constitution · epochs · watch · epoch 3

comparison

c_ebc883667d61 (tommy-mor) vs c_ca72f0995396 (tommy-mor)

download prompt · raw event · cmp_5289f0cf7693f0

council reasoning

~anthropic/claude-sonnet-latest · winner B · 55:45 · permalink

A is a pure mechanical fix removing an accidental duplicate file with no behavioral change beyond deduplication, useful but trivial housekeeping. B delivers an actual UX/feature improvement (grouped cli_panel API change across call sites, CSS updates, and a real safety assertion guarding against JS-injection via unescaped single quotes), representing more genuine design and correctness work.

~x-ai/grok-latest · winner B · 2:3 · permalink

B changes real product behavior: multi-command grouped CLI panels, click-to-copy rows, safety asserts for JS string embedding, and matching CSS across themes. A mostly deletes the leftover monolithic forum.rs and wires that same code into forum/ modules—valuable structure cleanup and ambiguity fix, but largely relocating existing logic rather than adding lasting capability.

openai/gpt-chat-latest · winner A · 4:1 · permalink

Side A removes the duplicate monolithic `server/src/html/forum.rs`, introduces `forum/mod.rs`, and makes the split `forum/*` modules the single module root, eliminating ambiguous module resolution and reducing long-term maintenance risk without changing behavior. Side B improves the CLI panel by supporting grouped commands, click-to-copy rows, and adding assertions to prevent unsafe single-quoted JS embedding, but this is primarily a UI enhancement rather than a foundational structural fix.

sides

A — c_ebc883667d61 (tommy-mor)

message

[21b57b50] fix(html): drop duplicate forum.rs; use forum/ as sole module root

Removes the leftover monolithic file so mod forum resolves to forum/mod.rs
without ambiguity. Keeps feed, views, and other split modules as the source.

