constitution · epochs · watch · epoch 3

comparison

c_14dd365ffe22 (tommy-mor) vs c_effff18688f9 (tommy-mor)

download prompt · raw event · cmp_a27c50f9e538aa

council reasoning

~anthropic/claude-sonnet-latest · winner B · 6:4 · permalink

Side B consolidates three parallel legacy POST endpoints (/post, /post/check, /post/redact) into the single /ui RPC dispatch path, removing duplicated auth/session logic (web_post.rs deleted entirely) and updating tests/fixtures accordingly—this is a substantive architectural simplification with real behavioral consolidation. Side A mainly swaps a cookie-based theme system for a /~/ URL-based browse route and deletes CSS themes, which is a reasonable but narrower and more cosmetic refactor (URL scheme change plus theme removal) with less overall reduction in duplicated logic.

~x-ai/grok-latest · winner A · 3:2 · permalink

Commit A lands a lasting navigation design: ItemId browse_href/from_browse_uri (with https:/ normalization and tests), a /~/ route, and call-site cleanup—plus real simplification by dropping the theme cookie/CSS stack. Commit B is valuable consolidation (fold web_post into POST /ui, WebSession, form __rpc__ migration) but mostly relocates existing ingest/check/redact behavior rather than adding comparable core design.

openai/gpt-chat-latest · winner A · 3:2 · permalink

Side A introduces a new canonical browse URL scheme (`/~/...`) with `ItemId::browse_href`, parsing helpers, routing, and integration tests, replacing ad hoc query-string links and centralizing URL generation. Although it also removes theme support, the core change establishes a cleaner navigation design reused across the UI. Side B mainly refactors existing web post/check/redact flows into the `/ui` dispatcher and consolidates session handling, improving structure but with less new end-user capability.

sides

A — c_14dd365ffe22 (tommy-mor)

message

[8d5328d3] -theme

diff preview

diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index 82b2aa51d21ada1d0d849d3ddfc3a81e4241d861..e74e42e0f0ffc4224f5ef5421b486a5f35434999 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -73,11 +73,7 @@ pub async fn post_ui_html(
                     ensure_partial_tree(&mut tree, &item);
                 }
                 let _ = state.ensure_node(&item).await;
-                let dest = if item.is_root() {
-                    "/".to_string()
-                } else {
-                    format!("/?item={}", item.as_str())
-                };
+                let dest = item.browse_href();
                 JsBuilder::new()
                     .raw(&format!(
                         "window.location.href={};",
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index c973cb718ac74b95570dabea76e24459417790b9..a8353c6de0cd6d268219e552b7ca1ba4e3000585 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -1,13 +1,10 @@
 use axum::{
     body::Body,
     extract::{Path, State},
-    http::{header, HeaderValue, StatusCode, Uri},
+    http::{header, StatusCode, Uri},
     response::{IntoResponse, Response},
-    Form,
 };
-use axum_extra::extract::cookie::CookieJar;
 use maud::{html, Markup, DOCTYPE};
-use serde::Deserialize;
 
 use crate::{
     form_template::template_json_compact,
@@ -15,96 +12,25 @@ use crate::{
     path_types::ItemId,
     ranking::{top_bottom, RankedItem},
     reducer::{GroupState, NodeState},
-    state::{parse_item_param, AppState},
+    state::AppState,
     ui_action::UI_RPC_FIELD,
 };
 
-const THEME_DEFAULT_CSS: &str = include_str!("../../static/theme_default.css");
-const THEME_RETRO_CSS: &str = include_str!("../../static/theme_retro.css");
+const SORTER_CSS: &str = include_str!("../../static/sorter.css");
 const SORTER_UI_JS: &str = include_str!("../../static/sorter_ui.js");
 
