B is a coherent, compiling change that simplifies the room model (drops the unused/confusing ThreadVisibility field), threads that change consistently through events, reducer, RPC, CLI (adds `room create`), docs, and tests. A is a chaotic dump of speculative/idea files placed at repo root (not in server/src), several of which literally contain pasted shell prompts and `cat` commands baked into the file content, indicating they are not real, integrated source files but seed notes/junk with no demonstrated build integration.
constitution · epochs · watch · epoch 3
c_f6d0fed9bf9a (tommy-mor) vs c_1c1c8e7a2de8 (tommy-mor)
download prompt · raw event · cmp_0e6310479aa3ab
council reasoning
Side B ships a real, integrated feature path: CLI `room create`, a cleaner private-room model (drop ThreadVisibility/RoomState, rooms as HashSet), matching RPC/reducer/timeline/test/doc updates. Side A is mostly an exploratory dump (notes .tdsl files, TEST scripts, a large Reddit parser prototype) with lasting code quality undercut by corrupted patches (forms.rs/ranking.rs are shell `cat` paste, not clean sources).
Side A introduces substantial new project functionality across multiple areas: a ranking engine with connected-component and rank-centrality logic plus tests, a reducer for event-driven state, UI action parsing with JSON form templates, browser plumbing, and a large parser/autocomplete system. Side B is a focused refinement that adds a CLI `room create` command and simplifies room handling by removing the room visibility concept (replacing a room map with a `HashSet` and updating RPC/tests/docs), which is useful but comparatively incremental.
sides
A — c_f6d0fed9bf9a (tommy-mor)
message
[1d9d8ade] init seed
diff preview
diff --git a/TEST.sh b/TEST.sh
new file mode 100755
index 0000000000000000000000000000000000000000..266b71f29259f5c2cad2617476ebe2ebc9596d39
--- /dev/null
+++ b/TEST.sh
@@ -0,0 +1,4 @@
+#!/usr/bin/env bash
+set -euo pipefail
+cargo test --all
+./scripts/clj-test.sh
diff --git a/bundle.js b/bundle.js
new file mode 100644
index 0000000000000000000000000000000000000000..8d316f9a57cc7c379fe4bd8e42e092c7eac5d265
--- /dev/null
+++ b/bundle.js
@@ -0,0 +1,52 @@
+/**
+ * Slug web UI: only plumbing — fetch/eval/SSE. No product UI logic here.
+ */
+(function () {
+ function evalJs(js) {
+ if (js && String(js).trim()) {
+ eval(js);
+ }
+ }
+
+ // Theme cookie sync (runs before paint; full reload if localStorage disagrees with cookie)
+
+ function initSlugUi() {
+ // POST forms → eval response (except theme + full-navigation forms)
+ document.addEventListener('submit', async function (e) {
+ var f = e.target;
+ if (!f || f.tagName !== 'FORM') return;
+ if ((f.method || 'get').toLowerCase() !== 'post') return;
+ if (f.id === 'slug-theme-form') return;
+ if (f.getAttribute('data-navigate') === 'full') return;
+ e.preventDefault();
+ var resp = await fetch(f.action, {
+ method: 'POST',
+ body: new URLSearchParams(new FormData(f)),
+ headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
+ credentials: 'same-origin',
+ });
+ evalJs(await resp.text());
+ });
+
+ // SSE: server-pushed JS
+ function connectSSE() {
+ var ssePath = window.location.pathname + window.location.search;
+ var es = new EventSource('/sse?path=' + encodeURIComponent(ssePath));
+ es.onmessage = function (e) {
+ evalJs(e.data);
+ };
+ es.onerror = function () {
+ es.close();
+ setTimeout(connectSSE, 3000);
+ };
+ }
+ connectSSE();
+ }
+
+ if (document.readyState === 'loading') {
+ document.addEventListener('DOMContentLoaded', initSlugUi);
+ } else {
+ initSlugUi();
+ }
+})();
+
diff --git a/clj-test.sh b/clj-test.sh
new file mode 100755
index 0000000000000000000000000000000000000000..b62a49b98ed60a65a46807b7ad80fa3142f14952
--- /dev/null
+++ b/clj-test.sh
@@ -0,0 +1,5 @@
+#!/usr/bin/env bash
+set -euo pipefail
+cd "$(dirname "$0")/.."
