From 80d3e36679eeb783282c7812eb494f3a49b68f63 Mon Sep 17 00:00:00 2001 From: Esa Kataja Date: Fri, 31 Jul 2026 21:42:49 +0300 Subject: [PATCH] Add the submission pipeline and the review loop MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Steps 3 and 4 of the build order. A member can now upload a song, watch it convert, publish it, and review what everyone else has published. Pipeline: - ffprobe reads tags synchronously at submit so prefill never races typing; ffmpeg converts to Opus in the background, two at a time - ffmpeg succeeding is the validation — no container sniffing - publish moves the file inside the transaction, so a song row and its .ogg appear together or neither does - five submissions per rolling 24h, failures excluded Reviews and the reveal rule: - the queue is unreviewed songs only, oldest first, never your own - other people's reviews and the average are withheld in the query, not the template — a hidden average is never sent - 30 minutes to edit or delete your own review, enforced in the WHERE clause - deleting the last review unlocks the song for its submitter again The waiting page has one button: the metadata form autosaves after a pause in typing, and Julkaise submits it and publishes in the same request, so nothing is lost without JS. Genres store an English code and render a Finnish label. --- docs/spec.md | 32 +- main.go | 21 +- media.go | 126 ++++++++ render.go | 7 +- reviews.go | 200 +++++++++++++ songs.go | 314 ++++++++++++++++++++ songs_test.go | 232 +++++++++++++++ static/htmx.min.js | 1 + static/style.css | 83 ++++++ submit.go | 519 +++++++++++++++++++++++++++++++++ submit_test.go | 222 ++++++++++++++ templates/home.html | 5 - templates/layout.html | 3 + templates/partials/player.html | 30 ++ templates/queue.html | 18 ++ templates/song.html | 105 +++++++ templates/songs.html | 16 + templates/submission.html | 55 ++++ templates/submit.html | 67 +++++ 19 files changed, 2040 insertions(+), 16 deletions(-) create mode 100644 media.go create mode 100644 reviews.go create mode 100644 songs.go create mode 100644 songs_test.go create mode 100644 static/htmx.min.js create mode 100644 submit.go create mode 100644 submit_test.go delete mode 100644 templates/home.html create mode 100644 templates/partials/player.html create mode 100644 templates/queue.html create mode 100644 templates/song.html create mode 100644 templates/songs.html create mode 100644 templates/submission.html create mode 100644 templates/submit.html diff --git a/docs/spec.md b/docs/spec.md index c8dc18c..1411123 100644 --- a/docs/spec.md +++ b/docs/spec.md @@ -96,10 +96,20 @@ zero reviews, it is editable again. ### 2.2 Genres -Fixed list, `text` column, validated app-side: +Fixed list, `text` column, validated app-side. The **stored value is the English code** and the +Finnish label is display only — the same split the statuses use, so rewording a genre never touches +a song row: -Rock, Metal, Punk, Blues, Jazz, Electronic, Hip Hop, Pop, Folk / Country, Classical, Soundtrack, -Experimental, Finnish, Just Plain Weird, Other +| Code | Label | | Code | Label | +|---|---|---|---|---| +| Rock | Rock | | Soundtrack | Elokuvamusiikki | +| Metal | Metal | | Experimental | Kokeellinen | +| Punk | Punk | | Classical | Klassinen | +| Blues | Blues | | Electronic | Elektroninen | +| Jazz | Jazz | | Hip Hop | Hip hop | +| Pop | Pop | | Finnish | Kotimainen | +| Folk / Country | Folk / Country | | Just Plain Weird | Ihan outoa | +| | | | Other | Muu | --- @@ -201,9 +211,17 @@ States: `queued` → (`downloading`, URL only) → `converting` → `ready` | `f Submitter-only. Live status plus the editable metadata form, so the wait is spent writing the introduction rather than watching a spinner. -The button reads *Muunnetaan…* and is disabled until `status = 'ready'`, when it becomes -**Julkaise**. Publishing is always an explicit click — firing it automatically would race the -submitter mid-sentence. +**One button, at the bottom of the form: Julkaise**, disabled until `status = 'ready'`. Publishing +is always an explicit click — firing it automatically would race the submitter mid-sentence. + +There is no separate save button: two buttons made it unclear which one committed the text. + +- The metadata form **autosaves** — `hx-post` on `input changed delay:1.2s` and on `change`, + answering with a quiet "Tallennettu 21.37" line and nothing else. +- Julkaise lives outside the form and is bound to it with the HTML `form=` attribute, so pressing + it submits the metadata *and* publishes in one request. The last keystrokes therefore arrive with + the click even if the autosave never fired — which is also what makes the page work with no JS at + all. The live part is HTMX polling a fragment: @@ -211,7 +229,7 @@ The live part is HTMX polling a fragment:

{{.Label}}

- +
``` diff --git a/main.go b/main.go index 5eb566b..bd80553 100644 --- a/main.go +++ b/main.go @@ -135,9 +135,24 @@ func (a *app) memberMux() *http.ServeMux { mux.HandleFunc("POST /register", a.register) mux.HandleFunc("POST /logout", a.logout) - mux.HandleFunc("GET /{$}", a.requireMember(func(w http.ResponseWriter, r *http.Request) { - a.render(w, r, http.StatusOK, "home.html", page{Title: "Jono"}) - })) + mux.HandleFunc("GET /{$}", a.requireMember(a.queuePage)) + mux.HandleFunc("GET /songs", a.requireMember(a.browsePage)) + mux.HandleFunc("GET /songs/{id}", a.requireMember(a.songPage)) + mux.HandleFunc("POST /songs/{id}", a.requireMember(a.editSong)) + mux.HandleFunc("POST /songs/{id}/delete", a.requireMember(a.deleteSong)) + mux.HandleFunc("GET /audio/{id}", a.requireMember(a.audio)) + + mux.HandleFunc("POST /songs/{id}/review", a.requireMember(a.createReview)) + mux.HandleFunc("POST /reviews/{id}", a.requireMember(a.editReview)) + mux.HandleFunc("POST /reviews/{id}/delete", a.requireMember(a.deleteReview)) + + mux.HandleFunc("GET /submit", a.requireMember(a.submitPage)) + mux.HandleFunc("POST /submit", a.requireMember(a.submit)) + mux.HandleFunc("GET /submit/{id}", a.requireMember(a.submissionPage)) + mux.HandleFunc("GET /submit/{id}/status", a.requireMember(a.submissionStatus)) + mux.HandleFunc("POST /submit/{id}", a.requireMember(a.saveSubmission)) + mux.HandleFunc("POST /submit/{id}/publish", a.requireMember(a.publish)) + mux.HandleFunc("POST /submit/{id}/discard", a.requireMember(a.discard)) return mux } diff --git a/media.go b/media.go new file mode 100644 index 0000000..0d0ce7f --- /dev/null +++ b/media.go @@ -0,0 +1,126 @@ +package main + +import ( + "context" + "encoding/json" + "os/exec" + "strconv" + "strings" + "time" +) + +// Everything here shells out with exec.CommandContext and an argument list — never a shell string. + +type probeResult struct { + Title string + Artist string + Duration time.Duration +} + +type ffprobeOutput struct { + Format struct { + Duration string `json:"duration"` + Tags map[string]string `json:"tags"` + } `json:"format"` + Streams []struct { + CodecType string `json:"codec_type"` + Tags map[string]string `json:"tags"` + } `json:"streams"` +} + +// probe reads duration and whatever title/artist tags the container carries. Tag keys vary in case +// by container (title, TITLE, Title), so the map is lowercased before anything is read from it. +func probe(ctx context.Context, path string) (probeResult, error) { + ctx, cancel := context.WithTimeout(ctx, 30*time.Second) + defer cancel() + + out, err := exec.CommandContext(ctx, "ffprobe", + "-v", "quiet", "-print_format", "json", "-show_format", "-show_streams", path).Output() + if err != nil { + return probeResult{}, err + } + var parsed ffprobeOutput + if err := json.Unmarshal(out, &parsed); err != nil { + return probeResult{}, err + } + + tags := map[string]string{} + for _, stream := range parsed.Streams { + if stream.CodecType != "audio" { + continue + } + for k, v := range stream.Tags { + tags[strings.ToLower(k)] = v + } + } + // Container tags win over stream tags when both exist. + for k, v := range parsed.Format.Tags { + tags[strings.ToLower(k)] = v + } + + var res probeResult + res.Title = clean(tags["title"], 100) + res.Artist = clean(firstOf(tags, "artist", "album_artist"), 100) + if secs, err := strconv.ParseFloat(parsed.Format.Duration, 64); err == nil { + res.Duration = time.Duration(secs * float64(time.Second)) + } + return res, nil +} + +func firstOf(m map[string]string, keys ...string) string { + for _, k := range keys { + if v := strings.TrimSpace(m[k]); v != "" { + return v + } + } + return "" +} + +// Tag text is attacker-controlled and arrives inside an uploaded file. html/template escapes on +// render, but a title with an embedded newline wrecks every list layout it appears in. +func clean(s string, max int) string { + s = strings.Map(func(r rune) rune { + if r == '\n' || r == '\r' || r == '\t' { + return ' ' + } + if r < 0x20 || r == 0x7f { + return -1 + } + return r + }, s) + s = strings.TrimSpace(strings.Join(strings.Fields(s), " ")) + if r := []rune(s); len(r) > max { + s = strings.TrimSpace(string(r[:max])) + } + return s +} + +// convertToOpus is also the validation: if ffmpeg produced an Opus stream, the upload was audio. +// No container sniffing, no magic-byte library. Returns the stderr tail on failure, which is worth +// showing — "Invalid data found when processing input" beats "submission failed". +func convertToOpus(ctx context.Context, in, out string) (string, error) { + ctx, cancel := context.WithTimeout(ctx, 15*time.Minute) + defer cancel() + + cmd := exec.CommandContext(ctx, "ffmpeg", "-nostdin", "-y", + "-i", in, "-c:a", "libopus", "-b:a", "96k", "-ac", "2", "-vn", out) + var stderr strings.Builder + cmd.Stderr = &stderr + if err := cmd.Run(); err != nil { + return tail(stderr.String(), 400), err + } + return "", nil +} + +func tail(s string, n int) string { + s = strings.TrimSpace(s) + lines := strings.Split(s, "\n") + if len(lines) > 3 { + lines = lines[len(lines)-3:] + } + s = strings.TrimSpace(strings.Join(lines, " ")) + if r := []rune(s); len(r) > n { + s = string(r[len(r)-n:]) + } + return s +} diff --git a/render.go b/render.go index 7eedab5..de85ec6 100644 --- a/render.go +++ b/render.go @@ -7,6 +7,7 @@ import ( "log/slog" "net/http" "net/url" + "strconv" "time" ) @@ -15,6 +16,7 @@ var assetFS embed.FS var funcs = template.FuncMap{ "fidate": func(t time.Time) string { return t.Local().Format("2.1.2006 15:04") }, + "score": func(f *float64) string { return strconv.FormatFloat(*f, 'f', 1, 64) }, } // Each page is parsed with the layout into its own set, so two pages may both define "content". @@ -29,8 +31,11 @@ func init() { if e.Name() == "layout.html" { continue } + if e.IsDir() { + continue + } pages[e.Name()] = template.Must(template.New("layout.html").Funcs(funcs). - ParseFS(assetFS, "templates/layout.html", "templates/"+e.Name())) + ParseFS(assetFS, "templates/layout.html", "templates/partials/*.html", "templates/"+e.Name())) } } diff --git a/reviews.go b/reviews.go new file mode 100644 index 0000000..1bd1c36 --- /dev/null +++ b/reviews.go @@ -0,0 +1,200 @@ +package main + +import ( + "context" + "errors" + "fmt" + "log/slog" + "net/http" + "strconv" + "time" + + "github.com/jackc/pgx/v5" +) + +const ( + editWindow = 30 * time.Minute + maxReview = 5000 +) + +type review struct { + ID int64 + SongID int64 + ReviewerID int64 + Reviewer string + Score int + Text string + CreatedAt time.Time + UpdatedAt time.Time + Own bool +} + +// The window is measured from updated_at, so an edit extends it. It gates deletion as well as +// editing: for 30 minutes a review is yours to change or withdraw, after that it is on the record. +func (r *review) EditableUntil() time.Time { return r.UpdatedAt.Add(editWindow) } +func (r *review) CanEdit() bool { return r.Own && time.Now().Before(r.EditableUntil()) } + +func (r *review) Initials() string { + m := member{Name: r.Reviewer} + return m.Initials() +} + +func (a *app) reviewsFor(ctx context.Context, songID, viewerID int64) ([]*review, error) { + rows, err := a.pool.Query(ctx, ` + select r.id, r.song_id, r.reviewer_id, u.name, r.score, r.text, r.created_at, r.updated_at, + r.reviewer_id = $2 + from reviews r join users u on u.id = r.reviewer_id + where r.song_id = $1 + order by r.created_at`, songID, viewerID) + if err != nil { + return nil, err + } + defer rows.Close() + var out []*review + for rows.Next() { + var v review + if err := rows.Scan(&v.ID, &v.SongID, &v.ReviewerID, &v.Reviewer, &v.Score, &v.Text, + &v.CreatedAt, &v.UpdatedAt, &v.Own); err != nil { + return nil, err + } + out = append(out, &v) + } + return out, rows.Err() +} + +func (a *app) viewerReview(ctx context.Context, songID, viewerID int64) (*review, error) { + var v review + err := a.pool.QueryRow(ctx, ` + select r.id, r.song_id, r.reviewer_id, u.name, r.score, r.text, r.created_at, r.updated_at, true + from reviews r join users u on u.id = r.reviewer_id + where r.song_id = $1 and r.reviewer_id = $2`, songID, viewerID). + Scan(&v.ID, &v.SongID, &v.ReviewerID, &v.Reviewer, &v.Score, &v.Text, + &v.CreatedAt, &v.UpdatedAt, &v.Own) + if