gitoriaLog in with ident

tickets

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commitc7bd2645c7bd2645tickets: Hybriel master 73267707 (#122 fixed); compactNow workaround removed (#110 covered)mrec7bd2645/invites.hl

3.2 KB

  1. // invites.hl — PEOPLE JOIN A PROJECT THROUGH IDENT'S INVITE SERVICE (ticket #20; ident README "Invites",
  2. // ident#22). tickets asks ident for an invite for one project and a role and shows the link; whoever opens
  3. // it and picks an identity is sent back to /login/callback?ident_code=…&invite=<invite id>. project.hl then
  4. // exchanges the code (users.hl), asks ident who ACCEPTED the invite (`identities`) and only then makes that
  5. // person a member. Statics only, the server realm. A failed fetch is absorbed by project.hl's `on Error`
  6. // (the call then yields null → "ident did not answer").
  7. import { fetch } from 'hl:fetch'
  8. import { identKey, identSecret, identExchangeUrl, callbackUrl } from './users.hl'
  9. static ua = { 'user-agent' = 'tickets.worldapi.org (ident invites)' }
  10. // only letters, digits and dashes (ident's invite ids)
  11. static isInviteId = (s) => {
  12. if (s == null || hlTypeName(s) != 'String' || s.length == 0 || s.length > 100) { return false }
  13. let i = 0
  14. while (i < s.length) {
  15. let c = s.charCodeAt(i)
  16. if (!((c >= 48 && c <= 57) || (c >= 97 && c <= 122) || (c >= 65 && c <= 90) || c == 45 || c == 95)) { return false }
  17. i = i + 1
  18. }
  19. return true
  20. }
  21. static identCall = (path, body) => {
  22. if (identKey == '' || identSecret == '') { return { error = 'invites are not set up on this server (IDENT_API_KEY / IDENT_API_SECRET missing)' } }
  23. let json = { key = identKey secret = identSecret }
  24. for (k of body.keys()) { json[k] = body[k] }
  25. let r = fetch(identExchangeUrl + path, { method = 'POST' json = json headers = ua timeoutMs = 10000 })
  26. if (r == null || r.status == null || r.status == 0) { return { error = 'ident did not answer' } }
  27. let j = r.json()
  28. if (r.status != 200) { return { error = 'ident refused (' + r.status + (j != null && j.error != null ? ': ' + j.error : '') + ')' } }
  29. if (j == null) { return { error = 'ident answered nothing readable' } }
  30. return { body = j }
  31. }
  32. // an invite link for `projectId` and `role`: { url, id, expires } | { error }. `email` (optional) makes ident mail it.
  33. static createInvite = (projectId, role, uses, days, email) => {
  34. let body = { project = projectId role = role return = callbackUrl uses = uses days = days }
  35. if (email != null && email != '') { body.email = email }
  36. let r = identCall('/api/invites', body)
  37. if (r.error != null) { return r }
  38. let j = r.body
  39. if (j.url == null || j.id == null) { return { error = 'ident answered no invite link' } }
  40. return { url = j.url id = j.id expires = j.expires mailed = j.mailed == true }
  41. }
  42. // did this identity accept this invite? { project (id), role } | { error }
  43. static acceptedInvite = (inviteId, identity) => {
  44. if (!isInviteId(inviteId)) { return { error = 'that is not an invite id' } }
  45. let r = identCall('/api/invites/get', { id = inviteId })
  46. if (r.error != null) { return r }
  47. let inv = r.body.invite
  48. if (inv == null || inv.project == null || inv.role == null) { return { error = 'ident answered no invite' } }
  49. let ok = false
  50. if (inv.identities != null && countOfIds(inv.identities) > 0) { for (i of inv.identities) { if (i == identity) { ok = true } } }
  51. if (!ok) { return { error = 'this login did not accept that invite' } }
  52. return { project = inv.project role = inv.role }
  53. }
  54. static countOfIds = (list) => {
  55. let n = list.length
  56. return n == null ? 0 : n
  57. }

Branches

Latest commits

  • c7bd2645tickets: Hybriel master 73267707 (#122 fixed); compactNow workaround removed (#110 covered)mre
  • 2ab91ee9tickets: gate checks rows appear once (session sync); re-vendor to ff51cf46 stopped on hybriel#122, stays 837fe120mre
  • e01c2b1dtickets#24: installable app (manifest, service worker, offline list), own icon; gate waits for the hello's pongmre
  • 752fbb7fdeploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • 38bdd5e4deploy.sh: never send .git or .gitignore to Byrodinmre
  • f12fa1bcState of 2026-09-27, before the move to gitoriamre