<feed xmlns='http://www.w3.org/2005/Atom'>
<title>typerpunk/data/packs, branch main</title>
<subtitle>Rust + WASM typing game.
</subtitle>
<id>https://srdusr.com/git/typerpunk/atom?h=main</id>
<link rel='self' href='https://srdusr.com/git/typerpunk/atom?h=main'/>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/typerpunk/'/>
<updated>2026-03-04T09:18:00+00:00</updated>
<entry>
<title>Add long passages for people who want a longer sit</title>
<updated>2026-03-04T09:18:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2026-03-04T09:18:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/typerpunk/commit/?id=d79f429d801b7cac077c5573070610563f92bbf1'/>
<id>urn:sha1:d79f429d801b7cac077c5573070610563f92bbf1</id>
<content type='text'>
Eleven passages of 320 to 600 characters, which is two to four minutes at an
ordinary speed. Five are public domain openings that run long by nature; the
rest were written to run long rather than padded.

The floor in getRandomTextItem stops a test being too short. Nothing stopped
one being long, and the dataset simply had none: before this the longest
passage was 320 characters and there were three of them.

465 passages, longest now 500 characters.
</content>
</entry>
<entry>
<title>Make every passage long enough to be worth timing, and credit all of them</title>
<updated>2026-01-14T20:23:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2026-01-14T20:23:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/typerpunk/commit/?id=4933f669f8338ca5e4c64cf0294818c5d15ed122'/>
<id>urn:sha1:4933f669f8338ca5e4c64cf0294818c5d15ed122</id>
<content type='text'>
The dataset's median passage was 69 characters, about twelve words, which is
over in twelve seconds at an ordinary speed. Some packs were worse: shell had
a median of 46 and a shortest entry of 17. That is the reason packs felt
small. It was not the number of entries, which was 15 to 37 per pack, but the
length of each one.

Multiplayer had already hit this and worked around it: load_race_texts
filters to 120 characters or more. That filter left only 61 of 350 passages
eligible, 38 of them from two packs, so races repeated constantly and four
packs could never come up at all.

Both halves are fixed.

Content: 104 longer passages added across every pack. The command packs get
whole pipelines rather than single flags, which is how the tools are actually
used and what the explanations were always for. Prose packs get passages that
run 150 to 320 characters.

Selection: a floor of 120 characters. Prose packs draw from their long
entries where a pack holds at least five, so no pack is reduced to the same
few passages. The command packs chain consecutive entries into one drill,
which is the natural shape for them, and the explanations are collected so
each line is still described.

Measured over 400 draws per pack, every category now runs a median of 146 to
218 characters with a shortest draw of 120. The race pool went from 61 of 350
to 130 of 454.

Attribution: 24 passages had none and displayed nothing at all under the
text. They now say Unknown, which is the honest answer for a fact written for
the pack, and the pangram is credited as one. The results and typing screens
both fall back to Unknown rather than rendering an empty line, and the pack
name is shown beside the source.

Multiplayer results, three fixes:

- PB never appeared. A race has no mode of its own, so modeKey was undefined,
  so recordResult never ran. Races share one key, because the passage is
  whatever the server dealt and a per-passage best would never be beaten.
- Play Again started a solo test. A race carries standings and a solo run does
  not, so the results screen can tell them apart and now queues for another
  race. The end screen's own cleanup leaves the old room first.
- CONSISTENCY was the longest label on the screen and made the accuracy
  column wider than the WPM column opposite it. It reads CON.

RaceText carries the pack name so the results can show it for a race the same
way single player does.

24 Rust tests and 3 browser tests pass.
</content>
</entry>
<entry>
<title>Harden for production: dependencies, headers, admin roles, docs</title>
<updated>2025-12-15T18:44:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2025-12-15T18:44:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/typerpunk/commit/?id=1740327557074df0c8b99635ee949e2540ac94d0'/>
<id>urn:sha1:1740327557074df0c8b99635ee949e2540ac94d0</id>
<content type='text'>
Dependencies
- The server build carried 37 known advisories, including RUSTSEC-2024-0363
  in sqlx 0.7, which is the database layer. sqlx moved to 0.8 with
  default-features off, which also drops the MySQL and SQLite drivers and
  with them rsa and RUSTSEC-2023-0071. reqwest moved to 0.12, which brings
  hyper 1.x and was the sole source of every remaining advisory: h2 0.3,
  rustls-webpki 0.101, rustls-pemfile 1.0 and idna 0.3.
- The server build now reports no known vulnerabilities against OSV. cargo
  audit itself would not compile, so the check queries OSV with the crate
  versions cargo tree reports for the server binary.
- Cargo.lock is committed. This workspace produces binaries, so the lockfile
  is what makes a deployed build reproducible and the audit above meaningful.

Headers
- The application sent no security headers at all. The static server now
  sends a Content-Security-Policy, nosniff, frame options, a referrer policy
  and a permissions policy; the API sends a policy of its own, since it
  serves JSON and should load and frame nothing.
- The one inline script in index.html moved to a file so script-src needs no
  unsafe-inline. WebAssembly needs wasm-unsafe-eval, without which nothing
  types at all, so that is present and explained.
- Five style attributes moved to the CSSOM rather than adding unsafe-inline
  for styles. A style attribute in markup is refused by the policy; the same
  property set through element.style is not.

Production configuration
- With TYPERPUNK_ENV=production the server refuses to start if COOKIE_SECURE
  is off, if DATABASE_URL is still the development default, or if
  FRONTEND_ORIGIN is http on a non-local host. These were warnings, and a
  warning in a log nobody reads is not a safeguard.

Administration
- Moderators were appointed with psql. There is now an admin role,
  bootstrapped from TYPERPUNK_ADMIN_USERNAME at startup, and a UI to appoint
  and remove moderators. An administrator's own role cannot be changed
  through the API, so a mistake cannot lock everyone out of moderation.

Corpus
- scripts/export_approved.js writes approved submissions back into
  data/packs/community-*.json. Approved passages are served from the database
  and merged at startup, so without this the repository dataset and the live
  corpus drift apart, and a fresh checkout or the TUI sees only what shipped.

Documentation
- README rewritten for the repository: what it does, how to run it, the pack
  format, the server variables, deployment, and what the security posture
  actually is. Plain English, no em dashes, no emoji.

Checked and found already correct: every private endpoint refuses anonymous
callers, session cookies are HttpOnly and SameSite=Lax, CORS names a single
origin, internal errors are logged rather than returned, and every query is
parameterised.
</content>
</entry>
<entry>
<title>Rebuild the generic packs, add shell and sysadmin, fix short race passages</title>
<updated>2025-12-07T19:58:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2025-12-07T19:58:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/typerpunk/commit/?id=8fc4440150ce84c9cc3f5ec13d50beb58a5b65bc'/>
<id>urn:sha1:8fc4440150ce84c9cc3f5ec13d50beb58a5b65bc</id>
<content type='text'>
The packs were not proper. An audit found 86 of 253 items (33%) carrying an
attribution that just restated the category - prose *about* a topic with an
invented source, which is the same fault the movies pack had. Six of thirteen
packs were mostly that: technology had 15 items and one distinct attribution.

- science, technology, history, nature and business are now sourced quotes
  with real attributions: Feynman, Curie, Hopper, Dijkstra, Lincoln, Carson,
  Drucker, Goodhart. 82 items, all attributed to a person or a work.
- general is original factual prose, so it now carries no attribution at all
  rather than claiming "General knowledge" as a source. merge_packs no longer
  invents one from the pack's filename.
- Four explanatory passages in philosophy lost their "Philosophy" attribution
  for the same reason.
- One duplicated passage removed.

Generic attributions: 86/253 before, 0/349 now.

New technical packs
- shell: 24 awk, sed and pipeline drills, each explaining what the line does
  - field splitting, associative arrays, !seen[$0]++, process substitution,
  xargs -0, strict mode.
- sysadmin: 24 operational one-liners across systemd, disk, processes,
  network, permissions, SSH, backup and containers.
- programming grew to 37 and hacking to 30, with git bisect, window
  functions, EXPLAIN ANALYZE, certificate transparency and capability audits.
- All 115 technical drills carry an explanation.

Race passage length
- Multiplayer drew from the same pool as single player, so a race could land
  on a 22-character quote and be over before anyone had their hands in
  position. Races now require 120 characters; the filter is applied when the
  pool is loaded, not to the packs, since a short quote is fine to type alone.

For reference, TypeRacer organises by difficulty and language rather than
topic: one default English pool of ~11,900 texts plus per-language universes
and specials (accuracy, repeat, easytexts, anime). Their scale comes from user
submission with moderation, which is still the feature this does not have.
</content>
</entry>
<entry>
<title>Move the server to PostgreSQL, harden the lyrics proxy, add a hacking mode</title>
<updated>2025-12-07T18:38:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2025-12-07T18:38:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/typerpunk/commit/?id=5b1ea38522dbf6bf60db5a2270463de0c12d9de3'/>
<id>urn:sha1:5b1ea38522dbf6bf60db5a2270463de0c12d9de3</id>
<content type='text'>
PostgreSQL
- sqlx switched from the sqlite feature to postgres; the server now runs on
  Postgres 18 and the SQLite file is gone.
- 95 placeholders renumbered from ? to $N.
- REAL widened to DOUBLE PRECISION: Postgres REAL is float4 and will not
  decode into the f64 the code reads.
- flagged and is_bot are real BOOLEANs rather than 0/1 integers, with the
  decode side reading bool.
- The leaderboard's derived table gained the alias Postgres requires, its
  flag comparisons became boolean predicates, and INSERT OR IGNORE became
  ON CONFLICT DO NOTHING.
- u32 binds cast to i64; Postgres has no unsigned integer types.
- Integration tests run against a real database - Postgres has no in-memory
  mode - each in a throwaway schema, with search_path set per connection
  because it is session state and the pool opens more than one.
- Timestamps stay TEXT for now and LISTEN/NOTIFY is still unused; both are
  recorded in TODO-postgres.md rather than left implied.

