gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit44b7d9f944b7d9f9tracker#6: /schedule — upcoming episodes of followed shows, soonest firstmre44b7d9f9/STATUS.md

26.3 KB

  1. # STATUS — tracker.worldapi.org
  2. ## 2026-09-27 — ticket #6: /schedule
  3. Built `/schedule` (`components/schedule.hl`): every episode of a show the signed-in user follows
  4. that is NOT yet released (`e.release > today`), soonest first. Creator: "/schedule has a similar
  5. list without check icons for the upcoming episodes of shows followed" — same row shape as
  6. `/unwatched` (`components/unwatched.hl`) minus the check icon.
  7. **Reuse, not copy**: imports the exact same `followedShowIds` (`follows.hl`), `showById` /
  8. `seasonsOfShow` / `episodesOfSeason` (`shows.hl`) that `/unwatched` already uses — nothing new
  9. added to either file. `watches.hl` is not imported at all: a row here is never watched/unwatched,
  10. there is no check icon and no click, so the page needed no per-user watch state and no `on server`
  11. face — the whole component is a single read-only server-side render (`rows` computed once from
  12. `session`, same as every other reactive member here).
  13. **Order**: soonest first, ascending by `release` (a plain `'YYYY-MM-DD'` string, ordering
  14. operators confirmed working against this app's own vendored `bin/hybriel`, same as `/unwatched`'s
  15. STATUS entry) — the ticket named this the architect's own reading ("the creator named the order
  16. only for /unwatched"), so `insertByReleaseAsc` mirrors `/unwatched`'s `insertByReleaseDesc` with
  17. the comparison flipped.
  18. **`decided`**: "upcoming" = `release` strictly after today (not `>=`) — the natural complement of
  19. `/unwatched`'s own `release <= today`, so every released-or-today episode is unambiguously on one
  20. list, never both, never neither.
  21. **Gate** (`tests/browser.mjs`, 35 → 38 checks): reused the same fixture (`tests/seed-show.hl`,
  22. unchanged) — episode 3 already carried a far-future release (`2099-01-01`) for `/unwatched`'s own
  23. "excludes the future one" check; `/schedule` now proves the mirror image with the same fixture:
  24. signed out, no rows, the sign-in message; signed in, only that one future episode shows (the two
  25. already-released ones excluded), no `button.checkicon` anywhere on the page, unaffected by any of
  26. the watch toggles the other checks perform on the same fixture (run in any order — `/schedule`
  27. never reads watch state).
  28. ```
  29. node tests/browser.mjs
  30. 38 passed, 0 failed
  31. ps -eo pid,args | grep [h]l-browser-tier
  32. (nothing)
  33. ```
  34. Updated `README.md` ("What it does (step 6)", Test, Files) and this file.
  35. **Open**: nothing shown on the homepage still points to `/schedule` (same as `/unwatched` before
  36. it — the homepage stays empty per ticket #1's decision).
  37. ## 2026-09-27 — ticket #5: /unwatched
  38. Built `/unwatched`: every episode of a show the signed-in user follows that is already released
  39. (`release` ≤ today, a plain `'YYYY-MM-DD'` string — migrated as-is by `tools/migrate.hl`, never
  40. run through `dateOf`) and not yet watched, newest release first (creator: "/unwatched lists all
  41. unwatched episodes of shows followed in release date desc order").
  42. **Reuse, not copy** (the ticket's own instruction, re "the same check icon and watch logic as the
  43. show page"): `watchClassOf` (watched → `'checkicon solid'`/`'checkicon regular'`) was a private
  44. `static` in `components/show.hl`; moved it to `watches.hl` so both pages import the SAME
  45. definition instead of each declaring their own — `show.hl` now imports it too, nothing duplicated.
  46. `isWatched`/`setWatched` (already in `watches.hl`) needed no change. New `follows.hl`
  47. (`followedShowIds`) and `shows.hl` `showById` (one line) round out the read-only data access this
  48. page and `/schedule` (ticket #6) both need.
  49. **String comparison** (`e.release <= today`, `row.release >= x.release` for the desc sort):
  50. hybriel#2 ("no ordering operators on strings") is filed as still-open in this ticket's brief, but
  51. its own history shows it was fixed and merged to master 2026-09-25 — confirmed directly against
  52. THIS app's own vendored `bin/hybriel` (`'2020-09-03' <= '2026-09-27'` → `true`), so no numeric
  53. date workaround was needed.
