diff options
| author | grm <grm@eyesin.space> | 2026-09-16 18:37:20 +0300 |
|---|---|---|
| committer | grm <grm@eyesin.space> | 2026-09-16 18:37:20 +0300 |
| commit | 6b6b5d2e35ff182a0732da245f4eb37c8afa0564 (patch) | |
| tree | f56960ae86c3c289f9a68e38ec01f1e3ff997466 /internal/store | |
| parent | 5119018feeaa22c47c0e91e15d3b9414dd6e0772 (diff) | |
| download | blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.tar.gz blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.tar.bz2 blogspace-6b6b5d2e35ff182a0732da245f4eb37c8afa0564.zip | |
Add an HTML mode to posts, page intros and announcements
Markdown is the default and unchanged; the editor's new Format switch
stores the text as raw HTML instead, put on the blog exactly as written.
Like the custom HTML module it is unsanitised on purpose: the escape
hatch for embeds, scripts and inline styles that Markdown cannot express.
The source column keeps holding the text in both modes and a `format`
column says how to read it, so the public templates and the feed still
print the stored `*_html`. The dashboard preview of HTML goes into a
sandboxed iframe rather than the page, because a superadmin edits other
people's blogs and their markup must never run on the dashboard origin.
Search snippets of HTML posts are cut from a tag-stripped copy.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/store')
| -rw-r--r-- | internal/store/pages.go | 17 | ||||
| -rw-r--r-- | internal/store/posts.go | 13 | ||||
| -rw-r--r-- | internal/store/sections.go | 15 | ||||
| -rw-r--r-- | internal/store/store.go | 16 |
4 files changed, 40 insertions, 21 deletions
diff --git a/internal/store/pages.go b/internal/store/pages.go index 3d5b02d..74da379 100644 --- a/internal/store/pages.go +++ b/internal/store/pages.go @@ -11,6 +11,7 @@ type Page struct { Title string IntroMD string IntroHTML string + Format string // FormatMarkdown | FormatHTML: how IntroMD is read NavOrder int ShowInNav bool // derived: the page has a menu entry IsHome bool @@ -18,11 +19,11 @@ type Page struct { PostCount int // filled by ListPages only } -const pageCols = `id, slug, title, intro_md, intro_html, nav_order, EXISTS (SELECT 1 FROM menu_items m WHERE m.page_id=pages.id), is_home, created_at` +const pageCols = `id, slug, title, intro_md, intro_html, format, nav_order, EXISTS (SELECT 1 FROM menu_items m WHERE m.page_id=pages.id), is_home, created_at` func scanPage(row interface{ Scan(...any) error }) (*Page, error) { var p Page - err := row.Scan(&p.ID, &p.Slug, &p.Title, &p.IntroMD, &p.IntroHTML, &p.NavOrder, &p.ShowInNav, &p.IsHome, &p.CreatedAt) + err := row.Scan(&p.ID, &p.Slug, &p.Title, &p.IntroMD, &p.IntroHTML, &p.Format, &p.NavOrder, &p.ShowInNav, &p.IsHome, &p.CreatedAt) if err != nil { return nil, wrap(err) } @@ -39,7 +40,7 @@ func (bs *BlogStore) ListPages(ctx context.Context) ([]Page, error) { var out []Page for rows.Next() { var p Page - if err := rows.Scan(&p.ID, &p.Slug, &p.Title, &p.IntroMD, &p.IntroHTML, &p.NavOrder, &p.ShowInNav, &p.IsHome, &p.CreatedAt, &p.PostCount); err != nil { + if err := rows.Scan(&p.ID, &p.Slug, &p.Title, &p.IntroMD, &p.IntroHTML, &p.Format, &p.NavOrder, &p.ShowInNav, &p.IsHome, &p.CreatedAt, &p.PostCount); err != nil { return nil, err } out = append(out, p) @@ -67,9 +68,9 @@ func (bs *BlogStore) CreatePage(ctx context.Context, p *Page) (*Page, error) { return nil, err } defer tx.Rollback(ctx) - created, err := scanPage(tx.QueryRow(ctx, `INSERT INTO pages (slug, title, intro_md, intro_html, nav_order) - VALUES ($1,$2,$3,$4,(SELECT coalesce(max(nav_order),-1)+1 FROM pages)) RETURNING `+pageCols, - p.Slug, p.Title, p.IntroMD, p.IntroHTML)) + created, err := scanPage(tx.QueryRow(ctx, `INSERT