Zoo

staging

← back to the zoo

2. Visitors get a real page

Someone who is not signed in sees the page, not a bounce to a sign-in screen.

auth_user() is null for a visitor. The app decides what a visitor sees; the platform never forces a sign-in.

This is the code serving the zoo right now: read from disk for this request, from commit 77ff74344d (staging). The zoo's own self-check fetches this page and compares it byte for byte with the file it runs.

exhibits/02-visitors.php sha256 8984b3a3d08f · raw

1<?php
2// Exhibit 2. auth_user() returns null for a visitor and never redirects them, so the app can
3// simply render its page for nobody.
4return [
5    "n" => 2, "wing" => "Identity",
6    "title" => "Visitors get a real page",
7    "promise" => "Someone who is not signed in sees the page, not a bounce to a sign-in screen.",
8    "block" => "auth_user() is null for a visitor. The app decides what a visitor sees; the platform never forces a sign-in.",
9    "show" => function (?array $me): string {
10        return $me ? '<p>You are signed in. Open this page in a private window: it loads and says "you are a visitor".</p>'
11                   : '<p><b>You are a visitor.</b> This whole page loaded without a sign-in.</p>';
12    },
13    // Load the front page with no cookies at all, as a private window does.
14    "check" => function (): array {
15        [$code, $loc, $body] = (new Browser())->get("https://" . env("RC_HOST") . "/");
16        if ($code !== 200 || $loc !== "") return [false, "a visitor got $code" . ($loc ? " to $loc" : "") . " instead of the page"];
17        if (!str_contains((string)$body, "You are a visitor")) return [false, "the page loaded but does not say \"you are a visitor\""];
18        return [true, "a visitor gets the page (200, no redirect) and it says \"you are a visitor\""];
19    },
20];