6 Commits
Author SHA1 Message Date
portal release 00449916a3 Match portal v0.5.7
Test / test (push) Successful in 2m13s
Publish release / publish (push) Successful in 26s
2026-09-30 13:36:50 +02:00
Bendik Aagaard LynghaugandClaude Fable 5.1 41db6093e5 The effort budget counts what a person fills in, not carrier fields
Test / test (push) Successful in 2m38s
A type: record field carries the case an answer is about on the link,
and a hidden preset carries a value; neither is asked. An objection
form that carried the application's id counted one field over.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GT37Z1Xtfd9pUuQtMTg6Yt
2026-09-30 08:57:03 +02:00
portal release 572dfc200c Match portal v0.5.6
Test / test (push) Successful in 30s
Publish release / publish (push) Successful in 26s
2026-09-30 08:22:10 +02:00
portal release 955a33609a Match portal v0.5.5
Test / test (push) Successful in 30s
Publish release / publish (push) Successful in 25s
2026-09-30 07:54:29 +02:00
portal release 9b96111916 Match portal v0.5.4
Test / test (push) Successful in 30s
Publish release / publish (push) Successful in 25s
2026-09-29 21:14:02 +02:00
portal release f2fc5097f7 Match portal v0.5.3
Test / test (push) Successful in 29s
Publish release / publish (push) Successful in 25s
2026-09-29 13:33:07 +02:00
7 changed files with 46 additions and 349 deletions
+24
View File
@@ -3,6 +3,30 @@
One line per change, grouped by the release that shipped it. Newest One line per change, grouped by the release that shipped it. Newest
first. Each release names the portal tag it is built against. first. Each release names the portal tag it is built against.
## 0.5.7 (2026-09-30) - portal v0.5.7
- Matches portal v0.5.7 (released by portal's publish job).
## Unreleased
- The effort budget counts what a person fills in: a `type: record` field (the case an answer is about, carried on the link) and a `hidden` preset are not asked and no longer count. An objection page whose form carried the application's id used to be one field over.
## 0.5.6 (2026-09-30) - portal v0.5.6
- Matches portal v0.5.6 (released by portal's publish job).
## 0.5.5 (2026-09-30) - portal v0.5.5
- Matches portal v0.5.5 (released by portal's publish job).
## 0.5.4 (2026-09-29) - portal v0.5.4
- Matches portal v0.5.4 (released by portal's publish job).
## 0.5.3 (2026-09-29) - portal v0.5.3
- Matches portal v0.5.3 (released by portal's publish job).
## 0.5.2 (2026-09-28) - portal v0.5.2 ## 0.5.2 (2026-09-28) - portal v0.5.2
- Matches portal v0.5.2 (released by portal's publish job). - Matches portal v0.5.2 (released by portal's publish job).
Generated
+3 -3
View File
@@ -2287,7 +2287,7 @@ checksum = "791930b43c0d5973160d90a8f3894509f2b273430f5c5c73b668636d0287c5c0"
[[package]] [[package]]
name = "iris" name = "iris"
version = "0.5.2" version = "0.5.7"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"async-nats", "async-nats",
@@ -3406,8 +3406,8 @@ dependencies = [
[[package]] [[package]]
name = "portal" name = "portal"
version = "0.5.2" version = "0.5.7"
source = "git+https://project.uhhm.no/uhhm/portal.git?tag=v0.5.2#45240b7cabcc59f1802ad1bd432f512a47110d2c" source = "git+https://project.uhhm.no/uhhm/portal.git?tag=v0.5.7#cc26a232ec3ce8e84a4f89a73609f6d7fb74b9d7"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"arc-swap", "arc-swap",
+2 -2
View File
@@ -1,6 +1,6 @@
[package] [package]
name = "iris" name = "iris"
version = "0.5.2" version = "0.5.7"
edition = "2021" edition = "2021"
description = "The iris over a portal site: nothing from a content repo comes through until it checks out" description = "The iris over a portal site: nothing from a content repo comes through until it checks out"
license = "MIT" license = "MIT"
@@ -10,7 +10,7 @@ repository = "https://project.uhhm.no/uhhm/iris"
# The site's own content types and loaders, so iris reads a repo exactly # The site's own content types and loaders, so iris reads a repo exactly
# the way the running site does. Pinned to the portal release it # the way the running site does. Pinned to the portal release it