+mkdir -p target
+exec clojure -M:kaocha
diff --git a/forms.rs b/forms.rs
new file mode 100644
index 0000000000000000000000000000000000000000..d509fd889fde3fed2662ce0a39006b7a51ae762a
--- /dev/null
+++ b/forms.rs
@@ -0,0 +1,145 @@
+tommy@Tommys-Laptop:~/programming/slug-star/slug|main ⇒ cat server/src/form_template.rs
+//! Plan2-style JSON templates with `{"$form": "field_name"}` holes, filled from
+//! `application/x-www-form-urlencoded` (or any `String` → `String` map) **before**
+//! deserializing into a typed struct.
+//!
+//! # Wire format
+//!
+//! Templates are **compact JSON** (`serde_json::to_string`): one line, no pretty
+//! printing, strings escaped per JSON rules (`\"`, `\n`, etc.). Embed that string
+//! in HTML attributes or text nodes with normal HTML escaping (e.g. maud), not
+//! bespoke encodings.
+//!
+//! # Power vs flat hidden fields
+//!
+//! A form is always a string→string map. You can fake depth with dotted keys (`a.b.c`),
+//! but one structured blob (`__rpc__` = compact JSON) gives you nested objects,
+//! arrays, and optional fields without inventing a new naming scheme each time.
+//!
+//! # Security
+//!
+//! Substitution runs **before** `serde` into your command type. It does not fix
+//! authorization: if the client can replace the hidden `__rpc__` value, they can
+//! change the command shape unless you validate (signed blob, server-side session
+//! context, or treat the blob as hints only). Same threat model as any hidden field.
+
+use serde::Serialize;
+use serde_json::Value;
+use std::collections::HashMap;
+
+/// Serialize a value to compact JSON for a hidden `__rpc__` (or similar) field.
+pub fn template_json_compact<T: Serialize>(v: &T) -> serde_json::Result<String> {
+ serde_json::to_string(v)
+}
+
+/// Recursively walk the JSON AST and replace `{"$form": "key"}` with the submitted
+/// string for `key` (empty if missing). Other keys are unchanged.
+pub fn substitute_form_vars(val: &mut Value, form_data: &HashMap<String, String>) {
+ match val {
+ Value::Object(map) => {
+ if map.len() == 1 {
+ if let Some(Value::String(field_name)) = map.get("$form") {
+ let submitted = form_data
+ .get(field_name.as_str())
+ .map(|s| s.as_str())
+ .unwrap_or("");
+ *val = Value::String(submitted.to_string());
+ return;
+ }
+ }
+ for v in map.values_mut() {
+ substitute_form_vars(v, form_data);
+ }
+ }
+ Value::Array(arr) => {
+ for v in arr.iter_mut() {
+ substitute_form_vars(v, form_data);
+ }
+ }
+ _ => {}
+ }
+}
+
+/// Parse JSON, apply [`substitute_form_vars`], return the mutated value.
+pub fn fill_template_from_form(
+ template_json: &str,
+ form_data: &HashMap<String, String>,
+) -> Result<Value, serde_json::Error> {
+ let mut v: Value = serde_json::from_str(template_json)?;
+ substitute_form_vars(&mut v, form_data);
+ Ok(v)
+}
+
+#[cfg(test)]
+mod tests {
+ use super::*;
+ use serde::Deserialize;
+
+ #[derive(Debug, Deserialize, PartialEq, Eq)]
+ struct Demo {
+ room: String,
+ thread_tag: String,
+ nested: Nested,
+ }
+
+ #[derive(Debug, Deserialize, PartialEq, Eq)]
+ struct Nested {
+ text: String,
+ }
+
+ #[test]
+ fn holes_become_strings() {
+ let json = r#"{
+ "room": "public",
+ "thread_tag": {"$form": "tag"},
+ "nested": {"text": {"$form": "body"}}
+ }"#;
+ let mut form = HashMap::new();
+ form.insert("tag".into(), "foo".into());
+ form.insert("body".into(), "hello\nworld".into());
+
+ let v = fill_template_from_form(json, &form).unwrap();
+ let d: Demo = serde_json::from_value(v).unwrap();
+ assert_eq!(
+ d,
+ Demo {
+ room: "public".into(),
+ thread_tag: "foo".into(),
+ nested: Nested {
+ text: "hello\nworld".into(),
+ },
+ }
+ );
+ }
+
+ #[test]
+ fn missing_form_key_is_empty_string() {
+ let json = r#"{"x": {"$form": "nope"}}"#;
+ let mut form = HashMap::new();
+ form.insert("other".into(), "y".into());
+ let v = fill_template_from_form(json, &form).unwrap();
+ assert_eq!(v["x"], "");
+ }
+
+ #[test]
+ fn array_of_holes() {
+ let json = r#"{"items": [{"$form": "a"}, {"$form": "b"}]}"#;
+ let mut form = HashMap::new();
+ form.insert("a".into(), "1".into());
+ form.insert("b".into(), "2".into());
+ let v = fill_template_from_form(json, &form).unwrap();
+ assert_eq!(v["items"], serde_json::json!(["1", "2"]));
+ }
+
+ #[test]
+ fn template_json_compact_escapes_and_single_line() {
+ let s = template_json_compact(&serde_json::json!({
+ "x": "quote\"and\nnewline"
+ }))
+ .unwrap();
+ assert!(!s.contains('\n'));
+ assert!(s.contains("\\\"") || s.contains("\\n"));
+ }
+}
+tommy@Tommys-Laptop:~/programming/slug-star/slug|main ⇒
+
diff --git a/gameifying.tdsl b/gameifying.tdsl
new file mode 100644
index 0000000000000000000000000000000000000000..93d2a61d94fcba4370c82d9612e6bb0f0318cc15
--- /dev/null
+++ b/gameifying.tdsl
@@ -0,0 +1,2 @@
+consider gating certain views (top all time?) by a 10 day usage streak.. or something like that.
+or like a path, on homepage(?), that shows day 1: r/amitheasshole, day2: r/aww, day3: gaming, or something like that. progressive revelation + usage incentive.
diff --git a/pagerank_streaming.tdsl b/pagerank_streaming.tdsl
new file mode 100644
index 0000000000000000000000000000000000000000..0f2231b94936c17610adf653ca26b0faa6f2ac3a
--- /dev/null
+++ b/pagerank_streaming.tdsl
@@ -0,0 +1,11 @@
+eventually i want to have ranking histories.
+like "visionary" and "fraud" waxing and waning in a uplot graph over time for #elon-musk.
+there are too many query combinations to precomupte the ranking histories
+(arbitrary user filters, and tag overlap combinations maybe),
+so we're just going to have to calculate them all on demand.
+computers are fast, its okay. for each vote, we need to calculate rank centrality again.
+i was thinking, for n votes we calculate the rank centrality,
+and get node weights. we then output that data to the client (over websocket, or testable barrier).
+then we calculate n+1 votes, _but we keep the node weights in memory_
+so the rank centrality process converges faster.
+this also has the side effect of making the ranking stream in satisfyingly as you load the page.
