constitution · epochs · watch · epoch 3

comparison

c_c0df72aee6da (tommy-mor) vs c_af08bd851e49 (tommy-mor)

download prompt · raw event · cmp_b187747b663739

council reasoning

~anthropic/claude-sonnet-latest · winner A · 3:1 · permalink

Side A fixes a real, security-relevant bug (XSS via untrusted Reddit HTML) with a small, focused, well-tested change (new sanitize module + call sites + tests), delivering clear lasting value. Side B is a large, diffuse refactor touching voting UI, pair selection, ID normalization, and test infra with mixed concerns and no security or correctness fix of comparable importance, making its net contribution harder to justify as cleanly as A's targeted fix; notably it also reintroduces the unsanitized `PreEscaped(body)` pattern for entity bodies in vote_compare_item_card, potentially regressing the exact issue A addresses.

~x-ai/grok-latest · winner B · 2:5 · permalink

B lands lasting product design: bridge-aware pair selection in pair.rs, the /vote compare page with in-place morph after record_vote, ItemId::from_storage slug normalization (used in reddit/reducer/parse paths), plus integration coverage—far more than module reshuffling. A is a correct, necessary XSS fix (ammonia at PreEscaped render sites with tests) but a narrow hardening change versus B’s core ranking/vote behavior.

openai/gpt-chat-latest · winner A · 4:1 · permalink

Side A fixes a concrete security issue by introducing HTML sanitization with the `ammonia` library before rendering untrusted Reddit `body_html`, replacing direct `PreEscaped(body)` output with `entity_body_html(body)` and adding tests that verify scripts and event handlers are stripped while benign markup is preserved. Side B adds a substantial new voting UI, pair-selection logic, and refactoring, but it is largely feature work and even continues rendering `body_html` with `PreEscaped` in the new vote comparison page, whereas Side A provides a focused, lasting security improvement that protects all affected rendering paths.

sides

A — c_c0df72aee6da (tommy-mor)

message

[bf118bdf] Sanitize Reddit entity body HTML before rendering.

Use ammonia at render time so untrusted selftext_html cannot execute scripts in our origin.

Co-authored-by: Cursor <cursoragent@cursor.com>

diff preview

diff --git a/Cargo.lock b/Cargo.lock
index 3dec7cb72a182dc654a37dca8ba0b49d77504daa..0dd4fce5fb6400ae153cca4e3dbf5a5158e6d8b4 100644
--- a/Cargo.lock
+++ b/Cargo.lock
@@ -11,6 +11,19 @@ dependencies = [
  "memchr",
 ]
 
+[[package]]
+name = "ammonia"
+version = "4.1.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "17e913097e1a2124b46746c980134e8c954bc17a6a59bb3fde96f088d126dde6"
+dependencies = [
+ "cssparser",
+ "html5ever",
+ "maplit",
+ "tendril",
+ "url",
+]
+
 [[package]]
 name = "anyhow"
 version = "1.0.102"
@@ -355,6 +368,29 @@ version = "0.2.4"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "460fbee9c2c2f33933d720630a6a0bac33ba7053db5344fac858d4b8952d77d5"
 
+[[package]]
+name = "cssparser"
+version = "0.35.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "4e901edd733a1472f944a45116df3f846f54d37e67e68640ac8bb69689aca2aa"
+dependencies = [
+ "cssparser-macros",
+ "dtoa-short",
+ "itoa",
+ "phf",
+ "smallvec",
+]
+
+[[package]]
+name = "cssparser-macros"
+version = "0.6.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "13b588ba4ac1a99f7f2964d24b3d896ddc6bf847ee3855dbd4366f058cfcd331"
+dependencies = [
+ "quote",
+ "syn",
+]
+
 [[package]]
 name = "deranged"
 version = "0.5.8"
@@ -381,6 +417,21 @@ version = "0.15.7"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "1aaf95b3e5c8f23aa320147307562d361db0ae0d51242340f558153b4eb2439b"
 
