]> gitweb.ps.run Git - chirp/blobdiff - src/main.zig
get things working again
[chirp] / src / main.zig
index b016e1b89c93320fb87e8a87ea9c4d63b6caf4ba..65dab0798228554b0cbacd70e96cad0b2fb66ea6 100644 (file)
 const std = @import("std");
 const lmdb = @import("lmdb");
+const db = @import("db");
+const http = @import("http");
 
 // db {{{
 
-const Prng = struct {
-    var prng: std.Random.DefaultPrng = std.Random.DefaultPrng.init(0);
-
-    pub fn gen_id(dbi: anytype) Id {
-        var id = Prng.prng.next();
-
-        while (dbi.has(id)) {
-            id = Prng.prng.next();
-        }
-
-        return id;
+const Db = struct {
+    fn users(txn: lmdb.Txn) !db.Db(UserId, User) {
+        return try db.Db(UserId, User).init(txn, "users");
+    }
+    fn user_ids(txn: lmdb.Txn) !db.Db(Username, UserId) {
+        return try db.Db(Username, UserId).init(txn, "user_ids");
+    }
+    fn sessions(txn: lmdb.Txn) !db.Db(SessionToken, UserId) {
+        return try db.Db(SessionToken, UserId).init(txn, "sessions");
+    }
+    fn posts(txn: lmdb.Txn) !db.Db(PostId, Post) {
+        return try db.Db(PostId, Post).init(txn, "posts");
     }
 };
 
 // }}}
 
-// http stuff {{{
-
-pub fn redirect(req: *std.http.Server.Request, location: []const u8) !void {
-    try req.respond("", .{ .status = .see_other, .extra_headers = &.{.{ .name = "Location", .value = location }} });
-}
+// content {{{
 
-pub fn get_body(req: *std.http.Server.Request) []const u8 {
-    return req.server.read_buffer[req.head_end .. req.head_end + (req.head.content_length orelse 0)];
-}
+const User = struct {
+    // TODO: choose sizes
+    id: UserId,
+    name: Username,
+    password_hash: PasswordHash,
+    posts: PostList,
+};
 
-pub fn get_value(req: *std.http.Server.Request, name: []const u8) ?[]const u8 {
-    const body = get_body(req);
-    if (std.mem.indexOf(u8, body, name)) |name_index| {
-        if (std.mem.indexOfScalarPos(u8, body, name_index, '=')) |eql_index| {
-            if (std.mem.indexOfScalarPos(u8, body, name_index, '&')) |amp_index| {
-                return body[eql_index + 1 .. amp_index];
-            }
+const Post = struct {
+    id: PostId,
 
-            return body[eql_index + 1 .. body.len];
-        }
-    }
-    return null;
-}
+    user_id: UserId,
+    time: Timestamp,
 
-pub fn get_cookie(req: *std.http.Server.Request, name: []const u8) ?CookieValue {
-    var header_it = req.iterateHeaders();
-    while (header_it.next()) |header| {
-        if (std.mem.eql(u8, header.name, "Cookie")) {
-            if (std.mem.indexOf(u8, header.value, name)) |name_index| {
-                if (std.mem.indexOfScalarPos(u8, header.value, name_index, '=')) |eql_index| {
-                    if (std.mem.indexOfPos(u8, header.value, name_index, "; ")) |semi_index| {
-                        return CookieValue.fromSlice(header.value[eql_index + 1 .. semi_index]) catch null;
-                    }
+    upvotes: u64 = 0,
+    downvotes: u64 = 0,
+    votes: VoteList,
+    comments: PostList,
+    // quote posts
 
-                    return CookieValue.fromSlice(header.value[eql_index + 1 .. header.value.len]) catch null;
-                }
-            }
-        }
-    }
-    return null;
-}
+    text: PostText,
+};
 
-// }}}
+const Vote = struct {
+    const Kind = enum { Up, Down };
 
-// content {{{
-
-const User = struct {
-    // TODO: choose sizes
-    username: Username,
-    password_hash: PasswordHash,
+    kind: Kind,
+    time: Timestamp,
 };
 
 const Id = u64;
+const Login = struct {
+    user: User,
+    user_id: UserId,
+    session_token: SessionToken,
+};
+const UserId = enum(u64) { _ };
+const PostId = enum(u64) { _ };
+const Timestamp = i64;
 const Username = std.BoundedArray(u8, 16);
 const PasswordHash = std.BoundedArray(u8, 128);
 const SessionToken = u64;
 const CookieValue = std.BoundedArray(u8, 128);
+const PostText = std.BoundedArray(u8, 1024);
+const PostList = db.SetList(PostId, void);
+const UserList = db.SetList(UserId, User);
+const VoteList = db.SetList(UserId, Vote);
 
