18 Commits
Author SHA1 Message Date
sbstp 842c4c9b0c fix ci
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
2026-08-08 16:37:07 -04:00
sbstp 58200b2bf9 add screen to view a barcode isolated 2026-08-08 16:35:54 -04:00
sbstp 35de0e1990 meal filtering feature
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline failed
2026-08-08 16:19:49 -04:00
sbstp 975cf38170 add reward card feature with barcodes 2026-08-08 15:55:18 -04:00
sbstp ab46e63bf0 try to make e2e test less flaky 2026-08-08 15:04:56 -04:00
sbstp 3f7414707a morphing to fix scroll reset issues 2026-08-08 14:38:20 -04:00
sbstp cd99cd20df optimize test pipeline 2026-08-08 14:16:33 -04:00
sbstp 8bb0471a71 create & use logo 2026-08-08 14:11:39 -04:00
sbstp f24d8aa062 vendor assets with versionning
ci/woodpecker/tag/release Pipeline was successful
2026-08-08 12:21:33 -04:00
sbstp 5233b1e6fd real-time list counts 2026-08-08 11:36:28 -04:00
sbstp ff9f679fcb proper closing of sqlite connection
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
2026-08-07 23:27:49 -04:00
sbstp a13bc17629 use memory databases for e2e tests 2026-08-07 23:20:27 -04:00
sbstp f480407927 update htmx to latest in 2.x branch
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
ci/woodpecker/tag/release Pipeline was successful
2026-08-07 22:53:42 -04:00
sbstp 9267786371 cargo fmt
ci/woodpecker/push/fmt Pipeline is pending
ci/woodpecker/push/test Pipeline is pending
ci/woodpecker/push/e2e Pipeline was canceled
2026-08-07 22:49:50 -04:00
sbstp e24f4ff7e2 archived list count 2026-08-07 22:49:31 -04:00
sbstp 56cd6e32e9 hx boost + bug fix 2026-08-07 22:46:53 -04:00
sbstp 689bd95ff0 list archive
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline failed
ci/woodpecker/push/test Pipeline was successful
2026-08-07 22:16:29 -04:00
sbstp 240d993d57 improve ux 2026-08-07 21:42:38 -04:00
31 changed files with 2219 additions and 244 deletions
-17
View File
@@ -1,17 +0,0 @@
when:
event: [push, pull_request]
steps:
e2e-build:
image: rust:1
commands:
- cargo build
e2e-test:
image: node:24
directory: e2e
commands:
- apt-get update
- apt-get install -y --no-install-recommends ca-certificates fonts-liberation libasound2 libatk-bridge2.0-0 libatk1.0-0 libcups2 libdbus-1-3 libdrm2 libgbm1 libglib2.0-0 libgtk-3-0 libnspr4 libnss3 libpango-1.0-0 libx11-6 libxcb1 libxcomposite1 libxdamage1 libxext6 libxfixes3 libxkbcommon0 libxrandr2 xdg-utils
- npm install && npx playwright install chromium
- npx playwright test
+10
View File
@@ -6,3 +6,13 @@ steps:
image: rust:1
commands:
- cargo test --all
- cargo build --all
e2e-test:
image: node:24
directory: e2e
commands:
- apt-get update
- apt-get install -y --no-install-recommends ca-certificates fonts-liberation libasound2 libatk-bridge2.0-0 libatk1.0-0 libcups2 libdbus-1-3 libdrm2 libgbm1 libglib2.0-0 libgtk-3-0 libnspr4 libnss3 libpango-1.0-0 libx11-6 libxcb1 libxcomposite1 libxdamage1 libxext6 libxfixes3 libxkbcommon0 libxrandr2 xdg-utils
- npm install && npx playwright install chromium
- npx playwright test
Generated
+7
View File
@@ -116,6 +116,12 @@ dependencies = [
"tracing",
]
[[package]]
name = "barcoders"
version = "2.0.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "a3826fb6e98ec72c0c0db8c9a40af4932d16793021027469857e84c1b50a1e8f"
[[package]]
name = "base64"
version = "0.13.1"
@@ -1777,6 +1783,7 @@ dependencies = [
"argon2",
"async-trait",
"axum",
"barcoders",
"base64 0.22.1",
"futures-util",
"hex",
+1
View File
@@ -7,6 +7,7 @@ edition = "2024"
argon2 = "0.5"
async-trait = "0.1"
axum = { version = "0.8", features = ["ws"] }
barcoders = { version = "2.0.0", features = ["svg"] }
base64 = "0.22"
futures-util = "0.3"
hex = "0.4"
+2
View File
@@ -57,6 +57,8 @@ The file is optional — if it is missing or invalid, seeding is silently skippe
- Global categories with common defaults seeded at startup and custom category creation
- Items grouped by category and assigned from the add/edit forms
- Meals with ingredients, markdown descriptions, and one-click "add meal to list"
- Rewards cards with store name and number, rendered as scannable Code 128 / Code 39 barcodes
- Single-card scan view that shows one barcode at a time and keeps the screen awake for scanning
- Server-authoritative last-write-wins updates
- Per-list WebSocket updates with server-rendered htmx fragments
- In-memory presence for members currently viewing a list
+5 -19
View File
@@ -1,13 +1,12 @@
import { test as base, expect, Page } from "@playwright/test";
import { spawn, ChildProcess } from "child_process";
import * as fs from "fs";
import * as os from "os";
import * as path from "path";
/**
* Starts a fresh Sustenance server against a unique, throwaway database on a
* unique port for each test, and tears it down afterwards. This gives every
* test a clean DB with no shared state between tests.
* Starts a fresh Sustenance server against an in-memory SQLite database on a
* unique port for each test, and tears it down afterwards. Every test gets a
* clean DB with no shared state between tests, and nothing is written to disk.
*/
export const test = base.extend<{ server: { baseURL: string }; page: Page }>({
server: [
@@ -15,10 +14,6 @@ export const test = base.extend<{ server: { baseURL: string }; page: Page }>({
const server = await startServer();
await use({ baseURL: server.baseURL });
await killTree(server.child);
// Clean up the DB files (including -wal / -shm).
for (const suffix of ["", "-wal", "-shm"]) {
fs.rmSync(server.dbPath + suffix, { force: true });
}
},
{ scope: "test", auto: true },
],
@@ -35,12 +30,6 @@ export const test = base.extend<{ server: { baseURL: string }; page: Page }>({
/** Starts a server, retrying on a fresh port if the first attempt fails to bind. */
async function startServer() {
for (let attempt = 0; attempt < 5; attempt++) {
const dbPath = path.join(
os.tmpdir(),
`sustenance-e2e-${process.pid}-${Date.now()}-${Math.random()
.toString(36)
.slice(2)}.db`,
);
const port = 20000 + Math.floor(Math.random() * 30000);
const baseURL = `http://localhost:${port}`;
@@ -50,7 +39,7 @@ async function startServer() {
{
env: {
...process.env,
DATABASE_PATH: dbPath,
DATABASE_IN_MEMORY: "1",
REGISTRATION_MODE: "open",
BIND_ADDRESS: `127.0.0.1:${port}`,
PUBLIC_BASE_URL: baseURL,
@@ -72,13 +61,10 @@ async function startServer() {
try {
await waitForServer(baseURL, child);
return { baseURL, child, dbPath };
return { baseURL, child };
} catch (error) {
// The server may have failed to bind (port collision). Clean up and retry.
await killTree(child);
for (const suffix of ["", "-wal", "-shm"]) {
fs.rmSync(dbPath + suffix, { force: true });
}
if (attempt === 4) {
throw new Error(
`server failed to start after retries; last stderr:\n${stderr}\n${error}`,
+12 -1
View File
@@ -46,12 +46,23 @@ export async function addItem(page: Page, name: string, quantity = "") {
}
/** Adds an ingredient to the current meal page. */
export async function addIngredient(page: Page, name: string, quantity = "") {
export async function addIngredient(
page: Page,
name: string,
quantity = "",
category?: string,
) {
await page.fill("#ingredient-name", name);
if (category) {
await page.selectOption("#ingredient-category", { label: category });
}
if (quantity) {
await page.fill("#ingredient-quantity", quantity);
}
await page.click("#add-ingredient-button");
// The form submit is hx-boosted (full body swap to the same URL), so wait for
// the new row to appear. This also acts as a settle point so the next action
// doesn't race the async body replacement and target a stale form.
await expect(page.locator(".ingredient-list").filter({ hasText: name })).toBeVisible();
}
+83
View File
@@ -0,0 +1,83 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin, createList, addItem } from "../helpers";
test("a user can archive a list and it moves to the archive page", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
// Archive from the list page.
await page.click('button:has-text("Archive")');
// Lands back on the lists page; the list is no longer shown.
await expect(page).toHaveURL(/\/lists/);
await expect(page.locator(".list-card").filter({ hasText: "Weekly shop" })).toHaveCount(0);
// The archived list is reachable from the archive page.
await page.goto("/archive");
await expect(page.locator(".list-card").filter({ hasText: "Weekly shop" })).toBeVisible();
});
test("the lists frame links to the archive page", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await page.goto("/lists");
await page.click('a.archive-link');
await expect(page).toHaveURL(/\/archive/);
});
test("an archived list is read-only", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await addItem(page, "Apple");
await page.click('button:has-text("Archive")');
// Open the archived list directly.
await page.goto("/archive");
await page.locator(".list-card").filter({ hasText: "Weekly shop" }).click();
await expect(page).toHaveURL(/\/lists\/\d+/);
// The item is still visible.
await expect(page.locator(".item-row").filter({ hasText: "Apple" })).toBeVisible();
// No mutation UI is present.
await expect(page.locator("#add-item-form")).toHaveCount(0);
await expect(page.locator(".item-actions-button")).toHaveCount(0);
await expect(page.locator(".check-form")).toHaveCount(0);
await expect(page.locator('button:has-text("+ Add meal")')).toHaveCount(0);
});
test("a user can restore an archived list and edit it again", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await addItem(page, "Apple");
await page.click('button:has-text("Archive")');
// Open the archived list and restore it.
await page.goto("/archive");
await page.locator(".list-card").filter({ hasText: "Weekly shop" }).click();
await page.click('button:has-text("Restore")');
// Back on the lists page, the list is active again.
await expect(page).toHaveURL(/\/lists/);
await expect(page.locator(".list-card").filter({ hasText: "Weekly shop" })).toBeVisible();
// The list is editable again.
await page.locator(".list-card").filter({ hasText: "Weekly shop" }).click();
await expect(page.locator("#add-item-form")).toBeVisible();
await addItem(page, "Banana");
await expect(page.locator(".item-row").filter({ hasText: "Banana" })).toBeVisible();
});
test("the archive page shows the list name and created date", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createList(page, "Weekly shop");
await page.click('button:has-text("Archive")');
await page.goto("/archive");
const card = page.locator(".list-card").filter({ hasText: "Weekly shop" });
await expect(card).toBeVisible();
// The card shows a created date (e.g. "Created 7 Aug 2026").
await expect(card.locator("small")).toContainText("Created");
});
+57
View File
@@ -0,0 +1,57 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin, createList, createMeal } from "../helpers";
test("the meals page filters by name as you type", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Spaghetti Bolognese", "");
await createMeal(page, "Chicken Curry", "");
await createMeal(page, "Pancakes", "");
await page.goto("/meals");
await expect(page.locator(".list-card").filter({ hasText: "Spaghetti Bolognese" })).toBeVisible();
await expect(page.locator(".list-card").filter({ hasText: "Chicken Curry" })).toBeVisible();
await expect(page.locator(".list-card").filter({ hasText: "Pancakes" })).toBeVisible();
// Type a query; only matching meals remain.
await page.fill("#meal-search", "chicken");
await expect(page.locator(".list-card").filter({ hasText: "Chicken Curry" })).toBeVisible();
await expect(page.locator(".list-card").filter({ hasText: "Spaghetti Bolognese" })).toHaveCount(0);
await expect(page.locator(".list-card").filter({ hasText: "Pancakes" })).toHaveCount(0);
// Clearing the search restores all meals.
await page.fill("#meal-search", "");
await expect(page.locator(".list-card").filter({ hasText: "Spaghetti Bolognese" })).toBeVisible();
await expect(page.locator(".list-card").filter({ hasText: "Pancakes" })).toBeVisible();
});
test("the meals page shows an empty state when nothing matches", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Spaghetti Bolognese", "");
await page.goto("/meals");
await page.fill("#meal-search", "zzzz");
await expect(page.locator(".meal-filter-empty")).toBeVisible();
await expect(page.locator(".list-card")).toHaveCount(0);
});
test("the add-meal picker filters meals as you type", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Spaghetti Bolognese", "");
await createMeal(page, "Chicken Curry", "");
await createList(page, "Weekly shop");
await page.click(".add-meal-button");
const picker = page.locator(".meal-picker-backdrop");
await expect(picker).toBeVisible();
await expect(picker.locator(".meal-picker-button").filter({ hasText: "Spaghetti Bolognese" })).toBeVisible();
await expect(picker.locator(".meal-picker-button").filter({ hasText: "Chicken Curry" })).toBeVisible();
await picker.locator(".meal-filter").fill("curry");
await expect(picker.locator(".meal-picker-button").filter({ hasText: "Chicken Curry" })).toBeVisible();
await expect(picker.locator(".meal-picker-button").filter({ hasText: "Spaghetti Bolognese" })).toHaveCount(0);
// The search box keeps focus and the modal stays open.
await expect(picker.locator(".meal-filter")).toBeFocused();
await expect(picker).toBeVisible();
});
+2 -3
View File
@@ -32,6 +32,7 @@ test("a user can delete a meal", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Spaghetti Bolognese", "");
page.on("dialog", (dialog) => dialog.accept());
await page.click('button:has-text("Delete")');
await expect(page).toHaveURL(/\/meals$/);
await expect(page.locator(".list-card").filter({ hasText: "Spaghetti Bolognese" })).toHaveCount(0);
@@ -76,9 +77,7 @@ test("ingredients are grouped under their categories", async ({ page }) => {
await createMeal(page, "Spaghetti Bolognese", "");
// Add an ingredient in the default "Produce" category.
await page.fill("#ingredient-name", "Tomato");
await page.selectOption("#ingredient-category", { label: "Produce" });
await page.click("#add-ingredient-button");
await addIngredient(page, "Tomato", "", "Produce");
// Add one without a category.
await addIngredient(page, "Penne");
+169
View File
@@ -0,0 +1,169 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin } from "../helpers";
/** Navigates to the rewards cards page. */
async function gotoRewards(page: import("@playwright/test").Page) {
await page.goto("/rewards");
await expect(page.locator("h1")).toContainText("Rewards cards");
}
/**
* Adds a rewards card and lands back on the /rewards page with it rendered.
