Side B is a small, correct bugfix that closes a real state-corruption issue (ghost items and falsely-marked voted pairs) and updates the test to verify the fix, providing clear lasting value. Side A adds a large new subsystem (form templating, __rpc__ JSON holes, /ui endpoint) which is more architecturally ambitious but unproven, more speculative, and much larger surface area for bugs without corresponding test coverage of the new endpoint's integration behavior.
constitution · epochs · watch · epoch 3
c_48edc893c5b0 (tommy-mor) vs c_abd68b5e771a (tommy-mor)
download prompt · raw event · cmp_263959dc35e754
council reasoning
A adds lasting architecture: a reusable form_template hole-fill layer, typed HtmlUiAction + POST /ui dispatcher, shared run_* web_post helpers, and lazy new-thread UI morphs—real product and API design with tests. B is a correct, high-leverage reducer bugfix (zero-ratio early-return before ensure_item/voted_pairs) with an updated test, but it is a narrow localized correctness patch versus A’s broader durable surface.
Side B fixes a real correctness bug by moving the zero-ratio guard before any side effects in the reducer, preventing ghost items and incorrectly recorded voted pairs, and updates the test to verify no state is registered. Side A introduces a substantial new `/ui` endpoint, form templating, and UI action infrastructure, but it is primarily new feature work and refactoring rather than addressing a demonstrated correctness issue with lasting integrity impact.
sides
A — c_48edc893c5b0 (tommy-mor)
message
[3f35edab] progress
diff preview
diff --git a/server/src/api/mod.rs b/server/src/api/mod.rs
index a10ce662105cff8fad949c6b83f7035ce79bed18..a986f706ea4b261cbaf004c02b4cf84184b41371 100644
--- a/server/src/api/mod.rs
+++ b/server/src/api/mod.rs
@@ -3,6 +3,7 @@ mod helpers;
mod rpc;
mod stream;
mod validate;
+mod ui_html;
mod web_post;
pub use auth::{
@@ -33,6 +34,7 @@ pub use stream::{get_html_stream, get_stream};
pub use validate::{normalize_room_and_thread, validate_ingest_document, ValidatedIngest};
+pub use ui_html::post_ui_html;
pub use web_post::{check_web_ingest, post_web_ingest, post_web_redact};
#[cfg(test)]
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
new file mode 100644
index 0000000000000000000000000000000000000000..2b40a72059981d558768f73d189b991f3448c257
--- /dev/null
+++ b/server/src/api/ui_html.rs
@@ -0,0 +1,139 @@
+//! Single `POST /ui` entry for browser [`crate::html::ui_action::HtmlUiAction`] (JSON in `__rpc__` + holes).
+
+use axum::{
+ body::Body,
+ extract::State,
+ http::{header, HeaderMap, StatusCode},
+ response::{IntoResponse, Response},
+ Form,
+};
+use axum_extra::extract::cookie::CookieJar;
+use std::collections::HashMap;
+
+use crate::{
+ api::{
+ auth::optional_principal,
+ web_post::{run_check_web_ingest, run_post_web_ingest, run_post_web_redact, WebPostForm, WebRedactForm},
+ },
+ html::{
+ fragment_public_new_thread_form, fragment_room_new_thread_form, login_to_post_hint_markup,
+ parse_html_ui_from_form, user_can_post_room, user_can_view_room, HtmlUiAction, JsBuilder,
+ ThreadNav,
+ },
+ state::AppState,
+};
+
+pub async fn post_ui_html(
+ State(state): State<AppState>,
+ headers: HeaderMap,
+ jar: CookieJar,
+ Form(form): Form<HashMap<String, String>>,
+) -> impl IntoResponse {
+ let action = match parse_html_ui_from_form(&form) {
+ Ok(a) => a,
+ Err(e) => return ui_js_warn(&e.to_string()).into_response(),
+ };
+
+ match action {
+ HtmlUiAction::PostIngest {
+ room,
+ thread_tag,
+ text,
+ error_target,
+ form_id,
+ } => {
+ run_post_web_ingest(
+ &state,
+ &headers,
+ &jar,
+ WebPostForm {
+ room,
+ thread_tag,
+ text,
+ error_target,
+ form_id,
+ },
+ )
+ .await
+ }
+ HtmlUiAction::CheckIngest {
