tracker
All repositories: gitoria
7.8 KB
// THE SESSION LAYER — a port of the archived hl:web's web_session.hl (mission 093,// 252, 255, 261), re-read 2026-09-12. The design is the creator's own from// hybrilior: one cookie holds a random id, the SERVER holds everything else; a// session fans out to every socket that shares the cookie; delivery is a// predicate per socket (here: the app's `audience`).//// THE FILE IS THE SESSION; MEMORY IS A CACHE OF THE ONES IN FLIGHT. A lookup// misses in memory, reads ONE file, revives it. Nothing loads the directory at// boot; a restart is a cold cache, not a wipe. The boot sweep walks the store// once to REMOVE expired files, never to revive.//// THE FILENAME IS A HASH OF THE ID, NEVER THE ID: a value a client sent must not// become a path, and `ls` on the store must not hand out live ids.//// THREE CLOCKS, all seconds: `maxAge` is how long a session stays VALID after its// last touch (the cookie's Max-Age too); `idle` how long it stays RESIDENT in// memory with no live socket (eviction is non-destructive — the file is the// truth — so a short clock is safe); `sweepEvery` how often the sweep may run,// piggybacking on real requests (no timer: a site with no requests has nothing// to sweep). `stampDrift` bounds how far the on-disk `seen` may lag the one in// memory, so an active session does not cost a disk write per asset request.//// `dir` is the store's absolute path, or null for memory only (the app's// `sessionDir = false`). The default the framework hands in is `<project>/.sessions`// — a DOT directory, which the dev watcher skips by construction (measured in the// archive: a store inside the watched tree made every session write a re-analysis).import HlwSession from './session.hl'import { randomToken } from 'hl:http1'import { now } from 'hl:time'import { sha256 } from 'hl:crypto'import { readFile, listDir, exists, writeFile, mkDir, remove } from 'hl:fs'String dir = nullNumber maxAge = 1209600Number idle = 900Number sweepEvery = 300Number stampDrift = 60String cookie = 'hlsid'Boolean secure = false // the app is reached over https: the cookie carries `Secure`String domain = '' // the cookie's `Domain` (ticket #44): '' = this host onlymap = {} // id → Session, the resident onespersistedSeen = {} // id → the `seen` last written to disk (write avoidance only)lastSweep = 0reported = {} // path → true: a foreign file in the store, said once// ---- the store --------------------------------------------------------------------path(sid) {if (dir == null) { return null }return dir + '/' + sha256(sid)}open() {if (dir != null) { mkDir(dir, 448) }lastSweep = now()if (dir != null) {let n = sweepStore(now() - maxAge * 1000)if (n > 0) { console.log('sessions: boot sweep removed ' + n + ' expired session file(s) from ' + dir) }}return null}load(sid) {let p = path(sid)if (p == null || !exists(p)) { return null }let raw = readFile(p)if (raw == null || !isSessionText(raw)) { return null }let rec = JSON.parse(raw)if (rec == null || rec.id != sid) { return null }let s = rec > new HlwSession()map[sid] = spersistedSeen[sid] = s.seenreturn s}put(s) {let p = path(s.id)if (p == null) { return null }if (!exists(dir)) { mkDir(dir, 448) }writeFile(p, JSON.stringify(s), 384)persistedSeen[s.id] = s.seenreturn null}drop(sid) {let p = path(sid)if (p != null) { remove(p) }persistedSeen[sid] = nullreturn null}// ---- the cookie ----------------------------------------------------------------parseCookies(header) {let out = {}if (header == null) { return out }for (part of header.split(';')) {let eq = part.indexOf('=')if (eq > 0) { out[part.slice(0, eq).trim()] = part.slice(eq + 1).trim() }}return out}cookieHeader(sid) {return cookie + '=' + sid + '; Path=/; HttpOnly; SameSite=Lax; Max-Age=' + maxAge + (domain != '' ? '; Domain=' + domain : '') + (secure ? '; Secure' : '')}// ---- the map ---------------------------------------------------------------------// the session a cookie header names: resident, or revived from its file; null when// it names none (no cookie, or an id nobody knows — that browser is anonymous)resolve(cookieHeader) {return byId(parseCookies(cookieHeader)[cookie])}byId(sid) {if (sid == null) { return null }let s = map[sid]if (s == null) { s = load(sid) }if (s == null) { return null }touch(s)return s}// a new session, resident and on disk; the