gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commitf14db671f14db671tracker#22-#25 (mission 058): episode air dates, season check = all episodes watched, movie watched check (+ /my/movies count), /genres/<genre> pages (movies + series, newest first, paginated); gate 238, tests/realdata-058.mjs, README + STATUSmref14db671/project.hl

20.2 KB

  1. // project.hl — tracker.worldapi.org: STEP 1 (tracker.worldapi.org#1), an empty shell. Login copied unchanged from
  2. // calendar.worldapi.org (rejected once for a centered sign-in and no header selector — architect, 2026-09-27):
  3. // ident only, no own passwords (README "How apps use ident" of ident.worldapi.org), the identity selector in the
  4. // header (components/main.hl). No shows, no data yet — later steps come from the creator (CONCEPT.md).
  5. //
  6. // the header's ident-selector / "Log in with ident" -> <ident>/login?key=&return=<this app>/login/callback
  7. // /login/callback?ident_code=<code> the app's server exchanges the code for the identity's short id
  8. // (POST <ident>/api/exchange) and signs this app's OWN session in
  9. // (session.user = { id = <users @id> }, users.hl)
  10. // the header's "Log out" button signs this app's session out via the face trackerLogOut (components/main.hl)
  11. // — ident's own session, and the browser's ident cookie, are untouched
  12. //
  13. // Config (env; no committed secret — the first deploy registers this app in ident and sets these, done by the
  14. // architect, as with ident's own .env for SMTP):
  15. // TRACKER_PORT (45008), TRACKER_URL (this app's own public address, for the return URL),
  16. // IDENT_URL (https://ident.worldapi.org), TRACKER_KEY (pk_…), TRACKER_SECRET (sk_…)
  17. import WebFramework from 'hl:web'
  18. import { Response } from 'hl:http1'
  19. import { randomBytes } from 'hl:crypto'
  20. import { env } from 'hl:proc'
  21. import { readBytes, exists } from 'hl:fs'
  22. import { now, timestamp, every } from 'hl:time'
  23. import Styles from './styles.hl'
  24. import { exchangeCode, ensureUser } from './users.hl'
  25. import Home from './components/home.hl'
  26. import LoginFailed from './components/loginfailed.hl'
  27. import Show from './components/show.hl'
  28. import Unwatched from './components/unwatched.hl'
  29. import Schedule from './components/schedule.hl'
  30. import MyShows from './components/myshows.hl'
  31. import MyMovies from './components/mymovies.hl'
  32. import Movies from './components/movies.hl'
  33. import AllShows from './components/allshows.hl'
  34. import Search from './components/search.hl'
  35. import Person from './components/person.hl'
  36. import Genre from './components/genre.hl'
  37. import { ensureIndex, searchTitleChanged } from './search.hl'
  38. import { syncEnabled, syncShow, persistSync, emptyTotals, addTotals, totalsLine, pauseMsAfter, msPerRequest, adultBackfillQueue, backfillTitle } from './tmdbsync.hl'
  39. import { allFollowedShowIds } from './follows.hl'
  40. import { refreshCatalogShow } from './catalog.hl'
  41. import { dark, darker } from './shared/tokens.hl'
  42. static appTitle = "tracker"
  43. // ---- THE INSTALLABLE APP (tracker.worldapi.org#10), the same way calendar.worldapi.org does it: hl:web's own web app
  44. // manifest (/__hl/manifest.webmanifest, linked from every head with the apple-touch-icon and theme-color) and service
  45. // worker (/__hl/sw.js) from these settings — no JavaScript of ours. Icons in icons/ (icon.svg is the source, the PNGs
  46. // are rendered from it with rsvg-convert, README "Icons"). The theme colour is the header's background (darker), the
  47. // splash background the page's (dark) — both off the tokens, not written out again.
