Compare commits

..
22 Commits
Author SHA1 Message Date
Bendik Aagaard LynghaugandClaude Fable 5 013fd7151e Release 0.3.27
Test / test (push) Successful in 26s
Publish release / publish (push) Successful in 1m40s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 20:26:34 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 99b29bb09f wordmark_invert: explicit, not inferred from .svg
A content-shipped colour logo (Klingenberg's red tile) was being
inverted to teal in light theme by the .svg heuristic. Invert is now
an explicit site.yaml flag defaulting to house-mark-only; content
logos keep their colours unless they opt in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 20:26:34 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 b08e1af139 Release 0.3.26
Test / test (push) Successful in 26s
Publish release / publish (push) Successful in 1m42s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 20:20:50 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 c1cdc53187 Select fields: inline static options
A select requirement can now declare a plain options: [A, B, C] list
instead of a resource - each string is both value and label. Restores
the ancestor question format's inline enums (used by the klingenberg
port) without needing a resource endpoint for a fixed list.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 20:20:50 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 4fee02ab82 Release 0.3.25
Test / test (push) Successful in 28s
Publish release / publish (push) Successful in 1m41s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 20:12:06 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 405bb98185 Content-shipped stylesheet override (site.yaml stylesheet)
A content repo can now ship a CSS file named in site.yaml's
stylesheet field; portal serves it same-origin at /site/<path> and
leptos_meta appends it after the default stylesheet so content rules
win. Plain repo-relative .css path only, validated on load.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 20:12:06 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 7fd40aaca9 Release 0.3.24
Test / test (push) Successful in 26s
Publish release / publish (push) Successful in 1m39s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 20:01:28 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 de6a90bbf5 Gateway submit-as-link loses the underline
A no-requirements gateway alternative renders .alt-submit as an <a>
for plain navigation; strip the link underline so it reads as the
button it's styled to be.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 20:01:28 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 88b1b96322 Release 0.3.23
Test / test (push) Successful in 28s
Publish release / publish (push) Successful in 1m44s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 17:23:33 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 b259bf39bb Chrome speaks the site's language: site.yaml lang + i18n table
The strings the portal itself says - Asked by, Also worth asking,
Sign in, the not-found page, defaults - translate via a small en/no
table selected by site.yaml's lang, which also sets the html lang
attribute. Content keeps speaking for itself; unknown languages fall
back to English per key.

Also: a scheme-gated markdown image now swallows its alt text instead
of leaking it as stray text - this is the fix for the test that has
been red since 0.3.19 (publish is tag-triggered and does not gate on
the test workflow; caught late).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 17:23:28 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 528e2badaf Release 0.3.22
Test / test (push) Failing after 25s
Publish release / publish (push) Successful in 1m39s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 17:17:26 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 f4e9f6d0ba site.yaml wordmark_height; raster logos keep their colors
Custom wordmark sizing per site (0.5-6 rem, clamped at render), and
the light-theme invert now applies only to .svg wordmarks - the
white-stroke house style - so a client's raster logo is never
recolored.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 17:17:11 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 3b2cdc07b7 Release 0.3.21
Test / test (push) Failing after 29s
Publish release / publish (push) Successful in 1m42s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 17:10:49 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 2de936d995 Hero paragraph centers its measure box
max-width: 46ch without auto margins left-anchored the box inside the
centered column; the text centered in the wrong frame.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 17:10:44 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 9fca79b8ee Release 0.3.20
Test / test (push) Failing after 25s
Publish release / publish (push) Successful in 1m36s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 16:54:40 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 3d51aa1e6a Sign-in becomes optional: KANIDM_URL unset disables auth cleanly
A content-only instance (westra preview) has no review desk and no
Kanidm client; booting no longer demands one. Auth routes answer 503
'sign-in is not configured on this instance'; everything public
renders as usual.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 16:54:35 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 d5eb362c87 Release 0.3.19
Test / test (push) Failing after 25s
Publish release / publish (push) Successful in 1m40s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 16:47:01 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 7f10ba20d3 Markdown images in descriptions, gated and framed
Images already flowed through render_inline_markdown ungated; they
now take the same scheme gate as links (https or same-origin only -
no data:, no plain http) and render as full-width framed figures in
alternative, feature, and item-card descriptions. Carries whole-site
imagery for content-driven instances (westra).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 16:46:56 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 756818cacd Release 0.3.18
Test / test (push) Successful in 26s
Publish release / publish (push) Successful in 1m42s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 15:58:45 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 0423e9c368 Merge convergence: ink-to-key animation + overlay results
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 15:58:41 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 ea7acf4d7d Gesture results overlay the canvas - the page never jumps
Echo thumbnails float centered along the canvas's bottom edge and the
empty-state line sits in the same band; both are out of flow, so the
widget's height is fixed by the canvas alone whether results come
back or not. The strip is pointer-inert except the thumbnails
themselves, so drawing near the bottom edge still works.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 15:55:58 +02:00
Bendik Aagaard LynghaugandClaude Fable 5 19f8fbaf03 Convergence: ink converges onto the decoded key (WebGL glow)
On ack (and on picking a place) a glowing copy of the stroke peels
off and converges point-by-point onto the key's decoded path - a
staggered wave from stroke start to end, comet trails, additive on
dark / ink on light, ghost deposited where the light settles. WebGL
point sprites on an overlay canvas; no WebGL or reduced-motion means
exactly the previous behavior. ?relay= query override points widgets
at a local relay for dev.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Y42TyF8Zu7NGRR2893vNcZ
2026-09-01 15:47:09 +02:00
10 changed files with 531 additions and 33 deletions
Generated
+1 -1
View File
@@ -2948,7 +2948,7 @@ dependencies = [
[[package]] [[package]]
name = "portal" name = "portal"
version = "0.3.17" version = "0.3.26"
dependencies = [ dependencies = [
"anyhow", "anyhow",
"arc-swap", "arc-swap",
+1 -1
View File
@@ -1,6 +1,6 @@
[package] [package]
name = "portal" name = "portal"
version = "0.3.17" version = "0.3.27"
edition = "2021" edition = "2021"
[lib] [lib]
+232 -2
View File
@@ -43,6 +43,77 @@ const MAX_ECHOES = 8;
const RECONNECT_BASE_MS = 1000; const RECONNECT_BASE_MS = 1000;
const RECONNECT_MAX_MS = 30000; const RECONNECT_MAX_MS = 30000;
// ── Convergence animation (ink → what the network heard) ──────────
//
// When the ack lands, a glowing copy of the stroke peels off and
// converges point-by-point onto the key's decoded path: a wave of
// "being understood" travels from the stroke's start to its end,
// and the ghost materializes where the light settles. WebGL point
// sprites with additive glow on a dedicated overlay canvas; the 2d
// layer underneath never changes its final render, so losing WebGL
// (or prefers-reduced-motion) degrades to exactly today's behavior.
