Compare commits
24
Commits
build-2b593ba
...
v0.3.3
@@ -1,14 +1,16 @@
|
||||
name: Publish release
|
||||
|
||||
# Portal no longer deploys itself. Each content repo (uhhm/questions,
|
||||
# redoal/questions) owns its instance - domain, port, env, Caddy route -
|
||||
# and its deploy workflow downloads a pinned release published here.
|
||||
# Rolling a new portal version out to a site = bumping PORTAL_RELEASE
|
||||
# in that site's .gitea/workflows/deploy.yml (an auditable commit).
|
||||
# Portal does not deploy itself. Cutting a version is deliberate:
|
||||
# `cargo release <level>` bumps Cargo.toml, commits, tags v<semver>,
|
||||
# and pushes; this workflow reacts to the tag and publishes the
|
||||
# artifact as a Gitea release. Each content repo (uhhm/questions,
|
||||
# redoal/questions) pins PORTAL_RELEASE to one of these tags in its
|
||||
# own deploy workflow - bumping the pin there is what rolls a version
|
||||
# out to a site. Plain main pushes only run test.yml.
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
tags: ["v*"]
|
||||
|
||||
jobs:
|
||||
publish:
|
||||
@@ -62,37 +64,41 @@ jobs:
|
||||
- name: Package
|
||||
run: |
|
||||
set -euo pipefail
|
||||
tag="build-$(echo ${{ github.sha }} | cut -c1-7)"
|
||||
echo "TAG=$tag" >> "$GITHUB_ENV"
|
||||
tag="${{ github.ref_name }}"
|
||||
stage=$(mktemp -d)
|
||||
cp "$CARGO_TARGET_DIR/release/portal" "$stage/portal"
|
||||
cp "$CARGO_TARGET_DIR/release/question_lint" "$stage/question_lint"
|
||||
# hash-files = true: leptos resolves hash.txt next to the running
|
||||
# binary, so it ships beside portal in the release dir.
|
||||
cp "$CARGO_TARGET_DIR/release/hash.txt" "$stage/hash.txt"
|
||||
# site-root ("target/site" in Cargo.toml) is project-relative,
|
||||
# not affected by CARGO_TARGET_DIR - only the plain `cargo build`
|
||||
# outputs (release/, front/) move with that override.
|
||||
cp -r target/site "$stage/site"
|
||||
tar -C "$stage" -czf "portal-$tag.tar.gz" portal question_lint site
|
||||
tar -C "$stage" -czf "portal-$tag.tar.gz" portal question_lint hash.txt site
|
||||
rm -rf "$stage"
|
||||
|
||||
# The run's own ephemeral token has write access to this repo -
|
||||
# no long-lived PAT to manage. Re-running a build for the same sha
|
||||
# finds the existing release instead of failing on the tag.
|
||||
# no long-lived PAT to manage. The tag already exists (cargo
|
||||
# release pushed it), so the release attaches to it; a re-run
|
||||
# finds the existing release instead of failing.
|
||||
- name: Publish release
|
||||
run: |
|
||||
set -euo pipefail
|
||||
tag="${{ github.ref_name }}"
|
||||
api="${{ github.server_url }}/api/v1/repos/${{ github.repository }}"
|
||||
auth="Authorization: token ${{ secrets.GITHUB_TOKEN }}"
|
||||
subject=$(git log -1 --format=%s)
|
||||
body=$(printf '{"tag_name":"%s","target_commitish":"%s","name":"%s"}' \
|
||||
"$TAG" "${{ github.sha }}" "$TAG: $(echo "$subject" | sed 's/"/\\"/g')")
|
||||
body=$(printf '{"tag_name":"%s","name":"%s"}' \
|
||||
"$tag" "$tag: $(echo "$subject" | sed 's/"/\\"/g')")
|
||||
id=$(curl -sf -X POST -H "$auth" -H 'Content-Type: application/json' \
|
||||
-d "$body" "$api/releases" | jq .id) \
|
||||
|| id=$(curl -sf -H "$auth" "$api/releases/tags/$TAG" | jq .id)
|
||||
|| id=$(curl -sf -H "$auth" "$api/releases/tags/$tag" | jq .id)
|
||||
# Replace the asset if a re-run already uploaded one.
|
||||
for aid in $(curl -sf -H "$auth" "$api/releases/$id/assets" | jq '.[].id'); do
|
||||
curl -sf -X DELETE -H "$auth" "$api/releases/$id/assets/$aid"
|
||||
done
|
||||
curl -sf -X POST -H "$auth" \
|
||||
-F "attachment=@portal-$TAG.tar.gz" \
|
||||
"$api/releases/$id/assets?name=portal-$TAG.tar.gz" > /dev/null
|
||||
echo "published $TAG"
|
||||
-F "attachment=@portal-$tag.tar.gz" \
|
||||
"$api/releases/$id/assets?name=portal-$tag.tar.gz" > /dev/null
|
||||
echo "published $tag"
|
||||
@@ -0,0 +1,26 @@
|
||||
name: Test
|
||||
|
||||
# Publishing only happens on v* tags (publish.yml), so this is what
|
||||
# keeps plain main pushes honest between releases.
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [main]
|
||||
pull_request:
|
||||
|
||||
jobs:
|
||||
test:
|
||||
runs-on: bare
|
||||
env:
|
||||
# Same shared-toolchain/cache story as publish.yml.
|
||||
CARGO_HOME: /var/local/cargo
|
||||
RUSTUP_HOME: /var/local/rustup
|
||||
PATH: /var/local/cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/bin
|
||||
SCCACHE_DIR: /var/local/sccache
|
||||
SCCACHE_SERVER_PORT: "4228"
|
||||
CARGO_TARGET_DIR: /var/local/cargo-target
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Test
|
||||
run: cargo test --features ssr
|
||||
Generated
+1
-1
@@ -2948,7 +2948,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "portal"
|
||||
version = "0.1.0"
|
||||
version = "0.3.3"
|
||||
dependencies = [
|
||||
"anyhow",
|
||||
"arc-swap",
|
||||
|
||||
+17
-2
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "portal"
|
||||
version = "0.1.0"
|
||||
version = "0.3.3"
|
||||
edition = "2021"
|
||||
|
||||
[lib]
|
||||
@@ -19,7 +19,7 @@ axum = { version = "0.8", features = ["multipart"], optional = true }
|
||||
aws-sdk-s3 = { version = "1", optional = true }
|
||||
tokio = { version = "1", features = ["rt-multi-thread", "macros", "signal"], optional = true }
|
||||
tower = { version = "0.5", optional = true }
|
||||
tower-http = { version = "0.6", features = ["fs"], optional = true }
|
||||
tower-http = { version = "0.6", features = ["fs", "set-header"], optional = true }
|
||||
tower-sessions = { version = "0.14", optional = true }
|
||||
async-nats = { version = "0.38", optional = true }
|
||||
arc-swap = { version = "1", optional = true }
|
||||
@@ -131,3 +131,18 @@ bin-default-features = false
|
||||
lib-features = ["hydrate"]
|
||||
lib-default-features = false
|
||||
lib-profile-release = "wasm-release"
|
||||
# Content-hashed pkg names (portal.<hash>.js/wasm/css) + hash.txt: a
|
||||
# freshly served page can never reference a stale cached bundle - an
|
||||
# iPhone kept a heuristically-cached portal.js across three releases
|
||||
# and paired it with new wasm, silently killing hydration. Runtime
|
||||
# needs LEPTOS_HASH_FILES=true (set in each content repo's deploy env).
|
||||
hash-files = true
|
||||
|
||||
# cargo release <level> is how a portal version is cut: bump, commit,
|
||||
# tag v{{version}}, push. CI (publish.yml) reacts to the tag and
|
||||
# publishes the release artifact; nothing on crates.io.
|
||||
[package.metadata.release]
|
||||
publish = false
|
||||
push = true
|
||||
tag-name = "v{{version}}"
|
||||
pre-release-commit-message = "Release {{version}}"
|
||||
|
||||
@@ -1,17 +1,44 @@
|
||||
# portal
|
||||
|
||||
The question runtime behind [uhhm.no](https://uhhm.no). Every page,
|
||||
form, review desk, and state machine it serves is declared in the
|
||||
[`questions`](https://project.uhhm.no/uhhm/questions) content repo —
|
||||
this codebase is the engine that renders, enforces, and records, and
|
||||
it special-cases none of it.
|
||||
A content-driven question engine: one Rust binary that turns a Git
|
||||
repo of YAML into a live site — pages, forms, review desks, and state
|
||||
machines, with a durable event-sourced record of every answer
|
||||
underneath. The engine special-cases nothing: everything a site
|
||||
serves is declared in its content repo, and the same build serves any
|
||||
number of sites.
|
||||
|
||||
Point an instance at a content repo and that repo *is* the site:
|
||||
pages, copy, state graphs, branding, and even the landing hero
|
||||
(`site.yaml`: title, wordmark, and `hero: {kind: module, module:
|
||||
hero.js}` — a JavaScript module the content repo ships, served
|
||||
same-origin at `/site/<path>`, that portal mounts at parse time and
|
||||
stops on navigation; the YES canvas and redoal's sine swings are both
|
||||
content, not engine). Content
|
||||
pushes hot-reload every running instance; instances differ only by
|
||||
env vars. [uhhm.no](https://uhhm.no)
|
||||
([uhhm/questions](https://project.uhhm.no/uhhm/questions)) and
|
||||
[redoal.com](https://redoal.com)
|
||||
([redoal/questions](https://project.uhhm.no/redoal/questions)) are
|
||||
two faces of the same binary, deployed from the same release
|
||||
artifact.
|
||||
|
||||
It composes with the surrounding stack rather than bundling it: Gitea
|
||||
hosts and serves the content, NATS JetStream stores events and
|
||||
projections, Kanidm provides identity, and anything downstream
|
||||
(automations, newsletters, onboarding) subscribes to the answer
|
||||
stream.
|
||||
|
||||
## What the engine provides
|
||||
|
||||
- **Content-driven pages** (`src/content.rs`, `src/app.rs`): YAML
|
||||
loaded from Gitea at boot and hot-swapped on a NATS reload signal;
|
||||
a bad push keeps the last-good content serving. A page's `id` is
|
||||
its URL; `qualifies` gates it to a Kanidm group.
|
||||
a bad push keeps the last-good content serving. The `questions/`
|
||||
tree IS the router — file paths become URLs, `_section.yaml`
|
||||
applies criteria to a whole directory, `[name].yaml` pages serve
|
||||
any `/dir/<value>` with the segment fed into resource keys, and
|
||||
`requires_chain` gates a page on verifiable answer provenance next
|
||||
to `qualifies`' Kanidm-group identity gate (see
|
||||
`docs/design/filesystem-routes.md`).
|
||||
- **State machines as content** (`src/aggregates/`): `aggregates.yaml`
|
||||
declares each bucket's states and legal transitions; the engine
|
||||
replays a record's event history and refuses undeclared moves, with
|
||||
@@ -28,8 +55,13 @@ it special-cases none of it.
|
||||
lineage; `?chain=` links carry it, and self-service transitions
|
||||
(unsubscribe) authorize by holding one.
|
||||
- **Live resources** (`src/resource.rs`): content can pull a KV
|
||||
bucket, Gitea starred/org repos, or any public JSON URL (SSRF
|
||||
fail-closed), reshaped by a content-declared `jq` filter.
|
||||
bucket, Gitea starred/org repos/releases, or any public JSON URL
|
||||
(SSRF fail-closed), reshaped by a content-declared `jq` filter.
|
||||
- **Input kinds as content**: a requirement's `type:` picks the
|
||||
widget — plain fields, a rich-text editor, or a `gesture` drawing
|
||||
canvas that can connect to a redoal relay so similar strokes echo
|
||||
between visitors live. Submitted values are arbitrary JSON; the
|
||||
engine records what the widget produced.
|
||||
- **Review desks**: any Kv resource with `transitions` renders rows
|
||||
with per-state action buttons and one shared confirm per
|
||||
alternative — owners walk records through their graphs without
|
||||
@@ -38,9 +70,10 @@ it special-cases none of it.
|
||||
## Binaries
|
||||
|
||||
- `portal` — the server (Leptos SSR + hydrate, Axum underneath).
|
||||
- `question_lint` — headless content validation, run by the
|
||||
`questions` repo's CI against a prebuilt copy this repo's deploy
|
||||
publishes; also works offline: `question_lint --path <dir>`.
|
||||
- `question_lint` — headless content validation, shipped inside every
|
||||
release artifact so each content repo's CI lints with the exact
|
||||
portal version its instance runs; also works offline:
|
||||
`question_lint --path <dir>`.
|
||||
|
||||
## Development
|
||||
|
||||
@@ -50,17 +83,58 @@ cargo test --features ssr # engine tests
|
||||
cargo build --features ssr --bin question_lint
|
||||
```
|
||||
|
||||
Runtime configuration is env vars (see `src/main.rs` and
|
||||
`.gitea/workflows/deploy.yml`): `NATS_URL`, `CONTENT_REPO`/
|
||||
`CONTENT_BRANCH`, Kanidm OIDC (`KANIDM_URL`, `OAUTH2_CLIENT_*`),
|
||||
optional `GARAGE_*` for uploads, `GITEA_API_TOKEN` for authenticated
|
||||
resource pulls, `AUTOMATION_READ_TOKEN` for the automation KV read
|
||||
endpoint.
|
||||
Runtime configuration is env vars (see `src/main.rs`, and each
|
||||
content repo's `.gitea/workflows/deploy.yml` for the values in
|
||||
production): `NATS_URL`, `CONTENT_REPO`/`CONTENT_BRANCH`, Kanidm OIDC
|
||||
(`KANIDM_URL`, `OAUTH2_CLIENT_*`), optional `GARAGE_*` for uploads,
|
||||
`GITEA_API_TOKEN` for authenticated resource pulls,
|
||||
`AUTOMATION_READ_TOKEN` for the automation KV read endpoint.
|
||||
|
||||
## Deploy
|
||||
## Release and deploy
|
||||
|
||||
Pushing `main` triggers `.gitea/workflows/deploy.yml` on the
|
||||
bare-metal runner: release build, ship to
|
||||
`/srv/app/uhhm-portal/releases/<sha>`, flip the `current` symlink,
|
||||
restart `app@uhhm-portal`, reload Caddy. Content changes never come
|
||||
through here — they hot-reload live from the `questions` repo.
|
||||
Portal doesn't deploy itself — it publishes versions, and each site
|
||||
decides when to take one. The whole day-to-day surface is two
|
||||
commands:
|
||||
|
||||
**Cut a release** (here):
|
||||
|
||||
```sh
|
||||
cargo release patch # or minor / major
|
||||
```
|
||||
|
||||
That bumps `Cargo.toml`, tags `v<version>`, and pushes; CI
|
||||
(`.gitea/workflows/publish.yml`) reacts to the tag, builds once, and
|
||||
attaches `portal-v<version>.tar.gz` (`portal` + `question_lint` +
|
||||
`hash.txt` + `site/`) to the Gitea release. Pkg files are
|
||||
content-hashed (`hash-files = true`; instances run with
|
||||
`LEPTOS_HASH_FILES=true`), so a freshly served page can never pair a
|
||||
stale cached bundle with new wasm. Plain pushes to `main` only run the
|
||||
tests (`test.yml`) — nothing reaches production from this repo.
|
||||
|
||||
**Roll it out** (in a content repo): edit one line in that repo's
|
||||
`.gitea/workflows/deploy.yml` —
|
||||
|
||||
```yaml
|
||||
env:
|
||||
PORTAL_RELEASE: v0.1.1 # <- bump, commit, push
|
||||
```
|
||||
|
||||
Its CI downloads the pinned artifact, ships
|
||||
`/srv/app/<instance>/releases/<tag>`, flips `current`, rewrites the
|
||||
instance env from that repo's own Actions variables/secrets, restarts
|
||||
`app@<instance>`, and refreshes the Caddy route. Every rollout is a
|
||||
commit, so reverting a bad version is `git revert` + push. Sites
|
||||
upgrade independently: uhhm.no (uhhm/questions → `app@uhhm-portal`,
|
||||
:3010) and redoal.com (redoal/questions → `app@redoal-portal`,
|
||||
:3020) can pin different versions.
|
||||
|
||||
Content changes never come through any of this — they hot-reload
|
||||
live from the content repos over NATS.
|
||||
|
||||
**Add a site**: new content repo with a copy of an existing
|
||||
`deploy.yml` (change `INSTANCE`, port, domains), Actions variables
|
||||
(`KANIDM_URL`, `OAUTH2_CLIENT_ID`, `PUBLIC_URL`, `SITE_NAME`) and
|
||||
secrets (`NATS_URL`, `OAUTH2_CLIENT_SECRET`,
|
||||
`PORTAL_GITEA_API_TOKEN` — Gitea reserves the `GITEA_` prefix for
|
||||
secret names), a Kanidm OAuth2 client, and DNS. `site.yaml` in the
|
||||
content repo handles all branding; no portal changes needed.
|
||||
|
||||
@@ -0,0 +1,133 @@
|
||||
# Filesystem routes, sections, and where chains fit
|
||||
|
||||
Status: implemented in v0.2.0 (2026-08-24) — all three phases, with
|
||||
one deviation: dynamic-page params substitute into resource keys via
|
||||
server-side `resolve_question` at lookup time (get_question,
|
||||
find_feature, submit_answer all resolve concrete paths), so no param
|
||||
threading exists client-side. The user-facing routing contract is
|
||||
documented in uhhm/questions' README ("Routing: the tree is the
|
||||
router"); this file stays as the design rationale.
|
||||
|
||||
## What exists today, precisely
|
||||
|
||||
- A question's `id` doubles as its URL. Filenames are meaningless:
|
||||
`questions/` is loaded as a **flat** directory (both the Gitea
|
||||
loader and `question_lint --path`), every `*.yaml` becomes a
|
||||
`Question` keyed by its own declared `id`.
|
||||
- Hierarchy exists only as strings: `action: /proposed` edges, plus a
|
||||
manual `followup: true` flag that hides post-submission pages from
|
||||
the nav. The graph is invisible in a repo listing — you open every
|
||||
file to learn the flow. (uhhm's actual graph: `/` fans out to three
|
||||
followups; `/develop` → `/develop-proposal` → `/proposed` is a
|
||||
two-step flow flattened into three top-level files.)
|
||||
- Criteria are per-file: `qualifies: <kanidm-group>` on a question,
|
||||
`requires_group` on a resource. Gating a whole area means
|
||||
repeating the flag in every file of that area.
|
||||
- Chains are query-string lineage: submitting hashes
|
||||
`(question, parents, responses, ts)` into `chain_hash`, the next
|
||||
page is `action + ?chain=<hash>`, and holding a chain is itself a
|
||||
capability (`self_transition` + email second factor). `chain.rs`
|
||||
reserves DAG shape (multiple parents) but nothing produces it yet.
|
||||
- `Question.route` is a declared-but-never-read field — a fossil of
|
||||
this exact idea.
|
||||
|
||||
## The proposal, in three phases
|
||||
|
||||
### Phase 1 — the tree is the router
|
||||
|
||||
Directory structure becomes the URL structure, next-js style:
|
||||
|
||||
```
|
||||
questions/
|
||||
index.yaml → /
|
||||
applied.yaml → /applied
|
||||
develop/
|
||||
index.yaml → /develop
|
||||
proposal.yaml → /develop/proposal
|
||||
proposed.yaml → /develop/proposed
|
||||
review/
|
||||
index.yaml → /review
|
||||
```
|
||||
|
||||
- `id:` becomes optional and **derived from the path** (`index.yaml`
|
||||
names its directory). An explicit `id:` still wins so both content
|
||||
repos keep working unchanged; lint warns when it disagrees with the
|
||||
path, and the field can retire later along with `route`.
|
||||
- `action:` accepts **relative references**: `action: proposed`
|
||||
resolves against the file's directory, `action: /subscribed` stays
|
||||
absolute. Resolution happens at load time, so validation and the
|
||||
runtime see absolute ids exactly as today. A flow directory becomes
|
||||
self-contained: rename `develop/` and every internal edge moves
|
||||
with it.
|
||||
- **`followup:` is inferred**: `index.yaml` files are nav pages,
|
||||
non-index files are followups unless they say `nav: true`. This
|
||||
matches the real content exactly (uhhm's four `followup: true`
|
||||
files are precisely its non-index leaf pages) and deletes a flag
|
||||
people must remember.
|
||||
- Loader: switch from the per-directory contents API to Gitea's git
|
||||
trees API (`/git/trees/{branch}?recursive=true`) — one request for
|
||||
the whole tree instead of one per directory, which the flat loader
|
||||
should be using anyway.
|
||||
|
||||
### Phase 2 — sections: criteria scoped by URL prefix
|
||||
|
||||
A `_section.yaml` in any directory applies to everything beneath it
|
||||
(underscore = not a page, like next's private folders):
|
||||
|
||||
```
|
||||
questions/review/_section.yaml:
|
||||
qualifies: portal_owners
|
||||
responsible: { name: Bendik, contact: … }
|
||||
```
|
||||
|
||||
This is the URL/criteria interplay actually worth having: **a URL
|
||||
prefix becomes a trust boundary**. "Everything under /review is
|
||||
owner-only" is one line in one place, instead of a flag per file that
|
||||
drifts. Per-question `qualifies` still overrides (tighter or looser —
|
||||
lint should warn on looser). Sections are also the natural home for
|
||||
shared `responsible` contacts and, later, per-section branding
|
||||
accents.
|
||||
|
||||
### Phase 3 — dynamic segments, and chains stay out of the path
|
||||
|
||||
Two criteria axes exist: **who you are** (Kanidm group) and **what
|
||||
you've done** (holding a chain). Phase 2 scopes the first by prefix;
|
||||
phase 3 does the same for the second, plus gives records addresses:
|
||||
|
||||
- `[record].yaml` — a dynamic segment, one YAML file rendered per
|
||||
record: `questions/review/[record].yaml` serves `/review/<key>`,
|
||||
with the param available to the page's `ResourceSpec.key`. Today a
|
||||
single record is only reachable through a desk row or a
|
||||
`?chain=` link; this gives every record a real, gated URL —
|
||||
linkable from review desks, automations, and n8n notifications.
|
||||
- `requires_chain: <question-ref>` (page- or section-level): the page
|
||||
only renders for a visitor whose chain tip answers the referenced
|
||||
question. Today's followup pages are soft-hidden (out of nav) but
|
||||
fully reachable; this makes "you must have come from X" an actual
|
||||
criterion, declared with a relative ref like actions are.
|
||||
|
||||
**Deliberately not proposed: encoding the chain in the path.** The
|
||||
page tree is static structure; the chain is runtime lineage and a
|
||||
bearer capability. Putting it in the path makes it look canonical and
|
||||
shareable — exactly what a capability URL shouldn't invite — and a
|
||||
DAG (the reserved multi-parent shape) doesn't linearize into a path
|
||||
anyway. `?chain=` stays a query parameter: pages keep one canonical
|
||||
URL, lineage rides along only when it's actually held.
|
||||
|
||||
## Migration
|
||||
|
||||
Phase 1 is fully backward compatible (explicit `id` wins, flat repos
|
||||
are just trees of depth one). The content repos migrate by `git mv`:
|
||||
uhhm's develop flow nests under `develop/`, its followups either stay
|
||||
top-level (`/applied` keeps its URL) or move with their flows if URL
|
||||
churn is acceptable; redoal's three files are already the tree. Lint
|
||||
learns the same resolution rules in the same commit, so a bad
|
||||
reference stays a caught push, never a 404.
|
||||
|
||||
## Order of value
|
||||
|
||||
Phase 1 is cheap and pays immediately (the repo listing becomes the
|
||||
sitemap). Phase 2 is small and unlocks gated areas properly. Phase 3
|
||||
is the real feature work — `[record]` pages change what desks and
|
||||
automations can link to — and can wait until something concrete needs
|
||||
it.
|
||||
+6
-28
@@ -42,14 +42,12 @@ const RECONNECT_BASE_MS = 1000;
|
||||
const RECONNECT_MAX_MS = 30000;
|
||||
|
||||
class GestureWidget {
|
||||
constructor(container, hidden, relayUrl, hero) {
|
||||
constructor(container, hidden, relayUrl) {
|
||||
this.container = container;
|
||||
this.hidden = hidden || null;
|
||||
this.relayUrl = relayUrl || '';
|
||||
this.hero = !!hero;
|
||||
this.points = [];
|
||||
this.ghost = null;
|
||||
this.ambient = []; // hero mode: echoed strokes drawn in place
|
||||
this.drawing = false;
|
||||
this.stopped = false;
|
||||
this.ws = null;
|
||||
@@ -60,11 +58,9 @@ class GestureWidget {
|
||||
this.canvas = document.createElement('canvas');
|
||||
this.canvas.className = 'gesture-canvas';
|
||||
container.appendChild(this.canvas);
|
||||
if (!this.hero) {
|
||||
this.echoes = document.createElement('div');
|
||||
this.echoes.className = 'gesture-echoes';
|
||||
container.appendChild(this.echoes);
|
||||
}
|
||||
this.echoes = document.createElement('div');
|
||||
this.echoes.className = 'gesture-echoes';
|
||||
container.appendChild(this.echoes);
|
||||
if (this.relayUrl) {
|
||||
this.status = document.createElement('span');
|
||||
this.status.className = 'gesture-status offline';
|
||||
@@ -119,7 +115,6 @@ class GestureWidget {
|
||||
this.drawing = true;
|
||||
this.points = [this.pos(e)];
|
||||
this.ghost = null;
|
||||
this.ambient = [];
|
||||
this.render();
|
||||
}
|
||||
|
||||
@@ -223,13 +218,7 @@ class GestureWidget {
|
||||
this.ghost = msg.path;
|
||||
this.render();
|
||||
} else if (msg.type === 'echo') {
|
||||
if (this.hero) {
|
||||
this.ambient.push(msg.path);
|
||||
if (this.ambient.length > MAX_ECHOES) this.ambient.shift();
|
||||
this.render();
|
||||
} else {
|
||||
this.addEchoThumbnail(msg);
|
||||
}
|
||||
this.addEchoThumbnail(msg);
|
||||
}
|
||||
// 'error' frames are intentionally silent: the widget is a
|
||||
// form field first, and a rate-limited announce shouldn't
|
||||
@@ -284,11 +273,6 @@ class GestureWidget {
|
||||
if (!this.ctx) return;
|
||||
const t = this.theme();
|
||||
this.ctx.clearRect(0, 0, this.cssWidth, this.cssHeight);
|
||||
for (const path of this.ambient) {
|
||||
this.ctx.globalAlpha = 0.25;
|
||||
this.drawPath(this.ctx, path, this.cssWidth, this.cssHeight, t.echo, 1.5, 0.2);
|
||||
}
|
||||
this.ctx.globalAlpha = 1;
|
||||
if (this.ghost) {
|
||||
this.drawPath(this.ctx, this.ghost, this.cssWidth, this.cssHeight, t.ghost, 2, 0.2);
|
||||
}
|
||||
@@ -325,11 +309,5 @@ class GestureWidget {
|
||||
}
|
||||
|
||||
export function mountGesture(container, hidden, relayUrl) {
|
||||
return new GestureWidget(container, hidden, relayUrl, false);
|
||||
}
|
||||
|
||||
// Hero variant: no form field to mirror into, and echoes render as
|
||||
// ambient strokes on the drawing canvas itself instead of thumbnails.
|
||||
export function mountGestureHero(container, relayUrl) {
|
||||
return new GestureWidget(container, null, relayUrl, true);
|
||||
return new GestureWidget(container, hidden, relayUrl);
|
||||
}
|
||||
|
||||
@@ -30,6 +30,12 @@ pub struct AggregateSchema {
|
||||
pub event_for_state: HashMap<String, String>,
|
||||
pub state_for_event: HashMap<String, String>,
|
||||
pub transitions: HashMap<String, Vec<String>>,
|
||||
/// Names what consumes this bucket's answers when no page in the
|
||||
/// content repo reads it (e.g. "n8n newsletter compose").
|
||||
/// Free-text - it exists so `validate_questions`' attended-bucket
|
||||
/// rule has an explicit, auditable opt-out instead of a silent
|
||||
/// one, and so the next reader knows where the answers go.
|
||||
pub attended_by: Option<String>,
|
||||
}
|
||||
|
||||
impl AggregateSchema {
|
||||
@@ -57,6 +63,8 @@ struct RawAggregateSchema {
|
||||
states: HashMap<String, RawState>,
|
||||
#[serde(default)]
|
||||
transitions: HashMap<String, Vec<String>>,
|
||||
#[serde(default)]
|
||||
attended_by: Option<String>,
|
||||
}
|
||||
|
||||
#[derive(Debug, serde::Deserialize)]
|
||||
@@ -123,6 +131,7 @@ pub fn parse_aggregates_yaml(raw: &str) -> anyhow::Result<HashMap<String, Aggreg
|
||||
event_for_state,
|
||||
state_for_event,
|
||||
transitions: raw_schema.transitions,
|
||||
attended_by: raw_schema.attended_by,
|
||||
},
|
||||
);
|
||||
}
|
||||
|
||||
+271
-133
@@ -1,5 +1,5 @@
|
||||
use leptos::prelude::*;
|
||||
use leptos_meta::{provide_meta_context, MetaTags, Stylesheet, Title};
|
||||
use leptos_meta::{provide_meta_context, HashedStylesheet, MetaTags, Title};
|
||||
use leptos_router::{
|
||||
components::{Route, Router, Routes},
|
||||
hooks::{use_location, use_navigate, use_query_map},
|
||||
@@ -39,6 +39,9 @@ pub fn shell(options: LeptosOptions) -> impl IntoView {
|
||||
// once loaded via <link>/<img> on Safari/iOS.
|
||||
<link rel="icon" media="(prefers-color-scheme: light)" href="/favicon-light.svg" type="image/svg+xml"/>
|
||||
<link rel="icon" media="(prefers-color-scheme: dark)" href="/favicon-dark.svg" type="image/svg+xml"/>
|
||||
// Server-side, so it can read hash.txt and link the
|
||||
// content-hashed stylesheet (hash-files = true).
|
||||
<HashedStylesheet id="leptos" options=options.clone()/>
|
||||
<AutoReload options=options.clone()/>
|
||||
<HydrationScripts options/>
|
||||
<MetaTags/>
|
||||
@@ -54,20 +57,60 @@ pub fn shell(options: LeptosOptions) -> impl IntoView {
|
||||
pub fn App() -> impl IntoView {
|
||||
provide_meta_context();
|
||||
|
||||
// ONE site resource and ONE <Title> for the whole app, both living
|
||||
// outside the router. Two dueling Title components (a static
|
||||
// SITE_NAME fallback here + a per-page override) turned every SPA
|
||||
// navigation into a remount race that the compile-time fallback
|
||||
// kept winning - redoal.com's tab flipped to "uhhm" on the first
|
||||
// client-side nav. App never remounts, so this Title never
|
||||
// unmounts; the Suspense makes SSR await the resolved title so the
|
||||
// served <head> is right too. Pages read the same resource via
|
||||
// context instead of fetching their own copy.
|
||||
let site = Resource::new(|| (), |_| get_site());
|
||||
provide_context(site);
|
||||
|
||||
view! {
|
||||
<Stylesheet id="leptos" href="/pkg/portal.css"/>
|
||||
<Title text=SITE_NAME/>
|
||||
<Suspense fallback=|| ()>
|
||||
{move || {
|
||||
site.get()
|
||||
.map(|res| {
|
||||
let title = res
|
||||
.ok()
|
||||
.and_then(|s| s.title)
|
||||
.unwrap_or_else(|| SITE_NAME.to_string());
|
||||
view! { <Title text=title/> }
|
||||
})
|
||||
}}
|
||||
</Suspense>
|
||||
<Router>
|
||||
<Routes fallback=|| view! { <NotFound/> }>
|
||||
<Route path=path!("") view=QuestionPage/>
|
||||
<Route path=path!("/*any") view=QuestionPage/>
|
||||
</Routes>
|
||||
<PortalShell/>
|
||||
</Router>
|
||||
}
|
||||
}
|
||||
|
||||
/// Every server-fn resource the pages read, created exactly once for
|
||||
/// the app's lifetime and handed down via context. Wrapper structs
|
||||
/// because a bare `Resource<T>` context is claimed by whoever provides
|
||||
/// that T last.
|
||||
#[derive(Clone, Copy)]
|
||||
struct QuestionRes(Resource<Result<Option<Page>, ServerFnError>>);
|
||||
#[derive(Clone, Copy)]
|
||||
struct UserRes(Resource<Result<Option<User>, ServerFnError>>);
|
||||
#[derive(Clone, Copy)]
|
||||
struct NavRes(Resource<Result<Vec<(String, String)>, ServerFnError>>);
|
||||
|
||||
/// Owns the app's data resources, above the routes and reactive on the
|
||||
/// location instead of recreated per page. Route components creating
|
||||
/// their own resources broke on the first client-side navigation: the
|
||||
/// remounted component's fresh Resource consumed a stale SSR hydration
|
||||
/// buffer instead of fetching - concretely, the nav list
|
||||
/// `[[id, name], ..]` deserialized as a `Page` (serde fills a struct
|
||||
/// from a sequence in field order), rendering the landing question
|
||||
/// gated behind its own nav entry. Stable resources + context makes
|
||||
/// that class of misalignment impossible: navigation only changes a
|
||||
/// key, and a key change always refetches.
|
||||
#[component]
|
||||
fn QuestionPage() -> impl IntoView {
|
||||
fn PortalShell() -> impl IntoView {
|
||||
let location = use_location();
|
||||
let query = use_query_map();
|
||||
let path = Memo::new(move |_| {
|
||||
@@ -78,12 +121,37 @@ fn QuestionPage() -> impl IntoView {
|
||||
p
|
||||
}
|
||||
});
|
||||
let chain = Memo::new(move |_| query.with(|q| q.get("chain")));
|
||||
|
||||
let question = Resource::new(
|
||||
move || (path.get(), chain.get()),
|
||||
|(path, chain)| get_question(path, chain),
|
||||
);
|
||||
let user = Resource::new(|| (), |_| current_user());
|
||||
let nav = Resource::new(move || chain.get().is_some(), list_qualifying_questions);
|
||||
provide_context(QuestionRes(question));
|
||||
provide_context(UserRes(user));
|
||||
provide_context(NavRes(nav));
|
||||
|
||||
view! {
|
||||
<Routes fallback=|| view! { <NotFound/> }>
|
||||
<Route path=path!("") view=QuestionPage/>
|
||||
<Route path=path!("/*any") view=QuestionPage/>
|
||||
</Routes>
|
||||
}
|
||||
}
|
||||
|
||||
#[component]
|
||||
fn QuestionPage() -> impl IntoView {
|
||||
let query = use_query_map();
|
||||
let parent_hash = Memo::new(move |_| query.with(|q| q.get("chain")));
|
||||
let query_email = Memo::new(move |_| query.with(|q| q.get("email")));
|
||||
|
||||
let question = Resource::new(move || path.get(), get_question);
|
||||
let user = Resource::new(|| (), |_| current_user());
|
||||
let site = Resource::new(|| (), |_| get_site());
|
||||
// All shared, app-lifetime resources (see PortalShell / App) -
|
||||
// never created per navigation.
|
||||
let QuestionRes(question) = expect_context();
|
||||
let UserRes(user) = expect_context();
|
||||
let site = expect_context::<Resource<Result<SiteConfig, ServerFnError>>>();
|
||||
|
||||
view! {
|
||||
<Suspense fallback=|| {
|
||||
@@ -103,18 +171,12 @@ fn QuestionPage() -> impl IntoView {
|
||||
let site_cfg = site.get().and_then(|r| r.ok()).unwrap_or_default();
|
||||
question_res
|
||||
.map(|res| match res {
|
||||
Ok(Some(q)) => {
|
||||
Ok(Some(page)) => {
|
||||
let current = user_res.and_then(|r| r.ok()).flatten();
|
||||
view! {
|
||||
// A second <Title> outranks App's
|
||||
// SITE_NAME fallback only when content
|
||||
// actually declares one.
|
||||
{site_cfg
|
||||
.title
|
||||
.clone()
|
||||
.map(|t| view! { <Title text=t/> })}
|
||||
<QuestionView
|
||||
question=q
|
||||
question=page.question
|
||||
chain_gate=page.chain_gate
|
||||
parent_hash=parent_hash.get()
|
||||
query_email=query_email.get()
|
||||
user=current
|
||||
@@ -133,12 +195,45 @@ fn QuestionPage() -> impl IntoView {
|
||||
#[component]
|
||||
fn QuestionView(
|
||||
question: Question,
|
||||
chain_gate: Option<(String, String)>,
|
||||
parent_hash: Option<String>,
|
||||
query_email: Option<String>,
|
||||
user: Option<User>,
|
||||
site: SiteConfig,
|
||||
) -> impl IntoView {
|
||||
let question_id = question.id.clone();
|
||||
let has_chain = parent_hash.is_some();
|
||||
|
||||
// The provenance counterpart to the qualifies gate below: a
|
||||
// requires_chain page whose visitor holds no verifiable lineage to
|
||||
// the required question renders a pointer there instead of its
|
||||
// alternatives.
|
||||
if let Some((target, target_name)) = chain_gate {
|
||||
let label = if target_name.is_empty() {
|
||||
target.clone()
|
||||
} else {
|
||||
target_name
|
||||
};
|
||||
return view! {
|
||||
<Hero
|
||||
title=question.name.clone()
|
||||
description=question.description.clone()
|
||||
landing=question_id == "/"
|
||||
site=site.clone()
|
||||
/>
|
||||
<div class="alternatives">
|
||||
<section class="alt-card gate-card">
|
||||
<p>"This page follows from an answer you don't seem to carry yet."</p>
|
||||
<a class="alt-submit" href=target>
|
||||
{label}
|
||||
</a>
|
||||
</section>
|
||||
</div>
|
||||
// A gate is never a dead end: the same nav as every page.
|
||||
<QuestionNav current_id=question_id has_chain=has_chain/>
|
||||
}
|
||||
.into_any();
|
||||
}
|
||||
|
||||
// Generic: any question with `qualifies` set renders this same gate
|
||||
// instead of its alternatives - "/review" isn't a special case, it's
|
||||
@@ -171,6 +266,7 @@ fn QuestionView(
|
||||
}}
|
||||
</section>
|
||||
</div>
|
||||
<QuestionNav current_id=question_id has_chain=has_chain/>
|
||||
}
|
||||
.into_any();
|
||||
}
|
||||
@@ -180,7 +276,6 @@ fn QuestionView(
|
||||
// on pages where some alternative actually declares a deck.
|
||||
let needs_swiper = question.alternatives.iter().any(|a| a.images.len() > 1);
|
||||
|
||||
let has_chain = parent_hash.is_some();
|
||||
|
||||
view! {
|
||||
{needs_swiper.then(|| view! { <leptos_meta::Script src="/swiper-element-bundle.min.js"/> })}
|
||||
@@ -243,7 +338,8 @@ fn QuestionView(
|
||||
/// claiming front-page space (an owner also sees the gated desks here).
|
||||
#[component]
|
||||
fn QuestionNav(current_id: String, has_chain: bool) -> impl IntoView {
|
||||
let nav = Resource::new(move || has_chain, list_qualifying_questions);
|
||||
let _ = has_chain; // keyed into the shared resource by PortalShell
|
||||
let NavRes(nav) = expect_context();
|
||||
view! {
|
||||
<Suspense fallback=|| ()>
|
||||
{move || {
|
||||
@@ -313,27 +409,6 @@ fn ResponsibleNote(responsible: Responsible) -> impl IntoView {
|
||||
}
|
||||
}
|
||||
|
||||
// Binds the actual "YES - Rasterized Lines" piece live at uhhm.no
|
||||
// (ported to `public/yes.js`, an ES module now instead of a page-owning
|
||||
// script) as a typed JS class - the idiomatic wasm-bindgen way to drive
|
||||
// an existing JS module from Rust, rather than re-implementing canvas
|
||||
// animation logic here.
|
||||
#[cfg(feature = "hydrate")]
|
||||
mod yes {
|
||||
use wasm_bindgen::prelude::*;
|
||||
|
||||
#[wasm_bindgen(module = "/yes.js")]
|
||||
extern "C" {
|
||||
#[wasm_bindgen(js_name = RasterizedYES)]
|
||||
pub type RasterizedYes;
|
||||
|
||||
#[wasm_bindgen(constructor, js_class = "RasterizedYES")]
|
||||
pub fn new() -> RasterizedYes;
|
||||
|
||||
#[wasm_bindgen(method)]
|
||||
pub fn stop(this: &RasterizedYes);
|
||||
}
|
||||
}
|
||||
|
||||
// Same idiomatic-typed-module approach as `yes` above, for the
|
||||
// prosekit-backed rich-text requirement kind (`prosekit-editor.js`,
|
||||
@@ -379,12 +454,6 @@ mod gesture {
|
||||
relay_url: &str,
|
||||
) -> GestureWidget;
|
||||
|
||||
#[wasm_bindgen(js_name = mountGestureHero)]
|
||||
pub fn mount_gesture_hero(
|
||||
container: &web_sys::HtmlDivElement,
|
||||
relay_url: &str,
|
||||
) -> GestureWidget;
|
||||
|
||||
#[wasm_bindgen(method)]
|
||||
pub fn stop(this: &GestureWidget);
|
||||
}
|
||||
@@ -392,101 +461,103 @@ mod gesture {
|
||||
|
||||
#[component]
|
||||
fn Hero(title: String, description: String, landing: bool, site: SiteConfig) -> impl IntoView {
|
||||
// Only the landing page gets a full interactive piece - it's the
|
||||
// one page a hero is actually "the" hero for; other pages
|
||||
// (thank-you pages, /review) get the plain dark header below.
|
||||
// WHICH piece is the content repo's call (`site.yaml`'s
|
||||
// hero.kind): the YES canvas (default - uhhm's look), a redoal
|
||||
// gesture canvas, or nothing.
|
||||
let hero_kind = if landing { site.hero.kind.clone() } else { "plain".to_string() };
|
||||
let show_yes = hero_kind == "yes";
|
||||
let show_gesture = hero_kind == "gesture";
|
||||
// Only the landing page gets a piece - it's the one page a hero is
|
||||
// actually "the" hero for; every other page gets the plain header.
|
||||
// WHAT the piece is belongs to the content repo: site.yaml's
|
||||
// `hero: {kind: module, module: hero.js}` names a JavaScript module
|
||||
// (served same-origin at /site/<path>) exporting
|
||||
// `mount(container) -> handle` with `handle.stop()`. Portal knows
|
||||
// nothing about what it draws.
|
||||
let module = if landing && site.hero.kind == "module" {
|
||||
site.hero.module.clone()
|
||||
} else {
|
||||
None
|
||||
};
|
||||
let has_module = module.is_some();
|
||||
let wordmark = site.wordmark.clone().unwrap_or_else(|| "/wordmark.svg".to_string());
|
||||
let site_title = site.title.clone().unwrap_or_else(|| SITE_NAME.to_string());
|
||||
|
||||
// Starts the YES animation once the canvas elements exist, and
|
||||
// explicitly stops the requestAnimationFrame loop on unmount - the
|
||||
// original page-owning script never needed this since navigating
|
||||
// away meant a full document unload, which doesn't happen in an
|
||||
// SPA.
|
||||
let raster_ref: NodeRef<leptos::html::Canvas> = NodeRef::new();
|
||||
let gesture_ref: NodeRef<leptos::html::Div> = NodeRef::new();
|
||||
let piece_ref: NodeRef<leptos::html::Div> = NodeRef::new();
|
||||
#[cfg(feature = "hydrate")]
|
||||
if show_yes {
|
||||
// `on_cleanup` requires Send + Sync (even single-threaded, wasm),
|
||||
// which a JS-backed value never is - `StoredValue`'s `LocalStorage`
|
||||
// variant is the established way around this (same pattern
|
||||
// cnats' WebRTC call state uses for its own non-Send peer map).
|
||||
let instance: StoredValue<Option<yes::RasterizedYes>, LocalStorage> =
|
||||
StoredValue::new_local(None);
|
||||
// Gated on the canvas NodeRef resolving, not just "the Effect
|
||||
// ran" - on a fresh page load the DOM is already there by the
|
||||
// time this fires, but navigating back to `/` client-side hit a
|
||||
// real race: the Effect ran before the new view's <canvas> was
|
||||
// actually inserted, RasterizedYES::new() (yes.js) did an
|
||||
// unchecked `document.getElementById(...).getContext(...)` on
|
||||
// null and threw mid-reactive-update - which then corrupted
|
||||
// wasm_bindgen_futures' single-threaded executor state badly
|
||||
// enough to panic ("RefCell already borrowed") on the next
|
||||
// tick. Waiting for the NodeRef itself guarantees DOM presence
|
||||
// the same way the prosekit editor's own mount Effect does.
|
||||
Effect::new(move |_| {
|
||||
if raster_ref.get().is_none() {
|
||||
return;
|
||||
}
|
||||
instance.set_value(Some(yes::RasterizedYes::new()));
|
||||
});
|
||||
on_cleanup(move || {
|
||||
instance.update_value(|opt| {
|
||||
if let Some(inst) = opt.take() {
|
||||
inst.stop();
|
||||
}
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
// The gesture hero mounts the same widget the `type: gesture`
|
||||
// requirement uses, in hero mode (no form field; echoes render as
|
||||
// ambient strokes on the canvas itself). Same StoredValue +
|
||||
// on_cleanup shape as the YES piece - it may own a live WebSocket.
|
||||
#[cfg(feature = "hydrate")]
|
||||
if show_gesture {
|
||||
let relay = site.hero.relay.clone().unwrap_or_default();
|
||||
let widget: StoredValue<Option<gesture::GestureWidget>, LocalStorage> =
|
||||
if has_module {
|
||||
use wasm_bindgen::JsCast;
|
||||
// Handle = whatever the module's mount() returned; kept as a
|
||||
// raw JsValue so the contract stays "has a stop()", nothing
|
||||
// typed on the Rust side.
|
||||
let handle: StoredValue<Option<wasm_bindgen::JsValue>, LocalStorage> =
|
||||
StoredValue::new_local(None);
|
||||
Effect::new(move |_| {
|
||||
let Some(container) = gesture_ref.get() else {
|
||||
let Some(container) = piece_ref.get() else {
|
||||
return;
|
||||
};
|
||||
if widget.with_value(|w| w.is_some()) {
|
||||
if handle.with_value(|h| h.is_some()) {
|
||||
return;
|
||||
}
|
||||
widget.set_value(Some(gesture::mount_gesture_hero(&container, &relay)));
|
||||
// Adopt the inline early-mount's instance (started at HTML
|
||||
// parse time) if it's there; otherwise (client-side
|
||||
// navigation back to /) mount fresh through the helper the
|
||||
// inline script left on window. Either order is safe.
|
||||
let global = js_sys::global();
|
||||
let _ = js_sys::Reflect::set(&global, &"__heroAdopted".into(), &true.into());
|
||||
let early = js_sys::Reflect::get(&global, &"__heroEarly".into())
|
||||
.ok()
|
||||
.filter(|v| !v.is_undefined() && !v.is_null());
|
||||
match early {
|
||||
Some(v) => {
|
||||
let _ = js_sys::Reflect::delete_property(&global, &"__heroEarly".into());
|
||||
handle.set_value(Some(v));
|
||||
}
|
||||
None => {
|
||||
if let Ok(mounter) = js_sys::Reflect::get(&global, &"__mountHero".into()) {
|
||||
if let Some(f) = mounter.dyn_ref::<js_sys::Function>() {
|
||||
if let Ok(promise) = f.call1(&global, &container) {
|
||||
let promise: js_sys::Promise = promise.unchecked_into();
|
||||
leptos::task::spawn_local(async move {
|
||||
if let Ok(h) =
|
||||
wasm_bindgen_futures::JsFuture::from(promise).await
|
||||
{
|
||||
handle.set_value(Some(h));
|
||||
}
|
||||
});
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
on_cleanup(move || {
|
||||
widget.update_value(|opt| {
|
||||
if let Some(w) = opt.take() {
|
||||
w.stop();
|
||||
handle.update_value(|opt| {
|
||||
if let Some(h) = opt.take() {
|
||||
if let Ok(stop) = js_sys::Reflect::get(&h, &"stop".into()) {
|
||||
if let Some(f) = stop.dyn_ref::<js_sys::Function>() {
|
||||
let _ = f.call0(&h);
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
// The inline script starts the piece at HTML parse time instead of
|
||||
// waiting out the wasm bundle; it also leaves __mountHero for the
|
||||
// hydrate side's client-side-navigation case. Module path is
|
||||
// validated to plain segments by SiteConfig::validate, so it can't
|
||||
// break out of the string here.
|
||||
let early_script = module.as_ref().map(|m| {
|
||||
format!(
|
||||
"const url = '/site/{m}'; window.__mountHero = (el) => import(url).then((mod) => mod.mount(el)); if (!window.__heroAdopted && !window.__heroEarly) window.__mountHero(document.querySelector('.hero-piece')).then((h) => {{ if (!window.__heroAdopted) window.__heroEarly = h; else if (h && h.stop) h.stop(); }});"
|
||||
)
|
||||
});
|
||||
|
||||
view! {
|
||||
<header class="hero" class:hero-yes=show_yes class:hero-gesture=show_gesture>
|
||||
{show_yes
|
||||
<header class="hero" class:hero-module=has_module>
|
||||
{has_module
|
||||
.then(|| {
|
||||
view! {
|
||||
<div class="hero-canvas" aria-hidden="true">
|
||||
<canvas id="lineCanvas"></canvas>
|
||||
<canvas id="rasterCanvas" node_ref=raster_ref></canvas>
|
||||
</div>
|
||||
<div class="hero-piece" aria-hidden="true" node_ref=piece_ref></div>
|
||||
<script type="module" inner_html=early_script.unwrap_or_default()></script>
|
||||
}
|
||||
})}
|
||||
{show_gesture
|
||||
.then(|| {
|
||||
view! { <div class="hero-draw" node_ref=gesture_ref></div> }
|
||||
})}
|
||||
<div class="hero-copy">
|
||||
<a class="wordmark" href="/">
|
||||
<img src=wordmark alt=site_title/>
|
||||
@@ -829,6 +900,7 @@ fn AlternativeCard(
|
||||
alternative=alt_name.clone()
|
||||
feature_name=feature_name.clone()
|
||||
transitions=spec.transitions.clone()
|
||||
empty=spec.empty.clone()
|
||||
pending_transitions=pending_transitions
|
||||
transition_batch=transition_batch
|
||||
/>
|
||||
@@ -1148,6 +1220,7 @@ fn ResourceFeature(
|
||||
alternative: String,
|
||||
feature_name: String,
|
||||
transitions: Vec<Transition>,
|
||||
empty: Option<String>,
|
||||
pending_transitions: RwSignal<std::collections::HashMap<(String, String), String>>,
|
||||
transition_batch: ServerAction<TransitionAnswers>,
|
||||
) -> impl IntoView {
|
||||
@@ -1181,6 +1254,7 @@ fn ResourceFeature(
|
||||
{move || {
|
||||
let feature_name = feature_name.clone();
|
||||
let transitions = transitions.clone();
|
||||
let empty = empty.clone().unwrap_or_else(|| "Nothing here yet.".to_string());
|
||||
data.get()
|
||||
.map(|res| match res {
|
||||
Ok(value) => {
|
||||
@@ -1188,6 +1262,7 @@ fn ResourceFeature(
|
||||
<ResourceValue
|
||||
feature_name=feature_name
|
||||
transitions=transitions
|
||||
empty=empty
|
||||
value=value
|
||||
pending_transitions=pending_transitions
|
||||
transition_batch=transition_batch
|
||||
@@ -1214,11 +1289,23 @@ fn ResourceFeature(
|
||||
fn ResourceValue(
|
||||
feature_name: String,
|
||||
transitions: Vec<Transition>,
|
||||
empty: String,
|
||||
value: serde_json::Value,
|
||||
pending_transitions: RwSignal<std::collections::HashMap<(String, String), String>>,
|
||||
transition_batch: ServerAction<TransitionAnswers>,
|
||||
) -> impl IntoView {
|
||||
// A jq like `.[] | {...}` over an empty list yields no output at
|
||||
// all - that arrives as null, and it's the same silence as [].
|
||||
if value.is_null() {
|
||||
return view! { <p class="resource-empty">{empty}</p> }.into_any();
|
||||
}
|
||||
if let serde_json::Value::Array(items) = &value {
|
||||
// Before the Answer parse below: an empty list deserializes as
|
||||
// an (empty) Vec<Answer> too, and rendered as a blank
|
||||
// answer-list instead of saying anything.
|
||||
if items.is_empty() {
|
||||
return view! { <p class="resource-empty">{empty}</p> }.into_any();
|
||||
}
|
||||
if let Ok(answers) = serde_json::from_value::<Vec<Answer>>(value.clone()) {
|
||||
let mut answers = answers;
|
||||
answers.sort_by(|a, b| {
|
||||
@@ -1251,9 +1338,6 @@ fn ResourceValue(
|
||||
}
|
||||
.into_any();
|
||||
}
|
||||
if items.is_empty() {
|
||||
return view! { <p class="resource-empty">"Nothing here yet."</p> }.into_any();
|
||||
}
|
||||
// A list of plain objects (e.g. a jq-shaped GiteaStarred/Url
|
||||
// resource) - render as cards rather than dumping raw JSON.
|
||||
// Generic on purpose, no content-declared "kind": `name`/`title`
|
||||
@@ -1640,11 +1724,56 @@ fn NotFound() -> impl IntoView {
|
||||
}
|
||||
}
|
||||
|
||||
/// What a URL resolves to: the question (dynamic pages arrive with
|
||||
/// their segment value already substituted, see
|
||||
/// `content::resolve_question`) plus whether a `requires_chain` gate
|
||||
/// blocked it - `(target id, target name)` so the gate can point the
|
||||
/// visitor at where the required answer comes from.