INTO pages (slug, title, intro_md, intro_html, format, nav_order) + VALUES ($1,$2,$3,$4,$5,(SELECT coalesce(max(nav_order),-1)+1 FROM pages)) RETURNING `+pageCols, + p.Slug, p.Title, p.IntroMD, p.IntroHTML, formatOrMD(p.Format))) if err != nil { return nil, err } @@ -89,8 +90,8 @@ func (bs *BlogStore) UpdatePage(ctx context.Context, p *Page) error { return err } defer tx.Rollback(ctx) - if _, err := tx.Exec(ctx, `UPDATE pages SET slug=$2, title=$3, intro_md=$4, intro_html=$5 WHERE id=$1`, - p.ID, p.Slug, p.Title, p.IntroMD, p.IntroHTML); err != nil { + if _, err := tx.Exec(ctx, `UPDATE pages SET slug=$2, title=$3, intro_md=$4, intro_html=$5, format=$6 WHERE id=$1`, + p.ID, p.Slug, p.Title, p.IntroMD, p.IntroHTML, formatOrMD(p.Format)); err != nil { return wrap(err) } if p.ShowInNav { diff --git a/internal/store/posts.go b/internal/store/posts.go index 1bffd51..0e01e9c 100644 --- a/internal/store/posts.go +++ b/internal/store/posts.go @@ -12,6 +12,7 @@ type Post struct { Title string BodyMD string BodyHTML string + Format string // FormatMarkdown | FormatHTML: how BodyMD is read Published bool CreatedAt time.Time UpdatedAt time.Time @@ -23,14 +24,14 @@ type Post struct { // The tags come along as two parallel arrays (names and slugs, both by name) // so every post query stays a single round trip; the alias p is the posts row. -const postCols = `p.id, p.page_id, p.slug, p.title, p.body_md, p.body_html, p.published, p.created_at, p.updated_at, g.slug, g.title, +const postCols = `p.id, p.page_id, p.slug, p.title, p.body_md, p.body_html, p.format, p.published, p.created_at, p.updated_at, g.slug, g.title, coalesce((SELECT array_agg(t.name ORDER BY t.name) FROM post_tags pt JOIN tags t ON t.id=pt.tag_id WHERE pt.post_id=p.id), '{}'), coalesce((SELECT array_agg(t.slug ORDER BY t.name) FROM post_tags pt JOIN tags t ON t.id=pt.tag_id WHERE pt.post_id=p.id), '{}')` func scanPost(row interface{ Scan(...any) error }) (*Post, error) { var p Post var names, slugs []string - err := row.Scan(&p.ID, &p.PageID, &p.Slug, &p.Title, &p.BodyMD, &p.BodyHTML, &p.Published, &p.CreatedAt, &p.UpdatedAt, &p.PageSlug, &p.PageTitle, &names, &slugs) + err := row.Scan(&p.ID, &p.PageID, &p.Slug, &p.Title, &p.BodyMD, &p.BodyHTML, &p.Format, &p.Published, &p.CreatedAt, &p.UpdatedAt, &p.PageSlug, &p.PageTitle, &names, &slugs) if err != nil { return nil, wrap(err) } @@ -139,8 +140,8 @@ func (bs *BlogStore) CreatePost(ctx context.Context, p *Post) (*Post, error) { p.CreatedAt = time.Now() } var id int64 - err := bs.db.QueryRow(ctx, `INSERT INTO posts (page_id, slug, title, body_md, body_html, published, created_at) VALUES ($1,$2,$3,$4,$5,$6,$7) RETURNING id`, - p.PageID, p.Slug, p.Title, p.BodyMD, p.BodyHTML, p.Published, p.CreatedAt).Scan(&id) + err := bs.db.QueryRow(ctx, `INSERT INTO posts (page_id, slug, title, body_md, body_html, format, published, created_at) VALUES ($1,$2,$3,$4,$5,$6,$7,$8) RETURNING id`, + p.PageID, p.Slug, p.Title, p.BodyMD, p.BodyHTML, formatOrMD(p.Format), p.Published, p.CreatedAt).Scan(&id) if err != nil { return nil, wrap(err) } @@ -148,8 +149,8 @@ func (bs *BlogStore) CreatePost(ctx context.Context, p *Post) (*Post, error) { } func (bs *BlogStore) UpdatePost(ctx context.Context, p *Post) error { - _, err := bs.db.Exec(ctx, `UPDATE posts SET page_id=$2, slug=$3, title=$4, body_md=$5, body_html=$6, published=$7, created_at=$8, updated_at=now() WHERE id=$1`, - p.ID, p.PageID, p.Slug, p.Title, p.BodyMD, p.BodyHTML, p.Published, p.CreatedAt) + _, err := bs.db.Exec(ctx, `UPDATE posts SET page_id=$2, slug=$3, title=$4, body_md=$5, body_html=$6, format=$7, published=$8, created_at=$9, updated_at=now() WHERE