Custom text and lyrics, checked rather than assumed
- Custom files never reach the server: they are read in the browser through
  the File API, so there is no upload, no path handling and no remote file
  inclusion to have. Verified by driving a hostile file - markup in the body
  and in the filename - all the way onto the typing screen: it renders as
  literal characters, no nodes are created, nothing executes, and the
  filename is escaped in the attribution too.
- That test found a real regression: picking Custom from the new mode picker
  selected it without ever starting it, so the mode was unstartable.
- /api/lyrics fixes its upstream host, so it cannot be pointed elsewhere, but
  it was an unbounded relay: now rate limited per IP, with length caps on
  artist and track and a ceiling on the response body it will read.

Hacking mode
- 22 single-line drills across recon, web, memory safety, exploit
  development, crypto, post-exploitation and defence, each syntax
  highlighted and each explaining what the line actually does.

All 19 modes verified to start, render and be typable.
</content>
</entry>
<entry>
<title>Fix content packs, seed the leaderboard, and add the missing site furniture</title>
<updated>2025-12-05T22:58:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2025-12-05T22:58:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/typerpunk/commit/?id=24f1eb6cc611f458c45f0ac4046efce51211d7d3'/>
<id>urn:sha1:24f1eb6cc611f458c45f0ac4046efce51211d7d3</id>
<content type='text'>
Naming
- "Typing Test" removed from the browser tab, the crate description and the
  READMEs. The scope outgrew it: solo practice, live races, code drills and
  adaptive weak-key training.

Content
- Movies was prose *about* film, not film quotes - the same mistake the
  programming pack had. Replaced with 28 attributed lines. New anime pack,
  28 lines across 24 series.
- This follows the model TypeRacer states outright ("type quotes from popular
  music, songs, anime, comic books and more"): short excerpts attributed to
  the work they came from. The scalable half of their approach is user
  submission with moderation, which is a feature this does not have yet.

Leaderboard
- An empty board tells a new player nobody is here. Bots now race the eight
  fixed-length leaderboard modes, seeded with a fortnight of backdated results
  on first run and one new result every 90 seconds after.
- They are ordinary users carrying is_bot, returned by the same query and
  labelled "bot" in the UI. Seeding a board is reasonable; passing synthetic
  scores off as human results is not, so the flag travels with the row.
- Seeding is checked per mode. A single result from the live ticker used to
  satisfy an "any bot results" guard and leave every other mode empty forever.

Stats
- The per-key accuracy data Practice mode is built on was computed, used to
  generate text, and never shown. The screen now ranks your weakest keys with
  the error rate and pause length behind each one.
- Added recent form against your lifetime average, best accuracy, and tests
  this week.

Multiplayer standings
- Now place, racer, WPM, accuracy and time, with column labels - the columns
  TypeRacer and 10FastFingers both show.

Site furniture
- Share (Web Share where available, clipboard otherwise - no third-party
  button, no tracking script), a GitHub link, and a real privacy page written
  from what the code actually stores rather than from a template.

Button hierarchy
- Everything was an outlined box of roughly equal weight, so a screen's one
  real action, a settings toggle and a filter chip looked alike. Three tiers
  now: primary (filled, one per screen), default (outlined), quiet (toggles
  and filters, bordered only when hovered or active).
</content>
</entry>
<entry>
<title>Rework the end screen figures, mode picker, corners and race view</title>
<updated>2025-09-13T19:11:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2025-09-13T19:11:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/typerpunk/commit/?id=0d3864bcebcdba1b1743367d0f84389fd53e37e1'/>
<id>urn:sha1:0d3864bcebcdba1b1743367d0f84389fd53e37e1</id>
<content type='text'>
End screen
- Every figure is now a dim label directly over its value, the two centred on
  each other, grouped by what they qualify: RAW and PB under WPM, ERR and
  CONSISTENCY under ACC, KEYSTROKES and CHARACTERS either side of TIME. The
  row is a grid so TIME sits on the graph's exact centre line rather than
  drifting with its neighbours' widths.
- Errors go back onto the wpm line. Their own y axis implied a magnitude a
  mistake does not have; what matters is when one happened.
- Graph hover reads "wpm ... raw ... time" - the figures first, the second
  they happened in as the qualifier.