# matches; bumping this tag is what a new iris release is. # matches; bumping this tag is what a new iris release is.
portal = { git = "https://project.uhhm.no/uhhm/portal.git", tag = "v0.5.2", features = ["ssr"] } portal = { git = "https://project.uhhm.no/uhhm/portal.git", tag = "v0.5.7", features = ["ssr"] }
anyhow = "1" anyhow = "1"
serde = { version = "1", features = ["derive"] } serde = { version = "1", features = ["derive"] }
serde_json = "1" serde_json = "1"
-15
View File
@@ -102,21 +102,6 @@ pub async fn run(argv: Vec<String>) -> anyhow::Result<()> {
std::process::exit(1); std::process::exit(1);
} }
println!("OK: access policy, {} rule(s), validates", policy.rules.len()); println!("OK: access policy, {} rule(s), validates", policy.rules.len());
// What the site mails, checked before anyone receives it:
// placeholders that would go out blank, links to pages
// that are not there, grants and invites nobody hears of.
let findings = crate::mail::check(&questions, &aggregates_map, &site);
for f in &findings {
let tag = if f.level == needs::Level::Fail { "FAIL" } else { "WARN" };
eprintln!("{tag}: {}", f.text);
}
if findings.iter().any(|f| f.level == needs::Level::Fail) {
std::process::exit(1);
}
let mails = crate::mail::count(&aggregates_map, &site);
if mails > 0 {
println!("OK: {mails} mail(s): every placeholder fills, every link lands");
}
if show_access { if show_access {
println!("\n{:<16} {:<44} {:<40} {}", "ACTION", "RESOURCE", "WHO", "WHEN"); println!("\n{:<16} {:<44} {:<40} {}", "ACTION", "RESOURCE", "WHO", "WHEN");
let mut rows = policy.rules.clone(); let mut rows = policy.rules.clone();
-327
View File
@@ -1,327 +0,0 @@
//! What the site's mail promises, checked before it is sent to anyone.
//!
//! A mail is read alone, away from the page that caused it, by a
//! person who cannot ask what a blank means. Portal renders a `{key}`
//! it has no value for as nothing, silently, and sends a link to a
//! page that is not there as readily as one that is. So the things a
//! mail can get wrong without any runtime error are checked here:
//!
//! - **fail** a placeholder no record in the bucket can fill: the mail
//! goes out with a hole in it;
//! - **fail** a link to a page the site does not have;
//! - **fail** a state that grants a group on a site that sends no mail:
//! the account is made and its sign-in link reaches nobody;
//! - **fail** an invite mail without its `{link}`, or with a
//! placeholder the invite cannot fill;
//! - **warn** a placeholder only some of the bucket's forms collect, or
//! one every form marks optional: it is blank in the mails about the
//! others, or about anyone who skipped it;
//! - **warn** a dialogue that does not close: the person is mailed on
//! the way in and not told how their case ended;
//! - **warn** a mail that tells a person their case is where they may
//! now act on it, and gives them no link to do so;
//! - **warn** a long answer (a `textarea` field) put in a subject line,
//! which becomes the whole brief in someone's inbox list.
use std::collections::{BTreeMap, BTreeSet, HashMap};
use portal::aggregates::AggregateSchema;
use portal::content::{self, Question, SiteConfig};
use crate::needs::Level;
/// What portal fills in a case mail besides the record's own answers
/// (`mail.rs`, `vars_for`).
const CASE_VARS: &[&str] = &["email", "site", "chain", "bucket", "state"];
/// What portal fills in the invite mail (`mail.rs`, `on_invite`).
const INVITE_VARS: &[&str] = &["name", "username", "email", "group", "link", "site", "site_name", "expires"];
#[derive(Debug)]
pub struct Finding {
pub level: Level,
pub text: String,
}
/// `{key}` exactly as portal's renderer reads one: ASCII alphanumerics,
/// `_`, `-` and `.`, closed by `}`. A brace that opens no key is text.
pub fn placeholders(template: &str) -> Vec<String> {
let mut keys = Vec::new();
let mut rest = template;
while let Some(start) = rest.find('{') {
let after = &rest[start + 1..];
let len = after
.char_indices()
.take_while(|(_, c)| c.is_ascii_alphanumeric() || matches!(c, '_' | '-' | '.'))
