nigig-org/crates/apps/nigig-site/Cargo.toml
Arena Agent 12f59109d7 revert(nigig-site): ce9e12b was wrong — the HTTP wire field is body, not text
Commits dfffe9e + 13ae501 landed nigig-lite/crates/common (package
`nigig-common`) and a vendored xitca-web into this repository, which makes the
/sync wire format readable for the first time. Reading it shows ce9e12b was
incorrect.

There are TWO MessageContent types, deliberately:
- nigig_common::MessageContent::Text { body, formatted_body, mentions } — the
  HTTP/JSON REST DTO. Its own doc-comment: "Serialises externally tagged,
  e.g. {"Text":{"body":"hi",…}}". This is what SendMessageRequest.content and
  TimelineEvent::Message.content are.
- nimanyatta_protocol::MessageContent::Text { text } — the WebSocket chat
  protocol, serialized with postcard. nigig-common's manifest says that format
  "must match nimanyatta/crates/nimanyatta-protocol (the client library)".

ce9e12b changed the E2E test's outgoing posts from {"Text":{"body":…}} to
{"Text":{"text":…}}, reasoning from the WebSocket type. The original `body`
was correct for these HTTP endpoints; my change would have made both requests
fail deserialization. Reverted, and the now-unused nimanyatta-protocol
dev-dependency is dropped from nigig-site.

What ce9e12b got right is kept: the parser had keyed on "type":"message",
but TimelineEvent carries no serde tag attribute, so it is externally tagged —
{"Message":{…,"sender":…,"content":…}} with sender and content at the variant
level. event_text still accepts that envelope (plus the legacy lowercase shape
and `text` as last-resort field names).

The fixture's cross-check test was rebuilt against nigig_common's real shape
instead of the WebSocket type. It is NOT verified by execution: nigig-site's
test target pulls in makepad-widgets, which is SIGKILLed on this host. The
parser was verified instead by extracting event_text/sync_timelines verbatim
into a standalone harness over four cases — nigig_common Message with `body`
-> Some(("alice","slab done")); Membership -> None; Redaction -> None; legacy
lowercase -> Some(("bob","old")). All pass. The harness is scratch, not
shipped.

EXECUTION_PLAN.md SITE-12 rewritten: the sibling repos are no longer missing,
the /sync DTOs are named with their file paths, both MessageContent types are
distinguished, and the narrower remaining blockers are stated — nimanyatta
still cannot be a workspace member (xitca-web/web/Cargo.toml inherits
rust-version and lints from a workspace root, and nested here it resolves to
ours, which defines neither), and a full `cargo check --features b_server` has
not completed on this host, so no build claim is made.

Verified: cargo test -p nimanyatta-protocol = 14; cargo test -p nigig-site-core
= 228 / 1 ignored; clippy -D warnings clean; cargo fmt --check clean;
cargo metadata exit 0.
2026-09-26 17:39:20 +00:00

63 lines
3.1 KiB
TOML

[package]
name = "nigig-site"
version = "0.1.0"
edition = "2021"
description = "Nigig Site — fail-closed encrypted local construction records under SITE-01 containment."
[dependencies]
makepad-widgets = { workspace = true }
robius-directories = { git = "https://github.com/project-robius/robius", rev = "b766e62b0600f5d2ee21cc6995648346fc277bd8" }
serde = { version = "1", features = ["derive"] }
serde_json = "1"
chrono = { version = "0.4", features = ["serde"] }
ulid = { version = "1", features = ["serde"] }
uuid = { version = "1", features = ["v4", "serde"] }
# Domain aggregates, typed ids, explicit site context, fail-closed encrypted
# repository, and the SITE-04..SITE-19 hardening contracts live in the UI-free
# core crate (scope §5 "Rust core crate"; plan §6). One source copy, re-exported
# below, so the app and the core's unit tests compile the same files.
nigig-site-core = { path = "../nigig-site-core" }
# Fail-closed authenticated storage (see src/crypto.rs and src/store.rs).
# `aes-gcm` 0.10 does not propagate its optional zeroization into the AES and
# GHASH backends, so the feature-only direct pins below deliberately unify those
# already-transitive crates with their drop-time zeroization support enabled.
aes-gcm = { version = "0.10", default-features = false, features = ["aes", "alloc", "zeroize"] }
aes = { version = "0.8.4", features = ["zeroize"] }
ghash = { version = "0.5.1", features = ["zeroize"] }
polyval = { version = "0.6.2", features = ["zeroize"] }
aead = "0.5"
getrandom = "0.2"
zeroize = "1"
keyring-core = "1"
# Use one explicit native credential-store provider per desktop platform. The
# all-in-one `keyring` facade is intentionally not linked by production code.
[target.'cfg(target_os = "linux")'.dependencies]
zbus-secret-service-keyring-store = { version = "1", features = ["crypto-rust"] }
[target.'cfg(target_os = "macos")'.dependencies]
apple-native-keyring-store = { version = "1", features = ["keychain"] }
[target.'cfg(target_os = "windows")'.dependencies]
windows-native-keyring-store = { version = "1", default-features = false }
windows-sys = { version = "0.61.2", features = ["Win32_Foundation", "Win32_Storage_FileSystem"] }
[target.'cfg(unix)'.dependencies]
libc = "0.2"
# Contained media/export and live-network fixtures execute only in the owned
# Linux CI jobs. Keeping their broad dependency graph out of macOS/Windows test
# builds lets the target-native repository contracts compile independently.
[target.'cfg(target_os = "linux")'.dev-dependencies]
makepad-test = { workspace = true }
nigig-core = { path = "../../nigig-core" }
# Legacy media/export implementations are test-only containment fixtures.
nigig-pdf-cos = { path = "../pdf/pdf-cos" }
nigig-pdf-document = { path = "../pdf/pdf-document" }
nigig-pdf-graphics = { path = "../pdf/pdf-graphics" }
nigig_doc_scanner = { path = "../nigig_doc_scanner" }
image = { version = "0.25", default-features = false, features = ["png", "jpeg"] }
weezl = "0.1"
zip = "8"
# Explicit test-only live-server contract; production has no HTTP dispatcher.
reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls", "blocking"] }