constitution · epochs · watch · epoch 3

comparison

c_df12ba3b70a8 (tommy-mor) vs c_25172cf8caa0 (tommy-mor)

download prompt · raw event · cmp_ef49eae4f2528c

council reasoning

~anthropic/claude-sonnet-latest · winner B · 6:4 · permalink

Side B fixes a real concurrency/correctness bug (a shared sentinel delegate binding on first vote silently blocked every other human voter) with a minimal, well-targeted change plus a multi-user regression test proving the fix. Side A adds substantial new feature surface (GitHub import cards, resolver module split, external-root fix) which is valuable but larger/noisier and mostly additive feature work rather than a critical correctness fix; B's change prevents active user-facing breakage, giving it slightly more lasting value per line changed.

~x-ai/grok-latest · winner B · 2:5 · permalink

B fixes a core multi-user correctness bug: shared WEB_BROWSER_AGENT/INVITE_BROWSER_AGENT caused AgentBound on first browser vote and blocked every later human; PendingSession.agent becomes Option, UI posts pass no delegate, and a two-user vote integration test locks it in. A’s /- external-root fix and GitHub card/resolvers work are real lasting value, but much of the patch is a module move plus richer import UI, which matters less than unblocking multi-user voting.

openai/gpt-chat-latest · winner A · 4:1 · permalink

Side A fixes a real functional bug where the external garden index (`/-/`) appeared empty by introducing `external_root_host_items`, and it also adds a durable resolver architecture (`server/src/resolvers/`) with GitHub import-card storage/rendering, integration into item rendering, and accompanying tests. Side B is a valuable correctness fix—removing browser sentinel delegates so browser users no longer share a delegate and multi-user voting works correctly—but it is a narrower authentication/data-model change centered on making browser sessions use `None` delegates and updating attribution and tests.

sides

A — c_df12ba3b70a8 (tommy-mor)

message

[23c8134e] Fix /-/ external garden index; resolvers/ + GitHub import cards (#150)

* Fix external garden root listing; add resolvers/ with GitHub cards

The public and room external index pages queried children of a bogus
https://./ parent, so /-/ always looked empty. Collect host-only https
roots from all Web items and item_children edges so ghost parents from
add_child_edge appear.

Move GitHub resolver into server/src/resolvers/ with default_external.rs
and a try_render_resolver_item_body hook. Resolver ingests now store
slug-github-card fenced JSON; render_item_body_in_scope shows a small
GitHub article card (with legacy support for schema-less json fences on
github.com URLs). Styling in theme_default.css; agents.md updated.

Co-authored-by: tommy <thmorriss@gmail.com>

* Vote compare: GitHub cards in columns, layout CSS, tests

Pass item_bodies into vote_compare_item_card for linkified tooltips on
non-card bodies; clone item_bodies before dropping reducer read guard.

Add layout rules so rich cards sit in the grid corners (default + retro).

Unit test on vote_compare_item_card; integration GET /vote/compare with
ingested slug-github-card bodies. agents.md clarifies compare columns.

Co-authored-by: tommy <thmorriss@gmail.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>

diff preview

diff --git a/agents.md b/agents.md
index 7508234d9b04223d0e64cfe69fedbebd06a256b5..d8b801e454fdf37e7ac6038b91a69f83b0746d59 100644
--- a/agents.md
+++ b/agents.md
@@ -42,7 +42,7 @@ Strict **CSP** that blocks `eval` would break the current app. Other projects ma
 
 - **`VoteComparePost`:** On success returns **`text/javascript`** that **morphs** **`#vote-edge-history-region`** (recomputed **`<ul>`** — ratios match **`left`/`right`** query order, bullets, sorted by strength toward **`left`** then newer) and **`.vote-compare-nav`** (fresh next-pair link). The compare **`GET`** page uses **`layout_full_bleed_chromeless`** (no breadcrumbs, no **`#controls`**, no **`slug-pin-hud`**; **`view-vote-compare-fullscreen`** full-width **`body`**). **`__rpc__`** carries **`form_action: "/ui"`**; **`thread_tag`** and ratio fields come from the same form as **`$form`** holes.
 
