tracker
All repositories: gitoria
4.5 KB
\* hl:crypto — passwords first. Native realm wrapper (see server.js for the JS twin).The whole surface is eight calls, and six of them exist to serve the first two.What this plugin is FOR is that an application never stores a password: itstores the answer to "could this password have produced that", and the answercarries its own algorithm and cost so it stays readable when both change.hash(password, options) the stored value — a PHC stringverify(password, stored) true / false, in constant timeparsePhc(stored) what a stored value says about itselfkdf() which algorithm THIS host hashes withsha256(data) content hashing (fast on purpose — not for passwords)randomBytes(n, encoding) n bytes from the kernel CSPRNGtoBase64(data) a String's or a Bytes' bytes as base64 textfromBase64(text) base64 text back to a Bytes (null if it is not base64)The realm is SERVER (plugin.json). A password never crosses to the client, soimporting this file is also a declaration about where the importing code runs. *\\* Hash a password for storage. Returns a self-describing PHC string:$argon2id$v=19$m=32768,t=2,p=1$<salt>$<hash>$scrypt$ln=15,r=8,p=1$<salt>$<hash>Every call salts freshly, so hashing the same password twice gives twodifferent strings and both verify.`options` is optional: { cost = 15; kdf = "argon2id" }cost base-2 log of the working memory in KiB — 15 is 32 MiB, the default.CAPPED to 10..17 (1 MiB .. 128 MiB); the string records what wasactually used, so asking for 999 and reading the result back is howyou see the cap rather than being told about it.kdf force an algorithm instead of taking the host's best one. Normallyunnecessary: `hash` picks argon2id when the system libcrypto has it(OpenSSL >= 3.2) and scrypt otherwise, and `verify` reads both. *\hash(password, options) {return __native("crypto.hash", password, options)}\* Check a password against a stored PHC string. The comparison is constant-timeand the answer is a plain boolean: a wrong password, a truncated string, aflipped character and a string that is not PHC at all are all `false`. Astored string whose ALGORITHM this host cannot compute is a loud errorinstead, because answering `false` to that would read as "wrong password". *\verify(password, stored) {return __native("crypto.verify", password, stored)}\* Read a stored string without the password:{ kdf = "argon2id"; version = 19; params = { m; t; p }; saltLen; hashLen }{ kdf = "scrypt"; version = null; params = { ln; r; p }; saltLen; hashLen }`null` when the string is not a PHC string this plugin understands — which isalso the cheapest way to spot a store that was never migrated. *\parsePhc(stored) {return __native("crypto.parse", stored)}\* Which algorithm `hash()` writes with on this host. Reporting only — nothingneeds to branch on it, because every stored string names its own. *\kdf() {return __native("crypto.kdf")}\* SHA-256 of a string, as 64 lowercase hex characters. Content hashing: fast bydesign, and therefore exactly the wrong tool for a password. *\sha256(data) {return __native("crypto.sha256", data)}\* n random bytes from the kernel CSPRNG, rendered as "hex" (the default) or"base64". n is 1..1024. Suitable for session ids, one-time tokens and nonces. *\randomBytes(n, encoding) {return __native("crypto.random_bytes", n, encoding)}\* Base64 (the standard alphabet, padded) of a String's bytes — its UTF-8 — orof a Bytes, byte for byte:toBase64('user:pa55') \\ "dXNlcjpwYTU1"toBase64(req.bytes) \\ any bytes at all, NUL and 0xff included *\toBase64(data \\ a String or a Bytes) {if (hlTypeName(data) == 'Bytes') {return __native("crypto.base64_encode_hex", data.hex())}return __native("crypto.base64_encode", data)}\* Base64 text back to its bytes, as a Bytes; `.toString()` of it is the textwhen the bytes are UTF-8. Padded and unpadded text both decode; anythingthat is not base64 in the standard alphabet is null, not an error — amalformed `Authorization: Basic` header is an answer, not a crash:let b = fromBase64(req.headers.authorization.slice(6))if (b != null) { let pair = b.toString() } \\ "user:pa55" *\fromBase64(String text) {let raw = __native("crypto.base64_decode", text)if (raw == null) {return null}return toBytes(raw)}
