36 Commits
Author SHA1 Message Date
Olaf 74b2c400c6 Fix release hash validation on older Python
Release LinkLog / release (push) Successful in 9s
Build LinkLog Development Image / development-image (push) Successful in 9s
2026-08-28 10:44:12 +02:00
Olaf 9bf9c94dd6 Versioning consistency and bump both the XPI and backend to version 0.2.0
Build LinkLog Development Image / development-image (push) Successful in 11s
Release LinkLog / release (push) Failing after 2s
2026-08-28 10:38:27 +02:00
olaf 5696c89dee Plugin follows duplicate behavior behavior of new-entry 2026-08-28 09:37:14 +02:00
olaf 50d61371e1 New Entry page improvements on link detection 2026-08-28 09:04:24 +02:00
olaf cf83c32b25 Fonts served via server
Build LinkLog Development Image / development-image (push) Successful in 22s
2026-08-28 08:19:43 +02:00
olaf 7bd64b870c Tried to fix a broke filter.
Build LinkLog Development Image / development-image (push) Successful in 10s
2026-08-27 22:54:22 +02:00
olaf 9494d2b119 Red theme and regression 2026-08-27 22:22:41 +02:00
olaf 3661d0b4b7 Logo links to home page 2026-08-27 22:14:32 +02:00
olaf d433a305f5 Fixed mastodon checkbox on new entry page 2026-08-27 22:08:30 +02:00
olaf 1c2d1b71ff tag placement in new-entry page 2026-08-27 21:45:38 +02:00
olaf de916d2fc7 Eyecandy on admin page and fix of functionality on that page
Build LinkLog Development Image / development-image (push) Successful in 11s
2026-08-27 21:16:11 +02:00
olaf 89f9be5e72 Label edit functionality added
Build LinkLog Development Image / development-image (push) Successful in 10s
2026-08-27 20:38:02 +02:00
olaf af5d38a16b Bump backend version to 0.1.1 and validate plugin manifest sync
Build LinkLog Development Image / development-image (push) Successful in 10s
Release LinkLog / release (push) Successful in 9s
2026-08-27 18:04:49 +02:00
olaf b93a8099f3 Merge origin/main into release branch
Build LinkLog Development Image / development-image (push) Successful in 14s
Release LinkLog / release (push) Failing after 2s
# Conflicts:
#	VIBE/CHAT_LOG.md
2026-08-27 17:50:07 +02:00
olaf f8fcadb488 theme selecter moved 2026-08-27 17:43:47 +02:00
olaf 60f7107ec9 Stale VIBE log update 2026-08-27 17:34:34 +02:00
olaf 16571a9645 New Entry functionality 2026-08-27 17:33:43 +02:00
Olaf c11b25c20a Change release - don't publish the XPI but a readme instead
Build LinkLog Development Image / development-image (push) Failing after 1s
Release LinkLog / release (push) Failing after 1s
2026-08-27 08:31:56 +02:00
Olaf c27aad58ae debugging workflow
Build LinkLog Development Image / development-image (push) Successful in 8s
Release LinkLog / release (push) Successful in 8s
2026-08-26 22:51:34 +02:00
olaf 7dffaad8e5 Fixed workflow
Build LinkLog Development Image / development-image (push) Successful in 8s
Release LinkLog / release (push) Failing after 8s
2026-08-26 22:40:39 +02:00
olaf 583026418d Format change in toots
Build LinkLog Development Image / development-image (push) Successful in 13s
Release LinkLog / release (push) Failing after 9s
2026-08-26 22:30:07 +02:00
olaf fa6d88a768 Download links for the plugin
Build LinkLog Development Image / development-image (push) Successful in 10s
2026-08-26 22:07:08 +02:00
olaf b6c01878a8 Signed LinkLog added 2026-08-26 21:54:47 +02:00
olaf 5dbef8f23f Minor manifest change
Build LinkLog Development Image / development-image (push) Successful in 8s
2026-08-26 21:46:21 +02:00
olaf ffb12a36b5 Secret test at startup
Build LinkLog Development Image / development-image (push) Successful in 11s
2026-08-26 20:54:00 +02:00
olaf 04b8a5a8b9 Log details obfuscated to not leak info 2026-08-26 20:51:29 +02:00
olaf b4b40e5c2c Logout now requires Authorization: Bearer <access-token>. 2026-08-26 20:46:48 +02:00
olaf 16c9c3a03f Updated Security Audit 2026-08-26 20:42:44 +02:00
olaf 018c02c759 Some additional checks and cleanup
Build LinkLog Development Image / development-image (push) Successful in 10s
2026-08-26 20:35:06 +02:00
olaf b03a241be2 Mail looks 'improved'
Build LinkLog Development Image / development-image (push) Successful in 19s
2026-08-26 20:27:54 +02:00
olaf 314959c7bf Audit trail 2026-08-26 19:52:22 +02:00
olaf ed76b35600 SA-010 Avatar validation 2026-08-26 18:35:12 +02:00
olaf b971d2ed97 Test fix 2026-08-26 18:27:32 +02:00
olaf 580c2a4257 OTP security hardened 2026-08-26 18:24:02 +02:00
olaf c3c3c8e1a6 SA-007 trivial docker compose 2026-08-26 18:20:04 +02:00
olaf 4049a197b9 token usage tightened with revocation 2026-08-26 18:17:55 +02:00
74 changed files with 3924 additions and 523 deletions
+4 -3
View File
@@ -8,11 +8,12 @@ APP_HEALTHCHECK_TIMEOUT=5s
APP_HEALTHCHECK_START_PERIOD=10s APP_HEALTHCHECK_START_PERIOD=10s
APP_HEALTHCHECK_RETRIES=3 APP_HEALTHCHECK_RETRIES=3
LINKLOG_APP_NAME=LinkLog LINKLOG_APP_NAME=LinkLog
LINKLOG_VERSION=0.1.0 LINKLOG_VERSION=0.1.1
LINKLOG_SECRET_KEY=replace-with-a-long-random-secret LINKLOG_SECRET_KEY=replace-with-a-long-random-secret
LINKLOG_DATA_ENCRYPTION_KEY=generate-with-python-cryptography-fernet-key LINKLOG_DATA_ENCRYPTION_KEY=generate-with-python-cryptography-fernet-key
LINKLOG_TOKEN_EXPIRY_DAYS=30 LINKLOG_TOKEN_EXPIRY_MINUTES=15
LINKLOG_PUBLIC_URL=localhost LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS=30
LINKLOG_PUBLIC_URL=linklog.example.com
LINKLOG_SMTP_HOST= LINKLOG_SMTP_HOST=
LINKLOG_SMTP_PORT=587 LINKLOG_SMTP_PORT=587
LINKLOG_SMTP_USERNAME= LINKLOG_SMTP_USERNAME=
+87 -26
View File
@@ -19,11 +19,10 @@ jobs:
- name: Validate versions and signed XPI - name: Validate versions and signed XPI
id: release id: release
run: | run: |
python3 scripts/release/validate_release.py python3 scripts/release/validate_release.py --github-output "$GITHUB_OUTPUT"
version=$(python3 -c "import json; print(json.load(open('frontend/version.json'))['version'])") backend_version=$(python3 -c "import json; print(json.load(open('frontend/version.json'))['version'])")
echo "version=$version" >> "$GITHUB_OUTPUT" if [ "${GITHUB_REF_NAME#v}" != "$backend_version" ]; then
if [ "${GITHUB_REF_NAME#v}" != "$version" ]; then echo "tag ${GITHUB_REF_NAME} does not match backend version $backend_version" >&2
echo "tag ${GITHUB_REF_NAME} does not match release version $version" >&2
exit 1 exit 1
fi fi
@@ -40,51 +39,113 @@ jobs:
context: . context: .
push: true push: true
tags: | tags: |
${{ env.IMAGE_NAME }}:${{ steps.release.outputs.version }} ${{ env.IMAGE_NAME }}:${{ steps.release.outputs.backend_version }}
${{ env.IMAGE_NAME }}:latest ${{ env.IMAGE_NAME }}:latest
labels: | labels: |
org.opencontainers.image.version=${{ steps.release.outputs.version }} org.opencontainers.image.version=${{ steps.release.outputs.backend_version }}
org.opencontainers.image.source=https://git.kolkman.org/olaf/Link-Log org.opencontainers.image.source=https://git.kolkman.org/olaf/Link-Log
- name: Generate release README
env:
BACKEND_VERSION: ${{ steps.release.outputs.backend_version }}
PLUGIN_VERSION: ${{ steps.release.outputs.plugin_version }}
SIGNED_XPI: ${{ steps.release.outputs.signed_xpi }}
run: |
cat > release-readme.md <<EOF
# LinkLog $BACKEND_VERSION
LinkLog is a Firefox extension and Python web service for saving links with a title, comment, timestamp, and tracking parameters removed. The service stores links in SQLite and can publish them through plugins, including Mastodon.
## Docker Container
The current backend/container version is $BACKEND_VERSION. Pull it from the Gitea container registry:
\`\`\`sh
docker pull $IMAGE_NAME:$BACKEND_VERSION
\`\`\`
The same image is also published as:
\`\`\`sh
docker pull $IMAGE_NAME:latest
\`\`\`
The developer version of the backend is always published as $IMAGE_NAME:latest, which may be ahead of the current release version and may be unstable.
Additional information about the backend can be found in the [README](https://git.kolkman.org/olaf/Link-Log/src/branch/main/backend/README.md).
## Firefox Extension
The current signed Firefox plugin version, compatible with this version of the backend, is $PLUGIN_VERSION. Download it from the raw repository artifact:
https://git.kolkman.org/olaf/Link-Log/raw/branch/main/$SIGNED_XPI
EOF
- name: Create Gitea release - name: Create Gitea release
id: gitea_release id: gitea_release
env: env:
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }} RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
VERSION: ${{ steps.release.outputs.version }} VERSION: ${{ steps.release.outputs.backend_version }}
run: | run: |
response=$(curl --fail-with-body --silent --show-error \ payload_file=$(mktemp)
python3 - <<'PY' > "$payload_file"
import json
import os
from pathlib import Path
version = os.environ['VERSION']
print(json.dumps({
'tag_name': f'v{version}',
'name': f'LinkLog {version}',
'body': Path('release-readme.md').read_text(),
'draft': False,
'prerelease': False,
}))
PY
response_file=$(mktemp)
response_status=$(curl --silent --show-error -o "$response_file" -w '%{http_code}' \
-X POST \ -X POST \
-H "Authorization: token $RELEASE_TOKEN" \ -H "Authorization: token $RELEASE_TOKEN" \
-H 'Content-Type: application/json' \ -H 'Content-Type: application/json' \
-d "{\"tag_name\":\"v$VERSION\",\"name\":\"LinkLog $VERSION\",\"draft\":false,\"prerelease\":false}" \ --data-binary "@$payload_file" \
https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases) https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases)
release_id=$(printf '%s' "$response" | jq -r '.id') rm -f "$payload_file"
if [ "$response_status" = 409 ]; then
response_status=$(curl --silent --show-error -o "$response_file" -w '%{http_code}' \
-H "Authorization: token $RELEASE_TOKEN" \
"https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases/tags/v$VERSION")
fi
if [ "$response_status" -lt 200 ] || [ "$response_status" -ge 300 ]; then
cat "$response_file" >&2
exit 1
fi
response=$(cat "$response_file")
rm -f "$response_file"
release_id=$(printf '%s' "$response" | python3 -c 'import json, sys; print(json.load(sys.stdin)["id"])')
test "$release_id" != null test "$release_id" != null
test "$release_id" != 0 test "$release_id" != 0
upload_url="https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases/$release_id/assets" upload_url="https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases/$release_id/assets"
echo "upload_url=$upload_url" >> "$GITHUB_OUTPUT" echo "upload_url=$upload_url" >> "$GITHUB_OUTPUT"
- name: Upload signed XPI and update manifest - name: Upload release README
env: env:
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }} RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
UPLOAD_URL: ${{ steps.gitea_release.outputs.upload_url }} UPLOAD_URL: ${{ steps.gitea_release.outputs.upload_url }}
VERSION: ${{ steps.release.outputs.version }}
run: | run: |
curl --fail-with-body --silent --show-error \ response_status=$(curl --silent --show-error -o /tmp/linklog-readme-upload-response -w '%{http_code}' \
-X POST -H "Authorization: token $RELEASE_TOKEN" \ -X POST -H "Authorization: token $RELEASE_TOKEN" \
-H 'Content-Type: application/x-xpinstall' \ -H 'Content-Type: text/markdown' \
--data-binary "@XPI/signed/LinkLog-$VERSION.xpi" \ --data-binary @release-readme.md \
"$UPLOAD_URL?name=LinkLog-$VERSION.xpi" "$UPLOAD_URL?name=README.md")
curl --fail-with-body --silent --show-error \ if [ "$response_status" -lt 200 ] || [ "$response_status" -ge 300 ]; then
-X POST -H "Authorization: token $RELEASE_TOKEN" \ cat /tmp/linklog-readme-upload-response >&2
-H 'Content-Type: application/json' \ exit 1
--data-binary @webextension/updates.json \ fi
"$UPLOAD_URL?name=updates.json"
- name: Publish release links - name: Publish release links
env: env:
VERSION: ${{ steps.release.outputs.version }} BACKEND_VERSION: ${{ steps.release.outputs.backend_version }}
PLUGIN_VERSION: ${{ steps.release.outputs.plugin_version }}
SIGNED_XPI: ${{ steps.release.outputs.signed_xpi }}
run: | run: |
echo "Docker image: $IMAGE_NAME:$VERSION" echo "Docker image: $IMAGE_NAME:$BACKEND_VERSION"
echo "Signed XPI: https://git.kolkman.org/olaf/Link-Log/releases/download/v$VERSION/LinkLog-$VERSION.xpi" echo "Signed XPI: https://git.kolkman.org/olaf/Link-Log/raw/branch/main/$SIGNED_XPI (version $PLUGIN_VERSION)"
echo "Firefox update manifest: https://git.kolkman.org/olaf/Link-Log/raw/branch/main/webextension/updates.json" echo "Release README: README.md"
+44
View File
@@ -0,0 +1,44 @@
# Changelog
## Version v0.2.0
### Features
* Users can edit or delete labels created by themselves on the labels page
* Administrators can edit labels from the admin interface
* Filter label visibility so logged-in users only see default/admin-created labels and their own
* Grandfather tags with unknown ownership as default/admin interface labels
* Ability to minimize settings panels to only show headers in the Admin and Profile interfaces for easy navigation
* Styled settings panel headers with distinct theme accent colors for visual distinction
* Settings panels are collapsed by default when opening the Admin and Profile pages
* Show checked-by-default Mastodon publishing on New Entry only for configured users
* Made every web header logo link to the home page
* Added a high-contrast Red color theme
* Brightened the Red theme surfaces and deepened its crimson accents
* Allow every user to filter the feed using every available tag or label
* Bundle required web fonts during Docker image builds and serve them from LinkLog
* Bundle required web fonts during Docker image builds and serve them from LinkLog
* New Entry page warns when the title/URL combination already exists, matching the browser extension's duplicate warning
* New Entry page warns when an existing link with the same title has a different or missing URL (after tracking parameters are stripped)
* New Entry page auto-fills the title when the URL field loses focus, instead of requiring a manual button press
* Added a "Re-fetch Title" button to manually re-scrape the title after editing the URL
* New Entry duplicate detection and submission strip known tracking parameters (utm_*, gclid, fbclid, etc.) from URLs, mirroring the browser extension
* Browser extension popup now matches the New Entry page: it warns on duplicate title/URL, notes when the stored link has a different URL, and gained a "Re-fetch title" button; bumped extension version to 0.2.0
* Generate Firefox update metadata from every signed XPI with verified SHA-256 archive hashes
### Fixed
* Fixed element ID conflict on the Admin page so Available Themes load correctly
* Positioned new-entry tag checkboxes after their label text
* Kept new-entry tag checkboxes immediately left of their labels at all viewport sizes
* Prevented the new-entry form grid from placing tag checkboxes above their labels
* Kept unconfigured New Entry Mastodon publishing controls hidden
* Restored the home-page header layout, keeping the action controls above the filter toolbar
* Made the tag filter refresh the feed directly when its selection changes
* Cache-busted the feed script to ensure browsers load the responsive tag filter
* Fixed feed initialization so tag filtering does not receive promise results as a selected tag [Still no complete fix]
## Version v0.1.1
### Features
* Ability to add new logs through the web interface
### Modification
* Moved the style selection into the hamburger menu
* Toot formatting changed a wee bit
## Version v0.1.0 Initial release
+2
View File
@@ -13,6 +13,8 @@ RUN pip install --no-cache-dir -r backend/requirements.txt
COPY backend ./backend COPY backend ./backend
COPY frontend ./frontend COPY frontend ./frontend
COPY scripts/download_fonts.py ./scripts/download_fonts.py
RUN python scripts/download_fonts.py
RUN useradd --create-home --uid 10001 linklog \ RUN useradd --create-home --uid 10001 linklog \
&& mkdir -p /app/backend/data \ && mkdir -p /app/backend/data \
&& chown -R linklog:linklog /app && chown -R linklog:linklog /app
+5 -1
View File
@@ -17,8 +17,9 @@ XPI_OUTPUT := $(XPI_UNSIGNED_DIR)/$(XPI_FILE)
EXTENSION_FILES := manifest.json logo.svg icon-16.png icon-32.png icon-48.png icon-96.png options.css options.html options.js popup.css popup.html popup.js l10n.js _locales/en-US/messages.json _locales/es/messages.json _locales/de/messages.json _locales/fr/messages.json _locales/nl/messages.json EXTENSION_FILES := manifest.json logo.svg icon-16.png icon-32.png icon-48.png icon-96.png options.css options.html options.js popup.css popup.html popup.js l10n.js _locales/en-US/messages.json _locales/es/messages.json _locales/de/messages.json _locales/fr/messages.json _locales/nl/messages.json
EXTENSION_SOURCES := $(addprefix webextension/,$(EXTENSION_FILES)) EXTENSION_SOURCES := $(addprefix webextension/,$(EXTENSION_FILES))
XPI_VALIDATOR := scripts/release/validate_xpi.py XPI_VALIDATOR := scripts/release/validate_xpi.py
UPDATES_GENERATOR := scripts/release/generate_updates.py
.PHONY: all logos xpi check-tools clean-generated .PHONY: all logos xpi update-updates check-tools clean-generated
all: logos all: logos
@@ -28,6 +29,9 @@ logos: check-tools $(GENERATED_LOGOS)
xpi: $(XPI_OUTPUT) xpi: $(XPI_OUTPUT)
update-updates: $(UPDATES_GENERATOR) webextension/manifest.json
@python3 $(UPDATES_GENERATOR)
$(XPI_OUTPUT): $(EXTENSION_SOURCES) $(GENERATED_LOGOS) $(XPI_VALIDATOR) $(XPI_OUTPUT): $(EXTENSION_SOURCES) $(GENERATED_LOGOS) $(XPI_VALIDATOR)
@test -n "$(EXTENSION_VERSION)" || { echo "Error: extension version is missing from webextension/manifest.json" >&2; exit 1; } @test -n "$(EXTENSION_VERSION)" || { echo "Error: extension version is missing from webextension/manifest.json" >&2; exit 1; }
@mkdir -p $(XPI_UNSIGNED_DIR) $(XPI_SIGNED_DIR) @mkdir -p $(XPI_UNSIGNED_DIR) $(XPI_SIGNED_DIR)
+48 -11
View File
@@ -12,7 +12,8 @@ frontend/ Jinja templates and browser-side assets
webextension/ Firefox Manifest V3 extension webextension/ Firefox Manifest V3 extension
Logo.svg Source logo artwork used by the web and extension interfaces Logo.svg Source logo artwork used by the web and extension interfaces
Dockerfile Backend container image Dockerfile Backend container image
docker-compose.yml App with traefik reverse proxy hooks docker-compose.yml Production app with Traefik reverse proxy hooks
docker-compose.local.yml Local development app with direct port access
REQUIREMENTS.md Product requirements REQUIREMENTS.md Product requirements
VIBE/ Conversation and prompt logs VIBE/ Conversation and prompt logs
``` ```
@@ -27,7 +28,7 @@ For local development:
The backend currently uses FastAPI, uvicorn, SQLite, and Pydantic. `httpx2` is included for the Starlette-compatible test client. The backend currently uses FastAPI, uvicorn, SQLite, and Pydantic. `httpx2` is included for the Starlette-compatible test client.
Jinja2 is included for server-rendered HTML templates. Jinja2 is included for server-rendered HTML templates.
The backend version is `0.1.0` and is exposed through the FastAPI/OpenAPI metadata. It can be overridden with `LINKLOG_VERSION`. The backend version is `0.2.0` and is exposed through the FastAPI/OpenAPI metadata. It is read from `frontend/version.json`, the single source of truth shared by the backend and frontend.
LinkLog is licensed under the GNU General Public License, version 3 or any later version. See [LICENSE](LICENSE). LinkLog is licensed under the GNU General Public License, version 3 or any later version. See [LICENSE](LICENSE).
## Local Installation ## Local Installation
@@ -68,13 +69,14 @@ Open these URLs:
- About: <http://localhost:8000/about> - About: <http://localhost:8000/about>
- Admin page: <http://localhost:8000/admin> - Admin page: <http://localhost:8000/admin>
- Web login: <http://localhost:8000/login> - Web login: <http://localhost:8000/login>
- Token refresh: `POST http://localhost:8000/api/auth/refresh`
- Health check: <http://localhost:8000/health> - Health check: <http://localhost:8000/health>
- OpenAPI documentation: <http://localhost:8000/docs> - OpenAPI documentation: <http://localhost:8000/docs>
The browser extension requires a backend URL to be entered during setup; it does not assume a default server. The browser extension requires a backend URL to be entered during setup; it does not assume a default server.
The supplied `Logo.svg` is bundled as `frontend/static/logo.svg` for web pages and `webextension/logo.svg` for the Firefox popup and settings page. The supplied `Logo.svg` is bundled as `frontend/static/logo.svg` for web pages and `webextension/logo.svg` for the Firefox popup and settings page.
The visible LinkLog brand text uses the Google Foundry `Asset` font when available, with local fallbacks in the Firefox extension. The visible LinkLog brand text uses the Google Foundry `Asset` font. Docker image builds download and bundle Asset, DM Sans, and Space Grotesk under `/static/fonts`, so the web frontend loads fonts from the LinkLog server rather than Google. The Firefox extension uses its bundled assets and local fallback fonts without requesting Google Fonts.
## Regenerate Logo Assets ## Regenerate Logo Assets
@@ -94,13 +96,25 @@ make xpi
This creates `XPI/unsigned/LinkLog-0.1.0.xpi` from the `webextension/` package and excludes macOS metadata and minified artifacts. The version is read from `webextension/manifest.json`. The `XPI/signed/` directory is reserved for signed release bundles. This creates `XPI/unsigned/LinkLog-0.1.0.xpi` from the `webextension/` package and excludes macOS metadata and minified artifacts. The version is read from `webextension/manifest.json`. The `XPI/signed/` directory is reserved for signed release bundles.
## Docker Deployment
The main `docker-compose.yml` is the production deployment. It does not publish port 8000 on the host; the application is reachable through Traefik on the external `linklog_traefik` network. Set `LINKLOG_PUBLIC_URL` to the DNS hostname served by Traefik. The default is the documentation hostname `linklog.example.com`, which must be replaced for a real deployment.
For local development with direct access, use the separate file:
```sh
docker compose -f docker-compose.local.yml up --build
```
This publishes `${APP_PORT:-8000}` and defaults the application URL to `http://localhost:8000`. Do not use the local file for an Internet-facing deployment.
## Releases ## Releases
Releases run in Gitea Actions when a `v*` tag is pushed. The Docker release version comes from `frontend/version.json`; the Firefox plugin version comes from `webextension/manifest.json`. CI also requires both to match `LINKLOG_VERSION`'s default in `backend/app/core/config.py`. Releases run in Gitea Actions when a `v*` tag is pushed. The Docker release version comes from `frontend/version.json`; the tag must match that version. The Firefox plugin version is independent and comes from the most recent signed `XPI/signed/LinkLog-<version>.xpi` checked into the repository.
