20 Commits
Author SHA1 Message Date
Bendik Aagaard LynghaugandClaude Opus 5.5 07dd6c0f40 check: warn on a mail placeholder every form marks optional
Test / test (pull_request) Successful in 1m16s
Found the same way: 'your brief for {organization}, {org_contact}' with
the contact optional reads ', .' for most people.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 18:30:57 +02:00
Bendik Aagaard LynghaugandClaude Opus 5.5 de622e4164 check: warn on a long answer (textarea) in a mail's subject line
Test / test (pull_request) Successful in 2m6s
Found by the trainer's first mail rewording: 'We'll take on {project}'
puts the whole brief in the inbox list.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 18:27:17 +02:00
Bendik Aagaard LynghaugandClaude Opus 5.5 8bee3ed4ec check: what the site mails, before anyone receives it
Test / test (pull_request) Successful in 1m42s
A mail is read alone, by a person who cannot ask what a blank means,
and portal renders an unknown {key} as nothing and sends a dead link as
readily as a live one. iris check now fails on a placeholder no form in
the bucket collects and portal does not fill, on a {site}/path link to
a page the site does not have, on a state that grants a group on a site
with no mail sender (the sign-in link would reach nobody), and on an
invite mail without {link} or with a key the invite cannot fill. It
warns on a placeholder only some forms collect, on a dialogue that does
not close (mailed on the way in, not told how it ended), and on a mail
that tells a person they may now act on their case without their link.

No FAIL on any live content repo (uhhm, redoal, westra, klingenbergbygg,
tomtervel); tomtervel gets two warnings, both real.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 18:18:38 +02:00
portal release f2ca00b309 Match portal v0.5.2
Test / test (push) Successful in 1m17s
Publish release / publish (push) Successful in 26s
2026-09-28 18:11:49 +02:00
portal release ac4af4395a Match portal v0.5.1
Test / test (push) Successful in 1m0s
Publish release / publish (push) Successful in 26s
2026-09-28 17:51:11 +02:00
portal release 1e7245b062 Match portal v0.5.0
Test / test (push) Failing after 34s
Publish release / publish (push) Successful in 28s
2026-09-28 16:50:47 +02:00
portal release a847d0defa Match portal v0.4.0
Test / test (push) Successful in 29s
Publish release / publish (push) Successful in 25s
2026-09-24 21:37:28 +02:00
portal release 57b733e606 Match portal v0.3.47
Test / test (push) Successful in 29s
Publish release / publish (push) Successful in 24s
2026-09-24 05:20:11 +02:00
Bendik Aagaard LynghaugandClaude Fable 5.1 3923d4d0dc needs: stage_words, each state in the site's own words, carried into the simulation model
Test / test (push) Successful in 29s
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-24 05:17:11 +02:00
Bendik Aagaard LynghaugandClaude Fable 5.1 00db014eae A card with no button is read, never picked
Test / test (push) Successful in 1m6s
The opener that says what the business does and the look-around card
lead nowhere: they are what the page says before its options, so a
task and a simulation step carry them as `page` context and offer
only the cards that lead somewhere. Five personas per round had been
"choosing" the opener and counted as misroutes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-23 22:36:20 +02:00
portal release d2450fcb75 Match portal v0.3.46
Test / test (push) Successful in 30s
Publish release / publish (push) Successful in 36s
2026-09-23 22:21:14 +02:00
portal release 0841ed561a Match portal v0.3.45
Test / test (push) Successful in 33s
Publish release / publish (push) Successful in 28s
2026-09-23 21:26:51 +02:00
portal release 79f85132c5 Match portal v0.3.44
Test / test (push) Successful in 30s
Publish release / publish (push) Successful in 26s
2026-09-23 21:18:10 +02:00
portal release 58d68c3bff Match portal v0.3.43
Test / test (push) Successful in 29s
Publish release / publish (push) Successful in 25s
2026-09-23 19:48:01 +02:00
portal release 0cf70502fc Match portal v0.3.42
Publish release / publish (push) Successful in 25s
Test / test (push) Successful in 29s
2026-09-23 14:35:49 +02:00
portal release fb66694b85 Match portal v0.3.41
Publish release / publish (push) Successful in 25s
Test / test (push) Successful in 1m6s
2026-09-23 11:55:10 +02:00
Bendik Aagaard LynghaugandClaude Fable 5.1 959e5f6ef0 check: compile and validate the access policy; --access prints the matrix
Test / test (push) Successful in 29s
Every check now compiles the content into portal's Cedar policy and
fails when it does not validate against the schema - a rule the
schema cannot express would grant nothing at runtime. `--access`
prints the matrix: action, resource, who, and the state move where it
applies. Pinned to portal v0.3.40, where the policy lives.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L4jrCgLiKKHAEFuZUJjckH
2026-09-23 11:48:33 +02:00
portal release 9cd5dff4c2 Match portal v0.3.39
Test / test (push) Successful in 24s
Publish release / publish (push) Successful in 20s
2026-09-23 06:03:18 +02:00
Bendik Aagaard LynghaugandClaude Fable 5.1 bd8a5e0c6c Versioned as portal: released by portal's publish job
Test / test (push) Successful in 1m0s
iris reports its own version as the portal it matches; the tag, the
pin and the changelog line are written by portal's release step.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L4jrCgLiKKHAEFuZUJjckH
2026-09-22 22:05:06 +02:00
Bendik Aagaard LynghaugandClaude Fable 5.1 e543b41cb0 CI: a writable CARGO_HOME, so the portal git dependency can be fetched
Test / test (push) Successful in 4m53s
The shared /var/local/cargo is read-only for the runner; 0.1.1 built
only because this machine had already cloned the same portal tag into
it.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01L4jrCgLiKKHAEFuZUJjckH
2026-09-22 17:50:53 +02:00
10 changed files with 1176 additions and 25 deletions
+3 -1
View File
@@ -12,7 +12,9 @@ jobs:
publish: publish:
runs-on: bare runs-on: bare
env: env:
CARGO_HOME: /var/local/cargo # Writable, unlike the shared /var/local/cargo - see test.yml.
