Skip to content

The Kary screen

Nerthus.Core (until cutover). This page describes the frozen system that runs today and is deleted at cutover. Replaced by: not yet written.

Kary is the register of sanctions: when each was recorded, how large it was, who signed it, and whether its contents still exist. The contents themselves are sealed, and this screen opens them only if you are holding the key.

https://dev-astral.nerthus.pl/#/kary

The list is the open part, and it is open on purpose

Every record has two halves and both are encrypted. What the register lists is the part that was never sealed: the day, the size band, which signing key was used, how many readers the record was addressed to, and whether the contents have been destroyed. Whoever runs the machines can see that much anyway, so hiding it on this screen would buy nothing.

The subject column is blinded. A record is filed under a tag rather than a nick, and the nick is inside the sealed half. Search still works, and it works in the direction that costs one step instead of a sweep: you type a nick and the screen turns it into the tag. That needs the second value from the Moderacja screen's Klucz pane, and the screen tells you so when it is missing.

Narrow the list by day, and by epoch. The epoch box takes a whole number - anything else is refused, because that is what the tool behind it accepts.

Open one record

Click a row. The address carries it, so a link to one record is a link somebody else can open:

https://dev-astral.nerthus.pl/#/kary?wpis=01J9Z3M7QK2F8B6T4V0XH5RSDN

Without a key loaded, a sealed field says so and offers you the way to fix it. It does not spin. A screen that says "loading" over something that is never going to arrive is lying to you.

With a key loaded, the record opens in two steps:

  1. The tally opens first. That is the accounting half - what the record counted.
  2. The body opens when you ask for it. That is the half with the reason, the note and the evidence. Opening it is something you decide to do, so you know afterwards that you looked.

Nothing is drawn as genuine before its signature has been checked. The verdict is settled first and the text is shown wearing it, because a tick this screen had not earned would be worse than no tick at all on the one surface whose job is to make a tampered register visible.

A destroyed body is reported as destroyed, not as an error and not as a missing key. The keys to those bytes were deleted deliberately and provably, and nobody will read them again.

When something does go wrong, the screen names which of four things happened rather than showing one banner. The four send you to four different people, and collapsing them would lose exactly the part you needed.

What this screen does not do

It does not create a sanction. There is no compose form here.

It does not decrypt the whole register to sort a column. Opening every record to fill in a column nobody asked for would be a great deal of work for a heading. The table stays the open index; the plaintext is in the record you opened.

It does not decide anything. Who may issue a kara and on what grounds is the Rada's, written in the regulation corpus - the Regulamin screen is where you read the text that was in force on the day, and the points a record cites.

Four addresses were retired when the register became one page with filters. They still work:

Old address Where it lands
#/kary/osoba/<nick> the register, narrowed to that subject
#/kara/<id> the register, with that record open
#/kary/nowa the register
#/kary/przeglad the register

A link pasted into a report is not the sort of thing to break for a tidy-up.