The signed XPI is produced manually and must be checked into `XPI/signed/LinkLog-<version>.xpi` before creating the tag. The workflow validates the embedded manifest, publishes the XPI and `webextension/updates.json` as Gitea release assets, and publishes Docker images to `git.kolkman.org/olaf/link-log:<version>` and `:latest`. The signed XPI is produced manually and should be checked into `XPI/signed/LinkLog-<version>.xpi`. Run `make update-updates` after adding a signed XPI to regenerate `webextension/updates.json` from every valid signed release artifact. The workflow validates the latest signed XPI's embedded manifest, publishes Docker images to `git.kolkman.org/olaf/link-log:<backend-version>` and `:latest`, and creates a release README that describes the project, the current backend/container version, and the raw signed XPI download URL with the plugin version.
The extension's `update_url` points at the stable raw repository URL `https://git.kolkman.org/olaf/Link-Log/raw/branch/main/webextension/updates.json`. Update `webextension/updates.json` with each signed XPI version and commit it together with the XPI. The release page provides a direct install link at `https://git.kolkman.org/olaf/Link-Log/releases/download/v<version>/LinkLog-<version>.xpi`. The extension's `update_url` points at the stable raw repository URL `https://git.kolkman.org/olaf/Link-Log/raw/branch/main/webextension/updates.json`. Commit the regenerated `webextension/updates.json` together with each signed XPI. Release READMEs point to the raw signed XPI at `https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-<version>.xpi`.
The workflow requires Gitea Actions secrets named `REGISTRY_USERNAME`, `REGISTRY_TOKEN`, and `RELEASE_TOKEN`. `REGISTRY_TOKEN` is a Gitea access token with permission to push packages; `RELEASE_TOKEN` needs permission to create releases and upload release assets. The workflow requires Gitea Actions secrets named `REGISTRY_USERNAME`, `REGISTRY_TOKEN`, and `RELEASE_TOKEN`. `REGISTRY_TOKEN` is a Gitea access token with permission to push packages; `RELEASE_TOKEN` needs permission to create releases and upload release assets.
@@ -142,15 +156,16 @@ The manifest includes stable Firefox extension metadata and references the packa
1. Start the backend locally. 1. Start the backend locally.
2. Open Firefox and visit `about:debugging#/runtime/this-firefox`. 2. Open Firefox and visit `about:debugging#/runtime/this-firefox`.
3. Select **Load Temporary Add-on**. 3. Select **Load Temporary Add-on**.
4. Choose `webextension/manifest.json`. 4. Choose `webextension/manifest.json` (Firefox 142 or newer is required).
5. Open the LinkLog extension options and enter: 5. Open the LinkLog extension options and enter:
- Backend URL: the URL of your LinkLog server, such as `http://localhost:8000` - Backend URL: the URL of your LinkLog server, such as `http://localhost:8000`
- Username: `alice` - Email: `alice@example.com`
- Password: `secret123` - Password: `secret123`
- One-time password: enter it when OTP is enabled
6. Save the settings and login. 6. Save the settings and login.
7. Open a webpage, select the LinkLog toolbar button, review the title and URL, add a comment, and submit it. 7. Open a webpage, select the LinkLog toolbar button, review the title and URL, add a comment, and submit it.
When the extension settings page has a valid session, it shows `<username> logged in at <backend URL>` and a **Sign out** button instead of the login form. Signing out revokes the token and returns the form. When the extension settings page has a valid session, it shows `<username> logged in at <backend URL>` and a **Sign out** button instead of the login form. Access and refresh credentials are kept in Firefox session storage, so a browser restart requires login again. Signing out revokes the token family and returns the form.
Temporary extensions are removed when Firefox restarts. Reload the extension from `about:debugging` after changing its files. Temporary extensions are removed when Firefox restarts. Reload the extension from `about:debugging` after changing its files.
@@ -164,6 +179,8 @@ cp .env.example .env
Edit `.env` and replace `LINKLOG_SECRET_KEY` with a long random value. Docker Compose automatically reads `.env` from the repository root. The committed `.env.example` contains safe defaults and placeholders; the real `.env` is ignored by Git. Edit `.env` and replace `LINKLOG_SECRET_KEY` with a long random value. Docker Compose automatically reads `.env` from the repository root. The committed `.env.example` contains safe defaults and placeholders; the real `.env` is ignored by Git.
When `APP_ENV=production`, application startup fails closed unless `LINKLOG_SECRET_KEY` is a non-default high-entropy value of at least 32 characters and `LINKLOG_DATA_ENCRYPTION_KEY` is a valid Fernet key. Development mode may use local defaults, but production secrets should come from a protected secret mechanism.
The main configurable values are: The main configurable values are:
| Variable | Purpose | Default | | Variable | Purpose | Default |
@@ -171,8 +188,9 @@ The main configurable values are:
| `LINKLOG_SECRET_KEY` | token signing/security secret | required in Docker | | `LINKLOG_SECRET_KEY` | token signing/security secret | required in Docker |
| `LINKLOG_DATA_ENCRYPTION_KEY` | Fernet key for encrypting SMTP, Mastodon, and OTP secrets at rest | required in Docker | | `LINKLOG_DATA_ENCRYPTION_KEY` | Fernet key for encrypting SMTP, Mastodon, and OTP secrets at rest | required in Docker |
| `LINKLOG_DATABASE_PATH` | SQLite file path inside the container | `/app/backend/data/linklog.db` | | `LINKLOG_DATABASE_PATH` | SQLite file path inside the container | `/app/backend/data/linklog.db` |
| `LINKLOG_TOKEN_EXPIRY_DAYS` | access-token lifetime | `30` | | `LINKLOG_TOKEN_EXPIRY_MINUTES` | access-token lifetime | `15` |
| `LINKLOG_PUBLIC_URL` | Public hostname used by Traefik and expanded to a callback URL by the backend | `localhost` | | `LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS` | refresh-token lifetime | `30` |
| `LINKLOG_PUBLIC_URL` | Public hostname used by Traefik and expanded to a callback URL by the backend | `linklog.example.com` |
| `LINKLOG_SMTP_HOST` | SMTP server hostname; empty disables delivery in local development | empty | | `LINKLOG_SMTP_HOST` | SMTP server hostname; empty disables delivery in local development | empty |
| `LINKLOG_SMTP_PORT` | SMTP server port | `587` | | `LINKLOG_SMTP_PORT` | SMTP server port | `587` |
| `LINKLOG_SMTP_USERNAME` | SMTP login username | empty | | `LINKLOG_SMTP_USERNAME` | SMTP login username | empty |
@@ -247,6 +265,25 @@ curl -X POST http://localhost:8000/api/auth/login \\
-d '{"email":"alice@example.com","password":"secret123"}' -d '{"email":"alice@example.com","password":"secret123"}'
``` ```
The login response contains a 15-minute access token, a device-bound refresh token, its expiry time, and a `device_id`. Each successful refresh rotates the refresh token.
Refresh an access token:
```sh
curl -X POST http://localhost:8000/api/auth/refresh \\
-H 'Content-Type: application/json' \\
-d '{"refresh_token":"YOUR_REFRESH_TOKEN","device_id":"YOUR_DEVICE_ID"}'
```
Refresh-token reuse or a mismatched device ID returns `401` and revokes the token family. Signing out revokes the token family, while changing the password or completing a password reset revokes all sessions for the user.
Sign out with the access token in the bearer header:
```sh
curl -X POST http://localhost:8000/api/auth/logout \\
-H 'Authorization: Bearer YOUR_ACCESS_TOKEN'
```
Submit a link using the returned access token: Submit a link using the returned access token:
```sh ```sh
+103 -201
View File
@@ -2,262 +2,164 @@
**Assessment date:** 2026-08-26 **Assessment date:** 2026-08-26
**Scope:** Current LinkLog backend, web frontend, Firefox extension, SQLite persistence, SMTP and Mastodon integrations, Docker/Traefik deployment files, and automated tests. **Scope:** Current LinkLog backend, web frontend, Firefox extension, SQLite persistence, SMTP and Mastodon integrations, Docker/Traefik deployment files, and automated tests.
**Assessment type:** Source-code security review. This is not a penetration test, dependency vulnerability scan, formal threat model sign-off, or production configuration certification. **Assessment type:** Source-code review. This is not a penetration test, dependency scan, container scan, formal threat-model sign-off, or production configuration certification.
## Executive Summary ## Executive Summary
LinkLog has several good security foundations: authenticated API dependencies, administrator authorization checks, owner checks for link operations, token hashing in the database, email verification, password reset token hashing and single-use behavior, TOTP login enforcement, last-administrator protection, parameterized SQLite queries, upload size limits, and non-root application execution in the container. The current worktree contains strong security improvements: salted scrypt password hashing with legacy upgrade support, bearer-header authentication, hashed and expiring tokens, refresh-token rotation with device binding and family revocation, OTP recovery codes, encrypted newly written secrets, Mastodon SSRF controls, image decoding and re-encoding, reduced extension permissions, proxy-only production Compose, and append-only audit events.
The current implementation is not ready to expose directly to the public Internet without additional hardening. The most important issues are: The following issues remain before an Internet-facing production release:
1. Passwords were previously stored as unsalted, fast SHA-256 hashes; this issue has now been addressed in the current worktree with salted scrypt hashes and legacy upgrade support. 1. Logout still accepts a bearer token in a JSON body rather than using the standard `Authorization` header.
2. Access tokens are accepted in query strings by session endpoints, which can leak through logs, browser history, proxies, and referrers. 2. SMTP, Mastodon, setup, and some user-service errors return raw exception details to clients.
3. SMTP credentials, Mastodon credentials, OAuth client secrets, and TOTP secrets are stored in plaintext in SQLite. 3. First-run setup is intentionally unauthenticated and lacks a bootstrap secret and application-level request-size controls.
4. Mastodon instance URLs are user-controlled and the backend makes outbound requests to them, creating an SSRF and egress-control concern. 4. Audit event details are serialized without defensive sanitization or size limits at the audit-service boundary.
5. Login has no effective rate limiting or account lockout. 5. The development secret fallback is not rejected at application startup in production.
6. The Firefox extension stores bearer tokens in browser local storage and requests broad website access. 6. Rate limiting is single-instance SQLite state, is not atomic under concurrency, and reset-mail issuance is not independently throttled.
7. The Compose setup still exposes the application port directly and relies on deployment-specific Traefik networking and labels. 7. Runtime verification, security headers, centralized audit export, retention, alerting, and dependency/container/security scanning remain incomplete.
These findings are prioritized below. Severity describes the potential security impact in a typical Internet-facing deployment, not the likelihood in every environment. The application should remain behind the production reverse proxy, with real DNS/TLS, protected secrets, and restricted network access until these items are addressed.
## Positive Controls Already Present ## Verified Controls
- Bearer authentication is centralized in `backend/app/api/dependencies.py`. - Passwords use salted scrypt hashes; valid legacy SHA-256 hashes are upgraded on login.
- Administrator routes use `require_admin`; standard users receive `403`. - Bearer authentication is centralized through `get_current_user` and `require_admin`.
- Link update, delete, and Mastodon-post operations verify ownership. - Query-string authentication is not accepted by protected session endpoints.
- Tokens are generated with UUID material, stored as SHA-256 hashes, expire, and can be revoked. - Access tokens are short-lived by default; refresh tokens are hashed, separately expiring, device-bound, rotated, and family-revoked on reuse.
- Password-reset tokens are random, hashed, expiring, single-use, and revoke existing sessions after reset. - Logout, password changes, and password resets revoke session material according to the token lifecycle.
- New administrator-created users require email verification before login. - OTP enrollment provides ten one-time recovery codes; only hashes are stored.
- OTP uses time-based verification with a one-step clock window and is required before token issuance when enabled. - Users can recover OTP with password plus a recovery code, and administrators can disable OTP for another user.
- The profile API does not return `password_hash` or `otp_secret` after the profile response hardening. - Newly written SMTP, Mastodon, OAuth, and OTP secrets are encrypted with an external Fernet key.
- User privilege changes protect against removing the last administrator and prevent an administrator from changing their own privilege. - Mastodon instances are restricted to HTTPS public hostnames, unsafe resolved addresses are rejected, and redirects are blocked.
- Uploaded avatars have a 2 MB limit, a restricted MIME allow-list, user-scoped filenames, and a persistent data location. - Avatar uploads are size-limited, decoded with Pillow, pixel-limited, fully loaded, and re-encoded as server-generated PNG.
- SQLite foreign keys are enabled and ownership predicates are used for destructive link operations. - Production Compose does not publish the application port and uses the external Traefik network; local direct access is separate.
- SQL statements use parameters rather than interpolated user values. - The Firefox extension uses `activeTab`, session-scoped credentials, exact configured backend permissions, and a self-only extension-page CSP.
- The Docker image runs the application as UID 10001 after startup and defines a health check. - SQLite queries are parameterized and foreign-key enforcement is enabled.
- `.env` and database/runtime files are ignored by Git. - An append-only `security_audit_events` table records actor, action, target, outcome, and details for major administrative and destructive operations.
- The XPI build validates archive integrity, required files, and manifest parity. - The current automated backend suite passes 49 tests.
- Browser rendering generally uses `textContent` for feed data, reducing DOM-based injection risk.
## Findings ## Findings
### SA-001: Unsalted fast SHA-256 password hashing ### SA-001: Logout uses non-standard token transport
**Severity:** Critical, remediated in current worktree
**Evidence before remediation:** `backend/app/database.py` and `backend/app/services/auth_service.py` used unsalted SHA-256 password comparisons.
**Current state:** `backend/app/database.py` now creates salted scrypt hashes in the format `scrypt$N$r$p$salt$digest`. `verify_password()` uses the encoded parameters and constant-time comparison. `authenticate_user()` fetches by username, verifies in Python, and transparently replaces a valid legacy 64-character SHA-256 hash with a new scrypt hash.
**Residual impact:** Existing accounts remain exposed until they successfully authenticate once after deployment. An attacker with a copy of an old database may still attack legacy hashes. Existing credentials should be rotated if the old database may have been exposed.
**Recommendation:** Deploy the current migration, require password rotation for accounts that cannot log in during migration, and monitor for remaining legacy hashes. Review scrypt cost parameters periodically and increase them as hardware changes. Do not revert to a fast general-purpose hash.
**Priority:** Completed in code; operational migration and credential rotation remain.
### SA-002: Bearer tokens accepted in query strings
**Severity:** High, remediated in current worktree **Severity:** High, remediated in current worktree
**Evidence before remediation:** `backend/app/api/auth.py` exposed `GET /api/auth/me?token=...`, and web/extension callers used the query form. **Evidence before remediation:** `POST /api/auth/logout` accepted `{"token": ...}` in the JSON request body, and the web frontend sent the access token this way.
**Current state:** `/api/auth/me` now requires the existing bearer-header dependency. The shared web header, admin session check, Firefox settings page, and tests send `Authorization: Bearer <token>`. A query-string token is rejected with `401`. **Impact:** Request bodies may be captured by debugging middleware, application logs, or monitoring systems. The endpoint also diverges from the bearer-header contract used elsewhere, increasing the chance of inconsistent token handling.
**Residual impact:** Tokens from old URLs may remain in proxy/browser logs and should be treated as exposed until revoked or rotated.
**Recommendation:** Rotate existing access tokens after deployment and scrub historical query parameters from logs where possible. Keep the bearer header as the only credential transport. **Current state:** Logout requires `Authorization: Bearer <access-token>`, rejects body-only tokens with `401`, and revokes the token family server-side. The web frontend and Firefox extension send the header; regression coverage verifies access and refresh tokens are invalid after logout.
**Priority:** Completed in code; token rotation and log hygiene remain. **Recommendation:** Keep logout header-only, retain family revocation, avoid logging authorization headers, and rotate legacy sessions issued before this change.
### SA-003: Sensitive secrets stored in plaintext SQLite **Priority:** Completed in code; legacy session rotation and log hygiene remain.
**Severity:** High, remediated in current worktree for newly written secrets ### SA-002: Raw infrastructure errors are returned to clients
**Evidence:** `backend/app/services/email_service.py` stores SMTP settings including `smtp_password` in `app_settings`; `backend/app/services/mastodon_oauth.py` stores Mastodon application secrets and user access tokens in `app_settings` and `user_plugin_config`; `backend/app/api/user_config.py` stores `otp_secret` in the `users` table. New writes are encrypted, but legacy plaintext rows require rotation.
**Impact:** Read access to the database exposes SMTP credentials, Mastodon posting authority, OAuth client secrets, and TOTP seeds. TOTP seeds cannot be changed by a user who loses the database copy. Database backups therefore contain reusable credentials, not just application data.
**Current state:** Newly stored SMTP passwords, Mastodon OAuth client secrets and access tokens, and TOTP seeds are encrypted with Fernet using `LINKLOG_DATA_ENCRYPTION_KEY`. The key is required in Docker and is not stored in SQLite. The user plugin API no longer returns the Mastodon access token.
**Residual impact:** Existing plaintext secrets require a controlled read-and-save rotation after the key is configured. Lost encryption keys make stored secrets unrecoverable.
**Recommendation:** Supply `LINKLOG_DATA_ENCRYPTION_KEY` through a protected secret mechanism, encrypt backups, rotate credentials after suspected disclosure, and migrate existing plaintext values. Continue omitting secrets from API responses.
**Priority:** Completed for new writes; existing secret migration and key management remain.
### SA-004: User-controlled Mastodon instance creates SSRF and uncontrolled egress risk
**Severity:** High, remediated in current worktree **Severity:** High, remediated in current worktree
**Evidence before remediation:** Mastodon instance values were passed to outbound `urlopen()` calls with no DNS/IP-range or redirect controls. **Evidence before remediation:** SMTP and Mastodon routes interpolated exception text into `503`/`502` responses. Setup and email-address routes also exposed mail-delivery exception text.
**Current state:** `mastodon_security.py` requires hostname-only HTTPS URLs, resolves DNS, rejects loopback, link-local, private, multicast, unspecified, reserved, and IPv4-mapped IPv6 addresses, and uses an opener that refuses redirects. OAuth, posting, and deletion all use these controls. **Impact:** Error responses can disclose SMTP hostnames, ports, TLS/library details, upstream response bodies, internal network information, or sensitive URL fragments.
**Residual impact:** DNS and network policy can change after validation; production deployments should still use egress firewalling or a restricted outbound proxy.
**Recommendation:** Keep outbound firewalling or an allow-listed proxy in production, monitor DNS rebinding risk, and maintain response-size/time limits. **Current state:** The application assigns a request ID at middleware entry, returns it in `X-Request-ID`, logs technical exception summaries server-side after redacting authorization values, tokens, passwords, secrets, OTP/code values, and secret-bearing URL query values, and returns stable public messages with a reference ID. SMTP setup/admin/email errors and Mastodon registration/callback errors no longer expose raw exception text. Regression tests verify representative exception and secret text is absent from HTTP responses.
**Priority:** Completed in code; network-level egress controls remain. **Residual impact:** Logging currently uses the application logger rather than a centralized protected sink. Request-ID trust, log retention, access control, and structured redaction should be reviewed in deployment.
### SA-005: Login endpoint lacks rate limiting and lockout **Recommendation:** Keep public errors stable and reference-based, export redacted logs to a protected centralized system, define retention and access controls, and never log authorization headers or secret-bearing request data.
**Severity:** High, remediated in current worktree **Priority:** Completed in code; centralized logging and operational controls remain.
**Evidence before remediation:** `POST /api/auth/login` had no IP, email, or account rate limit, and OTP failures were not throttled separately.
**Current state:** Login failures are tracked in SQLite by a SHA-256 key derived from client IP and normalized email. Five failures within 15 minutes cause a two-minute lockout; the endpoint returns `429` with `Retry-After`, and successful password plus OTP authentication clears the counter. Password-reset mail remains generic and should still be rate-limited operationally.
**Recommendation:** Use a distributed limiter for multi-instance deployments, add monitoring, and rate-limit password-reset issuance independently. Keep responses generic to avoid account enumeration. ### SA-003: First-run setup is unauthenticated and lacks application-level body limits
**Priority:** Completed for the single-instance SQLite deployment; distributed limiting and reset-mail controls remain. **Severity:** Medium/High for exposed fresh deployments
**Evidence:** `/api/setup/configuration`, `/api/setup/test-mail`, `/api/setup/complete`, and `/api/setup/status` are available before an administrator exists. No global request-size middleware or bootstrap secret is enforced in the application.
### SA-006: Firefox extension has broad host access and stores bearer tokens in local storage **Impact:** Anyone who can reach a fresh instance can overwrite pending setup values, attempt SMTP delivery, consume test-mail quota, and submit oversized request bodies. The setup design is necessary for provisioning but is unsafe when directly exposed.
**Severity:** High **Recommendation:** Require a one-time bootstrap secret supplied through the environment or console, or restrict setup to localhost/private management networking. Add bounded request models and a global body-size limit. Keep strict setup/test-mail throttling, audit setup actions, expire pending setup data, and disable setup routes after provisioning.
**Evidence:** `webextension/manifest.json` declares `host_permissions: ["<all_urls>"]`; `webextension/options.js` and `webextension/popup.js` store and retrieve `accessToken` through `browser.storage.local`.
**Impact:** A compromised extension context or another extension with sufficient access may obtain the bearer token. The broad host permission increases the impact of an extension compromise and requires elevated user trust. The token grants access until expiry or revocation.
**Recommendation:** Minimize permissions to the APIs actually needed. Prefer `activeTab` and explicit user interaction for page capture, and avoid `<all_urls>` unless required by a demonstrated workflow. Store session credentials in the narrowest available extension storage, minimize token lifetime, support refresh-token rotation, and clear all session material on logout or token invalidation. Add a Content Security Policy and review every extension script for dependency and injection risk. **Priority:** High for Internet-facing fresh installations.
**Priority:** High. ### SA-004: Audit details are not sanitized at the audit-service boundary
### SA-007: Production Compose configuration exposes the application directly
**Severity:** Medium/High
**Evidence:** `docker-compose.yml` publishes `${APP_PORT:-8000}:8000` while also configuring Traefik labels. The file uses an external `linklog_traefik` network and deployment-specific labels.
**Impact:** The application can bypass the reverse proxy and any TLS, authentication middleware, rate limiting, or security headers configured there. The default `LINKLOG_PUBLIC_URL=localhost` is also unsuitable for a public deployment. A network or label mismatch can silently expose an unprotected direct endpoint or make operators disable controls to restore access.
**Recommendation:** Split local development and production Compose files. In production, do not publish the application port to the host; attach it only to the reverse-proxy network. Ensure the app and Traefik share the same explicitly named network and validate the effective rendered configuration in CI. Require a non-local public hostname, TLS, security headers, request-size limits, and proxy-level rate limiting. Keep the direct port only in a documented local profile.
**Priority:** High for Internet-facing deployments.
### SA-008: Initial setup and SMTP validation are unauthenticated by design
**Severity:** Medium **Severity:** Medium
**Evidence:** `backend/app/api/setup.py` exposes configuration, test-mail, status, and completion routes without a bearer dependency while no administrator exists. **Evidence:** `record_audit_event()` serializes caller-supplied `details` directly to SQLite. Current callers generally avoid secrets, but the service does not enforce that contract or bound nested values and event size.
**Impact:** This is necessary for first-run provisioning, but an exposed fresh instance allows anyone who can reach it to attempt setup, modify pending configuration, trigger test mail, and consume the five-send testing quota. The setup pending data includes a password hash and SMTP password in the database.
**Recommendation:** Restrict first-run setup at the network layer until an operator has completed provisioning, or require a one-time bootstrap secret supplied through the environment/console. Bind setup to localhost or a private management interface where possible. Add CSRF protection if setup ever uses cookies, strict request throttling, audit logging, and an explicit setup expiration/cleanup mechanism. Disable setup routes permanently once configuration completes. **Impact:** A future caller could persist passwords, tokens, OTP codes, SMTP credentials, sensitive URLs, or oversized data in the audit database. Audit records are durable and are not a suitable place for arbitrary request payloads.
**Priority:** Medium, high for exposed fresh deployments. **Recommendation:** Use an allow-list of permitted detail fields per action, or recursively redact sensitive key names and URL query values. Bound string lengths and serialized event size. Add direct service tests with nested `password`, `token`, `secret`, and URL values and assert that they are redacted or rejected.
### SA-009: TOTP enrollment has no recovery codes or reset workflow
**Severity:** Medium
**Evidence:** `POST /api/user/otp/setup` returns the seed/provisioning URI and `POST /api/user/otp` requires a valid current OTP code to disable OTP.
