gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit91c9fc8c91c9fc8ctracker#5: /unwatched — unwatched released episodes of followed shows, newest firstmre91c9fc8c/project.hl

7.4 KB

  1. // project.hl — tracker.worldapi.org: STEP 1 (tracker.worldapi.org#1), an empty shell. Login copied unchanged from
  2. // calendar.worldapi.org (rejected once for a centered sign-in and no header selector — architect, 2026-09-27):
  3. // ident only, no own passwords (README "How apps use ident" of ident.worldapi.org), the identity selector in the
  4. // header (components/main.hl). No shows, no data yet — later steps come from the creator (CONCEPT.md).
  5. //
  6. // the header's ident-selector / "Log in with ident" -> <ident>/login?key=&return=<this app>/login/callback
  7. // /login/callback?ident_code=<code> the app's server exchanges the code for the identity's short id
  8. // (POST <ident>/api/exchange) and signs this app's OWN session in
  9. // (session.user = { id = <users @id> }, users.hl)
  10. // the header's "Log out" button signs this app's session out via the face trackerLogOut (components/main.hl)
  11. // — ident's own session, and the browser's ident cookie, are untouched
  12. //
  13. // Config (env; no committed secret — the first deploy registers this app in ident and sets these, done by the
  14. // architect, as with ident's own .env for SMTP):
  15. // TRACKER_PORT (45008), TRACKER_URL (this app's own public address, for the return URL),
  16. // IDENT_URL (https://ident.worldapi.org), TRACKER_KEY (pk_…), TRACKER_SECRET (sk_…)
  17. import WebFramework from 'hl:web'
  18. import { Response } from 'hl:http1'
  19. import { randomBytes } from 'hl:crypto'
  20. import { env } from 'hl:proc'
  21. import { readBytes, exists } from 'hl:fs'
  22. import Styles from './styles.hl'
  23. import { exchangeCode, ensureUser } from './users.hl'
  24. import Home from './components/home.hl'
  25. import LoginFailed from './components/loginfailed.hl'
  26. import Show from './components/show.hl'
  27. import Unwatched from './components/unwatched.hl'
  28. static appTitle = "tracker"
  29. styles = Styles
  30. port = env('TRACKER_PORT') != null ? toNumber(env('TRACKER_PORT')) : 45008
  31. watching = env('TRACKER_WATCH') != '0'
  32. // read by hl:web's own manifest config (WebFramework.hl `cfg.sessionDir`), not the constructor call below
  33. sessionDir = env('TRACKER_SESSIONS') != null ? env('TRACKER_SESSIONS') : null
  34. // ---- THE LOGIN BUTTON'S RETURN (ident README "How apps use ident"), copied from calendar.worldapi.org's project.hl
  35. // BACK TO THE PAGE: /login.js puts `?next=` into the button's return URL at the click. Only a same-origin PATH
  36. // goes (one `/`, URL-safe characters, ≤ 500). Anything else → `/`.
  37. nextChars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-._~/?&=%+,;@!$()*:'
  38. safePath = (want) => {
  39. if (want == null || hlTypeName(want) != 'String' || want == '' || want.length > 500) { return '/' }
  40. if (want.slice(0, 1) != '/' || want.slice(0, 2) == '//' || want.slice(0, 7) == '/login/') { return '/' }
  41. let i = 0
  42. while (i < want.length) {
  43. if (!nextChars.includes(want[i])) { return '/' }
  44. i = i + 1
  45. }
  46. return want
  47. }
  48. // A FAILED LOGIN is a page (components/loginfailed.hl): the reason is parked in the session, then → /login/failed
  49. failed = (req, why) => {
  50. let s = req.session
  51. let fresh = s == null
  52. if (fresh) { s = server.sessions.mint() }
  53. s.data.loginError = why
  54. server.sessions.save(s)
  55. let res = new Response('login failed: ' + why, { status = 302 headers = { 'Location' = '/login/failed' 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  56. if (fresh) { res.headers['Set-Cookie'] = server.sessions.cookieHeader(s.id) }
  57. return res
  58. }
  59. // the function route gets the cookie's session as req.session (hybriel #11); none yet → minted here
  60. loginCallback = (route, req) => {
  61. if (req.method != 'GET') { return failed(req, 'GET only') }
  62. let q = req.query != null ? req.query : {}
  63. let code = q.ident_code
  64. if (code == null || code == '') { return failed(req, 'ident sent no login code') }
  65. let x = exchangeCode(code)
  66. if (x.error != null) { return failed(req, x.error) }
  67. let u = ensureUser(x.identity)
  68. if (u == null) { return failed(req, 'could not store the user') }
  69. let s = req.session
  70. let fresh = s == null
  71. if (fresh) { s = server.sessions.mint() }
