gitoriaLog in with ident

ident

All repositories: gitoria

ReadmeCodePull requestsReleasesTicketsSettings
Commitff805b9aff805b9aantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmreff805b9a/missions/002-ident-accounts-identities.md

4.0 KB

  1. # Mission 002 (old 005) — ident 1/6: account and identities (ticket #24)
  2. One-shot worker. The architect (Claude Code on Byrodin) verifies your report, then the creator tests.
  3. ## Read first — in this order
  4. 1. **`loreana:/media/STORAGE/projects/ident.worldapi.org/CONCEPT.md`** — the creator's concept of ident.
  5. It is the source of truth. Do not add features it does not describe; if something you need is not
  6. in it, make the smallest choice and list it under "Questions for the creator".
  7. 2. The app's current `README.md` and `STATUS.md` in the same folder (built in mission 001 (old 003) WITHOUT the
  8. concept — its email-code login is reusable, its data model and app flow are not).
  9. 3. `/CONTAINERS/projects/antcolony/README.md` (how this project works; section "Lessons learned").
  10. 4. Ticket: `GET http://100.77.141.84:8350/api/tickets/24`.
  11. ## Where
  12. - Host Loreana (`ssh loreana`, fish login shell → `bash -c '…'` or script files).
  13. - App: `/media/STORAGE/projects/ident.worldapi.org` (vendored `bin/hybriel` + `plugins/`, same binary
  14. as tickets, sha256 c51d163d…). Dev port **8351**. Hybriel repo `/media/STORAGE/projects/hybriel` READ ONLY.
  15. - Stack and conventions exactly as the tickets app (`/media/STORAGE/projects/tickets.worldapi.org`, read only).
  16. ## Scope (piece 1 of 6 only)
  17. 1. **Login to ident** with an email one-time code (keep mission 001 (old 003)'s OTP rules: 6 digits, 10 min,
  18. single use, 5 tries, send rate limit; mail goes to the file sink, no real mail).
  19. 2. **No registration**: the first successful OTP login creates the user **with a default identity**,
  20. then shows the name fields and **clearly states they are optional** (skippable).
  21. 3. **Identities**: no mandatory fields; optional nickname, firstname, lastname; an **identity name**
  22. (the one the selector will show later). The user can create further identities and edit them.
  23. A user always has at least one identity. Deleting identities: only if it is not the last one.
  24. 4. **Time zone**: taken from the browser at first ident use, stored on the account, visible and
  25. changeable in ident.
  26. 5. UI: signed-out = login; signed-in = the user's identities (list, create, edit). Accent orange
  27. `#ce9178`, tokens + conventions as in the tickets app. Phone (390px) and desktop.
  28. **Out of scope** (later tickets #25–#29): apps, API keys, per-app ids, login button flow, selector,
  29. notifications. The mission-003 app flow (`/login?app=…`, `/api/exchange`, `testclient/`, the `.env`
  30. allow list) does not fit the concept: **remove it** from the app and the gate (and stop the test client
  31. on :8354 — PID in `testclient/testclient.pid`). Piece 2 rebuilds it per the concept. Record the removal.
  32. ## Data
  33. Current `storage/` holds only test data from mission 001 (old 003). Back it up to `.scratch/storage-backup-<ts>/`,
  34. then you may start with an empty store.
  35. ## Rules
  36. - No git. Don't touch other project folders. Only kill your own PIDs or the ones in ident's
  37. `server.pid` / `testclient/testclient.pid`. Clean up headless Chromes (`--disable-gpu`). Scratch in `.scratch/`.
  38. - Do NOT POST to the live tickets server (:8350). The architect files tickets.
  39. - A test is the whole process: real headless browser drives first login → default identity → optional
  40. names skipped AND filled → second identity → edit → delete → time zone; plus API/negative cases.
  41. Look at your screenshots at 390px and 1280px.
  42. - Strict API: unknown/missing fields → 400 naming the field; invalid JSON → 400 (see tickets' `jsoncheck.hl`).
  43. - Hybriel bugs: don't fix in the repo; report with repro (check open hybriel tickets #6–#23 first,
  44. `GET /api/tickets?project=hybriel`, and don't re-report known ones).
  45. - Leave the dev server RUNNING on 8351 (setsid/nohup, `server.pid`, `server.log`).
  46. - Update the app's `README.md` and `STATUS.md` (concise). Do NOT edit `CONCEPT.md`.
  47. ## Report (final answer, this structure)
  48. ```
  49. ## Done
  50. ## Verified (each: command run + observed output)
  51. ## Not verified / open
  52. ## Hybriel issues (repro, observed, expected)
  53. ## Questions for the creator
  54. ## Running (URL, PID, log path)
  55. ```

Branches

Latest commits

  • ff805b9aantcolony#40: history (LOG.md), worker briefs (missions/) and reports moved here from antcolony, numbered per project; old numbers in antcolony docs/mission-map.mdmre
  • 51a7bcdfident: Hybriel master 73267707 (#122); /code uses the new page() signature; pending address passed as parameter; once-checksmre
  • 836f644fident#24: installable app (manifest, service worker, data-free offline /start), own iconmre
  • 8bebbbf2deploy.sh: back up live storage/.sessions/.env before every deploy (newest 5 kept)mre
  • cc063ea2deploy.sh: never send .git or .gitignore to Byrodinmre
  • 81b15b7bState of 2026-09-27, before the move to gitoriamre