CARGO_HOME: /var/local/cargo-target/iris-cargo-home
RUSTC_WRAPPER: /usr/bin/sccache
RUSTUP_HOME: /var/local/rustup RUSTUP_HOME: /var/local/rustup
PATH: /var/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/bin PATH: /var/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/bin
SCCACHE_DIR: /var/local/sccache SCCACHE_DIR: /var/local/sccache
+6 -1
View File
@@ -10,7 +10,12 @@ jobs:
runs-on: bare runs-on: bare
env: env:
# Same shared toolchain and cache as uhhm/portal's workflows. # Same shared toolchain and cache as uhhm/portal's workflows.
CARGO_HOME: /var/local/cargo # Not the shared /var/local/cargo: the runner may only read it, and
# the portal git dependency has to be cloned into CARGO_HOME. This
# one lives under the writable target dir; the rustc wrapper the
# shared config would have set is given here instead.
CARGO_HOME: /var/local/cargo-target/iris-cargo-home
RUSTC_WRAPPER: /usr/bin/sccache
RUSTUP_HOME: /var/local/rustup RUSTUP_HOME: /var/local/rustup
PATH: /var/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/bin PATH: /var/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/bin
SCCACHE_DIR: /var/local/sccache SCCACHE_DIR: /var/local/sccache
+48
View File
@@ -3,6 +3,54 @@
One line per change, grouped by the release that shipped it. Newest One line per change, grouped by the release that shipped it. Newest
first. Each release names the portal tag it is built against. first. Each release names the portal tag it is built against.
## 0.5.2 (2026-09-28) - portal v0.5.2
- Matches portal v0.5.2 (released by portal's publish job).
## 0.5.1 (2026-09-28) - portal v0.5.1
- Matches portal v0.5.1 (released by portal's publish job).
## 0.5.0 (2026-09-28) - portal v0.5.0
- Matches portal v0.5.0 (released by portal's publish job).
## 0.4.0 (2026-09-24) - portal v0.4.0
- Matches portal v0.4.0 (released by portal's publish job).
## 0.3.47 (2026-09-24) - portal v0.3.47
- Matches portal v0.3.47 (released by portal's publish job).
## 0.3.46 (2026-09-23) - portal v0.3.46
- Matches portal v0.3.46 (released by portal's publish job).
## 0.3.45 (2026-09-23) - portal v0.3.45
- Matches portal v0.3.45 (released by portal's publish job).
## 0.3.44 (2026-09-23) - portal v0.3.44
- Matches portal v0.3.44 (released by portal's publish job).
## 0.3.43 (2026-09-23) - portal v0.3.43
- Matches portal v0.3.43 (released by portal's publish job).
## 0.3.42 (2026-09-23) - portal v0.3.42
- Matches portal v0.3.42 (released by portal's publish job).
## 0.3.41 (2026-09-23) - portal v0.3.41
- Matches portal v0.3.41 (released by portal's publish job).
## 0.3.39 (2026-09-23) - portal v0.3.39
- Matches portal v0.3.39 (released by portal's publish job).
## 0.1.1 (2026-09-22) - portal v0.3.36 ## 0.1.1 (2026-09-22) - portal v0.3.36
- `check --repo` fetches needs.yaml itself; the v0.1.0 tag never published (a cache permission on the runner, since fixed). - `check --repo` fetches needs.yaml itself; the v0.1.0 tag never published (a cache permission on the runner, since fixed).
