Side B fixes a real build-breaking ambiguity (duplicate forum.rs vs forum/mod.rs) that would prevent the module from compiling/resolving correctly, restoring a clean modular structure already begun by prior refactors. Side A fixes several genuine but narrower test-infra bugs (regex vs string split, wrong stream method, missing null-guards, error handling in mock server) that meaningfully unblock E2E auth tests but only affect test tooling, not production code.
constitution · epochs · watch · epoch 3
c_597d3f736194 (tommy-mor) vs c_ebc883667d61 (tommy-mor)
download prompt · raw event · cmp_26df3294fa0a98
council reasoning
Side A makes precise, lasting bugfixes in the OAuth/Reddit mocks (regex split on "=", getRequestBody vs getInputStream, sendResponseHeaders length 0, nil-safe token parse, try/catch, and real CSS selectors in auth_login) that restore broken Clojure E2E auth flows. Side B only removes a duplicate monolithic forum.rs and re-exports already-split modules under forum/mod.rs—necessary hygiene that eliminates ambiguity but adds no new behavior beyond import tidy-ups.
Side A fixes concrete regressions in the OAuth test infrastructure: it corrects query parsing (`str/split` regex), reads POST bodies from `getRequestBody`, avoids null handling crashes (`parse-token-user`, `state` encoding), fixes redirect response handling, wraps handlers with error reporting, and updates Playwright helpers to use real selectors. Side B is primarily a structural refactor that removes a duplicate `forum.rs` and reorganizes code into modules without materially changing behavior, improving maintainability but adding little new functionality.
sides
A — c_597d3f736194 (tommy-mor)
message
[075d4d37] Fix OAuth test mocks so Clojure E2E auth flows work again. HttpServer handlers were crashing on query parsing and token POSTs, which broke Playwright login; also read alias/history via real CSS selectors. Co-authored-by: Cursor <cursoragent@cursor.com>
diff preview
diff --git a/test/auth_login.clj b/test/auth_login.clj
index 6f2f00d7aa7340e63d1ac465b0a2234cec7a983f..aa63b66ccb2471b710ba3d168d0461252b39fc10 100644
--- a/test/auth_login.clj
+++ b/test/auth_login.clj
@@ -14,27 +14,27 @@
(defn- type-alias! [pg text]
(page/evaluate pg
(.replace
- "(() => { const i = document.getElementById('alias-input'); const f = document.getElementById('alias-check-form'); if (!i || !f) return;
+ "(() => { const i = document.getElementById('alias-input'); const f = document.getElementById('alias-check-form'); if (!i || !f) return Promise.resolve('missing-form');
i.value = __TEXT__;
const cf = document.getElementById('alias-claim-field'); if (cf) cf.value = i.value;
return fetch(f.action, { method: 'POST', credentials: 'same-origin',
headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
body: new URLSearchParams(new FormData(f)).toString() })
.then(function (r) { return r.text(); })
- .then(function (t) { eval(t); }); })()"
+ .then(function (t) { eval(t); return document.getElementById('alias-status')?.textContent || ''; }); })()"
"__TEXT__"
- (pr-str text)))
- (Thread/sleep 400))
+ (pr-str text))))
-(defn- element-text [pg test-id]
+(defn- element-text [pg selector]
(let [raw (page/evaluate pg
- (str "document.querySelector('[data-testid=\"" test-id "\"]')?.textContent || ''"))]
+ (str "document.querySelector(" (pr-str selector) ")?.textContent || ''"))]
(when (string? raw) (str/trim raw))))
(defn- wait-for-text [pg test-id text timeout-ms]
- (let [deadline (+ (System/currentTimeMillis) timeout-ms)]
+ (let [deadline (+ (System/currentTimeMillis) timeout-ms)