-pub fn hash_password(password: []const u8) !PasswordHash {
-    var hash_buffer = try PasswordHash.init(128);
+const Chirp = struct {
+    pub fn hash_password(password: []const u8) !PasswordHash {
+        var hash_buffer = try PasswordHash.init(128);
 
-    // TODO: choose buffer size
-    // TODO: dont allocate on stack, maybe zero memory?
-    var buffer: [1024 * 10]u8 = undefined;
-    var alloc = std.heap.FixedBufferAllocator.init(&buffer);
+        // TODO: choose buffer size
+        // TODO: dont allocate on stack, maybe zero memory?
+        var buffer: [1024 * 10]u8 = undefined;
+        var alloc = std.heap.FixedBufferAllocator.init(&buffer);
 
-    // TODO: choose limits
-    const result = try std.crypto.pwhash.argon2.strHash(password, .{
-        .allocator = alloc.allocator(),
-        .params = std.crypto.pwhash.argon2.Params.fromLimits(1000, 1024),
-    }, hash_buffer.slice());
+        // TODO: choose limits
+        const result = try std.crypto.pwhash.argon2.strHash(password, .{
+            .allocator = alloc.allocator(),
+            .params = std.crypto.pwhash.argon2.Params.fromLimits(1000, 1024),
+        }, hash_buffer.slice());
 
-    try hash_buffer.resize(result.len);
+        try hash_buffer.resize(result.len);
 
-    return hash_buffer;
-}
+        return hash_buffer;
+    }
 
-pub fn verify_password(password: []const u8, hash: PasswordHash) bool {
-    var buffer: [1024 * 10]u8 = undefined;
-    var alloc = std.heap.FixedBufferAllocator.init(&buffer);
-
-    if (std.crypto.pwhash.argon2.strVerify(hash.constSlice(), password, .{
-        .allocator = alloc.allocator(),
-    })) {
-        return true;
-    } else |err| {
-        std.debug.print("verify error: {}\n", .{err});
-        return false;
+    pub fn verify_password(password: []const u8, hash: PasswordHash) bool {
+        var buffer: [1024 * 10]u8 = undefined;
+        var alloc = std.heap.FixedBufferAllocator.init(&buffer);
+
+        if (std.crypto.pwhash.argon2.strVerify(hash.constSlice(), password, .{
+            .allocator = alloc.allocator(),
+        })) {
+            return true;
+        } else |err| {
+            std.debug.print("verify error: {}\n", .{err});
+            return false;
+        }
     }
-}
 
-pub fn register_user(env: *lmdb.Env, username: []const u8, password: []const u8) !void {
-    const username_array = try Username.fromSlice(username);
+    pub fn register_user(env: *lmdb.Env, username: []const u8, password: []const u8) !bool {
+        const username_array = try Username.fromSlice(username);
 
-    const txn = try env.txn();
-    defer {
-        txn.commit();
-        env.sync();
-    }
+        const txn = try env.txn();
+        defer txn.commit() catch {};
 
-    const users = try txn.dbi("users", Id, User);
-    const user_id = Prng.gen_id(users);
-    users.put(user_id, User{
-        .username = username_array,
-        .password_hash = try hash_password(password),
-    });
+        const users = try Db.users(txn);
+        const user_ids = try Db.user_ids(txn);
 
-    const user_ids = try txn.dbi("user_ids", Username, Id);
-    user_ids.put(username_array, user_id);
-}
+        if (try user_ids.has(username_array)) {
+            return false;
+        } else {
+            const user_id = try db.Prng.gen(users.dbi, UserId);
+            const posts = try Db.posts(txn);
 
-pub fn login_user(env: *lmdb.Env, username: []const u8, password: []const u8) !SessionToken {
-    const username_array = try Username.fromSlice(username);
+            try users.put(user_id, User{
+                .id = user_id,
+                .name = username_array,
+                .password_hash = try hash_password(password),
+                .posts = try PostList.init(posts.dbi),
+            });
 
