ameer cfbda260fa fix: soft-reset UX + stale-cookie handling + leaderboard 'is_you' by id
Three coupled fixes from the first manual test pass:

1. Stale signed cookie no longer 500s. `rooms.me()` now raises KeyError
   when the participant row is gone (the previous code deref'd None and
   threw TypeError, caught by quiz.js's catch-all as 'link expired').
   `/api/session/{sid}/me` translates KeyError into 401 + delete_cookie,
   so the client falls back to the join form cleanly.
   Returning a JSONResponse directly because `raise HTTPException`
   discards Response.delete_cookie mutations (FastAPI middleware
   composes a fresh response on exception).

2. Reset is now a soft restart from the student's perspective. Before
   closing each student WS in `RoomManager.reset`, the server now sends
   a `{"type": "session_reset"}` message. The student SPA tears down
   local state and re-runs boot(); /me returns 401 (now that the
   participant is gone) and the join form renders without the user
   having to manually reload. The WS close handler suppresses its
   "Disconnected" screen during a reset to avoid a flash.

3. "You" highlight on the student leaderboard is now matched by id, not
   by name. `RoomManager.leaderboard()` accepts an optional
   `you_student_id` and stamps `is_you: true` on the matching entry only.
   No other students' ids leak over the wire (we still don't include
   `student_id` in the public top5 payload). quiz.js's renderBoard
   prefers `r.is_you` when any row is marked, falling back to name match
   for backward compatibility.

41/41 tests pass. Two new tests cover (a) the 401 + cookie-clear path
after reset and (b) `is_you` marking only the requesting student.
2026-05-02 22:40:52 +08:00
2026-05-02 02:54:34 +08:00

Live in-lecture quiz portal

FastAPI + WebSocket + SQLite quiz portal designed for ~40 students per class session. Single-process, in-memory room manager, vanilla HTML/JS front-end, Caddy in front for TLS.

Quick local run

python3 -m venv .venv
. .venv/bin/activate
pip install -e '.[dev]'
cp .env.example .env  # edit QUIZ_SECRET_KEY + QUIZ_ADMIN_PASSWORD
uvicorn app.main:app --host 127.0.0.1 --port 8001 --reload

Open http://127.0.0.1:8001/admin/, log in, create a quiz pool from a JSON pool file (see examples/pool_example.json for the schema), create a session, and share the join URL.

VPS deploy (one-shot)

On a fresh Ubuntu 24.04 LTS root SSH:

curl -fsSL https://gitea.ahkhan.me/apps/quiz/raw/branch/master/deploy/bootstrap.sh | bash

The bootstrap:

  1. apt-installs Caddy + Python venv tooling
  2. Creates a quiz system user (no shell, no SSH)
  3. Clones this repo to /opt/quiz
  4. Builds the venv and installs the app
  5. Generates QUIZ_SECRET_KEY, prompts for QUIZ_ADMIN_PASSWORD
  6. Drops the systemd unit and Caddyfile
  7. Starts both services
  8. Curl-checks 127.0.0.1:8001/healthz

After: quiz.ahkhan.me is live with auto-Let's-Encrypt cert. To override the domain or repo URL, set DOMAIN= or REPO_URL= in the environment before running the script.

Class-day workflow

  1. Provision Aliyun Intl HK ECS pay-as-you-go (ecs.t6-c2m1.large, Ubuntu 24.04 LTS).
  2. Point DNS A-record quiz.ahkhan.me at the new IP.
  3. SSH in as root, run the curl|bash one-liner above.
  4. Open quiz.ahkhan.me/admin/, log in, upload the week's pool JSON, create a session.
  5. Share the QR / join URL with the class.
  6. After class: scp root@<ip>:/opt/quiz/quiz.db ./backups/quiz-YYYY-MM-DD.db
  7. Destroy the instance.

Quiz pool files

Real pool JSON files contain answer keys and must not be committed to this repo. .gitignore excludes examples/*_pool.json (only examples/pool_example.json may be tracked). Author pools elsewhere (e.g., your course-material directory) and upload at runtime via the admin UI.

Tests

pytest -q
pytest --cov=app

For the WebSocket adversarial stress harness (Node.js + Playwright, runs in a tmux loop), see tests/stress/README.md.

Spec

SPEC.md documents the locked v1.0 design (state machine, scoring, identity flow, all WS message types).

Description
No description provided
Readme 226 KiB
Languages
Python 43.7%
JavaScript 33%
CSS 19.3%
Shell 3.1%
Smarty 0.6%
Other 0.3%