-- **`ResolveExternal`:** GitHub resolver buttons are browser actions through **`POST /ui`**. Success responses morph **`#external-resolver-status`** then redirect to the sanitized shareable **`GET`** page so imported children render through the normal page path; errors morph the same status region. Resolver results are durable system ingests, while cooldown state is RAM-only.
+- **`ResolveExternal`:** GitHub resolver buttons are browser actions through **`POST /ui`**. Success responses morph **`#external-resolver-status`** then redirect to the sanitized shareable **`GET`** page so imported children render through the normal page path; errors morph the same status region. Resolver results are durable system ingests, while cooldown state is RAM-only. Implementation lives under **`server/src/resolvers/`** (GitHub resolver + import card JSON); ontology item pages and the **`GET /vote/compare`** left/right columns use **`render_item_body_in_scope`** in **`server/src/html/mod.rs`**, which calls **`server/src/resolvers/mod.rs::try_render_resolver_item_body`** before falling back to the usual **`<pre>`** linkified view.
 
 - **Garden pin / compare voting:** Cookie **`slug_garden_pin`** via **`set_garden_pin`**. Pairwise UI: **`GET /vote/compare?…`** / **`GET /r/:room_key/vote/compare?…`** (fullscreen **`GET`** page: no HUD; other garden pages). HUD (**`#slug-pin-hud`**): only when **`layout`** passes garden metadata on **`body`**; the label is **`POST /ui`** **`set_garden_pin`** **`clear:true`** (**`slug_ui.js`**), not a permalink to the item.
 