Generated
+687 -3
View File
File diff suppressed because it is too large Load Diff
+2 -2
View File
@@ -1,6 +1,6 @@
[package] [package]
name = "iris" name = "iris"
version = "0.1.1" version = "0.5.2"
edition = "2021" edition = "2021"
description = "The iris over a portal site: nothing from a content repo comes through until it checks out" description = "The iris over a portal site: nothing from a content repo comes through until it checks out"
license = "MIT" license = "MIT"
@@ -10,7 +10,7 @@ repository = "https://project.uhhm.no/uhhm/iris"
# The site's own content types and loaders, so iris reads a repo exactly # The site's own content types and loaders, so iris reads a repo exactly
# the way the running site does. Pinned to the portal release it # the way the running site does. Pinned to the portal release it
# matches; bumping this tag is what a new iris release is. # matches; bumping this tag is what a new iris release is.
portal = { git = "https://project.uhhm.no/uhhm/portal.git", tag = "v0.3.36", features = ["ssr"] } portal = { git = "https://project.uhhm.no/uhhm/portal.git", tag = "v0.5.2", features = ["ssr"] }
anyhow = "1" anyhow = "1"
serde = { version = "1", features = ["derive"] } serde = { version = "1", features = ["derive"] }
serde_json = "1" serde_json = "1"
+13 -9
View File
@@ -39,15 +39,19 @@ what sits around those.
## Matching the site ## Matching the site
Every type iris reads is portal's own: portal is a library dependency Every type iris reads is portal's own: portal is a library dependency
pinned to a release tag in `Cargo.toml`, and `iris --version` says pinned to a release tag in `Cargo.toml`, and iris carries the same
which. A content repo should run the iris that matches the portal version number as that tag, so `iris v0.3.39` is the lint for portal
release its site runs. Portal's own release tarball ships an `iris` v0.3.39 and nothing else. A content repo pins `IRIS_RELEASE` to the
binary built the same way, so a site that pins nothing extra has one `PORTAL_RELEASE` its site runs. Portal's own release tarball ships the
at `/srv/app/<instance>/current/iris`. matching `iris` binary too, at `/srv/app/<instance>/current/iris`.
## Release ## Release
Move the `Unreleased` lines in `CHANGELOG.md` under a heading for the Iris is released by portal's publish job, never by hand: when a
version, bump `Cargo.toml`, commit, tag `v<version>`, push. CI builds portal tag is pushed, that job re-pins this crate to the tag, sets
the binary and attaches it to the Gitea release as `iris`, with that the version to match, builds and tests it, adds the changelog line,
section as the notes. and pushes the commit and the tag here. This repo's own CI then
attaches the binary to the Gitea release as `iris`. A portal change
to something the lint reads fails the portal release at that step.
Changes to iris itself land on `main` between releases and ship with
the next portal tag.
+36 -1
View File
@@ -23,6 +23,7 @@ pub async fn run(argv: Vec<String>) -> anyhow::Result<()> {
let mut min_accuracy: f64 = 0.0; let mut min_accuracy: f64 = 0.0;
let mut skim = false; let mut skim = false;
let mut sim_out: Option<String> = None; let mut sim_out: Option<String> = None;
let mut show_access = false;
while let Some(arg) = args.next() { while let Some(arg) = args.next() {
match arg.as_str() { match arg.as_str() {
@@ -33,6 +34,7 @@ pub async fn run(argv: Vec<String>) -> anyhow::Result<()> {
"--needs-tasks" => tasks_out = args.next(), "--needs-tasks" => tasks_out = args.next(),
"--skim" => skim = true, "--skim" => skim = true,
"--needs-sim" => sim_out = args.next(), "--needs-sim" => sim_out = args.next(),
"--access" => show_access = true,
"--needs-score" => answers_in = args.next(), "--needs-score" => answers_in = args.next(),
"--min-accuracy" => { "--min-accuracy" => {
min_accuracy = args.next().and_then(|v| v.parse().ok()).unwrap_or(min_accuracy) min_accuracy = args.next().and_then(|v| v.parse().ok()).unwrap_or(min_accuracy)
@@ -62,7 +64,7 @@ pub async fn run(argv: Vec<String>) -> anyhow::Result<()> {
(questions, aggregates_map, site, needs_raw) (questions, aggregates_map, site, needs_raw)
} else { } else {
eprintln!( eprintln!(
"usage: iris check (--repo <gitea-url> [--branch main] [--subdir questions] | --path <local-dir>) [--needs-tasks <out.jsonl> [--skim]] [--needs-sim <model.json>] [--needs-score <answers.jsonl> [--min-accuracy 0.8]]" "usage: iris check (--repo <gitea-url> [--branch main] [--subdir questions] | --path <local-dir>) [--needs-tasks <out.jsonl> [--skim]] [--needs-sim <model.json>] [--access] [--needs-score <answers.jsonl> [--min-accuracy 0.8]]"
); );
std::process::exit(2); std::process::exit(2);
}; };
@@ -91,6 +93,39 @@ pub async fn run(argv: Vec<String>) -> anyhow::Result<()> {
questions.len(), questions.len(),
aggregates_map.len() aggregates_map.len()
); );
// The access policy the site will compile from this content.
// It must type-check against portal's schema: a rule the
// schema cannot express would grant nothing at runtime.
let policy = portal::access::Policy::from_content(&questions, &aggregates_map);
if let Err(e) = policy.validate() {
eprintln!("FAIL: access policy does not validate: {e}");
std::process::exit(1);
}
println!("OK: access policy, {} rule(s), validates", policy.rules.len());
// What the site mails, checked before anyone receives it:
// placeholders that would go out blank, links to pages
// that are not there, grants and invites nobody hears of.
let findings = crate::mail::check(&questions, &aggregates_map, &site);
for f in &findings {
let tag = if f.level == needs::Level::Fail { "FAIL" } else { "WARN" };
eprintln!("{tag}: {}", f.text);
}
if findings.iter().any(|f| f.level == needs::Level::Fail) {
std::process::exit(1);
}
let mails = crate::mail::count(&aggregates_map, &site);
if mails > 0 {
println!("OK: {mails} mail(s): every placeholder fills, every link lands");
}
if show_access {
println!("\n{:<16} {:<44} {:<40} {}", "ACTION", "RESOURCE", "WHO", "WHEN");
let mut rows = policy.rules.clone();
rows.sort_by(|a, b| (&a.resource, &a.action, &a.who).cmp(&(&b.resource, &b.action, &b.who)));
for r in rows {
println!("{:<16} {:<44} {:<40} {}", r.action, r.resource, r.who, r.when);
}
println!();
}
check_needs( check_needs(
needs_raw.as_deref(), needs_raw.as_deref(),
&questions, &questions,
+327
View File
@@ -0,0 +1,327 @@
//! What the site's mail promises, checked before it is sent to anyone.
//!
//! A mail is read alone, away from the page that caused it, by a
//! person who cannot ask what a blank means. Portal renders a `{key}`
//! it has no value for as nothing, silently, and sends a link to a
//! page that is not there as readily as one that is. So the things a
//! mail can get wrong without any runtime error are checked here:
//!
//! - **fail** a placeholder no record in the bucket can fill: the mail
//! goes out with a hole in it;
//! - **fail** a link to a page the site does not have;
//! - **fail** a state that grants a group on a site that sends no mail:
//! the account is made and its sign-in link reaches nobody;
//! - **fail** an invite mail without its `{link}`, or with a
//! placeholder the invite cannot fill;
//! - **warn** a placeholder only some of the bucket's forms collect, or
//! one every form marks optional: it is blank in the mails about the
//! others, or about anyone who skipped it;
//! - **warn** a dialogue that does not close: the person is mailed on
//! the way in and not told how their case ended;
//! - **warn** a mail that tells a person their case is where they may
//! now act on it, and gives them no link to do so;
//! - **warn** a long answer (a `textarea` field) put in a subject line,
//! which becomes the whole brief in someone's inbox list.
use std::collections::{BTreeMap, BTreeSet, HashMap};
use portal::aggregates::AggregateSchema;
use portal::content::{self, Question, SiteConfig};
use crate::needs::Level;
/// What portal fills in a case mail besides the record's own answers
/// (`mail.rs`, `vars_for`).
const CASE_VARS: &[&str] = &["email", "site", "chain", "bucket", "state"];
/// What portal fills in the invite mail (`mail.rs`, `on_invite`).
const INVITE_VARS: &[&str] = &["name", "username", "email", "group", "link", "site", "site_name", "expires"];
#[derive(Debug)]
pub struct Finding {
pub level: Level,
pub text: String,
}
/// `{key}` exactly as portal's renderer reads one: ASCII alphanumerics,
/// `_`, `-` and `.`, closed by `}`. A brace that opens no key is text.
pub fn placeholders(template: &str) -> Vec<String> {
let mut keys = Vec::new();
let mut rest = template;
while let Some(start) = rest.find('{') {
let after = &rest[start + 1..];
let len = after
.char_indices()
.take_while(|(_, c)| c.is_ascii_alphanumeric() || matches!(c, '_' | '-' | '.'))
.last()
.map(|(i, c)| i + c.len_utf8())
.unwrap_or(0);
if len > 0 && after[len..].starts_with('}') {
keys.push(after[..len].to_string());
rest = &after[len + 1..];
} else {
rest = after;
}
}
keys
}
/// The paths a template links to on its own site: `{site}/x/y?...`.
fn site_links(template: &str) -> Vec<String> {
template
.match_indices("{site}")
.map(|(i, _)| {
let tail = &template[i + "{site}".len()..];
let end = tail.find(|c: char| c.is_whitespace() || matches!(c, '?' | '#' | ')' | '>' | '"' | '\'')).unwrap_or(tail.len());
let path = tail[..end].trim_end_matches(['.', ',', ';', ':']);
if path.is_empty() { "/".to_string() } else { path.to_string() }
})
.collect()
}
fn page_exists(questions: &HashMap<String, Question>, path: &str) -> bool {
let path = path.trim_end_matches('/');
let path = if path.is_empty() { "/" } else { path };
questions.contains_key(path)
|| questions.values().any(|q| q.is_dynamic() && content::path_matches(&q.id, path).is_some())
}
/// For each bucket, the field names of every alternative that records
/// into it: one set per form.
