constitution · epochs · watch · epoch 3

comparison

c_410d9361a866 (tommy-mor) vs c_effff18688f9 (tommy-mor)

download prompt · raw event · cmp_90173f947f2fdd

council reasoning

~anthropic/claude-sonnet-latest · winner B · 6:4 · permalink

B consolidates three separate POST endpoints into a single /ui dispatch path, removing ~360 lines of duplicated auth/session-resolution logic while preserving behavior (verified by updated integration tests and fixture), a genuine architectural simplification with real test coverage. A adds a legitimate feature (Reddit post rendering with image/link extraction and a new render module) with a unit test, but it's narrower in scope and mostly additive rather than resolving existing duplication/tech debt.

~x-ai/grok-latest · winner A · 2:1 · permalink

A adds lasting product capability: EntityData gains image_url/link_url with real Reddit preview/link parsing, a dedicated render::reddit path for post cards/thumbnails, CSS, and a fixture-backed test. B mainly consolidates already-working web ingest/check/redact onto POST /ui by deleting web_post.rs and rewriting callers/tests—valuable cleanup, but largely relocation of existing behavior rather than new design substance.

openai/gpt-chat-latest · winner A · 4:1 · permalink

Side A adds substantial new end-user functionality: Reddit-specific rendering for entity pages and ranking lists, extends `EntityData` with `image_url` and `link_url`, implements robust extraction of preview/full-image URLs while avoiding unsuitable Redgifs links, and adds a regression test fixture. Side B is primarily an architectural refactor that consolidates web posting flows into `POST /ui` and removes duplicate handlers; while useful for maintainability, it mostly reorganizes existing behavior rather than adding comparable lasting capabilities.

sides

A — c_410d9361a866 (tommy-mor)

message

[78964dd7] nice

diff preview

diff --git a/server/src/fetch/html.rs b/server/src/fetch/html.rs
index 9b6c2d0964640a157bca2a6a64cb0820238d8e4f..3e0309ff1c2ac1b17923922d2340ba6710e0f9d1 100644
--- a/server/src/fetch/html.rs
+++ b/server/src/fetch/html.rs
@@ -11,6 +11,9 @@ use crate::{
 };
 
 fn entity_panel(node: &NodeState) -> Markup {
+    if let Some(markup) = crate::render::reddit::entity_markup(node) {
+        return markup;
+    }
     html! {
         @if let Some(data) = &node.data {
             div id="entity-panel" class="entity-card" {
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index e88cc43ddc9d8100f7994be6f5960ec4d8f22c55..3bf9fc7e92e50beed24e2c25106a77421038c90b 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -153,16 +153,21 @@ pub fn breadcrumb_path(item: &ItemId) -> Markup {
     }
 }
 