+[[package]]
+name = "dtoa"
+version = "1.0.11"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "4c3cf4824e2d5f025c7b531afcb2325364084a16806f6d47fbc1f5fbd9960590"
+
+[[package]]
+name = "dtoa-short"
+version = "0.3.5"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "cd1511a7b6a56299bd043a9c167a6d2bfb37bf84a6dfceaba651168adfb43c87"
+dependencies = [
+ "dtoa",
+]
+
 [[package]]
 name = "durable"
 version = "0.2.0"
@@ -482,6 +533,16 @@ dependencies = [
  "percent-encoding",
 ]
 
+[[package]]
+name = "futf"
+version = "0.1.5"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "df420e2e84819663797d1ec6544b13c5be84629e7bb00dc960d6917db2987843"
+dependencies = [
+ "mac",
+ "new_debug_unreachable",
+]
+
 [[package]]
 name = "futures-channel"
 version = "0.3.32"
@@ -614,6 +675,17 @@ version = "0.5.0"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "2304e00983f87ffb38b55b444b5e3b60a884b5d30c0fca7d82fe33449bbe55ea"
 
+[[package]]
+name = "html5ever"
+version = "0.35.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "55d958c2f74b664487a2035fe1dadb032c48718a03b63f3ab0b8537db8549ed4"
+dependencies = [
+ "log",
+ "markup5ever",
+ "match_token",
+]
+
 [[package]]
 name = "http"
 version = "1.4.1"
@@ -974,6 +1046,15 @@ version = "0.8.2"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "92daf443525c4cce67b150400bc2316076100ce0b3686209eb8cf3c31612e6f0"
 
+[[package]]
+name = "lock_api"
+version = "0.4.14"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "224399e74b87b5f3557511d98dff8b14089b3dadafcab6bb93eab67d3aace965"
+dependencies = [
+ "scopeguard",
+]
+
 [[package]]
 name = "log"
 version = "0.4.30"
@@ -990,6 +1071,40 @@ dependencies = [
  "libc",
 ]
 
+[[package]]
+name = "mac"
+version = "0.1.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "c41e0c4fef86961ac6d6f8a82609f55f31b05e4fce149ac5710e439df7619ba4"
+
+[[package]]
+name = "maplit"
+version = "1.0.2"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "3e2e65a1a2e43cfcb47a895c4c8b10d1f4a61097f9f254f183aee60cad9c651d"
+
+[[package]]
+name = "markup5ever"
+version = "0.35.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "311fe69c934650f8f19652b3946075f0fc41ad8757dbb68f1ca14e7900ecc1c3"
+dependencies = [
+ "log",
+ "tendril",
+ "web_atoms",
+]
+
+[[package]]
+name = "match_token"
+version = "0.35.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "ac84fd3f360fcc43dc5f5d186f02a94192761a080e8bc58621ad4d12296a58cf"
+dependencies = [
+ "proc-macro2",
+ "quote",
+ "syn",
+]
+
 [[package]]
 name = "matchers"
 version = "0.2.0"
@@ -1092,6 +1207,12 @@ dependencies = [
  "tempfile",
 ]
 
+[[package]]
+name = "new_debug_unreachable"
+version = "1.0.6"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "650eef8c711430f1a879fdd01d4745a7deea475becfb90269c06775983bbf086"
+
 [[package]]
 name = "nom"
 version = "7.1.3"
@@ -1175,6 +1296,29 @@ dependencies = [
  "vcpkg",
 ]
 
+[[package]]
+name = "parking_lot"
+version = "0.12.5"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "93857453250e3077bd71ff98b6a65ea6621a19bb0f559a85248955ac12c45a1a"
+dependencies = [
+ "lock_api",
+ "parking_lot_core",
+]
+
+[[package]]
+name = "parking_lot_core"
+version = "0.9.12"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "2621685985a2ebf1c516881c026032ac7deafcda1a2c9b7850dc81e3dfcb64c1"
+dependencies = [
+ "cfg-if",
+ "libc",
+ "redox_syscall",
+ "smallvec",
+ "windows-link",
+]
+
 [[package]]
 name = "peeking_take_while"
 version = "0.1.2"
@@ -1187,6 +1331,58 @@ version = "2.3.2"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "9b4f627cb1b25917193a259e49bdad08f671f8d9708acfd5fe0a8c1455d87220"
 