fn forms_by_bucket(questions: &HashMap<String, Question>) -> BTreeMap<String, Vec<(String, BTreeSet<String>)>> {
let mut out: BTreeMap<String, Vec<(String, BTreeSet<String>)>> = BTreeMap::new();
for q in questions.values() {
for alt in &q.alternatives {
if let Some(bucket) = &alt.record_as {
let fields = alt.features.iter().flat_map(|f| &f.requirements).map(|r| r.name.clone()).collect();
out.entry(bucket.clone()).or_default().push((format!("{} / {}", q.id, alt.name), fields));
}
}
}
out
}
/// States with no move out of them: where a case ends.
fn endings(schema: &AggregateSchema) -> BTreeSet<String> {
let mut states: BTreeSet<String> = schema.event_for_state.keys().cloned().collect();
states.insert(schema.initial.clone());
states.into_iter().filter(|s| schema.allowed(s).is_empty()).collect()
}
/// States reachable from `from` along declared moves, `from` included.
fn reachable(schema: &AggregateSchema, from: &str) -> BTreeSet<String> {
let mut seen = BTreeSet::from([from.to_string()]);
let mut todo = vec![from.to_string()];
while let Some(s) = todo.pop() {
for next in schema.allowed(&s) {
if seen.insert(next.clone()) {
todo.push(next.clone());
}
}
}
seen
}
pub fn check(questions: &HashMap<String, Question>, aggregates: &HashMap<String, AggregateSchema>, site: &SiteConfig) -> Vec<Finding> {
let mut findings = Vec::new();
let mut fail = |text: String| findings.push(Finding { level: Level::Fail, text });
let forms = forms_by_bucket(questions);
let mut warns = Vec::new();
// Where the submitter may act on their own record: bucket -> state
// -> the labels of the moves they may make from there.
let mut own_moves: BTreeMap<String, BTreeMap<String, Vec<String>>> = BTreeMap::new();
for q in questions.values() {
for alt in &q.alternatives {
if let Some(st) = &alt.self_transition {
if let Some(schema) = aggregates.get(&st.bucket) {
for from in st.from_states(&schema.initial) {
own_moves.entry(st.bucket.clone()).or_default().entry(from).or_default().push(st.label.clone());
}
}
}
}
}
let mut buckets: Vec<&AggregateSchema> = aggregates.values().collect();
buckets.sort_by(|a, b| a.bucket.cmp(&b.bucket));
for schema in buckets {
let bucket = &schema.bucket;
let bucket_forms = forms.get(bucket).cloned().unwrap_or_default();
let mut states: Vec<(&String, &portal::aggregates::MailSpec)> = schema.mail_for_state.iter().collect();
states.sort_by(|a, b| a.0.cmp(b.0));
for (state, mail) in &states {
let at = format!("mail on {bucket}:{state}");
for key in placeholders(&mail.subject).into_iter().chain(placeholders(&mail.body)) {
if CASE_VARS.contains(&key.as_str()) {
continue;
}
let having: Vec<&String> = bucket_forms.iter().filter(|(_, f)| f.contains(&key)).map(|(n, _)| n).collect();
if having.is_empty() {
fail(format!("{at}: {{{key}}} is not a field any form recording into {bucket:?} collects, nor one portal fills ({}) - it would be sent blank", CASE_VARS.join(", ")));
} else if questions
.values()
.flat_map(|q| &q.alternatives)
.filter(|a| a.record_as.as_deref() == Some(bucket.as_str()))
.flat_map(|a| a.features.iter().flat_map(|f| &f.requirements))
.filter(|r| r.name == key)
.all(|r| r.optional)
{
warns.push(format!("{at}: {{{key}}} is optional on every form - blank for anyone who skipped it"));
} else if having.len() < bucket_forms.len() {
let missing: Vec<&String> = bucket_forms.iter().filter(|(_, f)| !f.contains(&key)).map(|(n, _)| n).collect();
warns.push(format!("{at}: {{{key}}} is blank for records sent from {}", missing.iter().map(|n| format!("{n:?}")).collect::<Vec<_>>().join(", ")));
}
}
for key in placeholders(&mail.subject) {
let long = questions.values().flat_map(|q| &q.alternatives).filter(|a| a.record_as.as_deref() == Some(bucket.as_str())).flat_map(|a| a.features.iter().flat_map(|f| &f.requirements)).any(|r| r.name == key && r.kind == "textarea");
if long {
warns.push(format!("{at}: the subject carries {{{key}}}, a long answer (textarea) - the whole of it lands in the subject line"));
}
}
for path in site_links(&mail.body).into_iter().chain(site_links(&mail.subject)) {
if path.contains('{') {
continue; // filled per record; the page is checked where the pattern is declared
}
if !page_exists(questions, &path) {
fail(format!("{at}: links to {path:?}, which is not a page on this site"));
}
}
}
if !schema.grants_for_state.is_empty() && site.mail.is_none() {
let mut granting: Vec<&String> = schema.grants_for_state.keys().collect();
granting.sort();
fail(format!("{bucket}: state(s) {granting:?} grant a group, and site.yaml has no `mail: {{ from }}` - the account would be made and its sign-in link sent to nobody"));
}
// The dialogue closes: a person mailed on the way in hears how
// it ended, from every ending their case can still reach.
