2. Visitors get a real page
Someone who is not signed in sees the page, not a bounce to a sign-in screen.
auth_user() is null for a visitor. The app decides what a visitor sees; the platform never forces a sign-in.
This is the code serving the zoo right now: read from disk for this request, from commit
77ff74344d (staging). The zoo's own self-check fetches this
page and compares it byte for byte with the file it runs.
exhibits/02-visitors.php sha256 8984b3a3d08f · raw
1<?php 2// Exhibit 2. auth_user() returns null for a visitor and never redirects them, so the app can 3// simply render its page for nobody. 4return [ 5 "n" => 2, "wing" => "Identity", 6 "title" => "Visitors get a real page", 7 "promise" => "Someone who is not signed in sees the page, not a bounce to a sign-in screen.", 8 "block" => "auth_user() is null for a visitor. The app decides what a visitor sees; the platform never forces a sign-in.", 9 "show" => function (?array $me): string { 10 return $me ? '<p>You are signed in. Open this page in a private window: it loads and says "you are a visitor".</p>' 11 : '<p><b>You are a visitor.</b> This whole page loaded without a sign-in.</p>'; 12 }, 13 // Load the front page with no cookies at all, as a private window does. 14 "check" => function (): array { 15 [$code, $loc, $body] = (new Browser())->get("https://" . env("RC_HOST") . "/"); 16 if ($code !== 200 || $loc !== "") return [false, "a visitor got $code" . ($loc ? " to $loc" : "") . " instead of the page"]; 17 if (!str_contains((string)$body, "You are a visitor")) return [false, "the page loaded but does not say \"you are a visitor\""]; 18 return [true, "a visitor gets the page (200, no redirect) and it says \"you are a visitor\""]; 19 }, 20];