aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/server.go
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-18 19:34:35 +0300
committergrm <grm@eyesin.space>2026-09-18 19:34:35 +0300
commit96336d8bacd2bdf81acf9a18e2fe57be9d4e9b4f (patch)
treee7851ddadf2ed776ab24a1bad4d446b7c48567db /internal/web/server.go
parent63f9fdff6e5bdf6333a4b7813ebeb5b797838b6d (diff)
downloadblogspace-96336d8bacd2bdf81acf9a18e2fe57be9d4e9b4f.tar.gz
blogspace-96336d8bacd2bdf81acf9a18e2fe57be9d4e9b4f.tar.bz2
blogspace-96336d8bacd2bdf81acf9a18e2fe57be9d4e9b4f.zip
Show a live preview of the header on the Design tab's Menu card
The menu options had grown to a dozen switches with nothing to look at but the blog after a save. A new POST /b/{sub}/design/preview reads the form as a save would and renders the header alone — the real blog.css and theme CSS, the modules in their order, the menu as edited — into a sandboxed frame that refreshes shortly after every change, with a Wide screen / Phone toggle. Nothing is stored. The frame keeps the dashboard's origin (allow-same-origin, no scripts) so the blog's logo and fonts, linked through /b/<sub>/media since the root host's /media is the root blog's, get the session cookie; that is safe because no header module is owner HTML. The frame runs no scripts, so the page's own script folds the menu in it the way the blog does. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/server.go')
-rw-r--r--internal/web/server.go3
1 files changed, 2 insertions, 1 deletions
diff --git a/internal/web/server.go b/internal/web/server.go
index f5d32d1..e3fef6e 100644
--- a/internal/web/server.go
+++ b/internal/web/server.go
@@ -373,6 +373,7 @@ type view struct {
RootURL string
Path string
Lang string // i18n code, also the <html lang>
+ Media string // where the blog's files are served: /media, or /b/<sub>/media for the design preview on the root host
Data map[string]any
}
@@ -384,7 +385,7 @@ func (s *Server) renderStatus(w http.ResponseWriter, r *http.Request, status int
if data == nil {
data = map[string]any{}
}
- v := view{User: currentUser(r), Blog: currentBlog(r), RootURL: s.cfg.RootURL(), Path: r.URL.Path, Lang: s.lang(r), Data: data}
+ v := view{User: currentUser(r), Blog: currentBlog(r), RootURL: s.cfg.RootURL(), Path: r.URL.Path, Lang: s.lang(r), Media: "/media", Data: data}
if v.User != nil {
v.CSRF = auth.CSRFToken(s.cfg.JWTSecret, v.User.ID, v.User.TokenVersion)
}