let to_submitter: BTreeSet<&String> = states.iter().filter(|(_, m)| m.to_submitter()).map(|(s, _)| *s).collect();
if let Some(first) = to_submitter.iter().min_by_key(|s| (s.as_str() != schema.initial, s.to_string())) {
let reach = reachable(schema, first);
let silent: Vec<String> = endings(schema).into_iter().filter(|e| reach.contains(e) && !to_submitter.contains(e)).collect();
if !silent.is_empty() {
warns.push(format!("{bucket}: the person is mailed at {first:?} and not told when their case ends at {silent:?}"));
}
}
// A mail telling a person their case is where they may act on
// it carries the link that lets them.
for (state, mail) in &states {
if !mail.to_submitter() {
continue;
}
if let Some(labels) = own_moves.get(bucket).and_then(|m| m.get(*state)) {
if !mail.body.contains("{chain}") {
warns.push(format!("mail on {bucket}:{state}: the person may now {:?} themselves, and the mail gives them no link (`{{chain}}`) to do it", labels));
}
}
}
}
if let Some(invite) = site.mail.as_ref().and_then(|m| m.invite.as_ref()) {
let keys: Vec<String> = placeholders(&invite.subject).into_iter().chain(placeholders(&invite.body)).collect();
for key in &keys {
if !INVITE_VARS.contains(&key.as_str()) {
fail(format!("site.yaml mail.invite: {{{key}}} is not something the invite mail knows ({}) - it would be sent blank", INVITE_VARS.join(", ")));
}
}
if !invite.body.contains("{link}") {
fail("site.yaml mail.invite: the body has no {link} - the person invited could never sign in".to_string());
}
}
findings.extend(warns.into_iter().map(|text| Finding { level: Level::Warn, text }));
findings
}
/// How many mails the site declares, invite included.
pub fn count(aggregates: &HashMap<String, AggregateSchema>, site: &SiteConfig) -> usize {
aggregates.values().map(|s| s.mail_for_state.len()).sum::<usize>()
+ usize::from(site.mail.as_ref().is_some_and(|m| m.invite.is_some()))
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn placeholders_are_read_the_way_portal_renders_them() {
assert_eq!(placeholders("Hi {name}, see {site}/decide/x?chain={chain}. {not a key} {}"), ["name", "site", "chain"]);
assert_eq!(site_links("Open {site}/decide/trial?chain={chain}. Or {site}."), ["/decide/trial", "/"]);
}
fn site(yaml: &str) -> SiteConfig {
serde_yaml::from_str(yaml).unwrap()
}
fn repo(aggregates: &str, pages: &[(&str, &str)]) -> (HashMap<String, Question>, HashMap<String, AggregateSchema>) {
let aggregates = portal::aggregates::parse_aggregates_yaml(aggregates).unwrap();
let questions = pages
.iter()
.map(|(id, yaml)| {
let mut q: Question = serde_yaml::from_str(yaml).unwrap();
q.id = id.to_string();
(id.to_string(), q)
})
.collect();
(questions, aggregates)
}
const AGG: &str = "aggregates:\n - bucket: trials\n initial: open\n states:\n open: { event: received, mail: { to: submitter, subject: \"Got it, {name}\", body: \"Withdraw at {site}/decide/trial?chain={chain}\" } }\n approved: { event: approved, mail: { to: submitter, subject: Yes, body: \"{business} is approved\" } }\n declined: { event: declined }\n withdrawn: { event: withdrawn }\n transitions:\n open: [approved, declined, withdrawn]\n";
const FORM: &str = "name: Q?\nalternatives:\n - name: Try it\n record_as: trials\n features:\n - name: f\n requirements:\n - { name: name }\n - { name: email, type: email }\n";
const DECIDE: &str = "name: Decide?\nalternatives:\n - name: Withdraw\n self_transition: { bucket: trials, to: withdrawn, label: Withdraw }\n";
#[test]
fn a_blank_placeholder_a_dead_link_and_a_silent_ending_are_found() {
let (q, a) = repo(AGG, &[("/", FORM), ("/decide/trial", DECIDE)]);
let f = check(&q, &a, &site("mail: { from: x@y.no }\n"));
let text = |lvl: Level| f.iter().filter(|x| x.level == lvl).map(|x| x.text.clone()).collect::<Vec<_>>();
let fails = text(Level::Fail);
assert_eq!(fails.len(), 1, "{fails:?}");
assert!(fails[0].contains("{business}"));
let warns = text(Level::Warn);
assert!(warns.iter().any(|w| w.contains("declined") && w.contains("withdrawn")), "{warns:?}");
let (q, a) = repo(AGG, &[("/", FORM)]);
let f = check(&q, &a, &site("mail: { from: x@y.no }\n"));
assert!(f.iter().any(|x| x.level == Level::Fail && x.text.contains("/decide/trial")));
}
#[test]
