Compare commits

..
Author SHA1 Message Date
sjg 3c3fc69542 Refactor HTTP account system
CI / frontend (pull_request) Successful in 5m13s
CI / reuse (pull_request) Successful in 29s
CI / frontend (push) Successful in 4m15s
CI / reuse (push) Successful in 5s
CI / lint (pull_request) Successful in 2m25s
CI / test (pull_request) Successful in 9m24s
CI / lint (push) Successful in 2m23s
CI / test (push) Successful in 8m19s
2026-08-10 23:47:51 +02:00
sjgandClaude Opus 5 d539ff96e5 [docs](trx-rs): write down how a contest and a confirmation are worked
CI / frontend (pull_request) Successful in 5m12s
CI / reuse (pull_request) Successful in 5s
CI / test (push) Successful in 8m0s
CI / lint (pull_request) Successful in 2m22s
CI / test (pull_request) Successful in 8m57s
CI / lint (push) Successful in 2m32s
CI / frontend (push) Successful in 4m13s
CI / reuse (push) Successful in 6s
The manual gains the contest exchange, the Cabrillo entry and the
confirmations.  The plan marks all five phases done, corrects the API paths
to the /api/logbook they were built under -- /logbook is the page, and the
bookmarks API already shadows its own page that way -- and records the two
decisions phase 5 settled: that the Cabrillo header comes from the operator
because no log can derive it, and that a confirmation counts from whichever
bureau answered.

The plan itself travels with this branch: it was written on a branch of its
own that was never proposed for merge, and the earlier attempts to update it
from the implementation branches were silent no-ops, because the edits did
not assert that they had found what they were replacing.

Refs #54

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SyX26FCpMQxiBoC7r5K1A7
Signed-off-by: Stan Grams <sjg@haxx.space>
2026-08-07 21:31:06 +02:00
sjgandClaude Opus 5 ca5cd65c85 [docs](trx-rs): settle the logbook's remaining questions
The clock is the server's, as asked: it is the machine at the radio, where
the browser may be a phone in another timezone with a clock nobody checked.
When the two disagree by more than a second the panel says so, rather than
logging a time the operator did not expect.

The rest, decided against how logging is actually done:

One station log, not one per rig.  DXCC, WAS and LoTW count the callsign, not
the radio, and a station worked on the second rig is still worked.  The rig
goes on the QSO as MY_RIG.  Station location does follow the rig, though —
these rigs can be in different places, so MY_GRIDSQUARE comes from the one
that made the contact, which is what LoTW's station locations expect too.

The operator is a per-QSO field set once per session.  ADIF separates the
callsign used on the air from the person at the key, and multi-operator
stations rotate people through one station callsign.  It defaults from the
configured callsign, so a single operator never touches it.  It cannot come
from the session: the auth roles are control and rx, with nobody's name on
them.

The log file is configurable, defaulting to the user's data directory.
Bookmarks sit in the config directory because they are settings and decode
logs in the cache directory because they are disposable; a QSO log is
irreplaceable, and cache directories get swept.

Import collisions match on callsign, band, mode and a two-minute window.
Loggers rarely agree to the second on the same QSO — one stamps the contact,
the other the entry — so an exact-minute key duplicates half of what it is
asked to merge.  Two minutes absorbs that without swallowing a legitimate
re-work, since contest rules forbid a second contact on the same band and
mode.  Times compare as instants so midnight matches, and modes are
normalised or an imported SSB would miss our USB.

That normalisation is now written down: a rig mode is not an ADIF mode.  DIG
is the one the rig cannot answer — a rig in DIG is in FT8 or FT4 depending on
what is decoding — and WSPR never opens an entry at all, because hearing a
beacon is not a contact.

Refs #54

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SyX26FCpMQxiBoC7r5K1A7
Signed-off-by: Stan Grams <sjg@haxx.space>
2026-08-07 21:30:10 +02:00
sjgandClaude Opus 5 a9e1e86fdc [docs](trx-rs): settle the logbook's panel, its prefill, and its formats
Three answers from the issue, folded into the proposal.

The logbook is a panel of its own rather than a strip on the radio page, and
it stands in every layout: a log can be kept without adopting the ham layout,
and read while another is selected.  The ham layout is then the arrangement
that starts from it, with the radio controls around it.

Prefill is exactly six fields — frequency, mode, rig name, time, callsign and
locator — and nothing else.  A signal report in particular stays empty: an
FT8 SNR is not what was sent, and prefilling one would put a number in the
log that nobody exchanged.  The station's own callsign and locator are not
per-entry fields at all; they are station identity, shown once at the top of
the panel and written into the QSO from configuration.

The file format was left to me.  ADIF stays, because it is not one option
among several: LoTW, eQSL, Club Log, QRZ and every other logger read it and
nothing else, so a log that cannot write it cannot be uploaded, confirmed or
moved.  Nothing on disk is ADI regardless — the store is JSON Lines.  The
second format is Cabrillo 3.0, which ADIF cannot replace: contest logs are
submitted in it and rejected in anything else.  It lands with the contest
exchange fields, since without a serial or a zone it has nothing to write.

Refs #54

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SyX26FCpMQxiBoC7r5K1A7
Signed-off-by: Stan Grams <sjg@haxx.space>
2026-08-07 21:30:10 +02:00
sjgandClaude Opus 5 76e33a91bb [docs](trx-rs): propose the logbook and the ham radio layout
Issue #54 asks for a ham radio layout and an ADIF logbook, with no detail
behind either.  This is what they would be: what the logbook has to hold, how
it is stored, where ADIF is read and written, and which of the existing parts
each half hangs off.

Two things it settles before any code is written.  The log is append-only
JSON Lines rather than the whole-file dump the bookmarks use, because a
station with forty thousand QSOs would rewrite megabytes to log one contact
and lose the lot if the power went mid-dump.  And a decode is not a QSO: the
decoders only ever heard something, so a decoded callsign pre-fills an entry
and never writes one.

The layout is a fifth entry in the operator layouts that already exist,
gated on the rig being able to transmit.

Refs #54

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SyX26FCpMQxiBoC7r5K1A7
Signed-off-by: Stan Grams <sjg@haxx.space>
2026-08-07 21:30:10 +02:00
sjgandClaude Opus 5 ee185b98bc [feat](trx-logbook): work a contest, and record what came back
Phase 5 of the logbook: the exchange, the entry sponsors take, and the
confirmations an award counts.

Contest fields go on the contact — the contest, the serials both ways as
numbers and as words, and the zones — because an exchange is not always a
number: a zone, a section or a name goes in as written.  The serial sent and
the contest stay between contacts, since they belong to the session and not
to the contact just logged, and the serial counts on by itself rather than
being retyped forty times an hour.

Cabrillo 3.0 is written because ADIF cannot do this job: sponsors take
Cabrillo and reject everything else.  Its shape is not ADIF's either — the
frequency is kilohertz below 30 MHz and a band designator above it, the modes
are CW, PH, FM, RY and DG, and the contacts go oldest first, as a contest log
is read.  The header cannot be derived from a log — how many operators, how
much power, what the score is claimed to be — so it comes from the operator,
with single-op, low power, all bands and mixed behind it.

QSL, LoTW and eQSL states are held as ADIF's single letters, and anything
else is refused rather than written: a log that grew states of its own would
be one no other program could read.  A contact is confirmed when any one of
the three says so — an award wants a card or an electronic match, not one of
each, and counting them separately would tell the operator they were short of
what they have.

The bands report counts contacts, distinct stations and confirmations per
band, ordered by wavelength as a band plan reads.

Closes #54

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SyX26FCpMQxiBoC7r5K1A7
Signed-off-by: Stan Grams <sjg@haxx.space>
2026-08-07 21:28:40 +02:00
sjgandClaude Opus 5 18b2d0efe6 [feat](trx-rs): keep a station log, and a layout to work the bands from
CI / lint (pull_request) Successful in 2m23s
CI / frontend (pull_request) Successful in 5m52s
CI / reuse (pull_request) Successful in 6s
CI / test (pull_request) Successful in 9m12s
The logbook of issue #54, in the shape the proposal settled on.

A new crate, trx-logbook, holds the contact, the ADIF reader and writer, the
file, and the rules for telling one contact from two.  ADIF because it is the
only thing the ecosystem reads: LoTW, eQSL, Club Log, QRZ and every other
logger take it and nothing else, so a log that cannot write .adi cannot be
uploaded, confirmed or moved.  The reader is forgiving in the ways real files
are irregular -- lowercase tags, CRLF, missing header, unknown fields, a
declared length that is the only thing ending a value -- and carries what it
does not model through to the export, so a round trip does not strip what
another program wrote.

The file is JSON Lines, appended one line per contact.  A log is the one
thing here that cannot be regenerated, and the bookmark store's whole-file
dump would rewrite megabytes to log one contact and lose all of them if the
power went halfway; an append costs the record being written and no more,
which a test tears a line in half to prove.  Edits append revisions, deletes
append tombstones, and the file compacts when the superseded outnumber the
live.

The panel is its own tab and stands in every layout.  An entry opens with six
fields and no more -- frequency, mode, rig name, time, and the callsign and
locator of whatever decode it was started from.  A report stays empty: an FT8
SNR is not what was sent.  Times come from the server, because the browser
may be a phone in another timezone, and the panel says so when the two
disagree by more than a second.  Worked-before answers as a callsign is
typed.

A decode is not a contact, so the Log button on an FT8 or APRS row opens an
entry and logs nothing by itself.

The ham layout is the fifth operator layout, opening on the logbook with the
radio controls around it, offered only where the rig can transmit.

Two bugs found on the way, both in code written here: a frequency of a whole
number of megahertz ending in a zero rendered as a tenth of itself, in Rust
and in TypeScript alike, because trimming trailing zeros from "20.000000"
walks back through the point.  The API also sits under /api/logbook rather
than /logbook, so it cannot shadow its own page the way /bookmarks does.

