1
0

Signing in puts people in the building

`member` and `anon` were told apart inside the office by the client and by
nothing else. `access.ts` picked an `officeDepth`, `createOfficeScene` built a
presence layer at full depth — and then nobody ever called `setPresence`, so
both tiers rendered the identical empty room. A tier that changes nothing you
can see is not a tier, and `routes/markers.ts` had already written down why one
drawn only in the browser is worse than none: it is a UI hiding a control over a
body the API hands to whoever asks.

So the refusal happens on the server now.

`GET /api/v1/offices/:id/presence` is the one route that always takes a session,
whatever else the deployment is configured for. `markers.ts` serves its feed to
anonymous callers when no feed is configured, on the grounds that there is
nothing there to protect; that reasoning does not transfer, and the difference is
the whole point — a marker is a company at an address and a presence is a person
at a desk.

The ordering inside the handler is the security property, not a detail. It
resolves the viewer *before* it looks at the id, so an anonymous caller gets an
identical 401 for a real office, a private one and one that was never created.
Check the office first and 404-for-unknown against 401-for-known tells them apart
perfectly, which is the enumeration oracle CONTRACT.md §6 forbids, wearing a
different status code. Three requests and one `deepEqual` hold that down.

`TERA_PRESENCE_DIR` is a second directory rather than a `people` field on the
pack, and that is the design. `types.ts` says a `Presence` binds to a `seatId`
and never to a coordinate so the geometry can be published while the people
cannot — which buys nothing if both live in one file, because an operator who
wants a public floorplan then has to strip the roster out by hand, and the first
time they forget the leak is permanent. Two directories makes the safe thing the
default thing. An office with no roster is 200 and empty, never 404: "no such
office" and "nobody has told me who is in this one" are different problems with
different fixes, and one 404 sends an operator after the wrong one.

On the client, occupancy arrives after the room is on screen rather than before —
the building is worth looking at while a second request is in flight. An API that
answers is believed, including when it answers with nobody; an office where
everyone has gone home is a real fact and overwriting it with invented people to
liven up the demo is the one thing this must never do. An API that does not
answer falls back to a fabricated roster, exactly as the markers do, because a
clone with no server is the flagship case and a member shown the same empty room
as a stranger has been told the tier means something when it does not.

Those twenty-five people are invented and the page says so. `sample.ts` says it
to a reader of the source; `#office-badge` now says "Sample occupancy — these
people are invented" to the person looking at the room, and it is not suppressed
when a real deployment's API merely happened to be down — that is exactly the
case where a member would otherwise read invented names as their colleagues.
Fabricated names at real desks look like a staff list, and a screenshot of one
must not be possible to take without the caption.

The floor plan marks the occupied desks, one colour for everybody where the
scene has four: at three device pixels a hue is a guess. The plan answers "is
anyone there" and the room answers "who, and what are they doing". Hovering a
desk names them, and the readout reads as an address getting more specific —
metres, then room, then person.

server: 127 tests pass, 11 of them new. Client typechecks and builds; the office
chunk absorbed the plan renderer and the entry chunk moved 2.3 kB for the sample
roster. Checked in the browser at office.lumbridgecorp.com: FULL VIEW, the badge,
figures at the benches, dots on the plan, and "3.7, 16.7 m · Alcatraz ·
Clementine Roux" under the pointer.
This commit is contained in:
2026-08-06 01:58:22 -07:00
parent df534c3530
commit 3e9b97ed8b
13 changed files with 856 additions and 5 deletions
+24
View File
@@ -50,6 +50,7 @@ import type {
HealthBody,
MarkersBody,
OfficeDoc,
PresenceBody,
WeatherBody,
} from "../server/wire.ts";
import { SAMPLE_MARKERS, SAMPLE_PALETTE } from "./sample.ts";
@@ -214,6 +215,16 @@ export interface TeraClient {
* a bundled office of its own already has the better answer.
*/
office(id: string): Promise<OfficeDoc | null>;
/**
* Occupancy for one office, or `null` when this deployment will not say.
*
* Always an authenticated call — `routes/presence.ts` refuses an anonymous
* one whatever the deployment's other settings are, because a marker is a
* company at an address and a presence is a person at a desk. A build with no
* API behind it gets `null` and renders the empty building, which is the
* correct picture of an office nobody has told it about.
*/
presence(officeId: string): Promise<PresenceBody | null>;
}
/**
@@ -323,6 +334,19 @@ export function createTeraClient(options: TeraApiOptions = {}): TeraClient {
},
office: (id) => get<OfficeDoc>(`/offices/${encodeURIComponent(id)}`),
/**
* Who is in that office.
*
* `null` for every refusal, which here folds three different facts into one:
* no API at all, an API that wants a session this browser does not have, and
* an office the server will not name. The caller does the same thing with
* all three — draw the building with nobody in it — and a taxonomy it does
* not branch on is a taxonomy nobody maintains. `get` already logs nothing
* and throws nothing; see the note on coarseness at the top of this file.
*/
presence: (officeId) =>
get<PresenceBody>(`/offices/${encodeURIComponent(officeId)}/presence`),
};
}