gitoriaLog in with ident

tickets

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Main branchmainbb64d57cmission 012 (ticket #25 API part): every /api/projects/<x>/… route takes the project's id (12-char record id) as well as its slug, same answers byte for byte; tickets stay under their project, no global /api/tickets/<x>. gate 315/0 (old code: the 13 id checks fail), connect 60/0, live-data copy old vs new 1,484 identical, slug vs id 772 identicalmremain/login.js

3.4 KB

  1. // login.js — the small bridge between ident's <ident-selector> and the tickets shell
  2. // (components/main.hl; ticket #7). Plain JS because hl:webex cannot listen to a custom DOM
  3. // event: `ident-login` (event.detail.code, the one-time code) goes into the hidden input
  4. // #identcode, whose `change` the shell handles (→ face identLogin, server-side exchange).
  5. // The host tells the selector whether this site is logged in: the shell keeps the
  6. // element's class at `in` / `out`, mirrored here into its `loggedIn` property
  7. // (= the `logged-in` attribute; false = reset to "choose ident").
  8. //
  9. // RUNS ONCE PER DOCUMENT (ticket #9, mission 012). hl:webex re-creates the shell's header
  10. // and its <script> elements whenever the login state flips (login, logout): the browser
  11. // then executes this file AGAIN, and the selector element is a NEW one. The old version
  12. // added one more `ident-login` listener per run, so after a logout ONE selection fired
  13. // two `change`s → two exchanges of the same one-time code → the second one failed
  14. // ("ident refused the login (400: unknown or already used code)") although the first
  15. // had logged the user in. Now: one guarded install, listeners on `document` (the event
  16. // bubbles and is composed), the CURRENT #selector looked up each time, and a code is
  17. // handed to the shell at most once.
  18. //
  19. // LOGIN BUTTON (ticket #10): just before the browser follows "Log in with ident", its
  20. // return URL gets `?next=<this page's path + query>`; /login/callback checks it
  21. // (same-origin path only) and sends the user back there.
  22. (() => {
  23. if (window.__ticketsLogin) { window.__ticketsLogin.sync(); return; }
  24. const selector = () => document.getElementById('selector');
  25. const sync = () => {
  26. const sel = selector();
  27. // not upgraded yet: a property set now would shadow the element's own accessor
  28. if (!sel || !window.customElements || !customElements.get('ident-selector')) return;
  29. const want = sel.classList.contains('in');
  30. if (sel.loggedIn !== want) sel.loggedIn = want;
  31. };
  32. // the class flips, and whole new selector elements arrive (hl:webex re-renders the header)
  33. new MutationObserver(sync).observe(document.documentElement, { subtree: true, childList: true, attributes: true, attributeFilter: ['class'] });
  34. if (window.customElements) customElements.whenDefined('ident-selector').then(sync);
  35. const handed = new Set();
  36. document.addEventListener('ident-login', (e) => {
  37. const code = e.detail && e.detail.code;
  38. const input = document.getElementById('identcode');
  39. if (!input || !code || handed.has(code)) return; // a one-time code is exchanged once
  40. handed.add(code);
  41. input.value = code;
  42. input.dispatchEvent(new Event('change', { bubbles: true }));
  43. });
  44. // "Log in with ident": return to this page (the server accepts only a same-origin path)
  45. const withNext = (a) => {
  46. try {
  47. const u = new URL(a.href);
  48. const ret = new URL(u.searchParams.get('return'));
  49. const here = location.pathname + location.search;
  50. ret.search = '';
  51. if (here !== '/' && here.length <= 500) ret.searchParams.set('next', here);
  52. u.searchParams.set('return', ret.href);
  53. a.href = u.href;
  54. } catch (err) { /* keep the server's href: the login still works, it returns to / */ }
  55. };
  56. const onButton = (e) => {
  57. const a = e.target && e.target.closest && e.target.closest('#loginbutton');
  58. if (a) withNext(a);
  59. };
  60. for (const t of ['click', 'auxclick', 'contextmenu']) document.addEventListener(t, onButton, true);
  61. window.__ticketsLogin = { sync };
  62. })();

Branches

Latest commits

  • bb64d57cmission 012 (ticket #25 API part): every /api/projects/<x>/… route takes the project's id (12-char record id) as well as its slug, same answers byte for byte; tickets stay under their project, no global /api/tickets/<x>. gate 315/0 (old code: the 13 id checks fail), connect 60/0, live-data copy old vs new 1,484 identical, slug vs id 772 identicalmre
  • 7538b034mission 011 (ticket #25 web part): short page URLs /<slug> and /<slug>/<number>; /projects/<slug>, /projects/<slug>/<n>, /projects/<slug>/tickets/<n> and /tickets/<ref> answer 301 (current slug); slug pages moved behind hl:web's own routes after construction (they answered /__hl/* and /components/*.hl); reserved slugs refused; API paths unchanged. gate 293/0, connect 60/0, live-data copy 187/0, API old vs new: only page links differmre
  • 0369106emission 010 (code order) 4/4: README file map + import order + 'Same output' test, STATUS (entry, lessons, how to verify), LOG, report; tests/realdata-baseline.mjs + realdata-compare*.py (a cleanup answers the same on live data), tests/letcount.pymre
  • a75e0279mission 010 (code order) 3/4: let only where a variable is reassigned or re-bound in a loop body (456 lets → plain declarations; Hybriel refuses a plain declaration inside a loop on its 2nd pass). gate 249/0, connect 60/0, real-data reads identical, a 50-step write sequence (API + faces) identical to the old codemre
  • e9d5c618mission 010 (code order) 2/4: one lib/ file per topic — store.hl split into projects / tickets (+ relations) / events / tickets-helpers, util.hl shared helpers (env, storage dir, URLs, sorts, Vienna time), the function routes out of project.hl into lib/api.hl (thin; auth/filters/Accept in api-helpers.hl), invite + member-removal logic out of the faces/routes into invites.hl / tickets.hl; project.hl is the map. /login/callback gets req + the session store by reference. gate 249/0, connect 60/0, real-data reads identicalmre
  • 97e269b5mission 010 (code order) 1/4: .hl files out of the root — lib/ (store, users, connections, invites, migrate, markdown, mdview, import = ticketfile, util = localtime, jsoncheck, api-helpers = api), tools/import.hl, components/styles.hl; import paths only. gate 249/0, connect 60/0, real-data reads identicalmre
  • 38f9d10ftickets: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gate 249/0, connect 60/0mre
  • d3db6139tickets: Hybriel master 190aa11d (fc838894 GC correctness, #126 closure scopes, #127); gate 249/0, connect 60/0mre
  • bce182e3tickets: Hybriel master 7eea0d32 (#126 memory, #48 lambda copies its argument); migrate.hl lambdas take &logmre
  • 4137be0fantcolony#40: mission references point to the moved missionsmre
  • 9bfba36aantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • c7bd2645tickets: Hybriel master 73267707 (#122 fixed); compactNow workaround removed (#110 covered)mre
  • 2ab91ee9tickets: gate checks rows appear once (session sync); re-vendor to ff51cf46 stopped on hybriel#122, stays 837fe120mre
  • e01c2b1dtickets#24: installable app (manifest, service worker, offline list), own icon; gate waits for the hello's pongmre
  • 752fbb7fdeploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • 38bdd5e4deploy.sh: never send .git or .gitignore to Byrodinmre
  • f12fa1bcState of 2026-09-27, before the move to gitoriamre