.last()
.map(|(i, c)| i + c.len_utf8())
.unwrap_or(0);
if len > 0 && after[len..].starts_with('}') {
keys.push(after[..len].to_string());
rest = &after[len + 1..];
} else {
rest = after;
}
}
keys
}
/// The paths a template links to on its own site: `{site}/x/y?...`.
fn site_links(template: &str) -> Vec<String> {
template
.match_indices("{site}")
.map(|(i, _)| {
let tail = &template[i + "{site}".len()..];
let end = tail.find(|c: char| c.is_whitespace() || matches!(c, '?' | '#' | ')' | '>' | '"' | '\'')).unwrap_or(tail.len());
let path = tail[..end].trim_end_matches(['.', ',', ';', ':']);
if path.is_empty() { "/".to_string() } else { path.to_string() }
})
.collect()
}
fn page_exists(questions: &HashMap<String, Question>, path: &str) -> bool {
let path = path.trim_end_matches('/');
let path = if path.is_empty() { "/" } else { path };
questions.contains_key(path)
|| questions.values().any(|q| q.is_dynamic() && content::path_matches(&q.id, path).is_some())
}
/// For each bucket, the field names of every alternative that records
/// into it: one set per form.
fn forms_by_bucket(questions: &HashMap<String, Question>) -> BTreeMap<String, Vec<(String, BTreeSet<String>)>> {
let mut out: BTreeMap<String, Vec<(String, BTreeSet<String>)>> = BTreeMap::new();
for q in questions.values() {
for alt in &q.alternatives {
if let Some(bucket) = &alt.record_as {
let fields = alt.features.iter().flat_map(|f| &f.requirements).map(|r| r.name.clone()).collect();
out.entry(bucket.clone()).or_default().push((format!("{} / {}", q.id, alt.name), fields));
}
}
}
out
}
/// States with no move out of them: where a case ends.
fn endings(schema: &AggregateSchema) -> BTreeSet<String> {
let mut states: BTreeSet<String> = schema.event_for_state.keys().cloned().collect();
states.insert(schema.initial.clone());
states.into_iter().filter(|s| schema.allowed(s).is_empty()).collect()
}
/// States reachable from `from` along declared moves, `from` included.
fn reachable(schema: &AggregateSchema, from: &str) -> BTreeSet<String> {
let mut seen = BTreeSet::from([from.to_string()]);
let mut todo = vec![from.to_string()];
while let Some(s) = todo.pop() {
for next in schema.allowed(&s) {
if seen.insert(next.clone()) {
todo.push(next.clone());
}
}
}
seen
}
pub fn check(questions: &HashMap<String, Question>, aggregates: &HashMap<String, AggregateSchema>, site: &SiteConfig) -> Vec<Finding> {
let mut findings = Vec::new();
let mut fail = |text: String| findings.push(Finding { level: Level::Fail, text });
let forms = forms_by_bucket(questions);
let mut warns = Vec::new();
// Where the submitter may act on their own record: bucket -> state
// -> the labels of the moves they may make from there.