  48. appThemeColor = darker.value
  49. appBackgroundColor = dark.value
  50. appIcons = [
  51. { src = '/icons/icon-192.png' sizes = '192x192' purpose = 'any' }
  52. { src = '/icons/icon-512.png' sizes = '512x512' purpose = 'any' }
  53. { src = '/icons/icon-192.png' sizes = '192x192' purpose = 'maskable' }
  54. { src = '/icons/icon-512.png' sizes = '512x512' purpose = 'maskable' }
  55. ]
  56. appTouchIcon = '/icons/apple-touch-icon.png'
  57. appFavicon = '/icons/favicon.svg'
  58. // OFFLINE: only the shell — the header and `/` (components/main.hl says "You are offline" while the browser has no
  59. // network). The data pages are not kept: without a network they get hl:web's "Unavailable offline" page.
  60. offline = [ Home ]
  61. styles = Styles
  62. port = env('TRACKER_PORT') != null ? toNumber(env('TRACKER_PORT')) : 45008
  63. watching = env('TRACKER_WATCH') != '0'
  64. // read by hl:web's own manifest config (WebFramework.hl `cfg.sessionDir`), not the constructor call below
  65. sessionDir = env('TRACKER_SESSIONS') != null ? env('TRACKER_SESSIONS') : null
  66. // ---- THE LOGIN BUTTON'S RETURN (ident README "How apps use ident"), copied from calendar.worldapi.org's project.hl
  67. // BACK TO THE PAGE: /login.js puts `?next=` into the button's return URL at the click. Only a same-origin PATH
  68. // goes (one `/`, URL-safe characters, ≤ 500). Anything else → `/`.
  69. nextChars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-._~/?&=%+,;@!$()*:'
  70. safePath = (want) => {
  71. if (want == null || hlTypeName(want) != 'String' || want == '' || want.length > 500) { return '/' }
  72. if (want.slice(0, 1) != '/' || want.slice(0, 2) == '//' || want.slice(0, 7) == '/login/') { return '/' }
  73. let i = 0
  74. while (i < want.length) {
  75. if (!nextChars.includes(want[i])) { return '/' }
  76. i = i + 1
  77. }
  78. return want
  79. }
  80. // A FAILED LOGIN is a page (components/loginfailed.hl): the reason is parked in the session, then → /login/failed
  81. failed = (req, why) => {
  82. let s = req.session
  83. let fresh = s == null
  84. if (fresh) { s = server.sessions.mint() }
  85. s.data.loginError = why
  86. server.sessions.save(s)
  87. let res = new Response('login failed: ' + why, { status = 302 headers = { 'Location' = '/login/failed' 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  88. if (fresh) { res.headers['Set-Cookie'] = server.sessions.cookieHeader(s.id) }
  89. return res
  90. }
  91. // the function route gets the cookie's session as req.session (hybriel #11); none yet → minted here
  92. loginCallback = (route, req) => {
  93. if (req.method != 'GET') { return failed(req, 'GET only') }
  94. let q = req.query != null ? req.query : {}
  95. let code = q.ident_code
  96. if (code == null || code == '') { return failed(req, 'ident sent no login code') }
  97. let x = exchangeCode(code)
  98. if (x.error != null) { return failed(req, x.error) }
  99. let u = ensureUser(x.identity)
  100. if (u == null) { return failed(req, 'could not store the user') }
  101. let s = req.session
  102. let fresh = s == null
  103. if (fresh) { s = server.sessions.mint() }
  104. s.user = { id = u.id }
  105. s.data.tag = randomBytes(16)
  106. s.data.loginError = null
  107. server.sessions.save(s)
  108. let res = new Response('logged in', { status = 302 headers = { 'Location' = safePath(q.next) 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  109. if (fresh) { res.headers['Set-Cookie'] = server.sessions.cookieHeader(s.id) }
  110. return res
  111. }
  112. // ---- /posters/<name> (tracker.worldapi.org#4): a show's poster image, served dynamically from
  113. // storage/mpackdb/posters/ (the poster's file name is the show's oldId + its migrated extension,
  114. // shows.hl posterName) — falls back to a placeholder svg when the real file isn't there yet (the
  115. // mongo export never included the actual poster bytes, see the report's `open`).