-pub const SORTER_THEME_COOKIE: &str = "sorter-theme";
-
-pub fn normalize_theme(raw: &str) -> &'static str {
-    match raw {
-        "retro" => "retro",
-        _ => "default",
-    }
-}
-
-pub fn theme_from_jar(jar: &CookieJar) -> &'static str {
-    jar.get(SORTER_THEME_COOKIE)
-        .map(|c| normalize_theme(c.value()))
-        .unwrap_or("default")
-}
-
-pub fn theme_next_from_uri(uri: &Uri) -> String {
-    uri.path_and_query()
-        .map(|pq| pq.as_str().to_string())
-        .filter(|s| !s.is_empty())
-        .unwrap_or_else(|| "/".to_string())
-}
-
-pub fn theme_cookie_header_value(theme: &str) -> HeaderValue {
-    let t = normalize_theme(theme);
-    let s = format!("{SORTER_THEME_COOKIE}={t}; Path=/; SameSite=Lax; Max-Age=31536000");
-    HeaderValue::from_str(&s).expect("theme cookie must be ASCII")
-}
-
-fn sanitize_theme_next(next: Option<&str>) -> String {
-    let s = next.unwrap_or("/").trim();
-    if s.starts_with('/') && !s.starts_with("//") && s.len() < 8192 {
-        s.to_string()
-    } else {
-        "/".to_string()
-    }
-}
-
-#[derive(Debug, Deserialize)]
-pub struct ThemeForm {
-    theme: String,
-    next: Option<String>,
-}
-
-pub async fn post_theme(Form(form): Form<ThemeForm>) -> impl IntoResponse {
-    let theme = normalize_theme(&form.theme);
-    let next = sanitize_theme_next(form.next.as_deref());
-    let loc =
-        HeaderValue::try_from(next.as_str()).unwrap_or_else(|_| HeaderValue::from_static("/"));
-    Response::builder()
-        .status(StatusCode::SEE_OTHER)
-        .header(header::LOCATION, loc)
-        .header(header::SET_COOKIE, theme_cookie_header_value(theme))
-        .body(Body::empty())
-        .expect("theme redirect response")
-}
-
 pub async fn serve_static(Path(filename): Path<String>) -> impl IntoResponse {
-    if filename == "sorter_ui.js" {
-        return Response::builder()
-            .status(StatusCode::OK)
-            .header(header::CONTENT_TYPE, "text/javascript; charset=utf-8")
-            .header(header::CACHE_CONTROL, "public, max-age=3600")
-            .body(SORTER_UI_JS.to_string())
-            .unwrap()
-            .into_response();
-    }
-
-    let theme = filename
-        .strip_prefix("theme_")
-        .and_then(|s| s.strip_suffix(".css"));
-
-    let css = match theme {
-        Some("default") => THEME_DEFAULT_CSS,
-        Some("retro") => THEME_RETRO_CSS,
+    let (content_type, body) = match filename.as_str() {
+        "sorter.css" => ("text/css; charset=utf-8", SORTER_CSS),
+        "sorter_ui.js" => ("text/javascript; charset=utf-8", SORTER_UI_JS),
         _ => return (StatusCode::NOT_FOUND, "static file not found").into_response(),
     };
 
     Response::builder()
         .status(StatusCode::OK)
-        .header(header::CONTENT_TYPE, "text/css; charset=utf-8")
+        .header(header::CONTENT_TYPE, content_type)
         .header(header::CACHE_CONTROL, "public, max-age=3600")
-        .body(css.to_string())
+        .body(body.to_string())
         .unwrap()
         .into_response()
 }
@@ -162,8 +88,7 @@ fn asset_version() -> &'static str {
     V.get_or_init(|| {
         use std::hash::{Hash, Hasher};
         let mut h = std::collections::hash_map::DefaultHasher::new();
-        THEME_DEFAULT_CSS.hash(&mut h);
-        THEME_RETRO_CSS.hash(&mut h);
+        SORTER_CSS.hash(&mut h);
         SORTER_UI_JS.hash(&mut h);
         format!("{:x}", h.finish())
     })
@@ -176,9 +101,9 @@ pub fn now_ms() -> i64 {
     t.as_millis() as i64
 }
 