+ selector (str "[data-testid=\"" test-id "\"]")]
(loop []
- (let [got (or (element-text pg test-id) "")]
+ (let [got (or (element-text pg selector) "")]
(cond
(= got text) got
(< (System/currentTimeMillis) deadline) (do (Thread/sleep 200) (recur))
diff --git a/test/support/mock_oauth.clj b/test/support/mock_oauth.clj
index 5ba7e9be3cf6d2226648e9609a09ed45f306930f..333fe08d56cb06bac2a338cad1c73894d54c4495 100644
--- a/test/support/mock_oauth.clj
+++ b/test/support/mock_oauth.clj
@@ -7,7 +7,7 @@
(defn- query-param [query key]
(when query
(some (fn [pair]
- (let [[k v] (str/split pair "=" 2)]
+ (let [[k v] (str/split pair #"=" 2)]
(when (= k key)
(URLDecoder/decode (or v "") "UTF-8"))))
(str/split query #"&"))))
@@ -31,11 +31,11 @@
(defn- send-redirect [^HttpExchange ex location]
(.set (.getResponseHeaders ex) "Location" location)
- (.sendResponseHeaders ex 302 -1)
+ (.sendResponseHeaders ex 302 0)
(.close (.getResponseBody ex)))
(defn- read-form [^HttpExchange ex]
- (let [body (slurp (.getInputStream ex))]
+ (let [body (slurp (.getRequestBody ex))]
{:code (query-param body "code")
:grant (query-param body "grant_type")}))
@@ -45,7 +45,7 @@
(str/replace #"^[Bb]earer " "")))
(defn- parse-token-user [token]
- (when (str/starts-with? token "mock:")
+ (when (and token (str/starts-with? token "mock:"))
(parse-mock-user (subs token 5))))
(defn- authorize-redirect [exchange query]
@@ -55,7 +55,7 @@
user (parse-mock-user mock-user)
code (str "mock:" (:id user) ":" (:login user))
loc (str redirect-uri "?code=" (java.net.URLEncoder/encode code "UTF-8")
- "&state=" (java.net.URLEncoder/encode state "UTF-8"))]
+ "&state=" (java.net.URLEncoder/encode (or state "") "UTF-8"))]
(send-redirect exchange loc)))
(defn start-mock-oauth
@@ -65,49 +65,56 @@
handler
(proxy [HttpHandler] []
(handle [^HttpExchange exchange]
- (let [uri (.getRequestURI exchange)
- path (.getPath uri)
- query (.getQuery uri)
- method (.getRequestMethod exchange)]
- (cond
- ;; GitHub authorize
- (str/ends-with? path "/login/oauth/authorize")
- (authorize-redirect exchange query)
+ (try
+ (let [uri (.getRequestURI exchange)
+ path (.getPath uri)
+ query (.getQuery uri)
+ method (.getRequestMethod exchange)]
+ (cond
+ ;; GitHub authorize
+ (str/ends-with? path "/login/oauth/authorize")
+ (authorize-redirect exchange query)
- ;; Reddit authorize
- (str/ends-with? path "/api/v1/authorize")
- (authorize-redirect exchange query)
+ ;; Reddit authorize
+ (str/ends-with? path "/api/v1/authorize")
+ (authorize-redirect exchange query)
- ;; GitHub token
- (and (= method "POST") (str/ends-with? path "/login/oauth/access_token"))
- (let [code (or (:code (read-form exchange)) "mock:1002:newbie")]
- (send-json exchange 200 (str "{\"access_token\":\"" code "\",\"token_type\":\"bearer\"}")))
+ ;; GitHub token
+ (and (= method "POST") (str/ends-with? path "/login/oauth/access_token"))
+ (let [code (or (:code (read-form exchange)) "mock:1002:newbie")]
+ (send-json exchange 200 (str "{\"access_token\":\"" code "\",\"token_type\":\"bearer\"}")))
- ;; Reddit token (client_credentials for import + authorization_code for login)
- (and (= method "POST") (str/ends-with? path "/api/v1/access_token"))
- (let [form (read-form exchange)
- grant (or (:grant form) "")
- code (or (:code form) "mock:t2_test:redditor")]
- (if (= grant "client_credentials")
- (send-json exchange 200 "{\"access_token\":\"app-token\",\"token_type\":\"bearer\",\"expires_in\":3600}")
- (send-json exchange 200 (str "{\"access_token\":\"" code "\",\"token_type\":\"bearer\",\"expires_in\":3600}"))))
