Compare commits
15
Commits
build-2b593ba
...
v0.2.4
@@ -1,14 +1,16 @@
|
|||||||
name: Publish release
|
name: Publish release
|
||||||
|
|
||||||
# Portal no longer deploys itself. Each content repo (uhhm/questions,
|
# Portal does not deploy itself. Cutting a version is deliberate:
|
||||||
# redoal/questions) owns its instance - domain, port, env, Caddy route -
|
# `cargo release <level>` bumps Cargo.toml, commits, tags v<semver>,
|
||||||
# and its deploy workflow downloads a pinned release published here.
|
# and pushes; this workflow reacts to the tag and publishes the
|
||||||
# Rolling a new portal version out to a site = bumping PORTAL_RELEASE
|
# artifact as a Gitea release. Each content repo (uhhm/questions,
|
||||||
# in that site's .gitea/workflows/deploy.yml (an auditable commit).
|
# redoal/questions) pins PORTAL_RELEASE to one of these tags in its
|
||||||
|
# own deploy workflow - bumping the pin there is what rolls a version
|
||||||
|
# out to a site. Plain main pushes only run test.yml.
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches: [main]
|
tags: ["v*"]
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
publish:
|
publish:
|
||||||
@@ -62,8 +64,7 @@ jobs:
|
|||||||
- name: Package
|
- name: Package
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
tag="build-$(echo ${{ github.sha }} | cut -c1-7)"
|
tag="${{ github.ref_name }}"
|
||||||
echo "TAG=$tag" >> "$GITHUB_ENV"
|
|
||||||
stage=$(mktemp -d)
|
stage=$(mktemp -d)
|
||||||
cp "$CARGO_TARGET_DIR/release/portal" "$stage/portal"
|
cp "$CARGO_TARGET_DIR/release/portal" "$stage/portal"
|
||||||
cp "$CARGO_TARGET_DIR/release/question_lint" "$stage/question_lint"
|
cp "$CARGO_TARGET_DIR/release/question_lint" "$stage/question_lint"
|
||||||
@@ -75,24 +76,26 @@ jobs:
|
|||||||
rm -rf "$stage"
|
rm -rf "$stage"
|
||||||
|
|
||||||
# The run's own ephemeral token has write access to this repo -
|
# The run's own ephemeral token has write access to this repo -
|
||||||
# no long-lived PAT to manage. Re-running a build for the same sha
|
# no long-lived PAT to manage. The tag already exists (cargo
|
||||||
# finds the existing release instead of failing on the tag.
|
# release pushed it), so the release attaches to it; a re-run
|
||||||
|
# finds the existing release instead of failing.
|
||||||
- name: Publish release
|
- name: Publish release
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
|
tag="${{ github.ref_name }}"
|
||||||
api="${{ github.server_url }}/api/v1/repos/${{ github.repository }}"
|
api="${{ github.server_url }}/api/v1/repos/${{ github.repository }}"
|
||||||
auth="Authorization: token ${{ secrets.GITHUB_TOKEN }}"
|
auth="Authorization: token ${{ secrets.GITHUB_TOKEN }}"
|
||||||
subject=$(git log -1 --format=%s)
|
subject=$(git log -1 --format=%s)
|
||||||
body=$(printf '{"tag_name":"%s","target_commitish":"%s","name":"%s"}' \
|
body=$(printf '{"tag_name":"%s","name":"%s"}' \
|
||||||
"$TAG" "${{ github.sha }}" "$TAG: $(echo "$subject" | sed 's/"/\\"/g')")
|
"$tag" "$tag: $(echo "$subject" | sed 's/"/\\"/g')")
|
||||||
id=$(curl -sf -X POST -H "$auth" -H 'Content-Type: application/json' \
|
id=$(curl -sf -X POST -H "$auth" -H 'Content-Type: application/json' \
|
||||||
-d "$body" "$api/releases" | jq .id) \
|
-d "$body" "$api/releases" | jq .id) \
|
||||||
|| id=$(curl -sf -H "$auth" "$api/releases/tags/$TAG" | jq .id)
|
|| id=$(curl -sf -H "$auth" "$api/releases/tags/$tag" | jq .id)
|
||||||
# Replace the asset if a re-run already uploaded one.
|
# Replace the asset if a re-run already uploaded one.
|
||||||
for aid in $(curl -sf -H "$auth" "$api/releases/$id/assets" | jq '.[].id'); do
|
for aid in $(curl -sf -H "$auth" "$api/releases/$id/assets" | jq '.[].id'); do
|
||||||
curl -sf -X DELETE -H "$auth" "$api/releases/$id/assets/$aid"
|
curl -sf -X DELETE -H "$auth" "$api/releases/$id/assets/$aid"
|
||||||
done
|
done
|
||||||
curl -sf -X POST -H "$auth" \
|
curl -sf -X POST -H "$auth" \
|
||||||
-F "attachment=@portal-$TAG.tar.gz" \
|
-F "attachment=@portal-$tag.tar.gz" \
|
||||||
"$api/releases/$id/assets?name=portal-$TAG.tar.gz" > /dev/null
|
"$api/releases/$id/assets?name=portal-$tag.tar.gz" > /dev/null
|
||||||
echo "published $TAG"
|
echo "published $tag"
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
name: Test
|
||||||
|
|
||||||
|
# Publishing only happens on v* tags (publish.yml), so this is what
|
||||||
|
# keeps plain main pushes honest between releases.
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: [main]
|
||||||
|
pull_request:
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
test:
|
||||||
|
runs-on: bare
|
||||||
|
env:
|
||||||
|
# Same shared-toolchain/cache story as publish.yml.
|
||||||
|
CARGO_HOME: /var/local/cargo
|
||||||
|
RUSTUP_HOME: /var/local/rustup
|
||||||
|
PATH: /var/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/bin
|
||||||
|
SCCACHE_DIR: /var/local/sccache
|
||||||
|
SCCACHE_SERVER_PORT: "4228"
|
||||||
|
CARGO_TARGET_DIR: /var/local/cargo-target
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- name: Test
|
||||||
|
run: cargo test --features ssr
|
||||||
Generated
+1
-1
@@ -2948,7 +2948,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "portal"
|
name = "portal"
|
||||||
version = "0.1.0"
|
version = "0.2.4"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"arc-swap",
|
"arc-swap",
|
||||||
|
|||||||
+11
-2
@@ -1,6 +1,6 @@
|
|||||||
[package]
|
[package]
|
||||||
name = "portal"
|
name = "portal"
|
||||||
version = "0.1.0"
|
version = "0.2.4"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
|
|
||||||
[lib]
|
[lib]
|
||||||
@@ -19,7 +19,7 @@ axum = { version = "0.8", features = ["multipart"], optional = true }
|
|||||||
aws-sdk-s3 = { version = "1", optional = true }
|
aws-sdk-s3 = { version = "1", optional = true }
|
||||||
tokio = { version = "1", features = ["rt-multi-thread", "macros", "signal"], optional = true }
|
tokio = { version = "1", features = ["rt-multi-thread", "macros", "signal"], optional = true }
|
||||||
tower = { version = "0.5", optional = true }
|
tower = { version = "0.5", optional = true }
|
||||||
tower-http = { version = "0.6", features = ["fs"], optional = true }
|
tower-http = { version = "0.6", features = ["fs", "set-header"], optional = true }
|
||||||
tower-sessions = { version = "0.14", optional = true }
|
tower-sessions = { version = "0.14", optional = true }
|
||||||
async-nats = { version = "0.38", optional = true }
|
async-nats = { version = "0.38", optional = true }
|
||||||
arc-swap = { version = "1", optional = true }
|
arc-swap = { version = "1", optional = true }
|
||||||
@@ -131,3 +131,12 @@ bin-default-features = false
|
|||||||
lib-features = ["hydrate"]
|
lib-features = ["hydrate"]
|
||||||
lib-default-features = false
|
lib-default-features = false
|
||||||
lib-profile-release = "wasm-release"
|
lib-profile-release = "wasm-release"
|
||||||
|
|
||||||
|
# cargo release <level> is how a portal version is cut: bump, commit,
|
||||||
|
# tag v{{version}}, push. CI (publish.yml) reacts to the tag and
|
||||||
|
# publishes the release artifact; nothing on crates.io.
|
||||||
|
[package.metadata.release]
|
||||||
|
publish = false
|
||||||
|
push = true
|
||||||
|
tag-name = "v{{version}}"
|
||||||
|
pre-release-commit-message = "Release {{version}}"
|
||||||
|
|||||||
@@ -1,17 +1,41 @@
|
|||||||
# portal
|
# portal
|
||||||
|
|
||||||
The question runtime behind [uhhm.no](https://uhhm.no). Every page,
|
A content-driven question engine: one Rust binary that turns a Git
|
||||||
form, review desk, and state machine it serves is declared in the
|
repo of YAML into a live site — pages, forms, review desks, and state
|
||||||
[`questions`](https://project.uhhm.no/uhhm/questions) content repo —
|
machines, with a durable event-sourced record of every answer
|
||||||
this codebase is the engine that renders, enforces, and records, and
|
underneath. The engine special-cases nothing: everything a site
|
||||||
it special-cases none of it.
|
serves is declared in its content repo, and the same build serves any
|
||||||
|
number of sites.
|
||||||
|
|
||||||
|
Point an instance at a content repo and that repo *is* the site:
|
||||||
|
pages, copy, state graphs, and branding (`site.yaml`: title,
|
||||||
|
wordmark, and which hero the landing page opens on — the YES canvas,
|
||||||
|
a gesture-drawing canvas wired to a relay, or plain copy). Content
|
||||||
|
pushes hot-reload every running instance; instances differ only by
|
||||||
|
env vars. [uhhm.no](https://uhhm.no)
|
||||||
|
([uhhm/questions](https://project.uhhm.no/uhhm/questions)) and
|
||||||
|
[redoal.com](https://redoal.com)
|
||||||
|
([redoal/questions](https://project.uhhm.no/redoal/questions)) are
|
||||||
|
two faces of the same binary, deployed from the same release
|
||||||
|
artifact.
|
||||||
|
|
||||||
|
It composes with the surrounding stack rather than bundling it: Gitea
|
||||||
|
hosts and serves the content, NATS JetStream stores events and
|
||||||
|
projections, Kanidm provides identity, and anything downstream
|
||||||
|
(automations, newsletters, onboarding) subscribes to the answer
|
||||||
|
stream.
|
||||||
|
|
||||||
## What the engine provides
|
## What the engine provides
|
||||||
|
|
||||||
- **Content-driven pages** (`src/content.rs`, `src/app.rs`): YAML
|
- **Content-driven pages** (`src/content.rs`, `src/app.rs`): YAML
|
||||||
loaded from Gitea at boot and hot-swapped on a NATS reload signal;
|
loaded from Gitea at boot and hot-swapped on a NATS reload signal;
|
||||||
a bad push keeps the last-good content serving. A page's `id` is
|
a bad push keeps the last-good content serving. The `questions/`
|
||||||
its URL; `qualifies` gates it to a Kanidm group.
|
tree IS the router — file paths become URLs, `_section.yaml`
|
||||||
|
applies criteria to a whole directory, `[name].yaml` pages serve
|
||||||
|
any `/dir/<value>` with the segment fed into resource keys, and
|
||||||
|
`requires_chain` gates a page on verifiable answer provenance next
|
||||||
|
to `qualifies`' Kanidm-group identity gate (see
|
||||||
|
`docs/design/filesystem-routes.md`).
|
||||||
- **State machines as content** (`src/aggregates/`): `aggregates.yaml`
|
- **State machines as content** (`src/aggregates/`): `aggregates.yaml`
|
||||||
declares each bucket's states and legal transitions; the engine
|
declares each bucket's states and legal transitions; the engine
|
||||||
replays a record's event history and refuses undeclared moves, with
|
replays a record's event history and refuses undeclared moves, with
|
||||||
@@ -28,8 +52,13 @@ it special-cases none of it.
|
|||||||
lineage; `?chain=` links carry it, and self-service transitions
|
lineage; `?chain=` links carry it, and self-service transitions
|
||||||
(unsubscribe) authorize by holding one.
|
(unsubscribe) authorize by holding one.
|
||||||
- **Live resources** (`src/resource.rs`): content can pull a KV
|
- **Live resources** (`src/resource.rs`): content can pull a KV
|
||||||
bucket, Gitea starred/org repos, or any public JSON URL (SSRF
|
bucket, Gitea starred/org repos/releases, or any public JSON URL
|
||||||
fail-closed), reshaped by a content-declared `jq` filter.
