Foundation:
- Vendor xitca-web (upstream commit 7fa07dae, see xitca-web/VENDORED.md);
pin all six xitca crates via [patch.crates-io] in nimanyatta/Cargo.toml
- Reconstruct the lost nigig-common crate as nigig-lite/crates/common
(21 unit tests, clippy-clean), recovered from the wire contract in
crates/nimanyatta-protocol plus the server's own call sites
REST API:
- Register the four unwired room routes that were documented but never
reachable: {room_id}/invite POST, /typing PUT, /read_receipt POST,
/redact/{event_id} POST (root cause of the rooms.rs 50% coverage ceiling)
- REST read receipts now return 501 Not Implemented (documented) instead of
a 500 — receipts are recorded via the WebSocket MarkRead path
- README API tables corrected to the real paths/methods; env table expanded
(PROXY_TRUSTED_IPS, WS_ALLOWED_ORIGINS, CORS_ALLOWED_ORIGINS, ENABLE_OTEL,
token durations) plus proxy-trust and WS-origin explainer sections
Security & correctness:
- WS_ALLOWED_ORIGINS is now fail-closed in production: an empty list is a
configuration error at startup ('*' remains an explicit opt-out)
- Fix the OTP attempt counter: the BEGIN/IF SurrealQL block was a parse
error, so every wrong OTP failed the query and the fail-closed handler
masked it as a first-try 429 OTP_MAX_ATTEMPTS_EXCEEDED. Now a single
atomic conditional UPDATE ... WHERE attempts < $max, the handler logs the
underlying error before failing closed, and a regression test covers
store -> fetch -> increment -> persist
- Gateway KNOWN_ISSUES #1/#2/#5 fixed (centralised idempotent
cleanup_connection on all close paths; LoggedOut sent before
remove_session); #3 verified already enforced via session eviction
- DeliveryReceipt receipts now carry by_user: Option<String> per the
protocol crate (was Option<UserId> at the call sites)
Test suites:
- Repair every load-test binary: added mains for the three bins whose bodies
were #[tokio::test] functions (test items are cfg(test)-gated and vanish
from normal builds), fixed protocol-shape drift in the rest —
cargo check --features load --bins is clean
- New route coverage tests: invite/join/409-reinvite/404-unknown, typing
(member + 403 non-member), redact (happy path/404/403), read_receipt 501,
custom-role denial, non-member send 403, pagination edges (limit,
direction, invalid from-token), sync filter paths (room filter,
timeline_limit, invalid since-token, empty filter semantics)
- cargo test --features b_server: 51 passed / 0 failed
Docs:
- PLAN.md Phase 8 section + post-Phase-8 roadmap (per-site channels, pinned
document library, document read receipts, mentions/search/broadcast/
moderation/retention, offline queue — documented as open scope gaps)
- KNOWN_ISSUES.md statuses updated with the fixes above
34 lines
1.5 KiB
Markdown
34 lines
1.5 KiB
Markdown
# nigig-lite
|
|
|
|
Shared, dependency-light crates for the nigig / nimanyatta family.
|
|
|
|
## `crates/common` — `nigig-common`
|
|
|
|
The shared foundation crate consumed by the `nimanyatta` chat/sync server (as a
|
|
path dependency from `nimanyatta/Cargo.toml`) and by its load-test suites:
|
|
|
|
- **`ids`** — strongly-typed ULID identifiers (`UserId`, `RoomId`, `EventId`,
|
|
`DeviceId`) that serialise in prefixed wire form (`user_01H…`).
|
|
- **`errors`** — the unified `AppError` model: HTTP status mapping, stable
|
|
machine-readable codes, and an xitca-web `Service` impl that renders JSON
|
|
error bodies.
|
|
- **`auth`** — REST DTOs for register/login/refresh/logout, token pairs, and
|
|
the `UserProfile` record shape.
|
|
- **`rooms`** — room, membership, timeline-event and message-content models
|
|
plus the rooms REST DTOs.
|
|
- **`roles`** — server/room/custom role and permission model
|
|
(`PermissionSet`, `ResolvedPermissions`).
|
|
- **`sync`** — the `/sync` request/response contract (filters, pagination
|
|
tokens).
|
|
- **`protocol`** — the WebSocket chat protocol (`ClientToServerMsg`,
|
|
`ServerToClientMsg`, presence, receipts) mirrored from
|
|
`nimanyatta/crates/nimanyatta-protocol`.
|
|
- **`validatable`** — shared input validators (username/password/message body
|
|
rules).
|
|
|
|
The crate is standalone (empty `[workspace]` table) and has its own unit tests
|
|
(`cargo test` → 21 tests).
|
|
|
|
The WebSocket wire shapes are kept byte-compatible with
|
|
`nimanyatta/crates/nimanyatta-protocol` — the client library — so both sides
|
|
of the socket agree on field names and tagging.
|