feat(pit): filter the namespace as you type - #168
Merged
Conversation
Finding an ending meant paging through them. Now there is a filter box: `eggs` matches anywhere in the name, `def*` is a glob anchored at both ends, and the leading dot people naturally type is ignored. Debounced at 200ms on keyup, and the in-flight request is aborted when the next keystroke lands -- otherwise a slow answer for `de` arrives after the fast one for `def*` and the list flickers back to a query nobody is typing any more. `?q=` is also read server-side, so the filter is bookmarkable, shareable, and still works when the script does not run. The form is a plain GET; the script only upgrades it to answer without a page load. The script is the only one this page carries, and that is the bar it had to clear: /pit locked browsers up a fix ago with no JavaScript on it at all, so anything added here has to make the DOM smaller. A dozen matching rows instead of a page load does. Wildcards that mean something to LIKE and nothing in a TLD (% and _) are stripped when the query is parsed rather than escaped on the way to SQL, so no input can reach the database still carrying a wildcard we did not put there. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
ralyodio
marked this pull request as ready for review
August 1, 2026 02:47
Merged
ralyodio
added a commit
that referenced
this pull request
Aug 1, 2026
install.sh resolves releases/latest, so the sixteen commits merged since v0.13.3 have been sitting on main unreachable — including a fix for a page that locks browsers up. The headline is the pit. /pit rendered every ending an account held and a form per name under each, with no bound on either: at 50 endings x 100 names that was 3.1 MiB of HTML and 36,082 DOM elements, and it managed to jam a browser with no script on the page at all (#167). It now draws a window and says what it is not drawing — 173 KiB, 1,926 elements — with a filter box over the top that takes `eggs` as a substring and `def*` as a glob, debounced against the API (#168). The namespace also stopped being the one part of the product a script could not touch: /api/moshpit/* now accepts the same API key /api/me and /api/sessions already did (#169), and /pit/dns finally documents the TronBrowser route for machines whose DNS is not theirs to change (#165). moshcode: foreign keys are enforced, and the licence package.json claims actually ships (#154) cli: help aliases exit 0 (#157), invalid integration commands fail (#160), `--` is honoured (#159), a BOM before a shebang no longer breaks (#158) skills: engines with no skills primitive are reported, not dropped (#166); `--name` requires a value (#156) mcp: an unsupported flag is rejected rather than registered as the server name (#164) pit: the namespace rules are vendored again with a drift test holding them to the published package (#161, #162, #163) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Finding an ending meant paging through them. This adds a filter box over both tabs.
Syntax
eggs.eggs,.eggsalad.eggsdef*.default,.defer, but not.undefde**fExact hits sort first, then shortest, so
eggsputs.eggsabove.eggsaladrather than burying it alphabetically.How it works
keyup(plusinput, since paste and IME never firekeyup) againstGET /api/moshpit/tlds?q=&scope=. The in-flight request is aborted when the next keystroke lands — without that, a slow answer fordecan arrive after the fast one fordef*and overwrite it.?q=filters the page itself, so the filter is bookmarkable, shareable, and works with the script blocked. The form is a plain GET; the script only removes the page load.The script is the only one
/pitcarries, and that was the bar: this page locked browsers up one PR ago with no JavaScript on it at all, so anything added here has to make the DOM smaller. A dozen matching rows instead of a page load does.Safety
%and_mean something to LIKE and nothing in a TLD, so they're stripped when the query is parsed rather than escaped on the way to SQL — no input can reach the database still carrying a wildcard we didn't put there. Covered by a test.Testing
apps/pwa/test/moshpit-search.test.mjs— 16 tests: parser semantics, LIKE-wildcard smuggling, glob anchoring (undefis not adef*), scope isolation (?scope=mineneeds a session and never returns someone else's), the unfiltered response being byte-for-byte unchanged, and?q=filtering the page with no script.apps/pwa: 323 pass, 0 fail. Repo root: 762 pass, 0 fail, 2 skipped.🤖 Generated with Claude Code