-fn layout(title: &str, body: Markup, views: u64, theme: &str, theme_next: &str) -> Markup {
+fn layout(title: &str, body: Markup, views: u64) -> Markup {
     let ver = asset_version();
-    let css_href = format!("/static/theme_{theme}.css?v={ver}");
+    let css_href = format!("/static/sorter.css?v={ver}");
     let js_src = format!("/static/sorter_ui.js?v={ver}");
     html! {
         (DOCTYPE)
@@ -187,7 +112,7 @@ fn layout(title: &str, body: Markup, views: u64, theme: &str, theme_next: &str)
                 meta charset="utf-8";
                 meta name="viewport" content="width=device-width, initial-scale=1";
                 title { (title) }
-                link rel="stylesheet" href=(css_href) id="theme-stylesheet";
+                link rel="stylesheet" href=(css_href);
                 script src="https://unpkg.com/idiomorph@0.3.0/dist/idiomorph.min.js" {}
             }
             body class="home" {
@@ -196,21 +121,6 @@ fn layout(title: &str, body: Markup, views: u64, theme: &str, theme_next: &str)
                 }
                 div id="errors" {}
                 (body)
-                div id="controls" {
-                    a href="https://github.com/sortersocial/sorter2" id="src-link" { "src" }
-                    form id="sorter-theme-form" method="post" action="/theme" data-navigate="full" {
-                        input type="hidden" name="next" value=(theme_next);
-                        select id="theme-select" name="theme" onchange="this.form.submit()" aria-label="Theme" {
-                            @for (val, label) in [("default", "default"), ("retro", "retro")] {
-                                @if theme == val {
-                                    option value=(val) selected { (label) }
-                                } @else {
-                                    option value=(val) { (label) }
-                                }
-                            }
-                        }
-                    }
-                }
                 script src=(js_src) {}
             }
         }
@@ -218,11 +128,7 @@ fn layout(title: &str, body: Markup, views: u64, theme: &str, theme_next: &str)
 }
 
 fn item_href(id: &ItemId) -> String {
-    if id.is_root() {
-        "/".to_string()
-    } else {
-        format!("/?item={}", id.as_str())
-    }
+    id.browse_href()
 }
 
 fn segment_label(seg: &str) -> &str {
@@ -361,39 +267,10 @@ pub fn vote_panel(parent: &ItemId) -> Markup {
 }
 
 
-fn query_param(uri: &Uri, key: &str) -> Option<String> {
-    let q = uri.query()?;
-    q.split('&').find_map(|pair| {
-        let mut it = pair.splitn(2, '=');
-        if it.next()? == key {
-            Some(it.next().unwrap_or("").to_string())
-        } else {
-            None
-        }
-    })
-}
-
-pub async fn home(
-    State(state): State<AppState>,
-    jar: CookieJar,
-    uri: Uri,
-) -> impl IntoResponse {
+async fn item_page(state: AppState, uri: Uri, item: ItemId) -> Markup {
     let path = uri.path().to_string();
     state.views.increment(path.clone());
     let views = state.views.get_views(&path);
-    let theme = theme_from_jar(&jar);
-    let theme_next = theme_next_from_uri(&uri);
-
-    let item_raw = query_param(&uri, "item")
-        .or_else(|| query_param(&uri, "sub").map(|sub| {
-            if sub.is_empty() {
-                String::new()
-            } else {
-                format!("reddit.com/r/{sub}")
-            }
-        }))
-        .unwrap_or_default();
-    let item = parse_item_param(&item_raw);
 
