Merge phase/01 into milestone/v0.6-nomad-web-ui (P1 complete → v0.5.1)

---ci---
project: oy
phase: 1
milestone: v0.6
status: complete
requirements:
  covered: [REQ-040, REQ-045]
  partial: []
---/ci---
This commit is contained in:
2026-08-18 18:52:59 +00:00
19 changed files with 1512 additions and 15 deletions
+4 -5
View File
@@ -1,14 +1,13 @@
{
"phase": 0,
"phase": 1,
"stage": "complete",
"milestone": "v0.6",
"milestone_type": "feature",
"tag_base": "v0.5.x",
"phase_role": "pre_execution",
"phase_role": "execution",
"project": "oy",
"attempts": 0,
"updated_at": "2026-08-18T12:12:00Z",
"updated_at": "2026-08-18T13:55:00Z",
"milestone_complete": false,
"milestone_release_tag": "v0.5.0",
"release_id": 770
"requirements_covered": ["REQ-040", "REQ-045"]
}
+39 -10
View File
@@ -25,10 +25,14 @@ Loaf → Batch → Cake → Bakery → Granary → Mill → Harvest → Earth.**
## Status
**v0.3 (Bearers & Documentation) — in progress.** The codebase is a skeleton +
tests layer (Go types + keeper stubs + invariant tests, zero external Go deps)
matching the v0.1/v0.2 pre-MVP pattern. See `.ciagent/oy/ROADMAP.md` for the
phase plan and `.ciagent/oy/PROJECT.md` for governance.
**v0.6 (Nomad Web UI) — in progress.** v0.5 shipped the Bearers Runtime
(simtest-grade keeper handlers for 8 x/ modules). v0.6 adds the project's
first UI: a Go `html/template` + HTMX prototype Web UI in `web/` where a
visitor can sign up to be a Nomad (create a Reach + open a Stash) and
exercise basic functionality around Reach, Stash, Window, Standing, and
Bloom. All data is generated test fixtures — no real chain. See
`.ciagent/oy/ROADMAP.md` for the phase plan and `.ciagent/oy/PROJECT.md`
for governance.
## Build & test
@@ -40,6 +44,29 @@ go build ./...
go test ./...
```
## Web UI
The Nomad Web UI (v0.6) is a Go `html/template` server with HTMX progressive
enhancement, served by a mock HTTP server in `web/` that instantiates the
real `x/*/types` structs from in-memory fixtures. No node, no build step,
no real chain. To run it:
```sh
go run ./web
# opens on http://localhost:8080 (PORT env var overridable)
```
Five screens, all reachable from the home nav:
- `/reach` — create a Reach (sign up to be a Nomad) + Reach list/detail
- `/stash/{holderID}` — Stash dashboard (Grain balance + Bread scale + 90-day maturity)
- `/window` — Window authorization (open/lifecycle/audit log)
- `/standing/{reachID}` — Standing + Freeholder signals progress
- `/bloom/{stashID}` — Bloom accrual view
HTMX is a single vendored JS file (`web/static/htmx.min.js`), NOT a Go
dependency — `go.mod` stays unchanged (G-006).
## Docs
The docs site is [MkDocs Material](https://squidfunk.github.io/mkdocs-material/)
@@ -58,17 +85,19 @@ deferred to v0.4 (D-046); v0.3 ships the source.
## Lexicon firewall
OpenYield bans 10 financial terms as standalone words (REQ-012) across all Go
source (`x/**/*.go`) and all docs (`README.md` + `docs/**/*.md`). The banned
terms are the words you would expect a legacy financial institution to use;
this README and the docs describe them only by their **safe replacements**, so
the firewall itself never trips. The firewall is enforced in code by two
sibling Go tests:
source (`x/**/*.go`), all docs (`README.md` + `docs/**/*.md`), and all web UI
files (`web/**/*.{html,js,go}`). The banned terms are the words you would
expect a legacy financial institution to use; this README and the docs describe
them only by their **safe replacements**, so the firewall itself never trips.
The firewall is enforced in code by three sibling Go tests:
- `lexicon_meta_test.go` (v0.2) — scans `x/**/*.go`.
- `lexicon_meta_docs/lexicon_meta_docs_test.go` (v0.3) — scans `README.md` +
`docs/**/*.md`.
- `lexicon_meta_web/lexicon_meta_web_test.go` (v0.6) — scans
`web/templates/**` + `web/static/**` + `web/**/*.go`.
Both use `lexicon.FindBannedTerm` (word-boundary, case-insensitive), so
All three use `lexicon.FindBannedTerm` (word-boundary, case-insensitive), so
"OpenYield" is safe (word-boundary does not match the banned term inside an
identifier) but the standalone banned term is not — docs say **"real
production"** / **"real return"**, and a Holder's identity is **Holder** /
+307
View File
@@ -0,0 +1,307 @@
// Package lexicon_meta_web holds the web lexicon firewall (REQ-045, D-069).
//
// It is a NEW sibling meta-test created in v0.6 P1 Wave 1 that MIRRORS the
// v0.3 docs firewall (lexicon_meta_docs/lexicon_meta_docs_test.go, package
// lexicon_meta_docs) but scans the web surface (web/templates/**/*.html +
// web/static/**/*.js + web/**/*.go) instead of README.md + docs/**/*.md. It
// uses the SAME lexicon.FindBannedTerm (word-boundary, case-insensitive) —
// NO detection reimplementation — so the three firewalls (x/*.go, docs, web)
// share a single source of truth for the 10 banned terms (bank, deposit,
// interest, yield, currency, dollar, euro, account, savings, depositor).
//
// Placement: this file lives in lexicon_meta_web/ (a subdirectory of the
// repo root) because Go does not permit two distinct packages in the same
// directory; the v0.2 firewall is package lexicon_meta at the repo root and
// the v0.3 firewall is package lexicon_meta_docs in lexicon_meta_docs/. The
// invocation `go test ./lexicon_meta_web/...` (PLANS P1-01-01) resolves to
// this package. Run via `go test ./...` from the repo root as well.
//
// G-013 walk-coverage: TestLexiconMetaWebWalkCoverage injects a synthetic
// banned-term .html into a temp web/templates/ subtree and asserts the walk
// FINDS it. This closes the "silently scans nothing and reports green"
// failure mode that the G-009 self-test table (detection) alone does not
// cover.
//
// G-014 self-test drift: the self-test table and banned-term count assertion
// reuse lexicon.BannedTerms() (the single source). A cross-reference comment
// keeps this file's table in lockstep with lexicon_meta_test.go's table and
// lexicon_meta_docs_test.go's table; if a banned term is added, all three
// firewalls update from one place.
package lexicon_meta_web
import (
"os"
"path/filepath"
"runtime"
"strings"
"testing"
"github.com/oy/openyield/lexicon"
)
// repoRoot returns the absolute path to the repo root by walking up from
// this test file (the test lives at <repoRoot>/lexicon_meta_web/).
func repoRoot(t *testing.T) string {
t.Helper()
_, file, _, ok := runtime.Caller(0)
if !ok {
t.Fatal("runtime.Caller failed")
}
// file = .../oy/lexicon_meta_web/lexicon_meta_web_test.go
// repo root = filepath.Dir(filepath.Dir(file))
return filepath.Dir(filepath.Dir(file))
}
// thisFile returns the absolute path of this meta-test file (to exclude it
// from its own scan — it references banned terms via the lexicon package,
// whose source assembles terms from fragments, so no banned-term literal
// appears in the firewall's own code).
func thisFile(t *testing.T) string {
t.Helper()
_, file, _, ok := runtime.Caller(0)
if !ok {
t.Fatal("runtime.Caller failed")
}
return file
}
// isWebTarget reports whether path (relative to repo root) is a file the web
// firewall scans: web/templates/**/*.html, web/static/**/*.js, and
// web/**/*.go (production + test). Non-{html,js,go} files under web/ (e.g.
