gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commita97c0295a97c0295tracker#4: show page /shows/:slug (header, seasons, episodes, watch checks) + tools/relink-episode-seasons.hlmrea97c0295/STATUS.md

19.7 KB

  1. # STATUS — tracker.worldapi.org
  2. ## 2026-09-27 — ticket #4: the show page, watch checks (took over a previous half-done session)
  3. Continued from an earlier session that had built the whole page — header, seasons/episodes,
  4. the click-handling redesign to a flat `rows` list rebuilt server-side (`components/show.hl`'s
  5. own header comment explains why: a nested `for` over seasons > episodes risks hybriel#86) — but
  6. left with the gate red: clicking a check never turned it solid, no console error, and the
  7. session ran out of budget before finding why.
  8. **The actual bug**: the show page's own pure helpers (`buildRows`, `genreRowsOf`, `castRowsOf`,
  9. `watchClassOf`, `initialCollapsed`) were plain instance members (`buildRows = (show, …) => {…}`,
  10. no `static`). That shape works fine as a member's own top-level initializer (`rows = found ?
  11. buildRows(showRow, watchRows, collapsed) : []` — this is how the page renders correctly on first
  12. load) but throws when the SAME function is called from inside an `on server` face
  13. (`showToggleEpisode` etc.): the server log showed `'buildRows' is not callable — it holds null`.
  14. Found by running `.scratch/debug-click.mjs` (left by the previous session) with the server's
  15. stdout/stderr captured — the browser console itself stayed silent (the face's error never
  16. reaches the client at all, a separate Hybriel gap, hybriel#92 already covers that half).
  17. Confirmed the fix by grepping other worldapi apps for the same shape:
  18. `calendar.worldapi.org/components/calendar.hl` has `static soonOf = (u) => { … upcoming(u, …) }`
  19. (an mpackdb-backed helper), called from its `on server calLoad`/`calSettingsLoad` faces, and
  20. calendar's own gate is green — so `static` is the proven-safe shape for a component's own helper
  21. that both (a) touches an mpackdb-backed import and (b) needs calling from more than one place
  22. (its own initializer AND a later face). Declared all five helpers in `show.hl` `static`; reran
  23. the gate: 29/29 green, including the season-bulk-toggle and the reload-proves-server-side checks.
  24. Filed **hybriel#115 was already open** (from the previous session, about the CLIENT bundle
  25. omitting a case for such a helper) but this session's finding is the SAME root cause reaching
  26. further than that ticket says: the plain HL interpreter on the SERVER also treats such a helper
  27. as `null` outside its own initializer, not just the JS-compiled client bundle. Left as one
  28. `issues` entry pointing at hybriel#115 rather than opening a near-duplicate ticket — the
  29. repro/observed there already generalizes (a per-instance member function wrapping an
  30. mpackdb-backed import is unreliable wherever it is called from, not just the browser).
  31. Ran `node tests/browser.mjs`: 29 passed, 0 failed (was 20 passed / 1 failed — the click timeout
  32. — before the `static` fix).
  33. **Rehearsed `tools/relink-episode-seasons.hl` against a full COPY** of the real
  34. `storage/mpackdb/` (`.scratch/relink-rehearsal/`, since removed) — the tool's own header claimed
  35. this rehearsal already existed here; it didn't (a leftover claim from the previous session), so
  36. this session actually ran it:
  37. ```
  38. relink: episodes 231584, null season before 36194, linked 36194, still null (no matching season) 0
  39. relink: episodes.db replaced with the relinked file — re-run to confirm idempotency (0 linked the second time)
  40. ```
  41. Ran a second time on the same copy straight after — idempotency confirmed:
  42. ```
  43. relink: episodes 231584, null season before 0, linked 0, still null (no matching season) 0
  44. ```
  45. All 36,194 pre-existing null-season episodes (ticket #2's count) now link to a real season by
  46. `(show, seasonNumber)`; none left over. Not run against the LIVE `storage/mpackdb/` — that needs
  47. the tracker container stopped first (hl:mpackdb does not coordinate two processes on one storage
  48. directory, hybriel#21), the architect's job per the ticket ("the architect runs it live").
  49. Updated README.md ("What it does (step 4)", Test, Files) and this file.
  50. ## 2026-09-27 — ticket #2: old data migrated (took over a previous session's rewritten tool)
  51. Continued from an earlier session that had rewritten `tools/migrate.hl` to avoid a real data-loss
  52. bug (see below) but never run it even once, and had left the real `storage/mpackdb/` holding data
  53. from the OLDER, buggy two-pass version of the tool (put a bare record, then `update()` it once the
  54. other side of a circular reference existed). Took over: moved that buggy data aside
  55. (`.scratch/pre-migrate-buggy-backup`, since removed), kept `storage/mpackdb/users.db` (step 1's
  56. login table, untouched by the migration), and ran the already-fixed tool for the first time.