  72. s.user = { id = u.id }
  73. s.data.tag = randomBytes(16)
  74. s.data.loginError = null
  75. server.sessions.save(s)
  76. let res = new Response('logged in', { status = 302 headers = { 'Location' = safePath(q.next) 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  77. if (fresh) { res.headers['Set-Cookie'] = server.sessions.cookieHeader(s.id) }
  78. return res
  79. }
  80. // ---- /posters/<name> (tracker.worldapi.org#4): a show's poster image, served dynamically from
  81. // storage/mpackdb/posters/ (the poster's file name is the show's oldId + its migrated extension,
  82. // shows.hl posterName) — falls back to a placeholder svg when the real file isn't there yet (the
  83. // mongo export never included the actual poster bytes, see the report's `open`).
  84. postersDir = (env('TRACKER_STORAGE') != null ? env('TRACKER_STORAGE') : './storage/mpackdb') + '/posters'
  85. placeholderPoster = './assets/poster-placeholder.svg'
  86. posterNameChars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_'
  87. isSafePosterName = (name) => {
  88. if (name == null || hlTypeName(name) != 'String' || name == '' || name.length > 100) { return false }
  89. let i = 0
  90. while (i < name.length) {
  91. if (!posterNameChars.includes(name[i])) { return false }
  92. i = i + 1
  93. }
  94. return true
  95. }
  96. endsWithStr = (s, suffix) => { return s.length >= suffix.length && s.slice(s.length - suffix.length) == suffix }
  97. mimeOfPoster = (name) => {
  98. if (endsWithStr(name, '.png')) { return 'image/png' }
  99. if (endsWithStr(name, '.webp')) { return 'image/webp' }
  100. if (endsWithStr(name, '.svg')) { return 'image/svg+xml' }
  101. return 'image/jpeg'
  102. }
  103. posterRoute = (route, req) => {
  104. let name = route.params != null ? route.params.name : null
  105. if (!isSafePosterName(name)) { return new Response('bad poster name', { status = 400 headers = { 'Content-Type' = 'text/plain; charset=utf-8' } }) }
  106. let path = postersDir + '/' + name
  107. if (exists(path)) { return new Response(readBytes(path), { headers = { 'Content-Type' = mimeOfPoster(name) 'Cache-Control' = 'public, max-age=86400' } }) }
  108. return new Response(readBytes(placeholderPoster), { headers = { 'Content-Type' = 'image/svg+xml' 'Cache-Control' = 'public, max-age=3600' } })
  109. }
  110. routes = [
  111. { pattern = "/favicon.ico" direct = "" }
  112. { pattern = "/login/callback" function = loginCallback }
  113. { pattern = "/login/failed" component = LoginFailed }
  114. { pattern = "/login.js" file = "./login.js" headers = { 'Cache-Control' = 'no-cache' } }
  115. { pattern = "/posters/:name" function = posterRoute }
  116. { pattern = "/shows/:slug" component = Show }
  117. { pattern = "/unwatched" component = Unwatched }
  118. { pattern = "/" component = Home }
  119. ]
  120. // WHO GETS THE PUSH: the login state reaches the tabs of one session (components/main.hl trackerSignedIn/Out).
  121. tagOf = (session) => { return session != null && session.data != null ? session.data.tag : null }
  122. audience = {
  123. trackerSignedIn = (tag, session) => { return tag != null && tagOf(session) == tag }
  124. trackerSignedOut = (tag, session) => { return tag != null && tagOf(session) == tag }
  125. }
  126. // cookies are per host, not per port: an own name keeps this app's session apart from
  127. // ident's own (and from any other worldapi app sharing a dev host), see ident README "Design
  128. // tokens" / hybriel#10 hybriel#17.
  129. sessionCookie = 'trackersid'
  130. server = new WebFramework(routes = routes, styles = styles, port = port, sessionCookie = sessionCookie, watchMode = watching)
  131. on Error(e) { console.log('error absorbed: ' + e.message) }

Branches

Latest commits

  • 91c9fc8ctracker#5: /unwatched — unwatched released episodes of followed shows, newest firstmre
  • a97c0295tracker#4: show page /shows/:slug (header, seasons, episodes, watch checks) + tools/relink-episode-seasons.hlmre
  • 05f407c5tracker: no border on any button except inverted ones (Log out, ident status and identities too); header brand weight 100mre
  • 17375427tracker#2: tools/migrate.hl + tools/verify.hl — old MongoDB data into mpackdb with new idsmre
  • 31aac936tracker#3: no border on the header and on filled buttons; inverted buttons keep theirsmre
  • 2ad9d29ctracker#1: login exactly like calendar (identity selector in the header, empty homepage)mre
  • 3691e176tracker#1: empty tracker with the ident login (state of 2026-09-27)mre