B fixes real, concrete bugs (str/split with a string instead of regex, reading from the wrong stream, -1 vs 0 content-length, unhandled nil token/state causing crashes) that were actually breaking E2E auth tests, plus adds exception handling so the mock server doesn't die silently. A is a larger feature/refactor (theme cookie plumbing, room-scoped URL rewriting) which is plausibly useful but is unreviewed new surface area with added complexity across many files, whereas B's changes are small, targeted, and verifiably correct fixes to broken test infrastructure.
constitution · epochs · watch · epoch 3
c_3f420a1f5aa1 (tommy-mor) vs c_597d3f736194 (tommy-mor)
download prompt · raw event · cmp_84787f67c74684
council reasoning
A delivers durable product design: cookie-based SSR theming (POST /theme, layout/auth re-issue so login keeps theme) plus real private-room wire fixes (item_path_for_api_in_room, forum_thread_web_url, RPC/CLI URL correctness and tests). B is a precise, valuable unblocker for E2E OAuth mocks (split regex, getRequestBody, null-safe state/token, redirect length) but is test-only and narrower in lasting project impact.
Side A adds substantial user-facing and architectural functionality: persistent theme selection via cookies and a new `/theme` endpoint integrated across HTML rendering, preserves theme through authentication by reissuing cookies, and introduces room-aware URL generation (`item_path_for_api_in_room`, `forum_thread_web_url`) with broad RPC integration and tests. Side B is a valuable maintenance fix that repairs OAuth test mocks (query parsing, request-body handling, redirects, null checks, exception handling) so end-to-end auth tests work again, but its impact is confined to test infrastructure rather than core project behavior.
sides
A — c_3f420a1f5aa1 (tommy-mor)
message
[2fe70b0e] themes
diff preview
diff --git a/server/src/api/auth.rs b/server/src/api/auth.rs
index 559db65de14c6157690ffbf18eca0cf65b0a5202..b3631b06153d52f88348fef927e7a024b7b85ad6 100644
--- a/server/src/api/auth.rs
+++ b/server/src/api/auth.rs
@@ -1,7 +1,7 @@
use axum::{
body::Body,
extract::{Path, Query, State},
- http::{header, HeaderMap, HeaderValue, StatusCode},
+ http::{header, HeaderMap, HeaderValue, StatusCode, Uri},
response::{IntoResponse, Redirect, Response},
Form, Json,
};
@@ -17,7 +17,7 @@ use crate::{
events::{Event, GrantAdded, TokenIssued, UserRegistered},
html::{
auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment,
- choose_username_page, JsBuilder,
+ choose_username_page, theme_cookie_header_from_jar, theme_from_jar, theme_next_from_uri, JsBuilder,
},
identity::{parse_agent, parse_username},
reducer::ReducerState,
@@ -48,15 +48,17 @@ fn js_form_error_fragment(session: &str, error: &str) -> Response {
.into_response()
}
-fn js_signed_in_fragment(bearer: &str) -> Response {
+fn js_signed_in_fragment(bearer: &str, jar: &CookieJar) -> Response {
let mut response = JsBuilder::new()
.id("choose-username-form")
.morph_inner(auth_signed_in_fragment())
.redirect("/auth/complete")
.into_response();
- response
- .headers_mut()
- .insert(header::SET_COOKIE, session_cookie_header_value(bearer));
+ let headers = response.headers_mut();
+ headers.append(header::SET_COOKIE, session_cookie_header_value(bearer));
+ if let Some(theme) = theme_cookie_header_from_jar(jar) {
+ headers.append(header::SET_COOKIE, theme);
+ }
response
}
@@ -69,13 +71,18 @@ pub fn optional_principal(headers: &HeaderMap, jar: &CookieJar, reduced: &Reduce
verify_token(reduced, c.value()).ok()
}
-fn redirect_with_session_cookie(public_url: &str, path_and_query: &str, bearer: &str) -> Response {
- Response::builder()
+fn redirect_with_session_cookie(public_url: &str, path_and_query: &str, bearer: &str, jar: &CookieJar) -> Response {
