Side B fixes a genuine correctness/security bug: feed catch-up previously relied on wall-clock timestamps, which could miss or leak posts across users due to millisecond collisions or clock rollback, and adds strong multi-user private-room permission tests proving the anchor-by-ingest-position fix. Side A is a larger feature addition (GitHub import cards, resolver refactor) plus a real bug fix for the empty external garden index, but it's more feature/UI surface than a critical correctness fix, and part of the diff is churn from moving/renaming external_resolver.rs into resolvers/.
constitution · epochs · watch · epoch 3
c_df12ba3b70a8 (tommy-mor) vs c_0a9a8eab32ba (tommy-mor)
download prompt · raw event · cmp_1a43ad643ec6f1
council reasoning
B fixes foundational feed catch-up by anchoring on durable ingest index (not wall-clock ts), so same-ms and clock-rollback posts are not skipped, and adds permission-aware multi-user private-room filtering plus room on FeedPost with strong integration tests. A’s real /- empty-index fix and GitHub card renderer matter, but much of that patch is resolver relocation/UI chrome versus B’s core correctness and leak-prevention design.
Side B fixes a correctness issue in feed catch-up by anchoring implicit feeds to durable ingest order instead of timestamps, preventing missed posts when timestamps collide or move backwards, and preserving permission-aware behavior across private-room visibility changes. It also factors the logic into a reusable rpc_feed helper, adds room metadata to feed responses, and includes comprehensive multi-user integration tests covering concurrent ingests, permission revocation, and restoration, whereas Side A mixes one real bugfix for the external index with a larger feature/refactor for GitHub import cards and UI rendering.
sides
A — c_df12ba3b70a8 (tommy-mor)
message
[23c8134e] Fix /-/ external garden index; resolvers/ + GitHub import cards (#150) * Fix external garden root listing; add resolvers/ with GitHub cards The public and room external index pages queried children of a bogus https://./ parent, so /-/ always looked empty. Collect host-only https roots from all Web items and item_children edges so ghost parents from add_child_edge appear. Move GitHub resolver into server/src/resolvers/ with default_external.rs and a try_render_resolver_item_body hook. Resolver ingests now store slug-github-card fenced JSON; render_item_body_in_scope shows a small GitHub article card (with legacy support for schema-less json fences on github.com URLs). Styling in theme_default.css; agents.md updated. Co-authored-by: tommy <thmorriss@gmail.com> * Vote compare: GitHub cards in columns, layout CSS, tests Pass item_bodies into vote_compare_item_card for linkified tooltips on non-card bodies; clone item_bodies before dropping reducer read guard. Add layout rules so rich cards sit in the grid corners (default + retro). Unit test on vote_compare_item_card; integration GET /vote/compare with ingested slug-github-card bodies. agents.md clarifies compare columns. Co-authored-by: tommy <thmorriss@gmail.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
diff preview
diff --git a/agents.md b/agents.md
index 7508234d9b04223d0e64cfe69fedbebd06a256b5..d8b801e454fdf37e7ac6038b91a69f83b0746d59 100644
--- a/agents.md
+++ b/agents.md
@@ -42,7 +42,7 @@ Strict **CSP** that blocks `eval` would break the current app. Other projects ma
- **`VoteComparePost`:** On success returns **`text/javascript`** that **morphs** **`#vote-edge-history-region`** (recomputed **`<ul>`** — ratios match **`left`/`right`** query order, bullets, sorted by strength toward **`left`** then newer) and **`.vote-compare-nav`** (fresh next-pair link). The compare **`GET`** page uses **`layout_full_bleed_chromeless`** (no breadcrumbs, no **`#controls`**, no **`slug-pin-hud`**; **`view-vote-compare-fullscreen`** full-width **`body`**). **`__rpc__`** carries **`form_action: "/ui"`**; **`thread_tag`** and ratio fields come from the same form as **`$form`** holes.