  116. postersDir = (env('TRACKER_STORAGE') != null ? env('TRACKER_STORAGE') : './storage/mpackdb') + '/posters'
  117. placeholderPoster = './assets/poster-placeholder.svg'
  118. posterNameChars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789.-_'
  119. isSafePosterName = (name) => {
  120. if (name == null || hlTypeName(name) != 'String' || name == '' || name.length > 100) { return false }
  121. let i = 0
  122. while (i < name.length) {
  123. if (!posterNameChars.includes(name[i])) { return false }
  124. i = i + 1
  125. }
  126. return true
  127. }
  128. endsWithStr = (s, suffix) => { return s.length >= suffix.length && s.slice(s.length - suffix.length) == suffix }
  129. mimeOfPoster = (name) => {
  130. if (endsWithStr(name, '.png')) { return 'image/png' }
  131. if (endsWithStr(name, '.webp')) { return 'image/webp' }
  132. if (endsWithStr(name, '.svg')) { return 'image/svg+xml' }
  133. return 'image/jpeg'
  134. }
  135. posterRoute = (route, req) => {
  136. let name = route.params != null ? route.params.name : null
  137. if (!isSafePosterName(name)) { return new Response('bad poster name', { status = 400 headers = { 'Content-Type' = 'text/plain; charset=utf-8' } }) }
  138. let path = postersDir + '/' + name
  139. if (exists(path)) { return new Response(readBytes(path), { headers = { 'Content-Type' = mimeOfPoster(name) 'Cache-Control' = 'public, max-age=86400' } }) }
  140. return new Response(readBytes(placeholderPoster), { headers = { 'Content-Type' = 'image/svg+xml' 'Cache-Control' = 'public, max-age=3600' } })
  141. }
  142. // ---- /profiles/<name> (tracker.worldapi.org#16): a person's photo, from storage/mpackdb/profiles/ (people.hl syncProfile
  143. // downloads it on the first visit of the person page) — the same checks and placeholder as /posters/<name>
  144. profilesDir = (env('TRACKER_STORAGE') != null ? env('TRACKER_STORAGE') : './storage/mpackdb') + '/profiles'
  145. profileRoute = (route, req) => {
  146. let name = route.params != null ? route.params.name : null
  147. if (!isSafePosterName(name)) { return new Response('bad photo name', { status = 400 headers = { 'Content-Type' = 'text/plain; charset=utf-8' } }) }
  148. let path = profilesDir + '/' + name
  149. if (exists(path)) { return new Response(readBytes(path), { headers = { 'Content-Type' = mimeOfPoster(name) 'Cache-Control' = 'public, max-age=86400' } }) }
  150. return new Response(readBytes(placeholderPoster), { headers = { 'Content-Type' = 'image/svg+xml' 'Cache-Control' = 'public, max-age=3600' } })
  151. }
  152. // ---- the old addresses of the personal lists (tracker.worldapi.org#8): they all live under /my/ now —
  153. // a permanent redirect so old links keep working (architect's decision)
  154. movedTo = (path) => { return new Response('moved to ' + path, { status = 301 headers = { 'Location' = path 'Content-Type' = 'text/plain; charset=utf-8' } }) }
  155. unwatchedMoved = (route, req) => { return movedTo('/my/unwatched') }
  156. scheduleMoved = (route, req) => { return movedTo('/my/schedule') }
  157. // mission 058: the show page's genre pills linked `/genre/<x>` (no page there) — the genre pages are `/genres/<x>`
  158. genreMoved = (route, req) => {
  159. let g = route.params != null ? route.params.genre : null
  160. return movedTo(isSafePosterName(g) ? '/genres/' + g : '/')
  161. }
  162. routes = [
  163. { pattern = "/favicon.ico" file = "./icons/favicon.ico" headers = { 'Cache-Control' = 'no-cache' } }
  164. // the installable app (tracker.worldapi.org#10): the icons (manifest and service worker are hl:web's own, from appIcons / offline)
  165. { pattern = "/icons/icon-192.png" file = "./icons/icon-192.png" headers = { 'Cache-Control' = 'no-cache' } }