+ room,
+ thread_tag,
+ text,
+ error_target,
+ form_id,
+ } => {
+ run_check_web_ingest(
+ &state,
+ &headers,
+ &jar,
+ WebPostForm {
+ room,
+ thread_tag,
+ text,
+ error_target,
+ form_id,
+ },
+ )
+ .await
+ }
+ HtmlUiAction::RedactPost { post_id } => {
+ run_post_web_redact(&state, &headers, &jar, WebRedactForm { post_id }).await
+ }
+ HtmlUiAction::ExpandPublicNewThreadForm => {
+ let reduced = state.reduced.read().await;
+ let user = optional_principal(&headers, &jar, &reduced);
+ drop(reduced);
+ let markup = if user.is_some() {
+ fragment_public_new_thread_form(true)
+ } else {
+ login_to_post_hint_markup()
+ };
+ JsBuilder::new()
+ .morph_selector("#public-new-thread-ui-slot", markup)
+ .into_response()
+ }
+ HtmlUiAction::ExpandRoomNewThreadForm { room_wire } => {
+ let room_wire = room_wire.trim().to_string();
+ if room_wire.is_empty() {
+ return ui_js_warn("missing room").into_response();
+ }
+ let reduced = state.reduced.read().await;
+ let user = optional_principal(&headers, &jar, &reduced);
+ if !reduced.rooms.contains(&room_wire) {
+ drop(reduced);
+ return ui_js_warn("room not found").into_response();
+ }
+ if !user_can_view_room(&reduced, &room_wire, user.as_deref()) {
+ drop(reduced);
+ return ui_js_warn("forbidden").into_response();
+ }
+ let can_post = user
+ .as_ref()
+ .map(|u| user_can_post_room(&reduced, &room_wire, u))
+ .unwrap_or(false);
+ drop(reduced);
+ let Some(nav) = ThreadNav::from_room_id(&room_wire) else {
+ return ui_js_warn("bad room").into_response();
+ };
+ let markup = if can_post {
+ fragment_room_new_thread_form(&nav, true)
+ } else {
+ login_to_post_hint_markup()
+ };
+ JsBuilder::new()
+ .morph_selector("#room-new-thread-ui-slot", markup)
+ .into_response()
+ }
+ }
+}
+
+fn ui_js_warn(msg: &str) -> Response {
+ use crate::html::js_string_literal;
+ let js = format!("console.warn({});", js_string_literal(msg));
+ Response::builder()
+ .status(StatusCode::OK)
+ .header(header::CONTENT_TYPE, "text/javascript; charset=utf-8")
+ .body(Body::from(js))
+ .unwrap()
+}
diff --git a/server/src/api/web_post.rs b/server/src/api/web_post.rs
index a64010e382d3039821c836a5529adad0fe67cce5..265025f41ff1548d05b2d2d5d84202245388053f 100644
--- a/server/src/api/web_post.rs
+++ b/server/src/api/web_post.rs
@@ -222,8 +222,18 @@ pub async fn post_web_redact(
jar: CookieJar,
Form(form): Form<WebRedactForm>,
) -> impl IntoResponse {
+ run_post_web_redact(&state, &headers, &jar, form).await
+}
+
+/// Shared with [`crate::api::ui_html::post_ui_html`].
+pub(crate) async fn run_post_web_redact(
+ state: &AppState,
+ headers: &HeaderMap,
+ jar: &CookieJar,
+ form: WebRedactForm,
+) -> Response {
let reduced = state.reduced.read().await;
- let Some(_username) = optional_principal(&headers, &jar, &reduced) else {
+ let Some(_username) = optional_principal(headers, jar, &reduced) else {
drop(reduced);
return js_redirect("/login").into_response();
};
@@ -239,8 +249,8 @@ pub async fn post_web_redact(
return js_redirect("/login").into_response();
};
- match rpc_post_redact(&state, &headers, form.post_id).await {
- Ok(RpcResult::RedactPostOk {}) => redact_success_response(&state).await.into_response(),
+ match rpc_post_redact(state, headers, form.post_id).await {
+ Ok(RpcResult::RedactPostOk {}) => redact_success_response(state).await.into_response(),
Ok(_) => (StatusCode::BAD_REQUEST, "unexpected response").into_response(),
Err((msg, hint)) => {
let detail = hint.as_deref().unwrap_or("");
@@ -255,8 +265,18 @@ pub async fn post_web_ingest(
jar: CookieJar,
Form(form): Form<WebPostForm>,
) -> impl IntoResponse {
+ run_post_web_ingest(&state, &headers, &jar, form).await
+}
+
+/// Shared with [`crate::api::ui_html::post_ui_html`] (`POST /ui`).