|
(SSRF fail-closed), reshaped by a content-declared `jq` filter.
|
||||||
|
- **Input kinds as content**: a requirement's `type:` picks the
|
||||||
|
widget — plain fields, a rich-text editor, or a `gesture` drawing
|
||||||
|
canvas that can connect to a redoal relay so similar strokes echo
|
||||||
|
between visitors live. Submitted values are arbitrary JSON; the
|
||||||
|
engine records what the widget produced.
|
||||||
- **Review desks**: any Kv resource with `transitions` renders rows
|
- **Review desks**: any Kv resource with `transitions` renders rows
|
||||||
with per-state action buttons and one shared confirm per
|
with per-state action buttons and one shared confirm per
|
||||||
alternative — owners walk records through their graphs without
|
alternative — owners walk records through their graphs without
|
||||||
@@ -38,9 +67,10 @@ it special-cases none of it.
|
|||||||
## Binaries
|
## Binaries
|
||||||
|
|
||||||
- `portal` — the server (Leptos SSR + hydrate, Axum underneath).
|
- `portal` — the server (Leptos SSR + hydrate, Axum underneath).
|
||||||
- `question_lint` — headless content validation, run by the
|
- `question_lint` — headless content validation, shipped inside every
|
||||||
`questions` repo's CI against a prebuilt copy this repo's deploy
|
release artifact so each content repo's CI lints with the exact
|
||||||
publishes; also works offline: `question_lint --path <dir>`.
|
portal version its instance runs; also works offline:
|
||||||
|
`question_lint --path <dir>`.
|
||||||
|
|
||||||
## Development
|
## Development
|
||||||
|
|
||||||
@@ -50,17 +80,55 @@ cargo test --features ssr # engine tests
|
|||||||
cargo build --features ssr --bin question_lint
|
cargo build --features ssr --bin question_lint
|
||||||
```
|
```
|
||||||
|
|
||||||
Runtime configuration is env vars (see `src/main.rs` and
|
Runtime configuration is env vars (see `src/main.rs`, and each
|
||||||
`.gitea/workflows/deploy.yml`): `NATS_URL`, `CONTENT_REPO`/
|
content repo's `.gitea/workflows/deploy.yml` for the values in
|
||||||
`CONTENT_BRANCH`, Kanidm OIDC (`KANIDM_URL`, `OAUTH2_CLIENT_*`),
|
production): `NATS_URL`, `CONTENT_REPO`/`CONTENT_BRANCH`, Kanidm OIDC
|
||||||
optional `GARAGE_*` for uploads, `GITEA_API_TOKEN` for authenticated
|
(`KANIDM_URL`, `OAUTH2_CLIENT_*`), optional `GARAGE_*` for uploads,
|
||||||
resource pulls, `AUTOMATION_READ_TOKEN` for the automation KV read
|
`GITEA_API_TOKEN` for authenticated resource pulls,
|
||||||
endpoint.
|
`AUTOMATION_READ_TOKEN` for the automation KV read endpoint.
|
||||||
|
|
||||||
## Deploy
|
## Release and deploy
|
||||||
|
|
||||||
Pushing `main` triggers `.gitea/workflows/deploy.yml` on the
|
Portal doesn't deploy itself — it publishes versions, and each site
|
||||||
bare-metal runner: release build, ship to
|
decides when to take one. The whole day-to-day surface is two
|
||||||
`/srv/app/uhhm-portal/releases/<sha>`, flip the `current` symlink,
|
commands:
|
||||||
restart `app@uhhm-portal`, reload Caddy. Content changes never come
|
|
||||||
through here — they hot-reload live from the `questions` repo.
|
**Cut a release** (here):
|
||||||
|
|
||||||
|
```sh
|
||||||
|
cargo release patch # or minor / major
|
||||||
|
```
|
||||||
|
|
||||||
|
That bumps `Cargo.toml`, tags `v<version>`, and pushes; CI
|
||||||
|
(`.gitea/workflows/publish.yml`) reacts to the tag, builds once, and
|
||||||
|
attaches `portal-v<version>.tar.gz` (`portal` + `question_lint` +
|
||||||
|
`site/`) to the Gitea release. Plain pushes to `main` only run the
|
||||||
|
tests (`test.yml`) — nothing reaches production from this repo.
|
||||||
|
|
||||||
|
**Roll it out** (in a content repo): edit one line in that repo's
|
||||||
|
`.gitea/workflows/deploy.yml` —
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
env:
|
||||||
|
PORTAL_RELEASE: v0.1.1 # <- bump, commit, push
|
||||||
|
```
|
||||||
|
|
||||||
|
Its CI downloads the pinned artifact, ships
|
||||||
|
`/srv/app/<instance>/releases/<tag>`, flips `current`, rewrites the
|
||||||
|
instance env from that repo's own Actions variables/secrets, restarts
|
||||||
|
`app@<instance>`, and refreshes the Caddy route. Every rollout is a
|
||||||
|
commit, so reverting a bad version is `git revert` + push. Sites
|
||||||
|
upgrade independently: uhhm.no (uhhm/questions → `app@uhhm-portal`,
|
||||||
|
:3010) and redoal.com (redoal/questions → `app@redoal-portal`,
|
||||||
|
:3020) can pin different versions.
|
||||||
|
|
||||||
|
Content changes never come through any of this — they hot-reload
|
||||||
|
live from the content repos over NATS.
|
||||||
|
|
||||||
|
**Add a site**: new content repo with a copy of an existing
|
||||||
|
`deploy.yml` (change `INSTANCE`, port, domains), Actions variables
|
||||||
|
(`KANIDM_URL`, `OAUTH2_CLIENT_ID`, `PUBLIC_URL`, `SITE_NAME`) and
|
||||||
|
secrets (`NATS_URL`, `OAUTH2_CLIENT_SECRET`,
|
||||||
|
`PORTAL_GITEA_API_TOKEN` — Gitea reserves the `GITEA_` prefix for
|
||||||
|
secret names), a Kanidm OAuth2 client, and DNS. `site.yaml` in the
|
||||||
|
content repo handles all branding; no portal changes needed.
|
||||||
|
|||||||
@@ -0,0 +1,133 @@
|
|||||||
|
# Filesystem routes, sections, and where chains fit
|
||||||
|
|
||||||
|
Status: implemented in v0.2.0 (2026-08-24) — all three phases, with
|
||||||
|
one deviation: dynamic-page params substitute into resource keys via
|
||||||
|
server-side `resolve_question` at lookup time (get_question,
|
||||||
|
find_feature, submit_answer all resolve concrete paths), so no param
|
||||||
|
threading exists client-side. The user-facing routing contract is
|
||||||
|
documented in uhhm/questions' README ("Routing: the tree is the
|
||||||
|
router"); this file stays as the design rationale.
|
||||||
|
|
||||||
|
## What exists today, precisely
|
||||||
|
|
||||||
|
- A question's `id` doubles as its URL. Filenames are meaningless:
|
||||||
|
`questions/` is loaded as a **flat** directory (both the Gitea
|
||||||
|
loader and `question_lint --path`), every `*.yaml` becomes a
|
||||||
|
`Question` keyed by its own declared `id`.
|
||||||
|
- Hierarchy exists only as strings: `action: /proposed` edges, plus a
|
||||||
|
manual `followup: true` flag that hides post-submission pages from
|
||||||
|
the nav. The graph is invisible in a repo listing — you open every
|
||||||
|
file to learn the flow. (uhhm's actual graph: `/` fans out to three
|
||||||
|
followups; `/develop` → `/develop-proposal` → `/proposed` is a
|
||||||
|
two-step flow flattened into three top-level files.)
|
||||||
|
- Criteria are per-file: `qualifies: <kanidm-group>` on a question,
|
||||||
|
`requires_group` on a resource. Gating a whole area means
|
||||||
|
repeating the flag in every file of that area.
|
||||||
|
- Chains are query-string lineage: submitting hashes
|
||||||
|
`(question, parents, responses, ts)` into `chain_hash`, the next
|
||||||
|
page is `action + ?chain=<hash>`, and holding a chain is itself a
|
||||||
|
capability (`self_transition` + email second factor). `chain.rs`
|
||||||
|
reserves DAG shape (multiple parents) but nothing produces it yet.
|
||||||
|
- `Question.route` is a declared-but-never-read field — a fossil of
|
||||||
|
this exact idea.
|
||||||
|
|
||||||
|
## The proposal, in three phases
|
||||||
|
|
||||||
|
### Phase 1 — the tree is the router
|
||||||
|
|
||||||
|
Directory structure becomes the URL structure, next-js style:
|
||||||
|
|
||||||
|
```
|
||||||
|
questions/
|
||||||
|
index.yaml → /
|
||||||
|
applied.yaml → /applied
|
||||||
|
develop/
|
||||||
|
index.yaml → /develop
|
||||||
|
proposal.yaml → /develop/proposal
|
||||||
|
proposed.yaml → /develop/proposed
|
||||||
|
review/
|
||||||
|
index.yaml → /review
|
||||||
|
```
|
||||||
|
|
||||||
|
- `id:` becomes optional and **derived from the path** (`index.yaml`
|
||||||
|
names its directory). An explicit `id:` still wins so both content
|
||||||
|
repos keep working unchanged; lint warns when it disagrees with the
|
||||||
|
path, and the field can retire later along with `route`.
|
||||||
|
- `action:` accepts **relative references**: `action: proposed`
|
||||||
|
resolves against the file's directory, `action: /subscribed` stays
|
||||||
|
absolute. Resolution happens at load time, so validation and the
|
||||||
|
runtime see absolute ids exactly as today. A flow directory becomes
|
||||||
|
self-contained: rename `develop/` and every internal edge moves
|
||||||
|
with it.
|
||||||
|
- **`followup:` is inferred**: `index.yaml` files are nav pages,
|
||||||
|
non-index files are followups unless they say `nav: true`. This
|
||||||
|
matches the real content exactly (uhhm's four `followup: true`
|
||||||
|
files are precisely its non-index leaf pages) and deletes a flag
|
||||||
|
people must remember.
|
||||||
|
- Loader: switch from the per-directory contents API to Gitea's git
|
||||||
|
trees API (`/git/trees/{branch}?recursive=true`) — one request for
|
||||||
|
the whole tree instead of one per directory, which the flat loader
|
||||||
|
should be using anyway.
|
||||||
|
|
||||||
|
### Phase 2 — sections: criteria scoped by URL prefix
|
||||||
|
|
||||||
|
A `_section.yaml` in any directory applies to everything beneath it
|
||||||
|
(underscore = not a page, like next's private folders):
|
||||||
|
|
||||||
|
```
|
||||||
|
questions/review/_section.yaml:
|
||||||
|
qualifies: portal_owners
|
||||||
|
responsible: { name: Bendik, contact: … }
|
||||||
|
```
|
||||||
|
|
||||||
|
This is the URL/criteria interplay actually worth having: **a URL
|
||||||
|
prefix becomes a trust boundary**. "Everything under /review is
|
||||||
|
owner-only" is one line in one place, instead of a flag per file that
|
||||||
|
drifts. Per-question `qualifies` still overrides (tighter or looser —
|
||||||
|
lint should warn on looser). Sections are also the natural home for
|
||||||
|
shared `responsible` contacts and, later, per-section branding
|
||||||
|
accents.
|
||||||
|
|
||||||
|
### Phase 3 — dynamic segments, and chains stay out of the path
|
||||||
|
|
||||||
|
Two criteria axes exist: **who you are** (Kanidm group) and **what
|
||||||
|
you've done** (holding a chain). Phase 2 scopes the first by prefix;
|
||||||
|
phase 3 does the same for the second, plus gives records addresses:
|
||||||
|
|
||||||
|
- `[record].yaml` — a dynamic segment, one YAML file rendered per
|
||||||
|
record: `questions/review/[record].yaml` serves `/review/<key>`,
|
||||||
|
with the param available to the page's `ResourceSpec.key`. Today a
|
||||||
|
single record is only reachable through a desk row or a
|
||||||
|
`?chain=` link; this gives every record a real, gated URL —
|
||||||
|
linkable from review desks, automations, and n8n notifications.
|
||||||
|
- `requires_chain: <question-ref>` (page- or section-level): the page
|
||||||
|
only renders for a visitor whose chain tip answers the referenced
|
||||||
|
question. Today's followup pages are soft-hidden (out of nav) but
|
||||||
|
fully reachable; this makes "you must have come from X" an actual
|
||||||
|
criterion, declared with a relative ref like actions are.