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index 4b0214d18b173cd506d09176104f461dc4c4f208..c9eb8e242072e41fcf70da838bdf02dd4c838db8 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -18,7 +18,7 @@ use crate::{
         rpc::{rpc_post_redact, rpc_post_with_bearer, rpc_room_delete},
     },
     canonical_path::canonicalize_tag,
-    external_resolver::resolve_github_children,
+    resolvers::resolve_github_children,
     html::vote_compare_post_success_js,
     html::{
         external_resolver_status_markup, fragment_new_thread_slot, login_to_post_hint_markup,
diff --git a/server/src/external_resolver.rs b/server/src/external_resolver.rs
deleted file mode 100644
index a5812250fed7613950b5417f396f886a55fafccf..0000000000000000000000000000000000000000
--- a/server/src/external_resolver.rs
+++ /dev/null
@@ -1,630 +0,0 @@
-use async_trait::async_trait;
-use serde_json::Value;
-use tokio::sync::oneshot;
-
-use crate::{path_types::ItemId, state::AppState, write_cmd::WriteCmd};
-
-const GITHUB_SYSTEM_PRINCIPAL: &str = "system:github-resolver";
-const GITHUB_RESOLVER_COOLDOWN_MS: i64 = 15_000;
-const GITHUB_MAX_PAGES: usize = 3;
-
-fn now_ms() -> i64 {
-    use std::time::{SystemTime, UNIX_EPOCH};
-    SystemTime::now()
-        .duration_since(UNIX_EPOCH)
-        .unwrap_or_default()
-        .as_millis() as i64
-}
-
-#[derive(Debug, Clone, PartialEq, Eq)]
-pub struct ResolvedChild {
-    pub url: String,
-    pub title: String,
-    pub body: Option<String>,
-}
-
-#[async_trait]
-pub trait ExternalResolver: Send + Sync {
-    /// e.g. `"github.com"`
-    fn domain_match(&self) -> &'static str;
-
-    /// Normalizes URLs (e.g. stripping fragments); extend per-domain later.
-    fn normalize(&self, path: &str) -> String;
-
-    /// Fetches body when missing; GitHub hook lands here in a follow-up.
-    async fn fetch_body(&self, item: &ItemId) -> Result<String, String>;
-}
-
-#[derive(Clone)]
-pub struct GitHubResolver {
-    client: reqwest::Client,
-    api_base_url: String,
-    token: Option<String>,
-}
-
-impl GitHubResolver {
-    pub fn from_env() -> Self {
-        let api_base_url = std::env::var("SLUG_GITHUB_API_BASE_URL")
-            .ok()
-            .filter(|s| !s.trim().is_empty())
-            .unwrap_or_else(|| "https://api.github.com".to_string());
-        let token = std::env::var("SLUG_GITHUB_TOKEN")
-            .ok()
-            .filter(|s| !s.trim().is_empty());
-        Self {
-            client: reqwest::Client::new(),
-            api_base_url: api_base_url.trim_end_matches('/').to_string(),
-            token,
-        }
-    }
-
-    pub fn can_resolve_children(&self, item: &ItemId) -> bool {
-        github_segments(item).is_some()
-    }
-
-    pub async fn list_children(&self, item: &ItemId) -> Result<Vec<ResolvedChild>, String> {
-        let segments = github_segments(item).ok_or_else(|| "not a GitHub URL".to_string())?;
-        match segments.as_slice() {
-            [] => Ok(vec![]),
-            [owner] => self.list_repos(owner).await,
-            [owner, repo] => Ok(github_repo_sections(owner, repo)),
-            [owner, repo, section] if section == "issues" => self.list_issues(owner, repo).await,
-            [owner, repo, section] if section == "pulls" => self.list_pulls(owner, repo).await,
-            [owner, repo, section] if section == "commits" => self.list_commits(owner, repo).await,
-            [owner, repo, section] if section == "releases" => {
-                self.list_releases(owner, repo).await
-            }
-            _ => Ok(vec![]),
-        }
-    }
-
-    async fn get_json(&self, path: &str) -> Result<Value, String> {
-        let url = format!("{}/{}", self.api_base_url, path.trim_start_matches('/'));
-        let mut req = self
-            .client
-            .get(url)
-            .header(reqwest::header::USER_AGENT, "slugsocial-github-resolver");
-        if let Some(token) = &self.token {
-            req = req.bearer_auth(token);
-        }
-        let resp = req
-            .send()
-            .await
-            .map_err(|e| format!("GitHub request failed: {e}"))?;
-        let status = resp.status();
-        if !status.is_success() {
-            return Err(format!("GitHub request returned {status}"));
-        }
-        resp.json::<Value>()
-            .await
-            .map_err(|e| format!("GitHub response JSON failed: {e}"))
-    }
-
-    async fn get_json_array_pages(&self, path: &str) -> Result<Vec<Value>, String> {
-        let sep = if path.contains('?') { '&' } else { '?' };
-        let mut out = Vec::new();
-        for page in 1..=GITHUB_MAX_PAGES {
-            let value = self.get_json(&format!("{path}{sep}page={page}")).await?;
-            let arr = value
-                .as_array()
-                .ok_or_else(|| "GitHub paged response was not an array".to_string())?;
-            let n = arr.len();
-            out.extend(arr.iter().cloned());
-            if n < 100 {
-                break;
-            }
-        }
-        Ok(out)
-    }
-
-    async fn list_repos(&self, owner: &str) -> Result<Vec<ResolvedChild>, String> {
-        let arr = self
-            .get_json_array_pages(&format!(
-                "/users/{owner}/repos?per_page=100&sort=updated&type=owner"
-            ))
-            .await?;
-        let mut out = Vec::new();
-        for repo in &arr {
-            let name = repo
-                .get("name")
-                .and_then(|v| v.as_str())
-                .unwrap_or_default();
-            if name.is_empty() {
-                continue;
-            }
-            let full_name = repo
-                .get("full_name")
-                .and_then(|v| v.as_str())
-                .map(|s| s.to_ascii_lowercase())
-                .unwrap_or_else(|| format!("{owner}/{name}").to_ascii_lowercase());
-            out.push(ResolvedChild {
-                url: format!("https://github.com/{full_name}"),
-                title: full_name.clone(),
-                body: Some(github_repo_body(repo)),
-            });
-        }
-        out.sort_by(|a, b| a.url.cmp(&b.url));
-        Ok(out)
-    }
-
-    async fn list_issues(&self, owner: &str, repo: &str) -> Result<Vec<ResolvedChild>, String> {
-        let arr = self
-            .get_json_array_pages(&format!(
-                "/repos/{owner}/{repo}/issues?state=open&per_page=100"
-            ))
-            .await?;
-        let mut out = Vec::new();
-        for issue in &arr {
-            if issue.get("pull_request").is_some() {
-                continue;
-            }
-            let Some(number) = issue.get("number").and_then(|v| v.as_i64()) else {
-                continue;
-            };
-            let title = issue
-                .get("title")
-                .and_then(|v| v.as_str())
-                .unwrap_or("Untitled issue");
-            out.push(ResolvedChild {
-                url: format!("https://github.com/{owner}/{repo}/issues/{number}"),
-                title: format!("#{number} {title}"),
-                body: Some(github_issue_body(issue, "issue")),
-            });
-        }
-        out.sort_by(|a, b| a.url.cmp(&b.url));
-        Ok(out)
-    }
-
-    async fn list_pulls(&self, owner: &str, repo: &str) -> Result<Vec<ResolvedChild>, String> {
-        let arr = self
-            .get_json_array_pages(&format!(
-                "/repos/{owner}/{repo}/pulls?state=open&per_page=100"
-            ))
-            .await?;
-        let mut out = Vec::new();
-        for pull in &arr {
-            let Some(number) = pull.get("number").and_then(|v| v.as_i64()) else {
-                continue;
-            };
-            let title = pull
-                .get("title")
-                .and_then(|v| v.as_str())
-                .unwrap_or("Untitled pull request");
-            out.push(ResolvedChild {
-                url: format!("https://github.com/{owner}/{repo}/pulls/{number}"),
-                title: format!("#{number} {title}"),
-                body: Some(github_issue_body(pull, "pull request")),
-            });
-        }
-        out.sort_by(|a, b| a.url.cmp(&b.url));
-        Ok(out)
-    }
-
-    async fn list_commits(&self, owner: &str, repo: &str) -> Result<Vec<ResolvedChild>, String> {
-        let arr = self
-            .get_json_array_pages(&format!("/repos/{owner}/{repo}/commits?per_page=100"))
-            .await?;
-        let mut out = Vec::new();
-        for commit in &arr {
-            let Some(sha) = github_string(commit, "sha") else {
-                continue;
-            };
-            let short = sha.chars().take(7).collect::<String>();
-            let title = commit
-                .get("commit")
-                .and_then(|c| c.get("message"))
-                .and_then(|v| v.as_str())
-                .and_then(|m| m.lines().next())
-                .filter(|s| !s.trim().is_empty())
-                .unwrap_or("commit");
-            let url = github_string(commit, "html_url")
-                .map(|s| s.to_string())
-                .unwrap_or_else(|| format!("https://github.com/{owner}/{repo}/commit/{sha}"));
-            out.push(ResolvedChild {
-                url,
-                title: format!("{short} {title}"),
-                body: Some(github_commit_body(commit)),
-            });
-        }
-        out.sort_by(|a, b| a.url.cmp(&b.url));
-        Ok(out)
-    }
-
-    async fn list_releases(&self, owner: &str, repo: &str) -> Result<Vec<ResolvedChild>, String> {
-        let arr =

