aboutsummaryrefslogtreecommitdiffstats
path: root/internal
Commit message (Collapse)AuthorAgeFilesLines
* Keep the header rule on phonesHEADmastergrm2026-09-191-3/+10
| | | | | | | | | | | | | | The rule beside the title or logo was hidden under 700px so a long title could wrap, which left a small logo alone with empty space either side. The row is a flexbox on phones now: the brand wraps only when it must and the rules fill whatever is left, so a short title or a logo keeps its rule and a long title still wraps a word at a time and takes the whole row. Browsers without flexbox keep the table with a wrapping brand. A spread menu's links no longer justify their own words when one wraps inside. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Remove the menu foldgrm2026-09-197-213/+21
| | | | | | | | | | | The header menu no longer folds into a ☰ button: the nav_fold and nav_fold_label options, Layout.Fold/BurgerAt, the burger markup and its checkbox, the fold rules in blog.css and the measuring script on the public page are gone, and the Design tab's preview only sizes its frame again. The public page runs no script of its own once more. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Show a live preview of the header on the Design tab's Menu cardgrm2026-09-1810-14/+160
| | | | | | | | | | | | | | | | | | The menu options had grown to a dozen switches with nothing to look at but the blog after a save. A new POST /b/{sub}/design/preview reads the form as a save would and renders the header alone — the real blog.css and theme CSS, the modules in their order, the menu as edited — into a sandboxed frame that refreshes shortly after every change, with a Wide screen / Phone toggle. Nothing is stored. The frame keeps the dashboard's origin (allow-same-origin, no scripts) so the blog's logo and fonts, linked through /b/<sub>/media since the root host's /media is the root blog's, get the session cookie; that is safe because no header module is owner HTML. The frame runs no scripts, so the page's own script folds the menu in it the way the blog does. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Fold the header menu into a button when its links do not fitgrm2026-09-187-16/+205
| | | | | | | | | | | | | | | | | | A long menu wrapped onto two or three lines on phones and narrow windows. With the new Design switch the header menu folds into a ☰ button (an icon, the word Menu, or both) carried by the title or logo block just above it, at the right end of its row, or by the menu bar when nothing is above it; the button opens the links as a stacked list with the search box on top. The open/closed state is a hidden checkbox and the button its label, so opening needs no script and works in old browsers. Whether to fold is decided by a small inline script — any link on a second line means the menu does not fit — re-checked on resize; without it blog.css folds on phones only, and browsers too old for that keep the wrapping menu. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add menu link size, spacing, a current-page mark and a spread alignmentgrm2026-09-185-16/+70
| | | | | | | | | | | | Size and spacing selects, a choice of how the current page's link is marked (underlined as before, bold, boxed or not at all) and a fourth alignment that spreads the header's links across the bar. Alignment joins the other menu classes on the body, so the theme CSS no longer sets it; spread is justified text with a full-width last line, which old browsers lay out too, and stays out of the column menus. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Make the menu link styles switches that combinegrm2026-09-186-24/+86
| | | | | | | | | | | | | The one "Link style" select (normal, uppercase, plain) could not give uppercase links without the bold, or underlined bold links. Bold, uppercase and the underline (never, on hover, always) are now separate switches, drawn by blog.css from body classes (Theme.NavClass) so the theme CSS only colours the links. A stored nav_style is mapped onto the switches when the theme is read and dropped on the next save; themes without either keep the bold, underline-on-hover look blog.css always had. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Revert "Special pages: a gallery page of the blog's images"grm2026-09-1816-270/+59
| | | | | | | | | This reverts commit 0fc470a. The feature was not wanted. Migration 00013 stays on disk because databases have already run it (goose refuses a missing applied migration); 00014 drops the column and table it added. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Special pages: a gallery page of the blog's imagesgrm2026-09-1816-44/+286
| | | | | | | | | | | | | | | | A page's kind says what it shows between its intro and outro: posts, as before, or something special. The first special kind is a gallery — every image in the files library as a masonry wall (CSS columns, no script), newest first, each linked to its full-size file. The page form lists the library's images with a Hide tick per picture; exclusions are stored (page_hidden_files) rather than inclusions so a new upload shows up without editing the page, and the design's own pictures — logo, favicon, header and background image — are never shown. Special pages keep the page chrome (menu, announcements, home, ordering) but hold no posts: the post forms skip them and a forced page id is refused. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Give the double-dotted title rule the same gap as the othersgrm2026-09-181-1/+1
| | | | | | | | | | The second dotted row is positioned 5px inside the title's padding, so with dots2 the text sat 5px closer to the rule than with line, dots or stripes. The padding grows by that amount (0.7em for browsers without calc). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Keep template errors out of production responsesgrm2026-09-181-1/+7
| | | | | | | | | | A failed render printed the error into the page: template names, the failing field, sometimes a piece of the data. In production that is now a plain "Something went wrong" with the detail in the log; in dev mode it stays on the page, escaped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Throttle search, cap its words and give the query a deadlinegrm2026-09-184-10/+30
| | | | | | | | | | | | | /search runs an unindexed regular-expression scan over every published post, built from up to fifty ".*"-joined words, for anyone who asks — the cheapest way for a bot to keep Postgres busy. Queries are now cut at eight words (more never improve the answer), each address gets thirty searches and then thirty a minute, and the statement is cancelled after five seconds; a timeout reads as no results and is logged, rather than a 500. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Clamp page numbers so a huge ?p= cannot overflow the offsetgrm2026-09-182-4/+14
| | | | | | | | | | ?p=9223372036854775807 made (n-1)*per wrap negative, Postgres refused the OFFSET and every listing, tag and search page answered 500 — a line in the log per request for any bot fuzzing query strings. Page numbers now stop at 100000. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Send security headers; refuse to frame the dashboardgrm2026-09-182-3/+62
| | | | | | | | | | | | | | | Pages carried no X-Content-Type-Options, no Referrer-Policy, and the dashboard could be framed by any site (clickjacking a superadmin's delete buttons). Every response now says nosniff and strict-origin-when-cross-origin, and the management paths on the root host add X-Frame-Options: DENY plus a CSP of frame-ancestors, base-uri, form-action and object-src — the directives that do not touch the dashboard's inline scripts, which are a product constraint. Blog pages get no framing rule: they are the owner's content and may be embedded on purpose. HSTS moves into the same helper. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Refuse form posts a browser marks as coming from another origingrm2026-09-183-0/+44
| | | | | | | | | | | | | | Every blog is a subdomain of the root domain, which makes a blog page "same-site" to the dashboard: SameSite=Lax sends the session cookie with a form a blog's custom HTML submits to example.com. The HMAC token already stops those, but the login form had nothing (login CSRF), and a second, independent check costs one header lookup. A POST whose Sec-Fetch-Site is cross-site or same-site is now refused in guardPOST and on login; old browsers without the header keep working under the token alone. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Check the CSRF token on logoutgrm2026-09-182-0/+18
| | | | | | | | | | | /logout was the one management POST without the token. A blog lives on a subdomain of the root domain, which is same-site, so SameSite=Lax does not keep the cookie off a form a blog page submits: any blogger's custom HTML could log the superadmin out at will. The logout form already carried _csrf; the handler now checks it through guardPOST. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Reject backslashes in post-login redirect targetsgrm2026-09-182-2/+15
| | | | | | | | | safeNext only refused a second leading slash, but browsers treat "/\evil.com" as "//evil.com", so ?next= was still an open redirect after login. No path of ours contains a backslash, so any one is refused. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Add HTTPS and TRUST_PROXY settingsgrm2026-09-186-22/+92
| | | | | | | | | | | | | | | | | | The app only ever speaks plain HTTP, so it could not know the site was served over TLS: generated links were http:// (the /webadmin bounce from a blog host sent the login page over http), the session cookie was never Secure and nothing sent HSTS. HTTPS=true fixes all three; ClearSessionCookie now uses the same attributes as the set, since a browser only replaces a cookie whose Secure flag matches. TRUST_PROXY=true makes the client address the last X-Forwarded-For entry — the one our proxy appended — so throttling and the log see real addresses instead of the proxy's; earlier entries are whatever the client sent and are ignored. Production startup warns when HTTPS is off. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Cap the login body and log failed loginsgrm2026-09-182-0/+24
| | | | | | | | | | | POST /webadmin is the one form outside guardPOST, so nothing bounded its body: a multipart login could park 32 MB in memory or temp files per request. It now reads at most 64 KB. Wrong passwords are logged with the username and client address so an attack shows up in the log (fail2ban can read it) instead of being invisible. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Throttle login attempts with a per-address, per-account token bucketgrm2026-09-185-1/+141