const CONVERGE_MS = 1500;
const CONVERGE_FADE_MS = 450;
const CONVERGE_POINTS = 128;
const CONVERGE_STAGGER = 0.6; // fraction of the timeline spent on the travelling wave
const GLOW_VERT = `
attribute vec2 aFrom;
attribute vec2 aTo;
attribute float aIndex;
uniform float uT;
uniform vec2 uResolution;
uniform float uDpr;
varying float vLife;
void main() {
float lead = aIndex * ${CONVERGE_STAGGER};
float p = clamp((uT * ${1.0 + CONVERGE_STAGGER} - lead), 0.0, 1.0);
float e = p < 0.5 ? 4.0 * p * p * p : 1.0 - pow(-2.0 * p + 2.0, 3.0) / 2.0;
vec2 pos = mix(aFrom, aTo, e);
vec2 clip = (pos / uResolution) * 2.0 - 1.0;
gl_Position = vec4(clip.x, -clip.y, 0.0, 1.0);
float pulse = 1.0 + 1.4 * sin(3.14159 * p);
gl_PointSize = 9.0 * uDpr * pulse;
vLife = p;
}`;
const GLOW_FRAG = `
precision mediump float;
uniform vec3 uColor;
uniform float uAlpha;
varying float vLife;
void main() {
vec2 d = gl_PointCoord - 0.5;
float fall = exp(-dot(d, d) * 18.0);
float breathe = 0.55 + 0.45 * sin(3.14159 * vLife);
gl_FragColor = vec4(uColor, 1.0) * (fall * uAlpha * breathe);
}`;
// Uniform arc-length resample of a pixel-space polyline to n points.
function resamplePx(points, n) {
if (points.length === 1) return Array(n).fill(points[0]);
const dists = [0];
for (let i = 1; i < points.length; i++) {
const dx = points[i][0] - points[i - 1][0];
const dy = points[i][1] - points[i - 1][1];
dists.push(dists[i - 1] + Math.hypot(dx, dy));
}
const total = dists[dists.length - 1] || 1;
const out = [];
let seg = 0;
for (let i = 0; i < n; i++) {
const target = (i / (n - 1)) * total;
while (seg < points.length - 2 && dists[seg + 1] < target) seg++;
const span = dists[seg + 1] - dists[seg] || 1;
const t = (target - dists[seg]) / span;
out.push([
points[seg][0] + (points[seg + 1][0] - points[seg][0]) * t,
points[seg][1] + (points[seg + 1][1] - points[seg][1]) * t,
]);
}
return out;
}
class GestureWidget { class GestureWidget {
constructor(container, hidden, relayUrl) { constructor(container, hidden, relayUrl) {
this.container = container; this.container = container;
@@ -63,6 +134,17 @@ class GestureWidget {
this.canvas = document.createElement('canvas'); this.canvas = document.createElement('canvas');
this.canvas.className = 'gesture-canvas'; this.canvas.className = 'gesture-canvas';
container.appendChild(this.canvas); container.appendChild(this.canvas);
// Overlay for the convergence glow; sized with the main canvas,
// inert to pointers, empty until an ack arrives.
this.glow = document.createElement('canvas');
this.glow.className = 'gesture-glow';
this.glow.style.position = 'absolute';
this.glow.style.pointerEvents = 'none';
if (!container.style.position) container.style.position = 'relative';
container.appendChild(this.glow);
this.gl = null;
this.animFrame = null;
this.converging = false;
this.echoes = document.createElement('div'); this.echoes = document.createElement('div');
this.echoes.className = 'gesture-echoes'; this.echoes.className = 'gesture-echoes';
this.echoes.setAttribute('role', 'listbox'); this.echoes.setAttribute('role', 'listbox');
@@ -110,6 +192,13 @@ class GestureWidget {
this.ctx.scale(dpr, dpr); this.ctx.scale(dpr, dpr);
this.cssWidth = rect.width; this.cssWidth = rect.width;
this.cssHeight = rect.height; this.cssHeight = rect.height;
this.glow.style.left = `${this.canvas.offsetLeft}px`;
this.glow.style.top = `${this.canvas.offsetTop}px`;
this.glow.style.width = `${rect.width}px`;
this.glow.style.height = `${rect.height}px`;
this.glow.width = this.canvas.width;
this.glow.height = this.canvas.height;
this.cancelConvergence(); // buffers are in old pixels
} }
pos(e) { pos(e) {
@@ -123,6 +212,7 @@ class GestureWidget {
// One stroke only - a new pointerdown replaces the old drawing // One stroke only - a new pointerdown replaces the old drawing
// (and any ghost from the previous round). // (and any ghost from the previous round).
