Commit A fixes a real production-breaking bug (public Reddit API blocking cloud IPs) with a correct, well-tested retry/refresh design for OAuth tokens, adding lasting robustness to a critical integration. Commit B adds a nice-to-have UI feature (copy-to-clipboard for garden rankings) which is useful but purely additive and non-critical, with more surface area but less foundational impact than fixing a broken core fetch path.
constitution · epochs · watch · epoch 3
c_ca9169f732b8 (tommy-mor) vs c_57453fc5c6c0 (tommy-mor)
download prompt · raw event · cmp_3fc9407d75ecf4
council reasoning
A fixes a production-breaking Reddit fetch path (no public www fallback from cloud IPs, OAuth required when creds exist, 401/403 refresh/retry, clearer AuthRejected handling) plus a deploy pin for SORTER2_BASE_URL—core reliability. B is a polished UX add-on (CopyGardenRank markdown clipboard, wire-up, tests) that reuses existing patterns but does not fix foundational breakage.
Side A fixes a production reliability issue by requiring OAuth when credentials exist, preventing fallback to blocked public Reddit endpoints, adding token refresh/retry on 401/403, improving error propagation, and covering the behavior with a test. Side B adds a useful UI feature for copying garden rankings as markdown with routing, rendering, and tests, but it is an incremental convenience feature rather than a foundational correctness and availability improvement.
sides
A — c_ca9169f732b8 (tommy-mor)
message
[8f69c309] Require Reddit OAuth when credentials are set and refresh on 401/403. Avoid falling back to the public www.reddit.com API from cloud IPs, which returns Reddit's network-security block page. Also pin SORTER2_BASE_URL in fly.toml. Co-authored-by: Cursor <cursoragent@cursor.com>
diff preview
diff --git a/fly.toml b/fly.toml
index f0c6a39f643c204987debc177234d95a8ef44b65..ca7e0088a7efd7d58d29d808f8d89080b2bff233 100644
--- a/fly.toml
+++ b/fly.toml
@@ -5,6 +5,7 @@ primary_region = "iad"
dockerfile = "Dockerfile"
[env]
+ SORTER2_BASE_URL = "https://reddit.sorter.social"
SORTER2_DATA_DIR = "/data"
SORTER2_EVENT_LOG = "/data/events.jsonl"
PORT = "8080"
diff --git a/server/src/reddit.rs b/server/src/reddit.rs
index a874814f8927192ee62cab2d0db1efd27dcd57b7..f409764c1e1f36216f1b08107043c2eab905694c 100644
--- a/server/src/reddit.rs
+++ b/server/src/reddit.rs
@@ -283,26 +283,35 @@ async fn reddit_worker(
);
tokio::time::sleep(current_delay).await;
- if let Some(c) = &creds {
- oauth = ensure_oauth_token(&client, &oauth_token_base, c, oauth.take()).await;
- }
-
- let token = oauth.as_ref().map(|t| t.access_token.as_str());
- let fetch_base = if token.is_some() {
- tracing::debug!(
- item = %fetch_id,
- base = %oauth_api_base,
- "reddit fetch using OAuth bearer"
- );
- &oauth_api_base
- } else {
- &api_base
- };
- let url = match kind {
- FetchKind::SelfEntity => map_item_to_reddit_api(&fetch_id, fetch_base),
- FetchKind::Children => map_children_url(&fetch_id, fetch_base),
+ let outcome = match &creds {
+ Some(c) => {
+ // OAuth is required when credentials are configured — never fall
+ // back to the public www.reddit.com JSON endpoints (cloud IPs
+ // get blocked with a 403 HTML interstitial).
