gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit3691e1763691e176tracker#1: empty tracker with the ident login (state of 2026-09-27)mre3691e176/README.md

6.6 KB

  1. # tracker.worldapi.org
  2. The new tracker: a Hybriel app that will track the TV shows (and later movies) the creator
  3. follows and watches. **`CONCEPT.md` (the creator's) is the source of truth** — read it first;
  4. nothing is built that it does not describe. Built step by step, one ticket per step
  5. (tracker.worldapi.org#1, #2, …).
  6. **Built so far — step 1, ticket #1**: the shell. Sign in with ident, an empty homepage
  7. (your identity + a sign-out button), sign out. No shows, no data, no design carried over
  8. from the old app.
  9. Written in **Hybriel** on **hl:web**, same stack and conventions as `ident.worldapi.org`
  10. (vendored plugins/binary copied from there, see "Vendored Hybriel").
  11. ## Run (dev, Loreana)
  12. ```bash
  13. cd /media/STORAGE/projects/tracker.worldapi.org
  14. TRACKER_PORT=8700 setsid nohup ./bin/hybriel project.hl > server.log 2>&1 < /dev/null & echo $! > server.pid
  15. # stop: kill $(cat server.pid)
  16. ```
  17. * Config (env; the real environment outranks nothing here — there is no `.env` reader in
  18. project.hl, unlike ident's SMTP settings — set these in the shell or `docker-compose.yml`):
  19. | Variable | Default | |
  20. |---|---|---|
  21. | `TRACKER_PORT` | 45008 | |
  22. | `TRACKER_URL` | `http://127.0.0.1:<port>` | this app's own origin — the ident login button's `return=` is built from it |
  23. | `IDENT_URL` | `https://ident.worldapi.org` | |
  24. | `TRACKER_KEY` / `TRACKER_SECRET` | `''` | this app's API key + secret, from ident's `/apps` (register once, origin = `TRACKER_URL`) — **not set yet on Byrodin**: the first deploy (architect) registers the app in the live ident and puts these in `.env` next to `docker-compose.yml`, exactly like ident's own `.env` holds its SMTP settings |
  25. | `TRACKER_WATCH` | on | `0` = no dev watcher (the container) |
  26. | `HL_HOST` (or `HOST`) | 0.0.0.0 | interface to bind; `127.0.0.1` on Byrodin |
  27. Without `TRACKER_KEY`/`TRACKER_SECRET`, `/` still renders (signed out); `/login` answers a
  28. plain error page ("not registered with ident yet") instead of redirecting — so the app is
  29. never a dead 500 while waiting for that one-time setup.
  30. ## What it does (step 1)
  31. * **Login, exactly like calendar/notes**: ident only, no own passwords (ident's login
  32. button flow, ident.worldapi.org README "How apps use ident"). `GET /login` sends the
  33. browser to `<ident>/login?key=…&return=<this app>/callback`; `/callback` exchanges the
  34. one-time code for the identity's **short id** (`POST <ident>/api/exchange` — nothing else:
  35. ident does not hand over a display name yet, that is ident#23 done / ident#11 on hold) and
  36. signs this app's OWN session in (`session.user = { identity }`, this app's own cookie
  37. `trackersid` — cookies ignore ports, an own name keeps it apart from ident's `identsid` on
  38. the same dev host, hybriel#10/#17). `POST /logout` (the homepage's "Sign out" button) ends
  39. only this app's session; ident's own login is untouched.
  40. * **The empty homepage** (`/`, `components/home.hl`): signed out — a "Sign in with ident"
  41. link. Signed in — "Signed in as `<shortid>`" and "Sign out". Nothing else.
  42. * **No data at all**: no mpackdb table, no `storage/`. Step 2 (tracker.worldapi.org#2, on
  43. hold until the architect reopens it) brings the old tracker's data across.
  44. ## Test
  45. ```bash
  46. node tests/browser.mjs # THE GATE: a real ident copy (own storage, own mail sink —