  57. **The fix already on disk (kept as is):** `Show.seasons`/`Season.show` and `Show.cast`/
  58. `Person.shows` are two-way references, so the id on one side must exist before the record on the
  59. other side can be built. The old approach — `put()` a bare record, come back with `update()` once
  60. the far side's id exists — loses rows: reopening a table in a fresh process after an `update()` had
  61. touched it read back FEWER rows than were ever `put()` (seen directly: `persons.db`'s `count()`
  62. dropped 15157 → 15152 after one round of `update()` — a real `hl:mpackdb` bug, reported to Hybriel,
  63. not something an app is allowed to patch around). The fix assigns every new id itself (8 random
  64. bytes, `hl:crypto`) in one pass over each export file BEFORE building any record, so by the time a
  65. record is actually built every reference is already a known id — one `put()` per row, `update()`
  66. never called.
  67. **Run** (`tools/migrate.hl`, `TRACKER_OLD_DATA=.../old-tracker/mongo-export`,
  68. `TRACKER_STORAGE=$PWD/storage/mpackdb`):
  69. ```
  70. migrate: genres 27 new, 0 already there (old 27 -> new 27)
  71. migrate: persons 15157 new, 0 already there (old 15157 -> new 15157), show refs skipped 0
  72. migrate: shows 9453 new, 0 already there (old 9453 -> new 9453), cast refs skipped 0, genre refs skipped 0, season refs skipped 0
  73. migrate: seasons 6430 new, 0 already there (old 6430 -> new 6430), show refs skipped 0, episode refs skipped 0
  74. migrate: episodes 231584 new, 0 already there (old 231584 -> new 231584), show refs skipped 0, season refs left null (pre-existing) 1
  75. migrate: follows 128 new, 0 already there (old 128 -> new 128), show refs skipped 0
  76. migrate: watches 11692 new, 0 already there (old 11692 -> new 11692), target refs left null (pre-existing) 3
  77. migrate: 0 failed
  78. ```
  79. Every count equals the old export's own document count (`old-tracker/README-RECONSTRUCTED.md`:
  80. Show 9453, Season 6430, Episode 231584, Person 15157, Genre 27, Follow 128, Watch 11692). Ran a
  81. second time straight after (idempotency: the tool's `oldId` index finds each row again) — every
  82. table printed `0 new`, all rows `already there`, counts unchanged, 0 failed: the id-loss bug does
  83. not resurface across a real close-and-reopen.
  84. **Proof beyond the tool's own counters** (`tools/verify.hl`, new): the ticket asks for a check that
  85. does not just trust `migrate.hl`'s own "skipped" tallies. It runs against a plain filesystem COPY
  86. of `storage/mpackdb/` (hl:mpackdb rewrites a file's data on open, so the live store is never opened
  87. a second time) and independently re-derives, from the persisted records alone: every table's
  88. `count()` against the export's own document count, and — by building id sets for every table and
  89. walking every reference field (`Show.genres/cast/seasons`, `Season.show/episodes`,
  90. `Episode.show/season`, `Person.shows`, `Follow.show/user`, `Watch.target/user`) — that every
  91. non-null reference resolves to a real id. It also follows one show end to end (`Raised by Wolves`,
  92. 2 seasons, 18 episodes, 1 follow, 2 season-level watches — all cross-checked back to the show).
  93. ```
  94. $ cp -r storage/mpackdb .scratch/verify-copy && TRACKER_VERIFY_COPY=$PWD/.scratch/verify-copy ./bin/hybriel tools/verify.hl
  95. count ok genres: 27 (expected 27)
  96. count ok persons: 15157 (expected 15157)
  97. count ok shows: 9453 (expected 9453)
  98. count ok seasons: 6430 (expected 6430)
  99. count ok episodes: 231584 (expected 231584)
  100. count ok follows: 128 (expected 128)
  101. count ok watches: 11692 (expected 11692)
  102. users: 1 (expected 1, the creator)
  103. dangling references: 0 (episodes with a pre-existing null season: 36194, watches with a pre-existing null target: 3 — not dangling, the export already had no target)
  104. END-TO-END show 105ad9c91b14d663 "Raised by Wolves" seasons=2
  105. season 1 (be2965a5ab7165ca) episodes=10 show-back-ref-ok=true
  106. season 2 (0fe4e53157ed0367) episodes=8 show-back-ref-ok=true
  107. total episodes across seasons: 18
  108. follows on this show: 1, season-level watches touching it: 2
  109. VERIFY PASS
  110. ```
  111. (36194 episodes with no season = 36193 that never had one in the old export, plus the 1 the tool's
  112. own count already named as a pre-existing dangling `season` reference in the source data — neither
  113. is a reference this migration broke; `dangling references: 0` covers exactly that.)