… preview truncated; 60,917 characters omitted

download full diff A

B — c_25172cf8caa0 (tommy-mor)

message

[b9476669] Remove browser sentinel delegates so multi-user votes work.

Shared WEB_BROWSER_AGENT bound on first vote and blocked every later human; browser posts now use no delegate, matching forum UI.

Co-authored-by: Cursor <cursoragent@cursor.com>

diff preview

diff --git a/cli/src/main.rs b/cli/src/main.rs
index c4f1494df3aedbd8b883aea6249579aa8336abfe..af3e4fee876910a44f6f872b24821bc541a23e20 100644
--- a/cli/src/main.rs
+++ b/cli/src/main.rs
@@ -1741,8 +1741,8 @@ async fn run() -> Result<()> {
                     tokio::time::sleep(std::time::Duration::from_millis(poll_interval_ms)).await;
                     let poll: PendingSessionPollResponse =
                         expect_json(client.get(&poll_url).send().await?).await?;
-                    if !poll.agent.trim().is_empty() {
-                        agent_out = Some(poll.agent.clone());
+                    if let Some(a) = poll.agent.as_deref().map(str::trim).filter(|s| !s.is_empty()) {
+                        agent_out = Some(a.to_string());
                     }
                     if poll.complete {
                         token_out = poll.token;
diff --git a/server/src/api/auth.rs b/server/src/api/auth.rs
index 50dc6af908412b16343829eae25154ebf4e19fca..01c02f50c19bcd62c7f1717f9b927f203c3164d0 100644
--- a/server/src/api/auth.rs
+++ b/server/src/api/auth.rs
@@ -29,18 +29,6 @@ use crate::{
     write_cmd::WriteCmd,
 };
 
