Side B implements a substantial, coherent feature (Reddit OAuth linking with UUID-canonical identity, conflict handling, private linked-provider display) with corresponding storage schema changes, projection logic, and extensive mock-server test infrastructure updates. Side A mostly removes an unused demo counter feature and introduces a settlement-worker/caching refactor for ranking that adds real architectural value (batched async vote processing with cached scores), but is smaller in scope and partly consists of deleting demo scaffolding rather than building new lasting functionality.
constitution · epochs · watch · epoch 3
c_4772ee88dbe3 (tommy-mor) vs c_afa638171cf7 (tommy-mor)
download prompt · raw event · cmp_0a4cbbd7fb2844
council reasoning
B lands lasting identity architecture (UUID-only principals, multi-provider OAuth linking with conflict handling, private linked-provider UI, Reddit OAuth end-to-end, and projection/trust-weight fixes) that the product depends on. A is solid systems work—deleting the demo counter and adding a settlement worker plus ranking cache/read paths—but it is mostly internal cleanup and optimization versus B’s foundational auth model.
Side B introduces substantial new identity infrastructure by adding Reddit OAuth alongside GitHub, changing the account model so UUIDs are the canonical identity with provider linking, updating login/account flows, storage, projection logic, routes, and OAuth implementations. Side A mainly removes the demo counter, switches ranking rendering to use cached scores with read locks, and adds a settlement worker/cache path, which is useful performance and cleanup work but has a narrower long-term impact than the new authentication and identity capabilities.
sides
A — c_4772ee88dbe3 (tommy-mor)
message
[07715165] nice
diff preview
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index c3c62a76f424010d77a6090c84dd0b82098f573e..da2536112faea313352624cf2ce0ddd0ab3377c1 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -6,7 +6,7 @@ use axum::{
use std::collections::HashMap;
use crate::{
- html::{demo_counter_panel, js_string_literal, ranking_panel, JsBuilder},
+ html::{js_string_literal, ranking_panel, JsBuilder},
parser::parse_reddit_url,
parser_render::parser_panel_morph,
state::AppState,
@@ -35,13 +35,6 @@ pub async fn post_ui_html(
};
match action {
- HtmlUiAction::BumpDemoCounter => {
- let count = state.bump_demo_counter().await;
- let panel = demo_counter_panel(count, state.event_log.path().to_string_lossy().as_ref());
- JsBuilder::new()
- .morph_selector("#demo-counter-panel", panel)
- .into_response()
- }
HtmlUiAction::RecordVote {
a,
b,
@@ -54,8 +47,8 @@ pub async fn post_ui_html(
{
return ui_js_warn(&e).into_response();
}
- let mut group = state.group.write().await;
- let panel = ranking_panel(&mut group);
+ let group = state.group.read().await;
+ let panel = ranking_panel(&group);
JsBuilder::new()
.morph_selector("#ranking-panel", panel)
.into_response()
@@ -87,20 +80,6 @@ mod tests {
assert!(matches!(err, HtmlUiParseError::MissingRpc));
}
- #[test]
- fn bump_action_deserializes() {
- let template = serde_json::json!({ "action": "bump_demo_counter" });
- let mut form = HashMap::new();
- form.insert(
- UI_RPC_FIELD.to_string(),
- serde_json::to_string(&template).unwrap(),
- );
- assert_eq!(
- parse_html_ui_from_form(&form).unwrap(),
- HtmlUiAction::BumpDemoCounter
- );
- }
-
#[test]
fn record_vote_action_deserializes() {
let template = serde_json::json!({
diff --git a/server/src/events.rs b/server/src/events.rs
index b969242534e184d4f0a689543a479670b08a18df..eff80aef0257f706d2341f666e63d6a3d921bf6e 100644
--- a/server/src/events.rs
+++ b/server/src/events.rs
@@ -5,8 +5,6 @@ use serde::{Deserialize, Serialize};
pub enum Event {
/// Page view recorded (path → counter in views.json).
ViewRecorded { path: String, ts: i64 },
- /// Demo counter bump from `POST /ui` (persisted in the single JSONL log).
- DemoCounterBumped { ts: i64, value: u64 },
/// Pairwise comparison vote (replayed into [`crate::reducer::GroupState`] on boot).