+ fetch_with_oauth(
+ &client,
+ &oauth_token_base,
+ &oauth_api_base,
+ c,
+ &mut oauth,
+ &fetch_id,
+ kind,
+ )
+ .await
+ }
+ None => {
+ let url = match kind {
+ FetchKind::SelfEntity => map_item_to_reddit_api(&fetch_id, &api_base),
+ FetchKind::Children => map_children_url(&fetch_id, &api_base),
+ };
+ match do_fetch(&client, &url, &fetch_id, None).await {
+ Ok(FetchOutcome::AuthRejected { status, detail }) => {
+ Err(format!("Reddit API {status}: {detail}"))
+ }
+ other => other,
+ }
+ }
};
- let outcome = do_fetch(&client, &url, &fetch_id, token).await;
match outcome {
Ok(FetchOutcome::Payload(payload)) => {
@@ -342,6 +351,12 @@ async fn reddit_worker(
current_delay = (current_delay * 2).min(Duration::from_secs(60));
notify(done, FetchJobResult::RateLimited { reset_secs });
}
+ Ok(FetchOutcome::AuthRejected { status, detail }) => {
+ let e = format!("Reddit API {status}: {detail}");
+ tracing::warn!(item = %fetch_id, err = %e, "reddit fetch auth rejected");
+ current_delay = (current_delay * 2).min(Duration::from_secs(60));
+ notify(done, FetchJobResult::Failed(e));
+ }
Err(e) => {
tracing::warn!(item = %fetch_id, err = %e, "reddit fetch failed");
current_delay = (current_delay * 2).min(Duration::from_secs(60));
@@ -357,6 +372,60 @@ enum FetchOutcome {
Payload(Value),
NotFound,
RateLimited { reset_secs: u64 },
+ /// Bearer rejected — caller should drop the cached token and retry once.
+ AuthRejected { status: StatusCode, detail: String },
+}
+
+async fn fetch_with_oauth(
+ client: &Client,
+ oauth_token_base: &str,
+ oauth_api_base: &str,
+ creds: &RedditCredentials,
+ oauth: &mut Option<OAuthToken>,
+ fetch_id: &ItemId,
+ kind: FetchKind,
+) -> Result<FetchOutcome, String> {
+ for attempt in 0..2 {
+ let force_refresh = attempt > 0;
+ *oauth = Some(
+ ensure_oauth_token(client, oauth_token_base, creds, oauth.take(), force_refresh)
+ .await?,
+ );
+ let token = oauth
+ .as_ref()
+ .expect("token set above")
+ .access_token
+ .clone();
+
+ tracing::debug!(
+ item = %fetch_id,
+ base = %oauth_api_base,
+ attempt,
+ "reddit fetch using OAuth bearer"
+ );
+
+ let url = match kind {
+ FetchKind::SelfEntity => map_item_to_reddit_api(fetch_id, oauth_api_base),
+ FetchKind::Children => map_children_url(fetch_id, oauth_api_base),
+ };
+ match do_fetch(client, &url, fetch_id, Some(&token)).await? {
+ FetchOutcome::AuthRejected { status, detail } if attempt == 0 => {
+ tracing::warn!(
+ item = %fetch_id,
+ %status,
+ %detail,
+ "reddit OAuth rejected; refreshing token and retrying"
+ );
+ *oauth = None;
+ continue;
+ }
+ FetchOutcome::AuthRejected { status, detail } => {
+ return Err(format!("Reddit API {status}: {detail}"));
+ }
+ other => return Ok(other),
+ }
+ }
+ unreachable!("loop always returns")
}
async fn ensure_oauth_token(
@@ -364,35 +433,35 @@ async fn ensure_oauth_token(
oauth_base: &str,
creds: &RedditCredentials,
existing: Option<OAuthToken>,
-) -> Option<OAuthToken> {
- if let Some(t) = existing {
- if Instant::now() < t.expires_at - Duration::from_secs(60) {
- tracing::debug!("reddit OAuth token still valid");
- return Some(t);
+ force_refresh: bool,
+) -> Result<OAuthToken, String> {
+ if !force_refresh {
+ if let Some(t) = existing {
+ if Instant::now() < t.expires_at - Duration::from_secs(60) {
+ tracing::debug!("reddit OAuth token still valid");
+ return Ok(t);
+ }
}
}
let url = format!("{}/api/v1/access_token", oauth_base.trim_end_matches('/'));
- tracing::debug!(%url, "reddit OAuth token request");
+ tracing::debug!(%url, force_refresh, "reddit OAuth token request");
let resp = client
.post(&url)
.basic_auth(&creds.client_id, Some(&creds.client_secret))
.form(&[("grant_type", "client_credentials")])
.send()
- .await;
-
- let resp = match resp {
- Ok(r) => r,
- Err(e) => {
- tracing::warn!("reddit OAuth token request failed: {e}");
- return None;
- }
- };
+ .await
+ .map_err(|e| format!("Reddit OAuth token request failed: {e}"))?;
if !resp.status().is_success() {
- tracing::warn!("reddit OAuth token HTTP {}", resp.status());