  166. { pattern = "/icons/icon-512.png" file = "./icons/icon-512.png" headers = { 'Cache-Control' = 'no-cache' } }
  167. { pattern = "/icons/apple-touch-icon.png" file = "./icons/apple-touch-icon.png" headers = { 'Cache-Control' = 'no-cache' } }
  168. { pattern = "/icons/favicon.svg" file = "./icons/favicon.svg" headers = { 'Cache-Control' = 'no-cache' } }
  169. { pattern = "/login/callback" function = loginCallback }
  170. { pattern = "/login/failed" component = LoginFailed }
  171. { pattern = "/login.js" file = "./login.js" headers = { 'Cache-Control' = 'no-cache' } }
  172. { pattern = "/posters/:name" function = posterRoute }
  173. // tracker.worldapi.org#13: every movie / every series, 24 per page — the page is a PATH segment (`/movies/page/2`), a
  174. // page component cannot read `?page=` (hybriel#11) — and the movies the user follows
  175. { pattern = "/movies" component = Movies }
  176. { pattern = "/movies/page/:page" component = Movies }
  177. { pattern = "/shows" component = AllShows }
  178. { pattern = "/shows/page/:page" component = AllShows }
  179. { pattern = "/shows/:slug" component = Show }
  180. { pattern = "/my/shows" component = MyShows }
  181. { pattern = "/my/movies" component = MyMovies }
  182. { pattern = "/my/unwatched" component = Unwatched }
  183. { pattern = "/my/schedule" component = Schedule }
  184. { pattern = "/unwatched" function = unwatchedMoved }
  185. { pattern = "/schedule" function = scheduleMoved }
  186. // tracker.worldapi.org#14: the search — `/search/<text>` (hl:web gives a page no query string, so not `?q=`)
  187. { pattern = "/search/:q?" component = Search }
  188. // tracker.worldapi.org#16: a person's page (the show page's cast and the search link here) and their photo
  189. { pattern = "/person/:slug" component = Person }
  190. { pattern = "/profiles/:name" function = profileRoute }
  191. // mission 058 (tracker.worldapi.org#25): a genre's movies and series, like /movies (the page in the path)
  192. { pattern = "/genres/:genre" component = Genre }
  193. { pattern = "/genres/:genre/page/:page" component = Genre }
  194. { pattern = "/genre/:genre" function = genreMoved }
  195. { pattern = "/" component = Home }
  196. ]
  197. // WHO GETS THE PUSH: the login state reaches the tabs of one session (components/main.hl trackerSignedIn/Out).
  198. tagOf = (session) => { return session != null && session.data != null ? session.data.tag : null }
  199. audience = {
  200. trackerSignedIn = (tag, session) => { return tag != null && tagOf(session) == tag }
  201. trackerSignedOut = (tag, session) => { return tag != null && tagOf(session) == tag }
  202. }
  203. // cookies are per host, not per port: an own name keeps this app's session apart from
  204. // ident's own (and from any other worldapi app sharing a dev host), see ident README "Design
  205. // tokens" / hybriel#10 hybriel#17.
  206. sessionCookie = 'trackersid'
  207. // tracker.worldapi.org#14: the search index (search.hl) is built once here at boot (~0.6 s on the real data), not by the
  208. // first search
  209. searchIndexReady = ensureIndex()
  210. server = new WebFramework(routes = routes, styles = styles, port = port, sessionCookie = sessionCookie, watchMode = watching)
  211. // ---- THE DAILY TMDB SYNC (tracker.worldapi.org#9, tmdbsync.hl) --------------------------------------
  212. // Once a day at TRACKER_SYNC_HOUR (UTC, default 4 — hl:time has no time zones; the container runs UTC) every
  213. // followed show is synced from TMDB. hl:web serves ONE request at a time, so the run never takes the server
  214. // for itself: a 1-second clock does ONE show per tick (1–3 TMDB requests + maybe its poster) and returns — the
  215. // requests that queued meanwhile are served between two ticks, and a tick never starts inside a page render.