VoteRecorded {
ts: i64,
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index 5b1d0b5a887d89e7e80796aa7a6c8ed5baaf2782..d69ed962b5c8625bc83c933b1825f2cc1d0868e2 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -13,7 +13,7 @@ use crate::{
form_template::template_json_compact,
parser_action::ParserAction,
parser_render::parser_panel,
- ranking::ranked_items,
+ ranking::ranked_items_cached,
reducer::GroupState,
state::AppState,
ui_action::UI_RPC_FIELD,
@@ -199,10 +199,8 @@ fn layout(title: &str, body: Markup, views: u64, theme: &str, theme_next: &str)
}
}
-pub fn ranking_panel(group: &mut GroupState) -> Markup {
- const MAX_ITERS: usize = 10_000;
- const TOL: f64 = 1e-8;
- let items = ranked_items(group, MAX_ITERS, TOL);
+pub fn ranking_panel(group: &GroupState) -> Markup {
+ let items = ranked_items_cached(group);
html! {
section id="ranking-panel" class="demo-panel" {
h2 { "Ranking" }
@@ -260,35 +258,6 @@ pub fn vote_panel() -> Markup {
}
-pub fn demo_counter_panel(count: u64, event_log_path: &str) -> Markup {
- let rpc = template_json_compact(&serde_json::json!({ "action": "bump_demo_counter" }))
- .expect("rpc json");
- html! {
- section id="demo-counter-panel" class="demo-panel" {
- h1 { "sorter2" }
- p class="muted" {
- "Pairwise ranking scaffold — votes persist to JSONL and replay on boot."
- }
- p class="demo-count" {
- strong { "Counter: " }
- span id="demo-count-value" { (count) }
- }
- p class="muted small" {
- "Event log: " code { (event_log_path) }
- }
- form method="post" action="/ui" id="demo-bump-form" {
- input type="hidden" name=(UI_RPC_FIELD) value=(rpc);
- button type="submit" class="btn-primary" { "Bump (POST /ui → eval JS)" }
- }
- p class="muted small" {
- "Uses hidden "
- code { "__rpc__" }
- " JSON + Idiomorph morph — no full page reload."
- }
- }
- }
-}
-
pub async fn home(
State(state): State<AppState>,
jar: CookieJar,
@@ -297,16 +266,15 @@ pub async fn home(
let path = uri.path().to_string();
state.views.increment(path.clone());
let views = state.views.get_views(&path);
- let count = *state.demo_counter.read().await;
let theme = theme_from_jar(&jar);
let theme_next = theme_next_from_uri(&uri);
- let mut group = state.group.write().await;
+ let group = state.group.read().await;
let empty_action = ParserAction::suggest(String::new(), None);
let body = html! {
+ h1 { "sorter2" }
(parser_panel("", &empty_action))
(vote_panel())
- (ranking_panel(&mut group))
- (demo_counter_panel(count, state.event_log.path().to_string_lossy().as_ref()))
+ (ranking_panel(&group))
};
layout("sorter2", body, views, theme, &theme_next)
}
diff --git a/server/src/lib.rs b/server/src/lib.rs
index 6716c5b282e7980a7a0f03d63ad8b25eda61cc55..fa423640d598f4ba97a5885d228e78d7b97f7a22 100644
--- a/server/src/lib.rs
+++ b/server/src/lib.rs
@@ -9,6 +9,7 @@ pub mod parser_render;
pub mod path_types;
pub mod ranking;
pub mod reducer;
+pub mod settlement;
pub mod state;
pub mod ui_action;
pub mod views;
diff --git a/server/src/ranking.rs b/server/src/ranking.rs
index 89d3280126a8d8f841721ce8cb63ff735d68752a..2d706762792ba9239bb3f1c2e4974a2fde908013 100644
--- a/server/src/ranking.rs
+++ b/server/src/ranking.rs
@@ -91,6 +91,11 @@ pub fn compute_group_ranking(group: &mut GroupState, max_iters: usize, tol: f64)
pub fn ranked_items(group: &mut GroupState, max_iters: usize, tol: f64) -> Vec<RankedItem> {
compute_group_ranking(group, max_iters, tol);
+ ranked_items_cached(group)
+}
+
+/// Read cached scores without recomputing (HTTP fast path).
