srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/scripts
AgeCommit message (Collapse)AuthorFilesLines
2026-03-13Ship the store catalogue with the clientsrdusr1-0/+53
The store read its catalogue from the server and rendered nothing without one: a heading, a sign-in prompt and an empty page, which reads as a fault rather than as a shop that needs an account. It now falls back to a copy that ships with the client, the same arrangement the text packs already use: bundled here, served from the database, and the served copy wins. With no server the store shows all 26 cosmetics, 4 bundles and 6 merchandise items at their real prices. Nothing pretends to work. The buy controls become a "Soon" label rather than a button, because offline there is nothing to buy with and nowhere to sign in to: sending someone to the account screen would be sending them to another screen that needs the server they have not got. A line at the top says the shop is not open yet. scripts/export_store.js regenerates the file. Run it after changing prices or adding items. It shells out to psql so it needs no dependencies, matching the other scripts here. Verified both ways. With no backend: 26 items, 4 bundles, 6 merch, 36 Soon labels, no live buy controls, no page errors. With the backend running: the same catalogue, 37 live buy controls, no Soon labels, no offline notice. 3 browser tests pass.
2025-12-15Harden for production: dependencies, headers, admin roles, docssrdusr1-0/+61
Dependencies - The server build carried 37 known advisories, including RUSTSEC-2024-0363 in sqlx 0.7, which is the database layer. sqlx moved to 0.8 with default-features off, which also drops the MySQL and SQLite drivers and with them rsa and RUSTSEC-2023-0071. reqwest moved to 0.12, which brings hyper 1.x and was the sole source of every remaining advisory: h2 0.3, rustls-webpki 0.101, rustls-pemfile 1.0 and idna 0.3. - The server build now reports no known vulnerabilities against OSV. cargo audit itself would not compile, so the check queries OSV with the crate versions cargo tree reports for the server binary. - Cargo.lock is committed. This workspace produces binaries, so the lockfile is what makes a deployed build reproducible and the audit above meaningful. Headers - The application sent no security headers at all. The static server now sends a Content-Security-Policy, nosniff, frame options, a referrer policy and a permissions policy; the API sends a policy of its own, since it serves JSON and should load and frame nothing. - The one inline script in index.html moved to a file so script-src needs no unsafe-inline. WebAssembly needs wasm-unsafe-eval, without which nothing types at all, so that is present and explained. - Five style attributes moved to the CSSOM rather than adding unsafe-inline for styles. A style attribute in markup is refused by the policy; the same property set through element.style is not. Production configuration - With TYPERPUNK_ENV=production the server refuses to start if COOKIE_SECURE is off, if DATABASE_URL is still the development default, or if FRONTEND_ORIGIN is http on a non-local host. These were warnings, and a warning in a log nobody reads is not a safeguard. Administration - Moderators were appointed with psql. There is now an admin role, bootstrapped from TYPERPUNK_ADMIN_USERNAME at startup, and a UI to appoint and remove moderators. An administrator's own role cannot be changed through the API, so a mistake cannot lock everyone out of moderation. Corpus - scripts/export_approved.js writes approved submissions back into data/packs/community-*.json. Approved passages are served from the database and merged at startup, so without this the repository dataset and the live corpus drift apart, and a fresh checkout or the TUI sees only what shipped. Documentation - README rewritten for the repository: what it does, how to run it, the pack format, the server variables, deployment, and what the security posture actually is. Plain English, no em dashes, no emoji. Checked and found already correct: every private endpoint refuses anonymous callers, session cookies are HttpOnly and SameSite=Lax, CORS names a single origin, internal errors are logged rather than returned, and every query is parameterised.
2025-12-07Rebuild the generic packs, add shell and sysadmin, fix short race passagessrdusr1-0/+0
The packs were not proper. An audit found 86 of 253 items (33%) carrying an attribution that just restated the category - prose *about* a topic with an invented source, which is the same fault the movies pack had. Six of thirteen packs were mostly that: technology had 15 items and one distinct attribution. - science, technology, history, nature and business are now sourced quotes with real attributions: Feynman, Curie, Hopper, Dijkstra, Lincoln, Carson, Drucker, Goodhart. 82 items, all attributed to a person or a work. - general is original factual prose, so it now carries no attribution at all rather than claiming "General knowledge" as a source. merge_packs no longer invents one from the pack's filename. - Four explanatory passages in philosophy lost their "Philosophy" attribution for the same reason. - One duplicated passage removed. Generic attributions: 86/253 before, 0/349 now. New technical packs - shell: 24 awk, sed and pipeline drills, each explaining what the line does - field splitting, associative arrays, !seen[$0]++, process substitution, xargs -0, strict mode. - sysadmin: 24 operational one-liners across systemd, disk, processes, network, permissions, SSH, backup and containers. - programming grew to 37 and hacking to 30, with git bisect, window functions, EXPLAIN ANALYZE, certificate transparency and capability audits. - All 115 technical drills carry an explanation. Race passage length - Multiplayer drew from the same pool as single player, so a race could land on a 22-character quote and be over before anyone had their hands in position. Races now require 120 characters; the filter is applied when the pool is loaded, not to the packs, since a short quote is fine to type alone. For reference, TypeRacer organises by difficulty and language rather than topic: one default English pool of ~11,900 texts plus per-language universes and specials (accuracy, repeat, easytexts, anime). Their scale comes from user submission with moderation, which is still the feature this does not have.