  54. **A View text node cannot hold an inline expression** (`"Ep " + row.episodeNumber + " · " +
  55. row.title` inside a tag body) — same rule as View attributes (components/show.hl's own comment:
  56. "a View attribute must be a literal, a member or a field path"), just not documented for text
  57. nodes anywhere yet; it silently rendered `<!-- binary_expression not rendered yet -->` instead of
  58. erroring. Fixed by resolving the label into a plain field (`row.episodeLabel`) once, server-side,
  59. in `unwatchedRowsOf` — the same pattern `show.hl`'s `buildRows` already uses for every other
  60. ternary/concatenation. Not filed as a new Hybriel gap since it's the exact same restriction
  61. already known and worked around elsewhere in this app, just not yet hit for interpolated text.
  62. **Empty state**: signed out (no user, so no follows to show) and signed in with nothing unwatched
  63. both render a message; used `.muted` (colorTextMuted), not `.message` (colorDanger) — the existing
  64. `.message` class is for real errors (the login-failed banner), and an empty list isn't one (a
  65. `decided`, small).
  66. **Gate** (`tests/browser.mjs`, 29 → 35 checks): `tests/seed-show.hl` now takes an optional
  67. `TRACKER_SEED_IDENTITY` and, when given, seeds a fixed user + a follow of the fixture show for it
  68. — the only way to give `/unwatched` a known followed show before the browser ever signs in, since
  69. the real login's `ensureUser` matches an EXISTING `users.db` row by `identity` and reuses its id
  70. rather than minting a new one. The gate learns alice's per-app identity with one throwaway
  71. `ident.exchange` call (consuming one code) before writing the seed. Episode 1/2 of the fixture now
  72. carry a past `release` (`2020-01-01`/`2020-06-15`), episode 3 a far-future one (`2099-01-01`) —
  73. proving both the release-date filter and the desc order. The new checks run signed out (no rows,
  74. the sign-in message), then signed in RIGHT AFTER LOGIN, BEFORE the existing show-page checks that
  75. toggle these same fixture episodes watched (order matters — otherwise `/unwatched` would already
  76. be empty by the time it's tested): both unwatched episodes list newest-first, excluding the
  77. future one; a click on the newest (`Second`, ep 2) removes it from the list; a reload proves the
  78. watch is server-side, leaving only `Pilot` (ep 1).
  79. ```
  80. node tests/browser.mjs
  81. 35 passed, 0 failed
  82. ps -eo pid,args | grep [h]l-browser-tier
  83. (nothing)
  84. ```
  85. Updated `README.md` ("What it does (step 5)", Test, Files) and this file.
  86. **Open**: nothing shown on the homepage still points to `/unwatched` — no navigation exists yet
  87. (the homepage stays empty per ticket #1's decision; a later step, from the creator, presumably
  88. adds it). `/schedule` (ticket #6) is next and reuses `follows.hl`/`shows.hl`/`watches.hl` the same
  89. way.
  90. ## 2026-09-27 — ticket #4: the show page, watch checks (took over a previous half-done session)
  91. Continued from an earlier session that had built the whole page — header, seasons/episodes,
  92. the click-handling redesign to a flat `rows` list rebuilt server-side (`components/show.hl`'s
  93. own header comment explains why: a nested `for` over seasons > episodes risks hybriel#86) — but
  94. left with the gate red: clicking a check never turned it solid, no console error, and the
  95. session ran out of budget before finding why.
  96. **The actual bug**: the show page's own pure helpers (`buildRows`, `genreRowsOf`, `castRowsOf`,
  97. `watchClassOf`, `initialCollapsed`) were plain instance members (`buildRows = (show, …) => {…}`,
  98. no `static`). That shape works fine as a member's own top-level initializer (`rows = found ?
  99. buildRows(showRow, watchRows, collapsed) : []` — this is how the page renders correctly on first
  100. load) but throws when the SAME function is called from inside an `on server` face
  101. (`showToggleEpisode` etc.): the server log showed `'buildRows' is not callable — it holds null`.
  102. Found by running `.scratch/debug-click.mjs` (left by the previous session) with the server's
  103. stdout/stderr captured — the browser console itself stayed silent (the face's error never
  104. reaches the client at all, a separate Hybriel gap, hybriel#92 already covers that half).
  105. Confirmed the fix by grepping other worldapi apps for the same shape:
  106. `calendar.worldapi.org/components/calendar.hl` has `static soonOf = (u) => { … upcoming(u, …) }`
  107. (an mpackdb-backed helper), called from its `on server calLoad`/`calSettingsLoad` faces, and
  108. calendar's own gate is green — so `static` is the proven-safe shape for a component's own helper
  109. that both (a) touches an mpackdb-backed import and (b) needs calling from more than one place
  110. (its own initializer AND a later face). Declared all five helpers in `show.hl` `static`; reran
  111. the gate: 29/29 green, including the season-bulk-toggle and the reload-proves-server-side checks.
  112. Filed **hybriel#115 was already open** (from the previous session, about the CLIENT bundle
  113. omitting a case for such a helper) but this session's finding is the SAME root cause reaching
  114. further than that ticket says: the plain HL interpreter on the SERVER also treats such a helper
  115. as `null` outside its own initializer, not just the JS-compiled client bundle. Left as one
  116. `issues` entry pointing at hybriel#115 rather than opening a near-duplicate ticket — the
  117. repro/observed there already generalizes (a per-instance member function wrapping an
  118. mpackdb-backed import is unreliable wherever it is called from, not just the browser).
  119. Ran `node tests/browser.mjs`: 29 passed, 0 failed (was 20 passed / 1 failed — the click timeout
  120. — before the `static` fix).
  121. **Rehearsed `tools/relink-episode-seasons.hl` against a full COPY** of the real
  122. `storage/mpackdb/` (`.scratch/relink-rehearsal/`, since removed) — the tool's own header claimed
  123. this rehearsal already existed here; it didn't (a leftover claim from the previous session), so
  124. this session actually ran it:
  125. ```
  126. relink: episodes 231584, null season before 36194, linked 36194, still null (no matching season) 0
  127. relink: episodes.db replaced with the relinked file — re-run to confirm idempotency (0 linked the second time)
  128. ```
  129. Ran a second time on the same copy straight after — idempotency confirmed:
  130. ```
  131. relink: episodes 231584, null season before 0, linked 0, still null (no matching season) 0
  132. ```
  133. All 36,194 pre-existing null-season episodes (ticket #2's count) now link to a real season by
  134. `(show, seasonNumber)`; none left over. Not run against the LIVE `storage/mpackdb/` — that needs
  135. the tracker container stopped first (hl:mpackdb does not coordinate two processes on one storage
  136. directory, hybriel#21), the architect's job per the ticket ("the architect runs it live").
  137. Updated README.md ("What it does (step 4)", Test, Files) and this file.
  138. ## 2026-09-27 — ticket #2: old data migrated (took over a previous session's rewritten tool)
  139. Continued from an earlier session that had rewritten `tools/migrate.hl` to avoid a real data-loss
  140. bug (see below) but never run it even once, and had left the real `storage/mpackdb/` holding data
  141. from the OLDER, buggy two-pass version of the tool (put a bare record, then `update()` it once the
  142. other side of a circular reference existed). Took over: moved that buggy data aside
  143. (`.scratch/pre-migrate-buggy-backup`, since removed), kept `storage/mpackdb/users.db` (step 1's
  144. login table, untouched by the migration), and ran the already-fixed tool for the first time.
  145. **The fix already on disk (kept as is):** `Show.seasons`/`Season.show` and `Show.cast`/
  146. `Person.shows` are two-way references, so the id on one side must exist before the record on the
  147. other side can be built. The old approach — `put()` a bare record, come back with `update()` once
  148. the far side's id exists — loses rows: reopening a table in a fresh process after an `update()` had
  149. touched it read back FEWER rows than were ever `put()` (seen directly: `persons.db`'s `count()`
  150. dropped 15157 → 15152 after one round of `update()` — a real `hl:mpackdb` bug, reported to Hybriel,
  151. not something an app is allowed to patch around). The fix assigns every new id itself (8 random
  152. bytes, `hl:crypto`) in one pass over each export file BEFORE building any record, so by the time a
  153. record is actually built every reference is already a known id — one `put()` per row, `update()`
  154. never called.
  155. **Run** (`tools/migrate.hl`, `TRACKER_OLD_DATA=.../old-tracker/mongo-export`,
  156. `TRACKER_STORAGE=$PWD/storage/mpackdb`):
  157. ```
  158. migrate: genres 27 new, 0 already there (old 27 -> new 27)
  159. migrate: persons 15157 new, 0 already there (old 15157 -> new 15157), show refs skipped 0
  160. migrate: shows 9453 new, 0 already there (old 9453 -> new 9453), cast refs skipped 0, genre refs skipped 0, season refs skipped 0
  161. migrate: seasons 6430 new, 0 already there (old 6430 -> new 6430), show refs skipped 0, episode refs skipped 0
  162. migrate: episodes 231584 new, 0 already there (old 231584 -> new 231584), show refs skipped 0, season refs left null (pre-existing) 1
  163. migrate: follows 128 new, 0 already there (old 128 -> new 128), show refs skipped 0
  164. migrate: watches 11692 new, 0 already there (old 11692 -> new 11692), target refs left null (pre-existing) 3
  165. migrate: 0 failed
  166. ```
  167. Every count equals the old export's own document count (`old-tracker/README-RECONSTRUCTED.md`:
  168. Show 9453, Season 6430, Episode 231584, Person 15157, Genre 27, Follow 128, Watch 11692). Ran a
  169. second time straight after (idempotency: the tool's `oldId` index finds each row again) — every
  170. table printed `0 new`, all rows `already there`, counts unchanged, 0 failed: the id-loss bug does
  171. not resurface across a real close-and-reopen.
  172. **Proof beyond the tool's own counters** (`tools/verify.hl`, new): the ticket asks for a check that
  173. does not just trust `migrate.hl`'s own "skipped" tallies. It runs against a plain filesystem COPY
  174. of `storage/mpackdb/` (hl:mpackdb rewrites a file's data on open, so the live store is never opened
  175. a second time) and independently re-derives, from the persisted records alone: every table's
  176. `count()` against the export's own document count, and — by building id sets for every table and
  177. walking every reference field (`Show.genres/cast/seasons`, `Season.show/episodes`,
  178. `Episode.show/season`, `Person.shows`, `Follow.show/user`, `Watch.target/user`) — that every
  179. non-null reference resolves to a real id. It also follows one show end to end (`Raised by Wolves`,
  180. 2 seasons, 18 episodes, 1 follow, 2 season-level watches — all cross-checked back to the show).
  181. ```
  182. $ cp -r storage/mpackdb .scratch/verify-copy && TRACKER_VERIFY_COPY=$PWD/.scratch/verify-copy ./bin/hybriel tools/verify.hl
  183. count ok genres: 27 (expected 27)
  184. count ok persons: 15157 (expected 15157)
  185. count ok shows: 9453 (expected 9453)
  186. count ok seasons: 6430 (expected 6430)
  187. count ok episodes: 231584 (expected 231584)
  188. count ok follows: 128 (expected 128)
  189. count ok watches: 11692 (expected 11692)
  190. users: 1 (expected 1, the creator)
  191. dangling references: 0 (episodes with a pre-existing null season: 36194, watches with a pre-existing null target: 3 — not dangling, the export already had no target)
  192. END-TO-END show 105ad9c91b14d663 "Raised by Wolves" seasons=2
  193. season 1 (be2965a5ab7165ca) episodes=10 show-back-ref-ok=true
  194. season 2 (0fe4e53157ed0367) episodes=8 show-back-ref-ok=true
  195. total episodes across seasons: 18
  196. follows on this show: 1, season-level watches touching it: 2
  197. VERIFY PASS
  198. ```
  199. (36194 episodes with no season = 36193 that never had one in the old export, plus the 1 the tool's
  200. own count already named as a pre-existing dangling `season` reference in the source data — neither
  201. is a reference this migration broke; `dangling references: 0` covers exactly that.)
  202. The single old user (`User.jsonl`, `[email protected]`, password not taken over) is this app's
  203. user for ident short id `az5b2` (`storage/mpackdb/users.db`, the same table step 1's login uses) —
  204. confirmed in the copy: one record, `identity=az5b2`.
  205. **Two Hybriel bugs found while building this** (both already filed as issues on this ticket by an
  206. earlier session, not re-filed): `hl:fs readFile` silently truncates at 10 MiB (worked around here
  207. with `split`, no shell, no JS, see `tools/migrate.hl`'s header comment) and `hl:mpackdb` loses rows
  208. across `update()` + reopen (the reason this tool never calls `update()`).
