You are a constitutional council ranking individual git commits for ownership allocation. Compare these two commits. Decide which contributed more lasting value to the project. Judge substance, not spectacle: - Prefer correct, lasting design and real bugfixes over churn, formatting, renames, or generated noise. - Prefer clarity and necessity over sheer line count. A small precise change can beat a large diffuse one. - Do not favor a side merely because its patch is longer or noisier. - Weight what the change does for the project, not the contributor's name. Return ONLY a JSON object: {"winner": "A" or "B", "ratio": "N:M", "explanation": "..."} The explanation must cite concrete differences in the patches (1-3 sentences). Side A — contributor: tommy-mor Side A — commit message: [9acdf18a] feat: add RoomList RPC command and CLI room list subcommand Returns all rooms the authenticated principal has a grant in. Includes integration tests proving per-user isolation: users only see rooms they have been explicitly granted, not all rooms in the system. Co-Authored-By: Claude Sonnet 4.6 Side A — unified diff (full patch): diff --git a/bb.edn b/bb.edn index f7c53eb2d5def514a8f2c480ac420416205db14e..8dc6a5be7321de198cbb5939842a33b8c5d52625 100644 --- a/bb.edn +++ b/bb.edn @@ -47,16 +47,18 @@ "RUST_LOG" "info"})})))} test - {:doc "Full test suite: integration + auth + grants + invites" + {:doc "Full test suite: integration + auth + grants + invites + room-list" :requires ([test.integration :as integration] [test.auth :as auth] [test.grants :as grants] - [test.invites :as invites]) + [test.invites :as invites] + [test.room-list :as room-list]) :task (do (integration/integration) (auth/auth-test) (grants/grants-test) - (invites/invites-test))} + (invites/invites-test) + (room-list/room-list-test))} walkthrough-fixture {:doc "Run local server + mock OAuth + seeded walkthrough data for manual browser demos" diff --git a/cli/src/main.rs b/cli/src/main.rs index 69492cb5417a0a19c38f8cacbeadd103bd905b6f..b008cf377bb360aaae666d2dfd4b5e13dedb204a 100644 --- a/cli/src/main.rs +++ b/cli/src/main.rs @@ -219,6 +219,12 @@ enum RoomCmd { #[arg(long)] json: bool, }, + /// List rooms the authenticated user has access to + List { + /// Output as JSON for agent parsing + #[arg(long)] + json: bool, + }, } #[derive(Subcommand, Debug)] @@ -1319,6 +1325,38 @@ async fn main() -> Result<()> { _ => return Err(anyhow!("unexpected RPC result")), } } + RoomCmd::List { json } => { + let client = http_client()?; + let bearer = effective_bearer().ok_or_else(|| { + anyhow!( + "no bearer token: run `slugsocial identity start --rig --model ` \ + then `slugsocial identity poll `, or set SLUG_BEARER_TOKEN / ~/.config/slugsocial/token" + ) + })?; + let batch = send_rpc( + &client, + base, + Some(&bearer), + vec![RpcCommand::RoomList], + ) + .await?; + match rpc_line_ok(&batch.results[0])? { + RpcResult::RoomList(resp) => { + if json { + println!("{}", serde_json::to_string_pretty(&resp)?); + } else { + if resp.rooms.is_empty() { + println!("no rooms"); + } else { + for room in &resp.rooms { + println!("{room}"); + } + } + } + } + _ => return Err(anyhow!("unexpected RPC result")), + } + } }, Command::Healthz { json } => { diff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs index ed4800e7cbdeaf04e72192c191e71354e603c1fe..f1ee6d35b95a1a28490823e907b8f4dc5c091b94 100644 --- a/server/src/api/rpc.rs +++ b/server/src/api/rpc.rs @@ -1345,6 +1345,25 @@ pub async fn handle_rpc_batch( } } } + RpcCommand::RoomList => { + let principal = { + let reduced = state.reduced.read().await; + verify_bearer_principal(&headers, &*reduced) + }; + match principal { + Err((_, m)) => line_err(m, None), + Ok(principal) => { + let reduced = state.reduced.read().await; + let rooms: Vec = reduced + .grants + .iter() + .filter(|(_, members)| members.contains_key(&principal)) + .map(|(room, _)| room.clone()) + .collect(); + line_ok(RpcResult::RoomList(RoomListResponse { rooms })) + } + } + } RpcCommand::RoomRevoke { room, username, diff --git a/test/room_list.clj b/test/room_list.clj new file mode 100644 index 0000000000000000000000000000000000000000..a089a722ac8d5f822f47d5511a46f671d61d46cf --- /dev/null +++ b/test/room_list.clj @@ -0,0 +1,158 @@ +(ns test.room-list + "Room list integration test: list rooms user has access to via POST /api/v0/rpc. + + Covers: + - user with no rooms -> empty list + - user with one room -> list contains that room + - user with multiple rooms -> list contains all rooms" + (:require [babashka.fs :as fs] + [cheshire.core :as json] + [clojure.set :as set] + [test.common :as common] + [test.oauth :as oauth])) + +(def ^:private counts (atom {:pass 0 :fail 0})) + +(defn- assert! [pred msg] + (common/test-assert! counts pred msg)) + +(defn- bearer [token] {"Authorization" (str "Bearer " token)}) + +(defn- rpc-batch! [base-url token cmds] + (let [resp (oauth/http-post-json (str base-url "/api/v0/rpc") cmds :headers (bearer token))] + {:status (:status resp) + :parsed (json/parse-string (:body resp) false)})) + +(defn- rpc-line-ok? [parsed] + (true? (get-in parsed ["results" 0 "ok"]))) + +(defn- register-user! [base-url session-agent username] + (oauth/complete-registration! base-url + :agent session-agent + :username username + :assert! (fn [pred msg] (assert! pred msg)))) + +(defn room-list-test [& _args] + (println "\n━━━ room list integration check ━━━\n") + (reset! counts {:pass 0 :fail 0}) + + (println "building server binary…") + (common/letlocals + (bind build (common/run-cargo-build-release! ["slugsocial-server"])) + (assert! (zero? (:exit build)) "cargo build succeeds") + (bind server-bin "target/release/slugsocial-server") + + (bind tmp-dir (str (fs/create-temp-dir {:prefix "slug-room-list-"}))) + (bind slug-port (common/pick-port)) + (bind google-port (common/pick-port)) + (bind base-url (str "http://127.0.0.1:" slug-port)) + (bind google-url (str "http://127.0.0.1:" google-port)) + + (bind !server (atom nil)) + (bind !google (atom nil)) + + (bind server-env (common/slug-server-env tmp-dir base-url google-url slug-port)) + (try + (println (str "starting mock google on :" google-port)) + (reset! !google (oauth/start-mock-google google-port + :google-users ["google-user-alice" + "google-user-bob" + "google-user-carol"])) + + (println (str "starting server on :" slug-port)) + (reset! !server (common/start-server server-bin server-env)) + (assert! (common/wait-for-server base-url 10000) "server responds to /healthz") + + (println "\nregistering alice, bob, carol…") + (let [alice-token (register-user! base-url + "00000000-0000-0000-0000-000000000001:test:local/dev" + "alice") + bob-token (register-user! base-url + "00000000-0000-0000-0000-000000000002:test:local/dev" + "bob") + carol-token (register-user! base-url + "00000000-0000-0000-0000-000000000003:test:local/dev" + "carol") + + ;; Alice creates two private rooms + _ (println "\nalice creates two rooms…") + room-id-1 (-> (rpc-batch! base-url alice-token [{"RoomCreate" {"slug" "alice-room-one"}}]) + (get-in [:parsed "results" 0 "result" "RoomCreated" "room_id"])) + _ (assert! (some? room-id-1) "alice room-one created") + room-id-2 (-> (rpc-batch! base-url alice-token [{"RoomCreate" {"slug" "alice-room-two"}}]) + (get-in [:parsed "results" 0 "result" "RoomCreated" "room_id"])) + _ (assert! (some? room-id-2) "alice room-two created") + + ;; Carol creates her own room + _ (println "carol creates her own room…") + carol-room (-> (rpc-batch! base-url carol-token [{"RoomCreate" {"slug" "carol-room"}}]) + (get-in [:parsed "results" 0 "result" "RoomCreated" "room_id"])) + _ (assert! (some? carol-room) "carol room created")] + + ;; --- isolation: alice only sees her rooms, not carol's --- + (println "\nalice sees her 2 rooms but not carol's…") + (let [rooms (-> (rpc-batch! base-url alice-token ["RoomList"]) + (get-in [:parsed "results" 0 "result" "RoomList" "rooms"]) + set)] + (assert! (= #{room-id-1 room-id-2} rooms) + "alice sees exactly her 2 rooms") + (assert! (not (contains? rooms carol-room)) + "alice does NOT see carol's room")) + + ;; --- isolation: carol only sees her room, not alice's --- + (println "carol sees only her room…") + (let [rooms (-> (rpc-batch! base-url carol-token ["RoomList"]) + (get-in [:parsed "results" 0 "result" "RoomList" "rooms"]) + set)] + (assert! (= #{carol-room} rooms) + "carol