| | | | | | | | | | | | Nothing stopped a bot from trying passwords against /webadmin as fast as bcrypt would go. A small in-memory limiter (stdlib only, one process) now refuses a login with 429 once an address, or an account, has made ten attempts, and lets one more through every six seconds; keying on both means many addresses guessing one account are throttled too. Refusals are logged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Security: Serve /media single-range onlygrm2026-09-182-0/+26
| | | | | | | | | | | | http.ServeContent honours any number of comma-separated ranges and chunkReader caches one 512 KiB slice, so a Range header alternating between two chunks costs a substring() query per range: one 1 MB header could make Postgres read tens of gigabytes for a single anonymous request. Browsers and download managers only ever send one range, so a multi-range header is dropped and the file served whole. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Pair headed gizmo announcements two to a row, split by text lengthgrm2026-09-187-11/+106
| | | | | | | | | | | | Headed gizmo boxes used to share a row equally, up to three of them. Now placeNotices pairs consecutive ones in the main column and gives the pair one of the fixed splits — 25/75, 33/67, 50/50, 67/33, 75/25 — nearest the ratio of the text each shows, so the wordier box gets the room. The bases add up to 90% so a third box never joins the row, and a side column, too narrow for two, stacks them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Give the rule under titles more room above and belowgrm2026-09-181-2/+3
| | | | | | | | | | The rule sat 0.25em under the title text with the date or body starting 0.1em beneath it. Titles with a rule now keep 0.4em above it and 0.7em below; the stripes, being the ::after, get their gap from its margin instead of the padding so they sit as evenly as the borders. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Send a blogger to their own dashboard from another blog's /webadmingrm2026-09-181-9/+21
| | | | | | | | | | | Typing /webadmin on someone else's blog while logged in (or logging in from there) landed on /b/<their-sub>/ and a 403 "This is not your blog." Both login paths now go through landing(), which swaps a next that points at a blog the user cannot manage for /dashboard; superadmins keep going where they asked. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add switches to keep announcements off a page or off post pagesgrm2026-09-1810-33/+77
| | | | | | | | | | | Announcements showed on every public page. Now each page has a "Show announcements on this page" checkbox (pages.show_notices, on by default) that covers the page and its posts, and the Design tab's Content section has "Show announcements on post pages" (theme.post_notices, on by default) for bloggers who want notices only on listings, not while reading a post. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add Fira Code as a built-in font choicegrm2026-09-175-4/+113
| | | | | | | | | The variable face (v6.2, OFL, licence alongside) is bundled in static/ and declared as @font-face whenever the text or heading font is "fira"; the stack falls back through Fira Mono, Menlo and Consolas to Courier. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Make the blog text a little smaller and tightergrm2026-09-171-4/+4
| | | | | | | | Normal is 16px on 1.5 lines (was 17px on 1.55), small 14px and large 18px, matching the owner's reference site. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add a page width: cap the columns at so many pixels, centred or at the leftgrm2026-09-174-11/+93
| | | | | | | | | | | The header's and footer's text follows the cap when they already follow the main column; their backgrounds stay full width. The inset that lines them up with the main column is now exact — the wrap's 1em plus the column's share of the wrap's content box — and, with a page width, uses min() so it is right whether the page or the screen is the narrower. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Keep the tags off the title when a post shows no dategrm2026-09-171-1/+2
| | | | | | | | | The tags' negative top margin tucks them under the date line; without a date (hidden on the post, or blog-wide) it pulled them into the title. It now applies only when a date precedes them. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Replace the colons title rule with a double dotted bordergrm2026-09-175-9/+10
| | | | | | | | | A row of ":" characters did not read as a rule. "Double dots" is what the reference site does: the 3px dotted border and an absolutely positioned ::after carrying a second one 2px above it. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add a colons kind to the rule under titles, and stop its label wrappinggrm2026-09-175-5/+13
| | | | | | | | | | The design form's hint on "Rule under titles" wrapped to three lines and pushed the select below its neighbours; it is a note under the row now. "Colons" is a row of ":" (a long string in an ::after, clipped to the title's width), the look of the reference site's dotted borders in text. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Let a post hide its dategrm2026-09-178-19/+30