  209. **Open**: nothing shown yet — this ticket is data-only, on purpose (the next step, from the
  210. creator, is showing the data in the UI).
  211. ## 2026-09-27 — ticket #3: no border on the header or filled buttons
  212. Design notes from the first test (architect): "the application-header should have no bottom
  213. border" and "the buttons also no border except they are inverted". Two changes in
  214. `styles.hl`:
  215. - `applicationHeader`: dropped `borderBottom`.
  216. - `ident-selector::part(button)` (the signed-out "choose ident" button): added
  217. `border = 'none'` — the element's own CSS gave it a 1px border the same colour as its
  218. background (`--_accent`), invisible but still a real border in the computed style; this is
  219. the app-side restyling hook ident's README documents (`::part(button)`), not a change to
  220. ident's vendored `selector.js`.
  221. Left unchanged, already correct: the native `button` rule (filled, e.g. no other filled
  222. buttons on this page yet) already has `border = '0'`; `button.quiet` ("Log out") and the
  223. selector's dropdown `[part="identity"]` rows keep their border (transparent background —
  224. inverted style); `a.button` ("Log in with ident") has no border rule and browsers give `<a>`
  225. none by default. The selector's signed-in "logged in with ident" status pill
  226. (`::part(status)`) is not one of the buttons the ticket names and isn't a button element
  227. (a `<span>`) — left with its border.
  228. **Gate** (`tests/browser.mjs`, now 16 checks): added computed-style checks — the header's
  229. `borderBottomWidth` is `0px`; `#loginbutton`'s border is `0px`; the selector's
  230. `[part~="button"]` (inside its shadow root) border is `0px`; `#logout`'s border is NOT `0px`
  231. (still inverted-bordered) once signed in.
  232. ```
  233. node tests/browser.mjs
  234. 16 passed, 0 failed
  235. ```
  236. ## 2026-09-27 — ticket #1 reopened: login redone to match calendar exactly (header selector, empty page)
  237. The architect rejected the first build of ticket #1: the sign-in sat centered on the page
  238. (its own "Sign in with ident" card, identity + sign-out shown in a `homeCard`) instead of
  239. the header identity selector calendar/gitoria use, and there was no `<ident-selector>` at
  240. all. Rebuilt the login by copying calendar.worldapi.org's own files (unchanged in shape, per
  241. the architect's instruction "Copy calendar.worldapi.org's login unchanged"):
  242. - **`users.hl`** (new): the ident exchange + a `usersTable` (`storage/mpackdb/users.db`,
  243. `identity` → this app's user id), copied from calendar's `users.hl` with `TRACKER_KEY` /
  244. `TRACKER_SECRET` / `TRACKER_URL` / `TRACKER_STORAGE` in place of calendar's names (kept
  245. the names already in this app's `docker-compose.yml`/README/DECISIONS rather than
  246. switching to calendar's generic `IDENT_API_KEY`/`IDENT_API_SECRET`).
  247. - **`login.js`** (new): calendar's bridge between `<ident-selector>`'s `ident-login` DOM
  248. event and the hidden `#identcode` input, copied verbatim (creator: "login.js is correct,
  249. as thats for externals in general").
  250. - **`components/main.hl`**: now the header carries `userBox` (`<ident-selector>` + "Log in
  251. with ident" / "Log out"), the `trackerLogin`/`trackerLogOut` faces and the
  252. `trackerSignedIn`/`trackerSignedOut` client push — calendar's shell renamed to this app's
  253. event names.
  254. - **`components/home.hl`**: now truly empty (`View { home {} }`) — no sign-in link, no
  255. identity/sign-out duplicated on the page; that is entirely the header's job now.
  256. - **`components/loginfailed.hl`** (new) + **`project.hl`**: the login routes are now
  257. `/login/callback` (function route, the button's return AND the code exchange) and
  258. `/login/failed`, copied from calendar's `project.hl` (`safePath`, `failed()`,
  259. `loginCallback`) in place of the old `/login` + `/callback` + `/logout` routes; the old
  260. `/logout` POST route is gone (logout is a face, like calendar's).