-/// Delegate id for browser users who land via `/join/inv_…` (no CLI agent).
-const INVITE_BROWSER_AGENT: &str = "00000000-0000-0000-0000-000000000000:invite:web/join";
-
-/// Agent id for `/login` browser OAuth (no CLI); must pass [`parse_agent`].
-pub const WEB_BROWSER_AGENT: &str = "00000000-0000-0000-0000-000000000001:social:web/browser";
-
-/// True for well-known browser / human-form sentinel delegates (not real AI agents).
-/// HTML attribution should show the human username for these, not `@@uuid:rig:…`.
-pub fn is_browser_sentinel_delegate(agent: &str) -> bool {
-    agent == WEB_BROWSER_AGENT || agent == INVITE_BROWSER_AGENT
-}
-
 /// HttpOnly cookie storing the same `slug_*` bearer string the CLI uses.
 pub const SLUG_SESSION_COOKIE: &str = "slug_session";
 
@@ -288,7 +276,7 @@ pub async fn get_join_invite(
     let session = format!("p_{}", uuid::Uuid::new_v4().simple());
     let redirect_next = safe_local_redirect(q.next.as_deref().or(q.redirect.as_deref()));
     let s = PendingSession {
-        agent: INVITE_BROWSER_AGENT.to_string(),
+        agent: None,
         created_ts: now_ms(),
         provider: None,
         provider_id: None,
@@ -555,7 +543,7 @@ pub async fn post_choose_username(
     };
 
     let sessions = pending_sessions(&state);
-    let (provider, provider_id, agent) = {
+    let (provider, provider_id) = {
         let sessions_read = sessions.read().await;
         let Some(s) = sessions_read.get(&form.session) else {
             return api_error(StatusCode::NOT_FOUND, "unknown session", None).into_response();
@@ -566,14 +554,9 @@ pub async fn post_choose_username(
         let Some(provider_id) = s.provider_id.clone() else {
             return js_form_error_fragment(&form.session, "oauth not completed").into_response();
         };
-        (provider, provider_id, s.agent.clone())
+        (provider, provider_id)
     };
 
-    if let Err(msg) = parse_agent(&agent) {
-        return js_form_error_fragment(&form.session, &format!("invalid agent format — {msg}"))
-            .into_response();
-    }
-
     let redeem_invite = {
         let sessions_read = sessions.read().await;
         sessions_read
@@ -643,7 +626,8 @@ pub async fn get_web_login(
     let redirect_next = safe_local_redirect(q.next.as_deref().or(q.redirect.as_deref()))
         .or_else(|| Some("/".to_string()));
     let s = PendingSession {
-        agent: WEB_BROWSER_AGENT.to_string(),
+        // Humans sign in via the website with no AI delegate.
+        agent: None,
         created_ts: now_ms(),
         provider: None,
         provider_id: None,
@@ -704,7 +688,7 @@ pub async fn post_pending_session(
     );
     let poll_url = format!("/api/v0/pending-session/{session}");
     let s = PendingSession {
-        agent: agent_naked,
+        agent: Some(agent_naked),
         created_ts: now_ms(),
         provider: None,
         provider_id: None,
diff --git a/server/src/api/mod.rs b/server/src/api/mod.rs
index fdff6db0472b36cd7870a4be68574023e0daf120..920e967b47852ea82fa61b84c457ae3582dd9800 100644
--- a/server/src/api/mod.rs
+++ b/server/src/api/mod.rs
@@ -18,13 +18,11 @@ pub use auth::{
     get_choose_username,
     get_web_login,
     get_logout,
-    is_browser_sentinel_delegate,
     optional_principal,
     resolve_web_session,
     session_cookie_header_value,
     WebSession,
     SLUG_SESSION_COOKIE,
-    WEB_BROWSER_AGENT,
 };
 