-    const txn = try env.txn();
-    defer {
-        txn.commit();
-        env.sync();
+            try user_ids.put(username_array, user_id);
+
+            return true;
+        }
     }
 
-    const user_ids = try txn.dbi("user_ids", Username, Id);
-    const user_id = user_ids.get(username_array) orelse return error.UnknownUsername;
-    std.debug.print("id: {}\n", .{user_id});
+    pub fn login_user(
+        env: *lmdb.Env,
+        username: []const u8,
+        password: []const u8,
+    ) !SessionToken {
+        const username_array = try Username.fromSlice(username);
+
+        const txn = try env.txn();
+        defer txn.commit() catch {};
+
+        const user_ids = try Db.user_ids(txn);
+        const user_id = try user_ids.get(username_array);
+        std.debug.print("user logging in, id: {}\n", .{user_id});
+
+        const users = try Db.users(txn);
+        const user = try users.get(user_id);
 
-    const users = try txn.dbi("users", Id, User);
-    if (users.get(user_id)) |user| {
         if (verify_password(password, user.password_hash)) {
-            const sessions = try txn.dbi("sessions", Id, Id);
-            const session_token = Prng.gen_id(sessions);
-            sessions.put(session_token, user_id);
+            const sessions = try Db.sessions(txn);
+            const session_token = try db.Prng.gen(sessions.dbi, SessionToken);
+            try sessions.put(session_token, user_id);
             return session_token;
         } else {
             return error.IncorrectPassword;
         }
-    } else {
-        return error.UserNotFound;
     }
-}
 
-fn logout_user(env: *lmdb.Env, session_token: SessionToken) !void {
-    const txn = try env.txn();
-    defer {
-        txn.commit();
-        env.sync();
+    fn logout_user(env: *lmdb.Env, session_token: SessionToken) !void {
+        const txn = try env.txn();
+        defer txn.commit() catch {};
+
+        const sessions = try Db.sessions(txn);
+        try sessions.del(session_token);
     }
 
-    const sessions = try txn.dbi("sessions", Id, Id);
-    sessions.del(session_token);
-}
+    fn post(env: *lmdb.Env, user_id: UserId, text: []const u8) !void {
+        var post_id: PostId = undefined;
+
+        // TODO: do this in one commit
+
+        var txn: lmdb.Txn = undefined;
+        {
+            // create post
+            txn = try env.txn();
+            defer txn.commit() catch {};
+
+            const posts = try Db.posts(txn);
+            post_id = try db.Prng.gen(posts.dbi, PostId);
+            const votes = try txn.dbi("votes");
+            try posts.put(post_id, Post{
+                .id = post_id,
+                .user_id = user_id,
+                .time = std.time.timestamp(),
+                .votes = try VoteList.init(votes),
+                .comments = try PostList.init(posts.dbi),
+                .text = try PostText.fromSlice(text),
+            });
+        }
 