this.drawing = true; this.drawing = true;
this.cancelConvergence();
this.ghost = null; this.ghost = null;
this.ownKey = null; this.ownKey = null;
this.selected = null; this.selected = null;
@@ -254,6 +344,7 @@ class GestureWidget {
applySelection() { applySelection() {
if (this.points.length < 2) return; if (this.points.length < 2) return;
const points = this.normalized(); const points = this.normalized();
const before = this.ghost;
if (this.selected) { if (this.selected) {
this.ghost = this.selected.path; this.ghost = this.selected.path;
this.setValue({ points, key: this.selected.key, own_key: this.ownKey, selected_from: this.ownKey, selected_distance: this.selected.distance }); this.setValue({ points, key: this.selected.key, own_key: this.ownKey, selected_from: this.ownKey, selected_distance: this.selected.distance });
@@ -261,6 +352,7 @@ class GestureWidget {
this.ghost = this.ownGhost || null; this.ghost = this.ownGhost || null;
this.setValue({ points, key: this.ownKey }); this.setValue({ points, key: this.ownKey });
} }
if (this.ghost && this.ghost !== before) this.startConvergence(this.ghost);
for (const el of this.echoes.children) { for (const el of this.echoes.children) {
el.classList.toggle('selected', !!this.selected && el.dataset.key === this.selected.key); el.classList.toggle('selected', !!this.selected && el.dataset.key === this.selected.key);
el.setAttribute('aria-selected', String(!!this.selected && el.dataset.key === this.selected.key)); el.setAttribute('aria-selected', String(!!this.selected && el.dataset.key === this.selected.key));
@@ -317,6 +409,140 @@ class GestureWidget {
setTimeout(() => thumb.classList.add('shown'), 30); setTimeout(() => thumb.classList.add('shown'), 30);
} }
// ── Convergence ────────────────────────────────────────────────
initGlow() {
if (this.gl) return this.gl;
const gl = this.glow.getContext('webgl', { alpha: true, premultipliedAlpha: true });
if (!gl) return null;
const compile = (type, src) => {
const s = gl.createShader(type);
gl.shaderSource(s, src);
gl.compileShader(s);
return s;
};
const prog = gl.createProgram();
gl.attachShader(prog, compile(gl.VERTEX_SHADER, GLOW_VERT));
gl.attachShader(prog, compile(gl.FRAGMENT_SHADER, GLOW_FRAG));
gl.linkProgram(prog);
if (!gl.getProgramParameter(prog, gl.LINK_STATUS)) return null;
gl.useProgram(prog);
this.gl = gl;
this.glProg = prog;
this.glLoc = {
aFrom: gl.getAttribLocation(prog, 'aFrom'),
aTo: gl.getAttribLocation(prog, 'aTo'),
aIndex: gl.getAttribLocation(prog, 'aIndex'),
uT: gl.getUniformLocation(prog, 'uT'),
uResolution: gl.getUniformLocation(prog, 'uResolution'),
uDpr: gl.getUniformLocation(prog, 'uDpr'),
uColor: gl.getUniformLocation(prog, 'uColor'),
uAlpha: gl.getUniformLocation(prog, 'uAlpha'),
};
this.glBufFrom = gl.createBuffer();
this.glBufTo = gl.createBuffer();
this.glBufIndex = gl.createBuffer();
return gl;
}
// The ghost's pixel frame - same fit drawPath uses.
ghostToPx(path) {
const scale = (Math.min(this.cssWidth, this.cssHeight) / 2) * 0.8;
const cx = this.cssWidth / 2, cy = this.cssHeight / 2;
return path.map(([x, y]) => [cx + x * scale, cy + y * scale]);
}
startConvergence(targetPath) {
this.cancelConvergence();
if (!targetPath || this.points.length < 2) return;
if (window.matchMedia('(prefers-reduced-motion: reduce)').matches) return;
const gl = this.initGlow();
if (!gl) return;
const dpr = window.devicePixelRatio || 1;
const from = resamplePx(this.points.map((p) => [p.x, p.y]), CONVERGE_POINTS);
const to = resamplePx(this.ghostToPx(targetPath), CONVERGE_POINTS);
const f = new Float32Array(CONVERGE_POINTS * 2);
const t = new Float32Array(CONVERGE_POINTS * 2);
const idx = new Float32Array(CONVERGE_POINTS);
for (let i = 0; i < CONVERGE_POINTS; i++) {
f[i * 2] = from[i][0] * dpr;
f[i * 2 + 1] = from[i][1] * dpr;
t[i * 2] = to[i][0] * dpr;
t[i * 2 + 1] = to[i][1] * dpr;
idx[i] = i / (CONVERGE_POINTS - 1);
}
const bind = (buf, data, loc, size) => {
gl.bindBuffer(gl.ARRAY_BUFFER, buf);
gl.bufferData(gl.ARRAY_BUFFER, data, gl.STATIC_DRAW);
gl.enableVertexAttribArray(loc);
gl.vertexAttribPointer(loc, size, gl.FLOAT, false, 0, 0);
};
gl.useProgram(this.glProg);
bind(this.glBufFrom, f, this.glLoc.aFrom, 2);
bind(this.glBufTo, t, this.glLoc.aTo, 2);
bind(this.glBufIndex, idx, this.glLoc.aIndex, 1);
gl.viewport(0, 0, this.glow.width, this.glow.height);
gl.uniform2f(this.glLoc.uResolution, this.glow.width, this.glow.height);
gl.uniform1f(this.glLoc.uDpr, dpr);
const light = this._themeQuery.matches;
const color = light ? [0x47 / 255, 0x80 / 255, 0x7e / 255] : [0x8e / 255, 0xc2 / 255, 0xc0 / 255];
gl.uniform3f(this.glLoc.uColor, color[0], color[1], color[2]);
// Additive light on the dark ground; normal ink on the light one.
gl.enable(gl.BLEND);
if (light) gl.blendFunc(gl.SRC_ALPHA, gl.ONE_MINUS_SRC_ALPHA);
else gl.blendFunc(gl.ONE, gl.ONE);
this.converging = true;
this.render();
const started = performance.now();
const step = (now) => {
const raw = (now - started) / CONVERGE_MS;
if (raw >= 1) {
// Deposit the ghost, then let the glow breathe out.
if (this.converging) {
this.converging = false;
this.render();
}
const fade = (now - started - CONVERGE_MS) / CONVERGE_FADE_MS;
if (fade >= 1) {
this.cancelConvergence();
return;
}
gl.clearColor(0, 0, 0, 0);
gl.clear(gl.COLOR_BUFFER_BIT);
gl.uniform1f(this.glLoc.uT, 1);
gl.uniform1f(this.glLoc.uAlpha, 0.32 * (1 - fade));
gl.drawArrays(gl.POINTS, 0, CONVERGE_POINTS);
} else {
gl.clearColor(0, 0, 0, 0);
gl.clear(gl.COLOR_BUFFER_BIT);
// Trailing passes give the wave a comet tail.