*/
async function addCard(
page: import("@playwright/test").Page,
storeName: string,
number: string,
symbology?: string,
) {
await page.fill("#store-name", storeName);
await page.fill("#card-number", number);
if (symbology) {
await page.selectOption("#symbology", symbology);
}
await page.click('button:has-text("Add card")');
await expect(page).toHaveURL(/\/rewards$/);
const card = page.locator(".rewards-card").filter({ hasText: storeName });
await expect(card).toBeVisible();
return card;
}
test("the rewards page shows an empty state before any cards are added", async ({
page,
}) => {
await registerAndLogin(page, "alice@example.com");
await gotoRewards(page);
await expect(page.locator(".empty-state")).toContainText("No rewards cards yet");
await expect(page.locator(".rewards-card")).toHaveCount(0);
});
test("the Rewards link is available in the site navigation", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
const nav = page.locator(".site-nav");
await expect(nav.locator('a[href="/rewards"]')).toHaveText("Rewards");
});
test("a user can add a rewards card and see its barcode", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await gotoRewards(page);
const card = await addCard(page, "Kroger", "606171584511340224537");
// The card renders an inline SVG barcode and the store's card number.
await expect(card.locator(".rewards-barcode svg")).toBeVisible();
await expect(card.locator(".rewards-number")).toHaveText("606171584511340224537");
// The barcode should be included via the embedded SVG (Code 128 set B→C mix),
// not rendered client-side from scratch by an image.
const svg = card.locator(".rewards-barcode svg");
await expect(svg).toHaveAttribute("viewBox", /\d+ \d+/);
});
test("a user can add a card as Code 39 and see its barcode", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await gotoRewards(page);
const card = await addCard(page, "Safeway", "ABC123", "code39");
await expect(card.locator(".rewards-barcode svg")).toBeVisible();
});
test("multiple rewards cards are each rendered with their own barcode", async ({
page,
}) => {
await registerAndLogin(page, "alice@example.com");
await gotoRewards(page);
await addCard(page, "Kroger", "606171584511340224537");
await addCard(page, "Safeway", "012345678901");
await expect(page.locator(".rewards-card")).toHaveCount(2);
await expect(page.locator(".rewards-card").filter({ hasText: "Kroger" })).toBeVisible();
await expect(page.locator(".rewards-card").filter({ hasText: "Safeway" })).toBeVisible();
});
test("removing a rewards card prompts for confirmation and deletes on accept", async ({
page,
}) => {
await registerAndLogin(page, "alice@example.com");
await gotoRewards(page);
await addCard(page, "Kroger", "606171584511340224537");
await expect(page).toHaveURL(/\/rewards$/);
await expect(page.locator(".rewards-card")).toHaveCount(1);
page.on("dialog", (dialog) => dialog.accept());
await page.click('button:has-text("Remove")');
// The card is deleted and the empty state returns.
await expect(page.locator(".rewards-card")).toHaveCount(0);
await expect(page.locator(".empty-state")).toContainText("No rewards cards yet");
});
test("cancelling the remove confirmation keeps the rewards card", async ({
page,
}) => {
await registerAndLogin(page, "alice@example.com");
await gotoRewards(page);
await addCard(page, "Kroger", "606171584511340224537");
await expect(page.locator(".rewards-card")).toHaveCount(1);
page.on("dialog", (dialog) => dialog.dismiss());
await page.click('button:has-text("Remove")');
// The card must remain after cancelling.
await expect(page.locator(".rewards-card")).toHaveCount(1);
await expect(page.locator(".rewards-card").filter({ hasText: "Kroger" })).toBeVisible();
});
test("a user can open a single-card scan view with only one barcode", async ({
page,
}) => {
await registerAndLogin(page, "alice@example.com");
await gotoRewards(page);
await addCard(page, "Kroger", "606171584511340224537");
await addCard(page, "Safeway", "012345678901");
// Click the Kroger card's barcode to open its focused scan view.
await page
.locator(".rewards-card")
.filter({ hasText: "Kroger" })
.locator(".rewards-card-link")
.click();
await expect(page).toHaveURL(/\/rewards\/\d+/);
// Only one barcode is rendered on the scan page.
await expect(page.locator(".scan-barcode svg")).toHaveCount(1);
await expect(page.locator(".scan-store")).toHaveText("Kroger");
await expect(page.locator(".scan-card .rewards-number")).toHaveText(
"606171584511340224537",
);
// The wake-lock script is loaded on the scan page.
await expect(page.locator('script[src*="rewards.js"]')).toHaveCount(1);
// Back link returns to the list.
await page.click('.scan-back');
await expect(page).toHaveURL(/\/rewards$/);
});
test("a scan view for another user's card is not accessible", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await gotoRewards(page);
await addCard(page, "Kroger", "606171584511340224537");
// Grab the card id from the URL of the scan view.
await page
.locator(".rewards-card-link")
.click();
const url = page.url();
const cardId = url.split("/").pop();
// Sign out and sign in as a different user.
await page.click('button:has-text("Sign out")');
await registerAndLogin(page, "bob@example.com");
// Bob cannot view Alice's card.
await page.goto(`/rewards/${cardId}`);
await expect(page.locator(".scan-barcode svg")).toHaveCount(0);
});
+13
View File
@@ -20,12 +20,25 @@ test("a list updates live for another user via websocket", async ({ page, browse
// Give the websocket connections a moment to establish.
await page.waitForTimeout(500);
// Both start with an empty list.
await expect(pageB.locator("#list-meta")).toHaveText("0 items left out of 0");
// User A adds an item.
await addItem(page, "Apple", "2");
// It should appear on User B's page without any reload.
await expect(pageB.locator(".item-row").filter({ hasText: "Apple" })).toBeVisible();
await expect(pageB.locator(".item-row").filter({ hasText: "Apple" }).locator(".item-qty")).toHaveText("(2)");
// The left/total count should also update live for User B.
await expect(pageB.locator("#list-meta")).toHaveText("1 items left out of 1");
// User A removes the item.
await page.locator(".item-actions-button").first().click();
await page.locator("[id^='item-edit-delete']").click();
// The item and the count should update live on User B's page.
await expect(pageB.locator(".item-row").filter({ hasText: "Apple" })).toHaveCount(0);
await expect(pageB.locator("#list-meta")).toHaveText("0 items left out of 0");
await contextB.close();
});
@@ -0,0 +1 @@
ALTER TABLE lists ADD COLUMN archived_at INTEGER;
@@ -0,0 +1,10 @@
CREATE TABLE rewards_cards (
id INTEGER PRIMARY KEY AUTOINCREMENT,
user_id INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
store_name TEXT NOT NULL,
number TEXT NOT NULL,
symbology TEXT NOT NULL DEFAULT 'code128',
created_at INTEGER NOT NULL
);
CREATE INDEX rewards_cards_user_idx ON rewards_cards(user_id);
+85
View File
@@ -0,0 +1,85 @@
use std::collections::HashMap;
use std::sync::LazyLock;
use sha2::{Digest, Sha256};
/// A single static asset: its embedded bytes and a content hash used to
/// version its URL.
pub struct StaticAsset {
pub data: &'static [u8],
pub hash: String,
}
/// A registry of the app's static assets, keyed by filename. Each asset's
/// content hash is computed once on first use and cached, so the versioned URL
/// changes automatically whenever the underlying file changes.
pub struct StaticAssetStore {
assets: HashMap<&'static str, StaticAsset>,
}
impl StaticAssetStore {
fn new(entries: &[(&'static str, &'static [u8])]) -> Self {
let assets = entries
.iter()
.map(|(name, data)| {
let hash = content_hash(data);
(*name, StaticAsset { data, hash })
})
.collect();
Self { assets }
}
/// Looks up an asset by its filename (e.g. `"style.css"`).
pub fn get(&self, name: &str) -> Option<&StaticAsset> {
self.assets.get(name)
}
/// Returns the versioned URL for an asset, e.g. `/static/style.css?v=<hash>`.
pub fn url(&self, name: &str) -> Option<String> {
self.assets
.get(name)
.map(|asset| format!("/static/{name}?v={}", asset.hash))
}
}
fn content_hash(data: &[u8]) -> String {
let mut hasher = Sha256::new();
hasher.update(data);
hex::encode(hasher.finalize())
}
/// Constructs a `StaticAssetStore` from `name => path` pairs, embedding each
/// file's bytes at compile time via `include_bytes!`.
macro_rules! static_assets {
($($name:literal => $path:literal),* $(,)?) => {
StaticAssetStore::new(&[
$(($name, include_bytes!($path))),*
])
};
}
/// The app's static assets, loaded once on first use.
pub static STORE: LazyLock<StaticAssetStore> = LazyLock::new(|| {
static_assets! {
"style.css" => "../static/style.css",
"passkey-login.js" => "../static/passkey-login.js",
"passkey-register.js" => "../static/passkey-register.js",
"password-toggle.js" => "../static/password-toggle.js",
"rewards.js" => "../static/rewards.js",
"htmx.min.js" => "../static/htmx.min.js",
"idiomorph-ext.min.js" => "../static/idiomorph-ext.min.js",
"htmx-ws.min.js" => "../static/htmx-ws.min.js",
"favicon.ico" => "../static/favicon.ico",
"favicon-32x32.png" => "../static/favicon-32x32.png",
"apple-touch-icon.png" => "../static/apple-touch-icon.png",
"logo.svg" => "../static/logo.svg",
}
});
/// Returns the versioned URL for a known asset, panicking if the name isn't
/// registered (a programmer error, since these are compile-time constants).
pub fn url(name: &str) -> String {
STORE
.url(name)
.unwrap_or_else(|| panic!("unknown static asset: {name}"))
}
+20
View File
@@ -48,6 +48,10 @@ pub struct GroceryList {
pub id: i64,
pub name: String,
pub revision: i64,
/// Unix timestamp of when the list was created.
pub created_at: i64,
/// Unix timestamp of when the list was archived; `None` when active.
pub archived_at: Option<i64>,
}
#[derive(Clone, Debug)]
@@ -109,3 +113,19 @@ pub struct PresenceUser {
pub user_id: i64,
pub display_name: String,
}
/// A stored rewards-card number that can be shown as a scannable barcode.
#[derive(Clone, Debug)]
pub struct RewardsCard {
pub id: i64,
/// The owner of this card.
#[allow(dead_code)]
pub user_id: i64,
pub store_name: String,
pub number: String,
/// Symbology used to render the barcode (e.g. "code128", "code39").
pub symbology: String,
/// When the card was added.
#[allow(dead_code)]
pub created_at: i64,
}
+226 -25
View File
@@ -20,25 +20,22 @@ use thiserror::Error;
use tower_http::trace::{DefaultMakeSpan, DefaultOnResponse, TraceLayer};
use tracing::{Level, error, warn};
use crate::assets;
use crate::domain::{DomainError, SessionUser};
use crate::ports::{HubEvent, RealtimeNotifier};
use crate::services::{AuthService, InvitationService, ListService, MealService};
use crate::services::{
AuthService, InvitationService, ListService, MealService, RewardsCardService,
};
use crate::views;
use crate::webauthn::WebAuthnService;
/// The contents of `static/`, embedded into the binary at compile time so the
/// app can be shipped as a single executable without a separate static directory.
const STYLE_CSS: &[u8] = include_bytes!("../static/style.css");
const PASSKEY_LOGIN_JS: &[u8] = include_bytes!("../static/passkey-login.js");
const PASSKEY_REGISTER_JS: &[u8] = include_bytes!("../static/passkey-register.js");
const PASSWORD_TOGGLE_JS: &[u8] = include_bytes!("../static/password-toggle.js");
#[derive(Clone)]
pub struct AppState {
pub auth: Arc<AuthService>,
pub lists: Arc<ListService>,
pub meals: Arc<MealService>,
pub invitations: Arc<InvitationService>,
pub rewards_cards: Arc<RewardsCardService>,
pub webauthn: Arc<WebAuthnService>,
pub realtime: Arc<dyn RealtimeNotifier>,
pub cookie_secure: bool,
@@ -53,6 +50,8 @@ pub enum AppError {
BadRequest(String),
#[error("not found")]
NotFound,
#[error("list is archived")]
Archived,
}
impl IntoResponse for AppError {
@@ -72,6 +71,10 @@ impl IntoResponse for AppError {
StatusCode::NOT_FOUND,
views::error_page("404", "That page could not be found."),
),
AppError::Archived => status_html_response(
StatusCode::CONFLICT,
views::error_page("409", "This list is archived and cannot be modified."),
),
}
}
}
@@ -96,7 +99,10 @@ pub fn build_router(state: AppState) -> Router {
)
.route("/account/password", post(change_password))
.route("/lists", get(lists_page).post(create_list))
.route("/archive", get(archive_page))
.route("/lists/{list_id}", get(list_page))
.route("/lists/{list_id}/archive", post(archive_list))
.route("/lists/{list_id}/unarchive", post(unarchive_list))
.route("/lists/{list_id}/items", post(add_item))
.route("/lists/{list_id}/items/{item_id}/check", post(check_item))
.route("/lists/{list_id}/items/{item_id}/edit", post(edit_item))
@@ -127,6 +133,9 @@ pub fn build_router(state: AppState) -> Router {
"/lists/{list_id}/meals/{list_meal_id}/remove",
post(remove_meal_from_list),
)
.route("/rewards", get(rewards_page).post(create_rewards_card))
.route("/rewards/{card_id}", get(rewards_scan_page))
.route("/rewards/{card_id}/delete", post(delete_rewards_card))
.route("/lists/{list_id}/stream", get(list_stream))
.route("/invite/{token}", get(invitation_page))
.route("/invite/{token}/accept", post(accept_invitation))
@@ -258,6 +267,14 @@ struct CategoryForm {
csrf: String,
}
#[derive(Debug, Deserialize)]
struct RewardsCardForm {
store_name: String,
number: String,
symbology: String,
csrf: String,
}
#[derive(Debug, Deserialize)]
struct PasskeyRegisterStartForm {
csrf: String,
@@ -324,6 +341,7 @@ struct AddMealForm {
#[derive(Debug, Deserialize)]
struct MealPickerQuery {
picker: Option<i64>,
q: Option<String>,
}
async fn home() -> Redirect {
@@ -331,15 +349,27 @@ async fn home() -> Redirect {
}
/// Serves a file embedded in the binary from the `static/` folder.