  261. - **`styles.hl`**: added the header selector styles (`userBox`, `identSelector`,
  262. `ident-selector::part(...)`, sticky header) from calendar's `styles.hl`; dropped the
  263. now-unused `homeCard`/`accountBar`/`userName` rules from the rejected centered sign-in.
  264. **Gate rewritten** (`tests/browser.mjs`, 12 checks): replaced the old gate (which drove
  265. ident's full email-code UI through a vendored dev copy of ident at `.scratch/ident-dev`)
  266. with calendar's own pattern — `tests/identkit.mjs` (copied from calendar unchanged) starts a
  267. throwaway ident (a fresh copy of `/media/STORAGE/projects/ident.worldapi.org`'s code, no
  268. `.env`/storage copied, codes to a mail sink, never the live ident), signs in over its REST
  269. API and registers this app, then the gate proves the header in a real headless Chrome:
  270. signed out → `#selector` + `#loginbutton` in the header, **`main` is empty** → sign in
  271. (`/login/callback?ident_code=`, the same exchange the selector would trigger) → `#selector`
  272. shows `class="in"`, `#logout` appears, **`main` still empty** → sign out → signed out again
  273. → a reload stays signed out. No console errors.
  274. ```
  275. node tests/browser.mjs
  276. 12 passed, 0 failed
  277. ```
  278. `./deploy.sh --dry-run --target .scratch/deploy-preview --url http://127.0.0.1:0/`: gate
  279. passed as step [1/4], rsync preview held none of `storage/`, `.sessions/`, `.env`,
  280. `.scratch/`, `server.*`, logs. Removed the stale `.scratch/ident-dev` (the old gate's vendored
  281. ident copy) and `.scratch/browser-gate` (the old gate's storage) — unused by the new gate.
  282. **Still open**: the app is registered in ident's dev copies only (this gate's own throwaway
  283. ident). The LIVE ident registration (`TRACKER_KEY`/`TRACKER_SECRET` in `.env` next to
  284. `docker-compose.yml`) is the architect's first-deploy step (README "Deploy"), not built here.
  285. ## 2026-09-27 — ticket #2: data migration — blocked twice on sandbox access, nothing done
  286. Two workers in a row (`s-20260927T1029-f57b0f`, then this session) could not start: the
  287. migration source the ticket names, `/media/STORAGE/projects/old-tracker/mongo-export/*.jsonl`
  288. + its `README-RECONSTRUCTED.md`, is not reachable from this worker's sandbox. Verified fresh
  289. this session:
  290. ```
  291. $ ls -la /media/STORAGE/projects/
  292. antcolony-docs hybriel ident.worldapi.org tracker.worldapi.org # no old-tracker
  293. $ mount | grep STORAGE
  294. /dev/nvme1n1p6 on /media/STORAGE/projects/tracker.worldapi.org type btrfs (rw,...)
  295. /dev/nvme1n1p6 on /media/STORAGE/projects/hybriel type btrfs (ro,...)
  296. /dev/nvme1n1p6 on /media/STORAGE/projects/ident.worldapi.org type btrfs (ro,...)
  297. /dev/nvme1n1p6 on /media/STORAGE/projects/antcolony-docs type btrfs (ro,...)
  298. # old-tracker is not among the mounted subvolumes at all
  299. ```
  300. So this is not a data problem (the export is "complete" per the ticket) — it's the worker
  301. sandbox for this ticket that never got `old-tracker` mounted (read-only, like `hybriel` /
  302. `ident.worldapi.org` / `antcolony-docs` above). Nothing was built or changed this session:
  303. no `storage/`, no `tools/`, no id-mapping — writing the migration tool blind, guessing the
  304. JSONL shape from the ticket text alone, risks silently wrong data and was avoided on purpose
  305. (see the project's "Build it properly" rule). Filed as an antcolony issue so the next worker's
  306. sandbox includes `old-tracker` before another attempt.
  307. ## 2026-09-27 — ticket #1: the empty shell, ident login
  308. Built the app from scratch: vendored `bin/hybriel` + `plugins/` + `shared/tokens.hl` from
  309. `ident.worldapi.org` (newest local build, hybriel master 837fe120, no local patch — see
  310. README "Vendored Hybriel"). `project.hl` (routes `/login`, `/callback`, `/logout`, `/`),
  311. `components/home.hl` (the empty homepage), `components/main.hl` (shell), `styles.hl`
  312. (accent green `#4ec9b0`, per `antcolony/README.md` "look and style" / `CONCEPT.md`).