  216. // After a show that made n requests the next waits n × 260 ms (TMDB: ≤ 40 requests / 10 s) + 550 ms per TVmaze lookup
  217. // (≤ 20 / 10 s, tracker.worldapi.org#12).
  218. // TRACKER_SYNC=0 switches it off; without TMDB_READ_TOKEN it is off too (logged once).
  219. syncHour = env('TRACKER_SYNC_HOUR') != null ? toNumber(env('TRACKER_SYNC_HOUR')) : 4
  220. syncOn = env('TRACKER_SYNC') != '0' && syncEnabled
  221. syncQueue = []
  222. syncAt = 0
  223. syncDay = ''
  224. syncNextAt = 0
  225. syncTotals = emptyTotals()
  226. syncTick = () => {
  227. let t = now()
  228. if (syncQueue.length == 0) {
  229. let stamp = timestamp(t)
  230. let day = stamp.slice(0, 10)
  231. if (toNumber(stamp.slice(11, 13)) != syncHour || day == syncDay) { return null }
  232. syncDay = day
  233. syncQueue = allFollowedShowIds()
  234. syncAt = t
  235. syncNextAt = 0
  236. syncTotals = emptyTotals()
  237. console.log('tmdb sync: start, ' + syncQueue.length + ' followed shows')
  238. return null
  239. }
  240. if (t < syncNextAt) { return null }
  241. let id = syncQueue[0]
  242. let rest = []
  243. let i = 1
  244. while (i < syncQueue.length) { rest.push(syncQueue[i]) i = i + 1 }
  245. syncQueue = rest
  246. let r = syncShow(id)
  247. // the public lists (catalog.hl, tracker.worldapi.org#13): this show's place by its newest released episode; the sync
  248. // also brings TMDB's adult flag (mission 054) → the search's view of it too
  249. refreshCatalogShow(id)
  250. searchTitleChanged(id)
  251. let took = now() - t
  252. syncTotals = addTotals(syncTotals, r)
  253. if (r.error != '') { console.log('tmdb sync: ' + r.error) }
  254. // a step blocks every request meanwhile (Saturday Night Live, 53 seasons, 4 requests: ~1.7 s) — say so in the log
  255. if (took > 1500) { console.log('tmdb sync: slow step, show ' + id + ', ' + r.requests + ' requests, ' + took + ' ms') }
  256. syncNextAt = now() + pauseMsAfter(r)
  257. if (syncQueue.length == 0 || syncTotals.shows % 10 == 0) { persistSync() }
  258. if (syncQueue.length == 0) { console.log('tmdb sync done: ' + totalsLine(syncTotals) + ' seconds=' + ((now() - syncAt) / 1000)) }
  259. return null
  260. }
  261. // ---- THE ADULT-FLAG BACKFILL (mission 054, tmdbsync.hl backfillTitle) -----------------------------------
  262. // The public lists and the search show only titles TMDB says are not adult (shows.hl isPublicTitle; unknown = hidden). At
  263. // start the app collects every title whose flag is still unknown and asks TMDB for ONE title per step — like the daily
  264. // sync, on the same clock, so requests queued meanwhile are served between two steps: one details request (adult,
  265. // poster_path, external ids) + the poster file when missing, then a pause of 260 ms per TMDB API request (≤ 40 / 10 s;
  266. // the poster comes from TMDB's image host, not the API, and is not counted). Each answered title goes into the lists
  267. // (catalog.hl refreshCatalogShow) and the search at once. RESUMES after a restart: the queue is built from what is
  268. // still unknown. Stops when the queue is empty; titles TMDB answers 404 for are marked (`adultCheck`) and stay hidden; a
  269. // passing failure (no answer, 429, 5xx) goes to the back of the queue, at most 2 more tries per start.
  270. // While the daily sync runs, the backfill waits. Log: start, every TRACKER_BACKFILL_LOG_EVERY (500) titles, done.