sees exactly her own room") + (assert! (not (contains? rooms room-id-1)) + "carol does NOT see alice's room-one") + (assert! (not (contains? rooms room-id-2)) + "carol does NOT see alice's room-two")) + + ;; --- bob sees nothing yet: alice has 3 rooms total but bob is in none --- + (println "bob (no grants) sees no rooms despite 3 existing…") + (let [rooms (-> (rpc-batch! base-url bob-token ["RoomList"]) + (get-in [:parsed "results" 0 "result" "RoomList" "rooms"]))] + (assert! (zero? (count rooms)) + "bob sees 0 rooms even though 3 exist in the system")) + + ;; --- partial grant: alice grants bob room-one only --- + (println "\nalice grants bob view on room-one only…") + (assert! (rpc-line-ok? (:parsed (rpc-batch! base-url alice-token + [{"RoomGrant" {"room" room-id-1 + "username" "bob" + "capabilities" ["view"]}}]))) + "grant ok") + + ;; bob sees room-one but NOT room-two or carol's room + (println "bob sees room-one but not room-two or carol's room…") + (let [rooms (-> (rpc-batch! base-url bob-token ["RoomList"]) + (get-in [:parsed "results" 0 "result" "RoomList" "rooms"]) + set)] + (assert! (= #{room-id-1} rooms) + "bob sees exactly room-one") + (assert! (not (contains? rooms room-id-2)) + "bob does NOT see alice's room-two (not granted)") + (assert! (not (contains? rooms carol-room)) + "bob does NOT see carol's room (not granted)")) + + ;; alice's view is unchanged + (println "alice's view unchanged after granting bob…") + (let [rooms (-> (rpc-batch! base-url alice-token ["RoomList"]) + (get-in [:parsed "results" 0 "result" "RoomList" "rooms"]) + set)] + (assert! (= #{room-id-1 room-id-2} rooms) + "alice still sees exactly her 2 rooms after granting bob"))) + + (finally + (when-some [s @!server] (common/kill-server s)) + (when-some [g @!google] ((:stop-fn g))) + (fs/delete-tree tmp-dir))) + + (bind {pass :pass fail :fail} @counts) + (if (zero? fail) + (println (str "\n" common/ansi-green "━━━ " pass " room list checks passed ━━━" common/ansi-reset "\n")) + (do (println (str "\n" common/ansi-red "━━━ " fail " room list checks FAILED ━━━" common/ansi-reset "\n")) + (System/exit 1))))) diff --git a/test/runner.clj b/test/runner.clj index b5c5f1f839d51487e4dee00952c2339b586b7a97..365372a7d11ab7968aa981f9b246543e25decfea 100644 --- a/test/runner.clj +++ b/test/runner.clj @@ -4,13 +4,15 @@ [test.auth :as auth] [test.grants :as grants] [test.invites :as invites] + [test.room-list :as room-list] [test.browser-sse :as browser-sse])) (defn run-core! [] (integration/integration) (auth/auth-test) (grants/grants-test) - (invites/invites-test)) + (invites/invites-test) + (room-list/room-list-test)) (defn -main [& args] (if (= ["browser-sse"] (vec args)) diff --git a/types/src/lib.rs b/types/src/lib.rs index bb8586f1734f77d95598a9294bdb0de2d55bf715..341fff7be7f9b28abc79c738d84804f743ce5657 100644 --- a/types/src/lib.rs +++ b/types/src/lib.rs @@ -260,6 +260,11 @@ pub struct RoomAuditResponse { pub grants: Vec, } +#[derive(Debug, Serialize, Deserialize)] +pub struct RoomListResponse { + pub rooms: Vec, +} + #[derive(Debug, Serialize, Deserialize)] #[serde(transparent)] pub struct RpcBatch(pub Vec); @@ -342,6 +347,8 @@ pub enum RpcCommand { RoomAudit { room: String, }, + /// List rooms the authenticated principal has access to. + RoomList, GetGlobalRank { room: String, #[serde(default)] @@ -419,6 +426,7 @@ pub enum RpcResult { max_uses: usize, }, RoomAudit(RoomAuditResponse), + RoomList(RoomListResponse), GrantOk {}, GlobalRank(GlobalRankResponse), Pair(PairResponse), Side B — contributor: tommy-mor Side B — commit message: [3f35edab] progress Side B — unified diff (full patch): diff --git a/server/src/api/mod.rs b/server/src/api/mod.rs index a10ce662105cff8fad949c6b83f7035ce79bed18..a986f706ea4b261cbaf004c02b4cf84184b41371 100644 --- a/server/src/api/mod.rs +++ b/server/src/api/mod.rs @@ -3,6 +3,7 @@ mod helpers; mod rpc; mod stream; mod validate; +mod ui_html; mod web_post; pub use auth::{ @@ -33,6 +34,7 @@ pub use stream::{get_html_stream, get_stream}; pub use validate::{normalize_room_and_thread, validate_ingest_document, ValidatedIngest}; +pub use ui_html::post_ui_html; pub