fix(blur): the heid code-review and bug-hunt panels on r2b merge 1, folded

Both panels ran 4/4 on 5ded5ff. They converged on the board and doc-page
gaps independently.

- A board holding files lost both blur controls (they sat inside the
  board suppression meant for the one-click wipe), while its items'
  "◉ booth" labels pointed at them. Only the wipe is board-suppressed now.
- A blurred doc's own full page rendered clear. Its body is blurred there
  too, with its own reveal and a Reveal all to put the blur back.
- set_booth_blurred followed a planted .blurbooth symlink (`touch`), and
  the new control made that a click away. Anything at the name already
  reads as fogged; otherwise it is created O_CREAT|O_EXCL|O_NOFOLLOW.
- The fog landing echoed `back` unchecked into the 303. It is now built
  from the review ring, as the mark routes do.
- The fog form is its own region, so an in-place save refreshes its
  label. Reveal all stays outside every region: its state lives in the
  tab.
- The review's Space-to-advance no longer swallows Space on a focused
  button or link.
- Top-bar controls stay on one line at phone width.
- Tests tightened:
  - method="post" on the fog forms;
  - exact blur values;
  - a storage READ that throws;
  - an item's own reveal carried across a swap;
  - reveal gated where it can act.

r2b.toml: 26/26 proved. 774 passed.
This commit is contained in:
vh
2026-09-23 18:41:32 -07:00
parent 5ded5ffe55
commit 75623c7dbc
9 changed files with 405 additions and 30 deletions
+80 -1
View File
@@ -861,8 +861,10 @@ def test_the_booth_blur_toggle_works_without_js_and_lands_back_on_the_review(tmp
c = _client(tmp_path)
page = c.get("/b/g/").text
form = re.search(r'<form[^>]*action="/b/g/blurbooth".*?</form>', page, re.S).group(0)
assert 'method="post"' in form, "a GET form would not change anything with scripts off"
assert 'name="on" value="1"' in form and "blur booth" in form
assert all(form not in r for r in _regions(page)), "a swap must never replace it"
# a REGION: its label is server state, so an in-place save refreshes it
assert form in _region(page, "blur-booth")
assert "badge-blur" not in re.search(r'data-booth="g".*?</article>', c.get("/").text, re.S).group(0)
r = c.post("/b/g/blurbooth", data={"on": "1"}, follow_redirects=False)
@@ -876,6 +878,7 @@ def test_the_booth_blur_toggle_works_without_js_and_lands_back_on_the_review(tmp
view = c.get("/b/g/view?f=b.png").text
vbar = re.search(r'<div class="vbar">.*?</div>\s*\n', view, re.S).group(0)
vform = re.search(r'<form[^>]*action="/b/g/blurbooth".*?</form>', vbar, re.S).group(0)
assert 'method="post"' in vform
assert 'name="back" value="b.png"' in vform and 'name="on" value="0"' in vform
r = c.post("/b/g/blurbooth", data={"on": "0", "back": "b.png"}, follow_redirects=False)
assert r.headers["location"] == "/b/g/view?f=b.png" and not (b / ".blurbooth").exists()
@@ -918,3 +921,79 @@ def test_under_a_fogged_booth_each_items_blur_control_tells_the_truth(tmp_path):
assert re.search(r'action="/b/g/blur".*?name="on" value="0".*?◉ blurred', own, re.S)
assert 'action="/b/g/blur"' not in booth
assert "◉ booth" in booth
def test_a_board_with_files_gets_the_blur_controls_its_labels_point_at(tmp_path):
"""heid code-review (4/4): both booth-wide controls sat inside the board
suppression meant for the one-click wipe, so a links board holding a fogged
picture showed "◉ booth — un-blur the booth in the header" with no such
control in the header. Only the wipe is board-suppressed."""
b = _booth(tmp_path, "links", {"links.md": b"- [x](https://example.test/)\n", "a.png": PNG})
(b / ".blurbooth").write_bytes(b"")
page = _client(tmp_path).get("/b/links/").text
assert re.search(r'<form[^>]*action="/b/links/blurbooth"', page)
assert re.search(r"<button[^>]*data-reveal-all", page)
def test_reveal_all_renders_where_it_can_act(tmp_path):
"""heid code-review (3/4): the header offers Reveal all when ANY item is
blurred; the review only when an item of the review RING is — a blurred doc
is not on the review page, so a control there would act on nothing."""
from booth.app import set_blurred
b = _booth(tmp_path, "g", {"a.png": PNG, "n.md": b"# n"})
set_blurred(b, "n.md", True)
c = _client(tmp_path)
assert re.search(r"<button[^>]*data-reveal-all", c.get("/b/g/").text)
assert not re.search(r"<button[^>]*data-reveal-all", c.get("/b/g/view?f=a.png").text)
def test_a_blurred_docs_own_page_is_blurred_too(tmp_path):
"""heid code-review (hulda): the full-page doc view never read `blurred`,
so a blurred doc rendered clear at the size where it is most readable.
Its body is blurred there too, with its own JS-only reveal."""
from booth.app import set_blurred
b = _booth(tmp_path, "g", {"n.md": b"# secret", "o.md": b"# open"})
set_blurred(b, "n.md", True)
c = _client(tmp_path)
blurred, clear = c.get("/b/g/view?f=n.md").text, c.get("/b/g/view?f=o.md").text
assert re.search(r'class="docbody is-blurred"', blurred)
assert re.search(r'<button[^>]*id="docreveal"[^>]*hidden', blurred)
assert 'class="docbody"' in clear and not re.search(r'<button[^>]*id="docreveal"', clear)
def test_fogging_never_writes_through_a_planted_marker_link(tmp_path):
"""heid bug-hunt (kimi, hulda): `marker.touch()` followed a planted
`.blurbooth` symlink — a click of the new browser control rewrote an
outside file's mtime, or CREATED a dangling target. The same class
`record_view` was hardened against. A link already there reads as fogged
(is_booth_blurred counts it), so fogging has nothing to write."""
import os
outside = tmp_path / "outside.txt"
outside.write_text("x")
os.utime(outside, (1_000_000, 1_000_000))
b = _booth(tmp_path, "g", {"a.png": PNG})
(b / ".blurbooth").symlink_to(outside)
h = _booth(tmp_path, "h", {"a.png": PNG})
(h / ".blurbooth").symlink_to(tmp_path / "created-by-a-click")
c = _client(tmp_path)
assert c.post("/b/g/blurbooth", data={"on": "1"}, follow_redirects=False).status_code == 303
assert c.post("/b/h/blurbooth", data={"on": "1"}, follow_redirects=False).status_code == 303
assert outside.stat().st_mtime == 1_000_000
assert not (tmp_path / "created-by-a-click").exists()
c.post("/b/g/blurbooth", data={"on": "0"}, follow_redirects=False)
assert not (b / ".blurbooth").is_symlink() and outside.exists() # unlinked, target untouched
def test_the_fog_landing_is_built_from_the_ring_never_echoed(tmp_path):
"""heid bug-hunt (kimi, regin, groa): `back` went into the 303 unchecked, so
a stale or foreign value landed on a 404. Like the mark routes' back=view:
the review only for an item of the review ring, else the booth page."""
_booth(tmp_path, "g", {"a.png": PNG, "n.md": b"# n"})
c = _client(tmp_path)
loc = lambda back: c.post("/b/g/blurbooth", data={"on": "1", "back": back},
follow_redirects=False).headers["location"]
assert loc("a.png") == "/b/g/view?f=a.png"
assert loc("gone.png") == "/b/g/"
assert loc("n.md") == "/b/g/"
assert loc("") == "/b/g/"