-- **`ResolveExternal`:** GitHub resolver buttons are browser actions through **`POST /ui`**. Success responses morph **`#external-resolver-status`** then redirect to the sanitized shareable **`GET`** page so imported children render through the normal page path; errors morph the same status region. Resolver results are durable system ingests, while cooldown state is RAM-only.
+- **`ResolveExternal`:** GitHub resolver buttons are browser actions through **`POST /ui`**. Success responses morph **`#external-resolver-status`** then redirect to the sanitized shareable **`GET`** page so imported children render through the normal page path; errors morph the same status region. Resolver results are durable system ingests, while cooldown state is RAM-only. Implementation lives under **`server/src/resolvers/`** (GitHub resolver + import card JSON); ontology item pages and the **`GET /vote/compare`** left/right columns use **`render_item_body_in_scope`** in **`server/src/html/mod.rs`**, which calls **`server/src/resolvers/mod.rs::try_render_resolver_item_body`** before falling back to the usual **`<pre>`** linkified view.
- **Garden pin / compare voting:** Cookie **`slug_garden_pin`** via **`set_garden_pin`**. Pairwise UI: **`GET /vote/compare?…`** / **`GET /r/:room_key/vote/compare?…`** (fullscreen **`GET`** page: no HUD; other garden pages). HUD (**`#slug-pin-hud`**): only when **`layout`** passes garden metadata on **`body`**; the label is **`POST /ui`** **`set_garden_pin`** **`clear:true`** (**`slug_ui.js`**), not a permalink to the item.
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index 4b0214d18b173cd506d09176104f461dc4c4f208..c9eb8e242072e41fcf70da838bdf02dd4c838db8 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -18,7 +18,7 @@ use crate::{
rpc::{rpc_post_redact, rpc_post_with_bearer, rpc_room_delete},
},
canonical_path::canonicalize_tag,
- external_resolver::resolve_github_children,
+ resolvers::resolve_github_children,
html::vote_compare_post_success_js,
html::{
external_resolver_status_markup, fragment_new_thread_slot, login_to_post_hint_markup,
diff --git a/server/src/external_resolver.rs b/server/src/external_resolver.rs
deleted file mode 100644
index a5812250fed7613950b5417f396f886a55fafccf..0000000000000000000000000000000000000000
--- a/server/src/external_resolver.rs
+++ /dev/null
@@ -1,630 +0,0 @@
-use async_trait::async_trait;
-use serde_json::Value;
-use tokio::sync::oneshot;
-
-use crate::{path_types::ItemId, state::AppState, write_cmd::WriteCmd};
-
-const GITHUB_SYSTEM_PRINCIPAL: &str = "system:github-resolver";
-const GITHUB_RESOLVER_COOLDOWN_MS: i64 = 15_000;
-const GITHUB_MAX_PAGES: usize = 3;
-
-fn now_ms() -> i64 {
- use std::time::{SystemTime, UNIX_EPOCH};
- SystemTime::now()
- .duration_since(UNIX_EPOCH)
- .unwrap_or_default()
- .as_millis() as i64
-}
-
-#[derive(Debug, Clone, PartialEq, Eq)]
-pub struct ResolvedChild {
- pub url: String,
- pub title: String,
- pub body: Option<String>,
-}
-
-#[async_trait]
-pub trait ExternalResolver: Send + Sync {
- /// e.g. `"github.com"`
- fn domain_match(&self) -> &'static str;
-
- /// Normalizes URLs (e.g. stripping fragments); extend per-domain later.
- fn normalize(&self, path: &str) -> String;
-
- /// Fetches body when missing; GitHub hook lands here in a follow-up.
