gitoriaLog in with ident

calendar

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commit90a3fc2c90a3fc2cdeploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre90a3fc2c/users.hl

5.2 KB

  1. // users.hl — WHO OWNS EVENTS (ticket calendar#2; CONCEPT.md "login via ident"). Login is ident's LOGIN BUTTON flow
  2. // (ident README "How apps use ident", way 2): <ident>/login?key=&return=<public url>/login/callback → ?ident_code=
  3. // → the server exchanges it (key + secret) for the per-app identity id. Way 3, the IDENTITY SELECTOR, sits beside the
  4. // button (login.js hands its code to the shell).
  5. //
  6. // usersTable pk @id index !identity { identity, created } storage/mpackdb/users.db
  7. // identity = what ident's exchange answers: the identity's public SHORT id since ident#23 (`a68sz`; old 32-hex per-app
  8. // ids are rewritten once by tools/migrate-short-ids.hl) — stays SERVER SIDE, never sent to a page.
  9. // The session (hl:web) carries `user = { id = <users @id> }` only. No display name: events are private.
  10. //
  11. // Config (environment, or `.env` beside project.hl — never read or printed by workers):
  12. // IDENT_URL, IDENT_EXCHANGE_URL, IDENT_API_KEY, IDENT_API_SECRET as in gitoria
  13. // CALENDAR_PUBLIC_URL the app's address, default https://calendar.worldapi.org
  14. // CALENDAR_STORAGE table directory, default ./storage/mpackdb
  15. import { MPackDB } from 'hl:mpackdb'
  16. import { env } from 'hl:proc'
  17. import { now } from 'hl:time'
  18. import { fetch } from 'hl:fetch'
  19. static envOr = (name, fallback) => {
  20. let v = env(name)
  21. return v != null && v.trim() != '' ? v.trim() : fallback
  22. }
  23. static identUrl = envOr('IDENT_URL', 'https://ident.worldapi.org')
  24. static identExchangeUrl = envOr('IDENT_EXCHANGE_URL', identUrl)
  25. static identKey = envOr('IDENT_API_KEY', '')
  26. static identSecret = envOr('IDENT_API_SECRET', '')
  27. static publicUrl = envOr('CALENDAR_PUBLIC_URL', 'https://calendar.worldapi.org')
  28. static storageDir = envOr('CALENDAR_STORAGE', './storage/mpackdb')
  29. static usersTable = new MPackDB(file = storageDir + '/users.db', primaryKey = '@id', indexes = ['!identity'])
  30. static countOfList = (list) => {
  31. if (list == null) { return 0 }
  32. let n = list.length
  33. return n == null ? 0 : n
  34. }
  35. static firstOf = (list) => { return countOfList(list) > 0 ? list[0] : null }
  36. static selectorScript = identUrl + '/selector.js'
  37. static callbackUrl = publicUrl.replaceAll('/', '') == '' ? '' : publicUrl + '/login/callback'
  38. static loginHref = identUrl + '/login?key=' + identKey + '&return=' + encodeURIComponent(callbackUrl)
  39. // only lowercase hex (ident's one-time codes are 48 hex)
  40. static isHex = (s, max) => {
  41. if (s == null || hlTypeName(s) != 'String' || s.length == 0 || s.length > max) { return false }
  42. let i = 0
  43. while (i < s.length) {
  44. let c = s.charCodeAt(i)
  45. if (!((c >= 48 && c <= 57) || (c >= 97 && c <= 102))) { return false }
  46. i = i + 1
  47. }
  48. return true
  49. }
  50. // an identity id as ident answers it: its public SHORT ID since ident#23 (5 characters like `a68sz`: 2-9 and a-z),
  51. // before that the old per-app id (32 hex) — lower case letters and digits, at most 64 (mission 039; isHex refused `a68sz`)
  52. static isIdentId = (s) => {
  53. if (s == null || hlTypeName(s) != 'String' || s.length == 0 || s.length > 64) { return false }
  54. let i = 0
  55. while (i < s.length) {
  56. let c = s.charCodeAt(i)
  57. if (!((c >= 48 && c <= 57) || (c >= 97 && c <= 122))) { return false }
  58. i = i + 1
  59. }
  60. return true
  61. }
  62. // THE EXCHANGE: POST <ident>/api/exchange { key, secret, code } → { identity } | { error }
  63. // (a failed fetch is an `Error` event, absorbed by project.hl's `on Error`; the fetch then yields null)
  64. static exchangeCode = (code) => {
  65. if (identKey == '' || identSecret == '') { return { error = 'login is not set up on this server (IDENT_API_KEY / IDENT_API_SECRET missing)' } }
  66. if (!isHex(code, 200)) { return { error = 'that is not an ident login code' } }
  67. let r = fetch(identExchangeUrl + '/api/exchange', { method = 'POST' json = { key = identKey secret = identSecret code = code } headers = { 'user-agent' = 'calendar.worldapi.org (ident exchange)' } timeoutMs = 10000 })
  68. if (r == null || r.status == null || r.status == 0) { return { error = 'ident did not answer' } }
  69. let j = r.status == 200 ? r.json() : null
  70. if (j == null || j.identity == null || !isIdentId(j.identity)) {
  71. let why = ''
  72. if (r.status != 200) {
  73. let e = r.json()
  74. why = e != null && e.error != null ? ': ' + e.error : ''
  75. }
  76. return { error = 'ident refused the login (' + r.status + why + ')' }
  77. }
  78. return { identity = j.identity }
  79. }
  80. // ---- users --------------------------------------------------------------------------------
  81. // a face's trailing `session` is always the server's since hybriel #16 (a peer's extra argument is refused)
  82. static userRecord = (userId) => {
  83. if (userId == null || hlTypeName(userId) != 'String' || userId == '') { return null }
  84. return usersTable.fetch(userId)
  85. }
  86. // the user of an identity id, made at its first login
  87. static ensureUser = (identity) => {
  88. let u = firstOf(usersTable.find('identity', identity))
  89. if (u != null) { return u }
  90. let id = usersTable.put({ identity = identity created = now() })
  91. if (id == null) { return null }
  92. return usersTable.fetch(id)
  93. }
  94. static userOfSession = (session) => {
  95. if (session == null || session.user == null) { return null }
  96. return userRecord(session.user.id)
  97. }
  98. // the users @id of a session, or null (a page may know it: it is not the identity id)
  99. static userIdOfSession = (session) => {
  100. let u = userOfSession(session)
  101. return u == null ? null : u.id
  102. }

Branches

Latest commits

  • 90a3fc2cdeploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • 6722b72ddeploy.sh: never send .git or .gitignore to Byrodinmre
  • be099807State of 2026-09-27, before the move to gitoriamre