+[[package]]
+name = "phf"
+version = "0.11.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "1fd6780a80ae0c52cc120a26a1a42c1ae51b247a253e4e06113d23d2c2edd078"
+dependencies = [
+ "phf_macros",
+ "phf_shared",
+]
+
+[[package]]
+name = "phf_codegen"
+version = "0.11.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "aef8048c789fa5e851558d709946d6d79a8ff88c0440c587967f8e94bfb1216a"
+dependencies = [
+ "phf_generator",
+ "phf_shared",
+]
+
+[[package]]
+name = "phf_generator"
+version = "0.11.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "3c80231409c20246a13fddb31776fb942c38553c51e871f8cbd687a4cfb5843d"
+dependencies = [
+ "phf_shared",
+ "rand 0.8.6",
+]
+
+[[package]]
+name = "phf_macros"
+version = "0.11.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "f84ac04429c13a7ff43785d75ad27569f2951ce0ffd30a3321230db2fc727216"
+dependencies = [
+ "phf_generator",
+ "phf_shared",
+ "proc-macro2",
+ "quote",
+ "syn",
+]
+
+[[package]]
+name = "phf_shared"
+version = "0.11.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "67eabc2ef2a60eb7faa00097bd1ffdb5bd28e62bf39990626a582201b7a754e5"
+dependencies = [
+ "siphasher",
+]
+
 [[package]]
 name = "pin-project-lite"
 version = "0.2.17"
@@ -1223,6 +1419,12 @@ dependencies = [
  "zerocopy",
 ]
 
+[[package]]
+name = "precomputed-hash"
+version = "0.1.1"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "925383efa346730478fb4838dbe9137d2a47675ad789c546d150a6e1dd4ab31c"
+
 [[package]]
 name = "prettyplease"
 version = "0.2.37"
@@ -1379,6 +1581,15 @@ dependencies = [
  "rand_core 0.9.5",
 ]
 
+[[package]]
+name = "redox_syscall"
+version = "0.5.18"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "ed2bf2547551a7053d6fdfafda3f938979645c44812fbfcda098faae3f1a362d"
+dependencies = [
+ "bitflags 2.11.1",
+]
+
 [[package]]
 name = "regex"
 version = "1.12.3"
@@ -1563,6 +1774,12 @@ dependencies = [
  "windows-sys 0.61.2",
 ]
 
+[[package]]
+name = "scopeguard"
+version = "1.2.0"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "94143f37725109f92c262ed2cf5e59bce7498c01bcc1502d7b9afe439a4e9f49"
+
 [[package]]
 name = "security-framework"
 version = "3.7.0"
@@ -1683,6 +1900,12 @@ dependencies = [
  "libc",
 ]
 
+[[package]]
+name = "siphasher"
+version = "1.0.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "8ee5873ec9cce0195efcb7a4e9507a04cd49aec9c83d0389df45b1ef7ba2e649"
+
 [[package]]
 name = "slab"
 version = "0.4.12"
@@ -1709,6 +1932,7 @@ dependencies = [
 name = "sorter2-server"
 version = "0.0.1"
 dependencies = [
+ "ammonia",
  "async-stream",
  "axum",
  "axum-extra",
@@ -1742,6 +1966,31 @@ version = "1.2.1"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596"
 
+[[package]]
+name = "string_cache"
+version = "0.8.9"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "bf776ba3fa74f83bf4b63c3dcbbf82173db2632ed8452cb2d891d33f459de70f"
+dependencies = [
+ "new_debug_unreachable",
+ "parking_lot",
+ "phf_shared",
+ "precomputed-hash",
+ "serde",
+]
+
+[[package]]
+name = "string_cache_codegen"
+version = "0.5.4"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "c711928715f1fe0fe509c53b43e993a9a557babc2d0a3567d0a3006f1ac931a0"
+dependencies = [
+ "phf_generator",
+ "phf_shared",
+ "proc-macro2",
+ "quote",
+]
+
 [[package]]
 name = "subtle"
 version = "2.6.1"
@@ -1813,6 +2062,17 @@ dependencies = [
  "windows-sys 0.61.2",
 ]
 
+[[package]]
+name = "tendril"
+version = "0.4.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "d24a120c5fc464a3458240ee02c299ebcb9d67b5249c8848b09d639dca8d7bb0"
+dependencies = [
+ "futf",
+ "mac",
+ "utf-8",
+]
+
 [[package]]
 name = "thiserror"
 version = "1.0.69"
@@ -2116,6 +2376,12 @@ version = "2.1.3"
 source = "registry+https://github.com/rust-lang/crates.io-index"
 checksum = "daf8dba3b7eb870caf1ddeed7bc9d2a049f3cfdfae7cb521b087cc33ae4c49da"
 
+[[package]]
+name = "utf-8"
+version = "0.7.6"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "09cc8ee72d2a9becf2f2febe0205bbed8fc6615b7cb429ad062dc7b7ddd036a9"
+
 [[package]]
 name = "utf8_iter"
 version = "1.0.4"
@@ -2281,6 +2547,18 @@ dependencies = [
  "wasm-bindgen",
 ]
 
+[[package]]
+name = "web_atoms"
+version = "0.1.3"
+source = "registry+https://github.com/rust-lang/crates.io-index"
+checksum = "57ffde1dc01240bdf9992e3205668b235e59421fd085e8a317ed98da0178d414"
+dependencies = [
+ "phf",
+ "phf_codegen",
+ "string_cache",
+ "string_cache_codegen",
+]
+
 [[package]]
 name = "windows-link"
 version = "0.2.1"
diff --git a/server/Cargo.toml b/server/Cargo.toml
index 47659ff82fbfb50972eb2b87575e80f66e572ba4..27f552c20b97ef28cdde4cb6b1a4980375135111 100644
--- a/server/Cargo.toml
+++ b/server/Cargo.toml
@@ -13,6 +13,7 @@ serde = { version = "1", features = ["derive"] }
 serde_json = "1"
 thiserror = "1"
 maud = { version = "0.26", features = ["axum"] }
+ammonia = "4.1"
 tower = "0.5"
 tower-http = { version = "0.5", features = ["trace"] }
 tracing = "0.1"
diff --git a/server/src/fetch/html.rs b/server/src/fetch/html.rs
index dadf050515f0473943dad97df5d318032c8cb385..5b160c6b8bd216dfaf80149854aec0566cd00460 100644
--- a/server/src/fetch/html.rs
+++ b/server/src/fetch/html.rs
@@ -4,6 +4,7 @@ use maud::{html, Markup};
 
 use crate::{
     form_template::template_json_compact,
+    html::sanitize::entity_body_html,
     path_types::ItemId,
     reddit::{is_children_fetchable, is_fetchable},
     reducer::NodeState,
@@ -27,7 +28,7 @@ pub fn entity_panel(node: &NodeState) -> Markup {
                     p class="muted small" { "by " (author) }
                 }
                 @if let Some(body) = &data.body_html {
-                    div class="entity-body" { (maud::PreEscaped(body)) }
+                    div class="entity-body" { (maud::PreEscaped(entity_body_html(body))) }
                 }
             }
         }
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index e180a0ca542a33e2300c0a4809e6b9cfee07ecfe..a58cbbee3490a08a625cb06df06848c59a615d65 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -20,6 +20,7 @@ use crate::{
     ui