errors.Is(err, pgx.ErrNoRows) { + return nil, nil + } + return &v, err +} + +func reviewInput(r *http.Request) (int, string, string) { + score, _ := strconv.Atoi(r.FormValue("score")) + text := clean(r.FormValue("text"), maxReview) + switch { + case score < 1 || score > 100: + return 0, "", "Pisteiden tulee olla 1–100." + case text == "": + return 0, "", "Kirjoita muutama sana." + } + return score, text, "" +} + +func (a *app) createReview(w http.ResponseWriter, r *http.Request) { + songID, err := strconv.ParseInt(r.PathValue("id"), 10, 64) + if err != nil { + http.NotFound(w, r) + return + } + me := memberFrom(r.Context()) + score, text, problem := reviewInput(r) + if problem != "" { + a.flash(w, problem) + http.Redirect(w, r, fmt.Sprintf("/songs/%d", songID), http.StatusSeeOther) + return + } + + // You cannot review your own song, and the unique constraint is what stops a second review — + // no read-then-write race to lose. + var submitter int64 + err = a.pool.QueryRow(r.Context(), `select submitted_by from songs where id = $1`, songID).Scan(&submitter) + if errors.Is(err, pgx.ErrNoRows) { + http.NotFound(w, r) + return + } else if err != nil { + slog.Error("load song", "ctx", "reviews", "error", err, "song", songID) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + if submitter == me.ID { + http.Error(w, "omaa kappaletta ei voi arvostella", http.StatusForbidden) + return + } + + _, err = a.pool.Exec(r.Context(), + `insert into reviews (song_id, reviewer_id, score, text) values ($1, $2, $3, $4)`, + songID, me.ID, score, text) + if isUnique(err) { + a.flash(w, "Olet jo arvostellut tämän kappaleen.") + http.Redirect(w, r, fmt.Sprintf("/songs/%d", songID), http.StatusSeeOther) + return + } else if err != nil { + slog.Error("create review", "ctx", "reviews", "error", err, "song", songID) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + + slog.Info("review written", "ctx", "reviews", "song", songID, "user", me.ID) + a.flash(w, "Arvostelu tallennettu. Nyt näet muidenkin arvostelut.") + http.Redirect(w, r, fmt.Sprintf("/songs/%d", songID), http.StatusSeeOther) +} + +// Both edit and delete are gated by the same window, in the same WHERE clause — the database +// decides, so there is no clock-check in Go to get subtly wrong. +func (a *app) editReview(w http.ResponseWriter, r *http.Request) { + id, err := strconv.ParseInt(r.PathValue("id"), 10, 64) + if err != nil { + http.NotFound(w, r) + return + } + score, text, problem := reviewInput(r) + if problem != "" { + a.flash(w, problem) + http.Redirect(w, r, r.FormValue("from"), http.StatusSeeOther) + return + } + + var songID int64 + err = a.pool.QueryRow(r.Context(), ` + update reviews set score = $3, text = $4, updated_at = now() + where id = $1 and reviewer_id = $2 and updated_at > now() - $5::interval + returning song_id`, + id, memberFrom(r.Context()).ID, score, text, editWindow.String()).Scan(&songID) + if errors.Is(err, pgx.ErrNoRows) { + a.flash(w, "Muokkausaika on umpeutunut.") + http.Redirect(w, r, r.FormValue("from"), http.StatusSeeOther) + return + } else if err != nil { + slog.Error("edit review", "ctx", "reviews", "error", err, "review", id) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + a.flash(w, "Arvostelu päivitetty.") + http.Redirect(w, r, fmt.Sprintf("/songs/%d", songID), http.StatusSeeOther) +} + +// Deleting the last review unlocks the song for its submitter again — locked is a live state, and +// the 30-minute window is what keeps that from being a rug-pull months later. +func (a *app) deleteReview(w http.ResponseWriter, r *http.Request) { + id, err := strconv.ParseInt(r.PathValue("id"), 10, 64) + if err != nil { + http.NotFound(w, r) + return + } + var songID int64 + err = a.pool.QueryRow(r.Context(), ` + delete from reviews + where id = $1 and reviewer_id = $2 and updated_at > now() - $3::interval + returning song_id`, + id, memberFrom(r.Context()).ID, editWindow.String()).Scan(&songID) + if errors.Is(err, pgx.ErrNoRows) { + a.flash(w, "Muokkausaika on umpeutunut.") + http.Redirect(w, r, r.FormValue("from"), http.StatusSeeOther) + return + } else if err != nil { + slog.Error("delete review", "ctx", "reviews", "error", err, "review", id) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + slog.Info("review deleted", "ctx", "reviews", "review", id, "song", songID) + a.flash(w, "Arvostelu poistettu.") + http.Redirect(w, r, fmt.Sprintf("/songs/%d", songID), http.StatusSeeOther) +} diff --git a/songs.go b/songs.go new file mode 100644 index 0000000..b74cd12 --- /dev/null +++ b/songs.go @@ -0,0 +1,314 @@ +package main + +import ( + "context" + "errors" + "fmt" + "log/slog" + "net/http" + "os" + "strconv" + "time" + + "github.com/jackc/pgx/v5" +) + +const pageSize = 20 + +type songSummary struct { + ID int64 + Title string + Artist string + Genre string + Duration int + CreatedAt time.Time + Submitter string + SubmitterID int64 + ReviewCount int + // Nil unless the viewer has revealed the song. The reveal rule is applied in the query, not + // in the template — a hidden average is never sent. + Average *float64 + Own bool + Reviewed bool +} + +func (s *songSummary) GenreLabel() string { return genreLabel(s.Genre) } +func (s *songSummary) Revealed() bool { return s.Own || s.Reviewed } + +func (s *songSummary) Length() string { + return fmt.Sprintf("%d.%02d", s.Duration/60, s.Duration%60) +} + +type songList struct { + Items []*songSummary + NextCursor int64 // 0 when there is no next page + Queue bool +} + +// The select list is identical for both lists, so the reveal rule cannot drift between them. +const songColumns = ` + s.id, s.title, s.artist, s.genre, s.duration_seconds, s.created_at, u.id, u.name, + (select count(*) from reviews r where r.song_id = s.id), + case when s.submitted_by = $1 + or exists (select 1 from reviews r where r.song_id = s.id and r.reviewer_id = $1) + then (select avg(r.score)::float from reviews r where r.song_id = s.id) + end, + s.submitted_by = $1, + exists (select 1 from reviews r where r.song_id = s.id and r.reviewer_id = $1)` + +func scanSongs(rows pgx.Rows) ([]*songSummary, error) { + defer rows.Close() + var out []*songSummary + for rows.Next() { + var s songSummary + if err := rows.Scan(&s.ID, &s.Title, &s.Artist, &s.Genre, &s.Duration, &s.CreatedAt, + &s.SubmitterID, &s.Submitter, &s.ReviewCount, &s.Average, &s.Own, &s.Reviewed); err != nil { + return nil, err + } + out = append(out, &s) + } + return out, rows.Err() +} + +// The queue is a worklist: songs you can still review, oldest first, and never your own — you can +// never act on those, so they would sit at the front forever. +func (a *app) queue(ctx context.Context, viewerID, cursor int64) (*songList, error) { + rows, err := a.pool.Query(ctx, `select`+songColumns+` + from songs s join users u on u.id = s.submitted_by + where s.submitted_by <> $1 + and not exists (select 1 from reviews r where r.song_id = s.id and r.reviewer_id = $1) + and ($2 = 0 or s.id > $2) + order by s.created_at, s.id + limit $3`, viewerID, cursor, pageSize+1) + if err != nil { + return nil, err + } + items, err := scanSongs(rows) + if err != nil { + return nil, err + } + return paginate(items, true), nil +} + +// Everything, newest first. This is where a song lives once it has left the queue. +func (a *app) browse(ctx context.Context, viewerID, cursor int64) (*songList, error) { + rows, err := a.pool.Query(ctx, `select`+songColumns+` + from songs s join users u on u.id = s.submitted_by + where ($2 = 0 or s.id < $2) + order by s.created_at desc, s.id desc + limit $3`, viewerID, cursor, pageSize+1) + if err != nil { + return nil, err + } + items, err := scanSongs(rows) + if err != nil { + return nil, err + } + return paginate(items, false), nil +} + +// One row over the page size is fetched so "is there more" needs no second count query. +func paginate(items []*songSummary, isQueue bool) *songList { + l := &songList{Items: items, Queue: isQueue} + if len(items) > pageSize { + l.Items = items[:pageSize] + l.NextCursor = l.Items[pageSize-1].ID + } + return l +} + +func cursorOf(r *http.Request) int64 { + n, _ := strconv.ParseInt(r.URL.Query().Get("cursor"), 10, 64) + return n +} + +func (a *app) queuePage(w http.ResponseWriter, r *http.Request) { + list, err := a.queue(r.Context(), memberFrom(r.Context()).ID, cursorOf(r)) + if err != nil { + slog.Error("queue", "ctx", "songs", "error", err) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + a.render(w, r, http.StatusOK, "queue.html", page{Title: "Jono", Data: list}) +} + +func (a *app) browsePage(w http.ResponseWriter, r *http.Request) { + list, err := a.browse(r.Context(), memberFrom(r.Context()).ID, cursorOf(r)) + if err != nil { + slog.Error("browse", "ctx", "songs", "error", err) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + a.render(w, r, http.StatusOK, "songs.html", page{Title: "Kappaleet", Data: list}) +} + +// --- detail --- + +type songDetail struct { + songSummary + Description string + SourceURL *string + Reviews []*review // nil when the reveal rule is withholding them + ViewerReview *review + CanReview bool + CanEdit bool // submitter, and the song is unlocked + Genres []genre +} + +func (s *songDetail) Locked() bool { return s.ReviewCount > 0 } + +func (a *app) song(ctx context.Context, viewerID, songID int64) (*songDetail, error) { + var d songDetail + err := a.pool.QueryRow(ctx, `select`+songColumns+`, coalesce(s.description, ''), s.source_url + from songs s join users u on u.id = s.submitted_by + where s.id = $2`, viewerID, songID). + Scan(&d.ID, &d.Title, &d.Artist, &d.Genre, &d.Duration, &d.CreatedAt, + &d.SubmitterID, &d.Submitter, &d.ReviewCount, &d.Average, &d.Own, &d.Reviewed, + &d.Description, &d.SourceURL) + if err != nil { + return nil, err + } + d.Genres = genres + d.CanReview = !d.Own && !d.Reviewed + d.CanEdit = d.Own && d.ReviewCount == 0 + + if d.Reviewed { + d.ViewerReview, err = a.viewerReview(ctx, songID, viewerID) + if err != nil { + return nil, err + } + } + // The query only runs when the song is revealed: hidden reviews are never fetched, let alone + // sent and hidden with CSS. + if d.Revealed() { + d.Reviews, err = a.reviewsFor(ctx, songID, viewerID) + if err != nil { + return nil, err + } + } + return &d, nil +} + +func (a *app) songPage(w http.ResponseWriter, r *http.Request) { + id, err := strconv.ParseInt(r.PathValue("id"), 10, 64) + if err != nil { + http.NotFound(w, r) + return + } + d, err := a.song(r.Context(), memberFrom(r.Context()).ID, id) + if errors.Is(err, pgx.ErrNoRows) { + http.NotFound(w, r) + return + } else if err != nil { + slog.Error("song", "ctx", "songs", "error", err, "song", id) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + a.render(w, r, http.StatusOK, "song.html", page{Title: d.Title, Data: d}) +} + +// --- edit and delete --- + +// The submitter may change the four text fields while the song is unlocked. Once people have +// reviewed it, the thing they reviewed stops changing under them. +func (a *app) editSong(w http.ResponseWriter, r *http.Request) { + id, err := strconv.ParseInt(r.PathValue("id"), 10, 64) + if err != nil { + http.NotFound(w, r) + return + } + genre := r.FormValue("genre") + if !validGenre(genre) { + http.Error(w, "tuntematon genre", http.StatusUnprocessableEntity) + return + } + title, artist := clean(r.FormValue("title"), maxTitle), clean(r.FormValue("artist"), maxArtist) + if title == "" || artist == "" { + a.flash(w, "Nimi ja esittäjä ovat pakollisia.") + http.Redirect(w, r, fmt.Sprintf("/songs/%d", id), http.StatusSeeOther) + return + } + + tag, err := a.pool.Exec(r.Context(), ` + update songs set title = $3, artist = $4, genre = $5, description = nullif($6, '') + where id = $1 and submitted_by = $2 + and not exists (select 1 from reviews r where r.song_id = songs.id)`, + id, memberFrom(r.Context()).ID, title, artist, genre, + clean(r.FormValue("description"), maxDescription)) + if err != nil { + slog.Error("edit song", "ctx", "songs", "error", err, "song", id) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + if tag.RowsAffected() == 0 { + a.flash(w, "Kappaletta ei voi enää muokata — sitä on jo arvosteltu.") + } else { + a.flash(w, "Tiedot tallennettu.") + } + http.Redirect(w, r, fmt.Sprintf("/songs/%d", id), http.StatusSeeOther) +} + +// The row and the file go together, always. +func (a *app) deleteSong(w http.ResponseWriter, r *http.Request) { + id, err := strconv.ParseInt(r.PathValue("id"), 10, 64) + if err != nil { + http.NotFound(w, r) + return + } + tag, err := a.pool.Exec(r.Context(), ` + delete from songs where id = $1 and submitted_by = $2 + and not exists (select 1 from reviews r where r.song_id = songs.id)`, + id, memberFrom(r.Context()).ID) + if err != nil { + slog.Error("delete song", "ctx", "songs", "error", err, "song", id) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + if tag.RowsAffected() == 0 { + a.flash(w, "Kappaletta ei voi enää poistaa — sitä on jo arvosteltu.") + http.Redirect(w, r, fmt.Sprintf("/songs/%d", id), http.StatusSeeOther) + return + } + os.Remove(a.audioPath(id)) + slog.Info("song deleted", "ctx", "songs", "song", id) + a.flash(w, "Kappale poistettu.") + http.Redirect(w, r, "/songs", http.StatusSeeOther) +} + +// --- audio --- + +// Auth-gated, Range-capable, and not under /api because it serves bytes rather than JSON. +// Parsing the id as an integer is the traversal check. +func (a *app) audio(w http.ResponseWriter, r *http.Request) { + id, err := strconv.ParseInt(r.PathValue("id"), 10, 64) + if err != nil { + http.NotFound(w, r) + return + } + var name string + err = a.pool.QueryRow(r.Context(), `select audio_file from songs where id = $1`, id).Scan(&name) + if errors.Is(err, pgx.ErrNoRows) { + http.NotFound(w, r) + return + } else if err != nil { + slog.Error("audio lookup", "ctx", "songs", "error", err, "song", id) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + + f, err := os.Open(a.audioPath(id)) + if err != nil { + slog.Error("audio open", "ctx", "songs", "error", err, "song", id) + http.NotFound(w, r) + return + } + defer f.Close() + info, err := f.Stat() + if err != nil { + http.NotFound(w, r) + return + } + w.Header().Set("Content-Type", "audio/ogg") + // ServeContent handles 206, 416 and If-Range correctly, which hand-rolled Range parsing does not. + http.ServeContent(w, r, name, info.ModTime(), f) +} diff --git a/songs_test.go b/songs_test.go new file mode 100644 index 0000000..ce074b1 --- /dev/null +++ b/songs_test.go @@ -0,0 +1,232 @@ +package main + +import ( + "context" + "testing" +) + +func (a *app) seedSong(t *testing.T, submitter int64, title string) int64 { + t.Helper() + var id int64 + err := a.pool.QueryRow(context.Background(), ` + insert into songs (title, artist, genre, audio_file, duration_seconds, submitted_by) + values ($1, 'Testiartisti', 'Metal', 'x.ogg', 120, $2) returning id`, + title, submitter).Scan(&id) + if err != nil { + t.Fatal(err) + } + return id +} + +func (a *app) seedReview(t *testing.T, songID, reviewerID int64, score int) int64 { + t.Helper() + var id int64 + err := a.pool.QueryRow(context.Background(), ` + insert into reviews (song_id, reviewer_id, score, text) + values ($1, $2, $3, 'sanat') returning id`, songID, reviewerID, score).Scan(&id) + if err != nil { + t.Fatal(err) + } + return id +} + +// A member who hasn't reviewed a song must not receive other reviews *in the result set*, and must +// not receive the average either — not merely fail to render them. +func TestRevealRuleWithholdsReviewsAndAverage(t *testing.T) { + a := testApp(t) + ctx := context.Background() + aino := a.seedMember(t, "aino@example.com") + bertta := a.seedMember(t, "bertta@example.com") + cecilia := a.seedMember(t, "cecilia@example.com") + + songID := a.seedSong(t, aino, "Testikappale") + a.seedReview(t, songID, bertta, 88) + + // Cecilia has not reviewed it. + d, err := a.song(ctx, cecilia, songID) + if err != nil { + t.Fatal(err) + } + if d.Revealed() { + t.Fatal("song is revealed to a member who has not reviewed it") + } + if d.Reviews != nil { + t.Fatalf("withheld reviews were still fetched: %d of them", len(d.Reviews)) + } + if d.Average != nil { + t.Fatalf("withheld average was still sent: %v", *d.Average) + } + if d.ReviewCount != 1 { + t.Fatalf("review count = %d, want 1 — the count is not secret", d.ReviewCount) + } + + // Writing her own review unlocks both. + a.seedReview(t, songID, cecilia, 60) + d, err = a.song(ctx, cecilia, songID) + if err != nil { + t.Fatal(err) + } + if !d.Revealed() || len(d.Reviews) != 2 { + t.Fatalf("after reviewing: revealed = %v, reviews = %d, want true and 2", + d.Revealed(), len(d.Reviews)) + } + if d.Average == nil || *d.Average != 74 { + t.Fatalf("average = %v, want 74", d.Average) + } + + // The submitter sees everything without reviewing — they cannot review their own song. + d, err = a.song(ctx, aino, songID) + if err != nil { + t.Fatal(err) + } + if !d.Revealed() || len(d.Reviews) != 2 || d.Average == nil { + t.Fatal("the submitter cannot see the reviews of their own song") + } + if d.CanReview { + t.Fatal("the submitter is offered a review form for their own song") + } + + // And the same rule holds in the list query, which is a different SQL path. + list, err := a.browse(ctx, cecilia, 0) + if err != nil { + t.Fatal(err) + } + if len(list.Items) != 1 || list.Items[0].Average == nil { + t.Fatal("browse withheld the average from someone who has reviewed the song") + } + list, err = a.browse(ctx, a.seedMember(t, "dora@example.com"), 0) + if err != nil { + t.Fatal(err) + } + if list.Items[0].Average != nil { + t.Fatal("browse leaked the average to someone who has not reviewed the song") + } +} + +// The queue excludes your own songs and anything you have already reviewed, oldest first. +func TestQueueContents(t *testing.T) { + a := testApp(t) + ctx := context.Background() + aino := a.seedMember(t, "aino@example.com") + bertta := a.seedMember(t, "bertta@example.com") + + own := a.seedSong(t, aino, "Oma kappale") + reviewed := a.seedSong(t, bertta, "Jo arvosteltu") + fresh := a.seedSong(t, bertta, "Arvostelematon") + a.seedReview(t, reviewed, aino, 50) + + list, err := a.queue(ctx, aino, 0) + if err != nil { + t.Fatal(err) + } + if len(list.Items) != 1 { + var titles []string + for _, s := range list.Items { + titles = append(titles, s.Title) + } + t.Fatalf("queue = %v, want just the unreviewed song", titles) + } + if list.Items[0].ID != fresh { + t.Fatalf("queue holds song %d, want %d", list.Items[0].ID, fresh) + } + _ = own + + // Oldest first: a second unreviewed song comes after the first. + older := a.seedSong(t, bertta, "Vanhempi") + if _, err := a.pool.Exec(ctx, + `update songs set created_at = now() - interval '2 days' where id = $1`, older); err != nil { + t.Fatal(err) + } + list, err = a.queue(ctx, aino, 0) + if err != nil { + t.Fatal(err) + } + if list.Items[0].ID != older { + t.Fatal("queue is not oldest first") + } +} + +// Locked is a live state: deleting the only review makes the song editable again. +func TestSongUnlocksWhenTheLastReviewGoes(t *testing.T) { + a := testApp(t) + ctx := context.Background() + aino := a.seedMember(t, "aino@example.com") + bertta := a.seedMember(t, "bertta@example.com") + songID := a.seedSong(t, aino, "Testikappale") + + d, _ := a.song(ctx, aino, songID) + if !d.CanEdit { + t.Fatal("a song with no reviews is not editable by its submitter") + } + + reviewID := a.seedReview(t, songID, bertta, 88) + d, _ = a.song(ctx, aino, songID) + if d.CanEdit { + t.Fatal("a reviewed song is still editable") + } + + if _, err := a.pool.Exec(ctx, `delete from reviews where id = $1`, reviewID); err != nil { + t.Fatal(err) + } + d, _ = a.song(ctx, aino, songID) + if !d.CanEdit { + t.Fatal("song did not unlock after its only review was deleted") + } +} + +// The window is measured from updated_at, so an edit extends it — and it gates delete too. +func TestEditWindow(t *testing.T) { + a := testApp(t) + ctx := context.Background() + aino := a.seedMember(t, "aino@example.com") + bertta := a.seedMember(t, "bertta@example.com") + songID := a.seedSong(t, aino, "Testikappale") + reviewID := a.seedReview(t, songID, bertta, 88) + + v, err := a.viewerReview(ctx, songID, bertta) + if err != nil { + t.Fatal(err) + } + if !v.CanEdit() { + t.Fatal("a fresh review is not editable") + } + + // Just inside the window. + if _, err := a.pool.Exec(ctx, + `update reviews set updated_at = now() - interval '29 minutes' where id = $1`, + reviewID); err != nil { + t.Fatal(err) + } + v, _ = a.viewerReview(ctx, songID, bertta) + if !v.CanEdit() { + t.Fatal("a 29-minute-old review is not editable") + } + + // Past it. + if _, err := a.pool.Exec(ctx, + `update reviews set updated_at = now() - interval '31 minutes' where id = $1`, + reviewID); err != nil { + t.Fatal(err) + } + v, _ = a.viewerReview(ctx, songID, bertta) + if v.CanEdit() { + t.Fatal("a 31-minute-old review is still editable") + } + + // The database is the authority, not the Go clock: the update and the delete both refuse. + var n int64 + err = a.pool.QueryRow(ctx, ` + update reviews set score = 1, updated_at = now() + where id = $1 and reviewer_id = $2 and updated_at > now() - $3::interval + returning id`, reviewID, bertta, editWindow.String()).Scan(&n) + if err == nil { + t.Fatal("an expired review was edited") + } + err = a.pool.QueryRow(ctx, ` + delete from reviews + where id = $1 and reviewer_id = $2 and updated_at > now() - $3::interval + returning id`, reviewID, bertta, editWindow.String()).Scan(&n) + if err == nil { + t.Fatal("an expired review was deleted") + } +} diff --git a/static/htmx.min.js b/static/htmx.min.js new file mode 100644 index 0000000..59937d7 --- /dev/null +++ b/static/htmx.min.js @@ -0,0 +1 @@ +var htmx=function(){"use strict";const Q={onLoad:null,process:null,on:null,off:null,trigger:null,ajax:null,find:null,findAll:null,closest:null,values:function(e,t){const n=cn(e,t||"post");return n.values},remove:null,addClass:null,removeClass:null,toggleClass:null,takeClass:null,swap:null,defineExtension:null,removeExtension:null,logAll:null,logNone:null,logger:null,config:{historyEnabled:true,historyCacheSize:10,refreshOnHistoryMiss:false,defaultSwapStyle:"innerHTML",defaultSwapDelay:0,defaultSettleDelay:20,includeIndicatorStyles:true,indicatorClass:"htmx-indicator",requestClass:"htmx-request",addedClass:"htmx-added",settlingClass:"htmx-settling",swappingClass:"htmx-swapping",allowEval:true,allowScriptTags:true,inlineScriptNonce:"",inlineStyleNonce:"",attributesToSettle:["class","style","width","height"],withCredentials:false,timeout:0,wsReconnectDelay:"full-jitter",wsBinaryType:"blob",disableSelector:"[hx-disable], [data-hx-disable]",scrollBehavior:"instant",defaultFocusScroll:false,getCacheBusterParam:false,globalViewTransitions:false,methodsThatUseUrlParams:["get","delete"],selfRequestsOnly:true,ignoreTitle:false,scrollIntoViewOnBoost:true,triggerSpecsCache:null,disableInheritance:false,responseHandling:[{code:"204",swap:false},{code:"[23]..",swap:true},{code:"[45]..",swap:false,error:true}],allowNestedOobSwaps:true},parseInterval:null,_:null,version:"2.0.4"};Q.onLoad=j;Q.process=kt;Q.on=ye;Q.off=be;Q.trigger=he;Q.ajax=Rn;Q.find=u;Q.findAll=x;Q.closest=g;Q.remove=z;Q.addClass=K;Q.removeClass=G;Q.toggleClass=W;Q.takeClass=Z;Q.swap=$e;Q.defineExtension=Fn;Q.removeExtension=Bn;Q.logAll=V;Q.logNone=_;Q.parseInterval=d;Q._=e;const n={addTriggerHandler:St,bodyContains:le,canAccessLocalStorage:B,findThisElement:Se,filterValues:hn,swap:$e,hasAttribute:s,getAttributeValue:te,getClosestAttributeValue:re,getClosestMatch:o,getExpressionVars:En,getHeaders:fn,getInputValues:cn,getInternalData:ie,getSwapSpecification:gn,getTriggerSpecs:st,getTarget:Ee,makeFragment:P,mergeObjects:ce,makeSettleInfo:xn,oobSwap:He,querySelectorExt:ae,settleImmediately:Kt,shouldCancel:ht,triggerEvent:he,triggerErrorEvent:fe,withExtensions:Ft};const r=["get","post","put","delete","patch"];const H=r.map(function(e){return"[hx-"+e+"], [data-hx-"+e+"]"}).join(", ");function d(e){if(e==undefined){return undefined}let t=NaN;if(e.slice(-2)=="ms"){t=parseFloat(e.slice(0,-2))}else if(e.slice(-1)=="s"){t=parseFloat(e.slice(0,-1))*1e3}else if(e.slice(-1)=="m"){t=parseFloat(e.slice(0,-1))*1e3*60}else{t=parseFloat(e)}return isNaN(t)?undefined:t}function ee(e,t){return e instanceof Element&&e.getAttribute(t)}function s(e,t){return!!e.hasAttribute&&(e.hasAttribute(t)||e.hasAttribute("data-"+t))}function te(e,t){return ee(e,t)||ee(e,"data-"+t)}function c(e){const t=e.parentElement;if(!t&&e.parentNode instanceof ShadowRoot)return e.parentNode;return t}function ne(){return document}function m(e,t){return e.getRootNode?e.getRootNode({composed:t}):ne()}function o(e,t){while(e&&!t(e)){e=c(e)}return e||null}function i(e,t,n){const r=te(t,n);const o=te(t,"hx-disinherit");var i=te(t,"hx-inherit");if(e!==t){if(Q.config.disableInheritance){if(i&&(i==="*"||i.split(" ").indexOf(n)>=0)){return r}else{return null}}if(o&&(o==="*"||o.split(" ").indexOf(n)>=0)){return"unset"}}return r}function re(t,n){let r=null;o(t,function(e){return!!(r=i(t,ue(e),n))});if(r!=="unset"){return r}}function h(e,t){const n=e instanceof Element&&(e.matches||e.matchesSelector||e.msMatchesSelector||e.mozMatchesSelector||e.webkitMatchesSelector||e.oMatchesSelector);return!!n&&n.call(e,t)}function T(e){const t=/<([a-z][^\/\0>\x20\t\r\n\f]*)/i;const n=t.exec(e);if(n){return n[1].toLowerCase()}else{return""}}function q(e){const t=new DOMParser;return t.parseFromString(e,"text/html")}function L(e,t){while(t.childNodes.length>0){e.append(t.childNodes[0])}}function A(e){const t=ne().createElement("script");se(e.attributes,function(e){t.setAttribute(e.name,e.value)});t.textContent=e.textContent;t.async=false;if(Q.config.inlineScriptNonce){t.nonce=Q.config.inlineScriptNonce}return t}function N(e){return e.matches("script")&&(e.type==="text/javascript"||e.type==="module"||e.type==="")}function I(e){Array.from(e.querySelectorAll("script")).forEach(e=>{if(N(e)){const t=A(e);const n=e.parentNode;try{n.insertBefore(t,e)}catch(e){O(e)}finally{e.remove()}}})}function P(e){const t=e.replace(/]*)?