gitoriaLog in with ident

tracker

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commitf14db671f14db671tracker#22-#25 (mission 058): episode air dates, season check = all episodes watched, movie watched check (+ /my/movies count), /genres/<genre> pages (movies + series, newest first, paginated); gate 238, tests/realdata-058.mjs, README + STATUSmref14db671/users.hl

5.2 KB

  1. // users.hl — WHO IS SIGNED IN (tracker.worldapi.org#1; copied from calendar.worldapi.org's users.hl unchanged in
  2. // shape, per the architect: "Copy calendar.worldapi.org's login unchanged"). Login is ident's LOGIN BUTTON flow
  3. // (ident README "How apps use ident", way 2): <ident>/login?key=&return=<public url>/login/callback → ?ident_code=
  4. // → the server exchanges it (key + secret) for the per-app identity id. Way 3, the IDENTITY SELECTOR, sits beside the
  5. // button (login.js hands its code to the shell).
  6. //
  7. // usersTable pk @id index !identity { identity, created } storage/mpackdb/users.db
  8. // identity = what ident's exchange answers: the identity's public SHORT id (ident#23, `a68sz`) — stays SERVER
  9. // SIDE, never sent to a page.
  10. // The session (hl:web) carries `user = { id = <users @id> }` only. No display name: nothing else is stored.
  11. //
  12. // Config (environment, or `.env` beside project.hl — never read or printed by workers):
  13. // IDENT_URL, IDENT_EXCHANGE_URL, TRACKER_KEY, TRACKER_SECRET as calendar's IDENT_API_KEY/IDENT_API_SECRET
  14. // TRACKER_URL the app's own address, default https://tracker.worldapi.org
  15. // TRACKER_STORAGE table directory, default ./storage/mpackdb
  16. import { MPackDB } from 'hl:mpackdb'
  17. import { env } from 'hl:proc'
  18. import { now } from 'hl:time'
  19. import { fetch } from 'hl:fetch'
  20. static envOr = (name, fallback) => {
  21. let v = env(name)
  22. return v != null && v.trim() != '' ? v.trim() : fallback
  23. }
  24. static identUrl = envOr('IDENT_URL', 'https://ident.worldapi.org')
  25. static identExchangeUrl = envOr('IDENT_EXCHANGE_URL', identUrl)
  26. static identKey = envOr('TRACKER_KEY', '')
  27. static identSecret = envOr('TRACKER_SECRET', '')
  28. static publicUrl = envOr('TRACKER_URL', 'https://tracker.worldapi.org')
  29. static storageDir = envOr('TRACKER_STORAGE', './storage/mpackdb')
  30. static usersTable = new MPackDB(file = storageDir + '/users.db', primaryKey = '@id', indexes = ['!identity'])
  31. static countOfList = (list) => {
  32. if (list == null) { return 0 }
  33. let n = list.length
  34. return n == null ? 0 : n
  35. }
  36. static firstOf = (list) => { return countOfList(list) > 0 ? list[0] : null }
  37. static selectorScript = identUrl + '/selector.js'
  38. static callbackUrl = publicUrl.replaceAll('/', '') == '' ? '' : publicUrl + '/login/callback'
  39. static loginHref = identUrl + '/login?key=' + identKey + '&return=' + encodeURIComponent(callbackUrl)
  40. // only lowercase hex (ident's one-time codes are 48 hex)
  41. static isHex = (s, max) => {
  42. if (s == null || hlTypeName(s) != 'String' || s.length == 0 || s.length > max) { return false }
  43. let i = 0
  44. while (i < s.length) {
  45. let c = s.charCodeAt(i)
  46. if (!((c >= 48 && c <= 57) || (c >= 97 && c <= 102))) { return false }
  47. i = i + 1
  48. }
  49. return true
  50. }
  51. // an identity id as ident answers it: its public SHORT ID since ident#23 (5 characters like `a68sz`: 2-9 and a-z),
  52. // before that the old per-app id (32 hex) — lower case letters and digits, at most 64
  53. static isIdentId = (s) => {
  54. if (s == null || hlTypeName(s) != 'String' || s.length == 0 || s.length > 64) { return false }
  55. let i = 0
  56. while (i < s.length) {
  57. let c = s.charCodeAt(i)
  58. if (!((c >= 48 && c <= 57) || (c >= 97 && c <= 122))) { return false }
  59. i = i + 1
  60. }
  61. return true
  62. }
  63. // THE EXCHANGE: POST <ident>/api/exchange { key, secret, code } → { identity } | { error }
  64. // (a failed fetch is an `Error` event, absorbed by project.hl's `on Error`; the fetch then yields null)
  65. static exchangeCode = (code) => {
  66. if (identKey == '' || identSecret == '') { return { error = 'login is not set up on this server (TRACKER_KEY / TRACKER_SECRET missing)' } }
  67. if (!isHex(code, 200)) { return { error = 'that is not an ident login code' } }
  68. let r = fetch(identExchangeUrl + '/api/exchange', { method = 'POST' json = { key = identKey secret = identSecret code = code } headers = { 'user-agent' = 'tracker.worldapi.org (ident exchange)' } timeoutMs = 10000 })
  69. if (r == null || r.status == null || r.status == 0) { return { error = 'ident did not answer' } }
  70. let j = r.status == 200 ? r.json() : null
  71. if (j == null || j.identity == null || !isIdentId(j.identity)) {
  72. let why = ''
  73. if (r.status != 200) {
  74. let e = r.json()
  75. why = e != null && e.error != null ? ': ' + e.error : ''
  76. }
  77. return { error = 'ident refused the login (' + r.status + why + ')' }
  78. }
  79. return { identity = j.identity }
  80. }
  81. // ---- users --------------------------------------------------------------------------------
  82. // a face's trailing `session` is always the server's since hybriel #16 (a peer's extra argument is refused)
  83. static userRecord = (userId) => {
  84. if (userId == null || hlTypeName(userId) != 'String' || userId == '') { return null }
  85. return usersTable.fetch(userId)
  86. }
  87. // the user of an identity id, made at its first login
  88. static ensureUser = (identity) => {
  89. let u = firstOf(usersTable.find('identity', identity))
  90. if (u != null) { return u }
  91. let id = usersTable.put({ identity = identity created = now() })
  92. if (id == null) { return null }
  93. return usersTable.fetch(id)
  94. }
  95. static userOfSession = (session) => {
  96. if (session == null || session.user == null) { return null }
  97. return userRecord(session.user.id)
  98. }
  99. // the users @id of a session, or null (a page may know it: it is not the identity id)
  100. static userIdOfSession = (session) => {
  101. let u = userOfSession(session)
  102. return u == null ? null : u.id
  103. }