|
||||||
|
|
||||||
|
**Deliberately not proposed: encoding the chain in the path.** The
|
||||||
|
page tree is static structure; the chain is runtime lineage and a
|
||||||
|
bearer capability. Putting it in the path makes it look canonical and
|
||||||
|
shareable — exactly what a capability URL shouldn't invite — and a
|
||||||
|
DAG (the reserved multi-parent shape) doesn't linearize into a path
|
||||||
|
anyway. `?chain=` stays a query parameter: pages keep one canonical
|
||||||
|
URL, lineage rides along only when it's actually held.
|
||||||
|
|
||||||
|
## Migration
|
||||||
|
|
||||||
|
Phase 1 is fully backward compatible (explicit `id` wins, flat repos
|
||||||
|
are just trees of depth one). The content repos migrate by `git mv`:
|
||||||
|
uhhm's develop flow nests under `develop/`, its followups either stay
|
||||||
|
top-level (`/applied` keeps its URL) or move with their flows if URL
|
||||||
|
churn is acceptable; redoal's three files are already the tree. Lint
|
||||||
|
learns the same resolution rules in the same commit, so a bad
|
||||||
|
reference stays a caught push, never a 404.
|
||||||
|
|
||||||
|
## Order of value
|
||||||
|
|
||||||
|
Phase 1 is cheap and pays immediately (the repo listing becomes the
|
||||||
|
sitemap). Phase 2 is small and unlocks gated areas properly. Phase 3
|
||||||
|
is the real feature work — `[record]` pages change what desks and
|
||||||
|
automations can link to — and can wait until something concrete needs
|
||||||
|
it.
|
||||||
@@ -30,6 +30,12 @@ pub struct AggregateSchema {
|
|||||||
pub event_for_state: HashMap<String, String>,
|
pub event_for_state: HashMap<String, String>,
|
||||||
pub state_for_event: HashMap<String, String>,
|
pub state_for_event: HashMap<String, String>,
|
||||||
pub transitions: HashMap<String, Vec<String>>,
|
pub transitions: HashMap<String, Vec<String>>,
|
||||||
|
/// Names what consumes this bucket's answers when no page in the
|
||||||
|
/// content repo reads it (e.g. "n8n newsletter compose").
|
||||||
|
/// Free-text - it exists so `validate_questions`' attended-bucket
|
||||||
|
/// rule has an explicit, auditable opt-out instead of a silent
|
||||||
|
/// one, and so the next reader knows where the answers go.
|
||||||
|
pub attended_by: Option<String>,
|
||||||
}
|
}
|
||||||
|
|
||||||
impl AggregateSchema {
|
impl AggregateSchema {
|
||||||
@@ -57,6 +63,8 @@ struct RawAggregateSchema {
|
|||||||
states: HashMap<String, RawState>,
|
states: HashMap<String, RawState>,
|
||||||
#[serde(default)]
|
#[serde(default)]
|
||||||
transitions: HashMap<String, Vec<String>>,
|
transitions: HashMap<String, Vec<String>>,
|
||||||
|
#[serde(default)]
|
||||||
|
attended_by: Option<String>,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Debug, serde::Deserialize)]
|
#[derive(Debug, serde::Deserialize)]
|
||||||
@@ -123,6 +131,7 @@ pub fn parse_aggregates_yaml(raw: &str) -> anyhow::Result<HashMap<String, Aggreg
|
|||||||
event_for_state,
|
event_for_state,
|
||||||
state_for_event,
|
state_for_event,
|
||||||
transitions: raw_schema.transitions,
|
transitions: raw_schema.transitions,
|
||||||
|
attended_by: raw_schema.attended_by,
|
||||||
},
|
},
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|||||||
+213
-30
@@ -54,20 +54,61 @@ pub fn shell(options: LeptosOptions) -> impl IntoView {
|
|||||||
pub fn App() -> impl IntoView {
|
pub fn App() -> impl IntoView {
|
||||||
provide_meta_context();
|
provide_meta_context();
|
||||||
|
|
||||||
|
// ONE site resource and ONE <Title> for the whole app, both living
|
||||||
|
// outside the router. Two dueling Title components (a static
|
||||||
|
// SITE_NAME fallback here + a per-page override) turned every SPA
|
||||||
|
// navigation into a remount race that the compile-time fallback
|
||||||
|
// kept winning - redoal.com's tab flipped to "uhhm" on the first
|
||||||
|
// client-side nav. App never remounts, so this Title never
|
||||||
|
// unmounts; the Suspense makes SSR await the resolved title so the
|
||||||
|
// served <head> is right too. Pages read the same resource via
|
||||||
|
// context instead of fetching their own copy.
|
||||||
|
let site = Resource::new(|| (), |_| get_site());
|
||||||
|
provide_context(site);
|
||||||
|
|
||||||
view! {
|
view! {
|
||||||
<Stylesheet id="leptos" href="/pkg/portal.css"/>
|
<Stylesheet id="leptos" href="/pkg/portal.css"/>
|
||||||
<Title text=SITE_NAME/>
|
<Suspense fallback=|| ()>
|
||||||
|
{move || {
|
||||||
|
site.get()
|
||||||
|
.map(|res| {
|
||||||
|
let title = res
|
||||||
|
.ok()
|
||||||
|
.and_then(|s| s.title)
|
||||||
|
.unwrap_or_else(|| SITE_NAME.to_string());
|
||||||
|
view! { <Title text=title/> }
|
||||||
|
})
|
||||||
|
}}
|
||||||
|
</Suspense>
|
||||||
<Router>
|
<Router>
|
||||||
<Routes fallback=|| view! { <NotFound/> }>
|
<PortalShell/>
|
||||||
<Route path=path!("") view=QuestionPage/>
|
|
||||||
<Route path=path!("/*any") view=QuestionPage/>
|
|
||||||
</Routes>
|
|
||||||
</Router>
|
</Router>
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// Every server-fn resource the pages read, created exactly once for
|
||||||
|
/// the app's lifetime and handed down via context. Wrapper structs
|
||||||
|
/// because a bare `Resource<T>` context is claimed by whoever provides
|
||||||
|
/// that T last.
|
||||||
|
#[derive(Clone, Copy)]
|
||||||
|
struct QuestionRes(Resource<Result<Option<Page>, ServerFnError>>);
|
||||||
|
#[derive(Clone, Copy)]
|
||||||
|
struct UserRes(Resource<Result<Option<User>, ServerFnError>>);
|
||||||
|
#[derive(Clone, Copy)]
|
||||||
|
struct NavRes(Resource<Result<Vec<(String, String)>, ServerFnError>>);
|
||||||
|
|
||||||
|
/// Owns the app's data resources, above the routes and reactive on the
|
||||||
|
/// location instead of recreated per page. Route components creating
|
||||||
|
/// their own resources broke on the first client-side navigation: the
|
||||||
|
/// remounted component's fresh Resource consumed a stale SSR hydration
|
||||||
|
/// buffer instead of fetching - concretely, the nav list
|
||||||
|
/// `[[id, name], ..]` deserialized as a `Page` (serde fills a struct
|
||||||
|
/// from a sequence in field order), rendering the landing question
|
||||||
|
/// gated behind its own nav entry. Stable resources + context makes
|
||||||
|
/// that class of misalignment impossible: navigation only changes a
|
||||||
|
/// key, and a key change always refetches.
|
||||||
#[component]
|
#[component]
|
||||||
fn QuestionPage() -> impl IntoView {
|
fn PortalShell() -> impl IntoView {
|
||||||
let location = use_location();
|
let location = use_location();
|
||||||
let query = use_query_map();
|
let query = use_query_map();
|
||||||
let path = Memo::new(move |_| {
|
let path = Memo::new(move |_| {
|
||||||
@@ -78,12 +119,37 @@ fn QuestionPage() -> impl IntoView {
|
|||||||
p
|
p
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
let chain = Memo::new(move |_| query.with(|q| q.get("chain")));
|
||||||
|
|
||||||
|
let question = Resource::new(
|
||||||
|
move || (path.get(), chain.get()),
|
||||||
|
|(path, chain)| get_question(path, chain),
|
||||||
|
);
|
||||||
|
let user = Resource::new(|| (), |_| current_user());
|
||||||
|
let nav = Resource::new(move || chain.get().is_some(), list_qualifying_questions);
|
||||||
|
provide_context(QuestionRes(question));
|
||||||
|
provide_context(UserRes(user));
|
||||||
|
provide_context(NavRes(nav));
|
||||||
|
|
||||||
|
view! {
|
||||||
|
<Routes fallback=|| view! { <NotFound/> }>
|
||||||
|
<Route path=path!("") view=QuestionPage/>
|
||||||
|
<Route path=path!("/*any") view=QuestionPage/>
|
||||||
|
</Routes>
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
#[component]
|
||||||
|
fn QuestionPage() -> impl IntoView {
|
||||||
|
let query = use_query_map();
|
||||||
let parent_hash = Memo::new(move |_| query.with(|q| q.get("chain")));
|
let parent_hash = Memo::new(move |_| query.with(|q| q.get("chain")));
|
||||||
let query_email = Memo::new(move |_| query.with(|q| q.get("email")));
|
let query_email = Memo::new(move |_| query.with(|q| q.get("email")));
|
||||||
|
|
||||||
let question = Resource::new(move || path.get(), get_question);
|
// All shared, app-lifetime resources (see PortalShell / App) -
|
||||||
let user = Resource::new(|| (), |_| current_user());
|
// never created per navigation.
|
||||||
let site = Resource::new(|| (), |_| get_site());
|
let QuestionRes(question) = expect_context();
|
||||||
|
let UserRes(user) = expect_context();
|
||||||
|
let site = expect_context::<Resource<Result<SiteConfig, ServerFnError>>>();
|
||||||
|
|
||||||
view! {
|
view! {
|
||||||
<Suspense fallback=|| {
|
<Suspense fallback=|| {
|
||||||
@@ -103,18 +169,12 @@ fn QuestionPage() -> impl IntoView {
|
|||||||
let site_cfg = site.get().and_then(|r| r.ok()).unwrap_or_default();
|
let site_cfg = site.get().and_then(|r| r.ok()).unwrap_or_default();
|
||||||
question_res
|
question_res
|
||||||
.map(|res| match res {
|
.map(|res| match res {
|
||||||
Ok(Some(q)) => {
|
Ok(Some(page)) => {
|
||||||
let current = user_res.and_then(|r| r.ok()).flatten();
|
let current = user_res.and_then(|r| r.ok()).flatten();
|
||||||
view! {
|
view! {
|
||||||
// A second <Title> outranks App's
|
|
||||||
// SITE_NAME fallback only when content
|
|
||||||
// actually declares one.
|
|
||||||
{site_cfg
|
|
||||||
.title
|
|
||||||
.clone()
|
|
||||||
.map(|t| view! { <Title text=t/> })}
|
|
||||||
<QuestionView
|
<QuestionView
|
||||||
question=q
|
question=page.question
|
||||||
|
chain_gate=page.chain_gate
|
||||||
parent_hash=parent_hash.get()
|
parent_hash=parent_hash.get()
|
||||||
query_email=query_email.get()
|
query_email=query_email.get()
|
||||||
user=current
|
user=current
|
||||||
@@ -133,12 +193,45 @@ fn QuestionPage() -> impl IntoView {
|
|||||||
#[component]
|
#[component]
|
||||||
fn QuestionView(
|
fn QuestionView(
|
||||||
question: Question,
|
question: Question,
|
||||||
|
chain_gate: Option<(String, String)>,
|
||||||
parent_hash: Option<String>,
|
parent_hash: Option<String>,
|
||||||
query_email: Option<String>,
|
query_email: Option<String>,
|
||||||
user: Option<User>,
|
user: Option<User>,
|
||||||
site: SiteConfig,
|
site: SiteConfig,
|
||||||
) -> impl IntoView {
|
) -> impl IntoView {
|
||||||
let question_id = question.id.clone();
|
let question_id = question.id.clone();
|
||||||
|
let has_chain = parent_hash.is_some();
|
||||||
|
|
||||||
|
// The provenance counterpart to the qualifies gate below: a
|
||||||
|
// requires_chain page whose visitor holds no verifiable lineage to
|
||||||
|
// the required question renders a pointer there instead of its
|
||||||
|
// alternatives.
