constitution · epochs · watch · epoch 3

comparison

c_94135a1c4c58 (tommy-mor) vs c_b0194743d156 (tommy-mor)

download prompt · raw event · cmp_c67eef56fc4e7b

council reasoning

~anthropic/claude-sonnet-latest · winner A · 6:4 · permalink

Side A fixes a real security fail-open bug (votes falling back to anon on missing/expired session) with fail-closed logic, adds Secure cookie support, mock-OAuth gating, open-redirect hardening with tests, and nav UX—each backed by concrete tests. Side B is a legitimate but narrower bugfix (unifying tilde-root storage key variants) with good test coverage, but it's a more localized correctness patch versus A's broader security-critical hardening across auth, cookies, and vote integrity.

~x-ai/grok-latest · winner A · 3:2 · permalink

A delivers product-critical integrity: fail-closed vote auth (no silent anon fallback), mock OAuth gated behind env, Secure cookies, and tighter return-to sanitization—plus durable pinned by rev. B is a real lasting path-identity fix (tilde root normalization so garden child/rank lookups hit storage keys) with strong tests, but it is narrower domain plumbing than A’s multi-bug security/auth hardening.

openai/gpt-chat-latest · winner A · 4:3 · permalink

Side A makes substantive security and correctness improvements: voting now fails closed instead of silently falling back to an anonymous actor, auth cookies gain the Secure flag when appropriate, mock OAuth is gated behind an environment flag, open-redirect sanitization is strengthened, and these behaviors are covered by tests. Side B fixes canonical tilde-path handling and root normalization across routing, ranking, and rendering with good regression tests, but its impact is narrower than the authentication hardening and session correctness changes in Side A.

sides

A — c_94135a1c4c58 (tommy-mor)

message

[880eb778] Harden auth: fail-closed votes, mock OAuth gate, Secure cookies.

Also show the current alias in the top nav and pin durable by rev.

Co-authored-by: Cursor <cursoragent@cursor.com>

diff preview

diff --git a/AGENTS.md b/AGENTS.md
index babb889d6fbfb1fa7176c9e6b7544ae17b61dd2e..6e0fd8ebb65d665c9c1438e3275971d62b98fd95 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -10,11 +10,11 @@ Single Rust web app **`sorter2-server`**: pairwise voting, rank-centrality ranki
 
 - **Bootstrap script**: `./scripts/cursor-env-install.sh` (also run via `.cursor/environment.json` on Cloud Agent boot) installs Playwright Chromium, Babashka, bbin, `clj-paren-repair`, and warms the RocksDB build.
 - **Rust 1.88+** is required (`rust-toolchain.toml`). The Cloud Dockerfile and `cursor-env-install.sh` install **rustup** 1.88.0 first so `cargo` works while Playwright/Clojure bootstrap continues. Do not rely on `/usr/local/cargo` (often missing or stale).
-- **RocksDB / `durable`**: Ubuntu’s default `c++` is often **clang** without libc++ headers. Set **`CXX=g++`** and **`RUSTFLAGS="-C linker=g++"`** (or `CC=gcc`) before `cargo build` / `cargo test` — both are set in the bootstrap script and `.cursor/environment.json`.
+- **RocksDB / `durable`**: `durable` is an external git dependency (`tommy-mor/durable`, pinned by rev in `server/Cargo.toml`). Ubuntu’s default `c++` is often **clang** without libc++ headers. Set **`CXX=g++`** and **`RUSTFLAGS="-C linker=g++"`** (or `CC=gcc`) before `cargo build` / `cargo test` — both are set in the bootstrap script and `.cursor/environment.json`.
 - **System packages** for builds: `build-essential`, `g++`, `clang`, `libclang-dev`, `pkg-config`, `libssl-dev`, `openjdk-21-jre-headless` (for `reqwest` / OpenSSL, `librocksdb-sys`, `zstd-sys` / bindgen, and **bbin** / Clojure JVM). The bootstrap sets **`JAVA_HOME`** when Java is present.
 - **Clojure CLI 1.12.0.1530** (used in CI): install from https://clojure.org/guides/install_clojure — needed for `./scripts/clj-test.sh` / Kaocha tests.
 - **Babashka / bbin / clj-paren-repair**: installed by `cursor-env-install.sh` into `~/.local/bin` (bb tasks in `bb.edn`, delimiter repair for Clojure edits).
-- **Playwright** (Spel browser tests in `test/vote_compare.clj`): Chromium via `clojure -M -e "(com.microsoft.playwright.CLI/main ...)"` — run once after clone or use the bootstrap script.
+- **Playwright** (Spel browser tests in `test/vote_compare.clj` / `test/auth_login.clj`): Chromium via `clojure -M -e "(com.microsoft.playwright.CLI/main ...)"` — run once after clone or use the bootstrap script.
 