| | | | | | | | | A checkbox on the post form (posts.hide_date) overriding the theme's "show the date on posts" for that post alone: listings, the post page and search results leave the date out; the feed keeps its pubDate. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add a rule under page and post titles, and tags shown with a # in frontgrm2026-09-1710-16/+74
| | | | | | | | | | | | Two Design tab options in the Posts section. The title rule reuses the header rule's kinds (line, dots, stripes): a body class blog.css draws from — width and style only, so the theme CSS's link colour is not reset — ending at a floated thumbnail instead of running under it. The tag hash is applied everywhere tags are listed: under posts, in both tag modules and in the tag page's title. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add custom fonts: upload WOFF2/WOFF/TTF/OTF files and pick them on the ↵grm2026-09-1714-55/+196
| | | | | | | | | | | | | | | Design tab Fonts become a file kind of their own (sniffed from the bytes like images, served inline from /media), and the theme gets custom_font and custom_heading_font: a chosen file is declared as @font-face and put first in the stack, the built-in Font / Heading font choice behind it as the fallback, so there is no "custom" enum value and no invalid state. The pickers are plain selects with an upload input, no script. Fonts uploaded before this are reclassified by the migration. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add a header rule beside the title or logo, and plain menu linksgrm2026-09-176-13/+106
| | | | | | | | | | | | | | gizmolab's header is a logo with a striped rule filling the rest of the row, and a menu of plain underlined links under it; nothing in the Design tab could draw either. The rule (line, dots or stripes) is a theme option drawn in the header text colour beside the title and logo modules — on both sides when the header is centred — as table cells, so it is as tall as the brand and old browsers lay it out the same; it is hidden on phones so a long title can wrap. The menu's link style gains "plain, underlined" next to bold and uppercase. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Keep a chosen image older than the picker's list, and the layout on a ↵grm2026-09-173-31/+79
| | | | | | | | | | | | | | | | | | | | rejected save The image picker's select lists the newest recentImages library images and was meant to add the chosen one when it is older than those, but the fallback option was gated on the filename being unknown, which designData makes known: the option never rendered, the browser selected "None", and every save of the design form cleared a logo or favicon older than the 48 newest images (the post form's featured image the same way). The partial now checks whether the choice is listed and otherwise emits it, named. handleDesign ran the uploads before parsing the module and menu rows and gave up at the first problem, so a rejected upload rendered the form without any rows — and, since a missing row means delete, the next save would have wiped the layout and menu. Everything is read before the first problem is reported. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add the Gizmo look for announcements: framed boxes that share a rowgrm2026-09-179-6/+35
| | | | | | | | | | | | | gizmolab's "next event" and "next assembly" boxes were hand-written HTML in the home page's intro; they are announcements by nature, so now they can be: a fourth style, a box framed in the theme's link colour with an italic heading. Headed Gizmo boxes in the same spot share a row on wide screens (the notices wrapper is a flex row, stacking on old browsers like .cols); one without a heading takes the whole row, which is how a banner line goes above a pair of boxes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Let the header and footer follow the main columngrm2026-09-174-2/+25
| | | | | | | | | | | | With keep_columns and empty side columns the posts sit in a centred column while the header and footer still run edge to edge, which reads as two different pages stacked. The new switch insets their content by the column widths (the backgrounds stay full width, phones are untouched) so the whole page lines up as one column — the look a single-column site expects, without bringing back a content max-width. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add post summaries, featured images and a page outrogrm2026-09-1724-116/+372
| | | | | | | | | | | | | | | | | | | | | | | | | | | Recreating gizmolab.net as a blog showed three things the design system could not express, all of them ordinary blog features: - Listings can show a summary and a "Read more" link instead of the whole post (theme.list_style). The summary is the source up to <!--more-->; without the marker a Markdown post is cut at a block boundary after 70 words (never inside a code fence) and an HTML post is shown whole, since cutting hand-written markup blind would leave tags open. Computed at render time (Post.Excerpt/HasMore), nothing new is stored. - A post can carry a featured image (posts.image, a library file that is unset when the file is deleted): a thumbnail floated beside the entry on listings, and on the post page above or below the text, or not at all, as theme.post_image says. The picker is the design page's imagepick; its library panel moves out of design.html into partials/imagelib.html so both forms share it — which also removes a stale pickAction call the design form's click handler would have hit. - A page can have a closing text after its posts (pages.outro_md/html), in the intro's format: the per-page counterpart of the blog-wide "after the posts" module, for a home page that ends in a site map or a widget. The editor partial takes formatof to share another editor's Format row, and its upload field is now <name>_file so two editors fit in one form. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Merge the Layout and Design tabs into one form with a single Savegrm2026-09-1621-852/+1156
