Skip to content

feat: auth-aware welcome.html (completes MVP) - #19

Merged
melvincarvalho merged 1 commit into
gh-pagesfrom
feat-welcome-auth-aware
May 16, 2026
Merged

melvincarvalho merged 1 commit into
gh-pagesfrom
feat-welcome-auth-aware

Conversation

@melvincarvalho

Copy link
Copy Markdown
Contributor

Summary

Closes the visual disconnect where the welcome page looked identical regardless of authentication. Now it adapts to session state. This is the last UX gap from the score-check punch list and effectively completes MVP for the first-run friction-removal arc started in #1.

Signed-out (unchanged)

  • "Sign in" button revealed by HEAD probe to /idp/register
  • "Default sign-in: me / me" credentials block visible
  • Tiles probed with plain `fetch` — auth-gated tiles 401, get dimmed and rerouted to /signin.html

Signed-in (new)

  • "Sign in" button stays hidden
  • Credentials block hidden (already climbed past it)
  • Green "signed in as <webid>" note pointing at /account.html
  • Tiles probed via `session.authFetch` — DPoP-bound bearer attached, /private/ etc. return 200 → tiles stay lit

Implementation

solid-oidc imported as an ES module from the version-pinned jsdelivr URL (same pattern as signin.html and account.html). `session.restore()` on load decides the branch. The familiar "Missing refresh data" throw on a clean first visit is caught and treated as "not signed in."

Locked-tile fallback link also updated: was `./idp` (which 403s in single-user mode), now `./signin.html` (which actually starts a flow).

Test plan

  • Signed-out: identical to before — Sign in primary, creds block visible, auth tiles dim
  • Signed-in (verified in browser): Sign in hidden, creds block hidden, green signed-in note with WebID, all 5 tiles lit
  • Locked-tile click in signed-out state → /signin.html (not /idp)

Bumps jspod to 0.0.21.

Refs #1

The welcome page now reflects sign-in state instead of looking
identical regardless of whether the user is authenticated.

Behaviour change on first paint:

Signed out (unchanged from before):
- "Sign in" button revealed by HEAD probe to /idp/register
- "Default sign-in: me / me" credentials block visible
- Tiles probed with plain fetch — /private/, /inbox/, /settings/
  401 → dimmed and rerouted to /signin.html

Signed in (new):
- "Sign in" button stays hidden
- Credentials block hidden (the user has already climbed past it)
- Green "signed in as <webid>" note pointing to /account.html
- All tiles probed via session.authFetch — DPoP-bound bearer
  attached, /private/ etc. return 200 → tiles stay lit and
  navigate correctly

Implementation: solid-oidc imported as an ES module, same
version-pinned jsdelivr URL as the other auth-aware pages.
session.restore() on load decides which branch to render. The
familiar "Missing refresh data" throw on a clean first visit is
caught and treated as "not signed in."

Locked-tile fallback link changed from ./idp (which 403s in
single-user mode) to ./signin.html (which actually starts a flow).

Bumps jspod to 0.0.21.

Refs #1
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant