master
${ noResults }
9 Commits (master)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
3ca1945dd9 |
Nexo desktop-first redesign + demo restructure
Move servers/dating → demos/dating/server and the dating route's co-located _components/_lib/_design assets → demos/dating/web. Single `npm run dating:dev` boots both server and web via concurrently. Replace the warm-paper / raspberry-pink Claude Design adaptation with a sober desktop-first system: - Tokens: slate neutrals + violet accent, Inter family, dark mode via prefers-color-scheme + explicit data-theme. - Inline SVG icon set (Icon.svelte, Feather-style) — no Unicode glyph placeholders. - Layout shell: 240px rail nav on desktop, bottom tab bar on mobile; auth + onboarding own their own shell. - Discover: square photo carousel (dots + chevrons), name/age/location overlay, action buttons floating off the photo edge, sticky context panel on desktop. - Matches: clean conversation list with unread dot + chevron-on-hover. - Chat: 3-column on desktop (threads + thread + match context), 2-col on tablet, single thread on mobile. Day separators, retry/dismiss on failed messages, autogrow composer with Enter-to-send. - Profile: sticky hero card + 3-section form, dirty/saved indicator. - Photos: dropzone + grid with hover-only cell toolbar (set primary, reorder, delete). - Onboarding: sidebar stepper (320px) + content panel. - Auth: split layout (form left, brand quote right) on ≥900px. Server boot: env loader's repo-root resolution corrected after the move (../../.. instead of ../..) so .env.local at the repo root is picked up again. Hoist BRAND.md and SECURITY.md into docs/, drop superseded audit notes that were already closed. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
14888e63d9 |
Nexo realtime — WebSocket distributor for chat fan-out
Replaces the chat poll-every-3-seconds compromise with a real
WebSocket pipeline. Server side:
`realtime.mjs`:
- In-memory hub mapping `userId → Set<WebSocket>`. Single-process,
zero external deps; fine for the local demo. A clustered deployment
would swap in Redis pub/sub behind the same surface.
- `attach(userId, socket)` registers a socket and self-detaches on
close/error.
- `broadcast(userIds, event)` JSON-encodes once and dispatches to
every subscriber of every listed user, swallowing per-socket errors.
`server.mjs`:
- Adds a `WebSocketServer({ noServer: true })` that listens on the
HTTP server's `'upgrade'` event for `/api/realtime` paths.
- Authentication mirrors the HTTP path: extract `dating_session` from
the upgrade request's `Cookie` header, pass through `currentSession`
and reject with 401 if it doesn't resolve.
- Rejects upgrades from origins outside the CORS allowlist (the
cookie-based auth is the second line of defence; origin gating is
the first).
- On accept, attaches the socket to the hub and sends a `hello`
envelope so the client can confirm authentication round-trip.
`routes.mjs:messagesPost`:
- After persisting a new message, calls
`broadcast(relationIds(match.users), { type: 'dating.message.created',
message: view })`. Both members (sender and counterpart) get the
push, so multi-device sessions stay in sync.
Adds `ws` (8.20) + `@types/ws` to dependencies.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
f1055842dd |
Bloque A — sweep stale aliases and `App.<Capitalized>` references
Audit P1: documentation must stop teaching APIs the runtime no longer exposes. The svelte.config.js aliases are full words now (`$cache`, `$session`, `$connection`, `$timer`, `$logger`, `$format`, `$storage`, `$active-app`, `$bus`); the legacy 4-letter forms (`$cach`, `$sess`, `$conn`, `$timr`, `$logr`, `$fmts`, `$stor`, `$aapp`, `$buss`) were retired earlier but still lived in READMEs, demo pages, comments and a few code docstrings. Likewise, the `App.<service>` surface is lowercase for declarable services. The capitalized form is reserved for the four-piece core (`Logger`, `Bus`, `Timers`, `Orca`). References like `App.Cache`, `App.Sess`, `App.Storage`, `App.Format`, `App.Frontend`, `App.Lang`, `App.Auth`, `App.Perms`, `App.Http`, `App.Dom`, `App.Sium` were either ported to the new lowercase or migrated where it made sense. Mechanical sweep across `src/`, then a guard script: - `scripts/check-aliases.mjs` walks `src/`, fails the run if any forbidden alias or `App.<forbidden capitalized>` appears in any `.ts` / `.svelte` / `.md` / `.txt` / `.js` / `.mjs` file. `arts/active-app/types.ts` is allowlisted because its block comment explicitly documents the legacy uppercase surface as "removed". - `npm run test:aliases` exposes the script. - `npm run test:all` now includes the alias check. No runtime change; tests still 1486 / 1486. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
5 months ago |
|
|
e6e9c38f7c |
Prepare active 0.1 release gates
|
5 months ago |
|
|
6e29d73572 |
Checkpoint framework artifacts before perm cleanup
|
5 months ago |
|
|
c5dd0e337c |
Add arts/timr, arts/sess, arts/http; sess actor extension; aapp factory
New artifacts:
arts/timr — runtime timer scheduler (singleton-per-App, never global).
