tracker
All repositories: gitoria
8.8 KB
# STATUS — tracker.worldapi.org## 2026-09-27 — ticket #1 reopened: login redone to match calendar exactly (header selector, empty page)The architect rejected the first build of ticket #1: the sign-in sat centered on the page(its own "Sign in with ident" card, identity + sign-out shown in a `homeCard`) instead ofthe header identity selector calendar/gitoria use, and there was no `<ident-selector>` atall. Rebuilt the login by copying calendar.worldapi.org's own files (unchanged in shape, perthe architect's instruction "Copy calendar.worldapi.org's login unchanged"):- **`users.hl`** (new): the ident exchange + a `usersTable` (`storage/mpackdb/users.db`,`identity` → this app's user id), copied from calendar's `users.hl` with `TRACKER_KEY` /`TRACKER_SECRET` / `TRACKER_URL` / `TRACKER_STORAGE` in place of calendar's names (keptthe names already in this app's `docker-compose.yml`/README/DECISIONS rather thanswitching to calendar's generic `IDENT_API_KEY`/`IDENT_API_SECRET`).- **`login.js`** (new): calendar's bridge between `<ident-selector>`'s `ident-login` DOMevent and the hidden `#identcode` input, copied verbatim (creator: "login.js is correct,as thats for externals in general").- **`components/main.hl`**: now the header carries `userBox` (`<ident-selector>` + "Log inwith ident" / "Log out"), the `trackerLogin`/`trackerLogOut` faces and the`trackerSignedIn`/`trackerSignedOut` client push — calendar's shell renamed to this app'sevent names.- **`components/home.hl`**: now truly empty (`View { home {} }`) — no sign-in link, noidentity/sign-out duplicated on the page; that is entirely the header's job now.- **`components/loginfailed.hl`** (new) + **`project.hl`**: the login routes are now`/login/callback` (function route, the button's return AND the code exchange) and`/login/failed`, copied from calendar's `project.hl` (`safePath`, `failed()`,`loginCallback`) in place of the old `/login` + `/callback` + `/logout` routes; the old`/logout` POST route is gone (logout is a face, like calendar's).- **`styles.hl`**: added the header selector styles (`userBox`, `identSelector`,`ident-selector::part(...)`, sticky header) from calendar's `styles.hl`; dropped thenow-unused `homeCard`/`accountBar`/`userName` rules from the rejected centered sign-in.**Gate rewritten** (`tests/browser.mjs`, 12 checks): replaced the old gate (which droveident's full email-code UI through a vendored dev copy of ident at `.scratch/ident-dev`)with calendar's own pattern — `tests/identkit.mjs` (copied from calendar unchanged) starts athrowaway ident (a fresh copy of `/media/STORAGE/projects/ident.worldapi.org`'s code, no`.env`/storage copied, codes to a mail sink, never the live ident), signs in over its RESTAPI and registers this app, then the gate proves the header in a real headless Chrome:signed out → `#selector` + `#loginbutton` in the header, **`main` is empty** → sign in(`/login/callback?ident_code=`, the same exchange the selector would trigger) → `#selector`shows `class="in"`, `#logout` appears, **`main` still empty** → sign out → signed out again→ a reload stays signed out. No console errors.```node tests/browser.mjs12 passed, 0 failed````./deploy.sh --dry-run --target .scratch/deploy-preview --url http://127.0.0.1:0/`: gatepassed as step [1/4], rsync preview held none of `storage/`, `.sessions/`, `.env`,`.scratch/`, `server.*`, logs. Removed the stale `.scratch/ident-dev` (the old gate's vendoredident copy) and `.scratch/browser-gate` (the old gate's storage) — unused by the new gate.**Still open**: the app is registered in ident's dev copies only (this gate's own throwawayident). The LIVE ident registration (`TRACKER_KEY`/`TRACKER_SECRET` in `.env` next to`docker-compose.yml`) is the architect's first-deploy step (README "Deploy"), not built here.## 2026-09-27 — ticket #2: data migration — blocked twice on sandbox access, nothing doneTwo workers in a row (`s-20260927T1029-f57b0f`, then this session) could not start: themigration source the ticket names, `/media/STORAGE/projects/old-tracker/mongo-export/*.jsonl`+ its `README-RECONSTRUCTED.md`, is not reachable from this worker's sandbox. Verified freshthis session:```$ ls -la /media/STORAGE/projects/antcolony-docs hybriel ident.worldapi.org tracker.worldapi.org # no old-tracker$ mount | grep STORAGE/dev/nvme1n1p6 on /media/STORAGE/projects/tracker.worldapi.org type btrfs (rw,...)/dev/nvme1n1p6 on /media/STORAGE/projects/hybriel type btrfs (ro,...)/dev/nvme1n1p6 on /media/STORAGE/projects/ident.worldapi.org type btrfs (ro,...)/dev/nvme1n1p6 on /media/STORAGE/projects/antcolony-docs type btrfs (ro,...)# old-tracker is not among the mounted subvolumes at all```So this is not a data problem (the export is "complete" per the ticket) — it's the workersandbox for this ticket that never got `old-tracker` mounted (read-only, like `hybriel` /`ident.worldapi.org` / `antcolony-docs` above). Nothing was built or changed this session:no `storage/`, no `tools/`, no id-mapping — writing the migration tool blind, guessing theJSONL shape from the ticket text alone, risks silently wrong data and was avoided on purpose(see the project's "Build it properly" rule). Filed as an antcolony issue so the next worker'ssandbox includes `old-tracker` before another attempt.## 2026-09-27 — ticket #1: the empty shell, ident loginBuilt the app from scratch: vendored `bin/hybriel` + `plugins/` + `shared/tokens.hl` from`ident.worldapi.org` (newest local build, hybriel master 837fe120, no local patch — seeREADME "Vendored Hybriel"). `project.hl` (routes `/login`, `/callback`, `/logout`, `/`),`components/home.hl` (the empty homepage), `components/main.hl` (shell), `styles.hl`(accent green `#4ec9b0`, per `antcolony/README.md` "look and style" / `CONCEPT.md`).`docker-compose.yml` / `Dockerfile` / `deploy.sh` following ident's own house pattern(port 45008, container `tracker.worldapi.org`).**Login**: the ident login BUTTON flow (ident.worldapi.org README "How apps use ident"),server-side exchange (`POST <ident>/api/exchange`), this app's own framework session(`session.user = { identity }`, cookie `trackersid`). ident hands over only the identity'spublic **short id** — no display name yet (ident#11, properties handover, is on hold) — so"your name" on the homepage is `Signed in as <shortid>`, the same identifier every otherworldapi app would show; see `decided` in the report.**Lesson (Hybriel)**: a face that mutates `session.user` (e.g. `signOut`) does NOTautomatically re-render the page — a component's reactive members (`signedIn`, `identity`,…) are computed once at mount from the framework's read-only session snapshot; a clienthandler that calls `emit server X()` must ALSO flip the affected members itself afterwards(ident's own `components/home.hl` `on doSignOut(e)` does exactly this: `emit serversignOut()` then `signedIn = false` …). Missing that made the sign-out button silently donothing client-side (the ack came back `ok:true`, the server-side session really wascleared — proven by a reload — but the DOM never updated) until copied.**Gate** (`tests/browser.mjs`, 13 checks): a fresh copy of `ident.worldapi.org`'s code (no`.env`, no `storage/`, no `.sessions/` — verified empty of secrets/data before first use)runs as this gate's own ident, on its own storage and its own mail sink (no live ident, noreal mail). The gate registers this app in that dev ident once over the `/__hl/emit` API(the same one-time step a person does by hand in ident's `/apps` page), then drives theREAL login-button flow in a real headless Chrome: signed out → click "Sign in with ident" →ident's email form → the mail-sink code → the first-login optional-names form (Skip) → theone-identity choice (one click) → back on tracker, "Signed in as `<shortid>`" → "Sign out" →signed out again → a reload stays signed out. No console errors. Ran twice for stability, 0failures; no leftover Chrome/hybriel processes after either run.```node tests/browser.mjs13 passed, 0 failed````./deploy.sh --dry-run --target .scratch/deploy-preview --url http://127.0.0.1:0/` (a localdirectory, per ident's own convention for testing deploy.sh without touching Byrodin): gatepassed, rsync preview held none of `storage/`, `.sessions/`, `.env`, `.scratch/`, `server.*`,logs — confirmed by the same grep the script refuses on.**Open**: the app is not registered with the LIVE ident yet — `TRACKER_KEY`/`TRACKER_SECRET`are unset until the architect's first deploy does that (README "Deploy"); until then`/login` on the live site answers a plain error page instead of redirecting (`/` itselfstill renders). This is normal for a brand-new app, the same as ident's own SMTP `.env`before its first deploy — not something this ticket's worker can set (no `.env` access,and it is a LIVE ident registration).
Branches
- mainmain branch