|
||||||
|
if let Some((target, target_name)) = chain_gate {
|
||||||
|
let label = if target_name.is_empty() {
|
||||||
|
target.clone()
|
||||||
|
} else {
|
||||||
|
target_name
|
||||||
|
};
|
||||||
|
return view! {
|
||||||
|
<Hero
|
||||||
|
title=question.name.clone()
|
||||||
|
description=question.description.clone()
|
||||||
|
landing=question_id == "/"
|
||||||
|
site=site.clone()
|
||||||
|
/>
|
||||||
|
<div class="alternatives">
|
||||||
|
<section class="alt-card gate-card">
|
||||||
|
<p>"This page follows from an answer you don't seem to carry yet."</p>
|
||||||
|
<a class="alt-submit" href=target>
|
||||||
|
{label}
|
||||||
|
</a>
|
||||||
|
</section>
|
||||||
|
</div>
|
||||||
|
// A gate is never a dead end: the same nav as every page.
|
||||||
|
<QuestionNav current_id=question_id has_chain=has_chain/>
|
||||||
|
}
|
||||||
|
.into_any();
|
||||||
|
}
|
||||||
|
|
||||||
// Generic: any question with `qualifies` set renders this same gate
|
// Generic: any question with `qualifies` set renders this same gate
|
||||||
// instead of its alternatives - "/review" isn't a special case, it's
|
// instead of its alternatives - "/review" isn't a special case, it's
|
||||||
@@ -171,6 +264,7 @@ fn QuestionView(
|
|||||||
}}
|
}}
|
||||||
</section>
|
</section>
|
||||||
</div>
|
</div>
|
||||||
|
<QuestionNav current_id=question_id has_chain=has_chain/>
|
||||||
}
|
}
|
||||||
.into_any();
|
.into_any();
|
||||||
}
|
}
|
||||||
@@ -180,7 +274,6 @@ fn QuestionView(
|
|||||||
// on pages where some alternative actually declares a deck.
|
// on pages where some alternative actually declares a deck.
|
||||||
let needs_swiper = question.alternatives.iter().any(|a| a.images.len() > 1);
|
let needs_swiper = question.alternatives.iter().any(|a| a.images.len() > 1);
|
||||||
|
|
||||||
let has_chain = parent_hash.is_some();
|
|
||||||
|
|
||||||
view! {
|
view! {
|
||||||
{needs_swiper.then(|| view! { <leptos_meta::Script src="/swiper-element-bundle.min.js"/> })}
|
{needs_swiper.then(|| view! { <leptos_meta::Script src="/swiper-element-bundle.min.js"/> })}
|
||||||
@@ -243,7 +336,8 @@ fn QuestionView(
|
|||||||
/// claiming front-page space (an owner also sees the gated desks here).
|
/// claiming front-page space (an owner also sees the gated desks here).
|
||||||
#[component]
|
#[component]
|
||||||
fn QuestionNav(current_id: String, has_chain: bool) -> impl IntoView {
|
fn QuestionNav(current_id: String, has_chain: bool) -> impl IntoView {
|
||||||
let nav = Resource::new(move || has_chain, list_qualifying_questions);
|
let _ = has_chain; // keyed into the shared resource by PortalShell
|
||||||
|
let NavRes(nav) = expect_context();
|
||||||
view! {
|
view! {
|
||||||
<Suspense fallback=|| ()>
|
<Suspense fallback=|| ()>
|
||||||
{move || {
|
{move || {
|
||||||
@@ -322,7 +416,12 @@ fn ResponsibleNote(responsible: Responsible) -> impl IntoView {
|
|||||||
mod yes {
|
mod yes {
|
||||||
use wasm_bindgen::prelude::*;
|
use wasm_bindgen::prelude::*;
|
||||||
|
|
||||||
#[wasm_bindgen(module = "/yes.js")]
|
// raw_module (a runtime URL, not a bundled snippet) on purpose:
|
||||||
|
// the file lives in public/ so it's served at the stable /yes.js
|
||||||
|
// - the same URL the hero's inline early-mount script imports.
|
||||||
|
// A bundled snippet would sit under a per-build hashed
|
||||||
|
// /pkg/snippets/ path the inline script couldn't know.
|
||||||
|
#[wasm_bindgen(raw_module = "/yes.js")]
|
||||||
extern "C" {
|
extern "C" {
|
||||||
#[wasm_bindgen(js_name = RasterizedYES)]
|
#[wasm_bindgen(js_name = RasterizedYES)]
|
||||||
pub type RasterizedYes;
|
pub type RasterizedYes;
|
||||||
@@ -434,7 +533,28 @@ fn Hero(title: String, description: String, landing: bool, site: SiteConfig) ->
|
|||||||
if raster_ref.get().is_none() {
|
if raster_ref.get().is_none() {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
instance.set_value(Some(yes::RasterizedYes::new()));
|
if instance.with_value(|i| i.is_some()) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
// Adopt the hero's inline early-mount instance (started at
|
||||||
|
// HTML parse time, long before this wasm was even fetched)
|
||||||
|
// instead of starting a second animation. The flag covers
|
||||||
|
// the opposite ordering too: an inline script that runs
|
||||||
|
// after this sees it and stays inert.
|
||||||
|
use wasm_bindgen::JsCast;
|
||||||
|
let global = js_sys::global();
|
||||||
|
let _ = js_sys::Reflect::set(&global, &"__yesAdopted".into(), &true.into());
|
||||||
|
let early = js_sys::Reflect::get(&global, &"__yesEarly".into())
|
||||||
|
.ok()
|
||||||
|
.filter(|v| !v.is_undefined() && !v.is_null());
|
||||||
|
let inst = match early {
|
||||||
|
Some(v) => {
|
||||||
|
let _ = js_sys::Reflect::delete_property(&global, &"__yesEarly".into());
|
||||||
|
v.unchecked_into::<yes::RasterizedYes>()
|
||||||
|
}
|
||||||
|
None => yes::RasterizedYes::new(),
|
||||||
|
};
|
||||||
|
instance.set_value(Some(inst));
|
||||||
});
|
});
|
||||||
on_cleanup(move || {
|
on_cleanup(move || {
|
||||||
instance.update_value(|opt| {
|
instance.update_value(|opt| {
|
||||||
@@ -481,6 +601,15 @@ fn Hero(title: String, description: String, landing: bool, site: SiteConfig) ->
|
|||||||
<canvas id="lineCanvas"></canvas>
|
<canvas id="lineCanvas"></canvas>
|
||||||
<canvas id="rasterCanvas" node_ref=raster_ref></canvas>
|
<canvas id="rasterCanvas" node_ref=raster_ref></canvas>
|
||||||
</div>
|
</div>
|
||||||
|
// Starts the animation at HTML parse time
|
||||||
|
// instead of waiting out the wasm bundle's
|
||||||
|
// fetch + hydration; the hydrate Effect above
|
||||||
|
// adopts (never duplicates) the instance, and
|
||||||
|
// the guards make either execution order safe.
|
||||||
|
<script
|
||||||
|
type="module"
|
||||||
|
inner_html="import('/yes.js').then((m) => { if (!window.__yesAdopted && !window.__yesEarly) window.__yesEarly = new m.RasterizedYES(); });"
|
||||||
|
></script>
|
||||||
}
|
}
|
||||||
})}
|
})}
|
||||||
{show_gesture
|
{show_gesture
|
||||||
@@ -1640,11 +1769,56 @@ fn NotFound() -> impl IntoView {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/// What a URL resolves to: the question (dynamic pages arrive with
|
||||||
|
/// their segment value already substituted, see
|
||||||
|
/// `content::resolve_question`) plus whether a `requires_chain` gate
|
||||||
|
/// blocked it - `(target id, target name)` so the gate can point the
|
||||||
|
/// visitor at where the required answer comes from.
|
||||||
|
#[derive(Clone, Debug, Serialize, Deserialize)]
|
||||||
|
pub struct Page {
|
||||||
|
pub question: Question,
|
||||||
|
pub chain_gate: Option<(String, String)>,
|
||||||
|
}
|
||||||
|
|
||||||
#[server(endpoint = "get_question")]
|
#[server(endpoint = "get_question")]
|
||||||
pub async fn get_question(path: String) -> Result<Option<Question>, ServerFnError> {
|
pub async fn get_question(
|
||||||
|
path: String,
|
||||||
|
chain: Option<String>,
|
||||||
|
) -> Result<Option<Page>, ServerFnError> {
|
||||||
|
use crate::content::{path_matches, resolve_question};
|
||||||
use crate::server::AppState;
|
use crate::server::AppState;
|
||||||
let state = expect_context::<AppState>();
|
let state = expect_context::<AppState>();
|
||||||
Ok(state.questions.load().get(&path).cloned())
|
let questions = state.questions.load();
|
||||||
|
let Some(question) = resolve_question(&questions, &path) else {
|
||||||
|
return Ok(None);
|
||||||
|
};
|
||||||
|
let mut chain_gate = None;
|
||||||
|
if let Some(target) = &question.requires_chain {
|
||||||
|
// The claimed lineage must verifiably end at the required
|
||||||
|
// question - an unindexed or absent hash reads as unverified,
|
||||||
|
// and the gate stays shut. Dynamic targets match any concrete
|
||||||
|
// answer of theirs.
|
||||||
|
let verified = match &chain {
|
||||||
|
Some(hash) => crate::chain::lookup_node(&state.jetstream, hash)
|
||||||
|
.await
|
||||||
|
.is_some_and(|node| {
|
||||||
|
node.question_id == *target
|
||||||
|
|| path_matches(target, &node.question_id).is_some()
|
||||||
|
}),
|
||||||
|
None => false,
|
||||||
|
};
|
||||||
|
if !verified {
|
||||||
|
let name = questions
|
||||||
|
.get(target)
|
||||||
|
.map(|q| q.name.clone())
|
||||||
|
.unwrap_or_default();
|
||||||
|
chain_gate = Some((target.clone(), name));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(Some(Page {
|
||||||
|
question,
|
||||||
|
chain_gate,
|
||||||
|
}))
|
||||||
}
|
}
|
||||||
|
|
||||||
/// The content repo's branding (`site.yaml`) - title, wordmark, hero
|
/// The content repo's branding (`site.yaml`) - title, wordmark, hero
|
||||||
@@ -1681,7 +1855,9 @@ pub async fn list_qualifying_questions(
|
|||||||
.load()
|
.load()
|
||||||
.values()
|
.values()
|
||||||
.filter(|q| is_qualified(user.as_ref(), q))
|
.filter(|q| is_qualified(user.as_ref(), q))
|
||||||
.filter(|q| !q.followup || has_chain)
|
.filter(|q| !q.is_followup() || has_chain)
|
||||||
|
// A dynamic page has no URL of its own to link to.
|
||||||
|
.filter(|q| !q.is_dynamic())
|
||||||
.map(|q| (q.id.clone(), q.name.clone()))
|
.map(|q| (q.id.clone(), q.name.clone()))
|
||||||
.collect();
|
.collect();
|
||||||
out.sort();
|
out.sort();
|
||||||
@@ -1709,11 +1885,10 @@ pub async fn submit_answer(
|
|||||||
use crate::server::AppState;
|
use crate::server::AppState;
|
||||||
|
|
||||||
let state = expect_context::<AppState>();
|
let state = expect_context::<AppState>();
|
||||||
let question = state
|
// resolve_question, not a plain map get: a dynamic page's concrete
|
||||||
.questions
|
// path (what the client holds as its question id) resolves to the
|
||||||
.load()
|
// pattern page it came from.
|
||||||
.get(&question_id)
|
let question = crate::content::resolve_question(&state.questions.load(), &question_id)
|
||||||
.cloned()
|
|
||||||
.ok_or_else(|| ServerFnError::new("unknown question"))?;
|
.ok_or_else(|| ServerFnError::new("unknown question"))?;
|
||||||
|
|
||||||
let session: tower_sessions::Session = leptos_axum::extract().await?;
|
let session: tower_sessions::Session = leptos_axum::extract().await?;
|
||||||
@@ -1754,6 +1929,14 @@ pub async fn submit_answer(
|
|||||||
.await
|
.await
|
||||||
.map_err(|e| ServerFnError::new(format!("nats publish failed: {e}")))?;
|
.map_err(|e| ServerFnError::new(format!("nats publish failed: {e}")))?;
|
||||||
|
|
||||||
|
// Index the node so requires_chain pages can verify lineage.
|
||||||
|
// Best-effort: the NATS event above is the durable record.
|
||||||
|
if let Err(e) =
|
||||||
|
crate::chain::record_node(&state.jetstream, &chain_hash, &question_id, timestamp_ms).await
|
||||||
|
{
|
||||||
|
tracing::error!("failed to index chain node: {e}");
|
||||||
|
}
|
||||||
|
|
||||||
// Best-effort: a bucket-write hiccup shouldn't fail a submission the
|
// Best-effort: a bucket-write hiccup shouldn't fail a submission the
|
||||||
// NATS event has already recorded.
|
// NATS event has already recorded.