     let tree = state.tree.read().await;
     let empty_node = NodeState::default();
@@ -408,5 +285,14 @@ pub async fn home(
         (vote_panel(&item))
         (ranking_panel(&item, group))
     };
-    layout("sorter2", body, views, theme, &theme_next)
+    layout("sorter2", body, views)
+}
+
+pub async fn home(State(state): State<AppState>, uri: Uri) -> impl IntoResponse {
+    item_page(state, uri, ItemId::root()).await
+}
+
+pub async fn browse(State(state): State<AppState>, uri: Uri) -> impl IntoResponse {
+    let item = ItemId::from_browse_uri(uri.path()).unwrap_or(ItemId::root());
+    item_page(state, uri, item).await
 }
diff --git a/server/src/lib.rs b/server/src/lib.rs
index 14e7cfbc38feb5d07aff859b64bce6e2ec45cf91..cd56743192919cf4dcea539b3d8873a21fb7e72b 100644
--- a/server/src/lib.rs
+++ b/server/src/lib.rs
@@ -30,9 +30,9 @@ pub fn create_app(state: AppState) -> Router {
     Router::new()
         .route("/healthz", get(|| async { "ok" }))
         .route("/static/:filename", get(crate::html::serve_static))
+        .route("/~/*item_path", get(crate::html::browse))
         .route("/", get(crate::html::home))
         .route("/ui", post(crate::api::ui_html::post_ui_html))
-        .route("/theme", post(crate::html::post_theme))
         .with_state(state)
         .layer(TraceLayer::new_for_http())
 }
diff --git a/server/src/path_types.rs b/server/src/path_types.rs
index b5c41444f7bcd4d8d289ed3af464bc3f14d0df99..12dce9888f5cd4e1a0974d12d6468368d0f775b9 100644
--- a/server/src/path_types.rs
+++ b/server/src/path_types.rs
@@ -90,6 +90,50 @@ impl ItemId {
         paths
     }
 
+    /// Full URL for the browser location bar after `/~/`.
+    pub fn to_browse_url(&self) -> String {
+        if self.is_root() {
+            return String::new();
+        }
+        if self.as_str().contains("://") {
+            return self.as_str().to_string();
+        }
+        if self
+            .segments()
+            .first()
+            .is_some_and(|s| s.contains('.'))
+        {
+            format!("https://{}", self.as_str())
+        } else {
+            self.as_str().to_string()
+        }
+    }
+
+    /// App route, e.g. `/~/https://reddit.com/r/rust`.
+    pub fn browse_href(&self) -> String {
+        if self.is_root() {
+            "/".to_string()
+        } else {
+            format!("/~/{}", self.to_browse_url())
+        }
+    }
+
+    /// Parse the tail after `/~/` in a request path.
+    pub fn from_browse_tail(tail: &str) -> ItemId {
+        let raw = normalize_browse_tail(tail);
+        if raw.is_empty() {
+            return ItemId::root();
+        }
+        ItemId::from_url(&raw)
+            .or_else(|| ItemId::parse(&raw))
+            .unwrap_or_else(|| ItemId::opaque(raw))
+    }
+
+    pub fn from_browse_uri(path: &str) -> Option<ItemId> {
+        path.strip_prefix("/~/")
+            .map(ItemId::from_browse_tail)
+    }
+
     fn canonicalize(raw: &str) -> Option<String> {
         let s = raw.trim();
         if s.is_empty() {
@@ -155

… preview truncated; 6,669 characters omitted

download full diff A

B — c_effff18688f9 (tommy-mor)

message

[c3cbcaa7] refactor

diff preview

diff --git a/server/src/api/auth.rs b/server/src/api/auth.rs
index b3631b06153d52f88348fef927e7a024b7b85ad6..cd556eb89e9dd8203eba6c8969ffd144db5d329d 100644
--- a/server/src/api/auth.rs
+++ b/server/src/api/auth.rs
@@ -71,6 +71,24 @@ pub fn optional_principal(headers: &HeaderMap, jar: &CookieJar, reduced: &Reduce
     verify_token(reduced, c.value()).ok()
 }
 