+ ;; Reddit token (client_credentials for import + authorization_code for login)
+ (and (= method "POST") (str/ends-with? path "/api/v1/access_token"))
+ (let [form (read-form exchange)
+ grant (or (:grant form) "")
+ code (or (:code form) "mock:t2_test:redditor")]
+ (if (= grant "client_credentials")
+ (send-json exchange 200 "{\"access_token\":\"app-token\",\"token_type\":\"bearer\",\"expires_in\":3600}")
+ (send-json exchange 200 (str "{\"access_token\":\"" code "\",\"token_type\":\"bearer\",\"expires_in\":3600}"))))
- ;; GitHub user
- (= path "/user")
- (let [token (bearer-token exchange)
- user (or (parse-token-user token) {:id "1002" :login "newbie" :numeric? true})]
- (send-json exchange 200
- (str "{\"id\":" (:id user) ",\"login\":\"" (:login user) "\"}")))
+ ;; GitHub user
+ (= path "/user")
+ (let [token (bearer-token exchange)
+ user (or (parse-token-user token) {:id "1002" :login "newbie" :numeric? true})]
+ (send-json exchange 200
+ (str "{\"id\":" (:id user) ",\"login\":\"" (:login user) "\"}")))
- ;; Reddit /api/v1/me
- (str/ends-with? path "/api/v1/me")
- (let [token (bearer-token exchange)
- user (or (parse-token-user token) {:id "t2_test" :login "redditor"})]
- (send-json exchange 200
- (str "{\"id\":\"" (:id user) "\",\"name\":\"" (:login user) "\"}")))
+ ;; Reddit /api/v1/me
+ (str/ends-with? path "/api/v1/me")
+ (let [token (bearer-token exchange)
+ user (or (parse-token-user token) {:id "t2_test" :login "redditor"})]
+ (send-json exchange 200
+ (str "{\"id\":\"" (:id user) "\",\"name\":\"" (:login user) "\"}")))
- :else
- (send-json exchange 404 "{\"error\":\"not found\"}")))))]
+ :else
+ (send-json exchange 404 "{\"error\":\"not found\"}")))
+ (catch Throwable t
+ (binding [*out* *err*]
+ (println "mock-oauth handler error:" t))
+ (try
+ (send-json exchange 500 "{\"error\":\"mock-oauth internal\"}")
+ (catch Throwable _))))))]
(.createContext server "/" handler)
(.setExecutor server nil)
(.start server)
diff --git a/test/support/mock_reddit.clj b/test/support/mock_reddit.clj
index a630cf0938722193e9af88382d60e777ff371be4..faa27945b6394363914c853627a0bad1e819a5f9 100644
--- a/test/support/mock_reddit.clj
+++ b/test/support/mock_reddit.clj
@@ -12,7 +12,7 @@
(defn- query-param [query key]
(when query
(some (fn [pair]
- (let [[k v] (str/split pair "=" 2)]
+ (let [[k v] (str/split pair #"=" 2)]
(when (= k key)
(URLDecoder/decode (or v "") "UTF-8"))))
(str/split query #"&"))))
@@ -34,11 +34,11 @@
(defn- send-redirect [^HttpExchange ex location]
(.set (.getResponseHeaders ex) "Location" location)
- (.sendResponseHeaders ex 302 -1)
+ (.sendResponseHeaders ex 302 0)
(.close (.getResponseBody ex)))
(defn- read-form [^HttpExchange ex]
- (let [body (slurp (.getInputStream ex))]
+ (let [body (slurp (.getRequestBody ex))]
{:code (query-param body "code")
:grant (query-param body "grant_type")}))
@@ -48,7 +48,7 @@
(str/replace #"^[Bb]earer " "")))
(defn- parse-token-user [token]
- (when (str/starts-with? token "mock:")
+ (when (and token (str/starts-with? token "mock:"))
(parse-mock-user (subs token 5))))
(defn start-mock-reddit
@@ -72,7 +72,7 @@
user (parse-mock-user (query-param query "mock_user"))
code (str "mock:" (:id user) ":" (:login user))
loc (str redirect-uri "?code=" (java.net.URLEncoder/encode code "UTF-8")
- "&state=" (java.net.URLEncoder/encode state "UTF-8"))]
+ "&state=" (java.net.URLEncoder/encode (or state "") "UTF-8"))]
(send-redirect exchange loc))
(and (= method "POST") (str/ends-with? path "/api/v1/access_token"))
B — c_ebc883667d61 (tommy-mor)
message
[21b57b50] fix(html): drop duplicate forum.rs; use forum/ as sole module root Removes the leftover monolithic file so mod forum resolves to forum/mod.rs without ambiguity. Keeps feed, views, and other split modules as the source. Made-with: Cursor
diff preview
diff --git a/server/src/html/forum.rs b/server/src/html/forum.rs
deleted file mode 100644
index 5ad8dfc84dd735d589432e2c613ff687a75f2e61..0000000000000000000000000000000000000000
--- a/server/src/html/forum.rs
+++ /dev/null
@@ -1,1405 +0,0 @@
-use axum::{
- extract::{Path, Query, State},
- http::{HeaderMap, StatusCode, Uri},
- response::{Html, IntoResponse},
-};
-use axum_extra::extract::cookie::CookieJar;
-use maud::{html, Markup};
-use serde::Deserialize;
-
-use crate::{
- api::optional_principal,
- canonical_path::{canonicalize_item, canonicalize_tag},
- events::ThreadCapability,
- form_template::template_json_compact,
- identity::parse_username,
- reducer::{scope_from_room_wire, ReducerState, ScopeId},
- state::AppState,
- timeago,
-};
-use serde_json::json;
-
-use super::js_string_literal;
-use super::ui_action::{HtmlUiAction, UI_RPC_FIELD};
-
-use super::{
- bc_segment, bc_threads, cli_panel, layout, now_ms, profile_href, recency_class,
- render_linkified_with_embeds_in_scope, theme_from_jar, theme_next_from_uri, JsBuilder,
-};
-
-#[derive(Clone)]
-struct ThreadRow {
- tag: String,
- subtitle: Option<String>,
- last_ts: i64,
- ingests: usize,
-}
-
-#[derive(Clone)]
-struct RoomMemberRow {
- username: String,
- capabilities: Vec<&'static str>,
-}
-
-/// URL helpers for public `/t/…` and private room threads `/r/{short}/{slug}/t/…`.
-#[derive(Clone)]
-pub struct ThreadNav {
- pub room_wire: String,
- scope: ScopeId,
- room_path: String,
- thread_path_prefix: String,
- garden_path_prefix: String,
-}
-
-impl ThreadNav {
- pub(crate) fn public() -> Self {
- Self {
- room_wire: "public".into(),
- scope: ScopeId::Public,
- room_path: "/t".into(),
- thread_path_prefix: "/t".into(),
- garden_path_prefix: "/~".into(),
- }
- }
-
- /// `room_id` wire form `shortid/slug`.
- pub(crate) fn from_room_id(room_id: &str) -> Option<Self> {
- let (short, slug) = room_id.split_once('/')?;
- if short.is_empty() || slug.is_empty() {
- return None;
- }
- Some(Self {
- room_wire: room_id.to_string(),
- scope: ScopeId::Room(room_id.to_string()),
- room_path: format!("/r/{short}/{slug}"),
- thread_path_prefix: format!("/r/{short}/{slug}/t"),
- garden_path_prefix: format!("/r/{short}/{slug}/~"),
- })
- }
-
- pub(crate) fn scope(&self) -> ScopeId {
- self.scope.clone()
- }
-
- pub(crate) fn room_url(&self) -> &str {
- &self.room_path
- }
-
- pub(crate) fn thread_url(&self, tag: &str) -> String {
- format!("{}/{}", self.thread_path_prefix, tag)
- }
-
- pub(crate) fn garden_root_url(&self) -> &str {
- &self.garden_path_prefix
- }
-
- pub(crate) fn garden_item_url(&self, item: &str) -> String {
- if let Some(tail) = crate::path_types::CanonicalItemUrl::parse(item)
- .and_then(|c| c.tilde_tail().map(str::to_owned))
- {
- format!("{}/{}", self.garden_path_prefix, tail)
- } else {
- format!("{}/{}", self.garden_path_prefix, canonicalize_item(item))
- }
- }
-
- fn thread_page_url(&self, tag: &str, offset: usize) -> String {
- let base = self.thread_url(tag);
- if offset == 0 {
- base
- } else {
- format!("{base}?offset={offset}")
- }
- }
-
- fn post_url(&self, tag: &str, idx: usize) -> String {
- format!("{}/{}/{}", self.thread_path_prefix, tag, idx)
- }
-}
-
-/// `POST /ui` + `__rpc__` from an inline link (`onclick`); same-origin credentials as other morph actions.
-fn thread_ui_fetch_onclick(rpc_compact_json: &str) -> String {
- format!(
- "fetch('/ui',{{method:'POST',headers:{{'Content-Type':'application/x-www-form-urlencoded'}},body:new URLSearchParams({{__rpc__:{}}}).toString(),credentials:'same-origin'}}).then(r=>r.text()).then(eval);return false",
- js_string_literal(rpc_compact_json)
- )
-}
-
-fn thread_nav_for_ingest(ing: &crate::events::Ingest) -> Option<ThreadNav> {
- let room = ing.room_id.trim();
- if room.is_empty() || room == "public" {
- Some(ThreadNav::public())
- } else {
- ThreadNav::from_room_id(room)
- }
-}
-
-fn thread_post_index_in_scope(reduced: &ReducerState, ing: &crate::events::Ingest) -> Option<usize> {
- let scope = scope_from_room_wire(&ing.room_id);
- let tag = canonicalize_tag(&ing.thread_tag);
- reduced
- .ingests_by_scope_thread
- .get(&(scope, tag))
- .and_then(|q| q.iter().rev().position(|id| id == &ing.id))
-}
-
-fn post_header_meta(
- nav: &ThreadNav,
- tag: &str,
- post_idx: usize,
- principal: &str,
- ts: i64,
- now: i64,
-) -> Markup {
- let post_href = nav.post_url(tag, post_idx);
- let profile = profile_href(principal);
- let hover = timeago::rfc3339_utc(ts);
- let ago = timeago::timeago(now, ts);
- html! {
- div class="ingest-meta muted" title=(hover) {
- a href=(post_href) class="post-num" { "#" (post_idx) }
- " "
- a href=(profile) class="post-author" { "@" (principal) }
- " · "
- (ago)
- }
- }
-}
-
-fn post_header_row(
- nav: &ThreadNav,
- tag: &str,
- post_idx: usize,
- ing: &crate::events::Ingest,
- _viewer: Option<&str>,
- now: i64,
- show_delete: bool,
-) -> Markup {
- let meta = post_header_meta(nav, tag, post_idx, &ing.principal, ing.ts, now);
- html! {
- div class="ingest-header-row" {
- (meta)
- @if show_delete {
- form class="post-delete-form" method="POST" action="/ui" {
- input type="hidden" name=(UI_RPC_FIELD) value=(template_json_compact(&HtmlUiAction::RedactPost { post_id: ing.id.clone() }).unwrap());
- button type="submit" class="post-delete-btn" { "delete" }
- }
- }
- }
- }
-}
-
-fn redacted_header_row(
- nav: &ThreadNav,
- tag: &str,
- post_idx: usize,
- ing: &crate::events::Ingest,
- now: i64,
- expanded: bool,
-) -> Markup {
- let meta = post_header_meta(nav, tag, post_idx, &ing.principal, ing.ts, now);
- let rpc_expand = template_json_compact(&json!({
- "action": "expand_redacted_post",
- "room": nav.room_wire,
- "thread_tag": tag,
- "post_index": post_idx,
- }))
- .unwrap();
- let rpc_collapse = template_json_compact(&json!({
- "action": "collapse_redacted_post",
- "room": nav.room_wire,
- "thread_tag": tag,
- "post_index": post_idx,
- }))
- .unwrap();
- let onclick_expand = thread_ui_fetch_onclick(&rpc_expand);
- let onclick_collapse = thread_ui_fetch_onclick(&rpc_collapse);
- html! {
- div class="ingest-header-row ingest-tombstone-row" {
- (meta)
- span class="post-tombstone-inline muted" {
- "deleted · "
- @if expanded {
- a href="#" class="hide-deleted-link"
- onclick=(onclick_collapse) {
- "[hide deleted content]"
- }
- } @else {
- a href="#" class="show-deleted-link"
- onclick=(onclick_expand) {
- "[show deleted content]"
- }
- }
- }
- }
- }
-}
-
-fn ingest_entry_markup(
- nav: &ThreadNav,
- tag: &str,
- post_idx: usize,
- ing: &crate::events::Ingest,
- viewer: Option<&str>,
- now: i64,
- reduced: &ReducerState,
-) -> Markup {
- let redacted = reduced.redacted_posts.contains(&ing.id);
