Skip to content

sharing-pane: login prompt for anonymous viewers (#8) - #10

Merged
melvincarvalho merged 2 commits into
gh-pagesfrom
issue-8-sharing-anon-empty-state
May 3, 2026
Merged

melvincarvalho merged 2 commits into
gh-pagesfrom
issue-8-sharing-anon-empty-state

Conversation

@melvincarvalho

Copy link
Copy Markdown
Contributor

Closes #8.

Change

One early-return at the top of `render` in `panes/sharing-pane.js`. If `window.xlogin.id` is falsy (no Solid WebID / no Nostr pubkey), render a centered "Log in to manage sharing" panel with a button that calls `window.xlogin.login()`. Existing authenticated flow unchanged.

```diff

  • if (!(window.xlogin && window.xlogin.id)) {
  •  // ...login prompt...
    
  •  return
    
  • }
    ```

Why this shape

  • xlogin already exposes `window.xlogin.id` (set to a WebID/pubkey when logged in, `null` when not). Documented in xlogin.js:14-15.
  • Detecting anonymous before the fetch means anonymous viewers don't fire a guaranteed-401 against `.acl`.
  • Authenticated users with a real read-access denial still see the actual server response — the early-return only fires when there's literally no auth context.

Diff

+14 lines, no behavior change for authenticated users.

Test plan

  • Not browser-tested locally — needs verification in browser before merge:
    • Anonymous: `melvin.solid.social/public/` → Sharing tab shows login prompt, no red 401, no `.acl` request fired (check network tab)
    • Click "Log in" → xlogin modal opens
    • After login: hard-reload → existing ACL controls render
    • Authenticated user on a resource they can't read → still see real error (different case)

Edge case (acknowledged, no regression)

If user logs in while on the Sharing tab, the pane doesn't auto re-render — they'd need to click the tab again. Same limitation the current sharing-pane already has on auth-state changes; no regression introduced.

Skip the guaranteed-401 .acl fetch when window.xlogin.id is falsy and
show 'Log in to manage sharing' with a button that triggers
window.xlogin.login(). Authenticated users with a real read-access
denial still see the actual server response.

+14 lines, single early-return at the top of render. No fetch issued
for anonymous viewers.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds an anonymous-user empty-state to the Sharing pane so unauthenticated viewers see a login prompt (and avoid a guaranteed .acl 401 fetch) instead of a raw error.

Changes:

  • Short-circuits sharing-pane rendering when window.xlogin.id is falsy to skip the .acl fetch.
  • Renders a centered “Log in to manage sharing” panel with a button that calls window.xlogin.login().

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread panes/sharing-pane.js Outdated
Comment on lines +73 to +84
// Anonymous → login empty-state, skip the guaranteed-401 ACL fetch (#8)
if (!(window.xlogin && window.xlogin.id)) {
container.innerHTML = ''
var anon = document.createElement('div')
anon.style.cssText = 'max-width:520px;margin:60px auto;padding:40px;text-align:center;font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",sans-serif;'
anon.innerHTML = '<div style="font-size:42px;margin-bottom:12px;">\u{1F91D}</div>'
+ '<h2 style="font-size:22px;margin:0 0 8px;color:#1a1a1a;">Sharing</h2>'
+ '<p style="color:#888;margin:0 0 24px;">Log in to manage who can access this resource.</p>'
+ '<button id="sh-login-btn" style="background:#7c3aed;color:#fff;border:none;border-radius:8px;padding:10px 24px;font:600 14px inherit;cursor:pointer;">Log in</button>'
container.appendChild(anon)
anon.querySelector('#sh-login-btn').onclick = function() { window.xlogin && window.xlogin.login && window.xlogin.login() }
return

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in 5386214 — flipped the guard from !(window.xlogin && window.xlogin.id) to window.xlogin && !window.xlogin.id. Three explicit states now: xlogin+id → ACL flow, xlogin+no id → login prompt, no xlogin → fall through to real ACL fetch (so CSP/unpkg failure shows a legitimate error instead of a dead button).

)

If window.xlogin is undefined (script blocked / unpkg down / ad-blocker),
fall through to the real ACL fetch instead of rendering a Log in button
that no-ops. Caught by Copilot.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

sharing-pane: anonymous users see raw '401 Unauthorized' instead of 'Log in to manage sharing'

2 participants