caller sets the cookiemint() {maybeSweep([])let sid = randomToken(32)let s = new HlwSession(id = sid, created = now(), seen = now())map[sid] = sput(s)return s}// ONE WRITE PATH for the stamp: every request or frame that presents a session// moves `seen`; the file follows only when it has drifted `stampDrift` secondstouch(s) {s.seen = now()if (dir != null) {let last = persistedSeen[s.id]if (last == null || s.seen - last >= stampDrift * 1000) { put(s) }}return null}// what a face wrote (login, a cart) reaches the file now, not at the next driftsave(s) {if (s != null) { put(s) }return null}// ---- the sweep -------------------------------------------------------------------// `live` is the set of session ids with an open socket — those are never evictedmaybeSweep(live) {if (now() - lastSweep >= sweepEvery * 1000) { sweep(live) }return null}sweep(live) {lastSweep = now()let cutoff = now() - maxAge * 1000let cold = now() - idle * 1000let evicted = 0let expired = 0let next = {}for (k of map.keys()) {let s = map[k]if (s == null) {// dropped earlier} else if (s.seen <= cutoff) {drop(k)expired = expired + 1} else if (dir != null && s.seen <= cold && !live.includes(k)) {persistedSeen[k] = nullevicted = evicted + 1} else {next[k] = s}}map = next // a fresh hybrid: the compaction (archive, mission 261)let dropped = 0if (dir != null) { dropped = sweepStore(cutoff) }if (evicted + expired + dropped > 0) {console.log('sessions: sweep — evicted ' + evicted + ', expired ' + expired + ', ' + dropped + ' file(s) removed, ' + map.keys().length + ' resident')}return null}sweepStore(cutoff) {let gone = 0if (!exists(dir)) { return gone }for (e of listDir(dir)) {let raw = isSessionName(e.name) && e.type == 'file' ? readFile(e.path) : nullif (raw != null && !isSessionText(raw)) { raw = null }if (raw == null) { foreign(e) }if (raw != null) {let rec = JSON.parse(raw)if (rec != null && rec.seen <= cutoff) {remove(e.path)persistedSeen[rec.id] = nullgone = gone + 1}}}return gone}// ---- what the store holds that is not a session -----------------------------------// A FILE THAT IS NOT A SESSION IS SKIPPED, NEVER PARSED. The store is a directory an// operator can put anything into (a marker, an editor's backup, a copy), and// `JSON.parse` aborts the program on text that is not JSON — at the boot sweep that was// the whole server, before it served anything (ticket #26). Every file this layer// writes is named by a sha256 (64 lowercase hex characters) and holds a Session's JSON,// whose keys come out sorted, so it opens with `{"created":`; `writeFile` renames a// finished temp file over the target, so a torn session file cannot occur. A file that// is not that shape is left where it is, and said once.isSessionName(name) {if (name.length != 64) { return false }for (c of name.split('')) {if (!'0123456789abcdef'.includes(c)) { return false }}return true}isSessionText(raw) {let t = raw.trim()return t.startsWith('{"created":') && t.endsWith('}')}foreign(e) {if (reported[e.path] == null) {reported[e.path] = trueconsole.log('sessions: skipped ' + e.path + ' — not a session file (the store names its files by a hash and writes JSON); it is left where it is')}return null}
Branches
- mainmain branch
Latest commits
- 5cb85d75deploy.sh: a backup taken while a background job writes (tar exit 1) is a warning; archive checked with gzip -tmre
- 9abda75dtracker: report 035mre
- 12595e47mission 035: theme re-vendored from layouts.worldapi.org 0222f67 (two corner radii: radiusSmall 5px, radiusLarge 10px); the tracker's 18 own radii -> radiusSmall/radiusLarge (--layout-radius is gone); check-theme 0; gates 379/0, 32/0, 53/0, 229/0, 26/0; real copy: every computed radius in {0, 5px, 10px, 50%}mre
- e7305014tracker: report 032 (art + photos)mre
- fbb903cctracker#33/#37 (mission 032): a title without a TMDB poster gets its backdrop (w780, posterFromBackdrop, shown 2:3 centre-cropped); movies store runtime, the page shows release date + runtime; art backfill (public titles without poster file / movies without runtime) and person photo backfill (tmdbProfile / photoCheck) as the last start jobs (TRACKER_ART, TRACKER_PHOTOS; off in every gate start); gates 379/0, 32/0, 53/0, 229/0, 26/0, check-theme 0; live copy: art 4977 titles in 42 min (115 posters, 15 backdrops, 4609 runtimes), The Remaining shows its backdrop + 7 minmre