| | | | | | | | | | | | | | | | | | | | The look and the layout of a blog were split over two tabs that cross-linked each other, and the Layout tab saved every toggle, move and add straight away through a dozen tiny forms. Now one Design tab holds it all, organised by part of the blog (colours & fonts, header, menu, content, side columns, footer, logo & icon) behind a sticky side index, and one Save stores the theme, every module and the menu atomically (BlogStore.SaveDesign). Module settings are edited inline; Discard changes throws the edits away; a validation error shows the form again exactly as it was sent. The image pickers no longer render the whole library four times over: a select of the newest images, and a script-driven panel that fetches the library page by page (GET /files as JSON) with lazy thumbnails. New options: posts per page, site title size, footer alignment. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add an HTML mode to posts, page intros and announcementsgrm2026-09-1619-89/+250
| | | | | | | | | | | | | | | | | Markdown is the default and unchanged; the editor's new Format switch stores the text as raw HTML instead, put on the blog exactly as written. Like the custom HTML module it is unsanitised on purpose: the escape hatch for embeds, scripts and inline styles that Markdown cannot express. The source column keeps holding the text in both modes and a `format` column says how to read it, so the public templates and the feed still print the stored `*_html`. The dashboard preview of HTML goes into a sandboxed iframe rather than the page, because a superadmin edits other people's blogs and their markup must never run on the dashboard origin. Search snippets of HTML posts are cut from a tag-stripped copy. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Put the header search box in the menu row, and stop saying "Search"grm2026-09-165-15/+34
| | | | | | | | | | | | | The header search was a band of its own under the menu; now it floats at the right end of the menu row and only gets a thin bar when the header has no menu. The forms are a single input — Enter and the phone keyboard's search key submit a one-field form everywhere — with the placeholder as the label, side boxes start without a heading, and the results page shows a box only when no module does, so a page no longer reads "Search" a dozen times. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add a search box module and a search pagegrm2026-09-1616-15/+245
| | | | | | | | | | | | | | | | | | Readers had no way to find a post. The new "search" module goes in the header (a bar under the nav) or a side column (a box with a heading) and is a plain GET form to /search, so it works without JavaScript. The results page lists the published posts of every page whose title or Markdown body matches the query — case-insensitive, each word literal, spaces meaning "anything in between", in order — as title, date and a short snippet with the match marked, 20 per page. modules.kind is a CHECK constraint, so a migration widens it; "search" becomes a reserved page slug so the literal route keeps winning over /{page}. moduleHasSettings now takes the module: a header search box has no heading, hence nothing to edit. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Make the post form's tag input a box with a folded list of chipsgrm2026-09-156-30/+50
| | | | | | | | | | | A checkbox per existing tag stops working once a blog has dozens of them. The form is now one comma-separated box, prefilled with the post's tags, and the blog's tags sit folded under it as chips; a small script toggles a clicked chip in the box, and without it the chips are a plain list to copy from. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add post tags, with a tag page and two side-column modulesgrm2026-09-1525-54/+519
| | | | | | | | | | | | | | | | | | | | Posts can now carry tags, set on the post form as a checklist of the blog's existing tags plus a comma-separated box for new ones (no JS). A tag is a name and a unique slug, so "Go" and "go" are one tag and Greek tags get readable URLs; tags no post uses any more are deleted. On the blog, tags appear under the post date and link to /tag/<slug>, which lists the published posts from every page, paginated like a page. Two new layout modules show them: a Tags list (with counts, by use) and a Tag cloud (alphabetical, sized by use). Both are only fetched when a visible module needs them. The article loop and pager move to a shared postlist partial; while there, the pager stops adding a trailing slash — /news/?p=2 was a 404 because a {page} wildcard never matches one. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Give the editor a Markdown toolbar and preview, restyle the dashboardgrm2026-09-1510-166/+406