-fn get_session_user(env: *lmdb.Env, session_token: SessionToken) !User {
-    const txn = try env.txn();
-    defer txn.abort();
+        {
+            // append to user's posts
+            txn = try env.txn();
+            defer txn.commit() catch {};
+
+            const users = try Db.users(txn);
+            var user = try users.get(user_id);
+
+            const posts = try Db.posts(txn);
+            var posts_view = try user.posts.open(posts.dbi);
+            try posts_view.append(post_id, {});
+        }
+    }
+
+    fn vote(env: *lmdb.Env, post_id: PostId, user_id: UserId, kind: Vote.Kind) !void {
+        const txn = try env.txn();
+        defer txn.commit() catch {};
+
+        const posts = try Db.posts(txn);
+        const votes = try txn.dbi("votes");
+
+        var p = try posts.get(post_id);
+        var votes_view = try p.votes.open(votes);
+
+        if (try votes_view.has(user_id)) {
+            const old_vote = try votes_view.get(user_id);
+
+            if (old_vote.kind == kind) {
+                return;
+            } else {
+                try votes_view.del(user_id);
+
+                if (old_vote.kind == .Up) {
+                    p.upvotes -= 1;
+                } else {
+                    p.downvotes -= 1;
+                }
+                try posts.put(post_id, p);
+            }
+        }
+        try votes_view.append(user_id, Vote{
+            .kind = kind,
+            .time = std.time.timestamp(),
+        });
+
+        if (kind == .Up) {
+            p.upvotes += 1;
+        } else {
+            p.downvotes += 1;
+        }
+        try posts.put(post_id, p);
+    }
+
+    fn unvote(env: *lmdb.Env, post_id: PostId, user_id: UserId) !void {
+        const txn = try env.txn();
+        defer txn.commit() catch {};
+
+        const posts = try Db.posts(txn);
+        const votes = try txn.dbi("votes");
+
+        var p = try posts.get(post_id);
+        var votes_view = try p.votes.open(votes);
+
+        if (try votes_view.has(user_id)) {
+            const v = try votes_view.get(user_id);
+
+            if (v.kind == .Up) {
+                p.upvotes -= 1;
+            } else {
+                p.downvotes -= 1;
+            }
+            try posts.put(post_id, p);
+
+            try votes_view.del(user_id);
+        }
+    }
+
+    fn get_session_user_id(env: *lmdb.Env, session_token: SessionToken) !UserId {
+        const txn = try env.txn();
+        defer txn.abort();
+
+        const sessions = try Db.sessions(txn);
+
+        return try sessions.get(session_token);
+    }
+
+    fn get_user(env: *lmdb.Env, user_id: UserId) !User {
+        const txn = try env.txn();
+        defer txn.abort();
+
+        const users = try Db.users(txn);
+        return try users.get(user_id);
+    }
+};
+
+// }}}
+
+// html {{{
+fn html_form(res: *http.Response, comptime fmt_action: []const u8, args_action: anytype, inputs: anytype) !void {
+    try res.write("<form style=\"display: inline-block!important;\" action=\"", .{});
+    try res.write(fmt_action, args_action);
+    try res.write("\" method=\"post\">", .{});
+
+    inline for (inputs) |input| {
+        switch (@typeInfo(@TypeOf(input))) {
+            .Struct => {
+                try res.write("<input ", .{});
+                try res.write(input[0], input[1]);
+                try res.write(" />", .{});
+            },
+            else => {
+                try res.write("<input ", .{});
+                try res.write(input, .{});
+                try res.write(" />", .{});
+            },
+        }
+    }
 
-    const sessions = try txn.dbi("sessions", Id, Id);
-    const users = try txn.dbi("users", Id, User);
+    try res.write("</form>", .{});
+}
+// }}}
 
-    if (sessions.get(session_token)) |user_id| {
-        return users.get(user_id) orelse error.UnknownUser;
+// write {{{
+fn write_header(res: *http.Response, logged_in: ?Login) !void {
+    if (logged_in) |login| {
+        try res.write(
+            \\<a href="/user/{s}">Home</a><br />
+        , .{login.user.name.constSlice()});
+        try html_form(res, "/logout", .{}, .{
+            \\type="submit" value="Logout"
+        });
+        try html_form(res, "/quit", .{}, .{
+            \\type="submit" value="Quit"
+        });
+        try res.write("<br />", .{});
+        try html_form(res, "/post", .{}, .{
+            \\type="text" name="text"
+            ,
+            \\type="submit" value="Post"
+        });
     } else {
-        return error.SessionNotFound;
+        try res.write(
+            \\<a href="/">Home</a><br />
+            \\<a href="/register">Register</a>
+            \\<a href="/login">Login</a><br />
+        , .{});
+        try html_form(res, "/quit", .{}, .{
+            \\type="submit" value="Quit"
+        });
     }
 }
+fn write_posts(res: *http.Response, txn: lmdb.Txn, user: User, login: ?Login) !void {
+    const votes_dbi = try txn.dbi("votes");
+    const posts = try Db.posts(txn);
+    const posts_view = try user.posts.open(posts.dbi);
 
-// }}}
+    var it = posts_view.iterator();
+    while (it.next()) |kv| {
+        const post_id = kv.key;
+        const post = try posts.get(post_id);
 
-fn list_users(env: *lmdb.Env) !void {
-    const txn = try env.txn();
-    defer txn.abort();
+        try res.write(
+            \\<div>
+            \\<p>{s}</p>
+        , .{post.text.constSlice()});
 
-    const users = try txn.dbi("users", Id, User);
-    var cursor = try users.cursor();
+        const votes_view = try post.votes.open(votes_dbi);
+        const comments_view = try post.comments.open(posts.dbi);
 
-    var key: Id = undefined;
-    var user_maybe = cursor.get(&key, .First);
+        var has_voted: ?Vote.Kind = null;
 