- async fn fetch_body(&self, item: &ItemId) -> Result<String, String>;
-}
-
-#[derive(Clone)]
-pub struct GitHubResolver {
- client: reqwest::Client,
- api_base_url: String,
- token: Option<String>,
-}
-
-impl GitHubResolver {
- pub fn from_env() -> Self {
- let api_base_url = std::env::var("SLUG_GITHUB_API_BASE_URL")
- .ok()
- .filter(|s| !s.trim().is_empty())
- .unwrap_or_else(|| "https://api.github.com".to_string());
- let token = std::env::var("SLUG_GITHUB_TOKEN")
- .ok()
- .filter(|s| !s.trim().is_empty());
- Self {
- client: reqwest::Client::new(),
- api_base_url: api_base_url.trim_end_matches('/').to_string(),
- token,
- }
- }
-
- pub fn can_resolve_children(&self, item: &ItemId) -> bool {
- github_segments(item).is_some()
- }
-
- pub async fn list_children(&self, item: &ItemId) -> Result<Vec<ResolvedChild>, String> {
- let segments = github_segments(item).ok_or_else(|| "not a GitHub URL".to_string())?;
- match segments.as_slice() {
- [] => Ok(vec![]),
- [owner] => self.list_repos(owner).await,
- [owner, repo] => Ok(github_repo_sections(owner, repo)),
- [owner, repo, section] if section == "issues" => self.list_issues(owner, repo).await,
- [owner, repo, section] if section == "pulls" => self.list_pulls(owner, repo).await,
- [owner, repo, section] if section == "commits" => self.list_commits(owner, repo).await,
- [owner, repo, section] if section == "releases" => {
- self.list_releases(owner, repo).await
- }
- _ => Ok(vec![]),
- }
- }
-
- async fn get_json(&self, path: &str) -> Result<Value, String> {
- let url = format!("{}/{}", self.api_base_url, path.trim_start_matches('/'));
- let mut req = self
- .client
- .get(url)
- .header(reqwest::header::USER_AGENT, "slugsocial-github-resolver");
- if let Some(token) = &self.token {
- req = req.bearer_auth(token);
- }
- let resp = req
- .send()
- .await
- .map_err(|e| format!("GitHub request failed: {e}"))?;
- let status = resp.status();
- if !status.is_success() {
- return Err(format!("GitHub request returned {status}"));
- }
- resp.json::<Value>()
- .await
- .map_err(|e| format!("GitHub response JSON failed: {e}"))
- }
-
- async fn get_json_array_pages(&self, path: &str) -> Result<Vec<Value>, String> {
- let sep = if path.contains('?') { '&' } else { '?' };
- let mut out = Vec::new();
- for page in 1..=GITHUB_MAX_PAGES {
- let value = self.get_json(&format!("{path}{sep}page={page}")).await?;
- let arr = value
- .as_array()
- .ok_or_else(|| "GitHub paged response was not an array".to_string())?;
- let n = arr.len();
- out.extend(arr.iter().cloned());
- if n < 100 {
- break;
- }
- }
- Ok(out)
- }
-
- async fn list_repos(&self, owner: &str) -> Result<Vec<ResolvedChild>, String> {
- let arr = self
- .get_json_array_pages(&format!(
- "/users/{owner}/repos?per_page=100&sort=updated&type=owner"
- ))
- .await?;
- let mut out = Vec::new();
- for repo in &arr {
- let name = repo
- .get("name")
- .and_then(|v| v.as_str())
- .unwrap_or_default();
- if name.is_empty() {
- continue;
- }
- let full_name = repo
- .get("full_name")
- .and_then(|v| v.as_str())
- .map(|s| s.to_ascii_lowercase())
- .unwrap_or_else(|| format!("{owner}/{name}").to_ascii_lowercase());
- out.push(ResolvedChild {
- url: format!("https://github.com/{full_name}"),
- title: full_name.clone(),
- body: Some(github_repo_body(repo)),
- });
- }
- out.sort_by(|a, b| a.url.cmp(&b.url));
- Ok(out)
- }
-
- async fn list_issues(&self, owner: &str, repo: &str) -> Result<Vec<ResolvedChild>, String> {
- let arr = self
- .get_json_array_pages(&format!(