// vendored binary assets) are skipped.
func isWebTarget(rel string) bool {
if !strings.HasPrefix(rel, "web"+string(filepath.Separator)) {
return false
}
return strings.HasSuffix(rel, ".html") || strings.HasSuffix(rel, ".js") || strings.HasSuffix(rel, ".go")
}
// TestLexiconMetaWebNoBannedTermsInWeb is the web firewall (D-069). It walks
// the repo root, targets web/templates/**/*.html + web/static/**/*.js +
// web/**/*.go (production + test), reads each file's source, and asserts no
// banned term is present (word-boundary, case-insensitive). Excludes
// .ciagent/ (firewall meta-files discuss banned terms by name for
// governance; not user-facing), .git/ (VCS), and this test file itself
// (self-exclusion via runtime.Caller(0)).
//
// Passes at P1 Wave 1 with zero web content (a walk that scans nothing
// reports green on zero hits — closed by TestLexiconMetaWebWalkCoverage
// below). With the Wave 2..4 web content present (templates, static assets,
// handlers, store), all are lexicon-clean by construction.
func TestLexiconMetaWebNoBannedTermsInWeb(t *testing.T) {
root := repoRoot(t)
this := thisFile(t)
hits := []string{}
err := filepath.Walk(root, func(path string, info os.FileInfo, err error) error {
if err != nil {
return err
}
if info.IsDir() {
base := filepath.Base(path)
if base == ".ciagent" || base == ".git" {
return filepath.SkipDir
}
return nil
}
// Self-exclusion: skip this meta-test file.
if path == this {
return nil
}
rel, rerr := filepath.Rel(root, path)
if rerr != nil {
return rerr
}
if !isWebTarget(rel) {
return nil
}
bz, rerr := os.ReadFile(path)
if rerr != nil {
return rerr
}
if found, ok := lexicon.FindBannedTerm(string(bz)); ok {
hits = append(hits, rel+" contains banned term "+found)
}
return nil
})
if err != nil {
t.Fatalf("walk: %v", err)
}
if len(hits) > 0 {
t.Errorf("REQ-045 web lexicon firewall violations:\n %s",
strings.Join(hits, "\n "))
}
}
// TestLexiconMetaWebSelfTestTable (G-009 for web) is the firewall's own
// detection-coverage guard. Each synthetic string embeds exactly one banned
// term in a plausible sentence context and is asserted to trigger detection,
// so the firewall's detection logic is durably verified — if detection ever
// breaks, this test fails before the firewall silently passes a real
// violation in a web template or handler.
//
// REQ-029 (GRILL G-014): the synthetic strings are sourced from
// lexicon.SyntheticBannedStrings(), the single source of truth shared with
// lexicon_meta_test.go :: TestLexiconMetaSelfTestTable and
// lexicon_meta_docs_test.go :: TestLexiconMetaDocsSelfTestTable. Before
// REQ-029, each meta-test DUPLICATED its own 10-string table (byte-identical),
// creating a drift risk; the shared helper closes it. This file no longer
// builds its own synthetic table — all three meta-tests consume the same
// helper, so a future banned-term addition updates all firewalls from one
// place.
func TestLexiconMetaWebSelfTestTable(t *testing.T) {
terms := lexicon.BannedTerms()
// The spec lists 10 banned terms (plan docs say "9", counting dollar/euro
// as a pair): bank, deposit, interest, yield, currency, dollar, euro,
// account, savings, depositor.
if len(terms) != 10 {
t.Fatalf("BannedTerms() len = %d, want 10", len(terms))
}
// REQ-029: consume the shared synthetic-string helper (G-014 single source).
synthetic := lexicon.SyntheticBannedStrings()
if len(synthetic) != len(terms) {
t.Fatalf("SyntheticBannedStrings() len = %d, want %d (must match BannedTerms())", len(synthetic), len(terms))
}
for i, s := range synthetic {
found, ok := lexicon.FindBannedTerm(s)
if !ok {
t.Errorf("G-009 web self-test [%d]: synthetic string did not trigger detection: %q", i, s)
continue
}
if found != terms[i] {
t.Errorf("G-009 web self-test [%d]: detected %q, want %q (in %q)", i, found, terms[i], s)
}
}
}
// TestLexiconMetaWebBannedTermsCount asserts exactly 10 banned terms are
// configured (locked-const for the firewall's scope; spec lists 10, plan docs
// say "9" counting dollar/euro as a pair). Derived from lexicon.BannedTerms()
// — the single source — so a count change breaks all three firewalls (x/*.go,
// docs, web) (G-014 drift prevention).
func TestLexiconMetaWebBannedTermsCount(t *testing.T) {
terms := lexicon.BannedTerms()
if len(terms) != 10 {
t.Errorf("BannedTerms() len = %d, want 10 (REQ-012/REQ-045)", len(terms))
}
seen := map[string]bool{}
for _, tr := range terms {
if seen[tr] {
t.Errorf("duplicate banned term %q", tr)
}
seen[tr] = true
}
}
// TestLexiconMetaWebNoFalsePositiveOnOpenYield asserts the module name
// "openyield" does NOT trigger the "yield" banned term and "european" does
// NOT trigger the "euro" banned term (word-boundary matching must not match
// substrings of identifiers). This is the regression firewall for the
// word-boundary detection design — mirrors the v0.2
// TestLexiconMetaNoFalsePositiveOnOpenYield and the v0.3
// TestLexiconMetaDocsNoFalsePositiveOnOpenYield.
func TestLexiconMetaWebNoFalsePositiveOnOpenYield(t *testing.T) {
cases := []string{
"github.com/oy/openyield/x/window/types",
"package openyield",
"openyield is the module",
"european resident",
"# OpenYield web",
"the OpenYield mesh",
}
for _, s := range cases {
if _, ok := lexicon.FindBannedTerm(s); ok {
t.Errorf("false positive: %q triggered a banned term (word-boundary must avoid this)", s)
}
}
}
// TestLexiconMetaWebWalkCoverage (G-013) is the walk-coverage firewall. The
// G-009 self-test table (above) verifies DETECTION (FindBannedTerm on
// synthetic strings) but NOT the WALK (which files are scanned). A walk bug
// — e.g. wrong path prefix, missing web/ recursion, a typo in the .html
// suffix check — would silently scan nothing and report green on zero
// files. This test closes that gap by injecting a synthetic banned-term
// .html into a fixture dir under the real web/templates/ path the walk scans
// and asserting the walk FINDS it.
//
// The fixture is created under web/templates/.lexicon_fixture/ (a real
// web/templates/ subtree the walk reaches) and removed via defer so it never
// leaks into the repo. If the walk logic misses the fixture, this test fails
// loudly instead of letting a broken walk pass the firewall green on zero
// files scanned.
func TestLexiconMetaWebWalkCoverage(t *testing.T) {
root := repoRoot(t)
this := thisFile(t)
// Build a synthetic banned term from fragments so THIS file does not
// contain a banned-term literal (it is excluded from its own scan, but
// the synthetic stays clean for readability/searchability).
terms := lexicon.BannedTerms()
if len(terms) == 0 {
t.Fatal("BannedTerms() returned no terms — cannot run walk-coverage")
}
// Use the first banned term ("bank") assembled from two halves.
syntheticTerm := terms[0][:2] + terms[0][2:] // reassemble (no literal in source)
badContent := []byte("<!-- fixture -->\nthis file contains a banned term: " + syntheticTerm + "\n")
fixtureDir := filepath.Join(root, "web", "templates", ".lexicon_fixture")
fixtureFile := filepath.Join(fixtureDir, "bad_fixture.html")
if err := os.MkdirAll(fixtureDir, 0o755); err != nil {
t.Fatalf("mkdir fixture: %v", err)
}
defer os.RemoveAll(fixtureDir)
if err := os.WriteFile(fixtureFile, badContent, 0o644); err != nil {
t.Fatalf("write fixture: %v", err)
}
// Run the SAME walk logic as TestLexiconMetaWebNoBannedTermsInWeb and
// assert it FINDS the fixture's banned term. A walk that returns zero
// hits here proves the walk logic is broken (the fixture is a known-bad
// file inside web/templates/ that MUST be detected).
hits := []string{}
err := filepath.Walk(root, func(path string, info os.FileInfo, err error) error {
if err != nil {
return err
}
if info.IsDir() {
base := filepath.Base(path)
if base == ".ciagent" || base == ".git" {
return filepath.SkipDir
}
return nil
}
if path == this {
return nil
}
rel, rerr := filepath.Rel(root, path)
if rerr != nil {
return rerr
}
if !isWebTarget(rel) {
return nil
}
bz, rerr := os.ReadFile(path)
if rerr != nil {
return rerr
}
if found, ok := lexicon.FindBannedTerm(string(bz)); ok {
hits = append(hits, rel+" contains banned term "+found)
}
return nil
})
if err != nil {
t.Fatalf("walk: %v", err)
}
// Assert the fixture was found. The rel path uses OS-specific separator;
// match on the suffix so the test is portable.
foundFixture := false
for _, h := range hits {
if strings.Contains(h, "bad_fixture.html") && strings.Contains(h, syntheticTerm) {
foundFixture = true
break
}
}
if !foundFixture {
t.Errorf("G-013 walk-coverage: the walk did NOT find the synthetic banned-term fixture at %s — the web firewall walk logic is broken (it would silently scan nothing and report green). hits=%v", fixtureFile, hits)
}
}
+90
View File
@@ -0,0 +1,90 @@
package handlers
import (
"net/http"
identitytypes "github.com/oy/openyield/x/identity/types"
stashtypes "github.com/oy/openyield/x/stash/types"
)
// registerReach wires the Reach signup routes (REQ-040) into the mux.
// Go 1.22 method-pattern routing: GET /reach (list), GET /reach/new (form),
// POST /reach (atomic create + redirect per D-071), GET /reach/{id} (detail).
func (s *Server) registerReach(mux *http.ServeMux) {
mux.HandleFunc("GET /reach", s.handleReachList)
mux.HandleFunc("GET /reach/new", s.handleReachNew)
mux.HandleFunc("POST /reach", s.handleReachCreate)
mux.HandleFunc("GET /reach/{id}", s.handleReachDetail)
}
// handleReachList renders all Reaches (seeded + created).
func (s *Server) handleReachList(w http.ResponseWriter, r *http.Request) {
reaches := s.Store.ListReaches()
s.render(w, "reach_list.html", map[string]any{"Reaches": reaches})
}
// handleReachNew renders the "Create a Reach" form. Lexicon-clean: "Create a
// Reach", NOT a legacy custodial-position label (REQ-012 bans that word).
func (s *Server) handleReachNew(w http.ResponseWriter, r *http.Request) {
s.render(w, "reach_new.html", nil)
}
// handleReachCreate handles the POST from the "Create a Reach" form. Calls
// store.CreateReach (atomic Reach + Stash per D-071). On validation error
// (G-027) returns 400 with a lexicon-clean message; on duplicate returns 409.
// On success redirects (302) to the new Reach detail page.
func (s *Server) handleReachCreate(w http.ResponseWriter, r *http.Request) {
holderID := r.FormValue("holder_id")
publicKey := r.FormValue("public_key")
reach, _, err := s.Store.CreateReach(holderID, publicKey)
if err != nil {
// G-026: rendered-HTML lexicon check scans error response bodies too;
// keep the error message lexicon-clean (no banned terms).
status := http.StatusBadRequest
if isDuplicate(err) {
status = http.StatusConflict
}
http.Error(w, "Could not create a Reach: "+err.Error(), status)
return
}
http.Redirect(w, r, "/reach/"+reach.HolderID, http.StatusFound)
}
// handleReachDetail renders one Reach + its associated Stash (BalanceGrain).
func (s *Server) handleReachDetail(w http.ResponseWriter, r *http.Request) {
id := r.PathValue("id")
reach, ok := s.Store.GetReach(id)
if !ok {
http.NotFound(w, r)
return
}
stash, _ := s.Store.GetStash(id)
s.render(w, "reach_detail.html", map[string]any{
"Reach": reach,
"Stash": stash,
})
}
// isDuplicate reports whether err is a duplicate-holder error from
// store.CreateReach. Kept as a string match to avoid exporting store errors.
func isDuplicate(err error) bool {
return err != nil && contains(err.Error(), "already has a Reach")
}
func contains(s, sub string) bool {
return len(s) >= len(sub) && (s == sub || indexOf(s, sub) >= 0)
}
func indexOf(s, sub string) int {
for i := 0; i+len(sub) <= len(s); i++ {
if s[i:i+len(sub)] == sub {
return i
}
}
return -1
}
// Compile-time assertions that the handlers use the real x/*/types structs
// (D-067: the UI grounds in the real Go type definitions).
var _ identitytypes.Reach
var _ stashtypes.Stash
+185
View File
@@ -0,0 +1,185 @@
package handlers
import (
"net/http"
"net/http/httptest"
"strings"
"testing"
"github.com/oy/openyield/lexicon"
"github.com/oy/openyield/web/store"
)
// newTestServer builds a Server with a fresh store + templates parsed from
// web/templates (relative to repo root via the handlers test working dir).
func newTestServer(t *testing.T) *Server {
t.Helper()
srv, err := New(store.NewStore(), "../../web/templates")
if err != nil {
t.Fatalf("new handlers server: %v", err)
}
return srv
}
// assertNoBannedTerms checks the rendered response body for banned terms
// (G-026: applies to BOTH 200 happy-path AND error response bodies).