- return None;
+ let status = resp.status();
+ let body = resp.text().await.unwrap_or_default();
+ return Err(format!(
+ "Reddit OAuth token HTTP {status}: {}",
+ truncate_for_error(&body)
+ ));
}
#[derive(Deserialize)]
@@ -401,21 +470,40 @@ async fn ensure_oauth_token(
expires_in: u64,
}
- let body: TokenResponse = match resp.json().await {
- Ok(b) => b,
- Err(e) => {
- tracing::warn!("reddit OAuth token parse failed: {e}");
- return None;
- }
- };
+ let body: TokenResponse = resp
+ .json()
+ .await
+ .map_err(|e| format!("Reddit OAuth token parse failed: {e}"))?;
- tracing::debug!(expires_in = body.expires_in, "reddit OAuth token acquired");
- Some(OAuthToken {
+ tracing::info!(expires_in = body.expires_in, "reddit OAuth token acquired");
+ Ok(OAuthToken {
access_token: body.access_token,
expires_at: Instant::now() + Duration::from_secs(body.expires_in),
})
}
+fn truncate_for_error(body: &str) -> String {
+ let compact: String = body.split_whitespace().collect::<Vec<_>>().join(" ");
+ if compact.is_empty() {
+ return "(empty body)".into();
+ }
+ // Prefer the human-readable block message over dumping Reddit's CSS.
+ if let Some(idx) = compact.find("You've been blocked") {
+ let slice: String = compact.chars().skip(idx).take(160).collect();
+ return if compact.chars().count() > idx + 160 {
+ format!("{slice}…")
+ } else {
+ slice
+ };
+ }
+ let chars: String = compact.chars().take(200).collect();
+ if compact.chars().count() > 200 {
+ format!("{chars}…")
+ } else {
+ chars
+ }
+}
+
async fn do_fetch(
client: &Client,
url: &str,
@@ -460,15 +548,16 @@ async fn do_fetch(
if !status.is_success() {
let body = resp.text().await.unwrap_or_default();
+ let detail = truncate_for_error(&body);
tracing::debug!(
item = %id,
%status,
body_len = body.len(),
- body_prefix = %body.chars().take(240).collect::<String>(),
+ %detail,
"reddit non-success body"
);
if status == StatusCode::FORBIDDEN || status == StatusCode::UNAUTHORIZED {
- return Err(format!("Reddit API {status}: {body}"));
+ return Ok(FetchOutcome::AuthRejected { status, detail });
}
return Ok(FetchOutcome::NotFound);
}
@@ -716,6 +805,15 @@ fn reddit_direct_image_url(url: &str) -> bool {
mod tests {
use super::*;
+ #[test]
+ fn truncate_error_prefers_block_message() {
+ let html = r#"<style>.x{color:red}</style><div>You've been blocked by network security. To continue, log in</div>"#;
+ let msg = truncate_for_error(html);
+ assert!(msg.starts_with("You've been blocked"));
+ assert!(msg.len() < 200);
+ assert!(!msg.contains(".x{color"));
+ }
+
#[test]
fn map_subreddit_about_url() {
let id = ItemId::from_url("https://reddit.com/r/rust").unwrap();
B — c_57453fc5c6c0 (tommy-mor)
message
[8f6be6d0] Add copy button for garden rankings (markdown clipboard) (#168) * Add garden ranking markdown copy button via POST /ui Introduce HtmlUiAction::CopyGardenRank that rebuilds the visible child ranking and returns JsBuilder clipboard JS (fetch → eval), matching CopyThread. Place a copy control on garden ranking headings; clipboard text is a concise markdown numbered list with unranked bullets. Co-authored-by: tommy <thmorriss@gmail.com> * Fix paren balance in garden ranking copy browser test Co-authored-by: tommy <thmorriss@gmail.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com>
diff preview
diff --git a/agents.md b/agents.md
index 7d6fea5791f7c95677e17e8975a14df83f998fd6..1dc989e4b23071f2eef69f2479c9a1ca2bd04b32 100644
--- a/agents.md
+++ b/agents.md
@@ -40,6 +40,8 @@ Strict **CSP** that blocks `eval` would break the current app. Other projects ma
- **Non-morph `POST /ui` responses:** **`SetGardenPin`** returns **`303 See Other`** and **`Set-Cookie`** (same as **`POST /theme`**). Garden pin/unpin is a normal **`<form method="POST" action="/ui" data-navigate="full">`** — browser navigation applies cookies reliably (see **`test/browser_garden_pin.clj`**). Each **`__rpc__`** payload includes **`form_action: "/ui"`**; **`post_ui_html`** rejects mismatches to bind tokens to the UI endpoint.