- "/repos/{owner}/{repo}/issues?state=open&per_page=100"
- ))
- .await?;
- let mut out = Vec::new();
- for issue in &arr {
- if issue.get("pull_request").is_some() {
- continue;
- }
- let Some(number) = issue.get("number").and_then(|v| v.as_i64()) else {
- continue;
- };
- let title = issue
- .get("title")
- .and_then(|v| v.as_str())
- .unwrap_or("Untitled issue");
- out.push(ResolvedChild {
- url: format!("https://github.com/{owner}/{repo}/issues/{number}"),
- title: format!("#{number} {title}"),
- body: Some(github_issue_body(issue, "issue")),
- });
- }
- out.sort_by(|a, b| a.url.cmp(&b.url));
- Ok(out)
- }
-
- async fn list_pulls(&self, owner: &str, repo: &str) -> Result<Vec<ResolvedChild>, String> {
- let arr = self
- .get_json_array_pages(&format!(
- "/repos/{owner}/{repo}/pulls?state=open&per_page=100"
- ))
- .await?;
- let mut out = Vec::new();
- for pull in &arr {
- let Some(number) = pull.get("number").and_then(|v| v.as_i64()) else {
- continue;
- };
- let title = pull
- .get("title")
- .and_then(|v| v.as_str())
- .unwrap_or("Untitled pull request");
- out.push(ResolvedChild {
- url: format!("https://github.com/{owner}/{repo}/pulls/{number}"),
- title: format!("#{number} {title}"),
- body: Some(github_issue_body(pull, "pull request")),
- });
- }
- out.sort_by(|a, b| a.url.cmp(&b.url));
- Ok(out)
- }
-
- async fn list_commits(&self, owner: &str, repo: &str) -> Result<Vec<ResolvedChild>, String> {
- let arr = self
- .get_json_array_pages(&format!("/repos/{owner}/{repo}/commits?per_page=100"))
- .await?;
- let mut out = Vec::new();
- for commit in &arr {
- let Some(sha) = github_string(commit, "sha") else {
- continue;
- };
- let short = sha.chars().take(7).collect::<String>();
- let title = commit
- .get("commit")
- .and_then(|c| c.get("message"))
- .and_then(|v| v.as_str())
- .and_then(|m| m.lines().next())
- .filter(|s| !s.trim().is_empty())
- .unwrap_or("commit");
- let url = github_string(commit, "html_url")
- .map(|s| s.to_string())
- .unwrap_or_else(|| format!("https://github.com/{owner}/{repo}/commit/{sha}"));
- out.push(ResolvedChild {
- url,
- title: format!("{short} {title}"),
- body: Some(github_commit_body(commit)),
- });
- }
- out.sort_by(|a, b| a.url.cmp(&b.url));
- Ok(out)
- }
-
- async fn list_releases(&self, owner: &str, repo: &str) -> Result<Vec<ResolvedChild>, String> {
- let arr =
… preview truncated; 60,917 characters omittedB — c_0a9a8eab32ba (tommy-mor)
message
[c94456ff] Make feed catch-up stable and permission-aware Anchor implicit feeds to durable ingest order and cover multi-user private-room visibility so concurrent posts are not missed or leaked. Co-authored-by: Cursor <cursoragent@cursor.com>
diff preview
diff --git a/cli/src/main.rs b/cli/src/main.rs
index abb5a55b49f60fe28fbfd4ec02715cb94ea0b4ec..c4f1494df3aedbd8b883aea6249579aa8336abfe 100644
--- a/cli/src/main.rs
+++ b/cli/src/main.rs
@@ -878,6 +878,30 @@ mod tests {
"graph: 4 items, 3/6 pairs (50.0% density), 1 component, connected"
);
}
+
+ #[test]
+ fn feed_without_since_uses_logged_in_delegate_from_env() {
+ let key = "SLUG_DELEGATE";
+ let previous = std::env::var_os(key);
+ let expected = "00000000-0000-0000-0000-0000000000ee:test:local/model";
+ std::env::set_var(key, expected);
+
+ let cli = Cli::try_parse_from(["slugsocial", "feed"]).expect("parse feed");
+
+ match previous {
+ Some(value) => std::env::set_var(key, value),
+ None => std::env::remove_var(key),
+ }
+ match cli.cmd {
+ Some(Command::Feed {
+ delegate, since, ..