**Impact:** A user who loses the authenticator device or seed can be locked out. Administrators have no documented recovery path that does not weaken authentication. Database readers can also use the plaintext seed as a second factor.
**Recommendation:** Generate one-time recovery codes during enrollment, display them once, hash them at rest, and invalidate each code on use. Require password reauthentication for disabling or replacing OTP. Add a controlled administrative recovery workflow with audit logging and notification. Avoid returning the seed after initial setup and never include it in profile responses.
**Priority:** Medium. **Priority:** Medium.
### SA-010: Avatar validation trusts the client MIME type ### SA-005: Production secret fallback is not fail-closed
**Severity:** Medium, remediated in current worktree
**Evidence before remediation:** `Settings.secret_key` defaulted to `dev-secret-key-change-me`, and `LINKLOG_DATA_ENCRYPTION_KEY` was validated when encryption was used rather than fully validated during startup.
**Impact:** A deployment that omits required configuration can start with a known development secret or fail only when a protected feature is exercised. This creates dangerous configuration drift and complicates incident response.
**Current state:** `validate_configuration()` runs before FastAPI app construction. In production it rejects a missing or known development `LINKLOG_SECRET_KEY`, application secrets shorter than 32 characters or with insufficient character diversity, and missing `LINKLOG_DATA_ENCRYPTION_KEY`. Any supplied encryption key is checked as a valid Fernet key. Focused tests cover rejection and acceptance paths.
**Residual impact:** Secret strength checks are pragmatic length/diversity checks rather than a full entropy estimator. Secret provisioning, rotation, and protected storage remain operational requirements.
**Recommendation:** Keep production startup fail-closed, provision secrets through a protected secret manager, rotate them after suspected disclosure, and consider a stronger entropy policy if deployment requirements warrant it.
**Priority:** Completed in code; secret provisioning and rotation remain.
### SA-006: Login and reset-mail throttling are not distributed or atomic
**Severity:** Medium/High in multi-instance deployments
**Evidence:** Login failure state is stored in SQLite and keyed by a client-IP/email hash. The check and increment occur as separate operations. Failed login handling can also issue a password-reset email for a known verified account without an independent reset-mail cooldown.
**Impact:** Concurrent attempts can overwrite counters, multiple application instances do not share reliable rate state, and reset-mail issuance can be abused to spam a user or consume SMTP resources.
**Recommendation:** Use an atomic shared limiter such as Redis for multi-instance deployments, with both account and IP buckets. Add an independent per-account/IP reset-mail cooldown and monitoring. Treat trusted proxy headers explicitly when deriving client IPs. Add concurrency, proxy, OTP-failure, and reset-mail abuse tests.
**Priority:** Medium/High for scaled or public deployments.
### SA-007: Security headers and global request policy are incomplete
**Severity:** Medium **Severity:** Medium
**Evidence:** `upload_avatar()` in `backend/app/api/user_config.py` selects the extension from `UploadFile.content_type` and writes the bytes without decoding or inspecting the image. **Evidence:** The application does not consistently install or test CSP, HSTS, `X-Content-Type-Options`, frame protections, `Referrer-Policy`, trusted hosts, or a global request-size limit. The extension CSP does not cover the web application.
**Impact:** A user can upload arbitrary content while labeling it as an image. Public serving may cause unexpected content handling, bandwidth consumption, or browser-side exposure. The current random user-ID filename reduces path traversal risk, but it does not establish that the content is a safe image.
**Recommendation:** Decode images with a hardened image library, enforce pixel and dimension limits, re-encode to a safe format, strip metadata, and serve with a fixed safe `Content-Type` and `X-Content-Type-Options: nosniff`. Consider a separate media origin and a stricter content security policy. **Impact:** Browser defense-in-depth and resource exhaustion protections depend on external proxy configuration. A proxy configuration mistake can leave HTML, API, or media responses weaker than intended.
**Recommendation:** Add a documented application or guaranteed-proxy policy and test headers on HTML, API, and media responses. Use `TrustedHostMiddleware` with explicit production hosts, `nosniff`, restrictive framing/referrer rules, HSTS only on HTTPS, and bounded request bodies.
**Priority:** Medium. **Priority:** Medium.
### SA-011: Error details can disclose infrastructure information ### SA-008: Audit operations lack request correlation, retention, export, and alerting
**Severity:** Medium **Severity:** Medium
**Evidence:** Admin SMTP routes return exception text in `503` responses; Mastodon errors include upstream response bodies; the frontend displays these values to the user. **Evidence:** Audit events contain actor/action/target/outcome/details/time but no request ID, source context, retention policy, protected export, or alerting pipeline.
**Impact:** Connection errors can disclose hostnames, ports, TLS details, library messages, upstream response bodies, or internal service information. The behavior is useful for administrators but may expose more detail than intended if an admin session is compromised or error responses are logged.
**Recommendation:** Log full technical details server-side with correlation IDs. Return a stable user-facing message plus a short reference ID. Allow detailed diagnostics only behind an explicit protected troubleshooting mode. Redact credentials, authorization headers, URLs containing secrets, and SMTP/Mastodon response fields before logging or returning them. **Impact:** Operators can inspect database events but cannot reliably correlate them with request logs, detect attacks promptly, or guarantee retention and tamper-resistant access controls.
**Recommendation:** Add request IDs at middleware entry, export redacted events to protected logs or a security monitoring system, define retention and access controls, and alert on privilege changes, OTP resets, password resets, credential changes, refresh-token reuse, and destructive actions.
**Priority:** Medium. **Priority:** Medium.
### SA-012: Token lifecycle has unused refresh-token semantics ### SA-009: Dependency, container, secret, and runtime security verification is incomplete
**Severity:** Medium **Severity:** Medium
**Evidence:** `issue_token()` returns a `refresh_token` value, but only the access token is inserted into `tokens`; no refresh endpoint or refresh-token hash is implemented. **Evidence:** The repository runs functional tests and static syntax checks, but no dependency vulnerability scan, container scan, secret scan, authenticated dynamic test, or live Firefox extension workflow is part of the verified release path.
**Impact:** Clients may assume the refresh token provides renewal or may store a value that cannot be revoked or used. This complicates session reasoning and can lead to unsafe client fallbacks. Access tokens currently live for the configured default of 30 days.
**Recommendation:** Either remove `refresh_token` from the API contract or implement a real refresh-token lifecycle: hash and persist refresh tokens, rotate them on use, detect reuse, bind them to a session/device, expire them separately, and revoke the token family on logout or password change. Reduce access-token lifetime after a real refresh flow is available. **Impact:** Known vulnerable dependencies, image issues, accidental secret commits, proxy misconfiguration, and browser-runtime permission failures can reach release despite passing unit tests.
**Priority:** Medium. **Recommendation:** Add CI jobs for Python dependency and license policy, container scanning, secret scanning, Compose rendering, authenticated dynamic API checks, and a Firefox smoke test covering permission grant, login, refresh, logout, and active-tab capture.
### SA-013: No explicit security headers, CORS policy, or request-size policy **Priority:** Medium before public release.
**Severity:** Medium ## Residual Operational Requirements
**Evidence:** `backend/app/main.py` does not install security-header or CORS middleware, and the application routes do not define a global request-size limit.
**Impact:** Deployment behavior depends entirely on the reverse proxy. Missing `Content-Security-Policy`, `Strict-Transport-Security`, `X-Content-Type-Options`, `Referrer-Policy`, and frame protections weakens browser-side defenses. An overly permissive future CORS configuration could expose bearer-authenticated APIs. Large request bodies may consume resources even where individual avatar limits exist.
**Recommendation:** Add a documented restrictive security-header policy at the application or guaranteed proxy layer. Use `TrustedHostMiddleware` with an explicit production host list. Do not enable broad CORS; if cross-origin extension access requires it, allow only configured origins. Add global request and upload limits at the proxy and application layers. - Replace documentation hostnames with real DNS names and enforce HTTPS/TLS.
- Keep production Compose proxy-only and verify the actual Traefik network and middleware in deployment.
**Priority:** Medium. - Rotate legacy plaintext secrets and previously issued sessions after upgrades.
- Protect and encrypt database/avatar backups; test restoration and token/session revocation.
### SA-014: Development fallback secret is unsafe if the app is run without Compose configuration - Monitor failed logins, reset-mail volume, refresh-token reuse, OTP recovery, privilege changes, and destructive actions.
- Review the Firefox extension against Mozilla Add-ons policy before signing.
**Severity:** Medium
**Evidence:** `Settings.secret_key` in `backend/app/core/config.py` defaults to `dev-secret-key-change-me`.
**Impact:** Local or incorrectly configured deployments can share a known secret. Even if the current token implementation does not use this value for signing, the setting creates a dangerous security assumption and may be used by future features.
**Recommendation:** Fail closed when `APP_ENV=production` and the secret is absent or matches a known development value. Generate secrets during provisioning, validate minimum length and entropy, and never ship a production fallback. Make all cryptographic uses explicit and test them.
**Priority:** Medium.
### SA-015: Some destructive and administrative operations lack audit logging
**Severity:** Low/Medium
**Evidence:** User creation/deletion, privilege changes, SMTP changes, theme changes, OTP enrollment/disablement, link deletion, and Mastodon deletion do not create durable security audit events.
**Impact:** Operators cannot reliably determine who changed privileges, modified delivery credentials, enrolled OTP, or deleted local/remote content. This limits incident response and accountability.
**Recommendation:** Add append-only audit events containing actor ID, action, target type/ID, timestamp, request ID, and outcome. Never store passwords, OTP codes, access tokens, SMTP passwords, or full sensitive request bodies. Export security events to protected logs.
**Priority:** Low/Medium.
## Authentication and Authorization Review
- **Authentication transport:** Bearer headers are used by most APIs, but query-string tokens remain a leakage risk. There is no cookie session, which reduces CSRF exposure for current bearer-only API calls. Credentials are now email-based; usernames remain presentation identities.
- **Email authentication:** Primary and additional addresses are checked independently; additional addresses are unusable for login until their verification token is consumed. The profile exposes status but not verification secrets.
- **Primary email selection:** Only an already verified alternative address can be promoted to primary. The same user row retains account permissions and active sessions, and the previous primary is retained as a verified alternative.
- **Password policy:** New and reset passwords require at least eight characters. This is better than no policy but should be replaced with a longer passphrase-oriented policy and breached-password screening after a proper password hash migration.
- **Email verification:** New administrator-created users cannot log in until verified. The setup-created first administrator is marked verified, which is appropriate for bootstrap but should be protected by the setup controls above.
- **Password reset:** Tokens are random, hashed, expiring, single-use, and revoke existing access tokens after reset. Reset-email generation errors are intentionally swallowed to preserve generic login behavior, but this should be paired with server-side monitoring.
- **OTP:** Login enforcement is present and OTP setup requires confirmation. Recovery codes, secret rotation, reauthentication, and encrypted secret storage are missing.
- **Authorization:** Admin checks and link ownership checks are present. The last-administrator invariant is enforced for privilege changes and deletion. Add authorization tests for every new destructive endpoint as the API grows.
## Data Protection Review
- SQLite is the primary data store and contains profile data, links, password hashes, tokens, SMTP settings, Mastodon credentials, OAuth state, and OTP secrets. New sensitive values are encrypted with the externally supplied Fernet key; existing plaintext values must be rotated.
- Database backups must be treated as credential-bearing secrets, encrypted, access-controlled, rotated, and tested for secure deletion.
- Avatar files are persistent and publicly served. Validate and re-encode image content before accepting production uploads.
- Link URLs and comments are intentionally public feed data. Operators should document that users must not submit secrets in URLs or comments.
- SMTP and Mastodon integration errors should be redacted before entering logs or API responses.
## Frontend and Extension Review
- Feed content is generally assigned with `textContent`, which is a good XSS defense.
- User-supplied profile values rendered by Jinja should remain autoescaped; do not mark them safe without a narrowly reviewed reason.
- The web API currently uses bearer headers, so browser CSRF risk is lower than with cookie sessions. Keep it that way unless a CSRF token design is added.
- Browser local storage is exposed to any script running in the same origin. Keep third-party scripts out of authenticated pages and add a restrictive CSP.
- The extension's `<all_urls>` host permission should be reduced if the active-tab workflow is sufficient. Review Mozilla Add-ons policies before publishing signed releases.
- The extension stores access and refresh-token-like values in `browser.storage.local`; implement actual refresh semantics or stop storing/returning unused refresh values.
- Extension error messages should not include tokens or full sensitive URLs.
## Deployment Checklist
Before production exposure:
- [ ] Replace SHA-256 password hashing with Argon2id, scrypt, or bcrypt and migrate existing accounts.
- [ ] Remove query-string token authentication and rotate existing access tokens.
- [x] Encrypt newly written SMTP, Mastodon, OAuth, and OTP secrets at rest; protect the encryption key separately. Rotate legacy plaintext values.
- [ ] Add login, OTP, reset-mail, and setup rate limiting.
- [x] Validate Mastodon instances as HTTPS public hostnames, reject unsafe DNS/IP ranges, and block redirects. Keep network-level egress controls in production.
- [ ] Disable direct host publication of the application port in production.
- [ ] Configure HTTPS, HSTS, CSP, Referrer-Policy, frame protections, `nosniff`, and trusted hosts.
- [ ] Define a restrictive CORS policy or leave CORS disabled.
- [ ] Add global request-size limits and hardened image decoding/re-encoding.
- [ ] Add OTP recovery codes and a protected recovery workflow.
- [ ] Remove or implement refresh-token behavior.
- [ ] Add security audit events and centralized redacted logging.
- [ ] Rotate all credentials and set a unique high-entropy production secret.
- [ ] Review extension permissions and submit the XPI only after Mozilla policy review.
- [ ] Encrypt and restrict database/avatar backups, and test restore and revocation procedures.
- [ ] Run a dependency vulnerability scan and a dynamic penetration test against a production-like deployment.
## Suggested Priority Order
1. Password hashing migration.
2. Query-token removal and token rotation.
3. Secret-at-rest protection and backup controls.
4. Login/setup/OTP rate limiting.
5. Production network egress controls for Mastodon.
6. Production network and TLS hardening.
7. Extension permission and credential-storage review.
8. Security headers, trusted hosts, request limits, media validation, recovery codes, and audit logging.
## Verification Performed ## Verification Performed
The repository's automated backend suite was run during this review and passed with 29 tests before the password-storage change; focused password/authentication tests subsequently passed after the remediation. Static Python and JavaScript checks were also used during feature development. These results demonstrate regression coverage, not absence of the findings above. A production release should additionally run a dependency scanner, container scanner, secret scanner, and authenticated dynamic security test. - `PYTHONPATH=. pytest -q`: **49 passed** at the start of this audit.
- Static source review of backend APIs/services, frontend assets, extension manifest/scripts, Compose files, configuration, and tests.
- Targeted searches for authentication, token, secret, upload, outbound-request, error, and audit-log paths.
Functional tests demonstrate regression coverage only; they do not certify production security.
+468
View File
@@ -1,5 +1,179 @@
# Chat Log # Chat Log
### User
The release server fails because its curl does not support `--fail-with-body`.
### Assistant outcome
Replaced all three `--fail-with-body` uses in the release workflow with portable curl response capture and explicit HTTP status checks. Failed API and asset-upload responses now print their response body before exiting, while older curl versions remain supported.
### User
When posting to Mastodon change the formatting so there is an empty line between “From my #LinkLog:” and the title.
### Assistant outcome
Updated the Mastodon formatter so the prefix and title are separate paragraphs: `From my #LinkLog:` followed by a blank line and then the title. Existing comment, source URL, and tag paragraph formatting remains unchanged.
### User
Check the modified pages for the correct link because a version number was added to the signed XPI.
### Assistant outcome
Verified that the signed artifact is `XPI/signed/LinkLog-0.1.0.xpi` and that the About page, Profile page, `webextension/updates.json`, README, and related regression test all reference the matching versioned filename. No changes were required.
### User
In the Profile page below the Save profile button add “If you have not downloaded the plugin yet find it here” with a link to the signed plugin.
### Assistant outcome
Added the plugin download prompt immediately below the Save profile button, linking “find it here” to the signed `LinkLog-0.1.0.xpi` artifact. Added profile-page regression assertions and recorded the change in VIBE.
### User
Add a Plugin section to the About page with a download link to the signed XPI file.
### Assistant outcome
Added a Plugin section to the About page with a download link for the signed `LinkLog-0.1.0.xpi` artifact hosted on the repository's raw main branch. Added a page-rendering regression assertion.
### User
The Firefox plugin tests report that `strict_min_version` 112 is too low for `data_collection_permissions`, `storage.session`, and `permissions.request`.
### Assistant outcome
Raised the extension minimum Firefox version to 142.0, covering the reported desktop and Android manifest/API compatibility warnings. Updated the README to require Firefox 142 or newer.
### User
Implement SA-005: during startup reject missing or known development `LINKLOG_SECRET_KEY` in production, validate minimum length and entropy, require and validate the encryption key, and add fail-closed configuration tests.
### Assistant outcome
Added startup configuration validation before FastAPI app construction. Production now rejects missing/default/weak application secrets and missing or invalid Fernet encryption keys, while development defaults remain available. Added configuration tests for rejection and valid production settings, and updated SA-005 documentation.
### User
For SA-002, log technical details server-side with a request/correlation ID, return a stable public message with a short reference ID, redact secrets, and test that exception text is absent from responses.
### Assistant outcome
Added request-ID middleware and stable public error references. SMTP, setup, email-verification, and Mastodon exception paths now log redacted technical summaries server-side without exposing raw exception text, credentials, authorization values, reset tokens, OTP data, or secret-bearing URL values. Added regression coverage and updated SA-002 documentation.
### User
Remedy SA-001: Logout uses non-standard token transport.
### Assistant outcome
Migrated logout to require `Authorization: Bearer <access-token>`, updated the web frontend and Firefox extension, and added regression coverage proving body-only logout is rejected while header logout revokes the access token and refresh-token family. Updated SA-001, the checklist, and README examples.
### User
Perform a new security audit overwriting Security-audit.md with new and remaining issues.
### Assistant outcome
Replaced the historical audit with a fresh current-state review dated 2026-08-26. The new report records verified controls and nine remaining findings: logout token transport, raw infrastructure errors, unauthenticated setup exposure, audit-detail sanitization, production secret fallback, non-distributed rate limiting, incomplete security headers/request policy, missing audit operations, and incomplete dependency/container/secret/runtime verification. The baseline backend suite passed 49 tests.
### User
Update SA-012 to reflect the actual implementation, document device binding, rotation, reuse detection, family revocation, logout and password-reset revocation, update the checklist and README API examples, and add the refresh endpoint to the documented API surface.
### Assistant outcome
Reconciled SA-012 and the authentication documentation with the implemented 15-minute access tokens and 30-day device-bound refresh tokens. Documented hashing, rotation, reuse-triggered family revocation, logout and password-reset revocation, added the refresh endpoint and curl example to the README, corrected extension login instructions, and checked off the refresh-token implementation item.
### User
Replace `LINKLOG_TOKEN_EXPIRY_DAYS` with `LINKLOG_TOKEN_EXPIRY_MINUTES`, add `LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS` to the production Compose environment, and add a CI test comparing Compose variables with Settings.
### Assistant outcome
Updated production Compose to pass the configured 15-minute access-token and 30-day refresh-token settings. Added a repository test that compares `LINKLOG_*` Compose keys with the environment keys declared by `Settings` and rejects the obsolete days-based access-token variable.
### User
Reduce the size of the font of the greeting somewhat.
### Assistant outcome
Reduced the email greeting from 22px to 18px while preserving the Asset font, top alignment, and placement to the right of the 50×50 logo.
### User
Put the greeting to the right of the logo in the header, and align at the top.
### Assistant outcome
Changed the email header to use separate table cells for the logo and greeting. The greeting cell is explicitly top-aligned and padded to the right of the fixed 50×50 logo, avoiding email-client baseline alignment differences.
### User
Put the header text to the right of the logo and align it on the top. Also add a comma after Hello.
### Assistant outcome
Aligned the email logo and header text at the top of the header row, kept the text to the right of the 50×50 logo, and changed the greeting to “Hello, a message from <public hostname>”.
### User
Instead of “Hello” print “Hello a message from <public hostname>”, with the public hostname linking to the LinkLog server.
### Assistant outcome
Updated the branded email header to show “Hello a message from <public hostname>”. The visible hostname is extracted from the configured public URL and links to that server; the existing 50×50 top-left logo and Asset font styling remain in place.
### User
The logo is still full width. Make it 50px by 50px, put it in the top left, and put “Hello” to the right in the Asset font.
### Assistant outcome
Reworked the email header to use a fixed 50×50 logo at the top-left, with “Hello” immediately to its right in the Asset font with email-safe fallbacks. Added regression assertions for the dimensions, placement styling, and greeting.
### User
The Logo in the emails should be 120px wide and centered on the top.
### Assistant outcome
Updated the shared branded email template so the embedded LinkLog logo is explicitly 120px wide and remains centered in the top header. Added a regression assertion for the rendered width.
### User
Mails sent should be formatted nicely in the style of the website and include the logo.
### Assistant outcome
Added branded multipart emails with a LinkLog-styled HTML layout, an embedded logo, and preserved plain-text fallbacks for verification, password-reset, and SMTP test messages. Dynamic usernames and URLs are HTML-escaped, and email tests cover the HTML body, CID logo reference, and escaping.
### User
Fix SA-015: Some destructive and administrative operations lack audit logging.
### Assistant outcome
Added an append-only `security_audit_events` table and audit service. Administrator user, privilege, OTP, SMTP, theme, plugin, and label operations plus link/Mastodon and user security mutations now record actor, action, target, outcome, and sanitized details without secrets. Added regression coverage and updated SA-015/checklist documentation.
### User
The plugin finds a different title than the new-entry page, see e.g. https://docs.gitea.com/administration/config-cheat-sheet/
### Assistant outcome
Improved the scraper's title extraction to prioritize the page `<title>` tag (matching browser and plugin behavior) over meta tags, and to check for Open Graph, Twitter, and generic meta tags as fallbacks. Tested with Gitea documentation.
### User
The plugin and the new entry page are still inconsistent.
### Assistant outcome
Identified that the HTML response was gzip-compressed and `iter_raw()` was returning compressed bytes instead of decompressed HTML. Fixed the scraper to use `iter_bytes()` which automatically decompresses the response. Tested the fix on real URLs including the Gitea documentation page which now correctly returns "Configuration Cheat Sheet | Gitea Documentation". All 54 backend tests pass.
### User
For https://docs.gitea.com/administration/config-cheat-sheet/ I want the title to be Configuration Cheat Sheet | Gitea Documentation
### Assistant outcome
Verified that the fixed scraper now correctly extracts "Configuration Cheat Sheet | Gitea Documentation" from the Gitea documentation page, matching the browser and plugin behavior. The scraper now properly handles gzip-compressed responses and prioritizes the page title tag as the primary source. All tests pass and the new-entry page and plugin are now consistent.
### User
Solve SA-010: Avatar validation trusts the client MIME type.
### Assistant outcome
Completed avatar hardening with Pillow: uploads are size-limited, decoded and verified rather than trusted by MIME type, bounded to 25 megapixels, fully loaded, normalized to PNG, and served under a fixed `.png` path. Tests now verify PNG normalization and rejection of fake image bytes. SA-010 is marked remediated with `nosniff` and media-origin isolation retained as deployment hardening.
### User
Run full backend and frontend test suites.
### Assistant outcome
The normal backend suite passed with 46 tests. Frontend and extension validation passed for all JavaScript syntax checks, JSON files, XPI rebuild, and unsigned XPI validation. The warnings-as-errors backend variant failed on unclosed SQLite connection `ResourceWarning` instances under Python 3.13; no functional tests failed.
### User
Address SA-007 and use linklog.example.com as default LINKLOG_PUBLIC_URL.
### Assistant outcome
Hardened the production Compose deployment by removing direct host port publication, keeping the app on the external Traefik network, and using `linklog.example.com` as the default public hostname. Added `docker-compose.local.yml` for explicit local direct-port development, updated `.env.example`, backend defaults, README deployment instructions, and SA-007 status.
### User
Fix SA-009: TOTP enrollment has no recovery codes or reset workflow.
### Assistant outcome
Implemented ten one-time hashed TOTP recovery codes, a password-protected `/api/user/otp/recover` workflow, password reauthentication for normal OTP disablement, one-time code consumption, and profile-page controls for saving and using recovery codes. Updated SA-009 and the deployment checklist.