+pub(crate) async fn run_post_web_ingest(
+ state: &AppState,
+ headers: &HeaderMap,
+ jar: &CookieJar,
+ form: WebPostForm,
+) -> Response {
let reduced = state.reduced.read().await;
- let Some(_username) = optional_principal(&headers, &jar, &reduced) else {
+ let Some(_username) = optional_principal(headers, jar, &reduced) else {
drop(reduced);
return js_redirect("/login").into_response();
};
@@ -282,8 +302,8 @@ pub async fn post_web_ingest(
.into_response();
}
- match rpc_post_with_bearer(&state, &bearer, room.clone(), thread_tag.clone(), text).await {
- Ok(RpcResult::PostOk { .. }) => post_success_response(&state, &form, &headers, &jar)
+ match rpc_post_with_bearer(state, &bearer, room.clone(), thread_tag.clone(), text).await {
+ Ok(RpcResult::PostOk { .. }) => post_success_response(state, &form, headers, jar)
.await
.into_response(),
Ok(_) => form_js_error(&form, "unexpected response", "Post did not return PostOk.").into_response(),
@@ -297,8 +317,18 @@ pub async fn check_web_ingest(
jar: CookieJar,
Form(form): Form<WebPostForm>,
) -> impl IntoResponse {
+ run_check_web_ingest(&state, &headers, &jar, form).await
+}
+
+/// Shared with [`crate::api::ui_html::post_ui_html`] (`POST /ui`).
+pub(crate) async fn run_check_web_ingest(
+ state: &AppState,
+ headers: &HeaderMap,
+ jar: &CookieJar,
+ form: WebPostForm,
+) -> Response {
let reduced = state.reduced.read().await;
- let Some(_username) = optional_principal(&headers, &jar, &reduced) else {
+ let Some(_username) = optional_principal(headers, jar, &reduced) else {
drop(reduced);
return js_redirect("/login").into_response();
};
@@ -324,7 +354,7 @@ pub async fn check_web_ingest(
return js_clear_errors(&form_error_target(&form)).into_response();
}
- match rpc_check_with_bearer(&state, &bearer, room, form.text.clone()).await {
+ match rpc_check_with_bearer(state, &bearer, room, form.text.clone()).await {
Ok(RpcResult::CheckOk { .. }) => js_clear_errors(&form_error_target(&form)).into_response(),
Ok(_) => form_js_error(&form, "unexpected response", "Check did not return CheckOk.").into_response(),
Err((msg, hint)) => form_js_error(&form, &msg, hint.as_deref().unwrap_or("")).into_response(),
diff --git a/server/src/form_template.rs b/server/src/form_template.rs
new file mode 100644
index 0000000000000000000000000000000000000000..3709c2c09a859da006e4af173413d5d235bc19be
--- /dev/null
+++ b/server/src/form_template.rs
@@ -0,0 +1,142 @@
+//! Plan2-style JSON templates with `{"$form": "field_name"}` holes, filled from
+//! `application/x-www-form-urlencoded` (or any `String` → `String` map) **before**
+//! deserializing into a typed struct.
+//!
+//! # Wire format
+//!
+//! Templates are **compact JSON** (`serde_json::to_string`): one line, no pretty
+//! printing, strings escaped per JSON rules (`\"`, `\n`, etc.). Embed that string
+//! in HTML attributes or text nodes with normal HTML escaping (e.g. maud), not
+//! bespoke encodings.
+//!
+//! # Power vs flat hidden fields
+//!