|
||||
#[derive(Clone, Debug, Serialize, Deserialize)]
|
||||
pub struct Page {
|
||||
pub question: Question,
|
||||
pub chain_gate: Option<(String, String)>,
|
||||
}
|
||||
|
||||
#[server(endpoint = "get_question")]
|
||||
pub async fn get_question(path: String) -> Result<Option<Question>, ServerFnError> {
|
||||
pub async fn get_question(
|
||||
path: String,
|
||||
chain: Option<String>,
|
||||
) -> Result<Option<Page>, ServerFnError> {
|
||||
use crate::content::{path_matches, resolve_question};
|
||||
use crate::server::AppState;
|
||||
let state = expect_context::<AppState>();
|
||||
Ok(state.questions.load().get(&path).cloned())
|
||||
let questions = state.questions.load();
|
||||
let Some(question) = resolve_question(&questions, &path) else {
|
||||
return Ok(None);
|
||||
};
|
||||
let mut chain_gate = None;
|
||||
if let Some(target) = &question.requires_chain {
|
||||
// The claimed lineage must verifiably end at the required
|
||||
// question - an unindexed or absent hash reads as unverified,
|
||||
// and the gate stays shut. Dynamic targets match any concrete
|
||||
// answer of theirs.
|
||||
let verified = match &chain {
|
||||
Some(hash) => crate::chain::lookup_node(&state.jetstream, hash)
|
||||
.await
|
||||
.is_some_and(|node| {
|
||||
node.question_id == *target
|
||||
|| path_matches(target, &node.question_id).is_some()
|
||||
}),
|
||||
None => false,
|
||||
};
|
||||
if !verified {
|
||||
let name = questions
|
||||
.get(target)
|
||||
.map(|q| q.name.clone())
|
||||
.unwrap_or_default();
|
||||
chain_gate = Some((target.clone(), name));
|
||||
}
|
||||
}
|
||||
Ok(Some(Page {
|
||||
question,
|
||||
chain_gate,
|
||||
}))
|
||||
}
|
||||
|
||||
/// The content repo's branding (`site.yaml`) - title, wordmark, hero
|
||||
@@ -1681,7 +1810,9 @@ pub async fn list_qualifying_questions(
|
||||
.load()
|
||||
.values()
|
||||
.filter(|q| is_qualified(user.as_ref(), q))
|
||||
.filter(|q| !q.followup || has_chain)
|
||||
.filter(|q| !q.is_followup() || has_chain)
|
||||
// A dynamic page has no URL of its own to link to.
|
||||
.filter(|q| !q.is_dynamic())
|
||||
.map(|q| (q.id.clone(), q.name.clone()))
|
||||
.collect();
|
||||
out.sort();
|
||||
@@ -1709,11 +1840,10 @@ pub async fn submit_answer(
|
||||
use crate::server::AppState;
|
||||
|
||||
let state = expect_context::<AppState>();
|
||||
let question = state
|
||||
.questions
|
||||
.load()
|
||||
.get(&question_id)
|
||||
.cloned()
|
||||
// resolve_question, not a plain map get: a dynamic page's concrete
|
||||
// path (what the client holds as its question id) resolves to the
|
||||
// pattern page it came from.
|
||||
let question = crate::content::resolve_question(&state.questions.load(), &question_id)
|
||||
.ok_or_else(|| ServerFnError::new("unknown question"))?;
|
||||
|
||||
let session: tower_sessions::Session = leptos_axum::extract().await?;
|
||||
@@ -1754,6 +1884,14 @@ pub async fn submit_answer(
|
||||
.await
|
||||
.map_err(|e| ServerFnError::new(format!("nats publish failed: {e}")))?;
|
||||
|
||||
// Index the node so requires_chain pages can verify lineage.
|
||||
// Best-effort: the NATS event above is the durable record.
|
||||
if let Err(e) =
|
||||
crate::chain::record_node(&state.jetstream, &chain_hash, &question_id, timestamp_ms).await
|
||||
{
|
||||
tracing::error!("failed to index chain node: {e}");
|
||||
}
|
||||
|
||||
// Best-effort: a bucket-write hiccup shouldn't fail a submission the
|
||||
// NATS event has already recorded.
|
||||
if let Some(bucket) = &record_as {
|
||||
|
||||
+27
-12
@@ -108,23 +108,38 @@ fn load_aggregates_from_dir(
|
||||
}
|
||||
|
||||
/// The offline counterpart to `content::load_questions_from_gitea` -
|
||||
/// same "every `*.yaml` file becomes a `Question` keyed by its own
|
||||
/// `id`" shape, just reading a local checkout instead of Gitea's API,
|
||||
/// the same recursive tree walk and `content::build_questions`
|
||||
/// pipeline (derived ids, relative refs, sections, followup
|
||||
/// inference), just reading a local checkout instead of Gitea's API,
|
||||
/// for linting a branch that hasn't been pushed yet.
|
||||
fn load_from_dir(
|
||||
dir: &str,
|
||||
) -> anyhow::Result<std::collections::HashMap<String, content::Question>> {
|
||||
let mut out = std::collections::HashMap::new();
|
||||
let base = std::path::Path::new(dir);
|
||||
let mut files = Vec::new();
|
||||
collect_yaml(base, base, &mut files)?;
|
||||
content::build_questions(&files)
|
||||
}
|
||||
|
||||
fn collect_yaml(
|
||||
base: &std::path::Path,
|
||||
dir: &std::path::Path,
|
||||
out: &mut Vec<(String, String)>,
|
||||
) -> anyhow::Result<()> {
|
||||
for entry in std::fs::read_dir(dir)? {
|
||||
let entry = entry?;
|
||||
let path = entry.path();
|
||||
if path.extension().and_then(|e| e.to_str()) != Some("yaml") {
|
||||
continue;
|
||||
let path = entry?.path();
|
||||
if path.is_dir() {
|
||||
collect_yaml(base, &path, out)?;
|
||||
} else if path.extension().and_then(|e| e.to_str()) == Some("yaml") {
|
||||
let rel = path
|
||||
.strip_prefix(base)
|
||||
.expect("walked paths sit under their base")
|
||||
.to_string_lossy()
|
||||
.replace('\\', "/");
|
||||
let raw = std::fs::read_to_string(&path)
|
||||
.map_err(|e| anyhow::anyhow!("reading {}: {e}", path.display()))?;
|
||||
out.push((rel, raw));
|
||||
}
|
||||
let raw = std::fs::read_to_string(&path)?;
|
||||
let question: content::Question = serde_yaml::from_str(&raw)
|
||||
.map_err(|e| anyhow::anyhow!("parsing {}: {e}", path.display()))?;
|
||||
out.insert(question.id.clone(), question);
|
||||
}
|
||||
Ok(out)
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -9,6 +9,60 @@ use sha2::{Digest, Sha256};
|
||||
/// submitted responses, and a timestamp. Parents are sorted first so the
|
||||
/// hash doesn't depend on the order multiple parents happened to arrive
|
||||
/// in.
|
||||
/// Where submitted chain nodes are indexed - hash → which question was
|
||||
/// answered. Small on purpose (no responses), and shared by every
|
||||
/// portal instance on the JetStream (hashes are globally unique, so
|
||||
/// cross-site collisions can't happen). This is what lets
|
||||
/// `requires_chain` pages verify a visitor's `?chain=` actually ends
|
||||
/// at the question they claim to have answered.
|
||||
pub const CHAIN_BUCKET: &str = "portal_chains";
|
||||
|
||||
#[derive(serde::Serialize, serde::Deserialize)]
|
||||
pub struct ChainNode {
|
||||
pub question_id: String,
|
||||
pub timestamp_ms: i64,
|
||||
}
|
||||
|
||||
/// Indexes one submitted node. Best-effort by design (the caller logs
|
||||
/// and continues): the NATS event is the durable record, this is a
|
||||
/// lookup convenience.
|
||||
pub async fn record_node(
|
||||
js: &async_nats::jetstream::Context,
|
||||
chain_hash: &str,
|
||||
question_id: &str,
|
||||
timestamp_ms: i64,
|
||||
) -> anyhow::Result<()> {
|
||||
let store = match js.get_key_value(CHAIN_BUCKET).await {
|
||||
Ok(store) => store,
|
||||
Err(_) => {
|
||||
js.create_key_value(async_nats::jetstream::kv::Config {
|
||||
bucket: CHAIN_BUCKET.to_string(),
|
||||
..Default::default()
|
||||
})
|
||||
.await?
|
||||
}
|
||||
};
|
||||
let node = ChainNode {
|
||||
question_id: question_id.to_string(),
|
||||
timestamp_ms,
|
||||
};
|
||||
store.put(chain_hash, serde_json::to_vec(&node)?.into()).await?;
|
||||
Ok(())
|
||||
}
|
||||
|
||||
/// Looks a chain hash up - `None` covers both "no such node" and
|
||||
/// "bucket not created yet" (no submissions anywhere), which read the
|
||||
/// same to a `requires_chain` check: the claimed lineage can't be
|
||||
/// verified, so the gate stays shut.
|
||||
pub async fn lookup_node(
|
||||
js: &async_nats::jetstream::Context,
|
||||
chain_hash: &str,
|
||||
) -> Option<ChainNode> {
|
||||
let store = js.get_key_value(CHAIN_BUCKET).await.ok()?;
|
||||
let bytes = store.get(chain_hash).await.ok()??;
|
||||
serde_json::from_slice(&bytes).ok()
|
||||
}
|
||||
|
||||
pub fn hash_node(
|
||||
question_id: &str,
|
||||
parent_hashes: &[String],
|
||||
|
||||
+689
-68
@@ -1,35 +1,85 @@
|
||||
use serde::{Deserialize, Serialize};
|
||||
|
||||
/// One page: a prompt plus the paths on from it. `id` doubles as the URL
|
||||
/// path it's served at ("/" is the landing page). Loaded from a plain
|
||||
/// YAML file per question in a content directory kept in its own git
|
||||
/// repo (see ../portal-content) - editing content is a content-repo
|
||||
/// commit, not a Rust rebuild.
|
||||
/// One page: a prompt plus the paths on from it. The `questions/`
|
||||
/// directory tree IS the URL tree (`index.yaml` names its directory,
|
||||
/// `develop/proposal.yaml` serves `/develop/proposal`), so `id` is
|
||||
/// derived from the file's path - declaring it explicitly still works
|
||||
/// (and wins, with a logged warning when it disagrees) but is only
|
||||
/// needed by legacy content. Loaded from plain YAML files in a content
|
||||
/// directory kept in its own git repo - editing content is a
|
||||
/// content-repo commit, not a Rust rebuild.
|
||||
#[derive(Clone, Debug, Serialize, Deserialize)]
|
||||
pub struct Question {
|
||||
pub id: String,
|
||||
/// The URL path this page is served at. Derived from the file path
|
||||
/// when absent. A `[name]` segment (from a `[name].yaml` file)
|
||||
/// makes this a dynamic page: `/review/[record]` serves any
|
||||
/// `/review/<value>`, with the value substituted into `{record}`
|
||||
/// placeholders in the page's resource keys (see
|
||||
/// `resolve_question`).
|
||||
#[serde(default)]
|
||||
pub route: Option<String>,
|
||||
pub id: String,
|
||||
pub name: String,
|
||||
#[serde(default)]
|
||||
pub description: String,
|
||||
/// Kanidm group required to view/submit this question - `None` means
|
||||
/// open to anyone, matching every question today. Content-driven
|
||||
/// on purpose: a gated page like "/review" is just a Question with
|
||||
/// this set, not a bespoke Rust route.
|
||||
/// open to anyone. Content-driven on purpose: a gated page like
|
||||
/// "/review" is just a Question with this set, not a bespoke Rust
|
||||
/// route. Inherited from the nearest ancestor `_section.yaml` when
|
||||
/// not set on the question itself.
|
||||
#[serde(default)]
|
||||
pub qualifies: Option<String>,
|
||||
/// Question id (relative refs resolve against this file's
|
||||
/// directory) the visitor must have answered - their `?chain=`
|
||||
/// lineage's tip - to see this page. The provenance counterpart to
|
||||
/// `qualifies`' identity check. Inherited from `_section.yaml`
|
||||
/// like `qualifies`.
|
||||
#[serde(default)]
|
||||
pub requires_chain: Option<String>,
|
||||
#[serde(default)]
|
||||
pub alternatives: Vec<Alternative>,
|
||||
/// Who to contact if a visitor gets stuck - rendered as a small line
|
||||
/// on the page.
|
||||
/// on the page. Inherited from `_section.yaml` when not set.
|
||||
#[serde(default)]
|
||||
pub responsible: Option<Responsible>,
|
||||
/// A page that only makes sense after answering something (the
|
||||
/// post-submission pages) - kept out of the question nav unless the
|
||||
/// visitor's context carries an answer chain.
|
||||
/// visitor's context carries an answer chain. Unset means inferred
|
||||
/// from the file's place in the tree: files nested in a
|
||||
/// subdirectory are followups unless they're the directory's
|
||||
/// `index.yaml`; top-level files keep the historical default
|
||||
/// (not a followup).
|
||||
#[serde(default)]
|
||||
pub followup: bool,
|
||||
pub followup: Option<bool>,
|
||||
}
|
||||
|
||||
impl Question {
|
||||
pub fn is_followup(&self) -> bool {
|
||||
self.followup.unwrap_or(false)
|
||||
}
|
||||
|
||||
/// A dynamic page - one whose id still contains a `[name]`
|
||||
/// segment. Served per-value via `resolve_question`, never listed
|
||||
/// in nav, never a valid `action` target.
|
||||
pub fn is_dynamic(&self) -> bool {
|
||||
self.id.contains('[')
|
||||
}
|
||||
}
|
||||
|
||||
/// Directory-scoped defaults: a `_section.yaml` file applies to every
|
||||
/// question at or below its directory (nearest ancestor wins per
|
||||
/// field, and a question's own declaration always overrides). This is
|
||||
/// what makes a URL prefix a trust boundary - "everything under
|
||||
/// /review is owner-only" is one line in `review/_section.yaml`
|
||||
/// instead of a flag per file. Underscore-prefixed files that aren't
|
||||
/// `_section.yaml` are skipped entirely (drafts).
|
||||
#[derive(Clone, Debug, Default, Serialize, Deserialize)]
|
||||
pub struct SectionConfig {
|
||||
#[serde(default)]
|
||||
pub qualifies: Option<String>,
|
||||
#[serde(default)]
|
||||
pub requires_chain: Option<String>,
|
||||
#[serde(default)]
|
||||
pub responsible: Option<Responsible>,
|
||||
}
|
||||
|
||||
#[derive(Clone, Debug, Serialize, Deserialize)]
|
||||
@@ -152,6 +202,12 @@ pub struct ResourceSpec {
|
||||
/// `.[] | {name, url: .html_url}`. `None` returns it as-is.
|
||||
#[serde(default)]
|
||||
pub jq: Option<String>,
|
||||
/// What to say when the resource yields nothing - an empty list,
|
||||
/// or `null` (a `.[] | ...` jq over an empty list produces no
|
||||
/// output at all). Defaults to "Nothing here yet."; content sets
|
||||
/// it where the silence needs a voice ("Nothing released yet").
|
||||
#[serde(default)]
|
||||
pub empty: Option<String>,
|
||||
}
|
||||
|
||||
/// Where a resource's live data comes from. `Kv` (a NATS KV bucket
|
||||
@@ -297,51 +353,76 @@ pub struct SiteConfig {
|
||||
pub hero: HeroConfig,
|
||||
}
|
||||
|
||||
/// What the landing page's hero is: the YES canvas piece (`yes`, the
|
||||
/// default), a redoal gesture-drawing canvas (`gesture`), or copy
|
||||
/// only (`plain`).
|
||||
/// What the landing page's hero is. `plain` is just the copy; `module`
|
||||
/// hands the hero to a JavaScript module the content repo itself
|
||||
/// ships (`module: hero.js`, a repo-relative path portal serves
|
||||
/// same-origin at `/site/<path>`, since Gitea's raw endpoint sends no
|
||||
/// CORS headers). The module exports `mount(container) -> handle` and
|
||||
/// the handle has `stop()`; portal starts it at HTML parse time and
|
||||
/// adopts it on hydration. The piece's look - canvases, SVG, CSS - is
|
||||
/// entirely the module's: portal only reserves the box.
|
||||
#[derive(Clone, Debug, Serialize, Deserialize, PartialEq)]
|
||||
pub struct HeroConfig {
|
||||
#[serde(default = "default_hero_kind")]
|
||||
pub kind: String,
|
||||
/// `kind: gesture` only - ws(s):// URL of a redoal-relay for
|
||||
/// ambient echoes. Absent means the hero draws offline.
|
||||
#[serde(default)]
|
||||
pub relay: Option<String>,
|
||||
pub module: Option<String>,
|
||||
}
|
||||
|
||||
impl Default for HeroConfig {
|
||||
fn default() -> Self {
|
||||
Self { kind: default_hero_kind(), relay: None }
|
||||
Self { kind: default_hero_kind(), module: None }
|
||||
}
|
||||
}
|
||||
|
||||
fn default_hero_kind() -> String {
|
||||
"yes".to_string()
|
||||
"plain".to_string()
|
||||
}
|
||||
|
||||
#[cfg(feature = "ssr")]
|
||||
impl SiteConfig {
|
||||
/// Shared by `load_site_from_gitea` and the `question-lint` binary
|
||||
/// so a typo'd hero kind is a caught rejection, not a silently
|
||||
/// plain hero.
|
||||
/// Same policy as `validate_questions`: content declares, the
|
||||
/// runtime refuses what it doesn't understand at load time, so a
|
||||
/// typo'd hero kind is a caught rejection, not a silently plain
|
||||
/// hero.
|
||||
pub fn validate(&self) -> anyhow::Result<()> {
|
||||
if !matches!(self.hero.kind.as_str(), "yes" | "gesture" | "plain") {
|
||||
anyhow::bail!(
|
||||
"site.yaml: hero.kind {:?} is not one of yes | gesture | plain",
|
||||
self.hero.kind
|
||||
);
|
||||
}
|
||||
if let Some(relay) = &self.hero.relay {
|
||||
if self.hero.kind != "gesture" {
|
||||
anyhow::bail!("site.yaml: hero.relay only makes sense with hero.kind: gesture");
|
||||
match self.hero.kind.as_str() {
|
||||
"plain" => {
|
||||
if self.hero.module.is_some() {
|
||||
anyhow::bail!("site.yaml: hero.module only makes sense with hero.kind: module");
|
||||
}
|
||||
}
|
||||
validate_relay_url(relay).map_err(|e| anyhow::anyhow!("site.yaml: {e}"))?;
|
||||
"module" => {
|
||||
let Some(module) = &self.hero.module else {
|
||||
anyhow::bail!("site.yaml: hero.kind: module needs hero.module (a repo-relative path like hero.js)");
|
||||
};
|
||||
if !is_safe_site_path(module) {
|
||||
anyhow::bail!(
|
||||
"site.yaml: hero.module {module:?} must be a plain repo-relative path (no scheme, no .., no leading /)"
|
||||
);
|
||||
}
|
||||
}
|
||||
other => anyhow::bail!("site.yaml: hero.kind {other:?} is not one of plain | module"),
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
|
||||
/// A repo-relative asset path portal is willing to proxy from the
|
||||
/// content repo: plain segments only - no traversal, no leading slash,
|
||||
/// no scheme - so `/site/<path>` can only ever reach the content repo.