let mut own_moves: BTreeMap<String, BTreeMap<String, Vec<String>>> = BTreeMap::new();
for q in questions.values() {
for alt in &q.alternatives {
if let Some(st) = &alt.self_transition {
if let Some(schema) = aggregates.get(&st.bucket) {
for from in st.from_states(&schema.initial) {
own_moves.entry(st.bucket.clone()).or_default().entry(from).or_default().push(st.label.clone());
}
}
}
}
}
let mut buckets: Vec<&AggregateSchema> = aggregates.values().collect();
buckets.sort_by(|a, b| a.bucket.cmp(&b.bucket));
for schema in buckets {
let bucket = &schema.bucket;
let bucket_forms = forms.get(bucket).cloned().unwrap_or_default();
let mut states: Vec<(&String, &portal::aggregates::MailSpec)> = schema.mail_for_state.iter().collect();
states.sort_by(|a, b| a.0.cmp(b.0));
for (state, mail) in &states {
let at = format!("mail on {bucket}:{state}");
for key in placeholders(&mail.subject).into_iter().chain(placeholders(&mail.body)) {
if CASE_VARS.contains(&key.as_str()) {
continue;
}
let having: Vec<&String> = bucket_forms.iter().filter(|(_, f)| f.contains(&key)).map(|(n, _)| n).collect();
if having.is_empty() {
fail(format!("{at}: {{{key}}} is not a field any form recording into {bucket:?} collects, nor one portal fills ({}) - it would be sent blank", CASE_VARS.join(", ")));
} else if questions
.values()
.flat_map(|q| &q.alternatives)
.filter(|a| a.record_as.as_deref() == Some(bucket.as_str()))
.flat_map(|a| a.features.iter().flat_map(|f| &f.requirements))
.filter(|r| r.name == key)
.all(|r| r.optional)
{
warns.push(format!("{at}: {{{key}}} is optional on every form - blank for anyone who skipped it"));
} else if having.len() < bucket_forms.len() {
let missing: Vec<&String> = bucket_forms.iter().filter(|(_, f)| !f.contains(&key)).map(|(n, _)| n).collect();
warns.push(format!("{at}: {{{key}}} is blank for records sent from {}", missing.iter().map(|n| format!("{n:?}")).collect::<Vec<_>>().join(", ")));
}
}
for key in placeholders(&mail.subject) {
let long = questions.values().flat_map(|q| &q.alternatives).filter(|a| a.record_as.as_deref() == Some(bucket.as_str())).flat_map(|a| a.features.iter().flat_map(|f| &f.requirements)).any(|r| r.name == key && r.kind == "textarea");
if long {
warns.push(format!("{at}: the subject carries {{{key}}}, a long answer (textarea) - the whole of it lands in the subject line"));
}
}
for path in site_links(&mail.body).into_iter().chain(site_links(&mail.subject)) {
if path.contains('{') {
continue; // filled per record; the page is checked where the pattern is declared
}
if !page_exists(questions, &path) {
fail(format!("{at}: links to {path:?}, which is not a page on this site"));
}
}
}
if !schema.grants_for_state.is_empty() && site.mail.is_none() {
let mut granting: Vec<&String> = schema.grants_for_state.keys().collect();
granting.sort();
fail(format!("{bucket}: state(s) {granting:?} grant a group, and site.yaml has no `mail: {{ from }}` - the account would be made and its sign-in link sent to nobody"));
}
// The dialogue closes: a person mailed on the way in hears how
// it ended, from every ending their case can still reach.
let to_submitter: BTreeSet<&String> = states.iter().filter(|(_, m)| m.to_submitter()).map(|(s, _)| *s).collect();
if let Some(first) = to_submitter.iter().min_by_key(|s| (s.as_str() != schema.initial, s.to_string())) {
let reach = reachable(schema, first);
let silent: Vec<String> = endings(schema).into_iter().filter(|e| reach.contains(e) && !to_submitter.contains(e)).collect();
if !silent.is_empty() {
warns.push(format!("{bucket}: the person is mailed at {first:?} and not told when their case ends at {silent:?}"));
}
}
// A mail telling a person their case is where they may act on
// it carries the link that lets them.
for (state, mail) in &states {
if !mail.to_submitter() {
continue;
}
if let Some(labels) = own_moves.get(bucket).and_then(|m| m.get(*state)) {
if !mail.body.contains("{chain}") {
warns.push(format!("mail on {bucket}:{state}: the person may now {:?} themselves, and the mail gives them no link (`{{chain}}`) to do it", labels));
}
}
}
}
if let Some(invite) = site.mail.as_ref().and_then(|m| m.invite.as_ref()) {
let keys: Vec<String> = placeholders(&invite.subject).into_iter().chain(placeholders(&invite.body)).collect();
for key in &keys {
if !INVITE_VARS.contains(&key.as_str()) {
fail(format!("site.yaml mail.invite: {{{key}}} is not something the invite mail knows ({}) - it would be sent blank", INVITE_VARS.join(", ")));
}
}
if !invite.body.contains("{link}") {
fail("site.yaml mail.invite: the body has no {link} - the person invited could never sign in".to_string());
}
}
findings.extend(warns.into_iter().map(|text| Finding { level: Level::Warn, text }));
findings
}
/// How many mails the site declares, invite included.