+//! A form is always a string→string map. You can fake depth with dotted keys (`a.b.c`),
+//! but one structured blob (`__rpc__` = compact JSON) gives you nested objects,
+//! arrays, and optional fields without inventing a new naming scheme each time.
+//!
+//! # Security
+//!
+//! Substitution runs **before** `serde` into your command type. It does not fix
+//! authorization: if the client can replace the hidden `__rpc__` value, they can
+//! change the command shape unless you validate (signed blob, server-side session
+//! context, or treat the blob as hints only). Same threat model as any hidden field.
+
+use serde::Serialize;
+use serde_json::Value;
+use std::collections::HashMap;
+
+/// Serialize a value to compact JSON for a hidden `__rpc__` (or similar) field.
+pub fn template_json_compact<T: Serialize>(v: &T) -> serde_json::Result<String> {
+ serde_json::to_string(v)
+}
+
+/// Recursively walk the JSON AST and replace `{"$form": "key"}` with the submitted
+/// string for `key` (empty if missing). Other keys are unchanged.
+pub fn substitute_form_vars(val: &mut Value, form_data: &HashMap<String, String>) {
+ match val {
+ Value::Object(map) => {
+ if map.len() == 1 {
+ if let Some(Value::String(field_name)) = map.get("$form") {
+ let submitted = form_data
+ .get(field_name.as_str())
+ .map(|s| s.as_str())
+ .unwrap_or("");
+
… preview truncated; 13,273 characters omittedB — c_abd68b5e771a (tommy-mor)
message
[81de487b] Fix zero-ratio guard in reducer to drop before registering items or pair. Previously the early-return for zero-weight votes happened after ensure_item and voted_pairs.insert, leaving ghost items in the index and the pair incorrectly marked as voted. Move the check to before any side effects. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
diff preview
diff --git a/server/src/reducer.rs b/server/src/reducer.rs
index 6841d35cfc9de2389f340a22b8a45acb335e36c3..0e36979abe0f051493038ff7e652efc7f7a0ac80 100644
--- a/server/src/reducer.rs
+++ b/server/src/reducer.rs
@@ -112,6 +112,10 @@ impl GroupState {
if vote.ratio_right < 0 {
vote.ratio_right = 0;
}
+ if vote.ratio_left == 0 || vote.ratio_right == 0 {
+ // Zero on either side produces no valid edge; drop before registering items or pair.
+ return;
+ }
let a_idx = self.ensure_item(&vote.a);
let b_idx = self.ensure_item(&vote.b);
@@ -121,10 +125,6 @@ impl GroupState {
let w_a = vote.ratio_left as f64;
let w_b = vote.ratio_right as f64;
- if w_a == 0.0 || w_b == 0.0 {
- // Zero on either side produces no valid edge; drop the vote.
- return;
- }
self.add_edge_weight(b_idx, a_idx, w_a);
self.add_edge_weight(a_idx, b_idx, w_b);
diff --git a/server/tests/basic.rs b/server/tests/basic.rs
index cc8c1a0d139f3722ba6ecd13dd001c65be835b67..08159f4a7f0850fd165817a4a1af4f31ced2ad76 100644
--- a/server/tests/basic.rs
+++ b/server/tests/basic.rs
@@ -546,12 +546,10 @@ fn reducer_negative_ratio_clamped_to_zero() {
delegate: Some("00000000-0000-0000-0000-000000000000:test:local/test".to_string()),
thread_tag: "t".to_string(),
});
- // Items are registered, but the zero-clamped vote produces no edges.
- assert_eq!(group.idx_to_item.len(), 2);
- let a_idx = group.item_to_idx[&item_id("https://slug.social/~/t/a")];
- let b_idx = group.item_to_idx[&item_id("https://slug.social/~/t/b")];
- assert!(!group.edges.contains_key(&(a_idx, b_idx)));
- assert!(!group.edges.contains_key(&(b_idx, a_idx)));
+ // Nothing registered: zero-clamped vote is dropped before ensure_item.
+ assert!(group.idx_to_item.is_empty());
+ assert!(group.edges.is_empty());
+ assert!(group.voted_pairs.is_empty());
}
Hardlinks — judgments / attempts / prompt
judgments
attempts
Prompt text is loaded only by the download route.