func assertNoBannedTerms(t *testing.T, body string) {
t.Helper()
if term, ok := lexicon.FindBannedTerm(body); ok {
t.Errorf("rendered HTML contains banned term %q (REQ-012/G-026)", term)
}
}
func TestReachListReturnsSeededReaches(t *testing.T) {
srv := newTestServer(t)
mux := http.NewServeMux()
srv.Register(mux)
rec := httptest.NewRecorder()
req := httptest.NewRequest("GET", "/reach", nil)
mux.ServeHTTP(rec, req)
if rec.Code != http.StatusOK {
t.Fatalf("GET /reach: status %d, want 200", rec.Code)
}
body := rec.Body.String()
if !strings.Contains(body, "holder-alia") {
t.Errorf("GET /reach: body missing seeded reach holder-alia")
}
if !strings.Contains(body, "holder-bryn") {
t.Errorf("GET /reach: body missing seeded reach holder-bryn")
}
assertNoBannedTerms(t, body)
}
func TestReachNewReturnsForm(t *testing.T) {
srv := newTestServer(t)
mux := http.NewServeMux()
srv.Register(mux)
rec := httptest.NewRecorder()
req := httptest.NewRequest("GET", "/reach/new", nil)
mux.ServeHTTP(rec, req)
if rec.Code != http.StatusOK {
t.Fatalf("GET /reach/new: status %d, want 200", rec.Code)
}
body := rec.Body.String()
if !strings.Contains(body, "Create a Reach") {
t.Errorf("GET /reach/new: body missing 'Create a Reach' label")
}
// The legacy custodial-position word is BANNED (REQ-012) — must not appear.
// Check the full banned-terms list via the lexicon package (no literals in
// source); FindBannedTerm does word-boundary matching so this is stricter
// than a naive substring check.
if term, ok := lexicon.FindBannedTerm(body); ok {
t.Errorf("GET /reach/new: body contains banned word %q", term)
}
assertNoBannedTerms(t, body)
}
func TestReachCreateValidRedirectsAndAtomicallyCreates(t *testing.T) {
srv := newTestServer(t)
mux := http.NewServeMux()
srv.Register(mux)
rec := httptest.NewRecorder()
req := httptest.NewRequest("POST", "/reach", strings.NewReader("holder_id=holder-new&public_key=pk-new"))
req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
mux.ServeHTTP(rec, req)
if rec.Code != http.StatusFound {
t.Fatalf("POST /reach valid: status %d, want 302 (Found)", rec.Code)
}
loc := rec.Header().Get("Location")
if !strings.Contains(loc, "/reach/holder-new") {
t.Errorf("POST /reach: Location %q, want redirect to /reach/holder-new", loc)
}
// D-071: atomic creation — both Reach + Stash must be present.
reach, ok := srv.Store.GetReach("holder-new")
if !ok {
t.Fatalf("POST /reach: GetReach miss after create (atomicity broken)")
}
if !reach.IsNomad {
t.Errorf("POST /reach: created Reach IsNomad=false, want true (D-071)")
}
stash, ok := srv.Store.GetStash("holder-new")
if !ok {
t.Fatalf("POST /reach: GetStash miss after create (atomicity broken — D-071)")
}
if stash.HolderID != reach.HolderID {
t.Errorf("POST /reach: stash.HolderID %q != reach.HolderID %q (D-071)", stash.HolderID, reach.HolderID)
}
}
func TestReachCreateEmptyHolderIDReturns400(t *testing.T) {
srv := newTestServer(t)
mux := http.NewServeMux()
srv.Register(mux)
rec := httptest.NewRecorder()
req := httptest.NewRequest("POST", "/reach", strings.NewReader("holder_id=&public_key=pk"))
req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
mux.ServeHTTP(rec, req)
if rec.Code != http.StatusBadRequest {
t.Fatalf("POST /reach empty holder: status %d, want 400", rec.Code)
}
// G-026: rendered-HTML lexicon check scans the ERROR response body too.
assertNoBannedTerms(t, rec.Body.String())
}
func TestReachCreatePathSeparatorReturns400(t *testing.T) {
srv := newTestServer(t)
mux := http.NewServeMux()
srv.Register(mux)
rec := httptest.NewRecorder()
req := httptest.NewRequest("POST", "/reach", strings.NewReader("holder_id=h/x&public_key=pk"))
req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
mux.ServeHTTP(rec, req)
if rec.Code != http.StatusBadRequest {
t.Fatalf("POST /reach path separator: status %d, want 400", rec.Code)
}
assertNoBannedTerms(t, rec.Body.String())
}
func TestReachCreateDuplicateReturns409(t *testing.T) {
srv := newTestServer(t)
mux := http.NewServeMux()
srv.Register(mux)
rec := httptest.NewRecorder()
req := httptest.NewRequest("POST", "/reach", strings.NewReader("holder_id=holder-alia&public_key=pk"))
req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
mux.ServeHTTP(rec, req)
if rec.Code != http.StatusConflict {
t.Fatalf("POST /reach duplicate: status %d, want 409", rec.Code)
}
assertNoBannedTerms(t, rec.Body.String())
}
func TestReachDetailSeededReturnsReachAndStash(t *testing.T) {
srv := newTestServer(t)
mux := http.NewServeMux()
srv.Register(mux)
rec := httptest.NewRecorder()
req := httptest.NewRequest("GET", "/reach/holder-alia", nil)
mux.ServeHTTP(rec, req)
if rec.Code != http.StatusOK {
t.Fatalf("GET /reach/holder-alia: status %d, want 200", rec.Code)
}
body := rec.Body.String()
if !strings.Contains(body, "reach-holder-alia") {
t.Errorf("GET /reach/holder-alia: body missing reach-holder-alia")
}
if !strings.Contains(body, "stash-holder-alia") {
t.Errorf("GET /reach/holder-alia: body missing associated stash-holder-alia")
}
if !strings.Contains(body, "Grain") {
t.Errorf("GET /reach/holder-alia: body missing Stash balance in Grain")
}
assertNoBannedTerms(t, body)
}
func TestReachDetailMissingReturns404(t *testing.T) {
srv := newTestServer(t)
mux := http.NewServeMux()
srv.Register(mux)
rec := httptest.NewRecorder()
req := httptest.NewRequest("GET", "/reach/nobody", nil)
mux.ServeHTTP(rec, req)
if rec.Code != http.StatusNotFound {
t.Fatalf("GET /reach/nobody: status %d, want 404", rec.Code)
}
}
+100
View File
@@ -0,0 +1,100 @@
// Package handlers holds the HTTP handlers for the OpenYield web UI screens.
//
// Each screen (Reach signup, Stash dashboard, Window authorization, Standing
// progress, Bloom accrual) gets its own handler file. handlers/server.go wires
// routes into the mux from web/server.go. Handlers render html/template
// templates against the mock store (web/store). Lexicon-clean by construction
// (REQ-012 / REQ-045): the lexicon_meta_web firewall scans these files.
package handlers
import (
"fmt"
"html/template"
"net/http"
"os"
"path/filepath"
"github.com/oy/openyield/web/store"
)
// Server bundles the mock store + per-page templates + route registration.
// Each screen handler is a method on Server so it shares the store + tmpl.