-    while (user_maybe) |user| {
-        std.debug.print("[{}] {s}\n", .{ key, user.username.constSlice() });
+        if (login != null and try votes_view.has(login.?.user_id)) {
+            const vote = try votes_view.get(login.?.user_id);
 
-        user_maybe = cursor.get(&key, .Next);
+            has_voted = vote.kind;
+        }
+
+        if (has_voted != null and has_voted.? == .Up) {
+            try html_form(res, "/unupvote/{}", .{@intFromEnum(post_id)}, .{
+                .{ "type=\"submit\" value=\"&#x2B06; {}\"", .{post.upvotes} },
+            });
+        } else {
+            try html_form(res, "/upvote/{}", .{@intFromEnum(post_id)}, .{
+                .{ "type=\"submit\" value=\"&#x2B06; {}\"", .{post.upvotes} },
+            });
+        }
+        if (has_voted != null and has_voted.? == .Down) {
+            try html_form(res, "/undownvote/{}", .{@intFromEnum(post_id)}, .{
+                .{ "type=\"submit\" value=\"&#x2B07; {}\"", .{post.downvotes} },
+            });
+        } else {
+            try html_form(res, "/downvote/{}", .{@intFromEnum(post_id)}, .{
+                .{ "type=\"submit\" value=\"&#x2B07; {}\"", .{post.downvotes} },
+            });
+        }
+        try res.write(
+            \\<span>&#x1F4AD; {}</span>
+            \\</div>
+        , .{comments_view.len()});
     }
 }
-fn list_user_ids(env: *lmdb.Env) !void {
+// }}}
+
+fn list_users(env: lmdb.Env) !void {
     const txn = try env.txn();
     defer txn.abort();
 
-    const user_ids = try txn.dbi("user_ids", Username, Id);
-    var cursor = try user_ids.cursor();
+    const users = try Db.users(txn);
+    var it = try users.iterator();
 
-    var key: Username = undefined;
-    var user_id_maybe = cursor.get(&key, .First);
+    while (it.next()) |kv| {
+        const key = kv.key;
+        const user = kv.val;
+        std.debug.print("[{}] {s}\n", .{ key, user.name.constSlice() });
+    }
+}
+fn list_user_ids(env: lmdb.Env) !void {
+    const txn = try env.txn();
+    defer txn.abort();
 
-    while (user_id_maybe) |user_id| {
-        std.debug.print("[{s}] {}\n", .{ key.constSlice(), user_id });
+    const user_ids = try Db.user_ids(txn);
+    var it = try user_ids.iterator();
 
-        user_id_maybe = cursor.get(&key, .Next);
+    while (it.next()) |kv| {
+        const key = kv.key;
+        const user_id = kv.val;
+        std.debug.print("[{s}] {}\n", .{ key.constSlice(), user_id });
     }
 }
 
-fn list_sessions(env: *lmdb.Env) !void {
+fn list_sessions(env: lmdb.Env) !void {
     const txn = try env.txn();
     defer txn.abort();
 
-    const sessions = try txn.dbi("sessions", SessionToken, Id);
-    var cursor = try sessions.cursor();
+    const sessions = try Db.sessions(txn);
+    var it = try sessions.iterator();
+
+    while (it.next()) |kv| {
+        const key = kv.key;
+        const user_id = kv.val;
+        std.debug.print("[{x}] {}\n", .{ key, user_id });
+    }
+}
 
-    var key: SessionToken = undefined;
-    var user_id_maybe = cursor.get(&key, .First);
+fn list_posts(env: lmdb.Env) !void {
+    const txn = try env.txn();
+    defer txn.abort();
 
-    while (user_id_maybe) |user_id| {
-        std.debug.print("[{}] {}\n", .{ key, user_id });
+    const posts = try Db.posts(txn);
+    var it = try posts.iterator();
 
-        user_id_maybe = cursor.get(&key, .Next);
+    while (it.next()) |kv| {
+        const key = kv.key;
+        const post = kv.val;
+        std.debug.print("[{}] {s}\n", .{ key, post.text.constSlice() });
     }
 }
 
+const ReqBufferSize = 4096;
+const ResHeadBufferSize = 1024 * 16;
+const ResBodyBufferSize = 1024 * 16;
+
 pub fn main() !void {
     // server
-    const address = try std.net.Address.resolveIp("::", 8080);
-
-    var server = try address.listen(.{
-        .reuse_address = true,
-    });
+    var server = try http.Server.init("::", 8080);
     defer server.deinit();
 