+- **`CopyGardenRank`:** Browser copy control on garden ranking headings. Returns **`text/javascript`** via **`JsBuilder::clipboard_write_text_and_label_btn`** (same **`fetch` → `eval`** loop as **`CopyThread`**). Payload includes **`room`**, **`parent_path`**, **`depth`**, **`copy_btn_id`**, and optional **`external_hosts`** (for **`/-/`** host-root indexes). Clipboard text is a concise markdown numbered list of display paths (plus unranked bullets).
+
- **`VoteComparePost`:** On success returns **`text/javascript`** that **morphs** **`#vote-edge-history-region`** (recomputed **`<ul>`** — ratios match **`left`/`right`** query order, bullets, sorted by strength toward **`left`** then newer) and **`.vote-compare-nav`** (fresh next-pair link). The compare **`GET`** page uses **`layout_full_bleed_chromeless`** (no breadcrumbs, no **`#controls`**, no **`slug-pin-hud`**; **`view-vote-compare-fullscreen`** full-width **`body`**). **`__rpc__`** carries **`form_action: "/ui"`**; **`thread_tag`** and ratio fields come from the same form as **`$form`** holes. **Guests** on a shared pair see the compose UI with **`post vote`** as a link to **`/login?next=<pair path>`** (class **`vote-compare-login-cta`**); after OAuth / username selection they return to that matchup. An unauthenticated **`VoteComparePost`** (forged/stale form) still JS-redirects to the same **`/login?next=`** target.
- **`ThreadGraduate` / `GraduateThread`:** Private-room forum threads with **Manage** can be published to the public site under the same tag. The writer replays non-redacted ingests into **`room: public`** (chronological order), then appends a durable **`ThreadGraduated`** marker. Graduated private threads show a banner linking to public **`/t/:tag`**, block further private posts, and cannot be graduated twice. CLI: **`npx slugsocial private <room> forum graduate <tag>`**; RPC: **`ThreadGraduate`**.
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index b4a0c9e87e462050bd52728e49e0d6781bf1cfc8..611956d0a46062b49ce350be176e4be139312ff0 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -24,9 +24,9 @@ use crate::{
external_resolver_status_markup, fragment_new_thread_slot, login_to_post_hint_markup,
parse_html_ui_from_form, room_members_section_markup, thread_feed_html,
thread_feed_html_for_room, thread_feed_region_markup, thread_ui_collapse_redacted_post,
- thread_ui_copy_thread,
- thread_ui_expand_post_full, thread_ui_expand_redacted_post, ui_js_warn, user_can_post_room,
- user_can_view_room, HtmlUiAction, JsBuilder, ThreadNav,
+ garden_ui_copy_rank, thread_ui_copy_thread, thread_ui_expand_post_full,
+ thread_ui_expand_redacted_post, ui_js_warn, user_can_post_room, user_can_view_room,
+ HtmlUiAction, JsBuilder, ThreadNav,
},
reducer::{scope_from_room_wire, ScopeId},
state::AppState,
@@ -575,6 +575,25 @@ async fn dispatch_ui_action(
let viewer = session.map(|s| s.username.as_str());
thread_ui_copy_thread(state, &room, &thread_tag, ©_btn_id, viewer).await
}
+ HtmlUiAction::CopyGardenRank {
+ room,
+ parent_path,
+ depth,
+ copy_btn_id,
+ external_hosts,
+ } => {
+ let viewer = session.map(|s| s.username.as_str());
+ garden_ui_copy_rank(
+ state,
+ &room,
+ &parent_path,
+ depth,
+ ©_btn_id,
+ external_hosts,
+ viewer,
+ )
+ .await
+ }
HtmlUiAction::GraduateThread { room, thread_tag } => {
let Some(session) = session else {
return js_redirect("/login").into_response();
diff --git a/server/src/html/garden/copy.rs b/server/src/html/garden/copy.rs
new file mode 100644
index 0000000000000000000000000000000000000000..271ea87c34c99e23ab1b0d8572632fdc41380b78
--- /dev/null
+++ b/server/src/html/garden/copy.rs
@@ -0,0 +1,199 @@
+//! Copy garden rankings to the clipboard as concise markdown (POST /ui + JsBuilder eval).