|
||||
pub fn is_safe_site_path(path: &str) -> bool {
|
||||
!path.is_empty()
|
||||
&& !path.starts_with('/')
|
||||
&& path.split('/').all(|seg| {
|
||||
!seg.is_empty()
|
||||
&& seg != ".."
|
||||
&& seg
|
||||
.chars()
|
||||
.all(|c| c.is_ascii_alphanumeric() || c == '-' || c == '_' || c == '.')
|
||||
})
|
||||
}
|
||||
|
||||
/// A relay must be a ws:// or wss:// URL - shared between site.yaml's
|
||||
/// hero and `Requirement.relay` validation.
|
||||
#[cfg(feature = "ssr")]
|
||||
@@ -378,6 +459,15 @@ pub async fn load_site_from_gitea(repo_url: &str, branch: &str) -> anyhow::Resul
|
||||
|
||||
/// Extracts `scheme://host` from a repo's normal browser URL - the
|
||||
/// Gitea API base every helper in this module builds requests against.
|
||||
#[cfg(feature = "ssr")]
|
||||
/// `{gitea}/api/v1/repos/{owner}/{repo}/raw` - the base
|
||||
/// `site_asset_handler` proxies content-shipped files from.
|
||||
#[cfg(feature = "ssr")]
|
||||
pub fn gitea_raw_base(repo_url: &str) -> anyhow::Result<String> {
|
||||
let (owner, repo) = parse_owner_repo(repo_url)?;
|
||||
Ok(format!("{}/api/v1/repos/{owner}/{repo}/raw", gitea_api_base(repo_url)?))
|
||||
}
|
||||
|
||||
#[cfg(feature = "ssr")]
|
||||
pub fn gitea_api_base(repo_url: &str) -> anyhow::Result<String> {
|
||||
let parsed = url::Url::parse(repo_url)
|
||||
@@ -479,6 +569,228 @@ pub async fn load_aggregates_from_gitea(
|
||||
/// startup, and again on every `CONTENT_RELOAD_SUBJECT` message (see
|
||||
/// `watch_for_reload`), over Gitea's public contents API (no auth - the
|
||||
/// content repo is public).
|
||||
/// The URL a file at `rel` (path relative to the questions dir, forward
|
||||
/// slashes) serves: `index.yaml` names its directory, everything else
|
||||
/// appends its stem.
|
||||
pub fn route_from_path(rel: &str) -> String {
|
||||
let stem = rel.strip_suffix(".yaml").unwrap_or(rel);
|
||||
let mut segments: Vec<&str> = stem.split('/').collect();
|
||||
if segments.last() == Some(&"index") {
|
||||
segments.pop();
|
||||
}
|
||||
if segments.is_empty() {
|
||||
"/".to_string()
|
||||
} else {
|
||||
format!("/{}", segments.join("/"))
|
||||
}
|
||||
}
|
||||
|
||||
/// The directory (as a URL prefix) of the file at `rel` - the base
|
||||
/// relative references resolve against.
|
||||
pub fn dir_from_path(rel: &str) -> String {
|
||||
match rel.rsplit_once('/') {
|
||||
Some((dir, _)) => format!("/{dir}"),
|
||||
None => "/".to_string(),
|
||||
}
|
||||
}
|
||||
|
||||
/// Resolves a possibly-relative question reference (`action:`,
|
||||
/// `requires_chain:`) against the referencing file's directory:
|
||||
/// `/x` is absolute, `proposed` names a sibling, `../x` climbs.
|
||||
pub fn resolve_ref(base_dir: &str, reference: &str) -> String {
|
||||
if reference.starts_with('/') {
|
||||
return reference.to_string();
|
||||
}
|
||||
let mut segments: Vec<&str> = base_dir.split('/').filter(|s| !s.is_empty()).collect();
|
||||
for part in reference.split('/') {
|
||||
match part {
|
||||
"" | "." => {}
|
||||
".." => {
|
||||
segments.pop();
|
||||
}
|
||||
s => segments.push(s),
|
||||
}
|
||||
}
|
||||
if segments.is_empty() {
|
||||
"/".to_string()
|
||||
} else {
|
||||
format!("/{}", segments.join("/"))
|
||||
}
|
||||
}
|
||||
|
||||
/// Whether `path` matches `pattern`, capturing `[name]` segments.
|
||||
/// Returns the captured (name, value) pairs on a match - empty for an
|
||||
/// exact literal match.
|
||||
pub fn path_matches(pattern: &str, path: &str) -> Option<Vec<(String, String)>> {
|
||||
let pat: Vec<&str> = pattern.split('/').filter(|s| !s.is_empty()).collect();
|
||||
let got: Vec<&str> = path.split('/').filter(|s| !s.is_empty()).collect();
|
||||
if pat.len() != got.len() {
|
||||
return None;
|
||||
}
|
||||
let mut captures = Vec::new();
|
||||
for (p, g) in pat.iter().zip(got.iter()) {
|
||||
if let Some(name) = p.strip_prefix('[').and_then(|s| s.strip_suffix(']')) {
|
||||
if g.is_empty() {
|
||||
return None;
|
||||
}
|
||||
captures.push((name.to_string(), (*g).to_string()));
|
||||
} else if p != g {
|
||||
return None;
|
||||
}
|
||||
}
|
||||
Some(captures)
|
||||
}
|
||||
|
||||
/// Resolves a URL path to its question: an exact id first, else the
|
||||
/// one dynamic page whose pattern matches, with each captured segment
|
||||
/// substituted into `{name}` placeholders in the clone's resource keys
|
||||
/// and its id set to the concrete path (so every follow-up server call
|
||||
/// - resources, submissions - re-resolves the same way). The
|
||||
/// substituted key is still looked up in the content-declared bucket,
|
||||
/// so a visitor varies the key, never the bucket - the same trust
|
||||
/// shape as a `?chain=` link, where knowing a record's key is holding
|
||||
/// it.
|
||||
pub fn resolve_question(
|
||||
questions: &std::collections::HashMap<String, Question>,
|
||||
path: &str,
|
||||
) -> Option<Question> {
|
||||
if let Some(q) = questions.get(path) {
|
||||
return Some(q.clone());
|
||||
}
|
||||
for q in questions.values() {
|
||||
if !q.is_dynamic() {
|
||||
continue;
|
||||
}
|
||||
if let Some(captures) = path_matches(&q.id, path) {
|
||||
let mut resolved = q.clone();
|
||||
resolved.id = path.to_string();
|
||||
let substitute = |key: &mut Option<String>| {
|
||||
if let Some(k) = key {
|
||||
for (name, value) in &captures {
|
||||
*k = k.replace(&format!("{{{name}}}"), value);
|
||||
}
|
||||
}
|
||||
};
|
||||
for alt in &mut resolved.alternatives {
|
||||
for feature in &mut alt.features {
|
||||
if let Some(res) = &mut feature.resource {
|
||||
substitute(&mut res.key);
|
||||
}
|
||||
for req in &mut feature.requirements {
|
||||
if let Some(res) = &mut req.resource {
|
||||
substitute(&mut res.key);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return Some(resolved);
|
||||
}
|
||||
}
|
||||
None
|
||||
}
|
||||
|
||||
/// Builds the question map from raw (path, yaml) files - the shared
|
||||
/// back half of both loaders (Gitea tree and `question_lint --path`).
|
||||
/// Applies the whole filesystem-routing contract: derived ids,
|
||||
/// relative-reference resolution, followup inference, `_section.yaml`
|
||||
/// inheritance, and the tree-shape rules (no id collisions, at most
|
||||
/// one dynamic page per directory).
|
||||
#[cfg(feature = "ssr")]
|
||||
pub fn build_questions(
|
||||
files: &[(String, String)],
|
||||
) -> anyhow::Result<std::collections::HashMap<String, Question>> {
|
||||
// Sections first: (directory prefix, config), shallowest first so a
|
||||
// later (deeper) section overrides an outer one field-by-field.
|
||||
let mut sections: Vec<(String, SectionConfig)> = Vec::new();
|
||||
for (rel, raw) in files {
|
||||
let name = rel.rsplit('/').next().unwrap_or(rel);
|
||||
if name != "_section.yaml" {
|
||||
continue;
|
||||
}
|
||||
let mut section: SectionConfig = serde_yaml::from_str(raw)
|
||||
.map_err(|e| anyhow::anyhow!("parsing {rel}: {e}"))?;
|
||||
let dir = dir_from_path(rel);
|
||||
if let Some(rc) = §ion.requires_chain {
|
||||
section.requires_chain = Some(resolve_ref(&dir, rc));
|
||||
}
|
||||
sections.push((dir, section));
|
||||
}
|
||||
sections.sort_by_key(|(dir, _)| dir.len());
|
||||
|
||||
let mut out = std::collections::HashMap::new();
|
||||
let mut dynamic_dirs = std::collections::HashSet::new();
|
||||
for (rel, raw) in files {
|
||||
let name = rel.rsplit('/').next().unwrap_or(rel);
|
||||
// Underscore files are sections or drafts, never pages.
|
||||
if name.starts_with('_') {
|
||||
continue;
|
||||
}
|
||||
let mut question: Question =
|
||||
serde_yaml::from_str(raw).map_err(|e| anyhow::anyhow!("parsing {rel}: {e}"))?;
|
||||
let derived = route_from_path(rel);
|
||||
let dir = dir_from_path(rel);
|
||||
|
||||
if question.id.is_empty() {
|
||||
question.id = derived.clone();
|
||||
} else if question.id != derived {
|
||||
tracing::warn!(
|
||||
"{rel}: declared id {:?} disagrees with its path ({derived}) - the declared id wins, but consider moving the file",
|
||||
question.id
|
||||
);
|
||||
}
|
||||
|
||||
for alt in &mut question.alternatives {
|
||||
if let Some(action) = &alt.action {
|
||||
alt.action = Some(resolve_ref(&dir, action));
|
||||
}
|
||||
}
|
||||
if let Some(rc) = &question.requires_chain {
|
||||
question.requires_chain = Some(resolve_ref(&dir, rc));
|
||||
}
|
||||
|
||||
if question.followup.is_none() {
|
||||
// Nested non-index files are flow steps and outcomes -
|
||||
// followups by construction. Top-level files keep the
|
||||
// historical flat-repo default.
|
||||
let nested = rel.contains('/');
|
||||
let is_index = name == "index.yaml";
|
||||
question.followup = Some(nested && !is_index);
|
||||
}
|
||||
|
||||
// Nearest-ancestor section fills whatever the question left
|
||||
// unset (walk deepest-last, so later matches override earlier
|
||||
// section values but never the question's own).
|
||||
for (sdir, section) in §ions {
|
||||
let applies = *sdir == "/" || dir == *sdir || dir.starts_with(&format!("{sdir}/"));
|
||||
if !applies {
|
||||
continue;
|
||||
}
|
||||
if question.qualifies.is_none() {
|
||||
question.qualifies = section.qualifies.clone();
|
||||
}
|
||||
if question.requires_chain.is_none() {
|
||||
question.requires_chain = section.requires_chain.clone();
|
||||
}
|
||||
if question.responsible.is_none() {
|
||||
question.responsible = section.responsible.clone();
|
||||
}
|
||||
}
|
||||
|
||||
if question.is_dynamic() && !dynamic_dirs.insert(dir.clone()) {
|
||||
anyhow::bail!(
|
||||
"{rel}: more than one dynamic ([name].yaml) page in {dir} - matching would be ambiguous"
|
||||
);
|
||||
}
|
||||
if let Some(previous) = out.insert(question.id.clone(), question) {
|
||||
anyhow::bail!(
|
||||
"{rel}: id {:?} is already declared by another file",
|
||||
previous.id
|
||||
);
|
||||
}
|
||||
}
|
||||
Ok(out)
|
||||
}
|
||||
|
||||
#[cfg(feature = "ssr")]
|
||||
pub async fn load_questions_from_gitea(
|
||||
repo_url: &str,
|
||||
@@ -489,45 +801,59 @@ pub async fn load_questions_from_gitea(
|
||||
let api_base = gitea_api_base(repo_url)?;
|
||||
|
||||
let client = openidconnect::reqwest::Client::new();
|
||||
let list_url = format!("{api_base}/api/v1/repos/{owner}/{repo}/contents/{subdir}?ref={branch}");
|
||||
// One recursive git-trees call for the whole repo instead of a
|
||||
// contents listing per directory - the tree IS the router now, so
|
||||
// nested files matter.
|
||||
let tree_url =
|
||||
format!("{api_base}/api/v1/repos/{owner}/{repo}/git/trees/{branch}?recursive=true");
|
||||
let listing = client
|
||||
.get(&list_url)
|
||||
.get(&tree_url)
|
||||
.send()
|
||||
.await
|
||||
.map_err(|e| anyhow::anyhow!("listing {list_url}: {e}"))?
|
||||
.map_err(|e| anyhow::anyhow!("listing {tree_url}: {e}"))?
|
||||
.error_for_status()
|
||||
.map_err(|e| anyhow::anyhow!("listing {list_url}: {e}"))?
|
||||
.map_err(|e| anyhow::anyhow!("listing {tree_url}: {e}"))?
|
||||
.text()
|
||||
.await
|
||||
.map_err(|e| anyhow::anyhow!("reading directory listing from {list_url}: {e}"))?;
|
||||
let entries: Vec<serde_json::Value> = serde_json::from_str(&listing)
|
||||
.map_err(|e| anyhow::anyhow!("parsing directory listing from {list_url}: {e}"))?;
|
||||
.map_err(|e| anyhow::anyhow!("reading tree from {tree_url}: {e}"))?;
|
||||
let tree: serde_json::Value = serde_json::from_str(&listing)
|
||||
.map_err(|e| anyhow::anyhow!("parsing tree from {tree_url}: {e}"))?;
|
||||
if tree.get("truncated").and_then(|v| v.as_bool()) == Some(true) {
|
||||
anyhow::bail!("git tree listing for {owner}/{repo} was truncated - repo too large");
|
||||
}
|
||||
let prefix = format!("{subdir}/");
|
||||
|
||||
let mut out = std::collections::HashMap::new();
|
||||
for entry in entries {
|
||||
let name = entry.get("name").and_then(|v| v.as_str()).unwrap_or("");
|
||||
if !name.ends_with(".yaml") {
|
||||
let mut files = Vec::new();
|
||||
for entry in tree
|
||||
.get("tree")
|
||||
.and_then(|v| v.as_array())
|
||||
.map(|v| v.as_slice())
|
||||
.unwrap_or_default()
|
||||
{
|
||||
let path = entry.get("path").and_then(|v| v.as_str()).unwrap_or("");
|
||||
if entry.get("type").and_then(|v| v.as_str()) != Some("blob")
|
||||
|| !path.starts_with(&prefix)
|
||||
|| !path.ends_with(".yaml")
|
||||
{
|
||||
continue;
|
||||
}
|
||||
let download_url = entry
|
||||
.get("download_url")
|
||||
.and_then(|v| v.as_str())
|
||||
.ok_or_else(|| anyhow::anyhow!("no download_url for {name}"))?;
|
||||
// Brackets (dynamic pages like `[record].yaml`) must be
|
||||
// percent-encoded in the raw URL's path.
|
||||
let encoded = path.replace('[', "%5B").replace(']', "%5D");
|
||||
let raw_url = format!("{api_base}/api/v1/repos/{owner}/{repo}/raw/{encoded}?ref={branch}");
|
||||
let raw = client
|
||||
.get(download_url)
|
||||
.get(&raw_url)
|
||||
.send()
|
||||
.await
|
||||
.map_err(|e| anyhow::anyhow!("fetching {name}: {e}"))?
|
||||
.map_err(|e| anyhow::anyhow!("fetching {path}: {e}"))?
|
||||
.error_for_status()
|
||||
.map_err(|e| anyhow::anyhow!("fetching {name}: {e}"))?
|
||||
.map_err(|e| anyhow::anyhow!("fetching {path}: {e}"))?
|
||||
.text()
|
||||
.await
|
||||
.map_err(|e| anyhow::anyhow!("reading {name}: {e}"))?;
|
||||
let question: Question =
|
||||
serde_yaml::from_str(&raw).map_err(|e| anyhow::anyhow!("parsing {name}: {e}"))?;
|
||||
out.insert(question.id.clone(), question);
|
||||
.map_err(|e| anyhow::anyhow!("reading {path}: {e}"))?;
|
||||
files.push((path[prefix.len()..].to_string(), raw));
|
||||
}
|
||||
Ok(out)
|
||||
build_questions(&files)
|
||||
}
|
||||
|
||||
/// Validates every declared transition target (`SelfTransition.to`,
|
||||
@@ -546,15 +872,31 @@ pub fn validate_questions(
|
||||
aggregates: &std::collections::HashMap<String, crate::aggregates::AggregateSchema>,
|
||||
) -> anyhow::Result<()> {
|
||||
for question in questions.values() {
|
||||
if let Some(target) = &question.requires_chain {
|
||||
if !questions.contains_key(target) {
|
||||
anyhow::bail!(
|
||||
"question {:?}: requires_chain {:?} does not match any declared question id",
|
||||
question.id,
|
||||
target
|
||||
);
|
||||
}
|
||||
}
|
||||
for alternative in &question.alternatives {
|
||||
// A dangling action is a literal dead end: the submit
|
||||
// button navigates to "Nothing here".
|
||||
if let Some(action) = &alternative.action {
|
||||
if !questions.contains_key(action) {
|
||||
anyhow::bail!(
|
||||
match questions.get(action) {
|
||||
None => anyhow::bail!(
|
||||
"question {:?} alternative {:?}: action {:?} does not match any declared question id",
|
||||
question.id, alternative.name, action
|
||||
);
|
||||
),
|
||||
// A dynamic page needs a concrete segment value to
|
||||
// be a URL - a submit button can't supply one.
