constitution · epochs · watch · epoch 3

comparison

c_64faa3bee86f (tommy-mor) vs c_4ed2e2cca39b (tommy-mor)

download prompt · raw event · cmp_9705a449bc910b

council reasoning

~anthropic/claude-sonnet-latest · winner B · 3:2 · permalink

Side B fixes a real bug (undefined variable causing a NameError in a live OAuth callback path) with a minimal, correct patch. Side A is a larger UI/UX refactor (inline form morphing instead of redirect) that adds functionality but is more speculative/stylistic and carries more risk of regressions across auth flows; it's valuable but less clearly a durable correctness fix than B's crash fix.

~x-ai/grok-latest · winner A · 3:1 · permalink

A redesigns auth to return HTML fragments and extend the shared poem form interceptor for inline success/error morphing, while collapsing a separate auth_layout back into the main layout—lasting UX and architecture. B only adds a missing GITHUB_API_BASE_URL default (three lines), a real but narrowly scoped NameError fix with far less surface impact.

openai/gpt-chat-latest · winner A · 4:1 · permalink

Side A implements a lasting UX and architecture improvement for authentication by replacing redirect-based flows with HTML fragments, adding reusable rendering helpers, updating the shared form interception logic to morph non-empty responses, and integrating the auth pages back into the common layout. Side B is a valuable but narrowly scoped bug fix that defines a missing GITHUB_API_BASE_URL configuration with a sensible default to prevent a NameError in the OAuth callback.

sides

A — c_64faa3bee86f (tommy-mor)

message

[6b6eb0c3] Auth form: poem JS morphs form innerHTML on response; no redirect

- post_choose_username returns HTML fragments instead of redirects:
  success → auth_signed_in_fragment ("you're signed in — return to your agent")
  error   → choose_username_error_fragment (form re-rendered with error inline)
- Poem JS now reads response body; if non-empty, morphs form innerHTML with it
  (existing ingest forms return empty body, so they're unaffected)
- auth.rs: keep full layout() with poem JS — revert to single layout
- auth-success CSS class added to both themes

Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>

diff preview

diff --git a/server/src/api/auth.rs b/server/src/api/auth.rs
index c1194f79fd89fb47fe6b425b494a0ffa667abb2d..cb0faa29b834931e2c2b2f5c174c875e2e2e9346 100644
--- a/server/src/api/auth.rs
+++ b/server/src/api/auth.rs
@@ -16,7 +16,7 @@ use crate::{
         canonicalize_username, validate_agent_format, validate_username,
         Event, TokenIssued, UserRegistered,
     },
-    html::{auth_complete_page, choose_username_page},
+    html::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page},
     state::{AppState, PendingSession},
 };
 
@@ -274,8 +274,6 @@ pub async fn post_choose_username(
         return api_error(StatusCode::BAD_REQUEST, "invalid agent format", Some(msg)).into_response();
     }
 
-    let public_url = std::env::var("SLUG_PUBLIC_URL").unwrap_or_else(|_| "http://127.0.0.1:8080".to_string());
-
     let reduced_arc = state.reduced.clone();
     let reduced = reduced_arc.read().await;
     let provider_key = (provider.to_lowercase(), provider_id.clone());
@@ -284,11 +282,7 @@ pub async fn post_choose_username(
     }
     if reduced.users_by_provider.values().any(|u| u == &canonicalize_username(&form.username)) {
         drop(reduced);
-        return Redirect::to(&format!(
-            "{public_url}/auth/choose-username?session={}&error={}",
-            urlencoding::encode(&form.session),
-            urlencoding::encode("that username is taken — try another"),
-        )).into_response();
+        return choose_username_error_fragment(&form.session, "that username is taken — try another").into_response();
     }
     drop(reduced);
 
@@ -324,7 +318,7 @@ pub async fn post_choose_username(
         s.complete = Some((canon_user.clone(), bearer.clone()));
     }
 