///
/// Every asset is served with an immutable, long-lived cache header. Because
/// the HTML references each asset under a URL that is versioned by its content
/// hash, a changed file gets a new URL and the cache is never stale.
async fn static_asset(Path(path): Path<String>) -> Response {
let (mime, data) = match path.as_str() {
"style.css" => ("text/css", STYLE_CSS),
"passkey-login.js" => ("application/javascript", PASSKEY_LOGIN_JS),
"passkey-register.js" => ("application/javascript", PASSKEY_REGISTER_JS),
"password-toggle.js" => ("application/javascript", PASSWORD_TOGGLE_JS),
_ => return StatusCode::NOT_FOUND.into_response(),
let Some(asset) = assets::STORE.get(&path) else {
return StatusCode::NOT_FOUND.into_response();
};
([(header::CONTENT_TYPE, mime)], data).into_response()
let mime = match path.rsplit('.').next() {
Some("css") => "text/css",
Some("ico") => "image/x-icon",
Some("png") => "image/png",
Some("svg") => "image/svg+xml",
_ => "application/javascript",
};
let mut response = ([(header::CONTENT_TYPE, mime)], asset.data).into_response();
response.headers_mut().insert(
header::CACHE_CONTROL,
HeaderValue::from_static("public, max-age=31536000, immutable"),
);
response
}
async fn log_response_status(request: Request, next: Next) -> Response {
@@ -594,15 +624,28 @@ async fn lists_page(
user: CurrentUser,
) -> Result<Response, AppError> {
let lists = state.lists.list_summaries().await?;
let archived = state.lists.list_archived_summaries().await?;
let categories = state.lists.categories().await?;
Ok(html_response(views::lists_page(
&user.session.user,
&lists,
archived.len(),
&categories,
&user.session.csrf_token,
)))
}
async fn archive_page(
State(state): State<AppState>,
user: CurrentUser,
) -> Result<Response, AppError> {
let archived_lists = state.lists.list_archived_summaries().await?;
Ok(html_response(views::archive_page(
&user.session.user,
&archived_lists,
)))
}
async fn create_list(
State(state): State<AppState>,
user: CurrentUser,
@@ -640,6 +683,30 @@ async fn list_page(
)))
}
async fn archive_list(
State(state): State<AppState>,
user: CurrentUser,
Path(list_id): Path<i64>,
LoggedForm(form): LoggedForm<CsrfForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
require_list(&state, list_id).await?;
state.lists.archive_list(list_id).await?;
Ok(Redirect::to("/lists").into_response())
}
async fn unarchive_list(
State(state): State<AppState>,
user: CurrentUser,
Path(list_id): Path<i64>,
LoggedForm(form): LoggedForm<CsrfForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
require_list(&state, list_id).await?;
state.lists.unarchive_list(list_id).await?;
Ok(Redirect::to("/lists").into_response())
}
async fn add_item(
State(state): State<AppState>,
user: CurrentUser,
@@ -647,7 +714,7 @@ async fn add_item(
LoggedForm(form): LoggedForm<ItemForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
require_list(&state, list_id).await?;
require_mutable_list(&state, list_id).await?;
let name = form.name.trim().to_owned();
let quantity = form.quantity.trim().to_owned();
let note = form.note.trim().to_owned();
@@ -671,7 +738,7 @@ async fn check_item(
LoggedForm(form): LoggedForm<CheckForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
require_list(&state, list_id).await?;
require_mutable_list(&state, list_id).await?;
let checked = match form.checked.as_str() {
"1" | "true" => true,
"0" | "false" => false,
@@ -691,7 +758,7 @@ async fn edit_item(
LoggedForm(form): LoggedForm<ItemForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
require_list(&state, list_id).await?;
require_mutable_list(&state, list_id).await?;
let name = form.name.trim().to_owned();
if name.is_empty() || name.chars().count() > 120 {
return Err(AppError::BadRequest(
@@ -719,7 +786,7 @@ async fn delete_item(
LoggedForm(form): LoggedForm<CsrfForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
require_list(&state, list_id).await?;
require_mutable_list(&state, list_id).await?;
state.lists.delete_item(list_id, item_id).await?;
list_fragment_response(&state, &user, list_id).await
}
@@ -767,19 +834,131 @@ async fn delete_meal_category(
Ok(Redirect::to("/meals").into_response())
}
async fn rewards_page(
State(state): State<AppState>,
user: CurrentUser,
) -> Result<Response, AppError> {
let cards = state.rewards_cards.list_cards(user.session.user.id).await?;
Ok(html_response(views::rewards_page(
&user.session.user,
&cards,
&user.session.csrf_token,
)))
}
async fn rewards_scan_page(
State(state): State<AppState>,
user: CurrentUser,
Path(card_id): Path<i64>,
) -> Result<Response, AppError> {
let card = state
.rewards_cards
.get_card(user.session.user.id, card_id)
.await?
.ok_or(AppError::NotFound)?;
Ok(html_response(views::rewards_scan_page(
&user.session.user,
&card,
)))
}
async fn create_rewards_card(
State(state): State<AppState>,
user: CurrentUser,
LoggedForm(form): LoggedForm<RewardsCardForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
let store_name = form.store_name.trim().to_owned();
let number = form.number.trim().to_owned();
let symbology = normalize_symbology(&form.symbology);
if store_name.is_empty() || store_name.chars().count() > 60 {
return Err(AppError::BadRequest(
"Store names must be between 1 and 60 characters.".into(),
));
}
if number.is_empty() || number.chars().count() > 80 {
return Err(AppError::BadRequest(
"Card numbers must be between 1 and 80 characters.".into(),
));
}
state
.rewards_cards
.create_card(user.session.user.id, store_name, number, symbology)
.await?;
Ok(Redirect::to("/rewards").into_response())
}
async fn delete_rewards_card(
State(state): State<AppState>,
user: CurrentUser,
Path(card_id): Path<i64>,
LoggedForm(form): LoggedForm<CsrfForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
state
.rewards_cards
.delete_card(user.session.user.id, card_id)
.await?;
Ok(Redirect::to("/rewards").into_response())
}
/// Normalizes a submitted symbology value to a known barcode type, falling
/// back to Code 128 for unknown or empty values.
fn normalize_symbology(value: &str) -> String {
match value.trim().to_ascii_lowercase().as_str() {
"code39" => "code39".to_owned(),
_ => "code128".to_owned(),
}
}
async fn meals_page(
State(state): State<AppState>,
user: CurrentUser,
Query(query): Query<MealPickerQuery>,
headers: HeaderMap,
) -> Result<Response, AppError> {
let meals = state.meals.list_meals().await?;
let q = query.q.clone().unwrap_or_default();
let meals = state.meals.list_meals(&q).await?;
let meal_categories = state.meals.list_meal_categories().await?;
let is_htmx = headers
.get("hx-request")
.and_then(|value| value.to_str().ok())
.is_some_and(|value| value == "true");
// A boosted navigation (e.g. the category form's POST redirect) also sends
// `HX-Request: true`, but must render the full page, not just the results
// fragment. Only a live search (an `hx-get` on the filter box) swaps the
// fragment. htmx marks boosted requests with `HX-Boosted: true`.
let is_boosted = headers
.get("hx-boosted")
.and_then(|value| value.to_str().ok())
.is_some_and(|value| value == "true");
if let Some(list_id) = query.picker {
return Ok(html_response(views::meal_picker(
if query.q.is_some() {
// Live search inside the picker: swap only the grouped rows, keeping
// the modal and search box focused. The initial picker load has no
// `q`, so it falls through to the full modal below.
return Ok(html_response(views::meal_picker_results(
&meals,
&meal_categories,
list_id,
&user.session.csrf_token,
)));
}
let picker = views::meal_picker(
&meals,
&meal_categories,
list_id,
&user.session.csrf_token,
&q,
);
return Ok(html_response(picker));
}
if is_htmx && !is_boosted {
// Live search on the meals page: swap only the grouped results.
return Ok(html_response(views::meal_results(
&meals,
&meal_categories,
&q,
)));
}
Ok(html_response(views::meals_page(
@@ -787,6 +966,7 @@ async fn meals_page(
&meals,
&meal_categories,
&user.session.csrf_token,
&q,
)))
}
@@ -957,7 +1137,7 @@ async fn add_meal_to_list(
LoggedForm(form): LoggedForm<AddMealForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
require_list(&state, list_id).await?;
require_mutable_list(&state, list_id).await?;
state.meals.add_meal_to_list(form.meal_id, list_id).await?;
list_fragment_response(&state, &user, list_id).await
}
@@ -969,7 +1149,7 @@ async fn remove_meal_from_list(
LoggedForm(form): LoggedForm<CsrfForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
require_list(&state, list_id).await?;
require_mutable_list(&state, list_id).await?;
state
.meals
.remove_meal_from_list(list_id, list_meal_id)
@@ -1181,6 +1361,7 @@ async fn list_fragment_response(
let items = state.lists.items(list_id).await?;
let categories = state.lists.categories().await?;
let list_meals = state.meals.list_meals_on_list(list_id).await?;
let editable = access.archived_at.is_none();
Ok(html_response(PreEscaped(
views::list_items_fragment(
&access,
@@ -1188,10 +1369,17 @@ async fn list_fragment_response(
&categories,
&user.session.csrf_token,
false,
editable,
)
.into_string()
+ &views::list_meals_panel(&list_meals, list_id, &user.session.csrf_token, true)
.into_string(),
+ &views::list_meals_panel(
&list_meals,
list_id,
&user.session.csrf_token,
true,
editable,
)
.into_string(),
)))
}
@@ -1206,6 +1394,19 @@ async fn require_list(
.ok_or(AppError::NotFound)
}
/// Like [`require_list`], but also rejects archived lists so they stay
/// immutable until restored.
async fn require_mutable_list(
state: &AppState,
list_id: i64,
) -> Result<crate::domain::GroceryList, AppError> {
let list = require_list(state, list_id).await?;
if list.archived_at.is_some() {
return Err(AppError::Archived);
}
Ok(list)
}
async fn optional_user(
state: &AppState,
headers: &HeaderMap,
+25 -4
View File
@@ -1,3 +1,4 @@
mod assets;
mod domain;
mod http;
mod hub;
@@ -21,15 +22,18 @@ use crate::hub::InMemoryHub;
use crate::ports::{
CategoryRepository, InvitationRepository, ItemRepository, ListMealRepository, ListRepository,
MealCategoryRepository, MealIngredientRepository, MealRepository, PasskeyRepository,
PasswordHasher, RealtimeNotifier, SessionRepository, TokenGenerator, UserRepository,
PasswordHasher, RealtimeNotifier, RewardsCardRepository, SessionRepository, TokenGenerator,
UserRepository,
};
use crate::security::{Argon2PasswordHasher, RandomTokenGenerator};
use crate::services::{AuthService, InvitationService, ListService, MealService, RegistrationMode};
use crate::services::{
AuthService, InvitationService, ListService, MealService, RegistrationMode, RewardsCardService,
};
use crate::sqlite::{
SqliteCategoryRepository, SqliteDatabase, SqliteInvitationRepository, SqliteItemRepository,
SqliteListMealRepository, SqliteListRepository, SqliteMealCategoryRepository,
SqliteMealIngredientRepository, SqliteMealRepository, SqlitePasskeyRepository,
SqliteSessionRepository, SqliteUserRepository,
SqliteRewardsCardRepository, SqliteSessionRepository, SqliteUserRepository,
};
use crate::webauthn::{AppWebauthnConfig, WebAuthnService};
@@ -42,6 +46,9 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
.init();
let database_path = env::var("DATABASE_PATH").unwrap_or_else(|_| "sustenance.db".into());
let database_in_memory = env::var("DATABASE_IN_MEMORY")
.map(|value| value == "1" || value.eq_ignore_ascii_case("true"))
.unwrap_or(false);
let bind_address = env::var("BIND_ADDRESS").unwrap_or_else(|_| "127.0.0.1:3000".into());
// For loopback hosts, advertise `localhost` so WebAuthn works locally (browsers
// reject IP addresses as RP IDs). Access the app via http://localhost:PORT.
@@ -69,7 +76,11 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
};
// Build the adapters (ports) and wire them into application services.
let db = SqliteDatabase::open(&database_path).await?;
let db = if database_in_memory {
SqliteDatabase::open_in_memory().await?
} else {
SqliteDatabase::open(&database_path).await?
};
let users: Arc<dyn UserRepository> = Arc::new(SqliteUserRepository);
let sessions: Arc<dyn SessionRepository> = Arc::new(SqliteSessionRepository);
let lists: Arc<dyn ListRepository> = Arc::new(SqliteListRepository);
@@ -82,6 +93,7 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
let meal_categories: Arc<dyn MealCategoryRepository> = Arc::new(SqliteMealCategoryRepository);
let invitations: Arc<dyn InvitationRepository> = Arc::new(SqliteInvitationRepository);
let passkeys: Arc<dyn PasskeyRepository> = Arc::new(SqlitePasskeyRepository);
let rewards_cards: Arc<dyn RewardsCardRepository> = Arc::new(SqliteRewardsCardRepository);
let hasher: Arc<dyn PasswordHasher> = Arc::new(Argon2PasswordHasher);
let tokens: Arc<dyn TokenGenerator> = Arc::new(RandomTokenGenerator);
let realtime: Arc<dyn RealtimeNotifier> = Arc::new(InMemoryHub::default());
@@ -106,6 +118,10 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
Arc::clone(&invitations),
Arc::clone(&tokens),
));
let rewards_cards_service = Arc::new(RewardsCardService::new(
db.clone(),
Arc::clone(&rewards_cards),
));
let meals_service = Arc::new(MealService::new(
db.clone(),
Arc::clone(&meals),
@@ -149,6 +165,7 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
lists: lists_service,
meals: meals_service,
invitations: invitations_service,
rewards_cards: rewards_cards_service,
webauthn: webauthn_service,
realtime,
cookie_secure,
@@ -163,6 +180,10 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
.with_graceful_shutdown(shutdown_signal())
.await?;
info!("shutdown complete; closing database");
// Explicitly close the pool so SQLite can checkpoint and remove the
// WAL/SHM sidecar files. Without this, the pool's background close task
// races with process exit and the sidecars can be left behind.
db.close().await;
Ok(())
}
+42 -2
View File
@@ -3,7 +3,7 @@ use sqlx::SqliteConnection;
use crate::domain::{
Category, DomainResult, GroceryList, Item, ListMeal, Meal, MealCategory, MealIngredient,
Passkey, PresenceUser, SessionUser, User,
Passkey, PresenceUser, RewardsCard, SessionUser, User,
};
/// Repositories take `&mut SqliteConnection` (which a `Transaction` derefs to),
@@ -88,6 +88,10 @@ pub trait SessionRepository: Send + Sync {
#[async_trait]
pub trait ListRepository: Send + Sync {
async fn list_summaries(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<GroceryList>>;
async fn list_archived_summaries(
&self,
txn: &mut SqliteConnection,
) -> DomainResult<Vec<GroceryList>>;
async fn create_list(
&self,
txn: &mut SqliteConnection,
@@ -98,6 +102,12 @@ pub trait ListRepository: Send + Sync {
txn: &mut SqliteConnection,
list_id: i64,
) -> DomainResult<Option<GroceryList>>;
async fn set_archived(
&self,
txn: &mut SqliteConnection,
list_id: i64,
archived: bool,
) -> DomainResult<()>;
}
#[async_trait]
@@ -228,7 +238,7 @@ pub trait MealRepository: Send + Sync {
txn: &mut SqliteConnection,
meal_id: i64,
) -> DomainResult<Option<Meal>>;
async fn list_meals(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<Meal>>;
async fn list_meals(&self, txn: &mut SqliteConnection, query: &str) -> DomainResult<Vec<Meal>>;
async fn update_meal(
&self,
txn: &mut SqliteConnection,
@@ -304,3 +314,33 @@ pub enum HubEvent {
ListChanged { list_id: i64, revision: i64 },
PresenceChanged { list_id: i64 },
}
/// Stores and retrieves a user's rewards cards.