-fn rank_list(label: &str, items: &[RankedItem], start_rank: usize) -> Markup {
+fn rank_list(label: &str, items: &[RankedItem], start_rank: usize, tree: &GlobalTree) -> Markup {
     html! {
         @if !items.is_empty() {
             h3 class="rank-heading muted small" { (label) }
             ol class="rank-list" {
                 @for (i, r) in items.iter().enumerate() {
-                    li {
+                    @let href = item_href(&r.item);
+                    li class=(if crate::render::reddit::is_reddit_post(&r.item) { "reddit-post-row" } else { "" }) {
                         span class="rank-num" { (start_rank + i) ". " }
-                        a href=(item_href(&r.item)) {
-                            strong { (display_label(&r.item)) }
+                        @if let Some(row) = crate::render::reddit::child_row_markup(tree, &r.item, &href) {
+                            (row)
+                        } @else {
+                            a href=(href) {
+                                strong { (display_label(&r.item)) }
+                            }
                         }
                         span class="muted" {
                             " — "
@@ -196,9 +201,14 @@ fn unranked_list(label: &str, items: &[ItemId], tree: &GlobalTree) -> Markup {
             h3 class="rank-heading muted small" { (label) }
             ul class="rank-list unranked" {
                 @for it in items {
-                    li {
-                        a href=(item_href(it)) {
-                            strong { (child_label(tree, it)) }
+                    @let href = item_href(it);
+                    li class=(if crate::render::reddit::is_reddit_post(it) { "reddit-post-row" } else { "" }) {
+                        @if let Some(row) = crate::render::reddit::child_row_markup(tree, it, &href) {
+                            (row)
+                        } @else {
+                            a href=(href) {
+                                strong { (child_label(tree, it)) }
+                            }
                         }
                     }
                 }
@@ -253,7 +263,7 @@ pub fn ranking_panel(item: &ItemId, node: &NodeState, tree: &GlobalTree) -> Mark
             } @else {
                 @for (gi, ranked) in ranked_groups.iter().enumerate() {
                     @let label = if multi { format!("Ranking group {}", gi + 1) } else { "Ranking".to_string() };
-                    (rank_list(&label, ranked, 1))
+                    (rank_list(&label, ranked, 1, tree))
                 }
                 (unranked_list("Unranked", &unranked, tree))
             }
diff --git a/server/src/lib.rs b/server/src/lib.rs
index 0677363e0ed21d244bfa065f7ec728549ddd9e50..da5f3ebecec1794b05a2a69cc78379551b2ad769 100644
--- a/server/src/lib.rs
+++ b/server/src/lib.rs
@@ -8,6 +8,7 @@ pub mod parser;
 pub mod path_types;
 pub mod ranking;
 pub mod reddit;
+pub mod render;
 pub mod reducer;
 pub mod journal;
 pub mod state;
diff --git a/server/src/reddit.rs b/server/src/reddit.rs
index 69d979bc7e4a1cb078f70114dc539bdc1986b574..1168ec2afc77c092514eec91b513bac301cbe225 100644
--- a/server/src/reddit.rs
+++ b/server/src/reddit.rs
@@ -608,6 +608,8 @@ fn parse_subreddit_about(v: &Value) -> Option<crate::reducer::EntityData> {
         author: None,
         body_html,
         thumb_url,
+        image_url: None,
+        link_url: None,
     })
 }
 
@@ -635,15 +637,64 @@ fn parse_post_listing(v: &Value) -> Option<crate::reducer::EntityData> {
         .and_then(|t| t.as_str())
         .filter(|s| s.starts_with("http"))
         .map(|s| s.to_string());
+    let image_url = reddit_post_image_url(child);
+    let link_url = reddit_post_link_url(child);
 
     Some(crate::reducer::EntityData {
         title,
         author,
         body_html,
         thumb_url,
+        image_url,
+        link_url,
     })
 }
 
