gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit31aac93631aac936tracker#3: no border on the header and on filled buttons; inverted buttons keep theirsmre31aac936/STATUS.md

10.4 KB

  1. # STATUS — tracker.worldapi.org
  2. ## 2026-09-27 — ticket #3: no border on the header or filled buttons
  3. Design notes from the first test (architect): "the application-header should have no bottom
  4. border" and "the buttons also no border except they are inverted". Two changes in
  5. `styles.hl`:
  6. - `applicationHeader`: dropped `borderBottom`.
  7. - `ident-selector::part(button)` (the signed-out "choose ident" button): added
  8. `border = 'none'` — the element's own CSS gave it a 1px border the same colour as its
  9. background (`--_accent`), invisible but still a real border in the computed style; this is
  10. the app-side restyling hook ident's README documents (`::part(button)`), not a change to
  11. ident's vendored `selector.js`.
  12. Left unchanged, already correct: the native `button` rule (filled, e.g. no other filled
  13. buttons on this page yet) already has `border = '0'`; `button.quiet` ("Log out") and the
  14. selector's dropdown `[part="identity"]` rows keep their border (transparent background —
  15. inverted style); `a.button` ("Log in with ident") has no border rule and browsers give `<a>`
  16. none by default. The selector's signed-in "logged in with ident" status pill
  17. (`::part(status)`) is not one of the buttons the ticket names and isn't a button element
  18. (a `<span>`) — left with its border.
  19. **Gate** (`tests/browser.mjs`, now 16 checks): added computed-style checks — the header's
  20. `borderBottomWidth` is `0px`; `#loginbutton`'s border is `0px`; the selector's
  21. `[part~="button"]` (inside its shadow root) border is `0px`; `#logout`'s border is NOT `0px`
  22. (still inverted-bordered) once signed in.
  23. ```
  24. node tests/browser.mjs
  25. 16 passed, 0 failed
  26. ```
  27. ## 2026-09-27 — ticket #1 reopened: login redone to match calendar exactly (header selector, empty page)
  28. The architect rejected the first build of ticket #1: the sign-in sat centered on the page
  29. (its own "Sign in with ident" card, identity + sign-out shown in a `homeCard`) instead of
  30. the header identity selector calendar/gitoria use, and there was no `<ident-selector>` at
  31. all. Rebuilt the login by copying calendar.worldapi.org's own files (unchanged in shape, per
  32. the architect's instruction "Copy calendar.worldapi.org's login unchanged"):
  33. - **`users.hl`** (new): the ident exchange + a `usersTable` (`storage/mpackdb/users.db`,
  34. `identity` → this app's user id), copied from calendar's `users.hl` with `TRACKER_KEY` /
  35. `TRACKER_SECRET` / `TRACKER_URL` / `TRACKER_STORAGE` in place of calendar's names (kept
  36. the names already in this app's `docker-compose.yml`/README/DECISIONS rather than
  37. switching to calendar's generic `IDENT_API_KEY`/`IDENT_API_SECRET`).
  38. - **`login.js`** (new): calendar's bridge between `<ident-selector>`'s `ident-login` DOM
  39. event and the hidden `#identcode` input, copied verbatim (creator: "login.js is correct,
  40. as thats for externals in general").
  41. - **`components/main.hl`**: now the header carries `userBox` (`<ident-selector>` + "Log in
  42. with ident" / "Log out"), the `trackerLogin`/`trackerLogOut` faces and the
  43. `trackerSignedIn`/`trackerSignedOut` client push — calendar's shell renamed to this app's
  44. event names.
  45. - **`components/home.hl`**: now truly empty (`View { home {} }`) — no sign-in link, no
  46. identity/sign-out duplicated on the page; that is entirely the header's job now.
  47. - **`components/loginfailed.hl`** (new) + **`project.hl`**: the login routes are now
  48. `/login/callback` (function route, the button's return AND the code exchange) and
  49. `/login/failed`, copied from calendar's `project.hl` (`safePath`, `failed()`,
