Commit graph

3 commits

Author SHA1 Message Date
arena-agent
f9c12359bf nimanyatta: drop vendored xitca-web, use crates.io sources
Some checks failed
repo hygiene / hygiene (push) Has been cancelled
Delete the vendored xitca-web framework checkout at repo root and
repoint all consumers at the published crates:

- nimanyatta/Cargo.toml: drop path overrides on xitca-web (deps +
  dev-deps), remove the xitca-client dep (never published on
  crates.io) from the manifest and the load/b_server features, and
  remove the [patch.crates-io] section that forced every xitca-*
  crate onto the vendored checkout.
- nigig-lite/crates/common: xitca-web path dep -> version 0.8 from
  crates.io (vendored snapshot was 0.8.1, identical).
- Test suites (shared_test_client, security_suite, enhanced_security,
  enhanced_security_tests) and kra-etims-sdk: migrate xitca-client
  HTTP usage to reqwest from crates.io, preserving request
  semantics (header-override order, error mapping).

Verified in a fresh clone on the pinned toolchain (1.97.1):
nigig-common checks, security/enhanced suites check, and the
session/fast/regression harness binaries build.
2026-09-26 17:16:51 +00:00
dfffe9e6e6 nimanyatta: Phase 8 — reconstruct nigig-common, repair load suites, close REST coverage gaps
Foundation:
- Vendor xitca-web (upstream commit 7fa07dae, see xitca-web/VENDORED.md);
  pin all six xitca crates via [patch.crates-io] in nimanyatta/Cargo.toml
- Reconstruct the lost nigig-common crate as nigig-lite/crates/common
  (21 unit tests, clippy-clean), recovered from the wire contract in
  crates/nimanyatta-protocol plus the server's own call sites

REST API:
- Register the four unwired room routes that were documented but never
  reachable: {room_id}/invite POST, /typing PUT, /read_receipt POST,
  /redact/{event_id} POST (root cause of the rooms.rs 50% coverage ceiling)
- REST read receipts now return 501 Not Implemented (documented) instead of
  a 500 — receipts are recorded via the WebSocket MarkRead path
- README API tables corrected to the real paths/methods; env table expanded
  (PROXY_TRUSTED_IPS, WS_ALLOWED_ORIGINS, CORS_ALLOWED_ORIGINS, ENABLE_OTEL,
  token durations) plus proxy-trust and WS-origin explainer sections

Security & correctness:
- WS_ALLOWED_ORIGINS is now fail-closed in production: an empty list is a
  configuration error at startup ('*' remains an explicit opt-out)
- Fix the OTP attempt counter: the BEGIN/IF SurrealQL block was a parse
  error, so every wrong OTP failed the query and the fail-closed handler
  masked it as a first-try 429 OTP_MAX_ATTEMPTS_EXCEEDED. Now a single
  atomic conditional UPDATE ... WHERE attempts < $max, the handler logs the
  underlying error before failing closed, and a regression test covers
  store -> fetch -> increment -> persist
- Gateway KNOWN_ISSUES #1/#2/#5 fixed (centralised idempotent
  cleanup_connection on all close paths; LoggedOut sent before
  remove_session); #3 verified already enforced via session eviction
- DeliveryReceipt receipts now carry by_user: Option<String> per the
  protocol crate (was Option<UserId> at the call sites)

Test suites:
- Repair every load-test binary: added mains for the three bins whose bodies
  were #[tokio::test] functions (test items are cfg(test)-gated and vanish
  from normal builds), fixed protocol-shape drift in the rest —
  cargo check --features load --bins is clean
- New route coverage tests: invite/join/409-reinvite/404-unknown, typing
  (member + 403 non-member), redact (happy path/404/403), read_receipt 501,
  custom-role denial, non-member send 403, pagination edges (limit,
  direction, invalid from-token), sync filter paths (room filter,
  timeline_limit, invalid since-token, empty filter semantics)
- cargo test --features b_server: 51 passed / 0 failed

Docs:
- PLAN.md Phase 8 section + post-Phase-8 roadmap (per-site channels, pinned
  document library, document read receipts, mentions/search/broadcast/
  moderation/retention, offline queue — documented as open scope gaps)
- KNOWN_ISSUES.md statuses updated with the fixes above
2026-09-26 16:24:41 +00:00
fd8b0632ca Include nimanyatta as normal tree (not embedded git)
Some checks failed
repo hygiene / hygiene (push) Has been cancelled
2026-09-26 09:29:36 +03:00