Made-with: Cursor

diff preview

diff --git a/server/src/html/forum.rs b/server/src/html/forum.rs
deleted file mode 100644
index 5ad8dfc84dd735d589432e2c613ff687a75f2e61..0000000000000000000000000000000000000000
--- a/server/src/html/forum.rs
+++ /dev/null
@@ -1,1405 +0,0 @@
-use axum::{
-    extract::{Path, Query, State},
-    http::{HeaderMap, StatusCode, Uri},
-    response::{Html, IntoResponse},
-};
-use axum_extra::extract::cookie::CookieJar;
-use maud::{html, Markup};
-use serde::Deserialize;
-
-use crate::{
-    api::optional_principal,
-    canonical_path::{canonicalize_item, canonicalize_tag},
-    events::ThreadCapability,
-    form_template::template_json_compact,
-    identity::parse_username,
-    reducer::{scope_from_room_wire, ReducerState, ScopeId},
-    state::AppState,
-    timeago,
-};
-use serde_json::json;
-
-use super::js_string_literal;
-use super::ui_action::{HtmlUiAction, UI_RPC_FIELD};
-
-use super::{
-    bc_segment, bc_threads, cli_panel, layout, now_ms, profile_href, recency_class,
-    render_linkified_with_embeds_in_scope, theme_from_jar, theme_next_from_uri, JsBuilder,
-};
-
-#[derive(Clone)]
-struct ThreadRow {
-    tag: String,
-    subtitle: Option<String>,
-    last_ts: i64,
-    ingests: usize,
-}
-
-#[derive(Clone)]
-struct RoomMemberRow {
-    username: String,
-    capabilities: Vec<&'static str>,
-}
-
-/// URL helpers for public `/t/…` and private room threads `/r/{short}/{slug}/t/…`.
-#[derive(Clone)]
-pub struct ThreadNav {
-    pub room_wire: String,
-    scope: ScopeId,
-    room_path: String,
-    thread_path_prefix: String,
-    garden_path_prefix: String,
-}
-
-impl ThreadNav {
-    pub(crate) fn public() -> Self {
-        Self {
-            room_wire: "public".into(),
-            scope: ScopeId::Public,
-            room_path: "/t".into(),
-            thread_path_prefix: "/t".into(),
-            garden_path_prefix: "/~".into(),
-        }
-    }
-
-    /// `room_id` wire form `shortid/slug`.
-    pub(crate) fn from_room_id(room_id: &str) -> Option<Self> {
-        let (short, slug) = room_id.split_once('/')?;
-        if short.is_empty() || slug.is_empty() {
-            return None;
-        }
-        Some(Self {
-            room_wire: room_id.to_string(),
-            scope: ScopeId::Room(room_id.to_string()),
-            room_path: format!("/r/{short}/{slug}"),
-            thread_path_prefix: format!("/r/{short}/{slug}/t"),
-            garden_path_prefix: format!("/r/{short}/{slug}/~"),
-        })
-    }
-
-    pub(crate) fn scope(&self) -> ScopeId {
-        self.scope.clone()
-    }
-
-    pub(crate) fn room_url(&self) -> &str {
-        &self.room_path
-    }
-
-    pub(crate) fn thread_url(&self, tag: &str) -> String {
-        format!("{}/{}", self.thread_path_prefix, tag)
-    }
-
-    pub(crate) fn garden_root_url(&self) -> &str {
-        &self.garden_path_prefix
-    }
-
-    pub(crate) fn garden_item_url(&self, item: &str) -> String {
-        if let Some(tail) = crate::path_types::CanonicalItemUrl::parse(item)
-            .and_then(|c| c.tilde_tail().map(str::to_owned))
-        {
-            format!("{}/{}", self.garden_path_prefix, tail)
-        } else {
-            format!("{}/{}", self.garden_path_prefix, canonicalize_item(item))
-        }
-    }
-
-    fn thread_page_url(&self, tag: &str, offset: usize) -> String {
-        let base = self.thread_url(tag);
-        if offset == 0 {
-            base
-        } else {
-            format!("{base}?offset={offset}")
-        }
-    }
-
-    fn post_url(&self, tag: &str, idx: usize) -> String {
-        format!("{}/{}/{}", self.thread_path_prefix, tag, idx)
-    }
-}
-
-/// `POST /ui` + `__rpc__` from an inline link (`onclick`); same-origin credentials as other morph actions.
-fn thread_ui_fetch_onclick(rpc_compact_json: &str) -> String {
-    format!(
-        "fetch('/ui',{{method:'POST',headers:{{'Content-Type':'application/x-www-form-urlencoded'}},body:new URLSearchParams({{__rpc__:{}}}).toString(),credentials:'same-origin'}}).then(r=>r.text()).then(eval);return false",