|
||||||
if let Some(bucket) = &record_as {
|
if let Some(bucket) = &record_as {
|
||||||
|
|||||||
+27
-12
@@ -108,23 +108,38 @@ fn load_aggregates_from_dir(
|
|||||||
}
|
}
|
||||||
|
|
||||||
/// The offline counterpart to `content::load_questions_from_gitea` -
|
/// The offline counterpart to `content::load_questions_from_gitea` -
|
||||||
/// same "every `*.yaml` file becomes a `Question` keyed by its own
|
/// the same recursive tree walk and `content::build_questions`
|
||||||
/// `id`" shape, just reading a local checkout instead of Gitea's API,
|
/// pipeline (derived ids, relative refs, sections, followup
|
||||||
|
/// inference), just reading a local checkout instead of Gitea's API,
|
||||||
/// for linting a branch that hasn't been pushed yet.
|
/// for linting a branch that hasn't been pushed yet.
|
||||||
fn load_from_dir(
|
fn load_from_dir(
|
||||||
dir: &str,
|
dir: &str,
|
||||||
) -> anyhow::Result<std::collections::HashMap<String, content::Question>> {
|
) -> anyhow::Result<std::collections::HashMap<String, content::Question>> {
|
||||||
let mut out = std::collections::HashMap::new();
|
let base = std::path::Path::new(dir);
|
||||||
|
let mut files = Vec::new();
|
||||||
|
collect_yaml(base, base, &mut files)?;
|
||||||
|
content::build_questions(&files)
|
||||||
|
}
|
||||||
|
|
||||||
|
fn collect_yaml(
|
||||||
|
base: &std::path::Path,
|
||||||
|
dir: &std::path::Path,
|
||||||
|
out: &mut Vec<(String, String)>,
|
||||||
|
) -> anyhow::Result<()> {
|
||||||
for entry in std::fs::read_dir(dir)? {
|
for entry in std::fs::read_dir(dir)? {
|
||||||
let entry = entry?;
|
let path = entry?.path();
|
||||||
let path = entry.path();
|
if path.is_dir() {
|
||||||
if path.extension().and_then(|e| e.to_str()) != Some("yaml") {
|
collect_yaml(base, &path, out)?;
|
||||||
continue;
|
} else if path.extension().and_then(|e| e.to_str()) == Some("yaml") {
|
||||||
|
let rel = path
|
||||||
|
.strip_prefix(base)
|
||||||
|
.expect("walked paths sit under their base")
|
||||||
|
.to_string_lossy()
|
||||||
|
.replace('\\', "/");
|
||||||
|
let raw = std::fs::read_to_string(&path)
|
||||||
|
.map_err(|e| anyhow::anyhow!("reading {}: {e}", path.display()))?;
|
||||||
|
out.push((rel, raw));
|
||||||
}
|
}
|
||||||
let raw = std::fs::read_to_string(&path)?;
|
|
||||||
let question: content::Question = serde_yaml::from_str(&raw)
|
|
||||||
.map_err(|e| anyhow::anyhow!("parsing {}: {e}", path.display()))?;
|
|
||||||
out.insert(question.id.clone(), question);
|
|
||||||
}
|
}
|
||||||
Ok(out)
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -9,6 +9,60 @@ use sha2::{Digest, Sha256};
|
|||||||
/// submitted responses, and a timestamp. Parents are sorted first so the
|
/// submitted responses, and a timestamp. Parents are sorted first so the
|
||||||
/// hash doesn't depend on the order multiple parents happened to arrive
|
/// hash doesn't depend on the order multiple parents happened to arrive
|
||||||
/// in.
|
/// in.
|
||||||
|
/// Where submitted chain nodes are indexed - hash → which question was
|
||||||
|
/// answered. Small on purpose (no responses), and shared by every
|
||||||
|
/// portal instance on the JetStream (hashes are globally unique, so
|
||||||
|
/// cross-site collisions can't happen). This is what lets
|
||||||
|
/// `requires_chain` pages verify a visitor's `?chain=` actually ends
|
||||||
|
/// at the question they claim to have answered.
|
||||||
|
pub const CHAIN_BUCKET: &str = "portal_chains";
|
||||||
|
|
||||||
|
#[derive(serde::Serialize, serde::Deserialize)]
|
||||||
|
pub struct ChainNode {
|
||||||
|
pub question_id: String,
|
||||||
|
pub timestamp_ms: i64,
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Indexes one submitted node. Best-effort by design (the caller logs
|
||||||
|
/// and continues): the NATS event is the durable record, this is a
|
||||||
|
/// lookup convenience.
|
||||||
|
pub async fn record_node(
|
||||||
|
js: &async_nats::jetstream::Context,
|
||||||
|
chain_hash: &str,
|
||||||
|
question_id: &str,
|
||||||
|
timestamp_ms: i64,
|
||||||
|
) -> anyhow::Result<()> {
|
||||||
|
let store = match js.get_key_value(CHAIN_BUCKET).await {
|
||||||
|
Ok(store) => store,
|
||||||
|
Err(_) => {
|
||||||
|
js.create_key_value(async_nats::jetstream::kv::Config {
|
||||||
|
bucket: CHAIN_BUCKET.to_string(),
|
||||||
|
..Default::default()
|
||||||
|
})
|
||||||
|
.await?
|
||||||
|
}
|
||||||
|
};
|
||||||
|
let node = ChainNode {
|
||||||
|
question_id: question_id.to_string(),
|
||||||
|
timestamp_ms,
|
||||||
|
};
|
||||||
|
store.put(chain_hash, serde_json::to_vec(&node)?.into()).await?;
|
||||||
|
Ok(())
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Looks a chain hash up - `None` covers both "no such node" and
|
||||||
|
/// "bucket not created yet" (no submissions anywhere), which read the
|
||||||
|
/// same to a `requires_chain` check: the claimed lineage can't be
|
||||||
|
/// verified, so the gate stays shut.
|
||||||
|
pub async fn lookup_node(
|
||||||
|
js: &async_nats::jetstream::Context,
|
||||||
|
chain_hash: &str,
|
||||||
|
) -> Option<ChainNode> {
|
||||||
|
let store = js.get_key_value(CHAIN_BUCKET).await.ok()?;
|
||||||
|
let bytes = store.get(chain_hash).await.ok()??;
|
||||||
|
serde_json::from_slice(&bytes).ok()
|
||||||
|
}
|
||||||
|
|
||||||
pub fn hash_node(
|
pub fn hash_node(
|
||||||
question_id: &str,
|
question_id: &str,
|
||||||
parent_hashes: &[String],
|
parent_hashes: &[String],
|
||||||
|
|||||||
+565
-39
@@ -1,35 +1,85 @@
|
|||||||
use serde::{Deserialize, Serialize};
|
use serde::{Deserialize, Serialize};
|
||||||
|
|
||||||
/// One page: a prompt plus the paths on from it. `id` doubles as the URL
|
/// One page: a prompt plus the paths on from it. The `questions/`
|
||||||
/// path it's served at ("/" is the landing page). Loaded from a plain
|
/// directory tree IS the URL tree (`index.yaml` names its directory,
|
||||||
/// YAML file per question in a content directory kept in its own git
|
/// `develop/proposal.yaml` serves `/develop/proposal`), so `id` is
|
||||||
/// repo (see ../portal-content) - editing content is a content-repo
|
/// derived from the file's path - declaring it explicitly still works
|
||||||
/// commit, not a Rust rebuild.
|
/// (and wins, with a logged warning when it disagrees) but is only
|
||||||
|
/// needed by legacy content. Loaded from plain YAML files in a content
|
||||||
|
/// directory kept in its own git repo - editing content is a
|
||||||
|
/// content-repo commit, not a Rust rebuild.
|
||||||
#[derive(Clone, Debug, Serialize, Deserialize)]
|
#[derive(Clone, Debug, Serialize, Deserialize)]
|
||||||
pub struct Question {
|
pub struct Question {
|
||||||
pub id: String,
|
/// The URL path this page is served at. Derived from the file path
|
||||||
|
/// when absent. A `[name]` segment (from a `[name].yaml` file)
|
||||||
|
/// makes this a dynamic page: `/review/[record]` serves any
|
||||||
|
/// `/review/<value>`, with the value substituted into `{record}`
|
||||||
|
/// placeholders in the page's resource keys (see
|
||||||
|
/// `resolve_question`).
|
||||||
#[serde(default)]
|
#[serde(default)]
|
||||||
pub route: Option<String>,
|
pub id: String,
|
||||||
pub name: String,
|
pub name: String,
|
||||||
#[serde(default)]
|
#[serde(default)]
|
||||||
pub description: String,
|
pub description: String,
|
||||||
/// Kanidm group required to view/submit this question - `None` means
|
/// Kanidm group required to view/submit this question - `None` means
|
||||||
/// open to anyone, matching every question today. Content-driven
|
/// open to anyone. Content-driven on purpose: a gated page like
|
||||||
/// on purpose: a gated page like "/review" is just a Question with
|
/// "/review" is just a Question with this set, not a bespoke Rust
|
||||||
/// this set, not a bespoke Rust route.
|
/// route. Inherited from the nearest ancestor `_section.yaml` when
|
||||||
|
/// not set on the question itself.
|
||||||
#[serde(default)]
|
#[serde(default)]
|
||||||
pub qualifies: Option<String>,
|
pub qualifies: Option<String>,
|
||||||
|
/// Question id (relative refs resolve against this file's
|
||||||
|
/// directory) the visitor must have answered - their `?chain=`
|
||||||
|
/// lineage's tip - to see this page. The provenance counterpart to
|
||||||
|
/// `qualifies`' identity check. Inherited from `_section.yaml`
|
||||||
|
/// like `qualifies`.
|
||||||
|
#[serde(default)]
|
||||||
|
pub requires_chain: Option<String>,
|
||||||
#[serde(default)]
|
#[serde(default)]
|
||||||
pub alternatives: Vec<Alternative>,
|
pub alternatives: Vec<Alternative>,
|
||||||
/// Who to contact if a visitor gets stuck - rendered as a small line
|
/// Who to contact if a visitor gets stuck - rendered as a small line
|
||||||
/// on the page.
|
/// on the page. Inherited from `_section.yaml` when not set.
|
||||||
#[serde(default)]
|
#[serde(default)]
|
||||||
pub responsible: Option<Responsible>,
|
pub responsible: Option<Responsible>,
|
||||||
/// A page that only makes sense after answering something (the
|
/// A page that only makes sense after answering something (the
|
||||||
/// post-submission pages) - kept out of the question nav unless the
|
/// post-submission pages) - kept out of the question nav unless the
|
||||||
/// visitor's context carries an answer chain.
|
/// visitor's context carries an answer chain. Unset means inferred
|
||||||
|
/// from the file's place in the tree: files nested in a
|
||||||
|
/// subdirectory are followups unless they're the directory's
|
||||||
|
/// `index.yaml`; top-level files keep the historical default
|
||||||
|
/// (not a followup).
|
||||||
#[serde(default)]
|
#[serde(default)]
|
||||||
pub followup: bool,
|
pub followup: Option<bool>,
|
||||||
|
}
|
||||||
|
|
||||||
|
impl Question {
|
||||||
|
pub fn is_followup(&self) -> bool {
|
||||||
|
self.followup.unwrap_or(false)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// A dynamic page - one whose id still contains a `[name]`
|
||||||
|
/// segment. Served per-value via `resolve_question`, never listed
|
||||||
|
/// in nav, never a valid `action` target.
|
||||||
|
pub fn is_dynamic(&self) -> bool {
|
||||||
|
self.id.contains('[')
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Directory-scoped defaults: a `_section.yaml` file applies to every
|
||||||
|
/// question at or below its directory (nearest ancestor wins per
|
||||||
|
/// field, and a question's own declaration always overrides). This is
|
||||||
|
/// what makes a URL prefix a trust boundary - "everything under
|
||||||
|
/// /review is owner-only" is one line in `review/_section.yaml`
|
||||||
|
/// instead of a flag per file. Underscore-prefixed files that aren't
|
||||||
|
/// `_section.yaml` are skipped entirely (drafts).
