aboutsummaryrefslogtreecommitdiffstats
path: root/packages/meshbay-hub/src/meshbay_hub/api
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-08-18 17:46:54 +0200
committerChristophe Besson <cbesson@gmail.com>2026-08-18 17:46:54 +0200
commitcd2e89f5f5cccdb116db4fcb82d00b6325972782 (patch)
tree17be58fb00b49736f818a2f8063464960b5b1101 /packages/meshbay-hub/src/meshbay_hub/api
parent2ef5498ab1509a93691b87b4cc5d9b52bb3f52dc (diff)
downloadmeshbay-cd2e89f5f5cccdb116db4fcb82d00b6325972782.tar.gz
fix: the chat tab no longer scrolls, and a group is listed or invite-only
**The chat tab was 8px too tall, at every window size.** The panel is sized from JS to `viewport - top - 16`, which puts its bottom 16px above the fold — but it sits inside `.main`, which adds 24px of padding below it. Eight pixels of document past the window, whatever the window. Measured at 700, 900 and 1200: `scrollHeight` 708, 908, 1208. This is the second one of these — the sign-in card was `.page-center` and `.layout` each reserving `100vh - 52px` — so it is now measured in the suite rather than reasoned about. `tests/harness/scroll_probe.py` renders the real markup against the real stylesheet and **runs the real `fit()` lifted out of `app.js`**: a copy of the formula in a test would go on passing after the original changed, which is exactly the bug being guarded. The fix does not encode 24 anywhere. The first pass runs as before, then the leftover is measured and taken off, so anything added below the panel later is absorbed the same way. Now `scrollHeight == innerHeight` at all three heights, nothing below the fold, and the panel still fills the room it has — that last one has its own test, because shrinking the chat to 240px would satisfy every other assertion here and be useless. The Settings tab was measured too and is **not** a bug: it fits at 1200px and overflows only when its content is genuinely taller than the window. **Group creation asked one question twice.** Visibility and admission were separate selectors that could only ever be set together — picking Public reached over and set the policy — and two of the four combinations are meaningless. The API already refused public+invite with a 422, so the form could build a request that could not succeed. Private+open was accepted and should not have been: a group anyone may join that nobody can find is a listing with the listing removed, since joining goes through the node and there is no link to pass around. So: one selector, "who can join", and the request derives the rest. The API now refuses the other impossible pair as well, with a message that says which way to resolve it. Six locale strings the visibility box owned are deleted rather than left unread in ten files, and the two surviving descriptions now say what each choice means for who can *find* the group — with the word "public" gone from the page, nothing else would have said it, and someone would publish a group without meaning to. 865 tests pass. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/api')
-rw-r--r--packages/meshbay-hub/src/meshbay_hub/api/groups.py33
1 files changed, 23 insertions, 10 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/api/groups.py b/packages/meshbay-hub/src/meshbay_hub/api/groups.py
index 8283276..6819ff6 100644
--- a/packages/meshbay-hub/src/meshbay_hub/api/groups.py
+++ b/packages/meshbay-hub/src/meshbay_hub/api/groups.py
@@ -317,17 +317,30 @@ async def create_group(
current_user: User = Depends(require_user_scope),
db: AsyncSession = Depends(get_db),
):
+ # Being listed and being open are one question, not two.
+ #
+ # A public group that admits nobody is a contradiction: it is in the
+ # directory, so people find it and then discover they cannot get in.
+ # Admission by request was considered and dropped — between strangers the
+ # only channel is the hub, so the one-time code would travel through the
+ # very party it exists to keep out, and would protect nothing.
+ #
+ # The other way round was accepted until now and should not have been: a
+ # group anyone may join, that nobody can find, is a listing with the listing
+ # removed. Nothing could reach it but a link, and there is no link — joining
+ # goes through the node. The create form no longer offers either
+ # combination; refusing them here is what makes that true of the API too.
+ if body.visibility == "public" and body.join_policy != "open":
+ raise HTTPException(
+ status_code=422,
+ detail="A public group is open to join. Make it private if you "
+ "want to choose who comes in.")
+ if body.visibility != "public" and body.join_policy == "open":
+ raise HTTPException(
+ status_code=422,
+ detail="A private group is invite-only. Make it public if you want "
+ "anyone to be able to join.")
if body.visibility == "public":
- # A public group that admits nobody is a contradiction: it is listed in
- # the directory, so people find it and then discover they cannot get in.
- # Admission by request was considered and dropped — between strangers the
- # only channel is the hub, so the one-time code would travel through the
- # very party it exists to keep out, and would protect nothing.
- if body.join_policy != "open":
- raise HTTPException(
- status_code=422,
- detail="A public group is open to join. Make it private if you "
- "want to choose who comes in.")
await _check_public_group_quota(db, current_user)
desc = (body.description or "")[:512] if body.description else None