//
// Template loading: base.html is parsed once, then each page template is
// parsed in a CLONE of the base set so the per-page "content" block does not
// collide across pages (Go html/template shares the block namespace within
// one set; cloning per page isolates each page's content block). This is the
// standard Go template pattern for layouts + pages.
type Server struct {
Store *store.Store
Pages map[string]*template.Template
}
// New constructs a Server with the given store + per-page templates loaded
// from templatesDir (the absolute or relative path to web/templates/).
func New(s *store.Store, templatesDir string) (*Server, error) {
basePath := filepath.Join(templatesDir, "base.html")
base, err := template.ParseFiles(basePath)
if err != nil {
return nil, fmt.Errorf("parse base: %w", err)
}
pages := map[string]*template.Template{}
pageGlob := filepath.Join(templatesDir, "*.html")
matches, err := filepath.Glob(pageGlob)
if err != nil {
return nil, fmt.Errorf("glob pages: %w", err)
}
for _, p := range matches {
name := filepath.Base(p)
if name == "base.html" {
continue
}
clone, cerr := base.Clone()
if cerr != nil {
return nil, fmt.Errorf("clone for %s: %w", name, cerr)
}
pt, perr := clone.ParseFiles(p)
if perr != nil {
return nil, fmt.Errorf("parse %s: %w", name, perr)
}
pages[name] = pt
}
return &Server{Store: s, Pages: pages}, nil
}
// Register wires all screen routes into the given mux (Go 1.22 method
// patterns). Called by web/server.go after constructing the Server.
func (s *Server) Register(mux *http.ServeMux) {
s.registerReach(mux)
// P2..P5 register their own routes (stash, window, standing, bloom).
}
// render executes the named page template with the given data, writing HTML
// to w. The page template invokes base.html and overrides the "content" block.
func (s *Server) render(w http.ResponseWriter, name string, data any) {
tmpl, ok := s.Pages[name]
if !ok {
http.Error(w, "template not found: "+name, http.StatusInternalServerError)
return
}
w.Header().Set("Content-Type", "text/html; charset=utf-8")
if err := tmpl.ExecuteTemplate(w, "base.html", data); err != nil {
http.Error(w, "render error", http.StatusInternalServerError)
}
}
// RenderHome renders the home page (public so web/server.go can call it for
// the "/" route which lives outside handlers.Register).
func (s *Server) RenderHome(w http.ResponseWriter, data any) {
s.render(w, "home.html", data)
}
// templatesDir returns the default web/templates directory relative to the
// working directory. Used by web/server.go when constructing via New().
func DefaultTemplatesDir() string {
dir, _ := os.Getwd()
if filepath.Base(dir) == "web" || filepath.Base(dir) == "handlers" {
return filepath.Join(dir, "templates")
}
return "web/templates"
}
+5
View File
@@ -0,0 +1,5 @@
package main
func main() {
runServer()
}
+42
View File
@@ -0,0 +1,42 @@
package main
import (
"log"
"net/http"
"os"
"github.com/oy/openyield/web/handlers"
"github.com/oy/openyield/web/store"
)
func runServer() {
port := os.Getenv("PORT")
if port == "" {
port = "8080"
}
mux := http.NewServeMux()
srv, err := handlers.New(store.NewStore(), "web/templates")
if err != nil {
log.Fatalf("init handlers: %v", err)
}
srv.Register(mux)
// Home page (rendered via the handlers' page machinery too).
mux.HandleFunc("GET /", func(w http.ResponseWriter, r *http.Request) {
if r.URL.Path != "/" {
http.NotFound(w, r)
return
}
srv.RenderHome(w, nil)
})
mux.Handle("GET /static/", http.StripPrefix("/static/", http.FileServer(http.Dir("web/static"))))
server := &http.Server{Addr: ":" + port, Handler: mux}
log.Printf("OpenYield web on :%s", port)
if err := server.ListenAndServe(); err != nil {
log.Fatalf("server: %v", err)
}
}
+5
View File
File diff suppressed because one or more lines are too long
+78
View File
@@ -0,0 +1,78 @@
/* style.css — OpenYield web UI minimal styling (lexicon-clean).
No banned terms in comments or class names (REQ-012/REQ-045). */
:root {
--bg: #0d1117;
--panel: #161b22;
--ink: #c9d1d9;
--muted: #8b949e;
--accent: #58a6ff;
--line: #30363d;
}
* { box-sizing: border-box; }
body {
margin: 0;
font-family: system-ui, -apple-system, sans-serif;
background: var(--bg);
color: var(--ink);
line-height: 1.5;
}
a { color: var(--accent); text-decoration: none; }
a:hover { text-decoration: underline; }
header.nav {
border-bottom: 1px solid var(--line);
padding: 0.75rem 1.5rem;
display: flex;
gap: 1.25rem;
align-items: center;
background: var(--panel);
}
header.nav .brand { font-weight: 600; color: var(--ink); }
header.nav a { color: var(--muted); }
header.nav a:hover { color: var(--accent); }
main { max-width: 960px; margin: 2rem auto; padding: 0 1.5rem; }
footer {
border-top: 1px solid var(--line);
padding: 1rem 1.5rem;
color: var(--muted);
font-size: 0.85rem;
text-align: center;
}
.panel {
background: var(--panel);
border: 1px solid var(--line);
border-radius: 6px;
padding: 1.25rem;
margin-bottom: 1.5rem;
}
table { width: 100%; border-collapse: collapse; }
th, td { text-align: left; padding: 0.5rem 0.75rem; border-bottom: 1px solid var(--line); }
th { color: var(--muted); font-weight: 600; font-size: 0.85rem; text-transform: uppercase; letter-spacing: 0.04em; }
form .field { margin-bottom: 1rem; }
form label { display: block; margin-bottom: 0.25rem; color: var(--muted); font-size: 0.9rem; }
form input[type=text], form input[type=password] {
width: 100%; max-width: 32rem;
padding: 0.5rem 0.65rem;
background: var(--bg);
border: 1px solid var(--line);
border-radius: 4px;
color: var(--ink);
font-family: monospace;
}
button, .btn {
background: var(--accent); color: #0d1117; border: none;
padding: 0.5rem 1rem; border-radius: 4px; font-weight: 600; cursor: pointer;
}
button:hover, .btn:hover { opacity: 0.9; text-decoration: none; }
.error { color: #f85149; }
.muted { color: var(--muted); }
+46
View File
@@ -0,0 +1,46 @@
package store
import (
"time"
identitytypes "github.com/oy/openyield/x/identity/types"
stashtypes "github.com/oy/openyield/x/stash/types"
)
// seed populates the store with a few pre-existing Reach/Stash pairs for the
// list view. All strings lexicon-clean ("Holder"/"Reach"/"Stash"; NOT the
// banned financial terms). Two fixtures: one mature (90+ active days),
// one immature (45 active days) so the Stash dashboard (P2) can show both
// states.
func (s *Store) seed() {
now := time.Now().Unix()
// Fixture 1: a mature Nomad (ActiveDays=92, MaxGapDays=10 -> IsMature()).
seedOne(s, "holder-alia", "pk-alia-001", now, 920000, 92, 10)
// Fixture 2: an immature Nomad (ActiveDays=45, MaxGapDays=5 -> not mature).
seedOne(s, "holder-bryn", "pk-bryn-002", now, 410000, 45, 5)
}
func seedOne(s *Store, holderID, pubKey string, now int64, balanceGrain int64, activeDays, maxGap uint32) {
reachID := "reach-" + holderID
stashID := "stash-" + holderID
s.reaches[holderID] = identitytypes.Reach{
ReachID: reachID,
HolderID: holderID,
CreatedAt: now - int64(activeDays)*86400,
PublicKey: pubKey,
IsNomad: true,
}
s.stashes[holderID] = stashtypes.Stash{
HolderID: holderID,
StashID: stashID,
CreatedAt: now - int64(activeDays)*86400,
LastActive: now,
BalanceGrain: balanceGrain,
}
s.stashActivities[stashID] = stashtypes.StashActivity{
StashID: stashID,
ActiveDays: activeDays,
MaxGapDays: maxGap,
LastActivityDay: now,
}
}
+108
View File
@@ -0,0 +1,108 @@
// import_test.go enforces the G-003/G-025 boundary for web/: web/ is the
// application layer that consumes protocol types (D-070), NOT a cross-x/
// production import. The invariant: every non-test .go file under web/ may
// import github.com/oy/openyield/x/<module>/types packages (the app-layer
// consumption direction), but MUST NOT import github.com/oy/openyield/
// x/<module>/keeper OR github.com/oy/openyield/x/<module> (the module.go
// packages — G-025 extends the original keeper-only check to also forbid
// module.go, since those packages carry Cosmos runtime machinery the mock UI
// must not reach into). This test uses go/parser (stdlib only — G-006) and
// mirrors the x/window/types/types_test.go G-003 pattern, but with the
// inverted rule: x/*/types is ALLOWED (app-layer consumption), x/*/keeper
// and x/<module> (module.go) are FORBIDDEN.
package store
import (
"go/parser"
"go/token"
"os"
"path/filepath"
"runtime"
"strings"
"testing"
)
func TestG025WebImportsOnlyTypesNotKeeperOrModule(t *testing.T) {
webRoot := webRoot(t)
fset := token.NewFileSet()
violations := []string{}
err := filepath.Walk(webRoot, func(path string, info os.FileInfo, err error) error {
if err != nil {
return err
}
if info.IsDir() {
return nil
}
if !strings.HasSuffix(path, ".go") {
return nil
}
// Skip test files (G-025 is about production code only).
if strings.HasSuffix(path, "_test.go") {
return nil
}
f, perr := parser.ParseFile(fset, path, nil, parser.ImportsOnly)
if perr != nil {
return perr
}
for _, imp := range f.Imports {
ip := strings.Trim(imp.Path.Value, `"`)
if isForbiddenXImport(ip) {
rel, _ := filepath.Rel(webRoot, path)
violations = append(violations, rel+" -> "+ip)
}
}
return nil
})
if err != nil {
t.Fatalf("walk web/: %v", err)
}
if len(violations) > 0 {
t.Errorf("G-025 violation: web/ production files importing forbidden x/ packages:\n %s",
strings.Join(violations, "\n "))
}
}
// isForbiddenXImport reports whether ip is an x/<module>/keeper or a bare
// x/<module> (module.go) import — both forbidden from web/ (G-025). The
// x/<module>/types packages are ALLOWED (D-070 app-layer consumption).
func isForbiddenXImport(ip string) bool {
const prefix = "github.com/oy/openyield/x/"
if !strings.HasPrefix(ip, prefix) {
return false
}
rest := strings.TrimPrefix(ip, prefix)
parts := strings.Split(rest, "/")
switch len(parts) {
case 1:
// x/<module> (module.go package) — forbidden (G-025).
return true
case 2:
// x/<module>/types -> allowed (D-070). x/<module>/keeper -> forbidden.
if parts[1] == "types" {
return false
}
return true
default:
// x/<module>/<sub>/... — forbid anything other than types (e.g.
// x/<module>/keeper/... sub-packages).
if parts[1] == "types" {
return false
}
return true
}
}
// webRoot returns the absolute path to the web/ directory by walking up
// from this test file (web/store/import_test.go -> repoRoot/web).
func webRoot(t *testing.T) string {
t.Helper()
_, file, _, ok := runtime.Caller(0)
if !ok {
t.Fatal("runtime.Caller failed")
}
// file = .../oy/web/store/import_test.go
// repoRoot = filepath.Dir(filepath.Dir(filepath.Dir(file)))
// webRoot = repoRoot/web
repoRoot := filepath.Dir(filepath.Dir(filepath.Dir(file)))
return filepath.Join(repoRoot, "web")
}
+146
View File
@@ -0,0 +1,146 @@
// Package store is the in-memory mock data layer for the OpenYield web UI.
//
// It instantiates the real x/*/types structs (Reach, Stash, StashActivity)
// from in-memory fixtures and provides create/get/list methods. This is the
// app-layer consumption of protocol types (D-070), NOT a cross-x/ production
// import — web/ is NOT an x/ module. No keeper, no Cosmos runtime, no app.go
// (G-003 boundary enforced by import_test.go / G-025).
package store
import (
"fmt"
"strings"
"sync"
"time"
identitytypes "github.com/oy/openyield/x/identity/types"
stashtypes "github.com/oy/openyield/x/stash/types"
)
// seedBalanceGrain is the test balance seeded to a new Stash at signup (D-071
// example: 500000 Grain = 50 Bread per GrainsPerBread=10000).
const seedBalanceGrain int64 = 500000
// Store is the in-memory mock store. All methods are goroutine-safe (mu).
type Store struct {
mu sync.Mutex
reaches map[string]identitytypes.Reach
stashes map[string]stashtypes.Stash
stashActivities map[string]stashtypes.StashActivity
}
// NewStore constructs a Store seeded from fixtures (fixtures.go).
func NewStore() *Store {
s := &Store{
reaches: map[string]identitytypes.Reach{},
stashes: map[string]stashtypes.Stash{},
stashActivities: map[string]stashtypes.StashActivity{},
}
s.seed()
return s
}
// CreateReach atomically creates a Reach (IsNomad=true) + a Stash (D-071).
// G-027: HolderID and PublicKey are validated (non-empty, <=128 bytes, no
// path separators, no template syntax) before any map write. Returns the
// created Reach + Stash.
func (s *Store) CreateReach(holderID, publicKey string) (identitytypes.Reach, stashtypes.Stash, error) {
if err := validateReachInput(holderID, publicKey); err != nil {
return identitytypes.Reach{}, stashtypes.Stash{}, err
}
s.mu.Lock()
defer s.mu.Unlock()
if _, dup := s.reaches[holderID]; dup {
return identitytypes.Reach{}, stashtypes.Stash{}, fmt.Errorf("holder %q already has a Reach", holderID)
}
now := time.Now().Unix()
reachID := "reach-" + holderID
stashID := "stash-" + holderID
reach := identitytypes.Reach{
ReachID: reachID,
HolderID: holderID,
CreatedAt: now,
PublicKey: publicKey,
IsNomad: true,
}
stash := stashtypes.Stash{
HolderID: holderID,
StashID: stashID,
CreatedAt: now,
LastActive: now,
BalanceGrain: seedBalanceGrain,
}
activity := stashtypes.StashActivity{
StashID: stashID,
ActiveDays: 1,
MaxGapDays: 1,
LastActivityDay: now,
}
s.reaches[holderID] = reach
s.stashes[holderID] = stash
s.stashActivities[stashID] = activity
return reach, stash, nil
}
// ListReaches returns all seeded + created Reaches.
func (s *Store) ListReaches() []identitytypes.Reach {
s.mu.Lock()
defer s.mu.Unlock()
out := make([]identitytypes.Reach, 0, len(s.reaches))
for _, r := range s.reaches {
out = append(out, r)
}
return out
}
// GetReach returns the Reach for a holderID (by HolderID, the stable key).