pub fn count(aggregates: &HashMap<String, AggregateSchema>, site: &SiteConfig) -> usize {
aggregates.values().map(|s| s.mail_for_state.len()).sum::<usize>()
+ usize::from(site.mail.as_ref().is_some_and(|m| m.invite.is_some()))
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn placeholders_are_read_the_way_portal_renders_them() {
assert_eq!(placeholders("Hi {name}, see {site}/decide/x?chain={chain}. {not a key} {}"), ["name", "site", "chain"]);
assert_eq!(site_links("Open {site}/decide/trial?chain={chain}. Or {site}."), ["/decide/trial", "/"]);
}
fn site(yaml: &str) -> SiteConfig {
serde_yaml::from_str(yaml).unwrap()
}
fn repo(aggregates: &str, pages: &[(&str, &str)]) -> (HashMap<String, Question>, HashMap<String, AggregateSchema>) {
let aggregates = portal::aggregates::parse_aggregates_yaml(aggregates).unwrap();
let questions = pages
.iter()
.map(|(id, yaml)| {
let mut q: Question = serde_yaml::from_str(yaml).unwrap();
q.id = id.to_string();
(id.to_string(), q)
})
.collect();
(questions, aggregates)
}
const AGG: &str = "aggregates:\n - bucket: trials\n initial: open\n states:\n open: { event: received, mail: { to: submitter, subject: \"Got it, {name}\", body: \"Withdraw at {site}/decide/trial?chain={chain}\" } }\n approved: { event: approved, mail: { to: submitter, subject: Yes, body: \"{business} is approved\" } }\n declined: { event: declined }\n withdrawn: { event: withdrawn }\n transitions:\n open: [approved, declined, withdrawn]\n";
const FORM: &str = "name: Q?\nalternatives:\n - name: Try it\n record_as: trials\n features:\n - name: f\n requirements:\n - { name: name }\n - { name: email, type: email }\n";
const DECIDE: &str = "name: Decide?\nalternatives:\n - name: Withdraw\n self_transition: { bucket: trials, to: withdrawn, label: Withdraw }\n";
#[test]
fn a_blank_placeholder_a_dead_link_and_a_silent_ending_are_found() {
let (q, a) = repo(AGG, &[("/", FORM), ("/decide/trial", DECIDE)]);
let f = check(&q, &a, &site("mail: { from: x@y.no }\n"));
let text = |lvl: Level| f.iter().filter(|x| x.level == lvl).map(|x| x.text.clone()).collect::<Vec<_>>();
let fails = text(Level::Fail);
assert_eq!(fails.len(), 1, "{fails:?}");
assert!(fails[0].contains("{business}"));
let warns = text(Level::Warn);
assert!(warns.iter().any(|w| w.contains("declined") && w.contains("withdrawn")), "{warns:?}");
let (q, a) = repo(AGG, &[("/", FORM)]);
let f = check(&q, &a, &site("mail: { from: x@y.no }\n"));
assert!(f.iter().any(|x| x.level == Level::Fail && x.text.contains("/decide/trial")));
}
#[test]
fn a_grant_needs_a_sender_and_an_invite_needs_its_link() {
let agg = "aggregates:\n - bucket: b\n initial: open\n states:\n open: { event: received }\n in: { event: in, grants: members }\n transitions:\n open: [in]\n";
let (q, a) = repo(agg, &[("/", "name: Q?\nalternatives:\n - name: A\n record_as: b\n features:\n - name: f\n requirements:\n - { name: name }\n - { name: email, type: email }\n")]);
assert!(check(&q, &a, &site("title: T\n")).iter().any(|x| x.level == Level::Fail && x.text.contains("sent to nobody")));
let f = check(&q, &a, &site("mail: { from: x@y.no, invite: { subject: \"Hi {name}\", body: \"Welcome to {site_name}, {nickname}\" } }\n"));
assert!(f.iter().any(|x| x.text.contains("{nickname}")));
assert!(f.iter().any(|x| x.text.contains("no {link}")));
}
#[test]