  114. The single old user (`User.jsonl`, `[email protected]`, password not taken over) is this app's
  115. user for ident short id `az5b2` (`storage/mpackdb/users.db`, the same table step 1's login uses) —
  116. confirmed in the copy: one record, `identity=az5b2`.
  117. **Two Hybriel bugs found while building this** (both already filed as issues on this ticket by an
  118. earlier session, not re-filed): `hl:fs readFile` silently truncates at 10 MiB (worked around here
  119. with `split`, no shell, no JS, see `tools/migrate.hl`'s header comment) and `hl:mpackdb` loses rows
  120. across `update()` + reopen (the reason this tool never calls `update()`).
  121. **Open**: nothing shown yet — this ticket is data-only, on purpose (the next step, from the
  122. creator, is showing the data in the UI).
  123. ## 2026-09-27 — ticket #3: no border on the header or filled buttons
  124. Design notes from the first test (architect): "the application-header should have no bottom
  125. border" and "the buttons also no border except they are inverted". Two changes in
  126. `styles.hl`:
  127. - `applicationHeader`: dropped `borderBottom`.
  128. - `ident-selector::part(button)` (the signed-out "choose ident" button): added
  129. `border = 'none'` — the element's own CSS gave it a 1px border the same colour as its
  130. background (`--_accent`), invisible but still a real border in the computed style; this is
  131. the app-side restyling hook ident's README documents (`::part(button)`), not a change to
  132. ident's vendored `selector.js`.
  133. Left unchanged, already correct: the native `button` rule (filled, e.g. no other filled
  134. buttons on this page yet) already has `border = '0'`; `button.quiet` ("Log out") and the
  135. selector's dropdown `[part="identity"]` rows keep their border (transparent background —
  136. inverted style); `a.button` ("Log in with ident") has no border rule and browsers give `<a>`
  137. none by default. The selector's signed-in "logged in with ident" status pill
  138. (`::part(status)`) is not one of the buttons the ticket names and isn't a button element
  139. (a `<span>`) — left with its border.
  140. **Gate** (`tests/browser.mjs`, now 16 checks): added computed-style checks — the header's
  141. `borderBottomWidth` is `0px`; `#loginbutton`'s border is `0px`; the selector's
  142. `[part~="button"]` (inside its shadow root) border is `0px`; `#logout`'s border is NOT `0px`
  143. (still inverted-bordered) once signed in.
  144. ```
  145. node tests/browser.mjs
  146. 16 passed, 0 failed
  147. ```
  148. ## 2026-09-27 — ticket #1 reopened: login redone to match calendar exactly (header selector, empty page)
  149. The architect rejected the first build of ticket #1: the sign-in sat centered on the page
  150. (its own "Sign in with ident" card, identity + sign-out shown in a `homeCard`) instead of
  151. the header identity selector calendar/gitoria use, and there was no `<ident-selector>` at
  152. all. Rebuilt the login by copying calendar.worldapi.org's own files (unchanged in shape, per
  153. the architect's instruction "Copy calendar.worldapi.org's login unchanged"):
  154. - **`users.hl`** (new): the ident exchange + a `usersTable` (`storage/mpackdb/users.db`,
  155. `identity` → this app's user id), copied from calendar's `users.hl` with `TRACKER_KEY` /
  156. `TRACKER_SECRET` / `TRACKER_URL` / `TRACKER_STORAGE` in place of calendar's names (kept
  157. the names already in this app's `docker-compose.yml`/README/DECISIONS rather than
  158. switching to calendar's generic `IDENT_API_KEY`/`IDENT_API_SECRET`).
  159. - **`login.js`** (new): calendar's bridge between `<ident-selector>`'s `ident-login` DOM
  160. event and the hidden `#identcode` input, copied verbatim (creator: "login.js is correct,
  161. as thats for externals in general").
  162. - **`components/main.hl`**: now the header carries `userBox` (`<ident-selector>` + "Log in
  163. with ident" / "Log out"), the `trackerLogin`/`trackerLogOut` faces and the
  164. `trackerSignedIn`/`trackerSignedOut` client push — calendar's shell renamed to this app's
  165. event names.