use web_post::{check_web_ingest, post_web_ingest, post_web_redact}; #[cfg(test)] diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs new file mode 100644 index 0000000000000000000000000000000000000000..2b40a72059981d558768f73d189b991f3448c257 --- /dev/null +++ b/server/src/api/ui_html.rs @@ -0,0 +1,139 @@ +//! Single `POST /ui` entry for browser [`crate::html::ui_action::HtmlUiAction`] (JSON in `__rpc__` + holes). + +use axum::{ + body::Body, + extract::State, + http::{header, HeaderMap, StatusCode}, + response::{IntoResponse, Response}, + Form, +}; +use axum_extra::extract::cookie::CookieJar; +use std::collections::HashMap; + +use crate::{ + api::{ + auth::optional_principal, + web_post::{run_check_web_ingest, run_post_web_ingest, run_post_web_redact, WebPostForm, WebRedactForm}, + }, + html::{ + fragment_public_new_thread_form, fragment_room_new_thread_form, login_to_post_hint_markup, + parse_html_ui_from_form, user_can_post_room, user_can_view_room, HtmlUiAction, JsBuilder, + ThreadNav, + }, + state::AppState, +}; + +pub async fn post_ui_html( + State(state): State, + headers: HeaderMap, + jar: CookieJar, + Form(form): Form>, +) -> impl IntoResponse { + let action = match parse_html_ui_from_form(&form) { + Ok(a) => a, + Err(e) => return ui_js_warn(&e.to_string()).into_response(), + }; + + match action { + HtmlUiAction::PostIngest { + room, + thread_tag, + text, + error_target, + form_id, + } => { + run_post_web_ingest( + &state, + &headers, + &jar, + WebPostForm { + room, + thread_tag, + text, + error_target, + form_id, + }, + ) + .await + } + HtmlUiAction::CheckIngest { + room, + thread_tag, + text, + error_target, + form_id, + } => { + run_check_web_ingest( + &state, + &headers, + &jar, + WebPostForm { + room, + thread_tag, + text, + error_target, + form_id, + }, + ) + .await + } + HtmlUiAction::RedactPost { post_id } => { + run_post_web_redact(&state, &headers, &jar, WebRedactForm { post_id }).await + } + HtmlUiAction::ExpandPublicNewThreadForm => { + let reduced = state.reduced.read().await; + let user = optional_principal(&headers, &jar, &reduced); + drop(reduced); + let markup = if user.is_some() { + fragment_public_new_thread_form(true) + } else { + login_to_post_hint_markup() + }; + JsBuilder::new() + .morph_selector("#public-new-thread-ui-slot", markup) + .into_response() + } + HtmlUiAction::ExpandRoomNewThreadForm { room_wire } => { + let room_wire = room_wire.trim().to_string(); + if room_wire.is_empty() { + return ui_js_warn("missing room").into_response(); + } + let reduced = state.reduced.read().await; + let user = optional_principal(&headers, &jar, &reduced); + if !reduced.rooms.contains(&room_wire) { + drop(reduced); + return ui_js_warn("room not found").into_response(); + } + if !user_can_view_room(&reduced, &room_wire, user.as_deref()) { + drop(reduced); + return ui_js_warn("forbidden").into_response(); + } + let can_post = user + .as_ref() + .map(|u| user_can_post_room(&reduced, &room_wire, u)) + .unwrap_or(false); + drop(reduced); + let Some(nav) = ThreadNav::from_room_id(&room_wire) else { + return ui_js_warn("bad room").into_response(); + }; + let markup = if can_post { + fragment_room_new_thread_form(&nav, true) + } else { + login_to_post_hint_markup() + }; + JsBuilder::new() + .morph_selector("#room-new-thread-ui-slot", markup) + .into_response() + } + } +} + +fn ui_js_warn(msg: &str) -> Response { + use crate::html::js_string_literal; + let js = format!("console.warn({});", js_string_literal(msg)); + Response::builder() + .status(StatusCode::OK) + .header(header::CONTENT_TYPE, "text/javascript; charset=utf-8") + .body(Body::from(js)) + .unwrap() +} diff --git a/server/src/api/web_post.rs b/server/src/api/web_post.rs index a64010e382d3039821c836a5529adad0fe67cce5..265025f41ff1548d05b2d2d5d84202245388053f 100644 --- a/server/src/api/web_post.rs +++ b/server/src/api/web_post.rs @@ -222,8 +222,18 @@ pub async fn post_web_redact( jar: CookieJar, Form(form): Form, ) -> impl IntoResponse { + run_post_web_redact(&state, &headers, &jar, form).await +} + +/// Shared with [`crate::api::ui_html::post_ui_html`]. +pub(crate) async fn run_post_web_redact( + state: &AppState, + headers: &HeaderMap, + jar: &CookieJar, + form: WebRedactForm, +) -> Response { let reduced = state.reduced.read().await; - let Some(_username) = optional_principal(&headers, &jar, &reduced) else { + let Some(_username) = optional_principal(headers, jar, &reduced) else { drop(reduced); return js_redirect("/login").into_response(); }; @@ -239,8 +249,8 @@ pub async fn post_web_redact( return js_redirect("/login").into_response(); }; - match rpc_post_redact(&state, &headers, form.post_id).await { - Ok(RpcResult::RedactPostOk {}) => redact_success_response(&state).await.into_response(), + match rpc_post_redact(state, headers, form.post_id).await { + Ok(RpcResult::RedactPostOk {}) => redact_success_response(state).await.into_response(), Ok(_) => (StatusCode::BAD_REQUEST, "unexpected response").into_response(), Err((msg, hint)) => { let detail = hint.as_deref().unwrap_or(""); @@ -255,8 +265,18 @@ pub async fn post_web_ingest( jar: CookieJar, Form(form): Form, ) -> impl IntoResponse { + run_post_web_ingest(&state, &headers, &jar, form).await +} + +/// Shared with [`crate::api::ui_html::post_ui_html`] (`POST /ui`). +pub(crate) async fn run_post_web_ingest( + state: &AppState, + headers: &HeaderMap, + jar: &CookieJar, + form: WebPostForm, +) -> Response { let reduced = state.reduced.read().await; - let Some(_username) = optional_principal(&headers, &jar, &reduced) else { + let Some(_username) = optional_principal(headers, jar, &reduced) else { drop(reduced); return js_redirect("/login").into_response(); }; @@ -282,8 +302,8 @@ pub async fn post_web_ingest( .into_response(); } - match rpc_post_with_bearer(&state, &bearer, room.clone(), thread_tag.clone(), text).await { - Ok(RpcResult::PostOk { .. }) => post_success_response(&state, &form, &headers, &jar) + match rpc_post_with_bearer(state, &bearer, room.clone(), thread_tag.clone(), text).await { + Ok(RpcResult::PostOk { .. }) => post_success_response(state, &form, headers, jar) .await .into_response(), Ok(_) => form_js_error(&form, "unexpected response", "Post did not return PostOk.").into_response(), @@ -297,8 +317,18 @@ pub async fn check_web_ingest( jar: CookieJar, Form(form): Form, ) -> impl IntoResponse { + run_check_web_ingest(&state, &headers, &jar, form).await +} + +/// Shared with [`crate::api::ui_html::post_ui_html`] (`POST /ui`). +pub(crate) async fn run_check_web_ingest( + state: &AppState, + headers: &HeaderMap, + jar: &CookieJar, + form: WebPostForm, +) -> Response { let reduced = state.reduced.read().await; - let Some(_username) = optional_principal(&headers, &jar, &reduced) else { + let Some(_username) = optional_principal(headers, jar, &reduced) else { drop(reduced); return js_redirect("/login").into_response(); }; @@ -324,7 +354,7 @@ pub async fn check_web_ingest( return js_clear_errors(&form_error_target(&form)).into_response(); } - match rpc_check_with_bearer(&state, &bearer, room, form.text.clone()).await { + match rpc_check_with_bearer(state, &bearer, room, form.text.clone()).await { Ok(RpcResult::CheckOk { .. }) => js_clear_errors(&form_error_target(&form)).into_response(), Ok(_) => form_js_error(&form, "unexpected response", "Check did not return CheckOk.").into_response(), Err((msg, hint)) => form_js_error(&form, &msg, hint.as_deref().unwrap_or("")).into_response(), diff --git a/server/src/form_template.rs b/server/src/form_template.rs new file mode 100644 index 0000000000000000000000000000000000000000..3709c2c09a859da006e4af173413d5d235bc19be --- /dev/null +++ b/server/src/form_template.rs @@ -0,0 +1,142 @@ +//! Plan2-style JSON templates with `{"$form": "field_name"}` holes, filled from +//! `application/x-www-form-urlencoded` (or any `String` → `String` map) **before** +//! deserializing into a typed struct. +//! +//! # Wire format +//! +//! Templates are **compact JSON** (`serde_json::to_string`): one line, no pretty +//! printing, strings escaped per JSON rules (`\"`, `\n`, etc.). Embed that string +//! in HTML attributes or text nodes with normal HTML escaping (e.g. maud), not +//! bespoke encodings. +//! +//! # Power vs flat hidden fields +//! +//! A form is always a string→string map. You can fake depth