 ### Commands (see also `TEST.sh`)
 
@@ -34,13 +34,17 @@ Environment variables (defaults in `server/src/state.rs`):
 - `PORT` — default `8080`
 - `SORTER2_DATA_DIR` — default `./data` (created on startup)
 - `SORTER2_EVENT_LOG` — default `{data_dir}/events.jsonl`
+- `SORTER2_BASE_URL` — public origin (also drives Secure cookies when `https://`)
+- `GITHUB_CLIENT_ID` / `GITHUB_CLIENT_SECRET` — GitHub OAuth (optional; login disabled if unset)
+- `SORTER2_ALLOW_MOCK_OAUTH=1` — allow `mock_user` on `/auth/github` (tests only)
 
 Health check: `GET /healthz` → `ok`.
 
-Core UI flow: `POST /ui` with form field `__rpc__` (JSON). Example vote:
+Core UI flow: `POST /ui` with form field `__rpc__` (JSON). Votes require a session cookie (sign in via `/login`). Example vote:
 
 ```bash
 curl -sf -X POST http://127.0.0.1:8080/ui \
+  --cookie "sorter2_session=..." \
   --data-urlencode '__rpc__={"action":"record_vote","a":"alpha","b":"beta","ratio_left":2,"ratio_right":1}'
 ```
 
diff --git a/Cargo.lock b/Cargo.lock
index aa02997ad85777195f135bfd9456bcee0fc9a590..1f8690f3e486d099577a32c2ece48caf57ea7160 100644
--- a/Cargo.lock
+++ b/Cargo.lock
@@ -414,7 +414,7 @@ dependencies = [
 [[package]]
 name = "durable"
 version = "0.2.0"
-source = "git+https://github.com/tommy-mor/durable.git?branch=main#a6c14eaa809693140eea0c22b07ef24d8e74adaf"
+source = "git+https://github.com/tommy-mor/durable.git?rev=a6c14eaa809693140eea0c22b07ef24d8e74adaf#a6c14eaa809693140eea0c22b07ef24d8e74adaf"
 dependencies = [
  "ciborium",
  "durable-derive",
@@ -426,7 +426,7 @@ dependencies = [
 [[package]]
 name = "durable-derive"
 version = "0.2.0"
-source = "git+https://github.com/tommy-mor/durable.git?branch=main#a6c14eaa809693140eea0c22b07ef24d8e74adaf"
+source = "git+https://github.com/tommy-mor/durable.git?rev=a6c14eaa809693140eea0c22b07ef24d8e74adaf#a6c14eaa809693140eea0c22b07ef24d8e74adaf"
 dependencies = [
  "proc-macro2",
  "quote",
diff --git a/server/Cargo.toml b/server/Cargo.toml
index dfa39beddecfa37dcdeaa602cb30f4b547528fbb..bd88687fb0ba47d68f2c08eb5e11d0e08b7c4398 100644
--- a/server/Cargo.toml
+++ b/server/Cargo.toml
@@ -25,7 +25,7 @@ futures-util = { version = "0.3", default-features = false, features = ["std"] }
 rand = "0.8"
 urlencoding = "2"
 url = "2"
-durable = { git = "https://github.com/tommy-mor/durable.git", branch = "main" }
+durable = { git = "https://github.com/tommy-mor/durable.git", rev = "a6c14eaa809693140eea0c22b07ef24d8e74adaf" }
 
 [dev-dependencies]
 reqwest = { version = "0.12", features = ["json"] }
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index b86581b1f337650564274254d840e8a75b49524d..9da62ffbed07eb28729aa3160bf33b07ce0d7945 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -71,10 +71,16 @@ pub async fn post_ui_html(
                 return resp;
             }
             let parent = parent_from_scope(&scope);
-            let actor = resolve_vote_actor(
+            let actor = match resolve_vote_actor(
                 state.projection_store.db(),
                 session_id_from_jar(&jar).as_deref(),
-            );
+            ) {
+                Ok(actor) => actor,
+                Err(_) => {
+                    return vote_auth_redirect(&state, &jar)
+                        .unwrap_or_else(|| login_redirect_js().into_response());
+                }
+            };
             if let Err(e) = state
                 .record_vote(&parent, &a, &b, ratio_left, ratio_right, &actor)
                 .await
diff --git a/server/src/auth/config.rs b/server/src/auth/config.rs
index a1f042c655bf3e5234eeb87a7d889f64592807fb..a5976af9a52ea207b35ae87bd1fe927c47a477ca 100644
--- a/server/src/auth/config.rs
+++ b/server/src/auth/config.rs
@@ -1,9 +1,42 @@
 pub const AUTH_RETURN_COOKIE: &str = "sorter2_auth_return";
 
+/// Allow `mock_user` on `/auth/github` (test harness only).
+pub fn mock_oauth_allowed() -> bool {
+    matches!(
+        std::env::var("SORTER2_ALLOW_MOCK_OAUTH").as_deref(),
+        Ok("1") | Ok("true") | Ok("TRUE")
+    )
+}
+
+/// Set the Secure flag on auth cookies when serving over HTTPS.
+pub fn cookies_secure() -> bool {
+    std::env::var("SORTER2_BASE_URL")
+        .map(|u| u.starts_with("https://"))
+        .unwrap_or(false)
+}
+
 pub fn sanitize_return_to(raw: &str) -> String {
     let s = raw.trim();
-    if s.is_empty() || !s.starts_with('/') || s.starts_with("//") {
+    if s.is_empty() || !s.starts_with('/') || s.starts_with("//") || s.starts_with("/\\") {
+        return "/".to_string();
+    }
+    // Reject scheme-relative and protocol-smuggling forms.
+    if s.contains("://") || s.contains('\\') {
         return "/".to_string();
     }
     s.to_string()
 }
+
+#[cfg(test)]
+mod tests {
+    use super::*;
+
+    #[test]
+    fn sanitize_return_to_blocks_open_redirects() {
+        assert_eq!(sanitize_return_to(""), "/");
+        assert_eq!(sanitize_return_to("//evil.com"), "/");
+        assert_eq!(sanitize_return_to("/\\evil.com"), "/");
+        assert_eq!(sanitize_return_to("https://evil.com"), "/");
+        assert_eq!(sanitize_return_to("/vote?parent=x"), "/vote?parent=x");
+    }
+}
diff --git a/server/src/auth/mod.rs b/server/src/auth/mod.rs
index 5ed535ba199fa736f0048c32623b14c3b1e5de2d..d4a85ef52c15dc35148e4c743f0d646cbbdb056d 100644
--- a/server/src/auth/mod.rs
+++ b/server/src/auth/mod.rs
@@ -26,7 +26,7 @@ use crate::{
     ui_action::UI_RPC_FIELD,
 };
 
-pub use session::{resolve_vote_actor, session_id_from_jar, VoteActor};
+pub use session::{nav_pseudonym, resolve_vote_actor, session_id_from_jar, VoteActor};
 
 pub fn base_url_from_env(port: u16) -> String {
     std::env::var("SORTER2_BASE_URL")
@@ -168,6 +168,10 @@ pub async fn login_page(
         "login · sorter2",
         login_body(session.as_ref(), &aliases, &providers),
         state.views.get_views("/login"),
+        session
+            .as_ref()
+            .filter(|s| !s.pseudonym.trim().is_empty())
+            .map(|s| s.pseudonym.as_str()),
     );
     (jar, Html(markup.into_string())).into_response()
 }
@@ -222,6 +226,7 @@ pub async fn alias_page(
             "choose alias · sorter2",
             body,
             state.views.get_views("/login/alias"),
+            None,
         )
         .into_string(),
     )
@@ -237,7 +242,12 @@ pub async fn github_start(
         .ok_or(StatusCode::SERVICE_UNAVAILABLE)?;
     let return_to = return_from_query_or_jar(&jar, query.return_to.as_deref());
     let state_token = session::new_oauth_state();
-    let url = oauth::authorize_url(&cfg, &state_token, query.mock_user.as_deref());
+    let mock_user = if config::mock_oauth_allowed() {
+        query.mock_user.as_deref()
+    } else {
+        None
+    };
+    let url = oauth::authorize_url(&cfg, &state_token, mock_user);
     let jar = jar
         .add(session::oauth_state_cookie_value(&state_token))
         .add(session::auth_return_cookie_value(&return_to));
diff --git a/server/src/auth/session.rs b/server/src/auth/session.rs
index 09659240b9455c6fca12db5652e1d31cf8c2acfc..41df030ded3abcafc0ab3887ab769adf103f9aa0 100644
--- a/server/src/auth/session.rs
+++ b/server/src/auth/session.rs
@@ -5,7 +5,7 @@ use durable::{Db, Durability};
 use rand::Rng;
 
 use crate::{
-    auth::config::AUTH_RETURN_COOKIE,
+    auth::config::{self, AUTH_RETURN_COOKIE},
     fetch::now_ms,
     identity::{DEFAULT_ACTOR_UUID, DEFAULT_PSEUDONYM},
     storage_dto::{SessionDataV1, SESSION_DATA_VERSION},
@@ -37,6 +37,7 @@ pub struct VoteActor {
 }
 
 impl VoteActor {
+    /// Test / bench helper: seed votes as the default pseudonym without a session.
     pub fn anon() -> Self {
         Self {
             pseudonym: DEFAULT_PSEUDONYM.to_string(),
@@ -70,20 +71,51 @@ fn hex_encode(bytes: &[u8]) -> String {
     bytes.iter().map(|b| format!("{b:02x}")).collect()
 }
 
-pub fn resolve_vote_actor(db: &Db, session_id: Option<&str>) -> VoteActor {
-    let Some(session_id) = session_id else {
-        return VoteActor::anon();
-    };
-    let Ok(Some(session)) = load_session(db, session_id) else {
-        return VoteActor::anon();
-    };
-    if session.expires_at <= now_ms() {
-        return VoteActor::anon();
+fn build_cookie(name: &'static str, value: String) -> Cookie<'static> {
+    let mut builder = Cookie::build((name, value))
+        .http_only(true)
+        .same_site(SameSite::Lax)
+        .path("/");
+    if config::cookies_secure() {
+        builder = builder.secure(true);
+    }
+    builder.build()
+}
+
+fn clear_cookie(name: &'static str) -> Cookie<'static> {
+    let mut builder = Cookie::build((name, ""))
+        .http_only(true)
+        .same_site(SameSite::Lax)
+        .path("/")
+        .removal();
+    if config::cookies_secure() {
+        builder = builder.secure(true);
+    }
+    builder.build()
+}
+
+/// Resolve the vote actor from a live session. Fail-closed: never falls back to anon.
+pub fn resolve_vote_actor(db: &Db, session_id: Option<&str>) -> Result<VoteActor, &'static str> {
+    let session_id = session_id.ok_or("sign in to vote")?;
+    let session = load_valid_session(db, session_id).ok_or("session expired")?;
+    if !session_has_pseudonym(&session) {
+        return Err("choose an alias first");
     }
     let trust_weight = user_trust_weight(db, &session.uuid).unwrap_or(1.0);
-    VoteActor {
+    Ok(VoteActor {
         pseudonym: session.current_pseudonym,
         trust_weight,
+    })
+}
+
+/// Display name for the top nav, if any session is active.
+pub fn nav_pseudonym(db: &Db, jar: &CookieJar) -> Option<String> {
+    let sessio

… preview truncated; 10,040 characters omitted

download full diff A

B — c_b0194743d156 (tommy-mor)

message

[c59951f5] fixed canonical item paths business

diff preview

diff --git a/server/src/html/breadcrumb_path.rs b/server/src/html/breadcrumb_path.rs
index 12ad2c84faf2fbb693015d4552e45b5c54d587b9..c8a3937923161a6ff248bd77e87eff0dc6fe9ab0 100644
--- a/server/src/html/breadcrumb_path.rs
+++ b/server/src/html/breadcrumb_path.rs
@@ -1,4 +1,4 @@
-use crate::path_types::CanonicalItemUrl;
+use crate::path_types::{tilde_http_path_to_canonical, CanonicalItemUrl};
 
 /// Semantic view of an ontology path for rendering and routing decisions.
 pub(super) struct OntologyPath {
@@ -11,16 +11,7 @@ impl OntologyPath {
     /// Path is the `*path` segment from `/~/*path` (e.g. `topic/a`). Always treat it as under `~/`
     /// so it canonicalizes to `https://slug.social/~/…`, not the non-tilde site path.
     pub(super) fn from_input(path: &str) -> Self {
-        let p = path.trim_start_matches('/');
-        let raw = if p.starts_with("http://") || p.starts_with("https://") {
-            p.to_string()
-        } else if p.is_empty() {
-            "~/".to_string()
-        } else {
-            format!("~/{}", p)
-        };
-        let canonical = CanonicalItemUrl::parse(&raw)
-            .unwrap_or_else(|| CanonicalItemUrl::parse("~/").unwrap());
+        let canonical = tilde_http_path_to_canonical(path);
         Self::from_canonical(canonical)
     }
 
@@ -37,7 +28,7 @@ impl OntologyPath {
     }
 
     pub(super) fn root() -> Self {
-        Self::from_canonical(CanonicalItemUrl::parse("~/").unwrap())
+        Self::from_canonical(CanonicalItemUrl::ontology_root())
     }
 
     pub(super) fn is_root(&self) -> bool {
diff --git a/server/src/html/garden.rs b/server/src/html/garden.rs
index d58d9b46f575eb6b7e4971086b07dda75ca2f645..319feb15a6b68d2b5df98b4289fedbc9bdd048d3 100644
--- a/server/src/html/garden.rs
+++ b/server/src/html/garden.rs
@@ -459,6 +459,8 @@ struct ItemPageViewModel {
     item: String,
     body: Option<String>,
     sibling_rank: Option<SiblingRank>,
+    /// False at the tilde ontology root (`~/`): sibling-rank footnote does not apply.
+    item_has_parent: bool,
     child_rankings: ChildrenRankings,
     rank_history: Vec<RankHistoryEntryView>,
     /// Forum threads that mention or vote on this item.
@@ -470,11 +472,12 @@ fn build_sibling_rank(
     scope: &ScopeId,
     item: &CanonicalItemUrl,
 ) -> Option<SiblingRank> {
+    let item = item.clone().normalized_storage();
     let content = reduced
         .content_for_scope(scope)
         .unwrap_or_else(|| reduced.public());
     let group = &content.ranking_group;
-    let parent = item.parent()?;
+    let parent = item.parent()?.normalized_storage();
     let siblings: Vec<CanonicalItemUrl> = content
         .item_children
         .get(&parent)
@@ -492,7 +495,7 @@ fn build_sibling_rank(
     if scoped_idxs.is_empty() {
         return None;
     }
-    let current_idx = *group.item_to_idx.get(item)?;
+    let current_idx = *group.item_to_idx.get(&item)?;
     if !scoped_idxs.contains(&current_idx) {
         return None;
     }
@@ -520,7 +523,7 @@ fn build_sibling_rank(
         .filter_map(|li| local_to_global.get(*li).copied())
         .collect();
     let ranked = ranked_items_subset(group, &comp_global, 10000, 1e-8);
-    let position = ranked.iter().position(|r| &r.item == item)? + 1;
+    let position = ranked.iter().position(|r| r.item == item)? + 1;
     Some(SiblingRank {
         position,
         component_size: ranked.len(),
@@ -597,7 +600,9 @@ fn build_item_page_view_model(
         .content_for_scope(scope)
         .unwrap_or_else(|| reduced.public());
     let item_key = CanonicalItemUrl::parse(item)
-        .unwrap_or_else(|| CanonicalItemUrl::parse("~/").unwrap());
+        .unwrap_or_else(|| CanonicalItemUrl::parse("~/").unwrap())
+        .normalized_storage();
+    let item_has_parent = item_key.parent().is_some();
     let child_rankings = build_children_rankings(content, &item_key);
 
     let rank_history = build_rank_history(reduced, scope, item_key.as_str());
@@ -617,6 +622,7 @@ fn build_item_page_view_model(
             .cloned()
             .or_else(|| reduced.public().item_bodies.get(&item_key).cloned()),
         sibling_rank: build_sibling_rank(reduced, scope, &item_key),
+        item_has_parent,
         child_rankings,
         rank_history,
         threads,
@@ -652,7 +658,7 @@ async fn render_scope_view(
                             (format!("#{} of {}", rank.position, rank.component_size))
                         }
                         span class="muted" { (format!("({} siblings)", rank.sibling_total)) }
-                    } @else {
+                    } @else if model.item_has_parent {
                         span class="muted" { "unranked among siblings" }
                     }
                 }
@@ -815,6 +821,18 @@ mod tests {
         }));
     }
 