+fn reddit_post_link_url(data: &Value) -> Option<String> {
+    for key in ["url_overridden_by_dest", "url"] {
+        if let Some(u) = data.get(key).and_then(|v| v.as_str()) {
+            if u.starts_with("http") {
+                return Some(u.to_string());
+            }
+        }
+    }
+    None
+}
+
+/// Full-size still for post detail: direct image `url`, else Reddit preview source.
+fn reddit_post_image_url(data: &Value) -> Option<String> {
+    for key in ["url", "url_overridden_by_dest"] {
+        if let Some(u) = data.get(key).and_then(|v| v.as_str()) {
+            if reddit_direct_image_url(u) {
+                return Some(u.to_string());
+            }
+        }
+    }
+    reddit_preview_source_url(data)
+}
+
+fn reddit_preview_source_url(data: &Value) -> Option<String> {
+    data.pointer("/preview/images/0/source/url")
+        .and_then(|v| v.as_str())
+        .filter(|s| s.starts_with("http"))
+        .map(str::to_string)
+}
+
+fn reddit_direct_image_url(url: &str) -> bool {
+    let u = url.to_ascii_lowercase();
+    if u.contains("redgifs.com") {
+        return false;
+    }
+    u.contains("i.redd.it")
+        || u.contains("preview.redd.it")
+        || u.contains("external-preview.redd.it")
+        || u.ends_with(".jpg")
+        || u.ends_with(".jpeg")
+        || u.ends_with(".png")
+        || u.ends_with(".gif")
+        || u.ends_with(".webp")
+}
+
 #[cfg(test)]
 mod tests {
     use super::*;
@@ -672,4 +723,20 @@ mod tests {
         .unwrap();
         assert_eq!(entity.title, "The Rust Programming Language");
     }
+
+    #[test]
+    fn parse_post_listing_extracts_thumb_and_full_preview() {
+        let json = include_str!("../../test/fixtures/reddit/post_preview.json");
+        let v: Value = serde_json::from_str(json).unwrap();
+        let id = ItemId::parse("reddit.com/r/nsfw/comments/1tpy6a1/angel_eyes").unwrap();
+        let entity = entity_view_from_payload(&id, &v).unwrap();
+        assert_eq!(entity.title, "Angel Eyes");
+        assert!(entity.thumb_url.as_ref().unwrap().contains("width=140"));
+        assert!(entity.image_url.as_ref().unwrap().contains("auto=webp"));
+        assert!(!entity.image_url.as_ref().unwrap().contains("redgifs"));
+        assert_eq!(
+            entity.link_url.as_deref(),
+            Some("http://v3.redgifs.com/watch/impossibleprestigioushedgehog")
+        );
+    }
 }
diff --git a/server/src/reducer.rs b/server/src/reducer.rs
index 4e42d0369dab50bb2f8ca664aa69b628292f6c07..336e78b77d3ab59361b89af5c9868e13da4ac962 100644
--- a/server/src/reducer.rs
+++ b/server/src/reducer.rs
@@ -122,7 +122,12 @@ pub struct EntityData {
     pub title: String,
     pub author: Option<String>,
     pub body_html: Option<String>,
+    /// Small preview (subreddit listing / child rows).
     pub thumb_url: Option<String>,
+    /// Full-size still image for the post detail view.
+    pub image_url: Option<String>,
+    /// Outbound link for link/video posts (`url` / `url_overridden_by_dest`).
+    pub link_url: Option<String>,
 }
 
 /// One node in the fractal tree: entity + ranked children.
diff --git a/server/src/render/mod.rs b/server/src/render/mod.rs
new file mode 100644
index 0000000000000000000000000000000000000000..c2c41404abe01c671139658fcccdeced5be388e4
--- /dev/null
+++ b/server/src/render/mod.rs
@@ -0,0 +1,3 @@
+//! Domain-specific HTML fragments for imported entities.
+
+pub mod reddit;
diff --git a/server/src/render/reddit.rs b/server/src/render/reddit.rs
new file mode 100644
index 0000000000000000000000000000000000000000..4a18de93cf57d8395ded3caa373a708f39b3f43f
--- /dev/null
+++ b/server/src/render/reddit.rs
@@ -0,0 +1,64 @@
+//! Reddit post cards: thumbnail in child lists, full image on the post page.
+
+use maud::{html, Markup};
+
+use crate::{
+    path_types::ItemId,
+    reducer::{EntityData, GlobalTree, NodeState},
+};
+
+pub fn is_reddit_post(id: &ItemId) -> bool {
+    id.as_str().starts_with("reddit.com/") && id.as_str().contains("/comments/")
+}
+
+/// Post detail card (`#entity-panel`).
+pub fn entity_markup(node: &NodeState) -> Option<Markup> {
+    if !is_reddit_post(&node.id) {
+        return None;
+    }
+    let data = node.data.as_ref()?;
+    Some(post_entity_card(data))
+}
+
+/// One row in a parent ranking list (thumbnail + title).
+pub fn child_row_markup(tree: &GlobalTree, id: &ItemId, href: &str) -> Option<Markup> {
+    if !is_reddit_post(id) {
+        return None;
+    }
+    let data = tree.get(id)?.data.as_ref()?;
+    Some(html! {
+        @if let Some(thumb) = &data.thumb_url {
+            a class="reddit-post-thumb-link" href=(href) {
+                img class="reddit-post-thumb" src=(thumb) alt="" loading="lazy";
+            }
+        }
+        a href=(href) {
+            strong { (data.title) }
+        }
+    })
+}
+
+fn post_entity_card(data: &EntityData) -> Markup {
+    let image = data.image_url.as_ref().or(data.thumb_url.as_ref());
+    html! {
+        div id="entity-panel" class="entity-card reddit-post" {
+            h2 { (data.title) }
+            @if let Some(author) = &data.author {
+                p class="muted small" { "by " (author) }
+            }
+            @if let Some(url) = &data.link_url {
+                p class="reddit-post-url muted small" {
+                    a href=(url) rel="noopener noreferrer" { (url) }
+                }
+            }
+            @if let Some(src) = image {
+                figure class="reddit-post-figure" {
+                    img class="reddit-post-image" src=(src) alt="" loading="lazy";
+                }
+            }
+            @if let Some(body) = &data.body_html {
+                div class="entity-body" { (maud::PreEscaped(body)) }
+            }
+        }
+    }
+}
diff --git a/server/static/sorter.css b/server/static/sorter.css
index 1f9f5158414902d43a380dd899232c70d8cf5d63..021918f8e778b84e4b3eac8559fab7d223a3d490 100644
--- a/server/static/sorter.css
+++ b/server/static/sorter.css
@@ -171,6 +171,41 @@ code {
   margin-top: 0;
 }
 