  271. // TRACKER_BACKFILL=0 switches it off; without TMDB_READ_TOKEN it is off too.
  272. backfillOn = env('TRACKER_BACKFILL') != '0' && syncEnabled
  273. backfillLogEvery = env('TRACKER_BACKFILL_LOG_EVERY') != null ? toNumber(env('TRACKER_BACKFILL_LOG_EVERY')) : 500
  274. backfillQueue = null
  275. backfillPos = 0
  276. backfillDone = false
  277. backfillAt = 0
  278. backfillNextAt = 0
  279. backfillTries = {}
  280. backfillTotals = { titles = 0 adult = 0 notAdult = 0 unknown = 0 posters = 0 ids = 0 requests = 0 errors = 0 retries = 0 }
  281. backfillLine = () => {
  282. let b = backfillTotals
  283. return b.titles + '/' + backfillQueue.length + ' titles, adult=' + b.adult + ' notAdult=' + b.notAdult + ' unknown=' + b.unknown + ' posters=' + b.posters
  284. + ' ids=' + b.ids + ' requests=' + b.requests + ' errors=' + b.errors + ' retries=' + b.retries + ' seconds=' + ((now() - backfillAt) / 1000)
  285. }
  286. backfillTick = () => {
  287. if (backfillDone) { return null }
  288. let t = now()
  289. if (backfillQueue == null) {
  290. backfillQueue = adultBackfillQueue()
  291. backfillAt = t
  292. console.log('adult backfill: start, ' + backfillQueue.length + ' titles without an adult flag (' + (now() - t) + ' ms to find them)')
  293. if (backfillQueue.length == 0) { backfillDone = true console.log('adult backfill: nothing to do') }
  294. return null
  295. }
  296. if (t < backfillNextAt) { return null }
  297. let id = backfillQueue[backfillPos]
  298. backfillPos = backfillPos + 1
  299. let r = backfillTitle(id)
  300. if (r.retry && (backfillTries[id] == null || backfillTries[id] < 2)) {
  301. backfillTries[id] = backfillTries[id] == null ? 1 : backfillTries[id] + 1
  302. let q = backfillQueue
  303. q.push(id)
  304. backfillQueue = q
  305. backfillTotals.retries = backfillTotals.retries + 1
  306. } else {
  307. backfillTotals.titles = backfillTotals.titles + 1
  308. if (r.adult == true) { backfillTotals.adult = backfillTotals.adult + 1 } else if (r.adult == false) { backfillTotals.notAdult = backfillTotals.notAdult + 1 } else { backfillTotals.unknown = backfillTotals.unknown + 1 }
  309. }
  310. backfillTotals.posters = backfillTotals.posters + r.posters
  311. backfillTotals.ids = backfillTotals.ids + r.ids
  312. backfillTotals.requests = backfillTotals.requests + r.requests
  313. backfillTotals.errors = backfillTotals.errors + r.errors
  314. if (r.error != '') { console.log('adult backfill: ' + r.error) }
  315. if (r.adult != null) {
  316. refreshCatalogShow(id)
  317. searchTitleChanged(id)
  318. }
  319. let took = now() - t
  320. if (took > 1500) { console.log('adult backfill: slow step, show ' + id + ', ' + took + ' ms') }
  321. backfillNextAt = now() + r.requests * msPerRequest
  322. let finished = backfillPos >= backfillQueue.length
  323. if (finished || backfillPos % 25 == 0) { persistSync() }
  324. if (!finished && backfillTotals.titles > 0 && backfillTotals.titles % backfillLogEvery == 0 && !r.retry) { console.log('adult backfill: ' + backfillLine()) }
  325. if (finished) {
  326. backfillDone = true
  327. console.log('adult backfill done: ' + backfillLine())
  328. }
  329. return null
  330. }
  331. // ONE clock for both (a tick every 0.1 s): the daily sync's step once a second as before; the backfill's steps in between,
  332. // only while no daily run is going on
  333. clockOn = syncOn || backfillOn
  334. clockTicks = 0
