, which reads the exhibit's files from the // checkout serving the request (lib/how.php). The check fetches every one of those pages over // HTTPS and compares it byte for byte with the file the zoo is running. return [ "n" => 19, "wing" => "Building", "title" => "Show me how", "promise" => "Every exhibit shows the code that makes it work.", "block" => "An app's code is plain files in its checkout; the zoo serves its own exhibits' files as they are on disk, so what you read is what runs.", "files" => ["lib/how.php", "lib/zoo.php"], "show" => function (?array $me): string { return '

Every card has a how link. Try the counter\'s or the doors\': the actual file serving this page, with its sha256.

'; }, "check" => function (): array { require_once ZOO_ROOT . "/lib/how.php"; $b = new Browser(); $n = 0; foreach (exhibits() as $e) { foreach (how_files($e) as $f) { [$code, , $body] = $b->get("https://" . env("RC_HOST") . "/how/{$e['n']}?raw=" . rawurlencode($f)); $body = is_array($body) ? json_encode($body) : $body; if ($code !== 200) return [false, "how for exhibit {$e['n']} ($f) answered $code"]; if ($body !== file_get_contents(ZOO_ROOT . "/$f")) return [false, "how for exhibit {$e['n']} shows a $f that differs from the running one"]; $n++; } } return [true, "$n how pages fetched over HTTPS, each identical to the file running"]; }, ];