tracker
All repositories: gitoria
5.4 KB
// project.hl — tracker.worldapi.org: STEP 1 (tracker.worldapi.org#1), an empty shell. Login copied unchanged from// calendar.worldapi.org (rejected once for a centered sign-in and no header selector — architect, 2026-09-27):// ident only, no own passwords (README "How apps use ident" of ident.worldapi.org), the identity selector in the// header (components/main.hl). No shows, no data yet — later steps come from the creator (CONCEPT.md).//// the header's ident-selector / "Log in with ident" -> <ident>/login?key=&return=<this app>/login/callback// /login/callback?ident_code=<code> the app's server exchanges the code for the identity's short id// (POST <ident>/api/exchange) and signs this app's OWN session in// (session.user = { id = <users @id> }, users.hl)// the header's "Log out" button signs this app's session out via the face trackerLogOut (components/main.hl)// — ident's own session, and the browser's ident cookie, are untouched//// Config (env; no committed secret — the first deploy registers this app in ident and sets these, done by the// architect, as with ident's own .env for SMTP):// TRACKER_PORT (45008), TRACKER_URL (this app's own public address, for the return URL),// IDENT_URL (https://ident.worldapi.org), TRACKER_KEY (pk_…), TRACKER_SECRET (sk_…)import WebFramework from 'hl:web'import { Response } from 'hl:http1'import { randomBytes } from 'hl:crypto'import { env } from 'hl:proc'import Styles from './styles.hl'import { exchangeCode, ensureUser } from './users.hl'import Home from './components/home.hl'import LoginFailed from './components/loginfailed.hl'static appTitle = "tracker"styles = Stylesport = env('TRACKER_PORT') != null ? toNumber(env('TRACKER_PORT')) : 45008watching = env('TRACKER_WATCH') != '0'// read by hl:web's own manifest config (WebFramework.hl `cfg.sessionDir`), not the constructor call belowsessionDir = env('TRACKER_SESSIONS') != null ? env('TRACKER_SESSIONS') : null// ---- THE LOGIN BUTTON'S RETURN (ident README "How apps use ident"), copied from calendar.worldapi.org's project.hl// BACK TO THE PAGE: /login.js puts `?next=` into the button's return URL at the click. Only a same-origin PATH// goes (one `/`, URL-safe characters, ≤ 500). Anything else → `/`.nextChars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-._~/?&=%+,;@!$()*:'safePath = (want) => {if (want == null || hlTypeName(want) != 'String' || want == '' || want.length > 500) { return '/' }if (want.slice(0, 1) != '/' || want.slice(0, 2) == '//' || want.slice(0, 7) == '/login/') { return '/' }let i = 0while (i < want.length) {if (!nextChars.includes(want[i])) { return '/' }i = i + 1}return want}// A FAILED LOGIN is a page (components/loginfailed.hl): the reason is parked in the session, then → /login/failedfailed = (req, why) => {let s = req.sessionlet fresh = s == nullif (fresh) { s = server.sessions.mint() }s.data.loginError = whyserver.sessions.save(s)let res = new Response('login failed: ' + why, { status = 302 headers = { 'Location' = '/login/failed' 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })if (fresh) { res.headers['Set-Cookie'] = server.sessions.cookieHeader(s.id) }return res}// the function route gets the cookie's session as req.session (hybriel #11); none yet → minted hereloginCallback = (route, req) => {if (req.method != 'GET') { return failed(req, 'GET only') }let q = req.query != null ? req.query : {}let code = q.ident_codeif (code == null || code == '') { return failed(req, 'ident sent no login code') }let x = exchangeCode(code)if (x.error != null) { return failed(req, x.error) }let u = ensureUser(x.identity)if (u == null) { return failed(req, 'could not store the user') }let s = req.sessionlet fresh = s == nullif (fresh) { s = server.sessions.mint() }s.user = { id = u.id }s.data.tag = randomBytes(16)s.data.loginError = nullserver.sessions.save(s)let res = new Response('logged in', { status = 302 headers = { 'Location' = safePath(q.next) 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })if (fresh) { res.headers['Set-Cookie'] = server.sessions.cookieHeader(s.id) }return res}routes = [{ pattern = "/favicon.ico" direct = "" }{ pattern = "/login/callback" function = loginCallback }{ pattern = "/login/failed" component = LoginFailed }{ pattern = "/login.js" file = "./login.js" headers = { 'Cache-Control' = 'no-cache' } }{ pattern = "/" component = Home }]// WHO GETS THE PUSH: the login state reaches the tabs of one session (components/main.hl trackerSignedIn/Out).tagOf = (session) => { return session != null && session.data != null ? session.data.tag : null }audience = {trackerSignedIn = (tag, session) => { return tag != null && tagOf(session) == tag }trackerSignedOut = (tag, session) => { return tag != null && tagOf(session) == tag }}// cookies are per host, not per port: an own name keeps this app's session apart from// ident's own (and from any other worldapi app sharing a dev host), see ident README "Design// tokens" / hybriel#10 hybriel#17.sessionCookie = 'trackersid'server = new WebFramework(routes = routes, styles = styles, port = port, sessionCookie = sessionCookie, watchMode = watching)on Error(e) { console.log('error absorbed: ' + e.message) }
Branches
- mainmain branch