constitution · epochs · watch · epoch 3

comparison

c_939729b4d9a6 (tommy-mor) vs c_ca72f0995396 (tommy-mor)

download prompt · raw event · cmp_6b15858c6d222c

council reasoning

~anthropic/claude-sonnet-latest · winner A · 6:4 · permalink

Side A adds substantive new functionality (typed form holes for numeric fields, vote-page routing/redirect logic, new dependencies wired in) accompanied by unit tests validating the new behavior, giving it broader lasting impact. Side B is a focused but narrower UI refactor (merging multiple cli_panel calls into one bordered panel with hover-to-copy and a JS-safety assert) that improves polish but touches less core logic and lacks tests.

~x-ai/grok-latest · winner A · 4:1 · permalink

A adds real product capability: typed $form:i32 substitution with tests, RecordVote next-navigation, vote CTAs/route wiring, and the compare-page CSS/JS slider behavior. B only refactors the existing cli_panel into a grouped hover-to-copy widget plus safety asserts—useful UX polish, but narrower and less foundational than A’s feature and form-template work.

openai/gpt-chat-latest · winner A · 4:1 · permalink

Side A adds substantive application behavior: typed `{"$form:i32":...}` template substitution with tests, a new `next` navigation field for vote handling, vote-page routing/UI integration, and client-side support for vote sliders and redirects after recording a vote. Side B mainly refactors the CLI helper into a grouped, clickable panel with CSS updates and a defensive assertion that command strings are safe for embedding in single-quoted JavaScript, which is a useful UI improvement but has a narrower long-term impact.

sides

A — c_939729b4d9a6 (tommy-mor)

message

[7964b28f] fix

diff preview

diff --git a/Cargo.lock b/Cargo.lock
index 8c43fb75c472b102e6e1d3b837dce3355be898f2..e55d87f32ab32064686431c7082ef8c9ca872d63 100644
--- a/Cargo.lock
+++ b/Cargo.lock
@@ -923,6 +923,15 @@ version = "0.2.0"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "439ee305def115ba05938db6eb1644ff94165c5ab5e9420d1c1bcedbba909391"
 
+[[package]]
+name = "ppv-lite86"
+version = "0.2.21"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "85eae3c4ed2f50dcfe72643da4befc30deadb458a9b590d720cde2f2b1e97da9"
+dependencies = [
+ "zerocopy",
+]
+
 [[package]]
 name = "prettyplease"
 version = "0.2.37"
@@ -980,6 +989,36 @@ version = "6.0.0"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "f8dcc9c7d52a811697d2151c701e0d08956f92b0e24136cf4cf27b57a6a0d9bf"
 
+[[package]]
+name = "rand"
+version = "0.8.6"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "5ca0ecfa931c29007047d1bc58e623ab12e5590e8c7cc53200d5202b69266d8a"
+dependencies = [
+ "libc",
+ "rand_chacha",
+ "rand_core",
+]
+
+[[package]]
+name = "rand_chacha"
+version = "0.3.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "e6c10a63a0fa32252be49d21e7709d4d4baf8d231c2dbce1eaa8141b9b127d88"
+dependencies = [
+ "ppv-lite86",
+ "rand_core",
+]
+
+[[package]]
+name = "rand_core"
+version = "0.6.4"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "ec0be4795e2f6a28069bec0b5ff3e2ac9bafc99e6a9a7dc3547996c5c816922c"
+dependencies = [
+ "getrandom 0.2.17",
+]
+
 [[package]]
 name = "regex-automata"
 version = "0.4.14"
@@ -1270,6 +1309,7 @@ dependencies = [
  "dotenvy",
  "futures-util",
  "maud",
+ "rand",
  "reqwest",
  "serde",
  "serde_json",
@@ -1280,6 +1320,7 @@ dependencies = [
  "tower-http 0.5.2",
  "tracing",
  "tracing-subscriber",
+ "urlencoding",
 ]
 