for (const [lag, alpha] of [[0, 0.32], [0.035, 0.16], [0.07, 0.08], [0.105, 0.04]]) {
gl.uniform1f(this.glLoc.uT, Math.max(0, raw - lag));
gl.uniform1f(this.glLoc.uAlpha, alpha);
gl.drawArrays(gl.POINTS, 0, CONVERGE_POINTS);
}
}
this.animFrame = requestAnimationFrame(step);
};
this.animFrame = requestAnimationFrame(step);
}
cancelConvergence() {
if (this.animFrame) cancelAnimationFrame(this.animFrame);
this.animFrame = null;
if (this.converging) {
this.converging = false;
this.render();
}
if (this.gl) {
this.gl.clearColor(0, 0, 0, 0);
this.gl.clear(this.gl.COLOR_BUFFER_BIT);
}
}
// ── Rendering ────────────────────────────────────────────────── // ── Rendering ──────────────────────────────────────────────────
// Draw a normalized (-1..1) path fitted into w×h with padding. // Draw a normalized (-1..1) path fitted into w×h with padding.
@@ -341,7 +567,7 @@ class GestureWidget {
if (!this.ctx) return; if (!this.ctx) return;
const t = this.theme(); const t = this.theme();
this.ctx.clearRect(0, 0, this.cssWidth, this.cssHeight); this.ctx.clearRect(0, 0, this.cssWidth, this.cssHeight);
if (this.ghost) { if (this.ghost && !this.converging) {
this.drawPath(this.ctx, this.ghost, this.cssWidth, this.cssHeight, t.ghost, 2, 0.2); this.drawPath(this.ctx, this.ghost, this.cssWidth, this.cssHeight, t.ghost, 2, 0.2);
} }
if (this.points.length >= 1) { if (this.points.length >= 1) {
@@ -360,6 +586,7 @@ class GestureWidget {
stop() { stop() {
this.stopped = true; this.stopped = true;
if (this.animFrame) cancelAnimationFrame(this.animFrame);
clearTimeout(this.emptyTimer); clearTimeout(this.emptyTimer);
if (this.reconnectTimer) clearTimeout(this.reconnectTimer); if (this.reconnectTimer) clearTimeout(this.reconnectTimer);
if (this.ws) { if (this.ws) {
@@ -378,5 +605,8 @@ class GestureWidget {
} }
export function mountGesture(container, hidden, relayUrl) { export function mountGesture(container, hidden, relayUrl) {
return new GestureWidget(container, hidden, relayUrl); // Dev convenience: `?relay=ws://127.0.0.1:9040` points every widget
// on the page at a local relay (prod relays reject foreign Origins).
const override = new URLSearchParams(window.location.search).get('relay');
return new GestureWidget(container, hidden, override || relayUrl);
} }
+58 -16
View File
@@ -1,5 +1,5 @@
use leptos::prelude::*; use leptos::prelude::*;
use leptos_meta::{provide_meta_context, HashedStylesheet, MetaTags, Title}; use leptos_meta::{provide_meta_context, HashedStylesheet, Html, MetaTags, Stylesheet, Title};
use leptos_router::{ use leptos_router::{
components::{Route, Router, Routes}, components::{Route, Router, Routes},
hooks::{use_location, use_navigate, use_query_map}, hooks::{use_location, use_navigate, use_query_map},
@@ -10,6 +10,7 @@ use serde::{Deserialize, Serialize};
use crate::answers::{Answer, SelfTransitionAnswer, TransitionAnswers, TransitionItem}; use crate::answers::{Answer, SelfTransitionAnswer, TransitionAnswers, TransitionItem};
use crate::auth::{current_user, User}; use crate::auth::{current_user, User};
use crate::content::{is_qualified, render_inline_markdown, Alternative, Question, Responsible, SiteConfig, Transition}; use crate::content::{is_qualified, render_inline_markdown, Alternative, Question, Responsible, SiteConfig, Transition};
use crate::i18n::t;
use crate::resource::{get_requirement_binding, get_requirement_options, get_resource}; use crate::resource::{get_requirement_binding, get_requirement_options, get_resource};
/// The visible site name/wordmark - "portal" is just this codebase's /// The visible site name/wordmark - "portal" is just this codebase's
@@ -68,8 +69,30 @@ pub fn App() -> impl IntoView {
// context instead of fetching their own copy. // context instead of fetching their own copy.
let site = Resource::new(|| (), |_| get_site()); let site = Resource::new(|| (), |_| get_site());
provide_context(site); provide_context(site);
// The chrome's language, from site.yaml (default "en"); content
// speaks for itself. Components read this via context for t().
let lang = Memo::new(move |_| {
site.get()
.and_then(|r| r.ok())
.and_then(|s| s.lang)
.unwrap_or_else(|| "en".to_string())
});
provide_context(Lang(lang));
// A content-shipped stylesheet (site.yaml `stylesheet:`) layered
// after the default one - leptos_meta appends it at the MetaTags
// slot, which the shell places after HashedStylesheet, so content
// rules win at equal specificity.
let custom_css = Memo::new(move |_| {
site.get()
.and_then(|r| r.ok())
.and_then(|s| s.stylesheet)
.map(|p| format!("/site/{p}"))
});
view! { view! {
<Html attr:lang=move || lang.get()/>
{move || custom_css.get().map(|href| view! { <Stylesheet id="site-custom" href=href/> })}
<Suspense fallback=|| ()> <Suspense fallback=|| ()>
{move || { {move || {
site.get() site.get()
@@ -88,6 +111,15 @@ pub fn App() -> impl IntoView {
} }
} }
/// The site's chrome language as a context signal - see App.
#[derive(Clone, Copy)]
pub struct Lang(pub Memo<String>);
/// The current chrome language, for `t()` calls inside views.
fn lang() -> Memo<String> {
expect_context::<Lang>().0
}
/// Every server-fn resource the pages read, created exactly once for /// Every server-fn resource the pages read, created exactly once for
/// the app's lifetime and handed down via context. Wrapper structs /// the app's lifetime and handed down via context. Wrapper structs
/// because a bare `Resource<T>` context is claimed by whoever provides /// because a bare `Resource<T>` context is claimed by whoever provides
@@ -241,7 +273,7 @@ fn QuestionView(
/> />
<div class="alternatives"> <div class="alternatives">
<section class="alt-card gate-card"> <section class="alt-card gate-card">
<p>"This page follows from an answer you don't seem to carry yet."</p> <p>{move || t(&lang().get(), "follows_answer")}</p>
<a class="alt-submit" href=target> <a class="alt-submit" href=target>
{label} {label}
</a> </a>
@@ -269,7 +301,7 @@ fn QuestionView(
<div class="alternatives"> <div class="alternatives">
<section class="alt-card gate-card"> <section class="alt-card gate-card">
{if signed_in { {if signed_in {
view! { <p>"This part of the site is for organizational owners — sign in with that account to take a look."</p> } view! { <p>{move || t(&lang().get(), "owners_only")}</p> }
.into_any() .into_any()
} else { } else {
view! { view! {
@@ -278,7 +310,7 @@ fn QuestionView(
href=format!("/auth/login?redirect={question_id}") href=format!("/auth/login?redirect={question_id}")
rel="external" rel="external"
> >
"Sign in" {move || t(&lang().get(), "sign_in")}
</a> </a>
} }
.into_any() .into_any()
@@ -371,7 +403,7 @@ fn QuestionNav(current_id: String, has_chain: bool) -> impl IntoView {
.collect(); .collect();
(!others.is_empty()).then(|| view! { (!others.is_empty()).then(|| view! {
<nav class="question-nav"> <nav class="question-nav">
<span class="question-nav-lead">"Also worth asking"</span> <span class="question-nav-lead">{move || t(&lang().get(), "also_worth_asking")}</span>
<For <For
each=move || others.clone() each=move || others.clone()
key=|(id, _)| id.clone() key=|(id, _)| id.clone()
@@ -399,7 +431,7 @@ fn Announcements(current_id: String) -> impl IntoView {
let current_id = current_id.clone(); let current_id = current_id.clone();
announcements.get().and_then(|res| res.ok()).map(|items| { announcements.get().and_then(|res| res.ok()).map(|items| {
(!items.is_empty()).then(|| view! { (!items.is_empty()).then(|| view! {
<nav class="announce" aria-label="Announcements"> <nav class="announce" aria-label=move || t(&lang().get(), "announcements")>
<For <For
each=move || items.clone() each=move || items.clone()
key=|a| a.id.clone() key=|a| a.id.clone()
@@ -459,11 +491,11 @@ fn ResponsibleNote(responsible: Responsible) -> impl IntoView {
view! { view! {
<small class="question-responsible"> <small class="question-responsible">
"Asked by " {responsible.name.clone()} "" {move || t(&lang().get(), "asked_by")} {responsible.name.clone()} ""
<a data-user=user data-domain=domain on:mouseover=assemble on:click=assemble> <a data-user=user data-domain=domain on:mouseover=assemble on:click=assemble>
"contact them" {move || t(&lang().get(), "contact_them")}
</a> </a>
" if you get stuck." {move || t(&lang().get(), "if_stuck")}
</small> </small>
} }
} }
@@ -555,7 +587,17 @@ fn Hero(title: String, description: String, landing: bool, site: SiteConfig, cur
None None
}; };
let has_module = module.is_some(); let has_module = module.is_some();
// Light theme can invert a white-stroke wordmark to ink. Default:
// only the built-in house mark inverts; a content-shipped logo
// keeps its colours unless site.yaml opts in with wordmark_invert.
let house_wordmark = site.wordmark_invert.unwrap_or(site.wordmark.is_none());
let wordmark = site.wordmark.clone().unwrap_or_else(|| "/wordmark.svg".to_string()); let wordmark = site.wordmark.clone().unwrap_or_else(|| "/wordmark.svg".to_string());
// Clamped server-side too, but belt and braces for the inline style.
let wordmark_style = site
.wordmark_height
.filter(|h| (0.5..=6.0).contains(h))
.map(|h| format!("height: {h}rem"))
.unwrap_or_default();
let site_title = site.title.clone().unwrap_or_else(|| SITE_NAME.to_string()); let site_title = site.title.clone().unwrap_or_else(|| SITE_NAME.to_string());
let piece_ref: NodeRef<leptos::html::Div> = NodeRef::new(); let piece_ref: NodeRef<leptos::html::Div> = NodeRef::new();
@@ -641,8 +683,8 @@ fn Hero(title: String, description: String, landing: bool, site: SiteConfig, cur
} }
})} })}
<div class="hero-copy"> <div class="hero-copy">
<a class="wordmark" href="/"> <a class="wordmark" class:wordmark-house=house_wordmark href="/">
<img src=wordmark alt=site_title/> <img src=wordmark alt=site_title style=wordmark_style/>
</a> </a>
<h1>{title}</h1> <h1>{title}</h1>
<p>{description}</p> <p>{description}</p>
@@ -727,7 +769,7 @@ fn AlternativeCard(
</button> </button>
} }
.into_any(), .into_any(),
Some(Ok(())) => view! { <p>"Done."</p> }.into_any(), Some(Ok(())) => view! { <p>{move || t(&lang().get(), "done")}</p> }.into_any(),
Some(Err(e)) => view! { <p class="resource-error">{e.to_string()}</p> }.into_any(), Some(Err(e)) => view! { <p class="resource-error">{e.to_string()}</p> }.into_any(),
} }
}} }}
@@ -922,7 +964,7 @@ fn AlternativeCard(
.consequence .consequence
.first() .first()
.cloned() .cloned()
.unwrap_or_else(|| "Send".to_string()); .unwrap_or_else(|| t(&lang().get(), "send").to_string());
view! { view! {
<section class="alt-card"> <section class="alt-card">
@@ -1412,7 +1454,7 @@ fn ResourceFeature(
{move || { {move || {
let feature_name = feature_name.clone(); let feature_name = feature_name.clone();
let transitions = transitions.clone(); let transitions = transitions.clone();
let empty = empty.clone().unwrap_or_else(|| "Nothing here yet.".to_string()); let empty = empty.clone().unwrap_or_else(|| t(&lang().get(), "nothing_here_yet").to_string());
data.get() data.get()
.map(|res| match res { .map(|res| match res {
Ok(value) => { Ok(value) => {
@@ -1881,8 +1923,8 @@ fn format_ms(ms: i64) -> String {
fn NotFound() -> impl IntoView { fn NotFound() -> impl IntoView {
view! { view! {
<main class="not-found"> <main class="not-found">
<h1>"Nothing here"</h1> <h1>{move || t(&lang().get(), "nothing_here")}</h1>
<a href="/">"back to the start"</a> <a href="/">{move || t(&lang().get(), "back_to_start")}</a>
</main> </main>
} }
} }
+64 -2
View File
@@ -183,6 +183,7 @@ pub fn render_inline_markdown(text: &str) -> String {
use pulldown_cmark::{html, Event, Options, Parser, Tag, TagEnd}; use pulldown_cmark::{html, Event, Options, Parser, Tag, TagEnd};
let parser = Parser::new_ext(text, Options::empty()); let parser = Parser::new_ext(text, Options::empty());
let mut in_link = 0usize; let mut in_link = 0usize;
let mut in_dropped_image = 0usize;
let filtered = parser.filter_map(|event| match event { let filtered = parser.filter_map(|event| match event {
Event::Html(_) | Event::InlineHtml(_) => None, Event::Html(_) | Event::InlineHtml(_) => None,
Event::Start(Tag::Paragraph) | Event::End(TagEnd::Paragraph) => None, Event::Start(Tag::Paragraph) | Event::End(TagEnd::Paragraph) => None,
@@ -199,6 +200,21 @@ pub fn render_inline_markdown(text: &str) -> String {
in_link -= 1; in_link -= 1;
None None
} }
// Images take the same gate as links: https or same-origin
// only - no data:, no plain http. Unlike a dropped link (whose
// label is real text worth keeping), a dropped image's alt
// text is a caption for something that isn't there - swallow it.