- 4ecc67b2tracker: STATUS/LOG for the t38 + t40 merge (gates 374/0, 32/0, 53/0, 229/0, 26/0, check-theme 0; live copy checks)mre
- e5945d2fMerge t40 (tracker#40 curated franchises, Franchises menu, superseded collections) into main: deploy.sh lists all six gates (browser, kinds, franchises, pager, franchiseseed, check-theme); search.hl keeps #37's personPhotoOf + #40's importWithCredits; pager gate runs with TRACKER_FRANCHISE_SEED=0; gates 374/0, 32/0, 53/0, 229/0, 26/0, check-theme 0mre
- b638e99dMerge t38 (tracker#38 pagination, #35 Returning/Airing label) into main: LOG/STATUS keep both sides; pager gate follows #37's /people (everyone, last updated first: seed updatedAt); gates pager 229/0, browser 374/0mre
- f8ffa4dbtracker: report 032 + The Remaining + #39mre
- 7565a863tracker: LOG timemre
- b10f00c8tracker#39: double episodes — migrated episodes whose TMDB id TMDB replaced are adopted by their number in the sync (old id -> migratedTmdbId); merge.hl step 3 merges each season's doubles at start (keeper: most watches > synced > first; watches moved/parked; tombstones into mergedEpisodes, nothing deleted); tools/count-duplicate-episodes.hl; gate fixture + paths-m039; live copy 850 -> 0 in 64 s; gates 373/0, 32/0, 52/0mre
- 8f1d4542tracker#40: superseded collections — a TMDB collection timeline whose titles are all in one curated timeline is hidden (supersededBy; kept: own page + editor finder), set by the collection seed when it makes one and by the curated build (lifted when the cover is gone); partly covered ones join that franchise; no second widget (First Contact: only Star Trek — Prime); gate franchiseseed 26/0, browser 365/0, kinds 32/0, franchises 53/0, check-theme 0; real copy 24 supersededmre
- 9448d643tracker#35 follow-up (mission 033): TVmaze 'Running' is labelled 'Returning', or 'Airing' while a non-special episode of the two newest seasons is released within today +-7 days (data unchanged); gate fixtures Running/Airing/Aired + a special; browser 366/0, kinds 32/0, franchises 52/0, pager 229/0, check-theme 0mre
- 7d4b293dtracker#40: "Franchises" in the main menu (desktop header after People, phone sidebar) → /franchises, marked on franchise and timeline pages; gates 365/0, 32/0, 53/0, 24/0, check-theme 0mre
- 8751adb8tracker: report 032mre
- 9bce1f65tracker mission 032: STATUS gate files + the hour-boundary flakemre
- 718bfb89tracker#37 (mission 032): /people = everyone, last updated first (updatedAt stamped by the person fill; view built at boot, touched people first at once), photo + name tiles (person colour) with the /movies pagination, /people/<letter> removed; photo = our file, tmdbProfile, a cast/crew entry's profile (in-memory map at boot), else the new 'no photo' placeholder; new cast/crew/created_by people keep tmdbProfile; search people rows with the photo; /settings = the heading only; util.hl sortDesc starts from sorted runs (same result, 105k: 1.6 s -> 0.15 s); gates 369/0, 32/0, 52/0, check-theme 0; README/STATUS/LOGmre
- 93dfb0batracker#40 (mission 034): the curated franchises — data/franchises.json (17 franchises, 31 timelines, 285 TMDB titles, movies + series, in-universe/release order, 12 TMDB collections attached); lib/franchiseseed.hl + jobs.hl franchiseSeedTick (last start job, imports missing titles via details.hl importWithCredits = the search's Add, one per step paced, then one build; franchiseseed.db: editor changes win, the creator's same-name franchise adopted / timeline left alone, 404 remembered, resumable, idempotent); timeline heads 'N titles · in-universe order' (orderKind) and wrap on a phone; series pages show the widget; new gate tests/franchiseseed.mjs (5th in deploy.sh), the others run with TRACKER_FRANCHISE_SEED=0; gates 365/0, 32/0, 52/0, 24/0, check-theme 0; real copy 196 imported, 0 failed, 7 min, restart unchanged=31mre
- 03ec792ftracker#38 (mission 033): pagination goes exactly to the clicked page — tilelist read the clicked button's text after pagination.hl's own handler had rebuilt the buttons (real clicks only); now li.current, else the button's own text; new gate tests/pager.mjs (5 lists x 11 pages, 390/1280, real + script clicks, Back/Forward) 229/0; browser 365/0, kinds 32/0, franchises 52/0, check-theme 0mre
- 96ba683adeploy.sh: a gate without a 'passed,' line (check-theme) no longer ends the scriptmre