fn a_grant_needs_a_sender_and_an_invite_needs_its_link() {
let agg = "aggregates:\n - bucket: b\n initial: open\n states:\n open: { event: received }\n in: { event: in, grants: members }\n transitions:\n open: [in]\n";
let (q, a) = repo(agg, &[("/", "name: Q?\nalternatives:\n - name: A\n record_as: b\n features:\n - name: f\n requirements:\n - { name: name }\n - { name: email, type: email }\n")]);
assert!(check(&q, &a, &site("title: T\n")).iter().any(|x| x.level == Level::Fail && x.text.contains("sent to nobody")));
let f = check(&q, &a, &site("mail: { from: x@y.no, invite: { subject: \"Hi {name}\", body: \"Welcome to {site_name}, {nickname}\" } }\n"));
assert!(f.iter().any(|x| x.text.contains("{nickname}")));
assert!(f.iter().any(|x| x.text.contains("no {link}")));
}
#[test]
fn an_optional_answer_in_a_mail_is_found() {
let agg = AGG.replace("Got it, {name}", "Got it, {nick}");
let form = FORM.replace(" - { name: email, type: email }\n", " - { name: email, type: email }\n - { name: nick, optional: true }\n");
let (q, a) = repo(&agg, &[("/", &form), ("/decide/trial", DECIDE)]);
let f = check(&q, &a, &site("mail: { from: x@y.no }\n"));
assert!(f.iter().any(|x| x.level == Level::Warn && x.text.contains("{nick}") && x.text.contains("optional")), "{f:?}");
}
#[test]
fn a_long_answer_in_a_subject_line_is_found() {
let agg = AGG.replace("Got it, {name}", "About {brief}");
let form = FORM.replace(" - { name: email, type: email }\n", " - { name: email, type: email }\n - { name: brief, type: textarea }\n");
let (q, a) = repo(&agg, &[("/", &form), ("/decide/trial", DECIDE)]);
let f = check(&q, &a, &site("mail: { from: x@y.no }\n"));
assert!(f.iter().any(|x| x.level == Level::Warn && x.text.contains("{brief}") && x.text.contains("subject")), "{f:?}");
}
#[test]
fn a_mail_about_a_case_the_person_may_act_on_links_to_it() {
let agg = AGG.replace("Withdraw at {site}/decide/trial?chain={chain}", "We have it");
let (q, a) = repo(&agg, &[("/", FORM), ("/decide/trial", DECIDE)]);
let f = check(&q, &a, &site("mail: { from: x@y.no }\n"));
assert!(f.iter().any(|x| x.level == Level::Warn && x.text.contains("no link")), "{f:?}");
}
}
+4 -5
View File
@@ -18,6 +18,7 @@
//! it matches, so the lint and the site never disagree about what a //! it matches, so the lint and the site never disagree about what a
//! page is. //! page is.
mod mail;
mod check; mod check;
mod local; mod local;
mod needs; mod needs;
@@ -38,19 +39,17 @@ async fn main() -> anyhow::Result<()> {
replay::run(argv).await replay::run(argv).await
} }
Some("--version") | Some("-V") => { Some("--version") | Some("-V") => {
println!("iris {} (portal {})", env!("CARGO_PKG_VERSION"), PORTAL_TAG); println!("iris {v} (portal v{v})", v = env!("CARGO_PKG_VERSION"));
Ok(()) Ok(())
} }
Some(flag) if flag.starts_with("--") => check::run(argv).await, Some(flag) if flag.starts_with("--") => check::run(argv).await,
_ => { _ => {
eprintln!( eprintln!(
"iris {} - matches portal {PORTAL_TAG}\n\nusage:\n iris check (--repo <gitea-url> [--branch main] [--subdir questions] | --path <dir>) [--needs-tasks <out.jsonl> [--skim]] [--needs-sim <model.json>] [--needs-score <answers.jsonl> [--min-accuracy 0.8]]\n iris replay --path <dir> --nats <url> (--cases <cases.jsonl> | --report-only)", "iris {v} - matches portal v{v}\n\nusage:\n iris check (--repo <gitea-url> [--branch main] [--subdir questions] | --path <dir>) [--needs-tasks <out.jsonl> [--skim]] [--needs-sim <model.json>] [--access] [--needs-score <answers.jsonl> [--min-accuracy 0.8]]\n iris replay --path <dir> --nats <url> (--cases <cases.jsonl> | --report-only)",
env!("CARGO_PKG_VERSION") v = env!("CARGO_PKG_VERSION")
); );
std::process::exit(2) std::process::exit(2)
} }
} }
} }
/// The portal release this iris was built against (see Cargo.toml).
const PORTAL_TAG: &str = "v0.3.36";
+50 -3
View File
@@ -73,6 +73,11 @@ pub struct Need {
/// as a warning, so the gap stays visible without failing CI. /// as a warning, so the gap stays visible without failing CI.
#[serde(default)] #[serde(default)]
pub planned: bool, pub planned: bool,
/// Each state of the bucket in plain words, in the site's
/// language, for the scorer: state ids are ASCII, and a Norwegian
/// `ikke_lost` reads as English to a model.