Event::Start(Tag::Image { dest_url, .. })
if !(dest_url.starts_with("https://") || dest_url.starts_with('/')) =>
{
in_dropped_image += 1;
None
}
Event::End(TagEnd::Image) if in_dropped_image > 0 => {
in_dropped_image -= 1;
None
}
Event::Text(_) if in_dropped_image > 0 => None,
other => Some(other), other => Some(other),
}); });
let mut out = String::new(); let mut out = String::new();
@@ -430,6 +446,12 @@ pub struct Requirement {
/// `ResourceSpec` mechanism a `Feature.resource` uses. /// `ResourceSpec` mechanism a `Feature.resource` uses.
#[serde(default)] #[serde(default)]
pub resource: Option<ResourceSpec>, pub resource: Option<ResourceSpec>,
/// `type: select` only - a static list of options, as an
/// alternative to a `resource`. Each string is both the option's
/// stored value and its label. Faithful to the ancestor format's
/// inline enums.
#[serde(default)]
pub options: Vec<String>,
/// `type: select` only - which field in each item is the option's /// `type: select` only - which field in each item is the option's
/// stable id. Defaults to trying `_id` then `id`. /// stable id. Defaults to trying `_id` then `id`.
#[serde(default)] #[serde(default)]
@@ -501,6 +523,27 @@ pub struct SiteConfig {
/// `None` falls back to `/wordmark.svg`. /// `None` falls back to `/wordmark.svg`.
#[serde(default)] #[serde(default)]
pub wordmark: Option<String>, pub wordmark: Option<String>,
/// Whether to invert the wordmark in light theme. `None` inverts
/// only the built-in house wordmark (a white-stroke SVG); a
/// content-shipped logo keeps its own colours unless it sets this
/// true (e.g. a sibling site's white-stroke mark).
#[serde(default)]
pub wordmark_invert: Option<bool>,
/// Wordmark display height in rem (0.56.0). `None` keeps the
/// stylesheet's default. Raster logos look best at or below their
/// intrinsic pixel height.
#[serde(default)]
pub wordmark_height: Option<f32>,
/// BCP 47-ish language code for the portal's own chrome strings
/// ("Asked by", the nav lead...) and the html lang attribute.
/// `None` means "en"; unknown codes fall back to English per key.
#[serde(default)]
pub lang: Option<String>,
/// A content-repo-relative CSS file (e.g. "custom.css") layered
/// *after* the default stylesheet, so it overrides. Served
/// same-origin at `/site/<path>`; plain path only.
#[serde(default)]
pub stylesheet: Option<String>,
#[serde(default)] #[serde(default)]
pub hero: HeroConfig, pub hero: HeroConfig,
} }
@@ -556,6 +599,13 @@ impl SiteConfig {
} }
other => anyhow::bail!("site.yaml: hero.kind {other:?} is not one of plain | module"), other => anyhow::bail!("site.yaml: hero.kind {other:?} is not one of plain | module"),
} }
if let Some(sheet) = &self.stylesheet {
if !is_safe_site_path(sheet) || !sheet.ends_with(".css") {
anyhow::bail!(
"site.yaml: stylesheet {sheet:?} must be a plain repo-relative .css path"
);
}
}
Ok(()) Ok(())
} }
} }
@@ -1166,9 +1216,12 @@ pub fn validate_questions(
.collect(); .collect();
for feature in &alternative.features { for feature in &alternative.features {
for requirement in &feature.requirements { for requirement in &feature.requirements {
if requirement.kind == "select" && requirement.resource.is_none() { if requirement.kind == "select"
&& requirement.resource.is_none()
&& requirement.options.is_empty()
{
anyhow::bail!( anyhow::bail!(
"question {:?} alternative {:?} feature {:?}: requirement {:?} is type: select but declares no resource to select from", "question {:?} alternative {:?} feature {:?}: requirement {:?} is type: select but declares neither a resource nor inline options",
question.id, alternative.name, feature.name, requirement.name question.id, alternative.name, feature.name, requirement.name
); );
} }
@@ -2026,6 +2079,15 @@ alternatives:
fn markdown_drops_html_and_unsafe_links() { fn markdown_drops_html_and_unsafe_links() {
assert_eq!(render_inline_markdown("x <script>y</script> z"), "x y z"); assert_eq!(render_inline_markdown("x <script>y</script> z"), "x y z");
assert_eq!(render_inline_markdown("[bad](javascript:alert(1))"), "bad"); assert_eq!(render_inline_markdown("[bad](javascript:alert(1))"), "bad");
assert_eq!(
render_inline_markdown("![site](https://x.no/a.jpg)"),
"<img src=\"https://x.no/a.jpg\" alt=\"site\" />"
);
assert_eq!(render_inline_markdown("![x](data:image/png;base64,AA)"), "");
assert_eq!(
render_inline_markdown("![local](/images/a.jpg)"),
"<img src=\"/images/a.jpg\" alt=\"local\" />"
);
assert_eq!(render_inline_markdown("[ok](/shape)"), "<a href=\"/shape\">ok</a>"); assert_eq!(render_inline_markdown("[ok](/shape)"), "<a href=\"/shape\">ok</a>");
assert_eq!(render_inline_markdown("[mail](mailto:bl@uhhm.no)"), "<a href=\"mailto:bl@uhhm.no\">mail</a>"); assert_eq!(render_inline_markdown("[mail](mailto:bl@uhhm.no)"), "<a href=\"mailto:bl@uhhm.no\">mail</a>");
} }
+97
View File
@@ -0,0 +1,97 @@
//! Chrome-string translations, selected by `site.yaml`'s `lang`.
