gitoriaLog in with ident

calendar

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit6722b72d6722b72ddeploy.sh: never send .git or .gitignore to Byrodinmre6722b72d/project.hl

4.8 KB

  1. // project.hl — calendar.worldapi.org: THE CALENDAR. The month view at `/` (ticket #1); login with ident and the
  2. // user's private events (ticket #2).
  3. import WebFramework from 'hl:web'
  4. import { env } from 'hl:proc'
  5. import { Response } from 'hl:http1'
  6. import { randomBytes } from 'hl:crypto'
  7. import Styles from './styles.hl'
  8. import { exchangeCode, ensureUser } from './users.hl'
  9. import Calendar from './components/calendar.hl'
  10. import LoginFailed from './components/loginfailed.hl'
  11. static siteName = "Calendar"
  12. appTitle = siteName
  13. appThemeColor = '#191e23'
  14. appBackgroundColor = '#191e23'
  15. appIcons = [
  16. { src = '/icons/icon-192.png' sizes = '192x192' purpose = 'any' }
  17. { src = '/icons/icon-512.png' sizes = '512x512' purpose = 'any' }
  18. { src = '/icons/icon-192.png' sizes = '192x192' purpose = 'maskable' }
  19. { src = '/icons/icon-512.png' sizes = '512x512' purpose = 'maskable' }
  20. ]
  21. offline = [ Calendar ]
  22. styles = Styles
  23. // ---- THE LOGIN BUTTON'S RETURN (ident README "How apps use ident") ----------------------------
  24. // BACK TO THE PAGE: /login.js puts `?next=` into the button's return URL at the click. Only a same-origin PATH
  25. // goes (one `/`, URL-safe characters, ≤ 500). Anything else → `/`.
  26. nextChars = 'abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789-._~/?&=%+,;@!$()*:'
  27. safePath = (want) => {
  28. if (want == null || hlTypeName(want) != 'String' || want == '' || want.length > 500) { return '/' }
  29. if (want.slice(0, 1) != '/' || want.slice(0, 2) == '//' || want.slice(0, 7) == '/login/') { return '/' }
  30. let i = 0
  31. while (i < want.length) {
  32. if (!nextChars.includes(want[i])) { return '/' }
  33. i = i + 1
  34. }
  35. return want
  36. }
  37. // A FAILED LOGIN is a page (components/loginfailed.hl): the reason is parked in the session, then → /login/failed
  38. failed = (req, why) => {
  39. let s = req.session
  40. let fresh = s == null
  41. if (fresh) { s = server.sessions.mint() }
  42. s.data.loginError = why
  43. server.sessions.save(s)
  44. let res = new Response('login failed: ' + why, { status = 302 headers = { 'Location' = '/login/failed' 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  45. if (fresh) { res.headers['Set-Cookie'] = server.sessions.cookieHeader(s.id) }
  46. return res
  47. }
  48. // the function route gets the cookie's session as req.session (hybriel #11); none yet → minted here
  49. loginCallback = (route, req) => {
  50. if (req.method != 'GET') { return failed(req, 'GET only') }
  51. let q = req.query != null ? req.query : {}
  52. let code = q.ident_code
  53. if (code == null || code == '') { return failed(req, 'ident sent no login code') }
  54. let x = exchangeCode(code)
  55. if (x.error != null) { return failed(req, x.error) }
  56. let u = ensureUser(x.identity)
  57. if (u == null) { return failed(req, 'could not store the user') }
  58. let s = req.session
  59. let fresh = s == null
  60. if (fresh) { s = server.sessions.mint() }
  61. s.user = { id = u.id }
  62. s.data.tag = randomBytes(16)
  63. s.data.loginError = null
  64. server.sessions.save(s)
  65. let res = new Response('logged in', { status = 302 headers = { 'Location' = safePath(q.next) 'Cache-Control' = 'no-store' 'Content-Type' = 'text/plain; charset=utf-8' } })
  66. if (fresh) { res.headers['Set-Cookie'] = server.sessions.cookieHeader(s.id) }
  67. return res
  68. }
  69. routes = [
  70. { pattern = "/favicon.ico" direct = "" }
  71. { pattern = "/login/callback" function = loginCallback }
  72. { pattern = "/login/failed" component = LoginFailed }
  73. { pattern = "/login.js" file = "./login.js" headers = { 'Cache-Control' = 'no-cache' } }
  74. // the installable app (ticket #3): the icons (manifest and service worker are hl:web's own, from appIcons / offline)
  75. { pattern = "/icons/icon-192.png" file = "./icons/icon-192.png" headers = { 'Cache-Control' = 'no-cache' } }
  76. { pattern = "/icons/icon-512.png" file = "./icons/icon-512.png" headers = { 'Cache-Control' = 'no-cache' } }
  77. { pattern = "/" component = Calendar }
  78. ]
  79. // WHO GETS THE PUSH: the login state reaches the tabs of one session.
  80. // `calendarSignedIn` / `calendarSignedOut` go to the tabs of ONE session: the one whose login carries that random tag.
  81. tagOf = (session) => { return session != null && session.data != null ? session.data.tag : null }
  82. audience = {
  83. calendarSignedIn = (tag, session) => { return tag != null && tagOf(session) == tag }
  84. calendarSignedOut = (tag, session) => { return tag != null && tagOf(session) == tag }
  85. }
  86. sessionDir = env('CALENDAR_SESSIONS') != null ? env('CALENDAR_SESSIONS') : null
  87. port = env('CALENDAR_PORT') != null ? toNumber(env('CALENDAR_PORT')) : 8380
  88. // HL_HOST = the interface hl:web binds: 127.0.0.1 on Byrodin behind nginx; unset = 0.0.0.0 (dev on Loreana).
  89. // CALENDAR_WATCH=0 = no dev watcher.
  90. watching = env('CALENDAR_WATCH') != '0'
  91. // The session idles out after the 14 days of sessionMaxAge, not after 15 minutes.
  92. sessionCookie = 'calendarsid'
  93. sessionIdle = 1209600
  94. server = new WebFramework(routes = routes, styles = styles, minify = true, port = port, watchMode = watching, sessionCookie = sessionCookie)
  95. on Error(e) { console.log('error absorbed: ' + e.message) }

Branches

Latest commits

  • 6722b72ddeploy.sh: never send .git or .gitignore to Byrodinmre
  • be099807State of 2026-09-27, before the move to gitoriamre