+ }) => {
+ assert_eq!(delegate.as_deref(), Some(expected));
+ assert!(since.is_none());
+ }
+ _ => panic!("expected feed command"),
+ }
+ }
}
async fn run_scoped(base: &str, room: &str, sub: ScopedCmd) -> Result<()> {
@@ -1626,7 +1650,15 @@ async fn run() -> Result<()> {
} else {
for p in &resp.posts {
let ago = slug_types::timeago::timeago(now_ms, p.ts);
- println!("<post id=\"{}\" ts=\"{}\">", p.id, ago);
+ let thread_attr = p
+ .thread
+ .as_deref()
+ .map(|thread| format!(" thread=\"{thread}\""))
+ .unwrap_or_default();
+ println!(
+ "<post id=\"{}\" ts=\"{}\" room=\"{}\"{}>",
+ p.id, ago, p.room, thread_attr
+ );
print!("{}", p.body);
if !p.body.ends_with('\n') { println!(); }
println!("</post>");
diff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs
index afc4f95bef160c1e38ecff2c096d6440cd94e2b3..46d748f918d9b225acc4ecedfe5a1793089407b5 100644
--- a/server/src/api/rpc.rs
+++ b/server/src/api/rpc.rs
@@ -72,6 +72,80 @@ fn can_view_scope(reduced: &ReducerState, scope: &ScopeId, principal: Option<&st
}
}
+/// Build a feed in durable ingest order.
+///
+/// An implicit feed boundary is an ingest position, not only its millisecond timestamp. Two users
+/// can post in the same millisecond, and wall-clock timestamps can move backwards during replay.
+/// Explicit `since` remains a timestamp query for API compatibility, but scans the whole ordered
+/// ledger rather than assuming timestamps are monotonic.
+fn rpc_feed(
+ reduced: &ReducerState,
+ viewer: &str,
+ delegate: Option<String>,
+ requested_since: Option<i64>,
+ implicit_anchor: Option<(usize, i64)>,
+ limit: usize,
+) -> FeedResponse {
+ let since = requested_since.or_else(|| implicit_anchor.map(|(_, ts)| ts));
+ let implicit_anchor_index = requested_since
+ .is_none()
+ .then(|| implicit_anchor.map(|(index, _)| index))
+ .flatten();
+
+ let matching: Vec<&str> = reduced
+ .ingests_ordered
+ .iter()
+ .enumerate()
+ .rev()
+ .filter(|(index, id)| {
+ reduced.ingests_by_id.get(id.as_str()).is_some_and(|ing| {
+ match requested_since {
+ Some(cutoff) => ing.ts > cutoff,
+ None => implicit_anchor_index.is_none_or(|anchor| *index > anchor),
+ }
+ })
+ })
+ .map(|(_, id)| id.as_str())
+ .filter(|id| {
+ reduced.ingests_by_id.get(*id).is_some_and(|ing| {
+ let scope = scope_from_room_wire(&ing.room_id);
+ can_view_scope(reduced, &scope, Some(viewer))
+ })
+ })
+ .filter(|id| !reduced.redacted_posts.contains(*id))
+ .collect();
+
+ let total = matching.len();
+ let posts = matching
+ .into_iter()
+ .take(limit)
+ .filter_map(|id| reduced.ingests_by_id.get(id))
+ .map(|ing| {
+ let scope = scope_from_room_wire(&ing.room_id);
+ let thread_post_index = reduced.try_thread_post_index_chronological(
+ &scope,
+ &ing.thread_tag,
+ &ing.id,
+ );
+ FeedPost {
+ ts: ing.ts,
+ id: ing.id.clone(),
+ room: ing.room_id.clone(),
+ thread: Some(ing.thread_tag.clone()),
+ thread_post_index,
+ body: ing.raw.clone(),
+ }
+ })
+ .collect();
+
+ FeedResponse {
+ delegate,
+ since,
+ posts,
+ total,
+ }
+}
+
fn principal_from_optional_bearer(headers: &HeaderMap, reduced: &ReducerState) -> Result<Option<String>, RpcErr> {