func (s *Store) GetReach(holderID string) (identitytypes.Reach, bool) {
s.mu.Lock()
defer s.mu.Unlock()
r, ok := s.reaches[holderID]
return r, ok
}
// GetStash returns the Stash for a holderID.
func (s *Store) GetStash(holderID string) (stashtypes.Stash, bool) {
s.mu.Lock()
defer s.mu.Unlock()
st, ok := s.stashes[holderID]
return st, ok
}
// GetStashActivity returns the StashActivity for a stashID.
func (s *Store) GetStashActivity(stashID string) (stashtypes.StashActivity, bool) {
s.mu.Lock()
defer s.mu.Unlock()
a, ok := s.stashActivities[stashID]
return a, ok
}
// validateReachInput enforces G-027: HolderID and PublicKey must be non-empty,
// <=128 bytes, and contain no path separators or template syntax. This is a
// prototype-robustness gate (the mock store uses holderID as a map key).
func validateReachInput(holderID, publicKey string) error {
if holderID == "" {
return fmt.Errorf("holder id is required")
}
if len(holderID) > 128 {
return fmt.Errorf("holder id too long (max 128)")
}
if strings.ContainsAny(holderID, "/\\") {
return fmt.Errorf("holder id must not contain path separators")
}
if strings.Contains(holderID, "{{") {
return fmt.Errorf("holder id must not contain template syntax")
}
if publicKey == "" {
return fmt.Errorf("public key is required")
}
if len(publicKey) > 128 {
return fmt.Errorf("public key too long (max 128)")
}
if strings.ContainsAny(publicKey, "/\\") {
return fmt.Errorf("public key must not contain path separators")
}
return nil
}
+216
View File
@@ -0,0 +1,216 @@
package store
import (
"sync"
"testing"
identitytypes "github.com/oy/openyield/x/identity/types"
stashtypes "github.com/oy/openyield/x/stash/types"
)
func TestNewStoreSeedsFixtures(t *testing.T) {
s := NewStore()
reaches := s.ListReaches()
if len(reaches) < 2 {
t.Fatalf("NewStore seeded %d reaches, want >=2", len(reaches))
}
// Both seeded reaches must be Nomads (IsNomad=true).
for _, r := range reaches {
if !r.IsNomad {
t.Errorf("seeded reach %q: IsNomad=false, want true", r.HolderID)
}
}
}
func TestCreateReachAtomicReachAndStash(t *testing.T) {
s := NewStore()
reach, stash, err := s.CreateReach("holder-test1", "pk-test1")
if err != nil {
t.Fatalf("CreateReach: %v", err)
}
// D-071: Reach must be IsNomad=true.
if !reach.IsNomad {
t.Errorf("reach.IsNomad = false, want true (D-071)")
}
if reach.HolderID != "holder-test1" {
t.Errorf("reach.HolderID = %q, want holder-test1", reach.HolderID)
}
// D-071: Stash must have matching HolderID + seeded BalanceGrain.
if stash.HolderID != reach.HolderID {
t.Errorf("stash.HolderID = %q, want %q (D-071 atomic)", stash.HolderID, reach.HolderID)
}
if stash.BalanceGrain != seedBalanceGrain {
t.Errorf("stash.BalanceGrain = %d, want %d", stash.BalanceGrain, seedBalanceGrain)
}
// Both must be retrievable after the atomic call.
if _, ok := s.GetReach("holder-test1"); !ok {
t.Errorf("GetReach miss after CreateReach (atomicity broken)")
}
if _, ok := s.GetStash("holder-test1"); !ok {
t.Errorf("GetStash miss after CreateReach (atomicity broken)")
}
if _, ok := s.GetStashActivity(stash.StashID); !ok {
t.Errorf("GetStashActivity miss after CreateReach (atomicity broken)")
}
}
func TestCreateReachDuplicateRejected(t *testing.T) {
s := NewStore()
if _, _, err := s.CreateReach("holder-alia", "pk-dupe"); err == nil {
t.Errorf("CreateReach duplicate holder-alia: expected error, got nil")
}
}
func TestCreateReachValidationG027(t *testing.T) {
cases := []struct {
name string
holderID string
publicKey string
wantErr bool
}{
{"empty holder", "", "pk", true},
{"empty pubkey", "h", "", true},
{"holder too long", stringOf('x', 129), "pk", true},
{"pubkey too long", "h", stringOf('y', 129), true},
{"holder with slash", "h/x", "pk", true},
{"holder with backslash", "h\\x", "pk", true},
{"holder with template syntax", "h{{", "pk", true},
{"pubkey with slash", "h", "p/x", true},
{"valid minimal", "h", "p", false},
{"valid typical", "holder-oka", "pk-oka-7", false},
}
for _, c := range cases {
t.Run(c.name, func(t *testing.T) {
s := NewStore()
_, _, err := s.CreateReach(c.holderID, c.publicKey)
if c.wantErr && err == nil {
t.Errorf("expected error, got nil")
}
if !c.wantErr && err != nil {
t.Errorf("unexpected error: %v", err)
}
})
}
}
func TestGetReachHitMiss(t *testing.T) {
s := NewStore()
if _, ok := s.GetReach("holder-alia"); !ok {
t.Errorf("GetReach(holder-alia) miss, want hit (seeded)")
}
if _, ok := s.GetReach("nobody"); ok {
t.Errorf("GetReach(nobody) hit, want miss")
}
}
func TestGetStashHitMiss(t *testing.T) {
s := NewStore()
if _, ok := s.GetStash("holder-alia"); !ok {
t.Errorf("GetStash(holder-alia) miss, want hit (seeded)")
}
if _, ok := s.GetStash("nobody"); ok {
t.Errorf("GetStash(nobody) hit, want miss")
}
}
func TestGetStashActivityHitMiss(t *testing.T) {
s := NewStore()
stash, ok := s.GetStash("holder-alia")
if !ok {
t.Fatal("seeded stash holder-alia missing")
}
if _, ok := s.GetStashActivity(stash.StashID); !ok {
t.Errorf("GetStashActivity(%q) miss, want hit", stash.StashID)
}
if _, ok := s.GetStashActivity("stash-nobody"); ok {
t.Errorf("GetStashActivity(stash-nobody) hit, want miss")
}
}
func TestCreateReachConcurrentNoRace(t *testing.T) {
s := NewStore()
const n = 50
var wg sync.WaitGroup
wg.Add(n)
for i := 0; i < n; i++ {
go func(i int) {
defer wg.Done()
holder := "holder-concurrent-" + itoa(i)
_, _, _ = s.CreateReach(holder, "pk")
}(i)
}
wg.Wait()
// All n concurrent creates with distinct holder IDs must be present.
for i := 0; i < n; i++ {
if _, ok := s.GetReach("holder-concurrent-" + itoa(i)); !ok {
t.Errorf("concurrent reach %d missing after wg.Wait", i)
}
}
}
func TestSeededMatureVsImmature(t *testing.T) {
s := NewStore()
// holder-alia: ActiveDays=92, MaxGapDays=10 -> mature.