//!
//! Content carries its own language; this covers only the strings the
//! portal itself speaks around it ("Asked by", the nav lead, the
//! not-found page...). Unknown languages and unknown keys fall back
//! to English, so a typo degrades to the default instead of a blank.
/// Translate `key` for `lang`. `en` is the reference table; every
/// other language falls through to it for keys it doesn't carry.
pub fn t(lang: &str, key: &str) -> &'static str {
if let Some(s) = lookup(lang, key) {
return s;
}
lookup("en", key).unwrap_or(key_missing(key))
}
fn lookup(lang: &str, key: &str) -> Option<&'static str> {
Some(match (lang, key) {
("en", "also_worth_asking") => "Also worth asking",
("en", "asked_by") => "Asked by ",
("en", "contact_them") => "contact them",
("en", "if_stuck") => " if you get stuck.",
("en", "send") => "Send",
("en", "sign_in") => "Sign in",
("en", "nothing_here_yet") => "Nothing here yet.",
("en", "nothing_here") => "Nothing here",
("en", "back_to_start") => "back to the start",
("en", "done") => "Done.",
("en", "follows_answer") => {
"This page follows from an answer you don't seem to carry yet."
}
("en", "owners_only") => {
"This part of the site is for organizational owners — sign in with that account to take a look."
}
("en", "announcements") => "Announcements",
("no", "also_worth_asking") => "Også verdt å spørre",
("no", "asked_by") => "Stilt av ",
("no", "contact_them") => "ta kontakt",
("no", "if_stuck") => " om du står fast.",
("no", "send") => "Send",
("no", "sign_in") => "Logg inn",
("no", "nothing_here_yet") => "Ingenting her ennå.",
("no", "nothing_here") => "Ingenting her",
("no", "back_to_start") => "tilbake til start",
("no", "done") => "Ferdig.",
("no", "follows_answer") => {
"Denne siden følger av et svar du ikke ser ut til å bære ennå."
}
("no", "owners_only") => {
"Denne delen av siden er for organisasjonens eiere — logg inn med den kontoen for å ta en titt."
}
("no", "announcements") => "Kunngjøringer",
_ => return None,
})
}
/// A missing key is a programmer error; render the key itself so it
/// is findable, never a panic in a view.
fn key_missing(key: &str) -> &'static str {
// Leak is bounded: keys are a small fixed set of literals.
Box::leak(key.to_string().into_boxed_str())
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn norwegian_covers_the_english_table() {
for key in [
"also_worth_asking",
"asked_by",
"contact_them",
"if_stuck",
"send",
"sign_in",
"nothing_here_yet",
"nothing_here",
"back_to_start",
"done",
"follows_answer",
"owners_only",
"announcements",
] {
assert!(lookup("en", key).is_some(), "en missing {key}");
assert!(lookup("no", key).is_some(), "no missing {key}");
}
}
#[test]
fn unknown_language_falls_back_to_english() {
assert_eq!(t("de", "sign_in"), "Sign in");
assert_eq!(t("en", "sign_in"), "Sign in");
}
}
+1
View File
@@ -4,6 +4,7 @@ pub mod auth;
pub mod chain; pub mod chain;
pub mod content; pub mod content;
pub mod events; pub mod events;
pub mod i18n;
pub mod resource; pub mod resource;
#[cfg(feature = "ssr")] #[cfg(feature = "ssr")]
+10
View File
@@ -68,6 +68,16 @@ pub async fn get_requirement_options(
.iter() .iter()
.find(|r| r.name == requirement_name) .find(|r| r.name == requirement_name)
.ok_or_else(|| ServerFnError::new("unknown requirement"))?; .ok_or_else(|| ServerFnError::new("unknown requirement"))?;
// Inline options: return them as {id,label} objects, the shape the
// SelectField renders, without touching a resource.
if !requirement.options.is_empty() {
let items: Vec<serde_json::Value> = requirement
.options
.iter()
.map(|o| serde_json::json!({ "id": o, "label": o }))
.collect();
return Ok(serde_json::Value::Array(items));
}
let resource = requirement let resource = requirement
.resource .resource
.as_ref() .as_ref()
+26 -4
View File
@@ -33,6 +33,13 @@ type OidcClient = CoreClient<
>; >;
pub struct Oidc { pub struct Oidc {
/// `None` when `KANIDM_URL` is unset: a content-only instance with
/// sign-in disabled - auth routes answer 503, everything public
/// renders as usual.
inner: Option<OidcInner>,
}
struct OidcInner {
client: OidcClient, client: OidcClient,
http: openidconnect::reqwest::Client, http: openidconnect::reqwest::Client,
} }
@@ -45,7 +52,13 @@ const REDIRECT_KEY: &str = "oidc_post_login_redirect";
impl Oidc { impl Oidc {
/// Discovers the provider and builds the client from environment: /// Discovers the provider and builds the client from environment:
/// `KANIDM_URL`, `OAUTH2_CLIENT_ID`, `OAUTH2_CLIENT_SECRET`, `PUBLIC_URL`. /// `KANIDM_URL`, `OAUTH2_CLIENT_ID`, `OAUTH2_CLIENT_SECRET`, `PUBLIC_URL`.