diff --git a/parser.rs b/parser.rs
new file mode 100644
index 0000000000000000000000000000000000000000..2b87b974f8d1dd93bee35681d87668a94e4ef349
--- /dev/null
+++ b/parser.rs
@@ -0,0 +1,1808 @@
+use std::collections::HashMap;
+use std::rc::Rc;
+use std::cell::RefCell;
+use crate::ui::action::UIAction;
+use crate::ui::types::{Suggestion, GuideOption, ScrollingSuggestion};
+
+// --- Core Abstractions ---
+
+/// Unique identifier for nodes in the graph
+type NodeId = &'static str;
+
+/// Pattern matching for edges
+#[derive(Debug, Clone)]
+pub enum EdgePattern {
+ /// Matches exact literal string
+ Literal(&'static str),
+
+ /// Matches any prefix of a string and suggests the full string
+ /// e.g., PrefixOf("reddit.com") matches "r", "re", "red", "reddit", "reddit.com"
+ PrefixOf(&'static str),
+
+ /// Captures a variable segment (e.g., subreddit name, username)
+ Variable(&'static str),
+
+ /// Matches any string (wildcard)
+ Any,
+}
+
+impl EdgePattern {
+ /// Try to match this pattern against input, return (consumed_chars, captured_value)
+ fn matches(&self, input: &str) -> Option<(usize, Option<String>)> {
+ match self {
+ EdgePattern::Literal(lit) => {
+ if input.starts_with(lit) {
+ Some((lit.len(), None))
+ } else {
+ None
+ }
+ }
+ EdgePattern::PrefixOf(target) => {
+ // Check if input is a prefix of target
+ if target.starts_with(input) && !input.is_empty() {
+ // It's a valid prefix
+ Some((input.len(), None))
+ } else if input.starts_with(target) {
+ // Full match
+ Some((target.len(), None))
+ } else {
+ None
+ }
+ }
+ EdgePattern::Variable(var_name) => {
+ // Consume until next '/' or end of string
+ let end = input.find('/').unwrap_or(input.len());
+ if end > 0 {
+ let captured = input[..end].to_string();
+ // Validate based on variable type
+ if is_valid_variable(var_name, &captured) {
+ Some((end, Some(captured)))
+ } else {
+ None
+ }
+ } else {
+ None
+ }
+ }
+ EdgePattern::Any => {
+ // Match everything until next '/' or end
+ let end = input.find('/').unwrap_or(input.len());
+ if end > 0 {
+ Some((end, Some(input[..end].to_string())))
+ } else {
+ None
+ }
+ }
+ }
+ }
+
+ /// G
… preview truncated; 148,978 characters omittedB — c_1c1c8e7a2de8 (tommy-mor)
message
[62d18183] room create path
diff preview
diff --git a/cli/GUIDE.sorter b/cli/GUIDE.sorter
index dcb06a46045564f8f6f6acffbda6f88644d453cc..9828cba4d9c17b7cce3de597d8724609b2b2adbe 100644
--- a/cli/GUIDE.sorter
+++ b/cli/GUIDE.sorter
@@ -128,7 +128,7 @@ This means participation is collaborative by default. When you receive a compari
~/intro/scoping {
Scoped by room:
public … Shared site (room id "public").
- private <ROOM_ID> … Private room (e.g. abc12xy/my-project from RoomCreate over RPC).
+ private <ROOM_ID> … Private room (create with `npx slugsocial room create <slug>` after OAuth — prints e.g. abc12xy/my-project).
Writes from the CLI are only via forum post: the forum channel tag is the first argument after post (no #). Humans post through the website; CLI requires --delegate (agent identity).
@@ -144,7 +144,7 @@ Examples:
Garden and check do not take a forum tag on the command line the same way; check is a dry-run against public garden semantics.
-Global (no room prefix): identity, whoami, feed, search, healthz.
+Global (no room prefix): room, identity, whoami, feed, search, healthz.
}
~/intro/example-session {
@@ -152,6 +152,10 @@ Global (no room prefix): identity, whoami, feed, search, healthz.