- let show_delete = viewer == Some(ing.principal.as_str()) && !redacted;
- if redacted {
- html! {
- div class="ingest-entry ingest-redacted" data-ingest-id=(ing.id) {
- (redacted_header_row(nav, tag, post_idx, ing, now, false))
- }
- }
- } else {
- let truncated = ing.raw.len() > 2000;
- let display_body = if truncated { &ing.raw[..2000] } else { &ing.raw[..] };
- html! {
- div class="ingest-entry" data-ingest-id=(ing.id) {
- (post_header_row(nav, tag, post_idx, ing, viewer, now, show_delete))
- (render_linkified_with_embeds_in_scope(display_body, nav.garden_root_url()))
- @if truncated {
- @let rpc_full = template_json_compact(&json!({
- "action": "expand_post_full",
- "room": nav.room_wire,
- "thread_tag": tag,
- "post_index": post_idx,
- })).unwrap();
- @let onclick_full = thread_ui_fetch_onclick(&rpc_full);
- a href="#" class="show-full-link"
- onclick=(onclick_full) {
- "[show full post]"
- }
- }
- }
- }
- }
-}
-
-fn collect_thread_rows_for_scope(reduced: &ReducerState, scope: &ScopeId, now: i64) -> Vec<ThreadRow> {
- let _ = now;
- reduced
- .forum_threads
- .iter()
- .filter(|((s, _), _)| s == scope)
- .map(|((_, tag), thread)| {
- let ingests = reduced
- .ingests_by_scope_thread
- .get(&(scope.clone(), tag.clone()))
- .map(|q| q.len())
- .unwrap_or(0);
- ThreadRow {
- tag: tag.clone(),
- subtitle: None,
- last_ts: thread.last_activity_ts,
- ingests,
- }
- })
- .collect()
-}
-
-fn rooms_for_user(reduced: &ReducerState, username: &str) -> Vec<String> {
- let mut v: Vec<String> = reduced
- .grants
- .iter()
- .filter(|(rid, m)| reduced.rooms.contains(*rid) && m.contains_key(username))
- .map(|(rid, _)| rid.clone())
- .collect();
- v.sort();
- v
-}
-
-pub(crate) fn user_can_view_room(reduced: &ReducerState, room_id: &str, username: Option<&str>) -> bool {
- if !reduced.rooms.contains(room_id) {
- return false;
- }
- let Some(u) = username else {
- return false;
- };
- reduced.user_has_cap(room_id, u, ThreadCapability::View)
-}
-
-pub(crate) fn user_can_post_room(reduced: &ReducerState, room_id: &str, username: &str) -> bool {
- reduced.user_has_cap(room_id, username, ThreadCapability::Post)
-}
-
-fn capability_label(cap: ThreadCapability) -> &'static str {
- match cap {
- ThreadCapability::View => "view",
- ThreadCapability::Post => "post",
- ThreadCapability::Vote => "vote",
- ThreadCapability::AddItem => "add_item",
- ThreadCapability::Manage => "manage",
- }
-}
-
-fn room_members_for_room(reduced: &ReducerState, room_id: &str) -> Vec<RoomMemberRow> {
- let mut rows: Vec<RoomMemberRow> = reduced
- .grants
- .get(room_id)
- .into_iter()
- .flat_map(|members| members.iter())
- .map(|(username, caps)| {
- let mut ordered = Vec::new();
- for cap in [
- ThreadCapability::View,
- ThreadCapability::Post,
- ThreadCapability::Vote,
- ThreadCapability::AddItem,
- ThreadCapability::Manage,
- ] {
- if caps.contains(&cap) {
- ordered.push(capability_label(cap));
- }
- }
- RoomMemberRow {
- username: username.clone(),
- capabilities: ordered,
- }
- })
- .collect();
- rows.sort_by(|a, b| a.username.cmp(&b.username));
- rows
-}
-
-fn room_members_inner(members: &[RoomMemberRow]) -> Markup {
- html! {
- h3 { "members
… preview truncated; 77,260 characters omittedHardlinks — judgments / attempts / prompt
judgments
attempts
Prompt text is loaded only by the download route.