#[async_trait]
pub trait RewardsCardRepository: Send + Sync {
async fn list_cards(
&self,
txn: &mut SqliteConnection,
user_id: i64,
) -> DomainResult<Vec<RewardsCard>>;
async fn get_card(
&self,
txn: &mut SqliteConnection,
user_id: i64,
card_id: i64,
) -> DomainResult<Option<RewardsCard>>;
async fn create_card(
&self,
txn: &mut SqliteConnection,
user_id: i64,
store_name: String,
number: String,
symbology: String,
) -> DomainResult<RewardsCard>;
async fn delete_card(
&self,
txn: &mut SqliteConnection,
user_id: i64,
card_id: i64,
) -> DomainResult<()>;
}
+78 -4
View File
@@ -1,12 +1,13 @@
use std::sync::Arc;
use crate::domain::{
DomainError, DomainResult, GroceryList, Item, ListMeal, Meal, MealCategory, SessionUser, User,
DomainError, DomainResult, GroceryList, Item, ListMeal, Meal, MealCategory, RewardsCard,
SessionUser, User,
};
use crate::ports::{
CategoryRepository, InvitationRepository, ItemRepository, ListMealRepository, ListRepository,
MealCategoryRepository, MealIngredientRepository, MealRepository, NewItem, PasswordHasher,
RealtimeNotifier, SessionRepository, TokenGenerator, UserRepository,
RealtimeNotifier, RewardsCardRepository, SessionRepository, TokenGenerator, UserRepository,
};
use crate::sqlite::SqliteDatabase;
@@ -199,6 +200,13 @@ impl ListService {
.await
}
pub async fn list_archived_summaries(&self) -> DomainResult<Vec<GroceryList>> {
let lists = Arc::clone(&self.lists);
self.db
.run(move |txn| Box::pin(async move { lists.list_archived_summaries(txn).await }))
.await
}
pub async fn create_list(&self, name: String) -> DomainResult<GroceryList> {
let lists = Arc::clone(&self.lists);
self.db
@@ -213,6 +221,20 @@ impl ListService {
.await
}
pub async fn archive_list(&self, list_id: i64) -> DomainResult<()> {
let lists = Arc::clone(&self.lists);
self.db
.run(move |txn| Box::pin(async move { lists.set_archived(txn, list_id, true).await }))
.await
}
pub async fn unarchive_list(&self, list_id: i64) -> DomainResult<()> {
let lists = Arc::clone(&self.lists);
self.db
.run(move |txn| Box::pin(async move { lists.set_archived(txn, list_id, false).await }))
.await
}
pub async fn items(&self, list_id: i64) -> DomainResult<Vec<Item>> {
let items = Arc::clone(&self.items);
self.db
@@ -368,10 +390,11 @@ impl MealService {
.await
}
pub async fn list_meals(&self) -> DomainResult<Vec<Meal>> {
pub async fn list_meals(&self, query: &str) -> DomainResult<Vec<Meal>> {
let meals = Arc::clone(&self.meals);
let query = query.to_owned();
self.db
.run(move |txn| Box::pin(async move { meals.list_meals(txn).await }))
.run(move |txn| Box::pin(async move { meals.list_meals(txn, &query).await }))
.await
}
@@ -607,3 +630,54 @@ impl InvitationService {
.await
}
}
pub struct RewardsCardService {
db: SqliteDatabase,
cards: Arc<dyn RewardsCardRepository>,
}
impl RewardsCardService {
pub fn new(db: SqliteDatabase, cards: Arc<dyn RewardsCardRepository>) -> Self {
Self { db, cards }
}
pub async fn list_cards(&self, user_id: i64) -> DomainResult<Vec<RewardsCard>> {
let cards = Arc::clone(&self.cards);
self.db
.run(move |txn| Box::pin(async move { cards.list_cards(txn, user_id).await }))
.await
}
pub async fn get_card(&self, user_id: i64, card_id: i64) -> DomainResult<Option<RewardsCard>> {
let cards = Arc::clone(&self.cards);
self.db
.run(move |txn| Box::pin(async move { cards.get_card(txn, user_id, card_id).await }))
.await
}
pub async fn create_card(
&self,
user_id: i64,
store_name: String,
number: String,
symbology: String,
) -> DomainResult<RewardsCard> {
let cards = Arc::clone(&self.cards);
self.db
.run(move |txn| {
Box::pin(async move {
cards
.create_card(txn, user_id, store_name, number, symbology)
.await
})
})
.await
}
pub async fn delete_card(&self, user_id: i64, card_id: i64) -> DomainResult<()> {
let cards = Arc::clone(&self.cards);
self.db
.run(move |txn| Box::pin(async move { cards.delete_card(txn, user_id, card_id).await }))
.await
}
}
+508 -20
View File
@@ -8,12 +8,12 @@ use sqlx::{Connection, Row, SqliteConnection, SqlitePool, sqlite::SqliteConnectO
use crate::domain::{
Category, DomainError, DomainResult, GroceryList, Item, ListMeal, Meal, MealCategory,
MealIngredient, Passkey, SessionUser, User,
MealIngredient, Passkey, RewardsCard, SessionUser, User,
};
use crate::ports::{
CategoryRepository, InvitationRepository, ItemRepository, ListMealRepository, ListRepository,
MealCategoryRepository, MealIngredientRepository, MealRepository, NewItem, PasskeyRepository,
SessionRepository, UserRepository,
RewardsCardRepository, SessionRepository, UserRepository,
};
/// The embedded SQL migrations, applied automatically on startup.
@@ -39,26 +39,32 @@ impl SqliteDatabase {
Ok(Self { pool })
}
#[cfg(test)]
/// Opens an in-memory database. Every connection in the pool shares the same
/// in-memory database via a named shared-cache database, so the schema and
/// data are visible across the whole pool. Nothing is persisted to disk.
pub async fn open_in_memory() -> DomainResult<Self> {
// A pool of `:memory:` connections would each get a separate database,
// so use a unique temporary file that shares the schema across the pool.
// A plain `:memory:` database is private to each connection, so a pool
// would get a separate database per connection. Use a uniquely-named
// shared-cache in-memory database instead so the whole pool shares one.
//
// The name must be unique per call: shared-cache in-memory databases are
// keyed by name, so two calls with the same name within a process would
// resolve to the same database and share state. This matters for the
// unit tests, which run many `open_in_memory()` calls in parallel within
// a single process and need isolation from each other. The counter makes
// each call unique. (Shared-cache and in-memory databases are per-process,
// so there is no cross-process collision to guard against.)
use std::sync::atomic::{AtomicU64, Ordering};
static COUNTER: AtomicU64 = AtomicU64::new(0);
let unique = COUNTER.fetch_add(1, Ordering::Relaxed);
let path = std::env::temp_dir().join(format!(
"sustenance-test-{}-{}-{}.db",
std::process::id(),
now(),
unique
));
let path = path.to_str().unwrap();
let filename = format!("file:sustenance-in-memory-{}", unique);
let options = SqliteConnectOptions::new()
.filename(path)
.journal_mode(sqlx::sqlite::SqliteJournalMode::Wal)
.filename(filename)
.in_memory(true)
.shared_cache(true)
.journal_mode(sqlx::sqlite::SqliteJournalMode::Memory)
.foreign_keys(true)
.busy_timeout(std::time::Duration::from_secs(5))
.create_if_missing(true);
.busy_timeout(std::time::Duration::from_secs(5));
let pool = SqlitePool::connect_with(options).await.map_err(db_error)?;
MIGRATOR.run(&pool).await.map_err(migrate_error)?;
seed_default_categories(&pool).await?;
@@ -68,6 +74,14 @@ impl SqliteDatabase {
}
impl SqliteDatabase {
/// Closes the connection pool, waiting for all connections to be released
/// and closed. This lets SQLite checkpoint and remove the WAL/SHM sidecar
/// files on a clean shutdown; without it, the pool's background close task
/// races with process exit and the sidecars may be left behind.
pub async fn close(&self) {
self.pool.close().await;
}
/// Runs `operation` inside a single transaction, committing on success and
/// rolling back on error. Multiple repositories can participate in the same
/// transaction so their writes commit together atomically.
@@ -442,8 +456,9 @@ pub struct SqliteListRepository;
impl ListRepository for SqliteListRepository {
async fn list_summaries(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<GroceryList>> {
let rows = sqlx::query(
"SELECT l.id, l.name, l.revision
"SELECT l.id, l.name, l.revision, l.created_at, l.archived_at
FROM lists l
WHERE l.archived_at IS NULL
ORDER BY l.created_at DESC",
)
.fetch_all(&mut *txn)
@@ -455,6 +470,33 @@ impl ListRepository for SqliteListRepository {
id: row.get(0),
name: row.get(1),
revision: row.get(2),
created_at: row.get(3),
archived_at: row.get(4),
})
.collect())
}
async fn list_archived_summaries(
&self,
txn: &mut SqliteConnection,
) -> DomainResult<Vec<GroceryList>> {
let rows = sqlx::query(
"SELECT l.id, l.name, l.revision, l.created_at, l.archived_at
FROM lists l
WHERE l.archived_at IS NOT NULL
ORDER BY l.archived_at DESC, l.created_at DESC",
)
.fetch_all(&mut *txn)
.await
.map_err(db_error)?;
Ok(rows
.into_iter()
.map(|row| GroceryList {
id: row.get(0),
name: row.get(1),
revision: row.get(2),
created_at: row.get(3),
archived_at: row.get(4),
})
.collect())
}
@@ -479,6 +521,8 @@ impl ListRepository for SqliteListRepository {
id: list_id,
name,
revision: 0,
created_at: now(),
archived_at: None,
})
}
@@ -488,7 +532,7 @@ impl ListRepository for SqliteListRepository {
list_id: i64,
) -> DomainResult<Option<GroceryList>> {
let row = sqlx::query(
"SELECT l.id, l.name, l.revision
"SELECT l.id, l.name, l.revision, l.created_at, l.archived_at
FROM lists l
WHERE l.id = ?1",
)
@@ -500,8 +544,36 @@ impl ListRepository for SqliteListRepository {
id: row.get(0),
name: row.get(1),
revision: row.get(2),
created_at: row.get(3),
archived_at: row.get(4),
}))
}
async fn set_archived(
&self,
txn: &mut SqliteConnection,
list_id: i64,
archived: bool,
) -> DomainResult<()> {
let result = if archived {
sqlx::query("UPDATE lists SET archived_at = ?1 WHERE id = ?2")
.bind(now())
.bind(list_id)
.execute(&mut *txn)
.await
.map_err(db_error)?
} else {
sqlx::query("UPDATE lists SET archived_at = NULL WHERE id = ?1")
.bind(list_id)
.execute(&mut *txn)
.await
.map_err(db_error)?
};
if result.rows_affected() == 0 {
return Err(DomainError::NotFound);
}
Ok(())
}
}
#[derive(Clone, Copy)]
@@ -1025,12 +1097,15 @@ impl MealRepository for SqliteMealRepository {
}))
}
async fn list_meals(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<Meal>> {
async fn list_meals(&self, txn: &mut SqliteConnection, query: &str) -> DomainResult<Vec<Meal>> {
let rows = sqlx::query(
"SELECT id, name, description, category_id
FROM meals
WHERE (?1 = '' OR name LIKE '%' || ?2 || '%' ESCAPE '\\')
ORDER BY name COLLATE NOCASE ASC",
)
.bind(query)
.bind(escape_like(query))
.fetch_all(&mut *txn)
.await
.map_err(db_error)?;
@@ -1220,6 +1295,115 @@ impl MealIngredientRepository for SqliteMealIngredientRepository {
}
}
#[derive(Clone, Copy)]
pub struct SqliteRewardsCardRepository;
#[async_trait]
impl RewardsCardRepository for SqliteRewardsCardRepository {
async fn list_cards(
&self,
txn: &mut SqliteConnection,
user_id: i64,
) -> DomainResult<Vec<RewardsCard>> {
let rows = sqlx::query(
"SELECT id, user_id, store_name, number, symbology, created_at
FROM rewards_cards
WHERE user_id = ?1
ORDER BY created_at DESC, id DESC",
)
.bind(user_id)
.fetch_all(&mut *txn)
.await
.map_err(db_error)?;
Ok(rows.into_iter().map(map_rewards_card_row).collect())
}
async fn get_card(
&self,
txn: &mut SqliteConnection,
user_id: i64,
card_id: i64,
) -> DomainResult<Option<RewardsCard>> {
let row = sqlx::query(
"SELECT id, user_id, store_name, number, symbology, created_at
FROM rewards_cards
WHERE id = ?1 AND user_id = ?2",
)
.bind(card_id)
.bind(user_id)
.fetch_optional(&mut *txn)
.await
.map_err(db_error)?;
Ok(row.map(map_rewards_card_row))
}
async fn create_card(
&self,
txn: &mut SqliteConnection,
user_id: i64,
store_name: String,
number: String,
symbology: String,
) -> DomainResult<RewardsCard> {
sqlx::query(
"INSERT INTO rewards_cards (user_id, store_name, number, symbology, created_at)
VALUES (?1, ?2, ?3, ?4, ?5)",
)
.bind(user_id)
.bind(&store_name)
.bind(&number)
.bind(&symbology)
.bind(now())
.execute(&mut *txn)
.await
.map_err(db_error)?;
let card_id = sqlx::query("SELECT last_insert_rowid()")
.fetch_one(&mut *txn)
.await
.map_err(db_error)?