+pub fn ranked_items_cached(group: &GroupState) -> Vec<RankedItem> {
let mut items: Vec<RankedItem> = group
.idx_to_item
.iter()
@@ -105,7 +110,12 @@ pub fn ranked_items(group: &mut GroupState, max_iters: usize, tol: f64) -> Vec<R
items
}
-fn compute_scores_from_edges(n: usize, edges: impl Iterator<Item = ((usize, usize), f64)>, max_iters: usize, tol: f64) -> Vec<f64> {
+pub fn compute_scores_from_edges(
+ n: usize,
+ edges: impl Iterator<Item = ((usize, usize), f64)>,
+ max_iters: usize,
+ tol: f64,
+) -> Vec<f64> {
if n == 0 {
return vec![];
}
diff --git a/server/src/settlement.rs b/server/src/settlement.rs
new file mode 100644
index 0000000000000000000000000000000000000000..1f722ceaea62cda22c28ab71551f259fbf049b81
--- /dev/null
+++ b/server/src/settlement.rs
@@ -0,0 +1,114 @@
+use std::sync::Arc;
+
+use tokio::sync::{mpsc, oneshot, RwLock};
+
+use crate::{
+ event_log::EventLog,
+ events::Event,
+ ranking::compute_scores_from_edges,
+ reducer::{GroupState, VoteData},
+};
+
+const MAX_ITERS: usize = 10_000;
+const TOL: f64 = 1e-8;
+
+pub struct SettlementCommand {
+ pub vote: VoteData,
+ pub event: Event,
+ pub reply: oneshot::Sender<Result<(), String>>,
+}
+
+#[derive(Clone)]
+pub struct SettlementClient {
+ tx: mpsc::Sender<SettlementCommand>,
+}
+
+impl SettlementClient {
+ pub fn spawn(group: Arc<RwLock<GroupState>>, event_log: Arc<EventLog>) -> Self {
+ let (tx, rx) = mpsc::channel(64);
+ tokio::spawn(settlement_worker(rx, group, event_log));
+ Self { tx }
+ }
+
+ pub async fn record_vote(&self, vote: VoteData, event: Event) -> Result<(), String> {
+ let (reply, rx) = oneshot::channel();
+ self.tx
+ .send(SettlementCommand {
+ vote,
+ event,
+ reply,
+ })
+ .await
+ .map_err(|_| "settlement worker stopped".to_string())?;
+ rx.await
+ .map_err(|_| "settlement worker stopped".to_string())?
+ }
+}
+
+async fn settlement_worker(
+ mut rx: mpsc::Receiver<SettlementCommand>,
+ group: Arc<RwLock<GroupState>>,
+ event_log: Arc<EventLog>,
+) {
+ while let Some(first) = rx.recv().await {
+ let mut batch = vec![first];
+ while let Ok(more) = rx.try_recv() {
+ batch.push(more);
+ }
+
+ let mut disk_err: Option<String> = None;
+ for cmd in &batch {
+ if let Err(e) = event_log.append(&cmd.event).await {
+ disk_err = Some(e.to_string());
+ break;
+ }
+ }
+
+ if let Some(err) = disk_err {
+ for cmd in batch {
+ let _ = cmd.reply.send(Err(err.clone()));
+ }
+ continue;
+ }
+
+ let (edges, n) = {
+ let mut w = group.write().await;
+ for cmd in &batch {
+ w.apply_vote(cmd.vote.clone());
+ }
+ (w.edges.clone(), w.idx_to_item.len())
+ };
+
+ let new_scores = compute_scores_from_edges(
+ n,
+ edges.iter().map(|(&k, &v)| (k, v)),
+ MAX_ITERS,
+ TOL,
+ );
+
+ {
+ let mut w = group.write().await;
+ w.cached_scores = new_scores;
+ w.dirty = false;
+ }
+
+ for cmd in batch {
+ let _ = cmd.reply.send(Ok(()));
+ }
+ }
+}
+
+/// Compute ranking cache from current in-memory edges (startup replay only).
+pub fn warm_ranking_cache(group: &mut GroupState) {
+ if !group.dirty {
+ return;
+ }
+ let n = group.idx_to_item.len();
+ group.cached_scores = compute_scores_from_edges(
+ n,
+ group.edges.iter().map(|(&k, &v)| (k, v)),
+ MAX_ITERS,
+ TOL,
+ );
+ group.dirty = false;
+}
diff --git a/server/src/state.rs b/server/src/state.rs
index 8ec9902e2ecc31cf8208f7ad6365891dc5537eed..1922541a4064c2de1df2d993a461cae783320e05 100644
--- a/server/src/state.rs
+++ b/server/src/state.rs
@@ -6,6 +6,7 @@ use crate::{
event_log::EventLog,
events::Event,
reducer::{GroupState, VoteData},
+ settlement::{warm_ranking_cache, SettlementClient},
views::ViewStore,
};
@@ -38,8 +39,8 @@ pub struct AppState {
pub cfg: Arc<AppConfig>,
pub event_log: Arc<EventLog>,
pub views: ViewStore,
- pub demo_counter: Arc<RwLock<u64>>,
pub group: Arc<RwLock<GroupState>>,
+ settlement: SettlementClient,
}
impl AppState {
@@ -48,14 +49,10 @@ impl AppState {
let views_path = format!("{}/views.json", cfg.data_dir);
let views = ViewStore::new(&views_path);
- let mut demo_counter: u64 = 0;
let mut group = GroupState::new();
if let Ok((events, _)) = event_log.load_all().await {
for ev in events {
match ev {
- Event::DemoCounterBumped { value, .. } => {
- demo_counter = demo_counter.max(value);
- }
Event::VoteRecorded {
ts,
a,
@@ -74,30 +71,20 @@ impl AppState {
}
}
+
… preview truncated; 6,096 characters omittedB — c_afa638171cf7 (tommy-mor)
message
[52f5c51c] Add Reddit OAuth linking and make UUID the only account identity. OAuth providers only attach to a session UUID (first link creates the principal); linked providers stay private on the account page. Co-authored-by: Cursor <cursoragent@cursor.com>
diff preview
diff --git a/AGENTS.md b/AGENTS.md
index 6e0fd8ebb65d665c9c1438e3275971d62b98fd95..e9cc3173dbeb21ad0fc090ca7b407b027c7820a9 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -35,8 +35,11 @@ Environment variables (defaults in `server/src/state.rs`):
- `SORTER2_DATA_DIR` — default `./data` (created on startup)
- `SORTER2_EVENT_LOG` — default `{data_dir}/events.jsonl`
- `SORTER2_BASE_URL` — public origin (also drives Secure cookies when `https://`)
-- `GITHUB_CLIENT_ID` / `GITHUB_CLIENT_SECRET` — GitHub OAuth (optional; login disabled if unset)
-- `SORTER2_ALLOW_MOCK_OAUTH=1` — allow `mock_user` on `/auth/github` (tests only)
+- `GITHUB_CLIENT_ID` / `GITHUB_CLIENT_SECRET` — GitHub OAuth linking (optional)
+- `REDDIT_CLIENT_ID` / `REDDIT_CLIENT_SECRET` (or `REDDIT_APP_*`) — Reddit API import + OAuth linking (optional)
+- `SORTER2_ALLOW_MOCK_OAUTH=1` — allow `mock_user` on `/auth/github` and `/auth/reddit` (tests only)
+
+Identity: UUID is canonical. OAuth providers only *link* to a UUID (first link creates the principal). Linked providers are private to the account owner.
Health check: `GET /healthz` → `ok`.
diff --git a/server/src/auth/mod.rs b/server/src/auth/mod.rs
index 5906f93b13853421e96a3c37bc9d8202a47842bf..c706ae8045a811e5941f5f6c72da88f42a403a82 100644
--- a/server/src/auth/mod.rs
+++ b/server/src/auth/mod.rs
@@ -1,4 +1,8 @@
-//! GitHub OAuth login, session cookies, and vote actor resolution.
+//! OAuth linking, session cookies, and vote actor resolution.
+//!
+//! Canonical identity is a UUID. OAuth providers only *link* to that UUID
+//! (first link creates the principal; later links attach while logged in).
+//! Which providers are linked is private to the account owner.
pub mod config;
pub mod identity;
@@ -22,7 +26,9 @@ use crate::{
form_template::template_json_compact,
html::layout,
state::AppState,
- storage_schema::{oauth_link_owner, pseudonym_owner, Store, StoreFields},
+ storage_schema::{
+ linked_providers_for_uuid, oauth_link_owner, pseudonym_owner, Store, StoreFields,
+ },
ui_action::UI_RPC_FIELD,
};
@@ -53,10 +59,12 @@ fn new_actor_uuid() -> String {
pub struct LoginQuery {
#[serde(default)]
pub return_to: Option<String>,
+ #[serde(default)]
+ pub error: Option<String>,
}
#[derive(Debug, Deserialize)]
-pub struct GitHubStartQuery {
+pub struct OAuthStartQuery {
#[serde(default)]
pub return_to: Option<String>,
#[serde(default)]
@@ -72,15 +80,22 @@ fn return_from_query_or_jar(jar: &CookieJar, query: Option<&str>) -> String {
.unwrap_or_else(|| "/".to_string())
}
-fn oauth_providers(base_url: &str, return_to: &str) -> Vec<(&'static str, String)> {
+/// Available OAuth link targets: `(provider_key, label, start_href)`.