|
||||
Some(target) if target.is_dynamic() => anyhow::bail!(
|
||||
"question {:?} alternative {:?}: action {:?} targets a dynamic page - actions must name a concrete question",
|
||||
question.id, alternative.name, action
|
||||
),
|
||||
Some(_) => {}
|
||||
}
|
||||
}
|
||||
if let Some(st) = &alternative.self_transition {
|
||||
@@ -646,6 +988,54 @@ pub fn validate_questions(
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Attended buckets: no publicly collected answer may land somewhere
|
||||
// nothing reads. Every `record_as` bucket must either be read back
|
||||
// by some Kv resource in this same content repo (a desk or listing)
|
||||
// or carry an explicit `attended_by:` annotation in aggregates.yaml
|
||||
// naming the automation that consumes it. This is a contract, not a
|
||||
// convention, because convention already failed once: a question
|
||||
// was dropped and its bucket - answers included - silently fell out
|
||||
// of every reader's view.
|
||||
let mut read_buckets = std::collections::HashSet::new();
|
||||
let note_resource = |spec: &ResourceSpec, set: &mut std::collections::HashSet<String>| {
|
||||
if let ResourceSource::Kv { bucket } = &spec.source {
|
||||
set.insert(bucket.clone());
|
||||
}
|
||||
};
|
||||
for question in questions.values() {
|
||||
for alternative in &question.alternatives {
|
||||
for feature in &alternative.features {
|
||||
if let Some(spec) = &feature.resource {
|
||||
note_resource(spec, &mut read_buckets);
|
||||
}
|
||||
for requirement in &feature.requirements {
|
||||
if let Some(spec) = &requirement.resource {
|
||||
note_resource(spec, &mut read_buckets);
|
||||
}
|
||||
if let Some(bind) = &requirement.bind {
|
||||
note_resource(&bind.resource, &mut read_buckets);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
for question in questions.values() {
|
||||
for alternative in &question.alternatives {
|
||||
if let Some(bucket) = &alternative.record_as {
|
||||
let attended = read_buckets.contains(bucket)
|
||||
|| aggregates
|
||||
.get(bucket)
|
||||
.is_some_and(|schema| schema.attended_by.is_some());
|
||||
if !attended {
|
||||
anyhow::bail!(
|
||||
"question {:?} alternative {:?}: record_as {bucket:?} is unattended - no page reads that bucket back, and aggregates.yaml declares no attended_by for it. Add a desk/listing resource over it, or annotate the automation that consumes it.",
|
||||
question.id, alternative.name
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
@@ -741,6 +1131,54 @@ pub struct GiteaRepoQuery {
|
||||
pub repo: String,
|
||||
}
|
||||
|
||||
/// `GET /site/{*path}` - serves a file from the content repo's default
|
||||
/// branch same-origin, so content-shipped assets (the hero module,
|
||||
/// its stylesheet) are importable by the page: Gitea's raw endpoint
|
||||
/// sends no CORS headers, and an ES module import across origins is
|
||||
/// refused without them. Path is validated to plain segments
|
||||
/// (`is_safe_site_path`), the response revalidates like /pkg
|
||||
/// (Cache-Control: no-cache) so a content push shows up on reload.
|
||||
#[cfg(feature = "ssr")]
|
||||
pub async fn site_asset_handler(
|
||||
axum::extract::State(state): axum::extract::State<crate::server::AppState>,
|
||||
axum::extract::Path(path): axum::extract::Path<String>,
|
||||
) -> axum::response::Response {
|
||||
use axum::http::{header, StatusCode};
|
||||
use axum::response::IntoResponse;
|
||||
|
||||
if !is_safe_site_path(&path) {
|
||||
return (StatusCode::BAD_REQUEST, "invalid asset path").into_response();
|
||||
}
|
||||
let url = format!("{}/{path}?ref={}", state.content_raw_base, state.content_branch);
|
||||
let client = openidconnect::reqwest::Client::new();
|
||||
let resp = match client.get(&url).send().await.and_then(|r| r.error_for_status()) {
|
||||
Ok(r) => r,
|
||||
Err(e) => {
|
||||
tracing::warn!("site asset {path}: {e}");
|
||||
return (StatusCode::NOT_FOUND, "no such site asset").into_response();
|
||||
}
|
||||
};
|
||||
let bytes = match resp.bytes().await {
|
||||
Ok(b) => b,
|
||||
Err(e) => return (StatusCode::BAD_GATEWAY, e.to_string()).into_response(),
|
||||
};
|
||||
let mime = match path.rsplit('.').next() {
|
||||
Some("js") | Some("mjs") => "text/javascript; charset=utf-8",
|
||||
Some("css") => "text/css; charset=utf-8",
|
||||
Some("svg") => "image/svg+xml",
|
||||
Some("json") => "application/json",
|
||||
Some("png") => "image/png",
|
||||
Some("webp") => "image/webp",
|
||||
Some("woff2") => "font/woff2",
|
||||
_ => "application/octet-stream",
|
||||
};
|
||||
(
|
||||
[(header::CONTENT_TYPE, mime), (header::CACHE_CONTROL, "no-cache")],
|
||||
bytes,
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
|
||||
/// Looks up `owner/repo` on the same Gitea instance content is loaded
|
||||
/// from (`AppState.gitea_base`) - a raw Axum handler (mounted at
|
||||
/// `/gitea-repo` in `main.rs`), not a Leptos server fn, since the
|
||||
@@ -1036,9 +1474,9 @@ alternatives:
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn site_config_defaults_to_the_yes_hero() {
|
||||
fn site_config_defaults_to_the_plain_hero() {
|
||||
let site = SiteConfig::default();
|
||||
assert_eq!(site.hero.kind, "yes");
|
||||
assert_eq!(site.hero.kind, "plain");
|
||||
assert!(site.validate().is_ok());
|
||||
// And an empty file parses to the same thing.
|
||||
let parsed: SiteConfig = serde_yaml::from_str("{}").unwrap();
|
||||
@@ -1053,20 +1491,203 @@ alternatives:
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn site_config_rejects_relay_without_gesture_hero() {
|
||||
let site: SiteConfig =
|
||||
serde_yaml::from_str("hero: { kind: yes, relay: \"wss://relay.redoal.com\" }").unwrap();
|
||||
assert!(site.validate().is_err());
|
||||
fn site_config_module_hero_needs_a_safe_path() {
|
||||
let missing: SiteConfig = serde_yaml::from_str("hero: { kind: module }").unwrap();
|
||||
assert!(missing.validate().is_err());
|
||||
let traversal: SiteConfig =
|
||||
serde_yaml::from_str("hero: { kind: module, module: ../etc/passwd }").unwrap();
|
||||
assert!(traversal.validate().is_err());
|
||||
let absolute: SiteConfig =
|
||||
serde_yaml::from_str("hero: { kind: module, module: https://x/y.js }").unwrap();
|
||||
assert!(absolute.validate().is_err());
|
||||
let ok: SiteConfig = serde_yaml::from_str("hero: { kind: module, module: hero.js }").unwrap();
|
||||
assert!(ok.validate().is_ok());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn redoal_site_yaml_shape_parses() {
|
||||
let site: SiteConfig = serde_yaml::from_str(
|
||||
"title: redoal\nwordmark: https://project.uhhm.no/redoal/questions/raw/branch/main/wordmark.svg\nhero:\n kind: gesture\n relay: wss://relay.redoal.com\n",
|
||||
"title: redoal\nwordmark: https://project.uhhm.no/redoal/questions/raw/branch/main/wordmark.svg\nhero:\n kind: module\n module: hero.js\n",
|
||||
)
|
||||
.unwrap();
|
||||
assert!(site.validate().is_ok());
|
||||
assert_eq!(site.title.as_deref(), Some("redoal"));
|
||||
assert_eq!(site.hero.kind, "gesture");
|
||||
assert_eq!(site.hero.module.as_deref(), Some("hero.js"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn routes_derive_from_paths() {
|
||||
assert_eq!(route_from_path("index.yaml"), "/");
|
||||
assert_eq!(route_from_path("applied.yaml"), "/applied");
|
||||
assert_eq!(route_from_path("develop/index.yaml"), "/develop");
|
||||
assert_eq!(route_from_path("develop/proposal.yaml"), "/develop/proposal");
|
||||
assert_eq!(route_from_path("review/[record].yaml"), "/review/[record]");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn relative_refs_resolve_against_the_file_dir() {
|
||||
assert_eq!(resolve_ref("/develop", "proposed"), "/develop/proposed");
|
||||
assert_eq!(resolve_ref("/develop", "/subscribed"), "/subscribed");
|
||||
assert_eq!(resolve_ref("/develop", "../applied"), "/applied");
|
||||
assert_eq!(resolve_ref("/", "applied"), "/applied");
|
||||
assert_eq!(resolve_ref("/", ".."), "/");
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn dynamic_patterns_capture_segments() {
|
||||
assert_eq!(path_matches("/review/[record]", "/review/abc"),
|
||||
Some(vec![("record".into(), "abc".into())]));
|
||||
assert_eq!(path_matches("/review/[record]", "/review"), None);
|
||||
assert_eq!(path_matches("/review/[record]", "/other/abc"), None);
|
||||
assert_eq!(path_matches("/review", "/review"), Some(vec![]));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn tree_becomes_router_with_inference_and_sections() {
|
||||
let files = vec![
|
||||
("index.yaml".to_string(), "name: Home\nalternatives:\n - name: go\n action: applied\n".to_string()),
|
||||
("applied.yaml".to_string(), "name: Applied\nfollowup: true\n".to_string()),
|
||||
("develop/index.yaml".to_string(), "name: Develop\nalternatives:\n - name: propose\n action: proposal\n".to_string()),
|
||||
("develop/proposal.yaml".to_string(), "name: Proposal\nalternatives:\n - name: send\n action: proposed\n".to_string()),
|
||||
("develop/proposed.yaml".to_string(), "name: Proposed\n".to_string()),
|
||||
("review/_section.yaml".to_string(), "qualifies: portal_owners\n".to_string()),
|
||||
("review/index.yaml".to_string(), "name: Review\n".to_string()),
|
||||
("review/_draft.yaml".to_string(), "not even valid yaml: [\n".to_string()),
|
||||
];
|
||||
let questions = build_questions(&files).unwrap();
|
||||
|
||||
// Derived ids and resolved relative actions.
|
||||
assert_eq!(questions["/"].alternatives[0].action.as_deref(), Some("/applied"));
|
||||
assert_eq!(
|
||||
questions["/develop"].alternatives[0].action.as_deref(),
|
||||
Some("/develop/proposal")
|
||||
);
|
||||
assert_eq!(
|
||||
questions["/develop/proposal"].alternatives[0].action.as_deref(),
|
||||
Some("/develop/proposed")
|
||||
);
|
||||
|
||||
// Followup inference: nested non-index files are followups,
|
||||
// index files and top-level files are not (explicit wins).
|
||||
assert!(!questions["/"].is_followup());
|
||||
assert!(questions["/applied"].is_followup());
|
||||
assert!(!questions["/develop"].is_followup());
|
||||
assert!(questions["/develop/proposal"].is_followup());
|
||||
|
||||
// Section inheritance gates the directory; drafts are skipped.
|
||||
assert_eq!(questions["/review"].qualifies.as_deref(), Some("portal_owners"));
|
||||
assert_eq!(questions["/"].qualifies, None);
|
||||
assert!(!questions.contains_key("/review/_draft"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn declared_id_wins_over_path() {
|
||||
let files = vec![(
|
||||
"legacy.yaml".to_string(),
|
||||
"id: /somewhere-else\nname: Legacy\n".to_string(),
|
||||
)];
|
||||
let questions = build_questions(&files).unwrap();
|
||||
assert!(questions.contains_key("/somewhere-else"));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn colliding_ids_and_ambiguous_dynamics_are_rejected() {
|
||||
let collision = vec![
|
||||
("a.yaml".to_string(), "name: A\n".to_string()),
|
||||
("b.yaml".to_string(), "id: /a\nname: B\n".to_string()),
|
||||
];
|
||||
assert!(build_questions(&collision).is_err());
|
||||
|
||||
let ambiguous = vec![
|
||||
("review/[a].yaml".to_string(), "name: A\n".to_string()),
|
||||
("review/[b].yaml".to_string(), "name: B\n".to_string()),
|
||||
];
|
||||
assert!(build_questions(&ambiguous).is_err());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn dynamic_pages_resolve_with_key_substitution() {
|
||||
let files = vec![(
|
||||
"review/[record].yaml".to_string(),
|
||||
"name: Record\nalternatives:\n - name: view\n features:\n - name: detail\n resource:\n public: true\n key: \"{record}\"\n source:\n kind: kv\n bucket: applicants\n".to_string(),
|
||||
)];
|
||||
let questions = build_questions(&files).unwrap();
|
||||
let page = resolve_question(&questions, "/review/abc123").unwrap();
|
||||
assert_eq!(page.id, "/review/abc123");
|
||||
assert_eq!(
|
||||
page.alternatives[0].features[0].resource.as_ref().unwrap().key.as_deref(),
|
||||
Some("abc123")
|
||||
);
|
||||
assert!(resolve_question(&questions, "/review").is_none());
|
||||
// The pattern itself still resolves exactly (it IS an id).
|
||||
assert!(resolve_question(&questions, "/review/[record]").is_some());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn requires_chain_resolves_and_validates() {
|
||||
let files = vec![
|
||||
("shape.yaml".to_string(), "name: Shape\n".to_string()),
|
||||
(
|
||||
"shaped.yaml".to_string(),
|
||||
"name: Shaped\nrequires_chain: shape\n".to_string(),
|
||||
),
|
||||
];
|
||||
let questions = build_questions(&files).unwrap();
|
||||
assert_eq!(questions["/shaped"].requires_chain.as_deref(), Some("/shape"));
|
||||
assert!(validate_questions(&questions, &Default::default()).is_ok());
|
||||
|
||||
let dangling = vec![(
|
||||
"shaped.yaml".to_string(),
|
||||
"name: Shaped\nrequires_chain: /nowhere\n".to_string(),
|
||||
)];
|
||||
let questions = build_questions(&dangling).unwrap();
|
||||
assert!(validate_questions(&questions, &Default::default()).is_err());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn recorded_buckets_must_be_attended() {
|
||||
let write_only = vec![(
|
||||
"index.yaml".to_string(),
|
||||
"name: Home\nalternatives:\n - name: send\n record_as: black_hole\n".to_string(),
|
||||
)];
|
||||
let questions = build_questions(&write_only).unwrap();
|
||||
let err = validate_questions(&questions, &Default::default()).unwrap_err();
|
||||
assert!(err.to_string().contains("unattended"), "got: {err}");
|
||||
|
||||
// A desk (any Kv resource over the bucket, anywhere in the
|
||||
// repo) attends it.
|
||||
let with_desk = vec![
|
||||
(
|
||||
"index.yaml".to_string(),
|
||||
"name: Home\nalternatives:\n - name: send\n record_as: inbox\n".to_string(),
|
||||
),
|
||||
(
|
||||
"review/index.yaml".to_string(),
|
||||
"name: Desk\nalternatives:\n - name: Inbox\n features:\n - name: \"\"\n resource:\n requires_group: owners\n source:\n kind: kv\n bucket: inbox\n".to_string(),
|
||||
),
|
||||
];
|
||||
let questions = build_questions(&with_desk).unwrap();
|
||||
assert!(validate_questions(&questions, &Default::default()).is_ok());
|
||||
|
||||
// ..or an explicit attended_by annotation in aggregates.yaml.
|
||||
let aggregates = crate::aggregates::parse_aggregates_yaml(
|
||||
"aggregates:\n - bucket: black_hole\n initial: open\n attended_by: n8n nightly digest\n states:\n open: { event: submitted }\n",
|
||||
)
|
||||
.unwrap();
|
||||
let questions = build_questions(&write_only).unwrap();
|
||||
assert!(validate_questions(&questions, &aggregates).is_ok());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn actions_may_not_target_dynamic_pages() {
|
||||
let files = vec![
|
||||
(
|
||||
"index.yaml".to_string(),
|
||||
"name: Home\nalternatives:\n - name: go\n action: /review/[record]\n".to_string(),
|
||||
),
|
||||
("review/[record].yaml".to_string(), "name: Record\n".to_string()),
|
||||
];
|
||||
let questions = build_questions(&files).unwrap();
|
||||
assert!(validate_questions(&questions, &Default::default()).is_err());
|
||||
}
|
||||
}
|
||||
|
||||
+22
-2
@@ -29,6 +29,7 @@ async fn main() -> anyhow::Result<()> {
|
||||
.unwrap_or_else(|_| "https://project.uhhm.no/uhhm/questions".to_string());
|
||||
let content_branch = std::env::var("CONTENT_BRANCH").unwrap_or_else(|_| "main".to_string());
|
||||
let gitea_base = content::gitea_api_base(&content_repo)?;
|
||||
let content_raw_base = content::gitea_raw_base(&content_repo)?;
|
||||
let aggregates = content::load_aggregates_from_gitea(&content_repo, &content_branch).await?;
|
||||
let questions = content::load_questions_from_gitea(&content_repo, &content_branch, "questions").await?;
|
||||
content::validate_questions(&questions, &aggregates)?;
|
||||
@@ -67,7 +68,7 @@ async fn main() -> anyhow::Result<()> {
|
||||
tokio::spawn(content::watch_for_reload(
|
||||
nats.clone(),
|
||||
content_repo,
|
||||
content_branch,
|
||||
content_branch.clone(),
|
||||
"questions".to_string(),
|
||||
questions.clone(),
|
||||
aggregates.clone(),
|
||||
@@ -82,6 +83,8 @@ async fn main() -> anyhow::Result<()> {
|
||||
aggregates,
|
||||
site,
|
||||
gitea_base,
|
||||
content_raw_base,
|
||||
content_branch: content_branch.clone(),
|
||||
oidc: oidc_state,
|
||||
garage,
|
||||
};
|
||||
@@ -138,8 +141,25 @@ async fn main() -> anyhow::Result<()> {
|
||||
.route("/api/{*fn_name}", any(server_fn_handler))
|
||||
.route("/upload", post(upload::upload))
|
||||
.route("/gitea-repo", get(content::gitea_repo_handler))
|
||||
// Content-shipped assets (hero module etc.), same-origin.
