constitution · epochs · watch · epoch 3

comparison

c_afa638171cf7 (tommy-mor) vs c_c6f5afec1d36 (tommy-mor)

download prompt · raw event · cmp_d3d499b037fbc7

council reasoning

~anthropic/claude-sonnet-latest · winner A · 6:4 · permalink

Side A implements a meaningful identity-model change (UUID as canonical principal, multi-provider linking with conflict handling, privacy semantics) plus a full Reddit OAuth integration, backed by updated docs, mock servers, and unit tests validating trust-weight and link-owner behavior. Side B adds a useful but narrower UX feature (pool-scoped vote pairing) with reasonable but smaller-scope changes and no new tests, making it valuable but less foundational than A's identity/auth rework.

~x-ai/grok-latest · winner A · 3:1 · permalink

A redesigns canonical identity around UUID-only principals with multi-provider OAuth linking (including full Reddit OAuth, conflict handling, private linked-provider UI, trust-weight batch fixes, and test mocks)—foundational auth architecture. B adds a solid but narrower UX feature: optional pool-scoped pair selection and threading pool through vote navigation/UI, without comparable system-level depth.

openai/gpt-chat-latest · winner A · 3:1 · permalink

Side A makes a substantial architectural change by shifting identity to UUIDs with OAuth account linking, adding Reddit OAuth support, handling link conflicts, exposing linked providers privately, updating routing, storage queries, and fixing trust-weight projection batching with pending in-batch state. Side B adds a useful pool-scoped voting workflow and UI context propagation, but it is a narrower feature layered onto existing voting rather than a cross-cutting identity and authentication redesign.

sides

A — c_afa638171cf7 (tommy-mor)

message

[52f5c51c] Add Reddit OAuth linking and make UUID the only account identity.

OAuth providers only attach to a session UUID (first link creates the
principal); linked providers stay private on the account page.

Co-authored-by: Cursor <cursoragent@cursor.com>

diff preview

diff --git a/AGENTS.md b/AGENTS.md
index 6e0fd8ebb65d665c9c1438e3275971d62b98fd95..e9cc3173dbeb21ad0fc090ca7b407b027c7820a9 100644
--- a/AGENTS.md
+++ b/AGENTS.md
@@ -35,8 +35,11 @@ Environment variables (defaults in `server/src/state.rs`):
 - `SORTER2_DATA_DIR` — default `./data` (created on startup)
 - `SORTER2_EVENT_LOG` — default `{data_dir}/events.jsonl`
 - `SORTER2_BASE_URL` — public origin (also drives Secure cookies when `https://`)
-- `GITHUB_CLIENT_ID` / `GITHUB_CLIENT_SECRET` — GitHub OAuth (optional; login disabled if unset)
-- `SORTER2_ALLOW_MOCK_OAUTH=1` — allow `mock_user` on `/auth/github` (tests only)
+- `GITHUB_CLIENT_ID` / `GITHUB_CLIENT_SECRET` — GitHub OAuth linking (optional)
+- `REDDIT_CLIENT_ID` / `REDDIT_CLIENT_SECRET` (or `REDDIT_APP_*`) — Reddit API import + OAuth linking (optional)
+- `SORTER2_ALLOW_MOCK_OAUTH=1` — allow `mock_user` on `/auth/github` and `/auth/reddit` (tests only)
+
+Identity: UUID is canonical. OAuth providers only *link* to a UUID (first link creates the principal). Linked providers are private to the account owner.
 
 Health check: `GET /healthz` → `ok`.
 
diff --git a/server/src/auth/mod.rs b/server/src/auth/mod.rs
index 5906f93b13853421e96a3c37bc9d8202a47842bf..c706ae8045a811e5941f5f6c72da88f42a403a82 100644
--- a/server/src/auth/mod.rs
+++ b/server/src/auth/mod.rs
@@ -1,4 +1,8 @@
-//! GitHub OAuth login, session cookies, and vote actor resolution.
+//! OAuth linking, session cookies, and vote actor resolution.
+//!
+//! Canonical identity is a UUID. OAuth providers only *link* to that UUID
+//! (first link creates the principal; later links attach while logged in).
+//! Which providers are linked is private to the account owner.
 
 pub mod config;
 pub mod identity;
@@ -22,7 +26,9 @@ use crate::{
     form_template::template_json_compact,
     html::layout,
     state::AppState,
-    storage_schema::{oauth_link_owner, pseudonym_owner, Store, StoreFields},
+    storage_schema::{
+        linked_providers_for_uuid, oauth_link_owner, pseudonym_owner, Store, StoreFields,
+    },
     ui_action::UI_RPC_FIELD,
 };
 
@@ -53,10 +59,12 @@ fn new_actor_uuid() -> String {
 pub struct LoginQuery {
     #[serde(default)]
     pub return_to: Option<String>,
+    #[serde(default)]
+    pub error: Option<String>,
 }
 
 #[derive(Debug, Deserialize)]
-pub struct GitHubStartQuery {
+pub struct OAuthStartQuery {
     #[serde(default)]
     pub return_to: Option<String>,
     #[serde(default)]
@@ -72,15 +80,22 @@ fn return_from_query_or_jar(jar: &CookieJar, query: Option<&str>) -> String {
         .unwrap_or_else(|| "/".to_string())
 }
 
-fn oauth_providers(base_url: &str, return_to: &str) -> Vec<(&'static str, String)> {
+/// Available OAuth link targets: `(provider_key, label, start_href)`.
+fn oauth_providers(base_url: &str, return_to: &str) -> Vec<(&'static str, &'static str, String)> {
     let mut out = Vec::new();
+    let enc = urlencoding::encode(return_to);
     if oauth::GitHubConfig::from_env(base_url).is_some() {
         out.push((
-            "GitHub",
-            format!(
-                "/auth/github?return_to={}",
-                urlencoding::encode(return_to)
-            ),
+            "github",
+            oauth::provider_label("github"),
+            format!("/auth/github?return_to={enc}"),
+        ));
+    }
+    if oauth::RedditConfig::from_env(base_url).is_some() {
+        out.push((
+            "reddit",
+            oauth::provider_label("reddit"),
+            format!("/auth/reddit?return_to={enc}"),
         ));
     }
     out
@@ -125,23 +140,41 @@ fn alias_claim_forms(return_to: &str, submit_label: &str) -> Result<Markup, Stat
     })
 }
 
-fn signed_out_body(providers: &[(&str, String)]) -> Markup {
+fn login_error_message(code: Option<&str>) -> Option<&'static str> {
+    match code {
+        Some("oauth_taken") => {
+            Some("that OAuth account is already linked to a different sorter2 account")
+        }
+        Some("oauth_failed") => Some("OAuth failed — try again"),
+        _ => None,
+    }
+}
+
+fn signed_out_body(
+    providers: &[(&str, &str, String)],
+    error: Option<&str>,
+) -> Markup {
     html! {
         main class="panel login-page" {
             section class="login-section" {
                 h1 { "sign in" }
-                p class="muted" { "link an account to vote under a lasting alias" }
+                p class="muted" {
+                    "link an OAuth account to create your identity, then claim an alias to vote"
+                }
+                @if let Some(msg) = login_error_message(error) {
+                    p class="alias-bad" data-testid="login-error" { (msg) }
+                }
                 @if providers.is_empty() {
                     p class="muted" {
-                        "OAuth is not configured. Set GITHUB_CLIENT_ID and GITHUB_CLIENT_SECRET."
+                        "OAuth is not configured. Set GitHub and/or Reddit client credentials."
                     }
                 } @else {
                     ul class="oauth-provider-list" {
-                        @for (name, href) in providers {
+                        @for (key, label, href) in providers {
                             li {
                                 a href=(href) class="btn-primary oauth-provider"
-                                    data-testid=(format!("oauth-{}", name.to_lowercase())) {
-                                    (format!("Continue with {name}"))
+                                    data-testid=(format!("oauth-{key}")) {
+                                    (format!("Link {label}"))
                                 }
                             }
                         }
@@ -156,7 +189,10 @@ fn signed_out_body(providers: &[(&str, String)]) -> Markup {
 fn account_body(
     actor: &session::SessionActor,
     aliases: &[String],
-    providers: &[(&str, String)],
+    // Provider keys already linked to this UUID (private).
+    linked: &[String],
+    // Providers available to link: not yet attached.
+    unlinkable: &[(&str, &str, String)],
     claim_forms: Markup,
 ) -> Markup {
     let current = actor.pseudonym.trim();
@@ -212,16 +248,29 @@ fn account_body(
                 (claim_forms)
             }
 