|
||||||
|
#[derive(Clone, Debug, Default, Serialize, Deserialize)]
|
||||||
|
pub struct SectionConfig {
|
||||||
|
#[serde(default)]
|
||||||
|
pub qualifies: Option<String>,
|
||||||
|
#[serde(default)]
|
||||||
|
pub requires_chain: Option<String>,
|
||||||
|
#[serde(default)]
|
||||||
|
pub responsible: Option<Responsible>,
|
||||||
}
|
}
|
||||||
|
|
||||||
#[derive(Clone, Debug, Serialize, Deserialize)]
|
#[derive(Clone, Debug, Serialize, Deserialize)]
|
||||||
@@ -479,6 +529,228 @@ pub async fn load_aggregates_from_gitea(
|
|||||||
/// startup, and again on every `CONTENT_RELOAD_SUBJECT` message (see
|
/// startup, and again on every `CONTENT_RELOAD_SUBJECT` message (see
|
||||||
/// `watch_for_reload`), over Gitea's public contents API (no auth - the
|
/// `watch_for_reload`), over Gitea's public contents API (no auth - the
|
||||||
/// content repo is public).
|
/// content repo is public).
|
||||||
|
/// The URL a file at `rel` (path relative to the questions dir, forward
|
||||||
|
/// slashes) serves: `index.yaml` names its directory, everything else
|
||||||
|
/// appends its stem.
|
||||||
|
pub fn route_from_path(rel: &str) -> String {
|
||||||
|
let stem = rel.strip_suffix(".yaml").unwrap_or(rel);
|
||||||
|
let mut segments: Vec<&str> = stem.split('/').collect();
|
||||||
|
if segments.last() == Some(&"index") {
|
||||||
|
segments.pop();
|
||||||
|
}
|
||||||
|
if segments.is_empty() {
|
||||||
|
"/".to_string()
|
||||||
|
} else {
|
||||||
|
format!("/{}", segments.join("/"))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// The directory (as a URL prefix) of the file at `rel` - the base
|
||||||
|
/// relative references resolve against.
|
||||||
|
pub fn dir_from_path(rel: &str) -> String {
|
||||||
|
match rel.rsplit_once('/') {
|
||||||
|
Some((dir, _)) => format!("/{dir}"),
|
||||||
|
None => "/".to_string(),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Resolves a possibly-relative question reference (`action:`,
|
||||||
|
/// `requires_chain:`) against the referencing file's directory:
|
||||||
|
/// `/x` is absolute, `proposed` names a sibling, `../x` climbs.
|
||||||
|
pub fn resolve_ref(base_dir: &str, reference: &str) -> String {
|
||||||
|
if reference.starts_with('/') {
|
||||||
|
return reference.to_string();
|
||||||
|
}
|
||||||
|
let mut segments: Vec<&str> = base_dir.split('/').filter(|s| !s.is_empty()).collect();
|
||||||
|
for part in reference.split('/') {
|
||||||
|
match part {
|
||||||
|
"" | "." => {}
|
||||||
|
".." => {
|
||||||
|
segments.pop();
|
||||||
|
}
|
||||||
|
s => segments.push(s),
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if segments.is_empty() {
|
||||||
|
"/".to_string()
|
||||||
|
} else {
|
||||||
|
format!("/{}", segments.join("/"))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Whether `path` matches `pattern`, capturing `[name]` segments.
|
||||||
|
/// Returns the captured (name, value) pairs on a match - empty for an
|
||||||
|
/// exact literal match.
|
||||||
|
pub fn path_matches(pattern: &str, path: &str) -> Option<Vec<(String, String)>> {
|
||||||
|
let pat: Vec<&str> = pattern.split('/').filter(|s| !s.is_empty()).collect();
|
||||||
|
let got: Vec<&str> = path.split('/').filter(|s| !s.is_empty()).collect();
|
||||||
|
if pat.len() != got.len() {
|
||||||
|
return None;
|
||||||
|
}
|
||||||
|
let mut captures = Vec::new();
|
||||||
|
for (p, g) in pat.iter().zip(got.iter()) {
|
||||||
|
if let Some(name) = p.strip_prefix('[').and_then(|s| s.strip_suffix(']')) {
|
||||||
|
if g.is_empty() {
|
||||||
|
return None;
|
||||||
|
}
|
||||||
|
captures.push((name.to_string(), (*g).to_string()));
|
||||||
|
} else if p != g {
|
||||||
|
return None;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Some(captures)
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Resolves a URL path to its question: an exact id first, else the
|
||||||
|
/// one dynamic page whose pattern matches, with each captured segment
|
||||||
|
/// substituted into `{name}` placeholders in the clone's resource keys
|
||||||
|
/// and its id set to the concrete path (so every follow-up server call
|
||||||
|
/// - resources, submissions - re-resolves the same way). The
|
||||||
|
/// substituted key is still looked up in the content-declared bucket,
|
||||||
|
/// so a visitor varies the key, never the bucket - the same trust
|
||||||
|
/// shape as a `?chain=` link, where knowing a record's key is holding
|
||||||
|
/// it.
|
||||||
|
pub fn resolve_question(
|
||||||
|
questions: &std::collections::HashMap<String, Question>,
|
||||||
|
path: &str,
|
||||||
|
) -> Option<Question> {
|
||||||
|
if let Some(q) = questions.get(path) {
|
||||||
|
return Some(q.clone());
|
||||||
|
}
|
||||||
|
for q in questions.values() {
|
||||||
|
if !q.is_dynamic() {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if let Some(captures) = path_matches(&q.id, path) {
|
||||||
|
let mut resolved = q.clone();
|
||||||
|
resolved.id = path.to_string();
|
||||||
|
let substitute = |key: &mut Option<String>| {
|
||||||
|
if let Some(k) = key {
|
||||||
|
for (name, value) in &captures {
|
||||||
|
*k = k.replace(&format!("{{{name}}}"), value);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
for alt in &mut resolved.alternatives {
|
||||||
|
for feature in &mut alt.features {
|
||||||
|
if let Some(res) = &mut feature.resource {
|
||||||
|
substitute(&mut res.key);
|
||||||
|
}
|
||||||
|
for req in &mut feature.requirements {
|
||||||
|
if let Some(res) = &mut req.resource {
|
||||||
|
substitute(&mut res.key);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return Some(resolved);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
None
|
||||||
|
}
|
||||||
|
|
||||||
|
/// Builds the question map from raw (path, yaml) files - the shared
|
||||||
|
/// back half of both loaders (Gitea tree and `question_lint --path`).
|
||||||
|
/// Applies the whole filesystem-routing contract: derived ids,
|
||||||
|
/// relative-reference resolution, followup inference, `_section.yaml`
|
||||||
|
/// inheritance, and the tree-shape rules (no id collisions, at most
|
||||||
|
/// one dynamic page per directory).
|
||||||
|
#[cfg(feature = "ssr")]
|
||||||
|
pub fn build_questions(
|
||||||
|
files: &[(String, String)],
|
||||||
|
) -> anyhow::Result<std::collections::HashMap<String, Question>> {
|
||||||
|
// Sections first: (directory prefix, config), shallowest first so a
|
||||||
|
// later (deeper) section overrides an outer one field-by-field.
|
||||||
|
let mut sections: Vec<(String, SectionConfig)> = Vec::new();
|
||||||
|
for (rel, raw) in files {
|
||||||
|
let name = rel.rsplit('/').next().unwrap_or(rel);
|
||||||
|
if name != "_section.yaml" {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
let mut section: SectionConfig = serde_yaml::from_str(raw)
|
||||||
|
.map_err(|e| anyhow::anyhow!("parsing {rel}: {e}"))?;
|
||||||
|
let dir = dir_from_path(rel);
|
||||||
|
if let Some(rc) = §ion.requires_chain {
|
||||||
|
section.requires_chain = Some(resolve_ref(&dir, rc));
|
||||||
|
}
|
||||||
|
sections.push((dir, section));
|
||||||
|
}
|
||||||
|
sections.sort_by_key(|(dir, _)| dir.len());
|
||||||
|
|
||||||
|
let mut out = std::collections::HashMap::new();
|
||||||
|
let mut dynamic_dirs = std::collections::HashSet::new();
|
||||||
|
for (rel, raw) in files {
|
||||||
|
let name = rel.rsplit('/').next().unwrap_or(rel);
|
||||||
|
// Underscore files are sections or drafts, never pages.
|
||||||
|
if name.starts_with('_') {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
let mut question: Question =
|
||||||
|
serde_yaml::from_str(raw).map_err(|e| anyhow::anyhow!("parsing {rel}: {e}"))?;
|
||||||
|
let derived = route_from_path(rel);
|
||||||
|
let dir = dir_from_path(rel);
|
||||||
|
|
||||||
|
if question.id.is_empty() {
|
||||||
|
question.id = derived.clone();
|
||||||
|
} else if question.id != derived {
|
||||||
|
tracing::warn!(
|
||||||
|
"{rel}: declared id {:?} disagrees with its path ({derived}) - the declared id wins, but consider moving the file",
|
||||||
|
question.id
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
for alt in &mut question.alternatives {
|
||||||
|
if let Some(action) = &alt.action {
|
||||||
|
alt.action = Some(resolve_ref(&dir, action));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if let Some(rc) = &question.requires_chain {
|
||||||
|
question.requires_chain = Some(resolve_ref(&dir, rc));
|
||||||
|
}
|
||||||
|
|
||||||
|
if question.followup.is_none() {
|
||||||
|
// Nested non-index files are flow steps and outcomes -
|
||||||
|
// followups by construction. Top-level files keep the
|
||||||
|
// historical flat-repo default.
|
||||||
|
let nested = rel.contains('/');
|
||||||
|
let is_index = name == "index.yaml";
|
||||||
|
question.followup = Some(nested && !is_index);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Nearest-ancestor section fills whatever the question left
|
||||||
|
// unset (walk deepest-last, so later matches override earlier
|
||||||
|
// section values but never the question's own).
|
||||||
|
for (sdir, section) in §ions {
|
||||||
|
let applies = *sdir == "/" || dir == *sdir || dir.starts_with(&format!("{sdir}/"));
|
||||||
|
if !applies {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if question.qualifies.is_none() {
|
||||||
|
question.qualifies = section.qualifies.clone();
|
||||||
|
}
|
||||||
|
if question.requires_chain.is_none() {
|
||||||
|
question.requires_chain = section.requires_chain.clone();
|
||||||
|
}
|
||||||
|
if question.responsible.is_none() {
|
||||||
|
question.responsible = section.responsible.clone();
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if question.is_dynamic() && !dynamic_dirs.insert(dir.clone()) {
|
||||||
|
anyhow::bail!(
|
||||||
|
"{rel}: more than one dynamic ([name].yaml) page in {dir} - matching would be ambiguous"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
if let Some(previous) = out.insert(question.id.clone(), question) {
|
||||||
|
anyhow::bail!(
|
||||||
|
"{rel}: id {:?} is already declared by another file",
|
||||||
|
previous.id
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Ok(out)
|
||||||
|
}
|
||||||
|
|
||||||
#[cfg(feature = "ssr")]
|
#[cfg(feature = "ssr")]
|
||||||
pub async fn load_questions_from_gitea(
|
pub async fn load_questions_from_gitea(
|
||||||
repo_url: &str,
|
repo_url: &str,
|
||||||
@@ -489,45 +761,59 @@ pub async fn load_questions_from_gitea(
|
|||||||
let api_base = gitea_api_base(repo_url)?;
|
let api_base = gitea_api_base(repo_url)?;
|
||||||
|
|
||||||
let client = openidconnect::reqwest::Client::new();
|
let client = openidconnect::reqwest::Client::new();
|
||||||
let list_url = format!("{api_base}/api/v1/repos/{owner}/{repo}/contents/{subdir}?ref={branch}");
|
// One recursive git-trees call for the whole repo instead of a
|
||||||
|
// contents listing per directory - the tree IS the router now, so
|
||||||
|
// nested files matter.
|
||||||
|
let tree_url =
|
||||||
|
format!("{api_base}/api/v1/repos/{owner}/{repo}/git/trees/{branch}?recursive=true");
|
||||||
let listing = client
|
let listing = client
|
||||||
.get(&list_url)
|
.get(&tree_url)
|
||||||
.send()
|
.send()
|
||||||
.await
|
.await
|
||||||
.map_err(|e| anyhow::anyhow!("listing {list_url}: {e}"))?
|
.map_err(|e| anyhow::anyhow!("listing {tree_url}: {e}"))?
|
||||||
.error_for_status()
|
.error_for_status()
|
||||||
.map_err(|e| anyhow::anyhow!("listing {list_url}: {e}"))?
|
.map_err(|e| anyhow::anyhow!("listing {tree_url}: {e}"))?
|
||||||
.text()
|
.text()
|
||||||
.await
|
.await
|
||||||
.map_err(|e| anyhow::anyhow!("reading directory listing from {list_url}: {e}"))?;
|
.map_err(|e| anyhow::anyhow!("reading tree from {tree_url}: {e}"))?;
|
||||||
let entries: Vec<serde_json::Value> = serde_json::from_str(&listing)
|
let tree: serde_json::Value = serde_json::from_str(&listing)
|
||||||
.map_err(|e| anyhow::anyhow!("parsing directory listing from {list_url}: {e}"))?;
|
.map_err(|e| anyhow::anyhow!("parsing tree from {tree_url}: {e}"))?;
|
||||||
|
if tree.get("truncated").and_then(|v| v.as_bool()) == Some(true) {
|
||||||
|
anyhow::bail!("git tree listing for {owner}/{repo} was truncated - repo too large");
|
||||||
|
}
|
||||||
|
let prefix = format!("{subdir}/");
|
||||||
|
|
||||||
let mut out = std::collections::HashMap::new();
|
let mut files = Vec::new();
|
||||||
for entry in entries {
|
for entry in tree
|
||||||
let name = entry.get("name").and_then(|v| v.as_str()).unwrap_or("");
|
.get("tree")
|
||||||
if !name.ends_with(".yaml") {
|
.and_then(|v| v.as_array())
|
||||||
|
.map(|v| v.as_slice())
|
||||||
|
.unwrap_or_default()
|
||||||
|
{
|
||||||
|
let path = entry.get("path").and_then(|v| v.as_str()).unwrap_or("");
|
||||||
|
if entry.get("type").and_then(|v| v.as_str()) != Some("blob")
|
||||||
|
|| !path.starts_with(&prefix)
|
||||||
|
|| !path.ends_with(".yaml")
|
||||||
|
{
|
||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
let download_url = entry
|
// Brackets (dynamic pages like `[record].yaml`) must be
|
||||||
.get("download_url")
|
// percent-encoded in the raw URL's path.
|
||||||
.and_then(|v| v.as_str())
|
let encoded = path.replace('[', "%5B").replace(']', "%5D");
|
||||||
.ok_or_else(|| anyhow::anyhow!("no download_url for {name}"))?;
|
let raw_url = format!("{api_base}/api/v1/repos/{owner}/{repo}/raw/{encoded}?ref={branch}");
|
||||||
let raw = client
|
let raw = client
|
||||||
.get(download_url)
|
.get(&raw_url)
|
||||||
.send()
|
.send()
|
||||||
.await
|
.await
|
||||||
.map_err(|e| anyhow::anyhow!("fetching {name}: {e}"))?
|
.map_err(|e| anyhow::anyhow!("fetching {path}: {e}"))?
|
||||||
.error_for_status()
|
.error_for_status()
|
||||||
.map_err(|e| anyhow::anyhow!("fetching {name}: {e}"))?
|
.map_err(|e| anyhow::anyhow!("fetching {path}: {e}"))?
|
||||||
.text()
|
.text()
|
||||||
.await
|
.await
|
||||||
.map_err(|e| anyhow::anyhow!("reading {name}: {e}"))?;
|
.map_err(|e| anyhow::anyhow!("reading {path}: {e}"))?;
|
||||||
let question: Question =
|
files.push((path[prefix.len()..].to_string(), raw));
|
||||||
serde_yaml::from_str(&raw).map_err(|e| anyhow::anyhow!("parsing {name}: {e}"))?;
|
|
||||||
out.insert(question.id.clone(), question);
|
|
||||||
}
|
}
|
||||||
Ok(out)
|
build_questions(&files)
|
||||||
}
|
}
|
||||||
|
|
||||||
/// Validates every declared transition target (`SelfTransition.to`,
|
/// Validates every declared transition target (`SelfTransition.to`,
|
||||||
@@ -546,15 +832,31 @@ pub fn validate_questions(
|
|||||||
aggregates: &std::collections::HashMap<String, crate::aggregates::AggregateSchema>,
|
aggregates: &std::collections::HashMap<String, crate::aggregates::AggregateSchema>,
|
||||||
) -> anyhow::Result<()> {
|
) -> anyhow::Result<()> {
|
||||||
for question in questions.values() {
|
for question in questions.values() {
|
||||||
|
if let Some(target) = &question.requires_chain {
|
||||||
|
if !questions.contains_key(target) {
|
||||||
|
anyhow::bail!(
|
||||||
|
"question {:?}: requires_chain {:?} does not match any declared question id",
|
||||||
|
question.id,
|
||||||
|
target
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
for alternative in &question.alternatives {
|
for alternative in &question.alternatives {
|
||||||
// A dangling action is a literal dead end: the submit
|
// A dangling action is a literal dead end: the submit
|
||||||
// button navigates to "Nothing here".
|
// button navigates to "Nothing here".
|
||||||
if let Some(action) = &alternative.action {
|
if let Some(action) = &alternative.action {
|
||||||
if !questions.contains_key(action) {
|
match questions.get(action) {
|
||||||
anyhow::bail!(
|
None => anyhow::bail!(
|
||||||
"question {:?} alternative {:?}: action {:?} does not match any declared question id",
|
"question {:?} alternative {:?}: action {:?} does not match any declared question id",
|
||||||
question.id, alternative.name, action
|
question.id, alternative.name, action
|
||||||
);
|
),
|
||||||
|
// A dynamic page needs a concrete segment value to
|
||||||
|
// be a URL - a submit button can't supply one.
|
||||||
|
Some(target) if target.is_dynamic() => anyhow::bail!(
|
||||||
|
"question {:?} alternative {:?}: action {:?} targets a dynamic page - actions must name a concrete question",
|
||||||
|
question.id, alternative.name, action
|
||||||
|
),
|
||||||
|
Some(_) => {}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if let Some(st) = &alternative.self_transition {
|
if let Some(st) = &alternative.self_transition {
|
||||||
@@ -646,6 +948,54 @@ pub fn validate_questions(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Attended buckets: no publicly collected answer may land somewhere
|
||||||
|
// nothing reads. Every `record_as` bucket must either be read back
|
||||||
|
// by some Kv resource in this same content repo (a desk or listing)
|
||||||
|
// or carry an explicit `attended_by:` annotation in aggregates.yaml
|
||||||
|
// naming the automation that consumes it. This is a contract, not a
|
||||||
|
// convention, because convention already failed once: a question
|
||||||
|
// was dropped and its bucket - answers included - silently fell out
|
||||||
|
// of every reader's view.
|
||||||
|
let mut read_buckets = std::collections::HashSet::new();
|
||||||
|
let note_resource = |spec: &ResourceSpec, set: &mut std::collections::HashSet<String>| {
|
||||||
|
if let ResourceSource::Kv { bucket } = &spec.source {
|
||||||
|
set.insert(bucket.clone());
|
||||||
|
}
|
||||||
|
};
|
||||||
|
for question in questions.values() {
|
||||||
|
for alternative in &question.alternatives {
|
||||||
|
for feature in &alternative.features {
|
||||||
|
if let Some(spec) = &feature.resource {
|
||||||
|
note_resource(spec, &mut read_buckets);
|
||||||
|
}
|
||||||
|
for requirement in &feature.requirements {
|
||||||
|
if let Some(spec) = &requirement.resource {
|
||||||
|
note_resource(spec, &mut read_buckets);
|
||||||
|
}
|
||||||
|
if let Some(bind) = &requirement.bind {
|
||||||
|
note_resource(&bind.resource, &mut read_buckets);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
for question in questions.values() {
|
||||||
|
for alternative in &question.alternatives {
|
||||||
|
if let Some(bucket) = &alternative.record_as {
|
||||||
|
let attended = read_buckets.contains(bucket)
|
||||||
|
|| aggregates
|
||||||
|
.get(bucket)
|
||||||
|
.is_some_and(|schema| schema.attended_by.is_some());
|
||||||
|
if !attended {
|
||||||
|
anyhow::bail!(
|
||||||
|
"question {:?} alternative {:?}: record_as {bucket:?} is unattended - no page reads that bucket back, and aggregates.yaml declares no attended_by for it. Add a desk/listing resource over it, or annotate the automation that consumes it.",
|
||||||
|
question.id, alternative.name
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
Ok(())
|
Ok(())
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1069,4 +1419,180 @@ alternatives:
|
|||||||
assert_eq!(site.title.as_deref(), Some("redoal"));
|
assert_eq!(site.title.as_deref(), Some("redoal"));
|
||||||
assert_eq!(site.hero.kind, "gesture");
|
assert_eq!(site.hero.kind, "gesture");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn routes_derive_from_paths() {
|
||||||
|
assert_eq!(route_from_path("index.yaml"), "/");
|
||||||
|
assert_eq!(route_from_path("applied.yaml"), "/applied");
|
||||||
|
assert_eq!(route_from_path("develop/index.yaml"), "/develop");
|
||||||
|
assert_eq!(route_from_path("develop/proposal.yaml"), "/develop/proposal");
|
||||||
|
assert_eq!(route_from_path("review/[record].yaml"), "/review/[record]");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn relative_refs_resolve_against_the_file_dir() {
|
||||||
|
assert_eq!(resolve_ref("/develop", "proposed"), "/develop/proposed");
|
||||||
|
assert_eq!(resolve_ref("/develop", "/subscribed"), "/subscribed");
|
||||||
|
assert_eq!(resolve_ref("/develop", "../applied"), "/applied");
|
||||||
|
assert_eq!(resolve_ref("/", "applied"), "/applied");
|
||||||
|
assert_eq!(resolve_ref("/", ".."), "/");
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn dynamic_patterns_capture_segments() {
|
||||||
|
assert_eq!(path_matches("/review/[record]", "/review/abc"),
|
||||||
|
Some(vec![("record".into(), "abc".into())]));
|
||||||
|
assert_eq!(path_matches("/review/[record]", "/review"), None);
|
||||||
|
assert_eq!(path_matches("/review/[record]", "/other/abc"), None);
|
||||||
|
assert_eq!(path_matches("/review", "/review"), Some(vec![]));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn tree_becomes_router_with_inference_and_sections() {
|
||||||
|
let files = vec![
|
||||||
|
("index.yaml".to_string(), "name: Home\nalternatives:\n - name: go\n action: applied\n".to_string()),
|
||||||
|
("applied.yaml".to_string(), "name: Applied\nfollowup: true\n".to_string()),
|
||||||
|
("develop/index.yaml".to_string(), "name: Develop\nalternatives:\n - name: propose\n action: proposal\n".to_string()),
|
||||||
|
("develop/proposal.yaml".to_string(), "name: Proposal\nalternatives:\n - name: send\n action: proposed\n".to_string()),
|
||||||
|
("develop/proposed.yaml".to_string(), "name: Proposed\n".to_string()),
|
||||||
|
("review/_section.yaml".to_string(), "qualifies: portal_owners\n".to_string()),
|
||||||
|
("review/index.yaml".to_string(), "name: Review\n".to_string()),
|
||||||
|
("review/_draft.yaml".to_string(), "not even valid yaml: [\n".to_string()),
|
||||||
|
];
|
||||||
|
let questions = build_questions(&files).unwrap();
|
||||||
|
|
||||||
|
// Derived ids and resolved relative actions.
|
||||||
|
assert_eq!(questions["/"].alternatives[0].action.as_deref(), Some("/applied"));
|
||||||
|
assert_eq!(
|
||||||
|
questions["/develop"].alternatives[0].action.as_deref(),
|
||||||
|
Some("/develop/proposal")
|
||||||
|
);
|
||||||
|
assert_eq!(
|
||||||
|
questions["/develop/proposal"].alternatives[0].action.as_deref(),
|
||||||
|
Some("/develop/proposed")
|
||||||
|
);
|
||||||
|
|
||||||
|
// Followup inference: nested non-index files are followups,
|
||||||
|
// index files and top-level files are not (explicit wins).
|
||||||
|
assert!(!questions["/"].is_followup());
|
||||||
|
assert!(questions["/applied"].is_followup());
|
||||||
|
assert!(!questions["/develop"].is_followup());
|
||||||
|
assert!(questions["/develop/proposal"].is_followup());
|
||||||
|
|
||||||
|
// Section inheritance gates the directory; drafts are skipped.