+.reddit-post-row {
+  display: flex;
+  align-items: center;
+  gap: 0.6rem;
+}
+
+.reddit-post-thumb-link {
+  flex-shrink: 0;
+  line-height: 0;
+}
+
+.reddit-post-thumb {
+  width: 64px;
+  height: 64px;
+  object-fit: cover;
+  border-radius: 4px;
+  border: 1px solid var(--border);
+}
+
+.reddit-post-url a {
+  word-break: break-all;
+}
+
+.reddit-post-figure {
+  margin: 0.75rem 0;
+}
+
+.reddit-post-image {
+  display: block;
+  max-width: 100%;
+  height: auto;
+  border-radius: 6px;
+  border: 1px solid var(--border);
+}
+
 .scope-name {
   color: var(--accent);
   font-weight: 600;
diff --git a/test/fixtures/reddit/post_preview.json b/test/fixtures/reddit/post_preview.json
new file mode 100644
index 0000000000000000000000000000000000000000..c6ed31ae397dc0f7b6e07e5e010e617df78d9c18
--- /dev/null
+++ b/test/fixtures/reddit/post_preview.json
@@ -0,0 +1,22 @@
+{
+  "kind": "t3",
+  "data": {
+    "title": "Angel Eyes",
+    "permalink": "/r/nsfw/comments/1tpy6a1/angel_eyes/",
+    "author": "alice",
+    "thumbnail": "https://external-preview.redd.it/Kb6Nf5Q4RAucat-2RFcYMeQb2d6vgYNo5EPlf6kGLbs.jpeg?width=140&height=140&auto=webp&s=d7238240ebf191b954ef5f42b0cf61b67aecec88",
+    "url": "http://v3.red

… preview truncated; 410 characters omitted

download full diff A

B — c_effff18688f9 (tommy-mor)

message

[c3cbcaa7] refactor

diff preview

diff --git a/server/src/api/auth.rs b/server/src/api/auth.rs
index b3631b06153d52f88348fef927e7a024b7b85ad6..cd556eb89e9dd8203eba6c8969ffd144db5d329d 100644
--- a/server/src/api/auth.rs
+++ b/server/src/api/auth.rs
@@ -71,6 +71,24 @@ pub fn optional_principal(headers: &HeaderMap, jar: &CookieJar, reduced: &Reduce
     verify_token(reduced, c.value()).ok()
 }
 
