Repository navigation
sharing-pane: login prompt for anonymous viewers (#8) - #10
Merged
Merged
Conversation
Skip the guaranteed-401 .acl fetch when window.xlogin.id is falsy and show 'Log in to manage sharing' with a button that triggers window.xlogin.login(). Authenticated users with a real read-access denial still see the actual server response. +14 lines, single early-return at the top of render. No fetch issued for anonymous viewers.
There was a problem hiding this comment.
Pull request overview
Adds an anonymous-user empty-state to the Sharing pane so unauthenticated viewers see a login prompt (and avoid a guaranteed .acl 401 fetch) instead of a raw error.
Changes:
- Short-circuits
sharing-panerendering whenwindow.xlogin.idis falsy to skip the.aclfetch. - Renders a centered “Log in to manage sharing” panel with a button that calls
window.xlogin.login().
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+73
to
+84
| // Anonymous → login empty-state, skip the guaranteed-401 ACL fetch (#8) | ||
| if (!(window.xlogin && window.xlogin.id)) { | ||
| container.innerHTML = '' | ||
| var anon = document.createElement('div') | ||
| anon.style.cssText = 'max-width:520px;margin:60px auto;padding:40px;text-align:center;font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",sans-serif;' | ||
| anon.innerHTML = '<div style="font-size:42px;margin-bottom:12px;">\u{1F91D}</div>' | ||
| + '<h2 style="font-size:22px;margin:0 0 8px;color:#1a1a1a;">Sharing</h2>' | ||
| + '<p style="color:#888;margin:0 0 24px;">Log in to manage who can access this resource.</p>' | ||
| + '<button id="sh-login-btn" style="background:#7c3aed;color:#fff;border:none;border-radius:8px;padding:10px 24px;font:600 14px inherit;cursor:pointer;">Log in</button>' | ||
| container.appendChild(anon) | ||
| anon.querySelector('#sh-login-btn').onclick = function() { window.xlogin && window.xlogin.login && window.xlogin.login() } | ||
| return |
Contributor
Author
There was a problem hiding this comment.
Addressed in 5386214 — flipped the guard from !(window.xlogin && window.xlogin.id) to window.xlogin && !window.xlogin.id. Three explicit states now: xlogin+id → ACL flow, xlogin+no id → login prompt, no xlogin → fall through to real ACL fetch (so CSP/unpkg failure shows a legitimate error instead of a dead button).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #8.
Change
One early-return at the top of `render` in `panes/sharing-pane.js`. If `window.xlogin.id` is falsy (no Solid WebID / no Nostr pubkey), render a centered "Log in to manage sharing" panel with a button that calls `window.xlogin.login()`. Existing authenticated flow unchanged.
```diff
```
Why this shape
Diff
+14 lines, no behavior change for authenticated users.
Test plan
Edge case (acknowledged, no regression)
If user logs in while on the Sharing tab, the pane doesn't auto re-render — they'd need to click the tab again. Same limitation the current sharing-pane already has on auth-state changes; no regression introduced.