-            @if !providers.is_empty() {
-                section class="login-section" {
-                    h2 { "linked sign-in" }
-                    p class="muted small" { "sign in again with the same provider to return to this account" }
+            section class="login-section" {
+                h2 { "linked sign-in" }
+                p class="muted small" {
+                    "private to you — linking more providers raises trust weight without publishing which accounts you use"
+                }
+                @if linked.is_empty() {
+                    p class="muted" data-testid="linked-providers-empty" { "none yet" }
+                } @else {
+                    ul class="linked-provider-list" data-testid="linked-providers" {
+                        @for key in linked {
+                            li data-testid=(format!("linked-{key}")) {
+                                (oauth::provider_label(key))
+                            }
+                        }
+                    }
+                }
+                @if !unlinkable.is_empty() {
                     ul class="oauth-provider-list" {
-                        @for (name, href) in providers {
+                        @for (key, label, href) in unlinkable {
                             li {
                                 a href=(href) class="btn-secondary oauth-provider"
-                                    data-testid=(format!("oauth-relink-{}", name.to_lowercase())) {
-                                    (format!("Re-link {name}"))
+                                    data-testid=(format!("oauth-link-{key}")) {
+                                    (format!("Link {label}"))
                                 }
                             }
                         }
@@ -243,12 +292,21 @@ fn account_body(
 fn login_body(
     session: Option<&session::SessionActor>,
     aliases: &[String],
-    providers: &[(&str, String)],
+    linked: &[String],
+    providers: &[(&str, &str, String)],
     claim_forms: Option<Markup>,
+    error: Option<&str>,
 ) -> Markup {
     match (session, claim_forms) {
-        (Some(actor), Some(forms)) => account_body(actor, aliases, providers, forms),
-        _ => signed_out_body(providers),
+        (Some(actor), Some(forms)) => {
+            let unlinkable: Vec<_> = providers
+                .iter()
+                .filter(|(key, _, _)| !linked.iter().any(|p| p == key))
+                .cloned()
+                .collect();
+            account_body(actor, aliases, linked, &unlinkable, forms)
+        }
+        _ => signed_out_body(providers, error),
     }
 }
 
@@ -268,6 +326,10 @@ pub async fn login_page(
         .as_ref()
         .map(|s| alias_list(db, &s.uuid))
         .unwrap_or_default();
+    let linked = session
+        .as_ref()
+        .map(|s| linked_providers_for_uuid(db, &s.uuid).unwrap_or_default())
+        .unwrap_or_default();
     let providers = oauth_providers(&base_url_from_env(state.cfg.port), &return_to);
 
     let claim_forms = if session.is_some() {
@@ -282,7 +344,14 @@ pub async fn login_page(
         } else {
             "login · sorter2"
         },
-        login_body(session.as_ref(), &aliases, &providers, claim_forms),
+        login_body(
+            session.as_ref(),
+            &aliases,
+            &linked,
+            &providers,
+            claim_forms,
+            query.error.as_deref(),
+        ),
         state.views.get_views("/login"),
         session
             .as_ref()
@@ -302,7 +371,6 @@ pub async fn alias_page(
     let db = state.projection_store.db();
     let session = session::load_valid_session(db, &session_id).ok_or(StatusCode::UNAUTHORIZED)?;
     if session::session_has_pseudonym(&session) {
-        // Already onboarded — manage aliases on the account page.
         return Ok(Redirect::to("/login").into_response());
     }
 
@@ -331,7 +399,7 @@ pub async fn alias_page(
 pub async fn github_start(
     State(state): State<AppState>,
     jar: CookieJar,
-    Query(query): Query<GitHubStartQuery>,
+    Query(query): Query<OAuthStartQuery>,
 ) -> Result<Response, StatusCode> {
     let cfg = oauth::GitHubConfig::from_env(&base_url_from_env(state.cfg.port))
         .ok_or(StatusCode::SERVICE_UNAVAILABLE)?;
@@ -342,7 +410,28 @@ pub async fn github_start(
     } else {
         None
     };
-    let url = oauth::authorize_url(&cfg, &state_token, mock_user);
+    let url = oauth::github_authorize_url(&cfg, &state_token, mock_user);
+    let jar = jar
+        .add(session::oauth_state_cookie_value(&state_token))
+        .add(session::auth_return_cookie_value(&return_to));
+    Ok((jar, Redirect::temporary(&url)).into_response())
+}
+
+pub async fn reddit_start(
+    State(state): State<AppState>,
+    jar: CookieJar,
+    Query(query): Query<OAuthStartQuery>,
+) -> Result<Response, StatusCode> {
+    let cfg = oauth::RedditConfig::from_env(&base_url_from_env(state.cfg.port))
+        .ok_or(StatusCode::SERVICE_UNAVAILABLE)?;
+    let return_to = return_from_query_or_jar(&jar, query.return_to.as_deref());
+    let state_token = session::new_oauth_state();
+    let mock_user = if config::mock_oauth_allowed() {
+        query.mock_user.as_deref()
+    } else {
+        None
+    };
+    let url = oauth::reddit_authorize_url(&cfg, &state_token, mock_user);
     let jar = jar
         .add(session::oauth_state_cookie_value(&state_token))
         .add(session::auth_return_cookie_value(&return_to));
@@ -355,6 +444,13 @@ pub struct OAuthCallbackQuery {
     pub state: String,
 }
 
+/// Link `provider:provider_id` to a UUID.
+///
+/// - Logged in + new provider → attach to session UUID
+/// - Logged in + already ours → no-op
+/// - Logged in 

… preview truncated; 29,823 characters omitted

download full diff A

B — c_c6f5afec1d36 (tommy-mor)

message

[5350388a] Add pool-scoped voting: /vote?pool=<parent> picks pairs from children.

- /vote now accepts an optional `pool` param (parent item path). When
  provided without left/right, it picks the first unvoted pair from the
  pool's children. When provided alongside left/right, it constrains
  "next pair" navigation to siblings within the pool.
- "vote on children" button appears on item pages with ≥2 children,
  linking to /vote?pool=<item>.
- Pool is threaded through VoteComparePost → success JS so in-page
  morph after voting keeps the pool context for next-pair navigation.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

