState(event) { + processStatus.textContent = event.message || 'Waiting for the next epoch'; + setProgress(event.progress); + if (event.kind !== 'connection') addEvent(event); +} + +function connect() { + if (source) return; + source = new EventSource('/sse'); + connection.classList.remove('warn'); + connection.classList.add('live'); + connection.querySelector('span:last-child').textContent = 'connecting'; + play.disabled = true; + pause.disabled = false; + source.onopen = () => { + connection.querySelector('span:last-child').textContent = 'live'; + }; + source.addEventListener('audit', event => applyState(JSON.parse(event.data))); + source.onerror = () => { + connection.classList.remove('live'); + connection.classList.add('warn'); + connection.querySelector('span:last-child').textContent = 'reconnecting'; + }; +} + +function disconnect() { + if (source) source.close(); + source = null; + connection.classList.remove('live'); + connection.classList.add('warn'); + connection.querySelector('span:last-child').textContent = 'paused locally'; + play.disabled = false; + pause.disabled = true; +} + +play.addEventListener('click', connect); +pause.addEventListener('click', disconnect); +initial.feed.forEach(addEvent); +processStatus.textContent = initial.process.message; +setProgress(initial.process.progress); +connect(); +""" + + +@app.get("/watch") +async def watch(): + initial = json.dumps( + _watch_initial_state(), separators=(",", ":") + ).replace(" 0") - ;; 9. SSE connects and sends initial event + ;; 9. watch UI exposes progress, controls, readiness, and live SSE + (println "\nchecking /watch UI…") + (bind watch-html (slurp (str base-url "/watch"))) + (assert! (str/includes? watch-html "role=\"progressbar\"") + "watch page has progress bar") + (assert! (str/includes? watch-html "id=\"play\"") + "watch page has play control") + (assert! (str/includes? watch-html "id=\"pause\"") + "watch page has pause control") + (assert! (str/includes? watch-html "OpenRouter configured") + "watch page reports council readiness") + (bind status-resp (get-json base-url "/api/status")) + (assert! (true? (:openrouter_configured status-resp)) + "status API reports OpenRouter configuration") + + ;; 10. SSE connects and sends initial event (println "\nchecking /sse initial event…") (bind sse-events (read-sse-events (str base-url "/sse") 1 5000)) (assert! (= 1 (count sse-events)) "received 1 SSE event") (assert! (not (str/blank? (first sse-events))) "initial SSE event contains executable audit data") - ;; 10. POST /test/emit — full ranking pipeline hits mocks + ;; 11. POST /test/emit — full ranking pipeline hits mocks (println "\ntriggering /test/emit (epoch 1)…") (bind emit-resp (post-json! base-url "/test/emit")) (assert! (= "emission" (:type emit-resp)) "emit response type is emission") @@ -503,7 +518,7 @@ (bind rank-after (get-json base-url "/api/ranking")) (assert! (= 1 (:epoch rank-after)) "latest ranking is epoch 1") - ;; 11. kill and restart — prove replay determinism + ;; 12. kill and restart — prove replay determinism (println "\nkilling server for replay test…") (.destroyForcibly (:proc server)) (deref server) diff --git a/tests/test_git_discovery.py b/tests/test_git_discovery.py index 0dd31bc42a19bc8c59842dc61f193c595c474659..5a9e167e16ad2ffb25988af85820f6f19e8910cd 100644 --- a/tests/test_git_discovery.py +++ b/tests/test_git_discovery.py @@ -393,7 +393,9 @@ def test_empty_epoch_records_zero_emission_without_burning_pool( monkeypatch.setattr(c, "store", c.JsonlStore(discovery_config / "ledger.jsonl")) async def discover(_epoch, _boundary): - return SimpleNamespace(commits=[], snapshot_id="empty-snapshot") + return SimpleNamespace( + observations=[], commits=[], snapshot_id="empty-snapshot" + ) async def rank(_commits): return {}, [] @@ -412,7 +414,11 @@ def test_emission_distribution_sums_exactly_to_total( monkeypatch.setattr(c, "store", c.JsonlStore(discovery_config / "ledger.jsonl")) async def discover(_epoch, _boundary): - return SimpleNamespace(commits=[{"x": 1}], snapshot_id="ranked-snapshot") + return SimpleNamespace( + observations=[{"x": 1}], + commits=[{"x": 1}], + snapshot_id="ranked-snapshot", + ) async def rank(_commits): return { @@ -454,6 +460,7 @@ def test_any_council_failure_aborts_ranking(monkeypatch): monkeypatch.setattr(c, "fetch_top_models", models) monkeypatch.setattr(c, "llm_pairwise_compare", compare) + monkeypatch.setattr(c, "OPENROUTER_API_KEY", "test-key") commits = [ { "contributor": contributor, @@ -465,3 +472,54 @@ def test_any_council_failure_aborts_ranking(monkeypatch): ] with pytest.raises(RuntimeError, match="council model failed"): asyncio.run(c.rank_commits(commits)) + + +def test_contested_ranking_requires_openrouter_key(monkeypatch): + monkeypatch.setattr(c, "OPENROUTER_API_KEY", "") + commits = [ + { + "contributor": contributor, + "oid": "sha1:" + char * 40, + "message": contributor, + "patch": "patch", + } + for contributor, char in [("alice", "a"), ("bob", "b")] + ] + with pytest.raises(RuntimeError, match="OPENROUTER_API_KEY"): + asyncio.run(c.rank_commits(commits)) + + +def test_watch_page_has_live_controls_progress_and_key_warning( + discovery_config, monkeypatch +): + monkeypatch.setattr(c, "store", c.JsonlStore(discovery_config / "ledger.jsonl")) + monkeypatch.setattr(c, "OPENROUTER_API_KEY", "") + monkeypatch.setattr(c, "current_epoch", lambda: (3, 0, 1)) + response = asyncio.run(c.watch()) + html = response.body.decode() + assert 'role="progressbar"' in html + assert 'id="play"' in html + assert 'id="pause"' in html + assert "new EventSource('/sse')" in html + assert "OpenRouter key missing" in html + + +def test_audit_events_are_json_sse_and_update_process_state(monkeypatch): + clients = [] + history = [] + monkeypatch.setattr(c, "SSE_CLIENTS", clients) + monkeypatch.setattr(c, "AUDIT_HISTORY", history) + queue = asyncio.Queue() + clients.append(queue) + + async def emit(): + event = await c.broadcast_audit( + "progress", "halfway", progress=50, phase="ranking" + ) + return event, await queue.get() + + event, wire = asyncio.run(emit()) + assert event["progress"] == 50 + assert event["phase"] == "ranking" + assert wire.startswith("event: audit\ndata: {") + assert '"message":"halfway"' in wire Side B — contributor: tommy-mor Side B — commit message: [80ad7753] refactor: split canonical_path and identity; strict wire identity without @ - Add canonical_path.rs (tag + item URL normalization) and identity.rs (parse_username/parse_agent; reject @ in API input). - Slim events.rs to event types only; reducer applies no identity rewriting. - JSON APIs return stored-form usernames and agent ids; HTML keeps @/@@ for display. - Optional delegate on ingest; CLI and tests use naked uuid:rig:model. Made-with: Cursor Side B — unified diff (full patch): diff --git a/cli/src/main.rs b/cli/src/main.rs index 5ac8e289f2b7a366b5959d9338d02f9b546f408a..630c5dea1f78c0ec9bc53e6b96234a0dc75bb705 100644 --- a/cli/src/main.rs +++ b/cli/src/main.rs @@ -61,8 +61,8 @@ enum Command { /// Example: --before 2026-06-01 #[arg(long, value_name = "DATE_OR_MS")] before: Option, - /// Filter to posts from this actor (UUID prefix match). - /// Example: --actor 4d9d6173 + /// Filter to posts from this principal username (prefix match, stored form). + /// Example: --actor alice #[arg(long, value_name = "PREFIX")] actor: Option, /// Fetch a single post by its ingest ID (from --json output). @@ -75,9 +75,8 @@ enum Command { /// /// SYNTAX: /// - /// Actor (required, once per document): - /// @:: - /// Example: @7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet + /// Identity: human comes from the bearer token; optional AI delegate from `--delegate` + /// (`uuid:rig:provider/model`). The document body is DSL only (items, votes, prose) — no `@` lines. /// /// Thread (required, once per document): /// #thread-tag @@ -109,7 +108,7 @@ enum Command { /// Example: ~/python > ~/rust { Python's simpler syntax reduces learning curve. } /// /// Prose (optional, anywhere): - /// Any line that doesn't start with @, #, or ~ is prose. + /// Any line that doesn't start with # or ~ (or `http`) is prose. /// Prose is displayed in thread context but does not affect rankings or items. /// Use prose to write blog