 pub use helpers::{
diff --git a/server/src/api/ui_html.rs b/server/src/api/ui_html.rs
index 611956d0a46062b49ce350be176e4be139312ff0..6e56c039a184953cd1d0593c34cf4d5abe41f2a3 100644
--- a/server/src/api/ui_html.rs
+++ b/server/src/api/ui_html.rs
@@ -277,7 +277,7 @@ async fn dispatch_ui_action(
                 &session.bearer,
                 room.clone(),
                 thread_tag.clone(),
-                Some(crate::api::auth::WEB_BROWSER_AGENT.to_string()),
+                None,
                 text,
             )
             .await
diff --git a/server/src/html/mod.rs b/server/src/html/mod.rs
index 645d54f2e117ba901e02ed958ada6ff69a78ae34..03ad762e88709c77b9d5dd130c48bc96226616a1 100644
--- a/server/src/html/mod.rs
+++ b/server/src/html/mod.rs
@@ -560,27 +560,28 @@ fn identity_color_css(seed: &str) -> String {
     format!("hsl({hue}, 62%, 66%)")
 }
 
-/// Seed for author color: real AI → delegate uuid; human/sentinel → principal username.
+/// Seed for author color: AI → delegate uuid; human (no delegate) → principal username.
 fn authorship_color_seed<'a>(principal: &'a str, delegate: &'a Option<String>) -> &'a str {
     match delegate {
-        Some(d) if !crate::api::is_browser_sentinel_delegate(d) => {
-            d.split(':').next().filter(|s| !s.is_empty()).unwrap_or(d.as_str())
-        }
-        _ => principal,
+        Some(d) => d
+            .split(':')
+            .next()
+            .filter(|s| !s.is_empty())
+            .unwrap_or(d.as_str()),
+        None => principal,
     }
 }
 
-/// Prefer the AI delegate in attribution; fall back to the human username when there is no
-/// delegate or the delegate is a browser/human-form sentinel.
+/// Prefer the AI delegate in attribution; humans post with no delegate and show `@username`.
 pub(crate) fn authorship_attr(principal: &str, delegate: &Option<String>) -> AuthorshipAttr {
     let color = identity_color_css(authorship_color_seed(principal, delegate));
     match delegate {
-        Some(d) if !crate::api::is_browser_sentinel_delegate(d) => AuthorshipAttr {
+        Some(d) => AuthorshipAttr {
             label: format!("@@{}", actor_label(d)),
             author_title: Some(format!("@{principal}")),
             color,
         },
-        _ => AuthorshipAttr {
+        None => AuthorshipAttr {
             label: format!("@{principal}"),
             author_title: None,
             color,
@@ -933,7 +934,6 @@ pub(super) fn recency_class(now_ms: i64, ts_ms: i64) -> &'static str {
 #[cfg(test)]
 mod authorship_tests {
     use super::*;
-    use crate::api::WEB_BROWSER_AGENT;
 
     #[test]
     fn human_or_missing_delegate_shows_username() {
@@ -943,15 +943,6 @@ mod authorship_tests {
         assert!(a.color.starts_with("hsl("));
     }
 
-    #[test]
-    fn browser_sentinel_delegate_shows_username() {
-        let d = Some(WEB_BROWSER_AGENT.to_string());
-        let a = authorship_attr("alice", &d);
-        assert_eq!(a.label, "@alice");
-        assert_eq!(a.author_title, None);
-        assert_eq!(authorship_address("alice", &d), "@alice");
-    }
-
     #[test]
     fn real_ai_delegate_shows_short_agent_with_username_hover() {
         let d = Some(
diff --git a/server/src/state.rs b/server/src/state.rs
index 648ab5304764a329fcabbbbcd3782b94e3e005a8..8ea84dcf9b1df8f8037e913cdd94e5908e6d5d55 100644
--- a/server/src/state.rs
+++ b/server/src/state.rs
@@ -21,7 +21,8 @@ pub struct InviteState {
 