/// With `KANIDM_URL` unset, sign-in is disabled instead of fatal -
/// the shape of a public content instance without a review desk.
pub async fn from_env() -> anyhow::Result<Self> { pub async fn from_env() -> anyhow::Result<Self> {
if std::env::var("KANIDM_URL").is_err() {
tracing::warn!("KANIDM_URL not set - sign-in disabled on this instance");
return Ok(Self { inner: None });
}
let kanidm_url = require_env("KANIDM_URL")?; let kanidm_url = require_env("KANIDM_URL")?;
let client_id = require_env("OAUTH2_CLIENT_ID")?; let client_id = require_env("OAUTH2_CLIENT_ID")?;
let client_secret = require_env("OAUTH2_CLIENT_SECRET")?; let client_secret = require_env("OAUTH2_CLIENT_SECRET")?;
@@ -75,7 +88,16 @@ impl Oidc {
) )
.set_redirect_uri(redirect); .set_redirect_uri(redirect);
Ok(Self { client, http }) Ok(Self {
inner: Some(OidcInner { client, http }),
})
}
fn configured(&self) -> Result<&OidcInner, HandlerError> {
self.inner.as_ref().ok_or((
StatusCode::SERVICE_UNAVAILABLE,
"sign-in is not configured on this instance".to_string(),
))
} }
} }
@@ -118,10 +140,10 @@ pub async fn login(
session.insert(REDIRECT_KEY, redirect).await.map_err(internal)?; session.insert(REDIRECT_KEY, redirect).await.map_err(internal)?;
} }
let oidc = state.oidc.configured()?;
let (pkce_challenge, pkce_verifier) = PkceCodeChallenge::new_random_sha256(); let (pkce_challenge, pkce_verifier) = PkceCodeChallenge::new_random_sha256();
let (auth_url, csrf_state, nonce) = state let (auth_url, csrf_state, nonce) = oidc
.oidc
.client .client
.authorize_url( .authorize_url(
CoreAuthenticationFlow::AuthorizationCode, CoreAuthenticationFlow::AuthorizationCode,
@@ -182,7 +204,7 @@ pub async fn callback(
)); ));
} }
let oidc = &state.oidc; let oidc = state.oidc.configured()?;
let token_response = oidc let token_response = oidc
.client .client
.exchange_code(AuthorizationCode::new(params.code)) .exchange_code(AuthorizationCode::new(params.code))
+41 -7
View File
@@ -99,10 +99,10 @@
--hero-glow: rgba(246, 245, 241, 0.85); --hero-glow: rgba(246, 245, 241, 0.85);
} }
/* The wordmark SVG is a hardcoded white stroke (also used raw in /* The house wordmark SVG is a hardcoded white stroke (also used
dark contexts elsewhere) - flip it to ink here rather than fork raw in dark contexts elsewhere) - flip it to ink here rather
the asset. */ than fork the asset. A content-provided logo keeps its colors. */
.wordmark img { .wordmark-house img {
filter: invert(0.92); filter: invert(0.92);
} }
@@ -193,6 +193,10 @@ main.not-found {
color: var(--ink-dim); color: var(--ink-dim);
font-size: 1.05rem; font-size: 1.05rem;
max-width: 46ch; max-width: 46ch;
/* The measure cap shrinks the box below the copy column; without
auto margins the box left-anchors and its centered text centers
in the wrong frame. */
margin-inline: auto;
} }
/* A content-shipped hero module (site.yaml hero.kind: module) draws /* A content-shipped hero module (site.yaml hero.kind: module) draws
@@ -536,6 +540,18 @@ main.not-found {
color: var(--accent); color: var(--accent);
} }
/* images inside markdown descriptions: full-width figures in the
card's flow, framed like the rest of the press sheet */
.alt-description img,
.item-card-description img,
.feature p img {
display: block;
width: 100%;
margin: 0.6rem 0 0.2rem;
border-radius: 0.5rem;
border: 0.06rem solid var(--line);
}
.alt-description code, .alt-description code,
.feature p code { .feature p code {
font-size: 0.9em; font-size: 0.9em;
@@ -647,11 +663,17 @@ textarea:focus {
touch-action: none; touch-action: none;
} }
/* Results overlay the canvas instead of growing the widget - the
page never jumps when places arrive (or don't). */
.gesture-echoes { .gesture-echoes {
position: absolute;
left: 0.6rem;
right: 0.6rem;
bottom: 0.6rem;
display: flex; display: flex;
justify-content: center;
gap: 0.5rem; gap: 0.5rem;
margin-top: 0.5rem; pointer-events: none;
min-height: 3rem;
} }
.gesture-echoes:empty { .gesture-echoes:empty {
@@ -666,6 +688,8 @@ textarea:focus {
border-radius: 0.4rem; border-radius: 0.4rem;
opacity: 0; opacity: 0;
transition: opacity 0.5s ease; transition: opacity 0.5s ease;
pointer-events: auto;
box-shadow: 0 0.15rem 0.6rem rgba(0, 0, 0, 0.18);
} }
.gesture-echo.shown { .gesture-echo.shown {
@@ -691,9 +715,15 @@ textarea:focus {
} }
.gesture-empty { .gesture-empty {
margin: 0.5rem 0 0; position: absolute;
left: 0;
right: 0;
bottom: 0.7rem;
margin: 0;
text-align: center;
font-size: 0.85rem; font-size: 0.85rem;
color: var(--ink-dim); color: var(--ink-dim);
pointer-events: none;
} }
.gesture-empty:empty { .gesture-empty:empty {
@@ -831,6 +861,10 @@ textarea:focus {
padding: 0.75rem 1.4rem; padding: 0.75rem 1.4rem;
cursor: pointer; cursor: pointer;
transition: filter 120ms, transform 120ms; transition: filter 120ms, transform 120ms;
/* A gateway alternative renders this as an <a> (navigation, no POST);
kill the link chrome so it reads as the button it looks like. */
text-decoration: none;
display: inline-block;
} }
.alt-submit:hover { .alt-submit:hover {