id=$1`, + p.ID, p.PageID, p.Slug, p.Title, p.BodyMD, p.BodyHTML, formatOrMD(p.Format), p.Published, p.CreatedAt) return wrap(err) } diff --git a/internal/store/sections.go b/internal/store/sections.go index 2f742f7..2d72ea4 100644 --- a/internal/store/sections.go +++ b/internal/store/sections.go @@ -12,6 +12,7 @@ type Section struct { Title string BodyMD string BodyHTML string + Format string // FormatMarkdown | FormatHTML: how BodyMD is read Placement string // <column>-<position>: left|main|right - top|bottom Style string // plain | note | warning Enabled bool @@ -24,11 +25,11 @@ type Section struct { func (s Section) Column() string { c, _, _ := strings.Cut(s.Placement, "-"); return c } func (s Section) Position() string { _, p, _ := strings.Cut(s.Placement, "-"); return p } -const sectionCols = `id, title, body_md, body_html, placement, style, enabled, sort_order, created_at, updated_at` +const sectionCols = `id, title, body_md, body_html, format, placement, style, enabled, sort_order, created_at, updated_at` func scanSection(row interface{ Scan(...any) error }) (*Section, error) { var s Section - err := row.Scan(&s.ID, &s.Title, &s.BodyMD, &s.BodyHTML, &s.Placement, &s.Style, &s.Enabled, &s.SortOrder, &s.CreatedAt, &s.UpdatedAt) + err := row.Scan(&s.ID, &s.Title, &s.BodyMD, &s.BodyHTML, &s.Format, &s.Placement, &s.Style, &s.Enabled, &s.SortOrder, &s.CreatedAt, &s.UpdatedAt) if err != nil { return nil, wrap(err) } @@ -66,14 +67,14 @@ func (bs *BlogStore) SectionByID(ctx context.Context, id int64) (*Section, error } func (bs *BlogStore) CreateSection(ctx context.Context, sec *Section) (*Section, error) { - return scanSection(bs.db.QueryRow(ctx, `INSERT INTO sections (title, body_md, body_html, placement, style, enabled, sort_order) - VALUES ($1,$2,$3,$4,$5,$6,(SELECT coalesce(max(sort_order),-1)+1 FROM sections)) RETURNING `+sectionCols, - sec.Title, sec.BodyMD, sec.BodyHTML, sec.Placement, sec.Style, sec.Enabled)) + return scanSection(bs.db.QueryRow(ctx, `INSERT INTO sections (title, body_md, body_html, format, placement, style, enabled, sort_order) + VALUES ($1,$2,$3,$4,$5,$6,$7,(SELECT coalesce(max(sort_order),-1)+1 FROM sections)) RETURNING `+sectionCols, + sec.Title, sec.BodyMD, sec.BodyHTML, formatOrMD(sec.Format), sec.Placement, sec.Style, sec.Enabled)) } func (bs *BlogStore) UpdateSection(ctx context.Context, sec *Section) error { - _, err := bs.db.Exec(ctx, `UPDATE sections SET title=$2, body_md=$3, body_html=$4, placement=$5, style=$6, enabled=$7, updated_at=now() WHERE id=$1`, - sec.ID, sec.Title, sec.BodyMD, sec.BodyHTML, sec.Placement, sec.Style, sec.Enabled) + _, err := bs.db.Exec(ctx, `UPDATE sections SET title=$2, body_md=$3, body_html=$4, format=$5, placement=$6, style=$7, enabled=$8, updated_at=now() WHERE id=$1`, + sec.ID, sec.Title, sec.BodyMD, sec.BodyHTML, formatOrMD(sec.Format), sec.Placement, sec.Style, sec.Enabled) return wrap(err) } diff --git a/internal/store/store.go b/internal/store/store.go index c8e97ea..30e5af0 100644 --- a/internal/store/store.go +++ b/internal/store/store.go @@ -18,6 +18,22 @@ import ( var ErrNotFound = errors.New("not found") var ErrConflict = errors.New("already exists") +// How a post, page intro or announcement source is read: Markdown (rendered +// and sanitised) or raw HTML (put on the blog as written). +const ( + FormatMarkdown = "markdown" + FormatHTML = "html" +) + +// formatOrMD is what gets stored: an unset Format means Markdown, so callers +// that predate the switch (the seed) keep working and the CHECK never fires. +func formatOrMD(f string) string { + if f == FormatHTML { + return FormatHTML + } + return FormatMarkdown +} + type Store struct { db *pgxpool.Pool // control database cluster *db.Cluster |