Engine + Active split. Race-safe via (id, key, version) guard against
stale native callbacks, async tasks resolving after cancel/replace,
interval ticks scheduled after dispose, and ack-style timeouts. Per-
entry AbortController; intervals reuse the signal across ticks.
awaitTask:true (default, no overlap) vs awaitTask:false (fire-and-
forget cadence; failures don't stop the interval — semantic frozen).
Recursive setTimeout for intervals. scheduleAt(past) → delay 0 (no
error). Fake-clock injectable for deterministic tests. Pure
computeBackoffDelay helper. 50 server tests + 7 browser tests + full
README + DESIGN_TIMR + interactive test page at /test/timr.
arts/sess — session lifecycle with three generics
(TUser/TCredential/TData) plus optional SessionActor metadata
(kind/source/confidence — orthogonal axis to identity).
Tagged AdoptResult/RefreshResult/RevokeResult; never void.
Generation guard against stale refresh from local cancel, cross-tab
storage events, or re-adopt. onRefresh contract (null=fatal,
throw=transient). onRevoke replaces revokeUrl (consumer controls
fetch; engine just gets boolean). Default scope: 'global' when
onRevoke configured. INITIAL_SESSION sync dispatch on subscribe.
BroadcastChannel payload: {type, event, generation} only — never
tokens. SSR cookie reader validates invariants. withAutoRefresh
helper, 401-retry hook with applyAuth + loop guard, JWT exp helper.
103 tests (60 server + 5 browser + 38 actor/error/etc) + README +
DESIGN.md + test page at /test/sess.
arts/http — HTTP client with Standard Schema body validation, retry
+ Retry-After, attempt + total timeout via AbortSignal composition,
hooks (beforeRequest/beforeRetry/afterResponse/beforeError),
tagged HttpResult. Test page at /test/http.
arts/conn — DESIGN_CONN.md only (no implementation yet).
aapp:
- App.createActiveSession<TUser, TCredential, TData>(opts) factory
auto-injects App.Logger; throws SessAlreadyCreatedError on second
call. App.Sess getter exposes the active session (undefined until
first call). Auto-disposed by App.dispose().
- App.Timers integration deferred to timr Fase 3.
libs/days:
- toEpochMs(value) — permissive coercion (number | Date | string) →
epoch ms. Exposed alongside the existing day/calendar helpers.
Other:
- sium examples moved to _examples/ (excluded from public surface).
- sium-provider.svelte test removed (port pending; tracked elsewhere).
- libs/env.ts — DEV flag single source of truth.
- Various README touch-ups across artifacts.
All artifacts: 1021 server tests + 12 browser tests; svelte-check + ESLint
clean. The 9 server "errors" are pre-existing jsdom missing — unrelated.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
585906e170 |
Build runtime infrastructure layer: aapp + 5 new artifacts
Adds the application composition root and six new runtime artifacts. lang
and logr alone could not cover an app surface — locale propagation, format
helpers, frontend preferences, validation, persistence and DOM service all
needed independent artifacts that aapp wires together under a single
locale source of truth and a shared logger.
New artifacts:
- aapp: composition root. createActiveApp + createTestApp +
App.createSiumEngine + frontend.persist + Storage wiring.