posts, reasoning, or notes within your ingest. /// @@ -125,8 +124,7 @@ enum Command { /// EXAMPLES: /// /// # From heredoc (recommended for agents) - /// npx slugsocial ingest << 'EOF' - /// @7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet + /// npx slugsocial ingest --delegate '7a3b9c2d-1234-5678-90ab-cdef12345678:claudecode:anthropic/claude-sonnet' << 'EOF' /// #languages: Python vs Rust for systems programming /// /// ~/languages/python { A high-level language with simple syntax and rich ecosystem. } @@ -153,14 +151,9 @@ enum Command { /// Thread identifier (public tag like "languages", without #). #[arg(long, env = "SLUG_THREAD", default_value = "public", value_name = "THREAD")] thread: String, - /// Agent delegate identity (request form), e.g. @@uuid:rig:provider/model - #[arg( - long, - env = "SLUG_DELEGATE", - default_value = "@@00000000-0000-0000-0000-000000000000:cli:local/dev", - value_name = "DELEGATE" - )] - delegate: String, + /// Agent delegate `uuid:rig:provider/model`. Omit for human-only ingests. + #[arg(long, env = "SLUG_DELEGATE", value_name = "DELEGATE")] + delegate: Option, /// Output as JSON for agent parsing #[arg(long)] json: bool, @@ -174,14 +167,9 @@ enum Command { /// Thread identifier (public tag like "languages", without #). #[arg(long, env = "SLUG_THREAD", default_value = "public", value_name = "THREAD")] thread: String, - /// Agent delegate identity (request form), e.g. @@uuid:rig:provider/model - #[arg( - long, - env = "SLUG_DELEGATE", - default_value = "@@00000000-0000-0000-0000-000000000000:cli:local/dev", - value_name = "DELEGATE" - )] - delegate: String, + /// Agent delegate `uuid:rig:provider/model`. Omit for human-only ingests. + #[arg(long, env = "SLUG_DELEGATE", value_name = "DELEGATE")] + delegate: Option, /// Output as JSON for agent parsing #[arg(long)] json: bool, @@ -193,10 +181,10 @@ enum Command { /// Useful for agents to catch up on activity after a context reset. /// /// Examples: - /// npx slugsocial feed @:: - /// npx slugsocial feed @:: --since 2026-01-01 + /// npx slugsocial feed tommy + /// npx slugsocial feed tommy --since 2026-01-01 Feed { - /// Actor identifier (@uuid:rig:model) + /// Principal username (stored form) #[arg(value_name = "ACTOR")] actor: String, /// Override the lower bound. Accepts Unix ms or YYYY-MM-DD. @@ -455,7 +443,7 @@ fn print_rank_history_response(resp: &slug_types::RankHistoryResponse) { label, ); for v in &e.caused_by { - println!(" {} {} {} {}", v.a, v.ratio, v.b, v.actor.as_deref().map(|a| format!(" (@{})", a)).unwrap_or_default()); + println!(" {} {} {} {}", v.a, v.ratio, v.b, v.actor.as_deref().map(|a| format!(" ({})", a)).unwrap_or_default()); if !v.body.is_empty() { println!(" {}", v.body.lines().next().unwrap_or(&v.body).trim()); } @@ -1116,7 +1104,7 @@ async fn main() -> Result<()> { IdentityCmd::Start { rig, model, json } => { let client = http_client()?; let uuid = uuid::Uuid::new_v4().to_string(); - let delegate = format!("@@{}:{}:{}", uuid, rig, model); + let delegate = format!("{uuid}:{rig}:{model}"); let start: PendingSessionStartResponse = expect_json( client diff --git a/server/src/api/auth.rs b/server/src/api/auth.rs index cb0faa29b834931e2c2b2f5c174c875e2e2e9346..995ce4a61d29b024c399c656134f541ecfd880cf 100644 --- a/server/src/api/auth.rs +++ b/server/src/api/auth.rs @@ -12,10 +12,8 @@ use tokio::sync::RwLock; use crate::{ api::helpers::{api_error, now_ms, sha256_hex}, - events::{ - canonicalize_username, validate_agent_format, validate_username, - Event, TokenIssued, UserRegistered, - }, + events::{Event, TokenIssued, UserRegistered}, + identity::{parse_agent, parse_username}, html::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page}, state::{AppState, PendingSession}, }; @@ -77,9 +75,9 @@ fn verify_token(reduced: &crate::reducer::ReducerState, bearer: &str) -> Result< Ok(username) } -fn issue_token_for_user(username: &str) -> (String, TokenIssued, String) { - // Returns: (bearer, event, canonical_username) - let canonical_user = canonicalize_username(username); +/// `stored_username` must already be in persisted shape (lowercase slug, no `@`). +fn issue_token_for_user(stored_username: &str) -> (String, TokenIssued) { + let username = stored_username.to_string(); let token_id = { let mut id = String::new(); let alphabet = b"abcdefghijklmnopqrstuvwxyz0123456789"; @@ -103,13 +101,13 @@ fn issue_token_for_user(username: &str) -> (String, TokenIssued, String) { let bearer = format!("slug_{token_id}_{secret}"); let event = TokenIssued { ts: now_ms(), - username: canonical_user.clone(), + username: username.clone(), token_id, token_hash, salt, issued_via: "oauth".to_string(), }; - (bearer, event, canonical_user) + (bearer, event) } #[derive(Debug, Deserialize)] @@ -207,7 +205,7 @@ pub async fn get_auth_callback(Query(q): Query, State(state): s.provider = Some("google".to_string()); s.provider_id = Some(sub.clone()); if let Some(username) = existing { - let (bearer, token_event, canon_user) = issue_token_for_user(&username); + let (bearer, token_event) = issue_token_for_user(&username); // append token event let ev = Event::TokenIssued(token_event); if let Err(err) = state.event_log.append(&ev).await { @@ -217,7 +215,7 @@ pub async fn get_auth_callback(Query(q): Query, State(state): let mut reduced = reduced_arc.write().await; reduced.apply_event(ev); } - s.complete = Some((canon_user, bearer)); + s.complete = Some((username, bearer)); return Redirect::temporary(&format!("{public_url}/auth/complete")).into_response(); } } @@ -251,9 +249,10 @@ pub async fn post_choose_username( State(state): State, Form(form): Form, ) -> impl IntoResponse { - if let Err(msg) = validate_username(&form.username) { - return api_error(StatusCode::BAD_REQUEST, "invalid username", Some(msg)).into_response(); - } + let canon_user = match parse_username(&form.username) { + Ok(u) => u, + Err(msg) => return api_error(StatusCode::BAD_REQUEST, "invalid username", Some(msg)).into_response(), + }; let sessions = pending_sessions(&state); let (provider, provider_id, agent) = { @@ -270,7 +269,7 @@ pub async fn post_choose_username( (provider, provider_id, s.agent.clone()) }; - if let Err(msg) = validate_agent_format(&agent) { + if let Err(msg) = parse_agent(&agent) { return api_error(StatusCode::BAD_REQUEST, "invalid agent format", Some(msg)).into_response(); } @@ -280,7 +279,7 @@ pub async fn post_choose_username( if reduced.users_by_provider.contains_key(&provider_key) { return api_error(StatusCode::CONFLICT, "provider already registered", None).into_response(); } - if reduced.users_by_provider.values().any(|u| u == &canonicalize_username(&form.username)) { + if reduced.users_by_provider.values().any(|u| u == &canon_user) { drop(reduced); return choose_username_error_fragment(&form.session, "that username is taken — try another").into_response(); } @@ -288,12 +287,12 @@ pub async fn post_choose_username( let ur = Event::UserRegistered(UserRegistered { ts: now_ms(), - username: canonicalize_username(&form.username), + username: canon_user.clone(), provider: provider.to_lowercase(), provider_id: provider_id.clone(), }); - let (bearer, ti, canon_user) = issue_token_for_user(&form.username); + let (bearer, ti) = issue_token_for_user(&canon_user); let ti_ev = Event::TokenIssued(ti); // Persist events. @@ -325,15 +324,18 @@ pub async fn post_pending_session( State(state): State, Json(req): Json, ) -> impl IntoResponse { - if let Err(msg) = validate_agent_format(&req.agent) { - return api_error(StatusCode::BAD_REQUEST, "invalid agent format", Some(msg)).into_response(); - } + let agent_naked = match parse_agent(&req.agent) { + Ok(a) => a, + Err(msg) => { + return api_error(StatusCode::BAD_REQUEST, "invalid agent format", Some(msg)).into_response(); + } + }; let session = format!("p_{}", uuid::Uuid::new_v4().simple()); let public_url = std::env::var("SLUG_PUBLIC_URL").unwrap_or_else(|_| "http://127.0.0.1:8080".to_string()); let login_url = format!("{public_url}/auth/login?session={}", urlencoding::encode(&session)); let poll_url = format!