Mode picker
- Opens from the Single Player button itself, and choosing a mode starts it:
  picking what to type and starting it are one action. The control has now
  been a chevron notched into that button, a caption between the two buttons,
  a pill above them and a chip row below them; as the button's own menu it
  needs no separate real estate at all.

Corners
- Settings and Store move to the bottom-left. The top-left is the wordmark's
  alone.
- The global racer count is gone from the home screen - it is not something
  you can act on there. The Friends control carries "N online" instead, which
  is.
- Presence: users gain a last_seen column, touched at most once a minute per
  active user on any authenticated request, and the friends list reports who
  has been seen inside a five-minute window.

Multiplayer race view
- The standings move to the middle of the screen, the space the end screen's
  graph occupies, and now include your own row rather than opponents only.
  Pinned to the top-left corner they put what you are racing against in your
  peripheral vision and left out the one bar you most need to see.

Programming mode
- Snippets carry an explanation of what the code does. Shown under the passage
  while you type in single player; in multiplayer that space belongs to the
  standings, so it waits for the end screen, where it appears either way.
</content>
</entry>
<entry>
<title>Add multiplayer bots, typing languages, and rework the UI layout</title>
<updated>2025-09-11T19:53:00+00:00</updated>
<author>
<name>srdusr</name>
<email>99972264+srdusr@users.noreply.github.com</email>
</author>
<published>2025-09-11T19:53:00+00:00</published>
<link rel='alternate' type='text/html' href='https://srdusr.com/git/typerpunk/commit/?id=a726d9f5fb56e1fd7983c5ac806d408ad78daa86'/>
<id>urn:sha1:a726d9f5fb56e1fd7983c5ac806d408ad78daa86</id>
<content type='text'>
Multiplayer
- Quick match: POST /api/multiplayer/quickmatch returns whichever room is
  still filling, or opens one. Players never see a room code; joining by
  code stays for racing specific people.
- Bots fill quick-match rooms after a short wait so a new game is never an
  empty lobby. They only ever join quick-match rooms, never a room opened
  by code. One or two per room, drawn from separate ~40 and ~80 WPM tiers so
  two bots are never near each other's pace, and they stall to correct
  mistakes rather than typing a clean straight line.
- Live player count via GET /api/multiplayer/online, shown on the
  Multiplayer control and under the main menu's Multiplayer button.
- Per-racer colours: you are the theme accent, opponents take distinct hues
  that stay the same from lobby to race.
- The countdown no longer holds the room lock for its full three seconds,
  which is what reset clients mid-countdown.

Typing languages
- 16 languages for the generated-word modes, each with its own
  high-frequency vocabulary rather than a translation of the English list.
- Picker in the top-right rail; non-English uses its own list at every
  difficulty tier instead of falling back to English words.

Fix UTF-8 accuracy in the game core
- update_game_state mixed byte and character counts: total_characters_typed
  accumulated byte-length deltas while total_correct_characters compared a
  char index against that byte count. Equal on ASCII, so it went unnoticed;
  a correctly typed Spanish passage scored 6%. The old byte slicing would
  also have panicked if an index landed inside a multi-byte character.
  Rewritten char-based, with regression tests.

Programming mode
- Replaced prose about programming with real code: 26 syntax-highlighted
  snippets across JavaScript, Python, Rust, C/Go/Java and shell. Single-line
  by necessity, since the typing input is a single-line field.

Layout and readability
- One icon rail arrangement on every screen: Settings/Store under the
  wordmark, Language/Theme/Friends/Account top-right, Stats/Leaderboard/
  Multiplayer bottom-right.
- Main menu: mode picker moved out of the Single Player button, which it was
  notching a divider through and pushing the label off-centre.
- Escape returns to the menu, closing any open popover first, and confirms
  before abandoning a live race.
- Split --text-color and --sub-color per theme; they shared one value that
  measured 3.65:1 against the background, below the 4.5:1 body-text floor.
- Semantic colours used in exactly one place each: gold for a personal best,
  amber for the race countdown and the mobile-result badge.
- Passage now sits in the same place on the typing and end screens, and its
  column is a whole number of characters wide so wrapping cannot leave a
  permanent gap on the right.
- End screen: keystrokes and a correct/wrong/extra/missed split, attribution
  carried over from the typing screen, and a graph with a separate error
  axis, axis titles including seconds, and smoothed lines.
</content>
</entry>
</feed>
