gitoriaLog in with ident

calendar

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit3b2a4cd03b2a4cd0calendar mission 001 (3/4): code order — let only where reassigned (147 dropped incl. components/month-view; 110 left: 67 reassigned, 43 loop-bound); gates 78/0 (3 of 4 runs; 1 known 'next month' flake) + 18/0, live-data run = step 2mre3b2a4cd0/lib/api.hl

2.2 KB

  1. // lib/api.hl — THE FUNCTION ROUTES (calendar mission 001, code order): thin wrappers — check the input and the session,
  2. // call the topic (lib/users.hl), answer. The calendar's own reads and writes are faces (components/calendar.hl).
  3. //
  4. // THE LOGIN BUTTON'S RETURN (ident README "How apps use ident"): /login/callback?ident_code=&next= → the user
  5. // (lib/users.hl userOfLoginCode) → the session is signed in → back to `next` (lib/api-helpers.hl safePath). A FAILED
  6. // LOGIN is a page (components/loginfailed.hl): the reason is parked in the session, then → /login/failed.
  7. // These two write the session: project.hl hands them the request and the session store BY REFERENCE (&req, &sessions);
  8. // a by-value copy would lose the write (tickets mission 010, gitoria mission 002, notes mission 002).
  9. import { Response } from 'hl:http1'
  10. import { randomBytes } from 'hl:crypto'
  11. import { userOfLoginCode } from './users.hl'
  12. import { safePath } from './api-helpers.hl'
  13. static loginFailed = (&req, &sessions, why) => {
  14. let s = req.session
  15. fresh = s == null
  16. if (fresh) { s = sessions.mint() }
  17. s.data.loginError = why
  18. sessions.save(s)
  19. res = new Response('login failed: ' + why, { status = 302 headers = { 'Location' = '/login/failed' 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  20. if (fresh) { res.headers['Set-Cookie'] = sessions.cookieHeader(s.id) }
  21. return res
  22. }
  23. // the function route gets the cookie's session as req.session (hybriel #11); none yet → minted here
  24. static loginCallback = (route, &req, &sessions) => {
  25. if (req.method != 'GET') { return loginFailed(&req, &sessions, 'GET only') }
  26. q = req.query != null ? req.query : {}
  27. code = q.ident_code
  28. if (code == null || code == '') { return loginFailed(&req, &sessions, 'ident sent no login code') }
  29. x = userOfLoginCode(code)
  30. if (x.error != null) { return loginFailed(&req, &sessions, x.error) }
  31. let s = req.session
  32. fresh = s == null
  33. if (fresh) { s = sessions.mint() }
  34. s.user = { id = x.user.id }
  35. s.data.tag = randomBytes(16)
  36. s.data.loginError = null
  37. sessions.save(s)
  38. res = new Response('logged in', { status = 302 headers = { 'Location' = safePath(q.next) 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  39. if (fresh) { res.headers['Set-Cookie'] = sessions.cookieHeader(s.id) }
  40. return res
  41. }

Branches

Latest commits

  • 3b2a4cd0calendar mission 001 (3/4): code order — let only where reassigned (147 dropped incl. components/month-view; 110 left: 67 reassigned, 43 loop-bound); gates 78/0 (3 of 4 runs; 1 known 'next month' flake) + 18/0, live-data run = step 2mre
  • f5ce6b1dcalendar mission 001 (2/4): code order — topics, map, thin faces: lib/util.hl, lib/events(-helpers).hl (+calendarView/settingsView/soonOf), lib/settings.hl, lib/users.hl (+userOfLoginCode, tagOf), lib/api(-helpers).hl; project.hl = map; login route takes &req/&sessions (failed-login reason now kept); gates 78/0 + 18/0mre
  • c6fbd011calendar mission 001 (1/4): code order — files moved: lib/events.hl, lib/users.hl, components/styles.hl (imports only); gates 78/0 + 18/0, live-data run identicalmre
  • d6c59290calendar: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); gates 78/0 + 18/0mre
  • 7bd0337ccalendar: Hybriel master 190aa11d (fc838894 GC correctness, #126 closure scopes, #127); gates 78/0 + 18/0mre
  • ff41310ccalendar: Hybriel master 8efba065 (#126 memory, #48 lambda copy; audit: no & needed)mre
  • 14ba08c7antcolony#40: mission references point to the moved missionsmre
  • 99c73346antcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 76edaa62calendar: Hybriel master ff51cf46 (re-vendor round, static workaround removed)mre
  • 90a3fc2cdeploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • 6722b72ddeploy.sh: never send .git or .gitignore to Byrodinmre
  • be099807State of 2026-09-27, before the move to gitoriamre