  313. `docker-compose.yml` / `Dockerfile` / `deploy.sh` following ident's own house pattern
  314. (port 45008, container `tracker.worldapi.org`).
  315. **Login**: the ident login BUTTON flow (ident.worldapi.org README "How apps use ident"),
  316. server-side exchange (`POST <ident>/api/exchange`), this app's own framework session
  317. (`session.user = { identity }`, cookie `trackersid`). ident hands over only the identity's
  318. public **short id** — no display name yet (ident#11, properties handover, is on hold) — so
  319. "your name" on the homepage is `Signed in as <shortid>`, the same identifier every other
  320. worldapi app would show; see `decided` in the report.
  321. **Lesson (Hybriel)**: a face that mutates `session.user` (e.g. `signOut`) does NOT
  322. automatically re-render the page — a component's reactive members (`signedIn`, `identity`,
  323. …) are computed once at mount from the framework's read-only session snapshot; a client
  324. handler that calls `emit server X()` must ALSO flip the affected members itself afterwards
  325. (ident's own `components/home.hl` `on doSignOut(e)` does exactly this: `emit server
  326. signOut()` then `signedIn = false` …). Missing that made the sign-out button silently do
  327. nothing client-side (the ack came back `ok:true`, the server-side session really was
  328. cleared — proven by a reload — but the DOM never updated) until copied.
  329. **Gate** (`tests/browser.mjs`, 13 checks): a fresh copy of `ident.worldapi.org`'s code (no
  330. `.env`, no `storage/`, no `.sessions/` — verified empty of secrets/data before first use)
  331. runs as this gate's own ident, on its own storage and its own mail sink (no live ident, no
  332. real mail). The gate registers this app in that dev ident once over the `/__hl/emit` API
  333. (the same one-time step a person does by hand in ident's `/apps` page), then drives the
  334. REAL login-button flow in a real headless Chrome: signed out → click "Sign in with ident" →
  335. ident's email form → the mail-sink code → the first-login optional-names form (Skip) → the
  336. one-identity choice (one click) → back on tracker, "Signed in as `<shortid>`" → "Sign out" →
  337. signed out again → a reload stays signed out. No console errors. Ran twice for stability, 0
  338. failures; no leftover Chrome/hybriel processes after either run.
  339. ```
  340. node tests/browser.mjs
  341. 13 passed, 0 failed
  342. ```
  343. `./deploy.sh --dry-run --target .scratch/deploy-preview --url http://127.0.0.1:0/` (a local
  344. directory, per ident's own convention for testing deploy.sh without touching Byrodin): gate
  345. passed, rsync preview held none of `storage/`, `.sessions/`, `.env`, `.scratch/`, `server.*`,
  346. logs — confirmed by the same grep the script refuses on.
  347. **Open**: the app is not registered with the LIVE ident yet — `TRACKER_KEY`/`TRACKER_SECRET`
  348. are unset until the architect's first deploy does that (README "Deploy"); until then
  349. `/login` on the live site answers a plain error page instead of redirecting (`/` itself
  350. still renders). This is normal for a brand-new app, the same as ident's own SMTP `.env`
  351. before its first deploy — not something this ticket's worker can set (no `.env` access,
  352. and it is a LIVE ident registration).

Branches

Latest commits

  • 44b7d9f9tracker#6: /schedule — upcoming episodes of followed shows, soonest firstmre
  • 91c9fc8ctracker#5: /unwatched — unwatched released episodes of followed shows, newest firstmre
  • a97c0295tracker#4: show page /shows/:slug (header, seasons, episodes, watch checks) + tools/relink-episode-seasons.hlmre
  • 05f407c5tracker: no border on any button except inverted ones (Log out, ident status and identities too); header brand weight 100mre
  • 17375427tracker#2: tools/migrate.hl + tools/verify.hl — old MongoDB data into mpackdb with new idsmre
  • 31aac936tracker#3: no border on the header and on filled buttons; inverted buttons keep theirsmre
  • 2ad9d29ctracker#1: login exactly like calendar (identity selector in the header, empty homepage)mre
  • 3691e176tracker#1: empty tracker with the ident login (state of 2026-09-27)mre