("/api/v0/pending-session/{}", session); let s = PendingSession { - agent: req.agent.clone(), + agent: agent_naked, created_ts: now_ms(), provider: None, provider_id: None, @@ -359,7 +361,7 @@ pub async fn get_pending_session( return api_error(StatusCode::NOT_FOUND, "unknown session", None).into_response(); }; let (complete, user, token) = match &s.complete { - Some((u, t)) => (true, Some(format!("@{}", u)), Some(t.clone())), + Some((u, t)) => (true, Some(u.clone()), Some(t.clone())), None => (false, None, None), }; Json(PendingSessionPollResponse { @@ -388,7 +390,7 @@ pub async fn get_whoami(State(state): State, headers: HeaderMap) -> im }; let agents_bound = reduced.agent_bindings.values().filter(|u| *u == &username).count(); Json(WhoamiResponse { - user: format!("@{}", username), + user: username, agents_bound, }) .into_response() diff --git a/server/src/api/feed.rs b/server/src/api/feed.rs index f665d34aef12f2bd6e71d1fb4a3d0b4d509aa775..983b7397a846bd540b6baf3773dd54c55ade4c45 100644 --- a/server/src/api/feed.rs +++ b/server/src/api/feed.rs @@ -1,11 +1,12 @@ use axum::{ extract::{Query, State}, + http::StatusCode, response::IntoResponse, Json, }; use serde::Deserialize; -use crate::{events::canonicalize_username, state::AppState}; +use crate::{api::helpers::api_error, identity::parse_username, state::AppState}; // ============================================================================ // Feed -- global reverse-chronological ingest stream since a cutoff @@ -32,7 +33,12 @@ pub async fn get_feed( let reduced_arc = state.reduced.clone(); let reduced = reduced_arc.read().await; - let actor = canonicalize_username(&q.actor); + let actor = match parse_username(&q.actor) { + Ok(u) => u, + Err(msg) => { + return api_error(StatusCode::BAD_REQUEST, "invalid actor", Some(msg)).into_response(); + } + }; let since = q.since.or_else(|| reduced.actor_last_post_ts.get(&actor).copied()); let cutoff = since.unwrap_or(0); let limit = q.limit.unwrap_or(DEFAULT_LIMIT).min(MAX_LIMIT); @@ -65,7 +71,7 @@ pub async fn get_feed( .collect(); Json(slug_types::FeedResponse { - actor: format!("@{}", actor), + actor, since, posts, total, diff --git a/server/src/api/forum.rs b/server/src/api/forum.rs index cf134e97a3aa9f2cea5efcf5bfa2564b9fc2ea46..ab6f3ec4936979fed9b3a9c47bef609610c751dd 100644 --- a/server/src/api/forum.rs +++ b/server/src/api/forum.rs @@ -8,7 +8,8 @@ use serde::Deserialize; use slug_types::*; use crate::{ - events::canonicalize_tag, + canonical_path::canonicalize_tag, + identity::parse_username, state::AppState, }; @@ -46,7 +47,7 @@ pub struct ThreadDetailQuery { pub since: Option, /// Only posts strictly before this Unix ms timestamp. pub before: Option, - /// Filter to posts whose actor starts with this prefix (UUID prefix or full actor string). + /// Filter to posts whose principal username starts with this prefix (stored form, no `@`). pub actor: Option, /// Return the single post with this ingest ID. pub post_id: Option, @@ -56,6 +57,13 @@ pub struct ThreadDetailQuery { pub async fn get_thread(State(state): State, Query(q): Query) -> impl IntoResponse { let reduced_arc = state.reduced.clone(); let tag = canonicalize_tag(&q.tag); + let actor_prefix = match q.actor.as_deref().map(str::trim) { + None | Some("") => String::new(), + Some(s) => match parse_username(s) { + Ok(u) => u, + Err(msg) => return api_error(StatusCode::BAD_REQUEST, "invalid actor filter", Some(msg)).into_response(), + }, + }; let reduced = reduced_arc.read().await; // Single post lookup by ingest ID -- return full body untruncated. @@ -72,7 +80,7 @@ pub async fn get_thread(State(state): State, Query(q): Query, Query(q): Query = all_ids .into_iter() .enumerate() @@ -119,7 +126,7 @@ pub async fn get_thread(State(state): State, Query(q): Query = match &req.delegate { + None => None, + Some(s) if s.trim().is_empty() => None, + Some(s) => match parse_agent(s) { + Ok(d) => Some(d), + Err(msg) => { + drop(reduced); + return api_error(StatusCode::BAD_REQUEST, "invalid delegate format", Some(msg)) + .into_response(); + } + }, + }; let thread_id = canonicalize_tag(&req.thread); let principal = match verify_bearer_principal(&headers, &reduced) { @@ -290,36 +296,43 @@ pub async fn post_ingest( } } - match reduced.agent_bindings.get(&delegate) { - Some(u) if u != &principal => { - drop(reduced); - return api_error( - StatusCode::FORBIDDEN, - "delegate already bound to another user", - None, - ) - .into_response(); + if let Some(ref d) = delegate { + match reduced.agent_bindings.get(d) { + Some(u) if u != &principal => { + drop(reduced); + return api_error( + StatusCode::FORBIDDEN, + "delegate already bound to another user", + None, + ) + .into_response(); + } + _ => {} } - _ => {} } - let need_agent_bind = reduced.agent_bindings.get(&delegate).is_none(); + let need_agent_bind = delegate + .as_ref() + .map(|d| reduced.agent_bindings.get(d).is_none()) + .unwrap_or(false); drop(reduced); let mut events_appended: usize = 0; if need_agent_bind { - let ab = Event::AgentBound(AgentBound { - ts: now_ms(), - agent: delegate.clone(), - username: principal.clone(), - }); - if let Err(err) = event_log.append(&ab).await { - return api_error(StatusCode::INTERNAL_SERVER_ERROR, format!("{err}"), None); - } - events_appended += 1; - { - let mut reduced = reduced_arc.write().await; - reduced.apply_event(ab); + if let Some(agent_id) = delegate.clone() { + let ab = Event::AgentBound(AgentBound { + ts: now_ms(), + agent: agent_id, + username: principal.clone(), + }); + if let Err(err) = event_log.append(&ab).await { + return api_error(StatusCode::INTERNAL_SERVER_ERROR, format!("{err}"), None); + } + events_appended += 1; + { + let mut reduced = reduced_arc.write().await; + reduced.apply_event(ab); + } } } @@ -413,12 +426,18 @@ pub async fn post_check( }; drop(reduced); - if let Err(msg) = validate_agent_format(&req.delegate) { - return api_error(StatusCode::BAD_REQUEST, "invalid delegate format", Some(msg)).into_response(); - } - let delegate = canonicalize_agent(&req.delegate); + let delegate: Option = match &req.delegate { + None => None, + Some(s) if s.trim().is_empty() => None, + Some(s) => match parse_agent(s) { + Ok(d) => Some(d), + Err(msg) => { + return api_error(StatusCode::BAD_REQUEST, "invalid delegate format", Some(msg)).into_response(); + } + }, + }; let thread_id = canonicalize_tag(&req.thread); - let principal = canonicalize_username("placeholder"); + let principal = "placeholder".to_string(); let event = Event::Ingest(Ingest { ts: v.ts, diff --git a/server/src/api/mod.rs b/server/src/api/mod.rs index f1d5c139b875c268cc46c3085c332d8de31b092e..f42e907775645166c60aeae2d98c5855223a71be 100644 --- a/server/src/api/mod.rs +++ b/server/src/api/mod.rs @@ -65,7 +65,7 @@ mod tests { id: format!("test-{ts}"), raw: raw.to_string(), principal: "test".to_string(), - delegate: "@00000000-0000-0000-0000-000000000000:test:local/test".to_string(), + delegate: Some("00000000-0000-0000-0000-000000000000:test:local/test".to_string()), thread_id: "t".to_string(), })); } diff --git a/server/src/api/rank.rs b/server/src/api/rank.rs index 059095bb512096da5e9699ff9c4b92cb7de7fa1c..f2d348280ec4d70a32044601964cb5dc9382d9d7 100644 --- a/server/src/api/rank.rs +++ b/server/src/api/rank.rs @@ -226,7 +226,7 @@ pub async fn get_rank_history( let reduced = reduced_arc.read().await; let content = reduced.public(); - let item_str = crate::events::canonicalize_item(&q.item); + let item_str = crate::canonical_path::canonicalize_item(&q.item); let item = CanonicalItemUrl(item_str.clone()); let entries = content.rank_history.get(&item).cloned().unwrap_or_default(); @@ -238,15 +238,15 @@ pub async fn get_rank_history( .map(|doc| { doc.statements.into_iter().filter_map(|s| { if let crate::dsl::Stmt::Vote { item1, item2, ratio_left, ratio_right, explanation } = s { - let a = crate::events::canonicalize_item(&item1); - let b = crate::events::canonicalize_item(&item2); + let a = crate::canonical_path::canonicalize_item(&item1); + let b = crate::canonical_path::canonicalize_item(&item2); if a == item_str || b == item_str { Some(VoteRow { ts: e.ts, a: item_path_for_api(&a), b: item_path_for_api(&b), ratio: format!("{}:{}", ratio_left, ratio_right), - actor: reduced.ingests_by_id.get(&e.post_id).map(|ing| format!("@{}", ing.principal)), + actor: reduced.ingests_by_id.get(&e.post_id).map(|ing| ing.principal.clone()), body: explanation, thread: Some(format!