+ let mut res = Response::builder()
.status(StatusCode::TEMPORARY_REDIRECT)
.header(header::LOCATION, format!("{public_url}{path_and_query}"))
- .header(header::SET_COOKIE, session_cookie_header_value(bearer))
.body(Body::empty())
- .unwrap()
+ .unwrap();
+ let headers = res.headers_mut();
+ headers.append(header::SET_COOKIE, session_cookie_header_value(bearer));
+ if let Some(theme) = theme_cookie_header_from_jar(jar) {
+ headers.append(header::SET_COOKIE, theme);
+ }
+ res
}
async fn apply_invite_redemption(state: &AppState, invite_token: &str, grantee_username: &str) -> Result<(), String> {
@@ -286,7 +293,11 @@ pub struct AuthCallbackQuery {
pub state: String,
}
-pub async fn get_auth_callback(Query(q): Query<AuthCallbackQuery>, State(state): State<AppState>) -> impl IntoResponse {
+pub async fn get_auth_callback(
+ Query(q): Query<AuthCallbackQuery>,
+ State(state): State<AppState>,
+ jar: CookieJar,
+) -> impl IntoResponse {
let sessions = pending_sessions(&state);
{
let sessions_read = sessions.read().await;
@@ -365,7 +376,7 @@ pub async fn get_auth_callback(Query(q): Query<AuthCallbackQuery>, State(state):
}
let cookie_bearer = bearer.clone();
s.complete = Some((username, bearer));
- return redirect_with_session_cookie(&public_url, "/", &cookie_bearer).into_response();
+ return redirect_with_session_cookie(&public_url, "/", &cookie_bearer, &jar).into_response();
}
}
@@ -378,14 +389,20 @@ pub struct ChooseUsernameQuery {
pub error: Option<String>,
}
-pub async fn get_choose_username(Query(q): Query<ChooseUsernameQuery>, State(state): State<AppState>) -> impl IntoResponse {
+pub async fn get_choose_username(
+ Query(q): Query<ChooseUsernameQuery>,
+ State(state): State<AppState>,
+ jar: CookieJar,
+ uri: Uri,
+) -> impl IntoResponse {
let sessions = pending_sessions(&state);
let sessions_read = sessions.read().await;
if !sessions_read.contains_key(&q.session) {
return api_error(StatusCode::NOT_FOUND, "unknown session", None).into_response();
}
drop(sessions_read);
- choose_username_page(&q.session, q.error.as_deref()).into_response()
+ let next = theme_next_from_uri(&uri);
+ choose_username_page(&q.session, q.error.as_deref(), theme_from_jar(&jar), &next).into_response()
}
#[derive(Debug, Deserialize)]
@@ -396,6 +413,7 @@ pub struct ChooseUsernameForm {
pub async fn post_choose_username(
State(state): State<AppState>,
+ jar: CookieJar,
Form(form): Form<ChooseUsernameForm>,
) -> impl IntoResponse {
let canon_user = match parse_username(&form.username) {
@@ -477,7 +495,7 @@ pub async fn post_choose_username(
s.complete = Some((canon_user.clone(), bearer.clone()));
}
- js_signed_in_fragment(&bearer).into_response()
+ js_signed_in_fragment(&bearer, &jar).into_response()
}
/// Start a browser-only OAuth flow (no CLI polling). Sets session cookie on success.
@@ -569,8 +587,9 @@ pub async fn get_pending_session(
.into_response()
}
-pub async fn get_auth_complete() -> impl IntoResponse {
- auth_complete_page()
+pub async fn get_auth_complete(jar: CookieJar, uri: Uri) -> impl IntoResponse {
+ let next = theme_next_from_uri(&uri);
+ auth_complete_page(theme_from_jar(&jar), &next).into_response()
}
pub async fn get_whoami(State(state): State<AppState>, headers: HeaderMap) -> impl IntoResponse {
diff --git a/server/src/api/helpers.rs b/server/src/api/helpers.rs
index 81e2a55fa3abb8609b4099f91a989480336e11eb..9b71491e9f9efc44a2a4beba09be8f64bd2ff2ee 100644
--- a/server/src/api/helpers.rs
+++ b/server/src/api/helpers.rs
@@ -39,6 +39,55 @@ pub fn item_path_for_api(item: &str) -> String {
}
}
+/// Same as [`item_path_for_api`], but for private rooms ontology items are prefixed with
+/// `/r/{short}/{slug}` so the URL matches the web app (`/r/…/~/…` routes).