>[\s\S]*?<\/head>/i,"");const n=T(t);let r;if(n==="html"){r=new DocumentFragment;const i=q(e);L(r,i.body);r.title=i.title}else if(n==="body"){r=new DocumentFragment;const i=q(t);L(r,i.body);r.title=i.title}else{const i=q('");r=i.querySelector("template").content;r.title=i.title;var o=r.querySelector("title");if(o&&o.parentNode===r){o.remove();r.title=o.innerText}}if(r){if(Q.config.allowScriptTags){I(r)}else{r.querySelectorAll("script").forEach(e=>e.remove())}}return r}function oe(e){if(e){e()}}function t(e,t){return Object.prototype.toString.call(e)==="[object "+t+"]"}function k(e){return typeof e==="function"}function D(e){return t(e,"Object")}function ie(e){const t="htmx-internal-data";let n=e[t];if(!n){n=e[t]={}}return n}function M(t){const n=[];if(t){for(let e=0;e=0}function le(e){return e.getRootNode({composed:true})===document}function F(e){return e.trim().split(/\s+/)}function ce(e,t){for(const n in t){if(t.hasOwnProperty(n)){e[n]=t[n]}}return e}function S(e){try{return JSON.parse(e)}catch(e){O(e);return null}}function B(){const e="htmx:localStorageTest";try{localStorage.setItem(e,e);localStorage.removeItem(e);return true}catch(e){return false}}function U(t){try{const e=new URL(t);if(e){t=e.pathname+e.search}if(!/^\/$/.test(t)){t=t.replace(/\/+$/,"")}return t}catch(e){return t}}function e(e){return vn(ne().body,function(){return eval(e)})}function j(t){const e=Q.on("htmx:load",function(e){t(e.detail.elt)});return e}function V(){Q.logger=function(e,t,n){if(console){console.log(t,e,n)}}}function _(){Q.logger=null}function u(e,t){if(typeof e!=="string"){return e.querySelector(t)}else{return u(ne(),e)}}function x(e,t){if(typeof e!=="string"){return e.querySelectorAll(t)}else{return x(ne(),e)}}function E(){return window}function z(e,t){e=y(e);if(t){E().setTimeout(function(){z(e);e=null},t)}else{c(e).removeChild(e)}}function ue(e){return e instanceof Element?e:null}function $(e){return e instanceof HTMLElement?e:null}function J(e){return typeof e==="string"?e:null}function f(e){return e instanceof Element||e instanceof Document||e instanceof DocumentFragment?e:null}function K(e,t,n){e=ue(y(e));if(!e){return}if(n){E().setTimeout(function(){K(e,t);e=null},n)}else{e.classList&&e.classList.add(t)}}function G(e,t,n){let r=ue(y(e));if(!r){return}if(n){E().setTimeout(function(){G(r,t);r=null},n)}else{if(r.classList){r.classList.remove(t);if(r.classList.length===0){r.removeAttribute("class")}}}}function W(e,t){e=y(e);e.classList.toggle(t)}function Z(e,t){e=y(e);se(e.parentElement.children,function(e){G(e,t)});K(ue(e),t)}function g(e,t){e=ue(y(e));if(e&&e.closest){return e.closest(t)}else{do{if(e==null||h(e,t)){return e}}while(e=e&&ue(c(e)));return null}}function l(e,t){return e.substring(0,t.length)===t}function Y(e,t){return e.substring(e.length-t.length)===t}function ge(e){const t=e.trim();if(l(t,"<")&&Y(t,"/>")){return t.substring(1,t.length-2)}else{return t}}function p(t,r,n){if(r.indexOf("global ")===0){return p(t,r.slice(7),true)}t=y(t);const o=[];{let t=0;let n=0;for(let e=0;e"){t--}}if(n0){const r=ge(o.shift());let e;if(r.indexOf("closest ")===0){e=g(ue(t),ge(r.substr(8)))}else if(r.indexOf("find ")===0){e=u(f(t),ge(r.substr(5)))}else if(r==="next"||r==="nextElementSibling"){e=ue(t).nextElementSibling}else if(r.indexOf("next ")===0){e=pe(t,ge(r.substr(5)),!!n)}else if(r==="previous"||r==="previousElementSibling"){e=ue(t).previousElementSibling}else if(r.indexOf("previous ")===0){e=me(t,ge(r.substr(9)),!!n)}else if(r==="document"){e=document}else if(r==="window"){e=window}else if(r==="body"){e=document.body}else if(r==="root"){e=m(t,!!n)}else if(r==="host"){e=t.getRootNode().host}else{s.push(r)}if(e){i.push(e)}}if(s.length>0){const e=s.join(",");const c=f(m(t,!!n));i.push(...M(c.querySelectorAll(e)))}return i}var pe=function(t,e,n){const r=f(m(t,n)).querySelectorAll(e);for(let e=0;e=0;e--){const o=r[e];if(o.compareDocumentPosition(t)===Node.DOCUMENT_POSITION_FOLLOWING){return o}}};function ae(e,t){if(typeof e!=="string"){return p(e,t)[0]}else{return p(ne().body,e)[0]}}function y(e,t){if(typeof e==="string"){return u(f(t)||document,e)}else{return e}}function xe(e,t,n,r){if(k(t)){return{target:ne().body,event:J(e),listener:t,options:n}}else{return{target:y(e),event:J(t),listener:n,options:r}}}function ye(t,n,r,o){Vn(function(){const e=xe(t,n,r,o);e.target.addEventListener(e.event,e.listener,e.options)});const e=k(n);return e?n:r}function be(t,n,r){Vn(function(){const e=xe(t,n,r);e.target.removeEventListener(e.event,e.listener)});return k(n)?n:r}const ve=ne().createElement("output");function we(e,t){const n=re(e,t);if(n){if(n==="this"){return[Se(e,t)]}else{const r=p(e,n);if(r.length===0){O('The selector "'+n+'" on '+t+" returned no matches!");return[ve]}else{return r}}}}function Se(e,t){return ue(o(e,function(e){return te(ue(e),t)!=null}))}function Ee(e){const t=re(e,"hx-target");if(t){if(t==="this"){return Se(e,"hx-target")}else{return ae(e,t)}}else{const n=ie(e);if(n.boosted){return ne().body}else{return e}}}function Ce(t){const n=Q.config.attributesToSettle;for(let e=0;e0){s=e.substring(0,e.indexOf(":"));n=e.substring(e.indexOf(":")+1)}else{s=e}o.removeAttribute("hx-swap-oob");o.removeAttribute("data-hx-swap-oob");const r=p(t,n,false);if(r){se(r,function(e){let t;const n=o.cloneNode(true);t=ne().createDocumentFragment();t.appendChild(n);if(!Re(s,e)){t=f(n)}const r={shouldSwap:true,target:e,fragment:t};if(!he(e,"htmx:oobBeforeSwap",r))return;e=r.target;if(r.shouldSwap){qe(t);_e(s,e,e,t,i);Te()}se(i.elts,function(e){he(e,"htmx:oobAfterSwap",r)})});o.parentNode.removeChild(o)}else{o.parentNode.removeChild(o);fe(ne().body,"htmx:oobErrorNoTarget",{content:o})}return e}function Te(){const e=u("#--htmx-preserve-pantry--");if(e){for(const t of[...e.children]){const n=u("#"+t.id);n.parentNode.moveBefore(t,n);n.remove()}e.remove()}}function qe(e){se(x(e,"[hx-preserve], [data-hx-preserve]"),function(e){const t=te(e,"id");const n=ne().getElementById(t);if(n!=null){if(e.moveBefore){let e=u("#--htmx-preserve-pantry--");if(e==null){ne().body.insertAdjacentHTML("afterend","
");e=u("#--htmx-preserve-pantry--")}e.moveBefore(n,null)}else{e.parentNode.replaceChild(n,e)}}})}function Le(l,e,c){se(e.querySelectorAll("[id]"),function(t){const n=ee(t,"id");if(n&&n.length>0){const r=n.replace("'","\\'");const o=t.tagName.replace(":","\\:");const e=f(l);const i=e&&e.querySelector(o+"[id='"+r+"']");if(i&&i!==e){const s=t.cloneNode();Oe(t,i);c.tasks.push(function(){Oe(t,s)})}}})}function Ae(e){return function(){G(e,Q.config.addedClass);kt(ue(e));Ne(f(e));he(e,"htmx:load")}}function Ne(e){const t="[autofocus]";const n=$(h(e,t)?e:e.querySelector(t));if(n!=null){n.focus()}}function a(e,t,n,r){Le(e,n,r);while(n.childNodes.length>0){const o=n.firstChild;K(ue(o),Q.config.addedClass);e.insertBefore(o,t);if(o.nodeType!==Node.TEXT_NODE&&o.nodeType!==Node.COMMENT_NODE){r.tasks.push(Ae(o))}}}function Ie(e,t){let n=0;while(n0}function $e(e,t,r,o){if(!o){o={}}e=y(e);const i=o.contextElement?m(o.contextElement,false):ne();const n=document.activeElement;let s={};try{s={elt:n,start:n?n.selectionStart:null,end:n?n.selectionEnd:null}}catch(e){}const l=xn(e);if(r.swapStyle==="textContent"){e.textContent=t}else{let n=P(t);l.title=n.title;if(o.selectOOB){const u=o.selectOOB.split(",");for(let t=0;t0){E().setTimeout(c,r.settleDelay)}else{c()}}function Je(e,t,n){const r=e.getResponseHeader(t);if(r.indexOf("{")===0){const o=S(r);for(const i in o){if(o.hasOwnProperty(i)){let e=o[i];if(D(e)){n=e.target!==undefined?e.target:n}else{e={value:e}}he(n,i,e)}}}else{const s=r.split(",");for(let e=0;e0){const s=o[0];if(s==="]"){e--;if(e===0){if(n===null){t=t+"true"}o.shift();t+=")})";try{const l=vn(r,function(){return Function(t)()},function(){return true});l.source=t;return l}catch(e){fe(ne().body,"htmx:syntax:error",{error:e,source:t});return null}}}else if(s==="["){e++}if(tt(s,n,i)){t+="(("+i+"."+s+") ? ("+i+"."+s+") : (window."+s+"))"}else{t=t+s}n=o.shift()}}}function C(e,t){let n="";while(e.length>0&&!t.test(e[0])){n+=e.shift()}return n}function rt(e){let t;if(e.length>0&&Ye.test(e[0])){e.shift();t=C(e,Qe).trim();e.shift()}else{t=C(e,v)}return t}const ot="input, textarea, select";function it(e,t,n){const r=[];const o=et(t);do{C(o,w);const l=o.length;const c=C(o,/[,\[\s]/);if(c!==""){if(c==="every"){const u={trigger:"every"};C(o,w);u.pollInterval=d(C(o,/[,\[\s]/));C(o,w);var i=nt(e,o,"event");if(i){u.eventFilter=i}r.push(u)}else{const a={trigger:c};var i=nt(e,o,"event");if(i){a.eventFilter=i}C(o,w);while(o.length>0&&o[0]!==","){const f=o.shift();if(f==="changed"){a.changed=true}else if(f==="once"){a.once=true}else if(f==="consume"){a.consume=true}else if(f==="delay"&&o[0]===":"){o.shift();a.delay=d(C(o,v))}else if(f==="from"&&o[0]===":"){o.shift();if(Ye.test(o[0])){var s=rt(o)}else{var s=C(o,v);if(s==="closest"||s==="find"||s==="next"||s==="previous"){o.shift();const h=rt(o);if(h.length>0){s+=" "+h}}}a.from=s}else if(f==="target"&&o[0]===":"){o.shift();a.target=rt(o)}else if(f==="throttle"&&o[0]===":"){o.shift();a.throttle=d(C(o,v))}else if(f==="queue"&&o[0]===":"){o.shift();a.queue=C(o,v)}else if(f==="root"&&o[0]===":"){o.shift();a[f]=rt(o)}else if(f==="threshold"&&o[0]===":"){o.shift();a[f]=C(o,v)}else{fe(e,"htmx:syntax:error",{token:o.shift()})}C(o,w)}r.push(a)}}if(o.length===l){fe(e,"htmx:syntax:error",{token:o.shift()})}C(o,w)}while(o[0]===","&&o.shift());if(n){n[t]=r}return r}function st(e){const t=te(e,"hx-trigger");let n=[];if(t){const r=Q.config.triggerSpecsCache;n=r&&r[t]||it(e,t,r)}if(n.length>0){return n}else if(h(e,"form")){return[{trigger:"submit"}]}else if(h(e,'input[type="button"], input[type="submit"]')){return[{trigger:"click"}]}else if(h(e,ot)){return[{trigger:"change"}]}else{return[{trigger:"click"}]}}function lt(e){ie(e).cancelled=true}function ct(e,t,n){const r=ie(e);r.timeout=E().setTimeout(function(){if(le(e)&&r.cancelled!==true){if(!gt(n,e,Mt("hx:poll:trigger",{triggerSpec:n,target:e}))){t(e)}ct(e,t,n)}},n.pollInterval)}function ut(e){return location.hostname===e.hostname&&ee(e,"href")&&ee(e,"href").indexOf("#")!==0}function at(e){return g(e,Q.config.disableSelector)}function ft(t,n,e){if(t instanceof HTMLAnchorElement&&ut(t)&&(t.target===""||t.target==="_self")||t.tagName==="FORM"&&String(ee(t,"method")).toLowerCase()!=="dialog"){n.boosted=true;let r,o;if(t.tagName==="A"){r="get";o=ee(t,"href")}else{const i=ee(t,"method");r=i?i.toLowerCase():"get";o=ee(t,"action");if(o==null||o===""){o=ne().location.href}if(r==="get"&&o.includes("?")){o=o.replace(/\?[^#]+/,"")}}e.forEach(function(e){pt(t,function(e,t){const n=ue(e);if(at(n)){b(n);return}de(r,o,n,t)},n,e,true)})}}function ht(e,t){const n=ue(t);if(!n){return false}if(e.type==="submit"||e.type==="click"){if(n.tagName==="FORM"){return true}if(h(n,'input[type="submit"], button')&&(h(n,"[form]")||g(n,"form")!==null)){return true}if(n instanceof HTMLAnchorElement&&n.href&&(n.getAttribute("href")==="#"||n.getAttribute("href").indexOf("#")!==0)){return true}}return false}function dt(e,t){return ie(e).boosted&&e instanceof HTMLAnchorElement&&t.type==="click"&&(t.ctrlKey||t.metaKey)}function gt(e,t,n){const r=e.eventFilter;if(r){try{return r.call(t,n)!==true}catch(e){const o=r.source;fe(ne().body,"htmx:eventFilter:error",{error:e,source:o});return true}}return false}function pt(l,c,e,u,a){const f=ie(l);let t;if(u.from){t=p(l,u.from)}else{t=[l]}if(u.changed){if(!