feat(pit): accept a whole name in the claim box - #173
Merged
Conversation
The claim box was built for an ending (`eggs`) and hands its value to registerTlds(), which rejects a dotted token. So `scrambled.eggs` — the thing people actually type — came back as "not a valid TLD", even though holding it is just two ordinary steps in order. POST /pit/claim now forks when the value parses as a Moshpit name: claim the ending if it is free, then mint the name under it, and report the name that was asked for rather than the ending it had to take first. Someone else's ending is the one case this cannot finish — minting under it is not ours to do. Whether that name is for sale, taken, or simply unlisted is a question landingFor() already answers, so hand over that card instead of growing a second, thinner copy of the same rules here. A bare ending still goes down the existing list path untouched, and a token that is not a name (`a.b.c`) is still refused rather than being coerced into one. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
Merged
ralyodio
added a commit
that referenced
this pull request
Aug 1, 2026
install.sh resolves releases/latest, so the ten commits merged since v0.14.0 have been sitting on main unreachable — including the reason `curl <name>` did not work. The headline is parking. A parked name always resolved somewhere, but the address it pointed at was a host that routes by Host header and answers "Application not found" for a name it has never heard of, so `curl scrambled.eggs` resolved and then died one layer up (#180). It could not be fixed there: the platform rejects a Moshpit ending as a custom domain and no public CA will certify a TLD outside the DNS root. The bridge is already running locally for the name to resolve at all, so it now serves the answer too — parked names point at loopback and a catch-all responder 302s them to the Pit. Underneath that was a quieter one. fetchTlds read the first page of the ending list and stopped; the registry answers 200 rows and reports the real total, but 200 rows look exactly like a complete list of 200. `.eggs` sat past that line, so `dns install` wrote a config that did not route it and the name failed to resolve — a DNS-shaped symptom three layers from the cause. It was hiding 94% of the namespace: 3707 endings, 200 visible (#181). Also here: dns resolve now reports a parked name's page in the Pit instead of an IP that answers for nobody, with --open to go there (#179) the pit's /n/ pages are crawlable — robots.txt, a generated sitemap, and canonical tags that name the pit host rather than the app host it shares a service with (#175, #176) the claim box takes a whole name, claiming the ending first when it is free and minting the name under it (#173) the endings list pages instead of stopping at 200 (#174), the paste field reads names as well as endings (#172), related endings keep the name you are reading (#177), and integrations ship JSON support matrices (#178) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Typing
hawaiian.chickeninto the claim box on/pitfails with "not a valid TLD — letters, digits and dashes only, no dots".The box was built for an ending (
eggs) and hands its value toregisterTlds(), which rejects a dotted token. But holdinghawaiian.chickenis just two ordinary steps in order — claim.chicken, then minthawaiianunder it — and the form should do both rather than teaching the order to the visitor.Change
POST /pit/claimforks when the submitted value parses as a Moshpit name:hawaiian.chicken is yours./pit?name=hawaiian.chickenThat last case is the one this deliberately does not answer itself. Minting under someone else's ending isn't ours to do, and whether the name is for sale, taken, or simply unlisted is a question
landingFor()already decides — so it hands over that card instead of growing a second, thinner copy of the same rules in the handler.A bare ending still goes down the existing list path untouched, and
a.b.cis still refused rather than coerced into a name.The success flash lands on exactly the URL this was aimed at:
Verification
npm testinapps/pwa— 336 pass, 0 fail (5 new, route-level against a throwaway libSQL db using the same harness asmoshpit-pit-page.test.mjs):a.b.cis still refused🤖 Generated with Claude Code