next: exponentiation, modulo, chat API and webhooks #10

Open
clawbot wants to merge 5 commits from next into main
Collaborator

Merges next into main.

On the branch:

  • An HTTP API beside the bot (#4): GET /api/v1/chats lists its chats. Every request needs the bearer credential from the file named by API_TOKEN_FILE; without one configured, every request is refused.
  • A chat's recent messages, and sending a message to a chat (#5).
  • The calculator takes ^ (or **) for powers and % for modulo (#3). Values below about 2.2e-308, which main answers, are now refused.
  • cmd/simplexcalc/ is a single main.go; the command tree lives in internal/cli (#8).
  • The README clones from sneak/simplexcalc (#13).

Deploying: rebuild and recreate on the same volume; the address does not change. The API needs -p for its port (8080 by default) and -e API_TOKEN_FILE=... pointing at a credential file on the volume, as the README shows; without them the bot runs as before and the API refuses everything. The bot on sandcastle runs this branch as of ac72139.

The webhooks, the last parts of #2, land here one at a time after review.

Model: opus-5-5

Merges `next` into `main`. **On the branch:** - An HTTP API beside the bot (https://git.eeqj.de/sneak/simplexcalc/issues/4): `GET /api/v1/chats` lists its chats. Every request needs the bearer credential from the file named by `API_TOKEN_FILE`; without one configured, every request is refused. - A chat's recent messages, and sending a message to a chat (https://git.eeqj.de/sneak/simplexcalc/issues/5). - The calculator takes `^` (or `**`) for powers and `%` for modulo (https://git.eeqj.de/sneak/simplexcalc/issues/3). Values below about 2.2e-308, which `main` answers, are now refused. - `cmd/simplexcalc/` is a single `main.go`; the command tree lives in `internal/cli` (https://git.eeqj.de/sneak/simplexcalc/issues/8). - The README clones from `sneak/simplexcalc` (https://git.eeqj.de/sneak/simplexcalc/issues/13). **Deploying:** rebuild and recreate on the same volume; the address does not change. The API needs `-p` for its port (8080 by default) and `-e API_TOKEN_FILE=...` pointing at a credential file on the volume, as the README shows; without them the bot runs as before and the API refuses everything. The bot on sandcastle runs this branch as of `ac72139`. The webhooks, the last parts of https://git.eeqj.de/sneak/simplexcalc/issues/2, land here one at a time after review. Model: opus-5-5
clawbot added 1 commit 2026-09-29 01:52:03 +02:00
Move the command tree into internal/cli (closes #8)
check / check (push) Successful in 1m40s
09a5caa8ab
`cmd/simplexcalc/` now holds only `main.go`, whose body is one call, `os.Exit(cli.Main(version))`, as the Go style guide requires. The command tree and the `run` and `version` commands moved unchanged into `internal/cli`, with tests for `version` and for an unknown command. Output streams, exit statuses and the `-X main.version` build flag are as before.

Disclosure: the comment in `execute` saying cobra has already printed the error is false, since the root command silences cobra's errors; it moved unchanged and is left for a follow-up.

Model: opus-5-5
clawbot added the merge-ready label 2026-09-29 01:54:41 +02:00
sneak was assigned by clawbot 2026-09-29 01:54:41 +02:00
clawbot added 1 commit 2026-09-29 04:28:17 +02:00
The calculator now takes `^` (or `**`) for powers and `%` for modulo. Powers bind tighter than a sign on their left and group to the right, so `-2^2` is `-4` and `2^3^2` is `512`; `%` sits with `*` and `/` and takes the sign of the divisor. A small parser of our own replaces `go/parser`, which cannot express `^`; `go/constant` still computes.

A whole-number exponent is exact; a fractional one is computed in float64. Every number is held as a fraction under 4096 bits, and a float64 result must be a normal double, so one message cannot stall the bot; anything else gets "That needs a number too large or too small for me."

Disclosure: tiny values below about 2.2e-308, which `next` answered, are now refused.

Model: opus-5-5
clawbot added 1 commit 2026-09-29 04:55:51 +02:00
The bot now serves an HTTP API on `PORT` (default 8080) beside the chat client, whose WebSocket stays on 127.0.0.1 inside the container. Every request needs `Authorization: Bearer` with the credential from the file named by `API_TOKEN_FILE`, compared in constant time; with no credential configured every request is refused, `OPTIONS *` included. `GET /api/v1/chats` lists the bot's chats. Responses carry the security headers from the repository policies; bodies, requests and the server are time- and size-bounded. The chat client stops only after the API has finished its requests.

Disclosures: `contact_deleted` is an extra field; 404 and 405 answer in JSON; requests net/http cannot parse are refused by net/http without the security headers; three gosec findings are suppressed as false positives.

Model: opus-5-5
clawbot added 1 commit 2026-09-29 05:14:02 +02:00
README: clone from sneak/simplexcalc (closes #13)
check / check (push) Successful in 1m38s
8f0906d677
The repository moved to `sneak/simplexcalc`; the Getting Started clone command still named `clawbot/simplexcalc`, which only redirects. It was the only mention of the old location.

Model: opus-5-5
clawbot added 1 commit 2026-09-29 07:33:37 +02:00
`GET /api/v1/chats/{id}/messages?count=N` returns a chat's recent messages, oldest first (`count` 1 to 100, default 20), and `POST` to the same path sends a text message and returns it once the chat client has taken it. Both answer `404` for any id the chats list does not show, looked up in the same contact list. The message record is defined once, for the webhooks to reuse.

Disclosures: items are read five at a time, because one item can be many times its text and 100 at once could pass the 16 MiB read limit; text too long gets `413`, a contact who deleted the chat `409` (unverified for one still connecting); a query the server cannot read gets its own `400`.

Model: opus-5-5
All checks were successful
check / check (push) Successful in 1m5s
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin next:next
git checkout next
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/simplexcalc#10