Closes #54

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SyX26FCpMQxiBoC7r5K1A7
Signed-off-by: Stan Grams <sjg@haxx.space>
2026-08-07 21:12:03 +02:00
61 changed files with 6294 additions and 487 deletions
+1
View File
@@ -56,6 +56,7 @@ src/
trx-backend-ft450d/ # Yaesu FT-450D ASCII CAT
trx-backend-soapysdr/ # SoapySDR RX with full DSP pipeline (~5,000+ LOC)
trx-client/ # Client binary: remote connection, frontend spawning (~1,500 LOC)
trx-logbook/ # Station log: QSO record, ADIF reader/writer, append-only store
trx-frontend/ # Frontend trait (FrontendSpawner), runtime context
trx-frontend-http/ # Web UI: REST API, SSE, WebSocket audio, session auth
trx-frontend-http-json/ # JSON-over-TCP control frontend
Generated
+109 -5
View File
@@ -316,6 +316,18 @@ version = "1.0.102"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7f202df86484c868dbad7eaa557ef785d5c66295e41b460ef922eca0723b842c"
[[package]]
name = "argon2"
version = "0.5.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3c3610892ee6e0cbce8ae2700349fcf8f98adb0dbfbee85aec3c9179d29cc072"
dependencies = [
"base64ct",
"blake2",
"cpufeatures 0.2.17",
"password-hash",
]
[[package]]
name = "atomic-waker"
version = "1.1.2"
@@ -345,6 +357,12 @@ version = "0.22.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "72b3254f16251a8381aa12e40e3c4d2f0199f8c6508fbecb9d91f575e0fbb8c6"
[[package]]
name = "base64ct"
version = "1.8.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2af50177e190e07a26ab74f8b1efbfe2ef87da2116221318cb1c2e82baf7de06"
[[package]]
name = "bindgen"
version = "0.66.1"
@@ -395,6 +413,24 @@ version = "2.11.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c4512299f36f043ab09a583e57bceb5a5aab7a73db1805848e8fef3c9e8c78b3"
[[package]]
name = "blake2"
version = "0.10.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "46502ad458c9a52b69d4d4d32775c788b7a1b85e8bc9d482d92250fc0e3f8efe"
dependencies = [
"digest 0.10.7",
]
[[package]]
name = "block-buffer"
version = "0.10.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3078c7629b62d3f0439517fa394996acacc5cbc91c5a20d8c658e77abd503a71"
dependencies = [
"generic-array",
]
[[package]]
name = "block-buffer"
version = "0.12.0"
@@ -525,7 +561,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "6f8d983286843e49675a4b7a2d174efe136dc93a18d69130dd18198a6c167601"
dependencies = [
"cfg-if",
"cpufeatures",
"cpufeatures 0.3.0",
"rand_core 0.10.1",
]
@@ -721,6 +757,15 @@ dependencies = [
"windows",
]
[[package]]
name = "cpufeatures"
version = "0.2.17"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "59ed5838eebb26a2bb2e58f6d5b5316989ae9d08bab10e0e6d103e656d1b0280"
dependencies = [
"libc",
]
[[package]]
name = "cpufeatures"
version = "0.3.0"
@@ -739,6 +784,16 @@ dependencies = [
"cfg-if",
]
[[package]]
name = "crypto-common"
version = "0.1.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "78c8292055d1c1df0cce5d180393dc8cce0abec0a7102adb6c7b1eef6016d60a"
dependencies = [
"generic-array",
"typenum",
]
[[package]]
name = "crypto-common"
version = "0.2.1"
@@ -799,15 +854,26 @@ dependencies = [
"zeroize",
]
[[package]]
name = "digest"
version = "0.10.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292"
dependencies = [
"block-buffer 0.10.4",
"crypto-common 0.1.7",
"subtle",
]
[[package]]
name = "digest"
version = "0.11.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "4850db49bf08e663084f7fb5c87d202ef91a3907271aff24a94eb97ff039153c"
dependencies = [
"block-buffer",
"block-buffer 0.12.0",
"const-oid",
"crypto-common",
"crypto-common 0.2.1",
]
[[package]]
@@ -1019,6 +1085,16 @@ dependencies = [
"slab",
]
[[package]]
name = "generic-array"
version = "0.14.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "85649ca51fd72272d7821adaf274ad91c288277713d9c18820d8499a7ff69e9a"
dependencies = [
"typenum",
"version_check",
]
[[package]]
name = "getrandom"
version = "0.2.17"
@@ -1890,6 +1966,17 @@ dependencies = [
"windows-link",
]
[[package]]
name = "password-hash"
version = "0.5.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "346f04948ba92c43e8469c1ee6736c7563d71012b17d40745260fe106aac2166"
dependencies = [
"base64ct",
"rand_core 0.6.4",
"subtle",
]
[[package]]
name = "peeking_take_while"
version = "0.1.2"
@@ -2492,8 +2579,8 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "aacc4cc499359472b4abe1bf11d0b12e688af9a805fa5e3016f9a386dc2d0214"
dependencies = [
"cfg-if",
"cpufeatures",
"digest",
"cpufeatures 0.3.0",
"digest 0.11.2",
]
[[package]]
@@ -3215,9 +3302,11 @@ version = "0.1.0"
dependencies = [
"actix-web",
"actix-ws",
"argon2",
"base64",
"brotli 7.0.0",
"bytes",
"chrono",
"dirs",
"flate2",
"futures-util",
@@ -3226,11 +3315,13 @@ dependencies = [
"rand 0.8.6",
"serde",
"serde_json",
"tempfile",
"tokio",
"tokio-stream",
"tracing",
"trx-core",
"trx-frontend",
"trx-logbook",
"trx-protocol",
"ts-rs",
"uuid",
@@ -3269,6 +3360,19 @@ dependencies = [
"rustfft",
]
[[package]]
name = "trx-logbook"
version = "0.1.0"
dependencies = [
"chrono",
"dirs",
"serde",
"serde_json",
"tempfile",
"tracing",
"uuid",
]
[[package]]
name = "trx-protocol"
version = "0.1.0"
+1
View File
@@ -26,6 +26,7 @@ members = [
"src/trx-server/trx-backend/trx-backend-ft450d",
"src/trx-server/trx-backend/trx-backend-soapysdr",
"src/trx-client",
"src/trx-client/trx-logbook",
"src/trx-client/trx-frontend",
"src/trx-client/trx-frontend/trx-frontend-http",
"src/trx-client/trx-frontend/trx-frontend-http-json",
+1 -1
View File
@@ -1043,7 +1043,7 @@ The `FrontendRuntimeContext` struct in `trx-frontend/src/lib.rs` is decomposed i
|-----------|---------|------------|
| `AudioContext` | Audio streaming channels | `rx`, `tx`, `info`, `decode_rx`, `clients` |
| `DecodeHistoryContext` | Decode history for all types | `ais`, `vdes`, `aprs`, `hf_aprs`, `cw`, `ft8`, `ft4`, `ft2`, `wspr` |
| `HttpAuthConfig` | HTTP auth settings | `enabled`, `rx_passphrase`, `session_ttl_secs`, `tokens` |
| `HttpAuthConfig` | HTTP auth settings | `enabled`, `users_file`, bootstrap admin, `session_ttl_secs`, `tokens` |
| `HttpUiConfig` | HTTP UI display config | `show_sdr_gain_control`, `initial_map_zoom`, `spectrum_*` |
| `RigRoutingContext` | Remote rig state & routing | `active_rig_id`, `remote_rigs`, `rig_states`, `server_connected` |
| `OwnerInfo` | Station metadata | `callsign`, `website_url`, `ais_vessel_url_base` |
+27 -13
View File
@@ -453,25 +453,31 @@ put in the exchange there is nothing for it to write.
| `RigState` | `FREQ`, `BAND`, `MODE`/`SUBMODE`, and the rig id a QSO was made on | watch channel already in the frontend context |
| Client config `general.callsign` | `STATION_CALLSIGN`, and the default `OPERATOR` | already surfaced as `owner_callsign` in frontend meta |
| The QSO's own rig, and its position | `MY_GRIDSQUARE` | per-rig latitude and longitude already carried in the rig list |
| Server clock | `QSO_DATE`, `TIME_ON` in UTC | new `GET /logbook/now`, which also feeds the browser-clock check |
| Server clock | `QSO_DATE`, `TIME_ON` in UTC | new `GET /api/logbook/now`, which also feeds the browser-clock check |
| Decoder panels and map | a pre-filled entry: callsign, grid, and the report to offer | existing decode history; no new plumbing |
| `bandForHz` | `BAND` from a frequency | exists in `map-core.ts`; move to a shared module |
#### HTTP API
Under `/api/logbook`, as the recorder's endpoints are, because `/logbook` itself is the page:
the `/bookmarks` API and the bookmarks page already share a path, and whichever is registered
first wins.
| Method | Path | Purpose |
|--------|------|---------|
| `GET` | `/logbook` | Query: filters, paging |
| `POST` | `/logbook` | Add a QSO |
| `PUT` | `/logbook/{id}` | Edit |
| `DELETE` | `/logbook/{id}` | Delete |
| `GET` | `/logbook/export.adi` | ADIF export, honouring the current filter |
| `GET` | `/logbook/export.cbr` | Cabrillo export of a contest selection |
| `POST` | `/logbook/import` | Import, answering with counts: added, duplicate, rejected |
| `GET` | `/logbook/worked/{call}` | Worked-before: bands and modes |
| `GET` | `/logbook/now` | The server's UTC clock, for stamping entries and checking the browser's |
| `GET` | `/api/logbook` | Query: filters, paging |
| `POST` | `/api/logbook` | Add a QSO |
| `PUT` | `/api/logbook/{id}` | Edit |
| `DELETE` | `/api/logbook/{id}` | Delete |
| `GET` | `/api/logbook/export.adi` | ADIF export, honouring the current filter |
| `GET` | `/api/logbook/export.cbr` | Cabrillo export of a contest selection |
| `POST` | `/api/logbook/import` | Import, answering with counts: added, duplicate, rejected |
| `GET` | `/api/logbook/worked/{call}` | Worked-before: bands and modes |
| `GET` | `/api/logbook/statistics` | Contacts, stations and confirmations, per band |
| `GET` | `/api/logbook/now` | The server's UTC clock, for checking the browser's |
| `GET` | `/api/logbook/prefill` | The six fields an entry opens with |
Writes require the control role, as the rig endpoints do.
Writes require the admin role, as the rig endpoints do.
### Frontend
@@ -505,14 +511,22 @@ task and the rig is the instrument.
### Phases
All five are implemented.
| Phase | Lands |
|-------|-------|
| 1 | `trx-logbook`: `Qso`, the ADI reader and writer, round-trip tests against files from other loggers |
| 2 | Store, dedupe, and the HTTP API behind the control role |
| 2 | Store, dedupe, and the HTTP API behind the admin role |
| 3 | Logbook tab: entry, table, filters, import, export |
| 4 | Ham layout, pre-filled entry from a decode row or the map, worked-before |
| 5 | Contest exchange fields and Cabrillo export; QSL and LoTW/eQSL fields; per-band worked/confirmed statistics |
Two decisions phase 5 settled. The Cabrillo header cannot be derived from a log — how many
operators, how much power, what the score is claimed to be — so it comes from the operator,
with `SINGLE-OP`, `LOW`, `ALL` and `MIXED` behind it. And a confirmation counts from whichever
bureau answered: an award wants one card or one electronic match, not one of each, so a log
that counted them separately would tell the operator they were short of what they have.
### Decisions
**One station log, not one per rig.** Awards and uploads are per station callsign — DXCC, WAS
@@ -527,7 +541,7 @@ setting, which is also what LoTW's station locations expect.
rotate operators through one station callsign, which is why contest loggers record it per QSO.
It is stored per QSO, defaulted from the configured callsign so a single operator never touches
it, and changed on the station line at the top of the panel where it sticks for the session.
It cannot be taken from the session's identity: the auth roles are `control` and `rx`, with no
It cannot be taken from the session's identity: the auth roles are `admin` and `user`, with no
notion of who is logged in.
**Server clock, and the log says so.** The server is the machine at the radio; the browser may
+10 -11
View File
@@ -121,13 +121,12 @@ The spectrum panel uses `<canvas>` elements (WebGL renderer optional) and offers
When auth is enabled, an **auth gate** blocks the UI with:
- Title: "Access Required"
- Subtitle: "Enter passphrase to continue"
- Password input + Login button (green accent, full-width)
- Optional "Continue as Guest" button (shown when RX passphrase is not set)
- Subtitle: "Sign in to continue"
- Username and password inputs + Login button (green accent, full-width)
- Error message area (red `#ff6b6b`)
- Role badge display
Two roles: **Rx** (read-only) and **Control** (full access including TX/PTT).
Two roles: **User** (read-only) and **Admin** (full access including user management).
Session cookie: `trx_http_sid`, HttpOnly, configurable Secure and SameSite attributes.
@@ -340,21 +339,21 @@ Routes are classified into three tiers:
| Tier | Examples | Requirement |
|---|---|---|
| **Public** | `/`, `/index.html`, `/map`, `/auth/*`, static assets | None |
| **Read** | `/status`, `/events`, `/audio`, `/decode`, `/spectrum`, `/bookmarks` | Rx or Control role |
| **Control** | `/set_freq`, `/set_mode`, `/set_ptt`, `/toggle_power`, all other POST | Control role only |
| **Public** | `/`, `/index.html`, `/map`, login/session endpoints, static assets | None |
| **Read** | `/status`, `/events`, `/audio`, `/decode`, `/spectrum`, `/bookmarks` | User or Admin role |
| **Control** | `/set_freq`, `/set_mode`, `/set_ptt`, `/toggle_power`, all other POST | Admin role only |
### 7.2 Session Management
- Sessions are 128-bit random hex tokens stored in HttpOnly cookies
- Configurable TTL (default from TOML config)
- Expired sessions auto-pruned on access
- Constant-time passphrase comparison to mitigate timing attacks
- Passwords are verified against salted Argon2id hashes
### 7.3 TX Access Control
### 7.3 User Management
An additional `tx_access_control_enabled` flag can restrict transmit-related actions even
for Control-role users, providing an extra safety layer.
Only administrators can list, add, update, or remove accounts. The final
administrator cannot be removed or demoted.
---
+102 -23
View File
@@ -66,8 +66,7 @@ both:
|------------|----------|----------|
| `[listen.auth].tokens` | `tokens_file` | one token per line |
| `[[remotes]].auth.token` | `token_file` | the token |
| `[frontends.http.auth].rx_passphrase` | `rx_passphrase_file` | the passphrase |
| `[frontends.http.auth].control_passphrase` | `control_passphrase_file` | the passphrase |
| `[frontends.http.auth].bootstrap_admin_password` | `bootstrap_admin_password_file` | the initial administrator password |
| `[frontends.http_json.auth].tokens` | `tokens_file` | one token per line |
Blank lines and `#` comments are ignored in the list files. A config that holds
@@ -350,17 +349,17 @@ A name in any of those maps that no remote answers to is a config error.
| Field | Type | Default | Description |
|-------|------|---------|-------------|
| `enabled` | bool | `false` | Require a passphrase |
| `rx_passphrase` | string | — | Passphrase granting receive-only access |
| `rx_passphrase_file` | string | — | Read it from this file instead |
| `control_passphrase` | string | — | Passphrase granting full control |
| `control_passphrase_file` | string | — | Read it from this file instead |
| `tx_access_control_enabled` | bool | `true` | Hide TX from unauthenticated users |
| `enabled` | bool | `false` | Enable the user/password ACL |
| `users_file` | string | `"trx-http-users.json"` | Persistent managed user database |
| `bootstrap_admin_username` | string | — | First administrator, used only if the database is absent |
| `bootstrap_admin_password` | string | — | First administrator password |
| `bootstrap_admin_password_file` | string | — | Read the bootstrap password from this file instead |
| `session_ttl_min` | u64 | `480` | Session lifetime |
| `cookie_secure` | bool | `false` | Set Secure on the session cookie (needs HTTPS) |
| `cookie_same_site` | string | `"Lax"` | `Strict`, `Lax`, or `None` |
With `enabled = true`, at least one passphrase must be set.
When enabling ACL for the first time, configure both bootstrap fields. After
the database exists, remove the bootstrap credentials from configuration.
#### `[frontends.rigctl]`
@@ -477,6 +476,81 @@ Each browser tab keeps its own selection, so two tabs can watch two rigs.
---
## Logbook
The **Logbook** tab keeps the station's contacts and speaks ADIF, so a log can
be uploaded to LoTW, eQSL, Club Log or QRZ, or moved to another logger.
An entry opens pre-filled with six fields and no more: the frequency, mode and
name of the rig you are on, the time from the server's clock, and — when the
entry was started from a decode or a map station — that station's callsign and
locator. Signal reports, name, comment and the rest are yours to fill in; a
report in particular is never guessed, because an FT8 SNR is not what was sent.
Your own callsign and locator are not per-contact fields. They are station
identity: the callsign comes from `[trx-client.general].callsign`, the locator
from the rig's position, and both are shown once at the top of the panel. The
operator defaults to the station callsign and can be changed for the session,
which is what a multi-operator station needs.
**Times are the server's**, in UTC — the server is the machine at the radio. If
the browser's clock disagrees by more than a second the entry says so rather
than logging a time you did not expect.
**A decode is not a contact.** The decoders are receive-only, so a **Log**
button on an FT8 or APRS row opens an entry with what was heard in it and logs
nothing by itself. Digital QSOs made in WSJT-X come in through Import ADIF, the
way every other logger takes them.
| Action | What it does |
|--------|--------------|
| Log contact | Writes the entry and opens a fresh one |
| Export ADIF | Downloads the log — filtered, if a filter is set |
| Import ADIF | Reads a file, skipping contacts already held and reporting what could not be read |
| Worked before | Shows, as you type a callsign, which bands and modes it has been worked on |
Two contacts are treated as the same when the callsign, band and mode match and
the times are within two minutes: two loggers rarely stamp a QSO to the same
minute, one recording when it started and the other when it was typed.
The log is a JSON Lines file, appended one contact at a time so a crash costs at
most the contact being written. It lives in your data directory by default;
`[trx-client.logbook].path` moves it, for a station that keeps its log on a
backed-up volume.
### Contests
The **Contest exchange** block on the entry holds the contest's name and the
serials — sent and received. Both stay between contacts, because they belong to
the session rather than to the contact just logged, and the serial sent counts
on by itself so it is not retyped forty times an hour. An exchange that is a
zone, a section or a name rather than a number is kept as written.
**Contest entry (Cabrillo)** exports the entry sponsors accept. Only the
contacts of the contest named there are included. The header — operator
category, power, claimed score — cannot be worked out from a log, so it is
yours to fill in; the defaults are single operator, low power, all bands, mixed
mode.
### Confirmations
The **QSL** column shows a tick when the other station has confirmed, and the
**Confirm** button on a row records a card that has arrived. A confirmation
counts from wherever it came: a paper card, LoTW or eQSL. An award wants one of
them, not all three, so the log does not ask for all three.
**Bands worked** counts, per band, the contacts made, the distinct stations
worked, and how many of those contacts are confirmed.
### Ham radio layout
The **Ham radio** operator layout opens on the logbook with the transceiver
controls around it — the arrangement for working the bands, where logging the
contact is the task and the radio is the instrument. It is offered only where
the selected rig can transmit; a receiver has no contacts to log.
---
## Tune Links
Every page of the web UI carries what the radio is doing in its address, so the
@@ -503,7 +577,7 @@ The link button in the top bar copies the current link to the clipboard. The
address bar itself is updated as you tune, using `replaceState`, so sweeping
the dial does not fill the browser's history.
Applying a link changes the radio, so it needs the `control` role; an `rx`
Applying a link changes the radio, so it needs the `admin` role; a `user`
session opens the page and says the link was not applied. Links describe the
rig's own dial — while a tab is listening to a virtual channel the address is
left as it was, rather than publishing a frequency the rig is not on.
@@ -512,53 +586,58 @@ left as it was, rather than publishing a frequency the rig is not on.
## Authentication
The HTTP frontend supports optional passphrase-based authentication with two
The HTTP frontend supports an optional user/password ACL with multiple accounts and two
roles:
- **rx** — read-only access (monitoring, audio, decode streams)
- **control** — full access (frequency, mode, PTT, and all settings)
- **user** — read-only access (monitoring, audio, decode streams)
- **admin** — full radio control, settings, and user management
### Configuration
```toml
[frontends.http.auth]
enabled = false
rx_passphrase = "rx-only-passphrase"
control_passphrase = "full-control-passphrase"
tx_access_control_enabled = true
users_file = "trx-http-users.json"
bootstrap_admin_username = "admin"
bootstrap_admin_password = "change-this-password"
session_ttl_min = 480
cookie_secure = false # true if served via HTTPS
cookie_same_site = "Lax" # Strict|Lax|None
```
When `enabled = false` (the default), all auth is bypassed and the UI behaves
as before. When enabled, at least one passphrase must be set.
as before. When enabling it for the first time, bootstrap credentials create
the initial administrator and the Argon2id-hashed user database.
### Behaviour
- On login, the server issues an `HttpOnly` session cookie.
- Sessions are in-memory; a server restart invalidates all sessions.
- Rate limiting is applied per IP to mitigate brute-force attempts.
- When `tx_access_control_enabled = true`, TX/PTT controls are hidden and
rejected for unauthenticated or `rx`-role users.
- User records persist in `users_file`; passwords are stored as salted Argon2id hashes.
- `user` sessions cannot call control routes. There is no guest-access mode.
- Administrators can add/remove users and change roles/passwords in Settings.
- Removing an account or changing its password/role revokes its sessions.
### Routes
| Endpoint | Method | Description |
|----------|--------|-------------|
| `/auth/login` | POST | Submit `{ "passphrase": "..." }` |
| `/auth/login` | POST | Submit `{ "username": "...", "password": "..." }` |
| `/auth/logout` | POST | Clear session |
| `/auth/session` | GET | Check current session/role |
| `/auth/users` | GET/POST | List or add users (admin only) |
| `/auth/users/{username}` | PATCH/DELETE | Change password/role or remove user (admin only) |
Protected routes require at least `rx` role. Control routes (set frequency,
mode, PTT, etc.) require `control` role.
Protected routes require at least `user` role. Control routes (set frequency,
mode, PTT, etc.) require `admin` role.
### Frontend Flow
1. On load, the UI calls `/auth/session`.
2. If unauthenticated, a login screen is shown.
3. On successful login, the normal UI loads.
4. `rx` users see a read-only interface; `control` users get full controls.
4. `user` accounts see a read-only interface; admins get full controls.
5. If a session expires mid-use, streams stop and the login screen returns.
### Transport Security
+9 -5
View File
@@ -252,11 +252,11 @@ async fn async_init() -> DynResult<AppState> {
// Set HTTP frontend authentication config
frontend_runtime.http_auth.enabled = cfg.frontends.http.auth.enabled;
frontend_runtime.http_auth.rx_passphrase = cfg.frontends.http.auth.rx_passphrase.clone();
frontend_runtime.http_auth.control_passphrase =
cfg.frontends.http.auth.control_passphrase.clone();
frontend_runtime.http_auth.tx_access_control_enabled =
cfg.frontends.http.auth.tx_access_control_enabled;
frontend_runtime.http_auth.users_file = cfg.frontends.http.auth.users_file.clone();
frontend_runtime.http_auth.bootstrap_admin_username =
cfg.frontends.http.auth.bootstrap_admin_username.clone();
frontend_runtime.http_auth.bootstrap_admin_password =
cfg.frontends.http.auth.bootstrap_admin_password.clone();
frontend_runtime.http_auth.session_ttl_secs = cfg.frontends.http.auth.session_ttl().as_secs();
frontend_runtime.http_auth.cookie_secure = cfg.frontends.http.auth.cookie_secure;
frontend_runtime.http_auth.cookie_same_site = match cfg.frontends.http.auth.cookie_same_site {
@@ -279,6 +279,10 @@ async fn async_init() -> DynResult<AppState> {
.http
.decode_history_retention_min_by_rig
.clone();
frontend_runtime.http_ui.logbook_path = cfg.logbook.path.clone();
// The callsign the station is on the air with, which every contact is
// logged under and which the operator defaults to.
frontend_runtime.http_ui.station_callsign = cfg.general.callsign.clone();
// Resolve remote entries: CLI --url > [[remotes]] > legacy [remote] > error
let resolved_remotes: Vec<RemoteEntry> = if let Some(ref url) = cli.url {
+12 -6
View File
@@ -257,9 +257,9 @@ impl Default for DecodeHistoryContext {
/// HTTP authentication configuration.
pub struct HttpAuthConfig {
pub enabled: bool,
pub rx_passphrase: Option<String>,
pub control_passphrase: Option<String>,
pub tx_access_control_enabled: bool,
pub users_file: String,
pub bootstrap_admin_username: Option<String>,
pub bootstrap_admin_password: Option<String>,
pub session_ttl_secs: u64,
pub cookie_secure: bool,
pub cookie_same_site: String,
@@ -271,9 +271,9 @@ impl Default for HttpAuthConfig {
fn default() -> Self {
Self {
enabled: false,
rx_passphrase: None,
control_passphrase: None,
tx_access_control_enabled: true,
users_file: "trx-http-users.json".to_string(),
bootstrap_admin_username: None,
bootstrap_admin_password: None,
session_ttl_secs: 480 * 60,
cookie_secure: false,
cookie_same_site: "Lax".to_string(),
@@ -292,6 +292,10 @@ pub struct HttpUiConfig {
pub bandplan_region: String,
pub decode_history_retention_min: u64,
pub decode_history_retention_min_by_rig: HashMap<String, u64>,
/// Where the station log is kept; `None` takes the default.
pub logbook_path: Option<String>,
/// The callsign contacts are logged under, and the operator by default.
pub station_callsign: Option<String>,
}
impl Default for HttpUiConfig {
@@ -305,6 +309,8 @@ impl Default for HttpUiConfig {
bandplan_region: "iaru_r1".to_string(),
decode_history_retention_min: 24 * 60,
decode_history_retention_min_by_rig: HashMap::new(),
logbook_path: None,
station_callsign: None,
}
}
}
@@ -11,6 +11,8 @@ build = "build.rs"
[dependencies]
trx-core = { path = "../../../trx-core" }
trx-frontend = { path = ".." }
trx-logbook = { path = "../../trx-logbook" }
chrono = { version = "0.4", default-features = false, features = ["clock", "serde"] }
trx-protocol = { path = "../../../../src/trx-protocol" }
tokio = { workspace = true, features = ["full"] }
serde = { workspace = true, features = ["derive"] }
@@ -26,7 +28,11 @@ flate2 = { workspace = true }
brotli = "7"
rand = "0.8"
hex = "0.4"
argon2 = "0.5"
pickledb = "0.5"
dirs = "6"
uuid = { workspace = true }
ts-rs = "12.0.1"
[dev-dependencies]
tempfile = "3"
@@ -633,9 +633,12 @@ function elementById(id) {
compact: { label: "Compact", advanced: false, audio: false, scheduler: false, preferredTab: "main" },
broadcast: { label: "Broadcast", unavailable: "Broadcast requires an enumerated WFM-capable receiver", advanced: false, audio: true, scheduler: false, preferredTab: "main", capability: "broadcast" },
digital: { label: "Digital", unavailable: "Digital requires a compatible rig mode and an available decoder", advanced: false, audio: false, scheduler: false, preferredTab: "digital-modes", capability: "digital" },
full: { label: "Full controls", advanced: true, audio: true, scheduler: true, preferredTab: "main" }
full: { label: "Full controls", advanced: true, audio: true, scheduler: true, preferredTab: "main" },
// Working the bands: the log is the task and the radio is the instrument,
// so this one opens on the logbook with the controls a keystroke away.
ham: { label: "Ham radio", unavailable: "Ham radio needs a rig that can transmit", advanced: true, audio: true, scheduler: false, preferredTab: "logbook", capability: "ham" }
};
const layoutCapabilities = { broadcast: false, digital: false };
const layoutCapabilities = { broadcast: false, digital: false, ham: false };
let activeRigId = null;
const layoutSections = [
{ id: "advanced-radio-controls", key: "advanced" },
@@ -1320,7 +1323,7 @@ function decodeAuthSession(value) {
if (typeof session.authenticated !== "boolean") {
throw new TypeError("The authentication response has no authenticated flag");
}
if (session.role !== void 0 && session.role !== "rx" && session.role !== "control") {
if (session.role !== void 0 && session.role !== "user" && session.role !== "admin") {
throw new TypeError("The authentication response has an invalid role");
}
if (session.auth_disabled !== void 0 && typeof session.auth_disabled !== "boolean") {
@@ -1328,12 +1331,16 @@ function decodeAuthSession(value) {
}
const decoded = { authenticated: session.authenticated };
if (session.role !== void 0) decoded.role = session.role;
if (session.username !== void 0) {
if (typeof session.username !== "string") throw new TypeError("The authentication response has an invalid username");
decoded.username = session.username;
}
if (session.auth_disabled !== void 0) decoded.auth_disabled = session.auth_disabled;
return decoded;
}
var authDisabledSession = {
authenticated: true,
role: "control",
role: "admin",
auth_disabled: true
};
async function fetchAuthSession() {
@@ -1347,11 +1354,11 @@ async function fetchAuthSession() {
return { authenticated: false };
}
}
async function login(passphrase) {
async function login(username, password) {
const response = await fetch("/auth/login", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ passphrase })
body: JSON.stringify({ username, password })
});
if (response.status === 404) return authDisabledSession;
if (!response.ok) {
@@ -1360,6 +1367,34 @@ async function login(passphrase) {
}
return decodeAuthSession(await response.json());
}
async function userRequest(path, init) {
const response = await fetch(path, init);
if (!response.ok) {
const payload = await response.json().catch(() => ({}));
throw new Error(payload.error || `User operation failed (${response.status})`);
}
return response;
}
async function listUsers() {
const value = await userRequest("/auth/users").then((response) => response.json());
if (!Array.isArray(value) || !value.every((user) => {
if (typeof user !== "object" || user === null) return false;
const record = user;
return typeof record.username === "string" && (record.role === "user" || record.role === "admin");
})) {
throw new TypeError("The user list response is malformed");
}
return value;
}
async function createUser(username, password, role) {
await userRequest("/auth/users", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ username, password, role }) });
}
async function updateUser(username, changes) {
await userRequest(`/auth/users/${encodeURIComponent(username)}`, { method: "PATCH", headers: { "Content-Type": "application/json" }, body: JSON.stringify(changes) });
}
async function deleteUser(username) {
await userRequest(`/auth/users/${encodeURIComponent(username)}`, { method: "DELETE" });
}
async function logout() {
const response = await fetch("/auth/logout", { method: "POST" });
if (response.status !== 404 && !response.ok) throw new Error("Logout failed");
@@ -1530,6 +1565,7 @@ function decodeCbor(buffer) {
var TAB_ORDER = [
"main",
"bookmarks",
"logbook",
"digital-modes",
"map",
"satellites",
@@ -1541,6 +1577,7 @@ var TAB_ORDER = [
var TAB_PATHS = {
main: "/",
bookmarks: "/bookmarks",
logbook: "/logbook",
"digital-modes": "/digital-modes",
map: "/map",
satellites: "/satellites",
@@ -1764,6 +1801,7 @@ var pluginGroups = {
satellites: ["/satellite-predictions.js"],
statistics: ["/map-core.js"],
bookmarks: ["/bookmarks.js"],
logbook: ["/logbook.js"],
recorder: [],
settings: ["/vchan.js", "/scheduler.js"]
};
@@ -1788,7 +1826,7 @@ async function loadPlugins(group) {
for (const path of pluginGroups[group]) await loadPlugin(path);
}
async function loadEagerPlugins() {
await Promise.all(["digital-modes", "bookmarks", "settings"].map(loadPlugins));
await Promise.all(["digital-modes", "bookmarks", "logbook", "settings"].map(loadPlugins));
}
async function loadPluginsForTab(tab) {
await loadPlugins(tab);
@@ -1857,32 +1895,32 @@ function isVchanRdsEntry(value) {
}
void loadDecoderRegistry(refreshOperatorLayoutCapabilities);
var authRole = null;
var authUsername = null;
var authEnabled = true;
async function checkAuthStatus() {
return fetchAuthSession();
}
async function authLogin(passphrase) {
return login(passphrase);
async function authLogin(username, password) {
return login(username, password);
}
async function authLogout() {
try {
await logout();
authRole = null;
authUsername = null;
disconnect();
setDecodeHistoryOverlayVisible(false);
requiredElement("content").style.display = "none";
requiredElement("loading").style.display = "none";
requiredElement("auth-passphrase").value = "";
requiredElement("auth-password").value = "";
updateAuthUI();
const authStatus = await checkAuthStatus();
const allowGuest = authStatus.role === "rx";
showAuthGate(allowGuest);
showAuthGate();
} catch (e) {
console.error("Logout failed:", e);
showAuthError("Logout failed");
}
}
function showAuthGate(allowGuest = false) {
function showAuthGate() {
if (!authEnabled) return;
setDecodeHistoryOverlayVisible(false);
requiredElement("loading").style.display = "none";
@@ -1899,10 +1937,6 @@ function showAuthGate(allowGuest = false) {
document.querySelectorAll(".tab-panel").forEach((panel) => {
panel.style.display = "none";
});
const guestBtn2 = document.getElementById("auth-guest-btn");
if (guestBtn2) {
guestBtn2.style.display = allowGuest ? "block" : "none";
}
document.querySelectorAll(".tab-bar .tab").forEach((btn) => {
btn.classList.toggle("active", btn.dataset.tab === "main");
});
@@ -1946,7 +1980,7 @@ function updateAuthUI() {
}
if (authRole) {
if (badge) badge.style.display = "block";
if (badgeRole) badgeRole.textContent = authRole === "control" ? "Control (full access)" : "RX (read-only)";
if (badgeRole) badgeRole.textContent = `${authUsername || "local"}${authRole === "admin" ? "Admin" : "User (read-only)"}`;
if (headerAuthBtn2) {
headerAuthBtn2.textContent = "Logout";
headerAuthBtn2.style.display = "block";
@@ -1962,7 +1996,7 @@ function updateAuthUI() {
}
function applyAuthRestrictions() {
if (!authRole) return;
if (authRole === "rx") {
if (authRole === "user") {
const pttBtn2 = document.getElementById("ptt-btn");
const powerBtn2 = document.getElementById("power-btn");
const lockBtn2 = document.getElementById("lock-btn");
@@ -2265,7 +2299,7 @@ function syncTopBarAccess() {
rigSwitch.style.display = loggedOut ? "none" : "";
}
if (headerRigSwitchSelect) {
headerRigSwitchSelect.disabled = loggedOut || authRole === "rx" || lastRigIds.length === 0;
headerRigSwitchSelect.disabled = loggedOut || authRole === "user" || lastRigIds.length === 0;
}
}
var overviewDrawPending = false;
@@ -2901,7 +2935,7 @@ function applyRigList(activeRigId, rigIds, displayNames) {
}
const nextKey = lastRigIds.join("\0") + "|" + (lastActiveRigId || "");
const rigListChanged = prevKey !== nextKey;
const disableSwitch = lastRigIds.length === 0 || !authRole || authRole === "rx";
const disableSwitch = lastRigIds.length === 0 || !authRole || authRole === "user";
populateRigPicker(headerRigSwitchSelect, lastRigIds, lastActiveRigId, disableSwitch);
updateRigSubtitle(lastActiveRigId);
window.trxUi?.setActiveRig(lastActiveRigId);
@@ -2950,7 +2984,10 @@ function refreshOperatorLayoutCapabilities() {
));
window.trxUi?.setLayoutCapabilities({
broadcast: rigModes.some((modes) => modes.includes("WFM")),
digital: decoderModes.size > 0 && rigModes.some((modes) => modes.some((mode) => decoderModes.has(mode)))
digital: decoderModes.size > 0 && rigModes.some((modes) => modes.some((mode) => decoderModes.has(mode))),
// A logbook is for contacts made, so the layout built around it is offered
// where a rig can transmit.
ham: serverRigs.some((rig) => rig?.tx === true)
});
}
function showHint(msg, duration) {
@@ -4501,7 +4538,7 @@ function scheduleTuneLinkSync() {
async function applyTuneLink(link) {
const wanted = link.rig || link.mode || link.freqHz != null || link.bandwidthHz != null;
if (!wanted) return;
if (authRole === "rx") {
if (authRole === "user") {
showHint("Read-only session — link not applied", 2500);
return;
}
@@ -5244,8 +5281,8 @@ async function switchRigFromSelect(selectEl) {
showHint("No rig selected", 1500);
return;
}
if (authRole === "rx") {
showHint("Control role required", 1500);
if (authRole === "user") {
showHint("Admin role required", 1500);
return;
}
if (!lastRigIds.includes(selectEl.value)) {
@@ -5859,7 +5896,7 @@ function navigateToTab(name, options = {}) {
const leavingSatellites = _activeTab === "satellites" && name !== "satellites";
const { updateHistory = true, replaceHistory = false } = options;
if (authEnabled && !authRole && name !== "main") {
showAuthGate(false);
showAuthGate();
return;
}
const btn = document.querySelector(`.tab-bar .tab[data-tab="${name}"]`);
@@ -5972,11 +6009,11 @@ window.addEventListener("resize", () => {
scheduleSpectrumLayout();
});
async function initializeApp() {
showAuthGate(false);
showAuthGate();
const authStatus = await checkAuthStatus();
authEnabled = !authStatus.auth_disabled;
if (!authEnabled) {
authRole = "control";
authRole = "admin";
hideAuthGate();
updateAuthUI();
connect();
@@ -5988,6 +6025,7 @@ async function initializeApp() {
}
if (authStatus.authenticated) {
authRole = authStatus.role ?? null;
authUsername = authStatus.username ?? null;
hideAuthGate();
updateAuthUI();
applyAuthRestrictions();
@@ -5997,8 +6035,7 @@ async function initializeApp() {
resizeHeaderSignalCanvas();
startHeaderSignalSampling();
} else {
const allowGuest = authStatus.role === "rx";
showAuthGate(allowGuest);
showAuthGate();
}
}
var settingsUiReady = false;
@@ -6010,19 +6047,104 @@ function initSettingsUI() {
window.trx.modules.backgroundDecode.initialize(lastActiveRigId, authRole);
window.trx.modules.backgroundDecode.wireEvents();
}
void refreshUserManagement();
}
async function refreshUserManagement() {
const section = document.getElementById("user-management");
if (!section) return;
section.style.display = authEnabled && authRole === "admin" ? "block" : "none";
if (section.style.display === "none") return;
const list = requiredElement("user-list");
try {
const users = await listUsers();
list.replaceChildren(...users.map((user) => {
const row = document.createElement("div");
row.className = "sch-row";
row.style.cssText = "display:flex;align-items:center;gap:.5rem;flex-wrap:wrap;margin:.4rem 0";
const name = document.createElement("strong");
name.textContent = user.username;
name.style.minWidth = "10rem";
const role = document.createElement("select");
role.className = "auth-input";
for (const value of ["user", "admin"]) {
const option = document.createElement("option");
option.value = value;
option.textContent = value === "admin" ? "Admin" : "User";
option.selected = user.role === value;
role.append(option);
}
const password = document.createElement("input");
password.type = "password";
password.placeholder = "New password";
password.autocomplete = "new-password";
password.className = "auth-input";
password.minLength = 8;
const save = document.createElement("button");
save.type = "button";
save.textContent = "Save";
save.addEventListener("click", async () => {
const changes = { role: role.value };
if (password.value) changes.password = password.value;
await runUserOperation(() => updateUser(user.username, changes));
});
const remove = document.createElement("button");
remove.type = "button";
remove.textContent = "Remove";
remove.className = "danger";
remove.disabled = user.username === authUsername;
remove.addEventListener("click", async () => {
if (await window.trxUi.confirm({ title: "Remove user?", message: `Remove ${user.username} and revoke their sessions?`, confirmLabel: "Remove", danger: true })) {
await runUserOperation(() => deleteUser(user.username));
}
});
row.append(name, role, password, save, remove);
return row;
}));
} catch (error) {
showUserManagementError(error);
}
}
function showUserManagementError(error) {
const element = document.getElementById("user-management-error");
if (!element) return;
element.textContent = error instanceof Error ? error.message : String(error);
element.style.display = "block";
}
async function runUserOperation(operation) {
try {
await operation();
const error = document.getElementById("user-management-error");
if (error) error.style.display = "none";
await refreshUserManagement();
} catch (reason) {
showUserManagementError(reason);
}
}
document.getElementById("user-create-form")?.addEventListener("submit", (event) => {
event.preventDefault();
const username = requiredElement("user-create-username");
const password = requiredElement("user-create-password");
const role = requiredElement("user-create-role");
void runUserOperation(async () => {
await createUser(username.value, password.value, role.value);
username.value = "";
password.value = "";
role.value = "user";
});
});
requiredElement("auth-form").addEventListener("submit", async (e) => {
e.preventDefault();
const passphraseEl = requiredElement("auth-passphrase");
const passphrase = passphraseEl.value;
const usernameEl = requiredElement("auth-username");
const passwordEl = requiredElement("auth-password");
const btn = requiredElement("auth-form").querySelector("button[type=submit]");
if (!btn) return;
btn.disabled = true;
btn.textContent = "Logging in...";
try {
const result = await authLogin(passphrase);
const result = await authLogin(usernameEl.value, passwordEl.value);
authRole = result.role ?? null;