+pub fn item_path_for_api_in_room(item: &str, room_wire: &str) -> String {
+ let room = room_wire.trim();
+ if room.is_empty() || room == "public" {
+ return item_path_for_api(item);
+ }
+ let Some((short, slug)) = room.split_once('/') else {
+ return item_path_for_api(item);
+ };
+ if short.is_empty() || slug.is_empty() {
+ return item_path_for_api(item);
+ }
+ let Some(c) = CanonicalItemUrl::parse(item) else {
+ return item_path_for_api(item);
+ };
+ let root = CanonicalItemUrl::ontology_root();
+ let item_norm = c.as_str().trim_end_matches('/');
+ let root_norm = root.as_str().trim_end_matches('/');
+ if let Some(tail) = c.tilde_tail() {
+ return if tail.is_empty() {
+ format!("https://slug.social/r/{short}/{slug}/~")
+ } else {
+ format!("https://slug.social/r/{short}/{slug}/~/{}", tail)
+ };
+ }
+ if item_norm == root_norm {
+ return format!("https://slug.social/r/{short}/{slug}/~");
+ }
+ item_path_for_api(item)
+}
+
+/// Absolute thread URL for forum JSON (`/t/…` vs `/r/…/t/…`).
+pub fn forum_thread_web_url(room_wire: &str, thread_tag: &str) -> String {
+ let room = room_wire.trim();
+ let tag = thread_tag.trim().trim_start_matches('#');
+ if room.is_empty() || room == "public" {
+ format!("https://slug.social/t/{tag}")
+ } else if let Some((short, slug)) = room.split_once('/') {
+ if short.is_empty() || slug.is_empty() {
+ format!("https://slug.social/t/{tag}")
+ } else {
+ format!("https://slug.social/r/{short}/{slug}/t/{tag}")
+ }
+ } else {
+ format!("https://slug.social/t/{tag}")
+ }
+}
+
/// Resolve an item path as a first-class canonical path.
pub fn resolve_item(item: &str) -> Result<String, String> {
let canonical = canonicalize_item(item);
@@ -188,3 +237,52 @@ pub fn vote_touches_path(a: &str, b: &str, parent_canon: &str) -> bool {
let under = |item: &str| item == parent_canon || item.starts_with(&format!("{}/", parent_canon));
under(a) || under(b)
}
+
+#[cfg(test)]
+mod wire_url_tests {
+ use super::{forum_thread_web_url, item_path_for_api_in_room};
+
+ #[test]
+ fn public_room_unchanged() {
+ let u = "https://slug.social/~/a/b";
+ assert_eq!(item_path_for_api_in_room(u, "public"), u);
+ }
+
+ #[test]
+ fn private_room_prefixes_ontology() {
+ assert_eq!(
+ item_path_for_api_in_room("https://slug.social/~/topic/x", "9ab12cd/my-room"),
+ "https://slug.social/r/9ab12cd/my-room/~/topic/x"
+ );
+ }
+
+ #[test]
+ fn private_room_ontology_root() {
+ assert_eq!(
+ item_path_for_api_in_room("https://slug.social/~", "9ab12cd/my-room"),
+ "https://slug.social/r/9ab12cd/my-room/~"
+ );
+ assert_eq!(
+ item_path_for_api_in_room("https://slug.social/~/", "9ab12cd/my-room"),
+ "https://slug.social/r/9ab12cd/my-room/~"
+ );
+ }
+
+ #[test]
+ fn external_url_untouched_in_private_room() {
+ let u = "https://example.com/z";
+ assert_eq!(item_path_for_api_in_room(u, "9ab12cd/my-room"), u);
+ }
+
+ #[test]
+ fn forum_web_public_vs_room() {
+ assert_eq!(
+ forum_thread_web_url("public", "debate"),
+ "https://slug.social/t/debate"
+ );
+ assert_eq!(
+ forum_thread_web_url("9ab12cd/my-room", "#debate"),
+ "https://slug.social/r/9ab12cd/my-room/t/debate"
+ );
+ }
+}
diff --git a/server/src/api/rpc.rs b/server/src/api/rpc.rs
index 31f5fcfb4eaf4df0a9cbac532dd3dedfe3611810..5b91f5836625eedbb1cd9423168046e3fb576c17 100644
--- a/server/src/api/rpc.rs
+++ b/server/src/api/rpc.rs
@@ -27,8 +27,9 @@ use crate::{
use super::auth::verify_bearer_principal;
use super::helpers::{
- compute_connectivity_stats, is_pair_voted, item_path_for_api, now_ms, paginate_rankings,