("#{}", e.thread)), }) diff --git a/server/src/api/search.rs b/server/src/api/search.rs index 8028c3117b9b22460fb9677ca969741f6849d2d0..87621e6e4210a28c7802bb941200788f28518940 100644 --- a/server/src/api/search.rs +++ b/server/src/api/search.rs @@ -119,7 +119,7 @@ pub async fn get_search( .unwrap_or_else(|| "#unknown".to_string()); scored_posts.push((score, ingest.ts, slug_types::SearchPostHit { thread, - actor: format!("@{}", ingest.principal), + actor: ingest.principal.clone(), snippet: snippet_around(&ingest.raw, &words, 160), ts: ingest.ts, })); diff --git a/server/src/api/thread.rs b/server/src/api/thread.rs index 576b0b5be2767b0c6cba5e0701e4ffc9f215029d..be6ef446e316fef352a7eef5b35b40583dca4442 100644 --- a/server/src/api/thread.rs +++ b/server/src/api/thread.rs @@ -8,9 +8,8 @@ use serde::{Deserialize, Serialize}; use crate::{ api::helpers::{api_error, now_ms}, - events::{ - canonicalize_username, Event, GrantAdded, ThreadCapability, ThreadCreated, ThreadVisibility, - }, + events::{Event, GrantAdded, ThreadCapability, ThreadCreated, ThreadVisibility}, + identity::parse_username, state::AppState, }; use super::auth::verify_bearer_principal; @@ -150,10 +149,10 @@ pub async fn post_thread_grants( return api_error(StatusCode::FORBIDDEN, "requires Manage capability", None).into_response(); } - let target = canonicalize_username(&req.username); - if target.is_empty() { - return api_error(StatusCode::BAD_REQUEST, "invalid username", None).into_response(); - } + let target = match parse_username(&req.username) { + Ok(u) => u, + Err(msg) => return api_error(StatusCode::BAD_REQUEST, "invalid username", Some(msg)).into_response(), + }; if !reduced.users_by_provider.values().any(|u| u == &target) { return api_error(StatusCode::NOT_FOUND, format!("user @{target} not found"), None).into_response(); } diff --git a/server/src/canonical_path.rs b/server/src/canonical_path.rs new file mode 100644 index 0000000000000000000000000000000000000000..5c0febe883d8b3978a25896ed0d71df8509a8717 --- /dev/null +++ b/server/src/canonical_path.rs @@ -0,0 +1,92 @@ +//! Normalization for thread tags and ontology item URLs (DSL ↔ stored canonical form). +//! Not event types — see `events` and `path_types`. + +/// Thread / public tag: stored without leading `#`, lowercase. +pub fn canonicalize_tag(input: &str) -> String { + input.trim().trim_start_matches('#').to_lowercase() +} + +/// Ontology item reference → canonical absolute URL on the slug host. +pub fn canonicalize_item(input: &str) -> String { + let s = input.trim(); + if s.is_empty() { + return String::new(); + } + + if let Some(rest) = s.strip_prefix("https://") { + let (host, tail) = rest.split_once('/').map_or((rest, ""), |(h, t)| (h, t)); + let host = host.trim().to_lowercase(); + if tail.is_empty() { + return format!("https://{}", host); + } else { + return format!("https://{}/{}", host, tail); + } + } + if let Some(rest) = s.strip_prefix("http://") { + let (host, tail) = rest.split_once('/').map_or((rest, ""), |(h, t)| (h, t)); + let host = host.trim().to_lowercase(); + if tail.is_empty() { + return format!("http://{}", host); + } else { + return format!("http://{}/{}", host, tail); + } + } + + let is_tilde = s.starts_with("~/"); + let rest = s.strip_prefix("~/").or_else(|| s.strip_prefix("/")).unwrap_or(s); + + let tail = rest + .split('/') + .filter_map(|seg| { + let t = seg.trim(); + if t.is_empty() { + None + } else { + Some(t.to_lowercase()) + } + }) + .collect::>() + .join("/"); + + if is_tilde { + format!("https://slug.social/~/{}", tail) + } else if tail.is_empty() { + "https://slug.social".to_string() + } else { + format!("https://slug.social/{}", tail) + } +} + +pub fn item_path_segments(input: &str) -> Vec { + let canonical = canonicalize_item(input); + if canonical.is_empty() { + return vec![]; + } + + if let Some(rest) = canonical.strip_prefix("https://") { + let (host, tail) = rest.split_once('/').map_or((rest, ""), |(h, t)| (h, t)); + let mut out = vec![format!("https://{}", host)]; + out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string())); + return out; + } + if let Some(rest) = canonical.strip_prefix("http://") { + let (host, tail) = rest.split_once('/').map_or((rest, ""), |(h, t)| (h, t)); + let mut out = vec![format!("http://{}", host)]; + out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string())); + return out; + } + + canonical + .split('/') + .filter(|s| !s.is_empty()) + .map(|s| s.to_string()) + .collect() +} + +pub fn item_parent_path(input: &str) -> Option { + let segs = item_path_segments(input); + if segs.len() <= 1 { + return None; + } + Some(segs[..segs.len() - 1].join("/")) +} diff --git a/server/src/events.rs b/server/src/events.rs index 7775e59974a521f5fea9361a600802898d05c6ab..26edac7505ce4e67a042a5511113efba5fea4950 100644 --- a/server/src/events.rs +++ b/server/src/events.rs @@ -1,150 +1,5 @@ use serde::{Deserialize, Serialize}; -/// Canonical identifiers stored without sigils. -/// - tags are stored without leading '#' -/// - items are stored without leading '/' -pub fn canonicalize_tag(input: &str) -> String { - input.trim().trim_start_matches('#').to_lowercase() -} - -pub fn canonicalize_item(input: &str) -> String { - let s = input.trim(); - if s.is_empty() { - return String::new(); - } - - if let Some(rest) = s.strip_prefix("https://") { - let (host, tail) = rest.split_once('/').map_or((rest, ""), |(h, t)| (h, t)); - let host = host.trim().to_lowercase(); - if tail.is_empty() { - return format!("https://{}", host); - } else { - return format!("https://{}/{}", host, tail); - } - } - if let Some(rest) = s.strip_prefix("http://") { - let (host, tail) = rest.split_once('/').map_or((rest, ""), |(h, t)| (h, t)); - let host = host.trim().to_lowercase(); - if tail.is_empty() { - return format!("http://{}", host); - } else { - return format!("http://{}/{}", host, tail); - } - } - - let is_tilde = s.starts_with("~/"); - let rest = s.strip_prefix("~/").or_else(|| s.strip_prefix("/")).unwrap_or(s); - - let tail = rest - .split('/') - .filter_map(|seg| { - let t = seg.trim(); - if t.is_empty() { - None - } else { - Some(t.to_lowercase()) - } - }) - .collect::>() - .join("/"); - - if is_tilde { - format!("https://slug.social/~/{}", tail) - } else if tail.is_empty() { - "https://slug.social".to_string() - } else { - format!("https://slug.social/{}", tail) - } -} - -pub fn item_path_segments(input: &str) -> Vec { - let canonical = canonicalize_item(input); - if canonical.is_empty() { - return vec![]; - } - - if let Some(rest) = canonical.strip_prefix("https://") { - let (host, tail) = rest.split_once('/').map_or((rest, ""), |(h, t)| (h, t)); - let mut out = vec![format!("https://{}", host)]; - out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string())); - return out; - } - if let Some(rest) = canonical.strip_prefix("http://") { - let (host, tail) = rest.split_once('/').map_or((rest, ""), |(h, t)| (h, t)); - let mut out = vec![format!("http://{}", host)]; - out.extend(tail.split('/').filter(|s| !s.is_empty()).map(|s| s.to_string())); - return out; - } - - // Should be unreachable since all canonical items are now URLs - canonical - .split('/') - .filter(|s| !s.is_empty()) - .map(|s| s.to_string()) - .collect() -} - -pub fn item_parent_path(input: &str) -> Option { - let segs = item_path_segments(input); - if segs.len() <= 1 { - return None; - } - Some(segs[..segs.len() - 1].join("/")) -} - -/// Canonical username stored without leading '@'. -pub fn canonicalize_username(input: &str) -> String { - input.trim().trim_start_matches('@').to_lowercase() -} - -/// Validate username: lowercase alphanumeric + '-' '_' only; length 1-32. -pub fn validate_username(username: &str) -> Result<(), String> { - let u = canonicalize_username(username); - if u.is_empty() || u.len() > 32 { - return Err("username must be 1-32 characters".to_string()); - } - if !u - .chars() - .all(|c| c.is_ascii_lowercase() || c.is_ascii_digit() || c == '-' || c == '_') - { - return Err("username must be lowercase alphanumeric with '-' or '_' only".to_string()); - } - Ok(()) -} - -/// Canonical agent identity stored with single leading '@'. -/// -/// Request/display form is `@@uuid:rig:provider/model` but we store `@uuid:rig:provider/model`. -pub fn canonicalize_agent(input: &str) -> String { - let s = input.trim(); - let s = s.strip_prefix("@@").or_else(|| s.strip_prefix('@')).unwrap_or(s); - format!