|
||||||
|
assert_eq!(questions["/review"].qualifies.as_deref(), Some("portal_owners"));
|
||||||
|
assert_eq!(questions["/"].qualifies, None);
|
||||||
|
assert!(!questions.contains_key("/review/_draft"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn declared_id_wins_over_path() {
|
||||||
|
let files = vec![(
|
||||||
|
"legacy.yaml".to_string(),
|
||||||
|
"id: /somewhere-else\nname: Legacy\n".to_string(),
|
||||||
|
)];
|
||||||
|
let questions = build_questions(&files).unwrap();
|
||||||
|
assert!(questions.contains_key("/somewhere-else"));
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn colliding_ids_and_ambiguous_dynamics_are_rejected() {
|
||||||
|
let collision = vec![
|
||||||
|
("a.yaml".to_string(), "name: A\n".to_string()),
|
||||||
|
("b.yaml".to_string(), "id: /a\nname: B\n".to_string()),
|
||||||
|
];
|
||||||
|
assert!(build_questions(&collision).is_err());
|
||||||
|
|
||||||
|
let ambiguous = vec![
|
||||||
|
("review/[a].yaml".to_string(), "name: A\n".to_string()),
|
||||||
|
("review/[b].yaml".to_string(), "name: B\n".to_string()),
|
||||||
|
];
|
||||||
|
assert!(build_questions(&ambiguous).is_err());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn dynamic_pages_resolve_with_key_substitution() {
|
||||||
|
let files = vec![(
|
||||||
|
"review/[record].yaml".to_string(),
|
||||||
|
"name: Record\nalternatives:\n - name: view\n features:\n - name: detail\n resource:\n public: true\n key: \"{record}\"\n source:\n kind: kv\n bucket: applicants\n".to_string(),
|
||||||
|
)];
|
||||||
|
let questions = build_questions(&files).unwrap();
|
||||||
|
let page = resolve_question(&questions, "/review/abc123").unwrap();
|
||||||
|
assert_eq!(page.id, "/review/abc123");
|
||||||
|
assert_eq!(
|
||||||
|
page.alternatives[0].features[0].resource.as_ref().unwrap().key.as_deref(),
|
||||||
|
Some("abc123")
|
||||||
|
);
|
||||||
|
assert!(resolve_question(&questions, "/review").is_none());
|
||||||
|
// The pattern itself still resolves exactly (it IS an id).
|
||||||
|
assert!(resolve_question(&questions, "/review/[record]").is_some());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn requires_chain_resolves_and_validates() {
|
||||||
|
let files = vec![
|
||||||
|
("shape.yaml".to_string(), "name: Shape\n".to_string()),
|
||||||
|
(
|
||||||
|
"shaped.yaml".to_string(),
|
||||||
|
"name: Shaped\nrequires_chain: shape\n".to_string(),
|
||||||
|
),
|
||||||
|
];
|
||||||
|
let questions = build_questions(&files).unwrap();
|
||||||
|
assert_eq!(questions["/shaped"].requires_chain.as_deref(), Some("/shape"));
|
||||||
|
assert!(validate_questions(&questions, &Default::default()).is_ok());
|
||||||
|
|
||||||
|
let dangling = vec![(
|
||||||
|
"shaped.yaml".to_string(),
|
||||||
|
"name: Shaped\nrequires_chain: /nowhere\n".to_string(),
|
||||||
|
)];
|
||||||
|
let questions = build_questions(&dangling).unwrap();
|
||||||
|
assert!(validate_questions(&questions, &Default::default()).is_err());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn recorded_buckets_must_be_attended() {
|
||||||
|
let write_only = vec![(
|
||||||
|
"index.yaml".to_string(),
|
||||||
|
"name: Home\nalternatives:\n - name: send\n record_as: black_hole\n".to_string(),
|
||||||
|
)];
|
||||||
|
let questions = build_questions(&write_only).unwrap();
|
||||||
|
let err = validate_questions(&questions, &Default::default()).unwrap_err();
|
||||||
|
assert!(err.to_string().contains("unattended"), "got: {err}");
|
||||||
|
|
||||||
|
// A desk (any Kv resource over the bucket, anywhere in the
|
||||||
|
// repo) attends it.
|
||||||
|
let with_desk = vec![
|
||||||
|
(
|
||||||
|
"index.yaml".to_string(),
|
||||||
|
"name: Home\nalternatives:\n - name: send\n record_as: inbox\n".to_string(),
|
||||||
|
),
|
||||||
|
(
|
||||||
|
"review/index.yaml".to_string(),
|
||||||
|
"name: Desk\nalternatives:\n - name: Inbox\n features:\n - name: \"\"\n resource:\n requires_group: owners\n source:\n kind: kv\n bucket: inbox\n".to_string(),
|
||||||
|
),
|
||||||
|
];
|
||||||
|
let questions = build_questions(&with_desk).unwrap();
|
||||||
|
assert!(validate_questions(&questions, &Default::default()).is_ok());
|
||||||
|
|
||||||
|
// ..or an explicit attended_by annotation in aggregates.yaml.
|
||||||
|
let aggregates = crate::aggregates::parse_aggregates_yaml(
|
||||||
|
"aggregates:\n - bucket: black_hole\n initial: open\n attended_by: n8n nightly digest\n states:\n open: { event: submitted }\n",
|
||||||
|
)
|
||||||
|
.unwrap();
|
||||||
|
let questions = build_questions(&write_only).unwrap();
|
||||||
|
assert!(validate_questions(&questions, &aggregates).is_ok());
|
||||||
|
}
|
||||||
|
|
||||||
|
#[test]
|
||||||
|
fn actions_may_not_target_dynamic_pages() {
|
||||||
|
let files = vec![
|
||||||
|
(
|
||||||
|
"index.yaml".to_string(),
|
||||||
|
"name: Home\nalternatives:\n - name: go\n action: /review/[record]\n".to_string(),
|
||||||
|
),
|
||||||
|
("review/[record].yaml".to_string(), "name: Record\n".to_string()),
|
||||||
|
];
|
||||||
|
let questions = build_questions(&files).unwrap();
|
||||||
|
assert!(validate_questions(&questions, &Default::default()).is_err());
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+31
-1
@@ -129,6 +129,10 @@ async fn main() -> anyhow::Result<()> {
|
|||||||
let favicon_dark_path = format!("{}/favicon-dark.svg", leptos_options.site_root);
|
let favicon_dark_path = format!("{}/favicon-dark.svg", leptos_options.site_root);
|
||||||
let wordmark_path = format!("{}/wordmark.svg", leptos_options.site_root);
|
let wordmark_path = format!("{}/wordmark.svg", leptos_options.site_root);
|
||||||
let swiper_path = format!("{}/swiper-element-bundle.min.js", leptos_options.site_root);
|
let swiper_path = format!("{}/swiper-element-bundle.min.js", leptos_options.site_root);
|
||||||
|
// yes.js sits in public/ (not a wasm-bindgen snippet) so the
|
||||||
|
// hero's inline early-mount script and the wasm binding can share
|
||||||
|
// one stable URL - see `mod yes` in app.rs.
|
||||||
|
let yes_path = format!("{}/yes.js", leptos_options.site_root);
|
||||||
let fonts_dir = format!("{}/fonts", leptos_options.site_root);
|
let fonts_dir = format!("{}/fonts", leptos_options.site_root);
|
||||||
|
|
||||||
let app = Router::new()
|
let app = Router::new()
|
||||||
@@ -139,7 +143,22 @@ async fn main() -> anyhow::Result<()> {
|
|||||||
.route("/upload", post(upload::upload))
|
.route("/upload", post(upload::upload))
|
||||||
.route("/gitea-repo", get(content::gitea_repo_handler))
|
.route("/gitea-repo", get(content::gitea_repo_handler))
|
||||||
.route("/automation/kv/{bucket}", get(content::automation_kv_handler))
|
.route("/automation/kv/{bucket}", get(content::automation_kv_handler))
|
||||||
.nest_service("/pkg", ServeDir::new(pkg_dir))
|
// no-cache = "revalidate before reuse", not "don't cache":
|
||||||
|
// pkg files keep the same names across releases (portal.js,
|
||||||
|
// portal.wasm), and without this browsers heuristically cache
|
||||||
|
// them - a stale wasm from the previous release then talks to
|
||||||
|
// a server whose server-fn wire format has moved on and every
|
||||||
|
// page renders as its error branch. A 304 per load is the
|
||||||
|
// price of never shipping that skew again.
|
||||||
|
.nest_service(
|
||||||
|
"/pkg",
|
||||||
|
tower::ServiceBuilder::new()
|
||||||
|
.layer(tower_http::set_header::SetResponseHeaderLayer::overriding(
|
||||||
|
axum::http::header::CACHE_CONTROL,
|
||||||
|
axum::http::HeaderValue::from_static("no-cache"),
|
||||||
|
))
|
||||||
|
.service(ServeDir::new(pkg_dir)),
|
||||||
|
)
|
||||||
.nest_service("/fonts", ServeDir::new(fonts_dir))
|
.nest_service("/fonts", ServeDir::new(fonts_dir))
|
||||||
.route_service("/favicon-light.svg", ServeFile::new(favicon_light_path))
|
.route_service("/favicon-light.svg", ServeFile::new(favicon_light_path))
|
||||||
.route_service("/favicon-dark.svg", ServeFile::new(favicon_dark_path))
|
.route_service("/favicon-dark.svg", ServeFile::new(favicon_dark_path))
|
||||||
@@ -148,6 +167,17 @@ async fn main() -> anyhow::Result<()> {
|
|||||||
"/swiper-element-bundle.min.js",
|
"/swiper-element-bundle.min.js",
|
||||||
ServeFile::new(swiper_path),
|
ServeFile::new(swiper_path),
|
||||||
)
|
)
|
||||||
|
// Same skew concern as /pkg: the wasm's raw_module import and
|
||||||
|
// the hero's inline script both load this by fixed name.
|
||||||
|
.route_service(
|
||||||
|
"/yes.js",
|
||||||
|
tower::ServiceBuilder::new()
|
||||||
|
.layer(tower_http::set_header::SetResponseHeaderLayer::overriding(
|
||||||
|
axum::http::header::CACHE_CONTROL,
|
||||||
|
axum::http::HeaderValue::from_static("no-cache"),
|
||||||
|
))
|
||||||
|
.service(ServeFile::new(yes_path)),
|
||||||
|
)
|
||||||
.leptos_routes_with_context(
|
.leptos_routes_with_context(
|
||||||
&state,
|
&state,
|
||||||
routes,
|
routes,
|
||||||
|
|||||||
+6
-5
@@ -122,11 +122,12 @@ fn find_feature(
|
|||||||
alternative: &str,
|
alternative: &str,
|
||||||
feature_name: &str,
|
feature_name: &str,
|
||||||
) -> Result<crate::content::Feature, ServerFnError> {
|
) -> Result<crate::content::Feature, ServerFnError> {
|
||||||
let question = state
|
// resolve_question, not a plain map get: a dynamic page's client
|
||||||
.questions
|
// holds its concrete path as the question id, and resolution is
|
||||||
.load()
|
// also what substitutes the URL segment into the page's resource
|
||||||
.get(question_id)
|
// keys - so this lookup is where a `/review/<record>` page's
|
||||||
.cloned()
|
// feature acquires its record-specific key.
|
||||||
|
let question = crate::content::resolve_question(&state.questions.load(), question_id)
|
||||||
.ok_or_else(|| ServerFnError::new("unknown question"))?;
|
.ok_or_else(|| ServerFnError::new("unknown question"))?;
|
||||||
question
|
question
|
||||||
.alternatives
|
.alternatives
|
||||||
|
|||||||
@@ -270,6 +270,11 @@ main.not-found {
|
|||||||
position: relative;
|
position: relative;
|
||||||
width: 100%;
|
width: 100%;
|
||||||
max-width: 46rem;
|
max-width: 46rem;
|
||||||
|
/* Same jump-avoidance as .gesture-wrap: the canvas (55svh tall)
|
||||||
|
only exists after hydration, so hold its height open from the
|
||||||
|
first paint. Plain-vh fallback first, like the canvas itself. */
|
||||||
|
min-height: 55vh;
|
||||||
|
min-height: 55svh;
|
||||||
}
|
}
|
||||||
|
|
||||||
.hero-gesture .gesture-canvas {
|
.hero-gesture .gesture-canvas {
|
||||||
@@ -559,6 +564,11 @@ textarea:focus {
|
|||||||
custom properties - so palette changes go there AND here. */
|
custom properties - so palette changes go there AND here. */
|
||||||
.gesture-wrap {
|
.gesture-wrap {
|
||||||
position: relative;
|
position: relative;
|
||||||
|
/* The canvas is created by JS only after wasm hydration - reserve
|
||||||
|
its 3/2 box now so content below doesn't jump when it appears.
|
||||||
|
aspect-ratio is a preferred size, so the box still grows when the
|
||||||
|
echo thumbnail strip shows up under the canvas. */
|
||||||
|
aspect-ratio: 3 / 2;
|
||||||
}
|
}
|
||||||
|
|
||||||
.gesture-canvas {
|
.gesture-canvas {
|
||||||
|
|||||||
Reference in New Issue
Block a user