- parse_parent_specs, pick_random_distinct, resolve_item, vote_touches_path,
+ compute_connectivity_stats, forum_thread_web_url, is_pair_voted, item_path_for_api,
+ item_path_for_api_in_room, now_ms, paginate_rankings, parse_parent_specs, pick_random_distinct,
+ resolve_item, vote_touches_path,
};
use super::validate::{normalize_room_and_thread, validate_ingest_document};
@@ -148,6 +149,7 @@ fn compute_scope_rank_changes(
parent: &str,
before: &crate::scope_rank::ChildrenRankings,
after: &crate::scope_rank::ChildrenRankings,
+ room_wire: &str,
) -> Option<ScopeRankChanges> {
fn build_positions(rankings: &crate::scope_rank::ChildrenRankings) -> HashMap<String, Option<RankPosition>> {
let mut map = HashMap::new();
@@ -182,7 +184,7 @@ fn compute_scope_rank_changes(
};
if changed {
changes.push(RankChange {
- item: item_path_for_api(&item),
+ item: item_path_for_api_in_room(&item, room_wire),
before: b,
after: a,
});
@@ -204,7 +206,7 @@ fn compute_scope_rank_changes(
parent: if parent.is_empty() {
"/".to_string()
} else {
- item_path_for_api(parent)
+ item_path_for_api_in_room(parent, room_wire)
},
changes,
})
@@ -256,6 +258,7 @@ fn build_rank_response_for_content(
offset: usize,
limit: Option<usize>,
want_percent: bool,
+ room_wire: &str,
) -> Result<RankResponse, RpcErr> {
let parent_owned = parent.map(|s| s.to_string());
let specs = parse_parent_specs(parent_owned.as_ref());
@@ -299,7 +302,7 @@ fn build_rank_response_for_content(
.ranked
.into_iter()
.map(|r| RankRow {
-
… preview truncated; 42,928 characters omittedB — c_597d3f736194 (tommy-mor)
message
[075d4d37] Fix OAuth test mocks so Clojure E2E auth flows work again. HttpServer handlers were crashing on query parsing and token POSTs, which broke Playwright login; also read alias/history via real CSS selectors. Co-authored-by: Cursor <cursoragent@cursor.com>
diff preview
diff --git a/test/auth_login.clj b/test/auth_login.clj
index 6f2f00d7aa7340e63d1ac465b0a2234cec7a983f..aa63b66ccb2471b710ba3d168d0461252b39fc10 100644
--- a/test/auth_login.clj
+++ b/test/auth_login.clj
@@ -14,27 +14,27 @@
(defn- type-alias! [pg text]
(page/evaluate pg
(.replace
- "(() => { const i = document.getElementById('alias-input'); const f = document.getElementById('alias-check-form'); if (!i || !f) return;
+ "(() => { const i = document.getElementById('alias-input'); const f = document.getElementById('alias-check-form'); if (!i || !f) return Promise.resolve('missing-form');
i.value = __TEXT__;
const cf = document.getElementById('alias-claim-field'); if (cf) cf.value = i.value;
return fetch(f.action, { method: 'POST', credentials: 'same-origin',
headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
body: new URLSearchParams(new FormData(f)).toString() })
.then(function (r) { return r.text(); })
- .then(function (t) { eval(t); }); })()"
+ .then(function (t) { eval(t); return document.getElementById('alias-status')?.textContent || ''; }); })()"
"__TEXT__"
- (pr-str text)))
- (Thread/sleep 400))
+ (pr-str text))))
-(defn- element-text [pg test-id]
+(defn- element-text [pg selector]
(let [raw (page/evaluate pg
- (str "document.querySelector('[data-testid=\"" test-id "\"]')?.textContent || ''"))]
+ (str "document.querySelector(" (pr-str selector) ")?.textContent || ''"))]
(when (string? raw) (str/trim raw))))
(defn- wait-for-text [pg test-id text timeout-ms]
- (let [deadline (+ (System/currentTimeMillis) timeout-ms)]
+ (let [deadline (+ (System/currentTimeMillis) timeout-ms)
+ selector (str "[data-testid=\"" test-id "\"]")]
(loop []
- (let [got (or (element-text pg test-id) "")]