.get::<i64, _>(0);
Ok(RewardsCard {
id: card_id,
user_id,
store_name,
number,
symbology,
created_at: now(),
})
}
async fn delete_card(
&self,
txn: &mut SqliteConnection,
user_id: i64,
card_id: i64,
) -> DomainResult<()> {
let changed = sqlx::query("DELETE FROM rewards_cards WHERE id = ?1 AND user_id = ?2")
.bind(card_id)
.bind(user_id)
.execute(&mut *txn)
.await
.map_err(db_error)?
.rows_affected();
if changed == 0 {
return Err(DomainError::NotFound);
}
Ok(())
}
}
/// Maps a `rewards_cards` row (in the shared column order) to a `RewardsCard`.
fn map_rewards_card_row(row: sqlx::sqlite::SqliteRow) -> RewardsCard {
RewardsCard {
id: row.get(0),
user_id: row.get(1),
store_name: row.get(2),
number: row.get(3),
symbology: row.get(4),
created_at: row.get(5),
}
}
async fn ensure_category(txn: &mut SqliteConnection, category_id: Option<i64>) -> DomainResult<()> {
let Some(category_id) = category_id else {
return Ok(());
@@ -1296,6 +1480,14 @@ fn db_error(error: sqlx::Error) -> DomainError {
DomainError::Database(error.to_string())
}
/// Escapes a user-supplied search term so `%`, `_` and `\` are matched
/// literally when interpolated into a `LIKE` pattern with `ESCAPE '\'`.
fn escape_like(term: &str) -> String {
term.replace('\\', "\\\\")
.replace('%', "\\%")
.replace('_', "\\_")
}
fn migrate_error(error: sqlx::migrate::MigrateError) -> DomainError {
DomainError::Database(error.to_string())
}
@@ -1608,6 +1800,85 @@ mod tests {
assert_eq!(ids, vec![first.id, second.id]);
}
#[tokio::test]
async fn archiving_a_list_hides_it_from_summaries() {
let db = setup().await;
let list = create_list(&db, "Weekly shop").await;
let lists = SqliteListRepository;
let list_id = list.id;
db.run(move |txn| {
let lists = lists.clone();
Box::pin(async move { lists.set_archived(txn, list_id, true).await })
})
.await
.unwrap();
let summaries = db
.run(move |txn| {
let lists = lists.clone();
Box::pin(async move { lists.list_summaries(txn).await })
})
.await
.unwrap();
assert!(summaries.is_empty());
let archived = db
.run(move |txn| {
let lists = lists.clone();
Box::pin(async move { lists.list_archived_summaries(txn).await })
})
.await
.unwrap();
assert_eq!(archived.len(), 1);
assert_eq!(archived[0].id, list.id);
assert!(archived[0].archived_at.is_some());
}
#[tokio::test]
async fn unarchiving_a_list_restores_it_to_summaries() {
let db = setup().await;
let list = create_list(&db, "Weekly shop").await;
let lists = SqliteListRepository;
let list_id = list.id;
db.run(move |txn| {
let lists = lists.clone();
Box::pin(async move { lists.set_archived(txn, list_id, true).await })
})
.await
.unwrap();
db.run(move |txn| {
let lists = lists.clone();
Box::pin(async move { lists.set_archived(txn, list_id, false).await })
})
.await
.unwrap();
let summaries = db
.run(move |txn| {
let lists = lists.clone();
Box::pin(async move { lists.list_summaries(txn).await })
})
.await
.unwrap();
assert_eq!(summaries.len(), 1);
assert!(summaries[0].archived_at.is_none());
}
#[tokio::test]
async fn archiving_a_missing_list_fails() {
let db = setup().await;
let lists = SqliteListRepository;
let result = db
.run(move |txn| {
let lists = lists.clone();
Box::pin(async move { lists.set_archived(txn, 9999, true).await })
})
.await;
assert!(result.is_err());
}
#[tokio::test]
async fn get_list_returns_list_or_none() {
let db = setup().await;
@@ -2189,7 +2460,7 @@ mod tests {
let meals = db
.run(move |txn| {
let meals = meals.clone();
Box::pin(async move { meals.list_meals(txn).await })
Box::pin(async move { meals.list_meals(txn, "").await })
})
.await
.unwrap();
@@ -2198,6 +2469,51 @@ mod tests {
assert_eq!(names, vec!["Pasta".to_owned(), "Salad".to_owned()]);
}
#[tokio::test]
async fn list_meals_filters_by_name_case_insensitively() {
let db = setup().await;
create_meal(&db, "Pasta Carbonara").await;
create_meal(&db, "Chicken Curry").await;
let meals = SqliteMealRepository;
let names = |posted_query: &str| {
let meals = meals.clone();
let posted_query = posted_query.to_owned();
db.run(move |txn| {
let meals = meals.clone();
Box::pin(async move { meals.list_meals(txn, &posted_query).await })
})
};
let matched = names("pasta").await.unwrap();
let matched_names = matched.iter().map(|m| m.name.as_str()).collect::<Vec<_>>();
assert_eq!(matched_names, vec!["Pasta Carbonara"]);
assert!(names("pizza").await.unwrap().is_empty());
}
#[tokio::test]
async fn list_meals_escapes_like_wildcards() {
let db = setup().await;
create_meal(&db, "100% Wholemeal Bread").await;
create_meal(&db, "Salad").await;
let meals = SqliteMealRepository;
let names = |posted_query: &str| {
let meals = meals.clone();
let posted_query = posted_query.to_owned();
db.run(move |txn| {
let meals = meals.clone();
Box::pin(async move { meals.list_meals(txn, &posted_query).await })
})
};
// A bare `%` must not act as a wildcard matching every meal: it only
// matches meals that contain a literal `%` character.
let matched = names("%").await.unwrap();
assert_eq!(matched.len(), 1);
assert_eq!(matched[0].name, "100% Wholemeal Bread");
// `_` and `%` in the query are matched literally.
let matched = names("100%").await.unwrap();
assert_eq!(matched.len(), 1);
assert_eq!(matched[0].name, "100% Wholemeal Bread");
}
#[tokio::test]
async fn get_meal_returns_meal_with_ingredients() {
let db = setup().await;
@@ -2635,4 +2951,176 @@ mod tests {
.await;
assert!(matches!(result, Err(DomainError::NotFound)));
}
// ---- RewardsCardRepository ----
#[tokio::test]
async fn rewards_card_crud_roundtrip() {
let db = setup().await;
let user = create_user(&db, "alice@example.com").await;
let cards = SqliteRewardsCardRepository;
let created = db
.run(move |txn| {
let cards = cards.clone();
Box::pin(async move {
cards
.create_card(
txn,
user.id,
"Kroger".into(),
"6011 2345 6789".into(),
"code128".into(),
)
.await
})
})
.await
.unwrap();
assert!(created.id > 0);
assert_eq!(created.user_id, user.id);
assert_eq!(created.store_name, "Kroger");
assert_eq!(created.number, "6011 2345 6789");
assert_eq!(created.symbology, "code128");
let listed = db
.run(move |txn| {
let cards = cards.clone();
Box::pin(async move { cards.list_cards(txn, user.id).await })
})
.await
.unwrap();
assert_eq!(listed.len(), 1);
assert_eq!(listed[0].id, created.id);
db.run(move |txn| {
let cards = cards.clone();
Box::pin(async move { cards.delete_card(txn, user.id, created.id).await })
})
.await
.unwrap();
let after = db
.run(move |txn| {
let cards = cards.clone();
Box::pin(async move { cards.list_cards(txn, user.id).await })
})
.await
.unwrap();
assert!(after.is_empty());
}
#[tokio::test]
async fn rewards_cards_are_scoped_to_their_user() {
let db = setup().await;
let alice = create_user(&db, "alice@example.com").await;
let bob = create_user(&db, "bob@example.com").await;
let cards = SqliteRewardsCardRepository;
db.run(move |txn| {
let cards = cards.clone();
Box::pin(async move {
cards
.create_card(
txn,
alice.id,
"Kroger".into(),
"123".into(),
"code128".into(),
)
.await
})
})
.await
.unwrap();
let bobs = db
.run(move |txn| {
let cards = cards.clone();
Box::pin(async move { cards.list_cards(txn, bob.id).await })
})
.await
.unwrap();
assert!(bobs.is_empty());
// Bob cannot delete Alice's card.
let result = db
.run(move |txn| {
let cards = cards.clone();
Box::pin(async move { cards.delete_card(txn, bob.id, 1).await })
})
.await;
assert!(matches!(result, Err(DomainError::NotFound)));
}
#[tokio::test]
async fn delete_missing_rewards_card_fails() {
let db = setup().await;
let user = create_user(&db, "alice@example.com").await;
let cards = SqliteRewardsCardRepository;
let result = db
.run(move |txn| {
let cards = cards.clone();
Box::pin(async move { cards.delete_card(txn, user.id, 9999).await })
})
.await;
assert!(matches!(result, Err(DomainError::NotFound)));
}
#[tokio::test]
async fn get_rewards_card_returns_card_or_none() {
let db = setup().await;
let alice = create_user(&db, "alice@example.com").await;
let bob = create_user(&db, "bob@example.com").await;
let cards = SqliteRewardsCardRepository;
let created = db
.run(move |txn| {
let cards = cards.clone();
Box::pin(async move {
cards
.create_card(
txn,
alice.id,
"Kroger".into(),
"601123456789".into(),
"code128".into(),
)
.await
})
})
.await
.unwrap();
// The owner can fetch their card.
let found = db
.run(move |txn| {
let cards = cards.clone();
Box::pin(async move { cards.get_card(txn, alice.id, created.id).await })
})
.await
.unwrap();
assert_eq!(found.as_ref().map(|c| c.id), Some(created.id));
assert_eq!(found.unwrap().store_name, "Kroger");
// Another user cannot fetch it.
let not_found = db
.run(move |txn| {
let cards = cards.clone();
Box::pin(async move { cards.get_card(txn, bob.id, created.id).await })
})
.await
.unwrap();
assert!(not_found.is_none());
// A missing id returns None.
let missing = db
.run(move |txn| {
let cards = cards.clone();
Box::pin(async move { cards.get_card(txn, alice.id, 9999).await })
})
.await
.unwrap();
assert!(missing.is_none());
}
}
+573 -148
View File
@@ -4,7 +4,8 @@ use pulldown_cmark::{Options, Parser, html as cmark_html};
use crate::{
domain::PresenceUser,
domain::{
Category, GroceryList, Item, ListMeal, Meal, MealCategory, MealIngredient, Passkey, User,
Category, GroceryList, Item, ListMeal, Meal, MealCategory, MealIngredient, Passkey,
RewardsCard, User,
},
};
@@ -37,8 +38,8 @@ pub fn login_page(error: Option<&str>, invite: Option<&str>) -> Markup {
button id="passkey-login" class="button button-secondary" type="button" { "Sign in with a passkey" }
p class="auth-switch" { "Need an account? " a href="/register" { "Create one" } }
}
script src="/static/password-toggle.js" {}
script src="/static/passkey-login.js" {}
script src=(crate::assets::url("password-toggle.js")) {}
script src=(crate::assets::url("passkey-login.js")) {}
},
)
}
@@ -72,7 +73,7 @@ pub fn register_page(error: Option<&str>, invite: Option<&str>) -> Markup {
}
p class="auth-switch" { "Already have an account? " a href="/login" { "Sign in" } }
}
script src="/static/password-toggle.js" {}
script src=(crate::assets::url("password-toggle.js")) {}
},
)
}
@@ -164,8 +165,8 @@ pub fn account_page(
}
}
}
script src="/static/password-toggle.js" {}
script src="/static/passkey-register.js" {}
script src=(crate::assets::url("password-toggle.js")) {}
script src=(crate::assets::url("passkey-register.js")) {}
},
)
}
@@ -173,6 +174,7 @@ pub fn account_page(
pub fn lists_page(
user: &User,
lists: &[GroceryList],
archived_count: usize,
categories: &[Category],
csrf_token: &str,
) -> Markup {
@@ -192,6 +194,7 @@ pub fn lists_page(
div class="panel-heading" {
h2 { "Lists" }
span class="count-badge" { (lists.len()) }
a class="archive-link" href="/archive" { "Archived " span class="count-badge" { (archived_count) } "" }
}
@if lists.is_empty() {
div class="empty-state" {
@@ -242,11 +245,55 @@ pub fn lists_page(
)
}
pub fn archive_page(user: &User, archived_lists: &[GroceryList]) -> Markup {
page(
"Archive",
Some(user),
html! {
div class="page-heading" {
div {
p class="eyebrow" { "ARCHIVE" }
h1 class="page-title" { "Archived lists" }
p class="lede" { "Past lists, kept for reference." }
}
a class="button button-quiet" href="/lists" { "← Back to lists" }
}
section class="panel" {
div class="panel-heading" {
h2 { "Archive" }
span class="count-badge" { (archived_lists.len()) }
}
@if archived_lists.is_empty() {
div class="empty-state" {
div class="empty-mark" { "🗄" }
h3 { "Nothing archived yet" }
p { "Archive a list and it will show up here." }
}
} @else {
div class="list-cards" {
@for list in archived_lists {
a class="list-card archived-list-card" href=(format!("/lists/{}", list.id)) {
span class="list-card-icon" { "🗄" }
span class="list-card-copy" {
strong { (list.name) }
small { "Created " (format_date(list.created_at)) }
}
span class="list-card-arrow" { "" }
}
}
}
}
}
},
)
}
pub fn meals_page(
user: &User,
meals: &[Meal],
meal_categories: &[MealCategory],
csrf_token: &str,
q: &str,
) -> Markup {
page(
"Meals",
@@ -260,7 +307,7 @@ pub fn meals_page(
}
a class="button button-primary" href="/meals/new" { "New meal" }
}
@if meals.is_empty() {
@if meals.is_empty() && q.is_empty() {
div class="empty-state" {
div class="empty-mark" { "🍽" }
h3 { "No meals yet" }
@@ -273,28 +320,21 @@ pub fn meals_page(
h2 { "All meals" }
span class="count-badge" { (meals.len()) }
}
@if meals.is_empty() {
p class="muted" { "Create a meal to get started." }
} @else {
@for (category_name, category_meals) in meal_groups(meals, meal_categories) {
div class="category-group" {
div class="category-heading" {
h3 { (category_name) " (" (category_meals.len()) ")" }
}
div class="list-cards" {
@for meal in category_meals {
a class="list-card" href=(format!("/meals/{}", meal.id)) {
span class="list-card-icon" { "🍽" }
span class="list-card-copy" {
strong { (meal.name) }
small { (meal.ingredients.len()) " ingredients" }
}
span class="list-card-arrow" { "" }
}
}
}
}
}
div class="meal-filter-bar" {
input
class="meal-filter"
id="meal-search"
type="search"
name="q"
value=(q)
placeholder="Search meals"
hx-get="/meals"
hx-trigger="input changed delay:200ms"
hx-target="#meal-results"
hx-swap="innerHTML";
}
div id="meal-results" {
(meal_results(meals, meal_categories, q))
}
}
aside class="side-column" {
@@ -330,6 +370,42 @@ pub fn meals_page(
)
}
/// Renders the meals page's grouped results, or the appropriate empty state.
