Skip to content

Fix bulletin parsing and discovery; record cafe design lessons - #28

Merged
blisspixel merged 1 commit into
mainfrom
fix/bug-hunt-round-two
Oct 3, 2026
Merged

blisspixel merged 1 commit into
mainfrom
fix/bug-hunt-round-two

Conversation

@blisspixel

@blisspixel blisspixel commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Ambiguous bulletin JSON could publish after overwriting an earlier publication choice, and the root entrance ignored client representation preferences and returned inconsistent HEAD metadata. The reusable authentication helper also accepted empty or partial hashes when called directly with malformed grants; the deployed configuration parser already rejected those grants.

Fix the four reproduced cases:

  • Reject repeated decoded JSON member names at every depth before publication, reusing the existing syntax-only parser while retaining accepted original bytes.
  • Require equal digest lengths before byte comparison, so native callers cannot authenticate through a partial or empty comparison.
  • Negotiate the root's JSON and HTML representations using quality, specificity, and exclusions. Favor JSON on ties and return 406 when neither representation is acceptable.
  • Make root HEAD metadata match the selected GET representation, with no response body. Preserve conditional request headers, including ETag validation.

Regression tests failed before the fixes and now pass. Native cases cover publication, sender, body and extension duplicates, escaped keys, nested arrays, malformed grant hashes, media ranges, parameters, wildcards, and invalid weights. Actual local Cloudflare tests check unchanged history on rejected publication, root preferences, HEAD metadata and conditional requests. The service guide, schema description, machine instructions, validation notes, and roadmap match the implementation. Syntax sharing does not add archive bundles to the HTTP contract.

The requested historical and contemporary research is recorded in docs/CAFE_AND_BBS_LESSONS.md, linked from the README, hosted commons design, and roadmap. It compares primary BBS and hacker accounts, Moltbook continuity studies, modern persistent runtimes, durable shared worlds, and the implemented Numinous and Fragr interfaces. It distinguishes historical observations and bounded experiments from design inferences. The practical leads are revisitable encounters, participant-shaped purposes, cultural sources, optional play, and visible stewardship. Game adapters, a change feed, participant-shaped groups, and public deployment remain planned.

Validation completed locally:

  • Required Rust formatting, workspace Clippy, repository/schema checks, and strict mypy 2.3.1.
  • Rust workspace tests and coverage: 91.72% lines, above the 80% gate.
  • Python test/example sequence across both hosts: 91.04% coverage, above the 80% gate.
  • Wasm Clippy, pinned Worker build, current static assets, and all nine actual local Cloudflare runtime tests.

All 26 branch and pull-request checks passed before merge. Pull-request CI covers native platforms, actual Cloudflare runtime behavior, documentation, installers, and the coverage gates.

Merged-main validation: all 13 jobs passed on ddb6907a1da497546e293abf9ee067e9a157f3f4. Main CI. The short-lived branch was deleted; only main remains locally and on origin.

@blisspixel
blisspixel merged commit ddb6907 into main Oct 3, 2026
26 checks passed
@blisspixel
blisspixel deleted the fix/bug-hunt-round-two branch October 3, 2026 21:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant