Skip to content

chore: move to @chelonia/lib 2.0.0 and chel 3.4.1 - #7

Merged
taoeffect merged 2 commits into
feat/ts-conversionfrom
chore/chelonia-lib-2
Oct 2, 2026
Merged

taoeffect merged 2 commits into
feat/ts-conversionfrom
chore/chelonia-lib-2

Conversation

@akhileshthite

Copy link
Copy Markdown
Member

Closes #4. Based on #6.

Moves to @chelonia/lib 2.0.0 and chel 3.4.1, and removes the workarounds
they fix:

  • The username lookup uses the library's nameToContractID.
  • Signup says why the server refused it: 403 means signups are off, 429 means
    too many from this network.
  • Our randomUUID fallback and the LIGHTWEIGHT_CLIENT setting are gone, the
    library handles both now.
  • chel loads SQLite by itself, so the DENO_SQLITE_PATH workaround and its CI
    step are gone.
  • The identity contract is now todomvc/identity instead of borrowing Group
    Income's gi.contracts/identity, so the contract version is 0.3.0. Older
    local accounts still log in but their lists do not show. To start fresh,
    delete data/, contracts/ and chelonia.json.

Three new e2e tests: the two signup messages, and making a list after a
reload, which breaks if the app ever stops running as a lightweight client.

Two TODOs from #4 are left. Neither blocks anything, and both are listed in
AGENTS.md:

  • USERNAME_REGEX is a copy of chel's private name rule, so signup can say a
    name is invalid before sending anything. It matches chel today; apps just
    cannot import the rule yet.
  • The signup key list gets shorter once libcheloniajs#91 adds a helper. It is a
    tidy-up, not a workaround.

AI usage: Claude Opus 5.5 Max
Self review: Approved

@akhileshthite akhileshthite self-assigned this Oct 1, 2026
@akhileshthite akhileshthite added the enhancement New feature or request label Oct 1, 2026
@akhileshthite

akhileshthite commented Oct 1, 2026 •

Copy link
Copy Markdown
Member Author

/review


AI review started.

@socket-security

socket-security Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updated@​chelonia/​cli@​3.4.0 ⏵ 3.4.171 +210099 +189 +170
Updated@​chelonia/​lib@​1.5.0 ⏵ 2.0.073 +110090 +19170

View full report

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Advanced AI Review

  • Type: Agentic (crush)
  • Model: glm-5.3
Click to expand review

Code Review

Base: origin/feat/ts-conversion (6ba1bfe)
Head: HEAD (55e1360, "chore: move to @chelonia/lib 2.0.0 and chel 3.4.1")
Date: 2026-10-01
Model: glm-5.3


This PR bumps @chelonia/lib 1.5.0 → 2.0.0 and @chelonia/cli 3.4.0 → 3.4.1
(lockfile updated in the same commit), renames the identity contract from
gi.contracts/identity to todomvc/identity, drops the five workarounds the
new releases fix, and adds three e2e tests. Every claim the diff makes about
upstream behavior was verified against the actual published packages rather
than taken on trust:

  • chelonia/out/nameToContractID exists in @chelonia/lib 2.0.0, resolves
    null for 400/404/410 and empty bodies, throws
    ChelErrorUnexpectedHttpResponseCode with a numeric cause for other
    statuses, and propagates fetch's TypeError on network failure — exactly
    what the new lookupUsername in src/chelonia/auth.ts:176-187 assumes. The
    pre-existing test a login that never reaches the server says so
    (test/e2e/chelonia.spec.ts:87) still passes through this branch.
  • publishEvent in 2.0.0 throws ChelErrorUnexpectedHttpResponseCode with
    { cause: r.status } (a number), and registerContract does not wrap it,
    so the strict comparisons e.cause === 403 / === 429 at
    src/chelonia/auth.ts:295-298 are correct. The chel 3.4.1 server does send
    exactly 403 ("Registration disabled") and 429 ("Rate limit exceeded") on the
    account-less signup path, and its error bodies are plain text, which
    httpErrorDetail now reads without the old JSON-parse blowup.
  • Lightweight client is the 2.0.0 default (LIGHTWEIGHT_CLIENT !== 'false'
    in src/db.ts), so removing the define from vite.config.ts is safe, and
    the new "list made after a reload" e2e test guards exactly the regression
    the removal could cause.
  • @chelonia/lib 2.0.0 ships its own randomUUID fallback in
    functions.ts (used by persistent-actions.ts), so deleting
    ensureRandomUUID from src/chelonia/offline.ts is safe.
  • The chel 3.4.1 binary statically bundles SQLite (libsqlite3-sys symbols,
    no DENO_SQLITE_PATH strings), so the CI step and the scripts/chel.ts
    env plumbing are correctly gone; the lockfile pulls the platform packages.
  • chel 3.4.1 no longer special-cases gi.contracts/identity for account-less
    contract creation, and its NAME_REGEX still matches the copied
    USERNAME_REGEX in src/chelonia/auth.ts:81 byte for byte.
  • chelonia.json (newly mentioned in the build error and AGENTS.md as a file
    to delete when starting fresh) is real: it is written by chel pin.
  • The rename is complete: grep gi.contracts finds only the intentional
    historical mention in AGENTS.md, all CONTRACT_NAME consumers go through
    the single constant, and todomvc/identity/setDeletionToken matches the
    renamed action in src/contracts/identity.js:39. grep REMOVEME confirms
    only the two TODOs AGENTS.md still lists remain.

One minor gap found, otherwise no issues.

1. ⚪ Signup status mapping misses 409, the one status with an existing message

  • Addressed
  • Dismissed

The new status handling in src/chelonia/auth.ts:294-299 maps 403 and 429 to
specific messages but not 409. A username taken in the window between the
/zkpp/register check (src/chelonia/auth.ts:134, which catches the common
case) and the POST /event publish makes publishEvent throw
ChelErrorUnexpectedHttpResponseCode with cause: 409 (after its internal
retries), and the user sees the generic "Could not create the account." even
though the app already has the right message for this situation, used at
src/chelonia/auth.ts:134. The same applies to a 409 raised by the salt-token
redemption. Since the machinery is now in place, the missing branch is cheap:

    // The publish error carries the HTTP status on `cause`.
    if (e instanceof ChelErrorUnexpectedHttpResponseCode) {
      if (e.cause === 403) throw new AuthError('Signups are disabled on this server.')
      if (e.cause === 409) throw new AuthError('That username is already taken.')
      if (e.cause === 429) {
        throw new AuthError('Too many signups from this network. Try again in a while.')
      }
    }

Low importance: the window is a narrow race and the fallback message is still
truthful, just less helpful.


Review generated using glm-5.3 via Z.AI. Comment /review to re-run.

Comment thread AGENTS.md Outdated

@corrideat corrideat left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. See comment about removing a section that's probably redundant from the README.

@akhileshthite

Copy link
Copy Markdown
Member Author

@taoeffect need your review.

@taoeffect taoeffect left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks nice! Great job @akhileshthite !

@taoeffect
taoeffect merged commit 9d535ec into feat/ts-conversion Oct 2, 2026
2 checks passed
@akhileshthite akhileshthite mentioned this pull request Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants