gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit2ad9d29c2ad9d29ctracker#1: login exactly like calendar (identity selector in the header, empty homepage)mre2ad9d29c/STATUS.md

8.8 KB

  1. # STATUS — tracker.worldapi.org
  2. ## 2026-09-27 — ticket #1 reopened: login redone to match calendar exactly (header selector, empty page)
  3. The architect rejected the first build of ticket #1: the sign-in sat centered on the page
  4. (its own "Sign in with ident" card, identity + sign-out shown in a `homeCard`) instead of
  5. the header identity selector calendar/gitoria use, and there was no `<ident-selector>` at
  6. all. Rebuilt the login by copying calendar.worldapi.org's own files (unchanged in shape, per
  7. the architect's instruction "Copy calendar.worldapi.org's login unchanged"):
  8. - **`users.hl`** (new): the ident exchange + a `usersTable` (`storage/mpackdb/users.db`,
  9. `identity` → this app's user id), copied from calendar's `users.hl` with `TRACKER_KEY` /
  10. `TRACKER_SECRET` / `TRACKER_URL` / `TRACKER_STORAGE` in place of calendar's names (kept
  11. the names already in this app's `docker-compose.yml`/README/DECISIONS rather than
  12. switching to calendar's generic `IDENT_API_KEY`/`IDENT_API_SECRET`).
  13. - **`login.js`** (new): calendar's bridge between `<ident-selector>`'s `ident-login` DOM
  14. event and the hidden `#identcode` input, copied verbatim (creator: "login.js is correct,
  15. as thats for externals in general").
  16. - **`components/main.hl`**: now the header carries `userBox` (`<ident-selector>` + "Log in
  17. with ident" / "Log out"), the `trackerLogin`/`trackerLogOut` faces and the
  18. `trackerSignedIn`/`trackerSignedOut` client push — calendar's shell renamed to this app's
  19. event names.
  20. - **`components/home.hl`**: now truly empty (`View { home {} }`) — no sign-in link, no
  21. identity/sign-out duplicated on the page; that is entirely the header's job now.
  22. - **`components/loginfailed.hl`** (new) + **`project.hl`**: the login routes are now
  23. `/login/callback` (function route, the button's return AND the code exchange) and
  24. `/login/failed`, copied from calendar's `project.hl` (`safePath`, `failed()`,
  25. `loginCallback`) in place of the old `/login` + `/callback` + `/logout` routes; the old
  26. `/logout` POST route is gone (logout is a face, like calendar's).
  27. - **`styles.hl`**: added the header selector styles (`userBox`, `identSelector`,
  28. `ident-selector::part(...)`, sticky header) from calendar's `styles.hl`; dropped the
  29. now-unused `homeCard`/`accountBar`/`userName` rules from the rejected centered sign-in.
  30. **Gate rewritten** (`tests/browser.mjs`, 12 checks): replaced the old gate (which drove
  31. ident's full email-code UI through a vendored dev copy of ident at `.scratch/ident-dev`)
  32. with calendar's own pattern — `tests/identkit.mjs` (copied from calendar unchanged) starts a
  33. throwaway ident (a fresh copy of `/media/STORAGE/projects/ident.worldapi.org`'s code, no
  34. `.env`/storage copied, codes to a mail sink, never the live ident), signs in over its REST
  35. API and registers this app, then the gate proves the header in a real headless Chrome:
  36. signed out → `#selector` + `#loginbutton` in the header, **`main` is empty** → sign in
  37. (`/login/callback?ident_code=`, the same exchange the selector would trigger) → `#selector`
  38. shows `class="in"`, `#logout` appears, **`main` still empty** → sign out → signed out again
  39. → a reload stays signed out. No console errors.
  40. ```
  41. node tests/browser.mjs
  42. 12 passed, 0 failed
  43. ```
  44. `./deploy.sh --dry-run --target .scratch/deploy-preview --url http://127.0.0.1:0/`: gate
  45. passed as step [1/4], rsync preview held none of `storage/`, `.sessions/`, `.env`,
  46. `.scratch/`, `server.*`, logs. Removed the stale `.scratch/ident-dev` (the old gate's vendored
  47. ident copy) and `.scratch/browser-gate` (the old gate's storage) — unused by the new gate.
  48. **Still open**: the app is registered in ident's dev copies only (this gate's own throwaway
  49. ident). The LIVE ident registration (`TRACKER_KEY`/`TRACKER_SECRET` in `.env` next to
  50. `docker-compose.yml`) is the architect's first-deploy step (README "Deploy"), not built here.
  51. ## 2026-09-27 — ticket #2: data migration — blocked twice on sandbox access, nothing done
  52. Two workers in a row (`s-20260927T1029-f57b0f`, then this session) could not start: the
  53. migration source the ticket names, `/media/STORAGE/projects/old-tracker/mongo-export/*.jsonl`
  54. + its `README-RECONSTRUCTED.md`, is not reachable from this worker's sandbox. Verified fresh
  55. this session:
  56. ```
  57. $ ls -la /media/STORAGE/projects/
  58. antcolony-docs hybriel ident.worldapi.org tracker.worldapi.org # no old-tracker
  59. $ mount | grep STORAGE
  60. /dev/nvme1n1p6 on /media/STORAGE/projects/tracker.worldapi.org type btrfs (rw,...)