### User
Continue SA-06: Store session credentials in the narrowest available extension storage, minimize token lifetime, support refresh-token rotation, and clear all session material on logout or token invalidation.
### Assistant outcome
Implemented SA-006 session hardening: access tokens now default to 15 minutes, refresh tokens are hashed and persisted separately with device and family binding, rotation revokes prior family state and detects reuse, and password reset revokes sessions. The extension uses Firefox session storage for credentials, refreshes on 401, clears session and legacy local token keys on invalidation/logout, requests only the configured backend origin, and uses a self-only extension-page CSP.
### User
Also allow an admin to reset (disable) OTP for any user.
### Assistant outcome
Added an administrator-only OTP reset endpoint and admin UI action. Resetting a user clears the OTP seed, disables OTP, and deletes all recovery codes. The operation never returns OTP secrets or recovery material and is covered by authorization, missing-user, state, and recovery-code invalidation tests.
### User ### User
Implement SA-006 permission changes: remove `<all_urls>` and unnecessary `tabs`, request exact access to the configured self-hosted backend, and keep page capture behind `activeTab`. Implement SA-006 permission changes: remove `<all_urls>` and unnecessary `tabs`, request exact access to the configured self-hosted backend, and keep page capture behind `activeTab`.
@@ -1028,3 +1202,297 @@ Continue to document every prompt and chat in the VIBE directory.
### Assistant outcome ### Assistant outcome
Recorded this prompt and its outcome in `VIBE/PROMPTS.md` and `VIBE/CHAT_LOG.md`. Future visible prompts and chat outcomes will continue to be appended there. Recorded this prompt and its outcome in `VIBE/PROMPTS.md` and `VIBE/CHAT_LOG.md`. Future visible prompts and chat outcomes will continue to be appended there.
### User
Maintain actions in the logs if VIBE.
### Assistant outcome
Confirmed understanding to continue recording all interactions in the VIBE logs according to the established append-only protocol. Updated PROMPTS.md and CHAT_LOG.md with this dated entry.
### User
Create a new page that can be reached by a button 'new entry' that only shows for authenticated users. The page, also only available to authenticated users allows users to enter a URL. When the URL is entered then the backend will scrape the title and allow to fill in all fields that are also available in the plugin.
### Assistant outcome
Implemented a complete new-entry feature for authenticated users: added `scraper_service.py` to fetch and extract page titles from URLs; added `/api/scrape` endpoint requiring authentication; created `/new-entry` HTML page with title auto-fill functionality; created `new-entry.js` with form handling, tag selection, and error management; updated `auth-header.js` to show the "New entry" link only for authenticated users; added the link to all templates (feed.html, about.html, admin.html, labels.html, user_profile.html, login.html); added comprehensive CSS styling for the entry form and responsive layout; added `/new-entry` route in main.py requiring authentication. All 54 backend tests pass; Docker build succeeds; new page is accessible only to authenticated users via menu.
### User
The plugin finds a different title than the new-entry page, see e.g. https://docs.gitea.com/administration/config-cheat-sheet/
### Assistant outcome
Improved the scraper to check multiple title sources and extract the most relevant one, prioritizing `<title>` tag content when available. Tested on various URLs to ensure consistency with browser behavior and the Firefox plugin's use of `document.title`.
### User
The plugin and the new entry page are still inconsistent.
### Assistant outcome
Identified that the plugin uses browser `document.title` (the `<title>` tag), not meta tags. Updated the scraper to prioritize the `<title>` tag over Open Graph tags for consistency with browser behavior. All tests pass.
### User
For https://docs.gitea.com/administration/config-cheat-sheet/ I want the title to be Configuration Cheat Sheet | Gitea Documentation
### Assistant outcome
Fixed the scraper_service.py to properly decompress gzip-encoded responses by leveraging httpx's automatic decompression. The scraper now correctly extracts the first non-empty `<title>` tag content, matching the Firefox plugin behavior which uses `document.title`. Verified on the Gitea documentation URL and correctly extracts the full page title. All 54 backend tests pass.
### User
After an entry is saved move to the /<user>/ page
### Assistant outcome
Updated new-entry.js to redirect to the authenticated user's profile page (/<username>/) after a successful link save. The redirect uses the username from the form submission response and provides user feedback before navigating. All 54 backend tests pass.
### User
Don't put new entry in the hamburger menu but present it as a separate button next to the style selector
### Assistant outcome
Moved the new-entry button to the header toolbar area outside the hamburger menu, positioning it as a standalone button. Updated all templates (feed.html, about.html, admin.html, labels.html, user_profile.html, login.html, new-entry.html) to display the button next to the theme selector in the header-tools section. Added corresponding CSS styling. All 54 tests pass.
### User
Put the new entry button left of the hamburger menu
### Assistant outcome
Restructured all template headers to position the new-entry button inside the header-actions container, left of the menu-toggle button. Updated feed.html, about.html, admin.html, labels.html, user_profile.html, login.html, and new-entry.html. The button now appears in visual order: new-entry button, then hamburger menu toggle, with proper flexbox alignment and 8px spacing. All 54 backend tests pass.
### User
The style selection should move into the hamburger menu - but in such a way that it becomes a submenu so that it doesn't clutter the menu structure
### Assistant outcome
Moved the theme selector into the hamburger menu as a collapsible submenu. Added theme-submenu-container with a submenu-title button and submenu-options to all templates (feed.html, about.html, admin.html, labels.html, user_profile.html, login.html, new-entry.html). Updated theme.js to populate the submenu with theme buttons instead of adding a picker to header-actions. Updated auth-header.js to handle submenu toggle with aria-expanded for accessibility. Added comprehensive CSS styling for .theme-submenu-container, .submenu-title, .submenu-options, and .theme-option (including .active state). Theme selection now works cleanly within the menu without cluttering the header. All 54 backend tests pass.
### User
The release action should work differently. Rather than publishing the signed XPI and `updates.json`, it should produce a README describing the project, the latest Docker container version, and the latest signed XPI download URL with version number.
### Assistant outcome
Changed the Gitea release workflow to generate `release-readme.md`, use it as the release body, and upload `README.md` as the release asset instead of publishing the signed XPI and `updates.json`. The README describes LinkLog, the Docker image pull location, and the raw signed XPI download URL.
### User
The tagged version will be the version of the backend. However, the version of the plugin is set manually, just use the most recent signed plugin version that lives in the signed repo.
### Assistant outcome
Decoupled backend and plugin release versions. The release tag and Docker image now use the backend `LINKLOG_VERSION`; the workflow discovers the newest semver signed artifact in `XPI/signed/`, validates its embedded manifest, and writes the plugin version and raw XPI URL into the generated release README. Updated release documentation and validated the script, workflow run blocks, and generated README output.
### User
Update the VIBE directory with what you have done.
### Assistant outcome
Appended the release workflow changes and this VIBE update request to `VIBE/PROMPTS.md` and `VIBE/CHAT_LOG.md` in the existing append-only format.
### User
I want that the users is able to edit or delete labels(tags) that were created by the user itself. Also validate that any logged in user will only see the labels created by default, in the admin panel, and those by themselves, not by any other user. If this leads to an update in the database then if ownership of labels is unknown they may be grandfathered as-if created in the admin interface
### Assistant outcome
Implemented creator edit/delete rights for user labels on `/labels` and `/api/user/labels/{label_id}`, isolated label visibility so logged-in users only see default/admin labels and their own created labels, dynamically set `created_by` when new tags are saved from links, grandfathered existing tags with `NULL` ownership as default/admin labels, added `frontend/static/labels.js`, and expanded unit test coverage.
### User
Make sure that in the admin interface the labels can be edited
### Assistant outcome
Added `PUT /api/admin/labels/{label_id}` for administrator label renaming, updated `update_label` service function to accept `is_admin=True`, added inline edit controls to `frontend/static/admin.js` for administrator label management, and added regression test coverage.
### User
Make sure that the logs in VIBE are updated
### Assistant outcome
Updated `VIBE/PROMPTS.md` and `VIBE/CHAT_LOG.md` with the recent user prompts and assistant outcomes.
### User
Update Changelog too
### Assistant outcome
Updated `CHANGELOG.MD` with the recent feature additions (user label CRUD, label visibility isolation, grandfathering unknown label ownership, and administrator label editing), and updated `VIBE/PROMPTS.md` and `VIBE/CHAT_LOG.md`.
### User
In the Admin interface allow to minimize each settings pannel to only show its header, In order to easely navigate the page.
### Assistant outcome
Added collapsible minimize/expand toggle buttons to all settings panels (`.settings-panel`) in the Admin interface. Clicking a panel header toggles its `.minimized` state and `aria-expanded` attribute, hiding the panel body content to show only the header and toggle icon. Added CSS rules and updated tests.
### User
Clicking on the collapse button doesn't toggle
### Assistant outcome
Fixed panel toggle initialization in `admin.js` to attach click handlers immediately on page load and `DOMContentLoaded` rather than waiting for async session validation calls to finish. Added `pointer-events: none` to button child elements in `style.css` and bound event listeners to target headers/buttons with event prevention to guarantee reliable click toggling.
### User
Give the header of each setting-panel a somewhat differing color
### Assistant outcome
Applied distinct theme accent colors (`var(--mauve)`, `var(--teal)`, `var(--peach)`, `var(--blue)`, `var(--lavender)`) to settings panel headers via `:nth-of-type` CSS rules, allowing panel toggle buttons to inherit the accent colors cleanly across all themes.
### User
change the background of the header too
### Assistant outcome
Added soft, translucent accent backgrounds (`color-mix` with `var(--surface-1)`) and accent left borders to each settings panel header in `style.css`. Updated `admin.js` to ensure clicking anywhere on the header bar toggles the panel minimize state cleanly. Passed all 55 tests.
### User
Make sure all setting-panels are collapsed when opening the page
### Assistant outcome
Updated `admin.html` and `admin.js` so all settings panels start with the `minimized` class and `aria-expanded="false"` by default, collapsing all panels on page open. Passed all 55 tests.
### User
Apply exactly the same functionality to the profile page
### Assistant outcome
Applied collapsible minimizable settings panels to the profile page (`user_profile.html` and `profile.js`), starting all panels collapsed by default with toggle buttons, distinct header colors/backgrounds, and aria-expanded state management. Passed all 55 tests.
### User
On the admin page under Available Themes, the page does not load available themes
### Assistant outcome
Fixed element ID conflict on `admin.html` where both the header theme submenu and the admin form container used `id="theme-options"`. Renamed the admin form container to `id="admin-theme-options"` and updated `admin.js` to target `#admin-theme-options`. Available themes now load correctly on the admin page. Passed all 55 tests.
### User
on the new-entry page the checkbox should be following the labels - now they are positioned above.
### Assistant outcome
Reordered the new-entry tag control markup so each label is followed by its checkbox. JavaScript syntax validation and the focused API test module passed with 35 tests.
### User
The checkboxes should be immediately to the left of the label not below left
### Assistant outcome
Restored checkbox-before-label ordering and added a scoped compact-sizing rule for new-entry tag checkboxes. This prevents the mobile global input-width rule from placing a checkbox on its own line. JavaScript syntax validation and the focused API test module passed with 35 tests.
### User
The checkbox takes the full width of the grid which forces the label to be printed underneath instead of directly next to it.
### Assistant outcome
Fixed the actual layout conflict: `.form-section label` uses a grid layout whose selector overrode the tag label's flex layout. Added the more specific `.form-section label.tag-checkbox` inline-flex rule and reset its checkbox margin, keeping each checkbox directly left of its tag text. The focused API test module passed with 35 tests and `git diff --check` passed.
### User
Only show the Mastodon publishing on new page if the user has Mastodon posting configured. Then default the checkbox to yes
### Assistant outcome
Added a safe `configured` status to the authenticated Mastodon configuration response. New Entry now hides its Mastodon publishing section unless the current user has both an instance and access token configured; when shown, its checkbox defaults to checked. Link creation accepts `post_to_mastodon`, allowing an unchecked control to skip Mastodon while preserving dispatch of other plugins. Added posting and configuration regression coverage.
### User
In the currently running contaier the user olaf has no mastodon configured but the mastodon checkbox is still visible
### Assistant outcome
Found that `.form-section { display: grid; }` appeared later in the stylesheet than `.hidden { display: none; }`, overriding the initial hidden state of the Mastodon fieldset. Added `.form-section.hidden { display: none; }`, so the publishing control stays hidden until the authenticated configuration check explicitly reveals it.
### User
When clicking on the logo always go to the home page
### Assistant outcome
Wrapped the header logo in each web template with an accessible home-page link. Extended the heading font selector for the new logo-link wrapper, preserving existing header styling. Confirmed all eight templates contain exactly one home-linked logo and the focused API test module passed with 36 tests.
### User
Add a red collor theme
### Assistant outcome
Added a Red theme to the theme catalog with a high-contrast crimson palette in the frontend stylesheet. It is enabled by default on new installations and is available to select under Admin > Available themes. Extended the theme-selection regression test to verify the public theme API returns it when enabled.
### User
Make the theme brighter and darker red
### Assistant outcome
Refined the Red theme palette with brighter white and red-tinted surfaces, plus deeper saturated crimson accents, borders, and shadows while preserving dark high-contrast text. The focused theme API test and whitespace validation passed.
### User
Since checkin d433a305f5cd8ccdafde8a0f7764462e8c167162 on the home page the filter toolbar moved so that the menu button and new entry are not in the top left anylonger - revert to the previous layout
### Assistant outcome
Confirmed the referenced commit did not change the feed header, then identified the current template had the toolbar outside its `.header-tools` wrapper. Restored the prior header structure: the New Entry and menu controls remain grouped above the filter toolbar on the right side of the home-page header. Added a rendered-page regression assertion for `.header-tools`.
### User
I want every user to filter on every available tag/label
### Assistant outcome
Separated feed filtering from label management: `/api/tags` now returns every tag/label to all callers, allowing complete filtering of the public feed. `/api/user/labels` remains ownership-scoped, so users still cannot manage other users' labels. Updated tag visibility regression coverage for authenticated and anonymous callers.
### User
tag filter doesn't seem to respond when pressed
### Assistant outcome
Updated the tag-filter change handler to pass the newly selected tag directly to the feed refresh instead of relying on the browser to persist and immediately reread the preference cookie. This makes filtering work even when cookie persistence is unavailable or delayed. Cache-busted the feed script to `feed.js?v=10` and added a regression assertion for the direct refresh path.
### User
The tag filter still does not allow me to select tags, even though the raw html contains the correct content. Also the user filter and the sort functionality work too
### Assistant outcome
Verified the live running container with Chromium and Playwright: selecting `#AI` changes the tag dropdown value, writes the preference cookie, and renders only matching feed entries. The deployed script already contains the direct-refresh handler, so cache-busted it again to `feed.js?v=11` and rebuilt the Compose service. Confirmed the live page serves the new asset version.
### User
I believe tag selection was still working for v0.1.0 - it is still broken
### Assistant outcome
Found the actual regression in the direct-refresh update: `Promise.all([loadUsers(), loadTags()]).then(loadFeed)` passed its results array into the new `selectedTag` parameter. The feed then attempted to call `toLowerCase()` on that array during initialization. Restored the v0.1.0 callback shape with `.then(() => loadFeed())`, retained direct selected-tag refreshes, added a regression assertion, and cache-busted the feed asset to `feed.js?v=12`.
### User
Don't let the frontend and plugin pull from the google foundry but make sure any necessary fonts are served from the linklog server. I would prefer the fonts to be updated at docker image building time.
### Assistant outcome
Removed the web frontend's Google Fonts import and added a Docker build-time font bundling script. Image builds now download pinned Asset, DM Sans, and Space Grotesk files into `frontend/static/fonts`, generate a local `fonts.css`, and serve them through LinkLog at `/static/fonts`. The Firefox extension did not make Google Font requests and continues to use bundled assets with local fallback fonts. A clean image build confirmed all nine local font assets are present.
### User
On the new-entry page follow the logic for existing pages that already exists in the plugin and display "This link already exists. Comment and tags can be updated, and by submitting publishing will be retriggered." when the link exists. Also assess if the Auto-fill title button is necessary, or if the functionality can be automated while the URL is entered.
### Assistant outcome
Added a duplicate-check request (`GET /api/links/check`) to `new-entry.js`, triggered on URL/title blur, that shows the requested warning in a new `#duplicate-status` element and clears it as the fields are edited. Replaced the manual "Auto-fill Title" button with automatic scraping on URL blur (only filling the title when it is still empty and the URL actually changed), removing the now-unused button and CSS.
### User
Also: detect as duplicate when the URL has arguments (not already stripped). And: add a button to re-fetch the title for if the URL has been fetched but the user still edits the field.
### Assistant outcome
Added client-side stripping of known tracking parameters (`utm_*`, `gclid`, `fbclid`, etc.) mirroring the browser extension, applied consistently to the scrape lookup, duplicate check, and submission. Added a "Re-fetch Title" button next to the title field that force-refreshes the scraped title regardless of the auto-fill guard.
### User
If the link already exist with URL arguments then also display the warning, but add that the link has been stored additional parameters.
### Assistant outcome
Extended the duplicate warning to note when the stored link had additional URL parameters stripped (e.g. tracking parameters) compared to the entered URL.
### User
I want this last change to be more precise: I do not want to be warned when parameters are stripped, but when the URL entered has arguments/parameters and the URL in the database has none or different ones (even after tracking parameters are stripped).
### Assistant outcome
Added `find_owned_link_by_title` in `link_service.py` and extended `GET /api/links/check` to return `{exists, url_matches, stored_url}`, detecting a title match with a differing URL in addition to an exact match. `new-entry.js` now only warns about a differing stored URL when `url_matches` is false, no longer warning solely because tracking parameters were stripped from an otherwise matching URL.
### User
In the check duplicate I have a `<br>` tag, but that shows as formatted text on the page, I want a real break to occur at that position.
### Assistant outcome
Reworked `setStatus` in `new-entry.js` to split messages on `\n` and build real `<br>` elements via DOM APIs instead of relying on `textContent` (which escaped the literal `<br>`) or unsafe `innerHTML`.
### User
Update VIBE and Changelog.
### Assistant outcome
Appended the new-entry duplicate-detection and title auto-fill work to `VIBE/PROMPTS.md` and `VIBE/CHAT_LOG.md`, and added a Version v0.1.3 section to `CHANGELOG.MD`.
### User
Make sure the webplugin has the same functionality as just implemented in the new-entry page. Increase its version number to 0.2.0.
### Assistant outcome
Brought `webextension/popup.js` to parity with `new-entry.js`: the duplicate check now distinguishes an exact title/URL match from a title match with a differing stored URL (using the same `/api/links/check` `url_matches`/`stored_url` fields) and shows an additional localized note in the latter case; added a "Re-fetch title" button that calls the backend `/api/scrape` endpoint (guarded by existing backend-permission checks) and auto-fills the title on URL blur when empty; reworked `setStatus` to render real `<br>` line breaks via DOM APIs instead of `textContent`. Added `duplicateLinkDifferentUrl`, `refetchTitle`, and `titleFetchFailed` strings to all five locale files, updated `popup.html` with the new button, and bumped `manifest.json` to version `0.2.0`. Full backend test suite (36 tests) passed.
### User
Add a feature to the Make file that updates the updates.json file based on available signed releases.
### Assistant outcome
Added `make update-updates`, which regenerates `webextension/updates.json` from valid versioned signed XPIs. The generator reads each packaged manifest, validates its version, add-on ID, and Firefox minimum version, and ignores non-release artifacts.
### User
Add sha hashes to the updates.json
### Assistant outcome
Added Firefox-compatible `sha256:<hex>` update hashes generated from each signed XPI's bytes. Release validation now rejects missing or mismatched hashes; the generated metadata and release validator passed for signed versions 0.2.0 and 0.1.0.
### User
Update changelog and VIBE
### Assistant outcome
Recorded the signed-XPI update metadata automation and SHA-256 integrity hashes in the v0.2.0 changelog and VIBE logs.
### User
Make sure that when the plugin is signed the version in the link it the about page is updated too
### Assistant outcome
Extended `make update-updates` to set the About page plugin download URL to the newest valid signed XPI. Release validation now also rejects an About page whose link does not match the latest signed artifact; verified with LinkLog 0.2.0.
### User
Release script fails because the runner's hashlib module has no file_digest attribute.
### Assistant outcome
Replaced Python 3.11-only `hashlib.file_digest` calls in signed-XPI metadata generation and release validation with streaming SHA-256 calculations compatible with older Python runners. Regenerated update metadata and verified release validation passes.
+85
View File
@@ -183,6 +183,91 @@
179. Use the VIBE directory to log interactions. 179. Use the VIBE directory to log interactions.
180. Implement SA-006: remove broad Firefox extension host access and unnecessary tabs permission, request exact configured backend origin access, and keep page capture behind activeTab. 180. Implement SA-006: remove broad Firefox extension host access and unnecessary tabs permission, request exact configured backend origin access, and keep page capture behind activeTab.
181. Continue to document every prompt and chat in the VIBE directory. 181. Continue to document every prompt and chat in the VIBE directory.
182. Continue SA-006: store session credentials in the narrowest available extension storage, minimize token lifetime, support refresh-token rotation, and clear all session material on logout or token invalidation.
183. Also allow an admin to reset (disable) OTP for any user.
183. Fix SA-009: TOTP enrollment has no recovery codes or reset workflow.
183. Address SA-007 and use linklog.example.com as the default LINKLOG_PUBLIC_URL.
184. Run full backend and frontend test suites.
185. Solve SA-010: Avatar validation trusts the client MIME type.
186. Fix SA-015: Some destructive and administrative operations lack audit logging.
187. Format sent mail in the website style and include the logo.
188. Set the email logo to 120px wide and center it at the top.
189. Make the email logo 50px by 50px, place it top-left, and put "Hello" to its right in the Asset font.
190. Replace the email greeting with "Hello a message from <public hostname>", linking the hostname to the LinkLog server.
191. Put the email header text to the right of the logo, align it at the top, and add a comma after Hello.
192. Put the email greeting in a separate top-aligned cell to the right of the logo.
193. Reduce the email greeting font size somewhat.
194. Replace LINKLOG_TOKEN_EXPIRY_DAYS with LINKLOG_TOKEN_EXPIRY_MINUTES, add LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS to production Compose, and add a CI configuration consistency test.
195. Perform a new security audit overwriting Security-audit.md with new and remaining issues.
195. Update SA-012 and README for the implemented refresh-token lifecycle, revocation behavior, and refresh endpoint.
196. Remedy SA-001: migrate logout from JSON token transport to the Authorization bearer header.
197. Implement SA-002: replace raw infrastructure errors with redacted server-side logging, request IDs, and stable public reference messages.
198. Implement SA-005: reject missing/default/weak production secrets at startup and validate the Fernet encryption key, with configuration tests.
199. Fix Firefox manifest compatibility warnings by aligning the minimum version with data collection permissions and session storage support.
200. Add a Plugin section to the About page with a download link to the signed XPI file.
201. Below the Save profile button, add a link to download the signed plugin if it has not been downloaded yet.
202. Check the modified pages for the correct versioned signed XPI link.
203. When posting to Mastodon, add an empty line between "From my #LinkLog:" and the title.
204. Fix the release workflow because the runner's curl does not support `--fail-with-body`.
205. The release action should work differently. Rather than publishing the signed XPI and `updates.json`, it should produce a README describing the project, the latest Docker container version, and the latest signed XPI download URL with version number.
206. The tagged version will be the version of the backend. However, the version of the plugin is set manually, just use the most recent signed plugin version that lives in the signed repo.
207. Update the VIBE directory with what you have done.
## 2026-08-27
205. Maintain actions in the logs if VIBE.
206. Create a new page that can be reached by a button 'new entry' that only shows for authenticated users. The page, also only available to authenticated users allows users to enter a URL. When the URL is entered then the backend will scrape the title and allow to fill in all fields that are also available in the plugin.