     // lmdb
-    var env = lmdb.Env.open("db", 1024 * 100);
+    var env = try lmdb.Env.open("db", 1024 * 1024 * 10);
     defer env.close();
 
-    std.debug.print("Users:\n", .{});
-    try list_users(&env);
-    std.debug.print("User IDs:\n", .{});
-    try list_user_ids(&env);
-    std.debug.print("Sessions:\n", .{});
-    try list_sessions(&env);
+    // std.debug.print("Users:\n", .{});
+    // try list_users(env);
+    // std.debug.print("User IDs:\n", .{});
+    // try list_user_ids(env);
+    // std.debug.print("Sessions:\n", .{});
+    // try list_sessions(env);
+    // std.debug.print("Posts:\n", .{});
+    // try list_posts(env);
+
+    try handle_connection(&server, &env);
+    // const ThreadCount = 1;
+    // var ts: [ThreadCount]std.Thread = undefined;
+
+    // for (0..ThreadCount) |i| {
+    //     ts[i] = try std.Thread.spawn(.{}, handle_connection, .{ &server, &env });
+    // }
+    // for (0..ThreadCount) |i| {
+    //     ts[i].join();
+    // }
+
+    std.debug.print("done\n", .{});
+}
+
+fn handle_connection(server: *http.Server, env: *lmdb.Env) !void {
+    // TODO: static?
+    var req_buffer: [ReqBufferSize]u8 = undefined;
+    var res_head_buffer: [ResHeadBufferSize]u8 = undefined;
+    var res_body_buffer: [ResBodyBufferSize]u8 = undefined;
 
     accept: while (true) {
-        const conn = try server.accept();
-
-        std.debug.print("new connection: {}\n", .{conn});
+        server.wait();
 
-        var read_buffer: [1024]u8 = undefined;
-        var http_server = std.http.Server.init(conn, &read_buffer);
+        while (try server.next_request(&req_buffer)) |req| {
+            // std.debug.print("[{}]: {s}\n", .{ req.method, req.target });
 
-        while (http_server.state == .ready) {
-            var req = http_server.receiveHead() catch continue;
+            // reponse
+            var res = http.Response.init(req.fd, &res_head_buffer, &res_body_buffer);
 
-            std.debug.print("[{}]: {s}\n", .{ req.head.method, req.head.target });
+            // check session token
+            var logged_in: ?Login = null;
 
-            var logged_in: ?struct {
-                user: User,
-                session_token: SessionToken,
-            } = null;
+            if (req.get_cookie("session_token")) |session_token_str| {
+                const session_token = try std.fmt.parseUnsigned(SessionToken, session_token_str, 16);
+                // const session_token = try std.fmt.parseUnsigned(SessionToken, session_token_str, 10);
+                // const session_token = std.mem.bytesToValue(SessionToken, session_token_str);
+                if (Chirp.get_session_user_id(env, session_token)) |user_id| {
+                    const txn = try env.txn();
+                    defer txn.abort();
+                    const users = try Db.users(txn);
 
-            if (get_cookie(&req, "session_token")) |session_token_str| {
-                const session_token = try std.fmt.parseUnsigned(SessionToken, session_token_str.constSlice(), 10);
-                if (get_session_user(&env, session_token)) |user| {
                     logged_in = .{
-                        .user = user,
+                        .user = try users.get(user_id),
+                        .user_id = user_id,
                         .session_token = session_token,
                     };
                 } else |err| {
                     std.debug.print("get_session_user err: {}\n", .{err});
+
+                    try res.add_header(
+                        "Set-Cookie",
+                        .{"session_token=deleted; Expires=Thu, 01 Jan 1970 00:00:00 GMT"},
+                    );
                 }
-                // TODO: delete session token
-                // TODO: add changeable headers (set, delete cookies)
             }
 