 [[package]]
@@ -1656,6 +1697,12 @@ dependencies = [
  "serde",
 ]
 
+[[package]]
+name = "urlencoding"
+version = "2.1.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "daf8dba3b7eb870caf1ddeed7bc9d2a049f3cfdfae7cb521b087cc33ae4c49da"
+
 [[package]]
 name = "utf8_iter"
 version = "1.0.4"
@@ -2052,6 +2099,26 @@ dependencies = [
  "synstructure",
 ]
 
+[[package]]
+name = "zerocopy"
+version = "0.8.50"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "3b065d4f0e55f82fae73202e189638116a87c55ab6b8e6c2721e13dd9d854ad1"
+dependencies = [
+ "zerocopy-derive",
+]
+
+[[package]]
+name = "zerocopy-derive"
+version = "0.8.50"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "0b631b19d36a892ab55420c92dbc83ccd79274f25be714855d3074aa71cab639"
+dependencies = [
+ "proc-macro2",
+ "quote",
+ "syn",
+]
+
 [[package]]
 name = "zerofrom"
 version = "0.1.8"
diff --git a/server/Cargo.toml b/server/Cargo.toml
index c940acb687fb141d21760a3d6656172013cf6f41..6fb7bf52fa58f46f5e8fb0f7fd395247b57506d7 100644
--- a/server/Cargo.toml
+++ b/server/Cargo.toml
@@ -20,6 +20,8 @@ reqwest = { version = "0.12", features = ["json"] }
 dotenvy = "0.15"
 async-stream = "0.3"
 futures-util = { version = "0.3", default-features = false, features = ["std"] }
+rand = "0.8"
+urlencoding = "2"
 
 [dev-dependencies]
 reqwest = { version = "0.12", features = ["json"] }
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index e649a7d192feade465e19ce6187a829f6ec74372..06001212820101e0cc953d3687dea64f85e60787 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -47,6 +47,7 @@ pub async fn post_ui_html(
             ratio_left,
             ratio_right,
             scope,
+            next,
         } => {
             let parent = parent_from_scope(&scope);
             if let Err(e) = state
@@ -56,9 +57,19 @@ pub async fn post_ui_html(
                 return ui_js_warn(&e).into_response();
             }
             let tree = state.tree.read().await;
+            if !next.trim().is_empty() {
+                drop(tree);
+                return JsBuilder::new()
+                    .raw(&format!(
+                        "window.location.href={};",
+                        js_string_literal(next.trim())
+                    ))
+                    .into_response();
+            }
             let empty = crate::reducer::NodeState::default();
             let node = tree.get(&parent).unwrap_or(&empty);
             let panel = ranking_panel(&parent, node, &tree);
+            drop(tree);
             JsBuilder::new()
                 .morph_selector("#ranking-panel", panel)
                 .into_response()
@@ -126,6 +137,7 @@ mod tests {
                 ratio_left: 3,
                 ratio_right: 1,
                 scope: String::new(),
+                next: String::new(),
             }
         );
     }
diff --git a/server/src/form_template.rs b/server/src/form_template.rs
index b9bc3982a125e94e67c99175ea9055979541abba..bd4a7195a6eaabfed55333bab5640708ea108b81 100644
--- a/server/src/form_template.rs
+++ b/server/src/form_template.rs
@@ -7,19 +7,30 @@ pub fn template_json_compact<T: Serialize>(v: &T) -> serde_json::Result<String>
     serde_json::to_string(v)
 }
 