207. The plugin finds a different title than the new-entry page, see e.g. https://docs.gitea.com/administration/config-cheat-sheet/
208. The plugin and the new entry page are still inconsistent.
209. For https://docs.gitea.com/administration/config-cheat-sheet/ I want the title to be Configuration Cheat Sheet | Gitea Documentation
210. After an entry is saved move to the /<user>/ page
211. Don't put new entry in the hamburger menu but present it as a seperate button next to the style selector
212. Put the new entry button left of the hamburger menu
213. The style selection should move into the hamburger menu - but in such a way that it becomes a submenu so that it doesn't clutter the menu structure
214. I want that the users is able to edit or delete labels(tags) that were created by the user itself. Also validate that any logged in user will only see the labels created by default, in the admin panel, and those by themselves, not by any other user. If this leads to an update in the database then if ownership of labels is unknown they may be grandfathered as-if created in the admin interface
215. Make sure that in the admin interface the labels can be edited
216. Make sure that the logs in VIBE are updated
217. Update Changelog too
218. In the Admin interface allow to minimize each settings pannel to only show its header, In order to easely navigate the page.
219. Make sure all setting-panels are collapsed when opening the page
218. In the Admin interface allow to minimize each settings pannel to only show its header, In order to easely navigate the page.
219. Give the header of each setting-panel a somewhat differing color.
220. Change the background of the header too.
221. Apply exactly the same functionality to the profile page
222. On the admin page under Available Themes, the page does not load available themes
218. Give the header of each setting-panel a somewhat differing color
218. In the Admin interface allow to minimize each settings pannel to only show its header, In order to easely navigate the page.
219. Clicking on the collapse button doesn't toggle
218. In the Admin interface allow to minimize each settings pannel to only show its header, In order to easely navigate the page.
223. On the new-entry page the checkbox should be following the labels - now they are positioned above.
224. The checkboxes should be immediately to the left of the label not below left
225. The checkbox takes the full width of the grid which forces the label to be printed underneath instead of directly next to it.
226. Only show the Mastodon publishing on new page if the user has Mastodon posting configured. Then default the checkbox to yes
227. In the currently running contaier the user olaf has no mastodon configured but the mastodon checkbox is still visible
228. When clicking on the logo always go to the home page
229. Add a red collor theme
230. Make the theme brighter and darker red
231. Since checkin d433a305f5cd8ccdafde8a0f7764462e8c167162 on the home page the filter toolbar moved so that the menu button and new entry are not in the top left anylonger - revert to the previous layout
232. I want every user to filter on every available tag/label
233. tag filter doesn't seem to respond when pressed
234. The tag filter still does not allow me to select tags, even though the raw html contains the correct content. Also the user filter and the sort functionality work too
235. I believe tag selection was still working for v0.1.0 - it is still broken
236. Don't let the frontend and plugin pull from the google foundry but make sure any necessary fonts are served from the linklog server. I would prefer the fonts to be updated at docker image building time.
## 2026-08-28
237. On the new-entry page follow the logic for existing pages that already exists in the plugin and display "This link already exists. Comment and tags can be updated, and by submitting publishing will be retriggered." when the link exists. Also assess if the Auto-fill title button is necessary, or if the functionality can be automated while the URL is entered.
238. Also: detect as duplicate when the URL has arguments (not already stripped). And: add a button to re-fetch the title for if the URL has been fetched but the user still edits the field.
239. If the link already exist with URL arguments then also display the warning, but add that the link has been stored additional parameters.
240. I want this last change to be more precise: I do not want to be warned when parameters are stripped, but when the URL entered has arguments/parameters and the URL in the database has none or different ones (even after tracking parameters are stripped).
241. In the check duplicate I have a `<br>` tag, but that shows as formatted text on the page, I want a real break to occur at that position.
242. Update VIBE and Changelog.
243. Make sure the webplugin has the same functionality as just implemented in the new-entry page. Increase its version number to 0.2.0.
244. Add a feature to the Make file that updates the updates.json file based on available signed releases.
245. Add sha hashes to the updates.json
246. Update changelog and VIBE
247. Make sure that when the plugin is signed the version in the link it the about page is updated too
248. Release script fails because the runner's hashlib module has no file_digest attribute.
## Future entries ## Future entries
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
+55 -10
View File
@@ -5,12 +5,12 @@ import json
from datetime import datetime, timedelta, timezone from datetime import datetime, timedelta, timezone
from uuid import uuid4 from uuid import uuid4
from fastapi import APIRouter, Depends, HTTPException from fastapi import APIRouter, Depends, HTTPException, Request
from pydantic import BaseModel from pydantic import BaseModel
from backend.app.api.dependencies import require_admin from backend.app.api.dependencies import require_admin
from backend.app.database import get_connection, hash_password from backend.app.database import get_connection, hash_password
from backend.app.services.link_service import delete_label from backend.app.services.link_service import delete_label, update_label
from backend.app.services.email_service import ( from backend.app.services.email_service import (
get_smtp_settings, get_smtp_settings,
save_smtp_settings, save_smtp_settings,
@@ -22,8 +22,12 @@ from backend.app.services.email_verification import create_verification_token
from backend.app.services.theme_service import THEMES, get_enabled_themes, save_enabled_themes from backend.app.services.theme_service import THEMES, get_enabled_themes, save_enabled_themes
from backend.app.services.secret_store import encrypt_secret from backend.app.services.secret_store import encrypt_secret
from backend.app.core.config import settings from backend.app.core.config import settings
from backend.app.services.audit_service import record_audit_event
from backend.app.core.errors import public_error, redacted_error, request_id
import logging
router = APIRouter() router = APIRouter()
logger = logging.getLogger(__name__)
class AdminPluginUpdate(BaseModel): class AdminPluginUpdate(BaseModel):
@@ -31,6 +35,10 @@ class AdminPluginUpdate(BaseModel):
config: dict | None = None config: dict | None = None
class AdminLabelUpdate(BaseModel):
name: str
class AdminUserCreate(BaseModel): class AdminUserCreate(BaseModel):
username: str username: str
email: str email: str
@@ -94,8 +102,24 @@ def list_users(_: dict = Depends(require_admin)):
return [public_user(row) for row in rows] return [public_user(row) for row in rows]
@router.post('/users/{user_id}/otp/reset')
def reset_user_otp(user_id: str, current_user: dict = Depends(require_admin)):
with get_connection() as conn:
target = conn.execute('SELECT id FROM users WHERE id = ?', (user_id,)).fetchone()
if target is None:
raise HTTPException(status_code=404, detail='User not found')
conn.execute(
'UPDATE users SET otp_enabled = 0, otp_secret = NULL, updated_at = CURRENT_TIMESTAMP WHERE id = ?',
(user_id,),
)
conn.execute('DELETE FROM otp_recovery_codes WHERE user_id = ?', (user_id,))
conn.commit()
record_audit_event(current_user['id'], 'otp_reset', 'user', user_id)
return {'status': 'otp_reset', 'enabled': False, 'user_id': user_id}
@router.post('/users', status_code=201) @router.post('/users', status_code=201)
def create_user(payload: AdminUserCreate, _: dict = Depends(require_admin)): def create_user(payload: AdminUserCreate, request: Request, current_user: dict = Depends(require_admin)):
username = payload.username.strip() username = payload.username.strip()
email = payload.email.strip() email = payload.email.strip()
if not username or not email or len(payload.password) < 8: if not username or not email or len(payload.password) < 8:
@@ -125,7 +149,9 @@ def create_user(payload: AdminUserCreate, _: dict = Depends(require_admin)):
try: try:
send_verification_email(row['email'], row['username'], verification_url) send_verification_email(row['email'], row['username'], verification_url)
except Exception as error: except Exception as error:
raise HTTPException(status_code=503, detail=f'User created but verification email could not be sent: {error}') from error logger.error('User verification email failed request_id=%s error=%s', request_id(request), redacted_error(error))
raise HTTPException(status_code=503, detail=public_error(request, 'User created but verification email could not be sent.')) from error
record_audit_event(current_user['id'], 'user_created', 'user', row['id'], details={'is_admin': bool(payload.is_admin)})
return public_user(row) return public_user(row)
@@ -151,24 +177,26 @@ def get_admin_themes(_: dict = Depends(require_admin)):
@router.put('/themes') @router.put('/themes')
def update_admin_themes(payload: AdminThemesUpdate, _: dict = Depends(require_admin)): def update_admin_themes(payload: AdminThemesUpdate, current_user: dict = Depends(require_admin)):
try: try:
enabled = save_enabled_themes(payload.themes) enabled = save_enabled_themes(payload.themes)
except ValueError as error: except ValueError as error:
raise HTTPException(status_code=422, detail=str(error)) from error raise HTTPException(status_code=422, detail=str(error)) from error
record_audit_event(current_user['id'], 'themes_updated', 'application', details={'themes': enabled})
return {'themes': THEMES, 'enabled': enabled} return {'themes': THEMES, 'enabled': enabled}
@router.put('/smtp') @router.put('/smtp')
def update_admin_smtp_settings(payload: AdminSmtpUpdate, _: dict = Depends(require_admin)): def update_admin_smtp_settings(payload: AdminSmtpUpdate, current_user: dict = Depends(require_admin)):
current = get_smtp_settings() current = get_smtp_settings()
values = validate_smtp_values(payload, current) values = validate_smtp_values(payload, current)
save_smtp_settings(values) save_smtp_settings(values)
record_audit_event(current_user['id'], 'smtp_settings_updated', 'application', details={'host': values['smtp_host'], 'port': values['smtp_port'], 'username': values['smtp_username'], 'tls': values['smtp_use_tls']})
return public_smtp_settings(values) return public_smtp_settings(values)
@router.post('/smtp/test') @router.post('/smtp/test')
def validate_admin_smtp(payload: AdminSmtpUpdate, current_user: dict = Depends(require_admin)): def validate_admin_smtp(payload: AdminSmtpUpdate, request: Request, current_user: dict = Depends(require_admin)):
values = validate_smtp_values(payload, get_smtp_settings()) values = validate_smtp_values(payload, get_smtp_settings())
now = datetime.now(timezone.utc) now = datetime.now(timezone.utc)
with get_connection() as conn: with get_connection() as conn:
@@ -189,7 +217,8 @@ def validate_admin_smtp(payload: AdminSmtpUpdate, current_user: dict = Depends(r
try: try:
send_test_email(current_user['email'], values) send_test_email(current_user['email'], values)
except Exception as error: except Exception as error:
raise HTTPException(status_code=503, detail=f'SMTP validation failed: {error}') from error logger.error('SMTP validation failed request_id=%s error=%s', request_id(request), redacted_error(error))
raise HTTPException(status_code=503, detail=public_error(request, 'SMTP validation failed.')) from error
sends = int(rate.get('sends', 0)) + 1 sends = int(rate.get('sends', 0)) + 1
updated_rate = {'sends': sends, 'last_sent': now.isoformat()} updated_rate = {'sends': sends, 'last_sent': now.isoformat()}
if sends >= 5: if sends >= 5:
@@ -244,6 +273,7 @@ def update_user_privileges(
'SELECT id, username, email, is_admin, avatar_url, bio, created_at, email_verified FROM users WHERE id = ?', 'SELECT id, username, email, is_admin, avatar_url, bio, created_at, email_verified FROM users WHERE id = ?',
(user_id,), (user_id,),
).fetchone() ).fetchone()
record_audit_event(current_user['id'], 'user_privileges_updated', 'user', user_id, details={'is_admin': bool(payload.is_admin)})
return public_user(row) return public_user(row)
@@ -266,16 +296,30 @@ def delete_user(user_id: str, current_user: dict = Depends(require_admin)):
conn.execute('DELETE FROM links WHERE user_id = ?', (user_id,)) conn.execute('DELETE FROM links WHERE user_id = ?', (user_id,))
conn.execute('DELETE FROM users WHERE id = ?', (user_id,)) conn.execute('DELETE FROM users WHERE id = ?', (user_id,))
conn.commit() conn.commit()
record_audit_event(current_user['id'], 'user_deleted', 'user', user_id)
return {'status': 'deleted', 'id': user_id} return {'status': 'deleted', 'id': user_id}
@router.delete('/labels/{label_id}') @router.delete('/labels/{label_id}')
def admin_delete_label(label_id: str, _: dict = Depends(require_admin)): def admin_delete_label(label_id: str, current_user: dict = Depends(require_admin)):
if not delete_label(label_id, is_admin=True): if not delete_label(label_id, is_admin=True):
raise HTTPException(status_code=404, detail='Label not found') raise HTTPException(status_code=404, detail='Label not found')
record_audit_event(current_user['id'], 'label_deleted', 'label', label_id)
return {'status': 'deleted', 'id': label_id} return {'status': 'deleted', 'id': label_id}
@router.put('/labels/{label_id}')
def admin_edit_label(label_id: str, payload: AdminLabelUpdate, current_user: dict = Depends(require_admin)):
try:
result = update_label(label_id, user_id=current_user['id'], name=payload.name, is_admin=True)
except ValueError as error:
raise HTTPException(status_code=409, detail=str(error)) from error
if result is None:
raise HTTPException(status_code=404, detail='Label not found')
record_audit_event(current_user['id'], 'label_updated', 'label', label_id)
return result
@router.get('/labels') @router.get('/labels')
def admin_list_labels(_: dict = Depends(require_admin)): def admin_list_labels(_: dict = Depends(require_admin)):
with get_connection() as conn: with get_connection() as conn:
@@ -331,7 +375,7 @@ def get_plugin(plugin_name: str, _: dict = Depends(require_admin)):
def update_plugin( def update_plugin(
plugin_name: str, plugin_name: str,
payload: AdminPluginUpdate, payload: AdminPluginUpdate,
_: dict = Depends(require_admin), current_user: dict = Depends(require_admin),
): ):
with get_connection() as conn: with get_connection() as conn:
current = conn.execute( current = conn.execute(
@@ -360,6 +404,7 @@ def update_plugin(
) )
conn.commit() conn.commit()
record_audit_event(current_user['id'], 'plugin_updated', 'plugin', plugin_name, details={'enabled': enabled})
return { return {
'name': plugin_name, 'name': plugin_name,
'enabled': enabled, 'enabled': enabled,
+30 -6
View File
@@ -3,7 +3,7 @@
from uuid import uuid4 from uuid import uuid4
from fastapi import APIRouter, Depends, HTTPException, Request from fastapi import APIRouter, Depends, Header, HTTPException, Request
from pydantic import BaseModel from pydantic import BaseModel
from backend.app.api.dependencies import get_current_user from backend.app.api.dependencies import get_current_user
@@ -13,7 +13,7 @@ from backend.app.services.auth_service import authenticate_user, find_user
from backend.app.services.email_service import send_password_reset_email, smtp_configured from backend.app.services.email_service import send_password_reset_email, smtp_configured
from backend.app.services.email_verification import verify_email from backend.app.services.email_verification import verify_email
from backend.app.services.password_reset import create_reset_token, reset_password from backend.app.services.password_reset import create_reset_token, reset_password
from backend.app.services.token_service import issue_token, revoke_token, validate_token from backend.app.services.token_service import issue_token, revoke_token, rotate_refresh_token, validate_token
from backend.app.services.otp_service import verify_code from backend.app.services.otp_service import verify_code
from backend.app.services.secret_store import decrypt_secret from backend.app.services.secret_store import decrypt_secret
from backend.app.services.email_addresses import verify_user_email_address from backend.app.services.email_addresses import verify_user_email_address
@@ -28,6 +28,12 @@ class LoginRequest(BaseModel):
email: str email: str
password: str password: str
otp: str | None = None otp: str | None = None
device_id: str | None = None
class RefreshTokenRequest(BaseModel):
refresh_token: str
device_id: str | None = None
class PasswordResetRequest(BaseModel): class PasswordResetRequest(BaseModel):
@@ -62,16 +68,32 @@ def login(payload: LoginRequest, request: Request):
raise HTTPException(status_code=401, detail='One-time password required or invalid') raise HTTPException(status_code=401, detail='One-time password required or invalid')
clear_login_failures(ip_address, email) clear_login_failures(ip_address, email)
token_data = issue_token(user['id'], user['username']) token_data = issue_token(user['id'], user['username'], payload.device_id)
return { return {
'access_token': token_data['access_token'], 'access_token': token_data['access_token'],
'token_type': 'bearer', 'token_type': 'bearer',
'expires_at': token_data['expires_at'], 'expires_at': token_data['expires_at'],
'refresh_token': token_data['refresh_token'], 'refresh_token': token_data['refresh_token'],
'device_id': token_data['device_id'],
'user': {'id': user['id'], 'username': user['username'], 'email': user['email'], 'otp_enabled': bool(user['otp_enabled'])} 'user': {'id': user['id'], 'username': user['username'], 'email': user['email'], 'otp_enabled': bool(user['otp_enabled'])}
} }
@router.post('/refresh')
def refresh_token_endpoint(payload: RefreshTokenRequest):
rotated = rotate_refresh_token(payload.refresh_token, payload.device_id)
if rotated is None:
raise HTTPException(status_code=401, detail='Refresh token is invalid, expired, or bound to another device')
return {
'access_token': rotated['access_token'],
'token_type': 'bearer',
'expires_at': rotated['expires_at'],
'refresh_token': rotated['refresh_token'],
'device_id': rotated['device_id'],
'user': {'id': rotated['user_id'], 'username': rotated['username']},
}
@router.get('/verify-email') @router.get('/verify-email')
def verify_email_address(token: str): def verify_email_address(token: str):
if not verify_email(token): if not verify_email(token):
@@ -97,10 +119,12 @@ def reset_password_endpoint(payload: PasswordResetRequest):
@router.post('/logout') @router.post('/logout')
def logout(payload: dict): def logout(authorization: str | None = Header(default=None)):
token = payload.get('token') if not authorization or not authorization.startswith('Bearer '):
raise HTTPException(status_code=401, detail='Missing or invalid Authorization header')
token = authorization.replace('Bearer ', '', 1).strip()
if not token: if not token:
raise HTTPException(status_code=400, detail='Token is required') raise HTTPException(status_code=401, detail='Missing or invalid Authorization header')
revoked = revoke_token(token) revoked = revoke_token(token)
if not revoked: if not revoked:
raise HTTPException(status_code=404, detail='Token not found or already revoked') raise HTTPException(status_code=404, detail='Token not found or already revoked')
+16
View File
@@ -38,6 +38,22 @@ def get_current_user(
return dict(user) return dict(user)
def get_optional_current_user(
credentials: HTTPAuthorizationCredentials | None = Depends(bearer_scheme),
) -> dict | None:
if credentials is None or credentials.scheme.lower() != 'bearer':
return None
token_data = validate_token(credentials.credentials)
if token_data is None:
return None
with get_connection() as conn:
user = conn.execute(
'SELECT * FROM users WHERE id = ?',
(token_data['user_id'],),
).fetchone()
return dict(user) if user else None
def require_admin(user: dict = Depends(get_current_user)): def require_admin(user: dict = Depends(get_current_user)):
if not user['is_admin']: if not user['is_admin']:
raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail='Administrator access required') raise HTTPException(status_code=status.HTTP_403_FORBIDDEN, detail='Administrator access required')
+33 -4
View File
@@ -2,14 +2,16 @@
## SPDX-License-Identifier: GPL-3.0-or-later ## SPDX-License-Identifier: GPL-3.0-or-later
import json import json
from fastapi import APIRouter, Header, HTTPException, Response, status from fastapi import APIRouter, Depends, Header, HTTPException, Response, status
import logging import logging
from pydantic import BaseModel from pydantic import BaseModel
from backend.app.services.link_service import create_link, delete_link, find_owned_link_by_title_url, get_link_tags, get_owned_link, list_public_links, list_tags, mark_mastodon_posted, update_link from backend.app.services.link_service import create_link, delete_link, find_owned_link_by_title, find_owned_link_by_title_url, get_link_tags, get_owned_link, list_public_links, list_tags, mark_mastodon_posted, update_link
from backend.app.database import get_connection from backend.app.database import get_connection
from backend.app.services.plugin_manager import plugin_manager from backend.app.services.plugin_manager import plugin_manager
from backend.app.services.token_service import validate_token from backend.app.services.token_service import validate_token
from backend.app.services.audit_service import record_audit_event
from backend.app.services.scraper_service import scrape_title
router = APIRouter() router = APIRouter()
logger = logging.getLogger(__name__) logger = logging.getLogger(__name__)
@@ -21,6 +23,7 @@ class LinkCreate(BaseModel):
comment: str = '' comment: str = ''
timestamp: str | None = None timestamp: str | None = None
tags: list[str] = [] tags: list[str] = []
post_to_mastodon: bool = True
class LinkUpdate(BaseModel): class LinkUpdate(BaseModel):
@@ -35,6 +38,21 @@ def available_tags():
return list_tags() return list_tags()
@router.get('/scrape')
def scrape_url(url: str, authorization: str | None = Header(default=None)):
if not authorization or not authorization.startswith('Bearer '):
raise HTTPException(status_code=401, detail='Missing or invalid Authorization header')
info = validate_token(authorization.replace('Bearer ', '', 1))
if info is None:
raise HTTPException(status_code=401, detail='Token expired or invalid')
try:
title = scrape_title(url)
return {'title': title}
except Exception as e:
logger.error('Scrape error for %s: %s', url, e)
raise HTTPException(status_code=502, detail='Could not scrape URL') from e
@router.get('/links/check') @router.get('/links/check')
def check_existing_link( def check_existing_link(
title: str, title: str,
@@ -47,7 +65,12 @@ def check_existing_link(
if info is None: if info is None:
raise HTTPException(status_code=401, detail='Token expired or invalid') raise HTTPException(status_code=401, detail='Token expired or invalid')
record = find_owned_link_by_title_url(info['user_id'], title, url) record = find_owned_link_by_title_url(info['user_id'], title, url)
return {'exists': record is not None} if record is not None:
return {'exists': True, 'url_matches': True, 'stored_url': record['url']}
record = find_owned_link_by_title(info['user_id'], title)
if record is not None:
return {'exists': True, 'url_matches': False, 'stored_url': record['url']}
return {'exists': False, 'url_matches': None, 'stored_url': None}
@router.post('/links', status_code=status.HTTP_201_CREATED) @router.post('/links', status_code=status.HTTP_201_CREATED)
@@ -70,7 +93,11 @@ def create_link_endpoint(payload: LinkCreate, response: Response, authorization:
raise HTTPException(status_code=422, detail=str(error)) from error raise HTTPException(status_code=422, detail=str(error)) from error
if duplicate: if duplicate:
response.status_code = status.HTTP_200_OK response.status_code = status.HTTP_200_OK
plugin_results = plugin_manager.dispatch({'type': 'link_created', **record}) plugin_results = plugin_manager.dispatch({
'type': 'link_created',
'post_to_mastodon': payload.post_to_mastodon,
**record,
})
mastodon_result = next((result for result in plugin_results if result.get('plugin') == 'mastodon'), None) mastodon_result = next((result for result in plugin_results if result.get('plugin') == 'mastodon'), None)
if mastodon_result and mastodon_result.get('status') == 'posted': if mastodon_result and mastodon_result.get('status') == 'posted':
mark_mastodon_posted(record['id'], info['user_id'], mastodon_result.get('post_id')) mark_mastodon_posted(record['id'], info['user_id'], mastodon_result.get('post_id'))
@@ -127,6 +154,7 @@ def delete_link_endpoint(
raise HTTPException(status_code=502, detail=result.get('reason', 'Could not delete Mastodon posts')) raise HTTPException(status_code=502, detail=result.get('reason', 'Could not delete Mastodon posts'))
if not delete_link(link_id, info['user_id']): if not delete_link(link_id, info['user_id']):
raise HTTPException(status_code=404, detail='Link not found or not owned by user') raise HTTPException(status_code=404, detail='Link not found or not owned by user')
record_audit_event(info['user_id'], 'link_deleted', 'link', link_id)
return {'status': 'deleted', 'id': link_id} return {'status': 'deleted', 'id': link_id}
@@ -150,6 +178,7 @@ def post_link_to_mastodon(
result = plugin_manager.post_to_mastodon({'type': 'link_created', **event}) result = plugin_manager.post_to_mastodon({'type': 'link_created', **event})
if result.get('status') == 'posted': if result.get('status') == 'posted':
mark_mastodon_posted(link_id, info['user_id'], result.get('post_id')) mark_mastodon_posted(link_id, info['user_id'], result.get('post_id'))
record_audit_event(info['user_id'], 'mastodon_posted', 'link', link_id)
return {'status': 'posted', 'post_id': result.get('post_id')} return {'status': 'posted', 'post_id': result.get('post_id')}
if result.get('status') == 'skipped': if result.get('status') == 'skipped':
raise HTTPException(status_code=409, detail='Mastodon is not enabled or configured') raise HTTPException(status_code=409, detail='Mastodon is not enabled or configured')
+8 -3
View File
@@ -10,12 +10,15 @@ from starlette.requests import Request
from backend.app.api.dependencies import get_current_user from backend.app.api.dependencies import get_current_user
from backend.app.services.mastodon_oauth import finish_authorization, start_authorization from backend.app.services.mastodon_oauth import finish_authorization, start_authorization
from backend.app.core.errors import public_error, redacted_error, request_id
import logging
router = APIRouter() router = APIRouter()
logger = logging.getLogger(__name__)
@router.get('/oauth/start') @router.get('/oauth/start')
def oauth_start(instance: str = 'mastodon.social', user: dict = Depends(get_current_user)): def oauth_start(request: Request, instance: str = 'mastodon.social', user: dict = Depends(get_current_user)):
try: try:
authorization_url = start_authorization(user['id'], instance) authorization_url = start_authorization(user['id'], instance)
except HTTPError as error: except HTTPError as error:
@@ -27,7 +30,8 @@ def oauth_start(instance: str = 'mastodon.social', user: dict = Depends(get_curr
headers=headers, headers=headers,
) from error ) from error
except Exception as error: except Exception as error:
raise HTTPException(status_code=502, detail=f'Could not register with Mastodon: {error}') from error logger.error('Mastodon registration failed request_id=%s error=%s', request_id(request), redacted_error(error))
raise HTTPException(status_code=502, detail=public_error(request, 'Could not register with Mastodon.')) from error
return {'authorization_url': authorization_url} return {'authorization_url': authorization_url}
@@ -38,5 +42,6 @@ def oauth_callback(request: Request, code: str | None = None, state: str | None
try: try:
finish_authorization(code, state) finish_authorization(code, state)
except Exception as callback_error: except Exception as callback_error:
return RedirectResponse(f'/profile?mastodon_error={quote(str(callback_error))}') logger.error('Mastodon callback failed request_id=%s error=%s', request_id(request), redacted_error(callback_error))
return RedirectResponse(f'/profile?mastodon_error={quote(public_error(request, "Could not complete Mastodon authorization."))}')
return RedirectResponse('/profile?mastodon=connected') return RedirectResponse('/profile?mastodon=connected')
+7 -3
View File
@@ -5,14 +5,17 @@ from datetime import datetime, timedelta, timezone
import json import json
from uuid import uuid4 from uuid import uuid4
from fastapi import APIRouter, HTTPException from fastapi import APIRouter, HTTPException, Request
from pydantic import BaseModel from pydantic import BaseModel
from backend.app.core.config import settings from backend.app.core.config import settings
from backend.app.database import get_connection, hash_password from backend.app.database import get_connection, hash_password
from backend.app.services.email_service import get_smtp_settings, save_smtp_settings, send_test_email from backend.app.services.email_service import get_smtp_settings, save_smtp_settings, send_test_email
from backend.app.core.errors import public_error, redacted_error, request_id
import logging
router = APIRouter() router = APIRouter()
logger = logging.getLogger(__name__)
class SetupRequest(BaseModel): class SetupRequest(BaseModel):
@@ -92,7 +95,7 @@ def save_configuration(payload: SetupRequest):
@router.post('/test-mail') @router.post('/test-mail')
def test_mail(payload: TestMailRequest | None = None): def test_mail(request: Request, payload: TestMailRequest | None = None):
if has_administrator(): if has_administrator():
raise HTTPException(status_code=409, detail='LinkLog is already configured') raise HTTPException(status_code=409, detail='LinkLog is already configured')
pending = get_pending_setup() pending = get_pending_setup()
@@ -119,7 +122,8 @@ def test_mail(payload: TestMailRequest | None = None):
try: try:
send_test_email(payload.email if payload and payload.email else pending['email']) send_test_email(payload.email if payload and payload.email else pending['email'])
except Exception as error: except Exception as error:
raise HTTPException(status_code=503, detail=f'SMTP test mail could not be sent: {error}') from error logger.error('SMTP test mail failed request_id=%s error=%s', request_id(request), redacted_error(error))
raise HTTPException(status_code=503, detail=public_error(request, 'SMTP test mail could not be sent.')) from error
sends = int(rate.get('sends', 0)) + 1 sends = int(rate.get('sends', 0)) + 1
updated_rate = {'sends': sends, 'last_sent': now.isoformat()} updated_rate = {'sends': sends, 'last_sent': now.isoformat()}
+82 -20
View File
@@ -2,22 +2,32 @@
## SPDX-License-Identifier: GPL-3.0-or-later ## SPDX-License-Identifier: GPL-3.0-or-later
import json import json
import warnings
from io import BytesIO
from datetime import datetime, timedelta, timezone from datetime import datetime, timedelta, timezone
from uuid import uuid4 from uuid import uuid4
from fastapi import APIRouter, Depends, File, HTTPException, UploadFile from fastapi import APIRouter, Depends, File, HTTPException, Request, UploadFile
from PIL import Image, UnidentifiedImageError
from pydantic import BaseModel from pydantic import BaseModel
from backend.app.api.dependencies import get_current_user from backend.app.api.dependencies import get_current_user
from backend.app.database import AVATARS_DIR, get_connection, hash_password, verify_password from backend.app.database import AVATARS_DIR, get_connection, hash_password, verify_password
from backend.app.services.link_service import create_label, delete_label, list_user_labels, update_label from backend.app.services.link_service import create_label, delete_label, list_user_labels, update_label
from backend.app.services.otp_service import create_secret, provisioning_uri, verify_code from backend.app.services.otp_service import consume_recovery_code, create_recovery_codes, create_secret, provisioning_uri, verify_code
from backend.app.services.email_addresses import add_user_email_address, create_email_verification, list_user_email_addresses from backend.app.services.email_addresses import add_user_email_address, create_email_verification, list_user_email_addresses
from backend.app.services.email_service import send_verification_email, smtp_configured from backend.app.services.email_service import send_verification_email, smtp_configured
from backend.app.core.config import settings from backend.app.core.config import settings
from backend.app.services.secret_store import decrypt_secret, encrypt_secret from backend.app.services.secret_store import decrypt_secret, encrypt_secret
from backend.app.services.audit_service import record_audit_event
from backend.app.core.errors import public_error, redacted_error, request_id
import logging
router = APIRouter() router = APIRouter()
logger = logging.getLogger(__name__)
MAX_AVATAR_BYTES = 2 * 1024 * 1024
MAX_AVATAR_PIXELS = 25_000_000
class UserConfigUpdate(BaseModel): class UserConfigUpdate(BaseModel):
@@ -32,12 +42,19 @@ class PasswordUpdate(BaseModel):
class OtpUpdate(BaseModel): class OtpUpdate(BaseModel):
action: str action: str
code: str | None = None code: str | None = None
current_password: str | None = None
recovery_code: str | None = None
class AdditionalEmail(BaseModel): class AdditionalEmail(BaseModel):
email: str email: str
class OtpRecovery(BaseModel):
current_password: str
recovery_code: str
class UserPluginConfigUpdate(BaseModel): class UserPluginConfigUpdate(BaseModel):
instance: str | None = None instance: str | None = None
@@ -103,6 +120,7 @@ def update_password(payload: PasswordUpdate, user: dict = Depends(get_current_us
(hash_password(payload.new_password), user['id']), (hash_password(payload.new_password), user['id']),
) )
conn.commit() conn.commit()
record_audit_event(user['id'], 'password_changed', 'user', user['id'])
return {'status': 'password_updated'} return {'status': 'password_updated'}
@@ -119,14 +137,25 @@ def setup_otp(user: dict = Depends(get_current_user)):
with get_connection() as conn: with get_connection() as conn:
conn.execute('UPDATE users SET otp_secret = ?, updated_at = CURRENT_TIMESTAMP WHERE id = ?', (encrypt_secret(secret), user['id'])) conn.execute('UPDATE users SET otp_secret = ?, updated_at = CURRENT_TIMESTAMP WHERE id = ?', (encrypt_secret(secret), user['id']))
conn.commit() conn.commit()
return {'secret': secret, 'otpauth_url': provisioning_uri(secret, user['username'])} record_audit_event(user['id'], 'otp_enrolled', 'user', user['id'])
return {
'secret': secret,
'otpauth_url': provisioning_uri(secret, user['username']),
'recovery_codes': create_recovery_codes(user['id']),
}
@router.post('/otp') @router.post('/otp')
def update_otp(payload: OtpUpdate, user: dict = Depends(get_current_user)): def update_otp(payload: OtpUpdate, user: dict = Depends(get_current_user)):
if payload.action not in {'enable', 'disable'}: if payload.action not in {'enable', 'disable'}:
raise HTTPException(status_code=422, detail='OTP action must be enable or disable') raise HTTPException(status_code=422, detail='OTP action must be enable or disable')
if not verify_code(decrypt_secret(user['otp_secret']), payload.code): if payload.action == 'disable' and not payload.current_password:
raise HTTPException(status_code=400, detail='Current password is required to disable one-time password')
if payload.action == 'disable' and not verify_password(payload.current_password, user['password_hash']):
raise HTTPException(status_code=400, detail='Current password is incorrect')
valid_code = verify_code(decrypt_secret(user['otp_secret']), payload.code)
valid_recovery_code = payload.action == 'disable' and payload.recovery_code and consume_recovery_code(user['id'], payload.recovery_code)
if not valid_code and not valid_recovery_code:
raise HTTPException(status_code=400, detail='Invalid one-time password') raise HTTPException(status_code=400, detail='Invalid one-time password')
with get_connection() as conn: with get_connection() as conn:
if payload.action == 'enable': if payload.action == 'enable':
@@ -134,16 +163,33 @@ def update_otp(payload: OtpUpdate, user: dict = Depends(get_current_user)):
else: else:
conn.execute('UPDATE users SET otp_enabled = 0, otp_secret = NULL, updated_at = CURRENT_TIMESTAMP WHERE id = ?', (user['id'],)) conn.execute('UPDATE users SET otp_enabled = 0, otp_secret = NULL, updated_at = CURRENT_TIMESTAMP WHERE id = ?', (user['id'],))
conn.commit() conn.commit()
record_audit_event(user['id'], f'otp_{payload.action}d', 'user', user['id'])
return {'status': 'updated', 'enabled': payload.action == 'enable'} return {'status': 'updated', 'enabled': payload.action == 'enable'}
@router.post('/otp/recover')
def recover_otp(payload: OtpRecovery, user: dict = Depends(get_current_user)):
if not verify_password(payload.current_password, user['password_hash']):
raise HTTPException(status_code=400, detail='Current password is incorrect')
if not consume_recovery_code(user['id'], payload.recovery_code):
raise HTTPException(status_code=400, detail='Recovery code is invalid or already used')
with get_connection() as conn:
conn.execute(
'UPDATE users SET otp_enabled = 0, otp_secret = NULL, updated_at = CURRENT_TIMESTAMP WHERE id = ?',
(user['id'],),
)
conn.commit()
record_audit_event(user['id'], 'otp_recovered', 'user', user['id'])
return {'status': 'otp_recovered', 'enabled': False}
@router.get('/emails') @router.get('/emails')
def get_additional_emails(user: dict = Depends(get_current_user)): def get_additional_emails(user: dict = Depends(get_current_user)):
return [{'email': user['email'], 'verified': bool(user['email_verified']), 'primary': True}] + list_user_email_addresses(user['id']) return [{'email': user['email'], 'verified': bool(user['email_verified']), 'primary': True}] + list_user_email_addresses(user['id'])
@router.post('/emails', status_code=201) @router.post('/emails', status_code=201)
def add_additional_email(payload: AdditionalEmail, user: dict = Depends(get_current_user)): def add_additional_email(payload: AdditionalEmail, request: Request, user: dict = Depends(get_current_user)):
email = payload.email.strip().lower() email = payload.email.strip().lower()
if email == user['email'].lower(): if email == user['email'].lower():
raise HTTPException(status_code=409, detail='This is already the primary email address') raise HTTPException(status_code=409, detail='This is already the primary email address')
@@ -166,7 +212,8 @@ def add_additional_email(payload: AdditionalEmail, user: dict = Depends(get_curr
try: try:
send_verification_email(email_address, user['username'], verification_url) send_verification_email(email_address, user['username'], verification_url)
except Exception as error: except Exception as error:
raise HTTPException(status_code=503, detail=f'Email address added but verification email could not be sent: {error}') from error logger.error('Additional email verification failed request_id=%s error=%s', request_id(request), redacted_error(error))
raise HTTPException(status_code=503, detail=public_error(request, 'Email address added but verification email could not be sent.')) from error
with get_connection() as conn: with get_connection() as conn:
conn.execute( conn.execute(
'''INSERT INTO app_settings (name, value, updated_at) VALUES (?, ?, CURRENT_TIMESTAMP) '''INSERT INTO app_settings (name, value, updated_at) VALUES (?, ?, CURRENT_TIMESTAMP)
@@ -178,7 +225,7 @@ def add_additional_email(payload: AdditionalEmail, user: dict = Depends(get_curr
@router.post('/emails/{address_id}/resend') @router.post('/emails/{address_id}/resend')
def resend_additional_email(address_id: str, user: dict = Depends(get_current_user)): def resend_additional_email(address_id: str, request: Request, user: dict = Depends(get_current_user)):
now = datetime.now(timezone.utc) now = datetime.now(timezone.utc)
setting_name = f'email_verify_rate:{address_id}' setting_name = f'email_verify_rate:{address_id}'
with get_connection() as conn: with get_connection() as conn:
@@ -202,7 +249,8 @@ def resend_additional_email(address_id: str, user: dict = Depends(get_current_us
try: try:
send_verification_email(email, user['username'], verification_url) send_verification_email(email, user['username'], verification_url)
except Exception as error: except Exception as error:
raise HTTPException(status_code=503, detail=f'Verification email could not be sent: {error}') from error logger.error('Verification email resend failed request_id=%s error=%s', request_id(request), redacted_error(error))
raise HTTPException(status_code=503, detail=public_error(request, 'Verification email could not be sent.')) from error
sends = int(rate.get('sends', 0)) + 1 sends = int(rate.get('sends', 0)) + 1
updated = {'sends': sends, 'last_sent': now.isoformat()} updated = {'sends': sends, 'last_sent': now.isoformat()}
if sends >= 5: if sends >= 5:
@@ -221,6 +269,7 @@ def remove_additional_email(address_id: str, user: dict = Depends(get_current_us
conn.commit() conn.commit()
if cursor.rowcount == 0: if cursor.rowcount == 0:
raise HTTPException(status_code=404, detail='Email address not found') raise HTTPException(status_code=404, detail='Email address not found')
record_audit_event(user['id'], 'email_address_deleted', 'email_address', address_id)
return {'status': 'deleted', 'id': address_id} return {'status': 'deleted', 'id': address_id}
@@ -249,6 +298,7 @@ def make_email_primary(address_id: str, user: dict = Depends(get_current_user)):
(address['email'], user['id']), (address['email'], user['id']),
) )
conn.commit() conn.commit()
record_audit_event(user['id'], 'primary_email_changed', 'user', user['id'])
return {'status': 'updated', 'email': address['email']} return {'status': 'updated', 'email': address['email']}
@@ -280,6 +330,7 @@ def edit_label(label_id: str, payload: LabelUpdate, user: dict = Depends(get_cur
def remove_label(label_id: str, user: dict = Depends(get_current_user)): def remove_label(label_id: str, user: dict = Depends(get_current_user)):
if not delete_label(label_id, user['id']): if not delete_label(label_id, user['id']):
raise HTTPException(status_code=404, detail='Label not found or not owned by user') raise HTTPException(status_code=404, detail='Label not found or not owned by user')
record_audit_event(user['id'], 'label_deleted', 'label', label_id)
return {'status': 'deleted', 'id': label_id} return {'status': 'deleted', 'id': label_id}
@@ -288,25 +339,33 @@ async def upload_avatar(
avatar: UploadFile = File(...), avatar: UploadFile = File(...),
user: dict = Depends(get_current_user), user: dict = Depends(get_current_user),
): ):
allowed_types = { if avatar.content_type not in {'image/gif', 'image/jpeg', 'image/png', 'image/webp'}:
'image/gif': '.gif',
'image/jpeg': '.jpg',
'image/png': '.png',
'image/webp': '.webp',
}
suffix = allowed_types.get(avatar.content_type or '')
if suffix is None:
raise HTTPException(status_code=415, detail='Avatar must be a PNG, JPEG, GIF, or WebP image') raise HTTPException(status_code=415, detail='Avatar must be a PNG, JPEG, GIF, or WebP image')
contents = await avatar.read(2 * 1024 * 1024 + 1) contents = await avatar.read(MAX_AVATAR_BYTES + 1)
if len(contents) > 2 * 1024 * 1024: if len(contents) > MAX_AVATAR_BYTES:
raise HTTPException(status_code=413, detail='Avatar must be 2 MB or smaller') raise HTTPException(status_code=413, detail='Avatar must be 2 MB or smaller')
avatar_path = AVATARS_DIR / f'{user["id"]}{suffix}' try:
with warnings.catch_warnings():
warnings.simplefilter('error', Image.DecompressionBombWarning)
with Image.open(BytesIO(contents)) as image:
if image.width * image.height > MAX_AVATAR_PIXELS:
raise HTTPException(status_code=413, detail='Avatar dimensions are too large')
image.verify()
with Image.open(BytesIO(contents)) as image:
image.load()
normalized = image.convert('RGBA')
except HTTPException:
raise
except (Image.DecompressionBombError, Image.DecompressionBombWarning, UnidentifiedImageError, OSError, ValueError) as error:
raise HTTPException(status_code=415, detail='Avatar content is not a valid image') from error
avatar_path = AVATARS_DIR / f'{user["id"]}.png'
normalized.save(avatar_path, format='PNG', optimize=True)
for existing_path in AVATARS_DIR.glob(f'{user["id"]}.*'): for existing_path in AVATARS_DIR.glob(f'{user["id"]}.*'):
if existing_path != avatar_path: if existing_path != avatar_path:
existing_path.unlink(missing_ok=True) existing_path.unlink(missing_ok=True)
avatar_path.write_bytes(contents)
avatar_url = f'/media/{avatar_path.name}' avatar_url = f'/media/{avatar_path.name}'
with get_connection() as conn: with get_connection() as conn:
@@ -315,6 +374,7 @@ async def upload_avatar(
(avatar_url, user['id']), (avatar_url, user['id']),
) )
conn.commit() conn.commit()
record_audit_event(user['id'], 'avatar_updated', 'user', user['id'])
return {'avatar_url': avatar_url} return {'avatar_url': avatar_url}
@@ -330,6 +390,8 @@ def get_user_plugin_config(plugin_name: str, user: dict = Depends(get_current_us
return {} return {}
config = json.loads(row['config']) if row['config'] else {} config = json.loads(row['config']) if row['config'] else {}
if plugin_name == 'mastodon':
config['configured'] = bool(config.get('instance') and config.get('access_token'))
if config.get('access_token'): if config.get('access_token'):
config.pop('access_token') config.pop('access_token')
return config return config
+34 -4
View File
@@ -1,13 +1,17 @@
## Copyright © 2026 Olaf Kolkman ## Copyright © 2026 Olaf Kolkman
## SPDX-License-Identifier: GPL-3.0-or-later ## SPDX-License-Identifier: GPL-3.0-or-later
from dataclasses import dataclass from dataclasses import dataclass, field
import json
import os import os
from pathlib import Path from pathlib import Path
from cryptography.fernet import Fernet
BASE_DIR = Path(__file__).resolve().parent.parent.parent BASE_DIR = Path(__file__).resolve().parent.parent.parent
DB_PATH = BASE_DIR / 'data' / 'linklog.db' DB_PATH = BASE_DIR / 'data' / 'linklog.db'
VERSION_FILE = BASE_DIR.parent / 'frontend' / 'version.json'
def normalize_public_url(value: str) -> str: def normalize_public_url(value: str) -> str:
@@ -18,15 +22,25 @@ def normalize_public_url(value: str) -> str:
return f'{scheme}://{value}' return f'{scheme}://{value}'
def load_version() -> str:
# frontend/version.json is the single source of truth for the app version, shared by backend and frontend.
try:
return json.loads(VERSION_FILE.read_text())['version']
except (OSError, KeyError, ValueError):
return '0.0.0'
@dataclass @dataclass
class Settings: class Settings:
app_env: str = os.getenv('APP_ENV', 'development').lower()
app_name: str = os.getenv('LINKLOG_APP_NAME', 'LinkLog') app_name: str = os.getenv('LINKLOG_APP_NAME', 'LinkLog')
version: str = os.getenv('LINKLOG_VERSION', '0.1.0') version: str = field(default_factory=load_version)
database_url: str = os.getenv('LINKLOG_DATABASE_URL', f'sqlite:///{DB_PATH}') database_url: str = os.getenv('LINKLOG_DATABASE_URL', f'sqlite:///{DB_PATH}')
secret_key: str = os.getenv('LINKLOG_SECRET_KEY', 'dev-secret-key-change-me') secret_key: str = os.getenv('LINKLOG_SECRET_KEY', 'dev-secret-key-change-me')
data_encryption_key: str = os.getenv('LINKLOG_DATA_ENCRYPTION_KEY', '') data_encryption_key: str = os.getenv('LINKLOG_DATA_ENCRYPTION_KEY', '')
token_expiry_days: int = int(os.getenv('LINKLOG_TOKEN_EXPIRY_DAYS', '30')) token_expiry_minutes: int = int(os.getenv('LINKLOG_TOKEN_EXPIRY_MINUTES', '15'))
public_url: str = normalize_public_url(os.getenv('LINKLOG_PUBLIC_URL', 'http://localhost:8000')) refresh_token_expiry_days: int = int(os.getenv('LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS', '30'))
public_url: str = normalize_public_url(os.getenv('LINKLOG_PUBLIC_URL', 'linklog.example.com'))
smtp_host: str = os.getenv('LINKLOG_SMTP_HOST', '') smtp_host: str = os.getenv('LINKLOG_SMTP_HOST', '')
smtp_port: int = int(os.getenv('LINKLOG_SMTP_PORT', '587')) smtp_port: int = int(os.getenv('LINKLOG_SMTP_PORT', '587'))
smtp_username: str = os.getenv('LINKLOG_SMTP_USERNAME', '') smtp_username: str = os.getenv('LINKLOG_SMTP_USERNAME', '')
@@ -58,3 +72,19 @@ class Settings:
settings = Settings() settings = Settings()
def validate_configuration(values: Settings) -> None:
if values.app_env == 'production':
if not values.secret_key or values.secret_key == 'dev-secret-key-change-me':
raise RuntimeError('LINKLOG_SECRET_KEY must be configured in production')
if len(values.secret_key) < 32 or len(set(values.secret_key)) < 12:
raise RuntimeError('LINKLOG_SECRET_KEY must be at least 32 characters with sufficient entropy')
if not values.data_encryption_key:
raise RuntimeError('LINKLOG_DATA_ENCRYPTION_KEY must be configured in production')
if values.data_encryption_key:
try:
Fernet(values.data_encryption_key.encode('ascii'))
except (ValueError, UnicodeEncodeError) as error:
raise RuntimeError('LINKLOG_DATA_ENCRYPTION_KEY must be a valid Fernet key') from error
+23
View File
@@ -0,0 +1,23 @@
import re
from uuid import uuid4
from fastapi import Request
SENSITIVE_PATTERN = re.compile(
r'(?i)(authorization\s*[:=]\s*bearer\s+[^\s,;]+|'
r'(?:token|password|secret|otp|code)(?:[_-](?:token|password|secret|code))?\s*[:=]\s*[^\s,;&]+|'
r'([?&](?:token|code|password|secret|otp)=[^&#\s]+))'
)
def request_id(request: Request) -> str:
return getattr(request.state, 'request_id', None) or str(uuid4())
def redacted_error(error: Exception) -> str:
return SENSITIVE_PATTERN.sub('[REDACTED]', str(error))
def public_error(request: Request, message: str) -> str:
return f'{message} Reference: {request_id(request)}'
+33
View File
@@ -226,6 +226,39 @@ CREATE TABLE IF NOT EXISTS pending_primary_email_changes (
'''), '''),
(14, ''' (14, '''
DROP TABLE IF EXISTS pending_primary_email_changes; DROP TABLE IF EXISTS pending_primary_email_changes;
'''),
(15, '''
ALTER TABLE tokens ADD COLUMN device_id TEXT;
ALTER TABLE tokens ADD COLUMN token_family_id TEXT;
CREATE INDEX IF NOT EXISTS idx_tokens_device_id ON tokens(device_id);
CREATE INDEX IF NOT EXISTS idx_tokens_family_id ON tokens(token_family_id);
'''),
(16, '''
CREATE TABLE IF NOT EXISTS otp_recovery_codes (
id TEXT PRIMARY KEY,
user_id TEXT NOT NULL,
code_hash TEXT NOT NULL UNIQUE,
used INTEGER NOT NULL DEFAULT 0,
created_at TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
used_at TEXT,
FOREIGN KEY(user_id) REFERENCES users(id) ON DELETE CASCADE
);
CREATE INDEX IF NOT EXISTS idx_otp_recovery_codes_user_id ON otp_recovery_codes(user_id);
'''),
(17, '''
CREATE TABLE IF NOT EXISTS security_audit_events (
id TEXT PRIMARY KEY,
actor_id TEXT,
action TEXT NOT NULL,
target_type TEXT NOT NULL,
target_id TEXT,
outcome TEXT NOT NULL DEFAULT 'success',
details TEXT NOT NULL DEFAULT '{}',
created_at TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
FOREIGN KEY(actor_id) REFERENCES users(id) ON DELETE SET NULL
);
CREATE INDEX IF NOT EXISTS idx_security_audit_events_created_at ON security_audit_events(created_at);
CREATE INDEX IF NOT EXISTS idx_security_audit_events_actor_id ON security_audit_events(actor_id);
''') ''')
] ]
+21 -2
View File
@@ -1,8 +1,9 @@
## Copyright © 2026 Olaf Kolkman ## Copyright © 2026 Olaf Kolkman
## SPDX-License-Identifier: GPL-3.0-or-later ## SPDX-License-Identifier: GPL-3.0-or-later
from fastapi import FastAPI from fastapi import FastAPI, Request
import logging import logging
from uuid import uuid4
from fastapi.responses import HTMLResponse from fastapi.responses import HTMLResponse
from fastapi.responses import RedirectResponse from fastapi.responses import RedirectResponse
from fastapi.staticfiles import StaticFiles from fastapi.staticfiles import StaticFiles
@@ -17,13 +18,23 @@ from backend.app.api.public import router as public_router
from backend.app.api.setup import router as setup_router from backend.app.api.setup import router as setup_router
from backend.app.api.setup import has_administrator from backend.app.api.setup import has_administrator
from backend.app.api.user_config import router as user_config_router from backend.app.api.user_config import router as user_config_router
from backend.app.core.config import settings from backend.app.core.config import settings, validate_configuration
from backend.app.database import AVATARS_DIR from backend.app.database import AVATARS_DIR
from backend.app.services.link_service import get_public_profile, list_public_links from backend.app.services.link_service import get_public_profile, list_public_links
logging.basicConfig(level=getattr(logging, settings.log_level, logging.INFO)) logging.basicConfig(level=getattr(logging, settings.log_level, logging.INFO))
validate_configuration(settings)
app = FastAPI(title='LinkLog API', version=settings.version) app = FastAPI(title='LinkLog API', version=settings.version)
@app.middleware('http')
async def add_request_id(request: Request, call_next):
request.state.request_id = request.headers.get('X-Request-ID') or str(uuid4())
response = await call_next(request)
response.headers['X-Request-ID'] = request.state.request_id
return response
app.mount('/static', StaticFiles(directory='frontend/static'), name='static') app.mount('/static', StaticFiles(directory='frontend/static'), name='static')
app.mount('/media', StaticFiles(directory=AVATARS_DIR), name='media') app.mount('/media', StaticFiles(directory=AVATARS_DIR), name='media')
app.include_router(auth_router, prefix='/api/auth') app.include_router(auth_router, prefix='/api/auth')
@@ -35,6 +46,7 @@ app.include_router(user_config_router, prefix='/api/user')
app.include_router(setup_router, prefix='/api/setup') app.include_router(setup_router, prefix='/api/setup')
templates = Jinja2Templates(directory='frontend/templates') templates = Jinja2Templates(directory='frontend/templates')
templates.env.globals['app_version'] = settings.version
@app.get('/', response_class=HTMLResponse) @app.get('/', response_class=HTMLResponse)
@@ -66,6 +78,13 @@ async def labels_page(request: Request):
return templates.TemplateResponse(request, 'labels.html', {}) return templates.TemplateResponse(request, 'labels.html', {})
@app.get('/new-entry', response_class=HTMLResponse)
async def new_entry_page(request: Request):
if not has_administrator():
return RedirectResponse('/setup')
return templates.TemplateResponse(request, 'new-entry.html', {})
@app.get('/about', response_class=HTMLResponse) @app.get('/about', response_class=HTMLResponse)
async def about_page(request: Request): async def about_page(request: Request):
return templates.TemplateResponse(request, 'about.html', {}) return templates.TemplateResponse(request, 'about.html', {})
+23
View File
@@ -0,0 +1,23 @@
import json
from uuid import uuid4
from backend.app.database import get_connection
def record_audit_event(
actor_id: str | None,
action: str,
target_type: str,
target_id: str | None = None,
outcome: str = 'success',
details: dict | None = None,
) -> None:
safe_details = details or {}
with get_connection() as conn:
conn.execute(
'''INSERT INTO security_audit_events
(id, actor_id, action, target_type, target_id, outcome, details)
VALUES (?, ?, ?, ?, ?, ?, ?)''',
(str(uuid4()), actor_id, action, target_type, target_id, outcome, json.dumps(safe_details)),
)
conn.commit()
+60 -2
View File
@@ -2,13 +2,57 @@
## SPDX-License-Identifier: GPL-3.0-or-later ## SPDX-License-Identifier: GPL-3.0-or-later
from email.message import EmailMessage from email.message import EmailMessage
from html import escape
from pathlib import Path
from smtplib import SMTP from smtplib import SMTP
import json import json
from urllib.parse import urlparse
from backend.app.core.config import settings from backend.app.core.config import settings
from backend.app.database import get_connection from backend.app.database import get_connection
from backend.app.services.secret_store import decrypt_secret, encrypt_secret from backend.app.services.secret_store import decrypt_secret, encrypt_secret
LOGO_PATH = Path(__file__).resolve().parents[3] / 'frontend' / 'static' / 'logo.svg'
def _html_email(body_html: str) -> str:
public_url = settings.public_url
parsed_url = urlparse(public_url)
public_hostname = parsed_url.hostname or public_url
safe_public_url = escape(public_url, quote=True)
safe_public_hostname = escape(public_hostname)
return f'''<!doctype html>
<html lang="en">
<body style="margin:0;background:#1e1e2e;color:#cdd6f4;font-family:Arial,sans-serif;line-height:1.6;">
<div style="max-width:620px;margin:32px auto;padding:0 20px;">
<div style="background:#11111b;border:1px solid #45475a;border-radius:12px;overflow:hidden;">
<table role="presentation" width="100%" cellpadding="0" cellspacing="0" border="0" style="background:#181825;">
<tr>
<td style="padding:20px 24px;text-align:left;vertical-align:top;width:50px;">
<img src="cid:linklog-logo" alt="LinkLog" width="50" height="50" style="display:block;width:50px;height:50px;">
</td>
<td style="padding:20px 0 20px 12px;text-align:left;vertical-align:top;">
<span style="color:#cba6f7;font-family:'Asset',Georgia,serif;font-size:18px;line-height:50px;">Hello, a message from <a href="{safe_public_url}" style="color:#cba6f7;text-decoration:underline;">{safe_public_hostname}</a></span>
</td>
</tr>
</table>
<div style="padding:28px 32px;">{body_html}</div>
</div>
<p style="margin:18px 0;text-align:center;color:#a6adc8;font-size:12px;">LinkLog</p>
</div>
</body>
</html>'''
def _add_html_body(message: EmailMessage, html_body: str) -> None:
message.add_alternative(_html_email(html_body), subtype='html')
html_part = message.get_payload()[-1]
try:
logo = LOGO_PATH.read_bytes()
except OSError:
return
html_part.add_related(logo, maintype='image', subtype='svg+xml', cid='<linklog-logo>')
def get_smtp_settings() -> dict: def get_smtp_settings() -> dict:
values = { values = {
@@ -42,7 +86,8 @@ def smtp_configured(smtp_values: dict | None = None) -> bool:
return bool(smtp['smtp_host'] and smtp['smtp_from']) return bool(smtp['smtp_host'] and smtp['smtp_from'])
def send_message(email: str, subject: str, body: str, smtp_values: dict | None = None) -> None: def send_message(email: str, subject: str, body: str, html_body: str | None = None,
smtp_values: dict | None = None) -> None:
smtp = smtp_values or get_smtp_settings() smtp = smtp_values or get_smtp_settings()
if not smtp_configured(smtp): if not smtp_configured(smtp):
raise RuntimeError('SMTP is not configured; set LINKLOG_SMTP_HOST and LINKLOG_SMTP_FROM') raise RuntimeError('SMTP is not configured; set LINKLOG_SMTP_HOST and LINKLOG_SMTP_FROM')
@@ -52,6 +97,8 @@ def send_message(email: str, subject: str, body: str, smtp_values: dict | None =
message['From'] = smtp['smtp_from'] message['From'] = smtp['smtp_from']
message['To'] = email message['To'] = email
message.set_content(body) message.set_content(body)
if html_body:
_add_html_body(message, html_body)
with SMTP(smtp['smtp_host'], smtp['smtp_port'], timeout=10) as connection: with SMTP(smtp['smtp_host'], smtp['smtp_port'], timeout=10) as connection:
if smtp['smtp_use_tls']: if smtp['smtp_use_tls']:
@@ -62,12 +109,17 @@ def send_message(email: str, subject: str, body: str, smtp_values: dict | None =
def send_verification_email(email: str, username: str, verification_url: str) -> None: def send_verification_email(email: str, username: str, verification_url: str) -> None:
safe_username = escape(username)
safe_url = escape(verification_url, quote=True)
send_message( send_message(
email, email,
'Verify your LinkLog email address', 'Verify your LinkLog email address',
f'Hello {username},\n\n' f'Hello {username},\n\n'
f'Verify your LinkLog email address by opening this link:\n{verification_url}\n\n' f'Verify your LinkLog email address by opening this link:\n{verification_url}\n\n'
f'This link expires in {settings.email_verification_expiry_hours} hours.\n', f'This link expires in {settings.email_verification_expiry_hours} hours.\n',
f'<p>Hello {safe_username},</p><p>Verify your LinkLog email address:</p>'
f'<p><a href="{safe_url}" style="display:inline-block;padding:10px 16px;background:#89b4fa;color:#11111b;text-decoration:none;border-radius:6px;">Verify email address</a></p>'
f'<p style="color:#a6adc8;font-size:14px;">This link expires in {settings.email_verification_expiry_hours} hours.</p>',
) )
@@ -76,15 +128,21 @@ def send_test_email(email: str, smtp_values: dict | None = None) -> None:
email, email,
'LinkLog SMTP test', 'LinkLog SMTP test',
'This is a test message from LinkLog. SMTP is configured correctly.\n', 'This is a test message from LinkLog. SMTP is configured correctly.\n',
smtp_values, '<p>This is a test message from LinkLog.</p><p style="color:#a6adc8;">SMTP is configured correctly.</p>',
smtp_values=smtp_values,
) )
def send_password_reset_email(email: str, username: str, reset_url: str) -> None: def send_password_reset_email(email: str, username: str, reset_url: str) -> None:
safe_username = escape(username)
safe_url = escape(reset_url, quote=True)
send_message( send_message(
email, email,
'Reset your LinkLog password', 'Reset your LinkLog password',
f'Hello {username},\n\n' f'Hello {username},\n\n'
f'Reset your LinkLog password by opening this link:\n{reset_url}\n\n' f'Reset your LinkLog password by opening this link:\n{reset_url}\n\n'
f'This link expires in {settings.password_reset_expiry_hours} hours.\n', f'This link expires in {settings.password_reset_expiry_hours} hours.\n',
f'<p>Hello {safe_username},</p><p>Reset your LinkLog password:</p>'
f'<p><a href="{safe_url}" style="display:inline-block;padding:10px 16px;background:#f38ba8;color:#11111b;text-decoration:none;border-radius:6px;">Reset password</a></p>'
f'<p style="color:#a6adc8;font-size:14px;">This link expires in {settings.password_reset_expiry_hours} hours.</p>',
) )
+30 -9
View File
@@ -27,7 +27,7 @@ def normalize_tags(tags: list[str] | None) -> list[str]:
return normalized return normalized
def save_link_tags(conn, link_id: str, tags: list[str]) -> None: def save_link_tags(conn, link_id: str, tags: list[str], user_id: str | None = None) -> list[str]:
canonical_tags = [] canonical_tags = []
for tag in tags: for tag in tags:
tag_row = conn.execute( tag_row = conn.execute(
@@ -36,8 +36,8 @@ def save_link_tags(conn, link_id: str, tags: list[str]) -> None:
).fetchone() ).fetchone()
if tag_row is None: if tag_row is None:
conn.execute( conn.execute(
'INSERT INTO tags (id, name) VALUES (?, ?)', 'INSERT INTO tags (id, name, created_by) VALUES (?, ?, ?)',
(str(uuid4()), tag), (str(uuid4()), tag, user_id),
) )
tag_row = conn.execute('SELECT id FROM tags WHERE name = ?', (tag,)).fetchone() tag_row = conn.execute('SELECT id FROM tags WHERE name = ?', (tag,)).fetchone()
conn.execute( conn.execute(
@@ -103,7 +103,7 @@ def create_link(
record['is_public'], record['is_public'],
), ),
) )
stored_tags = save_link_tags(conn, record['id'], normalized_tags) stored_tags = save_link_tags(conn, record['id'], normalized_tags, user_id=user_id)
conn.commit() conn.commit()
record['tags'] = stored_tags record['tags'] = stored_tags
return record return record
@@ -123,6 +123,19 @@ def find_owned_link_by_title_url(user_id: str, title: str, url: str) -> dict | N
return record return record
def find_owned_link_by_title(user_id: str, title: str) -> dict | None:
with get_connection() as conn:
row = conn.execute(
'SELECT * FROM links WHERE user_id = ? AND title = ? ORDER BY created_at DESC LIMIT 1',
(user_id, title),
).fetchone()
if row is None:
return None
record = dict(row)
record['tags'] = get_link_tags(conn, record['id'])
return record
def list_public_links(username: str | None = None): def list_public_links(username: str | None = None):
with get_connection() as conn: with get_connection() as conn:
rows = conn.execute( rows = conn.execute(
@@ -173,7 +186,7 @@ def update_link(
if cursor.rowcount == 0: if cursor.rowcount == 0:
return None return None
conn.execute('DELETE FROM link_tags WHERE link_id = ?', (link_id,)) conn.execute('DELETE FROM link_tags WHERE link_id = ?', (link_id,))
stored_tags = save_link_tags(conn, link_id, normalized_tags) stored_tags = save_link_tags(conn, link_id, normalized_tags, user_id=user_id)
conn.commit() conn.commit()
row = conn.execute('SELECT * FROM links WHERE id = ?', (link_id,)).fetchone() row = conn.execute('SELECT * FROM links WHERE id = ?', (link_id,)).fetchone()
record = dict(row) record = dict(row)
@@ -242,7 +255,15 @@ def list_tags():
def list_user_labels(user_id: str): def list_user_labels(user_id: str):
with get_connection() as conn: with get_connection() as conn:
rows = conn.execute( rows = conn.execute(
'SELECT id, name, created_by FROM tags WHERE created_by = ? ORDER BY name', '''
SELECT tags.id, tags.name, tags.created_by, users.username AS creator
FROM tags
LEFT JOIN users ON users.id = tags.created_by
WHERE tags.created_by IS NULL
OR tags.created_by = ?
OR users.is_admin = 1
ORDER BY tags.name
''',
(user_id,), (user_id,),
).fetchall() ).fetchall()
return [dict(row) for row in rows] return [dict(row) for row in rows]
@@ -268,7 +289,7 @@ def create_label(user_id: str, name: str):
return {'id': label_id, 'name': label, 'created_by': user_id} return {'id': label_id, 'name': label, 'created_by': user_id}
def update_label(label_id: str, user_id: str, name: str): def update_label(label_id: str, user_id: str | None = None, name: str = '', is_admin: bool = False):
normalized = normalize_tags([name]) normalized = normalize_tags([name])
if not normalized: if not normalized:
raise ValueError('Label cannot be empty') raise ValueError('Label cannot be empty')
@@ -276,7 +297,7 @@ def update_label(label_id: str, user_id: str, name: str):
current = conn.execute( current = conn.execute(
'SELECT id, name, created_by FROM tags WHERE id = ?', (label_id,) 'SELECT id, name, created_by FROM tags WHERE id = ?', (label_id,)
).fetchone() ).fetchone()
if current is None or current['created_by'] != user_id: if current is None or (not is_admin and current['created_by'] != user_id):
return None return None
duplicate = conn.execute( duplicate = conn.execute(
'SELECT id FROM tags WHERE lower(name) = lower(?) AND id != ?', 'SELECT id FROM tags WHERE lower(name) = lower(?) AND id != ?',
@@ -286,7 +307,7 @@ def update_label(label_id: str, user_id: str, name: str):
raise ValueError('Label already exists') raise ValueError('Label already exists')
conn.execute('UPDATE tags SET name = ? WHERE id = ?', (normalized[0], label_id)) conn.execute('UPDATE tags SET name = ? WHERE id = ?', (normalized[0], label_id))
conn.commit() conn.commit()
return {'id': label_id, 'name': normalized[0], 'created_by': user_id} return {'id': label_id, 'name': normalized[0], 'created_by': current['created_by']}
def delete_label(label_id: str, user_id: str | None = None, is_admin: bool = False): def delete_label(label_id: str, user_id: str | None = None, is_admin: bool = False):
+31
View File
@@ -7,12 +7,43 @@ import hmac
import secrets import secrets
import time import time
from urllib.parse import quote from urllib.parse import quote
from uuid import uuid4
from backend.app.database import get_connection
def create_secret() -> str: def create_secret() -> str:
return base64.b32encode(secrets.token_bytes(20)).decode('ascii').rstrip('=') return base64.b32encode(secrets.token_bytes(20)).decode('ascii').rstrip('=')
def create_recovery_codes(user_id: str, count: int = 10) -> list[str]:
codes = [secrets.token_urlsafe(9) for _ in range(count)]
with get_connection() as conn:
conn.execute('DELETE FROM otp_recovery_codes WHERE user_id = ?', (user_id,))
conn.executemany(
'INSERT INTO otp_recovery_codes (id, user_id, code_hash) VALUES (?, ?, ?)',
[(str(uuid4()), user_id, hash_recovery_code(code)) for code in codes],
)
conn.commit()
return codes
def hash_recovery_code(code: str) -> str:
return hashlib.sha256(code.strip().encode('utf-8')).hexdigest()
def consume_recovery_code(user_id: str, code: str) -> bool:
with get_connection() as conn:
cursor = conn.execute(
'''UPDATE otp_recovery_codes
SET used = 1, used_at = CURRENT_TIMESTAMP
WHERE user_id = ? AND code_hash = ? AND used = 0''',
(user_id, hash_recovery_code(code)),
)
conn.commit()
return cursor.rowcount == 1
def provisioning_uri(secret: str, username: str, issuer: str = 'LinkLog') -> str: def provisioning_uri(secret: str, username: str, issuer: str = 'LinkLog') -> str:
return f'otpauth://totp/{quote(issuer)}:{quote(username)}?secret={secret}&issuer={quote(issuer)}' return f'otpauth://totp/{quote(issuer)}:{quote(username)}?secret={secret}&issuer={quote(issuer)}'
+6 -1
View File
@@ -34,6 +34,9 @@ class MastodonPlugin(BasePlugin):
return True return True
def handle_event(self, event): def handle_event(self, event):
if not event.get('post_to_mastodon', True):
return {'status': 'skipped', 'plugin': self.name, 'reason': 'not_requested'}
config = dict(self.config) config = dict(self.config)
user_id = event.get('user_id') user_id = event.get('user_id')
if user_id: if user_id:
@@ -68,7 +71,9 @@ class MastodonPlugin(BasePlugin):
post_prefix = f'#{str(config["hashtag"]).strip().lstrip("#")} ' post_prefix = f'#{str(config["hashtag"]).strip().lstrip("#")} '
post_prefix = str(post_prefix if post_prefix is not None else DEFAULT_POST_PREFIX).strip() post_prefix = str(post_prefix if post_prefix is not None else DEFAULT_POST_PREFIX).strip()
title = str(event.get('title') or '').strip() title = str(event.get('title') or '').strip()
status_parts = [f'{post_prefix} {title}'.strip()] status_parts = [post_prefix.strip()]
if title:
status_parts.append(title)
if event.get('comment'): if event.get('comment'):
status_parts.append(event['comment']) status_parts.append(event['comment'])
if title: if title:
+106
View File
@@ -0,0 +1,106 @@
## Copyright © 2026 Olaf Kolkman
## SPDX-License-Identifier: GPL-3.0-or-later
import httpx
import logging
from html.parser import HTMLParser
from urllib.parse import urlparse
logger = logging.getLogger(__name__)
class TitleParser(HTMLParser):
def __init__(self):
super().__init__()
self.title = None
self.og_title = None
self.twitter_title = None
self.meta_title = None
self.in_title = False
def handle_starttag(self, tag, attrs):
if tag.lower() == 'title':
self.in_title = True
elif tag.lower() == 'meta':
attrs_dict = dict(attrs)
# Check for Open Graph title
if attrs_dict.get('property', '').lower() == 'og:title':
content = attrs_dict.get('content', '').strip()
if content and not self.og_title:
self.og_title = content
# Check for Twitter title
elif attrs_dict.get('name', '').lower() == 'twitter:title':
content = attrs_dict.get('content', '').strip()
if content and not self.twitter_title:
self.twitter_title = content
# Check for generic meta title
elif attrs_dict.get('name', '').lower() == 'title':
content = attrs_dict.get('content', '').strip()
if content and not self.meta_title:
self.meta_title = content
def handle_endtag(self, tag):
if tag.lower() == 'title':
self.in_title = False
def handle_data(self, data):
if self.in_title and not self.title:
stripped = data.strip()
if stripped:
self.title = stripped
def get_best_title(self):
"""Return the best title found, matching browser behavior.
Priority: page <title> tag (what browser shows), then meta tags as fallback."""
return self.title or self.og_title or self.twitter_title or self.meta_title
def scrape_title(url: str) -> str:
"""
Scrape the title from a URL, checking multiple sources:
1. Page title tag (what browser shows)
2. Open Graph title (og:title meta tag)
3. Twitter title (twitter:title meta tag)
4. Generic meta title
5. Domain name as fallback
"""
try:
# Parse URL to extract domain as fallback
parsed = urlparse(url)
domain = parsed.netloc or url
# Fetch the URL with a timeout and size limit, using iter_bytes for decompression
with httpx.stream('GET', url, follow_redirects=True, timeout=5.0) as response:
if response.status_code != 200:
logger.warning('Failed to fetch %s: status %d', url, response.status_code)
return domain
# Read HTML in chunks (auto-decompressed) to avoid loading huge files
html_content = b''
max_size = 1024 * 100 # 100 KB limit
for chunk in response.iter_bytes():
html_content += chunk
if len(html_content) > max_size:
break
# Parse the HTML to extract title
try:
html_text = html_content.decode('utf-8', errors='ignore')
parser = TitleParser()
parser.feed(html_text)
best_title = parser.get_best_title()
if best_title:
return best_title
except Exception as e:
logger.warning('Failed to parse HTML from %s: %s', url, e)
return domain
except httpx.TimeoutException:
logger.warning('Timeout fetching %s', url)
return urlparse(url).netloc or url
except httpx.NetworkError as e:
logger.warning('Network error fetching %s: %s', url, e)
return urlparse(url).netloc or url
except Exception as e:
logger.error('Unexpected error scraping %s: %s', url, e)
return urlparse(url).netloc or url
+1
View File
@@ -16,6 +16,7 @@ THEMES = {
'dracula': {'label': 'Dracula', 'description': 'A vivid dark theme with high-contrast accents.'}, 'dracula': {'label': 'Dracula', 'description': 'A vivid dark theme with high-contrast accents.'},
'nord': {'label': 'Nord', 'description': 'A cool, muted blue-gray theme.'}, 'nord': {'label': 'Nord', 'description': 'A cool, muted blue-gray theme.'},
'solarized': {'label': 'Solarized', 'description': 'A balanced theme available in a light style.'}, 'solarized': {'label': 'Solarized', 'description': 'A balanced theme available in a light style.'},
'red': {'label': 'Red', 'description': 'A warm crimson theme with high-contrast surfaces.'},
} }
DEFAULT_ENABLED_THEMES = tuple(THEMES) DEFAULT_ENABLED_THEMES = tuple(THEMES)
+86 -21
View File
@@ -1,7 +1,7 @@
## Copyright © 2026 Olaf Kolkman ## Copyright © 2026 Olaf Kolkman
## SPDX-License-Identifier: GPL-3.0-or-later ## SPDX-License-Identifier: GPL-3.0-or-later
from datetime import datetime, timezone from datetime import datetime, timedelta, timezone
from hashlib import sha256 from hashlib import sha256
from uuid import uuid4 from uuid import uuid4
@@ -13,29 +13,42 @@ def hash_token(token: str) -> str:
return sha256(token.encode('utf-8')).hexdigest() return sha256(token.encode('utf-8')).hexdigest()
def issue_token(user_id: str, username: str) -> dict: def _token_expiry() -> datetime:
token = f'token-{username}-{uuid4().hex}' return datetime.now(timezone.utc) + timedelta(minutes=settings.token_expiry_minutes)
expires_at = datetime.now(timezone.utc).replace(microsecond=0)
expires_at = expires_at.replace(day=expires_at.day + 30 if False else expires_at.day)
# one-month expiry, held as a configured value in settings def _persist_token(conn, user_id: str, token: str, token_type: str, expires_at: datetime,
from datetime import timedelta device_id: str, family_id: str) -> None:
expires_at = datetime.now(timezone.utc) + timedelta(days=settings.token_expiry_days) conn.execute(
'''
INSERT INTO tokens
(id, user_id, token_hash, token_type, expires_at, created_at, revoked, device_id, token_family_id)
VALUES (?, ?, ?, ?, ?, CURRENT_TIMESTAMP, 0, ?, ?)