             // html
-            if (req.head.method == .GET) {
-                if (std.mem.eql(u8, req.head.target, "/register")) {
-                    try req.respond(
+            if (req.method == .GET) {
+                try write_header(&res, logged_in);
+
+                if (std.mem.eql(u8, req.target, "/register")) {
+                    try res.write(
                         \\<form action="/register" method="post">
                         \\<input type="text" name="username" />
                         \\<input type="password" name="password" />
                         \\<input type="submit" value="Register" />
                         \\</form>
                     , .{});
-                } else if (std.mem.eql(u8, req.head.target, "/login")) {
-                    try req.respond(
+                    try res.send();
+                } else if (std.mem.eql(u8, req.target, "/login")) {
+                    try res.write(
                         \\<form action="/login" method="post">
                         \\<input type="text" name="username" />
                         \\<input type="password" name="password" />
                         \\<input type="submit" value="Login" />
                         \\</form>
                     , .{});
+                    try res.send();
+                } else if (std.mem.startsWith(u8, req.target, "/user/")) {
+                    const username = req.target[6..req.target.len];
+
+                    const txn = try env.txn();
+                    defer txn.abort();
+
+                    const user_ids = try Db.user_ids(txn);
+                    if (user_ids.get(try Username.fromSlice(username))) |user_id| {
+                        const users = try Db.users(txn);
+                        const user = try users.get(user_id);
+                        try write_posts(&res, txn, user, logged_in);
+                    } else |err| {
+                        try res.write(
+                            \\<p>User not found [{}]</p>
+                        , .{err});
+                    }
+                    try res.send();
                 } else {
                     if (logged_in) |login| {
-                        var response_buffer = try std.BoundedArray(u8, 1024).init(0);
-                        try std.fmt.format(response_buffer.writer(),
-                            \\<a href="/user/{s}">Home</a>
-                            \\<form action="/logout" method="post"><input type="submit" value="Logout" /></form>
-                            \\<form action="/quit" method="post"><input type="submit" value="Quit" /></form>
-                        , .{login.user.username.constSlice()});
-                        try req.respond(response_buffer.constSlice(), .{});
+                        const user = try Chirp.get_user(env, login.user_id);
+
+                        const txn = try env.txn();
+                        defer txn.abort();
+
+                        try write_posts(&res, txn, user, logged_in);
+
+                        try res.send();
                     } else {
-                        try req.respond(
-                            \\<a href="/register">Register</a>
-                            \\<a href="/login">Login</a>
-                            \\<form action="/quit" method="post"><input type="submit" value="Quit" /></form>
-                        , .{});
+                        try res.write("[GET] {s}", .{req.target});
+                        try res.send();
                     }
                 }
             }
             // api
             else {
-                if (std.mem.eql(u8, req.head.target, "/register")) {
+                if (std.mem.eql(u8, req.target, "/register")) {
                     // TODO: handle args not supplied
-                    const username = get_value(&req, "username").?;
-                    const password = get_value(&req, "password").?;
+                    const username = req.get_value("username").?;
+                    const password = req.get_value("password").?;
 
                     std.debug.print("New user: {s} {s}\n", .{ username, password });
-                    try register_user(&env, username, password);
-
-                    try redirect(&req, "/login");
-                } else if (std.mem.eql(u8, req.head.target, "/login")) {
+                    if (try Chirp.register_user(env, username, password)) {
+                        try res.redirect("/login");
+                    } else {
+                        try res.redirect("/register");
+                    }
+                    try res.send();
+                } else if (std.mem.eql(u8, req.target, "/login")) {
                     // TODO: handle args not supplied
-                    const username = get_value(&req, "username").?;
-                    const password = get_value(&req, "password").?;
+                    const username = req.get_value("username").?;
+                    const password = req.get_value("password").?;
 