+/// Browser session: principal + bearer token string (same shape as CLI session cookie).
+#[derive(Debug, Clone)]
+pub struct WebSession {
+    pub username: String,
+    pub bearer: String,
+}
+
+/// Resolve username and bearer together for `POST /ui` dispatch (one read of headers + jar).
+pub fn resolve_web_session(headers: &HeaderMap, jar: &CookieJar, reduced: &ReducerState) -> Option<WebSession> {
+    let username = optional_principal(headers, jar, reduced)?;
+    let bearer = headers
+        .get(header::AUTHORIZATION)
+        .and_then(|v| v.to_str().ok())
+        .and_then(|s| s.strip_prefix("Bearer ").map(|t| t.trim().to_string()))
+        .or_else(|| jar.get(SLUG_SESSION_COOKIE).map(|c| c.value().to_string()))?;
+    Some(WebSession { username, bearer })
+}
+
 fn redirect_with_session_cookie(public_url: &str, path_and_query: &str, bearer: &str, jar: &CookieJar) -> Response {
     let mut res = Response::builder()
         .status(StatusCode::TEMPORARY_REDIRECT)
diff --git a/server/src/api/mod.rs b/server/src/api/mod.rs
index a986f706ea4b261cbaf004c02b4cf84184b41371..4e223a7460997c464706dca850281447bd754ed5 100644
--- a/server/src/api/mod.rs
+++ b/server/src/api/mod.rs
@@ -4,7 +4,6 @@ mod rpc;
 mod stream;
 mod validate;
 mod ui_html;
-mod web_post;
 
 pub use auth::{
     get_join_invite,
@@ -19,7 +18,9 @@ pub use auth::{
     get_web_login,
     get_logout,
     optional_principal,
+    resolve_web_session,
     session_cookie_header_value,
+    WebSession,
     SLUG_SESSION_COOKIE,
 };
 
@@ -35,7 +36,6 @@ pub use stream::{get_html_stream, get_stream};
 pub use validate::{normalize_room_and_thread, validate_ingest_document, ValidatedIngest};
 
 pub use ui_html::post_ui_html;
-pub use web_post::{check_web_ingest, post_web_ingest, post_web_redact};
 
 #[cfg(test)]
 mod tests {
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index 2b40a72059981d558768f73d189b991f3448c257..497f8fdd222a8ec7c3d76b0695e0352e973ca3ba 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -1,25 +1,29 @@
-//! Single `POST /ui` entry for browser [`crate::html::ui_action::HtmlUiAction`] (JSON in `__rpc__` + holes).
+//! Single `POST /ui` entry: parse `__rpc__` → [`HtmlUiAction`], resolve [`WebSession`] once, dispatch.
 
 use axum::{
-    body::Body,
+    body,
     extract::State,
-    http::{header, HeaderMap, StatusCode},
+    http::{header, HeaderMap, HeaderValue, StatusCode},
     response::{IntoResponse, Response},
     Form,
 };
 use axum_extra::extract::cookie::CookieJar;
+use slug_types::{RpcBatch, RpcBatchResponse, RpcCommand, RpcResult};
 use std::collections::HashMap;
 
 use crate::{
     api::{
-        auth::optional_principal,
-        web_post::{run_check_web_ingest, run_post_web_ingest, run_post_web_redact, WebPostForm, WebRedactForm},
+        auth::{resolve_web_session, WebSession},
+        handle_rpc_batch,
+        rpc::{rpc_post_redact, rpc_post_with_bearer},
     },
+    canonical_path::canonicalize_tag,
     html::{
         fragment_public_new_thread_form, fragment_room_new_thread_form, login_to_post_hint_markup,
-        parse_html_ui_from_form, user_can_post_room, user_can_view_room, HtmlUiAction, JsBuilder,
-        ThreadNav,
+        parse_html_ui_from_form, thread_feed_html, thread_feed_html_for_room, thread_feed_region_markup,
+        user_can_post_room, user_can_view_room, HtmlUiAction, JsBuilder, ThreadNav,
     },
+    reducer::{scope_from_room_wire, ScopeId},
     state::AppState,
 };
 
