Side A is a pure mechanical split/reorganization of forum.rs into submodules with no behavior change (net-zero functional value, mostly file-move churn). Side B implements a real UX/architecture improvement: it removes redirect-based auth flow in favor of AJAX form morphing, adds error/success fragment rendering, updates the shared poem JS to handle in-place form updates, and adds corresponding CSS — a genuine functional feature with lasting design impact.
constitution · epochs · watch · epoch 3
c_ebc883667d61 (tommy-mor) vs c_64faa3bee86f (tommy-mor)
download prompt · raw event · cmp_b6518a519a871d
council reasoning
B adds lasting product behavior: auth POSTs return Maud fragments (error form / signed-in message) and poem JS morphs non-empty bodies into the form, replacing redirect-based choose-username with inline success/error and shared layout. A’s huge diff mainly deletes leftover forum.rs and relocates the same thread HTML into forum/* with little logic change—useful module hygiene, but mostly structural churn versus B’s focused UX/API improvement.
Side B makes a lasting functional improvement: `post_choose_username` now returns HTML fragments for success/error instead of redirects, and the shared Poem JS reads non-empty responses to morph a form's `innerHTML`, enabling inline auth feedback while preserving existing empty-response behavior for other forms. Side A primarily removes the duplicate `server/src/html/forum.rs` and establishes `forum/mod.rs` with split modules to eliminate module-root ambiguity, which is valuable maintenance but mostly a structural cleanup rather than new user-facing behavior.
sides
A — c_ebc883667d61 (tommy-mor)
message
[21b57b50] fix(html): drop duplicate forum.rs; use forum/ as sole module root Removes the leftover monolithic file so mod forum resolves to forum/mod.rs without ambiguity. Keeps feed, views, and other split modules as the source. Made-with: Cursor
diff preview
diff --git a/server/src/html/forum.rs b/server/src/html/forum.rs
deleted file mode 100644
index 5ad8dfc84dd735d589432e2c613ff687a75f2e61..0000000000000000000000000000000000000000
--- a/server/src/html/forum.rs
+++ /dev/null
@@ -1,1405 +0,0 @@
-use axum::{
- extract::{Path, Query, State},
- http::{HeaderMap, StatusCode, Uri},
- response::{Html, IntoResponse},
-};
-use axum_extra::extract::cookie::CookieJar;
-use maud::{html, Markup};
-use serde::Deserialize;
-
-use crate::{
- api::optional_principal,
- canonical_path::{canonicalize_item, canonicalize_tag},
- events::ThreadCapability,
- form_template::template_json_compact,
- identity::parse_username,
- reducer::{scope_from_room_wire, ReducerState, ScopeId},
- state::AppState,
- timeago,
-};
-use serde_json::json;
-
-use super::js_string_literal;
-use super::ui_action::{HtmlUiAction, UI_RPC_FIELD};
-
-use super::{
- bc_segment, bc_threads, cli_panel, layout, now_ms, profile_href, recency_class,
- render_linkified_with_embeds_in_scope, theme_from_jar, theme_next_from_uri, JsBuilder,
-};
-
-#[derive(Clone)]
-struct ThreadRow {
- tag: String,
- subtitle: Option<String>,
- last_ts: i64,
- ingests: usize,
-}
-
-#[derive(Clone)]
-struct RoomMemberRow {
- username: String,
- capabilities: Vec<&'static str>,
-}
-
-/// URL helpers for public `/t/…` and private room threads `/r/{short}/{slug}/t/…`.
-#[derive(Clone)]
-pub struct ThreadNav {
- pub room_wire: String,
- scope: ScopeId,
- room_path: String,
- thread_path_prefix: String,
- garden_path_prefix: String,
-}
-
-impl ThreadNav {
- pub(crate) fn public() -> Self {
- Self {
- room_wire: "public".into(),
- scope: ScopeId::Public,
- room_path: "/t".into(),
- thread_path_prefix: "/t".into(),
- garden_path_prefix: "/~".into(),
- }
- }
-
- /// `room_id` wire form `shortid/slug`.