passphraseEl.value = "";
authUsername = result.username ?? usernameEl.value;
passwordEl.value = "";
hideAuthGate();
updateAuthUI();
applyAuthRestrictions();
@@ -6032,28 +6154,13 @@ requiredElement("auth-form").addEventListener("submit", async (e) => {
resizeHeaderSignalCanvas();
startHeaderSignalSampling();
} catch (err) {
showAuthError("Invalid passphrase");
showAuthError("Invalid username or password");
console.error("Login error:", err);
} finally {
btn.disabled = false;
btn.textContent = "Login";
}
});
var guestBtn = document.getElementById("auth-guest-btn");
if (guestBtn) {
guestBtn.addEventListener("click", () => {
authRole = "rx";
requiredElement("auth-passphrase").value = "";
hideAuthGate();
updateAuthUI();
applyAuthRestrictions();
connect();
connectDecode();
initSettingsUI();
resizeHeaderSignalCanvas();
startHeaderSignalSampling();
});
}
var headerAuthBtn = document.getElementById("header-auth-btn");
if (headerAuthBtn) {
headerAuthBtn.addEventListener("click", async () => {
@@ -6062,7 +6169,7 @@ if (headerAuthBtn) {
await authLogout();
}
} else {
showAuthGate(false);
showAuthGate();
}
});
}
@@ -4,7 +4,7 @@ import {
collapseAprsDuplicates,
normalizeAprsPacket,
renderAprsPacketRow
} from "./chunk-OPEIVJGD.js";
} from "./chunk-REYSUJQ4.js";
import {
forActiveRig,
isActiveRigDecode
@@ -139,6 +139,9 @@ function renderAprsRow(pkt, isFresh) {
},
onCopy: (text) => {
void copyAprsCoords(text);
},
onLog: (call, gridsquare) => {
aprsWindow.logContact?.({ call, gridsquare: gridsquare ?? void 0, decoder: "aprs" });
}
});
}
@@ -358,7 +358,7 @@ var bgdWindow = window;
btn.title = bgdDirty ? "Apply these bookmarks to the background decoder" : "No changes to save";
}
function isControlRole() {
return backgroundDecodeRole === "control" || hostState.authEnabled === false;
return backgroundDecodeRole === "admin" || hostState.authEnabled === false;
}
function showToast(msg, isError) {
const el = document.getElementById("background-decode-toast");
@@ -42,7 +42,7 @@ function bmEsc(str) {
return d.innerHTML;
}
function bmCanControl() {
return !hostState.authEnabled || hostState.authRole === "control";
return !hostState.authEnabled || hostState.authRole === "admin";
}
function bmSyncAccess() {
const canCtrl = bmCanControl();
@@ -214,6 +214,16 @@ function summarizeAprsPayload(packet) {
const text = info.replace(/^[>;<?]/, "").trim();
return text.length ? text : null;
}
function maidenheadForLatLon(lat, lon) {
const adjustedLon = lon + 180;
const adjustedLat = lat + 90;
const field = String.fromCharCode(65 + Math.floor(adjustedLon / 20)) + String.fromCharCode(65 + Math.floor(adjustedLat / 10));
const square = String(Math.floor(adjustedLon % 20 / 2)) + String(Math.floor(adjustedLat % 10));
const subLon = adjustedLon % 2 * 60 / 5;
const subLat = adjustedLat % 1 * 60 / 2.5;
const sub = String.fromCharCode(97 + Math.floor(subLon)) + String.fromCharCode(97 + Math.floor(subLat));
return `${field}${square}${sub}`.toUpperCase();
}
function renderAprsPacketRow(packet, options = {}) {
const row = document.createElement("details");
row.className = "aprs-packet";
@@ -224,7 +234,7 @@ function renderAprsPacketRow(packet, options = {}) {
const summary = summarizeAprsPayload(packet);
const hasPosition = packet.lat != null && packet.lon != null;
const qrzHref = `https://qrzcq.com/call/${encodeURIComponent(packet.srcCall || "")}`;
row.innerHTML = `<summary class="decode-line"><span class="aprs-time">${escapeAprsHtml(time)}</span>` + (options.badge ? `<span class="aprs-badge aprs-badge-band">${escapeAprsHtml(options.badge)}</span>` : "") + renderAprsSymbolSlot(packet, escapeAprsHtml) + `<span class="aprs-call">${escapeAprsHtml(packet.srcCall ?? "")}</span><span class="aprs-badge aprs-badge-type aprs-badge-type-${category}">${escapeAprsHtml(aprsCategoryLabel(category))}</span><span class="decode-line-summary">${summary ? escapeAprsHtml(summary) : renderAprsInfo(packet)}</span>` + (packet.crcOk ? "" : '<span class="aprs-badge aprs-badge-crc">CRC</span>') + (options.distance ? `<span class="decode-line-distance">${escapeAprsHtml(options.distance)}</span>` : "") + `</summary><div class="decode-expanded"><div class="decode-expanded-meta"><span>&gt;${escapeAprsHtml(packet.destCall || "--")}</span><span>${escapeAprsHtml(packet.path || "no path")}</span><span>${escapeAprsHtml(aprsAgeText(packet._tsMs))}</span><span>CRC ${packet.crcOk ? "ok" : "failed"}</span>` + (hasPosition ? `<a class="aprs-pos" href="javascript:void(0)" data-aprs-map="${packet.lat},${packet.lon}">${packet.lat?.toFixed(5)}, ${packet.lon?.toFixed(5)}</a>` : "") + `</div><div class="decode-expanded-raw">${renderAprsInfo(packet)}</div>` + (packet.info_bytes?.length ? `<div class="decode-expanded-bytes">${escapeAprsHtml(aprsHexBytes(packet.info_bytes))}</div>` : "") + `<div class="aprs-row-actions">` + (hasPosition ? `<button class="aprs-inline-btn" type="button" data-aprs-map="${packet.lat},${packet.lon}">Map</button>` : "") + (hasPosition ? `<button class="aprs-inline-btn" type="button" data-aprs-copy="${packet.lat},${packet.lon}">Copy Coords</button>` : "") + `<a class="aprs-inline-btn" href="${qrzHref}" target="_blank" rel="noopener">QRZ</a></div></div>`;
row.innerHTML = `<summary class="decode-line"><span class="aprs-time">${escapeAprsHtml(time)}</span>` + (options.badge ? `<span class="aprs-badge aprs-badge-band">${escapeAprsHtml(options.badge)}</span>` : "") + renderAprsSymbolSlot(packet, escapeAprsHtml) + `<span class="aprs-call">${escapeAprsHtml(packet.srcCall ?? "")}</span><span class="aprs-badge aprs-badge-type aprs-badge-type-${category}">${escapeAprsHtml(aprsCategoryLabel(category))}</span><span class="decode-line-summary">${summary ? escapeAprsHtml(summary) : renderAprsInfo(packet)}</span>` + (packet.crcOk ? "" : '<span class="aprs-badge aprs-badge-crc">CRC</span>') + (options.distance ? `<span class="decode-line-distance">${escapeAprsHtml(options.distance)}</span>` : "") + `</summary><div class="decode-expanded"><div class="decode-expanded-meta"><span>&gt;${escapeAprsHtml(packet.destCall || "--")}</span><span>${escapeAprsHtml(packet.path || "no path")}</span><span>${escapeAprsHtml(aprsAgeText(packet._tsMs))}</span><span>CRC ${packet.crcOk ? "ok" : "failed"}</span>` + (hasPosition ? `<a class="aprs-pos" href="javascript:void(0)" data-aprs-map="${packet.lat},${packet.lon}">${packet.lat?.toFixed(5)}, ${packet.lon?.toFixed(5)}</a>` : "") + `</div><div class="decode-expanded-raw">${renderAprsInfo(packet)}</div>` + (packet.info_bytes?.length ? `<div class="decode-expanded-bytes">${escapeAprsHtml(aprsHexBytes(packet.info_bytes))}</div>` : "") + `<div class="aprs-row-actions">` + (hasPosition ? `<button class="aprs-inline-btn" type="button" data-aprs-map="${packet.lat},${packet.lon}">Map</button>` : "") + (hasPosition ? `<button class="aprs-inline-btn" type="button" data-aprs-copy="${packet.lat},${packet.lon}">Copy Coords</button>` : "") + `<a class="aprs-inline-btn" href="${qrzHref}" target="_blank" rel="noopener">QRZ</a>` + (options.onLog && packet.srcCall ? '<button class="aprs-inline-btn" type="button" data-aprs-log="1">Log</button>' : "") + `</div></div>`;
row.querySelectorAll("[data-aprs-map]").forEach((element) => {
element.addEventListener("click", (event) => {
event.preventDefault();
@@ -233,6 +243,15 @@ function renderAprsPacketRow(packet, options = {}) {
if (Number.isFinite(lat) && Number.isFinite(lon)) options.onMap?.(lat, lon);
});
});
const logButton = row.querySelector("[data-aprs-log]");
if (logButton) {
logButton.addEventListener("click", (event) => {
event.preventDefault();
event.stopPropagation();
const grid = packet.lat != null && packet.lon != null ? maidenheadForLatLon(packet.lat, packet.lon) : null;
options.onLog?.(packet.srcCall ?? "", grid);
});
}
const copyButton = row.querySelector("[data-aprs-copy]");
if (copyButton) {
copyButton.addEventListener("click", (event) => {
@@ -152,6 +152,24 @@ function initializeFtxDecoder(config) {
second: "2-digit"
});
row.innerHTML = `<span class="ft8-time">${time}</span><span class="ft8-snr">${snr?.toFixed(1) ?? "--"}</span><span class="ft8-dt">${delta?.toFixed(2) ?? "--"}</span><span class="ft8-freq">${frequency?.toFixed(0) ?? "--"}</span><span class="ft8-msg">${renderMessage(raw)}</span>`;
const station = bridge.ft8ExtractLikelyCallsign?.(raw) ?? extractFtxCallsign(raw);
if (station) {
const log = document.createElement("button");
log.type = "button";
log.className = "ft8-log-btn";
log.textContent = "Log";
log.title = `Start a log entry for ${station}`;
log.addEventListener("click", (event) => {
event.stopPropagation();
const details = bridge.ft8ExtractLocatorDetails?.(raw) ?? extractFtxLocatorDetails(raw);
bridge.logContact?.({
call: station,
gridsquare: details.find((detail) => detail.station === station)?.grid,
decoder: id
});
});
row.appendChild(log);
}
return row;
};
const render = () => {
@@ -1,6 +1,6 @@
import {
initializeFtxDecoder
} from "./chunk-PJ5Q7CWJ.js";
} from "./chunk-WU5EWJX4.js";
import "./chunk-S57W63QN.js";
import "./chunk-KL66PICH.js";
@@ -1,6 +1,6 @@
import {
initializeFtxDecoder
} from "./chunk-PJ5Q7CWJ.js";
} from "./chunk-WU5EWJX4.js";
import "./chunk-S57W63QN.js";
import "./chunk-KL66PICH.js";
@@ -2,7 +2,7 @@ import {
initializeFt8FamilyBar,
initializeFtxDecoder,
installFtxCompatibilityHelpers
} from "./chunk-PJ5Q7CWJ.js";
} from "./chunk-WU5EWJX4.js";
import "./chunk-S57W63QN.js";
import "./chunk-KL66PICH.js";
@@ -4,7 +4,7 @@ import {
collapseAprsDuplicates,
normalizeAprsPacket,
renderAprsPacketRow
} from "./chunk-OPEIVJGD.js";
} from "./chunk-REYSUJQ4.js";
import {
forActiveRig,
isActiveRigDecode
@@ -0,0 +1,433 @@
import {
hostCore,
hostState
} from "./chunk-KL66PICH.js";
// src/plugins/logbook.ts
var bridge = window;
var el = (id) => document.getElementById(id);
var form = el("log-entry-form");
var callInput = el("log-call");
var freqInput = el("log-freq");
var modeInput = el("log-mode");
var rstSentInput = el("log-rst-sent");
var rstRcvdInput = el("log-rst-rcvd");
var gridInput = el("log-grid");
var nameInput = el("log-name");
var commentInput = el("log-comment");
var operatorInput = el("log-operator");
var rowsBody = el("log-rows");
var summaryEl = el("log-summary");
var workedEl = el("log-worked-before");
var clockEl = el("log-clock");
var stationCallEl = el("log-station-callsign");
var stationRigEl = el("log-station-rig-name");
var stationGridEl = el("log-station-grid");
var filterCall = el("log-filter-call");
var filterBand = el("log-filter-band");
var filterMode = el("log-filter-mode");
var importBtn = el("log-import-btn");
var importFile = el("log-import-file");
var exportLink = el("log-export-btn");
var clearBtn = el("log-clear-btn");
var saveBtn = el("log-save-btn");
var contestIdInput = el("log-contest-id");
var stxInput = el("log-stx");
var srxInput = el("log-srx");
var statisticsRows = el("log-statistics-rows");
var cabrilloContest = el("log-cbr-contest");
var cabrilloCallsign = el("log-cbr-callsign");
var cabrilloOperator = el("log-cbr-operator");
var cabrilloPower = el("log-cbr-power");
var cabrilloScore = el("log-cbr-score");
var cabrilloExport = el("log-cbr-export");
var entryStartedAt = null;
var entryRigId = null;
var entryRigName = null;
var entryGrid = null;
var qsos = [];
var workedRequest = 0;
function notify(message, kind) {
if (bridge.trxUi.notify) bridge.trxUi.notify(message, kind ? { kind } : void 0);
else hostCore.showHint(message, 2e3);
}
async function getJson(path) {
const response = await fetch(path);
if (!response.ok) throw new Error(`HTTP ${String(response.status)}`);
return await response.json();
}
function formatFreq(hz) {
if (!Number.isFinite(hz) || hz <= 0) return "";
return String(Number((hz / 1e6).toFixed(6)));
}
function parseFreq(text) {
const value = Number(text.trim().replace(/\s+/g, "").replace(",", "."));
if (!Number.isFinite(value) || value <= 0) return null;
return value < 1e5 ? Math.round(value * 1e6) : Math.round(value);
}
function numberOrNull(text) {
const trimmed = (text ?? "").trim();
if (!trimmed || !/^\d+$/.test(trimmed)) return null;
const value = Number(trimmed);
return Number.isSafeInteger(value) ? value : null;
}
function utcDate(iso) {
const date = new Date(iso);
return Number.isNaN(date.getTime()) ? "" : date.toISOString().slice(0, 10);
}
function utcTime(iso) {
const date = new Date(iso);
return Number.isNaN(date.getTime()) ? "" : date.toISOString().slice(11, 19);
}
async function openEntry(seed = {}) {
const params = new URLSearchParams();
if (hostState.lastActiveRigId) params.set("remote", hostState.lastActiveRigId);
if (seed.decoder) params.set("decoder", seed.decoder);
if (seed.call) params.set("call", seed.call);
if (seed.gridsquare) params.set("gridsquare", seed.gridsquare);
try {
const prefill = await getJson(`/api/logbook/prefill?${params.toString()}`);
applyPrefill(prefill);
} catch (error) {
console.error("logbook prefill failed", error);
}
}
function applyPrefill(prefill) {
entryStartedAt = prefill.started_at;
entryRigId = prefill.rig_id;
entryRigName = prefill.my_rig;
if (freqInput) freqInput.value = formatFreq(prefill.freq_hz);
if (modeInput) modeInput.value = prefill.submode ?? prefill.mode;
if (callInput && prefill.call) callInput.value = prefill.call;
if (gridInput && prefill.gridsquare) gridInput.value = prefill.gridsquare;
if (stationRigEl) stationRigEl.textContent = prefill.my_rig ?? "no rig";
showClock(prefill);
updateWorkedBefore();
}
function showClock(prefill) {
if (!clockEl) return;
const time = utcTime(prefill.started_at);
const drift = Math.abs(Date.now() - prefill.epoch_ms);
clockEl.textContent = drift > 1e3 ? `${time}Z · your clock is ${(drift / 1e3).toFixed(0)}s out` : `${time}Z`;
clockEl.classList.toggle("is-adrift", drift > 1e3);
}
function resetEntry() {
for (const input of [callInput, rstSentInput, rstRcvdInput, gridInput, nameInput, commentInput, srxInput]) {
if (input) input.value = "";
}
if (workedEl) workedEl.textContent = "";
void openEntry();
}
async function submitEntry(event) {
event.preventDefault();
const call = callInput?.value.trim() ?? "";
if (!call) {
notify("A contact needs a callsign", "error");
callInput?.focus();
return;
}
const freqHz = parseFreq(freqInput?.value ?? "");
if (freqHz == null) {
notify("A contact needs a frequency", "error");
freqInput?.focus();
return;
}
const typedMode = (modeInput?.value ?? "").trim().toUpperCase();
const isSideband = typedMode === "USB" || typedMode === "LSB";
const body = {
// The server stamps the time; this is the one it gave when the entry
// opened, so a contact logged five minutes later keeps the time it started.
started_at: entryStartedAt,
call,
freq_hz: freqHz,
mode: isSideband ? "SSB" : typedMode,
submode: isSideband ? typedMode : null,
rst_sent: rstSentInput?.value ?? null,
rst_rcvd: rstRcvdInput?.value ?? null,
gridsquare: gridInput?.value ?? null,
name: nameInput?.value ?? null,
comment: commentInput?.value ?? null,
contest_id: contestIdInput?.value ?? null,
// The exchange is a number when it is a serial and a word when it is a
// zone or a section; both are kept, and the log writes whichever it has.
stx: numberOrNull(stxInput?.value),
stx_string: numberOrNull(stxInput?.value) == null ? stxInput?.value ?? null : null,
srx: numberOrNull(srxInput?.value),
srx_string: numberOrNull(srxInput?.value) == null ? srxInput?.value ?? null : null,
station_callsign: stationCallEl?.textContent?.trim() ?? null,
operator: operatorInput?.value ?? null,
my_gridsquare: entryGrid,
my_rig: entryRigName,
rig_id: entryRigId
};
if (saveBtn) saveBtn.disabled = true;
try {
const response = await fetch("/api/logbook", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify(body)
});
if (!response.ok) {
const detail = await response.json().catch(() => ({}));
throw new Error(detail.error ?? `HTTP ${String(response.status)}`);
}
notify(`${call} logged`);
const sent = numberOrNull(stxInput?.value);
resetEntry();
if (stxInput && sent != null) stxInput.value = String(sent + 1);
await refreshLog();
} catch (error) {
notify(`Could not log: ${error instanceof Error ? error.message : String(error)}`, "error");
} finally {
if (saveBtn) saveBtn.disabled = false;
}
}
function updateWorkedBefore() {
if (!workedEl) return;
const call = callInput?.value.trim() ?? "";
if (call.length < 3) {
workedEl.textContent = "";
return;
}
const request = ++workedRequest;
void getJson(
`/api/logbook/worked/${encodeURIComponent(call)}`
).then((answer) => {
if (request !== workedRequest || !workedEl) return;
if (answer.worked.length === 0) {
workedEl.textContent = "Not worked before";
workedEl.classList.remove("is-worked");
return;
}
const where = answer.worked.map((entry) => `${entry.band} ${entry.mode}`).join(", ");
workedEl.textContent = `Worked before: ${where}`;
workedEl.classList.add("is-worked");
}).catch(() => {
});
}
function currentQuery() {
const params = new URLSearchParams();
const call = filterCall?.value.trim();
if (call) params.set("call", call);
if (filterBand?.value) params.set("band", filterBand.value);
if (filterMode?.value) params.set("mode", filterMode.value);
return params.toString();
}
async function refreshLog() {
try {
const query = currentQuery();
const answer = await getJson(
`/api/logbook${query ? `?${query}` : ""}`
);
qsos = answer.qsos;
renderRows();
renderFilterOptions();
if (summaryEl) {
summaryEl.textContent = query ? `${String(qsos.length)} of ${String(answer.total)} contacts` : `${String(answer.total)} contact${answer.total === 1 ? "" : "s"}`;
}
if (exportLink) exportLink.href = `/api/logbook/export.adi${query ? `?${query}` : ""}`;
await refreshStatistics();
} catch (error) {
console.error("logbook read failed", error);
}
}
async function refreshStatistics() {
if (!statisticsRows) return;
try {
const answer = await getJson("/api/logbook/statistics");
if (answer.bands.length === 0) {
statisticsRows.innerHTML = '<tr><td colspan="4" class="log-empty">Nothing worked yet.</td></tr>';
return;
}
const fragment = document.createDocumentFragment();
for (const band of answer.bands) {
const row = document.createElement("tr");
for (const value of [band.band, band.contacts, band.stations, band.confirmed]) {
const cell = document.createElement("td");
cell.textContent = String(value);
row.appendChild(cell);
}
fragment.appendChild(row);
}
statisticsRows.replaceChildren(fragment);
} catch (error) {
console.error("logbook statistics failed", error);
}
}
function syncCabrilloLink() {
if (!cabrilloExport) return;
const params = new URLSearchParams();
const contest = cabrilloContest?.value.trim();
if (contest) {
params.set("contest", contest);
}
const callsign = cabrilloCallsign?.value.trim() || (stationCallEl?.textContent?.trim() ?? "");
if (callsign) params.set("callsign", callsign);
if (cabrilloOperator?.value) params.set("category_operator", cabrilloOperator.value);
if (cabrilloPower?.value) params.set("category_power", cabrilloPower.value);
const score = numberOrNull(cabrilloScore?.value);
if (score != null) params.set("claimed_score", String(score));
const operator = operatorInput?.value.trim();
if (operator) params.set("operators", operator);
cabrilloExport.href = `/api/logbook/export.cbr?${params.toString()}`;
}
function renderRows() {
if (!rowsBody) return;
if (qsos.length === 0) {
rowsBody.innerHTML = '<tr><td colspan="10" class="log-empty">No contacts yet. Work someone and log them here, or bring a log in with Import ADIF.</td></tr>';
return;
}
const fragment = document.createDocumentFragment();
for (const qso of qsos) {
const row = document.createElement("tr");
row.dataset.qsoId = qso.id;
const cells = [
utcDate(qso.started_at),
utcTime(qso.started_at),
qso.call,
qso.band ?? "",
qso.submode ?? qso.mode,
qso.rst_sent ?? "",
qso.rst_rcvd ?? "",
qso.gridsquare ?? "",
qso.my_rig ?? "",
qso.confirmed ? "✓" : ""
];
for (const [index, value] of cells.entries()) {
const cell = document.createElement("td");
cell.textContent = value ?? "";
if (index === 2) cell.className = "log-cell-call";
row.appendChild(cell);
}
const actions = document.createElement("td");
const confirm = document.createElement("button");
confirm.type = "button";
confirm.className = "log-row-btn";
confirm.textContent = qso.confirmed ? "Unconfirm" : "Confirm";
confirm.title = qso.confirmed ? "Mark this contact as not confirmed" : "Mark this contact confirmed by QSL";
confirm.addEventListener("click", () => {
void setConfirmed(qso, !qso.confirmed);
});
actions.appendChild(confirm);
const remove = document.createElement("button");
remove.type = "button";
remove.className = "log-row-btn";
remove.textContent = "Delete";
remove.setAttribute("aria-label", `Delete the contact with ${qso.call}`);
remove.addEventListener("click", () => {
void deleteQso(qso);
});
actions.appendChild(remove);
row.appendChild(actions);
fragment.appendChild(row);
}
rowsBody.replaceChildren(fragment);
}
function renderFilterOptions() {
for (const [select, values] of [
[filterBand, [...new Set(qsos.map((q) => q.band).filter((b) => !!b))]],
[filterMode, [...new Set(qsos.map((q) => q.submode ?? q.mode).filter(Boolean))]]
]) {
if (!select) continue;
const chosen = select.value;
const known = new Set([...select.options].map((option) => option.value));
for (const value of [...values].sort()) {
if (known.has(value)) continue;
select.add(new Option(value, value));
}
select.value = chosen;
}
}
async function setConfirmed(qso, confirmed) {
try {
const response = await fetch(`/api/logbook/${encodeURIComponent(qso.id)}`, {
method: "PUT",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
...qso,
// A card is a card: this is the paper one, and an electronic
// confirmation the log already holds is left where it is.
qsl_rcvd: confirmed ? "Y" : "N"
})
});
if (!response.ok) throw new Error(`HTTP ${String(response.status)}`);
await refreshLog();
} catch (error) {
notify(`Could not update: ${error instanceof Error ? error.message : String(error)}`, "error");
}
}
async function deleteQso(qso) {
const confirmed = await bridge.trxUi.confirm({
title: "Delete this contact?",
message: `${qso.call} on ${qso.band ?? formatFreq(qso.freq_hz)} will be removed from the log.`,
confirmLabel: "Delete"
});
if (!confirmed) return;
try {
const response = await fetch(`/api/logbook/${encodeURIComponent(qso.id)}`, { method: "DELETE" });
if (!response.ok) throw new Error(`HTTP ${String(response.status)}`);
await refreshLog();
} catch (error) {
notify(`Could not delete: ${error instanceof Error ? error.message : String(error)}`, "error");
}
}
async function importAdif(file) {
try {
const response = await fetch("/api/logbook/import", { method: "POST", body: await file.arrayBuffer() });
if (!response.ok) throw new Error(`HTTP ${String(response.status)}`);
const outcome = await response.json();
const parts = [`${String(outcome.added)} added`];
if (outcome.duplicate > 0) parts.push(`${String(outcome.duplicate)} already held`);
if (outcome.rejected.length > 0) parts.push(`${String(outcome.rejected.length)} not readable`);
notify(parts.join(", "));
await refreshLog();
} catch (error) {
notify(`Import failed: ${error instanceof Error ? error.message : String(error)}`, "error");
}
}
function renderStation() {
const callsign = hostState.ownerCallsign ?? "";
if (stationCallEl) stationCallEl.textContent = callsign || "no callsign set";
if (operatorInput && !operatorInput.value) operatorInput.value = callsign;
if (stationGridEl) {
const grid = hostState.serverLat != null && hostState.serverLon != null ? hostCore.latLonToMaidenhead(hostState.serverLat, hostState.serverLon) : "";
entryGrid = grid || null;
stationGridEl.textContent = grid;
}
}
form?.addEventListener("submit", (event) => {
void submitEntry(event);
});
clearBtn?.addEventListener("click", resetEntry);
callInput?.addEventListener("input", updateWorkedBefore);
for (const control of [filterCall, filterBand, filterMode]) {
control?.addEventListener("input", () => {
void refreshLog();
});
control?.addEventListener("change", () => {
void refreshLog();
});
}
for (const control of [cabrilloContest, cabrilloCallsign, cabrilloOperator, cabrilloPower, cabrilloScore]) {
control?.addEventListener("input", syncCabrilloLink);
control?.addEventListener("change", syncCabrilloLink);
}
importBtn?.addEventListener("click", () => {
importFile?.click();
});
importFile?.addEventListener("change", () => {
const file = importFile.files?.[0];
if (file) void importAdif(file);
importFile.value = "";
});
bridge.logContact = (seed) => {
bridge.navigateToTab?.("logbook");
void openEntry(seed).then(() => callInput?.focus());
};
renderStation();
if (cabrilloCallsign && !cabrilloCallsign.value) {
cabrilloCallsign.value = stationCallEl?.textContent?.trim() ?? "";
}
syncCabrilloLink();
void openEntry();
void refreshLog();
@@ -1,6 +1,6 @@
import {
aprsSymbolSprite
} from "./chunk-OPEIVJGD.js";
} from "./chunk-REYSUJQ4.js";
// src/map-core.ts
function mapEl(id) {
@@ -272,7 +272,7 @@ function schedulerOptionalEl(id) {
const nextBtn = schedulerEl("scheduler-next-btn");
if (!prevBtn || !nextBtn) return;
const state = schedulerInterleaveState(currentConfig);
const enabled = schedulerRole === "control" && !!currentRigId && !schedulerStepPending && state.activeEntries.length > 1;
const enabled = schedulerRole === "admin" && !!currentRigId && !schedulerStepPending && state.activeEntries.length > 1;
prevBtn.disabled = !enabled;
nextBtn.disabled = !enabled;
const hint = enabled ? "Select a different active scheduler entry" : "Available only when multiple scheduler entries are active";
@@ -354,7 +354,7 @@ function schedulerOptionalEl(id) {
const panel = schedulerEl("scheduler-panel");
if (!panel) return;
const mode = currentConfig && currentConfig.mode || "disabled";
const isControl = schedulerRole === "control";
const isControl = schedulerRole === "admin";
setSelected("scheduler-mode-select", mode);
const satEnabled = currentConfig && currentConfig.satellites && currentConfig.satellites.enabled;
const controlRow = document.querySelector(".scheduler-control-row");
@@ -22,6 +22,7 @@ SPDX-License-Identifier: GPL-2.0-or-later
<svg xmlns="http://www.w3.org/2000/svg" style="display:none">
<symbol id="icon-home" viewBox="0 0 16 16" fill="none" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"><path d="M2.8 7 8 2.9 13.2 7"/><path d="M4.3 5.9V13h7.4V5.9"/><path d="M6.8 13V9.3h2.4V13"/></symbol>
<symbol id="icon-bookmark" viewBox="0 0 16 16" fill="none" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"><path d="M4 2h8v12l-4-2.5L4 14V2z"/></symbol>
<symbol id="icon-logbook" viewBox="0 0 16 16" fill="none" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"><path d="M3.5 2h8a1 1 0 0 1 1 1v10a1 1 0 0 1-1 1h-8a1 1 0 0 1-1-1V3a1 1 0 0 1 1-1z"/><path d="M5.5 2v12"/><path d="M7.5 5.5h3M7.5 8h3M7.5 10.5h2"/></symbol>
<symbol id="icon-digital" viewBox="0 0 16 16" fill="none" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"><path d="M1 11.5h2.6V4.5h3.2v7h3.2v-7h3.2v7H15"/></symbol>
<symbol id="icon-map" viewBox="0 0 16 16" fill="none" stroke="currentColor" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"><path d="M8 2a4 4 0 0 1 4 4c0 3-4 8-4 8S4 9 4 6a4 4 0 0 1 4-4z"/><circle cx="8" cy="6" r="1.2" fill="currentColor" stroke="none"/></symbol>
<symbol id="icon-satellite" viewBox="0 0 16 16" fill="none" stroke="currentColor" stroke-width="1.4" stroke-linecap="round" stroke-linejoin="round"><path d="M2 13.2 5.6 9.6"/><path d="M4.2 8.2a3.4 3.4 0 0 1 4.8 4.8z"/><path d="M9.2 6.6a3.2 3.2 0 0 1 2.6 2.6"/><path d="M9.8 3.6a6.2 6.2 0 0 1 5.2 5.2"/></symbol>
@@ -53,6 +54,10 @@ SPDX-License-Identifier: GPL-2.0-or-later
<svg class="tab-icon" aria-hidden="true"><use href="#icon-bookmark"/></svg>
<span class="tab-label">Bookmarks</span>
</button>
<button class="tab" data-tab="logbook">
<svg class="tab-icon" aria-hidden="true"><use href="#icon-logbook"/></svg>
<span class="tab-label">Logbook</span>
</button>
<button class="tab" data-tab="digital-modes" aria-label="Digital modes">
<svg class="tab-icon" aria-hidden="true"><use href="#icon-digital"/></svg>
<span class="tab-label">Digital modes</span>
@@ -118,13 +123,13 @@ SPDX-License-Identifier: GPL-2.0-or-later
<div id="auth-gate" class="auth-gate" style="display:none;">
<div class="auth-gate-head">
<div class="auth-gate-title">Access Required</div>
<div class="auth-gate-sub">Enter passphrase to continue</div>
<div class="auth-gate-sub">Sign in to continue</div>
</div>
<form id="auth-form" class="auth-form">
<input type="password" id="auth-passphrase" class="auth-input" placeholder="Passphrase" autocomplete="off" />
<input type="text" id="auth-username" class="auth-input" placeholder="Username" autocomplete="username" required />
<input type="password" id="auth-password" class="auth-input" placeholder="Password" autocomplete="current-password" required />
<button type="submit" class="auth-submit">Login</button>
</form>
<button id="auth-guest-btn" type="button" class="auth-guest" style="display: none;">Continue as Guest</button>
<div id="auth-error" class="auth-error" style="display: none;"></div>
<div id="auth-role" class="auth-role" style="display: none;"></div>
</div>
@@ -480,6 +485,192 @@ SPDX-License-Identifier: GPL-2.0-or-later
</div>
</div>
</div>
<div id="tab-logbook" class="tab-panel" style="display:none;">
<div id="logbook-panel" class="log-panel">
<!-- Station: who the contacts are logged under, and from where. Shown
once rather than typed into every entry. -->
<div class="log-station">
<div class="log-station-identity">
<span class="log-station-call" id="log-station-callsign">--</span>
<label class="log-station-operator">
<span>Operator</span>
<input type="text" id="log-operator" class="status-input" autocomplete="off"
spellcheck="false" aria-label="Operator callsign" />
</label>
</div>
<div class="log-station-rig">
<span id="log-station-rig-name">--</span>
<span id="log-station-grid" class="log-station-grid"></span>
<span id="log-clock" class="log-clock" aria-live="polite"></span>
</div>
</div>
<!-- Entry: opens pre-filled with the six fields the radio and the clock
can answer for. Everything else is the operator's. -->
<form id="log-entry-form" class="log-entry" autocomplete="off">
<div class="log-entry-grid">
<label class="log-field log-field-call">
<span>Callsign</span>
<input type="text" id="log-call" class="status-input" required
spellcheck="false" aria-describedby="log-worked-before" />
</label>
<label class="log-field">
<span>Frequency</span>
<input type="text" id="log-freq" class="status-input" inputmode="decimal" />
</label>
<label class="log-field log-field-narrow">
<span>Mode</span>
<input type="text" id="log-mode" class="status-input" spellcheck="false" />
</label>
<label class="log-field log-field-narrow">
<span>RST sent</span>
<input type="text" id="log-rst-sent" class="status-input" spellcheck="false" />
</label>
<label class="log-field log-field-narrow">
<span>RST rcvd</span>
<input type="text" id="log-rst-rcvd" class="status-input" spellcheck="false" />
</label>
<label class="log-field log-field-narrow">
<span>Locator</span>
<input type="text" id="log-grid" class="status-input" spellcheck="false" />
</label>
<label class="log-field">
<span>Name</span>
<input type="text" id="log-name" class="status-input" />
</label>
<label class="log-field">
<span>Comment</span>
<input type="text" id="log-comment" class="status-input" />
</label>
</div>
<details class="log-contest" id="log-contest-block">
<summary>Contest exchange</summary>
<div class="log-entry-grid">
<label class="log-field">
<span>Contest</span>
<input type="text" id="log-contest-id" class="status-input" spellcheck="false"
placeholder="CQ-WW-SSB" />
</label>
<label class="log-field log-field-narrow">
<span>Serial sent</span>
<input type="text" id="log-stx" class="status-input" inputmode="numeric" />
</label>
<label class="log-field log-field-narrow">
<span>Received</span>
<input type="text" id="log-srx" class="status-input" />
</label>
</div>
</details>
<div class="log-entry-actions">
<span id="log-worked-before" class="log-worked" aria-live="polite"></span>
<span class="log-entry-buttons">
<button type="button" id="log-clear-btn" class="log-secondary-btn">Clear</button>
<button type="submit" id="log-save-btn" class="log-primary-btn">Log contact</button>
</span>
</div>
</form>
<!-- The log itself. -->
<div class="log-list-toolbar">
<input type="text" id="log-filter-call" class="status-input" placeholder="Callsign&hellip;"
aria-label="Filter by callsign" />
<select id="log-filter-band" class="status-input" aria-label="Filter by band">
<option value="">All bands</option>
</select>
<select id="log-filter-mode" class="status-input" aria-label="Filter by mode">
<option value="">All modes</option>
</select>
<span class="log-toolbar-spacer"></span>
<a id="log-export-btn" class="log-secondary-btn" href="/api/logbook/export.adi"
download>Export ADIF</a>
<button type="button" id="log-import-btn" class="log-secondary-btn">Import ADIF</button>
<input type="file" id="log-import-file" accept=".adi,.adif,text/plain" hidden />
</div>
<div class="log-table-wrap">
<table class="log-table">
<thead>
<tr>
<th scope="col">Date</th>
<th scope="col">Time</th>
<th scope="col">Callsign</th>
<th scope="col">Band</th>
<th scope="col">Mode</th>
<th scope="col">Sent</th>
<th scope="col">Rcvd</th>
<th scope="col">Locator</th>
<th scope="col">Rig</th>
<th scope="col">QSL</th>
<th scope="col"><span class="visually-hidden">Actions</span></th>
</tr>
</thead>
<tbody id="log-rows"></tbody>
</table>
</div>
<div id="log-summary" class="log-summary" aria-live="polite"></div>
<details class="log-report" id="log-statistics-block">
<summary>Bands worked</summary>
<div class="log-table-wrap">
<table class="log-table">
<thead>
<tr>
<th scope="col">Band</th>
<th scope="col">Contacts</th>
<th scope="col">Stations</th>
<th scope="col">Confirmed</th>
</tr>
</thead>
<tbody id="log-statistics-rows"></tbody>
</table>
</div>
</details>
<details class="log-report" id="log-contest-export-block">
<summary>Contest entry (Cabrillo)</summary>
<p class="log-report-note">
Contest logs are submitted in Cabrillo and rejected in anything else.
Only the contacts of the contest named here go into the entry.
</p>
<div class="log-entry-grid">
<label class="log-field">
<span>Contest</span>
<input type="text" id="log-cbr-contest" class="status-input" spellcheck="false"
placeholder="CQ-WW-SSB" />
</label>
<label class="log-field">
<span>Callsign</span>
<input type="text" id="log-cbr-callsign" class="status-input" spellcheck="false" />
</label>
<label class="log-field">
<span>Operators</span>
<select id="log-cbr-operator" class="status-input">
<option value="SINGLE-OP">Single operator</option>
<option value="MULTI-OP">Multi operator</option>
<option value="CHECKLOG">Checklog</option>
</select>
</label>
<label class="log-field">
<span>Power</span>
<select id="log-cbr-power" class="status-input">
<option value="LOW">Low</option>
<option value="HIGH">High</option>
<option value="QRP">QRP</option>
</select>
</label>
<label class="log-field log-field-narrow">
<span>Claimed score</span>
<input type="text" id="log-cbr-score" class="status-input" inputmode="numeric" />
</label>
</div>
<div class="log-entry-actions">
<span class="log-entry-buttons">
<a id="log-cbr-export" class="log-secondary-btn" href="/api/logbook/export.cbr"
download>Export Cabrillo</a>
</span>
</div>
</details>
</div>
</div>
<div id="tab-bookmarks" class="tab-panel" style="display:none;">
<div class="bm-toolbar">
<select id="bm-scope-picker" class="status-input" aria-label="Bookmark scope">
@@ -1559,6 +1750,19 @@ SPDX-License-Identifier: GPL-2.0-or-later
</div>
</div>
</div>
<section id="user-management" style="display:none; margin-top:1rem;">
<h2 class="section-heading">User management</h2>
<div class="settings-card">
<form id="user-create-form" class="sch-row" style="flex-wrap:wrap; gap:.5rem;">
<input id="user-create-username" class="auth-input" placeholder="Username" autocomplete="off" required />
<input id="user-create-password" class="auth-input" type="password" placeholder="Password (8+ characters)" autocomplete="new-password" minlength="8" required />
<select id="user-create-role" class="auth-input"><option value="user">User</option><option value="admin">Admin</option></select>
<button type="submit" class="auth-submit">Add user</button>
</form>
<div id="user-management-error" class="auth-error" style="display:none;"></div>
<div id="user-list" style="margin-top:.75rem;"></div>
</div>
</section>
</div>
<div id="tab-about" class="tab-panel" style="display:none;">
<h2 class="section-heading">About</h2>
@@ -196,8 +196,7 @@ body {
font-size: var(--fs-base);
box-sizing: border-box;
}
.auth-submit,
.auth-guest {
.auth-submit {
width: 100%;
padding: 0.65rem 0.75rem;
border-radius: var(--radius-md);
@@ -213,16 +212,11 @@ body {
font-weight: 700;
}
.auth-submit:hover:not(:disabled) { background: var(--accent-green-hover); }
.auth-guest {
background: var(--btn-bg);
color: var(--text);
border: 1px solid var(--border-light);
font-weight: 600;
margin-top: var(--space-4);
}
.auth-guest:hover:not(:disabled) { background: var(--btn-hover-bg); }
.auth-error { color: var(--accent-red); font-size: var(--fs-sm); margin-top: var(--space-4); }
.auth-role { margin-top: var(--space-4); color: var(--text-muted); font-size: var(--fs-sm); }
#user-management .auth-input { width: auto; min-width: 9rem; flex: 1 1 10rem; margin-bottom: 0; }
#user-management .auth-submit { width: auto; }
#user-management button { padding: 0.55rem 0.75rem; }
.label { color: var(--text-muted); font-size: 0.9rem; margin-bottom: 6px; display: block; }
#tab-main .label > span {
@@ -6388,3 +6382,280 @@ body[data-operator-layout="broadcast"] #cw-bar-overlay {
}
#tab-statistics > .section-heading { margin-bottom: 0; }
/* =========================================================================
Logbook
========================================================================= */
.log-panel {
padding: 1rem;
display: flex;
flex-direction: column;
gap: 0.85rem;
}
/* Who the contacts are logged under, and from where: shown once, not typed
into every entry. */
.log-station {
display: flex;
flex-wrap: wrap;
align-items: center;
justify-content: space-between;
gap: 0.75rem;
padding: 0.6rem 0.85rem;
border: 1px solid var(--border-light);
border-radius: 0.5rem;
background: var(--bg-secondary);
}
.log-station-identity {
display: flex;
align-items: center;
gap: 0.85rem;
min-width: 0;
}
.log-station-call {
font-size: 1.05rem;
font-weight: 700;
letter-spacing: 0.04em;
color: var(--text);
}
.log-station-operator {
display: inline-flex;
align-items: center;
gap: 0.4rem;
font-size: 0.78rem;
color: var(--text-muted);
}
.log-station-operator input {
width: 7rem;
text-transform: uppercase;
}
.log-station-rig {
display: flex;
align-items: center;
gap: 0.75rem;
font-size: 0.82rem;
color: var(--text-muted);
min-width: 0;
}
.log-station-grid {
font-variant-numeric: tabular-nums;
}
.log-clock {
font-variant-numeric: tabular-nums;
padding: 0.1rem 0.45rem;
border-radius: 0.3rem;
background: color-mix(in srgb, var(--card-bg) 70%, transparent);
}
/* A browser clock that disagrees with the radio's is worth saying out loud:
the times in a log are the one thing that cannot be corrected later. */
.log-clock.is-adrift {
color: var(--accent-yellow, #b7791f);
font-weight: 600;
}
.log-entry {
border: 1px solid var(--border-light);
border-radius: 0.5rem;
padding: 0.85rem;
background: var(--bg-secondary);
}
.log-entry-grid {
display: grid;
grid-template-columns: repeat(auto-fit, minmax(8.5rem, 1fr));
gap: 0.6rem 0.75rem;
}
.log-field {
display: flex;
flex-direction: column;
gap: 0.25rem;
min-width: 0;
font-size: 0.75rem;
color: var(--text-muted);
}
.log-field input {
min-width: 0;
}
.log-field-call {
grid-column: span 2;
}
.log-field-call input {
font-size: 1.05rem;
font-weight: 700;
letter-spacing: 0.06em;
text-transform: uppercase;
}
.log-field-narrow {
max-width: 10rem;
}
.log-entry-actions {
display: flex;
align-items: center;
justify-content: space-between;
gap: 0.75rem;
margin-top: 0.75rem;
}
.log-entry-buttons {
display: inline-flex;
gap: 0.5rem;
margin-left: auto;
}
.log-worked {
font-size: 0.8rem;
color: var(--text-muted);
}
.log-worked.is-worked {
color: var(--accent-green);
font-weight: 600;
}
.log-primary-btn {
background: var(--accent-green);
color: #fff;
border: none;
border-radius: 0.35rem;
padding: 0.4rem 1.1rem;
font-weight: 600;
cursor: pointer;
}
.log-secondary-btn {
display: inline-flex;
align-items: center;
background: var(--bg-secondary);
border: 1px solid var(--border-light);
border-radius: 0.35rem;
color: var(--text-muted);
padding: 0.35rem 0.75rem;
font-size: 0.82rem;
text-decoration: none;
cursor: pointer;
}
.log-secondary-btn:hover {
background: var(--card-bg);
color: var(--text);
}
.log-list-toolbar {
display: flex;
flex-wrap: wrap;
align-items: center;
gap: 0.5rem;
}
.log-list-toolbar .status-input {
max-width: 11rem;
}
.log-toolbar-spacer {
flex: 1 1 auto;
}
.log-table-wrap {
overflow-x: auto;
border: 1px solid var(--border-light);
border-radius: 0.5rem;
}
.log-table {
width: 100%;
border-collapse: collapse;
font-size: 0.83rem;
}
.log-table th {
position: sticky;
top: 0;
z-index: 1;