  335. if (syncOn) { console.log('tmdb sync: daily at ' + syncHour + ':00 UTC') } else { console.log('tmdb sync: off (' + (syncEnabled ? 'TRACKER_SYNC=0' : 'no TMDB_READ_TOKEN') + ')') }
  336. if (!backfillOn) { console.log('adult backfill: off (' + (syncEnabled ? 'TRACKER_BACKFILL=0' : 'no TMDB_READ_TOKEN') + ')') }
  337. if (clockOn) {
  338. syncClock = every(0.1)
  339. on syncClock.tick(x) {
  340. clockTicks = clockTicks + 1
  341. let busy = syncQueue.length > 0
  342. if (syncOn && clockTicks % 10 == 0) { syncTick() }
  343. if (backfillOn && !busy && syncQueue.length == 0) { backfillTick() }
  344. return null
  345. }
  346. }
  347. on Error(e) { console.log('error absorbed: ' + e.message) }

Branches

Latest commits

  • f14db671tracker#22-#25 (mission 058): episode air dates, season check = all episodes watched, movie watched check (+ /my/movies count), /genres/<genre> pages (movies + series, newest first, paginated); gate 238, tests/realdata-058.mjs, README + STATUSmre
  • 1704ec45tracker#17 (mission 057): season caret down/up, skeleton rows while a season loads, sessionless showSeasonEpisodes face (no page re-mount), client-only close; gate 214, tests/realdata-057.mjs, README + STATUSmre
  • f2fe3e36mission 056: README + STATUS (merge, fixes, Hybriel 8590df63, real-data check), tests/realdata-056.mjs, tools/check-public-slugs.hlmre
  • f40c250emission 056: re-vendor hybriel master 8590df63 (#121, #122); an adult title's page is Not found for non-followers; gate: leave the page before stopping the servermre
  • 2b7fdd6cmission 056: signed-out header one row on phones ("Log in", nowrap), backfill skips adult titles' posters, gate checksmre
  • 2c53d5efMerge branch 't16-person' (tracker#16 person pages) into main; filmography shows only public titles (054 adult flag), gate race fix (backfill start line)mre
  • c171227emission 054: hide adult/unknown titles from the public lists and the search; in-app adult-flag backfill (TMDB details + poster per title, resumes), gate + real-data proofmre
  • 139fafd8tracker#16: short bio (4 lines, click = all), real-data check script, README + STATUSmre
  • 93be9476tracker#16: person pages /person/<slug> with the filmography fetched from TMDB on the first visit (step by step), gatemre
  • 47a3cae6STATUS: mission 053 merge commit idsmre
  • dcc5eecaMerge branch 't14-search'mre
  • 03edc783Merge branch 't15-tvmaze'mre
  • 71b46345tracker#15: numbering check by date or title, placeholder titles in other languages, docs + real-data proofmre
  • 6bb2daf1tracker#13: homepage (tiles, intro, latest movies/shows), /shows, /movies/page/N, /my/movies; lists cached in memorymre
  • b8bd1157tracker#14: README + STATUS (search, real-data numbers, gate, merge notes)mre
  • 65c694a8tracker#14: search — header magnifier, /search/<text> (in-memory word-prefix index over titles + people), Fetch from web (TMDB search/multi, ours left out), Add = import via syncShow; gate +25 checks, real-data scriptmre
  • 34f2c15btracker#15: TVmaze merge in the sync (gaps only: new episodes/seasons, empty titles/air dates; numbering check), fake TVmaze episodes + gatemre
  • cbdc4ea7tracker#12: link icons TMDB/IMDb/TVDB/TVmaze; sync fills missing ids (TVmaze lookup); movies fetched via /movie/mre
  • b105bcd8tracker#11: Hybriel master ff51cf46 (checks no longer vanish), mobile-first styles, carets, follow button, sign-in modal, inverted check, orange castmre
  • 31b758aatracker#10: installable app (manifest, service worker, offline shell), own icon + faviconmre