-/// Recursively walk the JSON AST and replace `{"$form": "key"}` with the submitted
-/// string for `key` (empty if missing). Other keys are unchanged.
+/// Recursively walk the JSON AST and replace form holes with submitted values.
+///
+/// - `{"$form": "key"}` → string (empty if missing)
+/// - `{"$form:i32": "key"}` → JSON number (0 if missing or unparseable)
 pub fn substitute_form_vars(val: &mut Value, form_data: &HashMap<String, String>) {
     match val {
         Value::Object(map) => {
             if map.len() == 1 {
-                if let Some(Value::String(field_name)) = map.get("$form") {
-                    let submitted = form_data
-                        .get(field_name.as_str())
-                        .map(|s| s.as_str())
-                        .unwrap_or("");
-                    *val = Value::String(submitted.to_string());
-                    return;
+                if let Some((hole_key, Value::String(field_name))) = map.iter().next() {
+                    if let Some(form_type) = hole_key.strip_prefix("$form") {
+                        let submitted = form_data
+                            .get(field_name.as_str())
+                            .map(|s| s.as_str())
+                            .unwrap_or("");
+                        *val = match form_type {
+                            "" => Value::String(submitted.to_string()),
+                            ":i32" => {
+                                let n: i32 = submitted.trim().parse().unwrap_or(0);
+                                Value::Number(n.into())
+                            }
+                            _ => Value::String(submitted.to_string()),
+                        };
+                        return;
+                    }
                 }
             }
             for v in map.values_mut() {
@@ -62,6 +73,45 @@ mod tests {
         text: String,
     }
 
+    #[test]
+    fn i32_holes_become_numbers() {
+        let json = r#"{
+            "ratio_left": {"$form:i32": "ratio_left"},
+            "ratio_right": {"$form:i32": "ratio_right"}
+        }"#;
+        let mut form = HashMap::new();
+        form.insert("ratio_left".into(), "75".into());
+        form.insert("ratio_right".into(), "25".into());
+        let v = fill_template_from_form(json, &form).unwrap();
+        assert_eq!(v["ratio_left"], 75);
+        assert_eq!(v["ratio_right"], 25);
+
+        #[derive(Debug, Deserialize, PartialEq, Eq)]
+        struct Ratios {
+            ratio_left: i32,
+            ratio_right: i32,
+        }
+        let r: Ratios = serde_json::from_value(v).unwrap();
+        assert_eq!(
+            r,
+            Ratios {
+                ratio_left: 75,
+                ratio_right: 25,
+            }
+        );
+    }
+
+    #[test]
+    fn i32_hole_missing_or_bad_defaults_to_zero() {
+        let json = r#"{"n": {"$form:i32": "missing"}}"#;
+        let v = fill_template_from_form(json, &HashMap::new()).unwrap();
+        assert_eq!(v["n"], 0);
+        let mut form = HashMap::new();
+        form.insert("missing".into(), "nope".into());
+        let v = fill_template_from_form(json, &form).unwrap();
+        assert_eq!(v["n"], 0);
+    }
+
     #[test]
     fn holes_become_strings() {
         let json = r#"{
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index 3bf9fc7e92e50beed24e2c25106a77421038c90b..61cdbc094819ddedb755572c59456ec0d6617619 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -20,6 +20,8 @@ use crate::{
     ui_action::UI_RPC_FIELD,
 };
 
+pub mod vote;
+
 const SORTER_CSS: &str = include_str!("../../static/sorter.css");
 const SORTER_UI_JS: &str = include_str!("../../static/sorter_ui.js");
 
@@ -131,7 +133,7 @@ fn layout(title: &str, body: Markup, views: u64) -> Markup {
     }
 }
 
-fn item_href(id: &ItemId) -> String {
+pub(crate) fn item_href(id: &ItemId) -> String {
     id.browse_href()
 }
 
@@ -309,11 +311,23 @@ async fn item_page(state: AppState, uri: Uri, item: ItemId) -> Markup {
     let empty_node = NodeState::default();
     let node = tree.get(&item).unwrap_or(&empty_node);
 