text-align: left;
padding: 0.5rem 0.65rem;
background: var(--bg-secondary);
border-bottom: 1px solid var(--border-light);
font-size: 0.72rem;
text-transform: uppercase;
letter-spacing: 0.05em;
color: var(--text-muted);
white-space: nowrap;
}
.log-table td {
padding: 0.4rem 0.65rem;
border-bottom: 1px solid color-mix(in srgb, var(--border-light) 60%, transparent);
white-space: nowrap;
font-variant-numeric: tabular-nums;
}
.log-table tr:last-child td {
border-bottom: none;
}
.log-table tbody tr:hover {
background: color-mix(in srgb, var(--card-bg) 60%, transparent);
}
.log-cell-call {
font-weight: 700;
letter-spacing: 0.04em;
font-variant-numeric: normal;
}
.log-row-btn {
background: transparent;
border: 1px solid var(--border-light);
border-radius: 0.3rem;
color: var(--text-muted);
font-size: 0.75rem;
padding: 0.15rem 0.5rem;
cursor: pointer;
}
.log-row-btn:hover {
color: var(--text);
background: var(--card-bg);
}
.log-empty {
padding: 1.5rem 0.75rem;
text-align: center;
color: var(--text-muted);
white-space: normal;
}
.log-summary {
color: var(--text-muted);
font-size: 0.8rem;
}
/* The ham layout works the bands: the broadcast furniture goes, and the entry
form is the thing the panel opens on. */
body[data-operator-layout="ham"] .controls-col-wfm { display: none !important; }
body[data-operator-layout="ham"] #rds-panel { display: none !important; }
@media (max-width: 700px) {
.log-station,
.log-entry-actions {
flex-direction: column;
align-items: stretch;
}
.log-entry-buttons {
margin-left: 0;
}
.log-field-call {
grid-column: span 2;
}
.log-list-toolbar .status-input {
max-width: none;
flex: 1 1 8rem;
}
}
/* Contest exchange and the reports below the log: folded away, because most
operating is not a contest and most sessions do not export one. */
.log-contest,
.log-report {
border: 1px solid var(--border-light);
border-radius: 0.5rem;
background: var(--bg-secondary);
padding: 0.5rem 0.85rem;
}
.log-contest {
margin-top: 0.75rem;
}
.log-contest > summary,
.log-report > summary {
cursor: pointer;
font-size: 0.78rem;
font-weight: 700;
text-transform: uppercase;
letter-spacing: 0.05em;
color: var(--text-muted);
}
.log-contest[open] > summary,
.log-report[open] > summary {
margin-bottom: 0.65rem;
}
.log-report-note {
margin: 0 0 0.65rem;
max-width: 62ch;
color: var(--text-muted);
font-size: 0.8rem;
line-height: 1.45;
}
@@ -33,6 +33,7 @@ await build({
"satellite-predictions": path.join(sourceDir, "plugins", "satellite-predictions.ts"),
vchan: path.join(sourceDir, "plugins", "vchan.ts"),
bookmarks: path.join(sourceDir, "plugins", "bookmarks.ts"),
logbook: path.join(sourceDir, "plugins", "logbook.ts"),
scheduler: path.join(sourceDir, "plugins", "scheduler.ts"),
"map-core": path.join(sourceDir, "map-core.ts"),
screenshot: path.join(sourceDir, "screenshot.ts"),
@@ -12,7 +12,7 @@
"typecheck": "tsc --project tsconfig.json && tsc --project tsconfig.worker.json",
"lint": "eslint \"src/**/*.ts\" \"tests/**/*.mjs\" build.mjs --no-error-on-unmatched-pattern",
"test": "node --test tests/*.test.mjs",
"test:browser": "node tests/browser-smoke.mjs && node tests/spectrum-layout.mjs && node tests/decode-flow.mjs && node tests/tune-links.mjs && node tests/mobile-layout.mjs && node tests/satellite-predictions.mjs && node tests/background-decode.mjs",
"test:browser": "node tests/browser-smoke.mjs && node tests/spectrum-layout.mjs && node tests/decode-flow.mjs && node tests/tune-links.mjs && node tests/mobile-layout.mjs && node tests/satellite-predictions.mjs && node tests/background-decode.mjs && node tests/logbook.mjs",
"verify-generated": "npm run generate-types && npm run build && git diff --exit-code -- ../assets/web/generated src/api/generated.ts"
},
"devDependencies": {
@@ -2,11 +2,12 @@
//
// SPDX-License-Identifier: GPL-2.0-or-later
export type AuthRole = "rx" | "control";
export type AuthRole = "user" | "admin";
export interface AuthSession {
authenticated: boolean;
role?: AuthRole;
username?: string;
auth_disabled?: boolean;
}
@@ -18,7 +19,7 @@ function decodeAuthSession(value: unknown): AuthSession {
if (typeof session.authenticated !== "boolean") {
throw new TypeError("The authentication response has no authenticated flag");
}
if (session.role !== undefined && session.role !== "rx" && session.role !== "control") {
if (session.role !== undefined && session.role !== "user" && session.role !== "admin") {
throw new TypeError("The authentication response has an invalid role");
}
if (session.auth_disabled !== undefined && typeof session.auth_disabled !== "boolean") {
@@ -26,13 +27,17 @@ function decodeAuthSession(value: unknown): AuthSession {
}
const decoded: AuthSession = { authenticated: session.authenticated };
if (session.role !== undefined) decoded.role = session.role;
if (session.username !== undefined) {
if (typeof session.username !== "string") throw new TypeError("The authentication response has an invalid username");
decoded.username = session.username;
}
if (session.auth_disabled !== undefined) decoded.auth_disabled = session.auth_disabled;
return decoded;
}
const authDisabledSession: AuthSession = {
authenticated: true,
role: "control",
role: "admin",
auth_disabled: true,
};
@@ -48,11 +53,11 @@ export async function fetchAuthSession(): Promise<AuthSession> {
}
}
export async function login(passphrase: string): Promise<AuthSession> {
export async function login(username: string, password: string): Promise<AuthSession> {
const response = await fetch("/auth/login", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({ passphrase }),
body: JSON.stringify({ username, password }),
});
if (response.status === 404) return authDisabledSession;
if (!response.ok) {
@@ -62,6 +67,41 @@ export async function login(passphrase: string): Promise<AuthSession> {
return decodeAuthSession(await response.json());
}
export interface ManagedUser { username: string; role: AuthRole }
async function userRequest(path: string, init?: RequestInit): Promise<Response> {
const response = await fetch(path, init);
if (!response.ok) {
const payload = await response.json().catch(() => ({})) as { error?: string };
throw new Error(payload.error || `User operation failed (${response.status})`);
}
return response;
}
export async function listUsers(): Promise<ManagedUser[]> {
const value: unknown = await userRequest("/auth/users").then(response => response.json());
if (!Array.isArray(value) || !value.every((user: unknown) => {
if (typeof user !== "object" || user === null) return false;
const record = user as Record<string, unknown>;
return typeof record.username === "string" && (record.role === "user" || record.role === "admin");
})) {
throw new TypeError("The user list response is malformed");
}
return value as ManagedUser[];
}
export async function createUser(username: string, password: string, role: AuthRole): Promise<void> {
await userRequest("/auth/users", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ username, password, role }) });
}
export async function updateUser(username: string, changes: { password?: string; role?: AuthRole }): Promise<void> {
await userRequest(`/auth/users/${encodeURIComponent(username)}`, { method: "PATCH", headers: { "Content-Type": "application/json" }, body: JSON.stringify(changes) });
}
export async function deleteUser(username: string): Promise<void> {
await userRequest(`/auth/users/${encodeURIComponent(username)}`, { method: "DELETE" });
}
export async function logout(): Promise<void> {
const response = await fetch("/auth/logout", { method: "POST" });
if (response.status !== 404 && !response.ok) throw new Error("Logout failed");
@@ -21,6 +21,10 @@ import {
fetchAuthSession,
login,
logout,
listUsers,
createUser,
updateUser,
deleteUser,
} from "./api/auth.js";
import {
formatByteSize as recorderFormatSize,
@@ -265,7 +269,7 @@ interface TrxUi {
confirm(options?: { title?: string; message?: string; confirmLabel?: string; danger?: boolean }): Promise<boolean>;
notify(message: string, options?: { kind?: "info" | "error" | "success" | "warning"; duration?: number; action?: { label?: string; run(): void } | null }): HTMLDivElement;
setActiveRig(rigId: string | null): void;
setLayoutCapabilities(capabilities?: Partial<Record<"broadcast" | "digital", boolean>>): void;
setLayoutCapabilities(capabilities?: Partial<Record<"broadcast" | "digital" | "ham", boolean>>): void;
setButtonState(element: HTMLButtonElement | null, options?: { active?: boolean; activeLabel?: string; inactiveLabel?: string; busy?: boolean; disabled?: boolean }): void;
closeMobileOverlays?(restoreFocus?: boolean): void;
syncSelectedTab(container: HTMLElement | null, selected: Element): void;
@@ -407,39 +411,38 @@ void loadDecoderRegistry(refreshOperatorLayoutCapabilities);
// --- Authentication ---
let authRole: AuthRole | null = null;
let authUsername: string | null = null;
let authEnabled = true;
async function checkAuthStatus() {
return fetchAuthSession();
}
async function authLogin(passphrase: string) {
return login(passphrase);
async function authLogin(username: string, password: string) {
return login(username, password);
}
async function authLogout() {
try {
await logout();
authRole = null;
authUsername = null;
// Disconnect and show auth gate without page reload
disconnect();
setDecodeHistoryOverlayVisible(false);
requiredElement("content").style.display = "none";
requiredElement("loading").style.display = "none";
requiredElement<HTMLInputElement>("auth-passphrase").value = "";
requiredElement<HTMLInputElement>("auth-password").value = "";
updateAuthUI();
// Check if guest mode is available after logout
const authStatus = await checkAuthStatus();
const allowGuest = authStatus.role === "rx";
showAuthGate(allowGuest);
showAuthGate();
} catch (e) {
console.error("Logout failed:", e);
showAuthError("Logout failed");
}
}
function showAuthGate(allowGuest = false) {
function showAuthGate() {
if (!authEnabled) return;
setDecodeHistoryOverlayVisible(false);
requiredElement("loading").style.display = "none";
@@ -459,12 +462,6 @@ function showAuthGate(allowGuest = false) {
panel.style.display = "none";
});
// Show guest button if guest mode is available
const guestBtn = document.getElementById("auth-guest-btn");
if (guestBtn) {
guestBtn.style.display = allowGuest ? "block" : "none";
}
document.querySelectorAll<HTMLElement>(".tab-bar .tab").forEach((btn) => {
btn.classList.toggle("active", btn.dataset.tab === "main");
});
@@ -516,7 +513,7 @@ function updateAuthUI() {
if (authRole) {
if (badge) badge.style.display = "block";
if (badgeRole) badgeRole.textContent = authRole === "control" ? "Control (full access)" : "RX (read-only)";
if (badgeRole) badgeRole.textContent = `${authUsername || "local"}${authRole === "admin" ? "Admin" : "User (read-only)"}`;
if (headerAuthBtn) {
headerAuthBtn.textContent = "Logout";
headerAuthBtn.style.display = "block";
@@ -534,8 +531,8 @@ function updateAuthUI() {
function applyAuthRestrictions() {
if (!authRole) return;
// Disable TX/PTT/frequency/mode/VFO controls for rx role
if (authRole === "rx") {
// Disable TX/PTT/frequency/mode/VFO controls for user role
if (authRole === "user") {
const pttBtn = document.getElementById("ptt-btn") as HTMLButtonElement | null;
const powerBtn = document.getElementById("power-btn") as HTMLButtonElement | null;
const lockBtn = document.getElementById("lock-btn") as HTMLButtonElement | null;
@@ -883,7 +880,7 @@ function syncTopBarAccess() {
}
if (headerRigSwitchSelect) {
headerRigSwitchSelect.disabled = loggedOut || authRole === "rx" || lastRigIds.length === 0;
headerRigSwitchSelect.disabled = loggedOut || authRole === "user" || lastRigIds.length === 0;
}
}
@@ -1464,7 +1461,7 @@ function applyRigList(activeRigId: string | null, rigIds: string[], displayNames
}
const nextKey = lastRigIds.join("\0") + "|" + (lastActiveRigId || "");
const rigListChanged = prevKey !== nextKey;
const disableSwitch = lastRigIds.length === 0 || !authRole || authRole === "rx";
const disableSwitch = lastRigIds.length === 0 || !authRole || authRole === "user";
populateRigPicker(headerRigSwitchSelect, lastRigIds, lastActiveRigId, disableSwitch);
updateRigSubtitle(lastActiveRigId);
window.trxUi?.setActiveRig(lastActiveRigId);
@@ -1522,6 +1519,9 @@ function refreshOperatorLayoutCapabilities() {
window.trxUi?.setLayoutCapabilities({
broadcast: rigModes.some((modes) => modes.includes("WFM")),
digital: decoderModes.size > 0 && rigModes.some((modes) => modes.some((mode) => decoderModes.has(mode))),
// A logbook is for contacts made, so the layout built around it is offered
// where a rig can transmit.
ham: serverRigs.some((rig) => rig?.tx === true),
});
}
@@ -3349,7 +3349,7 @@ function scheduleTuneLinkSync() {
async function applyTuneLink(link: TuneLink) {
const wanted = link.rig || link.mode || link.freqHz != null || link.bandwidthHz != null;
if (!wanted) return;
if (authRole === "rx") {
if (authRole === "user") {
showHint("Read-only session — link not applied", 2500);
return;
}
@@ -4188,8 +4188,8 @@ async function switchRigFromSelect(selectEl: HTMLSelectElement) {
showHint("No rig selected", 1500);
return;
}
if (authRole === "rx") {
showHint("Control role required", 1500);
if (authRole === "user") {
showHint("Admin role required", 1500);
return;
}
if (!lastRigIds.includes(selectEl.value)) {
@@ -4872,7 +4872,7 @@ function navigateToTab(name: TabName, options: { updateHistory?: boolean; replac
const leavingSatellites = _activeTab === "satellites" && name !== "satellites";
const { updateHistory = true, replaceHistory = false } = options;
if (authEnabled && !authRole && name !== "main") {
showAuthGate(false);
showAuthGate();
return;
}
const btn = document.querySelector<HTMLElement>(`.tab-bar .tab[data-tab="${name}"]`);
@@ -5005,12 +5005,12 @@ window.addEventListener("resize", () => { scheduleSpectrumLayout(); });
// --- Auth startup sequence ---
async function initializeApp() {
showAuthGate(false);
showAuthGate();
const authStatus = await checkAuthStatus();
authEnabled = !authStatus.auth_disabled;
if (!authEnabled) {
authRole = "control";
authRole = "admin";
hideAuthGate();
updateAuthUI();
connect();
@@ -5024,6 +5024,7 @@ async function initializeApp() {
if (authStatus.authenticated) {
// User has valid session
authRole = authStatus.role ?? null;
authUsername = authStatus.username ?? null;
hideAuthGate();
updateAuthUI();
applyAuthRestrictions();
@@ -5033,10 +5034,7 @@ async function initializeApp() {
resizeHeaderSignalCanvas();
startHeaderSignalSampling();
} else {
// No valid session - show auth gate
// Guest button is shown if guest mode is available (role granted without auth)
const allowGuest = authStatus.role === "rx";
showAuthGate(allowGuest);
showAuthGate();
}
}
@@ -5052,22 +5050,96 @@ function initSettingsUI() {
window.trx.modules.backgroundDecode.initialize(lastActiveRigId, authRole);
window.trx.modules.backgroundDecode.wireEvents();
}
void refreshUserManagement();
}
async function refreshUserManagement() {
const section = document.getElementById("user-management");
if (!section) return;
section.style.display = authEnabled && authRole === "admin" ? "block" : "none";
if (section.style.display === "none") return;
const list = requiredElement("user-list");
try {
const users = await listUsers();
list.replaceChildren(...users.map((user) => {
const row = document.createElement("div");
row.className = "sch-row";
row.style.cssText = "display:flex;align-items:center;gap:.5rem;flex-wrap:wrap;margin:.4rem 0";
const name = document.createElement("strong");
name.textContent = user.username;
name.style.minWidth = "10rem";
const role = document.createElement("select");
role.className = "auth-input";
for (const value of ["user", "admin"] as AuthRole[]) {
const option = document.createElement("option"); option.value = value; option.textContent = value === "admin" ? "Admin" : "User"; option.selected = user.role === value; role.append(option);
}
const password = document.createElement("input");
password.type = "password"; password.placeholder = "New password"; password.autocomplete = "new-password"; password.className = "auth-input"; password.minLength = 8;
const save = document.createElement("button"); save.type = "button"; save.textContent = "Save";
save.addEventListener("click", async () => {
const changes: { role?: AuthRole; password?: string } = { role: role.value as AuthRole };
if (password.value) changes.password = password.value;
await runUserOperation(() => updateUser(user.username, changes));
});
const remove = document.createElement("button"); remove.type = "button"; remove.textContent = "Remove"; remove.className = "danger";
remove.disabled = user.username === authUsername;
remove.addEventListener("click", async () => {
if (await window.trxUi.confirm({ title: "Remove user?", message: `Remove ${user.username} and revoke their sessions?`, confirmLabel: "Remove", danger: true })) {
await runUserOperation(() => deleteUser(user.username));
}
});
row.append(name, role, password, save, remove);
return row;
}));
} catch (error) {
showUserManagementError(error);
}
}
function showUserManagementError(error: unknown) {
const element = document.getElementById("user-management-error");
if (!element) return;
element.textContent = error instanceof Error ? error.message : String(error);
element.style.display = "block";
}
async function runUserOperation(operation: () => Promise<void>) {
try {
await operation();
const error = document.getElementById("user-management-error");
if (error) error.style.display = "none";
await refreshUserManagement();
} catch (reason) {
showUserManagementError(reason);
}
}
document.getElementById("user-create-form")?.addEventListener("submit", (event) => {
event.preventDefault();
const username = requiredElement<HTMLInputElement>("user-create-username");
const password = requiredElement<HTMLInputElement>("user-create-password");
const role = requiredElement<HTMLSelectElement>("user-create-role");
void runUserOperation(async () => {
await createUser(username.value, password.value, role.value as AuthRole);
username.value = ""; password.value = ""; role.value = "user";
});
});
// Setup auth form
requiredElement<HTMLFormElement>("auth-form").addEventListener("submit", async (e) => {
e.preventDefault();
const passphraseEl = requiredElement<HTMLInputElement>("auth-passphrase");
const passphrase = passphraseEl.value;
const usernameEl = requiredElement<HTMLInputElement>("auth-username");
const passwordEl = requiredElement<HTMLInputElement>("auth-password");
const btn = requiredElement<HTMLFormElement>("auth-form").querySelector<HTMLButtonElement>("button[type=submit]");
if (!btn) return;
btn.disabled = true;
btn.textContent = "Logging in...";
try {
const result = await authLogin(passphrase);
const result = await authLogin(usernameEl.value, passwordEl.value);
authRole = result.role ?? null;
passphraseEl.value = "";
authUsername = result.username ?? usernameEl.value;
passwordEl.value = "";
hideAuthGate();
updateAuthUI();
applyAuthRestrictions();
@@ -5077,7 +5149,7 @@ requiredElement<HTMLFormElement>("auth-form").addEventListener("submit", async (
resizeHeaderSignalCanvas();
startHeaderSignalSampling();
} catch (err) {
showAuthError("Invalid passphrase");
showAuthError("Invalid username or password");
console.error("Login error:", err);
} finally {
btn.disabled = false;
@@ -5085,23 +5157,6 @@ requiredElement<HTMLFormElement>("auth-form").addEventListener("submit", async (
}
});
// Setup guest button
const guestBtn = document.getElementById("auth-guest-btn") as HTMLButtonElement | null;
if (guestBtn) {
guestBtn.addEventListener("click", () => {
authRole = "rx";
requiredElement<HTMLInputElement>("auth-passphrase").value = "";
hideAuthGate();
updateAuthUI();
applyAuthRestrictions();
connect();
connectDecode();
initSettingsUI();
resizeHeaderSignalCanvas();
startHeaderSignalSampling();
});
}
// Setup header auth button (Login/Logout)
const headerAuthBtn = document.getElementById("header-auth-btn") as HTMLButtonElement | null;
if (headerAuthBtn) {
@@ -5113,7 +5168,7 @@ if (headerAuthBtn) {
}
} else {
// Not logged in - show auth gate
showAuthGate(false);
showAuthGate();
}
});
}
@@ -3,7 +3,7 @@
// SPDX-License-Identifier: GPL-2.0-or-later
export const TAB_ORDER = [
"main", "bookmarks", "digital-modes", "map", "satellites", "statistics", "recorder", "settings", "about",
"main", "bookmarks", "logbook", "digital-modes", "map", "satellites", "statistics", "recorder", "settings", "about",
] as const;
export type TabName = typeof TAB_ORDER[number];
@@ -11,6 +11,7 @@ export type TabName = typeof TAB_ORDER[number];
export const TAB_PATHS: Readonly<Record<TabName, string>> = {
main: "/",
bookmarks: "/bookmarks",
logbook: "/logbook",
"digital-modes": "/digital-modes",
map: "/map",
satellites: "/satellites",
@@ -4,7 +4,7 @@
type PluginGroup =
| "digital-modes" | "map-data" | "map" | "satellites" | "statistics"
| "bookmarks" | "recorder" | "settings";
| "bookmarks" | "logbook" | "recorder" | "settings";
const pluginGroups: Readonly<Record<PluginGroup, readonly string[]>> = {
// AIS, VDES and the two APRS decoders have panels on this tab, so they load
@@ -20,6 +20,7 @@ const pluginGroups: Readonly<Record<PluginGroup, readonly string[]>> = {
satellites: ["/satellite-predictions.js"],
statistics: ["/map-core.js"],
bookmarks: ["/bookmarks.js"],
logbook: ["/logbook.js"],
recorder: [],
settings: ["/vchan.js", "/scheduler.js"],
};
@@ -47,7 +48,7 @@ async function loadPlugins(group: string): Promise<void> {
}
export async function loadEagerPlugins(): Promise<void> {
await Promise.all(["digital-modes", "bookmarks", "settings"].map(loadPlugins));
await Promise.all(["digital-modes", "bookmarks", "logbook", "settings"].map(loadPlugins));
}
export async function loadPluginsForTab(tab: string): Promise<void> {
@@ -324,6 +324,21 @@ export interface AprsRowOptions {
onMap?: (lat: number, lon: number) => void;
/** Puts a frame's coordinates on the clipboard. */
onCopy?: (text: string, button: HTMLElement) => void;
/** Opens a log entry for the station that sent the frame. */
onLog?: (call: string, gridsquare: string | null) => void;
}
/** A position as a six-character locator, which is what a log wants. */
function maidenheadForLatLon(lat: number, lon: number): string {
const adjustedLon = lon + 180;
const adjustedLat = lat + 90;
const field = String.fromCharCode(65 + Math.floor(adjustedLon / 20))
+ String.fromCharCode(65 + Math.floor(adjustedLat / 10));
const square = String(Math.floor((adjustedLon % 20) / 2)) + String(Math.floor(adjustedLat % 10));
const subLon = ((adjustedLon % 2) * 60) / 5;
const subLat = ((adjustedLat % 1) * 60) / 2.5;
const sub = String.fromCharCode(97 + Math.floor(subLon)) + String.fromCharCode(97 + Math.floor(subLat));
return `${field}${square}${sub}`.toUpperCase();
}
export function renderAprsPacketRow(packet: AprsPacket, options: AprsRowOptions = {}): HTMLElement {
@@ -370,6 +385,7 @@ export function renderAprsPacketRow(packet: AprsPacket, options: AprsRowOptions
(hasPosition ? `<button class="aprs-inline-btn" type="button" data-aprs-map="${packet.lat},${packet.lon}">Map</button>` : "") +
(hasPosition ? `<button class="aprs-inline-btn" type="button" data-aprs-copy="${packet.lat},${packet.lon}">Copy Coords</button>` : "") +
`<a class="aprs-inline-btn" href="${qrzHref}" target="_blank" rel="noopener">QRZ</a>` +
(options.onLog && packet.srcCall ? '<button class="aprs-inline-btn" type="button" data-aprs-log="1">Log</button>' : "") +
`</div>` +
`</div>`;
@@ -381,6 +397,17 @@ export function renderAprsPacketRow(packet: AprsPacket, options: AprsRowOptions
if (Number.isFinite(lat) && Number.isFinite(lon)) options.onMap?.(lat as number, lon as number);
});
});
const logButton = row.querySelector<HTMLElement>("[data-aprs-log]");
if (logButton) {
logButton.addEventListener("click", (event) => {
event.preventDefault();
event.stopPropagation();
const grid = packet.lat != null && packet.lon != null
? maidenheadForLatLon(packet.lat, packet.lon)
: null;
options.onLog?.(packet.srcCall ?? "", grid);
});
}
const copyButton = row.querySelector<HTMLElement>("[data-aprs-copy]");
if (copyButton) {
copyButton.addEventListener("click", (event) => {
@@ -23,6 +23,7 @@ interface AprsBridge {
aprsMapAddStation?: (call: string, lat: number, lon: number, info: string, symbolTable: string | null | undefined, symbolCode: string | null | undefined, packet: AprsPacket) => void;
getDecodeRigMeta?: () => unknown;
trxUi: { confirm(options: { title: string; message: string; confirmLabel: string }): Promise<boolean> };
logContact?: (seed: { call?: string; gridsquare?: string | undefined; decoder?: string }) => void;
updateAprsBar?: () => void;
clearAprsBar?: () => void;
closeAprsBar?: () => void;
@@ -164,6 +165,9 @@ function renderAprsRow(pkt: AprsPacket, isFresh: boolean): HTMLElement {
distance: aprsDistanceText(pkt),
onMap: (lat, lon) => { aprsWindow.navigateToAprsMap?.(lat, lon); },
onCopy: (text) => { void copyAprsCoords(text); },
onLog: (call, gridsquare) => {
aprsWindow.logContact?.({ call, gridsquare: gridsquare ?? undefined, decoder: "aprs" });
},
});
}
@@ -468,7 +468,7 @@ const bgdWindow = window as unknown as BackgroundBridge;
}
function isControlRole(): boolean {
return backgroundDecodeRole === "control" || hostState.authEnabled === false;
return backgroundDecodeRole === "admin" || hostState.authEnabled === false;
}
function showToast(msg: string, isError: boolean): void {
@@ -100,7 +100,7 @@ function bmEsc(str: unknown): string {
}
function bmCanControl() {
return !hostState.authEnabled || hostState.authRole === "control";
return !hostState.authEnabled || hostState.authRole === "admin";
}
// Show/hide the Add Bookmark / Select All buttons based on the current auth role.
@@ -49,6 +49,8 @@ interface FtxBridge {
updateFt8Bar?: () => void;
registerFt8FamilyBarRenderer?: (decoder: FtxDecoderId, renderer: () => BarFrames) => void;
takeSchedulerControlForDecoderDisable?: (button: HTMLElement) => Promise<void>;
/** Opens a log entry from a decode. Pre-fills it; never logs by itself. */
logContact?: (seed: { call?: string; gridsquare?: string | undefined; decoder?: string }) => void;
trxUi: ConfirmApi;
clearFt8Bar?: () => void;
closeFt8Bar?: () => void;
@@ -224,6 +226,26 @@ export function initializeFtxDecoder(config: FtxConfig): void {
hour: "2-digit", minute: "2-digit", second: "2-digit",
});
row.innerHTML = `<span class="ft8-time">${time}</span><span class="ft8-snr">${snr?.toFixed(1) ?? "--"}</span><span class="ft8-dt">${delta?.toFixed(2) ?? "--"}</span><span class="ft8-freq">${frequency?.toFixed(0) ?? "--"}</span><span class="ft8-msg">${renderMessage(raw)}</span>`;
// A decode is not a contact: this opens an entry with what was heard in it
// and leaves the logging to the operator.
const station = bridge.ft8ExtractLikelyCallsign?.(raw) ?? extractFtxCallsign(raw);
if (station) {
const log = document.createElement("button");
log.type = "button";
log.className = "ft8-log-btn";
log.textContent = "Log";
log.title = `Start a log entry for ${station}`;
log.addEventListener("click", (event) => {
event.stopPropagation();
const details = bridge.ft8ExtractLocatorDetails?.(raw) ?? extractFtxLocatorDetails(raw);
bridge.logContact?.({
call: station,
gridsquare: details.find((detail) => detail.station === station)?.grid,
decoder: id,
});
});
row.appendChild(log);
}
return row;
};
const render = (): void => {
@@ -22,6 +22,8 @@ export interface HostDecoderDescriptor {
export interface HostState {
readonly serverLat: number | null;
readonly serverLon: number | null;
/** The callsign this station is on the air with, from the client config. */
readonly ownerCallsign: string | null;
readonly authEnabled: boolean;
readonly authRole: string | null;
readonly lastActiveRigId: string | null;
@@ -43,6 +45,7 @@ export interface HostCore {
armOptimisticFrequency(frequencyHz: number): void;
escapeMapHtml(value: string): string;
haversineKm(lat1: number, lon1: number, lat2: number, lon2: number): number;
latLonToMaidenhead(lat: number, lon: number): string;
showHint(message: string, durationMs?: number): void;
formatFreqForStep(frequencyHz: number, stepHz: number): string;
refreshFreqDisplay(): void;
@@ -0,0 +1,561 @@
// SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
//
// SPDX-License-Identifier: GPL-2.0-or-later
// The station log: one panel that opens an entry, keeps the log, and takes
// ADIF in and out.
//
// Times come from the server, never from here. The browser may be a phone in
// another timezone with a clock nobody has checked, and a log is only worth
// keeping if the times in it are the radio's.
import { hostCore, hostState } from "./host.js";
export {};
interface Qso {
id: string;
started_at: string;
call: string;
freq_hz: number;
band?: string | null;
mode: string;
submode?: string | null;
rst_sent?: string | null;
rst_rcvd?: string | null;
gridsquare?: string | null;
name?: string | null;
qth?: string | null;
comment?: string | null;
station_callsign?: string | null;
operator?: string | null;
my_gridsquare?: string | null;
my_rig?: string | null;
rig_id?: string | null;
contest_id?: string | null;
stx?: number | null;
srx?: number | null;
srx_string?: string | null;
qsl_rcvd?: string | null;
lotw_qsl_rcvd?: string | null;
confirmed?: boolean;
}
interface BandStatistics {
band: string;
contacts: number;
stations: number;
confirmed: number;
}
interface Prefill {
started_at: string;
epoch_ms: number;
freq_hz: number;
band: string | null;
mode: string;
submode: string | null;
rig_id: string | null;
my_rig: string | null;
call: string | null;
gridsquare: string | null;
}
interface LogbookBridge {
trxUi: {
confirm(options: { title: string; message: string; confirmLabel: string }): Promise<boolean>;
notify?(message: string, options?: { kind?: string }): void;
};
navigateToTab?: (name: string) => void;
/** Opens the panel with an entry started from a decode. */
logContact?: (seed: { call?: string; gridsquare?: string | undefined; decoder?: string }) => void;
}
const bridge = window as unknown as LogbookBridge;
const el = <T extends HTMLElement>(id: string): T | null => document.getElementById(id) as T | null;
const form = el<HTMLFormElement>("log-entry-form");
const callInput = el<HTMLInputElement>("log-call");
const freqInput = el<HTMLInputElement>("log-freq");
const modeInput = el<HTMLInputElement>("log-mode");
const rstSentInput = el<HTMLInputElement>("log-rst-sent");
const rstRcvdInput = el<HTMLInputElement>("log-rst-rcvd");
const gridInput = el<HTMLInputElement>("log-grid");
const nameInput = el<HTMLInputElement>("log-name");
const commentInput = el<HTMLInputElement>("log-comment");
const operatorInput = el<HTMLInputElement>("log-operator");
const rowsBody = el<HTMLTableSectionElement>("log-rows");
const summaryEl = el("log-summary");
const workedEl = el("log-worked-before");
const clockEl = el("log-clock");
const stationCallEl = el("log-station-callsign");
const stationRigEl = el("log-station-rig-name");
const stationGridEl = el("log-station-grid");
const filterCall = el<HTMLInputElement>("log-filter-call");
const filterBand = el<HTMLSelectElement>("log-filter-band");
const filterMode = el<HTMLSelectElement>("log-filter-mode");
const importBtn = el<HTMLButtonElement>("log-import-btn");
const importFile = el<HTMLInputElement>("log-import-file");
const exportLink = el<HTMLAnchorElement>("log-export-btn");
const clearBtn = el<HTMLButtonElement>("log-clear-btn");
const saveBtn = el<HTMLButtonElement>("log-save-btn");
const contestIdInput = el<HTMLInputElement>("log-contest-id");
const stxInput = el<HTMLInputElement>("log-stx");
const srxInput = el<HTMLInputElement>("log-srx");
const statisticsRows = el<HTMLTableSectionElement>("log-statistics-rows");
const cabrilloContest = el<HTMLInputElement>("log-cbr-contest");
const cabrilloCallsign = el<HTMLInputElement>("log-cbr-callsign");
const cabrilloOperator = el<HTMLSelectElement>("log-cbr-operator");
const cabrilloPower = el<HTMLSelectElement>("log-cbr-power");
const cabrilloScore = el<HTMLInputElement>("log-cbr-score");
const cabrilloExport = el<HTMLAnchorElement>("log-cbr-export");
/** The time the open entry was started, as the server gave it. */
let entryStartedAt: string | null = null;
/** The rig the open entry belongs to, likewise. */
let entryRigId: string | null = null;
let entryRigName: string | null = null;
let entryGrid: string | null = null;
let qsos: Qso[] = [];
let workedRequest = 0;
function notify(message: string, kind?: string): void {
if (bridge.trxUi.notify) bridge.trxUi.notify(message, kind ? { kind } : undefined);
else hostCore.showHint(message, 2000);
}
async function getJson<T>(path: string): Promise<T> {
const response = await fetch(path);
if (!response.ok) throw new Error(`HTTP ${String(response.status)}`);
return await response.json() as T;
}
function formatFreq(hz: number): string {
if (!Number.isFinite(hz) || hz <= 0) return "";
// Through Number, not a trailing-zero trim: trimming "20.000000" as a string
// walks back through the point and leaves "2".
return String(Number((hz / 1e6).toFixed(6)));
}
/** What the operator typed, in Hz: MHz unless it is plainly already Hz. */
function parseFreq(text: string): number | null {
const value = Number(text.trim().replace(/\s+/g, "").replace(",", "."));
if (!Number.isFinite(value) || value <= 0) return null;
return value < 100_000 ? Math.round(value * 1e6) : Math.round(value);
}
/** A serial, or null when the exchange is a word rather than a number. */
function numberOrNull(text: string | undefined): number | null {
const trimmed = (text ?? "").trim();
if (!trimmed || !/^\d+$/.test(trimmed)) return null;
const value = Number(trimmed);
return Number.isSafeInteger(value) ? value : null;
}
function utcDate(iso: string): string {
const date = new Date(iso);
return Number.isNaN(date.getTime()) ? "" : date.toISOString().slice(0, 10);
}
function utcTime(iso: string): string {
const date = new Date(iso);
return Number.isNaN(date.getTime()) ? "" : date.toISOString().slice(11, 19);
}
// ── The entry ───────────────────────────────────────────────────────────────
/** Open an entry, pre-filled with the six fields the radio and clock answer. */
async function openEntry(
seed: { call?: string; gridsquare?: string | undefined; decoder?: string } = {},
): Promise<void> {
const params = new URLSearchParams();
if (hostState.lastActiveRigId) params.set("remote", hostState.lastActiveRigId);
if (seed.decoder) params.set("decoder", seed.decoder);
if (seed.call) params.set("call", seed.call);
if (seed.gridsquare) params.set("gridsquare", seed.gridsquare);
try {
const prefill = await getJson<Prefill>(`/api/logbook/prefill?${params.toString()}`);
applyPrefill(prefill);
} catch (error: unknown) {
console.error("logbook prefill failed", error);
}
}
function applyPrefill(prefill: Prefill): void {
entryStartedAt = prefill.started_at;
entryRigId = prefill.rig_id;
entryRigName = prefill.my_rig;
if (freqInput) freqInput.value = formatFreq(prefill.freq_hz);
if (modeInput) modeInput.value = prefill.submode ?? prefill.mode;
if (callInput && prefill.call) callInput.value = prefill.call;
if (gridInput && prefill.gridsquare) gridInput.value = prefill.gridsquare;
if (stationRigEl) stationRigEl.textContent = prefill.my_rig ?? "no rig";
showClock(prefill);
updateWorkedBefore();
}
/** The entry's time, and whether this browser agrees with it. */
function showClock(prefill: Prefill): void {
if (!clockEl) return;
const time = utcTime(prefill.started_at);
const drift = Math.abs(Date.now() - prefill.epoch_ms);
clockEl.textContent = drift > 1000
? `${time}Z · your clock is ${(drift / 1000).toFixed(0)}s out`
: `${time}Z`;
clockEl.classList.toggle("is-adrift", drift > 1000);
}
/** Clear the entry and open a fresh one. */
function resetEntry(): void {
// The contest and the serial sent stay: they belong to the session, not to
// the contact just logged.
for (const input of [callInput, rstSentInput, rstRcvdInput, gridInput, nameInput, commentInput, srxInput]) {
if (input) input.value = "";
}
if (workedEl) workedEl.textContent = "";
void openEntry();
}
async function submitEntry(event: Event): Promise<void> {
event.preventDefault();
const call = callInput?.value.trim() ?? "";
if (!call) {
notify("A contact needs a callsign", "error");
callInput?.focus();
return;
}
const freqHz = parseFreq(freqInput?.value ?? "");
if (freqHz == null) {
notify("A contact needs a frequency", "error");
freqInput?.focus();
return;
}
const typedMode = (modeInput?.value ?? "").trim().toUpperCase();
// USB and LSB are how a rig says SSB; the log wants the mode with the
// sideband beside it, which is what other loggers read.
const isSideband = typedMode === "USB" || typedMode === "LSB";
const body = {
// The server stamps the time; this is the one it gave when the entry
// opened, so a contact logged five minutes later keeps the time it started.
started_at: entryStartedAt,
call,
freq_hz: freqHz,
mode: isSideband ? "SSB" : typedMode,
submode: isSideband ? typedMode : null,
rst_sent: rstSentInput?.value ?? null,
rst_rcvd: rstRcvdInput?.value ?? null,
gridsquare: gridInput?.value ?? null,
name: nameInput?.value ?? null,
comment: commentInput?.value ?? null,
contest_id: contestIdInput?.value ?? null,
// The exchange is a number when it is a serial and a word when it is a
// zone or a section; both are kept, and the log writes whichever it has.
stx: numberOrNull(stxInput?.value),
stx_string: numberOrNull(stxInput?.value) == null ? stxInput?.value ?? null : null,
srx: numberOrNull(srxInput?.value),
srx_string: numberOrNull(srxInput?.value) == null ? srxInput?.value ?? null : null,
station_callsign: stationCallEl?.textContent?.trim() ?? null,
operator: operatorInput?.value ?? null,
my_gridsquare: entryGrid,
my_rig: entryRigName,
rig_id: entryRigId,
};
if (saveBtn) saveBtn.disabled = true;
try {
const response = await fetch("/api/logbook", {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify(body),
});
if (!response.ok) {
const detail = await response.json().catch(() => ({})) as { error?: string };
throw new Error(detail.error ?? `HTTP ${String(response.status)}`);
}
notify(`${call} logged`);
// A contest runs on serials: the next one is this one plus one, so it is
// not retyped forty times an hour.
const sent = numberOrNull(stxInput?.value);
resetEntry();
if (stxInput && sent != null) stxInput.value = String(sent + 1);
await refreshLog();
} catch (error: unknown) {
notify(`Could not log: ${error instanceof Error ? error.message : String(error)}`, "error");
} finally {
if (saveBtn) saveBtn.disabled = false;
}
}
/** Whether this station has been worked, and on what. */
function updateWorkedBefore(): void {
if (!workedEl) return;
const call = callInput?.value.trim() ?? "";
if (call.length < 3) {
workedEl.textContent = "";
return;
}
const request = ++workedRequest;
void getJson<{ worked: { band: string; mode: string }[] }>(
`/api/logbook/worked/${encodeURIComponent(call)}`,
).then((answer) => {
// A slower answer to an earlier callsign must not overwrite a later one.
if (request !== workedRequest || !workedEl) return;
if (answer.worked.length === 0) {
workedEl.textContent = "Not worked before";
workedEl.classList.remove("is-worked");
return;
}
const where = answer.worked.map((entry) => `${entry.band} ${entry.mode}`).join(", ");
workedEl.textContent = `Worked before: ${where}`;
workedEl.classList.add("is-worked");
}).catch(() => { /* the log will still take the contact */ });
}
// ── The log ─────────────────────────────────────────────────────────────────
function currentQuery(): string {
const params = new URLSearchParams();
const call = filterCall?.value.trim();
if (call) params.set("call", call);
if (filterBand?.value) params.set("band", filterBand.value);
if (filterMode?.value) params.set("mode", filterMode.value);
return params.toString();
}
async function refreshLog(): Promise<void> {
try {
const query = currentQuery();
const answer = await getJson<{ total: number; qsos: Qso[] }>(
`/api/logbook${query ? `?${query}` : ""}`,
);
qsos = answer.qsos;
renderRows();
renderFilterOptions();
if (summaryEl) {
summaryEl.textContent = query
? `${String(qsos.length)} of ${String(answer.total)} contacts`
: `${String(answer.total)} contact${answer.total === 1 ? "" : "s"}`;
}
if (exportLink) exportLink.href = `/api/logbook/export.adi${query ? `?${query}` : ""}`;
await refreshStatistics();
} catch (error: unknown) {
console.error("logbook read failed", error);
}
}
/** What has been worked and confirmed, band by band. */
async function refreshStatistics(): Promise<void> {
if (!statisticsRows) return;
try {
const answer = await getJson<{ bands: BandStatistics[] }>("/api/logbook/statistics");
if (answer.bands.length === 0) {
statisticsRows.innerHTML = '<tr><td colspan="4" class="log-empty">Nothing worked yet.</td></tr>';
return;
}
const fragment = document.createDocumentFragment();
for (const band of answer.bands) {
const row = document.createElement("tr");
for (const value of [band.band, band.contacts, band.stations, band.confirmed]) {
const cell = document.createElement("td");
cell.textContent = String(value);
row.appendChild(cell);
}
fragment.appendChild(row);
}
statisticsRows.replaceChildren(fragment);
} catch (error: unknown) {
