tickets
All repositories: gitoria
4.3 KB
// lib/invites.hl — PEOPLE JOIN A PROJECT THROUGH IDENT'S INVITE SERVICE (ticket #20; ident README "Invites",// ident#22). An admin asks ident for an invite for one project and a role (mayInvite, createInvite) and shows the// link; whoever opens it and picks an identity is sent back to /login/callback?ident_code=…&invite=<invite id>.// lib/api.hl loginCallback then exchanges the code (users.hl), and joinByInvite asks ident who ACCEPTED the invite// (`identities`) and only then makes that person a member. Statics only, the server realm. A failed fetch is// absorbed by project.hl's `on Error` (the call then yields null → "ident did not answer").import { fetch } from 'hl:fetch'import { identKey, identSecret, identExchangeUrl, callbackUrl } from './users.hl'import { projectByRef, isAdminOf, roles, addMember } from './projects.hl'static ua = { 'user-agent' = 'tickets.worldapi.org (ident invites)' }// only letters, digits and dashes (ident's invite ids)static isInviteId = (s) => {if (s == null || hlTypeName(s) != 'String' || s.length == 0 || s.length > 100) { return false }let i = 0while (i < s.length) {let c = s.charCodeAt(i)if (!((c >= 48 && c <= 57) || (c >= 97 && c <= 122) || (c >= 65 && c <= 90) || c == 45 || c == 95)) { return false }i = i + 1}return true}static identCall = (path, body) => {if (identKey == '' || identSecret == '') { return { error = 'invites are not set up on this server (IDENT_API_KEY / IDENT_API_SECRET missing)' } }let json = { key = identKey secret = identSecret }for (k of body.keys()) { json[k] = body[k] }r = fetch(identExchangeUrl + path, { method = 'POST' json = json headers = ua timeoutMs = 10000 })if (r == null || r.status == null || r.status == 0) { return { error = 'ident did not answer' } }j = r.json()if (r.status != 200) { return { error = 'ident refused (' + r.status + (j != null && j.error != null ? ': ' + j.error : '') + ')' } }if (j == null) { return { error = 'ident answered nothing readable' } }return { body = j }}// may this user invite to project `p` with `role`? null, or the refusal { error, field, forbidden? }// (the caller then checks its numbers and calls createInvite)static mayInvite = (p, user, role) => {if (!isAdminOf(p.id, user)) { return { error = 'only an admin of the project can invite' field = '' forbidden = true } }if (!roles.includes(role)) { return { error = 'role must be one of: ' + roles.join(', ') field = 'role' } }return null}// an invite link for `projectId` and `role`: { url, id, expires } | { error }. `email` (optional) makes ident mail it.static createInvite = (projectId, role, uses, days, email) => {body = { project = projectId role = role return = callbackUrl uses = uses days = days }if (email != null && email != '') { body.email = email }r = identCall('/api/invites', body)if (r.error != null) { return r }j = r.bodyif (j.url == null || j.id == null) { return { error = 'ident answered no invite link' } }return { url = j.url id = j.id expires = j.expires mailed = j.mailed == true }}// did this identity accept this invite? { project (id), role } | { error }static acceptedInvite = (inviteId, identity) => {if (!isInviteId(inviteId)) { return { error = 'that is not an invite id' } }r = identCall('/api/invites/get', { id = inviteId })if (r.error != null) { return r }inv = r.body.inviteif (inv == null || inv.project == null || inv.role == null) { return { error = 'ident answered no invite' } }let ok = falseif (inv.identities != null && countOfIds(inv.identities) > 0) { for (i of inv.identities) { if (i == identity) { ok = true } } }if (!ok) { return { error = 'this login did not accept that invite' } }return { project = inv.project role = inv.role }}static countOfIds = (list) => {n = list.lengthreturn n == null ? 0 : n}// THE INVITED PERSON JOINS (the login callback brought `invite=<id>`): only when ident says this identity accepted// the invite does the user become a member, with the invite's role. Answers { project (record) } or { error }static joinByInvite = (inviteId, identity, userId) => {a = acceptedInvite(inviteId, identity)if (a.error != null) { return a }jp = projectByRef(a.project)if (jp == null || !roles.includes(a.role)) { return { error = 'the invite is for a project or role that does not exist here' } }addMember(jp.id, userId, a.role)return { project = jp }}
Branches
- mainmain branch
Latest commits
- 7538b034mission 011 (ticket #25 web part): short page URLs /<slug> and /<slug>/<number>; /projects/<slug>, /projects/<slug>/<n>, /projects/<slug>/tickets/<n> and /tickets/<ref> answer 301 (current slug); slug pages moved behind hl:web's own routes after construction (they answered /__hl/* and /components/*.hl); reserved slugs refused; API paths unchanged. gate 293/0, connect 60/0, live-data copy 187/0, API old vs new: only page links differmre
- 0369106emission 010 (code order) 4/4: README file map + import order + 'Same output' test, STATUS (entry, lessons, how to verify), LOG, report; tests/realdata-baseline.mjs + realdata-compare*.py (a cleanup answers the same on live data), tests/letcount.pymre
- a75e0279mission 010 (code order) 3/4: let only where a variable is reassigned or re-bound in a loop body (456 lets → plain declarations; Hybriel refuses a plain declaration inside a loop on its 2nd pass). gate 249/0, connect 60/0, real-data reads identical, a 50-step write sequence (API + faces) identical to the old codemre
- e9d5c618mission 010 (code order) 2/4: one lib/ file per topic — store.hl split into projects / tickets (+ relations) / events / tickets-helpers, util.hl shared helpers (env, storage dir, URLs, sorts, Vienna time), the function routes out of project.hl into lib/api.hl (thin; auth/filters/Accept in api-helpers.hl), invite + member-removal logic out of the faces/routes into invites.hl / tickets.hl; project.hl is the map. /login/callback gets req + the session store by reference. gate 249/0, connect 60/0, real-data reads identicalmre
- 97e269b5mission 010 (code order) 1/4: .hl files out of the root — lib/ (store, users, connections, invites, migrate, markdown, mdview, import = ticketfile, util = localtime, jsoncheck, api-helpers = api), tools/import.hl, components/styles.hl; import paths only. gate 249/0, connect 60/0, real-data reads identicalmre
- 38f9d10ftickets: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gate 249/0, connect 60/0mre
- d3db6139tickets: Hybriel master 190aa11d (fc838894 GC correctness, #126 closure scopes, #127); gate 249/0, connect 60/0mre
- bce182e3tickets: Hybriel master 7eea0d32 (#126 memory, #48 lambda copies its argument); migrate.hl lambdas take &logmre
- 4137be0fantcolony#40: mission references point to the moved missionsmre
- 9bfba36aantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
- c7bd2645tickets: Hybriel master 73267707 (#122 fixed); compactNow workaround removed (#110 covered)mre
- 2ab91ee9tickets: gate checks rows appear once (session sync); re-vendor to ff51cf46 stopped on hybriel#122, stays 837fe120mre
- e01c2b1dtickets#24: installable app (manifest, service worker, offline list), own icon; gate waits for the hello's pongmre
- 752fbb7fdeploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
- 38bdd5e4deploy.sh: never send .git or .gitignore to Byrodinmre
- f12fa1bcState of 2026-09-27, before the move to gitoriamre