+    let child_count = node.children.len();
+    let vote_link = if child_count >= 2 {
+        Some(vote::vote_href(&item))
+    } else {
+        None
+    };
+
     let body = html! {
         h1 { "sorter" }
         (input_panel("", None))
         (breadcrumb_path(&item))
         (entity_section(&item, node, false))
+        @if let Some(href) = vote_link {
+            p class="vote-cta" {
+                a class="btn-primary" href=(href) data-testid="vote-children" { "Vote on children" }
+            }
+        }
         (ranking_panel(&item, node, &tree))
     };
     layout("sorter2", body, views)
diff --git a/server/src/lib.rs b/server/src/lib.rs
index da5f3ebecec1794b05a2a69cc78379551b2ad769..7f7e28c8ac3758de87f1f8e073b24be4132d38da 100644
--- a/server/src/lib.rs
+++ b/server/src/lib.rs
@@ -4,6 +4,7 @@ pub mod events;
 pub mod fetch;
 pub mod form_template;
 pub mod html;
+pub mod pair;
 pub mod parser;
 pub mod path_types;
 pub mod ranking;
@@ -33,6 +34,7 @@ pub fn create_app(state: AppState) -> Router {
         .route("/static/:filename", get(crate::html::serve_static))
         .route("/~/*item_path", get(crate::html::browse))
         .route("/", get(crate::html::home))
+        .route("/vote", get(crate::html::vote::vote_page))
         .route("/ui", post(crate::api::ui_html::post_ui_html))
         .with_state(state)
         .layer(TraceLayer::new_for_http())
diff --git a/server/src/ui_action.rs b/server/src/ui_action.rs
index 2047713762c932ac9bc325fe15624f2aecb3364d..53581e1362bfcc5dfb4ae3069c41ea6f7be41437 100644
--- a/server/src/ui_action.rs
+++ b/server/src/ui_action.rs
@@ -31,6 +31,9 @@ pub enum HtmlUiAction {
         /// Parent node [`ItemId`] string; empty = tree root.
         #[serde(default)]
         scope: String,
+        /// After vote, navigate here (vote compare page).
+        #[serde(default)]
+        next: String,
     },
     /// Parse pasted Reddit URL/path; redirect to subreddit ranking on success.
     ParseQuery {
@@ -70,6 +73,36 @@ pub fn parse_html_ui_from_form(
 mod tests {
     use super::*;
 
+    #[test]
+    fn record_vote_round_trip_with_typed_ratio_holes() {
+        let template = serde_json::json!({
+            "action": "record_vote",
+            "a": "x",
+            "b": "y",
+            "ratio_left": {"$form:i32": "ratio_left"},
+            "ratio_right": {"$form:i32": "ratio_right"},
+            "scope": "parent",
+        });
+        let mut form = HashMap::new();
+        form.insert(
+            UI_RPC_FIELD.to_string(),
+            serde_json::to_string(&template).unwrap(),
+        );
+        form.insert("ratio_left".into(), "60".into());
+        form.

… preview truncated; 4,992 characters omitted

download full diff A

B — c_ca72f0995396 (tommy-mor)

message

[798c764d] feat(html): grouped cli_panel with hover-to-copy and JS-safe asserts

Single bordered panel for multiple commands; rows copy on click without a
separate copy control. Assert CLI strings contain no chars that would break
single-quoted onclick JS.