-        js_string_literal(rpc_compact_json)
-    )
-}
-
-fn thread_nav_for_ingest(ing: &crate::events::Ingest) -> Option<ThreadNav> {
-    let room = ing.room_id.trim();
-    if room.is_empty() || room == "public" {
-        Some(ThreadNav::public())
-    } else {
-        ThreadNav::from_room_id(room)
-    }
-}
-
-fn thread_post_index_in_scope(reduced: &ReducerState, ing: &crate::events::Ingest) -> Option<usize> {
-    let scope = scope_from_room_wire(&ing.room_id);
-    let tag = canonicalize_tag(&ing.thread_tag);
-    reduced
-        .ingests_by_scope_thread
-        .get(&(scope, tag))
-        .and_then(|q| q.iter().rev().position(|id| id == &ing.id))
-}
-
-fn post_header_meta(
-    nav: &ThreadNav,
-    tag: &str,
-    post_idx: usize,
-    principal: &str,
-    ts: i64,
-    now: i64,
-) -> Markup {
-    let post_href = nav.post_url(tag, post_idx);
-    let profile = profile_href(principal);
-    let hover = timeago::rfc3339_utc(ts);
-    let ago = timeago::timeago(now, ts);
-    html! {
-        div class="ingest-meta muted" title=(hover) {
-            a href=(post_href) class="post-num" { "#" (post_idx) }
-            " "
-            a href=(profile) class="post-author" { "@" (principal) }
-            " · "
-            (ago)
-        }
-    }
-}
-
-fn post_header_row(
-    nav: &ThreadNav,
-    tag: &str,
-    post_idx: usize,
-    ing: &crate::events::Ingest,
-    _viewer: Option<&str>,
-    now: i64,
-    show_delete: bool,
-) -> Markup {
-    let meta = post_header_meta(nav, tag, post_idx, &ing.principal, ing.ts, now);
-    html! {
-        div class="ingest-header-row" {
-            (meta)
-            @if show_delete {
-                form class="post-delete-form" method="POST" action="/ui" {
-                    input type="hidden" name=(UI_RPC_FIELD) value=(template_json_compact(&HtmlUiAction::RedactPost { post_id: ing.id.clone() }).unwrap());
-                    button type="submit" class="post-delete-btn" { "delete" }
-                }
-            }
-        }
-    }
-}
-
-fn redacted_header_row(
-    nav: &ThreadNav,
-    tag: &str,
-    post_idx: usize,
-    ing: &crate::events::Ingest,
-    now: i64,
-    expanded: bool,
-) -> Markup {
-    let meta = post_header_meta(nav, tag, post_idx, &ing.principal, ing.ts, now);
-    let rpc_expand = template_json_compact(&json!({
-        "action": "expand_redacted_post",
-        "room": nav.room_wire,
-        "thread_tag": tag,
-        "post_index": post_idx,
-    }))
-    .unwrap();
-    let rpc_collapse = template_json_compact(&json!({
-        "action": "collapse_redacted_post",
-        "room": nav.room_wire,
-        "thread_tag": tag,
-        "post_index": post_idx,
-    }))
-    .unwrap();
-    let onclick_expand = thread_ui_fetch_onclick(&rpc_expand);
-    let onclick_collapse = thread_ui_fetch_onclick(&rpc_collapse);
-    html! {
-        div class="ingest-header-row ingest-tombstone-row" {
-            (meta)
-            span class="post-tombstone-inline muted" {
-                "deleted · "
-                @if expanded {
-                    a href="#" class="hide-deleted-link"
-                      onclick=(onclick_collapse) {
-                        "[hide deleted content]"
-                    }
-                } @else {
-                    a href="#" class="show-deleted-link"
-                      onclick=(onclick_expand) {
-                        "[show deleted content]"
-                    }
-                }
-            }
-        }
-    }
-}
-
-fn ingest_entry_markup(
-    nav: &ThreadNav,
-    tag: &str,
-    post_idx: usize,
-    ing: &crate::events::Ingest,
-    viewer: Option<&str>,
-    now: i64,
-    reduced: &ReducerState,
-) -> Markup {
-    let redacted = reduced.redacted_posts.contains(&ing.id);
-    let show_delete = viewer == Some(ing.principal.as_str()) && !redacted;
-    if redacted {
-        html! {
-            div class="ingest-entry ingest-redacted" data-ingest-id=(ing.id) {