+/// Browser session: principal + bearer token string (same shape as CLI session cookie).
+#[derive(Debug, Clone)]
+pub struct WebSession {
+    pub username: String,
+    pub bearer: String,
+}
+
+/// Resolve username and bearer together for `POST /ui` dispatch (one read of headers + jar).
+pub fn resolve_web_session(headers: &HeaderMap, jar: &CookieJar, reduced: &ReducerState) -> Option<WebSession> {
+    let username = optional_principal(headers, jar, reduced)?;
+    let bearer = headers
+        .get(header::AUTHORIZATION)
+        .and_then(|v| v.to_str().ok())
+        .and_then(|s| s.strip_prefix("Bearer ").map(|t| t.trim().to_string()))
+        .or_else(|| jar.get(SLUG_SESSION_COOKIE).map(|c| c.value().to_string()))?;
+    Some(WebSession { username, bearer })
+}
+
 fn redirect_with_session_cookie(public_url: &str, path_and_query: &str, bearer: &str, jar: &CookieJar) -> Response {
     let mut res = Response::builder()
         .status(StatusCode::TEMPORARY_REDIRECT)
diff --git a/server/src/api/mod.rs b/server/src/api/mod.rs
index a986f706ea4b261cbaf004c02b4cf84184b41371..4e223a7460997c464706dca850281447bd754ed5 100644
--- a/server/src/api/mod.rs
+++ b/server/src/api/mod.rs
@@ -4,7 +4,6 @@ mod rpc;
 mod stream;
 mod validate;
 mod ui_html;
-mod web_post;
 
 pub use auth::{
     get_join_invite,
@@ -19,7 +18,9 @@ pub use auth::{
     get_web_login,
     get_logout,
     optional_principal,
+    resolve_web_session,
     session_cookie_header_value,
+    WebSession,
     SLUG_SESSION_COOKIE,
 };
 
@@ -35,7 +36,6 @@ pub use stream::{get_html_stream, get_stream};
 pub use validate::{normalize_room_and_thread, validate_ingest_document, ValidatedIngest};
 
 pub use ui_html::post_ui_html;
-pub use web_post::{check_web_ingest, post_web_ingest, post_web_redact};
 
 #[cfg(test)]
 mod tests {
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index 2b40a72059981d558768f73d189b991f3448c257..497f8fdd222a8ec7c3d76b0695e0352e973ca3ba 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -1,25 +1,29 @@
-//! Single `POST /ui` entry for browser [`crate::html::ui_action::HtmlUiAction`] (JSON in `__rpc__` + holes).
+//! Single `POST /ui` entry: parse `__rpc__` → [`HtmlUiAction`], resolve [`WebSession`] once, dispatch.
 
 use axum::{
-    body::Body,
+    body,
     extract::State,
-    http::{header, HeaderMap, StatusCode},
+    http::{header, HeaderMap, HeaderValue, StatusCode},
     response::{IntoResponse, Response},
     Form,
 };
 use axum_extra::extract::cookie::CookieJar;
+use slug_types::{RpcBatch, RpcBatchResponse, RpcCommand, RpcResult};
 use std::collections::HashMap;
 
 use crate::{
     api::{
-        auth::optional_principal,
-        web_post::{run_check_web_ingest, run_post_web_ingest, run_post_web_redact, WebPostForm, WebRedactForm},
+        auth::{resolve_web_session, WebSession},
+        handle_rpc_batch,
+        rpc::{rpc_post_redact, rpc_post_with_bearer},
     },
+    canonical_path::canonicalize_tag,
     html::{
         fragment_public_new_thread_form, fragment_room_new_thread_form, login_to_post_hint_markup,
-        parse_html_ui_from_form, user_can_post_room, user_can_view_room, HtmlUiAction, JsBuilder,
-        ThreadNav,
+        parse_html_ui_from_form, thread_feed_html, thread_feed_html_for_room, thread_feed_region_markup,
+        user_can_post_room, user_can_view_room, HtmlUiAction, JsBuilder, ThreadNav,
     },
+    reducer::{scope_from_room_wire, ScopeId},
     state::AppState,
 };
 