-    Redirect::to(&format!("{public_url}/auth/complete")).into_response()
+    auth_signed_in_fragment().into_response()
 }
 
 pub async fn post_pending_session(
diff --git a/server/src/html/auth.rs b/server/src/html/auth.rs
index 40b1ef30a6c1d4063aa2d8e9c93df8972df4b27c..0a14bdbfb66c65d1bd09993ffd4a7bb6f2fe041e 100644
--- a/server/src/html/auth.rs
+++ b/server/src/html/auth.rs
@@ -1,20 +1,25 @@
-use maud::{html, Markup, DOCTYPE};
+use maud::{html, Markup};
 
-/// Minimal layout for auth pages — no JS interceptor, real form navigation works.
-fn auth_layout(title: &str, body: Markup) -> Markup {
+fn form_inner(session: &str, error: Option<&str>) -> Markup {
     html! {
-        (DOCTYPE)
-        html {
-            head {
-                meta charset="utf-8";
-                meta name="viewport" content="width=device-width, initial-scale=1";
-                title { (title) }
-                link rel="stylesheet" href="/static/theme_default.css";
-            }
-            body class="view-auth" {
-                (body)
-            }
+        input type="hidden" name="session" value=(session);
+        label for="username" { "username" }
+        input
+            type="text"
+            id="username"
+            name="username"
+            placeholder="e.g. alice"
+            pattern="[a-z0-9_\\-]{1,32}"
+            maxlength="32"
+            autocomplete="off"
+            autofocus;
+        p.auth-hint {
+            "lowercase · alphanumeric · hyphens · underscores · max 32"
         }
+        @if let Some(msg) = error {
+            p.auth-error { (msg) }
+        }
+        button type="submit" { "continue" }
     }
 }
 
@@ -28,27 +33,23 @@ pub fn choose_username_page(session: &str, error: Option<&str>) -> Markup {
         h1 { "choose a username" }
         p { "pick a handle for slug.social." }
         form.auth-form method="POST" action="/auth/choose-username" {
-            input type="hidden" name="session" value=(session);
-            label for="username" { "username" }
-            input
-                type="text"
-                id="username"
-                name="username"
-                placeholder="e.g. alice"
-                pattern="[a-z0-9_\\-]{1,32}"
-                maxlength="32"
-                autocomplete="off"
-                autofocus;
-            p.auth-hint {
-                "lowercase · alphanumeric · hyphens · underscores · max 32"
-            }
-            @if let Some(msg) = error {
-                p.auth-error { (msg) }
-            }
-            button type="submit" { "continue" }
+            (form_inner(session, error))
         }
     };
-    auth_layout("join — slug.social", body)
+    super::layout("join — slug.social", "view-auth", body, None)
+}
+
+/// Fragment returned to the poem JS on error — replaces the form's innerHTML.
+pub fn choose_username_error_fragment(session: &str, error: &str) -> Markup {
+    form_inner(session, Some(error))
+}
+
+/// Fragment returned to the poem JS on success — replaces the form's innerHTML.
+pub fn auth_signed_in_fragment() -> Markup {
+    html! {
+        p.auth-success { "you're signed in — return to your agent." }
+        p.auth-hint { "you can close this tab." }
+    }
 }
 
 pub fn auth_complete_page() -> Markup {
@@ -62,5 +63,5 @@ pub fn auth_complete_page() -> Markup {
         p { "Return to your terminal — your agent is polling and will collect your token automatically." }
         p.auth-hint { "You can close this tab." }
     };
-    auth_layout("signed in — slug.social", body)
+    super::layout("signed in — slug.social", "view-auth", body, None)
 }
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index 2f16d701962d703db0c859bb586dfc08ec385690..8b48a25cce79f0eefc7e29849e1a667cae4c7986 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -15,7 +15,7 @@ mod search;
 mod tree;
 use breadcrumb_path::OntologyPath;
 
-pub use auth::{auth_complete_page, choose_username_page};
+pub use auth::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page};
 pub use editor::{editor_check, editor_page};
 pub use forum::{index, thread_feed_html, thread_post_expand, thread_post_view, thread_view};
 pub use garden::{garden_index, ontology_path};
@@ -114,6 +114,8 @@ script { (maud::PreEscaped(r#"
                         });
 