2025-09-13Rework the end screen figures, mode picker, corners and race viewsrdusr1-0/+0
End screen - Every figure is now a dim label directly over its value, the two centred on each other, grouped by what they qualify: RAW and PB under WPM, ERR and CONSISTENCY under ACC, KEYSTROKES and CHARACTERS either side of TIME. The row is a grid so TIME sits on the graph's exact centre line rather than drifting with its neighbours' widths. - Errors go back onto the wpm line. Their own y axis implied a magnitude a mistake does not have; what matters is when one happened. - Graph hover reads "wpm ... raw ... time" - the figures first, the second they happened in as the qualifier. Mode picker - Opens from the Single Player button itself, and choosing a mode starts it: picking what to type and starting it are one action. The control has now been a chevron notched into that button, a caption between the two buttons, a pill above them and a chip row below them; as the button's own menu it needs no separate real estate at all. Corners - Settings and Store move to the bottom-left. The top-left is the wordmark's alone. - The global racer count is gone from the home screen - it is not something you can act on there. The Friends control carries "N online" instead, which is. - Presence: users gain a last_seen column, touched at most once a minute per active user on any authenticated request, and the friends list reports who has been seen inside a five-minute window. Multiplayer race view - The standings move to the middle of the screen, the space the end screen's graph occupies, and now include your own row rather than opponents only. Pinned to the top-left corner they put what you are racing against in your peripheral vision and left out the one bar you most need to see. Programming mode - Snippets carry an explanation of what the code does. Shown under the passage while you type in single player; in multiplayer that space belongs to the standings, so it waits for the end screen, where it appears either way.
2025-09-11Add multiplayer bots, typing languages, and rework the UI layoutsrdusr2-0/+148
Multiplayer - Quick match: POST /api/multiplayer/quickmatch returns whichever room is still filling, or opens one. Players never see a room code; joining by code stays for racing specific people. - Bots fill quick-match rooms after a short wait so a new game is never an empty lobby. They only ever join quick-match rooms, never a room opened by code. One or two per room, drawn from separate ~40 and ~80 WPM tiers so two bots are never near each other's pace, and they stall to correct mistakes rather than typing a clean straight line. - Live player count via GET /api/multiplayer/online, shown on the Multiplayer control and under the main menu's Multiplayer button. - Per-racer colours: you are the theme accent, opponents take distinct hues that stay the same from lobby to race. - The countdown no longer holds the room lock for its full three seconds, which is what reset clients mid-countdown. Typing languages - 16 languages for the generated-word modes, each with its own high-frequency vocabulary rather than a translation of the English list. - Picker in the top-right rail; non-English uses its own list at every difficulty tier instead of falling back to English words. Fix UTF-8 accuracy in the game core - update_game_state mixed byte and character counts: total_characters_typed accumulated byte-length deltas while total_correct_characters compared a char index against that byte count. Equal on ASCII, so it went unnoticed; a correctly typed Spanish passage scored 6%. The old byte slicing would also have panicked if an index landed inside a multi-byte character. Rewritten char-based, with regression tests. Programming mode - Replaced prose about programming with real code: 26 syntax-highlighted snippets across JavaScript, Python, Rust, C/Go/Java and shell. Single-line by necessity, since the typing input is a single-line field. Layout and readability - One icon rail arrangement on every screen: Settings/Store under the wordmark, Language/Theme/Friends/Account top-right, Stats/Leaderboard/ Multiplayer bottom-right. - Main menu: mode picker moved out of the Single Player button, which it was notching a divider through and pushing the label off-centre. - Escape returns to the menu, closing any open popover first, and confirms before abandoning a live race. - Split --text-color and --sub-color per theme; they shared one value that measured 3.65:1 against the background, below the 4.5:1 body-text floor. - Semantic colours used in exactly one place each: gold for a personal best, amber for the race countdown and the mobile-result badge. - Passage now sits in the same place on the typing and end screens, and its column is a whole number of characters wide so wrapping cannot leave a permanent gap on the right. - End screen: keystrokes and a correct/wrong/extra/missed split, attribution carried over from the typing screen, and a graph with a separate error axis, axis titles including seconds, and smoothed lines.