|
||||
.route("/site/{*path}", get(content::site_asset_handler))
|
||||
.route("/automation/kv/{bucket}", get(content::automation_kv_handler))
|
||||
.nest_service("/pkg", ServeDir::new(pkg_dir))
|
||||
// no-cache = "revalidate before reuse", not "don't cache":
|
||||
// pkg files keep the same names across releases (portal.js,
|
||||
// portal.wasm), and without this browsers heuristically cache
|
||||
// them - a stale wasm from the previous release then talks to
|
||||
// a server whose server-fn wire format has moved on and every
|
||||
// page renders as its error branch. A 304 per load is the
|
||||
// price of never shipping that skew again.
|
||||
.nest_service(
|
||||
"/pkg",
|
||||
tower::ServiceBuilder::new()
|
||||
.layer(tower_http::set_header::SetResponseHeaderLayer::overriding(
|
||||
axum::http::header::CACHE_CONTROL,
|
||||
axum::http::HeaderValue::from_static("no-cache"),
|
||||
))
|
||||
.service(ServeDir::new(pkg_dir)),
|
||||
)
|
||||
.nest_service("/fonts", ServeDir::new(fonts_dir))
|
||||
.route_service("/favicon-light.svg", ServeFile::new(favicon_light_path))
|
||||
.route_service("/favicon-dark.svg", ServeFile::new(favicon_dark_path))
|
||||
|
||||
+6
-5
@@ -122,11 +122,12 @@ fn find_feature(
|
||||
alternative: &str,
|
||||
feature_name: &str,
|
||||
) -> Result<crate::content::Feature, ServerFnError> {
|
||||
let question = state
|
||||
.questions
|
||||
.load()
|
||||
.get(question_id)
|
||||
.cloned()
|
||||
// resolve_question, not a plain map get: a dynamic page's client
|
||||
// holds its concrete path as the question id, and resolution is
|
||||
// also what substitutes the URL segment into the page's resource
|
||||
// keys - so this lookup is where a `/review/<record>` page's
|
||||
// feature acquires its record-specific key.
|
||||
let question = crate::content::resolve_question(&state.questions.load(), question_id)
|
||||
.ok_or_else(|| ServerFnError::new("unknown question"))?;
|
||||
question
|
||||
.alternatives
|
||||
|
||||
@@ -38,6 +38,10 @@ pub struct AppState {
|
||||
/// rather than re-derived per call, since `resolve_gitea_repo` needs
|
||||
/// it too and has no other reason to see `CONTENT_REPO` itself.
|
||||
pub gitea_base: String,
|
||||
/// `{gitea}/api/v1/repos/{owner}/{repo}/raw` and the branch - what
|
||||
/// `content::site_asset_handler` proxies content-shipped assets from.
|
||||
pub content_raw_base: String,
|
||||
pub content_branch: String,
|
||||
pub oidc: Arc<oidc::Oidc>,
|
||||
/// `None` when `GARAGE_*` env vars aren't set - uploads are the one
|
||||
/// optional feature, everything else works without Garage.
|
||||
|
||||
+22
-92
@@ -51,7 +51,7 @@
|
||||
--ink-dim: #9a9a9a;
|
||||
--line: #2a2a2a;
|
||||
|
||||
/* Cards float over the sticky YES canvas - translucent so the piece
|
||||
/* Cards float over a sticky hero piece - translucent so the piece
|
||||
reads faintly through them (paired with backdrop-filter on
|
||||
.alt-card), shadowed so their edge against the animated backdrop
|
||||
is a soft lift rather than a hard contrast line. */
|
||||
@@ -78,8 +78,9 @@
|
||||
/* Light theme: the same muted-press idea on white stock - warm paper,
|
||||
near-black ink, and the accent deepened from dusty cyan to a teal
|
||||
ink that actually carries as text on light paper (the dark theme's
|
||||
#8ec2c0 washes out there). yes.js mirrors this palette on its own
|
||||
(matchMedia in setupTheme) since canvas paint can't read CSS vars. */
|
||||
#8ec2c0 washes out there). Canvas-drawing modules (gesture.js, and
|
||||
content-shipped hero modules) mirror this palette on their own,
|
||||
since canvas paint can't read CSS vars. */
|
||||
@media (prefers-color-scheme: light) {
|
||||
:root {
|
||||
--accent: #47807e;
|
||||
@@ -105,12 +106,6 @@
|
||||
filter: invert(0.92);
|
||||
}
|
||||
|
||||
/* overlay against near-white paper resolves to ~white and the
|
||||
raster ghost vanishes; multiply lets the light theme's gray YES
|
||||
(see rasterizeText's themed repaint in yes.js) show as ink. */
|
||||
.hero-canvas #rasterCanvas {
|
||||
mix-blend-mode: multiply;
|
||||
}
|
||||
}
|
||||
|
||||
* {
|
||||
@@ -200,91 +195,15 @@ main.not-found {
|
||||
max-width: 46ch;
|
||||
}
|
||||
|
||||
/* the actual "YES - Rasterized Lines" piece live at uhhm.no (see
|
||||
public/yes.js) - landing page only. Full-viewport so it's a real
|
||||
moment, not a thumbnail; hero-copy overlays near the bottom rather
|
||||
than interrupting the canvas. */
|
||||
|
||||
.hero-yes {
|
||||
/* Sticky at the viewport top for the whole scroll (its containing
|
||||
block is the page itself), so the piece stays animating behind
|
||||
everything that follows - the translucent cards scroll over it
|
||||
and it shows through them and in the gaps around them. z-index 0
|
||||
so positioned content below can stack above with z-index 1. */
|
||||
position: sticky;
|
||||
top: 0;
|
||||
z-index: 0;
|
||||
max-width: none;
|
||||
width: 100%;
|
||||
/* svh here is only the pre-JS/no-JS fallback (and first paint before
|
||||
yes.js's constructor runs). Once yes.js mounts, it overwrites this
|
||||
with an inline `height: <px>` frozen from a single measurement -
|
||||
see setupCanvas()'s comment in yes.js for why: on real mobile
|
||||
Safari, content bottom-aligned inside this box kept sliding down
|
||||
as the address bar collapsed even with a spec'd-stable viewport
|
||||
unit here, so the box's actual height can't be trusted to stay
|
||||
put on that unit alone. An inline style set from JS always wins
|
||||
the cascade over this rule, so that frozen number is what
|
||||
actually governs once the page is interactive.
|
||||
Plain-vh fallback declared first - an engine without svh support
|
||||
ignores the invalid second line rather than falling through to
|
||||
auto height, which would collapse this to the height of its
|
||||
in-flow content and clip the canvas via overflow:hidden below. */
|
||||
height: 100vh;
|
||||
height: 100svh;
|
||||
padding: 0;
|
||||
justify-content: flex-end;
|
||||
overflow: hidden;
|
||||
}
|
||||
|
||||
.hero-canvas {
|
||||
position: absolute;
|
||||
inset: 0;
|
||||
}
|
||||
|
||||
.hero-canvas canvas {
|
||||
position: absolute;
|
||||
top: 0;
|
||||
left: 0;
|
||||
cursor: pointer;
|
||||
}
|
||||
|
||||
.hero-canvas #rasterCanvas {
|
||||
mix-blend-mode: overlay;
|
||||
opacity: 0.5;
|
||||
}
|
||||
|
||||
.hero-yes .hero-copy {
|
||||
position: relative;
|
||||
z-index: 1;
|
||||
padding: 0 1.5rem 3.5rem;
|
||||
gap: 0.6rem;
|
||||
text-shadow: 0 0.12em 1.4em var(--hero-glow);
|
||||
}
|
||||
|
||||
/* The gesture hero (site.yaml hero.kind: gesture - redoal.com's
|
||||
landing): a tall drawing surface where the visitor's stroke and
|
||||
ambient echoes from the relay share the stage. Not sticky like the
|
||||
YES piece - drawing and scrolling fight over the same finger. */
|
||||
.hero-gesture .hero-draw {
|
||||
/* A content-shipped hero module (site.yaml hero.kind: module) draws
|
||||
into .hero-piece; the module owns its look (it may restyle .hero
|
||||
itself). Portal only reserves the box so the copy doesn't jump when
|
||||
the module mounts - plain-vh fallback first, as everywhere. */
|
||||
.hero-module .hero-piece {
|
||||
position: relative;
|
||||
width: 100%;
|
||||
max-width: 46rem;
|
||||
}
|
||||
|
||||
.hero-gesture .gesture-canvas {
|
||||
aspect-ratio: auto;
|
||||
/* Plain-vh fallback first, same reasoning as .hero-yes's height. */
|
||||
height: 55vh;
|
||||
height: 55svh;
|
||||
border: none;
|
||||
background: transparent;
|
||||
}
|
||||
|
||||
.hero-gesture .gesture-status {
|
||||
top: auto;
|
||||
bottom: 0.55rem;
|
||||
right: 0.55rem;
|
||||
min-height: 55vh;
|
||||
min-height: 55svh;
|
||||
}
|
||||
|
||||
/* alternatives */
|
||||
@@ -559,6 +478,17 @@ textarea:focus {
|
||||
custom properties - so palette changes go there AND here. */
|
||||
.gesture-wrap {
|
||||
position: relative;
|
||||
width: 100%;
|
||||
}
|
||||
|
||||
/* The canvas is created by JS only after wasm hydration - reserve its
|
||||
3/2 box until then so content below doesn't jump. Scoped to :empty
|
||||
on purpose: on the mounted wrap (a stretched item inside the flex
|
||||
.field) the same aspect-ratio turned the echo strip's extra height
|
||||
into extra WIDTH and the whole card ballooned past the viewport
|
||||
after the first stroke. */
|
||||
.gesture-wrap:empty {
|
||||
aspect-ratio: 3 / 2;
|
||||
}
|
||||
|
||||
.gesture-canvas {
|
||||
|
||||
@@ -1,578 +0,0 @@
|
||||
// Ported from ~/repos/webpage/content/visualize/ah.html ("YES - Rasterized
|
||||
// Lines"), the piece currently live at uhhm.no - kept as the actual asset,
|
||||
// not reinvented. Two changes from the original: exported as a class (no
|
||||
// auto-init on `window load`, since Leptos controls when this mounts) and
|
||||
// a `stop()` method that actually breaks the requestAnimationFrame loop -
|
||||
// the original ran forever once started, fine for a static page that's
|
||||
// the whole document, not fine in an SPA where this hero mounts/unmounts
|
||||
// as you navigate.
|
||||
|
||||
export class RasterizedYES {
|
||||
constructor() {
|
||||
this.rasterCanvas = document.getElementById('rasterCanvas');
|
||||
this.lineCanvas = document.getElementById('lineCanvas');
|
||||
|
||||
// The Rust side only constructs this once it's confirmed (via a
|
||||
// NodeRef) that the canvas is mounted, but that guard has shown
|
||||
// a real gap on fast client-side re-navigation back to `/` -
|
||||
// this is the actual failure point, so it gets its own defense
|
||||
// rather than depending on getting that timing exactly right
|
||||
// from the other side of the wasm boundary. Leaving the
|
||||
// instance otherwise-inert (no crash, no animation) rather than
|
||||
// throwing mid-render - `stop()` already tolerates a partially
|
||||
// (non-)initialized instance.
|
||||
if (!this.rasterCanvas || !this.lineCanvas) {
|
||||
console.warn('RasterizedYES: canvas not in DOM yet, skipping');
|
||||
this.destroyed = true;
|
||||
return;
|
||||
}
|
||||
|
||||
this.rasterCtx = this.rasterCanvas.getContext('2d');
|
||||
this.lineCtx = this.lineCanvas.getContext('2d');
|
||||
|
||||
this.lines = [];
|
||||
this.rasterData = null;
|
||||
this.isActive = true;
|
||||
this.destroyed = false;
|
||||
this.time = 0;
|
||||
|
||||
this.containmentStrength = 0.5;
|
||||
this.wiggleAmount = 0.5;
|
||||
|
||||
// .hero-canvas is inset:0 inside this - freezing an inline
|
||||
// height here (below) is what actually locks the box, not
|
||||
// just reading its rect.
|
||||
this.heroEl = this.rasterCanvas.closest('.hero');
|
||||
|
||||
this.setupCanvas();
|
||||
this.setupResizeHandler();
|
||||
this.setupDrift();
|
||||
this.setupTheme();
|
||||
this.setupScrollFade();
|
||||
this.setupClickHandler();
|
||||
this.rasterizeText();
|
||||
this.initializeLines();
|
||||
this.animate();
|
||||
}
|
||||
|
||||
stop() {
|
||||
this.destroyed = true;
|
||||
if (this._resizeHandler) {
|
||||
window.removeEventListener('resize', this._resizeHandler);
|
||||
}
|
||||
if (this._themeQuery) {
|
||||
this._themeQuery.removeEventListener('change', this._themeHandler);
|
||||
}
|
||||
if (this._scrollHandler) {
|
||||
window.removeEventListener('scroll', this._scrollHandler);
|
||||
}
|
||||
}
|
||||
|
||||
// The hero is position: sticky (main.css), so without this the
|
||||
// title/wordmark stay pinned at the viewport bottom for the whole
|
||||
// page and ghost through the translucent cards scrolling over
|
||||
// them. Fade the copy out across the first half-screen of scroll;
|
||||
// visibility: hidden at the end so the wordmark link can't be
|
||||
// clicked while invisible.
|
||||
setupScrollFade() {
|
||||
this.heroCopy = this.heroEl ? this.heroEl.querySelector('.hero-copy') : null;
|
||||
if (!this.heroCopy) return;
|
||||
this._scrollHandler = () => {
|
||||
const opacity = Math.max(0, 1 - window.scrollY / (this.displayHeight * 0.5));
|
||||
this.heroCopy.style.opacity = opacity;
|
||||
this.heroCopy.style.visibility = opacity <= 0.01 ? 'hidden' : '';
|
||||
};
|
||||
window.addEventListener('scroll', this._scrollHandler, { passive: true });
|
||||
this._scrollHandler();
|
||||
}
|
||||
|
||||
// Canvas paint can't read CSS custom properties, so the piece
|
||||
// carries its own copy of both palettes and follows
|
||||
// prefers-color-scheme itself - values must track main.css's :root
|
||||
// (--paper especially: the fade fill IS the page background where
|
||||
// the canvas shows through translucent cards). Dark keeps the
|
||||
// original neon-on-black inks; light restates them as CMYK process
|
||||
// inks dark enough to carry on paper, since 80%-lightness pastels
|
||||
// vanish on white.
|
||||
setupTheme() {
|
||||
this._themeQuery = window.matchMedia('(prefers-color-scheme: light)');
|
||||
this._themeHandler = () => {
|
||||
this.applyTheme();
|
||||
// Repaint the raster ghost in the new theme's ink and
|
||||
// hard-clear the trails - a slow 3%-alpha fade from the
|
||||
// old paper color would smear across the flip otherwise.
|
||||
this.rasterizeText();
|
||||
this.lineCtx.fillStyle = this.theme.paper;
|
||||
this.lineCtx.fillRect(0, 0, this.displayWidth, this.displayHeight);
|
||||
};
|
||||
this._themeQuery.addEventListener('change', this._themeHandler);
|
||||
this.applyTheme();
|
||||
}
|
||||
|
||||
applyTheme() {
|
||||
this.theme = this._themeQuery.matches
|
||||
? {
|
||||
paper: '#f6f5f1',
|
||||
fade: 'rgba(246, 245, 241, 0.03)',
|
||||
// White ground so multiply (the light theme's CSS
|
||||
// blend mode for #rasterCanvas) leaves the paper
|
||||
// untouched; gray ink becomes the faint YES ghost.
|
||||
rasterBg: '#ffffff',
|
||||
rasterInk: '#6b6b6b',
|
||||
strokes: [
|
||||
'hsla(185, 70%, 32%, 0.85)',
|
||||
'hsla(315, 60%, 38%, 0.85)',
|
||||
'hsla(50, 90%, 40%, 0.85)'
|
||||
]
|
||||
}
|
||||
: {
|
||||
paper: '#0a0a0a',
|
||||
fade: 'rgba(10, 10, 10, 0.03)',
|
||||
rasterBg: '#111111',
|
||||
rasterInk: '#ffffff',
|
||||
strokes: [
|
||||
'hsla(180, 90%, 80%, 0.8)',
|
||||
'hsla(300, 90%, 80%, 0.8)',
|
||||
'hsla(60, 90%, 80%, 0.8)'
|
||||
]
|
||||
};
|
||||
}
|
||||
|
||||
// Reading .hero-canvas's rendered rect (a prior attempt at this)
|
||||
// only helps if that rect actually stays put - and on real mobile
|
||||
// Safari it didn't: .hero-copy (bottom-aligned via flexbox inside
|
||||
// .hero-yes) kept sliding down as the address bar collapsed, even
|
||||
// with a spec'd-stable viewport unit (svh, then lvh) driving the
|
||||
// box's height. Either the browser isn't holding up its end, or
|
||||
// something in the cascade is still landing on a live value - not
|
||||
// provable from here without the device. Rather than keep
|
||||
// guessing at which CSS viewport unit actually holds still, yes.js
|
||||
// becomes the source of truth instead: it freezes .hero-yes's
|
||||
// rendered height to a literal inline px value once, up front. An
|
||||
// inline style always wins the cascade over the stylesheet's
|
||||
// `height: 100svh`, so once this runs, nothing the browser does
|
||||
// with that unit afterward can move the box - the number is fixed
|
||||
// in the DOM, not recomputed from a unit at all.
|
||||
setupCanvas() {
|
||||
const pixelRatio = window.devicePixelRatio || 1;
|
||||
const width = window.innerWidth;
|
||||
const height = window.innerHeight;
|
||||
|
||||
if (this.heroEl) {
|
||||
this.heroEl.style.height = height + 'px';
|
||||
}
|
||||
|
||||
this.rasterCanvas.style.width = width + 'px';
|
||||
this.rasterCanvas.style.height = height + 'px';
|
||||
this.lineCanvas.style.width = width + 'px';
|
||||
this.lineCanvas.style.height = height + 'px';
|
||||
|
||||
this.rasterCanvas.width = width * pixelRatio;
|
||||
this.rasterCanvas.height = height * pixelRatio;
|
||||
this.lineCanvas.width = width * pixelRatio;
|
||||
this.lineCanvas.height = height * pixelRatio;
|
||||
|
||||
this.rasterCtx.scale(pixelRatio, pixelRatio);
|
||||
this.lineCtx.scale(pixelRatio, pixelRatio);
|
||||
|
||||
this.displayWidth = width;
|
||||
this.displayHeight = height;
|
||||
this.pixelRatio = pixelRatio;
|
||||
}
|
||||
|
||||
setupResizeHandler() {
|
||||
// Gate on width, not height: mobile Safari's address-bar
|
||||
// animation changes window.innerHeight continuously with no
|
||||
// real layout change to react to (that's the live value this
|
||||
// whole method exists to stop trusting). A genuine resize -
|
||||
// orientation change, desktop window drag - always changes
|
||||
// width too, so that's the real signal to re-freeze on.