with dotted keys (`a.b.c`), +//! but one structured blob (`__rpc__` = compact JSON) gives you nested objects, +//! arrays, and optional fields without inventing a new naming scheme each time. +//! +//! # Security +//! +//! Substitution runs **before** `serde` into your command type. It does not fix +//! authorization: if the client can replace the hidden `__rpc__` value, they can +//! change the command shape unless you validate (signed blob, server-side session +//! context, or treat the blob as hints only). Same threat model as any hidden field. + +use serde::Serialize; +use serde_json::Value; +use std::collections::HashMap; + +/// Serialize a value to compact JSON for a hidden `__rpc__` (or similar) field. +pub fn template_json_compact(v: &T) -> serde_json::Result { + serde_json::to_string(v) +} + +/// Recursively walk the JSON AST and replace `{"$form": "key"}` with the submitted +/// string for `key` (empty if missing). Other keys are unchanged. +pub fn substitute_form_vars(val: &mut Value, form_data: &HashMap) { + match val { + Value::Object(map) => { + if map.len() == 1 { + if let Some(Value::String(field_name)) = map.get("$form") { + let submitted = form_data + .get(field_name.as_str()) + .map(|s| s.as_str()) + .unwrap_or(""); + *val = Value::String(submitted.to_string()); + return; + } + } + for v in map.values_mut() { + substitute_form_vars(v, form_data); + } + } + Value::Array(arr) => { + for v in arr.iter_mut() { + substitute_form_vars(v, form_data); + } + } + _ => {} + } +} + +/// Parse JSON, apply [`substitute_form_vars`], return the mutated value. +pub fn fill_template_from_form( + template_json: &str, + form_data: &HashMap, +) -> Result { + let mut v: Value = serde_json::from_str(template_json)?; + substitute_form_vars(&mut v, form_data); + Ok(v) +} + +#[cfg(test)] +mod tests { + use super::*; + use serde::Deserialize; + + #[derive(Debug, Deserialize, PartialEq, Eq)] + struct Demo { + room: String, + thread_tag: String, + nested: Nested, + } + + #[derive(Debug, Deserialize, PartialEq, Eq)] + struct Nested { + text: String, + } + + #[test] + fn holes_become_strings() { + let json = r#"{ + "room": "public", + "thread_tag": {"$form": "tag"}, + "nested": {"text": {"$form": "body"}} + }"#; + let mut form = HashMap::new(); + form.insert("tag".into(), "foo".into()); + form.insert("body".into(), "hello\nworld".into()); + + let v = fill_template_from_form(json, &form).unwrap(); + let d: Demo = serde_json::from_value(v).unwrap(); + assert_eq!( + d, + Demo { + room: "public".into(), + thread_tag: "foo".into(), + nested: Nested { + text: "hello\nworld".into(), + }, + } + ); + } + + #[test] + fn missing_form_key_is_empty_string() { + let json = r#"{"x": {"$form": "nope"}}"#; + let mut form = HashMap::new(); + form.insert("other".into(), "y".into()); + let v = fill_template_from_form(json, &form).unwrap(); + assert_eq!(v["x"], ""); + } + + #[test] + fn array_of_holes() { + let json = r#"{"items": [{"$form": "a"}, {"$form": "b"}]}"#; + let mut form = HashMap::new(); + form.insert("a".into(), "1".into()); + form.insert("b".into(), "2".into()); + let v = fill_template_from_form(json, &form).unwrap(); + assert_eq!(v["items"], serde_json::json!(["1", "2"])); + } + + #[test] + fn template_json_compact_escapes_and_single_line() { + let s = template_json_compact(&serde_json::json!({ + "x": "quote\"and\nnewline" + })) + .unwrap(); + assert!(!s.contains('\n')); + assert!(s.contains("\\\"") || s.contains("\\n")); + } +} diff --git a/server/src/html/forum.rs b/server/src/html/forum.rs index f789e347dc136f8ffd356f4492f0bd76cea04bf0..b1c037f3dd93c7bb96d6624cab6019228432c501 100644 --- a/server/src/html/forum.rs +++ b/server/src/html/forum.rs @@ -11,12 +11,15 @@ use crate::{ api::optional_principal, canonical_path::{canonicalize_item, canonicalize_tag}, events::ThreadCapability, + form_template::template_json_compact, identity::parse_username, reducer::{scope_from_room_wire, ReducerState, ScopeId}, state::AppState, timeago, }; +use super::ui_action::{HtmlUiAction, UI_RPC_FIELD}; + use super::{ bc_segment, bc_threads, cli_panel, layout, now_ms, profile_href, recency_class, render_linkified_with_embeds_in_scope, theme_from_jar, theme_next_from_uri, JsBuilder, @@ -289,7 +292,7 @@ fn rooms_for_user(reduced: &ReducerState, username: &str) -> Vec { v } -fn user_can_view_room(reduced: &ReducerState, room_id: &str, username: Option<&str>) -> bool { +pub(crate) fn user_can_view_room(reduced: &ReducerState, room_id: &str, username: Option<&str>) -> bool { if !reduced.rooms.contains(room_id) { return false; } @@ -299,7 +302,7 @@ fn user_can_view_room(reduced: &ReducerState, room_id: &str, username: Option<&s reduced.user_has_cap(room_id, u, ThreadCapability::View) } -fn user_can_post_room(reduced: &ReducerState, room_id: &str, username: &str) -> bool { +pub(crate) fn user_can_post_room(reduced: &ReducerState, room_id: &str, username: &str) -> bool { reduced.user_has_cap(room_id, username, ThreadCapability::Post) } @@ -591,7 +594,6 @@ pub async fn home( let nav = ThreadNav::public(); let reduced_read = state.reduced.read().await; let strip = auth_strip(&headers, &jar, &reduced_read); - let show_forms = user.is_some(); drop(reduced_read); let page = layout( @@ -617,8 +619,14 @@ pub async fn home( } } p class="muted" { "dark = time-ordered · light = vote-ranked" } + div class="thread-feed-toolbar" { + form method="POST" action="/ui" { + input type="hidden" name=(UI_RPC_FIELD) value=(expand_public_new_thread_rpc_value()); + button type="submit" class="section-add-btn" { "+" } + } + } + div id="public-new-thread-ui-slot" {} (render_thread_feed(Some(&nav), "thread-feed", &public_rows, now)) - (new_thread_form_public(show_forms)) (cli_panel("npx slugsocial public forum list")) }, None, @@ -901,7 +909,13 @@ pub async fn room_page( h3 { "threads" } (render_thread_feed(Some(&nav), "room-thread-feed", &rows, now)) @if show_new { - (new_thread_form_for_room(&nav, show_new)) + div class="thread-feed-toolbar" { + form method="POST" action="/ui" { + input type="hidden" name=(UI_RPC_FIELD) value=(expand_room_new_thread_rpc_value(&nav)); + button type="submit" class="section-add-btn" { "+" } + } + } + div id="room-new-thread-ui-slot" {} } (cli_panel(&forum_cli)) (cli_panel(&garden_cli)) @@ -945,6 +959,31 @@ fn new_thread_form_for_room(nav: &ThreadNav, show: bool) -> Markup { } } +pub(crate) fn expand_public_new_thread_rpc_value() -> String { + template_json_compact(&HtmlUiAction::ExpandPublicNewThreadForm).expect("static json") +} + +pub(crate) fn expand_room_new_thread_rpc_value(nav: &ThreadNav) -> String { + template_json_compact(&HtmlUiAction::ExpandRoomNewThreadForm { + room_wire: nav.room_wire.clone(), + }) + .expect("static json") +} + +pub(crate) fn login_to_post_hint_markup() -> Markup { + html! { + p class="muted" { "log in to post" } + } +} + +pub(crate) fn fragment_public_new_thread_form(show: bool) -> Markup { + new_thread_form_public(show) +} + +pub(crate) fn fragment_room_new_thread_form(nav: &ThreadNav, show: bool) -> Markup { + new_thread_form_for_room(nav, show) +} + async fn thread_post_view_inner( state: AppState, tag: String, diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs index 53041a0cf0b30e6f20749c92ecc15a4e9ac56e09..a4fd2dd60ac283f7eb9b2e64522501b21d1e27e9 100644 --- a/server/src/html/mod.rs +++ b/server/src/html/mod.rs @@ -16,6 +16,7 @@ mod editor; mod forum; mod garden; mod search; +pub mod ui_action; use breadcrumb_path::OntologyPath; pub use auth::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page}; @@ -27,9 +28,15 @@ pub use forum::{ thread_post_collapse_deleted, thread_post_expand, thread_post_expand_deleted, thread_post_view, thread_view, ThreadNav, }; + +pub(crate) use forum::{ + fragment_public_new_thread_form, fragment_room_new_thread_form, login_to_post_hint_markup, + user_can_post_room, user_can_view_room, +}; pub use garden::{garden_index, ontology_path, room_garden_index, room_ontology_path}; pub use search::{search_page, search_results_fragment}; pub use forum::user_profile_page; +pub use ui_action::{parse_html_ui_from_form, HtmlUiAction, HtmlUiParseError, UI_RPC_FIELD}; /// Public profile URL path for a stored username (no `@`). pub(crate) fn profile_href(username: &str) -> String { diff --git a/server/src/html/ui_action.rs b/server/src/html/ui_action.rs new