                     std.debug.print("New login: {s} {s}\n", .{ username, password });
-                    if (login_user(&env, username, password)) |session_token| {
-                        var redirect_buffer = try std.BoundedArray(u8, 128).init(0);
-                        try std.fmt.format(redirect_buffer.writer(), "/user/{s}", .{username});
-
-                        var cookie_buffer = try std.BoundedArray(u8, 128).init(0);
-                        try std.fmt.format(cookie_buffer.writer(), "session_token={}; Secure; HttpOnly", .{session_token});
-
-                        try req.respond("", .{
-                            .status = .see_other,
-                            .extra_headers = &.{
-                                .{ .name = "Location", .value = redirect_buffer.constSlice() },
-                                .{ .name = "Set-Cookie", .value = cookie_buffer.constSlice() },
-                            },
-                        });
+                    if (Chirp.login_user(env, username, password)) |session_token| {
+                        res.status = .see_other;
+                        try res.add_header(
+                            "Location",
+                            .{ "/user/{s}", .{username} },
+                        );
+                        try res.add_header(
+                            "Set-Cookie",
+                            .{ "session_token={x}; Secure; HttpOnly", .{session_token} },
+                        );
+
+                        try res.send();
                     } else |err| {
                         std.debug.print("login_user err: {}\n", .{err});
-                        try redirect(&req, "/login");
+                        try res.redirect("/login");
+                        try res.send();
                     }
-                } else if (std.mem.eql(u8, req.head.target, "/logout")) {
+                } else if (std.mem.eql(u8, req.target, "/logout")) {
                     if (logged_in) |login| {
-                        try logout_user(&env, login.session_token);
-                        try req.respond("", .{
-                            .status = .see_other,
-                            .extra_headers = &.{
-                                .{ .name = "Location", .value = "/" },
-                                .{ .name = "Set-Cookie", .value = "session_token=deleted; Expires=Thu, 01 Jan 1970 00:00:00 GMT" },
-                            },
-                        });
+                        try Chirp.logout_user(env, login.session_token);
+
+                        try res.add_header(
+                            "Set-Cookie",
+                            .{"session_token=deleted; Expires=Thu, 01 Jan 1970 00:00:00 GMT"},
+                        );
+
+                        try res.redirect("/");
+                        try res.send();
                     }
-                } else if (std.mem.eql(u8, req.head.target, "/quit")) {
-                    try redirect(&req, "/");
+                } else if (std.mem.eql(u8, req.target, "/post")) {
+                    if (logged_in) |login| {
+                        const text = req.get_value("text").?;
+                        try Chirp.post(env, login.user_id, text);
+
+                        try res.redirect("/");
+                        try res.send();
+                    }
+                } else if (std.mem.eql(u8, req.target, "/quit")) {
+                    try res.redirect("/");
+                    try res.send();
                     break :accept;
+                } else if (std.mem.startsWith(u8, req.target, "/upvote/")) {
+                    const login = logged_in orelse return error.NotLoggedIn;
+
+                    const post_id_str = req.target[8..req.target.len];
+                    const post_id: PostId = @enumFromInt(try std.fmt.parseUnsigned(u64, post_id_str, 10));
+
+                    try Chirp.vote(env, post_id, login.user_id, .Up);
+
+                    if (req.get_header("Referer")) |ref| {
+                        try res.redirect(ref);
+                    }
+                    try res.send();
+                } else if (std.mem.startsWith(u8, req.target, "/downvote/")) {
+                    const login = logged_in orelse return error.NotLoggedIn;
+
+                    const post_id_str = req.target[10..req.target.len];
+                    const post_id: PostId = @enumFromInt(try std.fmt.parseUnsigned(u64, post_id_str, 10));
+
+                    try Chirp.vote(env, post_id, login.user_id, .Down);
+
+                    if (req.get_header("Referer")) |ref| {
+                        try res.redirect(ref);
+                    }
+                    try res.send();
+                } else if (std.mem.startsWith(u8, req.target, "/unupvote/")) {
+                    // TODO: maybe move to one /unvote?
+                    const login = logged_in orelse return error.NotLoggedIn;
+
+                    const post_id_str = req.target[10..req.target.len];
+                    const post_id: PostId = @enumFromInt(try std.fmt.parseUnsigned(u64, post_id_str, 10));
+
+                    try Chirp.unvote(env, post_id, login.user_id);
+
+                    if (req.get_header("Referer")) |ref| {
+                        try res.redirect(ref);
+                    }
+                    try res.send();
+                } else if (std.mem.startsWith(u8, req.target, "/undownvote/")) {
+                    const login = logged_in orelse return error.NotLoggedIn;
+
+                    const post_id_str = req.target[12..req.target.len];
+                    const post_id: PostId = @enumFromInt(try std.fmt.parseUnsigned(u64, post_id_str, 10));
+
+                    try Chirp.unvote(env, post_id, login.user_id);
+
+                    if (req.get_header("Referer")) |ref| {
+                        try res.redirect(ref);
+                    }
+                    try res.send();
                 } else {
-                    try req.respond(
-                        \\<p>POST</p>
-                    , .{});
+                    // try req.respond(
+                    //     \\<p>POST</p>
+                    // , .{});
+                    try res.write("<p>[POST] {s}</p>", .{req.target});
+                    try res.send();
                 }
             }
         }