|
||||
this._resizeHandler = () => {
|
||||
if (window.innerWidth === this.displayWidth) return;
|
||||
this.setupCanvas();
|
||||
this.rasterizeText();
|
||||
};
|
||||
window.addEventListener('resize', this._resizeHandler);
|
||||
}
|
||||
|
||||
// The two behavior dials (containmentStrength from x, wiggleAmount
|
||||
// from y) used to follow the pointer. Now a smooth noise field
|
||||
// wanders them instead - the same 0..1 inputs a mouse would give,
|
||||
// but drifting at cloud pace, so the piece breathes on its own and
|
||||
// behaves identically with nobody touching it (which on a landing
|
||||
// hero is most of the time, and on touch devices was always the
|
||||
// case between taps). Value noise with two octaves: smooth
|
||||
// (C1-continuous via smoothstep), never repeats visibly, no jumps.
|
||||
setupDrift() {
|
||||
const channel = (seed) => {
|
||||
const rand = (i) => {
|
||||
let h = Math.imul(i ^ seed, 2654435761) >>> 0;
|
||||
h ^= h >>> 13;
|
||||
h = Math.imul(h, 0x5bd1e995) >>> 0;
|
||||
// The >>> 0 here is load-bearing: ^ yields a SIGNED
|
||||
// 32-bit value, and without the reinterpret a set top
|
||||
// bit made this "0..1" noise go as low as -0.5,
|
||||
// pushing both dials below their intended floors.
|
||||
h = (h ^ (h >>> 15)) >>> 0;
|
||||
return h / 4294967296;
|
||||
};
|
||||
const noise = (t) => {
|
||||
const i = Math.floor(t);
|
||||
const f = t - i;
|
||||
const s = f * f * (3 - 2 * f);
|
||||
return rand(i) * (1 - s) + rand(i + 1) * s;
|
||||
};
|
||||
// Two octaves, renormalized to 0..1: the slow octave sets
|
||||
// the overall weather, the faster one keeps it from
|
||||
// feeling like a pendulum.
|
||||
return (t) => (noise(t) * 2 / 3 + noise(t * 2.7 + 913) * 1 / 3);
|
||||
};
|
||||
|
||||
// One full "weather change" roughly every DRIFT_PERIOD
|
||||
// seconds per octave - the pace of watching clouds, not of a
|
||||
// hand on a mouse.
|
||||
this.driftPeriod = 25;
|
||||
this.driftX = channel(0x9e3779b9);
|
||||
this.driftY = channel(0x85ebca6b);
|
||||
|
||||
this.containmentStrength = 0.55;
|
||||
this.wiggleAmount = 1.05;
|
||||
}
|
||||
|
||||
updateDrift() {
|
||||
const t = this.time / this.driftPeriod;
|
||||
const x = this.driftX(t);
|
||||
const y = this.driftY(t);
|
||||
// Same mapping the mouse position used to feed.
|
||||
this.containmentStrength = 0.1 + (x * 0.9);
|
||||
this.wiggleAmount = 0.1 + (y * 1.9);
|
||||
}
|
||||
|
||||
setupClickHandler() {
|
||||
this.lineCanvas.addEventListener('click', () => {
|
||||
this.restartAnimation();
|
||||
});
|
||||
}
|
||||
|
||||
restartAnimation() {
|
||||
this.time = 0;
|
||||
this.lineCtx.fillStyle = this.theme.paper;
|
||||
this.lineCtx.fillRect(0, 0, this.displayWidth, this.displayHeight);
|
||||
this.initializeLines();
|
||||
this.isActive = true;
|
||||
}
|
||||
|
||||
rasterizeText() {
|
||||
const width = this.displayWidth;
|
||||
const height = this.displayHeight;
|
||||
|
||||
const aspectRatio = width / height;
|
||||
let fontSize;
|
||||
if (aspectRatio < 1) {
|
||||
fontSize = width * 0.4;
|
||||
} else {
|
||||
fontSize = height * 0.5;
|
||||
}
|
||||
|
||||
this.fontSize = fontSize;
|
||||
|
||||
this.rasterCtx.font = `bold ${fontSize}px Arial, sans-serif`;
|
||||
this.rasterCtx.textAlign = 'left';
|
||||
this.rasterCtx.textBaseline = 'middle';
|
||||
|
||||
const fullTextMetrics = this.rasterCtx.measureText('YES');
|
||||
const textWidth = fullTextMetrics.width;
|
||||
const textStartX = (width - textWidth) / 2;
|
||||
const textY = height / 2;
|
||||
|
||||
const letters = ['Y', 'E', 'S'];
|
||||
this.letterPositions = [];
|
||||
let currentX = textStartX;
|
||||
|
||||
for (let i = 0; i < letters.length; i++) {
|
||||
const letterMetrics = this.rasterCtx.measureText(letters[i]);
|
||||
this.letterPositions[i] = {
|
||||
x: currentX,
|
||||
y: textY,
|
||||
width: letterMetrics.width,
|
||||
centerX: currentX + letterMetrics.width / 2
|
||||
};
|
||||
currentX += letterMetrics.width;
|
||||
}
|
||||
|
||||
this.letterRasters = [];
|
||||
|
||||
for (let i = 0; i < 3; i++) {
|
||||
this.rasterCtx.fillStyle = '#111';
|
||||
this.rasterCtx.fillRect(0, 0, width, height);
|
||||
|
||||
this.rasterCtx.fillStyle = '#ffffff';
|
||||
this.rasterCtx.fillText(letters[i], this.letterPositions[i].x, this.letterPositions[i].y);
|
||||
|
||||
this.letterRasters[i] = this.rasterCtx.getImageData(0, 0, this.rasterCanvas.width, this.rasterCanvas.height);
|
||||
}
|
||||
|
||||
// The visible layer, distinct from the letterRasters sampled
|
||||
// above (those stay #111/#fff - isInSpecificLetter's red>128
|
||||
// test depends on it): painted in theme ink so the ghost works
|
||||
// under the theme's blend mode (overlay on dark, multiply on
|
||||
// light - see #rasterCanvas in main.css).
|
||||
this.rasterCtx.fillStyle = this.theme.rasterBg;
|
||||
this.rasterCtx.fillRect(0, 0, width, height);
|
||||
this.rasterCtx.fillStyle = this.theme.rasterInk;
|
||||
this.rasterCtx.fillText('YES', textStartX, textY);
|
||||
|
||||
this.rasterData = this.rasterCtx.getImageData(0, 0, this.rasterCanvas.width, this.rasterCanvas.height);
|
||||
}
|
||||
|
||||
isInSpecificLetter(x, y, letterIndex) {
|
||||
const canvasX = x * this.pixelRatio;
|
||||
const canvasY = y * this.pixelRatio;
|
||||
|
||||
if (!this.letterRasters || !this.letterRasters[letterIndex] ||
|
||||
canvasX < 0 || canvasY < 0 ||
|
||||
canvasX >= this.rasterCanvas.width || canvasY >= this.rasterCanvas.height) {
|
||||
return false;
|
||||
}
|
||||
|
||||
const index = (Math.floor(canvasY) * this.rasterCanvas.width + Math.floor(canvasX)) * 4;
|
||||
const red = this.letterRasters[letterIndex].data[index];
|
||||
return red > 128;
|
||||
}
|
||||
|
||||
initializeLines() {
|
||||
this.lines = [];
|
||||
const numLines = 60;
|
||||
|
||||
const letterCentroids = this.calculateLetterCentroids();
|
||||
|
||||
for (let i = 0; i < numLines; i++) {
|
||||
const letterIndex = Math.floor(i / (numLines / 3));
|
||||
let startX, startY, centerX, centerY;
|
||||
|
||||
if (letterCentroids[letterIndex]) {
|
||||
centerX = letterCentroids[letterIndex].x;
|
||||
centerY = letterCentroids[letterIndex].y;
|
||||
|
||||
const startVariation = this.fontSize * 0.1;
|
||||
startX = centerX + (Math.random() - 0.5) * startVariation;
|
||||
startY = centerY + (Math.random() - 0.5) * startVariation;
|
||||
|
||||
if (!this.isInSpecificLetter(startX, startY, letterIndex)) {
|
||||
const nearestPoint = this.findNearestSpecificLetterPixel(startX, startY, letterIndex);
|
||||
if (nearestPoint) {
|
||||
startX = nearestPoint.x;
|
||||
startY = nearestPoint.y;
|
||||
} else {
|
||||
startX = centerX;
|
||||
startY = centerY;
|
||||
}
|
||||
}
|
||||
} else {
|
||||
const letterPos = this.letterPositions[letterIndex];
|
||||
startX = letterPos.centerX;
|
||||
startY = letterPos.y;
|
||||
centerX = startX;
|
||||
centerY = startY;
|
||||
}
|
||||
|
||||
// Stroke color lives on the theme, looked up per frame by
|
||||
// letterIndex (see draw()) - not frozen per line - so a
|
||||
// theme flip recolors live lines instead of leaving
|
||||
// dark-theme neon smearing across light paper.
|
||||
this.lines.push({
|
||||
relativeX: (startX - centerX) / this.fontSize,
|
||||
relativeY: (startY - centerY) / this.fontSize,
|
||||
prevRelativeX: (startX - centerX) / this.fontSize,
|
||||
prevRelativeY: (startY - centerY) / this.fontSize,
|
||||
angle: Math.random() * Math.PI * 2,
|
||||
letterIndex: letterIndex,
|
||||
lastSeenInside: { x: (startX - centerX) / this.fontSize, y: (startY - centerY) / this.fontSize },
|
||||
outsideDuration: 0
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
calculateLetterCentroids() {
|
||||
const centroids = [];
|
||||
|
||||
for (let letterIndex = 0; letterIndex < 3; letterIndex++) {
|
||||
let sumX = 0, sumY = 0, count = 0;
|
||||
|
||||
const letterPos = this.letterPositions[letterIndex];
|
||||
const searchStartX = Math.max(0, letterPos.x - this.fontSize * 0.1);
|
||||
const searchEndX = Math.min(this.displayWidth, letterPos.x + letterPos.width + this.fontSize * 0.1);
|
||||
const searchStartY = Math.max(0, letterPos.y - this.fontSize * 0.6);
|
||||
const searchEndY = Math.min(this.displayHeight, letterPos.y + this.fontSize * 0.6);
|
||||
|
||||
const step = Math.max(1, Math.floor(this.fontSize * 0.02));
|
||||
for (let y = searchStartY; y <= searchEndY; y += step) {
|
||||
for (let x = searchStartX; x <= searchEndX; x += step) {
|
||||
if (this.isInSpecificLetter(x, y, letterIndex)) {
|
||||
sumX += x;
|
||||
sumY += y;
|
||||
count++;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if (count > 0) {
|
||||
centroids[letterIndex] = {
|
||||
x: sumX / count,
|
||||
y: sumY / count
|
||||
};
|
||||
} else {
|
||||
centroids[letterIndex] = {
|
||||
x: letterPos.centerX,
|
||||
y: letterPos.y
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
return centroids;
|
||||
}
|
||||
|
||||
updateLines() {
|
||||
this.time += 0.016;
|
||||
this.updateDrift();
|
||||
if (!this.isActive) return;
|
||||
|
||||
const letterCentroids = this.calculateLetterCentroids();
|
||||
|
||||
this.lines.forEach(line => {
|
||||
line.prevRelativeX = line.relativeX;
|
||||
line.prevRelativeY = line.relativeY;
|
||||
|
||||
const centroid = letterCentroids[line.letterIndex];
|
||||
if (!centroid) return;
|
||||
|
||||
const currentX = centroid.x + line.relativeX * this.fontSize;
|
||||
const currentY = centroid.y + line.relativeY * this.fontSize;
|
||||
|
||||
const currentlyInside = this.isInSpecificLetter(currentX, currentY, line.letterIndex);
|
||||
|
||||
if (currentlyInside) {
|
||||
line.outsideDuration = 0;
|
||||
line.lastSeenInside = { x: line.relativeX, y: line.relativeY };
|
||||
} else {
|
||||
line.outsideDuration++;
|
||||
}
|
||||
|
||||
const visionDistance = 0.08 * this.fontSize;
|
||||
const centerX = currentX + Math.cos(line.angle) * visionDistance;
|
||||
const centerY = currentY + Math.sin(line.angle) * visionDistance;
|
||||
const leftX = currentX + Math.cos(line.angle - 0.4) * visionDistance;
|
||||
const leftY = currentY + Math.sin(line.angle - 0.4) * visionDistance;
|
||||
const rightX = currentX + Math.cos(line.angle + 0.4) * visionDistance;
|
||||
const rightY = currentY + Math.sin(line.angle + 0.4) * visionDistance;
|
||||
|
||||
const centerSees = this.isInSpecificLetter(centerX, centerY, line.letterIndex);
|
||||
const leftSees = this.isInSpecificLetter(leftX, leftY, line.letterIndex);
|
||||
const rightSees = this.isInSpecificLetter(rightX, rightY, line.letterIndex);
|
||||
|
||||
let speed = 0.02;
|
||||
|
||||
const attractionThreshold = Math.floor(15 + (1 - this.containmentStrength) * 45);
|
||||
|
||||
if (line.outsideDuration > attractionThreshold) {
|
||||
const targetX = line.lastSeenInside.x;
|
||||
const targetY = line.lastSeenInside.y;
|
||||
const deltaX = targetX - line.relativeX;
|
||||
const deltaY = targetY - line.relativeY;
|
||||
const angleToTarget = Math.atan2(deltaY, deltaX);
|
||||
|
||||
let angleDiff = angleToTarget - line.angle;
|
||||
while (angleDiff > Math.PI) angleDiff -= 2 * Math.PI;
|
||||
while (angleDiff < -Math.PI) angleDiff += 2 * Math.PI;
|
||||
|
||||
const baseAttraction = Math.min(0.4, line.outsideDuration / 80);
|
||||
const attractionStrength = baseAttraction * this.containmentStrength;
|
||||
line.angle += angleDiff * attractionStrength;
|
||||
}
|
||||
|
||||
if (centerSees) {
|
||||
const baseWiggle = 0.15;
|
||||
line.angle += (Math.random() - 0.5) * baseWiggle * this.wiggleAmount;
|
||||
} else {
|
||||
speed *= (0.3 + this.containmentStrength * 0.4);
|
||||
|
||||
const baseTurnStrength = 0.3 + (this.containmentStrength * 0.4);
|
||||
const randomTurnAmount = 0.2 * this.wiggleAmount;
|
||||
|
||||
if (leftSees && !rightSees) {
|
||||
line.angle -= baseTurnStrength + Math.random() * randomTurnAmount;
|
||||
} else if (rightSees && !leftSees) {
|
||||
line.angle += baseTurnStrength + Math.random() * randomTurnAmount;
|
||||
} else {
|
||||
const randomTurn = (Math.random() - 0.5) * (0.8 + this.wiggleAmount * 0.7);
|
||||
line.angle += randomTurn;
|
||||
}
|
||||
}
|
||||
|
||||
line.relativeX += Math.cos(line.angle) * speed;
|
||||
line.relativeY += Math.sin(line.angle) * speed;
|
||||
|
||||
line.relativeX = Math.max(-1.7, Math.min(1.7, line.relativeX));
|
||||
line.relativeY = Math.max(-1.7, Math.min(1.7, line.relativeY));
|
||||
});
|
||||
}
|
||||
|
||||
findNearestSpecificLetterPixel(x, y, letterIndex) {
|
||||
const searchRadius = this.fontSize * 0.08;
|
||||
const step = Math.max(1, Math.floor(this.fontSize * 0.01));
|
||||
let nearestPoint = null;
|
||||
let nearestDistance = Infinity;
|
||||
|
||||
for (let dy = -searchRadius; dy <= searchRadius; dy += step) {
|
||||
for (let dx = -searchRadius; dx <= searchRadius; dx += step) {
|
||||
const testX = x + dx;
|
||||
const testY = y + dy;
|
||||
|
||||
if (this.isInSpecificLetter(testX, testY, letterIndex)) {
|
||||
const distance = Math.sqrt(dx * dx + dy * dy);
|
||||
if (distance < nearestDistance) {
|
||||
nearestDistance = distance;
|
||||
nearestPoint = { x: testX, y: testY };
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return nearestPoint;
|
||||
}
|
||||
|
||||
draw() {
|
||||
this.lineCtx.fillStyle = this.theme.fade;
|
||||
this.lineCtx.fillRect(0, 0, this.displayWidth, this.displayHeight);
|
||||
|
||||
const letterCentroids = this.calculateLetterCentroids();
|
||||
|
||||
this.lines.forEach(line => {
|
||||
const centroid = letterCentroids[line.letterIndex];
|
||||
if (!centroid) return;
|
||||
|
||||
const currentX = centroid.x + line.relativeX * this.fontSize;
|
||||
const currentY = centroid.y + line.relativeY * this.fontSize;
|
||||
const prevX = centroid.x + line.prevRelativeX * this.fontSize;
|
||||
const prevY = centroid.y + line.prevRelativeY * this.fontSize;
|
||||
|
||||
if (prevX === currentX && prevY === currentY) return;
|
||||
|
||||
this.lineCtx.strokeStyle = this.theme.strokes[line.letterIndex];
|
||||
this.lineCtx.lineWidth = this.fontSize * 0.003;
|
||||
this.lineCtx.lineCap = 'round';
|
||||
|
||||
this.lineCtx.beginPath();
|
||||
this.lineCtx.moveTo(prevX, prevY);
|
||||
this.lineCtx.lineTo(currentX, currentY);
|
||||
this.lineCtx.stroke();
|
||||
});
|
||||
}
|
||||
|
||||
animate() {
|
||||
if (this.destroyed) return;
|
||||
this.updateLines();
|
||||
this.draw();
|
||||
requestAnimationFrame(() => this.animate());
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user