… preview truncated; 2,223 characters omitted

download full diff A

B — c_af08bd851e49 (tommy-mor)

message

[2bc302c3] refactor

diff preview

diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index 06001212820101e0cc953d3687dea64f85e60787..d2f9769108def7ca2c5857aec8b4319426188a66 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -47,7 +47,7 @@ pub async fn post_ui_html(
             ratio_left,
             ratio_right,
             scope,
-            next,
+            vote_compare,
         } => {
             let parent = parent_from_scope(&scope);
             if let Err(e) = state
@@ -57,14 +57,12 @@ pub async fn post_ui_html(
                 return ui_js_warn(&e).into_response();
             }
             let tree = state.tree.read().await;
-            if !next.trim().is_empty() {
+            if vote_compare {
+                let left = parse_item_param(&a);
+                let right = parse_item_param(&b);
+                let morph = crate::html::vote::vote_recorded_morph(&tree, &parent, &left, &right);
                 drop(tree);
-                return JsBuilder::new()
-                    .raw(&format!(
-                        "window.location.href={};",
-                        js_string_literal(next.trim())
-                    ))
-                    .into_response();
+                return morph.into_response();
             }
             let empty = crate::reducer::NodeState::default();
             let node = tree.get(&parent).unwrap_or(&empty);
@@ -137,7 +135,7 @@ mod tests {
                 ratio_left: 3,
                 ratio_right: 1,
                 scope: String::new(),
-                next: String::new(),
+                vote_compare: false,
             }
         );
     }
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index 61cdbc094819ddedb755572c59456ec0d6617619..cd578a5fea46a9a1d49e238d08a80c2caf18708d 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -65,6 +65,15 @@ impl JsBuilder {
         self
     }
 