 #[derive(Debug, Clone)]
 pub struct PendingSession {
-    pub agent: String,
+    /// CLI `identity start` delegate (`uuid:rig:model`). `None` for browser `/login` and `/join`.
+    pub agent: Option<String>,
     pub created_ts: i64,
     pub provider: Option<String>,
     pub provider_id: Option<String>,
diff --git a/server/tests/integration_ui.rs b/server/tests/integration_ui.rs
index 6b1475b773106a2dd3f326475c9fb4cc727f6b4b..714563a8b330e3917d95a54ae29b4de143e3b8a4 100644
--- a/server/tests/integration_ui.rs
+++ b/server/tests/integration_ui.rs
@@ -418,6 +418,99 @@ async fn test_web_login_carries_vote_pair_next_into_pending_session() {
     let sessions = state.pending_sessions.read().await;
     let pending = sessions.get(&session).expect("pending session");
     assert_eq!(pending.redirect_next.as_deref(), Some(next));
+    assert_eq!(
+        pending.agent, None,
+        "browser /login must not invent a sentinel delegate"
+    );
+}
+
+#[tokio::test]
+async fn test_vote_compare_two_users_both_succeed_without_delegate() {
+    let (addr, _tmp, _log, state, _handle) = create_test_server_with_state().await;
+    let client = reqwest::Client::new();
+    let alice = test_bearer();
+    let bob = seed_test_identity(&state, "bob", "bobtok", "bobsecret").await;
+
+    // Define items first (votes require existing item bodies).
+    let seed = ui_post_ingest_rpc(
+        "public",
+        "multi-vote",
+        "~/multi-a {alpha}\n~/multi-b {beta}\n",
+    );
+    let seed_resp = client
+        .post(format!("http://{addr}/ui"))
+        .header("Authorization", format!("Bearer {alice}"))
+        .form(&[("__rpc__", seed.as_str())])
+        .send()
+        .await
+        .unwrap();
+    assert_eq!(seed_resp.status(), reqwest::StatusCode::OK);
+    let seed_js = seed_resp.text().await.unwrap();
+    assert!(
+        !seed_js.contains("auth-error"),
+        "item seed must succeed, got: {seed_js}"
+    );
+
+    for (bearer, left, right, explanation) in [
+        (&alice, "3", "1", "alice prefers a"),
+        (&bob, "1", "3", "bob prefers b"),
+    ] {
+        let rpc = ui_vote_compare_post_rpc(
+            "public",
+            "multi-vote",
+            "~/multi-a",
+            "~/multi-b",
+            left,
+            right,
+            explanation,
+        );
+        let resp = client
+            .post(format!("http://{addr}/ui"))
+            .header("Authorization", format!("Bearer {bearer}"))
+            .form(&[("__rpc__", rpc.as_str())])
+            .send()
+            .await
+            .unwrap();
+        assert_eq!(resp.status(), reqwest::StatusCode::OK);
+        let js = resp.text().await.unwrap();
+        assert!(
+            !js.contains("delegate already bound"),
+            "human vote must not hit shared-sentinel AgentBound ({explanation}), got: {js}"
+        );
+        assert!(
+            !js.contains("auth-error"),
+            "human vote must succeed ({explanation}), got: {js}"
+        );
+        assert!(
+            js.contains("vote-edge-history-region"),
+            "vote should morph edge history ({explanation}), got: {js}"
+        );
+    }
+
+    let reduced = state.reduced.read().await;
+    let human_votes: Vec<_> = reduced
+        .ingests_ordered
+        .iter()
+        .filter_map(|id| reduced.ingests_by_id.get(id))
+        .filter(|ing| ing.raw.contains("prefers"))
+        .collect();
+    assert_eq!(human_votes.len(), 2, "expected two vote ingests");
+    let mut principals: Vec<&str> = human_votes.iter().map(|i| i.principal.as_str()).collect();
+    principals.sort();
+    assert_eq!(principals, ["bob", "testuser"]);
+    for ing in &human_votes {
+        assert!(
+            ing.delegate.is_none(),
+            "browser votes must have no delegate, principal={} delegate={:?}",
+            ing.principal,
+            ing.delegate
+        );
+    }
+    assert!(
+        reduced.agent_bindings.is_empty(),
+        "human

… preview truncated; 3,004 characters omitted

download full diff B

Hardlinks — judgments / attempts / prompt

prompt download

judgments

attempts

Prompt text is loaded only by the download route.