/// Distinct from the database-empty state: when a search yields no matches the
/// list is empty (pre-filtered in SQL) even though meals exist, so we show a
/// search-specific message.
pub fn meal_results(meals: &[Meal], meal_categories: &[MealCategory], q: &str) -> Markup {
html! {
@if meals.is_empty() && q.is_empty() {
p class="muted" { "Create a meal to get started." }
} @else if meals.is_empty() {
div class="meal-filter-empty" {
p { "No meals match your search." }
}
} @else {
@for (category_name, category_meals) in meal_groups(meals, meal_categories) {
div class="category-group" {
div class="category-heading" {
h3 { (category_name) " (" (category_meals.len()) ")" }
}
div class="list-cards" {
@for meal in category_meals {
a class="list-card" href=(format!("/meals/{}", meal.id)) {
span class="list-card-icon" { "🍽" }
span class="list-card-copy" {
strong { (meal.name) }
small { (meal.ingredients.len()) " ingredients" }
}
span class="list-card-arrow" { "" }
}
}
}
}
}
}
}
}
fn meal_groups<'a>(
meals: &'a [Meal],
meal_categories: &[MealCategory],
@@ -370,6 +446,7 @@ pub fn meal_picker(
meal_categories: &[MealCategory],
list_id: i64,
csrf_token: &str,
q: &str,
) -> Markup {
html! {
div class="meal-picker-backdrop" onclick="if (event.target === this) this.remove()" {
@@ -381,7 +458,19 @@ pub fn meal_picker(
}
button class="meal-picker-close" type="button" aria-label="Close" onclick="this.closest('.meal-picker-backdrop').remove()" { "" }
}
@if meals.is_empty() {
div class="meal-filter-bar meal-filter-bar-picker" {
input
class="meal-filter"
name="q"
type="search"
value=(q)
placeholder="Search meals"
hx-get=(format!("/meals?picker={}", list_id))
hx-trigger="input changed delay:200ms"
hx-target="#meal-picker-results"
hx-swap="innerHTML";
}
@if meals.is_empty() && q.is_empty() {
div class="meal-picker-empty" {
span class="empty-mark" { "🍽" }
h3 { "No meals yet" }
@@ -389,32 +478,51 @@ pub fn meal_picker(
a class="button button-primary" href="/meals/new" { "Create a meal" }
}
} @else {
div class="meal-picker-list" {
@for (category_name, category_meals) in meal_groups(meals, meal_categories) {
div class="category-group" {
div class="category-heading" {
h3 { (category_name) }
}
@for meal in category_meals {
form
hx-post=(format!("/lists/{}/add-meal", list_id))
hx-target="#list-items"
hx-swap="outerHTML"
hx-on::after-request="if (event.detail.successful) this.closest('.meal-picker-backdrop').remove()"
class="meal-picker-row"
{
input type="hidden" name="csrf" value=(csrf_token);
input type="hidden" name="meal_id" value=(meal.id);
button class="meal-picker-button" type="submit" {
span class="meal-picker-icon" { "🍽" }
span class="meal-picker-copy" {
strong { (meal.name) }
small { (meal.ingredients.len()) " ingredients" }
}
span class="meal-picker-add" { "Add" }
}
}
div id="meal-picker-results" class="meal-picker-list" {
(meal_picker_results(meals, meal_categories, list_id, csrf_token))
}
}
}
}
}
}
/// The grouped picker rows, or the search-specific empty state. Kept separate
/// from the database-empty state above.
pub fn meal_picker_results(
meals: &[Meal],
meal_categories: &[MealCategory],
list_id: i64,
csrf_token: &str,
) -> Markup {
html! {
@if meals.is_empty() {
div class="meal-picker-empty" {
p { "No meals match your search." }
}
} @else {
@for (category_name, category_meals) in meal_groups(meals, meal_categories) {
div class="category-group" {
div class="category-heading" {
h3 { (category_name) }
}
@for meal in category_meals {
form
hx-post=(format!("/lists/{}/add-meal", list_id))
hx-target="#list-items"
hx-swap="morph:outerHTML"
hx-on::after-request="if (event.detail.successful) this.closest('.meal-picker-backdrop').remove()"
class="meal-picker-row"
{
input type="hidden" name="csrf" value=(csrf_token);
input type="hidden" name="meal_id" value=(meal.id);
button class="meal-picker-button" type="submit" {
span class="meal-picker-icon" { "🍽" }
span class="meal-picker-copy" {
strong { (meal.name) }
small { (meal.ingredients.len()) " ingredients" }
}
span class="meal-picker-add" { "Add" }
}
}
}
@@ -499,13 +607,6 @@ pub fn meal_page(
html! {
div class="page-heading" {
a class="back-link" href="/meals" { "← All meals" }
div class="list-topbar-actions" {
button type="button" class="button button-small button-quiet" onclick="document.getElementById('meal-edit-modal').showModal()" { "Edit" }
form method="post" action=(format!("/meals/{}/delete", meal.id)) {
input type="hidden" name="csrf" value=(csrf_token);
button class="danger-link" type="submit" { "Delete" }
}
}
}
dialog id="meal-edit-modal" class="item-modal" {
div class="item-modal-card" {
@@ -545,6 +646,13 @@ pub fn meal_page(
p class="eyebrow" { "MEAL" }
h1 { (meal.name) @if let Some(category_name) = meal_category_name(meal, meal_categories) { span class="meal-category-label" { "(" (category_name) ")" } } }
}
div class="list-topbar-actions" {
button type="button" class="button button-small button-quiet" onclick="document.getElementById('meal-edit-modal').showModal()" { "Edit" }
form method="post" action=(format!("/meals/{}/delete", meal.id)) hx-confirm="Delete this meal and its ingredients? This cannot be undone." {
input type="hidden" name="csrf" value=(csrf_token);
button class="danger-link bordered-delete" type="submit" { "Delete" }
}
}
}
@if meal.description.is_empty() {
p class="muted" { "No description." }
@@ -698,6 +806,19 @@ fn render_markdown(source: &str) -> Markup {
mod tests {
use super::*;
/// Extracts the rendered SVG width from `viewBox="0 0 <width> <height>"`.
fn svg_width(svg: &str) -> u32 {
let viewbox = svg
.split("viewBox=\"")
.nth(1)
.expect("expected viewBox")
.split('"')
.next()
.unwrap();
let width = viewbox.split_whitespace().nth(2).expect("expected width");
width.parse().expect("expected numeric width")
}
#[test]
fn render_markdown_turns_bullets_into_list_html() {
let html = render_markdown("- one\n- two\n").into_string();
@@ -712,6 +833,83 @@ mod tests {
assert!(html.contains("<strong>"), "expected <strong>, got: {html}");
assert!(html.contains("<em>"), "expected <em>, got: {html}");
}
#[test]
fn format_date_renders_human_readable_date() {
// 2026-08-07T00:00:00Z in Unix seconds.
let ts = 1_786_060_800;
assert_eq!(format_date(ts), "7 Aug 2026");
}
#[test]
fn barcode_svg_renders_code128_svg() {
let html = barcode_svg("code128", "601123456789").into_string();
assert!(html.contains("<svg"), "expected svg, got: {html}");
assert!(html.contains("</svg>"), "expected closing svg, got: {html}");
}
#[test]
fn code128_uses_set_c_for_even_digit_numbers() {
// Set C (Ć) packs two digits per symbol, so an even-length digit-only
// number should be encoded with set C rather than set B.
assert_eq!(code128_input("601123456789"), "Ć601123456789");
// Non-numeric data falls back to set B.
assert_eq!(code128_input("ABC123"), "ƁABC123");
assert_eq!(code128_input(""), "Ɓ");
}
#[test]
fn code128_odd_digit_numbers_lead_with_set_b_then_switch_to_set_c() {
// 21-digit number: first digit in set B, then set C for the rest.
assert_eq!(
code128_input("606171584511340224537"),
"Ɓ6Ć06171584511340224537"
);
}
#[test]
fn code128_set_c_renders_shorter_than_set_b() {
let number = "601123456789";
let set_c = barcode_svg("code128", number).into_string();
// Force set B by using a non-numeric character so the digit-only
// fast path doesn't kick in.
let set_b = barcode_svg("code128", &format!("{number} ")).into_string();
let width_c = svg_width(&set_c);
let width_b = svg_width(&set_b);
assert!(
width_c < width_b,
"expected set C ({width_c}) narrower than set B ({width_b})"
);
}
#[test]
fn code128_odd_digit_number_renders_shorter_than_pure_set_b() {
let number = "606171584511340224537";
let mixed = barcode_svg("code128", number).into_string();
// Force pure set B by appending a non-numeric character.
let set_b = barcode_svg("code128", &format!("{number} ")).into_string();
let width_mixed = svg_width(&mixed);
let width_b = svg_width(&set_b);
assert!(
width_mixed < width_b,
"expected mixed ({width_mixed}) narrower than set B ({width_b})"
);
}
#[test]
fn barcode_svg_renders_code39_svg() {
let html = barcode_svg("code39", "ABC123").into_string();
assert!(html.contains("<svg"), "expected svg, got: {html}");
}
#[test]
fn barcode_svg_falls_back_to_text_for_invalid_number() {
// Code 39 only supports uppercase letters and digits, so lowercase
// input cannot be encoded and falls back to plain text.