file mode 100644 index 0000000000000000000000000000000000000000..3bc69ecbb7e16a59d2d393b2d59f9cd3fedb12b1 --- /dev/null +++ b/server/src/html/ui_action.rs @@ -0,0 +1,116 @@ +//! Browser-only UI commands: JSON in hidden `__rpc__` plus hole fill ([`crate::form_template`]). +//! Not part of [`slug_types::RpcCommand`] (CLI / JSON API). + +use crate::form_template::fill_template_from_form; +use serde::{Deserialize, Serialize}; +use serde_json::Value; +use std::collections::HashMap; +use thiserror::Error; + +/// Form field name for the compact JSON template (possibly with `{"$form":"…"}` holes). +pub const UI_RPC_FIELD: &str = "__rpc__"; + +/// HTML form / fetch `POST /ui` payload after template fill and deserialization. +#[derive(Debug, Clone, Serialize, Deserialize, PartialEq, Eq)] +#[serde(tag = "action", rename_all = "snake_case")] +pub enum HtmlUiAction { + /// Same semantics as `POST /post` (forum ingest). + PostIngest { + room: String, + thread_tag: String, + text: String, + #[serde(default)] + error_target: Option, + #[serde(default)] + form_id: Option, + }, + /// Same as `POST /post/check`. + CheckIngest { + room: String, + thread_tag: String, + text: String, + #[serde(default)] + error_target: Option, + #[serde(default)] + form_id: Option, + }, + /// Same as `POST /post/redact`. + RedactPost { + post_id: String, + }, + /// Morph `#public-new-thread-ui-slot` to the new-thread form (or login hint). + ExpandPublicNewThreadForm, + /// Morph `#room-new-thread-ui-slot` for the given room wire id. + ExpandRoomNewThreadForm { + room_wire: String, + }, +} + +#[derive(Debug, Error)] +pub enum HtmlUiParseError { + #[error("missing __rpc__ field")] + MissingRpc, + #[error("invalid template json: {0}")] + Template(serde_json::Error), + #[error("invalid ui action: {0}")] + Action(serde_json::Error), +} + +/// Parse `__rpc__` JSON, apply `$form` holes from the rest of the form map, deserialize. +pub fn parse_html_ui_from_form(form: &HashMap) -> Result { + let template = form + .get(UI_RPC_FIELD) + .ok_or(HtmlUiParseError::MissingRpc)?; + let mut hole_map = form.clone(); + hole_map.remove(UI_RPC_FIELD); + let v: Value = fill_template_from_form(template, &hole_map).map_err(HtmlUiParseError::Template)?; + serde_json::from_value(v).map_err(HtmlUiParseError::Action) +} + +#[cfg(test)] +mod tests { + use super::*; + + #[test] + fn round_trip_post_ingest_with_holes() { + let template = serde_json::json!({ + "action": "post_ingest", + "room": "public", + "thread_tag": {"$form": "thread_tag"}, + "text": {"$form": "text"}, + "error_target": "e", + "form_id": "f", + }); + let mut form = HashMap::new(); + form.insert( + UI_RPC_FIELD.to_string(), + serde_json::to_string(&template).unwrap(), + ); + form.insert("thread_tag".into(), "x".into()); + form.insert("text".into(), "body".into()); + + let a = parse_html_ui_from_form(&form).unwrap(); + assert_eq!( + a, + HtmlUiAction::PostIngest { + room: "public".into(), + thread_tag: "x".into(), + text: "body".into(), + error_target: Some("e".into()), + form_id: Some("f".into()), + } + ); + } + + #[test] + fn expand_public_unit_variant() { + let template = serde_json::json!({ "action": "expand_public_new_thread_form" }); + let mut form = HashMap::new(); + form.insert( + UI_RPC_FIELD.to_string(), + serde_json::to_string(&template).unwrap(), + ); + let a = parse_html_ui_from_form(&form).unwrap(); + assert_eq!(a, HtmlUiAction::ExpandPublicNewThreadForm); + } +} diff --git a/server/src/lib.rs b/server/src/lib.rs index b9d4b79791ba8dd3a3c26ff777943a2548092de5..5f5b6b0f01b29350c7415e5801ec5caa74f0b452 100644 --- a/server/src/lib.rs +++ b/server/src/lib.rs @@ -3,6 +3,7 @@ pub mod paths; pub mod api; pub mod canonical_path; pub mod dsl; +pub mod form_template; pub mod html; pub mod event_log; pub mod events; @@ -33,6 +34,7 @@ pub fn create_app(state: AppState) -> Router { .route("/post", post(api::post_web_ingest)) .route("/post/redact", post(api::post_web_redact)) .route("/post/check", post(api::check_web_ingest)) + .route("/ui", post(api::post_ui_html)) .route("/theme", post(crate::html::post_theme)) .route("/sse", get(api::get_html_stream)) .route("/stream", get(api::get_stream))