  166. - **`components/home.hl`**: now truly empty (`View { home {} }`) — no sign-in link, no
  167. identity/sign-out duplicated on the page; that is entirely the header's job now.
  168. - **`components/loginfailed.hl`** (new) + **`project.hl`**: the login routes are now
  169. `/login/callback` (function route, the button's return AND the code exchange) and
  170. `/login/failed`, copied from calendar's `project.hl` (`safePath`, `failed()`,
  171. `loginCallback`) in place of the old `/login` + `/callback` + `/logout` routes; the old
  172. `/logout` POST route is gone (logout is a face, like calendar's).
  173. - **`styles.hl`**: added the header selector styles (`userBox`, `identSelector`,
  174. `ident-selector::part(...)`, sticky header) from calendar's `styles.hl`; dropped the
  175. now-unused `homeCard`/`accountBar`/`userName` rules from the rejected centered sign-in.
  176. **Gate rewritten** (`tests/browser.mjs`, 12 checks): replaced the old gate (which drove
  177. ident's full email-code UI through a vendored dev copy of ident at `.scratch/ident-dev`)
  178. with calendar's own pattern — `tests/identkit.mjs` (copied from calendar unchanged) starts a
  179. throwaway ident (a fresh copy of `/media/STORAGE/projects/ident.worldapi.org`'s code, no
  180. `.env`/storage copied, codes to a mail sink, never the live ident), signs in over its REST
  181. API and registers this app, then the gate proves the header in a real headless Chrome:
  182. signed out → `#selector` + `#loginbutton` in the header, **`main` is empty** → sign in
  183. (`/login/callback?ident_code=`, the same exchange the selector would trigger) → `#selector`
  184. shows `class="in"`, `#logout` appears, **`main` still empty** → sign out → signed out again
  185. → a reload stays signed out. No console errors.
  186. ```
  187. node tests/browser.mjs
  188. 12 passed, 0 failed
  189. ```
  190. `./deploy.sh --dry-run --target .scratch/deploy-preview --url http://127.0.0.1:0/`: gate
  191. passed as step [1/4], rsync preview held none of `storage/`, `.sessions/`, `.env`,
  192. `.scratch/`, `server.*`, logs. Removed the stale `.scratch/ident-dev` (the old gate's vendored
  193. ident copy) and `.scratch/browser-gate` (the old gate's storage) — unused by the new gate.
  194. **Still open**: the app is registered in ident's dev copies only (this gate's own throwaway
  195. ident). The LIVE ident registration (`TRACKER_KEY`/`TRACKER_SECRET` in `.env` next to
  196. `docker-compose.yml`) is the architect's first-deploy step (README "Deploy"), not built here.
  197. ## 2026-09-27 — ticket #2: data migration — blocked twice on sandbox access, nothing done
  198. Two workers in a row (`s-20260927T1029-f57b0f`, then this session) could not start: the
  199. migration source the ticket names, `/media/STORAGE/projects/old-tracker/mongo-export/*.jsonl`
  200. + its `README-RECONSTRUCTED.md`, is not reachable from this worker's sandbox. Verified fresh
  201. this session:
  202. ```
  203. $ ls -la /media/STORAGE/projects/
  204. antcolony-docs hybriel ident.worldapi.org tracker.worldapi.org # no old-tracker
  205. $ mount | grep STORAGE
  206. /dev/nvme1n1p6 on /media/STORAGE/projects/tracker.worldapi.org type btrfs (rw,...)
  207. /dev/nvme1n1p6 on /media/STORAGE/projects/hybriel type btrfs (ro,...)
  208. /dev/nvme1n1p6 on /media/STORAGE/projects/ident.worldapi.org type btrfs (ro,...)
  209. /dev/nvme1n1p6 on /media/STORAGE/projects/antcolony-docs type btrfs (ro,...)
  210. # old-tracker is not among the mounted subvolumes at all
  211. ```
  212. So this is not a data problem (the export is "complete" per the ticket) — it's the worker
  213. sandbox for this ticket that never got `old-tracker` mounted (read-only, like `hybriel` /
  214. `ident.worldapi.org` / `antcolony-docs` above). Nothing was built or changed this session:
  215. no `storage/`, no `tools/`, no id-mapping — writing the migration tool blind, guessing the
  216. JSONL shape from the ticket text alone, risks silently wrong data and was avoided on purpose
  217. (see the project's "Build it properly" rule). Filed as an antcolony issue so the next worker's
  218. sandbox includes `old-tracker` before another attempt.