diff preview

diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index 5faa642451d69555cb391974beb0ad22c9355c8c..b79efdb4d52bd445a67f38cbfd61d3507d2b3014 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -193,6 +193,7 @@ async fn dispatch_ui_action(
             ratio_right,
             explanation,
             next,
+            pool,
             form_action,
         } => {
             if form_action != "/ui" {
@@ -239,6 +240,9 @@ async fn dispatch_ui_action(
                         .into_response();
                 }
             };
+            let pool_id = pool.as_deref().and_then(|p| {
+                crate::path_types::ItemId::parse(p.trim()).map(|i| i.normalized_storage())
+            });
             let mut rl = ratio_left.trim().parse::<i32>().unwrap_or(0).max(0);
             let mut rr = ratio_right.trim().parse::<i32>().unwrap_or(0).max(0);
             if rl == 0 && rr == 0 {
@@ -294,6 +298,7 @@ async fn dispatch_ui_action(
                         &thread_tag,
                         &left_id,
                         &right_id,
+                        pool_id.as_ref(),
                         pid.as_str(),
                         post_index,
                     )
diff --git a/server/src/html/garden/pin.rs b/server/src/html/garden/pin.rs
index 5865cfdbc06aeb6555c97380e25591fae6b3d125..1820d7fe7ee167ecbf5ad5124f23b2ab92ffb01f 100644
--- a/server/src/html/garden/pin.rs
+++ b/server/src/html/garden/pin.rs
@@ -79,7 +79,7 @@ pub(super) fn ont_pin_vote_controls(
                         }
                     }
                 } @else {
-                    a class="ont-vote-compare-btn" href=(vote_compare_href(nav, pi, &current, None)) title="Compare and vote" {
+                    a class="ont-vote-compare-btn" href=(vote_compare_href(nav, pi, &current, None, None)) title="Compare and vote" {
                         span class="ont-vote-glyph" aria-hidden="true" { "⚖" }
                         span { "vote" }
                     }
@@ -121,7 +121,7 @@ pub(super) fn child_row_pin_or_vote(
                         if nv == 1 { "" } else { "s" },
                     );
                     @let aria = format!("Vote; {} pairwise {}", nv, if nv == 1 { "vote" } else { "votes" });
-                    a class="ont-garden-vote-ico" href=(vote_compare_href(nav, pi, row_item, None)) title=(tip) aria-label=(aria) {
+                    a class="ont-garden-vote-ico" href=(vote_compare_href(nav, pi, row_item, None, None)) title=(tip) aria-label=(aria) {
                         span class="ont-garden-vote-glyph" aria-hidden="true" { "⚖" }
                         span class="ont-garden-vote-count" { (format!("{}", nv)) }
                     }
diff --git a/server/src/html/garden/render.rs b/server/src/html/garden/render.rs
index 5c3986ca36902f6c9019a4b5590f0b3b9d2cb4ff..bd8cbce059ee789de6e8dc9b6f69f54beee2f994 100644
--- a/server/src/html/garden/render.rs
+++ b/server/src/html/garden/render.rs
@@ -29,6 +29,7 @@ use super::{
     item::{child_depth_from_uri, item_code_label, item_display_path, item_href},
     item_page::{build_item_page_view_model, sibling_nav_markup},
     pin::{child_row_pin_or_vote, ont_pin_vote_controls, pinned_item_from_jar},
+    vote::vote_pool_href,
 };
 
 pub(super) async fn render_scope_view(
@@ -186,12 +187,21 @@ pub(super) async fn render_scope_view(
             }
 