("lastValue"in f)){f.lastValue=new WeakMap}t.forEach(function(e){if(!f.lastValue.has(u)){f.lastValue.set(u,new WeakMap)}f.lastValue.get(u).set(e,e.value)})}se(t,function(i){const s=function(e){if(!le(l)){i.removeEventListener(u.trigger,s);return}if(dt(l,e)){return}if(a||ht(e,l)){e.preventDefault()}if(gt(u,l,e)){return}const t=ie(e);t.triggerSpec=u;if(t.handledFor==null){t.handledFor=[]}if(t.handledFor.indexOf(l)<0){t.handledFor.push(l);if(u.consume){e.stopPropagation()}if(u.target&&e.target){if(!h(ue(e.target),u.target)){return}}if(u.once){if(f.triggeredOnce){return}else{f.triggeredOnce=true}}if(u.changed){const n=event.target;const r=n.value;const o=f.lastValue.get(u);if(o.has(n)&&o.get(n)===r){return}o.set(n,r)}if(f.delayed){clearTimeout(f.delayed)}if(f.throttle){return}if(u.throttle>0){if(!f.throttle){he(l,"htmx:trigger");c(l,e);f.throttle=E().setTimeout(function(){f.throttle=null},u.throttle)}}else if(u.delay>0){f.delayed=E().setTimeout(function(){he(l,"htmx:trigger");c(l,e)},u.delay)}else{he(l,"htmx:trigger");c(l,e)}}};if(e.listenerInfos==null){e.listenerInfos=[]}e.listenerInfos.push({trigger:u.trigger,listener:s,on:i});i.addEventListener(u.trigger,s)})}let mt=false;let xt=null;function yt(){if(!xt){xt=function(){mt=true};window.addEventListener("scroll",xt);window.addEventListener("resize",xt);setInterval(function(){if(mt){mt=false;se(ne().querySelectorAll("[hx-trigger*='revealed'],[data-hx-trigger*='revealed']"),function(e){bt(e)})}},200)}}function bt(e){if(!s(e,"data-hx-revealed")&&X(e)){e.setAttribute("data-hx-revealed","true");const t=ie(e);if(t.initHash){he(e,"revealed")}else{e.addEventListener("htmx:afterProcessNode",function(){he(e,"revealed")},{once:true})}}}function vt(e,t,n,r){const o=function(){if(!n.loaded){n.loaded=true;he(e,"htmx:trigger");t(e)}};if(r>0){E().setTimeout(o,r)}else{o()}}function wt(t,n,e){let i=false;se(r,function(r){if(s(t,"hx-"+r)){const o=te(t,"hx-"+r);i=true;n.path=o;n.verb=r;e.forEach(function(e){St(t,e,n,function(e,t){const n=ue(e);if(g(n,Q.config.disableSelector)){b(n);return}de(r,o,n,t)})})}});return i}function St(r,e,t,n){if(e.trigger==="revealed"){yt();pt(r,n,t,e);bt(ue(r))}else if(e.trigger==="intersect"){const o={};if(e.root){o.root=ae(r,e.root)}if(e.threshold){o.threshold=parseFloat(e.threshold)}const i=new IntersectionObserver(function(t){for(let e=0;e0){t.polling=true;ct(ue(r),n,e)}else{pt(r,n,t,e)}}function Et(e){const t=ue(e);if(!t){return false}const n=t.attributes;for(let e=0;e", "+e).join(""));return o}else{return[]}}function Tt(e){const t=g(ue(e.target),"button, input[type='submit']");const n=Lt(e);if(n){n.lastButtonClicked=t}}function qt(e){const t=Lt(e);if(t){t.lastButtonClicked=null}}function Lt(e){const t=g(ue(e.target),"button, input[type='submit']");if(!t){return}const n=y("#"+ee(t,"form"),t.getRootNode())||g(t,"form");if(!n){return}return ie(n)}function At(e){e.addEventListener("click",Tt);e.addEventListener("focusin",Tt);e.addEventListener("focusout",qt)}function Nt(t,e,n){const r=ie(t);if(!Array.isArray(r.onHandlers)){r.onHandlers=[]}let o;const i=function(e){vn(t,function(){if(at(t)){return}if(!o){o=new Function("event",n)}o.call(t,e)})};t.addEventListener(e,i);r.onHandlers.push({event:e,listener:i})}function It(t){ke(t);for(let e=0;eQ.config.historyCacheSize){i.shift()}while(i.length>0){try{localStorage.setItem("htmx-history-cache",JSON.stringify(i));break}catch(e){fe(ne().body,"htmx:historyCacheError",{cause:e,cache:i});i.shift()}}}function Vt(t){if(!B()){return null}t=U(t);const n=S(localStorage.getItem("htmx-history-cache"))||[];for(let e=0;e=200&&this.status<400){he(ne().body,"htmx:historyCacheMissLoad",i);const e=P(this.response);const t=e.querySelector("[hx-history-elt],[data-hx-history-elt]")||e;const n=Ut();const r=xn(n);kn(e.title);qe(e);Ve(n,t,r);Te();Kt(r.tasks);Bt=o;he(ne().body,"htmx:historyRestore",{path:o,cacheMiss:true,serverResponse:this.response})}else{fe(ne().body,"htmx:historyCacheMissLoadError",i)}};e.send()}function Wt(e){zt();e=e||location.pathname+location.search;const t=Vt(e);if(t){const n=P(t.content);const r=Ut();const o=xn(r);kn(t.title);qe(n);Ve(r,n,o);Te();Kt(o.tasks);E().setTimeout(function(){window.scrollTo(0,t.scroll)},0);Bt=e;he(ne().body,"htmx:historyRestore",{path:e,item:t})}else{if(Q.config.refreshOnHistoryMiss){window.location.reload(true)}else{Gt(e)}}}function Zt(e){let t=we(e,"hx-indicator");if(t==null){t=[e]}se(t,function(e){const t=ie(e);t.requestCount=(t.requestCount||0)+1;e.classList.add.call(e.classList,Q.config.requestClass)});return t}function Yt(e){let t=we(e,"hx-disabled-elt");if(t==null){t=[]}se(t,function(e){const t=ie(e);t.requestCount=(t.requestCount||0)+1;e.setAttribute("disabled","");e.setAttribute("data-disabled-by-htmx","")});return t}function Qt(e,t){se(e.concat(t),function(e){const t=ie(e);t.requestCount=(t.requestCount||1)-1});se(e,function(e){const t=ie(e);if(t.requestCount===0){e.classList.remove.call(e.classList,Q.config.requestClass)}});se(t,function(e){const t=ie(e);if(t.requestCount===0){e.removeAttribute("disabled");e.removeAttribute("data-disabled-by-htmx")}})}function en(t,n){for(let e=0;en.indexOf(e)<0)}else{e=e.filter(e=>e!==n)}r.delete(t);se(e,e=>r.append(t,e))}}function on(t,n,r,o,i){if(o==null||en(t,o)){return}else{t.push(o)}if(tn(o)){const s=ee(o,"name");let e=o.value;if(o instanceof HTMLSelectElement&&o.multiple){e=M(o.querySelectorAll("option:checked")).map(function(e){return e.value})}if(o instanceof HTMLInputElement&&o.files){e=M(o.files)}nn(s,e,n);if(i){sn(o,r)}}if(o instanceof HTMLFormElement){se(o.elements,function(e){if(t.indexOf(e)>=0){rn(e.name,e.value,n)}else{t.push(e)}if(i){sn(e,r)}});new FormData(o).forEach(function(e,t){if(e instanceof File&&e.name===""){return}nn(t,e,n)})}}function sn(e,t){const n=e;if(n.willValidate){he(n,"htmx:validation:validate");if(!n.checkValidity()){t.push({elt:n,message:n.validationMessage,validity:n.validity});he(n,"htmx:validation:failed",{message:n.validationMessage,validity:n.validity})}}}function ln(n,e){for(const t of e.keys()){n.delete(t)}e.forEach(function(e,t){n.append(t,e)});return n}function cn(e,t){const n=[];const r=new FormData;const o=new FormData;const i=[];const s=ie(e);if(s.lastButtonClicked&&!le(s.lastButtonClicked)){s.lastButtonClicked=null}let l=e instanceof HTMLFormElement&&e.noValidate!==true||te(e,"hx-validate")==="true";if(s.lastButtonClicked){l=l&&s.lastButtonClicked.formNoValidate!==true}if(t!=="get"){on(n,o,i,g(e,"form"),l)}on(n,r,i,e,l);if(s.lastButtonClicked||e.tagName==="BUTTON"||e.tagName==="INPUT"&&ee(e,"type")==="submit"){const u=s.lastButtonClicked||e;const a=ee(u,"name");nn(a,u.value,o)}const c=we(e,"hx-include");se(c,function(e){on(n,r,i,ue(e),l);if(!h(e,"form")){se(f(e).querySelectorAll(ot),function(e){on(n,r,i,e,l)})}});ln(r,o);return{errors:i,formData:r,values:An(r)}}function un(e,t,n){if(e!==""){e+="&"}if(String(n)==="[object Object]"){n=JSON.stringify(n)}const r=encodeURIComponent(n);e+=encodeURIComponent(t)+"="+r;return e}function an(e){e=qn(e);let n="";e.forEach(function(e,t){n=un(n,t,e)});return n}function fn(e,t,n){const r={"HX-Request":"true","HX-Trigger":ee(e,"id"),"HX-Trigger-Name":ee(e,"name"),"HX-Target":te(t,"id"),"HX-Current-URL":ne().location.href};bn(e,"hx-headers",false,r);if(n!==undefined){r["HX-Prompt"]=n}if(ie(e).boosted){r["HX-Boosted"]="true"}return r}function hn(n,e){const t=re(e,"hx-params");if(t){if(t==="none"){return new FormData}else if(t==="*"){return n}else if(t.indexOf("not ")===0){se(t.slice(4).split(","),function(e){e=e.trim();n.delete(e)});return n}else{const r=new FormData;se(t.split(","),function(t){t=t.trim();if(n.has(t)){n.getAll(t).forEach(function(e){r.append(t,e)})}});return r}}else{return n}}function dn(e){return!!ee(e,"href")&&ee(e,"href").indexOf("#")>=0}function gn(e,t){const n=t||re(e,"hx-swap");const r={swapStyle:ie(e).boosted?"innerHTML":Q.config.defaultSwapStyle,swapDelay:Q.config.defaultSwapDelay,settleDelay:Q.config.defaultSettleDelay};if(Q.config.scrollIntoViewOnBoost&&ie(e).boosted&&!dn(e)){r.show="top"}if(n){const s=F(n);if(s.length>0){for(let e=0;e0?o.join(":"):null;r.scroll=u;r.scrollTarget=i}else if(l.indexOf("show:")===0){const a=l.slice(5);var o=a.split(":");const f=o.pop();var i=o.length>0?o.join(":"):null;r.show=f;r.showTarget=i}else if(l.indexOf("focus-scroll:")===0){const h=l.slice("focus-scroll:".length);r.focusScroll=h=="true"}else if(e==0){r.swapStyle=l}else{O("Unknown modifier in hx-swap: "+l)}}}}return r}function pn(e){return re(e,"hx-encoding")==="multipart/form-data"||h(e,"form")&&ee(e,"enctype")==="multipart/form-data"}function mn(t,n,r){let o=null;Ft(n,function(e){if(o==null){o=e.encodeParameters(t,r,n)}});if(o!=null){return o}else{if(pn(n)){return ln(new FormData,qn(r))}else{return an(r)}}}function xn(e){return{tasks:[],elts:[e]}}function yn(e,t){const n=e[0];const r=e[e.length-1];if(t.scroll){var o=null;if(t.scrollTarget){o=ue(ae(n,t.scrollTarget))}if(t.scroll==="top"&&(n||o)){o=o||n;o.scrollTop=0}if(t.scroll==="bottom"&&(r||o)){o=o||r;o.scrollTop=o.scrollHeight}}if(t.show){var o=null;if(t.showTarget){let e=t.showTarget;if(t.showTarget==="window"){e="body"}o=ue(ae(n,e))}if(t.show==="top"&&(n||o)){o=o||n;o.scrollIntoView({block:"start",behavior:Q.config.scrollBehavior})}if(t.show==="bottom"&&(r||o)){o=o||r;o.scrollIntoView({block:"end",behavior:Q.config.scrollBehavior})}}}function bn(r,e,o,i){if(i==null){i={}}if(r==null){return i}const s=te(r,e);if(s){let e=s.trim();let t=o;if(e==="unset"){return null}if(e.indexOf("javascript:")===0){e=e.slice(11);t=true}else if(e.indexOf("js:")===0){e=e.slice(3);t=true}if(e.indexOf("{")!==0){e="{"+e+"}"}let n;if(t){n=vn(r,function(){return Function("return ("+e+")")()},{})}else{n=S(e)}for(const l in n){if(n.hasOwnProperty(l)){if(i[l]==null){i[l]=n[l]}}}}return bn(ue(c(r)),e,o,i)}function vn(e,t,n){if(Q.config.allowEval){return t()}else{fe(e,"htmx:evalDisallowedError");return n}}function wn(e,t){return bn(e,"hx-vars",true,t)}function Sn(e,t){return bn(e,"hx-vals",false,t)}function En(e){return ce(wn(e),Sn(e))}function Cn(t,n,r){if(r!==null){try{t.setRequestHeader(n,r)}catch(e){t.setRequestHeader(n,encodeURIComponent(r));t.setRequestHeader(n+"-URI-AutoEncoded","true")}}}function On(t){if(t.responseURL&&typeof URL!=="undefined"){try{const e=new URL(t.responseURL);return e.pathname+e.search}catch(e){fe(ne().body,"htmx:badResponseUrl",{url:t.responseURL})}}}function R(e,t){return t.test(e.getAllResponseHeaders())}function Rn(t,n,r){t=t.toLowerCase();if(r){if(r instanceof Element||typeof r==="string"){return de(t,n,null,null,{targetOverride:y(r)||ve,returnPromise:true})}else{let e=y(r.target);if(r.target&&!e||r.source&&!e&&!y(r.source)){e=ve}return de(t,n,y(r.source),r.event,{handler:r.handler,headers:r.headers,values:r.values,targetOverride:e,swapOverride:r.swap,select:r.select,returnPromise:true})}}else{return de(t,n,null,null,{returnPromise:true})}}function Hn(e){const t=[];while(e){t.push(e);e=e.parentElement}return t}function Tn(e,t,n){let r;let o;if(typeof URL==="function"){o=new URL(t,document.location.href);const i=document.location.origin;r=i===o.origin}else{o=t;r=l(t,document.location.origin)}if(Q.config.selfRequestsOnly){if(!r){return false}}return he(e,"htmx:validateUrl",ce({url:o,sameHost:r},n))}function qn(e){if(e instanceof FormData)return e;const t=new FormData;for(const n in e){if(e.hasOwnProperty(n)){if(e[n]&&typeof e[n].forEach==="function"){e[n].forEach(function(e){t.append(n,e)})}else if(typeof e[n]==="object"&&!(e[n]instanceof Blob)){t.append(n,JSON.stringify(e[n]))}else{t.append(n,e[n])}}}return t}function Ln(r,o,e){return new Proxy(e,{get:function(t,e){if(typeof e==="number")return t[e];if(e==="length")return t.length;if(e==="push"){return function(e){t.push(e);r.append(o,e)}}if(typeof t[e]==="function"){return function(){t[e].apply(t,arguments);r.delete(o);t.forEach(function(e){r.append(o,e)})}}if(t[e]&&t[e].length===1){return t[e][0]}else{return t[e]}},set:function(e,t,n){e[t]=n;r.delete(o);e.forEach(function(e){r.append(o,e)});return true}})}function An(o){return new Proxy(o,{get:function(e,t){if(typeof t==="symbol"){const r=Reflect.get(e,t);if(typeof r==="function"){return function(){return r.apply(o,arguments)}}else{return r}}if(t==="toJSON"){return()=>Object.fromEntries(o)}if(t in e){if(typeof e[t]==="function"){return function(){return o[t].apply(o,arguments)}}else{return e[t]}}const n=o.getAll(t);if(n.length===0){return undefined}else if(n.length===1){return n[0]}else{return Ln(e,t,n)}},set:function(t,n,e){if(typeof n!=="string"){return false}t.delete(n);if(e&&typeof e.forEach==="function"){e.forEach(function(e){t.append(n,e)})}else if(typeof e==="object"&&!(e instanceof Blob)){t.append(n,JSON.stringify(e))}else{t.append(n,e)}return true},deleteProperty:function(e,t){if(typeof t==="string"){e.delete(t)}return true},ownKeys:function(e){return Reflect.ownKeys(Object.fromEntries(e))},getOwnPropertyDescriptor:function(e,t){return Reflect.getOwnPropertyDescriptor(Object.fromEntries(e),t)}})}function de(t,n,r,o,i,D){let s=null;let l=null;i=i!=null?i:{};if(i.returnPromise&&typeof Promise!=="undefined"){var e=new Promise(function(e,t){s=e;l=t})}if(r==null){r=ne().body}const M=i.handler||Dn;const X=i.select||null;if(!le(r)){oe(s);return e}const c=i.targetOverride||ue(Ee(r));if(c==null||c==ve){fe(r,"htmx:targetError",{target:te(r,"hx-target")});oe(l);return e}let u=ie(r);const a=u.lastButtonClicked;if(a){const L=ee(a,"formaction");if(L!=null){n=L}const A=ee(a,"formmethod");if(A!=null){if(A.toLowerCase()!=="dialog"){t=A}}}const f=re(r,"hx-confirm");if(D===undefined){const K=function(e){return de(t,n,r,o,i,!!e)};const G={target:c,elt:r,path:n,verb:t,triggeringEvent:o,etc:i,issueRequest:K,question:f};if(he(r,"htmx:confirm",G)===false){oe(s);return e}}let h=r;let d=re(r,"hx-sync");let g=null;let F=false;if(d){const N=d.split(":");const I=N[0].trim();if(I==="this"){h=Se(r,"hx-sync")}else{h=ue(ae(r,I))}d=(N[1]||"drop").trim();u=ie(h);if(d==="drop"&&u.xhr&&u.abortable!==true){oe(s);return e}else if(d==="abort"){if(u.xhr){oe(s);return e}else{F=true}}else if(d==="replace"){he(h,"htmx:abort")}else if(d.indexOf("queue")===0){const W=d.split(" ");g=(W[1]||"last").trim()}}if(u.xhr){if(u.abortable){he(h,"htmx:abort")}else{if(g==null){if(o){const P=ie(o);if(P&&P.triggerSpec&&P.triggerSpec.queue){g=P.triggerSpec.queue}}if(g==null){g="last"}}if(u.queuedRequests==null){u.queuedRequests=[]}if(g==="first"&&u.queuedRequests.length===0){u.queuedRequests.push(function(){de(t,n,r,o,i)})}else if(g==="all"){u.queuedRequests.push(function(){de(t,n,r,o,i)})}else if(g==="last"){u.queuedRequests=[];u.queuedRequests.push(function(){de(t,n,r,o,i)})}oe(s);return e}}const p=new XMLHttpRequest;u.xhr=p;u.abortable=F;const m=function(){u.xhr=null;u.abortable=false;if(u.queuedRequests!