+fn oauth_providers(base_url: &str, return_to: &str) -> Vec<(&'static str, &'static str, String)> {
let mut out = Vec::new();
+ let enc = urlencoding::encode(return_to);
if oauth::GitHubConfig::from_env(base_url).is_some() {
out.push((
- "GitHub",
- format!(
- "/auth/github?return_to={}",
- urlencoding::encode(return_to)
- ),
+ "github",
+ oauth::provider_label("github"),
+ format!("/auth/github?return_to={enc}"),
+ ));
+ }
+ if oauth::RedditConfig::from_env(base_url).is_some() {
+ out.push((
+ "reddit",
+ oauth::provider_label("reddit"),
+ format!("/auth/reddit?return_to={enc}"),
));
}
out
@@ -125,23 +140,41 @@ fn alias_claim_forms(return_to: &str, submit_label: &str) -> Result<Markup, Stat
})
}
-fn signed_out_body(providers: &[(&str, String)]) -> Markup {
+fn login_error_message(code: Option<&str>) -> Option<&'static str> {
+ match code {
+ Some("oauth_taken") => {
+ Some("that OAuth account is already linked to a different sorter2 account")
+ }
+ Some("oauth_failed") => Some("OAuth failed — try again"),
+ _ => None,
+ }
+}
+
+fn signed_out_body(
+ providers: &[(&str, &str, String)],
+ error: Option<&str>,
+) -> Markup {
html! {
main class="panel login-page" {
section class="login-section" {
h1 { "sign in" }
- p class="muted" { "link an account to vote under a lasting alias" }
+ p class="muted" {
+ "link an OAuth account to create your identity, then claim an alias to vote"
+ }
+ @if let Some(msg) = login_error_message(error) {
+ p class="alias-bad" data-testid="login-error" { (msg) }
+ }
@if providers.is_empty() {
p class="muted" {
- "OAuth is not configured. Set GITHUB_CLIENT_ID and GITHUB_CLIENT_SECRET."
+ "OAuth is not configured. Set GitHub and/or Reddit client credentials."
}
} @else {
ul class="oauth-provider-list" {
- @for (name, href) in providers {
+ @for (key, label, href) in providers {
li {
a href=(href) class="btn-primary oauth-provider"
- data-testid=(format!("oauth-{}", name.to_lowercase())) {
- (format!("Continue with {name}"))
+ data-testid=(format!("oauth-{key}")) {
+ (format!("Link {label}"))
}
}
}
@@ -156,7 +189,10 @@ fn signed_out_body(providers: &[(&str, String)]) -> Markup {
fn account_body(
actor: &session::SessionActor,
aliases: &[String],
- providers: &[(&str, String)],
+ // Provider keys already linked to this UUID (private).
+ linked: &[String],
+ // Providers available to link: not yet attached.