console.error("logbook statistics failed", error);
}
}
/** The Cabrillo link, carrying the header the operator filled in. */
function syncCabrilloLink(): void {
if (!cabrilloExport) return;
const params = new URLSearchParams();
const contest = cabrilloContest?.value.trim();
if (contest) {
// Only that contest's contacts belong in the entry.
params.set("contest", contest);
}
const callsign = cabrilloCallsign?.value.trim() || (stationCallEl?.textContent?.trim() ?? "");
if (callsign) params.set("callsign", callsign);
if (cabrilloOperator?.value) params.set("category_operator", cabrilloOperator.value);
if (cabrilloPower?.value) params.set("category_power", cabrilloPower.value);
const score = numberOrNull(cabrilloScore?.value);
if (score != null) params.set("claimed_score", String(score));
const operator = operatorInput?.value.trim();
if (operator) params.set("operators", operator);
cabrilloExport.href = `/api/logbook/export.cbr?${params.toString()}`;
}
function renderRows(): void {
if (!rowsBody) return;
if (qsos.length === 0) {
rowsBody.innerHTML =
'<tr><td colspan="10" class="log-empty">No contacts yet. Work someone and log them here,'
+ " or bring a log in with Import ADIF.</td></tr>";
return;
}
const fragment = document.createDocumentFragment();
for (const qso of qsos) {
const row = document.createElement("tr");
row.dataset.qsoId = qso.id;
const cells: (string | null | undefined)[] = [
utcDate(qso.started_at),
utcTime(qso.started_at),
qso.call,
qso.band ?? "",
qso.submode ?? qso.mode,
qso.rst_sent ?? "",
qso.rst_rcvd ?? "",
qso.gridsquare ?? "",
qso.my_rig ?? "",
qso.confirmed ? "✓" : "",
];
for (const [index, value] of cells.entries()) {
const cell = document.createElement("td");
cell.textContent = value ?? "";
if (index === 2) cell.className = "log-cell-call";
row.appendChild(cell);
}
const actions = document.createElement("td");
// Confirming is the commonest edit a log gets, so it is a button rather
// than a form: a card arrives, and the contact counts towards an award.
const confirm = document.createElement("button");
confirm.type = "button";
confirm.className = "log-row-btn";
confirm.textContent = qso.confirmed ? "Unconfirm" : "Confirm";
confirm.title = qso.confirmed
? "Mark this contact as not confirmed"
: "Mark this contact confirmed by QSL";
confirm.addEventListener("click", () => { void setConfirmed(qso, !qso.confirmed); });
actions.appendChild(confirm);
const remove = document.createElement("button");
remove.type = "button";
remove.className = "log-row-btn";
remove.textContent = "Delete";
remove.setAttribute("aria-label", `Delete the contact with ${qso.call}`);
remove.addEventListener("click", () => { void deleteQso(qso); });
actions.appendChild(remove);
row.appendChild(actions);
fragment.appendChild(row);
}
rowsBody.replaceChildren(fragment);
}
/** Bands and modes the log actually holds, so the filters offer only those. */
function renderFilterOptions(): void {
for (const [select, values] of [
[filterBand, [...new Set(qsos.map((q) => q.band).filter((b): b is string => !!b))]],
[filterMode, [...new Set(qsos.map((q) => q.submode ?? q.mode).filter(Boolean))]],
] as const) {
if (!select) continue;
const chosen = select.value;
const known = new Set([...select.options].map((option) => option.value));
for (const value of [...values].sort()) {
if (known.has(value)) continue;
select.add(new Option(value, value));
}
select.value = chosen;
}
}
/** Record, or withdraw, the other station's confirmation. */
async function setConfirmed(qso: Qso, confirmed: boolean): Promise<void> {
try {
const response = await fetch(`/api/logbook/${encodeURIComponent(qso.id)}`, {
method: "PUT",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
...qso,
// A card is a card: this is the paper one, and an electronic
// confirmation the log already holds is left where it is.
qsl_rcvd: confirmed ? "Y" : "N",
}),
});
if (!response.ok) throw new Error(`HTTP ${String(response.status)}`);
await refreshLog();
} catch (error: unknown) {
notify(`Could not update: ${error instanceof Error ? error.message : String(error)}`, "error");
}
}
async function deleteQso(qso: Qso): Promise<void> {
const confirmed = await bridge.trxUi.confirm({
title: "Delete this contact?",
message: `${qso.call} on ${qso.band ?? formatFreq(qso.freq_hz)} will be removed from the log.`,
confirmLabel: "Delete",
});
if (!confirmed) return;
try {
const response = await fetch(`/api/logbook/${encodeURIComponent(qso.id)}`, { method: "DELETE" });
if (!response.ok) throw new Error(`HTTP ${String(response.status)}`);
await refreshLog();
} catch (error: unknown) {
notify(`Could not delete: ${error instanceof Error ? error.message : String(error)}`, "error");
}
}
async function importAdif(file: File): Promise<void> {
try {
const response = await fetch("/api/logbook/import", { method: "POST", body: await file.arrayBuffer() });
if (!response.ok) throw new Error(`HTTP ${String(response.status)}`);
const outcome = await response.json() as { added: number; duplicate: number; rejected: string[] };
const parts = [`${String(outcome.added)} added`];
if (outcome.duplicate > 0) parts.push(`${String(outcome.duplicate)} already held`);
if (outcome.rejected.length > 0) parts.push(`${String(outcome.rejected.length)} not readable`);
notify(parts.join(", "));
await refreshLog();
} catch (error: unknown) {
notify(`Import failed: ${error instanceof Error ? error.message : String(error)}`, "error");
}
}
// ── Station line ────────────────────────────────────────────────────────────
function renderStation(): void {
const callsign = hostState.ownerCallsign ?? "";
if (stationCallEl) stationCallEl.textContent = callsign || "no callsign set";
if (operatorInput && !operatorInput.value) operatorInput.value = callsign;
if (stationGridEl) {
const grid = hostState.serverLat != null && hostState.serverLon != null
? hostCore.latLonToMaidenhead(hostState.serverLat, hostState.serverLon)
: "";
entryGrid = grid || null;
stationGridEl.textContent = grid;
}
}
// ── Wiring ──────────────────────────────────────────────────────────────────
form?.addEventListener("submit", (event) => { void submitEntry(event); });
clearBtn?.addEventListener("click", resetEntry);
callInput?.addEventListener("input", updateWorkedBefore);
for (const control of [filterCall, filterBand, filterMode]) {
control?.addEventListener("input", () => { void refreshLog(); });
control?.addEventListener("change", () => { void refreshLog(); });
}
for (const control of [cabrilloContest, cabrilloCallsign, cabrilloOperator, cabrilloPower, cabrilloScore]) {
control?.addEventListener("input", syncCabrilloLink);
control?.addEventListener("change", syncCabrilloLink);
}
importBtn?.addEventListener("click", () => { importFile?.click(); });
importFile?.addEventListener("change", () => {
const file = importFile.files?.[0];
if (file) void importAdif(file);
importFile.value = "";
});
/** Start an entry from a decode, and show the operator where it went. */
bridge.logContact = (seed) => {
bridge.navigateToTab?.("logbook");
void openEntry(seed).then(() => callInput?.focus());
};
renderStation();
if (cabrilloCallsign && !cabrilloCallsign.value) {
cabrilloCallsign.value = stationCallEl?.textContent?.trim() ?? "";
}
syncCabrilloLink();
void openEntry();
void refreshLog();
@@ -356,7 +356,7 @@ function schedulerOptionalEl(id: string): SchedulerElement | null {
if (!prevBtn || !nextBtn) return;
const state = schedulerInterleaveState(currentConfig);
const enabled =
schedulerRole === "control" &&
schedulerRole === "admin" &&
!!currentRigId &&
!schedulerStepPending &&
state.activeEntries.length > 1;
@@ -466,7 +466,7 @@ function schedulerOptionalEl(id: string): SchedulerElement | null {
if (!panel) return;
const mode = (currentConfig && currentConfig.mode) || "disabled";
const isControl = schedulerRole === "control";
const isControl = schedulerRole === "admin";
// Mode selector
setSelected("scheduler-mode-select", mode);
@@ -24,8 +24,8 @@ interface ButtonStateOptions {
disabled?: boolean;
}
type TabKind = "primary" | "secondary";
type LayoutCapability = "broadcast" | "digital";
type LayoutName = "compact" | "broadcast" | "digital" | "full";
type LayoutCapability = "broadcast" | "digital" | "ham";
type LayoutName = "compact" | "broadcast" | "digital" | "full" | "ham";
interface OperatorLayout {
label: string;
unavailable?: string;
@@ -191,8 +191,11 @@ function elementById<T extends HTMLElement>(id: string): T {
broadcast: { label: "Broadcast", unavailable: "Broadcast requires an enumerated WFM-capable receiver", advanced: false, audio: true, scheduler: false, preferredTab: "main", capability: "broadcast" },
digital: { label: "Digital", unavailable: "Digital requires a compatible rig mode and an available decoder", advanced: false, audio: false, scheduler: false, preferredTab: "digital-modes", capability: "digital" },
full: { label: "Full controls", advanced: true, audio: true, scheduler: true, preferredTab: "main" },
// Working the bands: the log is the task and the radio is the instrument,
// so this one opens on the logbook with the controls a keystroke away.
ham: { label: "Ham radio", unavailable: "Ham radio needs a rig that can transmit", advanced: true, audio: true, scheduler: false, preferredTab: "logbook", capability: "ham" },
};
const layoutCapabilities: Record<LayoutCapability, boolean> = { broadcast: false, digital: false };
const layoutCapabilities: Record<LayoutCapability, boolean> = { broadcast: false, digital: false, ham: false };
let activeRigId: string | null = null;
// A layout seeds the collapsible sections; it does not hold them there.
@@ -40,7 +40,7 @@ test("background decode loads configuration for the explicitly selected rig", as
const source = await bundleEntry(new URL("../src/plugins/background-decode.ts", import.meta.url));
new vm.Script(source).runInContext(context);
window.trx.modules.backgroundDecode.initialize("rig/a", "control");
window.trx.modules.backgroundDecode.initialize("rig/a", "admin");
await new Promise((resolve) => setTimeout(resolve, 0));
assert.ok(requested.includes("/background-decode/rig%2Fa"));
assert.ok(requested.includes("/bookmarks"));
@@ -32,7 +32,7 @@ function hostFixture(overrides = {}) {
const calls = { postPath: [], setRigFrequency: [], armOptimisticFrequency: [], applyLocalTunedFrequency: [], syncBandwidthInput: [], scheduleSpectrumDraw: 0, syncModePicker: 0 };
const state = {
authEnabled: false,
authRole: "control",
authRole: "admin",
lastActiveRigId: null,
lastRigIds: [],
lastRigDisplayNames: {},
@@ -157,7 +157,7 @@ test("bookmark controls follow the host authentication state", async () => {
if (!elements.has(id)) elements.set(id, new ElementFixture());
return elements.get(id);
};
const { window } = hostFixture({ authEnabled: true, authRole: "rx" });
const { window } = hostFixture({ authEnabled: true, authRole: "user" });
const context = vm.createContext({
window,
document: documentFixture(element),
@@ -171,7 +171,7 @@ test("bookmark controls follow the host authentication state", async () => {
assert.equal(element("bm-add-btn").style.display, "none");
window.trx.state.authRole = "control";
window.trx.state.authRole = "admin";
await window.trx.modules.bookmarks.fetch("");
assert.equal(element("bm-add-btn").style.display, "");
});
@@ -19,7 +19,7 @@ export function createHost({ state = {}, core = {}, modules = {} } = {}) {
serverLat: null,
serverLon: null,
authEnabled: false,
authRole: "control",
authRole: "admin",
lastActiveRigId: null,
lastRigIds: [],
lastRigDisplayNames: {},
@@ -0,0 +1,225 @@
// SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
//
// SPDX-License-Identifier: GPL-2.0-or-later
// The station log: the panel opens an entry pre-filled from the radio and the
// server's clock, writes a contact, keeps it, and says whether the station has
// been worked before. And the ham layout, which is offered only where a rig can
// transmit -- a log is of contacts made.
import assert from "node:assert/strict";
import { chromium } from "playwright-core";
import { startBrowser, startWebFixture } from "./web-fixture.mjs";
/* global document, window, location */
const HELD = [
{
id: "q1", started_at: "2026-08-06T14:22:00Z", call: "DL3ABC", freq_hz: 14_074_000,
band: "20m", mode: "FT8", rst_sent: "-07", rst_rcvd: "-12", gridsquare: "JO31",
my_rig: "Primary fixture",
},
{
id: "q2", started_at: "2026-08-06T13:05:00Z", call: "SP9XYZ", freq_hz: 7_120_000,
band: "40m", mode: "SSB", submode: "LSB", rst_sent: "59", rst_rcvd: "57",
gridsquare: "JO90", my_rig: "Primary fixture",
},
];
const fixture = await startWebFixture({ spectrum: true, tx: true, logbook: [...HELD] });
const { browser, page, runtimeErrors } = await startBrowser(chromium);
const readPanel = () => page.evaluate(() => ({
rows: [...(document.getElementById("log-rows")?.children ?? [])].map((row) => ({
call: row.querySelector(".log-cell-call")?.textContent ?? "",
cells: [...row.querySelectorAll("td")].map((cell) => cell.textContent),
})),
summary: document.getElementById("log-summary")?.textContent ?? "",
freq: document.getElementById("log-freq")?.value ?? "",
mode: document.getElementById("log-mode")?.value ?? "",
call: document.getElementById("log-call")?.value ?? "",
grid: document.getElementById("log-grid")?.value ?? "",
rig: document.getElementById("log-station-rig-name")?.textContent ?? "",
clock: document.getElementById("log-clock")?.textContent ?? "",
worked: document.getElementById("log-worked-before")?.textContent ?? "",
}));
try {
await page.setViewportSize({ width: 1400, height: 950 });
await page.goto(`${fixture.origin}/logbook`, { waitUntil: "domcontentloaded" });
await page.locator("#tab-logbook").waitFor({ state: "visible" });
await page.waitForTimeout(2500);
// The log is there, newest first, with the band and mode of each contact.
const opened = await readPanel();
assert.deepEqual(opened.rows.map((row) => row.call), ["DL3ABC", "SP9XYZ"]);
assert.equal(opened.summary, "2 contacts");
// A phone contact shows the sideband it was worked on, not just "SSB".
assert.ok(opened.rows[1].cells.includes("LSB"), `the row reads ${JSON.stringify(opened.rows[1].cells)}`);
// The entry opened pre-filled: frequency and mode from the rig, the rig's
// name, and the time from the server.
assert.equal(opened.freq, "100", `the frequency pre-filled as "${opened.freq}"`);
assert.equal(opened.mode, "USB", `the mode pre-filled as "${opened.mode}"`);
assert.equal(opened.rig, "Primary fixture");
assert.match(opened.clock, /^\d{2}:\d{2}:\d{2}Z$/, `the clock reads "${opened.clock}"`);
// ...and nothing else was: a report is the operator's to give.
assert.equal(opened.call, "");
assert.equal(await page.evaluate(() => document.getElementById("log-rst-sent")?.value), "");
// Worked-before answers as the callsign is typed.
await page.locator("#log-call").fill("DL3ABC");
await page.waitForTimeout(600);
assert.match((await readPanel()).worked, /Worked before: 20m FT8/);
await page.locator("#log-call").fill("OZ1NEW");
await page.waitForTimeout(600);
assert.match((await readPanel()).worked, /Not worked before/);
// Logging writes the contact and clears the entry for the next one.
await page.locator("#log-rst-sent").fill("59");
await page.locator("#log-rst-rcvd").fill("57");
await page.locator("#log-save-btn").click();
await page.waitForTimeout(900);
const afterLogging = await readPanel();
assert.deepEqual(afterLogging.rows.map((row) => row.call), ["OZ1NEW", "DL3ABC", "SP9XYZ"]);
assert.equal(afterLogging.summary, "3 contacts");
assert.equal(afterLogging.call, "", "the entry kept the callsign after logging it");
assert.equal(afterLogging.freq, "100", "the entry did not re-open pre-filled");
// A decode row starts an entry rather than logging one: what was heard goes
// into the form, and the operator finishes it.
await page.evaluate(() => { window.navigateToTab("digital-modes"); });
await page.waitForTimeout(800);
await page.locator('#tab-digital-modes .sub-tab[data-subtab="ft8"]').click();
await page.waitForTimeout(400);
await page.evaluate(() => {
window.trxPluginRuntime.dispatch("ft8", {
message: "CQ SP2SJG JO94", snr_db: -7, dt_s: 0.2, freq_hz: 1200,
ts_ms: Date.now(), rig_id: "rig-a",
});
});
await page.waitForTimeout(600);
await page.locator("#ft8-messages .ft8-log-btn").first().click();
await page.waitForTimeout(900);
const fromDecode = await page.evaluate(() => ({
path: location.pathname,
call: document.getElementById("log-call")?.value ?? "",
grid: document.getElementById("log-grid")?.value ?? "",
mode: document.getElementById("log-mode")?.value ?? "",
rows: document.getElementById("log-rows")?.children.length ?? 0,
}));
assert.equal(fromDecode.path, "/logbook", `the Log button landed on ${fromDecode.path}`);
assert.equal(fromDecode.call, "SP2SJG", "the heard callsign did not reach the entry");
assert.equal(fromDecode.grid, "JO94", "the heard locator did not reach the entry");
// The decoder answers for the mode, because a rig in DIG cannot.
assert.equal(fromDecode.mode, "FT8", `the mode came through as "${fromDecode.mode}"`);
assert.equal(fromDecode.rows, 3, "a decode logged itself instead of opening an entry");
// The ham layout is on offer, because this rig can transmit.
const layouts = await page.evaluate(() =>
[...document.querySelectorAll("#operator-layout-select option")].map((option) => option.value));
assert.ok(layouts.includes("ham"), `the layouts are ${JSON.stringify(layouts)}`);
// Choosing it the way the picker does. The <select> itself measures zero
// wide in a headless window, so Playwright will not click it; the change
// event is what the picker is wired to either way.
await page.evaluate(() => { window.navigateToTab("main"); });
await page.waitForTimeout(600);
await page.evaluate(() => {
const select = document.getElementById("operator-layout-select");
select.value = "ham";
select.dispatchEvent(new Event("change", { bubbles: true }));
});
await page.waitForTimeout(900);
const inHamLayout = await page.evaluate(() => ({
layout: document.body.dataset.operatorLayout,
path: location.pathname,
}));
assert.equal(inHamLayout.layout, "ham");
assert.equal(inHamLayout.path, "/logbook", "the ham layout opened somewhere else");
// ── Contest working ─────────────────────────────────────────────────────
// The exchange belongs to the session: the contest and the serial sent stay
// between contacts, and the serial counts on by itself.
await page.evaluate(() => { window.navigateToTab("logbook"); });
await page.waitForTimeout(600);
await page.locator("#log-contest-block > summary").click();
await page.locator("#log-contest-id").fill("CQ-WW-SSB");
await page.locator("#log-stx").fill("1");
await page.locator("#log-call").fill("DL9CON");
await page.locator("#log-srx").fill("014");
await page.locator("#log-rst-sent").fill("59");
await page.locator("#log-rst-rcvd").fill("59");
await page.locator("#log-save-btn").click();
await page.waitForTimeout(900);
const afterContest = await page.evaluate(() => ({
contest: document.getElementById("log-contest-id")?.value ?? "",
stx: document.getElementById("log-stx")?.value ?? "",
srx: document.getElementById("log-srx")?.value ?? "",
call: document.getElementById("log-call")?.value ?? "",
}));
assert.equal(afterContest.contest, "CQ-WW-SSB", "the contest was cleared with the contact");
assert.equal(afterContest.stx, "2", `the serial sent went to "${afterContest.stx}"`);
assert.equal(afterContest.srx, "", "the received exchange was kept for the next station");
assert.equal(afterContest.call, "");
// The Cabrillo link carries the header, and names the contest so that only
// its contacts are entered.
await page.locator("#log-contest-export-block > summary").click();
await page.locator("#log-cbr-contest").fill("CQ-WW-SSB");
await page.locator("#log-cbr-score").fill("4242");
await page.waitForTimeout(300);
const cabrillo = await page.evaluate(() =>
document.getElementById("log-cbr-export")?.getAttribute("href") ?? "");
assert.match(cabrillo, /contest=CQ-WW-SSB/, `the Cabrillo link reads "${cabrillo}"`);
assert.match(cabrillo, /claimed_score=4242/, `the Cabrillo link reads "${cabrillo}"`);
const entry = await page.evaluate(async (href) => {
const response = await fetch(href);
return await response.text();
}, cabrillo);
assert.match(entry, /^START-OF-LOG: 3\.0/, entry);
assert.match(entry, /DL9CON/, "the contest contact is not in the entry");
assert.ok(!entry.includes("OZ1NEW"), "a contact outside the contest was entered");
// ── Confirmations ───────────────────────────────────────────────────────
// A card arrives: the contact is marked confirmed, and the per-band report
// counts it.
const confirmRow = page.locator("#log-rows tr", { hasText: "DL9CON" }).first();
await confirmRow.getByRole("button", { name: "Confirm" }).click();
await page.waitForTimeout(800);
await page.locator("#log-statistics-block > summary").click();
await page.waitForTimeout(400);
const confirmed = await page.evaluate(() => ({
marks: [...document.querySelectorAll("#log-rows tr")]
.map((row) => [...row.querySelectorAll("td")].at(-2)?.textContent ?? ""),
bands: [...document.querySelectorAll("#log-statistics-rows tr")]
.map((row) => [...row.querySelectorAll("td")].map((cell) => cell.textContent)),
}));
assert.equal(confirmed.marks.filter((mark) => mark === "✓").length, 1,
`the QSL column reads ${JSON.stringify(confirmed.marks)}`);
const twenty = confirmed.bands.find((band) => band[0] === "20m");
assert.ok(twenty, `the bands are ${JSON.stringify(confirmed.bands)}`);
assert.equal(twenty[3], "1", `20m shows ${twenty[3]} confirmed`);
assert.deepEqual(runtimeErrors, []);
} finally {
await browser.close();
await fixture.close();
}
// Without a transmitter there is nothing to log, so the layout is not offered.
const listenerFixture = await startWebFixture({ spectrum: true, tx: false });
const listener = await startBrowser(chromium);
try {
await listener.page.setViewportSize({ width: 1400, height: 950 });
await listener.page.goto(`${listenerFixture.origin}/`, { waitUntil: "domcontentloaded" });
await listener.page.locator("#content").waitFor({ state: "visible" });
await listener.page.waitForTimeout(2000);
const layouts = await listener.page.evaluate(() =>
[...document.querySelectorAll("#operator-layout-select option")].map((option) => option.value));
assert.ok(!layouts.includes("ham"), `a receiver was offered the ham layout: ${JSON.stringify(layouts)}`);
} finally {
await listener.browser.close();
await listenerFixture.close();
}
console.log("logbook tests passed");
@@ -76,7 +76,7 @@ test("scheduler self-initializes for the active rig when a role is already known
return elements.get(id);
};
const window = {
...createHost({ state: { authRole: "control", lastActiveRigId: "sdr" } }),
...createHost({ state: { authRole: "admin", lastActiveRigId: "sdr" } }),
trxUi: { confirm: async () => true },
};
const context = vm.createContext({
@@ -140,6 +140,7 @@ export async function startWebFixture({
history = {},
bookmarks = [],
backgroundDecode = null,
logbook = [],
bandplan = {},
bandplanEnabled = false,
bandplanUnauthorizedFirst = false,
@@ -231,7 +232,7 @@ export async function startWebFixture({
};
const jsonRoutes = new Map([
["/auth/session", { authenticated: true, role: "control", auth_disabled: true }],
["/auth/session", { authenticated: true, role: "admin", auth_disabled: true }],
["/decoders", DECODER_REGISTRY],
["/rigs", rigsResponse],
["/status", status],
@@ -279,6 +280,130 @@ export async function startWebFixture({
response.writeHead(200).end();
return;
}
// The logbook: an in-memory station log, enough for the panel to open an
// entry, write it, read it back and export it.
if (url.pathname.startsWith("/api/logbook")) {
const tail = url.pathname.slice("/api/logbook".length);
if (tail === "/prefill") {
response.writeHead(200, { "content-type": "application/json" });
response.end(JSON.stringify({
started_at: new Date().toISOString(),
epoch_ms: Date.now(),
freq_hz: status.status.freq.hz,
band: "20m",
mode: url.searchParams.get("decoder") === "ft8" ? "FT8" : "SSB",
submode: url.searchParams.get("decoder") === "ft8" ? null : "USB",
rig_id: url.searchParams.get("remote") ?? "rig-a",
my_rig: "Primary fixture",
call: url.searchParams.get("call"),
gridsquare: url.searchParams.get("gridsquare"),
}));
return;
}
if (tail.startsWith("/worked/")) {
const call = decodeURIComponent(tail.slice("/worked/".length)).toUpperCase();
const worked = logbook
.filter((qso) => qso.call === call)
.map((qso) => ({ band: qso.band, mode: qso.mode }));
response.writeHead(200, { "content-type": "application/json" });
response.end(JSON.stringify({ call, worked }));
return;
}
if (tail === "/statistics") {
const bands = new Map();
for (const qso of logbook) {
const entry = bands.get(qso.band) ?? { band: qso.band, contacts: 0, stations: 0, confirmed: 0, calls: new Set() };
entry.contacts += 1;
entry.calls.add(qso.call);
if (qso.confirmed || qso.qsl_rcvd === "Y" || qso.lotw_qsl_rcvd === "Y") entry.confirmed += 1;
bands.set(qso.band, entry);
}
const list = [...bands.values()].map(({ calls, ...rest }) => ({ ...rest, stations: calls.size }));
response.writeHead(200, { "content-type": "application/json" });
response.end(JSON.stringify({
contacts: logbook.length,
confirmed: list.reduce((total, band) => total + band.confirmed, 0),
bands: list,
}));
return;
}
if (tail === "/export.cbr") {
const contest = url.searchParams.get("contest");
const entered = contest ? logbook.filter((qso) => qso.contest_id === contest) : logbook;
response.writeHead(200, { "content-type": "text/plain" });
response.end(`START-OF-LOG: 3.0\nCONTEST: ${contest ?? ""}\n`
+ entered.map((qso) => `QSO: 14200 PH ${qso.call}\n`).join("")
+ "END-OF-LOG:\n");
return;
}
if (request.method === "PUT") {
const raw = await new Promise((resolve) => {
let text = "";
request.on("data", (chunk) => { text += chunk; });
request.on("end", () => resolve(text));
});
const input = JSON.parse(raw);
const id = tail.replace("/", "");
const held = logbook.find((qso) => qso.id === id);
if (held) {
Object.assign(held, input, { id, confirmed: input.qsl_rcvd === "Y" });
}
response.writeHead(200, { "content-type": "application/json" });
response.end(JSON.stringify(held ?? {}));
return;
}
if (tail === "/export.adi") {
const body = logbook
.map((qso) => `<CALL:${qso.call.length}>${qso.call}<EOR>\n`)
.join("");
response.writeHead(200, { "content-type": "text/plain" });
response.end(body);
return;
}
if (request.method === "POST" && tail === "") {
const raw = await new Promise((resolve) => {
let text = "";
request.on("data", (chunk) => { text += chunk; });
request.on("end", () => resolve(text));
});
const input = JSON.parse(raw);
const qso = {
id: `qso-${String(logbook.length + 1)}`,
started_at: input.started_at ?? new Date().toISOString(),
call: String(input.call).toUpperCase(),
freq_hz: input.freq_hz,
band: "20m",
mode: input.mode,
submode: input.submode,
rst_sent: input.rst_sent,
rst_rcvd: input.rst_rcvd,
gridsquare: input.gridsquare ? String(input.gridsquare).toUpperCase() : null,
my_rig: input.my_rig,
operator: input.operator,
contest_id: input.contest_id ?? null,
stx: input.stx ?? null,
srx: input.srx ?? null,
confirmed: input.qsl_rcvd === "Y" || input.lotw_qsl_rcvd === "Y",
};
logbook.unshift(qso);
response.writeHead(200, { "content-type": "application/json" });
response.end(JSON.stringify(qso));
return;
}
if (request.method === "DELETE") {
const id = tail.replace("/", "");
const index = logbook.findIndex((qso) => qso.id === id);
if (index >= 0) logbook.splice(index, 1);
response.writeHead(200, { "content-type": "application/json" });
response.end(JSON.stringify({ deleted: index >= 0 }));
return;
}
const wanted = (url.searchParams.get("call") ?? "").toUpperCase();
const matching = wanted ? logbook.filter((qso) => qso.call.includes(wanted)) : logbook;
response.writeHead(200, { "content-type": "application/json" });
response.end(JSON.stringify({ total: logbook.length, qsos: matching }));
return;
}
// Background decode: the panel reads its config, its status, and the
// bookmark list, and writes the config back.
if (url.pathname.startsWith("/background-decode/")) {
@@ -138,6 +138,17 @@ pub(crate) async fn statistics_index(req: HttpRequest) -> impl Responder {
)
}
#[get("/logbook")]
pub(crate) async fn logbook_index(req: HttpRequest) -> impl Responder {
let c = gz_index_html();
static_asset_response(
&req,
"text/html; charset=utf-8",
c,
AssetCaching::Revalidate,
)
}
#[get("/satellites")]
pub(crate) async fn satellites_index(req: HttpRequest) -> impl Responder {
let c = gz_index_html();
@@ -0,0 +1,456 @@
// SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
//
// SPDX-License-Identifier: GPL-2.0-or-later
//! The logbook over HTTP: read, write, import, export, and the clock a contact
//! is stamped from.
use std::sync::Arc;
use actix_web::http::header;
use actix_web::{delete, get, post, put, web, HttpRequest, HttpResponse, Responder};
use chrono::Utc;
use serde::{Deserialize, Serialize};
use trx_logbook::qso::{adif_mode_for_rig_mode, band_for_hz, mode_for_decoder};
use trx_logbook::{LogQuery, Logbook, Qso};
use super::{active_rig_id_from_context, require_control};
use crate::server::auth::AuthState;
/// What a contact looks like on the wire.
///
/// The band is sent although it is derived, because every reader of the log
/// wants it and none of them should have to carry the band plan to get it.
#[derive(Debug, Serialize)]
struct QsoView {
#[serde(flatten)]
qso: Qso,
band: Option<&'static str>,
/// Whether the other station has confirmed, from whichever bureau answered.
confirmed: bool,
}
impl From<Qso> for QsoView {
fn from(qso: Qso) -> Self {
Self {
band: qso.band(),
confirmed: qso.is_confirmed(),
qso,
}
}
}
/// A contact as the panel sends it.
///
/// Times come from the server (`started_at` omitted means "now"), so a browser
/// with a wrong clock cannot write a wrong time into the log.
#[derive(Debug, Deserialize)]
struct QsoInput {
#[serde(default)]
id: Option<String>,
#[serde(default)]
started_at: Option<chrono::DateTime<Utc>>,
#[serde(default)]
ended_at: Option<chrono::DateTime<Utc>>,
call: String,
freq_hz: u64,
mode: String,
#[serde(default)]
submode: Option<String>,
#[serde(default)]
rst_sent: Option<String>,
#[serde(default)]
rst_rcvd: Option<String>,
#[serde(default)]
gridsquare: Option<String>,
#[serde(default)]
name: Option<String>,
#[serde(default)]
qth: Option<String>,
#[serde(default)]
comment: Option<String>,
#[serde(default)]
tx_pwr_w: Option<f64>,
#[serde(default)]
station_callsign: Option<String>,
#[serde(default)]
operator: Option<String>,
#[serde(default)]
my_gridsquare: Option<String>,
#[serde(default)]
my_rig: Option<String>,
#[serde(default)]
rig_id: Option<String>,
#[serde(default)]
contest_id: Option<String>,
#[serde(default)]
stx: Option<u32>,
#[serde(default)]
stx_string: Option<String>,
#[serde(default)]
srx: Option<u32>,
#[serde(default)]
srx_string: Option<String>,
#[serde(default)]
cqz: Option<u8>,
#[serde(default)]
ituz: Option<u8>,
#[serde(default)]
qsl_sent: Option<String>,
#[serde(default)]
qsl_rcvd: Option<String>,
#[serde(default)]
lotw_qsl_sent: Option<String>,
#[serde(default)]
lotw_qsl_rcvd: Option<String>,
#[serde(default)]
eqsl_qsl_sent: Option<String>,
#[serde(default)]
eqsl_qsl_rcvd: Option<String>,
}
/// ADIF's QSL states are single letters. Anything else is refused rather than
/// written, or a log would grow states no other program can read.
fn qsl_state(value: Option<String>) -> Option<String> {
let state = blank_to_none(value)?.to_uppercase();
matches!(state.as_str(), "Y" | "N" | "R" | "I" | "Q" | "V").then_some(state)
}
fn blank_to_none(value: Option<String>) -> Option<String> {
value
.map(|text| text.trim().to_string())
.filter(|text| !text.is_empty())
}
impl QsoInput {
fn into_qso(self, existing: Option<Qso>) -> Result<Qso, String> {
let call = self.call.trim();
if call.is_empty() {
return Err("a contact needs a callsign".to_string());
}
if self.mode.trim().is_empty() {
return Err("a contact needs a mode".to_string());
}
let started_at = self
.started_at
.or(existing.as_ref().map(|q| q.started_at))
.unwrap_or_else(Utc::now);
let mut qso = Qso::new(
self.id
.or(existing.as_ref().map(|q| q.id.clone()))
.unwrap_or_else(trx_logbook::new_id),
started_at,
call,
self.freq_hz,
&self.mode,
);
qso.ended_at = self.ended_at;
qso.submode = blank_to_none(self.submode).map(|s| s.to_uppercase());
qso.rst_sent = blank_to_none(self.rst_sent);
qso.rst_rcvd = blank_to_none(self.rst_rcvd);
qso.gridsquare = blank_to_none(self.gridsquare).map(|g| g.to_uppercase());
qso.name = blank_to_none(self.name);
qso.qth = blank_to_none(self.qth);
qso.comment = blank_to_none(self.comment);
qso.tx_pwr_w = self.tx_pwr_w;
qso.station_callsign = blank_to_none(self.station_callsign).map(|c| c.to_uppercase());
qso.operator = blank_to_none(self.operator).map(|c| c.to_uppercase());
qso.my_gridsquare = blank_to_none(self.my_gridsquare).map(|g| g.to_uppercase());
qso.my_rig = blank_to_none(self.my_rig);
qso.rig_id = blank_to_none(self.rig_id);
qso.contest_id = blank_to_none(self.contest_id).map(|c| c.to_uppercase());
qso.stx = self.stx;
qso.stx_string = blank_to_none(self.stx_string);
qso.srx = self.srx;
qso.srx_string = blank_to_none(self.srx_string);
qso.cqz = self.cqz;
qso.ituz = self.ituz;
qso.qsl_sent = qsl_state(self.qsl_sent);
qso.qsl_rcvd = qsl_state(self.qsl_rcvd);
qso.lotw_qsl_sent = qsl_state(self.lotw_qsl_sent);
qso.lotw_qsl_rcvd = qsl_state(self.lotw_qsl_rcvd);
qso.eqsl_qsl_sent = qsl_state(self.eqsl_qsl_sent);
qso.eqsl_qsl_rcvd = qsl_state(self.eqsl_qsl_rcvd);
// Whatever an imported contact carried that this application does not
// model stays with it through an edit.
if let Some(existing) = existing {
qso.extra = existing.extra;
}
Ok(qso)
}
}
fn book(logbook: &web::Data<Arc<Logbook>>) -> Arc<Logbook> {
logbook.get_ref().clone()
}
/// The rig's name as the operator knows it, which is what belongs in the log —
/// falling back to its id, since a log entry naming nothing is worse.
fn rig_display_name(context: &trx_frontend::FrontendRuntimeContext, rig_id: &str) -> String {
context
.routing
.remote_rigs
.lock()
.ok()
.and_then(|rigs| {
rigs.iter()
.find(|rig| rig.rig_id == rig_id)
.and_then(|rig| rig.display_name.clone())
})
.unwrap_or_else(|| rig_id.to_string())
}
/// `GET /api/logbook` — contacts, newest first, filtered.
#[get("/api/logbook")]
pub async fn list_qsos(
query: web::Query<LogQuery>,
logbook: web::Data<Arc<Logbook>>,
) -> impl Responder {
let query = query.into_inner();
let total = book(&logbook).count();
let qsos: Vec<QsoView> = book(&logbook)
.query(&query)
.into_iter()
.map(QsoView::from)
.collect();
HttpResponse::Ok().json(serde_json::json!({ "total": total, "qsos": qsos }))
}
/// `POST /api/logbook` — write a contact.
#[post("/api/logbook")]
pub async fn add_qso(
req: HttpRequest,
input: web::Json<QsoInput>,
logbook: web::Data<Arc<Logbook>>,
auth_state: web::Data<AuthState>,
) -> Result<HttpResponse, actix_web::Error> {
require_control(&req, auth_state.get_ref())?;
let qso = match input.into_inner().into_qso(None) {
Ok(qso) => qso,
Err(reason) => {
return Ok(HttpResponse::BadRequest().json(serde_json::json!({ "error": reason })))
}
};
match book(&logbook).put(qso) {
Ok(saved) => Ok(HttpResponse::Ok().json(QsoView::from(saved))),
Err(err) => Ok(HttpResponse::InternalServerError()
.json(serde_json::json!({ "error": err.to_string() }))),
}
}
/// `PUT /api/logbook/{id}` — change a contact.
#[put("/api/logbook/{id}")]
pub async fn edit_qso(
req: HttpRequest,
path: web::Path<String>,
input: web::Json<QsoInput>,
logbook: web::Data<Arc<Logbook>>,
auth_state: web::Data<AuthState>,
) -> Result<HttpResponse, actix_web::Error> {
require_control(&req, auth_state.get_ref())?;
let id = path.into_inner();
let Some(existing) = book(&logbook).get(&id) else {
return Ok(HttpResponse::NotFound().json(serde_json::json!({ "error": "no such contact" })));
};
let mut input = input.into_inner();
input.id = Some(id);
let qso = match input.into_qso(Some(existing)) {
Ok(qso) => qso,
Err(reason) => {
return Ok(HttpResponse::BadRequest().json(serde_json::json!({ "error": reason })))
}
};
match book(&logbook).put(qso) {
Ok(saved) => Ok(HttpResponse::Ok().json(QsoView::from(saved))),
Err(err) => Ok(HttpResponse::InternalServerError()
.json(serde_json::json!({ "error": err.to_string() }))),
}
}
/// `DELETE /api/logbook/{id}` — forget a contact.
#[delete("/api/logbook/{id}")]
pub async fn delete_qso(
req: HttpRequest,
path: web::Path<String>,
logbook: web::Data<Arc<Logbook>>,
auth_state: web::Data<AuthState>,
) -> Result<HttpResponse, actix_web::Error> {
require_control(&req, auth_state.get_ref())?;
match book(&logbook).delete(&path.into_inner()) {
Ok(true) => Ok(HttpResponse::Ok().json(serde_json::json!({ "deleted": true }))),
Ok(false) => {
Ok(HttpResponse::NotFound().json(serde_json::json!({ "error": "no such contact" })))
}
Err(err) => Ok(HttpResponse::InternalServerError()
.json(serde_json::json!({ "error": err.to_string() }))),
}
}
/// `GET /api/logbook/export.adi` — ADIF, honouring the same filters as a read.
#[get("/api/logbook/export.adi")]
pub async fn export_adi(
query: web::Query<LogQuery>,
logbook: web::Data<Arc<Logbook>>,
) -> impl Responder {
let text = book(&logbook).export_adi(&query.into_inner(), env!("CARGO_PKG_VERSION"));
let filename = format!("trx-rs-log-{}.adi", Utc::now().format("%Y%m%d"));
HttpResponse::Ok()
.insert_header((header::CONTENT_TYPE, "text/plain; charset=utf-8"))
.insert_header((
header::CONTENT_DISPOSITION,
format!("attachment; filename=\"{filename}\""),
))
.body(text)
}
/// `POST /api/logbook/import` — take an ADIF file, skipping what is already held.
#[post("/api/logbook/import")]
pub async fn import_adi(
req: HttpRequest,
body: web::Bytes,
logbook: web::Data<Arc<Logbook>>,
auth_state: web::Data<AuthState>,
) -> Result<HttpResponse, actix_web::Error> {
require_control(&req, auth_state.get_ref())?;
match book(&logbook).import_adi(&body) {
Ok(outcome) => Ok(HttpResponse::Ok().json(outcome)),
Err(err) => Ok(HttpResponse::InternalServerError()
.json(serde_json::json!({ "error": err.to_string() }))),
}
}
/// `GET /api/logbook/export.cbr` — a contest entry, in the only format sponsors
/// take.
///
/// The header cannot be worked out from the log — how many operators, how much
/// power — so it comes as query parameters from the operator.
#[get("/api/logbook/export.cbr")]
pub async fn export_cabrillo(
query: web::Query<LogQuery>,
header: web::Query<trx_logbook::CabrilloHeader>,
logbook: web::Data<Arc<Logbook>>,
) -> impl Responder {
let text = book(&logbook).export_cabrillo(&query.into_inner(), &header.into_inner());
let filename = format!("trx-rs-contest-{}.cbr", Utc::now().format("%Y%m%d"));
HttpResponse::Ok()
.insert_header((header::CONTENT_TYPE, "text/plain; charset=utf-8"))
.insert_header((
header::CONTENT_DISPOSITION,
format!("attachment; filename=\"{filename}\""),
))
.body(text)
}
/// `GET /api/logbook/statistics` — what has been worked and confirmed, per band.
#[get("/api/logbook/statistics")]
pub async fn statistics(logbook: web::Data<Arc<Logbook>>) -> impl Responder {
let bands = book(&logbook).band_statistics();
let contacts: usize = bands.iter().map(|band| band.contacts).sum();
let confirmed: usize = bands.iter().map(|band| band.confirmed).sum();
HttpResponse::Ok().json(serde_json::json!({
"contacts": contacts,
"confirmed": confirmed,
"bands": bands,
}))
}
/// `GET /api/logbook/worked/{call}` — which bands and modes this station has been
/// worked on.
#[get("/api/logbook/worked/{call}")]
pub async fn worked_before(
path: web::Path<String>,
logbook: web::Data<Arc<Logbook>>,
) -> impl Responder {
let call = path.into_inner();
let worked: Vec<serde_json::Value> = book(&logbook)
.worked_before(&call)
.into_iter()
.map(|(band, mode)| serde_json::json!({ "band": band, "mode": mode }))
.collect();
HttpResponse::Ok().json(serde_json::json!({
"call": trx_logbook::qso::normalize_call(&call),
"worked": worked,
}))
}
/// `GET /api/logbook/now` — the clock a contact is stamped from.
///
/// The panel shows the operator when their browser disagrees with it, rather
/// than logging a time nobody expected.
#[get("/api/logbook/now")]
pub async fn server_now() -> impl Responder {
let now = Utc::now();
HttpResponse::Ok().json(serde_json::json!({
"utc": now.to_rfc3339(),
"epoch_ms": now.timestamp_millis(),
}))
}
/// `GET /api/logbook/prefill` — the six fields an entry opens with.
///
/// Worked out on the server because that is where the rig state, the station
/// identity and the clock all are; the panel would otherwise have to assemble
/// them from three places and would still not have the clock.
#[derive(Debug, Deserialize)]
pub struct PrefillQuery {
/// The rig the entry is for.
#[serde(default)]
pub remote: Option<String>,
/// The decoder a decode row came from, which answers for the mode when the
/// rig only says `DIG`.
#[serde(default)]
pub decoder: Option<String>,
/// A callsign and locator carried over from a decode row.
#[serde(default)]
pub call: Option<String>,
#[serde(default)]
pub gridsquare: Option<String>,
}
#[get("/api/logbook/prefill")]
pub async fn prefill(
query: web::Query<PrefillQuery>,
context: web::Data<Arc<trx_frontend::FrontendRuntimeContext>>,
state: web::Data<tokio::sync::watch::Receiver<trx_core::RigState>>,
) -> impl Responder {
let query = query.into_inner();
let rig_id = query
.remote
.clone()
.filter(|id| !id.is_empty())
.or_else(|| active_rig_id_from_context(context.get_ref()));
let rig_state = rig_id
.as_deref()
.and_then(|id| context.rig_state_rx(id))
.unwrap_or_else(|| state.get_ref().clone())
.borrow()
.clone();
let freq_hz = rig_state.status.freq.hz;
let rig_mode = format!("{:?}", rig_state.status.mode);
// The rig cannot answer for DIG: a rig in DIG is in FT8 or FT4 depending on
// which decoder is running, so the decoder is asked first when there is one.
let (mode, submode) = query
.decoder
.as_deref()
.and_then(mode_for_decoder)
.or_else(|| adif_mode_for_rig_mode(&rig_mode))
.map_or((String::new(), None), |(mode, submode)| {
(mode.to_string(), submode.map(str::to_string))
});
let now = Utc::now();
HttpResponse::Ok().json(serde_json::json!({
"started_at": now.to_rfc3339(),
"epoch_ms": now.timestamp_millis(),
"freq_hz": freq_hz,
"band": band_for_hz(freq_hz),
"mode": mode,
"submode": submode,
"rig_id": rig_id,
"my_rig": rig_id.as_deref().map(|id| rig_display_name(context.get_ref(), id)),
"call": query.call.map(|c| trx_logbook::qso::normalize_call(&c)),
"gridsquare": query.gridsquare.map(|g| g.trim().to_uppercase()),
}))
}
@@ -7,6 +7,7 @@
mod assets;
mod bookmarks;
mod decoder;
mod logbook;
pub mod recorder;
pub mod rig;
mod sse;
@@ -398,8 +399,8 @@ fn require_control(
return Ok(());
}
match crate::server::auth::get_session_role(req, auth_state) {
Some(crate::server::auth::AuthRole::Control) => Ok(()),
_ => Err(actix_web::error::ErrorForbidden("control role required")),
Some(crate::server::auth::AuthRole::Admin) => Ok(()),
_ => Err(actix_web::error::ErrorForbidden("admin role required")),
}
}
@@ -664,6 +665,7 @@ pub fn configure(cfg: &mut web::ServiceConfig) {
.service(assets::recorder_index)
.service(assets::settings_index)
.service(assets::about_index)
.service(assets::logbook_index)
.service(assets::satellites_index)
.service(assets::statistics_index)
.service(assets::bookmarks_index)
@@ -706,7 +708,23 @@ pub fn configure(cfg: &mut web::ServiceConfig) {
// Auth endpoints
.service(crate::server::auth::login)
.service(crate::server::auth::logout)
.service(crate::server::auth::session_status);
.service(crate::server::auth::session_status)
.service(crate::server::auth::list_users)
.service(crate::server::auth::create_user)
.service(crate::server::auth::update_user)
.service(crate::server::auth::delete_user)
// Logbook
.service(logbook::list_qsos)
.service(logbook::add_qso)
.service(logbook::edit_qso)
.service(logbook::delete_qso)
.service(logbook::export_adi)
.service(logbook::export_cabrillo)
.service(logbook::statistics)
.service(logbook::import_adi)
.service(logbook::worked_before)
.service(logbook::server_now)
.service(logbook::prefill);
}
#[cfg(test)]
@@ -935,6 +953,286 @@ mod tests {
);
}
/// Auth off: every session may write without an account.
fn auth_state_disabled() -> crate::server::auth::AuthState {
crate::server::auth::AuthState::new(crate::server::auth::AuthConfig::new(
false,
std::path::PathBuf::from("unused-users.json"),
None,
None,
std::time::Duration::from_secs(3600),
false,
crate::server::auth::SameSite::Lax,
))
.unwrap()
}
/// Auth on with no session presented, which is what a listener is.
fn auth_state_locked() -> crate::server::auth::AuthState {
let directory = tempfile::tempdir().unwrap();
crate::server::auth::AuthState::new(crate::server::auth::AuthConfig::new(
true,
directory.path().join("users.json"),
Some("admin".to_string()),
Some("password123".to_string()),
std::time::Duration::from_secs(3600),
false,
crate::server::auth::SameSite::Lax,
))
.unwrap()
}
/// A contact written over HTTP comes back out of the log, and out of an
/// ADIF export that another logger could read.
#[actix_web::test]
async fn a_contact_written_over_http_is_kept_and_exported() {
let dir = tempfile::tempdir().expect("tempdir");
let logbook = std::sync::Arc::new(
trx_logbook::Logbook::open(&dir.path().join("logbook.jsonl")).expect("open"),
);
let app = actix_test::init_service(
App::new()
.app_data(web::Data::new(logbook.clone()))
.app_data(web::Data::new(auth_state_disabled()))
.service(logbook::add_qso)
.service(logbook::list_qsos)
.service(logbook::export_adi)
.service(logbook::worked_before),
)
.await;
let response = actix_test::call_service(
&app,
actix_test::TestRequest::post()
.uri("/api/logbook")
.set_json(serde_json::json!({
"call": "sp2sjg",
"freq_hz": 14_074_000_u64,
"mode": "FT8",
"rst_sent": "-07",
"gridsquare": "jo94",
}))
.to_request(),
)
.await;
assert_eq!(response.status(), 200);
let written: serde_json::Value = actix_test::read_body_json(response).await;
// Normalised on the way in, and the band worked out from the dial.
assert_eq!(written["call"], "SP2SJG");
assert_eq!(written["gridsquare"], "JO94");
assert_eq!(written["band"], "20m");
let listed: serde_json::Value = actix_test::call_and_read_body_json(
&app,
actix_test::TestRequest::get()
.uri("/api/logbook")
.to_request(),
)
.await;
assert_eq!(listed["total"], 1);
assert_eq!(listed["qsos"][0]["call"], "SP2SJG");
let worked: serde_json::Value = actix_test::call_and_read_body_json(
&app,
actix_test::TestRequest::get()
.uri("/api/logbook/worked/SP2SJG")
.to_request(),
)
.await;
assert_eq!(worked["worked"][0]["band"], "20m");
let exported = actix_test::call_and_read_body(
&app,
actix_test::TestRequest::get()
.uri("/api/logbook/export.adi")
.to_request(),
)
.await;
let text = String::from_utf8_lossy(&exported);
assert!(text.contains("<CALL:6>SP2SJG"), "{text}");
assert!(text.contains("<BAND:3>20m"), "{text}");
assert!(text.contains("<EOR>"), "{text}");
}
/// A contest entry comes out in Cabrillo, holding that contest's contacts
/// and no others, with the header the operator gave.
#[actix_web::test]
async fn a_contest_entry_is_exported_as_cabrillo() {
let dir = tempfile::tempdir().expect("tempdir");
let logbook = std::sync::Arc::new(
trx_logbook::Logbook::open(&dir.path().join("logbook.jsonl")).expect("open"),
);
let app = actix_test::init_service(
App::new()
.app_data(web::Data::new(logbook.clone()))
.app_data(web::Data::new(auth_state_disabled()))
.service(logbook::add_qso)
.service(logbook::export_cabrillo)
.service(logbook::statistics),
)
.await;
for (call, contest, serial, confirmed) in [
("DL1AB", Some("CQ-WW-SSB"), 1, true),
("OZ2CD", Some("CQ-WW-SSB"), 2, false),
("SP3EF", None, 0, false),
] {
let response = actix_test::call_service(
&app,
actix_test::TestRequest::post()
.uri("/api/logbook")
.set_json(serde_json::json!({
"call": call,
"freq_hz": 14_200_000_u64,
"mode": "SSB",
"rst_sent": "59",
"rst_rcvd": "59",
"station_callsign": "SP0TRX",
"contest_id": contest,
"stx": serial,
"srx": serial,
"lotw_qsl_rcvd": if confirmed { "Y" } else { "N" },
}))
.to_request(),
)
.await;
assert_eq!(response.status(), 200);
}
let entry = actix_test::call_and_read_body(
&app,
actix_test::TestRequest::get()
.uri("/api/logbook/export.cbr?contest=CQ-WW-SSB&callsign=SP0TRX&claimed_score=42")
.to_request(),
)
.await;
let text = String::from_utf8_lossy(&entry);
assert!(text.starts_with("START-OF-LOG: 3.0"), "{text}");
assert!(text.contains("CONTEST: CQ-WW-SSB"), "{text}");
assert!(text.contains("CLAIMED-SCORE: 42"), "{text}");
assert_eq!(
text.lines().filter(|line| line.starts_with("QSO:")).count(),
2,
"the entry holds contacts from outside the contest: {text}"
);
assert!(!text.contains("SP3EF"), "{text}");
// And the statistics count the station once per band, with the
// confirmation counted wherever it came from.
let stats: serde_json::Value = actix_test::call_and_read_body_json(
&app,
actix_test::TestRequest::get()
.uri("/api/logbook/statistics")
.to_request(),
)
.await;
assert_eq!(stats["contacts"], 3);
assert_eq!(stats["confirmed"], 1);
assert_eq!(stats["bands"][0]["band"], "20m");
assert_eq!(stats["bands"][0]["stations"], 3);
}
/// A QSL state that is not one of ADIF's letters is dropped rather than
/// written, or the log grows states nothing else can read.
#[actix_web::test]
async fn a_qsl_state_outside_the_enumeration_is_not_written() {
let dir = tempfile::tempdir().expect("tempdir");
let logbook = std::sync::Arc::new(
trx_logbook::Logbook::open(&dir.path().join("logbook.jsonl")).expect("open"),
);
let app = actix_test::init_service(
App::new()
.app_data(web::Data::new(logbook))
.app_data(web::Data::new(auth_state_disabled()))
.service(logbook::add_qso),
)
.await;
let written: serde_json::Value = actix_test::call_and_read_body_json(
&app,
actix_test::TestRequest::post()
.uri("/api/logbook")
.set_json(serde_json::json!({
"call": "SP1AA", "freq_hz": 14_074_000_u64, "mode": "FT8",
"qsl_rcvd": "maybe", "lotw_qsl_rcvd": "y",
}))
.to_request(),
)
.await;
assert!(written.get("qsl_rcvd").is_none(), "{written}");
// ...but a lowercase letter that is in the enumeration is taken.
assert_eq!(written["lotw_qsl_rcvd"], "Y");
assert_eq!(written["confirmed"], true);
}
/// A read-only session may read the log and may not write to it.
#[actix_web::test]
async fn a_read_only_session_cannot_write_to_the_log() {
let dir = tempfile::tempdir().expect("tempdir");
let logbook = std::sync::Arc::new(
trx_logbook::Logbook::open(&dir.path().join("logbook.jsonl")).expect("open"),
);
let app = actix_test::init_service(
App::new()
.app_data(web::Data::new(logbook))
.app_data(web::Data::new(auth_state_locked()))
.service(logbook::add_qso)
.service(logbook::list_qsos),
)
.await;
let response = actix_test::call_service(
&app,
actix_test::TestRequest::post()
.uri("/api/logbook")
.set_json(serde_json::json!({
"call": "SP2SJG", "freq_hz": 14_074_000_u64, "mode": "FT8",
}))
.to_request(),
)
.await;
assert!(
response.status().is_client_error(),
"a listener wrote to the log: {}",
response.status()
);
let listed: serde_json::Value = actix_test::call_and_read_body_json(
&app,
actix_test::TestRequest::get()
.uri("/api/logbook")
.to_request(),
)
.await;
assert_eq!(listed["total"], 0);
}
/// A contact needs a callsign; the panel is not the only thing that has to
/// insist on it.
#[actix_web::test]
async fn a_contact_without_a_callsign_is_refused() {
let dir = tempfile::tempdir().expect("tempdir");
let logbook = std::sync::Arc::new(
trx_logbook::Logbook::open(&dir.path().join("logbook.jsonl")).expect("open"),
);
let app = actix_test::init_service(
App::new()
.app_data(web::Data::new(logbook))
.app_data(web::Data::new(auth_state_disabled()))
.service(logbook::add_qso),
)
.await;
let response = actix_test::call_service(
&app,
actix_test::TestRequest::post()
.uri("/api/logbook")
.set_json(serde_json::json!({
"call": " ", "freq_hz": 14_074_000_u64, "mode": "FT8",
}))
.to_request(),
)
.await;
assert_eq!(response.status(), 400);
}
/// GET /status returns 200 with valid JSON containing rig snapshot fields.
#[actix_web::test]
async fn test_status_endpoint_returns_json() {
@@ -4,18 +4,24 @@
//! HTTP authentication module for trx-frontend-http.
//!
//! Provides optional session-based authentication with two roles:
//! - `Rx`: read-only access to status/events/audio
//! - `Control`: full access including TX/PTT control
//! Provides optional session-based authentication backed by a persistent,
//! administrator-managed user database.
use actix_web::{
cookie::Cookie,
delete,
dev::{forward_ready, Service, ServiceRequest, ServiceResponse, Transform},
get, post, web, Error, HttpRequest, HttpResponse, Responder,
get, patch, post, web, Error, HttpRequest, HttpResponse, Responder,
};
use argon2::{
password_hash::{rand_core::OsRng, PasswordHash, PasswordHasher, PasswordVerifier, SaltString},
Argon2,
};
use futures_util::future::LocalBoxFuture;
use serde::{Deserialize, Serialize};
use std::collections::HashMap;
use std::fs;
use std::path::{Path, PathBuf};
use std::sync::{Arc, Mutex, RwLock};
use std::time::{Duration, Instant, SystemTime};
use tracing::warn;
@@ -27,17 +33,17 @@ pub type SessionId = String;
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "lowercase")]
pub enum AuthRole {
/// Read-only access (rx passphrase)
Rx,
/// Full control access (control passphrase)
Control,
/// Read-only access.
User,
/// Full control and user-management access.
Admin,
}
impl AuthRole {
pub fn as_str(&self) -> &'static str {
match self {
Self::Rx => "rx",
Self::Control => "control",
Self::User => "user",
Self::Admin => "admin",
}
}
}
@@ -45,6 +51,7 @@ impl AuthRole {
/// Session record stored in the session store
#[derive(Debug, Clone)]
pub struct SessionRecord {
pub username: String,
pub role: AuthRole,
pub issued_at: SystemTime,
pub expires_at: SystemTime,
@@ -75,12 +82,13 @@ impl SessionStore {
}
/// Create a new session with the given role and TTL
pub fn create(&self, role: AuthRole, ttl: Duration) -> SessionId {
pub fn create(&self, username: String, role: AuthRole, ttl: Duration) -> SessionId {
let now = SystemTime::now();
let expires_at = now + ttl;
let session_id = Self::generate_session_id();
let record = SessionRecord {
username,
role,
issued_at: now,
expires_at,
@@ -121,6 +129,12 @@ impl SessionStore {
store.remove(session_id);
}
/// Invalidate every session belonging to a user.
pub fn remove_user(&self, username: &str) {
let mut store = self.sessions.write().unwrap_or_else(|e| e.into_inner());
store.retain(|_, record| record.username != username);
}
/// Remove all expired sessions
pub fn cleanup_expired(&self) {
let mut store = self.sessions.write().unwrap_or_else(|e| {
@@ -167,9 +181,9 @@ impl SameSite {
#[derive(Debug, Clone)]
pub struct AuthConfig {
pub enabled: bool,
pub rx_passphrase: Option<String>,
pub control_passphrase: Option<String>,
pub tx_access_control_enabled: bool,
pub users_file: PathBuf,
pub bootstrap_admin_username: Option<String>,
pub bootstrap_admin_password: Option<String>,
pub session_ttl: Duration,
pub cookie_secure: bool,
pub cookie_same_site: SameSite,
@@ -179,39 +193,236 @@ impl AuthConfig {
/// Create a new auth config with all fields
pub fn new(
enabled: bool,
rx_passphrase: Option<String>,
control_passphrase: Option<String>,
tx_access_control_enabled: bool,
users_file: PathBuf,
bootstrap_admin_username: Option<String>,
bootstrap_admin_password: Option<String>,
session_ttl: Duration,
cookie_secure: bool,
cookie_same_site: SameSite,
) -> Self {
Self {
enabled,
rx_passphrase,
control_passphrase,
tx_access_control_enabled,
users_file,
bootstrap_admin_username,
bootstrap_admin_password,
session_ttl,
cookie_secure,
cookie_same_site,
}
}
}
/// Check passphrase and return the corresponding role
pub fn check_passphrase(&self, passphrase: &str) -> Option<AuthRole> {
// Use constant-time comparison to reduce timing attacks
if let Some(ctrl_pass) = &self.control_passphrase {
if constant_time_eq(passphrase, ctrl_pass) {
return Some(AuthRole::Control);
#[derive(Debug, Clone, Serialize, Deserialize)]
pub struct UserRecord {
pub username: String,
pub password_hash: String,
pub role: AuthRole,
}
#[derive(Debug, Clone, Serialize, Deserialize, Default)]
struct UserDatabase {
users: Vec<UserRecord>,
}
/// Persistent user database. Passwords are Argon2id hashes; writes replace the
/// database atomically so an interrupted update cannot truncate it.
pub struct UserStore {
path: PathBuf,
users: RwLock<HashMap<String, UserRecord>>,
}
impl UserStore {
fn open(config: &AuthConfig) -> Result<Self, String> {
if !config.enabled {
return Ok(Self {
path: config.users_file.clone(),
users: RwLock::new(HashMap::new()),
});
}
let records = if config.users_file.exists() {
let bytes = fs::read(&config.users_file)
.map_err(|e| format!("read {}: {e}", config.users_file.display()))?;
let db: UserDatabase = serde_json::from_slice(&bytes)
.map_err(|e| format!("parse {}: {e}", config.users_file.display()))?;
db.users
} else {
let username = config.bootstrap_admin_username.as_deref().ok_or_else(|| {
format!(
"user database {} does not exist and no bootstrap administrator was configured",
config.users_file.display()
)
})?;
let password = config
.bootstrap_admin_password
.as_deref()
.ok_or_else(|| "bootstrap administrator password is missing".to_string())?;
vec![UserRecord {
username: validate_username(username)?.to_string(),
password_hash: hash_password(password)?,
role: AuthRole::Admin,
}]
};
let mut users = HashMap::new();
for record in records {
validate_username(&record.username)?;
if users.insert(record.username.clone(), record).is_some() {
return Err("user database contains duplicate usernames".to_string());
}
}
if let Some(rx_pass) = &self.rx_passphrase {
if constant_time_eq(passphrase, rx_pass) {
return Some(AuthRole::Rx);
}
if !users.values().any(|u| u.role == AuthRole::Admin) {
return Err("user database must contain at least one administrator".to_string());
}
None
let store = Self {
path: config.users_file.clone(),
users: RwLock::new(users),
};
if !store.path.exists() {
store.persist()?;
}
Ok(store)
}
fn authenticate(&self, username: &str, password: &str) -> Option<AuthRole> {
let users = self.users.read().unwrap_or_else(|e| e.into_inner());
let record = users.get(username)?;
let parsed = PasswordHash::new(&record.password_hash).ok()?;
Argon2::default()
.verify_password(password.as_bytes(), &parsed)
.ok()?;
Some(record.role)
}
fn list(&self) -> Vec<ManagedUser> {
let users = self.users.read().unwrap_or_else(|e| e.into_inner());
let mut result: Vec<_> = users
.values()
.map(|u| ManagedUser {
username: u.username.clone(),
role: u.role,
})
.collect();
result.sort_by(|a, b| a.username.cmp(&b.username));
result
}
fn add(&self, username: &str, password: &str, role: AuthRole) -> Result<(), String> {
let username = validate_username(username)?.to_string();
validate_password(password)?;
let record = UserRecord {
username: username.clone(),
password_hash: hash_password(password)?,
role,
};
let mut users = self.users.write().unwrap_or_else(|e| e.into_inner());
if users.contains_key(&username) {
return Err("user already exists".to_string());
}
users.insert(username.clone(), record);
if let Err(error) = persist_users(&self.path, &users) {
users.remove(&username);
return Err(error);
}
Ok(())
}
fn update(
&self,
username: &str,
password: Option<&str>,
role: Option<AuthRole>,
) -> Result<(), String> {
if let Some(value) = password {
validate_password(value)?;
}
let new_hash = password.map(hash_password).transpose()?;
let mut users = self.users.write().unwrap_or_else(|e| e.into_inner());
let old = users
.get(username)
.cloned()
.ok_or_else(|| "user not found".to_string())?;
if old.role == AuthRole::Admin
&& role == Some(AuthRole::User)
&& users.values().filter(|u| u.role == AuthRole::Admin).count() == 1
{
return Err("cannot demote the last administrator".to_string());
}
let record = users.get_mut(username).expect("checked above");
if let Some(hash) = new_hash {
record.password_hash = hash;
}
if let Some(value) = role {
record.role = value;
}
if let Err(error) = persist_users(&self.path, &users) {
users.insert(username.to_string(), old);
return Err(error);
}
Ok(())
}
fn remove(&self, username: &str) -> Result<(), String> {
let mut users = self.users.write().unwrap_or_else(|e| e.into_inner());
let old = users
.get(username)
.cloned()
.ok_or_else(|| "user not found".to_string())?;
if old.role == AuthRole::Admin
&& users.values().filter(|u| u.role == AuthRole::Admin).count() == 1
{
return Err("cannot remove the last administrator".to_string());
}
users.remove(username);
if let Err(error) = persist_users(&self.path, &users) {
users.insert(username.to_string(), old);
return Err(error);
}
Ok(())
}
fn persist(&self) -> Result<(), String> {
let users = self.users.read().unwrap_or_else(|e| e.into_inner());
persist_users(&self.path, &users)
}
}
fn persist_users(path: &Path, users: &HashMap<String, UserRecord>) -> Result<(), String> {
if let Some(parent) = path.parent().filter(|p| !p.as_os_str().is_empty()) {
fs::create_dir_all(parent).map_err(|e| format!("create {}: {e}", parent.display()))?;
}
let mut records: Vec<_> = users.values().cloned().collect();
records.sort_by(|a, b| a.username.cmp(&b.username));
let bytes =
serde_json::to_vec_pretty(&UserDatabase { users: records }).map_err(|e| e.to_string())?;
let temporary = path.with_extension("tmp");
fs::write(&temporary, bytes).map_err(|e| format!("write {}: {e}", temporary.display()))?;
fs::rename(&temporary, path).map_err(|e| format!("replace {}: {e}", path.display()))
}
fn hash_password(password: &str) -> Result<String, String> {
validate_password(password)?;
Argon2::default()
.hash_password(password.as_bytes(), &SaltString::generate(&mut OsRng))
.map(|hash| hash.to_string())
.map_err(|e| format!("password hashing failed: {e}"))
}
fn validate_username(username: &str) -> Result<&str, String> {
if username.is_empty()
|| username.len() > 64
|| !username
.chars()
.all(|c| c.is_ascii_alphanumeric() || matches!(c, '-' | '_' | '.'))
{
return Err("username must be 1-64 ASCII letters, digits, '.', '-' or '_'".to_string());
}
Ok(username)
}
fn validate_password(password: &str) -> Result<(), String> {
if password.len() < 8 {
return Err("password must contain at least 8 characters".to_string());
}
Ok(())
}
/// Simple per-IP rate limiter for login attempts.
@@ -283,39 +494,27 @@ impl Default for LoginRateLimiter {
pub struct AuthState {
pub config: AuthConfig,
pub store: SessionStore,
pub users: UserStore,
pub rate_limiter: LoginRateLimiter,
}
impl AuthState {
pub fn new(config: AuthConfig) -> Self {
Self {
pub fn new(config: AuthConfig) -> Result<Self, String> {
let users = UserStore::open(&config)?;
Ok(Self {
config,
store: SessionStore::new(),
users,
rate_limiter: LoginRateLimiter::default(),
}
})
}
}
/// Constant-time string comparison to mitigate timing attacks
fn constant_time_eq(a: &str, b: &str) -> bool {
let a_bytes = a.as_bytes();
let b_bytes = b.as_bytes();
if a_bytes.len() != b_bytes.len() {
return false;
}
let mut result = 0u8;
for (x, y) in a_bytes.iter().zip(b_bytes.iter()) {
result |= x ^ y;
}
result == 0
}
/// Login request body
#[derive(Debug, Deserialize)]
pub struct LoginRequest {
pub passphrase: String,
pub username: String,
pub password: String,
}
/// Session status response
@@ -323,6 +522,8 @@ pub struct LoginRequest {
pub struct SessionStatus {
pub authenticated: bool,
pub role: Option<String>,
pub username: Option<String>,
pub auth_disabled: bool,
}
/// Login response
@@ -330,6 +531,26 @@ pub struct SessionStatus {
pub struct LoginResponse {
pub authenticated: bool,
pub role: String,
pub username: String,
}
#[derive(Debug, Clone, Serialize)]
pub struct ManagedUser {
pub username: String,
pub role: AuthRole,
}
#[derive(Debug, Deserialize)]
pub struct CreateUserRequest {
pub username: String,
pub password: String,
pub role: AuthRole,
}
#[derive(Debug, Deserialize)]
pub struct UpdateUserRequest {
pub password: Option<String>,
pub role: Option<AuthRole>,
}
/// Extract session from cookie
@@ -345,6 +566,20 @@ pub fn get_session_role(req: &HttpRequest, auth_state: &AuthState) -> Option<Aut
Some(record.role)
}
fn require_admin(req: &HttpRequest, auth_state: &AuthState) -> Result<SessionRecord, HttpResponse> {
let session = extract_session_id(req)
.and_then(|id| auth_state.store.get(&id))
.ok_or_else(|| {
HttpResponse::Unauthorized()
.json(serde_json::json!({"error":"authentication required"}))
})?;
if session.role != AuthRole::Admin {
return Err(HttpResponse::Forbidden()
.json(serde_json::json!({"error":"administrator role required"})));
}
Ok(session)
}
// ============================================================================
// Endpoints
// ============================================================================
@@ -371,8 +606,10 @@ pub async fn login(
})));
}
// Check passphrase
let role = match auth_state.config.check_passphrase(&body.passphrase) {
let role = match auth_state
.users
.authenticate(&body.username, &body.password)
{
Some(r) => r,
None => {
return Ok(HttpResponse::Unauthorized().json(serde_json::json!({
@@ -385,7 +622,10 @@ pub async fn login(
auth_state.rate_limiter.reset(&peer_ip);
// Create session
let session_id = auth_state.store.create(role, auth_state.config.session_ttl);
let session_id =
auth_state
.store
.create(body.username.clone(), role, auth_state.config.session_ttl);
let mut cookie = Cookie::new("trx_http_sid", session_id);
cookie.set_path("/");
@@ -406,6 +646,7 @@ pub async fn login(
Ok(HttpResponse::Ok().cookie(cookie).json(LoginResponse {
authenticated: true,
role: role.as_str().to_string(),
username: body.username.clone(),
}))
}
@@ -445,7 +686,9 @@ pub async fn session_status(
if !auth_state.config.enabled {
return Ok(HttpResponse::Ok().json(SessionStatus {
authenticated: true,
role: Some("control".to_string()),
role: Some("admin".to_string()),
username: None,
auth_disabled: true,
}));
}
@@ -455,15 +698,8 @@ pub async fn session_status(
return Ok(HttpResponse::Ok().json(SessionStatus {
authenticated: true,
role: Some(session_record.role.as_str().to_string()),
}));
}
// No session - check if rx access is unrestricted
if auth_state.config.rx_passphrase.is_none() {
// No rx passphrase required - grant rx role to unauthenticated users
return Ok(HttpResponse::Ok().json(SessionStatus {
authenticated: false,
role: Some("rx".to_string()),
username: Some(session_record.username),
auth_disabled: false,
}));
}
@@ -471,9 +707,93 @@ pub async fn session_status(
Ok(HttpResponse::Ok().json(SessionStatus {
authenticated: false,
role: None,
username: None,
auth_disabled: false,
}))
}
/// GET /auth/users
#[get("/auth/users")]
pub async fn list_users(req: HttpRequest, auth_state: web::Data<AuthState>) -> impl Responder {
if let Err(response) = require_admin(&req, &auth_state) {
return response;
}
HttpResponse::Ok().json(auth_state.users.list())
}
/// POST /auth/users
#[post("/auth/users")]
pub async fn create_user(
req: HttpRequest,
body: web::Json<CreateUserRequest>,
auth_state: web::Data<AuthState>,
) -> impl Responder {
if let Err(response) = require_admin(&req, &auth_state) {
return response;
}
match auth_state
.users
.add(&body.username, &body.password, body.role)
{
Ok(()) => HttpResponse::Created().json(ManagedUser {
username: body.username.clone(),
role: body.role,
}),
Err(error) => HttpResponse::BadRequest().json(serde_json::json!({"error": error})),
}
}
/// PATCH /auth/users/{username}
#[patch("/auth/users/{username}")]
pub async fn update_user(
req: HttpRequest,
username: web::Path<String>,
body: web::Json<UpdateUserRequest>,
auth_state: web::Data<AuthState>,
) -> impl Responder {
if let Err(response) = require_admin(&req, &auth_state) {
return response;
}
if body.password.is_none() && body.role.is_none() {
return HttpResponse::BadRequest()
.json(serde_json::json!({"error":"password or role is required"}));
}
match auth_state
.users
.update(&username, body.password.as_deref(), body.role)
{
Ok(()) => {
auth_state.store.remove_user(&username);
HttpResponse::Ok().json(serde_json::json!({"updated": true}))
}
Err(error) => HttpResponse::BadRequest().json(serde_json::json!({"error": error})),
}
}
/// DELETE /auth/users/{username}
#[delete("/auth/users/{username}")]
pub async fn delete_user(
req: HttpRequest,
username: web::Path<String>,
auth_state: web::Data<AuthState>,
) -> impl Responder {
let admin = match require_admin(&req, &auth_state) {
Ok(value) => value,
Err(response) => return response,
};
if admin.username == *username {
return HttpResponse::BadRequest()
.json(serde_json::json!({"error":"administrators cannot remove their own account"}));
}
match auth_state.users.remove(&username) {
Ok(()) => {
auth_state.store.remove_user(&username);
HttpResponse::Ok().json(serde_json::json!({"deleted": true}))
}
Err(error) => HttpResponse::BadRequest().json(serde_json::json!({"error": error})),
}
}
// ============================================================================
// Middleware
// ============================================================================
@@ -483,9 +803,9 @@ pub async fn session_status(
enum RouteAccess {
/// Publicly accessible (no auth required)
Public,
/// Read-only (rx or control role required)
/// Read-only (user or admin role required)
Read,
/// Control only (control role required)
/// Control only (admin role required)
Control,
}
@@ -499,7 +819,9 @@ impl RouteAccess {
|| path == "/digital-modes"
|| path == "/settings"
|| path == "/about"
|| path.starts_with("/auth/")
|| path == "/auth/login"
|| path == "/auth/logout"
|| path == "/auth/session"
{
return Self::Public;
}
@@ -561,7 +883,7 @@ impl RouteAccess {
match self {
Self::Public => true,
Self::Read => role.is_some(),
Self::Control => matches!(role, Some(AuthRole::Control)),
Self::Control => matches!(role, Some(AuthRole::Admin)),
}
}
}
@@ -631,19 +953,6 @@ where
// Auth enabled - check role
let role = get_session_role(req.request(), &auth_state);
// If rx_passphrase is not set, allow unauthenticated read access
let allow_unrestricted_read = auth_state.config.rx_passphrase.is_none();
let is_read_route = access == RouteAccess::Read;
if is_read_route && allow_unrestricted_read {
// No rx authentication required - allow read access without role
let fut = self.service.call(req);
return Box::pin(async move {
let res = fut.await?;
Ok(res)
});
}
if !access.allows(role) {
// Access denied
return Box::pin(async move {
@@ -652,12 +961,6 @@ where
Err(actix_web::error::ErrorForbidden(
"Insufficient permissions".to_string(),
))
} else if allow_unrestricted_read {
// No session but rx access is unrestricted - 403 Forbidden
// (user has implicit rx role from unrestricted access)
Err(actix_web::error::ErrorForbidden(
"Insufficient permissions".to_string(),
))
} else {
// No session and no unrestricted access - 401 Unauthorized
Err(actix_web::error::ErrorUnauthorized(
@@ -676,18 +979,10 @@ where
}
}
/// Check if a path is a TX/PTT endpoint (used for TX access control).
pub fn is_tx_endpoint(path: &str) -> bool {
path.contains("ptt")
|| path.contains("set_ptt")
|| path.contains("toggle_ptt")
|| path.contains("set_tx")
|| path.contains("toggle_tx")
}
#[cfg(test)]
mod tests {
use super::*;
use actix_web::{test as aw_test, App};
#[test]
fn test_route_access_public_paths() {
@@ -701,6 +996,7 @@ mod tests {
assert_eq!(RouteAccess::from_path("/about"), RouteAccess::Public);
assert_eq!(RouteAccess::from_path("/auth/login"), RouteAccess::Public);
assert_eq!(RouteAccess::from_path("/auth/logout"), RouteAccess::Public);
assert_eq!(RouteAccess::from_path("/auth/users"), RouteAccess::Control);
assert_eq!(RouteAccess::from_path("/style.css"), RouteAccess::Public);
assert_eq!(RouteAccess::from_path("/app.js"), RouteAccess::Public);
// Static reference data, served to every role: ".json" is not in the
@@ -735,28 +1031,29 @@ mod tests {
#[test]
fn test_route_access_allows() {
assert!(RouteAccess::Public.allows(None));
assert!(RouteAccess::Public.allows(Some(AuthRole::Rx)));
assert!(RouteAccess::Public.allows(Some(AuthRole::Control)));
assert!(RouteAccess::Public.allows(Some(AuthRole::User)));
assert!(RouteAccess::Public.allows(Some(AuthRole::Admin)));
assert!(!RouteAccess::Read.allows(None));
assert!(RouteAccess::Read.allows(Some(AuthRole::Rx)));
assert!(RouteAccess::Read.allows(Some(AuthRole::Control)));
assert!(RouteAccess::Read.allows(Some(AuthRole::User)));
assert!(RouteAccess::Read.allows(Some(AuthRole::Admin)));
assert!(!RouteAccess::Control.allows(None));
assert!(!RouteAccess::Control.allows(Some(AuthRole::Rx)));
assert!(RouteAccess::Control.allows(Some(AuthRole::Control)));
assert!(!RouteAccess::Control.allows(Some(AuthRole::User)));
assert!(RouteAccess::Control.allows(Some(AuthRole::Admin)));
}
#[test]
fn test_session_store_create_and_get() {
let store = SessionStore::new();
let ttl = Duration::from_secs(3600);
let session_id = store.create(AuthRole::Rx, ttl);
let session_id = store.create("alice".to_string(), AuthRole::User, ttl);
let record = store.get(&session_id);
assert!(record.is_some());
let record = record.unwrap();
assert_eq!(record.role, AuthRole::Rx);
assert_eq!(record.username, "alice");
assert_eq!(record.role, AuthRole::User);
assert!(!record.is_expired());
}
@@ -764,81 +1061,151 @@ mod tests {
fn test_session_store_remove() {
let store = SessionStore::new();
let ttl = Duration::from_secs(3600);
let session_id = store.create(AuthRole::Rx, ttl);
let session_id = store.create("alice".to_string(), AuthRole::User, ttl);
store.remove(&session_id);
assert!(store.get(&session_id).is_none());
}
#[test]
fn test_constant_time_eq() {
assert!(constant_time_eq("test", "test"));
assert!(!constant_time_eq("test", "fail"));
assert!(!constant_time_eq("test", "test2"));
assert!(!constant_time_eq("", "test"));
}
#[test]
fn test_auth_config_check_passphrase_control() {
let config = AuthConfig {
enabled: true,
rx_passphrase: None,
control_passphrase: Some("ctrl-pass".to_string()),
tx_access_control_enabled: true,
session_ttl: Duration::from_secs(3600),
cookie_secure: false,
cookie_same_site: SameSite::Lax,
};
assert_eq!(
config.check_passphrase("ctrl-pass"),
Some(AuthRole::Control)
fn user_store_bootstraps_and_manages_users() {
let directory = tempfile::tempdir().unwrap();
let config = AuthConfig::new(
true,
directory.path().join("users.json"),
Some("admin".to_string()),
Some("password123".to_string()),
Duration::from_secs(3600),
false,
SameSite::Lax,
);
assert_eq!(config.check_passphrase("wrong"), None);
}
#[test]
fn test_auth_config_check_passphrase_rx() {
let config = AuthConfig {
enabled: true,
rx_passphrase: Some("rx-pass".to_string()),
control_passphrase: None,
tx_access_control_enabled: true,
session_ttl: Duration::from_secs(3600),
cookie_secure: false,
cookie_same_site: SameSite::Lax,
};
assert_eq!(config.check_passphrase("rx-pass"), Some(AuthRole::Rx));
assert_eq!(config.check_passphrase("wrong"), None);
}
#[test]
fn test_auth_config_check_passphrase_both() {
let config = AuthConfig {
enabled: true,
rx_passphrase: Some("rx-pass".to_string()),
control_passphrase: Some("ctrl-pass".to_string()),
tx_access_control_enabled: true,
session_ttl: Duration::from_secs(3600),
cookie_secure: false,
cookie_same_site: SameSite::Lax,
};
// Control is checked first
let users = UserStore::open(&config).unwrap();
assert_eq!(
config.check_passphrase("ctrl-pass"),
Some(AuthRole::Control)
users.authenticate("admin", "password123"),
Some(AuthRole::Admin)
);
assert_eq!(config.check_passphrase("rx-pass"), Some(AuthRole::Rx));
assert_eq!(config.check_passphrase("wrong"), None);
assert_eq!(users.authenticate("admin", "wrong"), None);
users.add("alice", "password456", AuthRole::User).unwrap();
assert_eq!(
users.authenticate("alice", "password456"),
Some(AuthRole::User)
);
users
.update("alice", Some("password789"), Some(AuthRole::Admin))
.unwrap();
assert_eq!(
users.authenticate("alice", "password789"),
Some(AuthRole::Admin)
);
users.remove("admin").unwrap();
assert_eq!(users.list().len(), 1);
drop(users);
let mut reopen_config = config.clone();
reopen_config.bootstrap_admin_username = None;
reopen_config.bootstrap_admin_password = None;
let reopened = UserStore::open(&reopen_config).unwrap();
assert_eq!(
reopened.authenticate("alice", "password789"),
Some(AuthRole::Admin)
);
let database = fs::read_to_string(&reopen_config.users_file).unwrap();
assert!(database.contains("$argon2"));
assert!(!database.contains("password789"));
}
#[test]
fn test_is_tx_endpoint() {
assert!(is_tx_endpoint("/set_ptt"));
assert!(is_tx_endpoint("/toggle_ptt"));
assert!(is_tx_endpoint("/set_tx"));
assert!(!is_tx_endpoint("/status"));
fn user_store_protects_last_admin() {
let directory = tempfile::tempdir().unwrap();
let config = AuthConfig::new(
true,
directory.path().join("users.json"),
Some("admin".to_string()),
Some("password123".to_string()),
Duration::from_secs(3600),
false,
SameSite::Lax,
);
let users = UserStore::open(&config).unwrap();
assert!(users.remove("admin").is_err());
assert!(users.update("admin", None, Some(AuthRole::User)).is_err());
}
#[actix_web::test]
async fn admin_endpoints_manage_multiple_users_and_reject_regular_users() {
let directory = tempfile::tempdir().unwrap();
let config = AuthConfig::new(
true,
directory.path().join("users.json"),
Some("admin".to_string()),
Some("password123".to_string()),
Duration::from_secs(3600),
false,
SameSite::Lax,
);
let state = web::Data::new(AuthState::new(config).unwrap());
let app = aw_test::init_service(
App::new()
.app_data(state)
.service(login)
.service(list_users)
.service(create_user)
.service(update_user)
.service(delete_user),
)
.await;
let request = aw_test::TestRequest::post()
.uri("/auth/login")
.set_json(serde_json::json!({"username":"admin","password":"password123"}))
.to_request();
let response = aw_test::call_service(&app, request).await;
assert_eq!(response.status(), actix_web::http::StatusCode::OK);
let admin_cookie = response.response().cookies().next().unwrap().to_string();
let request = aw_test::TestRequest::post()
.uri("/auth/users")
.insert_header((actix_web::http::header::COOKIE, admin_cookie.clone()))
.set_json(
serde_json::json!({"username":"alice","password":"password456","role":"user"}),
)
.to_request();
assert_eq!(
aw_test::call_service(&app, request).await.status(),
actix_web::http::StatusCode::CREATED
);
let request = aw_test::TestRequest::post()
.uri("/auth/login")
.set_json(serde_json::json!({"username":"alice","password":"password456"}))
.to_request();
let response = aw_test::call_service(&app, request).await;
let user_cookie = response.response().cookies().next().unwrap().to_string();
let request = aw_test::TestRequest::get()
.uri("/auth/users")
.insert_header((actix_web::http::header::COOKIE, user_cookie))
.to_request();
assert_eq!(
aw_test::call_service(&app, request).await.status(),
actix_web::http::StatusCode::FORBIDDEN
);
let request = aw_test::TestRequest::patch()
.uri("/auth/users/alice")
.insert_header((actix_web::http::header::COOKIE, admin_cookie.clone()))
.set_json(serde_json::json!({"password":"new-password","role":"admin"}))
.to_request();
assert_eq!(
aw_test::call_service(&app, request).await.status(),
actix_web::http::StatusCode::OK
);
let request = aw_test::TestRequest::delete()
.uri("/auth/users/alice")
.insert_header((actix_web::http::header::COOKIE, admin_cookie))
.to_request();
assert_eq!(
aw_test::call_service(&app, request).await.status(),
actix_web::http::StatusCode::OK
);
}
}
@@ -106,6 +106,39 @@ async fn serve(
activity_log_map.clone(),
);
// The log is opened once and shared: it is one station's log, not one per
// rig or per session.
let logbook_path = context
.http_ui
.logbook_path
.clone()
.map(std::path::PathBuf::from)
.unwrap_or_else(trx_logbook::default_log_path);
let logbook = match trx_logbook::Logbook::open(&logbook_path) {
Ok(logbook) => {
tracing::info!(
"Logbook: {} contact(s) in {}",
logbook.count(),
logbook_path.display()
);
Arc::new(logbook)
}
Err(err) => {
// A log that cannot be opened must not stop the radio working, but
// it must be said loudly: contacts made now will not be kept.
tracing::error!(
"Logbook at {} could not be opened ({err}); logging is unavailable",
logbook_path.display()
);
Arc::new(
trx_logbook::Logbook::open(std::path::Path::new(
&std::env::temp_dir().join("trx-rs-logbook.jsonl"),
))
.unwrap_or_else(|e| panic!("logbook fallback in the temp directory failed: {e}")),
)
}
};
let background_decode_path = BackgroundDecodeStore::default_path();
let background_decode_store = Arc::new(BackgroundDecodeStore::open(&background_decode_path));
let vchan_mgr = Arc::new(ClientChannelManager::new(
@@ -164,6 +197,7 @@ async fn serve(
session_rig_mgr,
background_decode_mgr,
recorder_mgr,
logbook,
)?;
let handle = server.handle();
tokio::spawn(async move {
@@ -192,6 +226,7 @@ fn build_server(
session_rig_mgr: Arc<api::SessionRigManager>,
background_decode_mgr: Arc<BackgroundDecodeManager>,
recorder_mgr: Arc<RecorderManager>,
logbook: Arc<trx_logbook::Logbook>,
) -> Result<Server, actix_web::Error> {
let state_data = web::Data::new(state_rx);
let rig_tx = web::Data::new(rig_tx);
@@ -209,6 +244,7 @@ fn build_server(
let session_rig_mgr = web::Data::new(session_rig_mgr);
let background_decode_mgr = web::Data::new(background_decode_mgr);
let recorder_mgr = web::Data::new(recorder_mgr);
let logbook = web::Data::new(logbook);
// Extract auth config values before moving context
let same_site = match context.http_auth.cookie_same_site.as_str() {
@@ -218,9 +254,9 @@ fn build_server(
};
let auth_config = AuthConfig::new(
context.http_auth.enabled,
context.http_auth.rx_passphrase.clone(),
context.http_auth.control_passphrase.clone(),
context.http_auth.tx_access_control_enabled,
context.http_auth.users_file.clone().into(),
context.http_auth.bootstrap_admin_username.clone(),
context.http_auth.bootstrap_admin_password.clone(),
Duration::from_secs(context.http_auth.session_ttl_secs),
context.http_auth.cookie_secure,
same_site,
@@ -237,7 +273,9 @@ fn build_server(
}
let context_data = web::Data::new(context);
let auth_state = web::Data::new(AuthState::new(auth_config.clone()));
let auth_state = web::Data::new(
AuthState::new(auth_config.clone()).map_err(actix_web::error::ErrorInternalServerError)?,
);
// Spawn session cleanup task if auth is enabled
if auth_config.enabled {
@@ -267,6 +305,7 @@ fn build_server(
.app_data(session_rig_mgr.clone())
.app_data(background_decode_mgr.clone())
.app_data(recorder_mgr.clone())
.app_data(logbook.clone())
.wrap(Compress::default())
.wrap(
DefaultHeaders::new()
+19
View File
@@ -0,0 +1,19 @@
# SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
#
# SPDX-License-Identifier: GPL-2.0-or-later
[package]
name = "trx-logbook"
version.workspace = true
edition = "2021"
[dependencies]
chrono = { version = "0.4", default-features = false, features = ["clock", "serde"] }
dirs = "6"
serde = { workspace = true, features = ["derive"] }
serde_json = { workspace = true }
tracing = { workspace = true }
uuid = { workspace = true }
[dev-dependencies]
tempfile = "3"
+466
View File
@@ -0,0 +1,466 @@
// SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
//
// SPDX-License-Identifier: GPL-2.0-or-later
//! ADIF, the format every other logger reads.
//!
//! ADI is a tagged text format: `<FIELD:length>value`, where the length counts
//! the bytes of the value that follows, records end at `<EOR>`, an optional
//! header ends at `<EOH>`, and anything outside a tag is ignored — which is how
//! files carry human notes between records.
//!
//! The reader is deliberately forgiving. Files in the wild have lowercase tags,
//! CRLF line endings, no header at all, type indicators on some fields and not
//! others, and fields this application has never heard of. None of that is a
//! reason to refuse someone's log. The writer, by contrast, is strict: what
//! leaves here has to be read by software that is not.
use std::collections::BTreeMap;
use chrono::Utc;
use crate::qso::{
adif_date, adif_time, freq_mhz_string, hz_from_mhz_string, normalize_call, parse_adif_datetime,
Qso,
};
/// Fields the [`Qso`] models itself. Everything else an import carries is kept
/// in `extra` under its own name, so a round trip does not strip it.
const MODELLED: &[&str] = &[
"CALL",
"QSO_DATE",
"TIME_ON",
"QSO_DATE_OFF",
"TIME_OFF",
"FREQ",
"BAND",
"MODE",
"SUBMODE",
"RST_SENT",
"RST_RCVD",
"GRIDSQUARE",
"NAME",
"QTH",
"COMMENT",
"TX_PWR",
"STATION_CALLSIGN",
"OPERATOR",
"MY_GRIDSQUARE",
"MY_RIG",
"CONTEST_ID",
"STX",
"STX_STRING",
"SRX",
"SRX_STRING",
"CQZ",
"ITUZ",
"QSL_SENT",
"QSL_RCVD",
"LOTW_QSL_SENT",
"LOTW_QSL_RCVD",
"EQSL_QSL_SENT",
"EQSL_QSL_RCVD",
];
/// ADIF's QSL states are single letters; anything else in that field is a
/// misunderstanding on the writer's part and is not carried into ours.
fn qsl_state(value: Option<&str>) -> Option<String> {
let state = value?.trim().to_uppercase();
matches!(state.as_str(), "Y" | "N" | "R" | "I" | "Q" | "V").then_some(state)
}
/// What a file gave up, and what it could not.
#[derive(Debug, Default, Clone)]
pub struct ParseReport {
/// Records that became a QSO.
pub qsos: Vec<Qso>,
/// Records that did not, and why — one line each, for showing the operator.
pub rejected: Vec<String>,
}
/// One `<NAME:LEN[:TYPE]>value` field.
struct Field {
name: String,
value: String,
}
/// Reads the next tag starting at `from`, returning it and where it ended.
///
/// Returns `None` at the end of input or on a tag that never closes, which is
/// how a truncated file stops rather than looping.
fn next_field(bytes: &[u8], from: usize) -> Option<(Field, usize)> {
let open = bytes[from..].iter().position(|b| *b == b'<')? + from;
let close = bytes[open..].iter().position(|b| *b == b'>')? + open;
let spec = String::from_utf8_lossy(&bytes[open + 1..close]).to_string();
let mut parts = spec.split(':');
let name = parts.next().unwrap_or_default().trim().to_uppercase();
// <EOR> and <EOH> carry no length and no value.
let Some(length_text) = parts.next() else {
return Some((
Field {
name,
value: String::new(),
},
close + 1,
));
};
let length: usize = length_text.trim().parse().unwrap_or(0);
let value_start = close + 1;
// A length that runs off the end is a truncated file, not a reason to lose
// everything before it: take what is there.
let value_end = value_start.saturating_add(length).min(bytes.len());
let value = String::from_utf8_lossy(&bytes[value_start..value_end]).to_string();
Some((Field { name, value }, value_end))
}
/// Read an ADI file.
///
/// Never fails as a whole: a record that cannot be made into a QSO is reported
/// on [`ParseReport::rejected`] and the rest of the file is still read.
pub fn parse_adi(input: &[u8]) -> ParseReport {
let mut report = ParseReport::default();
let mut position = 0usize;
let mut fields: Vec<Field> = Vec::new();
let mut in_header = looks_like_header(input);
let mut record_number = 0usize;
while let Some((field, next)) = next_field(input, position) {
position = next;
match field.name.as_str() {
"EOH" => {
in_header = false;
fields.clear();
}
"EOR" => {
record_number += 1;
if in_header {
// A file with no <EOH> but an <EOR>: the header guess was
// wrong, so treat what we have as a record.
in_header = false;
}
match qso_from_fields(&fields) {
Ok(qso) => report.qsos.push(qso),
Err(reason) => report
.rejected
.push(format!("record {record_number}: {reason}")),
}
fields.clear();
}
_ => fields.push(field),
}
}
// A last record without its <EOR> is still a record someone wrote.
if !fields.is_empty() && !in_header {
record_number += 1;
match qso_from_fields(&fields) {
Ok(qso) => report.qsos.push(qso),
Err(reason) => report
.rejected
.push(format!("record {record_number}: {reason}")),
}
}
report
}
/// Whether the file opens with a header, i.e. anything before the first tag.
///
/// ADIF says a file whose first character is not `<` has a header. Plenty of
/// exporters write no header at all, so the first `<EOR>` un-guesses this.
fn looks_like_header(input: &[u8]) -> bool {
match input.iter().position(|b| !b.is_ascii_whitespace()) {
Some(first) => input[first] != b'<',
None => false,
}
}
fn find<'a>(fields: &'a [Field], name: &str) -> Option<&'a str> {
fields
.iter()
.find(|f| f.name == name)
.map(|f| f.value.trim())
.filter(|value| !value.is_empty())
}
fn qso_from_fields(fields: &[Field]) -> Result<Qso, String> {
let call = find(fields, "CALL").ok_or("no CALL")?;
let date = find(fields, "QSO_DATE").ok_or("no QSO_DATE")?;
let started_at = parse_adif_datetime(date, find(fields, "TIME_ON"))
.ok_or("QSO_DATE or TIME_ON unreadable")?;
// FREQ is authoritative; BAND is the fallback for logs that record only the
// band, and its midpoint is the honest answer for "where in the band".
let freq_hz = match find(fields, "FREQ").and_then(hz_from_mhz_string) {
Some(hz) => hz,
None => find(fields, "BAND")
.and_then(band_midpoint_hz)
.ok_or("neither FREQ nor a known BAND")?,
};
let mode = find(fields, "MODE").unwrap_or("SSB").to_uppercase();
let ended_at = find(fields, "TIME_OFF").and_then(|time| {
let off_date = find(fields, "QSO_DATE_OFF").unwrap_or(date);
parse_adif_datetime(off_date, Some(time))
});
let mut extra = BTreeMap::new();
for field in fields {
if MODELLED.contains(&field.name.as_str()) {
continue;
}
if field.value.trim().is_empty() {
continue;
}
extra.insert(field.name.clone(), field.value.trim().to_string());
}
Ok(Qso {
id: crate::new_id(),
started_at,
ended_at,
call: normalize_call(call),
freq_hz,
mode,
submode: find(fields, "SUBMODE").map(|s| s.to_uppercase()),
rst_sent: find(fields, "RST_SENT").map(str::to_string),
rst_rcvd: find(fields, "RST_RCVD").map(str::to_string),
gridsquare: find(fields, "GRIDSQUARE").map(|g| g.to_uppercase()),
name: find(fields, "NAME").map(str::to_string),
qth: find(fields, "QTH").map(str::to_string),
comment: find(fields, "COMMENT").map(str::to_string),
tx_pwr_w: find(fields, "TX_PWR").and_then(|p| p.parse().ok()),
station_callsign: find(fields, "STATION_CALLSIGN").map(normalize_call),
operator: find(fields, "OPERATOR").map(normalize_call),
my_gridsquare: find(fields, "MY_GRIDSQUARE").map(|g| g.to_uppercase()),
my_rig: find(fields, "MY_RIG").map(str::to_string),
rig_id: None,
contest_id: find(fields, "CONTEST_ID").map(|c| c.to_uppercase()),
stx: find(fields, "STX").and_then(|value| value.parse().ok()),
stx_string: find(fields, "STX_STRING").map(str::to_string),
srx: find(fields, "SRX").and_then(|value| value.parse().ok()),
srx_string: find(fields, "SRX_STRING").map(str::to_string),
cqz: find(fields, "CQZ").and_then(|value| value.parse().ok()),
ituz: find(fields, "ITUZ").and_then(|value| value.parse().ok()),
qsl_sent: qsl_state(find(fields, "QSL_SENT")),
qsl_rcvd: qsl_state(find(fields, "QSL_RCVD")),
lotw_qsl_sent: qsl_state(find(fields, "LOTW_QSL_SENT")),
lotw_qsl_rcvd: qsl_state(find(fields, "LOTW_QSL_RCVD")),
eqsl_qsl_sent: qsl_state(find(fields, "EQSL_QSL_SENT")),
eqsl_qsl_rcvd: qsl_state(find(fields, "EQSL_QSL_RCVD")),
extra,
})
}
/// The middle of a named band, for logs that recorded a band and no frequency.
fn band_midpoint_hz(band: &str) -> Option<u64> {
crate::qso::band_midpoint_for_name(band)
}
fn write_field(out: &mut String, name: &str, value: &str) {
if value.is_empty() {
return;
}
out.push_str(&format!("<{}:{}>{}", name, value.len(), value));
}
/// Write QSOs as an ADI file, header and all.
pub fn write_adi(qsos: &[Qso], program_version: &str) -> String {
let mut out = String::with_capacity(qsos.len() * 256 + 256);
let now = Utc::now();
out.push_str("ADIF export from trx-rs\n");
write_field(&mut out, "ADIF_VER", "3.1.4");
write_field(&mut out, "PROGRAMID", "trx-rs");
write_field(&mut out, "PROGRAMVERSION", program_version);
write_field(
&mut out,
"CREATED_TIMESTAMP",
&format!("{} {}", adif_date(&now), adif_time(&now)),
);
out.push_str("<EOH>\n");
for qso in qsos {
write_field(&mut out, "CALL", &qso.call);
write_field(&mut out, "QSO_DATE", &adif_date(&qso.started_at));
write_field(&mut out, "TIME_ON", &adif_time(&qso.started_at));
if let Some(ended) = qso.ended_at {
write_field(&mut out, "QSO_DATE_OFF", &adif_date(&ended));
write_field(&mut out, "TIME_OFF", &adif_time(&ended));
}
write_field(&mut out, "FREQ", &freq_mhz_string(qso.freq_hz));
if let Some(band) = qso.band() {
write_field(&mut out, "BAND", band);
}
write_field(&mut out, "MODE", &qso.mode);
if let Some(submode) = &qso.submode {
write_field(&mut out, "SUBMODE", submode);
}
for (name, value) in [
("RST_SENT", &qso.rst_sent),
("RST_RCVD", &qso.rst_rcvd),
("GRIDSQUARE", &qso.gridsquare),
("NAME", &qso.name),
("QTH", &qso.qth),
("COMMENT", &qso.comment),
("STATION_CALLSIGN", &qso.station_callsign),
("OPERATOR", &qso.operator),
("MY_GRIDSQUARE", &qso.my_gridsquare),
("MY_RIG", &qso.my_rig),
("CONTEST_ID", &qso.contest_id),
("STX_STRING", &qso.stx_string),
("SRX_STRING", &qso.srx_string),
("QSL_SENT", &qso.qsl_sent),
("QSL_RCVD", &qso.qsl_rcvd),
("LOTW_QSL_SENT", &qso.lotw_qsl_sent),
("LOTW_QSL_RCVD", &qso.lotw_qsl_rcvd),
("EQSL_QSL_SENT", &qso.eqsl_qsl_sent),
("EQSL_QSL_RCVD", &qso.eqsl_qsl_rcvd),
] {
if let Some(value) = value {
write_field(&mut out, name, value);
}
}
for (name, value) in [
("STX", qso.stx),
("SRX", qso.srx),
("CQZ", qso.cqz.map(u32::from)),
("ITUZ", qso.ituz.map(u32::from)),
] {
if let Some(value) = value {
write_field(&mut out, name, &value.to_string());
}
}
if let Some(power) = qso.tx_pwr_w {
write_field(&mut out, "TX_PWR", &format!("{power}"));
}
// Whatever another logger wrote and this one does not model leaves as
// it arrived.
for (name, value) in &qso.extra {
write_field(&mut out, name, value);
}
out.push_str("<EOR>\n");
}
out
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn a_written_log_reads_back_the_same() {
let mut qso = Qso::new(
"id-1".into(),
parse_adif_datetime("20260807", Some("121530")).expect("time"),
"sp2sjg",
14_074_000,
"FT8",
);
qso.rst_sent = Some("-07".into());
qso.rst_rcvd = Some("-12".into());
qso.gridsquare = Some("JO94".into());
qso.station_callsign = Some("SP0TRX".into());
qso.operator = Some("SP0TRX".into());
qso.my_gridsquare = Some("JO91".into());
qso.my_rig = Some("Shack SDR".into());
let text = write_adi(&[qso.clone()], "0.1.0");
let report = parse_adi(text.as_bytes());
assert!(report.rejected.is_empty(), "{:?}", report.rejected);
assert_eq!(report.qsos.len(), 1);
let back = &report.qsos[0];
assert_eq!(back.call, "SP2SJG");
assert_eq!(back.freq_hz, qso.freq_hz);
assert_eq!(back.mode, "FT8");
assert_eq!(back.started_at, qso.started_at);
assert_eq!(back.rst_sent, qso.rst_sent);
assert_eq!(back.gridsquare, qso.gridsquare);
assert_eq!(back.my_rig, qso.my_rig);
}
/// Files from other loggers are irregular in ways that are not errors.
#[test]
fn a_file_from_another_logger_is_read_as_it_comes() {
let text = concat!(
"Generated by SomeLogger 4.2\r\n",
"<adif_ver:5>3.1.0<programid:10>SomeLogger<eoh>\r\n",
// lowercase tags, CRLF, a type indicator, no seconds on the time
"<call:6>W1AW/4<qso_date:8>20260101<time_on:4>1200<band:3>20m",
"<mode:3>SSB<rst_sent:2>59<rst_rcvd:2>59<my_antenna:6>Dipole<eor>\r\n",
// a record with the fields in another order and a full frequency
"<qso_date:8>20260102<time_on:6>235959<call:5>DL1AB<freq:6>7.0301",
"<mode:2>CW<eor>\r\n",
);
let report = parse_adi(text.as_bytes());
assert!(report.rejected.is_empty(), "{:?}", report.rejected);
assert_eq!(report.qsos.len(), 2);
let first = &report.qsos[0];
assert_eq!(first.call, "W1AW/4");
assert_eq!(first.mode, "SSB");
// No FREQ, so the band gives the frequency, and the band comes back.
assert_eq!(first.band(), Some("20m"));
// A field we do not model is kept, and comes back out on export.
assert_eq!(
first.extra.get("MY_ANTENNA").map(String::as_str),
Some("Dipole")
);
let exported = write_adi(&report.qsos, "0.1.0");
assert!(exported.contains("<MY_ANTENNA:6>Dipole"), "{exported}");
let second = &report.qsos[1];
assert_eq!(second.call, "DL1AB");
assert_eq!(second.freq_hz, 7_030_100);
assert_eq!(adif_time(&second.started_at), "235959");
}
#[test]
fn a_record_that_cannot_be_a_qso_is_reported_and_the_rest_still_read() {
let text = concat!(
"<call:5>NOCAL<eor>", // no date
"<qso_date:8>20260101<time_on:4>1200<mode:3>SSB<eor>", // no call
"<call:5>SP1AB<qso_date:8>20260101<time_on:4>1200<freq:6>14.074<mode:3>FT8<eor>",
);
let report = parse_adi(text.as_bytes());
assert_eq!(report.qsos.len(), 1);
assert_eq!(report.qsos[0].call, "SP1AB");
assert_eq!(report.rejected.len(), 2);
assert!(
report.rejected[0].contains("QSO_DATE"),
"{:?}",
report.rejected
);
assert!(report.rejected[1].contains("CALL"), "{:?}", report.rejected);
}
/// The declared length is the length, even when the value looks longer:
/// ADIF values may contain `<`, so the count is the only thing that can be
/// trusted to end them.
#[test]
fn the_declared_length_wins_over_what_the_value_looks_like() {
let text = "<call:5>SP1AB<qso_date:8>20260101<time_on:4>1200<freq:6>14.074<mode:3>FT8\
<comment:11>see <notes><eor>";
let report = parse_adi(text.as_bytes());
assert_eq!(report.qsos.len(), 1);
assert_eq!(report.qsos[0].comment.as_deref(), Some("see <notes>"));
}
#[test]
fn a_truncated_file_gives_up_what_it_has() {
// The length says 20 bytes of callsign; the file ends after five.
let text = "<call:20>SP1AB";
let report = parse_adi(text.as_bytes());
// No date, so it is rejected -- but the parser returned rather than
// running off the end or looping.
assert_eq!(report.qsos.len(), 0);
assert_eq!(report.rejected.len(), 1);
}
#[test]
fn a_file_with_no_header_is_still_a_file() {
let text = "<call:5>SP1AB<qso_date:8>20260101<time_on:4>1200<freq:6>14.074<mode:3>FT8<eor>";
let report = parse_adi(text.as_bytes());
assert_eq!(report.qsos.len(), 1);
}
}
+304
View File
@@ -0,0 +1,304 @@
// SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
//
// SPDX-License-Identifier: GPL-2.0-or-later
//! Cabrillo 3.0, the format contest logs are submitted in.
//!
//! ADIF cannot do this job: sponsors take Cabrillo and reject everything else.
//! It is export-only and narrower on purpose — a header naming the entrant and
//! the category, then one fixed-shape `QSO:` line per contact carrying the
//! frequency, the mode, the time, and both stations' calls, reports and
//! exchanges. Everything a log holds beyond that is left behind, which is why
//! this complements ADIF rather than replacing it.
use serde::Deserialize;
use crate::qso::Qso;
/// The header of a contest entry.
///
/// Sponsors want the entrant's own answers here — how many operators, how much
/// power, which bands — and no log can work them out for itself, so they come
/// from the operator with sane defaults behind them.
#[derive(Debug, Clone, Deserialize)]
pub struct CabrilloHeader {
/// The contest's Cabrillo name, e.g. `CQ-WW-SSB`.
#[serde(default)]
pub contest: Option<String>,
/// The callsign the entry is submitted under.
#[serde(default)]
pub callsign: Option<String>,
#[serde(default)]
pub category_operator: Option<String>,
#[serde(default)]
pub category_power: Option<String>,
#[serde(default)]
pub category_band: Option<String>,
#[serde(default)]
pub category_mode: Option<String>,
#[serde(default)]
pub claimed_score: Option<u64>,
#[serde(default)]
pub operators: Option<String>,
#[serde(default)]
pub name: Option<String>,
#[serde(default)]
pub email: Option<String>,
#[serde(default)]
pub soapbox: Option<String>,
}
impl Default for CabrilloHeader {
fn default() -> Self {
Self {
contest: None,
callsign: None,
category_operator: Some("SINGLE-OP".to_string()),
category_power: Some("LOW".to_string()),
category_band: Some("ALL".to_string()),
category_mode: Some("MIXED".to_string()),
claimed_score: None,
operators: None,
name: None,
email: None,
soapbox: None,
}
}
}
/// The mode letters Cabrillo uses, which are not ADIF's names.
fn cabrillo_mode(qso: &Qso) -> &'static str {
match qso.mode.trim().to_uppercase().as_str() {
"CW" | "CWR" => "CW",
"SSB" | "USB" | "LSB" | "AM" | "FM" | "SAM" | "WFM" | "PHONE" => {
// FM has a letter of its own; the rest of phone is PH.
if matches!(qso.mode.trim().to_uppercase().as_str(), "FM" | "WFM") {
"FM"
} else {
"PH"
}
}
"RTTY" => "RY",
_ => "DG",
}
}
/// Band designators above 30 MHz, where Cabrillo names the band rather than
/// the frequency.
const VHF_DESIGNATORS: &[(u64, u64, &str)] = &[
(50_000_000, 54_000_000, "50"),
(70_000_000, 71_000_000, "70"),
(144_000_000, 148_000_000, "144"),
(222_000_000, 225_000_000, "222"),
(420_000_000, 450_000_000, "432"),
(902_000_000, 928_000_000, "902"),
(1_240_000_000, 1_300_000_000, "1.2G"),
(2_300_000_000, 2_450_000_000, "2.3G"),
(3_300_000_000, 3_500_000_000, "3.4G"),
(5_650_000_000, 5_925_000_000, "5.7G"),
(10_000_000_000, 10_500_000_000, "10G"),
];
/// The frequency field: kilohertz below 30 MHz, a band designator above it.
fn cabrillo_frequency(hz: u64) -> String {
if hz < 30_000_000 {
return (hz / 1000).to_string();
}
VHF_DESIGNATORS
.iter()
.find(|(low, high, _)| hz >= *low && hz <= *high)
.map_or_else(
|| (hz / 1000).to_string(),
|(_, _, name)| (*name).to_string(),
)
}
fn header_line(out: &mut String, key: &str, value: Option<&str>) {
if let Some(value) = value {
let value = value.trim();
if !value.is_empty() {
out.push_str(&format!("{key}: {value}\n"));
}
}
}
/// Write a Cabrillo 3.0 entry for `qsos`.
///
/// The caller decides which contacts belong to the entry; this writes what it
/// is given, in the order it is given, oldest first as sponsors expect.
pub fn write_cabrillo(qsos: &[Qso], header: &CabrilloHeader) -> String {
let mut out = String::with_capacity(qsos.len() * 96 + 512);
out.push_str("START-OF-LOG: 3.0\n");
header_line(&mut out, "CREATED-BY", Some("trx-rs"));
header_line(&mut out, "CONTEST", header.contest.as_deref());
header_line(&mut out, "CALLSIGN", header.callsign.as_deref());
header_line(
&mut out,
"CATEGORY-OPERATOR",
header.category_operator.as_deref(),
);
header_line(&mut out, "CATEGORY-BAND", header.category_band.as_deref());
header_line(&mut out, "CATEGORY-MODE", header.category_mode.as_deref());
header_line(&mut out, "CATEGORY-POWER", header.category_power.as_deref());
if let Some(score) = header.claimed_score {
header_line(&mut out, "CLAIMED-SCORE", Some(&score.to_string()));
}
header_line(&mut out, "OPERATORS", header.operators.as_deref());
header_line(&mut out, "NAME", header.name.as_deref());
header_line(&mut out, "EMAIL", header.email.as_deref());
header_line(&mut out, "SOAPBOX", header.soapbox.as_deref());
// Oldest first: a contest log is read as it was worked.
let mut ordered: Vec<&Qso> = qsos.iter().collect();
ordered.sort_by_key(|qso| qso.started_at);
let station = header
.callsign
.clone()
.or_else(|| qsos.first().and_then(|qso| qso.station_callsign.clone()))
.unwrap_or_else(|| "UNKNOWN".to_string());
for qso in ordered {
let sent = qso.exchange_sent().unwrap_or_default();
let received = qso.exchange_received().unwrap_or_default();
out.push_str(&format!(
"QSO: {freq:>5} {mode:2} {date} {time} {mine:<13} {rst_sent:>3} {exch_sent:<6} {theirs:<13} {rst_rcvd:>3} {exch_rcvd:<6}\n",
freq = cabrillo_frequency(qso.freq_hz),
mode = cabrillo_mode(qso),
date = qso.started_at.format("%Y-%m-%d"),
time = qso.started_at.format("%H%M"),
mine = qso.station_callsign.as_deref().unwrap_or(&station),
rst_sent = qso.rst_sent.as_deref().unwrap_or(""),
exch_sent = sent,
theirs = qso.call,
rst_rcvd = qso.rst_rcvd.as_deref().unwrap_or(""),
exch_rcvd = received,
));
}
out.push_str("END-OF-LOG:\n");
out
}
#[cfg(test)]
mod tests {
use super::*;
use crate::qso::parse_adif_datetime;
fn contest_qso(call: &str, hz: u64, mode: &str, time: &str, sent: u32, rcvd: u32) -> Qso {
let mut qso = Qso::new(
format!("{call}-{time}"),
parse_adif_datetime("20260807", Some(time)).expect("time"),
call,
hz,
mode,
);
qso.station_callsign = Some("SP0TRX".into());
qso.rst_sent = Some("59".into());
qso.rst_rcvd = Some("59".into());
qso.stx = Some(sent);
qso.srx = Some(rcvd);
qso.contest_id = Some("CQ-WW-SSB".into());
qso
}
#[test]
fn an_entry_has_the_header_a_sponsor_expects() {
let header = CabrilloHeader {
contest: Some("CQ-WW-SSB".into()),
callsign: Some("SP0TRX".into()),
claimed_score: Some(1234),
..CabrilloHeader::default()
};
let text = write_cabrillo(
&[contest_qso("DL1AB", 14_200_000, "SSB", "120000", 1, 42)],
&header,
);
assert!(text.starts_with("START-OF-LOG: 3.0\n"), "{text}");
assert!(text.contains("CONTEST: CQ-WW-SSB\n"), "{text}");
assert!(text.contains("CALLSIGN: SP0TRX\n"), "{text}");
assert!(text.contains("CATEGORY-OPERATOR: SINGLE-OP\n"), "{text}");
assert!(text.contains("CLAIMED-SCORE: 1234\n"), "{text}");
assert!(text.trim_end().ends_with("END-OF-LOG:"), "{text}");
// A header field nobody filled in is left out, not written empty.
assert!(!text.contains("SOAPBOX:"), "{text}");
}
#[test]
fn a_qso_line_carries_both_sides_of_the_exchange() {
let text = write_cabrillo(
&[contest_qso("DL1AB", 14_200_000, "SSB", "120000", 1, 42)],
&CabrilloHeader::default(),
);
let line = text
.lines()
.find(|line| line.starts_with("QSO:"))
.expect("a QSO line");
// Frequency in kHz on HF, the phone mode letter, the date and UTC time,
// then mine, my report and my serial, then theirs.
assert!(line.contains("14200"), "{line}");
assert!(line.contains(" PH "), "{line}");
assert!(line.contains("2026-08-07 1200"), "{line}");
assert!(line.contains("SP0TRX"), "{line}");
assert!(line.contains("DL1AB"), "{line}");
assert!(line.contains("001"), "{line}");
assert!(line.contains("042"), "{line}");
}
/// Above 30 MHz Cabrillo names the band rather than the frequency.
#[test]
fn vhf_and_up_are_written_as_band_designators() {
assert_eq!(cabrillo_frequency(14_200_000), "14200");
assert_eq!(cabrillo_frequency(7_030_000), "7030");
assert_eq!(cabrillo_frequency(144_300_000), "144");
assert_eq!(cabrillo_frequency(432_100_000), "432");
assert_eq!(cabrillo_frequency(1_296_000_000), "1.2G");
assert_eq!(cabrillo_frequency(50_313_000), "50");
}
#[test]
fn the_mode_letters_are_cabrillos_not_adifs() {
let cw = contest_qso("DL1AB", 7_030_000, "CW", "120000", 1, 1);
let phone = contest_qso("DL1AB", 14_200_000, "SSB", "120000", 1, 1);
let fm = contest_qso("DL1AB", 145_500_000, "FM", "120000", 1, 1);
let digital = contest_qso("DL1AB", 14_074_000, "FT8", "120000", 1, 1);
assert_eq!(cabrillo_mode(&cw), "CW");
assert_eq!(cabrillo_mode(&phone), "PH");
assert_eq!(cabrillo_mode(&fm), "FM");
assert_eq!(cabrillo_mode(&digital), "DG");
}
#[test]
fn contacts_are_written_oldest_first_however_they_arrive() {
let text = write_cabrillo(
&[
contest_qso("LATER", 14_200_000, "SSB", "130000", 2, 2),
contest_qso("EARLIER", 14_200_000, "SSB", "120000", 1, 1),
],
&CabrilloHeader::default(),
);
let calls: Vec<&str> = text
.lines()
.filter(|line| line.starts_with("QSO:"))
.map(|line| {
if line.contains("EARLIER") {
"EARLIER"
} else {
"LATER"
}
})
.collect();
assert_eq!(calls, vec!["EARLIER", "LATER"]);
}
/// A word exchange -- a zone, a section, a name -- rather than a serial.
#[test]
fn an_exchange_that_is_not_a_number_is_written_as_it_was() {
let mut qso = contest_qso("DL1AB", 14_200_000, "SSB", "120000", 1, 1);
qso.stx_string = Some("14".into());
qso.srx_string = Some("BAVARIA".into());
let text = write_cabrillo(&[qso], &CabrilloHeader::default());
let line = text.lines().find(|l| l.starts_with("QSO:")).expect("line");
assert!(line.contains("BAVARIA"), "{line}");
assert!(!line.contains("001"), "{line}");
}
}
+191
View File
@@ -0,0 +1,191 @@
// SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
//
// SPDX-License-Identifier: GPL-2.0-or-later
//! Telling one contact from two.
//!
//! Two programs rarely stamp the same QSO to the same minute — one records when
//! the contact started, another when the operator finished typing — so matching
//! on an exact time duplicates half of what an import is asked to merge. The
//! key is therefore the callsign, the band and the mode, with the time compared
//! as a window.
//!
//! Two minutes is the window. It is wide enough for the disagreement between
//! loggers and narrow enough to keep a legitimate re-work: contest rules forbid
//! a second contact with the same station on the same band and mode, so a
//! repeat inside two minutes is the same contact written twice, while the same
//! station on another band an hour later is a different QSO and keys differently
//! anyway.
use std::collections::HashMap;
use chrono::Duration;
use crate::qso::Qso;
/// How far apart two records of the same contact may be stamped.
pub const MATCH_WINDOW_MINUTES: i64 = 2;
/// Modes as they are compared, not as they are written.
///
/// A log that stored `USB` and one that stored `SSB` describe the same contact;
/// without this an import from either would duplicate every phone QSO in the
/// other.
fn normalized_mode(qso: &Qso) -> String {
match qso.mode.trim().to_uppercase().as_str() {
"USB" | "LSB" | "SSB" => "SSB".to_string(),
"CWR" => "CW".to_string(),
"SAM" => "AM".to_string(),
"WFM" => "FM".to_string(),
other => other.to_string(),
}
}
fn key(qso: &Qso) -> (String, String, String) {
(
qso.call.clone(),
qso.band().unwrap_or("").to_string(),
normalized_mode(qso),
)
}
/// An index over an existing log, for asking whether an incoming record is
/// already held.
pub struct DuplicateIndex {
by_key: HashMap<(String, String, String), Vec<chrono::DateTime<chrono::Utc>>>,
}
impl DuplicateIndex {
pub fn build(existing: &[Qso]) -> Self {
let mut by_key: HashMap<_, Vec<_>> = HashMap::new();
for qso in existing {
by_key.entry(key(qso)).or_default().push(qso.started_at);
}
Self { by_key }
}
/// Whether this contact is already in the log.
pub fn contains(&self, candidate: &Qso) -> bool {
let window = Duration::minutes(MATCH_WINDOW_MINUTES);
self.by_key.get(&key(candidate)).is_some_and(|times| {
times
.iter()
// Compared as instants, so a contact either side of
// midnight matches rather than falling into two days.
.any(|held| (*held - candidate.started_at).abs() <= window)
})
}
/// Remember a contact, so a file that repeats itself does not import twice.
pub fn insert(&mut self, qso: &Qso) {
self.by_key
.entry(key(qso))
.or_default()
.push(qso.started_at);
}
}
/// Which bands and modes a callsign has been worked on.
pub fn worked_before(existing: &[Qso], call: &str) -> Vec<(String, String)> {
let wanted = crate::qso::normalize_call(call);
let mut seen: Vec<(String, String)> = existing
.iter()
.filter(|qso| qso.call == wanted)
.map(|qso| (qso.band().unwrap_or("").to_string(), normalized_mode(qso)))
.collect();
seen.sort();
seen.dedup();
seen
}
#[cfg(test)]
mod tests {
use super::*;
use crate::qso::parse_adif_datetime;
fn qso(call: &str, hz: u64, mode: &str, time: &str) -> Qso {
Qso::new(
format!("{call}-{time}"),
parse_adif_datetime("20260807", Some(time)).expect("time"),
call,
hz,
mode,
)
}
#[test]
fn the_same_contact_stamped_a_minute_apart_is_one_contact() {
let held = vec![qso("SP1AA", 14_074_000, "FT8", "120000")];
let index = DuplicateIndex::build(&held);
assert!(index.contains(&qso("SP1AA", 14_074_000, "FT8", "120100")));
assert!(index.contains(&qso("SP1AA", 14_074_000, "FT8", "115900")));
// Beyond the window it is another contact.
assert!(!index.contains(&qso("SP1AA", 14_074_000, "FT8", "120300")));
}
#[test]
fn phone_matches_however_the_other_logger_spelled_it() {
let held = vec![qso("SP1AA", 14_200_000, "SSB", "120000")];
let index = DuplicateIndex::build(&held);
assert!(index.contains(&qso("SP1AA", 14_200_000, "USB", "120000")));
assert!(index.contains(&qso("SP1AA", 14_200_000, "LSB", "120030")));
}
#[test]
fn another_band_or_another_mode_is_another_contact() {
let held = vec![qso("SP1AA", 14_074_000, "FT8", "120000")];
let index = DuplicateIndex::build(&held);
// Same station, same minute, 40 m: a band change during a QSO happens.
assert!(!index.contains(&qso("SP1AA", 7_074_000, "FT8", "120000")));
assert!(!index.contains(&qso("SP1AA", 14_074_000, "CW", "120000")));
assert!(!index.contains(&qso("SP2BB", 14_074_000, "FT8", "120000")));
}
#[test]
fn a_contact_either_side_of_midnight_still_matches() {
let before = Qso::new(
"1".into(),
parse_adif_datetime("20260807", Some("235930")).expect("time"),
"SP1AA",
14_074_000,
"FT8",
);
let after = Qso::new(
"2".into(),
parse_adif_datetime("20260808", Some("000030")).expect("time"),
"SP1AA",
14_074_000,
"FT8",
);
let index = DuplicateIndex::build(&[before]);
assert!(index.contains(&after));
}
#[test]
fn a_file_that_repeats_itself_imports_once() {
let mut index = DuplicateIndex::build(&[]);
let first = qso("SP1AA", 14_074_000, "FT8", "120000");
assert!(!index.contains(&first));
index.insert(&first);
assert!(index.contains(&qso("SP1AA", 14_074_000, "FT8", "120030")));
}
#[test]
fn worked_before_answers_by_band_and_mode() {
let held = vec![
qso("SP1AA", 14_074_000, "FT8", "120000"),
qso("SP1AA", 7_030_000, "CW", "130000"),
qso("SP1AA", 14_074_000, "FT8", "140000"),
qso("SP2BB", 14_200_000, "USB", "150000"),
];
let worked = worked_before(&held, "sp1aa");
assert_eq!(
worked,
vec![
("20m".to_string(), "FT8".to_string()),
("40m".to_string(), "CW".to_string()),
]
);
assert!(worked_before(&held, "SP9ZZ").is_empty());
}
}
+510
View File
@@ -0,0 +1,510 @@
// SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
//
// SPDX-License-Identifier: GPL-2.0-or-later
//! The station logbook: contacts, the file they live in, and ADIF in and out.
//!
//! One log per station rather than one per rig. Awards and uploads count the
//! callsign, not the radio — a station worked on the second rig is still worked
//! — so the rig is recorded on the contact instead of dividing the log by it.
//! Where a rig stands does follow the contact, though: `my_gridsquare` comes
//! from the rig that made it, because rigs can be in different places.
pub mod adif;
pub mod cabrillo;
pub mod dedupe;
pub mod qso;
pub mod store;
use std::path::PathBuf;
use std::sync::{Arc, Mutex};
use chrono::{DateTime, Utc};
use serde::{Deserialize, Serialize};
pub use cabrillo::{write_cabrillo, CabrilloHeader};
pub use dedupe::{worked_before, DuplicateIndex, MATCH_WINDOW_MINUTES};
pub use qso::Qso;
pub use store::LogStore;
/// A fresh contact identity.
pub fn new_id() -> String {
uuid::Uuid::new_v4().to_string()
}
/// Where the log lives when the configuration does not say.
///
/// The data directory, not the config directory the bookmarks use and not the
/// cache directory the decode logs use: a log is neither a setting nor
/// disposable, and cache directories get swept by cleaners.
pub fn default_log_path() -> PathBuf {
dirs::data_dir()
.map(|dir| dir.join("trx-rs").join("logbook.jsonl"))
.unwrap_or_else(|| PathBuf::from("logbook.jsonl"))
}
/// What a filtered read asks for.
#[derive(Debug, Default, Clone, Deserialize)]
pub struct LogQuery {
/// Substring of the callsign, case-insensitive.
#[serde(default)]
pub call: Option<String>,
/// Only contacts in this contest.
#[serde(default)]
pub contest: Option<String>,
/// Only contacts the other station has confirmed, or only those they have
/// not.
#[serde(default)]
pub confirmed: Option<bool>,
#[serde(default)]
pub band: Option<String>,
#[serde(default)]
pub mode: Option<String>,
/// Inclusive bounds on the contact's time.
#[serde(default)]
pub from: Option<DateTime<Utc>>,
#[serde(default)]
pub to: Option<DateTime<Utc>>,
#[serde(default)]
pub limit: Option<usize>,
#[serde(default)]
pub offset: Option<usize>,
}
/// One band's worth of the log.
#[derive(Debug, Clone, Serialize)]
pub struct BandStatistics {
pub band: String,
pub contacts: usize,
/// Distinct callsigns, which is the number an award counts.
pub stations: usize,
pub confirmed: usize,
}
/// What an import did.
#[derive(Debug, Default, Clone, Serialize)]
pub struct ImportOutcome {
pub added: usize,
/// Already held, by callsign, band, mode and the two-minute window.
pub duplicate: usize,
/// Records that could not be read as contacts, with the reason.
pub rejected: Vec<String>,
}
/// The logbook, shared by whoever serves it.
#[derive(Clone)]
pub struct Logbook {
store: Arc<Mutex<LogStore>>,
}
impl Logbook {
pub fn open(path: &std::path::Path) -> std::io::Result<Self> {
Ok(Self {
store: Arc::new(Mutex::new(LogStore::open(path)?)),
})
}
fn with_store<T>(&self, f: impl FnOnce(&mut LogStore) -> T) -> T {
// A poisoned lock means a panic while holding it, not a corrupt log --
// the file is on disk either way -- so carry on with what is there.
let mut store = self.store.lock().unwrap_or_else(|e| e.into_inner());
f(&mut store)
}
pub fn path(&self) -> PathBuf {
self.with_store(|store| store.path().to_path_buf())
}
pub fn count(&self) -> usize {
self.with_store(|store| store.len())
}
/// Contacts matching `query`, newest first.
pub fn query(&self, query: &LogQuery) -> Vec<Qso> {
self.with_store(|store| {
let call = query.call.as_deref().map(str::to_uppercase);
let band = query.band.as_deref().map(str::to_lowercase);
let mode = query.mode.as_deref().map(str::to_uppercase);
let contest = query.contest.clone();
let matching: Vec<Qso> = store
.all()
.into_iter()
.filter(|qso| {
call.as_ref().is_none_or(|c| qso.call.contains(c.as_str()))
&& band
.as_ref()
.is_none_or(|b| qso.band().is_some_and(|found| found == b))
&& mode.as_ref().is_none_or(|m| qso.mode == *m)
&& query.from.is_none_or(|from| qso.started_at >= from)
&& query.to.is_none_or(|to| qso.started_at <= to)
&& contest.as_ref().is_none_or(|wanted| {
qso.contest_id
.as_deref()
.is_some_and(|held| held.eq_ignore_ascii_case(wanted))
})
&& query
.confirmed
.is_none_or(|wanted| qso.is_confirmed() == wanted)
})
.collect();
let offset = query.offset.unwrap_or(0).min(matching.len());
let end = query
.limit
.map_or(matching.len(), |limit| (offset + limit).min(matching.len()));
matching[offset..end].to_vec()
})
}
pub fn get(&self, id: &str) -> Option<Qso> {
self.with_store(|store| store.get(id).cloned())
}
/// Add a contact, or replace one with the same id.
pub fn put(&self, qso: Qso) -> std::io::Result<Qso> {
self.with_store(|store| store.put(qso.clone()))?;
Ok(qso)
}
pub fn delete(&self, id: &str) -> std::io::Result<bool> {
self.with_store(|store| store.delete(id))
}
/// Which bands and modes a callsign has been worked on.
pub fn worked_before(&self, call: &str) -> Vec<(String, String)> {
self.with_store(|store| dedupe::worked_before(&store.all(), call))
}
/// Export as Cabrillo, for submitting a contest entry.
pub fn export_cabrillo(&self, query: &LogQuery, header: &CabrilloHeader) -> String {
cabrillo::write_cabrillo(&self.query(query), header)
}
/// What has been worked, and what has been confirmed, band by band.
///
/// One confirmation counts wherever it came from: an award wants a card or
/// an electronic match, not one of each.
pub fn band_statistics(&self) -> Vec<BandStatistics> {
self.with_store(|store| {
let mut by_band: std::collections::HashMap<String, BandStatistics> =
std::collections::HashMap::new();
let mut stations: std::collections::HashMap<String, std::collections::HashSet<String>> =
std::collections::HashMap::new();
for qso in store.all() {
let band = qso.band().unwrap_or("other").to_string();
let entry = by_band
.entry(band.clone())
.or_insert_with(|| BandStatistics {
band: band.clone(),
contacts: 0,
stations: 0,
confirmed: 0,
});
entry.contacts += 1;
if qso.is_confirmed() {
entry.confirmed += 1;
}
stations.entry(band).or_default().insert(qso.call.clone());
}
let mut all: Vec<BandStatistics> = by_band
.into_values()
.map(|mut entry| {
entry.stations = stations
.get(&entry.band)
.map_or(0, std::collections::HashSet::len);
entry
})
.collect();
// Ordered by wavelength, longest first, as a band plan reads.
all.sort_by_key(|entry| qso::band_order(&entry.band));
all
})
}
/// Export as ADIF, honouring the same filters as a read.
pub fn export_adi(&self, query: &LogQuery, program_version: &str) -> String {
adif::write_adi(&self.query(query), program_version)
}
/// Import an ADIF file, skipping contacts already held.
pub fn import_adi(&self, input: &[u8]) -> std::io::Result<ImportOutcome> {
let report = adif::parse_adi(input);
let mut outcome = ImportOutcome {
rejected: report.rejected,
..ImportOutcome::default()
};
self.with_store(|store| {
let mut index = DuplicateIndex::build(&store.all());
let mut fresh = Vec::new();
for qso in report.qsos {
if index.contains(&qso) {
outcome.duplicate += 1;
continue;
}
index.insert(&qso);
fresh.push(qso);
}
outcome.added = fresh.len();
store.put_all(fresh)
})?;
Ok(outcome)
}
}
#[cfg(test)]
mod tests {
use super::*;
use crate::qso::parse_adif_datetime;
fn new_book() -> (tempfile::TempDir, Logbook) {
let dir = tempfile::tempdir().expect("tempdir");
let book = Logbook::open(&dir.path().join("logbook.jsonl")).expect("open");
(dir, book)
}
fn qso(call: &str, hz: u64, mode: &str, time: &str) -> Qso {
Qso::new(
new_id(),
parse_adif_datetime("20260807", Some(time)).expect("time"),
call,
hz,
mode,
)
}
#[test]
fn a_log_answers_the_filters_it_is_asked() {
let (_dir, book) = new_book();
book.put(qso("SP1AA", 14_074_000, "FT8", "120000"))
.expect("put");
book.put(qso("SP2BB", 7_030_000, "CW", "130000"))
.expect("put");
book.put(qso("DL3CC", 14_200_000, "SSB", "140000"))
.expect("put");
assert_eq!(book.count(), 3);
assert_eq!(book.query(&LogQuery::default()).len(), 3);
// Newest first.
assert_eq!(book.query(&LogQuery::default())[0].call, "DL3CC");
let by_band = LogQuery {
band: Some("20m".into()),
..LogQuery::default()
};
assert_eq!(book.query(&by_band).len(), 2);
let by_call = LogQuery {
call: Some("sp".into()),
..LogQuery::default()
};
assert_eq!(book.query(&by_call).len(), 2);
let by_mode = LogQuery {
mode: Some("cw".into()),
..LogQuery::default()
};
assert_eq!(book.query(&by_mode)[0].call, "SP2BB");
let paged = LogQuery {
limit: Some(1),
offset: Some(1),
..LogQuery::default()
};
assert_eq!(book.query(&paged).len(), 1);
// Newest first, so offset 1 is the middle contact.
assert_eq!(book.query(&paged)[0].call, "SP2BB");
}
#[test]
fn an_import_skips_what_is_already_held_and_says_so() {
let (_dir, book) = new_book();
book.put(qso("SP1AA", 14_074_000, "FT8", "120000"))
.expect("put");
let file = concat!(
// the one already held, a minute out, as another logger stamped it
"<call:5>SP1AA<qso_date:8>20260807<time_on:6>120100<freq:6>14.074<mode:3>FT8<eor>\n",
// a new one
"<call:5>DL2XY<qso_date:8>20260807<time_on:6>121500<freq:6>14.074<mode:3>FT8<eor>\n",
// and something that is not a contact
"<call:5>NODAT<eor>\n",
);
let outcome = book.import_adi(file.as_bytes()).expect("import");
assert_eq!(outcome.added, 1);
assert_eq!(outcome.duplicate, 1);
assert_eq!(outcome.rejected.len(), 1);
assert_eq!(book.count(), 2);
// And importing the same file again adds nothing.
let again = book.import_adi(file.as_bytes()).expect("import again");
assert_eq!(again.added, 0);
assert_eq!(again.duplicate, 2);
assert_eq!(book.count(), 2);
}
#[test]
fn an_export_can_be_imported_into_an_empty_log() {
let (_dir, book) = new_book();
book.put(qso("SP1AA", 14_074_000, "FT8", "120000"))
.expect("put");
book.put(qso("DL3CC", 14_200_000, "SSB", "140000"))
.expect("put");
let exported = book.export_adi(&LogQuery::default(), "0.1.0");
let (_other_dir, other) = new_book();
let outcome = other.import_adi(exported.as_bytes()).expect("import");
assert_eq!(outcome.added, 2);
assert_eq!(other.count(), 2);
assert_eq!(other.query(&LogQuery::default())[0].call, "DL3CC");
}
#[test]
fn worked_before_reads_through_the_log() {
let (_dir, book) = new_book();
book.put(qso("SP1AA", 14_074_000, "FT8", "120000"))
.expect("put");
book.put(qso("SP1AA", 7_030_000, "CW", "130000"))
.expect("put");
assert_eq!(book.worked_before("sp1aa").len(), 2);
assert!(book.worked_before("SP9ZZ").is_empty());
}
#[test]
fn statistics_count_stations_and_confirmations_band_by_band() {
let (_dir, book) = new_book();
let mut first = qso("SP1AA", 14_074_000, "FT8", "120000");
first.lotw_qsl_rcvd = Some("Y".into());
book.put(first).expect("put");
// The same station again on the same band: one station, two contacts.
book.put(qso("SP1AA", 14_100_000, "SSB", "121000"))
.expect("put");
let mut third = qso("DL2BB", 7_030_000, "CW", "130000");
third.qsl_rcvd = Some("Y".into());
book.put(third).expect("put");
book.put(qso("OZ3CC", 7_040_000, "CW", "131000"))
.expect("put");
let stats = book.band_statistics();
// Longest wavelength first, as a band plan reads.
assert_eq!(
stats.iter().map(|s| s.band.as_str()).collect::<Vec<_>>(),
vec!["40m", "20m"]
);
let forty = &stats[0];
assert_eq!((forty.contacts, forty.stations, forty.confirmed), (2, 2, 1));
let twenty = &stats[1];
assert_eq!(
(twenty.contacts, twenty.stations, twenty.confirmed),
(2, 1, 1)
);
}
#[test]
fn a_contest_entry_holds_only_that_contest() {
let (_dir, book) = new_book();
for (call, contest, serial) in [
("SP1AA", Some("CQ-WW-SSB"), 1),
("DL2BB", Some("CQ-WW-SSB"), 2),
("OZ3CC", None, 0),
] {
let mut entry = qso(call, 14_200_000, "SSB", "120000");
entry.contest_id = contest.map(str::to_string);
entry.stx = Some(serial);
entry.station_callsign = Some("SP0TRX".into());
entry.rst_sent = Some("59".into());
entry.rst_rcvd = Some("59".into());
book.put(entry).expect("put");
}
let query = LogQuery {
contest: Some("cq-ww-ssb".into()),
..LogQuery::default()
};
assert_eq!(
book.query(&query).len(),
2,
"the contest filter is case-sensitive"
);
let text = book.export_cabrillo(
&query,
&CabrilloHeader {
contest: Some("CQ-WW-SSB".into()),
callsign: Some("SP0TRX".into()),
..CabrilloHeader::default()
},
);
let lines: Vec<&str> = text
.lines()
.filter(|line| line.starts_with("QSO:"))
.collect();
assert_eq!(lines.len(), 2, "{text}");
assert!(
!text.contains("OZ3CC"),
"a contact outside the contest was submitted"
);
}
#[test]
fn confirmations_come_from_whichever_bureau_answered() {
let (_dir, book) = new_book();
let mut card = qso("SP1AA", 14_074_000, "FT8", "120000");
card.qsl_rcvd = Some("Y".into());
let mut lotw = qso("DL2BB", 14_074_000, "FT8", "121000");
lotw.lotw_qsl_rcvd = Some("Y".into());
let mut requested = qso("OZ3CC", 14_074_000, "FT8", "122000");
requested.qsl_rcvd = Some("R".into());
for entry in [card, lotw, requested] {
book.put(entry).expect("put");
}
let confirmed = LogQuery {
confirmed: Some(true),
..LogQuery::default()
};
let calls: Vec<String> = book.query(&confirmed).into_iter().map(|q| q.call).collect();
assert_eq!(calls.len(), 2, "{calls:?}");
assert!(calls.contains(&"SP1AA".to_string()) && calls.contains(&"DL2BB".to_string()));
// Requested is not confirmed.
let outstanding = LogQuery {
confirmed: Some(false),
..LogQuery::default()
};
assert_eq!(book.query(&outstanding)[0].call, "OZ3CC");
}
#[test]
fn the_contest_and_qsl_fields_survive_a_trip_through_adif() {
let (_dir, book) = new_book();
let mut entry = qso("SP1AA", 14_200_000, "SSB", "120000");
entry.contest_id = Some("CQ-WW-SSB".into());
entry.stx = Some(7);
entry.srx_string = Some("BAVARIA".into());
entry.cqz = Some(15);
entry.qsl_sent = Some("Y".into());
entry.lotw_qsl_rcvd = Some("Y".into());
book.put(entry).expect("put");
let exported = book.export_adi(&LogQuery::default(), "0.1.0");
let (_other_dir, other) = new_book();
other.import_adi(exported.as_bytes()).expect("import");
let back = &other.query(&LogQuery::default())[0];
assert_eq!(back.contest_id.as_deref(), Some("CQ-WW-SSB"));
assert_eq!(back.stx, Some(7));
assert_eq!(back.srx_string.as_deref(), Some("BAVARIA"));
assert_eq!(back.cqz, Some(15));
assert_eq!(back.qsl_sent.as_deref(), Some("Y"));
assert!(back.is_confirmed());
}
#[test]
fn a_contact_can_be_changed_and_forgotten() {
let (_dir, book) = new_book();
let mut entry = qso("SP1AA", 14_074_000, "FT8", "120000");
let id = entry.id.clone();
book.put(entry.clone()).expect("put");
entry.rst_rcvd = Some("-11".into());
book.put(entry).expect("edit");
assert_eq!(book.get(&id).and_then(|q| q.rst_rcvd), Some("-11".into()));
assert!(book.delete(&id).expect("delete"));
assert!(book.get(&id).is_none());
assert_eq!(book.count(), 0);
}
}
+465
View File
@@ -0,0 +1,465 @@
// SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
//
// SPDX-License-Identifier: GPL-2.0-or-later
//! The record a contact is kept as, and the translations between what the radio
//! says and what a log file wants.
use std::collections::BTreeMap;
use chrono::{DateTime, Datelike, NaiveDate, NaiveDateTime, NaiveTime, Timelike, Utc};
use serde::{Deserialize, Serialize};
/// One contact.
///
/// The named fields are the ones the application fills, reads or filters on.
/// Everything else an imported file carried is kept in [`Qso::extra`] under its
/// ADIF field name, so a log that came from another program leaves with what it
/// arrived with rather than what this one happens to understand.
#[derive(Debug, Clone, Serialize, Deserialize, PartialEq)]
pub struct Qso {
/// Stable identity, ours, not from the file.
pub id: String,
/// UTC, always: the log is kept in the radio's time, not a browser's.
pub started_at: DateTime<Utc>,
/// Present once the operator records the end of a contact.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub ended_at: Option<DateTime<Utc>>,
/// The station worked.
pub call: String,
/// Dial frequency in Hz. The band is derived from it rather than stored
/// twice and allowed to disagree.
pub freq_hz: u64,
/// ADIF mode, e.g. `SSB`, `CW`, `FT8`.
pub mode: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub submode: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub rst_sent: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub rst_rcvd: Option<String>,
/// The worked station's Maidenhead locator.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub gridsquare: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub name: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub qth: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub comment: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub tx_pwr_w: Option<f64>,
/// The callsign this station was on the air with.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub station_callsign: Option<String>,
/// The person at the key, which is not always the station.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub operator: Option<String>,
/// Our locator *for this contact*: rigs can stand in different places.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub my_gridsquare: Option<String>,
/// The rig it was worked on, by display name (ADIF `MY_RIG`).
#[serde(default, skip_serializing_if = "Option::is_none")]
pub my_rig: Option<String>,
/// Which rig of this client, by id — ours, not ADIF's.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub rig_id: Option<String>,
/// The contest this contact counts towards, by its Cabrillo name.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub contest_id: Option<String>,
/// Serial sent. Kept as text as well as a number, because plenty of
/// exchanges are neither — a zone, a section, a name, a power.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub stx: Option<u32>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub stx_string: Option<String>,
/// Serial received, likewise.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub srx: Option<u32>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub srx_string: Option<String>,
/// CQ and ITU zones of the station worked.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub cqz: Option<u8>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub ituz: Option<u8>,
/// Paper QSL, and the two card-less bureaux, as ADIF's single letters:
/// `Y` yes, `N` no, `R` requested, `I` ignore, `Q` queued, `V` verified.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub qsl_sent: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub qsl_rcvd: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub lotw_qsl_sent: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub lotw_qsl_rcvd: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub eqsl_qsl_sent: Option<String>,
#[serde(default, skip_serializing_if = "Option::is_none")]
pub eqsl_qsl_rcvd: Option<String>,
/// ADIF fields this application does not model, kept verbatim.
#[serde(default, skip_serializing_if = "BTreeMap::is_empty")]
pub extra: BTreeMap<String, String>,
}
impl Qso {
/// A contact with only the fields every log needs.
pub fn new(
id: String,
started_at: DateTime<Utc>,
call: &str,
freq_hz: u64,
mode: &str,
) -> Self {
Self {
id,
started_at,
ended_at: None,
call: normalize_call(call),
freq_hz,
mode: mode.trim().to_uppercase(),
submode: None,
rst_sent: None,
rst_rcvd: None,
gridsquare: None,
name: None,
qth: None,
comment: None,
tx_pwr_w: None,
station_callsign: None,
operator: None,
my_gridsquare: None,
my_rig: None,
rig_id: None,
contest_id: None,
stx: None,
stx_string: None,
srx: None,
srx_string: None,
cqz: None,
ituz: None,
qsl_sent: None,
qsl_rcvd: None,
lotw_qsl_sent: None,
lotw_qsl_rcvd: None,
eqsl_qsl_sent: None,
eqsl_qsl_rcvd: None,
extra: BTreeMap::new(),
}
}
/// The ADIF band name for the frequency, if it falls in an amateur band.
pub fn band(&self) -> Option<&'static str> {
band_for_hz(self.freq_hz)
}
/// Whether the other station has confirmed this contact, anywhere.
///
/// One confirmation is a confirmation: an award needs one card or one
/// electronic match, not all three, and a log that counted them separately
/// would tell the operator they were three contacts short of what they have.
pub fn is_confirmed(&self) -> bool {
[&self.qsl_rcvd, &self.lotw_qsl_rcvd, &self.eqsl_qsl_rcvd]
.into_iter()
.flatten()
.any(|state| {
let state = state.trim().to_uppercase();
state == "Y" || state == "V"
})
}
/// The exchange as it goes into a contest log: what was sent, or received.
pub fn exchange_sent(&self) -> Option<String> {
self.stx_string
.clone()
.or_else(|| self.stx.map(|serial| format!("{serial:03}")))
}
pub fn exchange_received(&self) -> Option<String> {
self.srx_string
.clone()
.or_else(|| self.srx.map(|serial| format!("{serial:03}")))
}
/// What two logs have to agree on to be describing the same contact.
///
/// Not the time: that is compared as a window by [`crate::dedupe`], because
/// two programs rarely stamp the same QSO to the same minute.
pub fn match_key(&self) -> (String, String, String) {
(
self.call.clone(),
self.band().unwrap_or("").to_string(),
self.mode.clone(),
)
}
}
/// Callsigns are compared, sorted and deduplicated, so they are held one way:
/// upper case, without the spaces a hurried operator leaves behind.
pub fn normalize_call(call: &str) -> String {
call.trim().to_uppercase()
}
/// Amateur bands by their ADIF names, as frequency ranges in Hz.
///
/// Ranges are the widest any region allows, since a log records what was heard
/// rather than what a licence permits, and a QSO on a band edge must not fall
/// out of the log because one region stops earlier than another.
const BANDS: &[(&str, u64, u64)] = &[
("2190m", 135_700, 137_800),
("630m", 472_000, 479_000),
("560m", 501_000, 504_000),
("160m", 1_800_000, 2_000_000),
("80m", 3_500_000, 4_000_000),
("60m", 5_060_000, 5_450_000),
("40m", 7_000_000, 7_300_000),
("30m", 10_100_000, 10_150_000),
("20m", 14_000_000, 14_350_000),
("17m", 18_068_000, 18_168_000),
("15m", 21_000_000, 21_450_000),
("12m", 24_890_000, 24_990_000),
("10m", 28_000_000, 29_700_000),
("8m", 40_000_000, 45_000_000),
("6m", 50_000_000, 54_000_000),
("5m", 54_000_001, 69_900_000),
("4m", 70_000_000, 71_000_000),
("2m", 144_000_000, 148_000_000),
("1.25m", 222_000_000, 225_000_000),
("70cm", 420_000_000, 450_000_000),
("33cm", 902_000_000, 928_000_000),
("23cm", 1_240_000_000, 1_300_000_000),
("13cm", 2_300_000_000, 2_450_000_000),
("9cm", 3_300_000_000, 3_500_000_000),
("6cm", 5_650_000_000, 5_925_000_000),
("3cm", 10_000_000_000, 10_500_000_000),
];
/// The ADIF band a frequency falls in, or `None` outside the amateur bands —
/// a broadcast or utility frequency has no band name, and inventing one would
/// put a lie in the log.
pub fn band_for_hz(hz: u64) -> Option<&'static str> {
BANDS
.iter()
.find(|(_, low, high)| hz >= *low && hz <= *high)
.map(|(name, _, _)| *name)
}
/// The middle of a named band.
///
/// A log that recorded `20m` and no frequency knows the band and not the dial;
/// the midpoint is the honest reading of that, and the band name it exports
/// comes back the same.
pub fn band_midpoint_for_name(band: &str) -> Option<u64> {
let wanted = band.trim().to_lowercase();
BANDS
.iter()
.find(|(name, _, _)| *name == wanted)
.map(|(_, low, high)| low + (high - low) / 2)
}
/// Where a band sits in the table, for ordering a report by wavelength.
///
/// Anything not in the table sorts last, which is where "other" belongs.
pub fn band_order(band: &str) -> usize {
let wanted = band.trim().to_lowercase();
BANDS
.iter()
.position(|(name, _, _)| *name == wanted)
.unwrap_or(BANDS.len())
}
/// The frequency in MHz, as ADIF writes it.
pub fn freq_mhz_string(hz: u64) -> String {
// Six decimals is 1 Hz, which is finer than any dial reports and is what
// other loggers write. The zeros are then dropped from the fraction only:
// trimming the whole string would turn 20.000000 into 2, since the run of
// trailing zeros reaches back through the point into the integer.
let text = format!("{:.6}", hz as f64 / 1e6);
match text.split_once('.') {
Some((whole, fraction)) => {
let fraction = fraction.trim_end_matches('0');
if fraction.is_empty() {
whole.to_string()
} else {
format!("{whole}.{fraction}")
}
}
None => text,
}
}
/// ADIF's MHz back to Hz.
pub fn hz_from_mhz_string(text: &str) -> Option<u64> {
let mhz: f64 = text.trim().parse().ok()?;
if !mhz.is_finite() || mhz < 0.0 {
return None;
}
Some((mhz * 1e6).round() as u64)
}
/// What a rig mode becomes in a log.
///
/// A rig reports what it is demodulating; a log records what the contact was
/// made on, and the two are not the same word. `DIG` is deliberately absent:
/// a rig in `DIG` is in FT8 or FT4 or something else depending on which decoder
/// is running, so the caller has to say which — see [`mode_for_decoder`].
pub fn adif_mode_for_rig_mode(rig_mode: &str) -> Option<(&'static str, Option<&'static str>)> {
match rig_mode.trim().to_uppercase().as_str() {
"USB" => Some(("SSB", Some("USB"))),
"LSB" => Some(("SSB", Some("LSB"))),
"CW" | "CWR" => Some(("CW", None)),
"AM" | "SAM" => Some(("AM", None)),
"FM" | "WFM" => Some(("FM", None)),
"PKT" => Some(("PKT", None)),
// AIS and VDES are maritime, not amateur: nothing on them is a QSO.
// DIG says nothing on its own, and Other(..) is whatever a backend
// called it, which is the operator's to confirm rather than ours to
// guess into the log.
_ => None,
}
}
/// What a decoder's contacts are logged as.
///
/// WSPR is absent on purpose: it is a beacon mode. Hearing a beacon is not a
/// contact, so a WSPR spot never opens a log entry.
pub fn mode_for_decoder(decoder_id: &str) -> Option<(&'static str, Option<&'static str>)> {
match decoder_id.trim().to_lowercase().as_str() {
"ft8" => Some(("FT8", None)),
// FT4 is a submode of MFSK in ADIF, which is how WSJT-X logs it.
"ft4" => Some(("MFSK", Some("FT4"))),
"ft2" => Some(("MFSK", Some("FT2"))),
"cw" => Some(("CW", None)),
"aprs" | "hf-aprs" | "hf_aprs" => Some(("PKT", None)),
_ => None,
}
}
/// ADIF writes dates as `YYYYMMDD`, always UTC.
pub fn adif_date(at: &DateTime<Utc>) -> String {
format!("{:04}{:02}{:02}", at.year(), at.month(), at.day())
}
/// ADIF writes times as `HHMMSS`, always UTC.
pub fn adif_time(at: &DateTime<Utc>) -> String {
format!("{:02}{:02}{:02}", at.hour(), at.minute(), at.second())
}
/// ADIF's date and time back to an instant.
///
/// Times come as `HHMMSS` or `HHMM`; both are in the wild, and a missing time
/// is treated as midnight rather than rejecting the record, because a log with
/// a date and no time is still a log.
pub fn parse_adif_datetime(date: &str, time: Option<&str>) -> Option<DateTime<Utc>> {
let date = date.trim();
if date.len() != 8 || !date.bytes().all(|b| b.is_ascii_digit()) {
return None;
}
let year: i32 = date[0..4].parse().ok()?;
let month: u32 = date[4..6].parse().ok()?;
let day: u32 = date[6..8].parse().ok()?;
let date = NaiveDate::from_ymd_opt(year, month, day)?;
let time = time.map(str::trim).filter(|t| !t.is_empty());
let time = match time {
None => NaiveTime::from_hms_opt(0, 0, 0)?,
Some(text) if text.len() == 6 || text.len() == 4 => {
if !text.bytes().all(|b| b.is_ascii_digit()) {
return None;
}
let hour: u32 = text[0..2].parse().ok()?;
let minute: u32 = text[2..4].parse().ok()?;
let second: u32 = if text.len() == 6 {
text[4..6].parse().ok()?
} else {
0
};
NaiveTime::from_hms_opt(hour, minute, second)?
}
Some(_) => return None,
};
Some(NaiveDateTime::new(date, time).and_utc())
}
#[cfg(test)]
mod tests {
use super::*;
#[test]
fn bands_are_named_from_the_dial() {
assert_eq!(band_for_hz(14_074_000), Some("20m"));
assert_eq!(band_for_hz(7_030_000), Some("40m"));
assert_eq!(band_for_hz(144_300_000), Some("2m"));
// A band edge is in the band: a QSO at 14.350 is a 20 m QSO.
assert_eq!(band_for_hz(14_350_000), Some("20m"));
// Broadcast and utility frequencies have no band, and must not be given
// one -- a log that says 49m would be wrong, not merely unhelpful.
assert_eq!(band_for_hz(6_075_000), None);
assert_eq!(band_for_hz(162_025_000), None);
}
#[test]
fn frequencies_survive_the_trip_through_megahertz() {
for hz in [
14_074_000_u64,
7_030_000,
1_840_000,
432_100_000,
10_138_700,
20_000_000,
100_000_000,
] {
let text = freq_mhz_string(hz);
assert_eq!(
hz_from_mhz_string(&text),
Some(hz),
"{text} came back wrong"
);
}
assert_eq!(freq_mhz_string(14_074_000), "14.074");
assert_eq!(freq_mhz_string(14_000_000), "14");
// A whole number of MHz ending in a zero: trimming the string rather
// than the fraction turned 20 MHz into 2 MHz, and 100 into 1.
assert_eq!(freq_mhz_string(20_000_000), "20");
assert_eq!(freq_mhz_string(100_000_000), "100");
assert_eq!(freq_mhz_string(10_000_000), "10");
assert_eq!(freq_mhz_string(50_313_000), "50.313");
}
#[test]
fn a_rig_mode_is_not_an_adif_mode() {
assert_eq!(adif_mode_for_rig_mode("USB"), Some(("SSB", Some("USB"))));
assert_eq!(adif_mode_for_rig_mode("lsb"), Some(("SSB", Some("LSB"))));
assert_eq!(adif_mode_for_rig_mode("CWR"), Some(("CW", None)));
assert_eq!(adif_mode_for_rig_mode("SAM"), Some(("AM", None)));
// The rig cannot answer for DIG, and must not be allowed to guess.
assert_eq!(adif_mode_for_rig_mode("DIG"), None);
// Nor are the maritime modes contacts at all.
assert_eq!(adif_mode_for_rig_mode("AIS"), None);
assert_eq!(adif_mode_for_rig_mode("VDES"), None);
}
#[test]
fn a_decoder_answers_for_the_digital_modes() {
assert_eq!(mode_for_decoder("ft8"), Some(("FT8", None)));
assert_eq!(mode_for_decoder("ft4"), Some(("MFSK", Some("FT4"))));
assert_eq!(mode_for_decoder("aprs"), Some(("PKT", None)));
// Hearing a beacon is not a contact.
assert_eq!(mode_for_decoder("wspr"), None);
}
#[test]
fn adif_times_are_read_in_both_widths_and_written_in_one() {
let with_seconds = parse_adif_datetime("20260807", Some("121530")).expect("HHMMSS");
let without = parse_adif_datetime("20260807", Some("1215")).expect("HHMM");
assert_eq!(adif_date(&with_seconds), "20260807");
assert_eq!(adif_time(&with_seconds), "121530");
assert_eq!(adif_time(&without), "121500");
// A date with no time is still a log entry.
assert!(parse_adif_datetime("20260807", None).is_some());
// Nonsense is not.
assert!(parse_adif_datetime("2026080", Some("1215")).is_none());
assert!(parse_adif_datetime("20261307", Some("1215")).is_none());
assert!(parse_adif_datetime("20260807", Some("12:15")).is_none());
}
}
+330
View File
@@ -0,0 +1,330 @@
// SPDX-FileCopyrightText: 2026 Stan Grams <sjg@haxx.space>
//
// SPDX-License-Identifier: GPL-2.0-or-later
//! Where the log lives.
//!
//! One JSON Lines file, appended to and never rewritten in place. A log is the
//! one thing in this application that cannot be regenerated: a bookmark can be
//! typed again and a decode will come round again, but a contact happened once.
//! So every write is an append of a single line — atomic as far as a crash is
//! concerned, since a torn last line loses only the record being written and is
//! skipped on the next load — rather than a dump of the whole file, which at
//! forty thousand QSOs would rewrite megabytes to log one contact and lose all
//! of them if the power went halfway.
//!
//! An edit appends a new revision of the same id and a delete appends a
//! tombstone; the load keeps the last word on each id. Compaction rewrites the
//! file, through a temporary and a rename, once the superseded records outnumber
//! the live ones.
use std::collections::HashMap;
use std::fs::{create_dir_all, File, OpenOptions};
use std::io::{BufRead, BufReader, BufWriter, Write};
use std::path::{Path, PathBuf};
use serde::{Deserialize, Serialize};
use crate::qso::Qso;
/// One line of the file.
#[derive(Debug, Clone, Serialize, Deserialize)]
#[serde(tag = "op", rename_all = "snake_case")]
enum Entry {
/// A contact, as it stands after this line.
Qso(Box<Qso>),
/// This id is gone.
Delete { id: String },
}
/// Compact once more than this share of the file is superseded.
const COMPACT_WHEN_STALE_RATIO: f64 = 0.5;
/// ...but not while the file is still trivially small.
const COMPACT_MIN_LINES: usize = 256;
pub struct LogStore {
path: PathBuf,
/// Live records by id. The log is small enough to hold: forty thousand
/// QSOs is a few tens of megabytes, and every read wants it in memory.
qsos: HashMap<String, Qso>,
/// Lines in the file, live or not, for deciding when to compact.
lines_written: usize,
}
impl LogStore {
/// Open the log at `path`, creating it and its directory if need be.
///
/// A line that cannot be read is skipped and counted rather than failing the
/// open: a half-written last line from a crash must not cost the operator
/// the rest of the log.
pub fn open(path: &Path) -> std::io::Result<Self> {
if let Some(parent) = path.parent() {
create_dir_all(parent)?;
}
let mut store = Self {
path: path.to_path_buf(),
qsos: HashMap::new(),
lines_written: 0,
};
if path.exists() {
let file = File::open(path)?;
let mut damaged = 0usize;
for line in BufReader::new(file).lines() {
let line = line?;
if line.trim().is_empty() {
continue;
}
store.lines_written += 1;
match serde_json::from_str::<Entry>(&line) {
Ok(Entry::Qso(qso)) => {
store.qsos.insert(qso.id.clone(), *qso);
}
Ok(Entry::Delete { id }) => {
store.qsos.remove(&id);
}
Err(_) => damaged += 1,
}
}
if damaged > 0 {
tracing::warn!(
"logbook: skipped {damaged} unreadable line(s) in {}",
path.display()
);
}
}
Ok(store)
}
pub fn path(&self) -> &Path {
&self.path
}
pub fn len(&self) -> usize {
self.qsos.len()
}
pub fn is_empty(&self) -> bool {
self.qsos.is_empty()
}
/// Every contact, newest first.
pub fn all(&self) -> Vec<Qso> {
let mut all: Vec<Qso> = self.qsos.values().cloned().collect();
all.sort_by(|a, b| b.started_at.cmp(&a.started_at).then(a.id.cmp(&b.id)));
all
}
pub fn get(&self, id: &str) -> Option<&Qso> {
self.qsos.get(id)
}
/// Write a contact, new or changed.
pub fn put(&mut self, qso: Qso) -> std::io::Result<()> {
self.append(&Entry::Qso(Box::new(qso.clone())))?;
self.qsos.insert(qso.id.clone(), qso);
self.compact_if_needed()
}
/// Write several contacts, appending them in one open of the file.
pub fn put_all(&mut self, qsos: Vec<Qso>) -> std::io::Result<()> {
if qsos.is_empty() {
return Ok(());
}
let mut file = BufWriter::new(
OpenOptions::new()
.create(true)
.append(true)
.open(&self.path)?,
);
for qso in &qsos {
let line = serde_json::to_string(&Entry::Qso(Box::new(qso.clone())))
.map_err(std::io::Error::other)?;
writeln!(file, "{line}")?;
self.lines_written += 1;
}
file.flush()?;
for qso in qsos {
self.qsos.insert(qso.id.clone(), qso);
}
self.compact_if_needed()
}
/// Forget a contact. `Ok(false)` if there was nothing to forget.
pub fn delete(&mut self, id: &str) -> std::io::Result<bool> {
if !self.qsos.contains_key(id) {
return Ok(false);
}
self.append(&Entry::Delete { id: id.to_string() })?;
self.qsos.remove(id);
self.compact_if_needed()?;
Ok(true)
}
fn append(&mut self, entry: &Entry) -> std::io::Result<()> {
let line = serde_json::to_string(entry).map_err(std::io::Error::other)?;
let mut file = OpenOptions::new()
.create(true)
.append(true)
.open(&self.path)?;
writeln!(file, "{line}")?;
file.flush()?;
self.lines_written += 1;
Ok(())
}
fn compact_if_needed(&mut self) -> std::io::Result<()> {
if self.lines_written < COMPACT_MIN_LINES {
return Ok(());
}
let live = self.qsos.len();
let stale = self.lines_written.saturating_sub(live);
if (stale as f64) < (self.lines_written as f64) * COMPACT_WHEN_STALE_RATIO {
return Ok(());
}
self.compact()
}
/// Rewrite the file with one line per live contact.
///
/// Through a temporary and a rename, so an interrupted compaction leaves
/// the old file whole rather than a half-written new one.
pub fn compact(&mut self) -> std::io::Result<()> {
let temporary = self.path.with_extension("jsonl.compacting");
{
let mut file = BufWriter::new(File::create(&temporary)?);
for qso in self.all() {
let line = serde_json::to_string(&Entry::Qso(Box::new(qso)))
.map_err(std::io::Error::other)?;
writeln!(file, "{line}")?;
}
file.flush()?;
}
std::fs::rename(&temporary, &self.path)?;
self.lines_written = self.qsos.len();
Ok(())
}
}
#[cfg(test)]
mod tests {
use super::*;
use crate::qso::parse_adif_datetime;
fn qso(id: &str, call: &str, minute: u32) -> Qso {
Qso::new(
id.to_string(),
parse_adif_datetime("20260807", Some(&format!("12{minute:02}00"))).expect("time"),
call,
14_074_000,
"FT8",
)
}
#[test]
fn a_log_survives_being_closed_and_opened() {
let dir = tempfile::tempdir().expect("tempdir");
let path = dir.path().join("logbook.jsonl");
let mut store = LogStore::open(&path).expect("open");
store.put(qso("a", "SP1AA", 0)).expect("put");
store.put(qso("b", "SP2BB", 1)).expect("put");
drop(store);
let store = LogStore::open(&path).expect("reopen");
assert_eq!(store.len(), 2);
assert_eq!(store.get("a").map(|q| q.call.as_str()), Some("SP1AA"));
// Newest first.
assert_eq!(store.all()[0].call, "SP2BB");
}
#[test]
fn the_last_word_on_an_id_is_the_one_that_counts() {
let dir = tempfile::tempdir().expect("tempdir");
let path = dir.path().join("logbook.jsonl");
let mut store = LogStore::open(&path).expect("open");
store.put(qso("a", "SP1AA", 0)).expect("put");
let mut edited = qso("a", "SP1AA", 0);
edited.rst_sent = Some("-05".into());
store.put(edited).expect("edit");
store.put(qso("b", "SP2BB", 1)).expect("put");
assert!(store.delete("b").expect("delete"));
assert!(!store.delete("b").expect("delete again"));
drop(store);
let store = LogStore::open(&path).expect("reopen");
assert_eq!(store.len(), 1);
assert_eq!(
store.get("a").and_then(|q| q.rst_sent.clone()),
Some("-05".into())
);
}
/// A crash mid-write leaves a torn line. It costs that record and nothing
/// else — the point of appending one line at a time.
#[test]
fn a_torn_last_line_costs_only_itself() {
let dir = tempfile::tempdir().expect("tempdir");
let path = dir.path().join("logbook.jsonl");
let mut store = LogStore::open(&path).expect("open");
store.put(qso("a", "SP1AA", 0)).expect("put");
store.put(qso("b", "SP2BB", 1)).expect("put");
drop(store);
let mut text = std::fs::read_to_string(&path).expect("read");
text.push_str("{\"op\":\"qso\",\"id\":\"c\",\"call\":\"SP3");
std::fs::write(&path, text).expect("write");
let store = LogStore::open(&path).expect("reopen past the tear");
assert_eq!(store.len(), 2);
assert!(store.get("a").is_some() && store.get("b").is_some());
}
#[test]
fn compaction_keeps_the_log_and_shortens_the_file() {
let dir = tempfile::tempdir().expect("tempdir");
let path = dir.path().join("logbook.jsonl");
let mut store = LogStore::open(&path).expect("open");
// One live record, rewritten until compaction triggers.
for index in 0..COMPACT_MIN_LINES + 10 {
let mut entry = qso("a", "SP1AA", 0);
entry.comment = Some(format!("revision {index}"));
store.put(entry).expect("put");
}
let lines = std::fs::read_to_string(&path)
.expect("read")
.lines()
.count();
assert_eq!(store.len(), 1);
// Compacted along the way: the file holds the revisions written since,
// not the two hundred and sixty-six that were written.
assert!(
lines < COMPACT_MIN_LINES,
"the file kept {lines} lines for one contact"
);
assert_eq!(
store.get("a").and_then(|q| q.comment.clone()),
Some(format!("revision {}", COMPACT_MIN_LINES + 9))
);
// And the compacted file still reads.
drop(store);
let store = LogStore::open(&path).expect("reopen");
assert_eq!(store.len(), 1);
}
#[test]
fn an_import_appends_in_one_pass() {
let dir = tempfile::tempdir().expect("tempdir");
let path = dir.path().join("logbook.jsonl");
let mut store = LogStore::open(&path).expect("open");
store
.put_all(vec![qso("a", "SP1AA", 0), qso("b", "SP2BB", 1)])
.expect("put_all");
assert_eq!(store.len(), 2);
drop(store);
assert_eq!(LogStore::open(&path).expect("reopen").len(), 2);
}
}
+95 -89
View File
@@ -34,6 +34,23 @@ pub struct ClientConfig {
pub remotes: Vec<RemoteEntry>,
/// Frontend configurations
pub frontends: FrontendsConfig,
/// Station logbook
pub logbook: LogbookConfig,
}
/// Station logbook settings.
#[derive(Debug, Clone, Default, Serialize, Deserialize)]
#[serde(default)]
pub struct LogbookConfig {
/// Where the log is kept.
///
/// Defaults to `logbook.jsonl` in the user's data directory — not the
/// config directory the bookmarks use, and not the cache directory the
/// decode logs use: a log of contacts is neither a setting nor disposable,
/// and cache directories are swept by cleaners. Configurable because a
/// station that keeps its log on a synced or backed-up volume has to be
/// able to say so.
pub path: Option<String>,
}
/// General application settings.
@@ -251,18 +268,15 @@ impl AsRef<str> for CookieSameSite {
pub struct HttpAuthConfig {
/// Enable HTTP frontend authentication
pub enabled: bool,
/// Passphrase for read-only access (rx role)
pub rx_passphrase: Option<String>,
/// Read the rx passphrase from this file instead.
/// JSON file containing the managed user database.
pub users_file: String,
/// Username used to create the first administrator when the database is absent.
pub bootstrap_admin_username: Option<String>,
/// Password used to create the first administrator when the database is absent.
pub bootstrap_admin_password: Option<String>,
/// Read the bootstrap administrator password from this file instead.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub rx_passphrase_file: Option<String>,
/// Passphrase for full control access (control role)
pub control_passphrase: Option<String>,
/// Read the control passphrase from this file instead.
#[serde(default, skip_serializing_if = "Option::is_none")]
pub control_passphrase_file: Option<String>,
/// Enforce TX/PTT access control (hide from unauthenticated/rx users)
pub tx_access_control_enabled: bool,
pub bootstrap_admin_password_file: Option<String>,
/// Session time-to-live in minutes
pub session_ttl_min: u64,
/// Set Secure flag on session cookie (required for HTTPS)
@@ -275,11 +289,10 @@ impl Default for HttpAuthConfig {
fn default() -> Self {
Self {
enabled: false,
rx_passphrase: None,
rx_passphrase_file: None,
control_passphrase: None,
control_passphrase_file: None,
tx_access_control_enabled: true,
users_file: "trx-http-users.json".to_string(),
bootstrap_admin_username: None,
bootstrap_admin_password: None,
bootstrap_admin_password_file: None,
session_ttl_min: 480,
cookie_secure: false,
cookie_same_site: CookieSameSite::Lax,
@@ -785,14 +798,9 @@ impl ClientConfig {
)?;
}
resolve_secret(
&mut self.frontends.http.auth.rx_passphrase,
&self.frontends.http.auth.rx_passphrase_file,
"[frontends.http.auth].rx_passphrase",
)?;
resolve_secret(
&mut self.frontends.http.auth.control_passphrase,
&self.frontends.http.auth.control_passphrase_file,
"[frontends.http.auth].control_passphrase",
&mut self.frontends.http.auth.bootstrap_admin_password,
&self.frontends.http.auth.bootstrap_admin_password_file,
"[frontends.http.auth].bootstrap_admin_password",
)?;
resolve_secret_list(
&mut self.frontends.http_json.auth.tokens,
@@ -802,7 +810,7 @@ impl ClientConfig {
if let Some(path) = config_path {
if self.has_inline_secrets() {
crate::secrets::warn_if_group_readable(path, "tokens/passphrases");
crate::secrets::warn_if_group_readable(path, "tokens/passwords");
}
}
Ok(())
@@ -815,10 +823,13 @@ impl ClientConfig {
.remotes
.iter()
.any(|r| r.auth.token_file.is_none() && r.auth.token.is_some())
|| self.frontends.http.auth.rx_passphrase_file.is_none()
&& self.frontends.http.auth.rx_passphrase.is_some()
|| self.frontends.http.auth.control_passphrase_file.is_none()
&& self.frontends.http.auth.control_passphrase.is_some()
|| self
.frontends
.http
.auth
.bootstrap_admin_password_file
.is_none()
&& self.frontends.http.auth.bootstrap_admin_password.is_some()
|| self.frontends.http_json.auth.tokens_file.is_none()
&& !self.frontends.http_json.auth.tokens.is_empty()
}
@@ -888,11 +899,10 @@ impl ClientConfig {
decode_history_retention_min_by_rig: HashMap::new(),
auth: HttpAuthConfig {
enabled: false,
rx_passphrase: Some("rx-passphrase-example".to_string()),
rx_passphrase_file: None,
control_passphrase: Some("control-passphrase-example".to_string()),
control_passphrase_file: None,
tx_access_control_enabled: true,
users_file: "trx-http-users.json".to_string(),
bootstrap_admin_username: Some("admin".to_string()),
bootstrap_admin_password: Some("change-this-password".to_string()),
bootstrap_admin_password_file: None,
session_ttl_min: 480,
cookie_secure: false,
cookie_same_site: CookieSameSite::Lax,
@@ -907,6 +917,7 @@ impl ClientConfig {
http_json: HttpJsonFrontendConfig::default(),
audio: AudioClientConfig::default(),
},
logbook: LogbookConfig { path: None },
}
}
@@ -930,29 +941,27 @@ fn validate_http_auth(auth: &HttpAuthConfig) -> Result<(), String> {
return Ok(());
}
// If enabled, require at least one passphrase
if auth.rx_passphrase.is_none() && auth.control_passphrase.is_none() {
if auth.users_file.trim().is_empty() {
return Err("[frontends.http.auth].users_file must not be empty".to_string());
}
if auth.bootstrap_admin_username.is_some() != auth.bootstrap_admin_password.is_some() {
return Err("[frontends.http.auth] bootstrap_admin_username and bootstrap_admin_password must be set together".to_string());
}
if auth
.bootstrap_admin_username
.as_deref()
.is_some_and(|v| v.trim().is_empty())
|| auth
.bootstrap_admin_password
.as_deref()
.is_some_and(|v| v.is_empty())
{
return Err(
"[frontends.http.auth] enabled=true requires at least one passphrase \
(rx_passphrase and/or control_passphrase)"
"[frontends.http.auth] bootstrap administrator credentials must not be empty"
.to_string(),
);
}
// Validate passphrases are not empty strings
if let Some(rx) = &auth.rx_passphrase {
if rx.trim().is_empty() {
return Err("[frontends.http.auth].rx_passphrase must not be empty if set".to_string());
}
}
if let Some(ctrl) = &auth.control_passphrase {
if ctrl.trim().is_empty() {
return Err(
"[frontends.http.auth].control_passphrase must not be empty if set".to_string(),
);
}
}
// Session TTL must be > 0
if auth.session_ttl_min == 0 {
return Err("[frontends.http.auth].session_ttl_min must be > 0".to_string());
@@ -1220,42 +1229,34 @@ home-hf = "audio://10.0.0.5:4600"
}
#[test]
fn test_validate_rejects_http_auth_enabled_without_passphrases() {
fn test_validate_accepts_http_auth_with_user_database() {
let mut config = ClientConfig::default();
config.frontends.http.auth.enabled = true;
assert!(config.validate().is_ok());
}
#[test]
fn test_validate_accepts_bootstrap_admin_pair() {
let mut config = ClientConfig::default();
config.frontends.http.auth.enabled = true;
config.frontends.http.auth.bootstrap_admin_username = Some("admin".to_string());
config.frontends.http.auth.bootstrap_admin_password = Some("secret-password".to_string());
assert!(config.validate().is_ok());
}
#[test]
fn test_validate_rejects_incomplete_bootstrap_admin_pair() {
let mut config = ClientConfig::default();
config.frontends.http.auth.enabled = true;
config.frontends.http.auth.bootstrap_admin_username = Some("admin".to_string());
assert!(config.validate().is_err());
}
#[test]
fn test_validate_accepts_http_auth_with_rx_passphrase() {
fn test_validate_rejects_empty_users_file() {
let mut config = ClientConfig::default();
config.frontends.http.auth.enabled = true;
config.frontends.http.auth.rx_passphrase = Some("rx-secret".to_string());
assert!(config.validate().is_ok());
}
#[test]
fn test_validate_accepts_http_auth_with_control_passphrase() {
let mut config = ClientConfig::default();
config.frontends.http.auth.enabled = true;
config.frontends.http.auth.control_passphrase = Some("control-secret".to_string());
assert!(config.validate().is_ok());
}
#[test]
fn test_validate_accepts_http_auth_with_both_passphrases() {
let mut config = ClientConfig::default();
config.frontends.http.auth.enabled = true;
config.frontends.http.auth.rx_passphrase = Some("rx-secret".to_string());
config.frontends.http.auth.control_passphrase = Some("control-secret".to_string());
assert!(config.validate().is_ok());
}
#[test]
fn test_validate_rejects_empty_rx_passphrase() {
let mut config = ClientConfig::default();
config.frontends.http.auth.enabled = true;
config.frontends.http.auth.rx_passphrase = Some("".to_string());
config.frontends.http.auth.users_file.clear();
assert!(config.validate().is_err());
}
@@ -1263,16 +1264,15 @@ home-hf = "audio://10.0.0.5:4600"
fn test_validate_rejects_zero_session_ttl() {
let mut config = ClientConfig::default();
config.frontends.http.auth.enabled = true;
config.frontends.http.auth.rx_passphrase = Some("rx-secret".to_string());
config.frontends.http.auth.session_ttl_min = 0;
assert!(config.validate().is_err());
}
#[test]
fn test_validate_auth_disabled_ignores_passphrases() {
fn test_validate_auth_disabled_ignores_user_settings() {
let mut config = ClientConfig::default();
config.frontends.http.auth.enabled = false;
config.frontends.http.auth.rx_passphrase = Some("".to_string());
config.frontends.http.auth.users_file.clear();
assert!(config.validate().is_ok());
}
@@ -1280,9 +1280,9 @@ home-hf = "audio://10.0.0.5:4600"
fn test_http_auth_config_default() {
let auth = HttpAuthConfig::default();
assert!(!auth.enabled);
assert!(auth.rx_passphrase.is_none());
assert!(auth.control_passphrase.is_none());
assert!(auth.tx_access_control_enabled);
assert_eq!(auth.users_file, "trx-http-users.json");
assert!(auth.bootstrap_admin_username.is_none());
assert!(auth.bootstrap_admin_password.is_none());
assert_eq!(auth.session_ttl_min, 480);
assert!(!auth.cookie_secure);
assert!(matches!(auth.cookie_same_site, CookieSameSite::Lax));
@@ -1584,15 +1584,21 @@ spectrum_interval_ms = 0
}
#[test]
fn test_passphrase_file_fills_passphrase() {
fn test_bootstrap_password_file_fills_password() {
let f = secret_file("hunter2\n");
let mut config = ClientConfig::default();
config.frontends.http.auth.enabled = true;
config.frontends.http.auth.control_passphrase_file =
config.frontends.http.auth.bootstrap_admin_username = Some("admin".to_string());
config.frontends.http.auth.bootstrap_admin_password_file =
Some(f.path().to_str().unwrap().to_string());
config.resolve_secrets(None).unwrap();
assert_eq!(
config.frontends.http.auth.control_passphrase.as_deref(),
config
.frontends
.http
.auth
.bootstrap_admin_password
.as_deref(),
Some("hunter2")
);
assert!(config.validate().is_ok());
+6 -2
View File
@@ -111,8 +111,8 @@ const SECTION_COMMENTS: &[(&str, &str)] = &[
),
(
"trx-client.frontends.http.auth",
"Passphrase login for the web UI. rx_passphrase_file and\n\
control_passphrase_file keep the secrets out of this file.",
"Optional user/password ACL for the web UI. Administrators manage\n\
accounts stored in users_file.",
),
(
"trx-client.frontends.rigctl",
@@ -130,6 +130,10 @@ const SECTION_COMMENTS: &[(&str, &str)] = &[
"trx-client.frontends.audio.bridge",
"Play RX audio on a local sound device and capture TX from one.",
),
(
"trx-client.logbook",
"Station log of contacts. path defaults to logbook.jsonl in the user's\n data directory; set it to keep the log on a backed-up volume.",
),
];
/// Render the combined `trx-rs.toml.example` contents.
+9 -5
View File
@@ -203,13 +203,13 @@ decode_history_retention_min = 1440
[trx-client.frontends.http.decode_history_retention_min_by_rig]
# Passphrase login for the web UI. rx_passphrase_file and
# control_passphrase_file keep the secrets out of this file.
# Optional user/password ACL for the web UI. Administrators manage
# accounts stored in users_file.
[trx-client.frontends.http.auth]
enabled = false
rx_passphrase = "rx-passphrase-example"
control_passphrase = "control-passphrase-example"
tx_access_control_enabled = true
users_file = "trx-http-users.json"
bootstrap_admin_username = "admin"
bootstrap_admin_password = "change-this-password"
session_ttl_min = 480
cookie_secure = false
cookie_same_site = "Lax"
@@ -246,3 +246,7 @@ enabled = false
bitrate_bps = 192000
rx_gain = 1.0
tx_gain = 1.0
# Station log of contacts. path defaults to logbook.jsonl in the user's
# data directory; set it to keep the log on a backed-up volume.
[trx-client.logbook]