@@ -34,6 +38,19 @@ pub async fn post_ui_html(
         Err(e) => return ui_js_warn(&e.to_string()).into_response(),
     };
 
+    let reduced = state.reduced.read().await;
+    let session = resolve_web_session(&headers, &jar, &reduced);
+    drop(reduced);
+
+    dispatch_ui_action(&state, session.as_ref(), action).await
+}
+
+/// All UI command logic: HTTP extractors stop above; this only sees [`AppState`], session, and [`HtmlUiAction`].
+async fn dispatch_ui_action(
+    state: &AppState,
+    session: Option<&WebSession>,
+    action: HtmlUiAction,
+) -> Response {
     match action {
         HtmlUiAction::PostIngest {
             room,
@@ -42,47 +59,87 @@ pub async fn post_ui_html(
             error_target,
             form_id,
         } => {
-            run_post_web_ingest(
-                &state,
-                &headers,
-                &jar,
-                WebPostForm {
-                    room,
-                    thread_tag,
-                    text,
-                    error_target,
-                    form_id,
-                },
-            )
-            .await
+            let Some(session) = session else {
+                return js_redirect("/login").into_response();
+            };
+            let room = room.trim().to_string();
+            let thread_tag = thread_tag.trim().to_string();
+            if text.trim().is_empty() {
+                return form_js_error(
+                    error_target.as_ref(),
+                    "empty post",
+                    "Write something in the text area (DSL / prose).",
+                )
+                .into_response();
+            }
+            match rpc_post_with_bearer(state, &session.bearer, room.clone(), thread_tag.clone(), text).await {
+                Ok(RpcResult::PostOk { .. }) => {
+                    post_success_response(
+                        state,
+                        &room,
+                        &thread_tag,
+                        error_target.as_ref(),
+                        form_id.as_ref(),
+                        Some(session.username.as_str()),
+                    )
+                    .await
+                    .into_response()
+                }
+                Ok(_) => form_js_error(
+                    error_target.as_ref(),
+                    "unexpected response",
+                    "Post did not return PostOk.",
+                )
+                .into_response(),
+                Err((msg, hint)) => form_js_error(error_target.as_ref(), &msg, hint.as_deref().unwrap_or("")).into_response(),
+            }
         }
         HtmlUiAction::CheckIngest {
             room,
             thread_tag,
             text,
             error_target,
-            form_id,
+            form_id: _,
         } => {
-            run_check_web_ingest(
-                &state,
-                &headers,
-                &jar,
-                WebPostForm {
-                    room,
-                    thread_tag,
-                    text,
-                    error_target,
-                    form_id,
-                },
-            )
-            .await
+            let Some(session) = session else {
+                return js_redirect("/login").into_response();
+            };
+            let room = room.trim().to_string();
+            let thread_tag = canonicalize_tag(&thread_tag);
+            if thread_tag.is_empty() {
+                return form_js_error(
+                    error_target.as_ref(),
+                    "missing thread tag",
+                    "Set a thread tag before posting.",
+                )
+                .into_response();
+            }
+            if text.trim().is_empty() {
+                return js_clear_errors(&form_error_target(error_target.as_ref())).into_response();
+            }
+            match rpc_check_with_bearer(state, &session.bearer, room, text.clone()).await {
+                Ok(RpcResult::CheckOk { .. }) => js_clear_errors(&form_error_target(error_target.as_ref())).into_response(),
+                Ok(_) => form_js_error(error_target.as_ref(), "unexpected response", "Check did not return CheckOk.").into_response(),
+                Err((msg, hint)) => form_js_error(error_target.as_ref(), &msg, hint.as_deref().unwrap_or("")).into_response(),
+            }
         }
         HtmlUiAction::RedactPost { post_id } => {
-            run_post_web_redact(&state, &headers, &jar, WebRedactForm { post_id }).await
+            let Some(session) = session else {
+                return js_redirect("/login").into_response();
+            };
+            let h = headers_from_bearer(&session.bearer);
+            match rpc_post_redact(state, &h, post_id).await {
+                Ok(RpcResult::RedactPostOk {}) => redact_success_response(state).await.into_response(),
+                Ok(_) => (StatusCode::BAD_REQUEST, "unexpected response").into_response(),
+                Err((msg, hint)) => {
+                    let detail = hint.as_deref().unwrap_or("");
+                    js_error("#errors", &msg, detail).into_response()
+                }
+            }
         }
         HtmlUiAction::ExpandPublicNewThreadForm => {
             let reduced = state.reduced.read().await;
-            let user = optional_principal(&headers, &jar, &reduced);
+            let user = session.map(|s| s.username.as_str());
             drop(reduced);
             let markup = if user.is_some() {
                 fragment_public_new_thread_form(true)
@@ -99,18 +156,18 @@ pub async fn post_ui_html(
                 return ui_js_warn("missing room").into_response();
             }
             let reduced = state.reduced.read().await;
-            let user = optional_principal(&headers, &jar, &reduced);
+            let user = session.map(|s| s.username.as_str());
             if !reduced.rooms.contains(&room_wire) {
                 drop(reduced);
                 return ui_js_warn("room not found").into_response();
             }
-            if !user_can_view_room(&reduced, &room_wire, user.as_deref()) {
+            if !user_can_view_room(&reduced, &room_wire, user) {
                 drop(reduced);
                 return ui_js_warn("forbidden").into_response();
             }
-            let can_post = user
+            let can_post = session
                 .as_ref()
-                .map(|u| user_can_post_room(&reduced, &room_wire, u))
+                .map(|s| user_can_post_room(&reduced, &room_wire, &s.username))
                 .unwrap_or(false);
             drop(reduced);
             let Some(nav) = ThreadNav::from_room_id(&room_wire) else {
@@ -128,12 +185,195 @@ pub async fn post_ui_html(
     }
 }
 
+fn headers_from_bearer(bearer: &str) -> HeaderMap {
+    let mut headers = HeaderMap::new();
+    if let Ok(hv) = HeaderValue::from_str(&format!("Bearer {bearer}")) {
+        headers.insert(header::AUTHORIZATION, hv);
+    }
+    headers
+}
+
+fn post_redirect_location(room: &str, thread_tag: &str) -> String {
+    let tag = canonicalize_tag(thread_tag);
+    if room.trim() == "public" {
+        format!("/t/{tag}")
+    } else {
+        let room = room.trim();
+        let Some((a, b)) = room.split_once('/') else {
+            return "/".to_string();
+        };
+        format!("/r/{a}/{b}/t/{tag}")
+    }
+}
+
+fn js_quote(s: &str) -> String {
+    serde_json::to_string(s).expect("js string escaping must succeed")
+}
+
+fn js_redirect(to: &str) -> Response {
+    let js = format!("window.location = {};", js_quote(to));
+    Response::builder()
+        .status(StatusCode::OK)
+        .header(header::CONTENT_TYPE, "text/javascript; charset=utf-8")
+        .body(axum::body::Body::from(js))
+        .unwrap()
+}
+
+fn js_error(error_target: &str, title: &str, detail: &str) -> Response {
+    let markup = maud::html! {
+        div id=(error_target.trim_start_matches('#')) {
+            p class="auth-error" { (title) }
+            @if !detail.is_empty() {
+                pre class="muted" { (detail) }
+            }
+        }
+    };
+    JsBuilder::new()
+        .morph_selector(error_targe

… preview truncated; 33,445 characters omitted

download full diff B

Hardlinks — judgments / attempts / prompt

prompt download

judgments

attempts

Prompt text is loaded only by the download route.