let html = barcode_svg("code39", "abc").into_string();
assert!(!html.contains("<svg"), "expected no svg, got: {html}");
assert!(html.contains("abc"), "expected fallback text, got: {html}");
}
}
pub fn list_page(
@@ -733,6 +931,9 @@ pub fn list_page(
span class="live-pill" { span class="live-dot" {} "Live" }
}
}
@if let Some(ts) = list.archived_at {
div class="archived-banner" { "This list was archived on " (format_date(ts)) "." }
}
div id="meal-picker" class="meal-picker" {}
div class="list-layout" {
section class="panel list-panel" {
@@ -740,13 +941,26 @@ pub fn list_page(
div {
p class="eyebrow" { "SHARED LIST" }
h1 { (list.name) }
p class="list-meta" { (items.iter().filter(|item| !item.checked).count()) " items to get" }
(list_meta_fragment(items, false))
}
div class="list-topbar-actions" {
@if list.archived_at.is_some() {
form method="post" action=(format!("/lists/{}/unarchive", list.id)) {
input type="hidden" name="csrf" value=(csrf_token);
button class="button button-small button-quiet" type="submit" { "Restore" }
}
} @else {
form method="post" action=(format!("/lists/{}/archive", list.id)) {
input type="hidden" name="csrf" value=(csrf_token);
button class="button button-small button-quiet" type="submit" { "Archive" }
}
}
}
}
(list_content_fragment(list, items, categories, csrf_token, false))
(list_content_fragment(list, items, categories, csrf_token, false, list.archived_at.is_none()))
}
aside class="side-column" {
(list_meals_panel(list_meals, list.id, csrf_token, false))
(list_meals_panel(list_meals, list.id, csrf_token, false, list.archived_at.is_none()))
(presence_panel(presence, false))
section class="panel tip-panel" {
span class="tip-label" { "TIP" }
@@ -765,17 +979,18 @@ pub fn list_content_fragment(
categories: &[Category],
csrf_token: &str,
out_of_band: bool,
editable: bool,
) -> Markup {
if out_of_band {
html! {
div id="list-content" hx-swap-oob="outerHTML" {
(list_content(list, items, categories, csrf_token))
(list_content(list, items, categories, csrf_token, editable))
}
}
} else {
html! {
div id="list-content" {
(list_content(list, items, categories, csrf_token))
(list_content(list, items, categories, csrf_token, editable))
}
}
}
@@ -786,26 +1001,29 @@ fn list_content(
items: &[Item],
categories: &[Category],
csrf_token: &str,
editable: bool,
) -> Markup {
html! {
form
id="add-item-form"
class="add-item-form"
hx-post=(format!("/lists/{}/items", list.id))
hx-target="#list-items"
hx-swap="outerHTML"
hx-on::after-request="if (event.detail.successful) this.reset()"
{
input type="hidden" name="csrf" value=(csrf_token);
label class="sr-only" for="item-name" { "Item name" }
input id="item-name" name="name" type="text" maxlength="120" placeholder="Add an item..." autocomplete="off" required;
select id="item-category" name="category_id" aria-label="Category" {
(category_options(categories, None))
@if editable {
form
id="add-item-form"
class="add-item-form"
hx-post=(format!("/lists/{}/items", list.id))
hx-target="#list-items"
hx-swap="morph:outerHTML"
hx-on::after-request="if (event.detail.successful) this.reset()"
{
input type="hidden" name="csrf" value=(csrf_token);
label class="sr-only" for="item-name" { "Item name" }
input id="item-name" name="name" type="text" maxlength="120" placeholder="Add an item..." autocomplete="off" required;
select id="item-category" name="category_id" aria-label="Category" {
(category_options(categories, None))
}
input id="item-quantity" name="quantity" type="text" maxlength="40" placeholder="Qty" aria-label="Quantity";
button id="add-item-button" class="button button-primary add-button" type="submit" { "+ Add" }
}
input id="item-quantity" name="quantity" type="text" maxlength="40" placeholder="Qty" aria-label="Quantity";
button id="add-item-button" class="button button-primary add-button" type="submit" { "+ Add" }
}
(list_items_fragment(list, items, categories, csrf_token, false))
(list_items_fragment(list, items, categories, csrf_token, false, editable))
}
}
@@ -815,23 +1033,29 @@ pub fn list_items_fragment(
categories: &[Category],
csrf_token: &str,
out_of_band: bool,
editable: bool,
) -> Markup {
if out_of_band {
html! {
div id="list-items" class="items" data-revision=(list.revision) hx-swap-oob="outerHTML" {
(list_items_content(items, categories, csrf_token))
div id="list-items" class="items" data-revision=(list.revision) hx-swap-oob="morph" {
(list_items_content(items, categories, csrf_token, editable))
}
}
} else {
html! {
div id="list-items" class="items" data-revision=(list.revision) {
(list_items_content(items, categories, csrf_token))
(list_items_content(items, categories, csrf_token, editable))
}
}
}
}
fn list_items_content(items: &[Item], categories: &[Category], csrf_token: &str) -> Markup {
fn list_items_content(
items: &[Item],
categories: &[Category],
csrf_token: &str,
editable: bool,
) -> Markup {
html! {
@if items.is_empty() {
div class="empty-items" {
@@ -842,7 +1066,7 @@ fn list_items_content(items: &[Item], categories: &[Category], csrf_token: &str)
} @else {
div class="item-list" {
@for group in item_groups(items, categories) {
(category_group(&group.0, &group.1, categories, csrf_token))
(category_group(&group.0, &group.1, categories, csrf_token, editable))
}
}
}
@@ -876,32 +1100,37 @@ fn category_group(
items: &[&Item],
categories: &[Category],
csrf_token: &str,
editable: bool,
) -> Markup {
html! {
section class="category-group" {
h2 class="category-heading" { (name) }
@for item in items {
(item_row(item, categories, csrf_token))
(item_row(item, categories, csrf_token, editable))
}
}
}
}
fn item_row(item: &Item, categories: &[Category], csrf_token: &str) -> Markup {
fn item_row(item: &Item, categories: &[Category], csrf_token: &str, editable: bool) -> Markup {
let next_checked = if item.checked { "0" } else { "1" };
html! {
article class=(if item.checked { "item-row is-checked" } else { "item-row" }) id=(format!("item-{}", item.id)) data-version=(item.version) {
form
class="check-form"
hx-post=(format!("/lists/{}/items/{}/check", item.list_id, item.id))
hx-target="#list-items"
hx-swap="outerHTML"
{
input type="hidden" name="csrf" value=(csrf_token);
input type="hidden" name="checked" value=(next_checked);
button id=(format!("item-check-{}", item.id)) class="check-button" type="submit" aria-label=(if item.checked { "Mark unchecked" } else { "Mark complete" }) {
@if item.checked { "" } @else { "" }
@if editable {
form
class="check-form"
hx-post=(format!("/lists/{}/items/{}/check", item.list_id, item.id))
hx-target="#list-items"
hx-swap="morph:outerHTML"
{
input type="hidden" name="csrf" value=(csrf_token);
input type="hidden" name="checked" value=(next_checked);
button id=(format!("item-check-{}", item.id)) class="check-button" type="submit" aria-label=(if item.checked { "Mark unchecked" } else { "Mark complete" }) {
@if item.checked { "" } @else { "" }
}
}
} @else if item.checked {
span class="check-button check-button-static" { "" }
}
label class="item-copy" for=(format!("item-check-{}", item.id)) {
@if !item.quantity.is_empty() {
@@ -912,39 +1141,41 @@ fn item_row(item: &Item, categories: &[Category], csrf_token: &str) -> Markup {
small { (item.note) }
}
}
button type="button" class="item-actions-button" aria-label="Item actions" onclick=(format!("document.getElementById('item-edit-{}').showModal()", item.id)) { "•••" }
dialog id=(format!("item-edit-{}", item.id)) class="item-modal" {
div class="item-modal-card" {
div class="item-modal-header" {
h3 { (item.name) }
button type="button" class="meal-picker-close" aria-label="Close" onclick="this.closest('dialog').close()" { "" }
}
form
hx-post=(format!("/lists/{}/items/{}/edit", item.list_id, item.id))
hx-target="#list-items"
hx-swap="outerHTML"
class="stack"
{
input type="hidden" name="csrf" value=(csrf_token);
label { "Name" }
input id=(format!("item-edit-name-{}", item.id)) name="name" value=(item.name) maxlength="120" required;
label { "Category" }
select id=(format!("item-edit-category-{}", item.id)) name="category_id" {
(category_options(categories, item.category_id))
@if editable {
button type="button" class="item-actions-button" aria-label="Item actions" onclick=(format!("document.getElementById('item-edit-{}').showModal()", item.id)) { "•••" }
dialog id=(format!("item-edit-{}", item.id)) class="item-modal" {
div class="item-modal-card" {
div class="item-modal-header" {
h3 { (item.name) }
button type="button" class="meal-picker-close" aria-label="Close" onclick="this.closest('dialog').close()" { "" }
}
form
hx-post=(format!("/lists/{}/items/{}/edit", item.list_id, item.id))
hx-target="#list-items"
hx-swap="morph:outerHTML"
class="stack"
{
input type="hidden" name="csrf" value=(csrf_token);
label { "Name" }
input id=(format!("item-edit-name-{}", item.id)) name="name" value=(item.name) maxlength="120" required;
label { "Category" }
select id=(format!("item-edit-category-{}", item.id)) name="category_id" {
(category_options(categories, item.category_id))
}
label { "Quantity" }
input id=(format!("item-edit-quantity-{}", item.id)) name="quantity" value=(item.quantity) maxlength="40";
label { "Note" }
input id=(format!("item-edit-note-{}", item.id)) name="note" value=(item.note) maxlength="120";
button id=(format!("item-edit-save-{}", item.id)) class="button button-primary" type="submit" { "Save" }
}
form
hx-post=(format!("/lists/{}/items/{}/delete", item.list_id, item.id))
hx-target="#list-items"
hx-swap="morph:outerHTML"
{
input type="hidden" name="csrf" value=(csrf_token);
button id=(format!("item-edit-delete-{}", item.id)) class="button button-danger" type="submit" { "Remove item" }
}
label { "Quantity" }
input id=(format!("item-edit-quantity-{}", item.id)) name="quantity" value=(item.quantity) maxlength="40";
label { "Note" }
input id=(format!("item-edit-note-{}", item.id)) name="note" value=(item.note) maxlength="120";
button id=(format!("item-edit-save-{}", item.id)) class="button button-primary" type="submit" { "Save" }
}
form
hx-post=(format!("/lists/{}/items/{}/delete", item.list_id, item.id))
hx-target="#list-items"
hx-swap="outerHTML"
{
input type="hidden" name="csrf" value=(csrf_token);
button id=(format!("item-edit-delete-{}", item.id)) class="button button-danger" type="submit" { "Remove item" }
}
}
}
@@ -1010,6 +1241,21 @@ pub fn categories_panel(categories: &[Category], csrf_token: &str, out_of_band:
}
}
fn list_meta_fragment(items: &[Item], out_of_band: bool) -> Markup {
let left = items.iter().filter(|item| !item.checked).count();
let total = items.len();
let meta = html! {
p id="list-meta" class="list-meta" { (left) " items left out of " (total) }
};
if out_of_band {
html! {
p id="list-meta" class="list-meta" hx-swap-oob="outerHTML" { (left) " items left out of " (total) }
}
} else {
meta
}
}
pub fn live_list_fragments(
list: &GroceryList,
items: &[Item],
@@ -1017,9 +1263,11 @@ pub fn live_list_fragments(
list_meals: &[ListMeal],
csrf_token: &str,
) -> Markup {
let editable = list.archived_at.is_none();
html! {
(list_content_fragment(list, items, categories, csrf_token, true))
(list_meals_panel(list_meals, list.id, csrf_token, true))
(list_meta_fragment(items, true))
(list_items_fragment(list, items, categories, csrf_token, true, editable))
(list_meals_panel(list_meals, list.id, csrf_token, true, editable))
}
}
@@ -1028,6 +1276,7 @@ pub fn list_meals_panel(
list_id: i64,
csrf_token: &str,
out_of_band: bool,
editable: bool,
) -> Markup {
let panel = html! {
div class="panel-heading" {
@@ -1042,20 +1291,24 @@ pub fn list_meals_panel(
div class="list-meal-row" {
span class="list-meal-icon" { "🍽" }
span class="list-meal-name" { (meal.name) }
form
hx-post=(format!("/lists/{}/meals/{}/remove", list_id, meal.id))
hx-target="#list-items"
hx-swap="outerHTML"
class="list-meal-remove"
{
input type="hidden" name="csrf" value=(csrf_token);
button type="submit" class="list-meal-remove-button" aria-label=(format!("Remove {} from list", meal.name)) { "" }
@if editable {
form
hx-post=(format!("/lists/{}/meals/{}/remove", list_id, meal.id))
hx-target="#list-items"
hx-swap="morph:outerHTML"
class="list-meal-remove"
{
input type="hidden" name="csrf" value=(csrf_token);
button type="submit" class="list-meal-remove-button" aria-label=(format!("Remove {} from list", meal.name)) { "" }
}
}
}
}
}
}
button class="button button-small add-meal-button" hx-get=(format!("/meals?picker={}", list_id)) hx-target="#meal-picker" hx-swap="innerHTML" { "+ Add meal" }
@if editable {
button class="button button-small add-meal-button" hx-get=(format!("/meals?picker={}", list_id)) hx-target="#meal-picker" hx-swap="innerHTML" { "+ Add meal" }
}
};
if out_of_band {
@@ -1153,6 +1406,173 @@ pub fn invite_result(url: &str) -> Markup {
}
}
pub fn rewards_page(user: &User, cards: &[RewardsCard], csrf_token: &str) -> Markup {
page(
"Rewards cards",
Some(user),
html! {
div class="page-heading" {
div {
p class="eyebrow" { "REWARDS CARDS" }
h1 class="page-title" { "Rewards cards" }
p class="lede" { "Your store cards, ready to scan." }
}
}
div class="dashboard-grid" {
section class="panel" {
div class="panel-heading" {
h2 { "Your cards" }
span class="count-badge" { (cards.len()) }
}
@if cards.is_empty() {
div class="empty-state" {
div class="empty-mark" { "🏷" }
h3 { "No rewards cards yet" }
p { "Add a card to see its barcode here." }
}
} @else {
div class="rewards-grid" {
@for card in cards {
div class="rewards-card" {
a class="rewards-card-link" href=(format!("/rewards/{}", card.id)) aria-label=(format!("Show {} barcode", card.store_name)) {}
div class="rewards-card-heading" {
strong { (card.store_name) }
form method="post" action=(format!("/rewards/{}/delete", card.id)) hx-confirm="Remove this rewards card? This cannot be undone." {
input type="hidden" name="csrf" value=(csrf_token);
button class="danger-link bordered-delete" type="submit" { "Remove" }
}
}
div class="rewards-barcode" {
(barcode_svg(&card.symbology, &card.number))
}
p class="rewards-number" { (card.number) }
}
}
}
}
}
section class="panel create-panel" {
div class="panel-heading" { h2 { "Add a card" } }
form method="post" action="/rewards" class="stack" {
input type="hidden" name="csrf" value=(csrf_token);
label for="store-name" { "Store name" }
input id="store-name" name="store_name" type="text" maxlength="60" placeholder="e.g. Kroger" required;
label for="card-number" { "Card number" }
input id="card-number" name="number" type="text" maxlength="80" placeholder="e.g. 6011 2345 6789" required;
label for="symbology" { "Barcode type" }
select id="symbology" name="symbology" {
option value="code128" selected { "Code 128 (recommended)" }
option value="code39" { "Code 39" }
}
button class="button button-primary" type="submit" { "Add card" }
}
}
}
},
)
}
/// A focused, single-barcode view for scanning at the register. Only one
/// barcode is shown at a time so a scanner can't pick up multiple codes.
pub fn rewards_scan_page(user: &User, card: &RewardsCard) -> Markup {
page(
&card.store_name,
Some(user),
html! {
div class="scan-page" {
a class="button button-quiet scan-back" href="/rewards" { "← All cards" }
div class="scan-card" {
p class="eyebrow" { "REWARDS CARD" }
h1 class="scan-store" { (card.store_name) }
div class="scan-barcode" {
(barcode_svg(&card.symbology, &card.number))
}
p class="rewards-number" { (card.number) }
}
}
script src=(crate::assets::url("rewards.js")) {}
},
)
}
/// Renders a rewards-card number as an inline SVG barcode using the given
/// symbology. Falls back to a plain text label if the number can't be encoded
/// (for example, a Code 128 number that isn't valid for the chosen symbology).
fn barcode_svg(symbology: &str, number: &str) -> Markup {
let generated = match symbology {
"code39" => barcoders::sym::code39::Code39::new(number)
.ok()
.map(|code| code.encode())
.and_then(|encoded| {
barcoders::generators::svg::SVG::new(60)
.generate(&encoded)
.ok()
}),
_ => barcoders::sym::code128::Code128::new(&code128_input(number))
.ok()
.map(|code| code.encode())
.and_then(|encoded| {
barcoders::generators::svg::SVG::new(60)
.generate(&encoded)
.ok()
}),
};
match generated {
Some(svg) => html! { (maud::PreEscaped(svg)) },
None => html! { span class="rewards-unencodable" { (number) } },
}
}
/// Builds the Code 128 input string, choosing the most compact character set.
///
/// Code 128 set C packs two digits per symbol, so numeric data renders roughly
/// half as wide as set B (one character per symbol). Google Wallet (via ZXing)
/// picks set C automatically for numeric runs, so we do the same to keep the
/// rendered barcode compact and consistent with it:
///
/// - Even-length digit-only numbers: all set C (`Ć` prefix).
/// - Odd-length digit-only numbers: first digit in set B, then switch to set C
/// for the remaining even count of digits (e.g. `Ɓ6Ć0171...`).