| | | | | | | | | | | | | | | | | | | | The post/page/announcement editor was a bare textarea, so bloggers had to know the Markdown syntax by heart. It now has a toolbar (bold, italic, strike, heading cycle, quote, code, lists, rule, link box, insert file), Ctrl+B/I/K, list continuation on Enter and a Write/Preview toggle that renders the text through the same goldmark + bluemonday pipeline a save uses (POST /b/{sub}/preview; nothing is stored). Every edit goes through execCommand("insertText") so browser undo keeps working. The toolbar stays hidden without JavaScript, leaving the old form untouched. The dashboard moves from the "paper & ink" look to a lean one: neutral surfaces, 1px borders, one blue accent, system sans, with custom properties and flexbox/grid now allowed there (blog.css is unchanged). Class names were kept so the templates barely change; a global [hidden] rule keeps flex containers from overriding the hidden attribute. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Turn the image library into a file library, with a per-blog upload limitgrm2026-09-1435-359/+1295
| | | | | | | | | | | | | | | | | | | | | | | | | | Bloggers want to attach PDFs, archives, audio and other files to posts, not only images. The Images tab becomes Files: any type is accepted, listed by kind with search, paging, rename and multi-file upload, and the editor's paste/drop/"Insert file" takes anything (images are shown, everything else becomes a link). The default limit goes from 5 to 10 MB and the superadmin can override it per blog from /admin/. Files stay in Postgres so one pg_dump is still the whole blog. The bytea column is STORAGE EXTERNAL and /media streams it in substring() slices, so serving never holds a whole file in memory whatever limit a blog gets. Serving any type on the root domain, which carries the session cookie, needs a policy: uploads are typed by sniffing (the extension may only refine a generic sniff to an allowlisted type) and only images, PDF, plain text, audio and video render inline; HTML, SVG, XML, scripts, archives and binaries always go out as application/octet-stream with Content-Disposition: attachment. The body cap moves out of requireAuth into guardPOST, which runs after withBlog has resolved the blog and so knows its limit. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Let the blogger set a post's date, when writing it and afterwardsgrm2026-09-146-7/+54
| | | | | | | | | | | The post date is posts.created_at: it already drives ordering, the archive, the feed and the displayed dates, so making it editable is a form field rather than a new column. The datetime-local input degrades to a text box on old browsers, so the server also accepts the value typed by hand; blank keeps the current date. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Add languages: English and Greek, chosen per blog on the Settings tabgrm2026-09-1446-500/+1267
| | | | | | | | | | | | | | | | | | | | | | | Every blog and its dashboard were hard-wired to English. A blogger can now pick the language of their blog; it switches the whole dashboard and the blog's fixed text — post dates, archive months, the RSS link, the pager, the 404 page — while what the blogger wrote is left alone. The new internal/i18n package keys translations by the English string, so an untranslated key renders as English rather than blank, and TestGreekCatalogComplete scans the templates and handlers to fail when the Greek catalog misses a key or keeps a stale one. Templates are compiled once per language with t/tf/date/postdate/month closed over the language, so they need no data plumbing. The language lives in settings.language (blog migration 00002), not in the theme, so "Reset design" does not touch it. Public pages use the blog's language; management pages use the logged-in user's own blog's, so a superadmin editing someone else's blog keeps theirs; the login page follows Accept-Language. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Drop the single-database split and re-baseline the control migrationsgrm2026-09-149-323/+13
| | | | | | | | | | | | | | | | | Every deployment has been through the per-blog split, so the code that performed it (split.go, control migrations 00002–00007) is dead weight, and a fresh install replaying six migrations only to drop the tables again was silly. The control chain is now a single 00001_init.sql with the final users and blogs shape, matching the blog chain. Goose ignores versions recorded in the database that no longer exist in the source, but refuses a future migration numbered below the database's highest version. Databases that went through the split therefore need `DELETE FROM goose_db_version WHERE version_id > 1` once; README and AGENTS.md say so. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
* Send the dashboard brand link to the overview when logged ingrm2026-09-141-1/+1
| | | | | | | | | | Clicking "Blogspace" in the top bar went to the public root blog; from inside the dashboard it should go back to your blog's overview. /dashboard already resolves that (own blog, or /admin/ for a superadmin without one), so the link points there when there is a user and stays / on the login page. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A