("@{}", s.to_lowercase()) -} - -/// Validate agent format: @@:: -pub fn validate_agent_format(agent: &str) -> Result<(), String> { - let a = agent.trim(); - if !a.starts_with("@@") && !a.starts_with('@') { - return Err("agent must start with @@".to_string()); - } - let a = a.strip_prefix("@@").or_else(|| a.strip_prefix('@')).unwrap_or(a); - let parts: Vec<&str> = a.split(':').collect(); - if parts.len() != 3 { - return Err("agent must be @@::".to_string()); - } - let (uuid_part, rig_part, model_part) = (parts[0], parts[1], parts[2]); - if uuid::Uuid::parse_str(uuid_part).is_err() { - return Err("agent uuid must be a valid UUID v4".to_string()); - } - if rig_part.trim().is_empty() { - return Err("agent rig must be non-empty".to_string()); - } - if !model_part.contains('/') { - return Err("agent model must be ".to_string()); - } - Ok(()) -} - #[derive(Debug, Clone, Copy, Serialize, Deserialize, PartialEq, Eq)] #[serde(rename_all = "snake_case")] pub enum ThreadVisibility { @@ -236,10 +91,11 @@ pub struct Ingest { pub id: String, /// Raw DSL+prose body only (no identity/routing metadata). pub raw: String, - /// Human principal username (no leading '@'). + /// Human principal username (wire and storage: no `@`). pub principal: String, - /// Delegate agent identity (canonical stored with single leading '@'). - pub delegate: String, + /// AI delegate id `uuid:rig:model` (wire and storage: no `@`). Omitted when absent. + #[serde(default, skip_serializing_if = "Option::is_none")] + pub delegate: Option, /// Thread identifier: public tag (e.g. "languages") or private id/slug (e.g. "a7f2k9x/project-review"). pub thread_id: String, } @@ -247,5 +103,3 @@ pub struct Ingest { fn generate_id() -> String { uuid::Uuid::new_v4().to_string() } - - diff --git a/server/src/html/editor.rs b/server/src/html/editor.rs index 1d2c4be7eef4cc437cacddd0949307895f3ef018..4f206a0a895b47592df7669cd8d2fb4d83286fe7 100644 --- a/server/src/html/editor.rs +++ b/server/src/html/editor.rs @@ -33,7 +33,7 @@ pub async fn editor_page() -> impl IntoResponse { p class="muted" { "write DSL, see what happens. nothing is saved." } div class="editor-container" { textarea id="editor-input" rows="12" cols="80" - placeholder="@your-uuid:rig:provider/model\n#your-thread\n\n~/path/item-a { description }\n~/path/item-b { description }\n\n~/path/item-a 3:1 ~/path/item-b { reasoning }" + placeholder="your-uuid:rig:provider/model\n#your-thread\n\n~/path/item-a { description }\n~/path/item-b { description }\n\n~/path/item-a 3:1 ~/path/item-b { reasoning }" autocomplete="off" autofocus {} div id="editor-status" class="muted" { "type to check…" } div id="editor-results" {} @@ -110,7 +110,7 @@ pub async fn editor_check( id: uuid::Uuid::new_v4().to_string(), raw: form.text.clone(), principal: String::new(), - delegate: String::new(), + delegate: None, thread_id: String::new(), }); let mut simulated = { reduced_arc.read().await.clone() }; diff --git a/server/src/html/forum.rs b/server/src/html/forum.rs index d40cc6398aaf3b2348d91498b5b3a80ed593e55c..a4e17ddf0064b08dfa221c964ccaa0eb99948b5b 100644 --- a/server/src/html/forum.rs +++ b/server/src/html/forum.rs @@ -7,14 +7,14 @@ use serde::Deserialize; use maud::{html, Markup}; use crate::{ - events::canonicalize_tag, + canonical_path::canonicalize_tag, reducer::ReducerState, state::AppState, timeago, }; use super::{ - actor_label, bc_threads, cli_panel, layout, now_ms, + authorship_address, bc_threads, cli_panel, layout, now_ms, recency_class, render_linkified_with_embeds, }; @@ -260,7 +260,7 @@ pub async fn thread_post_view( @let ago = timeago::timeago(now, ing.ts); div class="ingest-entry" data-ingest-id=(ing.id) { div class="ingest-meta muted" title=(hover) { - span class="address" { "@" (actor_label(&ing.delegate)) } + span class="address" { (authorship_address(&ing.principal, &ing.delegate)) } " · " (ago) } diff --git a/server/src/html/garden.rs b/server/src/html/garden.rs index bddd90aa6eb288c0c97bb08f472e2934fd2fe67a..dcd7f0d4a2d7b602026b643c564d212cb084ff9f 100644 --- a/server/src/html/garden.rs +++ b/server/src/html/garden.rs @@ -5,7 +5,7 @@ use axum::{ use maud::html; use crate::{ - events::canonicalize_item, + canonical_path::canonicalize_item, path_types::CanonicalItemUrl, ranking::{connected_components_from_voted_pairs, ranked_items_subset}, scope_rank::{build_children_rankings, ChildrenRankings}, @@ -14,7 +14,7 @@ use crate::{ }; use super::{ - actor_label, bc_path, cli_panel, layout, now_ms, ratio_pct, render_linkified_with_embeds, + authorship_address, bc_path, cli_panel, layout, now_ms, ratio_pct, render_linkified_with_embeds, breadcrumb_path::OntologyPath, }; @@ -204,8 +204,8 @@ fn build_rank_history( .map(|doc| { doc.statements.into_iter().filter_map(|s| { if let crate::dsl::Stmt::Vote { item1, item2, ratio_left, ratio_right, explanation } = s { - let a_str = crate::events::canonicalize_item(&item1); - let b_str = crate::events::canonicalize_item(&item2); + let a_str = crate::canonical_path::canonicalize_item(&item1); + let b_str = crate::canonical_path::canonicalize_item(&item2); if a_str == item || b_str == item { Some(crate::reducer::VoteData { ts: e.ts, @@ -216,9 +216,7 @@ fn build_rank_history( principal: reduced.ingests_by_id.get(&e.post_id) .map(|ing| ing.principal.clone()) .unwrap_or_default(), - delegate: reduced.ingests_by_id.get(&e.post_id) - .map(|ing| ing.delegate.clone()) - .unwrap_or_default(), + delegate: reduced.ingests_by_id.get(&e.post_id).and_then(|ing| ing.delegate.clone()), thread_id: e.thread.clone(), }) } else { None } @@ -331,7 +329,7 @@ async fn render_scope_view(state: AppState, path: OntologyPath) -> axum::respons @let right_class = if v.b.as_str() == model.item { "ratio-right current" } else { "ratio-right" }; div class="ont-vote-entry" { div class="ont-vote-meta" title=(hover) { - span class="address" { "@" (actor_label(&v.delegate)) } + span class="address" { (authorship_address(&v.principal, &v.delegate)) } " · " (ago) } @@ -482,7 +480,7 @@ mod tests { id: format!("ing-{ts}"), raw: raw.to_string(), principal: "testuser".to_string(), - delegate: "@00000000-0000-0000-0000-000000000000:test:local/test".to_string(), + delegate: Some("00000000-0000-0000-0000-000000000000:test:local/test".to_string()), thread_id: String::new(), })); } diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs index 8b48a25cce79f0eefc7e29849e1a667cae4c7986..82c5993fabfeaf2ea8b9034bccaef37924100264 100644 --- a/server/src/html/mod.rs +++ b/server/src/html/mod.rs @@ -238,9 +238,9 @@ pub(super) fn bc_threads(thread_tag: Option<&str>) -> Markup { } } -/// Input is canonicalized without leading '@' (usually uuid:rig:provider/model). -pub(super) fn actor_label(actor: &str) -> String { - let a = actor.trim_start_matches('@').trim(); +/// Short display label for a stored agent id (`uuid:rig:model`, no `@`). +pub(super) fn actor_label(agent_naked: &str) -> String { + let a = agent_naked.trim(); let parts: Vec<&str> = a.split(':').collect(); if parts.len() >= 3 { let rig = parts[1].trim(); @@ -258,6 +258,13 @@ pub(super) fn actor_label(actor: &str) -> String { a.to_string() } +/// HTML attribution only: human `@name`, or agent `@@uuid8:rig:model` when a delegate is present. +pub(super) fn authorship_address(principal: &str, delegate: &Option) -> String { + match delegate { + Some(d) => format!("@@{}", actor_label(d)), + None => format!("@{}", principal), + } +} /// Escape HTML special chars for safe injection. fn escape_html(s: &str) -> String { diff --git a/server/src/html/search.rs b/server/src/html/search.rs index f56f31546b4870d41e594d0e3ac2a4b50ba831b8..df5cb0a59ff72956f4bc94e53b86ab8337452817 100644 --- a/server/src/html/search.rs +++ b/server/src/html/search.rs @@ -11,7 +11,7 @@ use crate::{ timeago, }; -use super::{actor_label, bc_segment, cli_panel, layout, now_ms}; +use super::{authorship_address, bc_segment, cli_panel, layout, now_ms}; /// Escape HTML special chars for safe injection. fn escape_html(s: &str) -> String { @@ -44,7 +44,8 @@ struct ThreadRow { struct PostRow { thread: String, - actor: String, + /// Pre-formatted attribution string for display (includes `@` / `@@` from `authorship_address`). + actor_display: String, text: String, ts: i64, } @@ -151,7 +152,7 @@ fn search(state: &ReducerState, q: &str, limit: usize) -> SearchResults { .unwrap_or_else(|| "unknown".to_string()); scored_posts.push((score, PostRow { thread, - actor: ingest.principal.clone(), + actor_display: authorship_address(&ingest.principal, &ingest.delegate), text: ingest.raw.clone(), ts: ingest.ts, })); @@ -321,7 +322,7 @@ fn render_search_results(results: &SearchResults, query: &str) -> Markup { li { div class="search-post-meta muted" { a href=(format!