tickets
All repositories: gitoria
7.2 KB
// tools/migrate-short-ids.hl — ONE-OFF MIGRATION (mission 039, ident#23): ident answers every identity's public// 5-character SHORT ID (e.g. `a68sz`) instead of the old per-app id (32 hex). tickets.worldapi.org keeps ident ids in ONE place:// users.db `identity` (lib/users.hl usersTable, unique index) — and the env TICKETS_CREATOR_IDENTITY (.env on Byrodin), for// which this tool prints the new value. events/links `user`, tokens.db `user`, assignees are the users @id.// Everything else points at the users @id, which does not change — sessions (`user = { id = <users @id> }`) stay signed in.//// What it does: POST <ident>/api/migrate-ids {key, secret} (NEVER `finish` — that is a separate, later step, runbook// antcolony-docs/docs/short-id-switch.md) → { ids: { <old id>: <short id> } }, then for every user:// * old id in the map → `identity` rewritten to the short id (MAPPED)// * already a short id → left alone (ALREADY) — so a second run changes nothing (idempotent)// * old id NOT in the map → left alone (UNMAPPED): an identity deleted in ident since; nobody can log in as it// * the short id is already another user's `identity` → left alone (CONFLICT; cannot happen while the app was// stopped between the ident switch and this run — needs a human, runbook "Conflicts"; the tool then exits non-zero)// Prints counts; the key/secret are read from the environment and never printed. Exit is non-zero on any refusal.//// RUN IT WITH THE APP STOPPED (the server holds the tables), after ident#23 is live, storage backed up:// TICKETS_STORAGE=$PWD/storage/mpackdb IDENT_API_KEY=… IDENT_API_SECRET=… IDENT_EXCHANGE_URL=<ident> bin/hybriel tools/migrate-short-ids.hl// On Byrodin (the key/secret come from the app's .env through docker's --env-file; hybriel itself only loads a .env// beside the ENTRY script, i.e. tools/.env, which does not exist):// docker run --rm --network host --env-file .env -e TICKETS_STORAGE=/home/tickets/storage/mpackdb \// -e IDENT_EXCHANGE_URL=http://127.0.0.1:45002 -v $PWD:/home/tickets -w /home/tickets \// worldapi-hybriel-runtime:debian12 ./bin/hybriel tools/migrate-short-ids.hl// TICKETS_STORAGE must be ABSOLUTE: Hybriel resolves a relative path against the entry script's folder (tools/).// Test: tests/short-id-switch.mjs (old ident → data → new ident → this tool twice → the same user logs in again).import { env } from 'hl:proc'import { fetch } from 'hl:fetch'import { usersTable, identKey, identSecret, identExchangeUrl } from '../lib/users.hl'import { countOf, first } from '../lib/util.hl'storage = env('TICKETS_STORAGE')if (storage == null || !storage.startsWith('/')) {hlError('set TICKETS_STORAGE to the ABSOLUTE table directory, e.g. TICKETS_STORAGE=$PWD/storage/mpackdb')}if (identKey == '' || identSecret == '') {hlError('IDENT_API_KEY / IDENT_API_SECRET are not set (on Byrodin: docker run --env-file .env …)')}// the characters of an id, as ident#23 makes them: 5+ of 2-9 and a-z without i, l, o (lower case)static isShortId = (s) => {if (s == null || hlTypeName(s) != 'String' || s.length < 5 || s.length > 16) { return false }let i = 0while (i < s.length) {let c = s.charCodeAt(i)let digit = c >= 50 && c <= 57let letter = c >= 97 && c <= 122 && c != 105 && c != 108 && c != 111if (!digit && !letter) { return false }i = i + 1}return true}// the old per-app id: exactly 32 lowercase hexstatic isOldId = (s) => {if (s == null || hlTypeName(s) != 'String' || s.length != 32) { return false }let i = 0while (i < s.length) {let c = s.charCodeAt(i)if (!((c >= 48 && c <= 57) || (c >= 97 && c <= 102))) { return false }i = i + 1}return true}// every field of the record, `identity` replaced (hl:mpackdb wants the whole @id record, its `id` included)static withIdentity = (rec, identity) => {let out = {}for (k of rec.keys()) { out[k] = rec[k] }out.identity = identityreturn out}console.log('migrate-short-ids: asking ' + identExchangeUrl + '/api/migrate-ids (storage ' + storage + ')')r = fetch(identExchangeUrl + '/api/migrate-ids', { method = 'POST' json = { key = identKey secret = identSecret } headers = { 'user-agent' = 'tickets.worldapi.org (migrate-short-ids)' } timeoutMs = 30000 })if (r == null || r.status == null || r.status == 0) { hlError('ident did not answer at ' + identExchangeUrl) }if (r.status != 200) {let e = r.json()hlError('ident refused migrate-ids (' + r.status + (e != null && e.error != null ? ': ' + e.error : '') + ') — is ident#23 live? right key/secret?')