- pub(crate) fn from_room_id(room_id: &str) -> Option<Self> {
- let (short, slug) = room_id.split_once('/')?;
- if short.is_empty() || slug.is_empty() {
- return None;
- }
- Some(Self {
- room_wire: room_id.to_string(),
- scope: ScopeId::Room(room_id.to_string()),
- room_path: format!("/r/{short}/{slug}"),
- thread_path_prefix: format!("/r/{short}/{slug}/t"),
- garden_path_prefix: format!("/r/{short}/{slug}/~"),
- })
- }
-
- pub(crate) fn scope(&self) -> ScopeId {
- self.scope.clone()
- }
-
- pub(crate) fn room_url(&self) -> &str {
- &self.room_path
- }
-
- pub(crate) fn thread_url(&self, tag: &str) -> String {
- format!("{}/{}", self.thread_path_prefix, tag)
- }
-
- pub(crate) fn garden_root_url(&self) -> &str {
- &self.garden_path_prefix
- }
-
- pub(crate) fn garden_item_url(&self, item: &str) -> String {
- if let Some(tail) = crate::path_types::CanonicalItemUrl::parse(item)
- .and_then(|c| c.tilde_tail().map(str::to_owned))
- {
- format!("{}/{}", self.garden_path_prefix, tail)
- } else {
- format!("{}/{}", self.garden_path_prefix, canonicalize_item(item))
- }
- }
-
- fn thread_page_url(&self, tag: &str, offset: usize) -> String {
- let base = self.thread_url(tag);
- if offset == 0 {
- base
- } else {
- format!("{base}?offset={offset}")
- }
- }
-
- fn post_url(&self, tag: &str, idx: usize) -> String {
- format!("{}/{}/{}", self.thread_path_prefix, tag, idx)
- }
-}
-
-/// `POST /ui` + `__rpc__` from an inline link (`onclick`); same-origin credentials as other morph actions.
-fn thread_ui_fetch_onclick(rpc_compact_json: &str) -> String {
- format!(
- "fetch('/ui',{{method:'POST',headers:{{'Content-Type':'application/x-www-form-urlencoded'}},body:new URLSearchParams({{__rpc__:{}}}).toString(),credentials:'same-origin'}}).then(r=>r.text()).then(eval);return false",
- js_string_literal(rpc_compact_json)
- )
-}
-
-fn thread_nav_for_ingest(ing: &crate::events::Ingest) -> Option<ThreadNav> {
- let room = ing.room_id.trim();
- if room.is_empty() || room == "public" {
- Some(ThreadNav::public())
- } else {
- ThreadNav::from_room_id(room)
- }
-}
-
-fn thread_post_index_in_scope(reduced: &ReducerState, ing: &crate::events::Ingest) -> Option<usize> {
- let scope = scope_from_room_wire(&ing.room_id);
- let tag = canonicalize_tag(&ing.thread_tag);
- reduced
- .ingests_by_scope_thread
- .get(&(scope, tag))
- .and_then(|q| q.iter().rev().position(|id| id == &ing.id))
-}
-
-fn post_header_meta(
- nav: &ThreadNav,
- tag: &str,
- post_idx: usize,
- principal: &str,
- ts: i64,
- now: i64,
-) -> Markup {
- let post_href = nav.post_url(tag, post_idx);
- let profile = profile_href(principal);
- let hover = timeago::rfc3339_utc(ts);
- let ago = timeago::timeago(now, ts);
- html! {
- div class="ingest-meta muted" title=(hover) {
- a href=(post_href) class="post-num" { "#" (post_idx) }
- " "
- a href=(profile) class="post-author" { "@" (principal) }
- " · "
- (ago)
- }
- }
-}
-
-fn post_header_row(
- nav: &ThreadNav,
- tag: &str,
- post_idx: usize,
- ing: &crate::events::Ingest,
- _viewer: Option<&str>,
- now: i64,
- show_delete: bool,
-) -> Markup {
- let meta = post_header_meta(nav, tag, post_idx, &ing.principal, ing.ts, now);
- html! {