+ (let [got (or (element-text pg selector) "")]
(cond
(= got text) got
(< (System/currentTimeMillis) deadline) (do (Thread/sleep 200) (recur))
diff --git a/test/support/mock_oauth.clj b/test/support/mock_oauth.clj
index 5ba7e9be3cf6d2226648e9609a09ed45f306930f..333fe08d56cb06bac2a338cad1c73894d54c4495 100644
--- a/test/support/mock_oauth.clj
+++ b/test/support/mock_oauth.clj
@@ -7,7 +7,7 @@
(defn- query-param [query key]
(when query
(some (fn [pair]
- (let [[k v] (str/split pair "=" 2)]
+ (let [[k v] (str/split pair #"=" 2)]
(when (= k key)
(URLDecoder/decode (or v "") "UTF-8"))))
(str/split query #"&"))))
@@ -31,11 +31,11 @@
(defn- send-redirect [^HttpExchange ex location]
(.set (.getResponseHeaders ex) "Location" location)
- (.sendResponseHeaders ex 302 -1)
+ (.sendResponseHeaders ex 302 0)
(.close (.getResponseBody ex)))
(defn- read-form [^HttpExchange ex]
- (let [body (slurp (.getInputStream ex))]
+ (let [body (slurp (.getRequestBody ex))]
{:code (query-param body "code")
:grant (query-param body "grant_type")}))
@@ -45,7 +45,7 @@
(str/replace #"^[Bb]earer " "")))
(defn- parse-token-user [token]
- (when (str/starts-with? token "mock:")
+ (when (and token (str/starts-with? token "mock:"))
(parse-mock-user (subs token 5))))
(defn- authorize-redirect [exchange query]
@@ -55,7 +55,7 @@
user (parse-mock-user mock-user)
code (str "mock:" (:id user) ":" (:login user))
loc (str redirect-uri "?code=" (java.net.URLEncoder/encode code "UTF-8")
- "&state=" (java.net.URLEncoder/encode state "UTF-8"))]
+ "&state=" (java.net.URLEncoder/encode (or state "") "UTF-8"))]
(send-redirect exchange loc)))
(defn start-mock-oauth
@@ -65,49 +65,56 @@
handler
(proxy [HttpHandler] []
(handle [^HttpExchange exchange]
- (let [uri (.getRequestURI exchange)
- path (.getPath uri)
- query (.getQuery uri)
- method (.getRequestMethod exchange)]
- (cond
- ;; GitHub authorize
- (str/ends-with? path "/login/oauth/authorize")
- (authorize-redirect exchange query)
+ (try
+ (let [uri (.getRequestURI exchange)
+ path (.getPath uri)
+ query (.getQuery uri)
+ method (.getRequestMethod exchange)]
+ (cond
+ ;; GitHub authorize
+ (str/ends-with? path "/login/oauth/authorize")
+ (authorize-redirect exchange query)
- ;; Reddit authorize
- (str/ends-with? path "/api/v1/authorize")
- (authorize-redirect exchange query)
+ ;; Reddit authorize
+ (str/ends-with? path "/api/v1/authorize")
+ (authorize-redirect exchange query)
- ;; GitHub token
- (and (= method "POST") (str/ends-with? path "/login/oauth/access_token"))
- (let [code (or (:code (read-form exchange)) "mock:1002:newbie")]
- (send-json exchange 200 (str "{\"access_token\":\"" code "\",\"token_type\":\"bearer\"}")))
+ ;; GitHub token
+ (and (= method "POST") (str/ends-with? path "/login/oauth/access_token"))
+ (let [code (or (:code (read-form exchange)) "mock:1002:newbie")]
+ (send-json exchange 200 (str "{\"access_token\":\"" code "\",\"token_type\":\"bearer\"}")))
- ;; Reddit token (client_credentials for import + authorization_code for login)
- (and (= method "POST") (str/ends-with? path "/api/v1/access_token"))
- (let [form (read-form exchange)
- grant (or (:grant form) "")
- code (or (:code form) "mock:t2_test:redditor")]
- (if (= grant "client_credentials")
- (send-json exchange 200 "{\"access_token\":\"app-token\",\"token_type\":\"bearer\",\"expires_in\":3600}")
- (send-json exchange 200 (str "{\"access_token\":\"" code "\",\"token_type\":\"bearer\",\"expires_in\":3600}"))))
+ ;; Reddit token (client_credentials for import + authorization_code for login)