  50. `loginCallback`) in place of the old `/login` + `/callback` + `/logout` routes; the old
  51. `/logout` POST route is gone (logout is a face, like calendar's).
  52. - **`styles.hl`**: added the header selector styles (`userBox`, `identSelector`,
  53. `ident-selector::part(...)`, sticky header) from calendar's `styles.hl`; dropped the
  54. now-unused `homeCard`/`accountBar`/`userName` rules from the rejected centered sign-in.
  55. **Gate rewritten** (`tests/browser.mjs`, 12 checks): replaced the old gate (which drove
  56. ident's full email-code UI through a vendored dev copy of ident at `.scratch/ident-dev`)
  57. with calendar's own pattern — `tests/identkit.mjs` (copied from calendar unchanged) starts a
  58. throwaway ident (a fresh copy of `/media/STORAGE/projects/ident.worldapi.org`'s code, no
  59. `.env`/storage copied, codes to a mail sink, never the live ident), signs in over its REST
  60. API and registers this app, then the gate proves the header in a real headless Chrome:
  61. signed out → `#selector` + `#loginbutton` in the header, **`main` is empty** → sign in
  62. (`/login/callback?ident_code=`, the same exchange the selector would trigger) → `#selector`
  63. shows `class="in"`, `#logout` appears, **`main` still empty** → sign out → signed out again
  64. → a reload stays signed out. No console errors.
  65. ```
  66. node tests/browser.mjs
  67. 12 passed, 0 failed
  68. ```
  69. `./deploy.sh --dry-run --target .scratch/deploy-preview --url http://127.0.0.1:0/`: gate
  70. passed as step [1/4], rsync preview held none of `storage/`, `.sessions/`, `.env`,
  71. `.scratch/`, `server.*`, logs. Removed the stale `.scratch/ident-dev` (the old gate's vendored
  72. ident copy) and `.scratch/browser-gate` (the old gate's storage) — unused by the new gate.
  73. **Still open**: the app is registered in ident's dev copies only (this gate's own throwaway
  74. ident). The LIVE ident registration (`TRACKER_KEY`/`TRACKER_SECRET` in `.env` next to
  75. `docker-compose.yml`) is the architect's first-deploy step (README "Deploy"), not built here.
  76. ## 2026-09-27 — ticket #2: data migration — blocked twice on sandbox access, nothing done
  77. Two workers in a row (`s-20260927T1029-f57b0f`, then this session) could not start: the
  78. migration source the ticket names, `/media/STORAGE/projects/old-tracker/mongo-export/*.jsonl`
  79. + its `README-RECONSTRUCTED.md`, is not reachable from this worker's sandbox. Verified fresh
  80. this session:
  81. ```
  82. $ ls -la /media/STORAGE/projects/
  83. antcolony-docs hybriel ident.worldapi.org tracker.worldapi.org # no old-tracker
  84. $ mount | grep STORAGE
  85. /dev/nvme1n1p6 on /media/STORAGE/projects/tracker.worldapi.org type btrfs (rw,...)
  86. /dev/nvme1n1p6 on /media/STORAGE/projects/hybriel type btrfs (ro,...)
  87. /dev/nvme1n1p6 on /media/STORAGE/projects/ident.worldapi.org type btrfs (ro,...)
  88. /dev/nvme1n1p6 on /media/STORAGE/projects/antcolony-docs type btrfs (ro,...)
  89. # old-tracker is not among the mounted subvolumes at all
  90. ```
  91. So this is not a data problem (the export is "complete" per the ticket) — it's the worker
  92. sandbox for this ticket that never got `old-tracker` mounted (read-only, like `hybriel` /
  93. `ident.worldapi.org` / `antcolony-docs` above). Nothing was built or changed this session:
  94. no `storage/`, no `tools/`, no id-mapping — writing the migration tool blind, guessing the
  95. JSONL shape from the ticket text alone, risks silently wrong data and was avoided on purpose
  96. (see the project's "Build it properly" rule). Filed as an antcolony issue so the next worker's
  97. sandbox includes `old-tracker` before another attempt.
  98. ## 2026-09-27 — ticket #1: the empty shell, ident login
  99. Built the app from scratch: vendored `bin/hybriel` + `plugins/` + `shared/tokens.hl` from
  100. `ident.worldapi.org` (newest local build, hybriel master 837fe120, no local patch — see