-                (redacted_header_row(nav, tag, post_idx, ing, now, false))
-            }
-        }
-    } else {
-        let truncated = ing.raw.len() > 2000;
-        let display_body = if truncated { &ing.raw[..2000] } else { &ing.raw[..] };
-        html! {
-            div class="ingest-entry" data-ingest-id=(ing.id) {
-                (post_header_row(nav, tag, post_idx, ing, viewer, now, show_delete))
-                (render_linkified_with_embeds_in_scope(display_body, nav.garden_root_url()))
-                @if truncated {
-                    @let rpc_full = template_json_compact(&json!({
-                        "action": "expand_post_full",
-                        "room": nav.room_wire,
-                        "thread_tag": tag,
-                        "post_index": post_idx,
-                    })).unwrap();
-                    @let onclick_full = thread_ui_fetch_onclick(&rpc_full);
-                    a href="#" class="show-full-link"
-                      onclick=(onclick_full) {
-                        "[show full post]"
-                    }
-                }
-            }
-        }
-    }
-}
-
-fn collect_thread_rows_for_scope(reduced: &ReducerState, scope: &ScopeId, now: i64) -> Vec<ThreadRow> {
-    let _ = now;
-    reduced
-        .forum_threads
-        .iter()
-        .filter(|((s, _), _)| s == scope)
-        .map(|((_, tag), thread)| {
-            let ingests = reduced
-                .ingests_by_scope_thread
-                .get(&(scope.clone(), tag.clone()))
-                .map(|q| q.len())
-                .unwrap_or(0);
-            ThreadRow {
-                tag: tag.clone(),
-                subtitle: None,
-                last_ts: thread.last_activity_ts,
-                ingests,
-            }
-        })
-        .collect()
-}
-
-fn rooms_for_user(reduced: &ReducerState, username: &str) -> Vec<String> {
-    let mut v: Vec<String> = reduced
-        .grants
-        .iter()
-        .filter(|(rid, m)| reduced.rooms.contains(*rid) && m.contains_key(username))
-        .map(|(rid, _)| rid.clone())
-        .collect();
-    v.sort();
-    v
-}
-
-pub(crate) fn user_can_view_room(reduced: &ReducerState, room_id: &str, username: Option<&str>) -> bool {
-    if !reduced.rooms.contains(room_id) {
-        return false;
-    }
-    let Some(u) = username else {
-        return false;
-    };
-    reduced.user_has_cap(room_id, u, ThreadCapability::View)
-}
-
-pub(crate) fn user_can_post_room(reduced: &ReducerState, room_id: &str, username: &str) -> bool {
-    reduced.user_has_cap(room_id, username, ThreadCapability::Post)
-}
-
-fn capability_label(cap: ThreadCapability) -> &'static str {
-    match cap {
-        ThreadCapability::View => "view",
-        ThreadCapability::Post => "post",
-        ThreadCapability::Vote => "vote",
-        ThreadCapability::AddItem => "add_item",
-        ThreadCapability::Manage => "manage",
-    }
-}
-
-fn room_members_for_room(reduced: &ReducerState, room_id: &str) -> Vec<RoomMemberRow> {
-    let mut rows: Vec<RoomMemberRow> = reduced
-        .grants
-        .get(room_id)
-        .into_iter()
-        .flat_map(|members| members.iter())
-        .map(|(username, caps)| {
-            let mut ordered = Vec::new();
-            for cap in [
-                ThreadCapability::View,
-                ThreadCapability::Post,
-                ThreadCapability::Vote,
-                ThreadCapability::AddItem,
-                ThreadCapability::Manage,
-            ] {
-                if caps.contains(&cap) {
-                    ordered.push(capability_label(cap));
-                }
-            }
-            RoomMemberRow {
-                username: username.clone(),
-                capabilities: ordered,
-            }
-        })
-        .collect();
-    rows.sort_by(|a, b| a.username.cmp(&b.username));
-    rows
-}
-
-fn room_members_inner(members: &[RoomMemberRow]) -> Markup {
-    html! {
-        h3 { "members