Branches
- mainmain branch
Latest commits
- dc40d859tracker#31 (mission 026): duplicate titles merged — the 68 type+tmdbId pairs held by 157 records were the old tracker's (all migrated); merge.hl repair job (own clock, before the TMDB jobs) keeps one keeper per title (follows/watches > old short id > oldest), moves follows, watches, seasons, cast, credits, timelines, tombstones the rest (mergedInto, never deleted), slugs + short ids 301 to the keeper; stray seasons merged into their listed twin (Reacher S3 watches) or linked when watched; search import re-checks before its put; deploy.sh waits up to 90 s for 200; real copy 68 -> 0 dup ids, az5b2 follows/watches equal; gates 342/0, 32/0, 52/0mre
- 2667da05tracker#30 (mission 025): /my/ pages from slim cached title cards, episode rows and watch sets (after the jobs /my/series 1.8 s -> 0.06 s, /my/unwatched 4.1 -> 0.18 s); timeline page shows its name once; franchise widget under the poster/title; movies with TV leftovers (First Contact) go through the details repair; tools/count-tmdb-ids.hl; gates 327/0, 52/0, 32/0mre
- 3909810dantcolony#40: mission references in README/STATUS/docs point to the moved missionsmre
- e63b1d28antcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
- 1cda451dtracker: Hybriel master 190aa11d (#127 both shapes, GC correctness fc838894) — conductor adopts despite /my/series 2.4x after jobs (memory 8.0 → 1.7 GB boot); see reports/071mre
- c1fa2f2etracker (mission 071): Hybriel master 190aa11d measured on the real copy vs the live binary 8590df63 — NOT adopted (after the first-start jobs /my/series 2.4x slower, /series 1.6x, RSS swings 7.4-12.2 GB; fresh it is flat at 1.7-2.2 GB and /my/unwatched faster), vendor stays 8efba065, candidate kept in .scratch/w071/vendor-190aa11d; tests/kinds.mjs: collection seed off (its TMDB request broke check 1 in 1 of 4 runs); tests/realdata-071.sh + realdata-071-bench.mjs + tools/realdata-071-table.py; README + STATUS (numbers, how to repeat); gates 325/0, 32/0, 50/0mre
- 8081350atracker docs (mission 070): README (summary, Config HL_GC_BYTES — kept at Hybriel's default, the 256 MiB setting is taken out of docker-compose.yml again: the jobs grew to 12+ GB with it too, see STATUS), Test (three gates), Deploy (first start ~50 min: kinds then seed, restart once after collections done, memory numbers), Vendored Hybriel 8efba065 + #48 audit, Files; STATUS mission 070 entry (merges, migrated counts, lambda audit, gates, RSS old vs new, how to repeat, open points); docs/kinds.md + docs/franchises.md job order; tests/realdata-070-*.sh, tools/count-migrated.hl, tools/ref-params.py, tools/lambda-audit.pymre
- 1ad19c8ctracker: re-vendor Hybriel master 8efba065 (#126 GC by bytes, #48 lambda parameters copy) (mission 070): bin/hybriel sha256 50361e95…, plugins core crypto data fetch fs http http1 mpackdb proc smtp time web; lambda audit: 13 lambdas change a passed record/list (11 through a local alias), no caller relies on it — unchanged; 319 read-only lambda parameters get & (no copy per call: /my/schedule 2.35 → 0.46 s, /my/unwatched 13.7 → 5.7 s on the real copy); /my/unwatched one merge sort instead of n² inserts; docker-compose HL_GC_BYTES=268435456; deploy.sh runs kinds.mjs + franchises.mjs too (default ports 8700–8710); tests/realdata-070.mjs; gates browser 325/0, kinds 32/0, franchises 50/0mre
- 46b21389tracker (mission 070, conductor): the sync never destroys migrated data — the one-time summary step MOVES a copied summary to migratedSummary (marker summaries-moved.txt) instead of clearing it; a migrated record's first title/genres/homepage/tagline TMDB replaces → migratedTitle/migratedGenres/migratedHomepage/migratedTagline, a migrated season's/episode's title/summary → migratedTitle/migratedSummary (set once); tests/peek-shows.hl prints them; gate 325/0mre
- 749019b0Merge t19 (tracker#19 franchises + timelines) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/browser.mjs/faketmdb.mjs, both sides kept; franchise/timeline pages get #20's typed heading (Franchise | …, Timeline | …), their title links via titlePath (/movies|/series|/shows); the collection seed waits for repair, kinds and credits too; franchises.mjs URLs + 2 new checks; gates browser 323/0, kinds 32/0, franchises 50/0mre