#[serde(default)]
pub stage_words: std::collections::BTreeMap<String, String>,
/// The finished states that are a good outcome for the business - /// The finished states that are a good outcome for the business -
/// a subset of `done_when`. "lost" is finished; "won" is success. /// a subset of `done_when`. "lost" is finished; "won" is success.
/// What a simulation or a live bucket report counts toward. /// What a simulation or a live bucket report counts toward.
@@ -571,7 +576,8 @@ pub fn sim_model(
json!({ json!({
"page": step.page, "page": step.page,
"question": page.name, "question": page.name,
"options": page.alternatives.iter().filter(|a| !a.disabled).map(|a| json!({ "context": page_context(page),
"options": page.alternatives.iter().filter(|a| !a.disabled && leads_somewhere(a)).map(|a| json!({
"name": a.name, "name": a.name,
"description": plain(&a.description), "description": plain(&a.description),
})).collect::<Vec<_>>(), })).collect::<Vec<_>>(),
@@ -597,6 +603,7 @@ pub fn sim_model(
json!({ json!({
"initial": schema.initial, "initial": schema.initial,
"transitions": schema.transitions, "transitions": schema.transitions,
"words": need.stage_words,
"desks": desks_over(questions, &need.lands_in).iter().map(|d| json!({ "desks": desks_over(questions, &need.lands_in).iter().map(|d| json!({
"page": d.page, "page": d.page,
"group": d.group, "group": d.group,
@@ -646,6 +653,41 @@ fn plain(text: &str) -> String {
text.split_whitespace().collect::<Vec<_>>().join(" ") text.split_whitespace().collect::<Vec<_>>().join(" ")
} }
/// A card a visitor can act on: it leads to a page, records an
/// answer, or moves a record. A card with none of those is read, not
/// picked - the opener that says what the business does, the look
/// around - and is context on the page, never an option.
pub fn leads_somewhere(a: &Alternative) -> bool {
a.action.is_some() || a.record_as.is_some() || a.self_transition.is_some()
}
/// What the page says before its options: every card that leads
/// nowhere, its heading, description and features, as one line each.
pub fn page_context(page: &Question) -> String {
page.alternatives
.iter()
.filter(|a| !a.disabled && !leads_somewhere(a))
.map(|a| {
let mut line = a.name.clone();
let description = plain(&a.description);
if !description.is_empty() {
line.push_str(&format!(": {description}"));
}
for f in &a.features {
let text = plain(&f.description);
match (f.name.trim().is_empty(), text.is_empty()) {
(true, true) => {}
(true, false) => line.push_str(&format!(" {text}")),
(false, true) => line.push_str(&format!(" {}.", f.name.trim())),
(false, false) => line.push_str(&format!(" {}: {text}", f.name.trim())),
}
}
line
})
.collect::<Vec<_>>()
.join("\n")
}
/// Every (persona, page-on-their-path) pair with a real choice on it. /// Every (persona, page-on-their-path) pair with a real choice on it.
/// `skim` shows the engine only each alternative's heading - what a /// `skim` shows the engine only each alternative's heading - what a
/// visitor who never reads the description has to go on. /// visitor who never reads the description has to go on.
@@ -660,10 +702,11 @@ pub fn tasks(file: &NeedsFile, questions: &Questions, skim: bool) -> Vec<Task> {
}; };
for (i, step) in path.iter().enumerate() { for (i, step) in path.iter().enumerate() {
let page = &questions[&step.page]; let page = &questions[&step.page];
let open: Vec<&Alternative> = page.alternatives.iter().filter(|a| !a.disabled).collect(); let open: Vec<&Alternative> = page.alternatives.iter().filter(|a| !a.disabled && leads_somewhere(a)).collect();
if open.len() < 2 { if open.len() < 2 {
continue; continue;
} }
let context = page_context(page);
let mut trail: Vec<String> = path[..=i].iter().map(|s| s.page.clone()).collect(); let mut trail: Vec<String> = path[..=i].iter().map(|s| s.page.clone()).collect();
let expect: Vec<String> = viable(questions, need, page, need.max_steps - i, i == 0, false, &mut trail) let expect: Vec<String> = viable(questions, need, page, need.max_steps - i, i == 0, false, &mut trail)
.into_iter() .into_iter()
@@ -684,7 +727,11 @@ pub fn tasks(file: &NeedsFile, questions: &Questions, skim: bool) -> Vec<Task> {
persona: persona.id.clone(), persona: persona.id.clone(),
need: need.id.clone(), need: need.id.clone(),
page: step.page.clone(), page: step.page.clone(),
state: BTreeMap::from([("body", plain(&persona.text))]), state: if context.is_empty() {
BTreeMap::from([("body", plain(&persona.text))])
} else {
BTreeMap::from([("body", plain(&persona.text)), ("page", context)])
},
questions: BTreeMap::from([( questions: BTreeMap::from([(
"pick", "pick",
ChoiceQuestion { ChoiceQuestion {