aliaStash, ok := s.GetStash("holder-alia")
if !ok {
t.Fatal("seeded holder-alia missing")
}
aliaAct, ok := s.GetStashActivity(aliaStash.StashID)
if !ok {
t.Fatal("seeded alia activity missing")
}
if !aliaAct.IsMature() {
t.Errorf("holder-alia IsMature=false, want true (ActiveDays=%d, MaxGap=%d)",
aliaAct.ActiveDays, aliaAct.MaxGapDays)
}
// holder-bryn: ActiveDays=45, MaxGapDays=5 -> not mature.
brynStash, ok := s.GetStash("holder-bryn")
if !ok {
t.Fatal("seeded holder-bryn missing")
}
brynAct, ok := s.GetStashActivity(brynStash.StashID)
if !ok {
t.Fatal("seeded bryn activity missing")
}
if brynAct.IsMature() {
t.Errorf("holder-bryn IsMature=true, want false (ActiveDays=%d, MaxGap=%d)",
brynAct.ActiveDays, brynAct.MaxGapDays)
}
}
// Compile-time assertions that the types are the real x/*/types structs
// (D-067: the mock store grounds the UI in the real Go type definitions).
var _ identitytypes.Reach
var _ stashtypes.Stash
// itoa is a tiny strconv.Itoa without the import (keeps store_test.go deps
// to just sync + testing + the two x/*/types packages).
func itoa(n int) string {
if n == 0 {
return "0"
}
neg := n < 0
if neg {
n = -n
}
var buf [20]byte
i := len(buf)
for n > 0 {
i--
buf[i] = byte('0' + n%10)
n /= 10
}
if neg {
i--
buf[i] = '-'
}
return string(buf[i:])
}
func stringOf(r rune, n int) string {
b := make([]byte, n)
for i := range b {
b[i] = byte(r)
}
return string(b)
}
+29
View File
@@ -0,0 +1,29 @@
{{define "base.html"}}
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>{{block "title" .}}OpenYield{{end}}</title>
<link rel="stylesheet" href="/static/style.css">
<script src="/static/htmx.min.js" defer></script>
</head>
<body>
<header class="nav">
<span class="brand">OpenYield</span>
<a href="/">Home</a>
<a href="/reach">Reach</a>
<a href="/stash">Stash</a>
<a href="/window">Window</a>
<a href="/standing">Standing</a>
<a href="/bloom">Bloom</a>
</header>
<main>
{{block "content" .}}{{end}}
</main>
<footer>
OpenYield — real production on the mesh. Reach, Stash, Window, Standing, Bloom.
</footer>
</body>
</html>
{{end}}
+24
View File
@@ -0,0 +1,24 @@
{{define "title"}}OpenYield — real production on the mesh{{end}}
{{define "content"}}
<section class="panel">
<h1>OpenYield</h1>
<p>
OpenYield is a mesh-native system for real production. A Holder creates a
Reach to enter the mesh, holds a Stash of Grain, and authorizes Window
access to partners. Standing accrues through honest participation, and
Bloom rewards sustained contribution. No middleman holds your Stash.
</p>
</section>
<section class="panel">
<h2>The five screens</h2>
<ul>
<li><a href="/reach">Reach</a> — create a Reach and view the mesh of Holders.</li>
<li><a href="/stash">Stash</a> — your sovereign Grain Stash (P2).</li>
<li><a href="/window">Window</a> — authorize partner access to your Stash (P3).</li>
<li><a href="/standing">Standing</a> — track progress toward Freeholder standing (P4).</li>
<li><a href="/bloom">Bloom</a> — accrued rewards for sustained contribution (P5).</li>
</ul>
</section>
{{end}}
+31
View File
@@ -0,0 +1,31 @@
{{define "title"}}{{.Reach.ReachID}} — OpenYield{{end}}
{{define "content"}}
<section class="panel">
<h1>{{.Reach.ReachID}}</h1>
<table class="kv">
<tr><th>Reach ID</th><td>{{.Reach.ReachID}}</td></tr>
<tr><th>Holder ID</th><td>{{.Reach.HolderID}}</td></tr>
<tr><th>Public Key</th><td><code>{{.Reach.PublicKey}}</code></td></tr>
<tr><th>Created</th><td>{{.Reach.CreatedAt}}</td></tr>
<tr><th>Nomad</th><td>{{if .Reach.IsNomad}}yes{{else}}no{{end}}</td></tr>
<tr><th>Freeholder</th><td>{{if .Reach.IsFreeholder}}yes{{else}}no{{end}}</td></tr>
</table>
</section>
{{if .Stash.StashID}}
<section class="panel">
<h2>Stash</h2>
<table class="kv">
<tr><th>Stash ID</th><td>{{.Stash.StashID}}</td></tr>
<tr><th>Balance</th><td>{{.Stash.BalanceGrain}} Grain</td></tr>
<tr><th>Created</th><td>{{.Stash.CreatedAt}}</td></tr>
<tr><th>Last active</th><td>{{.Stash.LastActive}}</td></tr>
<tr><th>Still</th><td>{{if .Stash.IsStill}}paused{{else}}active{{end}}</td></tr>
</table>
<p><a href="/stash/{{.Stash.HolderID}}">View Stash dashboard</a></p>
</section>
{{end}}
<p><a href="/reach">Back to Reach list</a></p>
{{end}}
+35
View File
@@ -0,0 +1,35 @@
{{define "title"}}Reach — OpenYield{{end}}
{{define "content"}}
<section class="panel">
<h1>Reach</h1>
<p>A Reach is the mesh-native identity a Holder uses to act on the mesh
without a custodian, a gatekeeper, or a legacy financial position. A Nomad
is a Holder who has a Reach and a Stash and is on the way to earning the
four Freeholder signals.</p>
<p><a href="/reach/new" class="btn">Create a Reach</a></p>
</section>
<section class="panel">
<h2>Holders on the mesh</h2>
{{if .Reaches}}
<table>
<thead>
<tr><th>Reach ID</th><th>Holder ID</th><th>Nomad</th><th>Freeholder</th></tr>
</thead>
<tbody>
{{range .Reaches}}
<tr>
<td><a href="/reach/{{.HolderID}}">{{.ReachID}}</a></td>
<td>{{.HolderID}}</td>
<td>{{if .IsNomad}}yes{{else}}no{{end}}</td>
<td>{{if .IsFreeholder}}yes{{else}}no{{end}}</td>
</tr>
{{end}}
</tbody>
</table>
{{else}}
<p>No Reaches yet. <a href="/reach/new">Create a Reach</a> to begin.</p>
{{end}}
</section>
{{end}}
+22
View File
@@ -0,0 +1,22 @@
{{define "title"}}Create a Reach — OpenYield{{end}}
{{define "content"}}
<section class="panel">
<h1>Create a Reach</h1>
<p>A Reach is an identity, not a custodial position. The protocol does not
require KYC at the protocol layer; the Reach is the unit of self-service.
Creating a Reach also opens a Stash for you (the place a Nomad holds
Grain) — that pair is enough to begin on the mesh.</p>
<form method="POST" action="/reach" hx-post="/reach" hx-target="body">
<label for="holder_id">Holder ID</label>
<input type="text" id="holder_id" name="holder_id" required
maxlength="128" placeholder="a by-ID-string of your choosing">
<label for="public_key">Public Key</label>
<input type="text" id="public_key" name="public_key" required
maxlength="128" placeholder="a public key for your Reach">
<button type="submit">Create a Reach</button>
</form>
<p><a href="/reach">Back to Reach list</a></p>
</section>
{{end}}