@@ -34,6 +38,19 @@ pub async fn post_ui_html(
         Err(e) => return ui_js_warn(&e.to_string()).into_response(),
     };
 
+    let reduced = state.reduced.read().await;
+    let session = resolve_web_session(&headers, &jar, &reduced);
+    drop(reduced);
+
+    dispatch_ui_action(&state, session.as_ref(), action).await
+}
+
+/// All UI command logic: HTTP extractors stop above; this only sees [`AppState`], session, and [`HtmlUiAction`].
+async fn dispatch_ui_action(
+    state: &AppState,
+    session: Option<&WebSession>,
+    action: HtmlUiAction,
+) -> Response {
     match action {
         HtmlUiAction::PostIngest {
             room,
@@ -42,47 +59,87 @@ pub async fn post_ui_html(
             error_target,
             form_id,
         } => {
-            run_post_web_ingest(
-                &state,
-                &headers,
-                &jar,
-                WebPostForm {
-                    room,
-                    thread_tag,
-                    text,
-                    error_target,
-                    form_id,
-                },
-            )
-            .await
+            let Some(session) = session else {
+                return js_redirect("/login").into_response();
+            };
+            let room = room.trim().to_string();
+            let thread_tag = thread_tag.trim().to_string();
+            if text.trim().is_empty() {
+                return form_js_error(
+                    error_target.as_ref(),
+                    "empty post",
+                    "Write something in the text area (DSL / prose).",
+                )
+                .into_response();
+            }
+            match rpc_post_with_bearer(state, &session.bearer, room.clone(), thread_tag.clone(), text).await {
+                Ok(RpcResult::PostOk { .. }) => {
+                    post_success_response(
+                        state,
+                        &room,
+                        &thread_tag,
+                        error_target.as_ref(),
+                        form_id.as_ref(),
+                        Some(session.username.as_str()),
+                    )
+                    .await
+                    .into_response()
+                }
+                Ok(_) => form_js_error(
+                    error_target.as_ref(),
+                    "unexpected response",
+                    "Post did not return PostOk.",
+                )
+                .into_response(),
+                Err((msg, hint)) => form_js_error(error_target.as_ref(), &msg, hint.as_deref().unwrap_or("")).into_response(),
+            }
         }
         HtmlUiAction::CheckIngest {
             room,
             thread_tag,
             text,
             error_target,
-            form_id,
+            form_id: _,
         } => {
-            run_check_web_ingest(
-                &state,
-                &headers,
-                &jar,
-                WebPostForm {
-                    room,
-                    thread_tag,
-                    text,
-                    error_target,
-                    form_id,
-                },
-            )
-            .await
+            let Some(session) = session else {
+                return js_redirect("/login").into_response();
+            };
+            let room = room.trim().to_string();
+            let thread_tag = canonicalize_tag(&thread_tag);
+            if thread_tag.is_empty() {
+                return form_js_error(
+                    error_target.as_ref(),
+                    "missing thread tag",
+                    "Set a thread tag before posting.",
+                )
+                .into_response();
+            }
+            if text.trim().is_empty() {
+                return js_clear_errors(&form_error_target(error_target.as_ref())).into_response();
+            }
+            match rpc_check_with_bearer(state, &session.bearer, room, text.clone()).await {
+                Ok(RpcResult::CheckOk { .. }) => js_clear_errors(&form_error_target(error_target.as_ref())).into_response(),
+                Ok(_) => form_js_error(error_target.as_ref(), "unexpected response", "Check did not return CheckOk.").into_response(),
+                Err((msg, hint)) => form_js_error(error_target.as_ref(), &msg, hint.as_deref().unwrap_or("")).into_response(),
+            }
         }
         HtmlUiAction::RedactPost { post_id } => {
-            run_post_web_redact(&state, &headers, &jar, WebRedactForm { post_id }).await
+            let Some(session) = session else {
+                return js_redirect("/login").into_response();
+            };
+            let h = headers_from_bearer(&session.bearer);
+            match rpc_post_redact(state, &h, post_id).await {
+                Ok(RpcResult::RedactPostOk {}) => redact_success_response(state).await.into_response(),
+                Ok(_) => (StatusCode::BAD_REQUEST, "unexpected response").into_response(),
+                Err((msg, hint)) => {
+                    let detail = hint.as_deref().unwrap_or("");
+                    js_error("#errors", &msg, detail).into_response()
+                }
+            }
         }
         HtmlUiAction::ExpandPublicNewThreadForm => {
             let reduced = state.reduced.read().await;
-            let user = optional_principal(&headers, &jar, &reduced);
+            let user = session.map(|s| s.username.as_str());
             drop(reduced);
             let markup = if user.is_some() {
                 fragment_public_new_thread_form(true)
@@ -99,18 +156,18 @@ pub async fn post_ui_html(
                 return ui_js_warn("missing room").into_response();
             }
             let reduced = state.reduced.read().await;
-            let user = optional_principal(&headers, &jar, &reduced);
+            let user = session.map(|s| s.username.as_str());
             if !reduced.rooms.contains(&room_wire) {
                 drop(reduced);
                 return ui_js_warn("room not found").into_response();
             }
-            if !user_can_view_room(&reduced, &room_wire, user.as_deref()) {
+            if !user_can_view_room(&reduced, &room_wire, user) {
                 drop(reduced);
                 return ui_js_warn("forbidden").into_response();
             }
-            let can_post = user
+            let can_post = session
                 .as_ref()
-                .map(|u| user_can_post_room(&reduced, &room_wire, u))
+                .map(|s| user_can_post_room(&reduced, &room_wire, &s.username))
                 .unwrap_or(false);
             drop(reduced);
             let Some(nav) = ThreadNav::from_room_id(&room_wire) else {
@@ -128,12 +185,195 @@ pub async fn post_ui_html(
     }
 }
 
+fn headers_from_bearer(bearer: &str) -> HeaderMap {
+    let mut headers = HeaderMap::new();
+    if let Ok(hv) = HeaderValue::from_str(&format!("Bearer {bearer}")) {
+        headers.insert(header::AUTHORIZATION, hv);
+    }
+    headers
+}
+
+fn post_redirect_location(room: &str, thread_tag: &str) -> String {
+    let tag = canonicalize_tag(thread_tag);
+    if room.trim() == "public" {
+        format!("/t/{tag}")
+    } else {
+        let room = room.trim();
+        let Some((a, b)) = room.split_once('/') else {
+            return "/".to_string();
+        };
+        format!("/r/{a}/{b}/t/{tag}")
+    }
+}
+
+fn js_quote(s: &str) -> String {
+    serde_json::to_string(s).expect("js string escaping must succeed")
+}
+
+fn js_redirect(to: &str) -> Response {
+    let js = format!("window.location = {};", js_quote(to));
+    Response::builder()
+        .status(StatusCode::OK)
+        .header(header::CONTENT_TYPE, "text/javascript; charset=utf-8")
+        .body(axum::body::Body::from(js))
+        .unwrap()
+}
+
+fn js_error(error_target: &str, title: &str, detail: &str) -> Response {
+    let markup = maud::html! {
+        div id=(error_target.trim_start_matches('#')) {
+            p class="auth-error" { (title) }
+            @if !detail.is_empty() {
+                pre class="muted" { (detail) }
+            }
+        }
+    };
+    JsBuilder::new()
+        .morph_selector(error_targe

… preview truncated; 33,445 characters omitted

download full diff B

Hardlinks — judgments / attempts / prompt

prompt download

judgments

attempts

Prompt text is loaded only by the download route.