Made-with: Cursor

diff preview

diff --git a/server/src/html/forum.rs b/server/src/html/forum.rs
index f6e45b05bb92126966e304619f80ef1d45be7a4b..075860914a6ce18bb0dfa73dc5651ef1a6318b67 100644
--- a/server/src/html/forum.rs
+++ b/server/src/html/forum.rs
@@ -718,7 +718,7 @@ pub async fn home(
             }
             div id="public-new-thread-ui-slot" {}
             (render_thread_feed(Some(&nav), "thread-feed", &public_rows, now))
-            (cli_panel("npx slugsocial public forum list"))
+            (cli_panel(&["npx slugsocial public forum list"]))
         },
         None,
         theme_from_jar(&jar),
@@ -868,7 +868,7 @@ async fn thread_view_inner(
             div id="thread-live-region" {
                 (compose_form(&nav, &tag, show_compose))
             }
-            (cli_panel(&cli))
+            (cli_panel(std::slice::from_ref(&cli)))
         },
         None,
         theme_from_jar(&jar),
@@ -984,9 +984,7 @@ pub async fn room_page(
                     (new_thread_form_for_room(&nav, true, false))
                 }
             }
-            (cli_panel(&forum_cli))
-            (cli_panel(&garden_cli))
-            (cli_panel(&audit_cli))
+            (cli_panel(&[forum_cli, garden_cli, audit_cli]))
         },
         None,
         theme_from_jar(&jar),
@@ -1409,7 +1407,7 @@ pub async fn user_profile_page(
                     }
                 }
             }
-            (cli_panel(&format!("npx slugsocial public forum list")))
+            (cli_panel(&[format!("npx slugsocial public forum list")]))
         },
         None,
         theme_from_jar(&jar),
diff --git a/server/src/html/garden.rs b/server/src/html/garden.rs
index 9b4789a79c3e293cbfc5f033a0eac8650320d94d..c8ce7de450f7d14e04020511e7eb7323bd487deb 100644
--- a/server/src/html/garden.rs
+++ b/server/src/html/garden.rs
@@ -139,7 +139,7 @@ pub async fn garden_index(
                     }
                 }
             }
-            (cli_panel("npx slugsocial garden tree"))
+            (cli_panel(&["npx slugsocial garden tree"]))
         },
         None,
         theme_from_jar(&jar),
@@ -542,7 +542,7 @@ async fn render_scope_view(
                 ScopeId::Public => format!("npx slugsocial public garden body {}", path.as_str().trim_start_matches("https://slug.social/~/")),
                 ScopeId::Room(room_id) => format!("npx slugsocial private {room_id} garden body {}", path.as_str().trim_start_matches("https://slug.social/~/")),
             };
-            (cli_panel(&cli))
+            (cli_panel(std::slice::from_ref(&cli)))
         },
         None,
         theme_from_jar(&jar),
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index e7f5bfb7a4b2dee2adf96447224c58d641092124..6617781a2e8e86c2e2693788ea7cd0eb0e3659a2 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -599,18 +599,38 @@ pub(super) fn render_linkified_with_embeds_in_scope(raw: &str, garden_prefix: &s
     }
 }
 
