<feed xmlns='http://www.w3.org/2005/Atom'>
<title>blogspace/internal/web/handlers_blog.go, branch master</title>
<subtitle>blogspace</subtitle>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/'/>
<entry>
<title>Revert "Special pages: a gallery page of the blog's images"</title>
<updated>2026-09-18T11:36:17+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T11:35:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=7ac90f8e99dbf763b0fe04a17d7eef19dd22cae8'/>
<id>7ac90f8e99dbf763b0fe04a17d7eef19dd22cae8</id>
<content type='text'>
This reverts commit 0fc470a. The feature was not wanted. Migration
00013 stays on disk because databases have already run it (goose refuses
a missing applied migration); 00014 drops the column and table it added.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
This reverts commit 0fc470a. The feature was not wanted. Migration
00013 stays on disk because databases have already run it (goose refuses
a missing applied migration); 00014 drops the column and table it added.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Special pages: a gallery page of the blog's images</title>
<updated>2026-09-18T11:32:22+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T11:32:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=0fc470a8d588cac1a51cc4b3e1a2237dc56041c9'/>
<id>0fc470a8d588cac1a51cc4b3e1a2237dc56041c9</id>
<content type='text'>
A page's kind says what it shows between its intro and outro: posts,
as before, or something special. The first special kind is a gallery —
every image in the files library as a masonry wall (CSS columns, no
script), newest first, each linked to its full-size file. The page form
lists the library's images with a Hide tick per picture; exclusions are
stored (page_hidden_files) rather than inclusions so a new upload shows
up without editing the page, and the design's own pictures — logo,
favicon, header and background image — are never shown. Special pages
keep the page chrome (menu, announcements, home, ordering) but hold no
posts: the post forms skip them and a forced page id is refused.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
A page's kind says what it shows between its intro and outro: posts,
as before, or something special. The first special kind is a gallery —
every image in the files library as a masonry wall (CSS columns, no
script), newest first, each linked to its full-size file. The page form
lists the library's images with a Hide tick per picture; exclusions are
stored (page_hidden_files) rather than inclusions so a new upload shows
up without editing the page, and the design's own pictures — logo,
favicon, header and background image — are never shown. Special pages
keep the page chrome (menu, announcements, home, ordering) but hold no
posts: the post forms skip them and a forced page id is refused.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Security: Throttle search, cap its words and give the query a deadline</title>
<updated>2026-09-18T10:50:42+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T10:50:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=c3026c34b042cc044cddfc5674d5f5ad69bb845d'/>
<id>c3026c34b042cc044cddfc5674d5f5ad69bb845d</id>
<content type='text'>
/search runs an unindexed regular-expression scan over every published
post, built from up to fifty ".*"-joined words, for anyone who asks —
the cheapest way for a bot to keep Postgres busy. Queries are now cut
at eight words (more never improve the answer), each address gets
thirty searches and then thirty a minute, and the statement is
cancelled after five seconds; a timeout reads as no results and is
logged, rather than a 500.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
/search runs an unindexed regular-expression scan over every published
post, built from up to fifty ".*"-joined words, for anyone who asks —
the cheapest way for a bot to keep Postgres busy. Queries are now cut
at eight words (more never improve the answer), each address gets
thirty searches and then thirty a minute, and the statement is
cancelled after five seconds; a timeout reads as no results and is
logged, rather than a 500.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Security: Clamp page numbers so a huge ?p= cannot overflow the offset</title>
<updated>2026-09-18T10:49:53+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T10:49:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=c47397ac1e2ceafafe2be3cdec86366dd396ed6f'/>
<id>c47397ac1e2ceafafe2be3cdec86366dd396ed6f</id>
<content type='text'>
?p=9223372036854775807 made (n-1)*per wrap negative, Postgres refused
the OFFSET and every listing, tag and search page answered 500 — a
line in the log per request for any bot fuzzing query strings. Page
numbers now stop at 100000.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
?p=9223372036854775807 made (n-1)*per wrap negative, Postgres refused
the OFFSET and every listing, tag and search page answered 500 — a
line in the log per request for any bot fuzzing query strings. Page
numbers now stop at 100000.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Pair headed gizmo announcements two to a row, split by text length</title>
<updated>2026-09-18T09:10:33+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T09:10:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=19353a51c869f4b24ef2253d856084b6e6728048'/>
<id>19353a51c869f4b24ef2253d856084b6e6728048</id>
<content type='text'>
Headed gizmo boxes used to share a row equally, up to three of them.
Now placeNotices pairs consecutive ones in the main column and gives the
pair one of the fixed splits — 25/75, 33/67, 50/50, 67/33, 75/25 —
nearest the ratio of the text each shows, so the wordier box gets the
room. The bases add up to 90% so a third box never joins the row, and a
side column, too narrow for two, stacks them.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Headed gizmo boxes used to share a row equally, up to three of them.
Now placeNotices pairs consecutive ones in the main column and gives the
pair one of the fixed splits — 25/75, 33/67, 50/50, 67/33, 75/25 —
nearest the ratio of the text each shows, so the wordier box gets the
room. The bases add up to 90% so a third box never joins the row, and a
side column, too narrow for two, stacks them.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Add switches to keep announcements off a page or off post pages</title>
<updated>2026-09-18T08:22:25+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-18T08:22:25+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=ac125593efe689fabd1e48a7023249c8973698b8'/>
<id>ac125593efe689fabd1e48a7023249c8973698b8</id>
<content type='text'>
Announcements showed on every public page. Now each page has a "Show
announcements on this page" checkbox (pages.show_notices, on by default)
that covers the page and its posts, and the Design tab's Content section
has "Show announcements on post pages" (theme.post_notices, on by default)
for bloggers who want notices only on listings, not while reading a post.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Announcements showed on every public page. Now each page has a "Show
announcements on this page" checkbox (pages.show_notices, on by default)
that covers the page and its posts, and the Design tab's Content section
has "Show announcements on post pages" (theme.post_notices, on by default)
for bloggers who want notices only on listings, not while reading a post.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Add post summaries, featured images and a page outro</title>
<updated>2026-09-17T13:42:15+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-17T13:42:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=d0601f06c080a8eb8d781fdd0e3338cd7ed42690'/>
<id>d0601f06c080a8eb8d781fdd0e3338cd7ed42690</id>
<content type='text'>
Recreating gizmolab.net as a blog showed three things the design system
could not express, all of them ordinary blog features:

- Listings can show a summary and a "Read more" link instead of the whole
  post (theme.list_style). The summary is the source up to &lt;!--more--&gt;;
  without the marker a Markdown post is cut at a block boundary after 70
  words (never inside a code fence) and an HTML post is shown whole, since
  cutting hand-written markup blind would leave tags open. Computed at
  render time (Post.Excerpt/HasMore), nothing new is stored.
- A post can carry a featured image (posts.image, a library file that is
  unset when the file is deleted): a thumbnail floated beside the entry on
  listings, and on the post page above or below the text, or not at all,
  as theme.post_image says. The picker is the design page's imagepick; its
  library panel moves out of design.html into partials/imagelib.html so
  both forms share it — which also removes a stale pickAction call the
  design form's click handler would have hit.
- A page can have a closing text after its posts (pages.outro_md/html), in
  the intro's format: the per-page counterpart of the blog-wide "after the
  posts" module, for a home page that ends in a site map or a widget. The
  editor partial takes formatof to share another editor's Format row, and
  its upload field is now &lt;name&gt;_file so two editors fit in one form.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Recreating gizmolab.net as a blog showed three things the design system
could not express, all of them ordinary blog features:

- Listings can show a summary and a "Read more" link instead of the whole
  post (theme.list_style). The summary is the source up to &lt;!--more--&gt;;
  without the marker a Markdown post is cut at a block boundary after 70
  words (never inside a code fence) and an HTML post is shown whole, since
  cutting hand-written markup blind would leave tags open. Computed at
  render time (Post.Excerpt/HasMore), nothing new is stored.
- A post can carry a featured image (posts.image, a library file that is
  unset when the file is deleted): a thumbnail floated beside the entry on
  listings, and on the post page above or below the text, or not at all,
  as theme.post_image says. The picker is the design page's imagepick; its
  library panel moves out of design.html into partials/imagelib.html so
  both forms share it — which also removes a stale pickAction call the
  design form's click handler would have hit.
- A page can have a closing text after its posts (pages.outro_md/html), in
  the intro's format: the per-page counterpart of the blog-wide "after the
  posts" module, for a home page that ends in a site map or a widget. The
  editor partial takes formatof to share another editor's Format row, and
  its upload field is now &lt;name&gt;_file so two editors fit in one form.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Merge the Layout and Design tabs into one form with a single Save</title>
<updated>2026-09-16T16:10:13+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-16T16:10:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=4a6f987bf7f9d73e9dd33d225fd2d73e9bf69a88'/>
<id>4a6f987bf7f9d73e9dd33d225fd2d73e9bf69a88</id>
<content type='text'>
The look and the layout of a blog were split over two tabs that cross-linked
each other, and the Layout tab saved every toggle, move and add straight
away through a dozen tiny forms. Now one Design tab holds it all, organised
by part of the blog (colours &amp; fonts, header, menu, content, side columns,
footer, logo &amp; icon) behind a sticky side index, and one Save stores the
theme, every module and the menu atomically (BlogStore.SaveDesign). Module
settings are edited inline; Discard changes throws the edits away; a
validation error shows the form again exactly as it was sent.