/// - Anything else: set B (`Ɓ` prefix).
fn code128_input(number: &str) -> String {
let is_all_digits = !number.is_empty() && number.chars().all(|c| c.is_ascii_digit());
if !is_all_digits {
return format!("Ɓ{number}");
}
let len = number.chars().count();
if len % 2 == 0 {
format!("Ć{number}")
} else {
let (first, rest) = number.split_at(1);
format!("Ɓ{first}Ć{rest}")
}
}
/// Formats a Unix timestamp as a human-readable date (e.g. "7 Aug 2026").
fn format_date(timestamp: i64) -> String {
let days = timestamp.div_euclid(86_400);
let (y, m, d) = civil_from_days(days);
const MONTHS: [&str; 12] = [
"Jan", "Feb", "Mar", "Apr", "May", "Jun", "Jul", "Aug", "Sep", "Oct", "Nov", "Dec",
];
format!("{} {} {}", d, MONTHS[(m - 1) as usize], y)
}
/// Converts a count of days since the Unix epoch into a (year, month, day)
/// civil date using Howard Hinnant's `civil_from_days` algorithm.
fn civil_from_days(z: i64) -> (i64, i64, i64) {
let z = z + 719_468;
let era = z.div_euclid(146_097);
let doe = z.rem_euclid(146_097);
let yoe = (doe - doe / 1460 + doe / 36524 - doe / 146096) / 365;
let y = yoe + era * 400;
let doy = doe - (365 * yoe + yoe / 4 - yoe / 100);
let mp = (5 * doy + 2) / 153;
let d = doy - (153 * mp + 2) / 5 + 1;
let m = if mp < 10 { mp + 3 } else { mp - 9 };
(if m <= 2 { y + 1 } else { y }, m, d)
}
pub fn error_page(status: &str, message: &str) -> Markup {
page(
status,
@@ -1176,17 +1596,22 @@ fn page(title: &str, user: Option<&User>, content: Markup) -> Markup {
meta charset="utf-8";
meta name="viewport" content="width=device-width, initial-scale=1";
title { (title) " · Sustenance" }
link rel="stylesheet" href="/static/style.css";
script src="https://unpkg.com/htmx.org@2.0.4" {}
script src="https://unpkg.com/htmx-ext-ws@2.0.2/ws.js" {}
link rel="icon" href=(crate::assets::url("favicon.ico")) sizes="any";
link rel="icon" type="image/png" href=(crate::assets::url("favicon-32x32.png")) sizes="32x32";
link rel="apple-touch-icon" href=(crate::assets::url("apple-touch-icon.png"));
link rel="stylesheet" href=(crate::assets::url("style.css"));
script src=(crate::assets::url("htmx.min.js")) {}
script src=(crate::assets::url("idiomorph-ext.min.js")) {}
script src=(crate::assets::url("htmx-ws.min.js")) {}
}
body {
body hx-boost="true" hx-ext="morph" {
header class="site-header" {
a class="brand" href="/lists" { span class="brand-mark" { "S" } "Sustenance" }
a class="brand" href="/lists" { img class="brand-mark" src=(crate::assets::url("logo.svg")) alt="Sustenance logo"; "Sustenance" }
@if let Some(user) = user {
nav class="site-nav" {
a href="/lists" { "Lists" }
a href="/meals" { "Meals" }
a href="/rewards" { "Rewards" }
}
div class="account-nav" {
a class="user-name" href="/account" { (user.display_name) }
Binary file not shown.

After

Width:  |  Height:  |  Size: 18 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.2 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 832 B

+1
View File
File diff suppressed because one or more lines are too long
+1
View File
File diff suppressed because one or more lines are too long
+1
View File
File diff suppressed because one or more lines are too long
+143
View File
@@ -0,0 +1,143 @@
<svg
xmlns="http://www.w3.org/2000/svg"
viewBox="0 0 64 64"
role="img"
aria-labelledby="title"
>
<title id="title">Sustenance grocery bag with produce</title>
<!-- Background -->
<rect width="64" height="64" rx="12" fill="#286247"/>
<!-- Back of the paper bag -->
<path
d="
M7 27
L16 22
L24 26
L32 22
L40 25
L49 21
L57 25
L47 31
L39 28
L31 32
L23 27
L16 31
Z
"
fill="#F2D39B"
/>
<!-- Back rim -->
<path
d="M7 27 16 22 24 26 32 22 40 25 49 21 57 25"
fill="none"
stroke="#1F4938"
stroke-width="2.75"
stroke-linecap="round"
stroke-linejoin="round"
/>
<!-- Leafy greens -->
<path
d="M42 28C39 21 42 12 49 7c2 3 2 6 1 9 3-2 6-2 8 0-1 5-5 9-12 13Z"
fill="#8EC866"
stroke="#1F4938"
stroke-width="2.5"
stroke-linejoin="round"
/>
<path
d="M45 27 53 15M47 22l7-1M49 18l-1-5"
fill="none"
stroke="#1F4938"
stroke-width="2"
stroke-linecap="round"
/>
<!-- Carrot leaves -->
<path
d="
M17 14c-2-4-1-7 0-10 3 3 4 6 3 10
m0 0c0-5 2-8 5-10 1 5-1 8-5 11
"
fill="#8EC866"
stroke="#1F4938"
stroke-width="2.5"
stroke-linecap="round"
stroke-linejoin="round"
/>
<!-- Carrot -->
<path
d="M13 18c3-4 9-5 13-2l-3 20-5 2Z"
fill="#F29A3F"
stroke="#1F4938"
stroke-width="2.5"
stroke-linejoin="round"
/>
<path
d="m16 24 7-2m-6 7 5-2"
fill="none"
stroke="#1F4938"
stroke-width="2"
stroke-linecap="round"
/>
<!-- Tomato -->
<path
d="M27 25c0-6 4-10 10-10s10 4 10 10c0 7-4 12-10 12S27 32 27 25Z"
fill="#E65A46"
stroke="#1F4938"
stroke-width="2.5"
/>
<path
d="m37 15-4 5 4-1 4 2-1-5"
fill="#78B75B"
stroke="#1F4938"
stroke-width="2"
stroke-linecap="round"
stroke-linejoin="round"
/>
<!-- Front and sides of the paper bag -->
<path
d="
M7 27
L16 31
L23 27
L31 32
L39 28
L47 31
L57 25
L55 51
L45 59
L11 51
Z
"
fill="#F2D39B"
stroke="#1F4938"
stroke-width="2.75"
stroke-linejoin="round"
/>
<!-- Front opening edge -->
<path
d="M7 27 16 31 23 27 31 32 39 28 47 31 57 25"
fill="none"
stroke="#1F4938"
stroke-width="2.75"
stroke-linecap="round"
stroke-linejoin="round"
/>
<!-- Side-panel seam and paper creases -->
<path
d="M47 31 45 59M45 59l10-8M15 36l1 9"
fill="none"
stroke="#1F4938"
stroke-width="2.25"
stroke-linecap="round"
stroke-linejoin="round"
/>
</svg>

After

Width:  |  Height:  |  Size: 2.6 KiB

+30
View File
@@ -0,0 +1,30 @@
// Keep the screen awake while a rewards barcode is on screen so the cashier
// can scan it without the display dimming or locking. This mirrors how wallet
// apps behave when showing a barcode. The Screen Wake Lock API is best-effort:
// it may be rejected (e.g. low battery) or auto-released when the tab is hidden,
// so we re-acquire whenever the page becomes visible again.
(function () {
var wakeLock = null;
function requestWakeLock() {
if (!("wakeLock" in navigator)) return;
navigator.wakeLock
.request("screen")
.then(function (sentinel) {
wakeLock = sentinel;
})
.catch(function () {
// Best-effort only; ignore failures (unsupported, low battery, etc.).
});
}
// Re-acquire if the lock was released (e.g. the tab was hidden) and the user
// returns to the page.
document.addEventListener("visibilitychange", function () {
if (document.visibilityState === "visible" && wakeLock === null) {
requestWakeLock();
}
});
requestWakeLock();
})();
+114 -1
View File
@@ -38,7 +38,7 @@ a { color: inherit; }
}
.brand { display: inline-flex; align-items: center; gap: 10px; text-decoration: none; font-weight: 800; letter-spacing: -.03em; }
.brand-mark { display: grid; place-items: center; width: 32px; height: 32px; border-radius: 11px 11px 11px 3px; background: var(--deep-sage); color: white; transform: rotate(-6deg); }
.brand-mark { display: block; width: 34px; height: 34px; border-radius: 9px; object-fit: cover; }
.site-nav { display: flex; align-items: center; gap: 6px; }
.site-nav a {
padding: 8px 14px;
@@ -71,6 +71,8 @@ h3 { margin-bottom: 6px; font-size: 1rem; }
.dashboard-grid { display: grid; grid-template-columns: minmax(0, 1.5fr) minmax(260px, .8fr); gap: 22px; align-items: start; }
.panel { padding: 26px; border: 1px solid rgba(221, 225, 210, .9); border-radius: 24px; background: rgba(255, 253, 248, .88); box-shadow: var(--shadow); }
.panel-heading { display: flex; justify-content: space-between; align-items: center; gap: 12px; margin-bottom: 22px; }
.archive-link { margin-left: auto; color: var(--muted); font-size: .78rem; font-weight: 700; text-decoration: none; }
.archive-link:hover { color: var(--deep-sage); }
.count-badge { display: inline-grid; place-items: center; min-width: 27px; height: 27px; padding: 0 8px; border-radius: 99px; color: var(--deep-sage); background: #e8f0e1; font-size: .78rem; font-weight: 800; }
.stack { display: grid; gap: 9px; }
.stack label { color: var(--muted); font-size: .82rem; font-weight: 700; }
@@ -100,6 +102,11 @@ textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85,
.list-card-copy { display: grid; flex: 1; gap: 2px; }
.list-card-copy small { color: var(--muted); font-size: .75rem; }
.list-card-arrow { color: var(--muted); font-size: 1.25rem; }
.archived-list-card { opacity: .72; }
.archived-list-card .list-card-icon { color: var(--muted); background: #eef0ea; }
.archived-list-card .list-card-copy { align-items: flex-start; }
.archived-list-card form { margin-left: auto; }
.archived-banner { margin-bottom: 18px; padding: 11px 14px; border: 1px solid var(--line); border-radius: 12px; color: var(--muted); background: #f1f3ec; font-size: .82rem; font-weight: 700; }
.empty-state { padding: 35px 18px 24px; text-align: center; color: var(--muted); }
.empty-mark { display: grid; place-items: center; width: 50px; height: 50px; margin: 0 auto 15px; border-radius: 18px; color: var(--deep-sage); background: #edf3e8; font-size: 1.8rem; }
.empty-state h3 { color: var(--ink); }
@@ -152,6 +159,8 @@ textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85,
.check-form { flex: 0 0 auto; }
.check-button { display: grid; place-items: center; width: 28px; height: 28px; padding: 0; border: 2px solid #c8d6c1; border-radius: 9px; color: #fff; background: transparent; cursor: pointer; font-size: .88rem; font-weight: 900; }
.is-checked .check-button { border-color: var(--deep-sage); background: var(--deep-sage); }
.check-button-static { cursor: default; }
.is-checked .check-button-static { border-color: var(--deep-sage); background: var(--deep-sage); }
.item-copy { display: grid; grid-template-columns: auto 1fr; flex: 1; min-width: 0; gap: 2px 7px; align-items: baseline; }
.item-copy strong { grid-column: 2; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
.item-qty { grid-column: 1; grid-row: 1; color: var(--muted); font-weight: 700; white-space: nowrap; }
@@ -220,6 +229,8 @@ textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85,
.edit-form { margin-bottom: 12px; }
.edit-form input { min-height: 38px; padding: 7px 10px; font-size: .85rem; }
.danger-link { padding: 0; border: 0; color: var(--coral); background: none; cursor: pointer; font-size: .8rem; font-weight: 800; }
.bordered-delete { padding: 7px 14px; border: 1px solid var(--coral); border-radius: 10px; background: none; }
.bordered-delete:hover { background: #fbeae4; }
.button-danger { width: 100%; color: var(--coral); background: #fbeae4; }
.button-danger:hover { background: #f7ddd4; }
.empty-items { padding: 34px 10px 18px; color: var(--muted); text-align: center; }
@@ -367,6 +378,11 @@ textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85,
.meal-picker-empty { padding: 34px 22px 30px; text-align: center; color: var(--muted); }
.meal-picker-empty h3 { color: var(--ink); }
.meal-picker-empty p { margin-bottom: 18px; }
.meal-filter-bar { margin: -6px 0 18px; }
.meal-filter-bar input { min-height: 40px; padding: 8px 12px; font-size: .9rem; }
.meal-filter-bar-picker { margin: 14px 24px 4px; }
.meal-filter-empty { padding: 28px 18px; text-align: center; color: var(--muted); }
.meal-filter-empty p { margin: 0; }
@media (max-width: 780px) {
.site-header, .site-main, .site-footer { width: min(100% - 28px, 600px); }
@@ -392,3 +408,100 @@ textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85,
.side-column { grid-template-columns: 1fr; }
.site-footer { margin-bottom: 20px; }
}
/* Rewards cards */
.rewards-grid { display: grid; gap: 16px; }
.rewards-card {
position: relative;
padding: 18px;
border: 1px solid var(--line);
border-radius: 18px;
background: #fff;
transition: border-color .16s ease, transform .16s ease;
}
.rewards-card:hover { border-color: var(--sage); transform: translateY(-1px); }
/* Stretched link: makes the whole card clickable to open the scan view. */
.rewards-card-link {
position: absolute;
inset: 0;
border-radius: inherit;
z-index: 1;
}
.rewards-card-heading {
display: flex;
justify-content: space-between;
align-items: center;
gap: 12px;
margin-bottom: 14px;
}
.rewards-card-heading strong { font-size: 1.05rem; }
.rewards-barcode {
display: flex;
justify-content: center;
padding: 14px;
border-radius: 12px;
background: #fff;
}
.rewards-barcode svg { width: 100%; height: auto; max-width: 340px; }
.rewards-number {
margin: 12px 0 0;
text-align: center;
color: var(--muted);
font-size: .85rem;
letter-spacing: .08em;
}
.rewards-unencodable {
display: block;
color: var(--coral);
font-weight: 700;
}
/* Keep the Remove button above the stretched link so it stays clickable. */
.rewards-card-heading form { position: relative; z-index: 2; }
/* Single-card scan view */
.scan-page {
display: flex;
flex-direction: column;
align-items: center;
gap: 22px;
padding: 12px 0 40px;
}
.scan-back { align-self: flex-start; }
.scan-card {
width: min(100%, 460px);
padding: clamp(24px, 6vw, 42px);
border: 1px solid var(--line);
border-radius: 28px;
background: #fff;
box-shadow: var(--shadow);
text-align: center;
}
.scan-store { margin: 4px 0 26px; font-size: clamp(1.3rem, 4vw, 1.7rem); }
.scan-barcode {
display: flex;
justify-content: center;
padding: 22px;
border-radius: 14px;
background: #fff;
}
.scan-barcode svg {
width: 100%;
height: auto;
max-width: 420px;
}
.scan-card .rewards-number {
margin-top: 18px;
font-size: 1rem;
}
select {
width: 100%;
min-height: 46px;
padding: 10px 13px;
border: 1px solid var(--line);
border-radius: 12px;
outline: none;
color: var(--ink);
background: #fff;
font: inherit;
}
select:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113, 93, .12); }