+ unlinkable: &[(&str, &str, String)],
claim_forms: Markup,
) -> Markup {
let current = actor.pseudonym.trim();
@@ -212,16 +248,29 @@ fn account_body(
(claim_forms)
}
- @if !providers.is_empty() {
- section class="login-section" {
- h2 { "linked sign-in" }
- p class="muted small" { "sign in again with the same provider to return to this account" }
+ section class="login-section" {
+ h2 { "linked sign-in" }
+ p class="muted small" {
+ "private to you — linking more providers raises trust weight without publishing which accounts you use"
+ }
+ @if linked.is_empty() {
+ p class="muted" data-testid="linked-providers-empty" { "none yet" }
+ } @else {
+ ul class="linked-provider-list" data-testid="linked-providers" {
+ @for key in linked {
+ li data-testid=(format!("linked-{key}")) {
+ (oauth::provider_label(key))
+ }
+ }
+ }
+ }
+ @if !unlinkable.is_empty() {
ul class="oauth-provider-list" {
- @for (name, href) in providers {
+ @for (key, label, href) in unlinkable {
li {
a href=(href) class="btn-secondary oauth-provider"
- data-testid=(format!("oauth-relink-{}", name.to_lowercase())) {
- (format!("Re-link {name}"))
+ data-testid=(format!("oauth-link-{key}")) {
+ (format!("Link {label}"))
}
}
}
@@ -243,12 +292,21 @@ fn account_body(
fn login_body(
session: Option<&session::SessionActor>,
aliases: &[String],
- providers: &[(&str, String)],
+ linked: &[String],
+ providers: &[(&str, &str, String)],
claim_forms: Option<Markup>,
+ error: Option<&str>,
) -> Markup {
match (session, claim_forms) {
- (Some(actor), Some(forms)) => account_body(actor, aliases, providers, forms),
- _ => signed_out_body(providers),
+ (Some(actor), Some(forms)) => {
+ let unlinkable: Vec<_> = providers
+ .iter()
+ .filter(|(key, _, _)| !linked.iter().any(|p| p == key))
+ .cloned()
+ .collect();
+ account_body(actor, aliases, linked, &unlinkable, forms)
+ }
+ _ => signed_out_body(providers, error),
}
}
@@ -268,6 +326,10 @@ pub async fn login_page(
.as_ref()
.map(|s| alias_list(db, &s.uuid))
.unwrap_or_default();
+ let linked = session
+ .as_ref()
+ .map(|s| linked_providers_for_uuid(db, &s.uuid).unwrap_or_default())
+ .unwrap_or_default();
let providers = oauth_providers(&base_url_from_env(state.cfg.port), &return_to);
let claim_forms = if session.is_some() {
@@ -282,7 +344,14 @@ pub async fn login_page(
} else {
"login · sorter2"
},
- login_body(session.as_ref(), &aliases, &providers, claim_forms),
+ login_body(
+ session.as_ref(),
+ &aliases,
+ &linked,
+ &providers,
+ claim_forms,
+ query.error.as_deref(),
+ ),
state.views.get_views("/login"),
session
.as_ref()
@@ -302,7 +371,6 @@ pub async fn alias_page(
let db = state.projection_store.db();
let session = session::load_valid_session(db, &session_id).ok_or(StatusCode::UNAUTHORIZED)?;
if session::session_has_pseudonym(&session) {
- // Already onboarded — manage aliases on the account page.
return Ok(Redirect::to("/login").into_response());
}
@@ -331,7 +399,7 @@ pub async fn alias_page(
pub async fn github_start(
State(state): State<AppState>,
jar: CookieJar,
- Query(query): Query<GitHubStartQuery>,
+ Query(query): Query<OAuthStartQuery>,
) -> Result<Response, StatusCode> {
let cfg = oauth::GitHubConfig::from_env(&base_url_from_env(state.cfg.port))
.ok_or(StatusCode::SERVICE_UNAVAILABLE)?;
@@ -342,7 +410,28 @@ pub async fn github_start(
} else {
None
};
- let url = oauth::authorize_url(&cfg, &state_token, mock_user);
+ let url = oauth::github_authorize_url(&cfg, &state_token, mock_user);
+ let jar = jar
+ .add(session::oauth_state_cookie_value(&state_token))
+ .add(session::auth_return_cookie_value(&return_to));
+ Ok((jar, Redirect::temporary(&url)).into_response())
+}
+
+pub async fn reddit_start(
+ State(state): State<AppState>,
+ jar: CookieJar,
+ Query(query): Query<OAuthStartQuery>,
+) -> Result<Response, StatusCode> {
+ let cfg = oauth::RedditConfig::from_env(&base_url_from_env(state.cfg.port))
+ .ok_or(StatusCode::SERVICE_UNAVAILABLE)?;
+ let return_to = return_from_query_or_jar(&jar, query.return_to.as_deref());
+ let state_token = session::new_oauth_state();
+ let mock_user = if config::mock_oauth_allowed() {
+ query.mock_user.as_deref()
+ } else {
+ None
+ };
+ let url = oauth::reddit_authorize_url(&cfg, &state_token, mock_user);
let jar = jar
.add(session::oauth_state_cookie_value(&state_token))
.add(session::auth_return_cookie_value(&return_to));
@@ -355,6 +444,13 @@ pub struct OAuthCallbackQuery {
pub state: String,
}
+/// Link `provider:provider_id` to a UUID.
+///
+/// - Logged in + new provider → attach to session UUID
+/// - Logged in + already ours → no-op
+/// - Logged in
… preview truncated; 29,823 characters omittedHardlinks — judgments / attempts / prompt
judgments
attempts
Prompt text is loaded only by the download route.