fn an_optional_answer_in_a_mail_is_found() {
let agg = AGG.replace("Got it, {name}", "Got it, {nick}");
let form = FORM.replace(" - { name: email, type: email }\n", " - { name: email, type: email }\n - { name: nick, optional: true }\n");
let (q, a) = repo(&agg, &[("/", &form), ("/decide/trial", DECIDE)]);
let f = check(&q, &a, &site("mail: { from: x@y.no }\n"));
assert!(f.iter().any(|x| x.level == Level::Warn && x.text.contains("{nick}") && x.text.contains("optional")), "{f:?}");
}
#[test]
fn a_long_answer_in_a_subject_line_is_found() {
let agg = AGG.replace("Got it, {name}", "About {brief}");
let form = FORM.replace(" - { name: email, type: email }\n", " - { name: email, type: email }\n - { name: brief, type: textarea }\n");
let (q, a) = repo(&agg, &[("/", &form), ("/decide/trial", DECIDE)]);
let f = check(&q, &a, &site("mail: { from: x@y.no }\n"));
assert!(f.iter().any(|x| x.level == Level::Warn && x.text.contains("{brief}") && x.text.contains("subject")), "{f:?}");
}
#[test]
fn a_mail_about_a_case_the_person_may_act_on_links_to_it() {
let agg = AGG.replace("Withdraw at {site}/decide/trial?chain={chain}", "We have it");
let (q, a) = repo(&agg, &[("/", FORM), ("/decide/trial", DECIDE)]);
let f = check(&q, &a, &site("mail: { from: x@y.no }\n"));
assert!(f.iter().any(|x| x.level == Level::Warn && x.text.contains("no link")), "{f:?}");
}
}
-1
View File
@@ -18,7 +18,6 @@
//! it matches, so the lint and the site never disagree about what a //! it matches, so the lint and the site never disagree about what a
//! page is. //! page is.
mod mail;
mod check; mod check;
mod local; mod local;
mod needs; mod needs;
+17 -1
View File
@@ -157,11 +157,14 @@ fn visible(q: &Question, as_group: Option<&str>) -> bool {
} }
} }
/// What a person has to fill in: required fields, less the ones that
/// carry rather than ask - a `record` naming the case an answer is
/// about, a `hidden` preset - which cost nobody anything.
fn required_fields(alt: &Alternative) -> usize { fn required_fields(alt: &Alternative) -> usize {
alt.features alt.features
.iter() .iter()
.flat_map(|f| &f.requirements) .flat_map(|f| &f.requirements)
.filter(|r| !r.optional) .filter(|r| !r.optional && r.kind != "record" && r.kind != "hidden")
.count() .count()
} }
@@ -860,6 +863,19 @@ mod tests {
let (questions, aggregates) = site(FULL_DESK); let (questions, aggregates) = site(FULL_DESK);
let findings = check(&needs(" max_fields: 1\n"), &questions, &aggregates); let findings = check(&needs(" max_fields: 1\n"), &questions, &aggregates);
assert_eq!(fails(&findings), vec!["the path asks for 2 required field(s), over the budget of 1"]); assert_eq!(fails(&findings), vec!["the path asks for 2 required field(s), over the budget of 1"]);
// A field that carries rather than asks is not effort: the
// record an answer is about arrives on the link.
let (mut questions, aggregates) = site(FULL_DESK);
let front = questions.get_mut("/").unwrap();
let brief = &mut front.alternatives[0].features[0].requirements;
let mut carrier = brief[0].clone();
carrier.name = "case".into();
carrier.kind = "record".into();
carrier.of = Some("projects".into());
carrier.optional = false;
brief.push(carrier);
let findings = check(&needs(" max_fields: 2\n"), &questions, &aggregates);
assert!(fails(&findings).is_empty(), "{findings:?}");
} }
#[test] #[test]