Branches

Latest commits

  • f14db671tracker#22-#25 (mission 058): episode air dates, season check = all episodes watched, movie watched check (+ /my/movies count), /genres/<genre> pages (movies + series, newest first, paginated); gate 238, tests/realdata-058.mjs, README + STATUSmre
  • 1704ec45tracker#17 (mission 057): season caret down/up, skeleton rows while a season loads, sessionless showSeasonEpisodes face (no page re-mount), client-only close; gate 214, tests/realdata-057.mjs, README + STATUSmre
  • f2fe3e36mission 056: README + STATUS (merge, fixes, Hybriel 8590df63, real-data check), tests/realdata-056.mjs, tools/check-public-slugs.hlmre
  • f40c250emission 056: re-vendor hybriel master 8590df63 (#121, #122); an adult title's page is Not found for non-followers; gate: leave the page before stopping the servermre
  • 2b7fdd6cmission 056: signed-out header one row on phones ("Log in", nowrap), backfill skips adult titles' posters, gate checksmre
  • 2c53d5efMerge branch 't16-person' (tracker#16 person pages) into main; filmography shows only public titles (054 adult flag), gate race fix (backfill start line)mre
  • c171227emission 054: hide adult/unknown titles from the public lists and the search; in-app adult-flag backfill (TMDB details + poster per title, resumes), gate + real-data proofmre
  • 139fafd8tracker#16: short bio (4 lines, click = all), real-data check script, README + STATUSmre
  • 93be9476tracker#16: person pages /person/<slug> with the filmography fetched from TMDB on the first visit (step by step), gatemre
  • 47a3cae6STATUS: mission 053 merge commit idsmre
  • dcc5eecaMerge branch 't14-search'mre
  • 03edc783Merge branch 't15-tvmaze'mre
  • 71b46345tracker#15: numbering check by date or title, placeholder titles in other languages, docs + real-data proofmre
  • 6bb2daf1tracker#13: homepage (tiles, intro, latest movies/shows), /shows, /movies/page/N, /my/movies; lists cached in memorymre
  • b8bd1157tracker#14: README + STATUS (search, real-data numbers, gate, merge notes)mre
  • 65c694a8tracker#14: search — header magnifier, /search/<text> (in-memory word-prefix index over titles + people), Fetch from web (TMDB search/multi, ours left out), Add = import via syncShow; gate +25 checks, real-data scriptmre
  • 34f2c15btracker#15: TVmaze merge in the sync (gaps only: new episodes/seasons, empty titles/air dates; numbering check), fake TVmaze episodes + gatemre
  • cbdc4ea7tracker#12: link icons TMDB/IMDb/TVDB/TVmaze; sync fills missing ids (TVmaze lookup); movies fetched via /movie/mre
  • b105bcd8tracker#11: Hybriel master ff51cf46 (checks no longer vanish), mobile-first styles, carets, follow button, sign-in modal, inverted check, orange castmre
  • 31b758aatracker#10: installable app (manifest, service worker, offline shell), own icon + faviconmre