The image pickers no longer render the whole library four times over: a
select of the newest images, and a script-driven panel that fetches the
library page by page (GET /files as JSON) with lazy thumbnails.

New options: posts per page, site title size, footer alignment.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The look and the layout of a blog were split over two tabs that cross-linked
each other, and the Layout tab saved every toggle, move and add straight
away through a dozen tiny forms. Now one Design tab holds it all, organised
by part of the blog (colours &amp; fonts, header, menu, content, side columns,
footer, logo &amp; icon) behind a sticky side index, and one Save stores the
theme, every module and the menu atomically (BlogStore.SaveDesign). Module
settings are edited inline; Discard changes throws the edits away; a
validation error shows the form again exactly as it was sent.

The image pickers no longer render the whole library four times over: a
select of the newest images, and a script-driven panel that fetches the
library page by page (GET /files as JSON) with lazy thumbnails.

New options: posts per page, site title size, footer alignment.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Add an HTML mode to posts, page intros and announcements</title>
<updated>2026-09-16T15:37:20+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-16T15:37:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=6b6b5d2e35ff182a0732da245f4eb37c8afa0564'/>
<id>6b6b5d2e35ff182a0732da245f4eb37c8afa0564</id>
<content type='text'>
Markdown is the default and unchanged; the editor's new Format switch
stores the text as raw HTML instead, put on the blog exactly as written.
Like the custom HTML module it is unsanitised on purpose: the escape
hatch for embeds, scripts and inline styles that Markdown cannot express.

The source column keeps holding the text in both modes and a `format`
column says how to read it, so the public templates and the feed still
print the stored `*_html`. The dashboard preview of HTML goes into a
sandboxed iframe rather than the page, because a superadmin edits other
people's blogs and their markup must never run on the dashboard origin.
Search snippets of HTML posts are cut from a tag-stripped copy.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Markdown is the default and unchanged; the editor's new Format switch
stores the text as raw HTML instead, put on the blog exactly as written.
Like the custom HTML module it is unsanitised on purpose: the escape
hatch for embeds, scripts and inline styles that Markdown cannot express.

The source column keeps holding the text in both modes and a `format`
column says how to read it, so the public templates and the feed still
print the stored `*_html`. The dashboard preview of HTML goes into a
sandboxed iframe rather than the page, because a superadmin edits other
people's blogs and their markup must never run on the dashboard origin.
Search snippets of HTML posts are cut from a tag-stripped copy.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
<entry>
<title>Add a search box module and a search page</title>
<updated>2026-09-15T21:00:57+00:00</updated>
<author>
<name>grm</name>
<email>grm@eyesin.space</email>
</author>
<published>2026-09-15T21:00:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.eyesin.space/blogspace/commit/?id=839343a3108734a15e331b542a20ed9c77ef582b'/>
<id>839343a3108734a15e331b542a20ed9c77ef582b</id>
<content type='text'>
Readers had no way to find a post. The new "search" module goes in the
header (a bar under the nav) or a side column (a box with a heading) and
is a plain GET form to /search, so it works without JavaScript. The
results page lists the published posts of every page whose title or
Markdown body matches the query — case-insensitive, each word literal,
spaces meaning "anything in between", in order — as title, date and a
short snippet with the match marked, 20 per page.

modules.kind is a CHECK constraint, so a migration widens it; "search"
becomes a reserved page slug so the literal route keeps winning over
/{page}. moduleHasSettings now takes the module: a header search box
has no heading, hence nothing to edit.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Readers had no way to find a post. The new "search" module goes in the
header (a bar under the nav) or a side column (a box with a heading) and
is a plain GET form to /search, so it works without JavaScript. The
results page lists the published posts of every page whose title or
Markdown body matches the query — case-insensitive, each word literal,
spaces meaning "anything in between", in order — as title, date and a
short snippet with the match marked, 20 per page.

modules.kind is a CHECK constraint, so a migration widens it; "search"
becomes a reserved page slug so the literal route keeps winning over
/{page}. moduleHasSettings now takes the module: a header search box
has no heading, hence nothing to edit.

Co-Authored-By: Claude Opus 5 &lt;noreply@anthropic.com&gt;
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
</pre>
</div>
</content>
</entry>
</feed>