-/// Small CLI hint panel showing how to look up this page from the terminal.
-pub(super) fn cli_panel(cmd: &str) -> Markup {
+/// CLI strings are embedded in a single-quoted JS literal; they must never need escaping.
+fn assert_cli_panel_cmd_js_single_quote_safe(s: &str) {
+    assert!(
+        !s.contains('\\')
+            && !s.contains('\'')
+            && !s.contains('\n')
+            && !s.contains('\r'),
+        "cli_panel cmd must not contain `\\`, `'`, or newlines (got {s:?})"
+    );
+}
+
+/// Small CLI hint panel: one border and title; each line is hover-highlighted and copies on click.
+pub(super) fn cli_panel<I: AsRef<str>>(cmds: &[I]) -> Markup {
+    if cmds.is_empty() {
+        return html! {};
+    }
+    for cmd in cmds {
+        assert_cli_panel_cmd_js_single_quote_safe(cmd.as_ref());
+    }
     html! {
         div class="cli-panel" {
             span class="cli-panel-label muted" { "cli" }
-            code class="cli-panel-cmd" { (cmd) }
-            button
-                class="cli-panel-copy"
-                title="Copy to clipboard"
-                onclick=(format!(r#"navigator.clipboard.writeText('{}'); this.textContent='✓'; setTimeout(() => this.textContent='copy', 2000);"#, cmd.replace("'", "\\'")))
-            {
-                "copy"
+            div class="cli-panel-cmds" {
+                @for cmd in cmds {
+                    @let s = cmd.as_ref();
+                    button type="button" class="cli-panel-row" title="Copy command" onclick=(format!(
+                        r#"navigator.clipboard.writeText('{}');"#,
+                        s
+                    )) {
+                        code class="cli-panel-cmd" { (s) }
+                    }
+                }
             }
         }
     }
diff --git a/server/src/html/search.rs b/server/src/html/search.rs
index 28ceaa53c3fcac6777311535e95fb771b19438f5..43e6ebf36cf0fe72c96f0f9d850bea51ac094c43 100644
--- a/server/src/html/search.rs
+++ b/server/src/html/search.rs
@@ -418,7 +418,7 @@ pub async fn search_page(
                     value=(query) autocomplete="off" autofocus;
             }
             (render_search_results(&results, &query))
-            (cli_panel("npx slugsocial search <query>"))
+            (cli_panel(&["npx slugsocial search <query>"]))
         },
         None,
         theme_from_jar(&jar),
diff --git a/server/static/theme_default.css b/server/static/theme_default.css
index e024a5c8b74139ae8be37b2a1bd17e4c3abe9324..764b66c8208e91e6138b83c534387cf43c85b8b5 100644
--- a/server/static/theme_default.css
+++ b/server/static/theme_default.css
@@ -610,7 +610,7 @@ code {
    CLI PANEL — how to view this page from the terminal
    ---------------------------------------------------------------- */
 div.cli-panel {
-  align-items: baseline;
+  align-items: flex-start;
   background: var(--g1);
   border: var(--bv) solid;
   border-color: var(--lo) var(--hi) var(--hi) var(--lo); /* inset */
@@ -621,11 +621,34 @@ div.cli-panel {
   width: fit-content;
   max-width: 100%;
 }
+.cli-panel-cmds {
+  display: flex;
+  flex-direction: column;
+  gap: 4px;
+  flex: 1;
+  min-width: 0;
+}
+button.cli-panel-row {
+  background: transparent;
+  border: none;
+  color: inherit;
+  cursor: pointer;
+  display: block;
+  font: inherit;
+  margin: 0;
+  padding: 2px 4px;
+  text-align: left;
+  width: 100%;
+}
+button.cli-panel-row:hover {
+  background: var(--g3);
+}
 .cli-panel-label {
   font-size: 11px;
   letter-spacing: 0.08em;
   text-transform: uppercase;
   flex-shrink: 0;
+  padding-top: 2px;
 }
 .cli-panel-cmd {
   background: none;
diff --git a/server/static/theme_retro_craft.css b/server/static/theme_retro_craft.css
index 00714575bfa533d1d9c66653b9089642e2b0a6ca..f89ecbc3a18eb9b2b27d1f7764330f6bd6987552 100644
--- a/server/static/theme_retro_craft.css
+++ b/server/static/theme_retro_craft.css
@@ -306,19 +306,41 @@ a.post-nav-btn:hover {
 }
 
 div.cli-panel {
-  align-items: baseline;
+  align-items: flex-start;
   border: 1px dashed var(--line);
   display: flex;
-  flex-wrap: wrap;
   gap: 0.5rem;
   margin: 0.65rem 0;
   padding: 0.45rem 0.65rem;
 }
+.cli-panel-cmds {
+  display: flex;
+  flex-direction: column;
+  gap: 0.25rem;
+  flex: 1;
+  min-width: 0;
+}
+button.cli-panel-row {
+  background: transparent;
+  border: none;
+  color: inherit;
+  cursor: pointer;
+  display: block;
+  font: inherit;
+  margin: 0;
+  padding: 0.1rem 0.2rem;
+  text-align: left;
+  width: 100%;
+}
+button.cli-panel-row:hover {
+  background: color-mix(in srgb, var(--accent) 14%, transparent);
+}
 .cli-panel-label {
   color: var(--ink-dim);
   font-size: 0.72rem;
   letter-spacing: 0.12em;
   text-transform: uppercase;
+  padding-top: 0.12rem;
 }
 .cli-panel-cmd {
   color: var(--accent);

download full diff B

Hardlinks — judgments / attempts / prompt

prompt download

judgments

attempts

Prompt text is loaded only by the download route.