gitoriaLog in with ident

ident

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commitd2e7f91bd2e7f91bident mission 009 (2/4): one lib file per topic (login, accounts, identities, apps, invites, selector, notify + helpers, util), function routes as thin wrappers in lib/api.hl, project.hl = the map; same outputmred2e7f91b/missions/003-ident-apps-login-button.md

4.9 KB

  1. # Mission 003 (old 006) — ident 2/6: apps and login button (ticket #25)
  2. One-shot worker. The architect (Claude Code on Byrodin) verifies your report, then the creator tests.
  3. ## Read first — in this order
  4. 1. **`loreana:/media/STORAGE/projects/ident.worldapi.org/CONCEPT.md`** — the creator's concept. Source
  5. of truth. Do not add features it does not describe; where it is silent, make the smallest choice
  6. and list it under "Questions for the creator".
  7. 2. The app's `README.md` and `STATUS.md` (piece 1, mission 002 (old 005), confirmed by the creator).
  8. Note `.scratch/removed-mission003/`: the old redirect + one-time-code exchange from mission 001 (old 003) —
  9. reuse its mechanics where they fit the concept, not its data model.
  10. 3. `/CONTAINERS/projects/antcolony/README.md` (section "Lessons learned").
  11. 4. Ticket: `GET http://100.77.141.84:8350/api/tickets/25`.
  12. ## Hybriel (standard block)
  13. Read `/CONTAINERS/projects/antcolony/docs/hybriel-for-app-workers.md` first — it lists which docs to
  14. trust, the known pitfalls with workarounds (note #31: forged face sessions), and the open hybriel
  15. tickets. Report new Hybriel findings under "Hybriel issues"; do not edit that guide.
  16. ## Where
  17. - Host Loreana (`ssh loreana`, fish login shell → `bash -c '…'` or script files).
  18. - App: `/media/STORAGE/projects/ident.worldapi.org`, dev port **8351**. Hybriel repo READ ONLY.
  19. ## Scope (piece 2 of 6 only)
  20. 1. **Apps**: any signed-in ident user can register apps in ident (name + the origin(s) it runs on,
  21. used to validate return URLs). Each app gets a **public API key** and a **secret** (shown once or
  22. re-viewable — your choice, list it). The user sees and manages their apps (list, edit, regenerate
  23. secret, delete).
  24. 2. **One identity id per app**: when an identity logs in to an app for the first time, ident creates
  25. the connection with a new, app-specific identity id (not derivable from other apps' ids) and
  26. stores when it was created ("when they registered in it" — needed later for the per-app page).
  27. 3. **Login button flow**: app sends the browser to ident with its API key and a return URL (return
  28. origin must be one of the app's registered origins, else an error page and no redirect). Not
  29. signed in → ident login first. Signed in → the user chooses one of their identities (with only one
  30. identity: still show which one is used, one click). Then ident redirects back with a one-time code
  31. (short-lived, single use).
  32. 4. **Exchange**: the app's server posts the code with its API key + secret and gets back **only the
  33. app-specific identity id** — no email, no names (concept: apps ask for extra data themselves).
  34. Wrong secret, other app's code, reused/expired code → 400/401.
  35. 5. A **minimal test app** (separate tiny hybriel app in `testapp/`, own port) that registers as an app
  36. and proves the whole flow, incl. that a second app gets a different id for the same identity.
  37. **Out of scope**: selector (#26), notifications (#27+), client-only apps.
  38. ## Mail — IMPORTANT
  39. The dev server on :8351 now sends **real mail** (SMTP via mail.byrod.in, set by the creator).
  40. - **Never trigger an OTP on the :8351 dev server.** Do not run `tests/dev-smoke.mjs` against it.
  41. - Your gate starts its own servers with `IDENT_MAIL_SINK` set (as the current gate does).
  42. - **Do not read, print, copy or edit `.env`** (it holds the SMTP password). If you need other settings,
  43. pass them as environment variables to your own test servers.
  44. - At the end restart the dev server (kill only the PID in `server.pid`, `setsid nohup ./bin/hybriel
  45. project.hl >> server.log`, update `server.pid`) and check it answers 200 on `/` — without logging in.
  46. Leave your test app running on its port so the creator can try the flow; report its URL/PID.
  47. ## Data
  48. The dev store holds the creator's real account now. Back up `storage/` to `.scratch/storage-backup-<ts>/`
  49. before the restart; migrate, never wipe. After the restart verify (read-only, e.g. with a small hybriel
  50. script against the store copy) that the account and its identities are still there.
  51. ## Rules
  52. - No git. Don't touch other project folders. Only kill your own PIDs or the ones in ident's pid files.
  53. Clean up headless Chromes (`--disable-gpu`). Scratch in `.scratch/`.
  54. - Do NOT POST to the live tickets server (:8350).
  55. - A test is the whole process: real headless browser drives register app → login button → ident
  56. login → choose identity → back → exchange → test app shows the id; plus negatives (foreign origin,
  57. wrong secret, reused/expired code, other app's code, face-session forging per #31).
  58. - Strict API: unknown/missing fields → 400 naming the field; invalid JSON → 400.
  59. - Screenshots at 390px and 1280px, look at them. Update `README.md` ("How apps use ident") and
  60. `STATUS.md`. Do NOT edit `CONCEPT.md`.
  61. ## Report (final answer, this structure)
  62. ```
  63. ## Done
  64. ## Verified (each: command run + observed output)
  65. ## Not verified / open
  66. ## Hybriel issues (repro, observed, expected)
  67. ## Questions for the creator
  68. ## Running (URL, PID, log path)
  69. ```

Branches

Latest commits

  • d2e7f91bident mission 009 (2/4): one lib file per topic (login, accounts, identities, apps, invites, selector, notify + helpers, util), function routes as thin wrappers in lib/api.hl, project.hl = the map; same outputmre
  • 91017164ident mission 009 (1/4): file moves — the root .hl files into lib/ (api.hl → lib/api-helpers.hl), styles.hl → components/styles.hl; imports adjusted, no other changemre
  • f8bdcbc2ident: Hybriel master 06617221 (plugin allocators 3a781359 + 413f60e4, mpackdb 2cb7ae5e, http1 773de63e); all gates greenmre
  • ff78726cident: Hybriel master 190aa11d (fc838894 GC correctness, #127, #126 closure scopes); gates all greenmre
  • a3a7d21aident: Hybriel master 8efba065 (#126 GC by bytes, #48 lambda params copy); session-writing lambdas take &sessionmre
  • 98226b41antcolony#40: mission references point to the moved missionsmre
  • ff805b9aantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 51a7bcdfident: Hybriel master 73267707 (#122); /code uses the new page() signature; pending address passed as parameter; once-checksmre
  • 836f644fident#24: installable app (manifest, service worker, data-free offline /start), own iconmre
  • 8bebbbf2deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • cc063ea2deploy.sh: never send .git or .gitignore to Byrodinmre
  • 81b15b7bState of 2026-09-27, before the move to gitoriamre