+    pub(crate) fn morph_inner_selector(mut self, selector: &str, markup: Markup) -> Self {
+        let html = js_string_literal(&markup.into_string());
+        self.snippets.push(format!(
+            "var __el = document.querySelector({sel}); if (__el) {{ Idiomorph.morph(__el, {html}, {{ morphStyle: 'innerHTML' }}); }}",
+            sel = js_string_literal(selector),
+        ));
+        self
+    }
+
     pub(crate) fn raw(mut self, js: &str) -> Self {
         if !js.is_empty() {
             self.snippets.push(js.to_string());
diff --git a/server/src/html/vote.rs b/server/src/html/vote.rs
new file mode 100644
index 0000000000000000000000000000000000000000..89ed621ad861214e147add2062224fc4137ff8ad
--- /dev/null
+++ b/server/src/html/vote.rs
@@ -0,0 +1,306 @@
+//! Pairwise vote UI — `/vote?parent=` with optional `left` / `right`.
+
+use axum::{
+    extract::{Query, State},
+    response::{Html, IntoResponse},
+};
+use maud::{html, Markup};
+use serde::Deserialize;
+
+use crate::{
+    form_template::template_json_compact,
+    html::JsBuilder,
+    pair::{children_of, resolve_pair, suggest_next_pair_in_pool},
+    path_types::ItemId,
+    reducer::{GlobalTree, GroupState, NodeState, VoteData},
+    state::{parse_item_param, AppState},
+    ui_action::UI_RPC_FIELD,
+};
+
+use super::{breadcrumb_path, item_href, layout};
+
+#[derive(Debug, Deserialize)]
+pub struct VoteQuery {
+    pub parent: String,
+    #[serde(default)]
+    pub left: Option<String>,
+    #[serde(default)]
+    pub right: Option<String>,
+}
+
+pub fn vote_href(parent: &ItemId) -> String {
+    format!(
+        "/vote?parent={}",
+        urlencoding::encode(parent.as_str())
+    )
+}
+
+fn vote_compare_href(parent: &ItemId, left: &ItemId, right: &ItemId) -> String {
+    format!(
+        "/vote?parent={}&left={}&right={}",
+        urlencoding::encode(parent.as_str()),
+        urlencoding::encode(left.as_str()),
+        urlencoding::encode(right.as_str()),
+    )
+}
+
+fn display_label(id: &ItemId) -> String {
+    id.segments()
+        .last()
+        .map_or("item".into(), |v| v.to_string())
+}
+
+fn child_title(tree: &GlobalTree, id: &ItemId) -> String {
+    tree.get(id)
+        .and_then(|n| n.data.as_ref())
+        .map(|d| d.title.clone())
+        .unwrap_or_else(|| display_label(id))
+}
+
+fn ratio_pct(ratio_left: i32, ratio_right: i32) -> f64 {
+    let l = ratio_left.max(0) as f64;
+    let r = ratio_right.max(0) as f64;
+    let sum = l + r;
+    if sum <= 0.0 {
+        50.0
+    } else {
+        (l / sum) * 100.0
+    }
+}
+
+fn ratios_for_page(v: &VoteData, page_left: &ItemId, page_right: &ItemId) -> (i32, i32) {
+    match (v.a.as_str(), v.b.as_str()) {
+        (a, b) if a == page_left.as_str() && b == page_right.as_str() => {
+            (v.ratio_left, v.ratio_right)
+        }
+        (a, b) if a == page_right.as_str() && b == page_left.as_str() => {
+            (v.ratio_right, v.ratio_left)
+        }
+        _ => (v.ratio_left, v.ratio_right),
+    }
+}
+
+fn edge_votes(group: &GroupState, left: &ItemId, right: &ItemId) -> Vec<VoteData> {
+    group
+        .recent_votes
+        .iter()
+        .filter(|v| {
+            (v.a.as_str() == left.as_str() && v.b.as_str() == right.as_str())
+                || (v.a.as_str() == right.as_str() && v.b.as_str() == left.as_str())
+        })
+        .cloned()
+        .collect()
+}
+
+fn vote_edge_history(tree: &GlobalTree, group: &GroupState, left: &ItemId, right: &ItemId) -> Markup {
+    let mut votes = edge_votes(group, left, right);
+    votes.sort_by(|a, b| b.ts.cmp(&a.ts));
+    let legend_left = child_title(tree, left);
+    let legend_right = child_title(tree, right);
+    html! {
+        @if votes.is_empty() {
+            p class="muted vote-edge-empty" { "no votes on this pair yet" }
+        } @else {
+            h3 class="vote-edge-history-title" {
+                "votes on this pair"
+                span class="vote-edge-history-axis muted" { " · " (legend_left) " : " (legend_right) }
+            }
+            ul class="vote-edge-history" {
+                @for v in &votes {
+                    @let (r_left, r_right) = ratios_for_page(v, left, right);
+                    @let pct = ratio_pct(r_left, r_right);
+                    li class="vote-edge-history-row" {
+                        div class="vote-edge-meta" {
+                            span class="vote-edge-ratio" { (format!("{}:{}", r_left, r_right)) }
+                        }
+                        div class="ratio-bar vote-edge-bar" aria-hidden="true" {
+                            div class="ratio-left" style={(format!("width: {:.3}%;", pct))} {}
+                            div class="ratio-right" style={(format!("width: {:.3}%;", 100.0 - pct))} {}
+                        }
+                    }
+                }
+            }
+        }
+    }
+}
+
+fn vote_back_nav(parent: &ItemId) -> Markup {
+    html! {
+        div class="vote-compare-nav" {
+            a class="vote-compare-back muted" href=(item_href(parent)) { "← back to " (display_label(parent)) }
+        }
+    }
+}
+
+fn vote_compare_actions(parent: &ItemId, next: Option<&(ItemId, ItemId)>) -> Markup {
+    let next_href = next.map(|(l, r)| vote_compare_href(parent, l, r));
+    html! {
+        div id="vote-compare-actions" class="vote-compare-actions" {
+            button type="submit" class="btn-primary" data-testid="vote-post" { "post vote" }
+            @if let Some(href) = &next_href {
+                a class="btn-secondary vote-compare-next" data-testid="vote-next-pair" href=(href) { "next pair" }
+            } @else {
+                span class="btn-secondary vote-compare-next is-disabled" { "no next pair" }
+            }
+        }
+    }
+}
+
+/// After recording a vote on the compare page: refresh edge history and next-pair link.
+pub(crate) fn vote_recorded_morph(
+    tree: &GlobalTree,
+    parent: &ItemId,
+    left: &ItemId,
+    right: &ItemId,
+) -> JsBuilder {
+    let pool = children_of(tree, parent);
+    let empty = NodeState::default();
+    let group = tree
+        .get(parent)
+        .unwrap_or(&empty)
+        .local_ranking
+        .clone();
+    let edge_history = vote_edge_history(tree, &group, left, right);
+    let next_pair = suggest_next(&group, left, right, &pool);
+    let actions = vote_compare_actions(parent, next_pair.as_ref());
+    JsBuilder::new()
+        .morph_inner_selector("#vote-edge-history-region", edge_history)
+        .morph_selector("#vote-compare-actions", actions)
+}
+
+fn vote_compare_item_card(tree: &GlobalTree, item: &ItemId, side_class: &str) -> Markup {
+    let href = item_href(item);
+    let title = child_title(tree, item);
+    html! {
+        div class=(format!("vote-compare-side {side_class}")) {
+            a class=(format!("vote-compare-item {side_class}")) href=(href) {
+                @if let Some(row) = crate::render::reddit::child_row_markup(tree, item, &href) {
+                    (row)
+                } @else {
+                    strong { (title) }
+                }
+            }
+            @if let Some(node) = tree.get(item) {
+                @if crate::render::reddit::is_reddit_post(item) {
+                    @if let Some(data) = &node.data {
+                        @if let Some(src) = data.image_url.as_ref().or(data.thumb_url.as_ref()) {
+                            figure class="vote-compare-figure" {
+                                img class="vote-compare-image" src=(src) alt="" loading="lazy";
+                            }
+                        }
+                        @if let Some(author) = &data.author {
+                            p class="muted small" { "by " (author) }
+                        }
+                    }
+                } @else if let Some(data) = &node.data {
+                    @if let Some(body) = &data.body_html {
+                        div class="vote-compare-item-body" {
+                            (maud::PreEscaped(body))
+                        }
+                    }
+                }
+            }
+        }
+    }
+}
+
+
+fn suggest_next(group: &GroupState, left: &ItemId, right: &ItemId, pool: &[ItemId]) -> Option<(ItemId, ItemId)> {
+    suggest_next_pair_in_pool(group, pool, Some((left, right)))
+}
+
+pub async fn vote_page(
+    State(state): State<AppState>,
+    Query(q): Query<VoteQuery>,
+) -> impl IntoResponse {
+    let parent = parse_item_param(&q.parent);
+    let left_param = q.left.as_deref().map(parse_item_param);
+    let right_param = q.right.as_deref().map(parse_item_param);
+
+    let tree = state.tree.read().await;
+    let empty = NodeState::default();
+    let parent_node = tree.get(&parent).unwrap_or(&empty);
+
+    let (left, right) = match resolve_pair(
+        &tree,
+        &parent,
+        left_param.as_ref(),
+        right_param.as_ref(),
+    ) {
+        Ok(p) => p,
+        Err(e) => {
+            let (msg, status) = e.status_message();
+            return (status, msg).into_response();
+        }
+    };
+
+    let pool = children_of(&tree, &parent);
+    let group = &parent_node.local_ranking;
+    let next_pair = suggest_next(group, &left, &right, &pool);
+    let edge_history = vote_edge_history(&tree, group, &left, &right);
+
+    let rpc_json = template_json_compact(&serde_json::json!({
+        "action": "record_vote",
+        "a": left.as_str(),
+        "b": right.as_str(),
+        "ratio_left": {"$form:i32": "ratio_left"},
+        "ratio_right": {"$form:i32": "ratio_right"},
+        "scope": parent.as_str(),
+        "vote_compare": true,
+    }))
+    .expect("vote rpc json");
+
+    let title = format!(
+        "vote — {} vs {}",
+        child_title(&tree, &left),
+        child_title(&tree, &right)
+    );
+
+    let body = html! {
+        section class="vote-compare-shell" {
+            h1 { "compare" }
+            (breadcrumb_path(&parent))
+            p class="muted vote-compare-scope" {
+                "ranking children of "
+                a href=(item_href(&par

… preview truncated; 32,381 characters omitted

download full diff B

Hardlinks — judgments / attempts / prompt

prompt download

judgments

attempts

Prompt text is loaded only by the download route.