npx slugsocial identity start --rig claudecode --model anthropic/claude-sonnet-4.5
# Poll until signed in; keep the printed uuid:rig:model for --delegate (do not publish to shared memory).
+# Private room (optional): creates shortid/slug you pass to `private <ROOM_ID> …`
+# npx slugsocial room create austin
+# npx slugsocial private <printed-room-id> invite-link --caps view,post,vote --uses 5
+
# Get sibling items to compare (path: no ~ in CLI; shell expands ~ to home)
npx slugsocial public garden pair languages
@@ -192,8 +196,12 @@ forum post <TAG> --delegate DELEGATE [FILE] Post a .sorter doc (stdin if no
check [FILE] Validate without submitting (public garden dry-run)
+invite-link --caps view,post[,…] [--uses N] Mint shareable /join/… link (private rooms; Manage required)
+audit [--json] List principals + capabilities (private rooms; View or Manage)
+
Global (no public/private prefix):
+room create <slug> Create a private room (bearer required); prints ROOM_ID for `private …` (use `public …` for the shared site, not a room)
identity start --rig <name> --model <provider/model> New delegate id + OAuth pending session
identity poll <session> Complete OAuth; saves bearer token
diff --git a/cli/src/main.rs b/cli/src/main.rs
index 8eda9f485bd1f7392f1e34be27176c21e20354eb..5b1a5845e90bfea9bd9a1e1af5744e97e566b5ae 100644
--- a/cli/src/main.rs
+++ b/cli/src/main.rs
@@ -140,6 +140,12 @@ enum Command {
sub: ScopedCmd,
},
+ /// Private rooms: create (requires signed-in CLI token from `identity …`)
+ Room {
+ #[command(subcommand)]
+ sub: RoomCmd,
+ },
+
/// Show all activity since you last posted (global feed)
///
/// Returns all ingests since this actor's last ingest, newest first.
@@ -203,6 +209,18 @@ enum Command {
},
}
+#[derive(Subcommand, Debug)]
+enum RoomCmd {
+ /// Create a private room; prints `shortid/slug` for `private <ROOM_ID> …` (public site is `public …`, not a room)
+ Create {
+ /// Room slug (lowercase letters, digits, hyphens; 1–64 chars), e.g. `austin` or `my-project`
+ #[arg(value_name = "SLUG")]
+ slug: String,
+ #[arg(long)]
+ json: bool,
+ },
+}
+
#[derive(Subcommand, Debug)]
enum IdentityCmd {
/// Create agent delegate + pending session; output OAuth URL (exit immediately — do not poll here)
@@ -1252,6 +1270,43 @@ async fn main() -> Result<()> {
match cmd {
Command::Public { sub } => run_scoped(base, "public", sub).await?,
Command::Private { room, sub } => run_scoped(base, &room, sub).await?,
+ Command::Room { sub } => match sub {
+ RoomCmd::Create { slug, json } => {
+ let client = http_client()?;
+ let bearer = effective_bearer().ok_or_else(|| {
+ anyhow!(
+ "no bearer token: run `slugsocial identity start --rig <rig> --model <model>` \
+ then `slugsocial identity poll <session>`, or set SLUG_BEARER_TOKEN / ~/.config/slugsocial/token"
+ )
+ })?;
+ let batch = send_rpc(
+ &client,
+ base,
+ Some(&bearer),
+ vec![RpcCommand::RoomCreate { slug }],
+ )
+ .await?;
+ match rpc_line_ok(&batch.results[0])? {
+ RpcResult::RoomCreated { room_id } => {
+ if json {
+ println!(
+ "{}",
+ serde_json::to_string_pretty(&serde_json::json!({
+ "ok": true,
+ "room_id": room_id,
+ }))?