+ (and (= method "POST") (str/ends-with? path "/api/v1/access_token"))
+ (let [form (read-form exchange)
+ grant (or (:grant form) "")
+ code (or (:code form) "mock:t2_test:redditor")]
+ (if (= grant "client_credentials")
+ (send-json exchange 200 "{\"access_token\":\"app-token\",\"token_type\":\"bearer\",\"expires_in\":3600}")
+ (send-json exchange 200 (str "{\"access_token\":\"" code "\",\"token_type\":\"bearer\",\"expires_in\":3600}"))))
- ;; GitHub user
- (= path "/user")
- (let [token (bearer-token exchange)
- user (or (parse-token-user token) {:id "1002" :login "newbie" :numeric? true})]
- (send-json exchange 200
- (str "{\"id\":" (:id user) ",\"login\":\"" (:login user) "\"}")))
+ ;; GitHub user
+ (= path "/user")
+ (let [token (bearer-token exchange)
+ user (or (parse-token-user token) {:id "1002" :login "newbie" :numeric? true})]
+ (send-json exchange 200
+ (str "{\"id\":" (:id user) ",\"login\":\"" (:login user) "\"}")))
- ;; Reddit /api/v1/me
- (str/ends-with? path "/api/v1/me")
- (let [token (bearer-token exchange)
- user (or (parse-token-user token) {:id "t2_test" :login "redditor"})]
- (send-json exchange 200
- (str "{\"id\":\"" (:id user) "\",\"name\":\"" (:login user) "\"}")))
+ ;; Reddit /api/v1/me
+ (str/ends-with? path "/api/v1/me")
+ (let [token (bearer-token exchange)
+ user (or (parse-token-user token) {:id "t2_test" :login "redditor"})]
+ (send-json exchange 200
+ (str "{\"id\":\"" (:id user) "\",\"name\":\"" (:login user) "\"}")))
- :else
- (send-json exchange 404 "{\"error\":\"not found\"}")))))]
+ :else
+ (send-json exchange 404 "{\"error\":\"not found\"}")))
+ (catch Throwable t
+ (binding [*out* *err*]
+ (println "mock-oauth handler error:" t))
+ (try
+ (send-json exchange 500 "{\"error\":\"mock-oauth internal\"}")
+ (catch Throwable _))))))]
(.createContext server "/" handler)
(.setExecutor server nil)
(.start server)
diff --git a/test/support/mock_reddit.clj b/test/support/mock_reddit.clj
index a630cf0938722193e9af88382d60e777ff371be4..faa27945b6394363914c853627a0bad1e819a5f9 100644
--- a/test/support/mock_reddit.clj
+++ b/test/support/mock_reddit.clj
@@ -12,7 +12,7 @@
(defn- query-param [query key]
(when query
(some (fn [pair]
- (let [[k v] (str/split pair "=" 2)]
+ (let [[k v] (str/split pair #"=" 2)]
(when (= k key)
(URLDecoder/decode (or v "") "UTF-8"))))
(str/split query #"&"))))
@@ -34,11 +34,11 @@
(defn- send-redirect [^HttpExchange ex location]
(.set (.getResponseHeaders ex) "Location" location)
- (.sendResponseHeaders ex 302 -1)
+ (.sendResponseHeaders ex 302 0)
(.close (.getResponseBody ex)))
(defn- read-form [^HttpExchange ex]
- (let [body (slurp (.getInputStream ex))]
+ (let [body (slurp (.getRequestBody ex))]
{:code (query-param body "code")
:grant (query-param body "grant_type")}))
@@ -48,7 +48,7 @@
(str/replace #"^[Bb]earer " "")))
(defn- parse-token-user [token]
- (when (str/starts-with? token "mock:")
+ (when (and token (str/starts-with? token "mock:"))
(parse-mock-user (subs token 5))))
(defn start-mock-reddit
@@ -72,7 +72,7 @@
user (parse-mock-user (query-param query "mock_user"))
code (str "mock:" (:id user) ":" (:login user))
loc (str redirect-uri "?code=" (java.net.URLEncoder/encode code "UTF-8")
- "&state=" (java.net.URLEncoder/encode state "UTF-8"))]
+ "&state=" (java.net.URLEncoder/encode (or state "") "UTF-8"))]
(send-redirect exchange loc))
(and (= method "POST") (str/ends-with? path "/api/v1/access_token"))
Hardlinks — judgments / attempts / prompt
judgments
attempts
Prompt text is loaded only by the download route.