- daf49feaMerge t20 (tracker#20 typed headings + #21 series/shows split) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/search.hl/components/search.hl/browser.mjs/faketmdb.mjs, both sides kept; clock order backfill → repair → kinds → credits; withDetailsFields stores tmdbType + kind; gates: browser.mjs URLs → /series|/movies, typed h1 selectors; kinds.mjs repair/credits off, fixture name = seed name; browser 323/0, kinds 32/0mre
- 20e09d89Merge t18 (tracker#18 delta sync) into main (mission 070): conflicts README/STATUS/show.hl/project.hl/browser.mjs, both sides kept; pageShowOf summary = summaryOfmre
- f83571c3tracker#18 (mission 067): daily sync by change lists — TMDB /tv|movie/changes (since the stored day, paged) + TVmaze /updates/shows → only our changed titles (followed: full step, unfollowed: light step — changed seasons, no TVmaze), full walk on first run / gap > 14 days / failed list; show record refreshed (title, tmdbSummary, tagline, status, genres …; renamed titles re-indexed); summary = the creator's own text (page: summary > tmdbSummary > tvmazeSummary), one-time clear of copied summaries (9,647 on the live copy); gate 261, tests/realdata-018*.mjs, README + STATUSmre
- 1ed5457etracker#20 + #21 (mission 068): typed headings "<Type> | <name>" in type colours; TV titles split into Series (/series) and Shows (/shows) by TMDB type + Reality/Talk/News genres — kind stored by sync/import/adult backfill + new kind backfill (resumes), /movies/<slug>, /shows/<slug> of a series/movie → 301, /my/series + /my/shows, home 5 tiles + 3 rows, search/filmography labels; gates kinds 32 + browser 266, tests/realdata-068.mjs, tools/count-kinds.hl, docs/kinds.md, README + STATUSmre
- f2b00674Merge t26 (tracker#26 + #28) into main (mission 062): short ids for every new person (castPersonId, guest route), guest stars stored on the title and created as people only when opened (/person/tmdb/<id>?show=<id> → 302), lean watch/follow clicks (showRow a small object, cast/crew from the slug, watches cached per user, face rows only after a season toggle); gate 311, tests/realdata-062.mjs, README + STATUSmre
- 0553b51ftracker#19 (mission 066): franchises and timelines — tables, /franchises, /franchises/<slug>, /timelines/<slug> (Timeline | Release sort, series by last episode), the Prequel | Timeline | Sequel widget with the franchise above, the creator's editor, TMDB collection seed in the app (resumes, paced); gate tests/franchises.mjs 48/0 + browser.mjs 266/0, tests/realdata-066.mjs, docs/franchises.md, README + STATUSmre
- fa1f9dfatracker#29 (mission 063): unwatched check muted grey outline + check (accent only on hover), watched stays solid — no code regression, the accent outline read as ticked; gate checks real checks visibly (computed style + screenshot pixel) on /my/unwatched, show, movie, /my/movies; gate 266, tests/realdata-063.mjs, README + STATUSmre
- 10bb3f93tracker#28 (mission 061): full cast (all seasons, main cast by episodes, guest stars) + crew (created by, directed by, written by, screenplay, story, music) — stored by the details completion, the daily sync, the search import (one details request) and a background credits job (resumes, RSS limit); show page collapsed after 20 with client-side Show all; showBySlug via a slug map; gate 249, tests/realdata-028.mjs, README + STATUSmre
- d8b12d67tracker#27 (mission 060): short ids for movies, series and persons — old 702 kept (data/old-short-ids.json), new random [a-z0-9]{5} unique across both, claimed at creation, background backfill (resumes), shown under poster/photo, /<shortId> → 301; gate 259, tests/realdata-060*, README + STATUSmre
- 25a50bc4tracker#26 (mission 059): titles from a filmography are completed — on open (skeleton, step-wise face showComplete, no reload) and by the in-app details repair (resumes, TMDB-paced, series in parts); cast from TMDB credits; gate 231, tests/realdata-026.mjs, README + STATUSmre