gitoriaLog in with ident

tickets

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Main branchmainbb64d57cmission 012 (ticket #25 API part): every /api/projects/<x>/… route takes the project's id (12-char record id) as well as its slug, same answers byte for byte; tickets stay under their project, no global /api/tickets/<x>. gate 315/0 (old code: the 13 id checks fail), connect 60/0, live-data copy old vs new 1,484 identical, slug vs id 772 identicalmremain/missions/005-tickets-ident-login.md

5.4 KB

  1. # Mission 005 (old 011) — tickets: login via ident (ticket tickets.worldapi.org#7)
  2. One-shot worker. The architect (Claude Code on Byrodin) verifies your report and deploys; you do NOT
  3. deploy and do NOT touch Byrodin.
  4. ## Read first — in this order
  5. 1. **`loreana:/media/STORAGE/projects/tickets.worldapi.org/CONCEPT.md`** — the creator's concept, section
  6. "Login via ident" is this mission. Source of truth; don't add what it doesn't describe; where it is
  7. silent, make the smallest choice and list it under "Questions for the creator".
  8. 2. **`loreana:/media/STORAGE/projects/ident.worldapi.org/CONCEPT.md` and `README.md`** — how apps use
  9. ident: `<ident-selector key=…>` from `/selector.js`, the `ident-login` event with a one-time code, the
  10. login button (`/login?key=&return=` → `?ident_code=`), `POST /api/exchange {key, secret, code}` →
  11. `{identity}` (a per-app id; no names, no email).
  12. 3. tickets' own `README.md` / `STATUS.md`. Ticket: `GET https://tickets.worldapi.org/api/projects/tickets.worldapi.org/tickets/7`
  13. (send a `user-agent` header — Cloudflare blocks default script agents).
  14. 4. `/CONTAINERS/projects/antcolony/README.md` — conventions (UUID `@id` keys, `storage/mpackdb/`, JSON writes
  15. + Markdown text fields), lessons.
  16. ## Hybriel (standard block)
  17. Read `/CONTAINERS/projects/antcolony/docs/hybriel-for-app-workers.md` first — which docs to trust, known
  18. pitfalls (#31 forged face sessions, #36 global face names, #24 HL_HOST, #25 no request context in faces,
  19. #40 open only COPIES of stores), conventions, deploy notes. Report new Hybriel findings under
  20. "Hybriel issues"; do not edit that guide.
  21. ## Where
  22. - Develop in `loreana:/media/STORAGE/projects/tickets.worldapi.org` (DEVELOPMENT only — live is on Byrodin;
  23. its local `storage/` is a stale copy you may use for tests). Work in `.scratch/dev` and copy back when
  24. green (as missions 004 (old 008)/ident 006 (old 010) did). The Loreana dev servers are stopped; start your own test servers.
  25. - For tests run your OWN ident instance from `/media/STORAGE/projects/ident.worldapi.org` code (read only:
  26. start it with its own storage dir, `IDENT_MAIL_SINK`, own port, e.g. as ident's `tests/selector.mjs`
  27. does) and register a test app in it. Never use the live ident, never send real mail.
  28. ## Scope
  29. 1. **ident login in tickets**: the identity selector top right (host tells it `logged-in`), plus the login
  30. button flow. tickets' server exchanges the code with `IDENT_API_KEY` / `IDENT_API_SECRET` from its
  31. environment (the live `.env` on Byrodin already has them — **you never read or write any `.env`**; in
  32. tests pass your own values as env vars). Logout on tickets resets the selector.
  33. 2. **Users**: a tickets user per ident per-app identity id. First login asks once for a **display name**
  34. (interim — see concept point 6: keep it a normal field so ident can fill it later).
  35. 3. **Reading stays public. Writing needs a login**: creating tickets, commenting, state changes — in the web
  36. UI (faces: check the real session, #31) and in the API. Anonymous writes → 401.
  37. 4. **Author from the login**: no free `author` field any more (API: refuse it with 400 naming the field, or
  38. ignore — list your choice). Events store the user; old events keep their author string.
  39. 5. **Confirm / reject only by the creator**: the creator is configured as `TICKETS_CREATOR_IDENTITY` =
  40. the creator's per-app identity id (env). Until it is set, nobody can confirm/reject. Provide a way for a
  41. logged-in user to see their own per-app id (e.g. on a small "you" page) so the architect can set it.
  42. 6. **API tokens** for machine clients: a logged-in user creates / lists / revokes their tokens in the UI;
  43. a token is shown once, stored hashed; `Authorization: Bearer <token>` acts as that user on every API
  44. write. Wrong / revoked token → 401.
  45. 7. Existing API endpoints keep working for reads; for writes they now need a token.
  46. 8. Data: new tables with `@id` keys in `storage/mpackdb/`; existing tickets/events untouched. The live
  47. store on Byrodin must keep working after the architect's deploy (no manual migration step if avoidable;
  48. if one is needed, write an idempotent tool and say so).
  49. ## Rules
  50. - No git. No `.env` access. Don't touch Byrodin. Don't POST to the live tickets server.
  51. - Only kill your own PIDs. Clean up headless Chromes (`--disable-gpu`). Scratch in `.scratch/`.
  52. - If any action is refused by the permission system, don't retry or work around it; report it.
  53. - A test is the whole process: real headless browsers, your own ident + tickets servers, same-site
  54. hostnames (both on 127.0.0.1, different ports): signed-out read works; write refused; selector login →
  55. display name → write shows the user as author; second user can't confirm; creator (configured id) can;
  56. token create → API write as that user → revoke → 401; forged face sessions refused; old events still
  57. show their authors. Extend `tests/browser.mjs` (all existing checks stay green, adapt the ones that write).
  58. Screenshots at 390px and 1280px (selector top right, name prompt, tokens page), look at them.
  59. - Update tickets' `README.md` (login, tokens, env vars, how to set `TICKETS_CREATOR_IDENTITY`) and
  60. `STATUS.md`. Do NOT edit `CONCEPT.md`. Also update `docker-compose.yml` if new env vars are needed
  61. (values come from `.env`, never hard-coded secrets).
  62. ## Report (final answer, this structure)
  63. ```
  64. ## Done
  65. ## Verified (each: command run + observed output)
  66. ## Not verified / open
  67. ## Hybriel issues (repro, observed, expected)
  68. ## Questions for the creator
  69. ## Running (URL, PID, log path)
  70. ```

Branches

Latest commits

  • bb64d57cmission 012 (ticket #25 API part): every /api/projects/<x>/… route takes the project's id (12-char record id) as well as its slug, same answers byte for byte; tickets stay under their project, no global /api/tickets/<x>. gate 315/0 (old code: the 13 id checks fail), connect 60/0, live-data copy old vs new 1,484 identical, slug vs id 772 identicalmre
  • 7538b034mission 011 (ticket #25 web part): short page URLs /<slug> and /<slug>/<number>; /projects/<slug>, /projects/<slug>/<n>, /projects/<slug>/tickets/<n> and /tickets/<ref> answer 301 (current slug); slug pages moved behind hl:web's own routes after construction (they answered /__hl/* and /components/*.hl); reserved slugs refused; API paths unchanged. gate 293/0, connect 60/0, live-data copy 187/0, API old vs new: only page links differmre
  • 0369106emission 010 (code order) 4/4: README file map + import order + 'Same output' test, STATUS (entry, lessons, how to verify), LOG, report; tests/realdata-baseline.mjs + realdata-compare*.py (a cleanup answers the same on live data), tests/letcount.pymre
  • a75e0279mission 010 (code order) 3/4: let only where a variable is reassigned or re-bound in a loop body (456 lets → plain declarations; Hybriel refuses a plain declaration inside a loop on its 2nd pass). gate 249/0, connect 60/0, real-data reads identical, a 50-step write sequence (API + faces) identical to the old codemre
  • e9d5c618mission 010 (code order) 2/4: one lib/ file per topic — store.hl split into projects / tickets (+ relations) / events / tickets-helpers, util.hl shared helpers (env, storage dir, URLs, sorts, Vienna time), the function routes out of project.hl into lib/api.hl (thin; auth/filters/Accept in api-helpers.hl), invite + member-removal logic out of the faces/routes into invites.hl / tickets.hl; project.hl is the map. /login/callback gets req + the session store by reference. gate 249/0, connect 60/0, real-data reads identicalmre
  • 97e269b5mission 010 (code order) 1/4: .hl files out of the root — lib/ (store, users, connections, invites, migrate, markdown, mdview, import = ticketfile, util = localtime, jsoncheck, api-helpers = api), tools/import.hl, components/styles.hl; import paths only. gate 249/0, connect 60/0, real-data reads identicalmre
  • 38f9d10ftickets: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gate 249/0, connect 60/0mre
  • d3db6139tickets: Hybriel master 190aa11d (fc838894 GC correctness, #126 closure scopes, #127); gate 249/0, connect 60/0mre
  • bce182e3tickets: Hybriel master 7eea0d32 (#126 memory, #48 lambda copies its argument); migrate.hl lambdas take &logmre
  • 4137be0fantcolony#40: mission references point to the moved missionsmre
  • 9bfba36aantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • c7bd2645tickets: Hybriel master 73267707 (#122 fixed); compactNow workaround removed (#110 covered)mre
  • 2ab91ee9tickets: gate checks rows appear once (session sync); re-vendor to ff51cf46 stopped on hybriel#122, stays 837fe120mre
  • e01c2b1dtickets#24: installable app (manifest, service worker, offline list), own icon; gate waits for the hello's pongmre
  • 752fbb7fdeploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • 38bdd5e4deploy.sh: never send .git or .gitignore to Byrodinmre
  • f12fa1bcState of 2026-09-27, before the move to gitoriamre