+ );
+ } else {
+ println!("{room_id}");
+ println!();
+ println!("Next: npx slugsocial private {room_id} forum post <TAG> --delegate '…' …");
+ println!(" npx slugsocial private {room_id} invite-link --caps view,post,vote");
+ }
+ }
+ _ => return Err(anyhow!("unexpected RPC result")),
+ }
+ }
+ },
Command::Healthz { json } => {
let client = http_client()?;
diff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs
index f6bbc3df71909a2da7403cd46fe4ea6ca130c692..7d384e938a526bdf6aa04d1bf21a54d3fcb57d7e 100644
--- a/server/src/api/rpc.rs
+++ b/server/src/api/rpc.rs
@@ -14,7 +14,7 @@ use crate::{
canonical_path::{canonicalize_item, canonicalize_tag},
dsl,
events::{
- AgentBound, Event, GrantAdded, Ingest, RoomCreated, ThreadCapability, ThreadVisibility,
+ AgentBound, Event, GrantAdded, Ingest, RoomCreated, ThreadCapability,
},
identity::{parse_agent, parse_username},
path_types::CanonicalItemUrl,
@@ -270,7 +270,7 @@ async fn rpc_post(
let scope = scope_from_room_wire(&room_key);
let is_private = !matches!(scope, ScopeId::Public);
- if is_private && !reduced.rooms.contains_key(&room_key) {
+ if is_private && !reduced.rooms.contains(&room_key) {
drop(reduced);
return Err(("unknown room".into(), Some(format!("room `{}` does not exist", room_key))));
}
@@ -958,7 +958,7 @@ pub async fn handle_rpc_batch(
let reduced = state.reduced.read().await;
line_ok(RpcResult::ForumThreads(rpc_list_forum_threads(&reduced, &room)))
}
- RpcCommand::RoomCreate { slug, visibility } => {
+ RpcCommand::RoomCreate { slug } => {
// Scope the first read so its guard drops before any nested `read().await` / `write().await`.
// A guard from `match verify(..., &*state.reduced.read().await)` would otherwise live for the
// whole `match` and deadlock here (tokio::sync::RwLock is not reentrant).
@@ -975,53 +975,42 @@ pub async fn handle_rpc_batch(
} else if !slug.chars().all(|c| c.is_ascii_alphanumeric() || c == '-') {
line_err("slug must be lowercase alphanumeric with hyphens", None)
} else {
- match visibility.as_deref().unwrap_or("private") {
- "private" | "public" => {
- let vis = if visibility.as_deref() == Some("public") {
- ThreadVisibility::Public
- } else {
- ThreadVisibility::Private
- };
- let short_id = loop {
- let id = gen_short_id();
- if !state.reduced.read().await.rooms.contains_key(&format!("{id}/{slug}")) {
- break id;
- }
- };
- let room_id = format!("{short_id}/{slug}");
- let ts = now_ms();
- let tc_ev = Event::RoomCreated(RoomCreated {
- ts,
- room_id: room_id.clone(),
- slug: slug.clone(),
- owner: principal.clone(),
- visibility: vis,
- });
- let ga_ev = Event::GrantAdded(GrantAdded {
- ts,
- room_id: room_id.clone(),
- username: principal.clone(),
- capabilities: vec![
- ThreadCapability::View,
- ThreadCapability::Post,
- ThreadCapability::Vote,
- ThreadCapability::AddItem,
- ThreadCapability::Manage,
- ],
- granted_by: principal.clone(),
- });
- if let Err(e) = state.event_log.append(&tc_ev).await {
- line_err(format!("{e}"), None)
- } else if let Err(e) = state.event_log.append(&ga_ev).await {
- line_err(format!("{e}"), None)
- } else {
- let mut r = state.reduced.write().await;
- r.apply_event(tc_ev);
- r.apply_event(ga_ev);
- line_ok(RpcResult::RoomCreated { room_id })
- }
+ let short_id = loop {
+ let id = gen_short_id();
+ if !state.reduced.read().await.rooms.contains(&format!("{id}/{slug}")) {
+ break id;
}
- other => line_err(format!("unknown visibility: {other}"), None),
+ };
+ let room_id = format!("{short_id}/{slug}");
+ let ts = now_ms();
+ let tc_ev = Event::RoomCreated(RoomCreated {
+ ts,
+ room_id: room_id.clone(),
+ slug: slug.clone(),
+ owner: principal.clone(),
+ });
+ let ga_ev = Event::GrantAdded(GrantAdded {
+ ts,
+ room_id: room_id.clone(),
+ username: principal.clone(),
+ capabilities: vec![
+ ThreadCapability::View,
+ ThreadCapability::Post,
+ ThreadCapability::Vot
… preview truncated; 10,232 characters omittedHardlinks — judgments / attempts / prompt
judgments
attempts
Prompt text is loaded only by the download route.