             section class="ont-tab-panel ont-tab-panel-children" {
+                @let total_children = model.child_rankings.component_rankings
+                    .iter().map(|c| c.ranked.len()).sum::<usize>()
+                    + model.child_rankings.unranked_items.len();
                 h3 {
                     "ranked child groups"
                     @if model.child_depth > 1 {
                         " "
                         span class="muted" { (format!("(depth {})", model.child_depth)) }
                     }
+                    @if total_children >= 2 {
+                        " "
+                        a class="ont-vote-children-btn" href=(vote_pool_href(&nav, &model.item)) {
+                            "vote on children"
+                        }
+                    }
                 }
                 @if model.child_rankings.component_rankings.is_empty() {
                     p class="muted" { "no voted pairs yet in this scope" }
diff --git a/server/src/html/garden/tests.rs b/server/src/html/garden/tests.rs
index 6900a6795bcde866a176722149d6378e5127b4c3..c2036fca7752aef63d260e36cfe9649f63b5c550 100644
--- a/server/src/html/garden/tests.rs
+++ b/server/src/html/garden/tests.rs
@@ -105,7 +105,7 @@ fn suggest_next_vote_pair_prefers_unvoted_sibling_pair() {
     let content = content_for_garden_view(&reduced, &ScopeId::Public);
     let a = ItemId::parse("~/topic/a").unwrap().normalized_storage();
     let b = ItemId::parse("~/topic/b").unwrap().normalized_storage();
-    let next = suggest_next_vote_pair(content, &a, &b).expect("next sibling pair");
+    let next = suggest_next_vote_pair(content, &a, &b, None).expect("next sibling pair");
     assert_ne!(
         canonical_edge_items(&next.0, &next.1),
         canonical_edge_items(&a, &b)
diff --git a/server/src/html/garden/vote.rs b/server/src/html/garden/vote.rs
index 1d7fc8aa7436bfa9c1186dfd940a8d751ab7e088..2682cfcbd2f834b56459a02831aa225cffe67c58 100644
--- a/server/src/html/garden/vote.rs
+++ b/server/src/html/garden/vote.rs
@@ -211,14 +211,15 @@ pub(crate) async fn vote_compare_post_success_js(
     _thread_tag: &str,
     left: &ItemId,
     right: &ItemId,
+    pool: Option<&ItemId>,
     _post_id: &str,
     _post_idx: Option<usize>,
 ) -> String {
     let reduced = state.reduced.read().await;
     let content = content_for_garden_view(&reduced, &nav.scope());
     let edge_history = vote_edge_history_markup(content, left, right);
-    let next_pair = suggest_next_vote_pair(content, left, right);
-    let nav_markup = vote_compare_nav_markup(nav, next_pair.as_ref());
+    let next_pair = suggest_next_vote_pair(content, left, right, pool);
+    let nav_markup = vote_compare_nav_markup(nav, next_pair.as_ref(), pool);
     drop(reduced);
     JsBuilder::new()
         .morph_inner_selector("#vote-edge-history-region", edge_history)
@@ -231,27 +232,39 @@ pub(super) fn vote_compare_href(
     left: &ItemId,
     right: &ItemId,
     thread_override: Option<&str>,
+    pool: Option<&ItemId>,
 ) -> String {
     let left_q = urlencoding::encode(left.as_str());
     let right_q = urlencoding::encode(right.as_str());
-    let base = format!(
+    let mut base = format!(
         "{}/vote?left={}&right={}",
         nav.room_path_prefix_for_vote_compare(),
         left_q,
         right_q
     );
     if let Some(t) = thread_override.filter(|s| !s.is_empty()) {
-        format!("{}&thread={}", base, urlencoding::encode(t))
-    } else {
-        base
+        base = format!("{}&thread={}", base, urlencoding::encode(t));
+    }
+    if let Some(p) = pool {
+        base = format!("{}&pool={}", base, urlencoding::encode(p.as_str()));
     }
+    base
+}
+
+pub(super) fn vote_pool_href(nav: &ThreadNav, pool_item_str: &str) -> String {
+    format!(
+        "{}/vote?pool={}",
+        nav.room_path_prefix_for_vote_compare(),
+        urlencoding::encode(pool_item_str)
+    )
 }
 
 fn vote_compare_nav_markup(
     nav: &ThreadNav,
     next_pair: Option<&(ItemId, ItemId)>,
+    pool: Option<&ItemId>,
 ) -> maud::Markup {
-    let next_pair_href = next_pair.map(|(nl, nr)| vote_compare_href(nav, nl, nr, None));
+    let next_pair_href = next_pair.map(|(nl, nr)| vote_compare_href(nav, nl, nr, None, pool));
     html! {
         div class="vote-compare-nav" {
             @if let Some(href) = &next_pair_href {
@@ -267,8 +280,15 @@ pub(super) fn suggest_next_vote_pair(
     content: &ContentState,
     current_left: &ItemId,
     current_right: &ItemId,
+    pool_parent: Option<&ItemId>,
 ) -> Option<(ItemId, ItemId)> {
-    let pool: Vec<ItemId> = if current_left.parent().as_ref().map(|p| p.as_str())
+    let pool: Vec<ItemId> = if let Some(parent) = pool_parent {
+        content
+            .item_children
+            .get(parent)
+            .map(|s| s.iter().cloned().collect())
+            .unwrap_or_default()
+    } else if current_left.parent().as_ref().map(|p| p.as_str())
         == current_right.parent().as_ref().map(|p| p.as_str())
     {
         current_left
@@ -322,10 +342,14 @@ pub(super) fn vote_compare_item_card(
 }
 #[derive(Debug, Deserialize)]
 pub struct VoteCompareQuery {
-    pub left: String,
-    pub right: String,
+    #[serde(default)]
+    pub left: Option<String>,
+    #[serde(default)]
+    pub right: Option<String>,
     #[serde(default)]
     pub thread: Option<String>,
+    #[serde(default)]
+    pub pool: Option<String>,
 }
 