if headers.contains_key(axum::http::header::AUTHORIZATION) {
verify_bearer_principal(headers, reduced)
@@ -1506,60 +1580,27 @@ pub async fn handle_rpc_batch(
Some("this delegate is not bound to your signed-in account".into()),
)
} else {
- let since_default = reduced
+ let implicit_anchor = reduced
.ingests_ordered
.iter()
+ .enumerate()
.rev()
- .filter_map(|id| reduced.ingests_by_id.get(id))
- .find(|ing| {
- if ing.delegate.as_deref() != Some(delegate_stored.as_str()) {
- return false;
- }
- let scope = scope_from_room_wire(&ing.room_id);
- can_view_scope(&reduced, &scope, Some(viewer.as_str()))
- })
- .map(|ing| ing.ts);
- let since = since.or(since_default);
- let cutoff = since.unwrap_or(0);
- let limit = limit.unwrap_or(DEFAULT_LIMIT).min(MAX_LIMIT);
- let matching: Vec<&str> = reduced.ingests_ordered.iter().rev()
- .map(|id| id.as_str())
- .take_while(|id| reduced.ingests_by_id.get(*id).is_some_and(|ing| ing.ts > cutoff))
- .filter(|id| {
- reduced.ingests_by_id.get(*id).is_some_and(|ing| {
- let scope = scope_from_room_wire(&ing.room_id);
- can_view_scope(&reduced, &scope, Some(viewer.as_str()))
+ .find_map(|(index, id)| {
+ reduced.ingests_by_id.get(id).and_then(|ing| {
+ (ing.delegate.as_deref()
+ == Some(delegate_stored.as_str()))
+ .then_some((index, ing.ts))
})
- })
- .filter(|id| !reduced.redacted_posts.contains(*id))
- .collect();
- let total = matching.len();
- let posts: Vec<FeedPost> = matching.into_iter()
- .take(limit)
- .filter_map(|id| reduced.ingests_by_id.get(id))
- .map(|ing| {
- let scope = scope_from_room_wire(&ing.room_id);
- let thread_post_index = reduced
- .try_thread_post_index_chronological(
- &scope,
- &ing.thread_tag,
- &ing.id,
- );
- FeedPost {
- ts: ing.ts,
- id: ing.id.clone(),
- thread: Some(ing.thread_tag.clone()),
- thread_post_index,
- body: ing.raw.clone(),
- }
- })
- .collect();
- line_ok(RpcResult::Feed(FeedResponse {
- delegate: Some(delegate_stored),
+ });
+ let limit = limit.unwrap_or(DEFAULT_LIMIT).min(MAX_LIMIT);
+ line_ok(RpcResult::Feed(rpc_feed(
+ &reduced,
+ &viewer,
+ Some(delegate_stored),
since,
- posts,
- total,
- }))
+ implicit_anchor,
+ limit,
+ )))
};
drop(reduced);
line
@@ -1567,60 +1608,25 @@ pub async fn handle_rpc_batch(
None => {
// Session catch-up: last time *you* posted anything (delegate or not), so revisiting
// an old chat with only a token still gets a sane cutoff.
- let since_default = reduced
+ let implicit_anchor = reduced
.ingests_ordered
.iter()
+ .enumerate()
.rev()
- .filter_map(|id| reduced.ingests_by_id.get(id))
- .find(|ing| {
- if ing.principal != viewer {
- return false;
- }
- let scope = scope_from_room_wire(&ing.room_id);
- can_view_scope(&reduced, &scope, Some(viewer.as_str()))
- })
- .map(|ing| ing.ts);
- let since = since.or(since_default);
- let cutoff = since.unwrap_or(0);
- let limit = limit.unwrap_or(DEFAULT_LIMIT).min(MAX_LIMIT);
- let matching: Vec<&str> = reduced.ingests_ordered.iter().rev()
- .map(|id| id.as_str())
- .take_while(|id| reduced.inges
… preview truncated; 14,758 characters omittedHardlinks — judgments / attempts / prompt
judgments
attempts
Prompt text is loaded only by the download route.