}j = r.json()if (j == null || j.ids == null || hlTypeName(j.ids) != 'Hybrid') { hlError('ident answered no id map: ' + JSON.stringify(j)) }ids = j.idsconsole.log('ident: ' + j.count + ' old ids in the map, finished = ' + j.finished)seen = 0mapped = 0already = 0unmapped = 0conflicts = 0failed = 0all = usersTable.find(null, null)if (countOf(all) > 0) {for (u of all) {seen = seen + 1let old = u.identitylet sid = isOldId(old) ? ids[old] : nullif (sid != null && isShortId(sid)) {let other = first(usersTable.find('identity', sid))if (other != null && other.id != u.id) {conflicts = conflicts + 1console.log('CONFLICT user ' + u.id + ': its short id ' + sid + ' is already user ' + other.id + ' — left alone')} else {usersTable.update(u.id, withIdentity(u, sid))let after = usersTable.fetch(u.id)if (after != null && after.identity == sid && first(usersTable.find('identity', sid)) != null && countOf(usersTable.find('identity', old)) == 0) {mapped = mapped + 1console.log('MAPPED user ' + u.id + ' → ' + sid)} else {failed = failed + 1console.log('FAILED user ' + u.id + ': ' + usersTable.lastError())}}} else if (isShortId(old) && !isOldId(old)) {already = already + 1} else {unmapped = unmapped + 1console.log('UNMAPPED user ' + u.id + ' (ident does not know its old id any more — deleted identity?)')}}}// TICKETS_CREATOR_IDENTITY (users.hl isCreator compares it with users.identity): its new value, to put into .envcreatorOld = env('TICKETS_CREATOR_IDENTITY')if (creatorOld == null || creatorOld.trim() == '') {console.log('TICKETS_CREATOR_IDENTITY: not set — nothing to do')} else if (isOldId(creatorOld.trim()) && ids[creatorOld.trim()] != null) {console.log('TICKETS_CREATOR_IDENTITY: an old id → set TICKETS_CREATOR_IDENTITY=' + ids[creatorOld.trim()] + ' in .env BEFORE tickets starts again')} else if (isShortId(creatorOld.trim()) && !isOldId(creatorOld.trim())) {console.log('TICKETS_CREATOR_IDENTITY: already a short id — nothing to do')} else {console.log('TICKETS_CREATOR_IDENTITY: ident has no short id for it (never logged in to tickets?) — the creator logs in, reads the id on /you, set it by hand')}console.log('migrate-short-ids: users seen ' + seen + ', mapped ' + mapped + ', already short ' + already + ', unmapped ' + unmapped + ', conflicts ' + conflicts + ', failed ' + failed)if (failed > 0) { hlError('some users could not be written — restore the backup and look') }if (conflicts > 0) { hlError('CONFLICTS: the app made a new user for a short id before this ran (it was not stopped?) — the old user keeps its old id; see the runbook "Conflicts"') }
Branches
- mainmain branch
Latest commits
- e9d5c618mission 010 (code order) 2/4: one lib/ file per topic — store.hl split into projects / tickets (+ relations) / events / tickets-helpers, util.hl shared helpers (env, storage dir, URLs, sorts, Vienna time), the function routes out of project.hl into lib/api.hl (thin; auth/filters/Accept in api-helpers.hl), invite + member-removal logic out of the faces/routes into invites.hl / tickets.hl; project.hl is the map. /login/callback gets req + the session store by reference. gate 249/0, connect 60/0, real-data reads identicalmre
- 97e269b5mission 010 (code order) 1/4: .hl files out of the root — lib/ (store, users, connections, invites, migrate, markdown, mdview, import = ticketfile, util = localtime, jsoncheck, api-helpers = api), tools/import.hl, components/styles.hl; import paths only. gate 249/0, connect 60/0, real-data reads identicalmre
- 38f9d10ftickets: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gate 249/0, connect 60/0mre
- d3db6139tickets: Hybriel master 190aa11d (fc838894 GC correctness, #126 closure scopes, #127); gate 249/0, connect 60/0mre
- bce182e3tickets: Hybriel master 7eea0d32 (#126 memory, #48 lambda copies its argument); migrate.hl lambdas take &logmre
- 4137be0fantcolony#40: mission references point to the moved missionsmre
- 9bfba36aantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
- c7bd2645tickets: Hybriel master 73267707 (#122 fixed); compactNow workaround removed (#110 covered)mre
- 2ab91ee9tickets: gate checks rows appear once (session sync); re-vendor to ff51cf46 stopped on hybriel#122, stays 837fe120mre
- e01c2b1dtickets#24: installable app (manifest, service worker, offline list), own icon; gate waits for the hello's pongmre
- 752fbb7fdeploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
- 38bdd5e4deploy.sh: never send .git or .gitignore to Byrodinmre
- f12fa1bcState of 2026-09-27, before the move to gitoriamre