  61. /dev/nvme1n1p6 on /media/STORAGE/projects/hybriel type btrfs (ro,...)
  62. /dev/nvme1n1p6 on /media/STORAGE/projects/ident.worldapi.org type btrfs (ro,...)
  63. /dev/nvme1n1p6 on /media/STORAGE/projects/antcolony-docs type btrfs (ro,...)
  64. # old-tracker is not among the mounted subvolumes at all
  65. ```
  66. So this is not a data problem (the export is "complete" per the ticket) — it's the worker
  67. sandbox for this ticket that never got `old-tracker` mounted (read-only, like `hybriel` /
  68. `ident.worldapi.org` / `antcolony-docs` above). Nothing was built or changed this session:
  69. no `storage/`, no `tools/`, no id-mapping — writing the migration tool blind, guessing the
  70. JSONL shape from the ticket text alone, risks silently wrong data and was avoided on purpose
  71. (see the project's "Build it properly" rule). Filed as an antcolony issue so the next worker's
  72. sandbox includes `old-tracker` before another attempt.
  73. ## 2026-09-27 — ticket #1: the empty shell, ident login
  74. Built the app from scratch: vendored `bin/hybriel` + `plugins/` + `shared/tokens.hl` from
  75. `ident.worldapi.org` (newest local build, hybriel master 837fe120, no local patch — see
  76. README "Vendored Hybriel"). `project.hl` (routes `/login`, `/callback`, `/logout`, `/`),
  77. `components/home.hl` (the empty homepage), `components/main.hl` (shell), `styles.hl`
  78. (accent green `#4ec9b0`, per `antcolony/README.md` "look and style" / `CONCEPT.md`).
  79. `docker-compose.yml` / `Dockerfile` / `deploy.sh` following ident's own house pattern
  80. (port 45008, container `tracker.worldapi.org`).
  81. **Login**: the ident login BUTTON flow (ident.worldapi.org README "How apps use ident"),
  82. server-side exchange (`POST <ident>/api/exchange`), this app's own framework session
  83. (`session.user = { identity }`, cookie `trackersid`). ident hands over only the identity's
  84. public **short id** — no display name yet (ident#11, properties handover, is on hold) — so
  85. "your name" on the homepage is `Signed in as <shortid>`, the same identifier every other
  86. worldapi app would show; see `decided` in the report.
  87. **Lesson (Hybriel)**: a face that mutates `session.user` (e.g. `signOut`) does NOT
  88. automatically re-render the page — a component's reactive members (`signedIn`, `identity`,
  89. …) are computed once at mount from the framework's read-only session snapshot; a client
  90. handler that calls `emit server X()` must ALSO flip the affected members itself afterwards
  91. (ident's own `components/home.hl` `on doSignOut(e)` does exactly this: `emit server
  92. signOut()` then `signedIn = false` …). Missing that made the sign-out button silently do
  93. nothing client-side (the ack came back `ok:true`, the server-side session really was
  94. cleared — proven by a reload — but the DOM never updated) until copied.
  95. **Gate** (`tests/browser.mjs`, 13 checks): a fresh copy of `ident.worldapi.org`'s code (no
  96. `.env`, no `storage/`, no `.sessions/` — verified empty of secrets/data before first use)
  97. runs as this gate's own ident, on its own storage and its own mail sink (no live ident, no
  98. real mail). The gate registers this app in that dev ident once over the `/__hl/emit` API
  99. (the same one-time step a person does by hand in ident's `/apps` page), then drives the
  100. REAL login-button flow in a real headless Chrome: signed out → click "Sign in with ident" →
  101. ident's email form → the mail-sink code → the first-login optional-names form (Skip) → the
  102. one-identity choice (one click) → back on tracker, "Signed in as `<shortid>`" → "Sign out" →
  103. signed out again → a reload stays signed out. No console errors. Ran twice for stability, 0
  104. failures; no leftover Chrome/hybriel processes after either run.
  105. ```
  106. node tests/browser.mjs
  107. 13 passed, 0 failed
  108. ```
  109. `./deploy.sh --dry-run --target .scratch/deploy-preview --url http://127.0.0.1:0/` (a local
  110. directory, per ident's own convention for testing deploy.sh without touching Byrodin): gate
  111. passed, rsync preview held none of `storage/`, `.sessions/`, `.env`, `.scratch/`, `server.*`,
  112. logs — confirmed by the same grep the script refuses on.
  113. **Open**: the app is not registered with the LIVE ident yet — `TRACKER_KEY`/`TRACKER_SECRET`
  114. are unset until the architect's first deploy does that (README "Deploy"); until then
  115. `/login` on the live site answers a plain error page instead of redirecting (`/` itself
  116. still renders). This is normal for a brand-new app, the same as ident's own SMTP `.env`
  117. before its first deploy — not something this ticket's worker can set (no `.env` access,
  118. and it is a LIVE ident registration).

Branches

Latest commits

  • 2ad9d29ctracker#1: login exactly like calendar (identity selector in the header, empty homepage)mre
  • 3691e176tracker#1: empty tracker with the ident login (state of 2026-09-27)mre