  219. ## 2026-09-27 — ticket #1: the empty shell, ident login
  220. Built the app from scratch: vendored `bin/hybriel` + `plugins/` + `shared/tokens.hl` from
  221. `ident.worldapi.org` (newest local build, hybriel master 837fe120, no local patch — see
  222. README "Vendored Hybriel"). `project.hl` (routes `/login`, `/callback`, `/logout`, `/`),
  223. `components/home.hl` (the empty homepage), `components/main.hl` (shell), `styles.hl`
  224. (accent green `#4ec9b0`, per `antcolony/README.md` "look and style" / `CONCEPT.md`).
  225. `docker-compose.yml` / `Dockerfile` / `deploy.sh` following ident's own house pattern
  226. (port 45008, container `tracker.worldapi.org`).
  227. **Login**: the ident login BUTTON flow (ident.worldapi.org README "How apps use ident"),
  228. server-side exchange (`POST <ident>/api/exchange`), this app's own framework session
  229. (`session.user = { identity }`, cookie `trackersid`). ident hands over only the identity's
  230. public **short id** — no display name yet (ident#11, properties handover, is on hold) — so
  231. "your name" on the homepage is `Signed in as <shortid>`, the same identifier every other
  232. worldapi app would show; see `decided` in the report.
  233. **Lesson (Hybriel)**: a face that mutates `session.user` (e.g. `signOut`) does NOT
  234. automatically re-render the page — a component's reactive members (`signedIn`, `identity`,
  235. …) are computed once at mount from the framework's read-only session snapshot; a client
  236. handler that calls `emit server X()` must ALSO flip the affected members itself afterwards
  237. (ident's own `components/home.hl` `on doSignOut(e)` does exactly this: `emit server
  238. signOut()` then `signedIn = false` …). Missing that made the sign-out button silently do
  239. nothing client-side (the ack came back `ok:true`, the server-side session really was
  240. cleared — proven by a reload — but the DOM never updated) until copied.
  241. **Gate** (`tests/browser.mjs`, 13 checks): a fresh copy of `ident.worldapi.org`'s code (no
  242. `.env`, no `storage/`, no `.sessions/` — verified empty of secrets/data before first use)
  243. runs as this gate's own ident, on its own storage and its own mail sink (no live ident, no
  244. real mail). The gate registers this app in that dev ident once over the `/__hl/emit` API
  245. (the same one-time step a person does by hand in ident's `/apps` page), then drives the
  246. REAL login-button flow in a real headless Chrome: signed out → click "Sign in with ident" →
  247. ident's email form → the mail-sink code → the first-login optional-names form (Skip) → the
  248. one-identity choice (one click) → back on tracker, "Signed in as `<shortid>`" → "Sign out" →
  249. signed out again → a reload stays signed out. No console errors. Ran twice for stability, 0
  250. failures; no leftover Chrome/hybriel processes after either run.
  251. ```
  252. node tests/browser.mjs
  253. 13 passed, 0 failed
  254. ```
  255. `./deploy.sh --dry-run --target .scratch/deploy-preview --url http://127.0.0.1:0/` (a local
  256. directory, per ident's own convention for testing deploy.sh without touching Byrodin): gate
  257. passed, rsync preview held none of `storage/`, `.sessions/`, `.env`, `.scratch/`, `server.*`,
  258. logs — confirmed by the same grep the script refuses on.
  259. **Open**: the app is not registered with the LIVE ident yet — `TRACKER_KEY`/`TRACKER_SECRET`
  260. are unset until the architect's first deploy does that (README "Deploy"); until then
  261. `/login` on the live site answers a plain error page instead of redirecting (`/` itself
  262. still renders). This is normal for a brand-new app, the same as ident's own SMTP `.env`
  263. before its first deploy — not something this ticket's worker can set (no `.env` access,
  264. and it is a LIVE ident registration).

Branches

Latest commits

  • a97c0295tracker#4: show page /shows/:slug (header, seasons, episodes, watch checks) + tools/relink-episode-seasons.hlmre
  • 05f407c5tracker: no border on any button except inverted ones (Log out, ident status and identities too); header brand weight 100mre
  • 17375427tracker#2: tools/migrate.hl + tools/verify.hl — old MongoDB data into mpackdb with new idsmre
  • 31aac936tracker#3: no border on the header and on filled buttons; inverted buttons keep theirsmre
  • 2ad9d29ctracker#1: login exactly like calendar (identity selector in the header, empty homepage)mre
  • 3691e176tracker#1: empty tracker with the ident login (state of 2026-09-27)mre