 /// Public pairwise vote UI — `/vote?left=&right=&thread=`.
@@ -376,17 +400,53 @@ async fn vote_compare_inner(
     jar: CookieJar,
     uri: Uri,
 ) -> axum::response::Response {
-    let left = match ItemId::parse(q.left.trim()) {
-        Some(i) => i.normalized_storage(),
-        None => return (StatusCode::NOT_FOUND, "bad left item").into_response(),
+    let pool_id: Option<ItemId> = match q.pool.as_deref() {
+        Some(p) => match ItemId::parse(p.trim()) {
+            Some(i) => Some(i.normalized_storage()),
+            None => return (StatusCode::BAD_REQUEST, "bad pool item").into_response(),
+        },
+        None => None,
     };
-    let right = match ItemId::parse(q.right.trim()) {
-        Some(i) => i.normalized_storage(),
-        None => return (StatusCode::NOT_FOUND, "bad right item").into_response(),
+
+    let (left, right) = match (q.left.as_deref(), q.right.as_deref()) {
+        (Some(l), Some(r)) => {
+            let left = match ItemId::parse(l.trim()) {
+                Some(i) => i.normalized_storage(),
+                None => return (StatusCode::NOT_FOUND, "bad left item").into_response(),
+            };
+            let right = match ItemId::parse(r.trim()) {
+                Some(i) => i.normalized_storage(),
+                None => return (StatusCode::NOT_FOUND, "bad right item").into_response(),
+            };
+            if left == right {
+                return (StatusCode::BAD_REQUEST, "items must differ").into_response();
+            }
+            (left, right)
+        }
+        (None, None) => {
+            let Some(pool) = pool_id.as_ref() else {
+                return (StatusCode::BAD_REQUEST, "provide left+right or pool").into_response();
+            };
+            let reduced = state.reduced.read().await;
+            let content = content_for_garden_view(&reduced, &nav.scope());
+            let children: Vec<ItemId> = content
+                .item_children
+                .get(pool)
+                .map(|s| s.iter().cloned().collect())
+                .unwrap_or_default();
+            if children.len() < 2 {
+                drop(reduced);
+                return (StatusCode::BAD_REQUEST, "pool has fewer than 2 children to compare").into_response();
+            }
+            let pair = suggest_next_pair_in_pool(&content.ranking_group, &children, None);
+            drop(reduced);
+            match pair {
+                Some(p) => p,
+                None => return (StatusCode::BAD_REQUEST, "no pairs available in pool").into_response(),
+            }
+        }
+        _ => return (StatusCode::BAD_REQUEST, "provide both left and right, or just pool").into_response(),
     };
-    if left == right {
-        return (StatusCode::BAD_REQUEST, "items must differ").into_response();
-    }
 
     let reduced = state.reduced.read().await;
     let content = content_for_garden_view(&reduced, &nav.scope());
@@ -409,7 +469,7 @@ async fn vote_compare_inner(
     let left_body = content.item_bodies.get(&left).cloned();
     let right_body = content.item_bodies.get(&right).cloned();
     let item_bodies_for_cards = content.item_bodies.

… preview truncated; 1,501 characters omitted

download full diff B

Hardlinks — judgments / attempts / prompt

prompt download

judgments

attempts

Prompt text is loaded only by the download route.