- div class="ingest-header-row" {
- (meta)
- @if show_delete {
- form class="post-delete-form" method="POST" action="/ui" {
- input type="hidden" name=(UI_RPC_FIELD) value=(template_json_compact(&HtmlUiAction::RedactPost { post_id: ing.id.clone() }).unwrap());
- button type="submit" class="post-delete-btn" { "delete" }
- }
- }
- }
- }
-}
-
-fn redacted_header_row(
- nav: &ThreadNav,
- tag: &str,
- post_idx: usize,
- ing: &crate::events::Ingest,
- now: i64,
- expanded: bool,
-) -> Markup {
- let meta = post_header_meta(nav, tag, post_idx, &ing.principal, ing.ts, now);
- let rpc_expand = template_json_compact(&json!({
- "action": "expand_redacted_post",
- "room": nav.room_wire,
- "thread_tag": tag,
- "post_index": post_idx,
- }))
- .unwrap();
- let rpc_collapse = template_json_compact(&json!({
- "action": "collapse_redacted_post",
- "room": nav.room_wire,
- "thread_tag": tag,
- "post_index": post_idx,
- }))
- .unwrap();
- let onclick_expand = thread_ui_fetch_onclick(&rpc_expand);
- let onclick_collapse = thread_ui_fetch_onclick(&rpc_collapse);
- html! {
- div class="ingest-header-row ingest-tombstone-row" {
- (meta)
- span class="post-tombstone-inline muted" {
- "deleted · "
- @if expanded {
- a href="#" class="hide-deleted-link"
- onclick=(onclick_collapse) {
- "[hide deleted content]"
- }
- } @else {
- a href="#" class="show-deleted-link"
- onclick=(onclick_expand) {
- "[show deleted content]"
- }
- }
- }
- }
- }
-}
-
-fn ingest_entry_markup(
- nav: &ThreadNav,
- tag: &str,
- post_idx: usize,
- ing: &crate::events::Ingest,
- viewer: Option<&str>,
- now: i64,
- reduced: &ReducerState,
-) -> Markup {
- let redacted = reduced.redacted_posts.contains(&ing.id);
- let show_delete = viewer == Some(ing.principal.as_str()) && !redacted;
- if redacted {
- html! {
- div class="ingest-entry ingest-redacted" data-ingest-id=(ing.id) {
- (redacted_header_row(nav, tag, post_idx, ing, now, false))
- }
- }
- } else {
- let truncated = ing.raw.len() > 2000;
- let display_body = if truncated { &ing.raw[..2000] } else { &ing.raw[..] };
- html! {
- div class="ingest-entry" data-ingest-id=(ing.id) {
- (post_header_row(nav, tag, post_idx, ing, viewer, now, show_delete))
- (render_linkified_with_embeds_in_scope(display_body, nav.garden_root_url()))
- @if truncated {
- @let rpc_full = template_json_compact(&json!({
- "action": "expand_post_full",
- "room": nav.room_wire,
- "thread_tag": tag,
- "post_index": post_idx,
- })).unwrap();
- @let onclick_full = thread_ui_fetch_onclick(&rpc_full);
- a href="#" class="show-full-link"
- onclick=(onclick_full) {
- "[show full post]"
- }
- }
- }
- }
- }
-}
-
-fn collect_thread_rows_for_scope(reduced: &ReducerState, scope: &ScopeId, now: i64) -> Vec<ThreadRow> {
- let _ = now;
- reduced
- .forum_threads
- .iter()
- .filter(|((s, _), _)| s == scope)
- .map(|((_, tag), thread)| {
- let ingests = reduced
- .ingests_by_scope_thread
- .get(&(scope.clone(), tag.clone()))
- .map(|q| q.len())
- .unwrap_or(0);
- ThreadRow {
- tag: tag.clone(),
- subtitle: None,
- last_ts: thread.last_activity_ts,
- ingests,
- }
- })
- .collect()
-}
-
-fn rooms_for_user(reduced: &ReducerState, username: &str) -> Vec<String> {
- let mut v: Vec<String> = reduced
- .grants
- .iter()
- .filter(|(rid, m)| reduced.rooms.contains(*rid) && m.contains_key(username))
- .map(|(rid, _)| rid.clone())
- .collect();
- v.sort();
- v
-}
-
-pub(crate) fn user_can_view_room(reduced: &ReducerState, room_id: &str, username: Option<&str>) -> bool {
- if !reduced.rooms.contains(room_id) {
- return false;
- }
- let Some(u) = username else {
- return false;
- };
- reduced.user_has_cap(room_id, u, ThreadCapability::View)
-}
-
-pub(crate) fn user_can_post_room(reduced: &ReducerState, room_id: &str, username: &str) -> bool {
- reduced.user_has_cap(room_id, username, ThreadCapability::Post)
-}
-
-fn capability_label(cap: ThreadCapability) -> &'static str {
- match cap {
- ThreadCapability::View => "view",
- ThreadCapability::Post => "post",
- ThreadCapability::Vote => "vote",
- ThreadCapability::AddItem => "add_item",
- ThreadCapability::Manage => "manage",
- }
-}
-
-fn room_members_for_room(reduced: &ReducerState, room_id: &str) -> Vec<RoomMemberRow> {
- let mut rows: Vec<RoomMemberRow> = reduced
- .grants
- .get(room_id)
- .into_iter()
- .flat_map(|members| members.iter())
- .map(|(username, caps)| {
- let mut ordered = Vec::new();
- for cap in [
- ThreadCapability::View,
- ThreadCapability::Post,
- ThreadCapability::Vote,
- ThreadCapability::AddItem,
- ThreadCapability::Manage,
- ] {
- if caps.contains(&cap) {
- ordered.push(capability_label(cap));
- }
- }
- RoomMemberRow {
- username: username.clone(),
- capabilities: ordered,
- }
- })
- .collect();
- rows.sort_by(|a, b| a.username.cmp(&b.username));
- rows
-}
-
-fn room_members_inner(members: &[RoomMemberRow]) -> Markup {
- html! {
- h3 { "members
… preview truncated; 77,260 characters omittedB — c_64faa3bee86f (tommy-mor)
message
[6b6eb0c3] Auth form: poem JS morphs form innerHTML on response; no redirect
- post_choose_username returns HTML fragments instead of redirects:
success → auth_signed_in_fragment ("you're signed in — return to your agent")
error → choose_username_error_fragment (form re-rendered with error inline)
- Poem JS now reads response body; if non-empty, morphs form innerHTML with it
(existing ingest forms return empty body, so they're unaffected)
- auth.rs: keep full layout() with poem JS — revert to single layout
- auth-success CSS class added to both themes
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>diff preview
diff --git a/server/src/api/auth.rs b/server/src/api/auth.rs
index c1194f79fd89fb47fe6b425b494a0ffa667abb2d..cb0faa29b834931e2c2b2f5c174c875e2e2e9346 100644
--- a/server/src/api/auth.rs
+++ b/server/src/api/auth.rs
@@ -16,7 +16,7 @@ use crate::{
canonicalize_username, validate_agent_format, validate_username,
Event, TokenIssued, UserRegistered,
},
- html::{auth_complete_page, choose_username_page},
+ html::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page},
state::{AppState, PendingSession},
};
@@ -274,8 +274,6 @@ pub async fn post_choose_username(
return api_error(StatusCode::BAD_REQUEST, "invalid agent format", Some(msg)).into_response();
}
- let public_url = std::env::var("SLUG_PUBLIC_URL").unwrap_or_else(|_| "http://127.0.0.1:8080".to_string());
-
let reduced_arc = state.reduced.clone();
let reduced = reduced_arc.read().await;
let provider_key = (provider.to_lowercase(), provider_id.clone());
@@ -284,11 +282,7 @@ pub async fn post_choose_username(
}
if reduced.users_by_provider.values().any(|u| u == &canonicalize_username(&form.username)) {
drop(reduced);
- return Redirect::to(&format!(
- "{public_url}/auth/choose-username?session={}&error={}",
- urlencoding::encode(&form.session),
- urlencoding::encode("that username is taken — try another"),
- )).into_response();
+ return choose_username_error_fragment(&form.session, "that username is taken — try another").into_response();
}
drop(reduced);
@@ -324,7 +318,7 @@ pub async fn post_choose_username(
s.complete = Some((canon_user.clone(), bearer.clone()));
}
- Redirect::to(&format!("{public_url}/auth/complete")).into_response()
+ auth_signed_in_fragment().into_response()
}
pub async fn post_pending_session(
diff --git a/server/src/html/auth.rs b/server/src/html/auth.rs
index 40b1ef30a6c1d4063aa2d8e9c93df8972df4b27c..0a14bdbfb66c65d1bd09993ffd4a7bb6f2fe041e 100644
--- a/server/src/html/auth.rs
+++ b/server/src/html/auth.rs
@@ -1,20 +1,25 @@
-use maud::{html, Markup, DOCTYPE};
+use maud::{html, Markup};
-/// Minimal layout for auth pages — no JS interceptor, real form navigation works.
-fn auth_layout(title: &str, body: Markup) -> Markup {
+fn form_inner(session: &str, error: Option<&str>) -> Markup {
html! {
- (DOCTYPE)
- html {
- head {
- meta charset="utf-8";
- meta name="viewport" content="width=device-width, initial-scale=1";
- title { (title) }
- link rel="stylesheet" href="/static/theme_default.css";
- }
- body class="view-auth" {
- (body)
- }
+ input type="hidden" name="session" value=(session);
+ label for="username" { "username" }
+ input
+ type="text"
+ id="username"
+ name="username"
+ placeholder="e.g. alice"
+ pattern="[a-z0-9_\\-]{1,32}"
+ maxlength="32"
+ autocomplete="off"
+ autofocus;
+ p.auth-hint {
+ "lowercase · alphanumeric · hyphens · underscores · max 32"
}
+ @if let Some(msg) = error {
+ p.auth-error { (msg) }
+ }
+ button type="submit" { "continue" }
}
}
@@ -28,27 +33,23 @@ pub fn choose_username_page(session: &str, error: Option<&str>) -> Markup {
h1 { "choose a username" }
p { "pick a handle for slug.social." }
form.auth-form method="POST" action="/auth/choose-username" {
- input type="hidden" name="session" value=(session);
- label for="username" { "username" }
- input
- type="text"
- id="username"
- name="username"
- placeholder="e.g. alice"
- pattern="[a-z0-9_\\-]{1,32}"
- maxlength="32"
- autocomplete="off"
- autofocus;
- p.auth-hint {
- "lowercase · alphanumeric · hyphens · underscores · max 32"
- }
- @if let Some(msg) = error {
- p.auth-error { (msg) }
- }
- button type="submit" { "continue" }
+ (form_inner(session, error))
}
};
- auth_layout("join — slug.social", body)
+ super::layout("join — slug.social", "view-auth", body, None)
+}
+
+/// Fragment returned to the poem JS on error — replaces the form's innerHTML.
+pub fn choose_username_error_fragment(session: &str, error: &str) -> Markup {
+ form_inner(session, Some(error))
+}
+
+/// Fragment returned to the poem JS on success — replaces the form's innerHTML.
+pub fn auth_signed_in_fragment() -> Markup {
+ html! {
+ p.auth-success { "you're signed in — return to your agent." }
+ p.auth-hint { "you can close this tab." }
+ }
}
pub fn auth_complete_page() -> Markup {
@@ -62,5 +63,5 @@ pub fn auth_complete_page() -> Markup {
p { "Return to your terminal — your agent is polling and will collect your token automatically." }
p.auth-hint { "You can close this tab." }
};
- auth_layout("signed in — slug.social", body)
+ super::layout("signed in — slug.social", "view-auth", body, None)
}
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index 2f16d701962d703db0c859bb586dfc08ec385690..8b48a25cce79f0eefc7e29849e1a667cae4c7986 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -15,7 +15,7 @@ mod search;
mod tree;
use breadcrumb_path::OntologyPath;
-pub use auth::{auth_complete_page, choose_username_page};
+pub use auth::{auth_complete_page, auth_signed_in_fragment, choose_username_error_fragment, choose_username_page};
pub use editor::{editor_check, editor_page};
pub use forum::{index, thread_feed_html, thread_post_expand, thread_post_view, thread_view};
pub use garden::{garden_index, ontology_path};
@@ -114,6 +114,8 @@ script { (maud::PreEscaped(r#"
});
// Poem: intercept POST forms, send via fetch, await SSE for DOM update.
+ // If the response body is non-empty HTML, morph the form's innerHTML with it
+ // (used for inline feedback without a page reload, e.g. auth forms).
document.addEventListener('submit', async (e) => {
const f = e.target;
if (!f || f.tagName !== 'FORM') return;
@@ -121,14 +123,19 @@ script { (maud::PreEscaped(r#"
e.preventDefault();
const btn = f.querySelector('button[type="submit"], input[type="submit"]');
if (btn) { btn.disabled = true; btn.textContent = '…'; }
- await fetch(f.action, {
+ const resp = await fetch(f.action, {
method: 'POST',
body: new URLSearchParams(new FormData(f)),
headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
credentials: 'same-origin',
});
- if (btn) { btn.disabled = false; btn.textContent = 'submit'; }
- f.reset();
+ const html = await resp.text();
+ if (html && html.trim()) {
+ Idiomorph.morph(f, html, {morphStyle: 'innerHTML'});
+ } else {
+ if (btn) { btn.disabled = false; btn.textContent = 'submit'; }
+ f.reset();
+ }
});
// Search: debounced fetch + idiomorph.
diff --git a/server/static/theme_default.css b/server/static/theme_default.css
index 9e71574da4bed3a0116c347610636780678bd1af..a1d8d1765a7812191edc579125facf1694554c2c 100644
--- a/server/static/theme_default.css
+++ b/server/static/theme_default.css
@@ -250,6 +250,11 @@ p.auth-error {
font-size: 12px;
margin: 4px 0 0;
}
+p.auth-success {
+ color: var(--signal);
+ font-size: 13px;
+ margin: 4px 0 0;
+}
/* ----------------------------------------------------------------
BUTTONS — raised, press on :active
diff --git a/server/static/theme_retro.css b/server/static/theme_retro.css
index dc9fa4654f529eb1843557fb580cf3982da46901..8ed8fd88efab32b36bd66cf200aa182219b0a8b5 100644
--- a/server/static/theme_retro.css
+++ b/server/static/theme_retro.css
@@ -32,6 +32,7 @@ input[type="text"] {
input[type="text"]:focus { border-color: #00ff41; }
p.auth-hint { color: #555; font-family: monospace; font-size: 0.75rem; margin: 0; }
p.auth-error { color: #ff4444; font-family: monospace; font-size: 0.8rem; margin: 0; }
+p.auth-success { color: #00ff41; font-family: monospace; font-size: 0.8rem; margin: 0; }
/* Ingest form (poem pattern) */
.ingest-form-wrap { margin-top: 1.5rem; }
Hardlinks — judgments / attempts / prompt
judgments
attempts
Prompt text is loaded only by the download route.