… preview truncated; 77,260 characters omitted

download full diff A

B — c_ca72f0995396 (tommy-mor)

message

[798c764d] feat(html): grouped cli_panel with hover-to-copy and JS-safe asserts

Single bordered panel for multiple commands; rows copy on click without a
separate copy control. Assert CLI strings contain no chars that would break
single-quoted onclick JS.

Made-with: Cursor

diff preview

diff --git a/server/src/html/forum.rs b/server/src/html/forum.rs
index f6e45b05bb92126966e304619f80ef1d45be7a4b..075860914a6ce18bb0dfa73dc5651ef1a6318b67 100644
--- a/server/src/html/forum.rs
+++ b/server/src/html/forum.rs
@@ -718,7 +718,7 @@ pub async fn home(
             }
             div id="public-new-thread-ui-slot" {}
             (render_thread_feed(Some(&nav), "thread-feed", &public_rows, now))
-            (cli_panel("npx slugsocial public forum list"))
+            (cli_panel(&["npx slugsocial public forum list"]))
         },
         None,
         theme_from_jar(&jar),
@@ -868,7 +868,7 @@ async fn thread_view_inner(
             div id="thread-live-region" {
                 (compose_form(&nav, &tag, show_compose))
             }
-            (cli_panel(&cli))
+            (cli_panel(std::slice::from_ref(&cli)))
         },
         None,
         theme_from_jar(&jar),
@@ -984,9 +984,7 @@ pub async fn room_page(
                     (new_thread_form_for_room(&nav, true, false))
                 }
             }
-            (cli_panel(&forum_cli))
-            (cli_panel(&garden_cli))
-            (cli_panel(&audit_cli))
+            (cli_panel(&[forum_cli, garden_cli, audit_cli]))
         },
         None,
         theme_from_jar(&jar),
@@ -1409,7 +1407,7 @@ pub async fn user_profile_page(
                     }
                 }
             }
-            (cli_panel(&format!("npx slugsocial public forum list")))
+            (cli_panel(&[format!("npx slugsocial public forum list")]))
         },
         None,
         theme_from_jar(&jar),
diff --git a/server/src/html/garden.rs b/server/src/html/garden.rs
index 9b4789a79c3e293cbfc5f033a0eac8650320d94d..c8ce7de450f7d14e04020511e7eb7323bd487deb 100644
--- a/server/src/html/garden.rs
+++ b/server/src/html/garden.rs
@@ -139,7 +139,7 @@ pub async fn garden_index(
                     }
                 }
             }
-            (cli_panel("npx slugsocial garden tree"))
+            (cli_panel(&["npx slugsocial garden tree"]))
         },
         None,
         theme_from_jar(&jar),
@@ -542,7 +542,7 @@ async fn render_scope_view(
                 ScopeId::Public => format!("npx slugsocial public garden body {}", path.as_str().trim_start_matches("https://slug.social/~/")),
                 ScopeId::Room(room_id) => format!("npx slugsocial private {room_id} garden body {}", path.as_str().trim_start_matches("https://slug.social/~/")),
             };
-            (cli_panel(&cli))
+            (cli_panel(std::slice::from_ref(&cli)))
         },
         None,
         theme_from_jar(&jar),
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index e7f5bfb7a4b2dee2adf96447224c58d641092124..6617781a2e8e86c2e2693788ea7cd0eb0e3659a2 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -599,18 +599,38 @@ pub(super) fn render_linkified_with_embeds_in_scope(raw: &str, garden_prefix: &s
     }
 }
 
-/// Small CLI hint panel showing how to look up this page from the terminal.
-pub(super) fn cli_panel(cmd: &str) -> Markup {
+/// CLI strings are embedded in a single-quoted JS literal; they must never need escaping.
+fn assert_cli_panel_cmd_js_single_quote_safe(s: &str) {
+    assert!(
+        !s.contains('\\')
+            && !s.contains('\'')
+            && !s.contains('\n')
+            && !s.contains('\r'),
+        "cli_panel cmd must not contain `\\`, `'`, or newlines (got {s:?})"
+    );
+}
+
+/// Small CLI hint panel: one border and title; each line is hover-highlighted and copies on click.
+pub(super) fn cli_panel<I: AsRef<str>>(cmds: &[I]) -> Markup {
+    if cmds.is_empty() {
+        return html! {};
+    }
+    for cmd in cmds {
+        assert_cli_panel_cmd_js_single_quote_safe(cmd.as_ref());
+    }
     html! {
         div class="cli-panel" {
             span class="cli-panel-label muted" { "cli" }
-            code class="cli-panel-cmd" { (cmd) }
-            button
-                class="cli-panel-copy"
-                title="Copy to clipboard"
-                onclick=(format!(r#"navigator.clipboard.writeText('{}'); this.textContent='✓'; setTimeout(() => this.textContent='copy', 2000);"#, cmd.replace("'", "\\'")))
-            {
-                "copy"
+            div class="cli-panel-cmds" {
+                @for cmd in cmds {
+                    @let s = cmd.as_ref();
+                    button type="button" class="cli-panel-row" title="Copy command" onclick=(format!(
+                        r#"navigator.clipboard.writeText('{}');"#,
+                        s
+                    )) {
+                        code class="cli-panel-cmd" { (s) }
+                    }
+                }
             }
         }
     }
diff --git a/server/src/html/search.rs b/server/src/html/search.rs
index 28ceaa53c3fcac6777311535e95fb771b19438f5..43e6ebf36cf0fe72c96f0f9d850bea51ac094c43 100644
--- a/server/src/html/search.rs
+++ b/server/src/html/search.rs
@@ -418,7 +418,7 @@ pub async fn search_page(
                     value=(query) autocomplete="off" autofocus;
             }
             (render_search_results(&results, &query))
-            (cli_panel("npx slugsocial search <query>"))
+            (cli_panel(&["npx slugsocial search <query>"]))
         },
         None,
         theme_from_jar(&jar),
diff --git a/server/static/theme_default.css b/server/static/theme_default.css
index e024a5c8b74139ae8be37b2a1bd17e4c3abe9324..764b66c8208e91e6138b83c534387cf43c85b8b5 100644
--- a/server/static/theme_default.css
+++ b/server/static/theme_default.css
@@ -610,7 +610,7 @@ code {
    CLI PANEL — how to view this page from the terminal
    ---------------------------------------------------------------- */
 div.cli-panel {
-  align-items: baseline;
+  align-items: flex-start;
   background: var(--g1);
   border: var(--bv) solid;
   border-color: var(--lo) var(--hi) var(--hi) var(--lo); /* inset */
@@ -621,11 +621,34 @@ div.cli-panel {
   width: fit-content;
   max-width: 100%;
 }
+.cli-panel-cmds {
+  display: flex;
+  flex-direction: column;
+  gap: 4px;
+  flex: 1;
+  min-width: 0;
+}
+button.cli-panel-row {
+  background: transparent;
+  border: none;
+  color: inherit;
+  cursor: pointer;
+  display: block;
+  font: inherit;
+  margin: 0;
+  padding: 2px 4px;
+  text-align: left;
+  width: 100%;
+}
+button.cli-panel-row:hover {
+  background: var(--g3);
+}
 .cli-panel-label {
   font-size: 11px;
   letter-spacing: 0.08em;
   text-transform: uppercase;
   flex-shrink: 0;
+  padding-top: 2px;
 }
 .cli-panel-cmd {
   background: none;
diff --git a/server/static/theme_retro_craft.css b/server/static/theme_retro_craft.css
index 00714575bfa533d1d9c66653b9089642e2b0a6ca..f89ecbc3a18eb9b2b27d1f7764330f6bd6987552 100644
--- a/server/static/theme_retro_craft.css
+++ b/server/static/theme_retro_craft.css
@@ -306,19 +306,41 @@ a.post-nav-btn:hover {
 }
 
 div.cli-panel {
-  align-items: baseline;
+  align-items: flex-start;
   border: 1px dashed var(--line);
   display: flex;
-  flex-wrap: wrap;
   gap: 0.5rem;
   margin: 0.65rem 0;
   padding: 0.45rem 0.65rem;
 }
+.cli-panel-cmds {
+  display: flex;
+  flex-direction: column;
+  gap: 0.25rem;
+  flex: 1;
+  min-width: 0;
+}
+button.cli-panel-row {
+  background: transparent;
+  border: none;
+  color: inherit;
+  cursor: pointer;
+  display: block;
+  font: inherit;
+  margin: 0;
+  padding: 0.1rem 0.2rem;
+  text-align: left;
+  width: 100%;
+}
+button.cli-panel-row:hover {
+  background: color-mix(in srgb, var(--accent) 14%, transparent);
+}
 .cli-panel-label {
   color: var(--ink-dim);
   font-size: 0.72rem;
   letter-spacing: 0.12em;
   text-transform: uppercase;
+  padding-top: 0.12rem;
 }
 .cli-panel-cmd {
   color: var(--accent);

download full diff B

Hardlinks — judgments / attempts / prompt

prompt download

judgments

attempts

Prompt text is loaded only by the download route.