+    fn apply_ingest_room(state: &mut ReducerState, ts: i64, room_id: &str, raw: &str) {
+        state.apply_event(Event::Ingest(Ingest {
+            ts,
+            id: format!("ing-{ts}"),
+            raw: raw.to_string(),
+            principal: "testuser".to_string(),
+            delegate: Some("00000000-0000-0000-0000-000000000000:test:local/test".to_string()),
+            room_id: room_id.to_string(),
+            thread_tag: String::new(),
+        }));
+    }
+
     #[test]
     fn item_page_model_includes_body_and_unranked_without_votes() {
         let mut reduced = ReducerState::default();
@@ -885,4 +903,85 @@ mod tests {
                 || model.child_rankings.unranked_items.contains(&CanonicalItemUrl("https://slug.social/~/topic/kid2".to_string()))
         );
     }
+
+    #[test]
+    fn item_page_room_scope_root_lists_top_level_children() {
+        let mut reduced = ReducerState::default();
+        apply_ingest_room(
+            &mut reduced,
+            1,
+            "9ab12cd/my-room",
+            "@00000000-0000-0000-0000-000000000000:test:local/test\n~/t1 {a}\n~/t2 {b}\n",
+        );
+        use crate::path_types::CanonicalItemUrl;
+        let root = CanonicalItemUrl::ontology_root();
+        let model = build_item_page_view_model(
+            &reduced,
+            &ScopeId::Room("9ab12cd/my-room".to_string()),
+            root.as_str(),
+        );
+        assert!(!model.item_has_parent);
+        assert_eq!(model.child_rankings.unranked_items.len(), 2);
+        let set: std::collections::HashSet<&str> = model
+            .child_rankings
+            .unranked_items
+            .iter()
+            .map(|u| u.as_str())
+            .collect();
+        assert!(set.contains("https://slug.social/~/t1"));
+        assert!(set.contains("https://slug.social/~/t2"));
+    }
+
+    /// Top-level `~/a` vs `~/b` votes form one ranked component under the ontology root.
+    #[test]
+    fn item_page_room_scope_root_shows_ranked_child_group() {
+        let mut reduced = ReducerState::default();
+        apply_ingest_room(
+            &mut reduced,
+            1,
+            "9ab12cd/my-room",
+            "@00000000-0000-0000-0000-000000000000:test:local/test\n\
+             ~/a {a}\n~/b {b}\n~/a 2:1 ~/b {because}\n",
+        );
+        use crate::path_types::CanonicalItemUrl;
+        let root = CanonicalItemUrl::ontology_root();
+        let model = build_item_page_view_model(
+            &reduced,
+            &ScopeId::Room("9ab12cd/my-room".to_string()),
+            root.as_str(),
+        );
+        assert_eq!(model.child_rankings.component_rankings.len(), 1);
+        assert_eq!(model.child_rankings.component_rankings[0].pairs, 1);
+        let names: Vec<&str> = model.child_rankings.component_rankings[0]
+            .ranked
+            .iter()
+            .map(|r| r.item.as_str())
+            .collect();
+        assert_eq!(
+            names,
+            vec!["https://slug.social/~/a", "https://slug.social/~/b"]
+        );
+        assert!(model.child_rankings.unranked_items.is_empty());
+    }
+
+    /// Legacy `https://slug.social/~/` spelling still resolves children under the real root key.
+    #[test]
+    fn item_page_model_normalizes_legacy_tilde_root_storage_url() {
+        let mut reduced = ReducerState::default();
+        apply_ingest(
+            &mut reduced,
+            1,
+            "@00000000-0000-0000-0000-000000000000:test:local/test\n~/x {x}\n",
+        );
+        let model = build_item_page_view_model(
+            &reduced,
+            &ScopeId::Public,
+            "https://slug.social/~/",
+        );
+        assert_eq!(model.child_rankings.unranked_items.len(), 1);
+        assert_eq!(
+            model.child_rankings.unranked_items[0].as_str(),
+            "https://slug.social/~/x"
+        );
+    }
 }
diff --git a/server/src/path_types.rs b/server/src/path_types.rs
index 4c8075bbd488f1b9a5eda9e03ced83f6238c6d5e..361a9d446c9043cbdea5f060db2e8633c2fd9bf9 100644
--- a/server/src/path_types.rs
+++ b/server/src/path_types.rs
@@ -1,3 +1,5 @@
 //! Re-exports — implementations live in `slug-types` (`paths` module).
 
-pub use slug_types::paths::{CanonicalItemUrl, RelativePath, TildePath};
+pub use slug_types::paths::{
+    tilde_http_path_to_canonical, CanonicalItemUrl, RelativePath, TildeHttpPathTail, TildePath,
+};
diff --git a/server/src/scope_rank.rs b/server/src/scope_rank.rs
index dc640848232b7e79142bfeeea3003c9023f84854..d656b2f0a0a3623ca6b234b746beaaca8ae6017d 100644
--- a/server/src/scope_rank.rs
+++ b/server/src/scope_rank.rs
@@ -149,9 +149,10 @@ pub fn build_rankings_for_item_set(content: &ContentState, items_in_scope: &[Can
 /// Build connected-component rankings for direct children of parent_scope.
 /// Matches the HTML garden view: multiple components, isolates, no-vote items.
 pub fn build_children_rankings(content: &ContentState, parent: &CanonicalItemUrl) -> ChildrenRankings {
+    let parent = parent.clone().normalized_storage();
     let items: Vec<CanonicalItemUrl> = content
         .item_children
-        .get(parent)
+        .get(&parent)
         .map(|s| s.iter().cloned().collect())
         .unwrap_or_default();
     build_rankings_for_item_set(content, &items)
diff --git a/server/tests/integration.rs b/server/tests/integration.rs
index f9c218378f6a173e56ae1cec797b3c492986eac0..d4c5bfe9c6f1c71dc61878bd8c5e729b1b7c69ef 100644
--- a/server/tests/integration.rs
+++ b/server/tests/integration.rs
@@ -704,6 +704,62 @@ async fn test_private_room_post_links_use_private_garden_routes() {
     assert!(garden_body.contains(&format!("/r/{room_short}/{room_slug}/t/garden-thread")));
 }
 
+#[tokio::test]
+async fn test_private_room_garden_root_lists_top_level_tilde_children() {
+    let (addr, _tmp, _log, _handle) = create_test_server().await;
+    let client = reqwest::Client::builder()
+        .redirect(reqwest::redirect::Policy::none())
+        .build()
+        .unwrap();
+    let bearer = test_bearer();
+
+    let create = rpc_batch(
+        &client,
+        addr,
+        Some(&bearer),
+        serde_json::json!([{
+            "RoomCreate": { "slug": "garden-root-list" }
+        }]),
+    )
+    .await;
+    let room_id = create["results"][0]["result"]["RoomCreated"]["room_id"]
+        .as_str()
+        .unwrap()
+        .to_string();
+    let (room_short, room_slug) = room_id.split_once('/').unwrap();
+
+    let rpc = ui_post_ingest_rpc(
+        &room_id,
+        "ing",
+        "~/test1 {wow}\n~/test2 {wow2}\n~/test1 2:1 ~/test2 {because}\n",
+    );
+    let post = client
+        .post(format!("http://{addr}/ui"))
+        .header("Authorization", format!("Bearer {bearer}"))
+        .form(&[("__rpc__", rpc.as_str())])
+        .send()
+        .await
+        .unwrap();
+    assert_eq!(post.status(), reqwest::StatusCode::OK);
+
+    let root_page = client
+        .get(format!("http://{addr}/r/{room_short}/{room_slug}/~"))
+        .header("Authorization", format!("Bearer {bearer}"))
+        .send()
+        .await
+        .unwrap();
+    assert!(root_page.status().is_success());
+    let body = root_page.text().await.unwrap();
+ 

… preview truncated; 14,119 characters omitted

download full diff B

Hardlinks — judgments / attempts / prompt

prompt download

judgments

attempts

Prompt text is loaded only by the download route.