("/t/{}", r.thread)) { "#" (r.thread) } - " · " (actor_label(&r.actor)) + " · " (r.actor_display) " · " (timeago::timeago(now, r.ts)) } div class="search-snippet" { diff --git a/server/src/html/tree.rs b/server/src/html/tree.rs index 568a08edbb548291ab6f03b46c79cdcb4b432468..339f69af3b3279918a97b1dced62e4e3e0b528e3 100644 --- a/server/src/html/tree.rs +++ b/server/src/html/tree.rs @@ -13,7 +13,7 @@ use serde::{Deserialize, Serialize}; use std::collections::BTreeSet; use crate::{ - events::canonicalize_item, + canonical_path::canonicalize_item, path_types::{CanonicalItemUrl, RelativePath}, scope_rank::ChildrenRankings, state::AppState, @@ -702,7 +702,8 @@ pub async fn tree_select( mod tests { use super::*; - use crate::events::{canonicalize_item, Event, Ingest}; + use crate::canonical_path::canonicalize_item; + use crate::events::{Event, Ingest}; use crate::reducer::ReducerState; fn ingest(raw: &str) -> Event { @@ -711,7 +712,7 @@ mod tests { id: "test-ingest".to_string(), raw: raw.to_string(), principal: "tester".to_string(), - delegate: String::new(), + delegate: None, thread_id: String::new(), }) } @@ -789,9 +790,9 @@ mod tests { fn reducer_parent_key_for_tilde_items_is_without_trailing_slash() { // This is the reducer invariant that the tree view must match. let item = canonicalize_item("~/alphabet/a"); - assert_eq!(crate::events::item_parent_path(&item).unwrap(), "https://slug.social/~/alphabet"); + assert_eq!(crate::canonical_path::item_parent_path(&item).unwrap(), "https://slug.social/~/alphabet"); let item2 = canonicalize_item("~/a"); - assert_eq!(crate::events::item_parent_path(&item2).unwrap(), "https://slug.social/~"); + assert_eq!(crate::canonical_path::item_parent_path(&item2).unwrap(), "https://slug.social/~"); } #[test] diff --git a/server/src/identity.rs b/server/src/identity.rs new file mode 100644 index 0000000000000000000000000000000000000000..ad654ae813f8f6fe6323746e2544250687d3d47f --- /dev/null +++ b/server/src/identity.rs @@ -0,0 +1,66 @@ +//! Usernames and agent delegate ids. Wire JSON and query params use **stored form only** (no `@` / `@@`). +//! The HTTP layer validates here; the reducer does not rewrite identity. For humans, `@name` / `@@agent` +//! appear only in HTML (see `html::authorship_address`). + +/// Parse username from query/body: trim, lowercase. `@` is not allowed (use `tommy`, not `@tommy`). +pub fn parse_username(input: &str) -> Result { + let s = input.trim(); + if s.is_empty() { + return Err("username must not be empty".to_string()); + } + if s.contains('@') { + return Err( + "username must not contain '@' — use stored form (e.g. `tommy`)".to_string(), + ); + } + let u = s.to_lowercase(); + validate_username_naked(&u)?; + Ok(u) +} + +fn validate_username_naked(u: &str) -> Result<(), String> { + if u.len() > 32 { + return Err("username must be 1-32 characters".to_string()); + } + if !u + .chars() + .all(|c| c.is_ascii_lowercase() || c.is_ascii_digit() || c == '-' || c == '_') + { + return Err("username must be lowercase alphanumeric with '-' or '_' only".to_string()); + } + Ok(()) +} + +/// Parse agent id: trim, lowercase. Must be `uuid:rig:provider/model` with no `@`. +pub fn parse_agent(input: &str) -> Result { + let s = input.trim(); + if s.is_empty() { + return Err("agent id must not be empty".to_string()); + } + if s.contains('@') { + return Err( + "agent id must not contain '@' — use `uuid:rig:provider/model`".to_string(), + ); + } + let a = s.to_lowercase(); + validate_agent_naked(&a)?; + Ok(a) +} + +fn validate_agent_naked(a: &str) -> Result<(), String> { + let parts: Vec<&str> = a.split(':').collect(); + if parts.len() != 3 { + return Err("agent must be ::".to_string()); + } + let (uuid_part, rig_part, model_part) = (parts[0], parts[1], parts[2]); + if uuid::Uuid::parse_str(uuid_part).is_err() { + return Err("agent uuid must be a valid UUID v4".to_string()); + } + if rig_part.trim().is_empty() { + return Err("agent rig must be non-empty".to_string()); + } + if !model_part.contains('/') { + return Err("agent model must be ".to_string()); + } + Ok(()) +} diff --git a/server/src/lib.rs b/server/src/lib.rs index 1820b0dd9cd2d0b6ce05789e3225e0d86a3d357a..173fbdd6b3f23c062a200b268d04491d5e030b3f 100644 --- a/server/src/lib.rs +++ b/server/src/lib.rs @@ -1,10 +1,12 @@ #[macro_use] pub mod paths; pub mod api; +pub mod canonical_path; pub mod dsl; pub mod html; pub mod event_log; pub mod events; +pub mod identity; pub mod middleware; pub mod path_types; pub mod ranking; diff --git a/server/src/path_types.rs b/server/src/path_types.rs index 5a903de4f8309b6c3874e2cd70f2eb5650fd50a8..997597f6659c1ba2092bc5348e393bf7a8fa7ae0 100644 --- a/server/src/path_types.rs +++ b/server/src/path_types.rs @@ -14,9 +14,9 @@ use std::fmt; use serde::{Deserialize, Serialize}; -use crate::events::canonicalize_item; +use crate::canonical_path::canonicalize_item; -/// Canonical item identifier as produced by `events::canonicalize_item`. +/// Canonical item identifier as produced by `canonical_path::canonicalize_item`. /// /// In practice this is usually: /// - `https://slug.social/~/...` for ontology items, or diff --git a/server/src/ranking.rs b/server/src/ranking.rs index 70119611473a430113429eafb6d92b2bf96a3eb5..f70da0d076da2ba8f0abb5a4415babae1c2305f9 100644 --- a/server/src/ranking.rs +++ b/server/src/ranking.rs @@ -265,7 +265,7 @@ mod tests { ratio_right: r, body: "because".to_string(), principal: "test".to_string(), - delegate: "@00000000-0000-0000-0000-000000000000:test:local/test".to_string(), + delegate: Some("00000000-0000-0000-0000-000000000000:test:local/test".to_string()), thread_id: "untagged".to_string(), } } diff --git a/server/src/reducer.rs b/server/src/reducer.rs index 9ab063a340e228edaa8967ec35762809fccd5d3a..550bcda1a1068df13908d19484d86ad46d65ddf1 100644 --- a/server/src/reducer.rs +++ b/server/src/reducer.rs @@ -2,7 +2,8 @@ use std::collections::{HashMap, HashSet, VecDeque}; use serde::{Deserialize, Serialize}; -use crate::events::{canonicalize_agent, canonicalize_tag, canonicalize_username, Event, Ingest, ThreadCapability}; +use crate::canonical_path::canonicalize_tag; +use crate::events::{Event, Ingest, ThreadCapability}; use crate::path_types::CanonicalItemUrl; #[derive(Debug, Clone, Hash, PartialEq, Eq, PartialOrd, Ord)] @@ -21,10 +22,10 @@ pub struct VoteData { pub ratio_left: i32, pub ratio_right: i32, pub body: String, - /// Human principal username (no leading '@'). + /// Human principal username (no `@` in stored events). pub principal: String, - /// Agent delegate identity (stored with single leading '@'). - pub delegate: String, + /// AI delegate id, if any (no `@` in stored events). + pub delegate: Option, /// Thread id where this vote was cast (public tag or private id/slug). pub thread_id: String, } @@ -99,8 +100,6 @@ impl GroupState { pub fn apply_vote(&mut self, mut vote: VoteData) { vote.a = CanonicalItemUrl::parse(vote.a.as_str()).unwrap_or(vote.a); vote.b = CanonicalItemUrl::parse(vote.b.as_str()).unwrap_or(vote.b); - vote.principal = canonicalize_username(&vote.principal); - vote.delegate = canonicalize_agent(&vote.delegate); vote.thread_id = canonicalize_tag(&vote.thread_id); if vote.ratio_left < 0 { vote.ratio_left = 0; @@ -189,7 +188,7 @@ pub struct ReducerState { pub users_by_provider: HashMap<(String, String), String>, /// token_id -> (username, salt, token_hash) pub tokens_by_id: HashMap, - /// agent delegate (canonical '@...') -> username + /// agent id (naked `uuid:rig:model`) -> username pub agent_bindings: HashMap, pub ingests_by_id: HashMap, @@ -330,26 +329,27 @@ impl ReducerState { pub fn apply_event(&mut self, event: Event) { match event { Event::UserRegistered(ur) => { - let username = canonicalize_username(&ur.username); - self.users_by_provider - .insert((ur.provider.to_lowercase(), ur.provider_id.clone()), username); + self.users_by_provider.insert( + (ur.provider.to_lowercase(), ur.provider_id.clone()), + ur.username, + ); } Event::TokenIssued(ti) => { - let username = canonicalize_username(&ti.username); - self.tokens_by_id - .insert(ti.token_id.clone(), (username, ti.salt.clone(), ti.token_hash.clone())); + self.tokens_by_id.insert( + ti.token_id.clone(), + (ti.username, ti.salt.clone(), ti.token_hash.clone()), + ); } Event::AgentBound(ab) => { - let username = canonicalize_username(&ab.username); - let agent = canonicalize_agent(&ab.agent); - self.agent_bindings.insert(agent, username); + if ab.agent.is_empty() { + return; + } + self.agent_bindings.insert(ab.agent, ab.username); } Event::ThreadCreated(tc) => { self.threads.entry(tc.thread_id.clone()).or_default().visibility = tc.visibility; } Event::Ingest(mut ing) => { - ing.principal = canonicalize_username(&ing.principal); - ing.delegate = canonicalize_agent(&ing.delegate); ing.thread_id = canonicalize_tag(&ing.thread_id); self.ingests_by_id.insert(ing.id.clone(), ing.clone()); @@ -528,7 +528,7 @@ impl ReducerState { let caps = self.grants .entry(ga.thread_id) .or_default() - .entry(canonicalize_username(&ga.username)) + .entry(ga.username) .or_default(); for cap in ga.capabilities { caps.insert(cap); @@ -536,7 +536,7 @@ impl ReducerState { } Event::GrantRevoked(gr) => { if let Some(thread_grants) = self.grants.get_mut(&gr.thread_id) { - let username = canonicalize_username(&gr.username); + let username = gr.username; if let Some(caps) = thread_grants.get_mut(&username) { for cap in &gr.capabilities { caps.remove(cap); diff --git a/server/tests/basic.rs b/server/tests/basic.rs index 8d7dd87d327c969ad953ecaa6b021a03e4d1842e..21cacd3049c9f5a307e75eefd5ebfc7bf0097b5d 100644 --- a/server/tests/basic.rs +++ b/server/tests/basic.rs @@ -1,6 +1,7 @@ use slugsocial_server::{ event_log::EventLog, - events::{canonicalize_item, canonicalize_tag, Event, Ingest}, + canonical_path::{canonicalize_item, canonicalize_tag}, + events::{Event, Ingest}, ranking::ranked_items, reducer::{GroupState, ReducerState}, }; @@ -15,7 +16,7 @@ fn ingest_event(ts: i64, raw: &str) -> Event { id: format!("test-{ts}"), raw: raw.to_string(), principal: "test".to_string(), - delegate: "@@00000000-0000-0000-0000-000000000000:test:local/test".to_string(), + delegate: Some("00000000-0000-0000-0000-000000000000:test:local/test".to_string()), thread_id: "t".to_string(), }) } @@ -491,7 +492,7 @@ fn reducer_negative_ratio_clamped_to_zero() { ratio_right: -3, body: "negative".to_string(), principal: "test".to_string(), - delegate: "@@00000000-0000-0000-0000-000000000000:test:local/test".to_string(), + delegate: Some("00000000-0000-0000-0000-000000000000:test:local/test".to_string()), thread_id: "t".to_string(), }); assert_eq!(group.idx_to_item.len(), 2); diff --git a/server/tests/integration.rs b/server/tests/integration.rs index 24ef464631cd269889b8bb751ef0e90289443e97..eaa25f2c5cc21df3096d9b8f54c060c83207bfd6 100644 --- a/server/tests/integration.rs +++ b/server/tests/integration.rs @@ -87,7 +87,7 @@ async fn test_ingest_actor_with_colons_is_detected_and_validated() { // Old archive style: agent includes colons but UUID is only a prefix (invalid). // We should detect the agent line, then fail with "invalid agent format". let ingest_payload = serde_json::json!({ - "delegate": "@@aec1e31c:claudecode:anthropic/claude-sonnet-4.5", + "delegate": "aec1e31c:claudecode:anthropic/claude-sonnet-4.5", "thread": "t", "text": "~/x {x}\n", }); @@ -108,6 +108,26 @@ async fn test_ingest_actor_with_colons_is_detected_and_validated() { hint.to_lowercase().contains("uuid"), "hint should mention uuid, got: {hint}" ); + + let at_payload = serde_json::json!({ + "delegate": "@00000000-0000-0000-0000-000000000000:test:local/test", + "thread": "t", + "text": "~/x {x}\n", + }); + let at_resp = client + .post(&format!("http://{}/api/v0/ingest", addr)) + .header("Authorization", format!("Bearer {}", test_bearer())) + .json(&at_payload) + .send() + .await + .unwrap(); + assert_eq!(at_resp.status(), reqwest::StatusCode::BAD_REQUEST); + let at_body: serde_json::Value = at_resp.json().await.unwrap(); + let at_hint = at_body["hint"].as_str().unwrap_or_default(); + assert!( + at_hint.contains('@'), + "hint should reject '@' in delegate, got: {at_hint}" + ); } #[tokio::test] @@ -117,7 +137,7 @@ async fn test_vote_endpoint() { // /api/v0/vote was removed; all votes are submitted via ingest. let ingest_payload = serde_json::json!({ - "delegate": "@@00000000-0000-0000-0000-000000000000:test:local/test", + "delegate": "00000000-0000-0000-0000-000000000000:test:local/test", "thread": "cli", "text": "~/clap {cli parser}\n~/argh {cli parser}\n~/clap 3:1 ~/argh {because clap is more full-featured}\n", }); @@ -143,7 +163,7 @@ async fn test_rank_endpoint() { // Ingest items + vote (vote endpoint removed). let ingest_payload = serde_json::json!({ - "delegate": "@@00000000-0000-0000-0000-000000000000:test:local/test", + "delegate": "00000000-0000-0000-0000-000000000000:test:local/test", "thread": "langs", "text": "~/rust {systems}\n~/go {concurrency}\n~/rust 3:1 ~/go {because i prefer rust for systems work}\n", }); @@ -180,7 +200,7 @@ async fn test_check_endpoint_does_not_commit() { let client = reqwest::Client::new(); let check_payload = serde_json::json!({ - "delegate": "@@00000000-0000-0000-0000-000000000000:test:local/test", + "delegate": "00000000-0000-0000-0000-000000000000:test:local/test", "thread": "t", "text": "~/a {x}\n~/b {y}\n~/a 2:1 ~/b {because}\n", }); @@ -220,7 +240,7 @@ async fn test_garden_item_pair_matchup_include_threads() { // Ingest with thread_id metadata so item_threads and vote.thread_id are populated. let ingest_payload = serde_json::json!({ - "delegate": "@@00000000-0000-0000-0000-000000000000:test:local/test", + "delegate": "00000000-0000-0000-0000-000000000000:test:local/test", "thread": "sorting-hat", "text": "~/sorts/insertion { O(n^2) }\n~/sorts/mergesort { O(n log n) }\n~/sorts/insertion 3:1 ~/sorts/mergesort { simpler for small n }\n", }); @@ -324,7 +344,7 @@ async fn test_rank_history() { // First ingest: rust vs python — two votes on rust in one doc (the multi-vote case). ingest( serde_json::json!({ - "delegate": "@@00000000-0000-0000-0000-000000000001:rig:test/model", + "delegate": "00000000-0000-0000-0000-000000000001:rig:test/model", "thread": "hist-test", "text": "~/hist/rust { systems }\n~/hist/python { scripting }\n~/hist/go { concurrency }\n~/hist/rust 3:1 ~/hist/python { ownership over gc }\n~/hist/rust 2:1 ~/hist/go { performance over simplicity }\n", }), @@ -354,7 +374,7 @@ async fn test_rank_history() { // Second ingest: python beats go — rust not directly touched, so python gets a new entry. ingest( serde_json::json!({ - "delegate": "@@00000000-0000-0000-0000-000000000002:rig:test/model", + "delegate": "00000000-0000-0000-0000-000000000002:rig:test/model", "thread": "hist-test", "text": "~/hist/python 3:1 ~/hist/go { dynamic typing is worth it }\n", }), @@ -404,7 +424,7 @@ async fn pair_returns_connectivity_stats() { // Ingest 4 items with 1 vote (a vs b), leaving c and d as isolates. let doc = serde_json::json!({ - "delegate": "@@00000000-0000-0000-0000-000000000001:testrig:test/model", + "delegate": "00000000-0000-0000-0000-000000000001:testrig:test/model", "thread": "connectivity-test", "text": "~/conn/a { item a }\n~/conn/b { item b }\n~/conn/c { item c }\n~/conn/d { item d }\n~/conn/a 3:1 ~/conn/b { a is better }\n", }); @@ -438,7 +458,7 @@ async fn pair_returns_connectivity_stats() { // Add a vote connecting c to a — should reduce components. let doc2 = serde_json::json!({ - "delegate": "@@00000000-0000-0000-0000-000000000001:testrig:test/model", + "delegate": "00000000-0000-0000-0000-000000000001:testrig:test/model", "thread": "connectivity-test", "text": "~/conn/c 2:1 ~/conn/a { c beats a }\n", }); diff --git a/test/auth.bb b/test/auth.bb index b54ea509aafd2d5ee85877665982d7fc00cd8b20..611e04f1806ef81d678a91f499597fe55f691dd7 100644 --- a/test/auth.bb +++ b/test/auth.bb @@ -155,7 +155,7 @@ (println "\nstarting pending session…") (let [start-resp (http-post-json (str base-url "/api/v0/pending-session") - {:agent "@@00000000-0000-0000-0000-000000000000:bb:local/dev"}) + {:agent "00000000-0000-0000-0000-000000000000:bb:local/dev"}) _ (assert! (= 200 (:status start-resp)) "pending-session start returns 200") start-json (json/parse-string (:body start-resp) true)] (assert! (clojure.string/starts-with? (:session start-json) "p_") "session id has p_ prefix") diff --git a/test/grants.bb b/test/grants.bb index 962ff01cdc25d6d6977cc9a810c404918c20856d..f72799ae6fe099f48bdf316deee07f15882e9d45 100644 --- a/test/grants.bb +++ b/test/grants.bb @@ -187,11 +187,11 @@ ;; Register two users. The mock google cycles through google-user-alice then google-user-bob. (println "\nregistering alice…") (let [alice-token (register-user base-url - "@@00000000-0000-0000-0000-000000000001:test:local/dev" + "00000000-0000-0000-0000-000000000001:test:local/dev" "alice") _ (println "registering bob…") bob-token (register-user base-url - "@@00000000-0000-0000-0000-000000000002:test:local/dev" + "00000000-0000-0000-0000-000000000002:test:local/dev" "bob") ;; Alice creates a private thread. @@ -206,14 +206,14 @@ ;; Alice (owner) can post prose to her own private thread. (println "\nalice posts prose to her private thread…") (assert! (= 200 (:status (ingest! base-url alice-token thread-id - "@@00000000-0000-0000-0000-000000000001:test:local/dev" + "00000000-0000-0000-0000-000000000001:test:local/dev" "Hello from alice."))) "alice prose post succeeds") ;; Bob has no grants at all — should get 403. (println "\nbob (no grants) tries to post prose…") (assert! (= 403 (:status (ingest! base-url bob-token thread-id - "@@00000000-0000-0000-0000-000000000002:test:local/dev" + "00000000-0000-0000-0000-000000000002:test:local/dev" "Hello from bob, unauthorized."))) "bob without grants gets 403") @@ -226,7 +226,7 @@ (println "\nbob (View only) tries to post prose…") (assert! (= 403 (:status (ingest! base-url bob-token thread-id - "@@00000000-0000-0000-0000-000000000002:test:local/dev" + "00000000-0000-0000-0000-000000000002:test:local/dev" "Hello from bob, view only."))) "bob with View but no Post gets 403") @@ -239,21 +239,21 @@ (println "\nbob (View + Post) posts prose…") (assert! (= 200 (:status (ingest! base-url bob-token thread-id - "@@00000000-0000-0000-0000-000000000002:test:local/dev" + "00000000-0000-0000-0000-000000000002:test:local/dev" "Hello from bob, now authorised."))) "bob with View + Post succeeds for prose") ;; Alice defines two items and votes on them in the private thread. (println "\nalice posts items + vote to private thread…") (assert! (= 200 (:status (ingest! base-url alice-token thread-id - "@@00000000-0000-0000-0000-000000000001:test:local/dev" + "00000000-0000-0000-0000-000000000001:test:local/dev" "~/fruits/apple { A crisp red apple. }\n~/fruits/banana { A yellow banana. }\n~/fruits/apple > ~/fruits/banana { apples are better }"))) "alice vote in private thread succeeds") ;; Bob (View + Post, no Vote) tries to vote — should be 403. (println "\nbob (no Vote) tries to vote…") (assert! (= 403 (:status (ingest! base-url bob-token thread-id - "@@00000000-0000-0000-0000-000000000002:test:local/dev" + "00000000-0000-0000-0000-000000000002:test:local/dev" "~/fruits/apple > ~/fruits/banana { bob's take }"))) "bob without Vote gets 403") @@ -266,7 +266,7 @@ (println "\nbob (View + Post + Vote) votes…") (assert! (= 200 (:status (ingest! base-url bob-token thread-id - "@@00000000-0000-0000-0000-000000000002:test:local/dev" + "00000000-0000-0000-0000-000000000002:test:local/dev" "~/fruits/apple > ~/fruits/banana { bob's take }"))) "bob with Vote succeeds")) diff --git a/test/integration.bb b/test/integration.bb index 93db8f3102b1b3a05f3c4bd2cc9f348072fe54cc..4ff5d625840be3bf5e4162cef107a3cbd45aec4d 100644 --- a/test/integration.bb +++ b/test/integration.bb @@ -166,7 +166,7 @@ ;; 3. ingest via CLI (bearer required) (println "\ningesting .sorter document via CLI…") - (bind ingest1-result (common/run-cli cli-bin base-url ["ingest" "--json" "--thread" "integration-test"] :input sorter-doc :extra-env token-env)) + (bind ingest1-result (common/run-cli cli-bin base-url ["ingest" "--json" "--thread" "integration-test" "--delegate" "00000000-0000-0000-0000-000000000000:cli:local/dev"] :input sorter-doc :extra-env token-env)) (assert! (zero? (:exit ingest1-result)) "cli ingest exits 0") (bind ingest1-resp (json/parse-string (:out ingest1-result) true)) (assert! (:ok ingest1-resp) "ingest response ok=true") @@ -237,7 +237,7 @@ "#integration-test" "~/languages/rust 4:1 ~/languages/python { type safety }" "~/languages/rust 3:1 ~/languages/go { zero-cost abstractions }"])) - (bind hist-ingest (common/run-cli cli-bin base-url ["ingest" "--json" "--thread" "integration-test"] :input two-vote-doc :extra-env token-env)) + (bind hist-ingest (common/run-cli cli-bin base-url ["ingest" "--json" "--thread" "integration-test" "--delegate" "00000000-0000-0000-0000-000000000000:cli:local/dev"] :input two-vote-doc :extra-env token-env)) (assert! (zero? (:exit hist-ingest)) (str "two-vote ingest exits 0 (err: " (:err hist-ingest) ")")) diff --git a/test/oauth.bb b/test/oauth.bb index f94583ee0f6fedfc023564ed7ee3a2986adcf660..84679e1a4adbe100dfe7e7d64a2c6270b023d275 100644 --- a/test/oauth.bb +++ b/test/oauth.bb @@ -85,11 +85,11 @@ stop-fn (http/run-server handler {:port port})] {:stop-fn stop-fn :port port})) -(def ^:private default-agent "@@00000000-0000-0000-0000-000000000000:cli:local/dev") +(def ^:private default-agent "00000000-0000-0000-0000-000000000000:cli:local/dev") (defn fetch-bearer-token! "Simulate browser OAuth + username choice; returns `slug_…` bearer token. - Agent must match CLI default `SLUG_DELEGATE` for ingest binding." + Ingest `--delegate` must match this agent string for `AgentBound` on first write." [base-url & {:keys [username agent] :or {username "intuser" agent default-agent}}] (let [start-resp (http-post-json (str base-url "/api/v0/pending-session") {:agent agent})] diff --git a/types/src/lib.rs b/types/src/lib.rs index a62822a36463c68fde6c5fc1aa9e4273c82ca0c8..92e6d122d573ea225f8fb86c548a81b3454425ad 100644 --- a/types/src/lib.rs +++ b/types/src/lib.rs @@ -138,7 +138,7 @@ pub struct PostRow { /// Chronological index within the thread (0 = oldest). pub index: usize, pub ts: i64, - /// Self-declared actor (`@uuid:rig:model`). + /// Principal username (stored form, no `@`). pub actor: String, pub body: String, pub truncated: bool, @@ -186,6 +186,7 @@ pub struct VoteRow { pub a: String, pub b: String, pub ratio: String, + /// Principal username when present (stored form, no `@`). pub actor: Option, pub body: String, /// Thread where this vote was cast (e.g. "#sorting-hat"). @@ -196,6 +197,7 @@ pub struct VoteRow { /// Response for the feed endpoint — all ingests since a cutoff, newest first. #[derive(Debug, Serialize, Deserialize)] pub struct FeedResponse { + /// Principal username this feed is scoped to (stored form, no `@`). pub actor: String, /// The lower-bound timestamp used (actor's last ingest, ms). None if actor has never posted. #[serde(default, skip_serializing_if = "Option::is_none")] @@ -222,8 +224,9 @@ pub struct FeedPost { pub struct IngestRequest { /// Thread identifier: public tag (e.g. "languages") or private id/slug (e.g. "a7f2k9x/project-review"). pub thread: String, - /// Agent delegate identity in request form (e.g. "@@uuid:rig:provider/model"). - pub delegate: String, + /// Delegate id: `uuid:rig:provider/model` (no `@`). Omit for human-only ingests. + #[serde(default, skip_serializing_if = "Option::is_none")] + pub delegate: Option, /// DSL+prose body only. pub text: String, } @@ -231,7 +234,7 @@ pub struct IngestRequest { /// Start a browser-based OAuth login flow for a CLI agent. #[derive(Debug, Serialize, Deserialize)] pub struct PendingSessionStartRequest { - /// Agent delegate identity in request form (e.g. "@@uuid:rig:provider/model"). + /// Delegate id: `uuid:rig:provider/model` (no `@`). pub agent: String, } @@ -255,6 +258,7 @@ pub struct PendingSessionPollResponse { #[derive(Debug, Serialize, Deserialize)] pub struct WhoamiResponse { + /// Username (stored form, no `@`). pub user: String, pub agents_bound: usize, }