  101. README "Vendored Hybriel"). `project.hl` (routes `/login`, `/callback`, `/logout`, `/`),
  102. `components/home.hl` (the empty homepage), `components/main.hl` (shell), `styles.hl`
  103. (accent green `#4ec9b0`, per `antcolony/README.md` "look and style" / `CONCEPT.md`).
  104. `docker-compose.yml` / `Dockerfile` / `deploy.sh` following ident's own house pattern
  105. (port 45008, container `tracker.worldapi.org`).
  106. **Login**: the ident login BUTTON flow (ident.worldapi.org README "How apps use ident"),
  107. server-side exchange (`POST <ident>/api/exchange`), this app's own framework session
  108. (`session.user = { identity }`, cookie `trackersid`). ident hands over only the identity's
  109. public **short id** — no display name yet (ident#11, properties handover, is on hold) — so
  110. "your name" on the homepage is `Signed in as <shortid>`, the same identifier every other
  111. worldapi app would show; see `decided` in the report.
  112. **Lesson (Hybriel)**: a face that mutates `session.user` (e.g. `signOut`) does NOT
  113. automatically re-render the page — a component's reactive members (`signedIn`, `identity`,
  114. …) are computed once at mount from the framework's read-only session snapshot; a client
  115. handler that calls `emit server X()` must ALSO flip the affected members itself afterwards
  116. (ident's own `components/home.hl` `on doSignOut(e)` does exactly this: `emit server
  117. signOut()` then `signedIn = false` …). Missing that made the sign-out button silently do
  118. nothing client-side (the ack came back `ok:true`, the server-side session really was
  119. cleared — proven by a reload — but the DOM never updated) until copied.
  120. **Gate** (`tests/browser.mjs`, 13 checks): a fresh copy of `ident.worldapi.org`'s code (no
  121. `.env`, no `storage/`, no `.sessions/` — verified empty of secrets/data before first use)
  122. runs as this gate's own ident, on its own storage and its own mail sink (no live ident, no
  123. real mail). The gate registers this app in that dev ident once over the `/__hl/emit` API
  124. (the same one-time step a person does by hand in ident's `/apps` page), then drives the
  125. REAL login-button flow in a real headless Chrome: signed out → click "Sign in with ident" →
  126. ident's email form → the mail-sink code → the first-login optional-names form (Skip) → the
  127. one-identity choice (one click) → back on tracker, "Signed in as `<shortid>`" → "Sign out" →
  128. signed out again → a reload stays signed out. No console errors. Ran twice for stability, 0
  129. failures; no leftover Chrome/hybriel processes after either run.
  130. ```
  131. node tests/browser.mjs
  132. 13 passed, 0 failed
  133. ```
  134. `./deploy.sh --dry-run --target .scratch/deploy-preview --url http://127.0.0.1:0/` (a local
  135. directory, per ident's own convention for testing deploy.sh without touching Byrodin): gate
  136. passed, rsync preview held none of `storage/`, `.sessions/`, `.env`, `.scratch/`, `server.*`,
  137. logs — confirmed by the same grep the script refuses on.
  138. **Open**: the app is not registered with the LIVE ident yet — `TRACKER_KEY`/`TRACKER_SECRET`
  139. are unset until the architect's first deploy does that (README "Deploy"); until then
  140. `/login` on the live site answers a plain error page instead of redirecting (`/` itself
  141. still renders). This is normal for a brand-new app, the same as ident's own SMTP `.env`
  142. before its first deploy — not something this ticket's worker can set (no `.env` access,
  143. and it is a LIVE ident registration).

Branches

Latest commits

  • 31aac936tracker#3: no border on the header and on filled buttons; inverted buttons keep theirsmre
  • 2ad9d29ctracker#1: login exactly like calendar (identity selector in the header, empty homepage)mre
  • 3691e176tracker#1: empty tracker with the ident login (state of 2026-09-27)mre