                         // Poem: intercept POST forms, send via fetch, await SSE for DOM update.
+                        // If the response body is non-empty HTML, morph the form's innerHTML with it
+                        // (used for inline feedback without a page reload, e.g. auth forms).
                         document.addEventListener('submit', async (e) => {
                             const f = e.target;
                             if (!f || f.tagName !== 'FORM') return;
@@ -121,14 +123,19 @@ script { (maud::PreEscaped(r#"
                             e.preventDefault();
                             const btn = f.querySelector('button[type="submit"], input[type="submit"]');
                             if (btn) { btn.disabled = true; btn.textContent = '…'; }
-                            await fetch(f.action, {
+                            const resp = await fetch(f.action, {
                                 method: 'POST',
                                 body: new URLSearchParams(new FormData(f)),
                                 headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
                                 credentials: 'same-origin',
                             });
-                            if (btn) { btn.disabled = false; btn.textContent = 'submit'; }
-                            f.reset();
+                            const html = await resp.text();
+                            if (html && html.trim()) {
+                                Idiomorph.morph(f, html, {morphStyle: 'innerHTML'});
+                            } else {
+                                if (btn) { btn.disabled = false; btn.textContent = 'submit'; }
+                                f.reset();
+                            }
                         });
 
                         // Search: debounced fetch + idiomorph.
diff --git a/server/static/theme_default.css b/server/static/theme_default.css
index 9e71574da4bed3a0116c347610636780678bd1af..a1d8d1765a7812191edc579125facf1694554c2c 100644
--- a/server/static/theme_default.css
+++ b/server/static/theme_default.css
@@ -250,6 +250,11 @@ p.auth-error {
   font-size: 12px;
   margin: 4px 0 0;
 }
+p.auth-success {
+  color: var(--signal);
+  font-size: 13px;
+  margin: 4px 0 0;
+}
 
 /* ----------------------------------------------------------------
    BUTTONS — raised, press on :active
diff --git a/server/static/theme_retro.css b/server/static/theme_retro.css
index dc9fa4654f529eb1843557fb580cf3982da46901..8ed8fd88efab32b36bd66cf200aa182219b0a8b5 100644
--- a/server/static/theme_retro.css
+++ b/server/static/theme_retro.css
@@ -32,6 +32,7 @@ input[type="text"] {
 input[type="text"]:focus { border-color: #00ff41; }
 p.auth-hint { color: #555; font-family: monospace; font-size: 0.75rem; margin: 0; }
 p.auth-error { color: #ff4444; font-family: monospace; font-size: 0.8rem; margin: 0; }
+p.auth-success { color: #00ff41; font-family: monospace; font-size: 0.8rem; margin: 0; }
 
 /* Ingest form (poem pattern) */
 .ingest-form-wrap { margin-top: 1.5rem; }

download full diff A

B — c_4ed2e2cca39b (tommy-mor)

message

[0d3270d1] Fix GitHub OAuth callback NameError on missing API base URL.

Co-authored-by: Cursor <cursoragent@cursor.com>

diff preview

diff --git a/constitution.py b/constitution.py
index f819007252f435680b8356fb4da83469b21e33af..4dd5b9dfbba231d46289c490f91b1dd5b1018bcf 100644
--- a/constitution.py
+++ b/constitution.py
@@ -119,6 +119,9 @@ JSONL_PATH = pathlib.Path(os.environ.get("JSONL_PATH", "/data/ledger.jsonl"))
 
 GITHUB_CLIENT_ID = os.environ.get("GITHUB_CLIENT_ID", "")
 GITHUB_CLIENT_SECRET = os.environ.get("GITHUB_CLIENT_SECRET", "")
+GITHUB_API_BASE_URL = os.environ.get(
+    "GITHUB_API_BASE_URL", "https://api.github.com"
+).rstrip("/")
 
 OPENROUTER_API_KEY = os.environ.get("OPENROUTER_API_KEY", "")
 OPENROUTER_BASE_URL = os.environ.get("OPENROUTER_BASE_URL", "https://openrouter.ai").rstrip("/")

download full diff B

Hardlinks — judgments / attempts / prompt

prompt download

judgments

attempts

Prompt text is loaded only by the download route.