=null&&u.queuedRequests.length>0){const e=u.queuedRequests.shift();e()}};const B=re(r,"hx-prompt");if(B){var x=prompt(B);if(x===null||!he(r,"htmx:prompt",{prompt:x,target:c})){oe(s);m();return e}}if(f&&!D){if(!confirm(f)){oe(s);m();return e}}let y=fn(r,c,x);if(t!=="get"&&!pn(r)){y["Content-Type"]="application/x-www-form-urlencoded"}if(i.headers){y=ce(y,i.headers)}const U=cn(r,t);let b=U.errors;const j=U.formData;if(i.values){ln(j,qn(i.values))}const V=qn(En(r));const v=ln(j,V);let w=hn(v,r);if(Q.config.getCacheBusterParam&&t==="get"){w.set("org.htmx.cache-buster",ee(c,"id")||"true")}if(n==null||n===""){n=ne().location.href}const S=bn(r,"hx-request");const _=ie(r).boosted;let E=Q.config.methodsThatUseUrlParams.indexOf(t)>=0;const C={boosted:_,useUrlParams:E,formData:w,parameters:An(w),unfilteredFormData:v,unfilteredParameters:An(v),headers:y,target:c,verb:t,errors:b,withCredentials:i.credentials||S.credentials||Q.config.withCredentials,timeout:i.timeout||S.timeout||Q.config.timeout,path:n,triggeringEvent:o};if(!he(r,"htmx:configRequest",C)){oe(s);m();return e}n=C.path;t=C.verb;y=C.headers;w=qn(C.parameters);b=C.errors;E=C.useUrlParams;if(b&&b.length>0){he(r,"htmx:validation:halted",C);oe(s);m();return e}const z=n.split("#");const $=z[0];const O=z[1];let R=n;if(E){R=$;const Z=!w.keys().next().done;if(Z){if(R.indexOf("?")<0){R+="?"}else{R+="&"}R+=an(w);if(O){R+="#"+O}}}if(!Tn(r,R,C)){fe(r,"htmx:invalidPath",C);oe(l);return e}p.open(t.toUpperCase(),R,true);p.overrideMimeType("text/html");p.withCredentials=C.withCredentials;p.timeout=C.timeout;if(S.noHeaders){}else{for(const k in y){if(y.hasOwnProperty(k)){const Y=y[k];Cn(p,k,Y)}}}const H={xhr:p,target:c,requestConfig:C,etc:i,boosted:_,select:X,pathInfo:{requestPath:n,finalRequestPath:R,responsePath:null,anchor:O}};p.onload=function(){try{const t=Hn(r);H.pathInfo.responsePath=On(p);M(r,H);if(H.keepIndicators!==true){Qt(T,q)}he(r,"htmx:afterRequest",H);he(r,"htmx:afterOnLoad",H);if(!le(r)){let e=null;while(t.length>0&&e==null){const n=t.shift();if(le(n)){e=n}}if(e){he(e,"htmx:afterRequest",H);he(e,"htmx:afterOnLoad",H)}}oe(s);m()}catch(e){fe(r,"htmx:onLoadError",ce({error:e},H));throw e}};p.onerror=function(){Qt(T,q);fe(r,"htmx:afterRequest",H);fe(r,"htmx:sendError",H);oe(l);m()};p.onabort=function(){Qt(T,q);fe(r,"htmx:afterRequest",H);fe(r,"htmx:sendAbort",H);oe(l);m()};p.ontimeout=function(){Qt(T,q);fe(r,"htmx:afterRequest",H);fe(r,"htmx:timeout",H);oe(l);m()};if(!he(r,"htmx:beforeRequest",H)){oe(s);m();return e}var T=Zt(r);var q=Yt(r);se(["loadstart","loadend","progress","abort"],function(t){se([p,p.upload],function(e){e.addEventListener(t,function(e){he(r,"htmx:xhr:"+t,{lengthComputable:e.lengthComputable,loaded:e.loaded,total:e.total})})})});he(r,"htmx:beforeSend",H);const J=E?null:mn(p,r,w);p.send(J);return e}function Nn(e,t){const n=t.xhr;let r=null;let o=null;if(R(n,/HX-Push:/i)){r=n.getResponseHeader("HX-Push");o="push"}else if(R(n,/HX-Push-Url:/i)){r=n.getResponseHeader("HX-Push-Url");o="push"}else if(R(n,/HX-Replace-Url:/i)){r=n.getResponseHeader("HX-Replace-Url");o="replace"}if(r){if(r==="false"){return{}}else{return{type:o,path:r}}}const i=t.pathInfo.finalRequestPath;const s=t.pathInfo.responsePath;const l=re(e,"hx-push-url");const c=re(e,"hx-replace-url");const u=ie(e).boosted;let a=null;let f=null;if(l){a="push";f=l}else if(c){a="replace";f=c}else if(u){a="push";f=s||i}if(f){if(f==="false"){return{}}if(f==="true"){f=s||i}if(t.pathInfo.anchor&&f.indexOf("#")===-1){f=f+"#"+t.pathInfo.anchor}return{type:a,path:f}}else{return{}}}function In(e,t){var n=new RegExp(e.code);return n.test(t.toString(10))}function Pn(e){for(var t=0;t0){E().setTimeout(e,x.swapDelay)}else{e()}}if(f){fe(o,"htmx:responseError",ce({error:"Response Status Error Code "+s.status+" from "+i.pathInfo.requestPath},i))}}const Mn={};function Xn(){return{init:function(e){return null},getSelectors:function(){return null},onEvent:function(e,t){return true},transformResponse:function(e,t,n){return e},isInlineSwap:function(e){return false},handleSwap:function(e,t,n,r){return false},encodeParameters:function(e,t,n){return null}}}function Fn(e,t){if(t.init){t.init(n)}Mn[e]=ce(Xn(),t)}function Bn(e){delete Mn[e]}function Un(e,n,r){if(n==undefined){n=[]}if(e==undefined){return n}if(r==undefined){r=[]}const t=te(e,"hx-ext");if(t){se(t.split(","),function(e){e=e.replace(/ /g,"");if(e.slice(0,7)=="ignore:"){r.push(e.slice(7));return}if(r.indexOf(e)<0){const t=Mn[e];if(t&&n.indexOf(t)<0){n.push(t)}}})}return Un(ue(c(e)),n,r)}var jn=false;ne().addEventListener("DOMContentLoaded",function(){jn=true});function Vn(e){if(jn||ne().readyState==="complete"){e()}else{ne().addEventListener("DOMContentLoaded",e)}}function _n(){if(Q.config.includeIndicatorStyles!==false){const e=Q.config.inlineStyleNonce?` nonce="${Q.config.inlineStyleNonce}"`:"";ne().head.insertAdjacentHTML("beforeend"," ."+Q.config.indicatorClass+"{opacity:0} ."+Q.config.requestClass+" ."+Q.config.indicatorClass+"{opacity:1; transition: opacity 200ms ease-in;} ."+Q.config.requestClass+"."+Q.config.indicatorClass+"{opacity:1; transition: opacity 200ms ease-in;} ")}}function zn(){const e=ne().querySelector('meta[name="htmx-config"]');if(e){return S(e.content)}else{return null}}function $n(){const e=zn();if(e){Q.config=ce(Q.config,e)}}Vn(function(){$n();_n();let e=ne().body;kt(e);const t=ne().querySelectorAll("[hx-trigger='restored'],[data-hx-trigger='restored']");e.addEventListener("htmx:abort",function(e){const t=e.target;const n=ie(t);if(n&&n.xhr){n.xhr.abort()}});const n=window.onpopstate?window.onpopstate.bind(window):null;window.onpopstate=function(e){if(e.state&&e.state.htmx){Wt();se(t,function(e){he(e,"htmx:restored",{document:ne(),triggerEvent:he})})}else{if(n){n(e)}}};E().setTimeout(function(){he(e,"htmx:load",{});e=null},0)});return Q}(); \ No newline at end of file diff --git a/static/style.css b/static/style.css index 36e72f2..a70411c 100644 --- a/static/style.css +++ b/static/style.css @@ -145,3 +145,86 @@ tr.banned { opacity: 0.55; } code { background: var(--surface-2); padding: 0.1rem 0.35rem; border-radius: var(--radius); } .invite { word-break: break-all; } + +/* Drop target that is the file input — the native control is hidden behind it, so keyboard + focus, validation and submission keep working. */ +.dropzone { + display: flex; + flex-direction: column; + align-items: center; + gap: 0.3rem; + padding: 2.2rem 1rem; + border: 2px dashed var(--border); + border-radius: var(--radius); + background: var(--surface); + cursor: pointer; + text-align: center; + transition: border-color 0.15s, background 0.15s; +} + +.dropzone:hover { border-color: var(--accent); } +.dropzone.over { border-color: var(--accent); background: var(--surface-2); } +.dropzone.has-file { border-style: solid; border-color: var(--accent); } + +/* Visually hidden, still focusable and still the thing that gets submitted. */ +.dropzone input[type="file"] { + position: absolute; + width: 1px; + height: 1px; + opacity: 0; +} + +.dropzone:focus-within { outline: 2px solid var(--accent); outline-offset: 2px; } + +.dz-title { font-family: var(--font-head); text-transform: uppercase; letter-spacing: 0.04em; } +.filename { color: var(--accent); word-break: break-all; } +.small { font-size: 0.85rem; } + +select, textarea { + background: var(--surface-2); + color: var(--text); + border: 1px solid var(--border); + border-radius: var(--radius); + padding: 0.5rem 0.6rem; + font: inherit; +} + +textarea { resize: vertical; } +select:focus-visible, textarea:focus-visible { outline: 2px solid var(--accent); outline-offset: 2px; } + +.player { width: 100%; margin: 0.6rem 0 1rem; } +.byline { color: var(--muted); margin-top: -0.3rem; } +.intro { white-space: pre-wrap; background: var(--surface); padding: 0.8rem 1rem; + border-left: 3px solid var(--border); border-radius: var(--radius); } +.empty { font-family: var(--font-head); text-transform: uppercase; color: var(--muted); + padding: 2rem 0; } +.nowrap { white-space: nowrap; } +.tag.done { background: var(--surface-2); color: var(--muted); } + +.average { font-size: 1.1rem; } +.score { display: inline-block; font-family: var(--font-head); font-size: 1.1rem; + color: var(--accent); } + +.review { background: var(--surface); border-radius: var(--radius); padding: 0.8rem 1rem; + margin-bottom: 0.8rem; } +.review header { display: flex; align-items: center; gap: 0.6rem; margin-bottom: 0.4rem; } +.review p { white-space: pre-wrap; margin: 0; } + +.scorerow { display: flex; align-items: center; gap: 0.8rem; } +.scorerow input[type="range"] { flex: 1; accent-color: var(--accent); } +.scorerow output { font-family: var(--font-head); font-size: 1.3rem; color: var(--accent); + min-width: 2.5ch; text-align: right; } + +.editbox { background: var(--surface); border-radius: var(--radius); padding: 0.6rem 1rem; + margin-bottom: 1.5rem; } +.editbox summary { cursor: pointer; font-family: var(--font-head); text-transform: uppercase; } +.editbox form { margin: 0.8rem 0; } + +button.danger { background: var(--accent-2); color: var(--text); } +button.danger:hover { background: #e53935; } + +.saved { color: var(--muted); font-size: 0.85rem; min-height: 1.2em; } +.status { background: var(--surface); border-left: 3px solid var(--accent); border-radius: var(--radius); + padding: 0.8rem 1rem; margin-bottom: 1.2rem; } +.status p { margin: 0 0 0.5rem; } +button:disabled { background: var(--surface-2); color: var(--muted); cursor: not-allowed; } diff --git a/submit.go b/submit.go new file mode 100644 index 0000000..1bfe8d7 --- /dev/null +++ b/submit.go @@ -0,0 +1,519 @@ +package main + +import ( + "context" + "errors" + "fmt" + "io" + "log/slog" + "net/http" + "os" + "path/filepath" + "strconv" + "strings" + "time" + + "github.com/jackc/pgx/v5" +) + +const ( + maxUploadBytes = 50 << 20 + maxDuration = 15 * time.Minute + maxPerDay = 5 + maxTitle = 100 + maxArtist = 100 + maxDescription = 2000 + quotaWindowText = "24 tunnin" +) + +// Fixed list, validated app-side. Not a table: it never changes without a code change anyway. +// +// The stored value is the English code and the Finnish label is display only — the same split the +// statuses use, so rewording a genre never touches a song row. +type genre struct { + Code string + Label string +} + +var genres = []genre{ + {"Rock", "Rock"}, + {"Metal", "Metal"}, + {"Punk", "Punk"}, + {"Blues", "Blues"}, + {"Jazz", "Jazz"}, + {"Electronic", "Elektroninen"}, + {"Hip Hop", "Hip hop"}, + {"Pop", "Pop"}, + {"Folk / Country", "Folk / Country"}, + {"Classical", "Klassinen"}, + {"Soundtrack", "Elokuvamusiikki"}, + {"Experimental", "Kokeellinen"}, + {"Finnish", "Kotimainen"}, + {"Just Plain Weird", "Ihan outoa"}, + {"Other", "Muu"}, +} + +func validGenre(code string) bool { + return genreLabel(code) != "" +} + +func genreLabel(code string) string { + for _, g := range genres { + if g.Code == code { + return g.Label + } + } + return "" +} + +// ponytail: in-process goroutines, 2 at a time. A real queue is the upgrade if this ever needs to +// survive a restart mid-conversion or run on another box. Unbounded goroutines shelling out to +// ffmpeg is how one enthusiastic evening fork-bombs a small VPS. +var slots = make(chan struct{}, 2) + +// The nullable metadata columns are read with coalesce and held as plain strings: templates +// indirect pointers when printing, so a nil *string would render as "" inside a form field. +type submission struct { + ID int64 + UserID int64 + Status string + StatusMsg *string + SourceURL *string + TmpPath string + Title string + Artist string + Genre string + Description string + CreatedAt time.Time +} + +func (s *submission) Ready() bool { return s.Status == "ready" } +func (s *submission) Failed() bool { return s.Status == "failed" } +func (s *submission) Done() bool { return s.Ready() || s.Failed() } + +// Every status ships with its Finnish label, so the strings never leave Go. +func (s *submission) Label() string { + switch s.Status { + case "queued": + return "Jonossa…" + case "downloading": + return "Ladataan…" + case "converting": + return "Muunnetaan…" + case "ready": + return "Valmis julkaistavaksi" + case "failed": + return "Epäonnistui" + } + return s.Status +} + +func (s *submission) Genres() []genre { return genres } + +// The chosen genre's Finnish label, for pages that show it rather than offer it. +func (s *submission) GenreLabel() string { return genreLabel(s.Genre) } + +func (a *app) tmpPath(id int64, ext string) string { + return filepath.Join(a.cfg.storageDir, "tmp", strconv.FormatInt(id, 10)+ext) +} + +func (a *app) audioPath(songID int64) string { + return filepath.Join(a.cfg.storageDir, "audio", strconv.FormatInt(songID, 10)+".ogg") +} + +// --- submit --- + +// The submit page also lists your own submissions still in flight, so one is reachable by +// something other than its URL. +func (a *app) submitPage(w http.ResponseWriter, r *http.Request) { + a.submitError(w, r, http.StatusOK, "") +} + +func (a *app) submitError(w http.ResponseWriter, r *http.Request, status int, msg string) { + subs, err := a.mySubmissions(r.Context(), memberFrom(r.Context()).ID) + if err != nil { + slog.Error("list submissions", "ctx", "submissions", "error", err) + } + a.render(w, r, status, "submit.html", + page{Title: "Lähetä kappale", Data: map[string]any{"Error": msg, "Submissions": subs}}) +} + +// Five submissions per rolling 24 hours. Failed ones never count: no audio, no submission, and +// yt-dlp breaking is not the submitter's fault. Published songs do count, so the row being gone +// from `submissions` is why this also looks at `songs`. +func (a *app) overQuota(ctx context.Context, userID int64) (bool, error) { + var n int + err := a.pool.QueryRow(ctx, ` + select (select count(*) from submissions + where user_id = $1 and status <> 'failed' + and created_at > now() - interval '24 hours') + + (select count(*) from songs + where submitted_by = $1 and created_at > now() - interval '24 hours')`, + userID).Scan(&n) + return n >= maxPerDay, err +} + +func (a *app) submit(w http.ResponseWriter, r *http.Request) { + m := memberFrom(r.Context()) + + over, err := a.overQuota(r.Context(), m.ID) + if err != nil { + slog.Error("quota", "ctx", "submissions", "error", err) + a.submitError(w, r, http.StatusInternalServerError, "Jokin meni pieleen.") + return + } + if over { + a.submitError(w, r, http.StatusTooManyRequests, + fmt.Sprintf("Olet lähettänyt jo %d kappaletta viimeisen %s aikana. Yritä huomenna.", + maxPerDay, quotaWindowText)) + return + } + + r.Body = http.MaxBytesReader(w, r.Body, maxUploadBytes) + file, header, err := r.FormFile("audio") + if err != nil { + a.submitError(w, r, http.StatusRequestEntityTooLarge, + "Tiedostoa ei voitu lukea. Enintään 50 MB.") + return + } + defer file.Close() + + var subID int64 + err = a.pool.QueryRow(r.Context(), + `insert into submissions (user_id, status) values ($1, 'queued') returning id`, + m.ID).Scan(&subID) + if err != nil { + slog.Error("create submission", "ctx", "submissions", "error", err) + a.submitError(w, r, http.StatusInternalServerError, "Jokin meni pieleen.") + return + } + + // The row exists before the file does, so nothing on disk is ever unaccounted for. + src := a.tmpPath(subID, filepath.Ext(header.Filename)) + dst, err := os.Create(src) + if err == nil { + _, err = io.Copy(dst, file) + dst.Close() + } + if err != nil { + slog.Error("save upload", "ctx", "submissions", "error", err, "submission", subID) + a.discardSubmission(r.Context(), subID, src) + a.submitError(w, r, http.StatusRequestEntityTooLarge, + "Tiedostoa ei voitu tallentaa. Enintään 50 MB.") + return + } + + // Metadata is read synchronously: arriving later, it would land in a form the submitter is + // already typing into and race their keystrokes. + meta, err := probe(r.Context(), src) + if err != nil { + a.discardSubmission(r.Context(), subID, src) + a.submitError(w, r, http.StatusUnprocessableEntity, + "Tiedostosta ei löytynyt ääntä. Onko se varmasti äänitiedosto?") + return + } + if meta.Duration > maxDuration { + a.discardSubmission(r.Context(), subID, src) + a.submitError(w, r, http.StatusUnprocessableEntity, + "Kappale on yli 15 minuuttia pitkä.") + return + } + + if _, err := a.pool.Exec(r.Context(), + `update submissions set tmp_path = $2, title = nullif($3, ''), artist = nullif($4, '') + where id = $1`, subID, src, meta.Title, meta.Artist); err != nil { + slog.Error("save metadata", "ctx", "submissions", "error", err, "submission", subID) + } + + slog.Info("submission received", "ctx", "submissions", "submission", subID, "user", m.ID) + go a.convert(subID, src) + http.Redirect(w, r, fmt.Sprintf("/submit/%d", subID), http.StatusSeeOther) +} + +func (a *app) discardSubmission(ctx context.Context, subID int64, path string) { + if path != "" { + os.Remove(path) + } + if _, err := a.pool.Exec(ctx, `delete from submissions where id = $1`, subID); err != nil { + slog.Error("discard submission", "ctx", "submissions", "error", err, "submission", subID) + } +} + +// --- convert --- + +func (a *app) convert(subID int64, src string) { + slots <- struct{}{} + defer func() { <-slots }() + + // Detached from the request: the submitter's browser is long gone by now. + ctx := context.Background() + a.setStatus(ctx, subID, "converting", "") + + out := a.tmpPath(subID, ".ogg") + msg, err := convertToOpus(ctx, src, out) + if err != nil { + os.Remove(out) + if msg == "" { + msg = err.Error() + } + a.setStatus(ctx, subID, "failed", msg) + slog.Warn("conversion failed", "ctx", "submissions", "submission", subID, "error", err) + return + } + // The original is discarded as soon as the Opus exists. + os.Remove(src) + + if _, err := a.pool.Exec(ctx, + `update submissions set status = 'ready', status_msg = null, tmp_path = $2 where id = $1`, + subID, out); err != nil { + slog.Error("mark ready", "ctx", "submissions", "error", err, "submission", subID) + return + } + slog.Info("conversion ready", "ctx", "submissions", "submission", subID) +} + +func (a *app) setStatus(ctx context.Context, subID int64, status, msg string) { + if _, err := a.pool.Exec(ctx, + `update submissions set status = $2, status_msg = nullif($3, '') where id = $1`, + subID, status, msg); err != nil { + slog.Error("set status", "ctx", "submissions", "error", err, "submission", subID) + } +} + +// --- the waiting page --- + +// Submitter-only: a submission is invisible to everyone else, including a failed one. +func (a *app) loadSubmission(w http.ResponseWriter, r *http.Request) *submission { + id, err := strconv.ParseInt(r.PathValue("id"), 10, 64) + if err != nil { + http.NotFound(w, r) + return nil + } + var s submission + err = a.pool.QueryRow(r.Context(), ` + select id, user_id, status, status_msg, source_url, coalesce(tmp_path, ''), + coalesce(title, ''), coalesce(artist, ''), coalesce(genre, ''), + coalesce(description, ''), created_at + from submissions where id = $1`, id). + Scan(&s.ID, &s.UserID, &s.Status, &s.StatusMsg, &s.SourceURL, &s.TmpPath, + &s.Title, &s.Artist, &s.Genre, &s.Description, &s.CreatedAt) + if errors.Is(err, pgx.ErrNoRows) { + http.NotFound(w, r) + return nil + } else if err != nil { + slog.Error("load submission", "ctx", "submissions", "error", err) + http.Error(w, "virhe", http.StatusInternalServerError) + return nil + } + if s.UserID != memberFrom(r.Context()).ID { + http.NotFound(w, r) + return nil + } + return &s +} + +func (a *app) submissionPage(w http.ResponseWriter, r *http.Request) { + s := a.loadSubmission(w, r) + if s == nil { + return + } + a.render(w, r, http.StatusOK, "submission.html", page{Title: "Lähetys", Data: s}) +} + +// The same partial the page includes on first paint, returned alone for the HTMX poll — so the +// markup exists once and arrives already populated. HTMX stops polling when the fragment drops +// hx-trigger, which it does on a terminal status. +func (a *app) submissionStatus(w http.ResponseWriter, r *http.Request) { + s := a.loadSubmission(w, r) + if s == nil { + return + } + w.Header().Set("Content-Type", "text/html; charset=utf-8") + if err := pages["submission.html"].ExecuteTemplate(w, "submission-status", s); err != nil { + slog.Error("render status", "ctx", "submissions", "error", err) + } +} + +// Metadata is editable while the conversion runs — that is the point of the waiting page. There is +// no save button: HTMX posts here after a pause in typing, and pressing Julkaise posts the same +// fields to publish, so a browser without JS loses nothing. +func (a *app) saveMetadata(ctx context.Context, subID int64, r *http.Request) error { + genre := r.FormValue("genre") + if genre != "" && !validGenre(genre) { + return fmt.Errorf("unknown genre %q", genre) + } + _, err := a.pool.Exec(ctx, ` + update submissions set title = nullif($2, ''), artist = nullif($3, ''), + genre = nullif($4, ''), description = nullif($5, '') + where id = $1`, + subID, + clean(r.FormValue("title"), maxTitle), + clean(r.FormValue("artist"), maxArtist), + genre, + clean(r.FormValue("description"), maxDescription)) + return err +} + +func (a *app) saveSubmission(w http.ResponseWriter, r *http.Request) { + s := a.loadSubmission(w, r) + if s == nil { + return + } + if err := a.saveMetadata(r.Context(), s.ID, r); err != nil { + slog.Error("save submission", "ctx", "submissions", "error", err, "submission", s.ID) + http.Error(w, "virhe", http.StatusUnprocessableEntity) + return + } + // The autosave answers with the "saved at" line and nothing else; a plain POST (no JS) goes + // back to the page. + if r.Header.Get("HX-Request") == "" { + http.Redirect(w, r, fmt.Sprintf("/submit/%d", s.ID), http.StatusSeeOther) + return + } + w.Header().Set("Content-Type", "text/html; charset=utf-8") + if err := pages["submission.html"].ExecuteTemplate(w, "saved", + time.Now().Local().Format("15.04")); err != nil { + slog.Error("render saved", "ctx", "submissions", "error", err) + } +} + +// --- publish --- + +func (a *app) publish(w http.ResponseWriter, r *http.Request) { + s := a.loadSubmission(w, r) + if s == nil { + return + } + if !s.Ready() { + http.Error(w, "ei vielä valmis", http.StatusConflict) + return + } + + // Julkaise submits the metadata form, so the last keystrokes arrive with it — the autosave is + // a convenience, not the only path. + if r.FormValue("title") != "" || r.FormValue("artist") != "" || r.FormValue("genre") != "" { + if err := a.saveMetadata(r.Context(), s.ID, r); err != nil { + slog.Error("save before publish", "ctx", "submissions", "error", err, "submission", s.ID) + http.Error(w, "virhe", http.StatusUnprocessableEntity) + return + } + if s = a.loadSubmission(w, r); s == nil { + return + } + } + + // Title, artist and genre are required here rather than at submit: the form is meant to be + // filled while the conversion runs, and prefill can legitimately produce nothing. + title, artist, genre := clean(s.Title, maxTitle), clean(s.Artist, maxArtist), s.Genre + if title == "" || artist == "" || !validGenre(genre) { + a.flash(w, "Täytä nimi, esittäjä ja genre ennen julkaisua.") + http.Redirect(w, r, fmt.Sprintf("/submit/%d", s.ID), http.StatusSeeOther) + return + } + + src := s.TmpPath + meta, err := probe(r.Context(), src) + if err != nil { + slog.Error("probe before publish", "ctx", "submissions", "error", err, "submission", s.ID) + a.flash(w, "Äänitiedostoa ei löytynyt. Lähetä kappale uudelleen.") + http.Redirect(w, r, fmt.Sprintf("/submit/%d", s.ID), http.StatusSeeOther) + return + } + + tx, err := a.pool.Begin(r.Context()) + if err != nil { + slog.Error("begin publish", "ctx", "submissions", "error", err) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + defer tx.Rollback(r.Context()) + + var songID int64 + err = tx.QueryRow(r.Context(), ` + insert into songs (title, artist, genre, description, audio_file, duration_seconds, + source_url, submitted_by) + values ($1, $2, $3, $4, '', $5, $6, $7) returning id`, + title, artist, genre, nilIfEmpty(clean(s.Description, maxDescription)), + int(meta.Duration.Seconds()), s.SourceURL, s.UserID).Scan(&songID) + if err != nil { + slog.Error("insert song", "ctx", "songs", "error", err, "submission", s.ID) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + + // The rename is inside the transaction: if the file move fails, the song row never existed. + // A crash between rename and commit leaves an orphan .ogg — the startup sweep gets it. + dst := a.audioPath(songID) + if err := os.Rename(src, dst); err != nil { + slog.Error("move audio", "ctx", "songs", "error", err, "submission", s.ID) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + if _, err := tx.Exec(r.Context(), + `update songs set audio_file = $2 where id = $1`, + songID, filepath.Base(dst)); err != nil { + os.Rename(dst, src) + slog.Error("set audio file", "ctx", "songs", "error", err, "song", songID) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + if _, err := tx.Exec(r.Context(), `delete from submissions where id = $1`, s.ID); err != nil { + os.Rename(dst, src) + slog.Error("delete submission", "ctx", "submissions", "error", err, "submission", s.ID) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + if err := tx.Commit(r.Context()); err != nil { + os.Rename(dst, src) + slog.Error("commit publish", "ctx", "songs", "error", err, "submission", s.ID) + http.Error(w, "virhe", http.StatusInternalServerError) + return + } + + slog.Info("song published", "ctx", "songs", "song", songID, "user", s.UserID) + a.flash(w, "Kappale julkaistu.") + http.Redirect(w, r, "/", http.StatusSeeOther) +} + +// A failed submission is denied in every sense that matters: invisible to everyone but its +// submitter and never in `songs`. Discard removes the row and its temp file. +func (a *app) discard(w http.ResponseWriter, r *http.Request) { + s := a.loadSubmission(w, r) + if s == nil { + return + } + a.discardSubmission(r.Context(), s.ID, s.TmpPath) + os.Remove(a.tmpPath(s.ID, ".ogg")) + a.flash(w, "Lähetys poistettu.") + http.Redirect(w, r, "/", http.StatusSeeOther) +} + +func nilIfEmpty(s string) *string { + if strings.TrimSpace(s) == "" { + return nil + } + return &s +} + +// Own in-flight submissions, for the home page — otherwise a submission is only reachable by URL. +func (a *app) mySubmissions(ctx context.Context, userID int64) ([]*submission, error) { + rows, err := a.pool.Query(ctx, ` + select id, user_id, status, status_msg, source_url, coalesce(tmp_path, ''), + coalesce(title, ''), coalesce(artist, ''), coalesce(genre, ''), + coalesce(description, ''), created_at + from submissions where user_id = $1 order by created_at desc`, userID) + if err != nil { + return nil, err + } + defer rows.Close() + var out []*submission + for rows.Next() { + var s submission + if err := rows.Scan(&s.ID, &s.UserID, &s.Status, &s.StatusMsg, &s.SourceURL, &s.TmpPath, + &s.Title, &s.Artist, &s.Genre, &s.Description, &s.CreatedAt); err != nil { + return nil, err + } + out = append(out, &s) + } + return out, rows.Err() +} diff --git a/submit_test.go b/submit_test.go new file mode 100644 index 0000000..7212d04 --- /dev/null +++ b/submit_test.go @@ -0,0 +1,222 @@ +package main + +import ( + "context" + "fmt" + "net/http" + "net/http/httptest" + "os" + "os/exec" + "path/filepath" + "testing" +) + +func TestClean(t *testing.T) { + for _, tc := range []struct{ in, want string }{ + {"Testikappale", "Testikappale"}, + {" padded ", "padded"}, + {"line\nbreak", "line break"}, + {"tab\tsep", "tab sep"}, + {"bell\x07null\x00", "bellnull"}, + {"a b c", "a b c"}, + } { + if got := clean(tc.in, 100); got != tc.want { + t.Errorf("clean(%q) = %q, want %q", tc.in, got, tc.want) + } + } + // Truncation counts runes, not bytes: a 100-ä title is 100 characters, not 50. + long := "" + for range 150 { + long += "ä" + } + if got := []rune(clean(long, 100)); len(got) != 100 { + t.Errorf("truncated to %d runes, want 100", len(got)) + } +} + +func makeAudio(t *testing.T, path string) { + t.Helper() + if _, err := exec.LookPath("ffmpeg"); err != nil { + t.Skip("ffmpeg not on PATH") + } + cmd := exec.Command("ffmpeg", "-nostdin", "-y", "-f", "lavfi", + "-i", "sine=frequency=440:duration=1", "-c:a", "libopus", path) + if out, err := cmd.CombinedOutput(); err != nil { + t.Fatalf("ffmpeg: %v\n%s", err, out) + } +} + +func (a *app) readySubmission(t *testing.T, userID int64) *submission { + t.Helper() + var id int64 + err := a.pool.QueryRow(context.Background(), ` + insert into submissions (user_id, status, title, artist, genre) + values ($1, 'ready', 'Testikappale', 'Testiartisti', 'Metal') returning id`, + userID).Scan(&id) + if err != nil { + t.Fatal(err) + } + path := a.tmpPath(id, ".ogg") + makeAudio(t, path) + if _, err := a.pool.Exec(context.Background(), + `update submissions set tmp_path = $2 where id = $1`, id, path); err != nil { + t.Fatal(err) + } + return &submission{ID: id, UserID: userID, Status: "ready", TmpPath: path} +} + +// A song row and its .ogg appear together, or neither does. +func TestPublishIsAllOrNothing(t *testing.T) { + a := testApp(t) + ctx := context.Background() + a.cfg.storageDir = t.TempDir() + audioDir := filepath.Join(a.cfg.storageDir, "audio") + for _, d := range []string{"audio", "tmp"} { + if err := os.MkdirAll(filepath.Join(a.cfg.storageDir, d), 0o755); err != nil { + t.Fatal(err) + } + } + + id := a.seedMember(t, "esa@example.com") + sub := a.readySubmission(t, id) + + // Make the move impossible, the same way a full or read-only disk would. + if err := os.Chmod(audioDir, 0o500); err != nil { + t.Fatal(err) + } + t.Cleanup(func() { os.Chmod(audioDir, 0o755) }) + + r := httptest.NewRequest("POST", fmt.Sprintf("/submit/%d/publish", sub.ID), nil) + r.SetPathValue("id", fmt.Sprint(sub.ID)) + r = r.WithContext(context.WithValue(ctx, memberKey, &member{ID: id})) + w := httptest.NewRecorder() + a.publish(w, r) + + if w.Code != http.StatusInternalServerError { + t.Fatalf("publish with an unwritable audio dir: status = %d, want 500", w.Code) + } + var songs, submissions int + if err := a.pool.QueryRow(ctx, `select count(*) from songs`).Scan(&songs); err != nil { + t.Fatal(err) + } + if songs != 0 { + t.Fatalf("orphan song row: %d rows with no audio file", songs) + } + if err := a.pool.QueryRow(ctx, `select count(*) from submissions`).Scan(&submissions); err != nil { + t.Fatal(err) + } + if submissions != 1 { + t.Fatalf("submission rows = %d, want 1 — a failed publish must leave it recoverable", submissions) + } + if _, err := os.Stat(sub.TmpPath); err != nil { + t.Fatalf("converted audio was lost: %v", err) + } + + // With the directory writable again, the same submission publishes. + os.Chmod(audioDir, 0o755) + w = httptest.NewRecorder() + a.publish(w, r) + if w.Code != http.StatusSeeOther { + t.Fatalf("publish: status = %d, want 303", w.Code) + } + var songID int64 + if err := a.pool.QueryRow(ctx, `select id from songs`).Scan(&songID); err != nil { + t.Fatal(err) + } + if _, err := os.Stat(a.audioPath(songID)); err != nil { + t.Fatalf("published song has no audio file: %v", err) + } + if err := a.pool.QueryRow(ctx, `select count(*) from submissions`).Scan(&submissions); err != nil { + t.Fatal(err) + } + if submissions != 0 { + t.Fatalf("submission survived publish: %d rows", submissions) + } +} + +// Five per rolling 24 hours, counting published songs, never counting failures. +func TestSubmissionQuota(t *testing.T) { + a := testApp(t) + ctx := context.Background() + id := a.seedMember(t, "esa@example.com") + + check := func(want bool, why string) { + t.Helper() + over, err := a.overQuota(ctx, id) + if err != nil { + t.Fatal(err) + } + if over != want { + t.Fatalf("%s: overQuota = %v, want %v", why, over, want) + } + } + + check(false, "no submissions") + + for range 4 { + if _, err := a.pool.Exec(ctx, + `insert into submissions (user_id, status) values ($1, 'ready')`, id); err != nil { + t.Fatal(err) + } + } + check(false, "four in flight") + + // Failures never count — yt-dlp rot and bad files are not the submitter's fault. + for range 10 { + if _, err := a.pool.Exec(ctx, + `insert into submissions (user_id, status) values ($1, 'failed')`, id); err != nil { + t.Fatal(err) + } + } + check(false, "failures do not count") + + // A published song still occupies a slot, even though its submission row is gone. + if _, err := a.pool.Exec(ctx, ` + insert into songs (title, artist, genre, audio_file, duration_seconds, submitted_by) + values ('T', 'A', 'Metal', '1.ogg', 60, $1)`, id); err != nil { + t.Fatal(err) + } + check(true, "four in flight plus one published") + + // Yesterday's submissions are outside the window. + if _, err := a.pool.Exec(ctx, + `update submissions set created_at = now() - interval '25 hours' where user_id = $1`, + id); err != nil { + t.Fatal(err) + } + check(false, "older than 24 hours") +} + +// A submission left mid-conversion by a restart must not say "converting" forever. +func TestRestartRecovery(t *testing.T) { + a := testApp(t) + ctx := context.Background() + id := a.seedMember(t, "esa@example.com") + + for _, status := range []string{"queued", "downloading", "converting"} { + if _, err := a.pool.Exec(ctx, + `insert into submissions (user_id, status) values ($1, $2)`, id, status); err != nil { + t.Fatal(err) + } + } + if err := sweep(ctx, a.pool); err != nil { + t.Fatal(err) + } + + var stuck int + if err := a.pool.QueryRow(ctx, + `select count(*) from submissions where status <> 'failed'`).Scan(&stuck); err != nil { + t.Fatal(err) + } + if stuck != 0 { + t.Fatalf("%d submissions survived the sweep still in flight", stuck) + } + var msg string + if err := a.pool.QueryRow(ctx, + `select status_msg from submissions limit 1`).Scan(&msg); err != nil { + t.Fatal(err) + } + if msg == "" { + t.Fatal("swept submission carries no explanation") + } +} diff --git a/templates/home.html b/templates/home.html deleted file mode 100644 index 8014827..0000000 --- a/templates/home.html +++ /dev/null @@ -1,5 +0,0 @@ -{{define "content"}} -

Jono

-

Jono on tyhjä — kappaleita ei vielä voi lähettää. Tämä sivu täyttyy kun - lähetysputki ja arvostelut ovat valmiit.

-{{end}} diff --git a/templates/layout.html b/templates/layout.html index 2a46c5a..79d5c54 100644 --- a/templates/layout.html +++ b/templates/layout.html @@ -5,6 +5,7 @@ {{.Title}} — Levyraati +
@@ -14,6 +15,8 @@ Ylläpito {{else if .Member}} Jono + Kappaleet + Lähetä {{.Member.Initials}}
{{else}} diff --git a/templates/partials/player.html b/templates/partials/player.html new file mode 100644 index 0000000..caa9495 --- /dev/null +++ b/templates/partials/player.html @@ -0,0 +1,30 @@ +{{define "player"}} + +{{end}} + +{{define "songrow"}} + + + {{.Title}} + — {{.Artist}} + {{if .Own}}oma{{else if .Reviewed}}arvosteltu{{end}} + + {{.GenreLabel}} + {{.Length}} + + {{if .Average}}{{score .Average}} ({{.ReviewCount}}) + {{else if .ReviewCount}}{{.ReviewCount}} arvostelua + {{else}}{{end}} + + +{{end}} + +{{define "scorefield"}} + +{{end}} diff --git a/templates/queue.html b/templates/queue.html new file mode 100644 index 0000000..3c42676 --- /dev/null +++ b/templates/queue.html @@ -0,0 +1,18 @@ +{{define "content"}} +

Jono

+ +{{if .Data.Items}} +

Arvostelemattomat kappaleet, vanhimmasta uusimpaan. Pisteet paljastuvat kun + olet kirjoittanut oman arvostelusi.

+ + + + {{range .Data.Items}}{{template "songrow" .}}{{end}} + +
KappaleGenreKestoArvostelut
+ {{with .Data.NextCursor}}

Lisää →

{{end}} +{{else}} +

Jono on tyhjä. Olet arvostellut kaiken, mitä muut ovat lähettäneet.

+

Lähetä kappale tai selaa kaikkia kappaleita.

+{{end}} +{{end}} diff --git a/templates/song.html b/templates/song.html new file mode 100644 index 0000000..358e758 --- /dev/null +++ b/templates/song.html @@ -0,0 +1,105 @@ +{{define "content"}} +{{$s := .Data}} +

{{$s.Title}}

+ + +{{template "player" $s}} + +{{with $s.Description}}

{{.}}

{{end}} +{{with $s.SourceURL}}

Kuuntele YouTubessa

{{end}} + +{{if $s.CanEdit}} +
+ Muokkaa tietoja +
+ + + + + +
+
+ +
+

Muokkaus ja poisto ovat mahdollisia vain ennen ensimmäistä arvostelua.

+
+{{else if $s.Own}} +

Kappaletta on jo arvosteltu, joten tietoja ei voi enää muuttaa.

+{{end}} + +
+ {{if $s.CanReview}} +

Arvostele

+
+ {{template "scorefield" 50}} + + +
+

Muiden arvostelut ja pisteet paljastuvat kun olet tallentanut omasi. + Voit muokata tai poistaa arvostelusi 30 minuutin ajan.

+ {{else if $s.ViewerReview}} +

Oma arvostelusi

+ {{with $s.ViewerReview}} + {{if .CanEdit}} +
+ + {{template "scorefield" .Score}} + + +
+
+ + +
+

Muokkausaika päättyy {{fidate .EditableUntil}}.

+ {{else}} +

{{.Score}}

+

{{.Text}}

+

Muokkausaika on päättynyt.

+ {{end}} + {{end}} + {{end}} +
+ +
+

Arvostelut{{if $s.ReviewCount}} ({{$s.ReviewCount}}){{end}}

+ + {{if $s.Revealed}} + {{if $s.Average}}

Keskiarvo {{score $s.Average}}

{{end}} + {{range $s.Reviews}} +
+
+ {{.Initials}} + {{.Reviewer}} + {{.Score}} + {{fidate .CreatedAt}} +
+

{{.Text}}

+
+ {{else}} +

Kukaan ei ole vielä arvostellut tätä kappaletta.

+ {{end}} + {{else}} +

Muiden arvostelut ja keskiarvo näkyvät kun olet kirjoittanut omasi. + {{if $s.ReviewCount}}Arvosteluja on {{$s.ReviewCount}}.{{end}}

+ {{end}} +
+{{end}} diff --git a/templates/songs.html b/templates/songs.html new file mode 100644 index 0000000..a1839a2 --- /dev/null +++ b/templates/songs.html @@ -0,0 +1,16 @@ +{{define "content"}} +

Kappaleet

+ +{{if .Data.Items}} + + + + {{range .Data.Items}}{{template "songrow" .}}{{end}} + +
KappaleGenreKestoPisteet
+ {{with .Data.NextCursor}}

Vanhempia →

{{end}} +{{else}} +

Yhtään kappaletta ei ole vielä julkaistu.

+

Lähetä ensimmäinen.

+{{end}} +{{end}} diff --git a/templates/submission.html b/templates/submission.html new file mode 100644 index 0000000..559f978 --- /dev/null +++ b/templates/submission.html @@ -0,0 +1,55 @@ +{{define "submission-status"}} +
+

{{.Label}}

+ {{if .Failed}} + {{with .StatusMsg}}

{{.}}

{{end}} +
+ +
+ {{else}} + + + {{if not .Ready}}

Julkaise aukeaa kun muunnos on valmis.

{{end}} + {{end}} +
+{{end}} + +{{define "saved"}}{{if .}}Tallennettu {{.}}{{end}}{{end}} + +{{define "content"}} +

Lähetys

+ +{{if .Data.Failed}}{{template "submission-status" .Data}}{{end}} + +{{if not .Data.Failed}} +
+ + + + + {{template "saved" ""}} +
+ +

Tiedot tallentuvat itsestään kirjoittaessasi. Nimi, esittäjä ja genre tarvitaan + ennen julkaisua.

+ +{{template "submission-status" .Data}} +{{end}} +{{end}} diff --git a/templates/submit.html b/templates/submit.html new file mode 100644 index 0000000..b39d938 --- /dev/null +++ b/templates/submit.html @@ -0,0 +1,67 @@ +{{define "content"}} +

Lähetä kappale

+ +{{with .Data.Error}}

{{.}}

{{end}} + +
+ + +
+ +{{with .Data.Submissions}} +
+

Omat lähetykset

+ + + + {{range .}} + + + + + + {{end}} + +
KappaleTilaLähetetty
{{if .Title}}{{.Title}}{{else}}(nimetön){{end}}{{.Label}}{{fidate .CreatedAt}}
+

Valmis lähetys odottaa Julkaise-painallusta — vasta se tuo kappaleen + muiden nähtäville.

+
+{{end}} + +

Enintään 50 MB ja 15 minuuttia. Tiedosto muunnetaan Opus-muotoon, ja pääset + kirjoittamaan esittelyn odotellessa. Kappale julkaistaan vasta kun painat Julkaise.

+ + +{{end}}