  47. # no live ident, no real mail) + a real headless Chrome:
  48. # signed out -> sign in (email code, skip the optional-names
  49. # form, choose the one identity) -> homepage shows the identity
  50. # + sign out -> signed out again -> a reload stays signed out.
  51. # 13 checks. Own servers :8703 (ident dev copy) / :8704 (this
  52. # app); own storage .scratch/browser-gate; Chrome on 8705-8709.
  53. ps -eo pid,args | grep [h]l-browser-tier # must print nothing afterwards
  54. ```
  55. ## Deploy (Byrodin)
  56. Target: `/CONTAINERS/projects/tracker.worldapi.org` on Byrodin, container
  57. `tracker.worldapi.org` (`docker-compose.yml`: debian:12-slim, host network,
  58. `HL_HOST=127.0.0.1`, `TRACKER_PORT=45008`, `TRACKER_WATCH=0`, the folder mounted at
  59. `/home/tracker`, `./bin/hybriel project.hl`), public https://tracker.worldapi.org/ via
  60. nginx (TLS ends there; no baseUrl/tls in the app, like ident/notes).
  61. * **First deploy: done by the architect** (folder, nginx vhost with WebSocket Upgrade
  62. headers, cert, DNS, **and registering this app in the live ident** — `/apps` → name +
  63. origin `https://tracker.worldapi.org` → the API key + secret go into `.env` next to
  64. `docker-compose.yml`, `TRACKER_KEY=… TRACKER_SECRET=…`).
  65. * **Later: `./deploy.sh`** on Loreana, in this folder: runs the gate (refuses on a failure;
  66. `--skip-tests` skips it LOUDLY), rsyncs the code to
  67. `[email protected]:/CONTAINERS/projects/tracker.worldapi.org` (never `storage/`,
  68. `.sessions/`, `.env`, `.scratch/`, `server.*`, logs — the preview is checked for them; no
  69. `--delete`), `docker compose up -d && docker compose restart` over `ssh -F /dev/null`,
  70. then waits for https://tracker.worldapi.org/ to answer 200.
  71. * `./deploy.sh --dry-run` = the gate + `rsync -n` + the commands it would run (no restart, no
  72. URL check). `--target DIR|HOST:DIR` and `--url URL` point it elsewhere (tested against a
  73. local directory, see STATUS.md).
  74. ## Data
  75. None yet (step 1 has no shows, no per-user data — only this app's own framework session,
  76. which holds the signed-in identity's short id and nothing else). Step 2 brings the old
  77. tracker's mpackdb tables (mongo export → mpackdb, new ids, references re-pointed).
  78. ## Files
  79. | File | |
  80. |---|---|
  81. | `CONCEPT.md` | the creator's concept — do not edit |
  82. | `project.hl` | manifest: routes (`/login`, `/callback`, `/logout`, `/` component Home), the app's own session cookie |
  83. | `components/home.hl` | `/`: the empty homepage, signed in / signed out |
  84. | `components/main.hl` | the shell (header) |
  85. | `styles.hl` | all CSS (imports the tokens from `shared/tokens.hl`; accent green `#4ec9b0`) |
  86. | `shared/tokens.hl` | the WorldAPI tokens, vendored verbatim from `ident.worldapi.org/shared/tokens.hl` |
  87. | `tests/browser.mjs` | the gate (above) |
  88. | `tests/cdp.mjs`, `tests/ports.mjs` | the CDP browser driver, copied from `ident.worldapi.org/tests/` |
  89. | `docker-compose.yml`, `Dockerfile`, `deploy.sh` | Byrodin container; the deploy from Loreana (section "Deploy") |
  90. ## Vendored Hybriel
  91. `bin/hybriel` + `plugins/` copied verbatim from `ident.worldapi.org` (2026-09-27), sha256
  92. `9e5e95b33680eb68a016e9e48a76c9f92193fd2ffdbdf437c1aab1bda2731a0d` — hybriel master
  93. 837fe120 (ident's mission 036), the newest vendored+gated build available locally. No local
  94. patch. Re-vendor the same way: copy `bin/hybriel` + `plugins/` from a current worldapi app,
  95. run the gate.

Branches

Latest commits

  • 3691e176tracker#1: empty tracker with the ident login (state of 2026-09-27)mre