- stor: pluggable adapters (local/session/memory/cookie + SSR via
cookieAdapter.fromCookies), envelope versioning + migrate +
TTL, validate via Standard Schema, intra-tab + cross-tab sync,
Storage.clear(), per-entry adapter/namespace overrides.
- adom: reactive DOM service. shareViewport opt-in + per-window
tracker, dispose(). breakpoints, viewport, attribute writes.
- fend: frontend preferences (theme, mode, dir, density,
reducedMotion, reducedSound) with auto/clear/isAuto pattern.
- fmts: localized formatting (numbers, currency, units, dates) with
shared LocaleSource and per-domain auto/clear pattern.
- sium: validation engine. Standard Schema interop, Lang/Logger
injection, codec/refine/transform, domain types
(color/date/time), introspection.
Existing artifacts extended:
- lang: BCP 47 SupportedLocale (LangBase | base-region), mono lang
for monolingual apps, extend() leaf-overwrite warning,
EngineLang/ActiveLang naming alignment with the rest of the
project (no Instance suffix).
- logr: EngineLogger.dispose(), failureThrottleMs anti-cascade for
transports, README sync to the per-level filter API
(minLevel removed).
Cross-cutting:
- $locale: shared LocaleSource type consumed by fmts and fend.
- arts/README.md: artifact map, dependency graph, naming conventions.
- Test pages for every artifact under /test/<artifact>.
733 tests passing; svelte-check clean except 2 pre-existing errors on
sium/svelte provider (port pending).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
5 months ago |
|
|
4c074e196e |
Add vitals, entry.id, per-level transport routing and buffering
logr:
- entry.id auto-generated (UUID v4 / hex fallback) — survives backend dedup, batched-retry, cross-transport correlation.
- Transport.levels replaces minLevel — per-level { enabled, filter? } record. More flexible: enable/disable individual levels, attach per-level filters. Helper levelsAtLeast(level) for the common min-level case; allLevels() for the permissive case.
- Transport buffering: buffer, flushIntervalMs, writeBatch on the Transport interface. Logger tracks per-transport queues, flushes on size/time/flush()/detach/beforeunload. httpTransport and lokiTransport implement writeBatch for true batched HTTP delivery.
- logger.flush() to drain all buffered transports manually.
- Web Vitals integration (src/arts/logr/vitals.ts): registerWebVitals(logger, webVitalsSDK, options?) turns LCP/INP/CLS/FCP/TTFB samples into structured log entries tagged with route/rating. Zero-deps in logr — SDK is injected.
- ConsoleTransportOptions now exposes filter so vitals can be silenced on console while still flowing to Sentry/Datadog/Loki.
- Runtime name constant: `engine_logger` (via src/arts/logr/consts.ts) replaces hardcoded 'logr' string in failure reports, console prefix and synthetic entry tags.
lang:
- README expanded with a dedicated section on ts() and the LangString type: plain strings, LangRecord, LangRef; the `message: LangString` prop pattern for generic components; when to use the isLang* guards.
Tests: 185 passing (added vitals + buffer + entry.id coverage).
Docs: logr README now documents vitals (hot-zone patterns for LogQL / Sentry Discover / Datadog), buffering, the levels config, and the helpers.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
|
6 months ago |
|
|
a6077dd357 |
Initial commit: lang + logr libraries with SvelteKit scaffold
lang — type-safe i18n engine (zero-deps): - Pure engine (createEngineLang) with explicit locale per call - Svelte 5 reactive wrapper (createActiveLang) via $state - Fallback chain, Intl.PluralRules, cross-key references, JSON round-trip - Type-safe paths with inference from schema logr — structured logger (zero-deps, decoupled from i18n): - 6 levels (TRACE..FATAL) aligned with pino/Log4j/OpenTelemetry/Sentry - Auto-generated entry.id (UUID v4 / hex fallback) - globalContext, child(), time/timeEnd, lazy messages, source capture - Dynamic transports with per-sink minLevel/filter, buffer + writeBatch - Hybrid dispatch: sync loop, transports may be async - Failure routing with deniedFor and cascade guard - Adapters: console, http, callback, sentry, datadog, logtail, loki, otel Test pages at /test/lang and /test/logr. 180 unit tests passing. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
6 months ago |