+
+use crate::form_template::template_json_compact;
+use crate::html::forum::ThreadNav;
+use crate::html::js_string_literal;
+use crate::html::ui_action::HtmlUiAction;
+use crate::html::{JsBuilder, ui_js_warn};
+use crate::path_types::ItemId;
+use crate::reducer::scope_from_room_wire;
+use crate::scope_rank::{
+ build_children_rankings, build_rankings_for_item_set, external_root_host_items,
+ resolve_scope_recursive, ChildrenRankings,
+};
+use crate::state::AppState;
+use maud::{html, Markup};
+
+use super::access::user_can_view_room;
+use super::item::item_display_path;
+use crate::reducer::{ContentState, ScopeId};
+
+const COPY_BTN_ID: &str = "garden-rank-copy";
+
+/// `POST /ui` + `__rpc__` from an inline button; response body is `eval`'d (same as forum copy).
+fn garden_ui_fetch_onclick(rpc_compact_json: &str) -> String {
+ format!(
+ "fetch('/ui',{{method:'POST',headers:{{'Content-Type':'application/x-www-form-urlencoded'}},body:new URLSearchParams({{__rpc__:{}}}).toString(),credentials:'same-origin'}}).then(r=>r.text()).then(eval);return false",
+ js_string_literal(rpc_compact_json)
+ )
+}
+
+/// Concise markdown for ranked child groups (numbered lists + unranked bullets).
+pub(crate) fn format_garden_rank_markdown(rankings: &ChildrenRankings) -> String {
+ let mut out = String::new();
+ let multi = rankings.component_rankings.len() > 1;
+ for (ci, comp) in rankings.component_rankings.iter().enumerate() {
+ if ci > 0 {
+ out.push('\n');
+ }
+ if multi {
+ out.push_str(&format!("### ordering {}\n\n", ci + 1));
+ }
+ for (i, r) in comp.ranked.iter().enumerate() {
+ out.push_str(&format!(
+ "{}. {}\n",
+ i + 1,
+ item_display_path(r.item.as_str())
+ ));
+ }
+ }
+ if !rankings.unranked_items.is_empty() {
+ if !out.is_empty() {
+ out.push('\n');
+ }
+ for name in &rankings.unranked_items {
+ out.push_str(&format!("- {}\n", item_display_path(name.as_str())));
+ }
+ }
+ out
+}
+
+fn rankings_for_copy(
+ state_content: &crate::reducer::ContentState,
+ parent_path: &str,
+ depth: usize,
+ external_hosts: bool,
+) -> ChildrenRankings {
+ if external_hosts {
+ let hosts = external_root_host_items(state_content);
+ return build_rankings_for_item_set(state_content, &hosts);
+ }
+ let parent = ItemId::parse(parent_path.trim())
+ .unwrap_or_else(|| ItemId::ontology_root())
+ .normalized_storage();
+ let depth = depth.clamp(1, 5);
+ if depth > 1 {
+ let items = resolve_scope_recursive(state_content, &[parent.as_str().to_string()], depth);
+ build_rankings_for_item_set(state_content, &items)
+ } else {
+ build_children_rankings(state_content, &parent)
+ }
+}
+
+pub(crate) async fn garden_ui_copy_rank(
+ state: &AppState,
+ room: &str,
+ parent_path: &str,
+ depth: usize,
+ copy_btn_id: &str,
+ external_hosts: bool,
+ viewer: Option<&str>,
+) -> axum::response::Response {
+ let room = room.trim();
+ let scope = scope_from_room_wire(room);
+ if let ScopeId::Room(ref rid) = scope {
+ let reduced = state.reduced.read().await;
+ if !user_can_view_room(&reduced, rid, viewer) {
+ return ui_js_warn("forbidden");
+ }
+ }
+
+ let reduced = state.reduced.read().await;
+ let empty = ContentState::default();
+ let content = match &scope {
+ ScopeId::Public => reduced.public(),
+ ScopeId::Room(_) => reduced.content_for_scope(&scope).unwrap_or(&empty),
+ };
+ let rankings = rankings_for_copy(content, parent_path, depth, external_hosts);
+ let text = format_garden_rank_markdown(&rankings);
+ drop(reduced);
+
+ if text.is_empty() {
+ return ui_js_warn("nothing to copy");
+ }
+
+ JsBuilder::new()
+ .clipboard_write_text_and_label_btn(&text, copy_btn_id, "copied")
+ .into_response()
+}
+
+pub(super) fn garden_rank_copy_button_markup(
+ nav: &ThreadNav,
+ parent_path: &str,
+ depth: usize,
+ external_hosts: bool,
+) -> Markup {
+ let rpc = template_json_compact(&HtmlUiAction::CopyGardenRank {
+ room: nav.room_wire.clone(),
+ parent_path: parent_path.to_string(),
+ depth,
+ copy_btn_id: COPY_BTN_ID.to_string(),
+ external_hosts,
+ })
+ .expect("CopyGardenRank serializes");
+ html! {
+ button type="button" id=(COPY_BTN_ID) class="post-nav-btn ont-rank-copy-btn" title="Copy ranking as markdown"
+ onclick=(garden_ui_fetch_onclick(&rpc)) {
+ "copy"
+ }
+ }
+}
+
+#[cfg(test)]
+mod tests {
+ use super::*;
+ use crate::path_types::ItemId;
+ use crate::ranking::RankedItem;
+ use crate::scope_rank::ScopedComponent;
+
+ #[test]
+ fn markdown_single_component_and_unranked() {
+ let rankings = ChildrenRankings {
+ component_rankings: vec![ScopedComponent {
+ pairs: 1,
+ ranked: vec![
+ RankedItem {
+ item: ItemId::parse("~/a").unwrap(),
+ score: 0.9,
+ },
+ RankedItem {
+ item: ItemId::parse("~/b").unwrap(),
+ score: 0.1,
+ },
+ ],
+ }],
+ unranked_items: vec![ItemId::parse("~/c").unwrap()],
+ };
+ assert_eq!(
+ format_garden_rank_markdown(&rankings),
+ "1. ~/a\n2. ~/b\n\n- ~/c\n"
+ );
+ }
+
+ #[test]
+ fn markdown_multi_component_headers() {
+ let rankings = ChildrenRankings {
+ component_rankings: vec![
+ ScopedComponent {
+ pairs: 1,
+ ranked: vec![RankedItem {
+ item: ItemId::parse("~/a").unwrap(),
+ score: 1.0,
+ }],
+ },
+ ScopedComponent {
+ pairs: 1,
+ ranked: vec![RankedItem {
+ item: ItemId::parse("~/b").unwrap(),
+ score: 1.0,
+ }],
+ },
+ ],
+ unranked_items: vec![],
+ };
+ assert_eq!(
+ format_garden_rank_markdown(&rankings),
+ "### ordering 1\n\n1. ~/a\n\n### ordering 2\n\n1. ~/b\n"
+ );
+ }
+}
diff --git a/server/src/html/garden/mod.rs b/server/src/html/garden/mod.rs
index ee8696727e5473fe1fa913b8a7b9f3cb9c32d12f..69012a2c1d069e47fa611d63d3bd2a329fd6255d 100644
--- a/server/src/html/garden/mod.rs
+++ b/server/src/html/garden/mod.rs
@@ -2,6 +2,7 @@
mod access;
mod browse;
+mod copy;
mod external;
mod item;
mod item_page;
@@ -13,6 +14,7 @@ mod vote;
#[cfg(test)]
mod tests;
+pub(crate) use copy::garden_ui_copy_rank;
pub(crate) use external::external_resolver_status_markup;
pub(crate) use pin::{encode_
… preview truncated; 12,313 characters omittedHardlinks — judgments / attempts / prompt
judgments
attempts
Prompt text is loaded only by the download route.