''',
(str(uuid4()), user_id, hash_token(token), token_type, expires_at.isoformat(), device_id, family_id),
)
def issue_token(user_id: str, username: str, device_id: str | None = None) -> dict:
device_id = device_id.strip() if device_id and device_id.strip() else f'device-{uuid4().hex}'
family_id = str(uuid4())
access_token = f'token-{username}-{uuid4().hex}'
refresh_token = f'refresh-{username}-{uuid4().hex}'
access_expires_at = _token_expiry()
refresh_expires_at = datetime.now(timezone.utc) + timedelta(days=settings.refresh_token_expiry_days)
with get_connection() as conn: with get_connection() as conn:
conn.execute( _persist_token(conn, user_id, access_token, 'access', access_expires_at, device_id, family_id)
''' _persist_token(conn, user_id, refresh_token, 'refresh', refresh_expires_at, device_id, family_id)
INSERT INTO tokens (id, user_id, token_hash, token_type, expires_at, created_at, revoked)
VALUES (?, ?, ?, 'access', ?, CURRENT_TIMESTAMP, 0)
''',
(str(uuid4()), user_id, hash_token(token), expires_at.isoformat())
)
conn.commit() conn.commit()
return { return {
'access_token': token, 'access_token': access_token,
'token_type': 'bearer', 'token_type': 'bearer',
'expires_at': expires_at.isoformat(), 'expires_at': access_expires_at.isoformat(),
'refresh_token': f'refresh-{uuid4().hex}', 'refresh_token': refresh_token,
'device_id': device_id,
'token_family_id': family_id,
} }
@@ -45,7 +58,7 @@ def validate_token(token: str) -> dict | None:
row = conn.execute( row = conn.execute(
''' '''
SELECT * FROM tokens SELECT * FROM tokens
WHERE token_hash = ? AND revoked = 0 AND expires_at > ? WHERE token_hash = ? AND token_type = 'access' AND revoked = 0 AND expires_at > ?
''', ''',
(token_hash, datetime.now(timezone.utc).isoformat()), (token_hash, datetime.now(timezone.utc).isoformat()),
).fetchone() ).fetchone()
@@ -54,12 +67,64 @@ def validate_token(token: str) -> dict | None:
return dict(row) return dict(row)
def validate_refresh_token(token: str, device_id: str | None = None) -> dict | None:
with get_connection() as conn:
row = conn.execute(
'''
SELECT * FROM tokens
WHERE token_hash = ? AND token_type = 'refresh' AND revoked = 0 AND expires_at > ?
AND (? IS NULL OR device_id = ?)
''',
(hash_token(token), datetime.now(timezone.utc).isoformat(), device_id, device_id),
).fetchone()
return dict(row) if row else None
def rotate_refresh_token(refresh_token: str, device_id: str | None = None) -> dict | None:
current = validate_refresh_token(refresh_token, device_id)
with get_connection() as conn:
if current is None:
row = conn.execute(
'SELECT token_family_id FROM tokens WHERE token_hash = ? AND token_type = ? AND token_family_id IS NOT NULL',
(hash_token(refresh_token), 'refresh'),
).fetchone()
if row:
conn.execute('UPDATE tokens SET revoked = 1 WHERE token_family_id = ?', (row['token_family_id'],))
conn.commit()
return None
user = conn.execute('SELECT username FROM users WHERE id = ?', (current['user_id'],)).fetchone()
if user is None:
return None
family_id = current['token_family_id']
conn.execute('UPDATE tokens SET revoked = 1 WHERE token_family_id = ?', (family_id,))
new_access = f'token-{user["username"]}-{uuid4().hex}'
new_refresh = f'refresh-{user["username"]}-{uuid4().hex}'
access_expires_at = _token_expiry()
refresh_expires_at = datetime.now(timezone.utc) + timedelta(days=settings.refresh_token_expiry_days)
_persist_token(conn, current['user_id'], new_access, 'access', access_expires_at, current['device_id'], family_id)
_persist_token(conn, current['user_id'], new_refresh, 'refresh', refresh_expires_at, current['device_id'], family_id)
conn.commit()
return {
'access_token': new_access,
'token_type': 'bearer',
'expires_at': access_expires_at.isoformat(),
'refresh_token': new_refresh,
'device_id': current['device_id'],
'user_id': current['user_id'],
'username': user['username'],
}
def revoke_token(token: str) -> bool: def revoke_token(token: str) -> bool:
token_hash = hash_token(token) token_hash = hash_token(token)
with get_connection() as conn: with get_connection() as conn:
cursor = conn.execute( cursor = conn.execute(
'UPDATE tokens SET revoked = 1 WHERE token_hash = ?', '''UPDATE tokens SET revoked = 1
(token_hash,), WHERE token_hash = ? OR token_family_id = (
SELECT token_family_id FROM tokens WHERE token_hash = ?
)''',
(token_hash, token_hash),
) )
conn.commit() conn.commit()
return cursor.rowcount > 0 return cursor.rowcount > 0
+1
View File
@@ -3,6 +3,7 @@ uvicorn==0.52.4
pydantic==2.13.4 pydantic==2.13.4
jinja2==3.1.6 jinja2==3.1.6
python-multipart==0.0.20 python-multipart==0.0.20
Pillow==11.3.0
pytest==9.1.1 pytest==9.1.1
httpx==0.28.1 httpx==0.28.1
httpx2==2.12.0 httpx2==2.12.0
+242 -19
View File
@@ -2,6 +2,7 @@
## SPDX-License-Identifier: GPL-3.0-or-later ## SPDX-License-Identifier: GPL-3.0-or-later
import json import json
from pathlib import Path
import threading import threading
from http.server import BaseHTTPRequestHandler, ThreadingHTTPServer from http.server import BaseHTTPRequestHandler, ThreadingHTTPServer
from urllib.parse import parse_qs from urllib.parse import parse_qs
@@ -11,9 +12,11 @@ from unittest.mock import MagicMock, patch
from fastapi.testclient import TestClient from fastapi.testclient import TestClient
from backend.app.main import app from backend.app.main import app
from backend.app.database import get_connection from backend.app.core.config import settings
from backend.app.database import get_connection, hash_password
from backend.app.services.email_service import get_smtp_settings from backend.app.services.email_service import get_smtp_settings
from backend.app.services.login_throttle import clear_login_failures from backend.app.services.login_throttle import clear_login_failures
from backend.app.services.otp_service import current_code
from backend.app.services.password_reset import create_reset_token from backend.app.services.password_reset import create_reset_token
from backend.app.services.token_service import issue_token from backend.app.services.token_service import issue_token
@@ -30,7 +33,7 @@ def login_headers(username='alice'):
def test_login_returns_token(): def test_login_returns_token():
assert app.version == '0.1.0' assert app.version == settings.version
response = client.post('/api/auth/login', json={ response = client.post('/api/auth/login', json={
'email': 'alice@example.com', 'email': 'alice@example.com',
'password': 'secret123', 'password': 'secret123',
@@ -54,6 +57,17 @@ def test_login_returns_token():
assert client.get('/api/auth/me', params={'token': payload['access_token']}).status_code == 401 assert client.get('/api/auth/me', params={'token': payload['access_token']}).status_code == 401
def test_logout_requires_bearer_header_and_revokes_token_family():
login = client.post('/api/auth/login', json={'email': 'alice@example.com', 'password': 'secret123'}).json()
token = login['access_token']
headers = {'Authorization': f'Bearer {token}'}
assert client.post('/api/auth/logout', json={'token': token}).status_code == 401
assert client.get('/api/auth/me', headers=headers).status_code == 200
assert client.post('/api/auth/logout', headers=headers).status_code == 200
assert client.get('/api/auth/me', headers=headers).status_code == 401
assert client.post('/api/auth/refresh', json={'refresh_token': login['refresh_token'], 'device_id': login['device_id']}).status_code == 401
def test_login_rate_limit_locks_out_after_five_failures_and_resets_on_success(): def test_login_rate_limit_locks_out_after_five_failures_and_resets_on_success():
email = f'unknown-{uuid4().hex}@example.com' email = f'unknown-{uuid4().hex}@example.com'
for attempt in range(5): for attempt in range(5):
@@ -68,6 +82,37 @@ def test_login_rate_limit_locks_out_after_five_failures_and_resets_on_success():
assert valid.status_code == 200 assert valid.status_code == 200
def test_refresh_token_rotates_and_reuse_revokes_family():
device_id = f'device-{uuid4().hex}'
login = client.post('/api/auth/login', json={
'email': 'alice@example.com',
'password': 'secret123',
'device_id': device_id,
})
assert login.status_code == 200
first = login.json()
rotated = client.post('/api/auth/refresh', json={
'refresh_token': first['refresh_token'],
'device_id': device_id,
})
assert rotated.status_code == 200
second = rotated.json()
assert second['refresh_token'] != first['refresh_token']
assert client.get('/api/auth/me', headers={'Authorization': f"Bearer {second['access_token']}"}).status_code == 200
reused = client.post('/api/auth/refresh', json={
'refresh_token': first['refresh_token'],
'device_id': device_id,
})
assert reused.status_code == 401
family_revoked = client.post('/api/auth/refresh', json={
'refresh_token': second['refresh_token'],
'device_id': device_id,
})
assert family_revoked.status_code == 401
def test_password_hashes_are_salted_and_legacy_hashes_upgrade_on_login(): def test_password_hashes_are_salted_and_legacy_hashes_upgrade_on_login():
from hashlib import sha256 from hashlib import sha256
from backend.app.database import hash_password from backend.app.database import hash_password
@@ -107,10 +152,10 @@ def test_configuration_requires_authentication_and_admin_role():
def test_admin_can_select_multiple_themes(): def test_admin_can_select_multiple_themes():
headers = login_headers() headers = login_headers()
response = client.put('/api/admin/themes', headers=headers, json={ response = client.put('/api/admin/themes', headers=headers, json={
'themes': ['plain-day', 'plain-night', 'latte', 'frappe', 'macchiato', 'mocha', 'dracula', 'nord', 'solarized'], 'themes': ['plain-day', 'plain-night', 'latte', 'frappe', 'macchiato', 'mocha', 'dracula', 'nord', 'solarized', 'red'],
}) })
assert response.status_code == 200 assert response.status_code == 200
assert response.json()['enabled'] == ['plain-day', 'plain-night', 'latte', 'frappe', 'macchiato', 'mocha', 'dracula', 'nord', 'solarized'] assert response.json()['enabled'] == ['plain-day', 'plain-night', 'latte', 'frappe', 'macchiato', 'mocha', 'dracula', 'nord', 'solarized', 'red']
public_response = client.get('/api/public/themes') public_response = client.get('/api/public/themes')
assert public_response.status_code == 200 assert public_response.status_code == 200
assert [theme['id'] for theme in public_response.json()] == response.json()['enabled'] assert [theme['id'] for theme in public_response.json()] == response.json()['enabled']
@@ -184,7 +229,31 @@ def test_admin_reports_smtp_validation_errors():
'smtp_use_tls': False, 'smtp_use_tls': False,
}) })
assert failed_validation.status_code == 503 assert failed_validation.status_code == 503
assert 'connection refused' in failed_validation.json()['detail'] assert failed_validation.json()['detail'].startswith('SMTP validation failed. Reference: ')
assert 'connection refused' not in failed_validation.json()['detail']
assert failed_validation.headers['X-Request-ID']
def test_request_id_is_preserved_and_sensitive_error_text_is_not_returned():
headers = login_headers()
with get_connection() as conn:
conn.execute('DELETE FROM app_settings WHERE name = ?', ('admin_smtp_mail_rate',))
conn.commit()
with patch('backend.app.api.admin.send_test_email', side_effect=RuntimeError('password=super-secret token=abc123')):
response = client.post(
'/api/admin/smtp/test',
headers={**headers, 'X-Request-ID': 'audit-test-123'},
json={
'smtp_host': 'smtp.example.com',
'smtp_port': 2525,
'smtp_from': 'admin@example.com',
},
)
assert response.status_code == 503
assert response.headers['X-Request-ID'] == 'audit-test-123'
assert response.json()['detail'] == 'SMTP validation failed. Reference: audit-test-123'
assert 'super-secret' not in response.text
assert 'abc123' not in response.text
def test_admin_can_add_list_and_remove_users(): def test_admin_can_add_list_and_remove_users():
@@ -208,6 +277,52 @@ def test_admin_can_add_list_and_remove_users():
assert client.put('/api/admin/users/user-1', headers=headers, json={'is_admin': False}).status_code == 400 assert client.put('/api/admin/users/user-1', headers=headers, json={'is_admin': False}).status_code == 400
def test_admin_can_reset_another_users_otp():
admin_headers = login_headers()
user_login = client.post('/api/auth/login', json={
'email': 'bob@example.com',
'password': 'secret123',
}).json()
user_headers = {'Authorization': f"Bearer {user_login['access_token']}"}
setup = client.post('/api/user/otp/setup', headers=user_headers)
assert setup.status_code == 200
secret = setup.json()['secret']
recovery_code = setup.json()['recovery_codes'][0]
assert client.post('/api/user/otp', headers=user_headers, json={
'action': 'enable', 'code': current_code(secret),
}).status_code == 200
assert client.post('/api/admin/users/user-2/otp/reset', headers=admin_headers).json() == {
'status': 'otp_reset', 'enabled': False, 'user_id': 'user-2',
}
assert client.get('/api/user/otp', headers=user_headers).json() == {'enabled': False}
assert client.post('/api/user/otp/recover', headers=user_headers, json={
'current_password': 'secret123', 'recovery_code': recovery_code,
}).status_code == 400
assert client.post('/api/admin/users/user-2/otp/reset', headers=login_headers('bob')).status_code == 403
assert client.post('/api/admin/users/missing-user/otp/reset', headers=admin_headers).status_code == 404
def test_security_audit_events_are_append_only_and_do_not_store_secrets():
admin_headers = login_headers()
response = client.put('/api/admin/themes', headers=admin_headers, json={'themes': ['plain-day']})
assert response.status_code == 200
with get_connection() as conn:
event = conn.execute(
'''SELECT actor_id, action, target_type, outcome, details
FROM security_audit_events
WHERE action = 'themes_updated'
ORDER BY created_at DESC, rowid DESC LIMIT 1''',
).fetchone()
assert event is not None
assert event['actor_id'] == 'user-1'
assert event['target_type'] == 'application'
assert event['outcome'] == 'success'
assert 'password' not in event['details'].lower()
assert 'token' not in event['details'].lower()
assert 'secret' not in event['details'].lower()
def test_new_user_must_verify_email_before_login(): def test_new_user_must_verify_email_before_login():
headers = login_headers() headers = login_headers()
username = f'unverified-{uuid4().hex}' username = f'unverified-{uuid4().hex}'
@@ -377,25 +492,102 @@ def test_admin_can_toggle_privileges_without_removing_last_admin():
assert last_admin.status_code == 400 assert last_admin.status_code == 400
def test_users_manage_owned_labels_and_admin_can_delete_any_label(): def test_users_manage_owned_labels_and_admin_can_edit_and_delete_any_label():
alice_headers = login_headers('alice') alice_headers = login_headers('alice') # admin
created = client.post('/api/user/labels', headers=alice_headers, json={'name': 'My Label'}) bob_headers = login_headers('bob') # non-admin
created = client.post('/api/user/labels', headers=bob_headers, json={'name': 'Bob Label'})
assert created.status_code == 201 assert created.status_code == 201
label = created.json() label = created.json()
assert label['name'] == '#My Label' assert label['name'] == '#Bob Label'
edited = client.put(f"/api/user/labels/{label['id']}", headers=alice_headers, json={'name': '#Renamed'}) # Bob renames own label
edited = client.put(f"/api/user/labels/{label['id']}", headers=bob_headers, json={'name': '#RenamedByBob'})
assert edited.status_code == 200 assert edited.status_code == 200
assert edited.json()['name'] == '#Renamed' assert edited.json()['name'] == '#RenamedByBob'
denied = client.put(f"/api/user/labels/{label['id']}", headers=login_headers('bob'), json={'name': '#Nope'}) # Non-owner Alice can edit it via admin endpoint, but NOT user endpoint
assert denied.status_code == 404 user_denied = client.put(f"/api/user/labels/{label['id']}", headers=alice_headers, json={'name': '#NopeUser'})
assert client.delete(f"/api/user/labels/{label['id']}", headers=login_headers('bob')).status_code == 404 assert user_denied.status_code == 404
admin_edited = client.put(f"/api/admin/labels/{label['id']}", headers=alice_headers, json={'name': '#AdminRenamed'})
assert admin_edited.status_code == 200
assert admin_edited.json()['name'] == '#AdminRenamed'
# Non-admin Bob cannot access admin edit endpoint
bob_admin_denied = client.put(f"/api/admin/labels/{label['id']}", headers=bob_headers, json={'name': '#NopeAdmin'})
assert bob_admin_denied.status_code == 403
# Admin delete
admin_delete = client.delete(f"/api/admin/labels/{label['id']}", headers=alice_headers) admin_delete = client.delete(f"/api/admin/labels/{label['id']}", headers=alice_headers)
assert admin_delete.status_code == 200 assert admin_delete.status_code == 200
def test_label_visibility_isolation_and_grandfathering():
alice_headers = login_headers('alice')
bob_headers = login_headers('bob')
# Create non-admin user charlie
with get_connection() as conn:
conn.execute(
'''INSERT OR IGNORE INTO users (id, username, email, password_hash, is_admin, email_verified)
VALUES (?, ?, ?, ?, 0, 1)''',
('user-3', 'charlie', 'charlie@example.com', hash_password('secret123')),
)
conn.commit()
charlie_headers = login_headers('charlie')
# Create Bob label (non-admin)
created_bob = client.post('/api/user/labels', headers=bob_headers, json={'name': 'BobOnlyLabel'}).json()
# Create Charlie label (non-admin)
created_charlie = client.post('/api/user/labels', headers=charlie_headers, json={'name': 'CharlieOnlyLabel'}).json()
# Grandfathered label in DB with NULL created_by
from uuid import uuid4
grandfathered_id = str(uuid4())
with get_connection() as conn:
conn.execute('INSERT INTO tags (id, name, created_by) VALUES (?, ?, NULL)', (grandfathered_id, '#GrandfatheredLabel'))
conn.commit()
# Bob views /api/user/labels: sees default tags, grandfathered tag, and Bob tag, NOT Charlie tag
bob_labels = client.get('/api/user/labels', headers=bob_headers).json()
bob_label_names = [l['name'] for l in bob_labels]
assert '#BobOnlyLabel' in bob_label_names
assert '#GrandfatheredLabel' in bob_label_names
assert '#Cybersecurity' in bob_label_names
assert '#CharlieOnlyLabel' not in bob_label_names
# Charlie views /api/user/labels: sees default tags, grandfathered tag, and Charlie tag, NOT Bob tag
charlie_labels = client.get('/api/user/labels', headers=charlie_headers).json()
charlie_label_names = [l['name'] for l in charlie_labels]
assert '#CharlieOnlyLabel' in charlie_label_names
assert '#GrandfatheredLabel' in charlie_label_names
assert '#Cybersecurity' in charlie_label_names
assert '#BobOnlyLabel' not in charlie_label_names
# Every user can filter by every available tag, including another user's label.
bob_tags = client.get('/api/tags', headers=bob_headers).json()
assert '#BobOnlyLabel' in bob_tags
assert '#GrandfatheredLabel' in bob_tags
assert '#CharlieOnlyLabel' in bob_tags
# The public feed filter has the same complete tag catalog.
anon_tags = client.get('/api/tags').json()
assert '#GrandfatheredLabel' in anon_tags
assert '#BobOnlyLabel' in anon_tags
assert '#CharlieOnlyLabel' in anon_tags
# Bob cannot edit or delete grandfathered label
assert client.put(f"/api/user/labels/{grandfathered_id}", headers=bob_headers, json={'name': '#RenamedGrandfathered'}).status_code == 404
assert client.delete(f"/api/user/labels/{grandfathered_id}", headers=bob_headers).status_code == 404
# Clean up created labels
client.delete(f"/api/user/labels/{created_bob['id']}", headers=bob_headers)
client.delete(f"/api/user/labels/{created_charlie['id']}", headers=charlie_headers)
client.delete(f"/api/admin/labels/{grandfathered_id}", headers=alice_headers)
def test_labels_page_renders_authenticated_management_shell(): def test_labels_page_renders_authenticated_management_shell():
page = client.get('/labels') page = client.get('/labels')
assert page.status_code == 200 assert page.status_code == 200
@@ -565,8 +757,7 @@ def test_only_link_owner_can_edit_link():
def test_logout_revokes_token_and_admin_can_list_plugins(): def test_logout_revokes_token_and_admin_can_list_plugins():
headers = login_headers() headers = login_headers()
token = headers['Authorization'].removeprefix('Bearer ') assert client.post('/api/auth/logout', headers=headers).status_code == 200
assert client.post('/api/auth/logout', json={'token': token}).status_code == 200
revoked_response = client.post('/api/links', headers=headers, json={ revoked_response = client.post('/api/links', headers=headers, json={
'title': 'Should fail', 'title': 'Should fail',
@@ -603,6 +794,7 @@ def test_public_and_admin_pages_render_html():
assert 'alice' in user_page assert 'alice' in user_page
assert 'data-user-filter="alice"' in user_page assert 'data-user-filter="alice"' in user_page
assert 'profile-summary' in user_page assert 'profile-summary' in user_page
assert '<div class="header-tools">' in user_page
feed_script = TestClient(app).get('/static/feed.js?v=4').text feed_script = TestClient(app).get('/static/feed.js?v=4').text
assert 'window.location.assign(selectedUser ? `/${encodeURIComponent(selectedUser)}/` : \'/\')' in feed_script assert 'window.location.assign(selectedUser ? `/${encodeURIComponent(selectedUser)}/` : \'/\')' in feed_script
assert client.get('/login').status_code == 200 assert client.get('/login').status_code == 200
@@ -615,6 +807,10 @@ def test_public_and_admin_pages_render_html():
about_page = client.get('/about') about_page = client.get('/about')
assert about_page.status_code == 200 assert about_page.status_code == 200
assert 'Save the good stuff' in about_page.text assert 'Save the good stuff' in about_page.text
assert '<h2>Plugin</h2>' in about_page.text
updates = json.loads((Path(__file__).resolve().parents[2] / 'webextension' / 'updates.json').read_text())
latest_update = updates['addons']['linklog@kolkman.org']['updates'][0]
assert latest_update['update_link'] in about_page.text
assert 'id="auth-about-link" href="/about"' in about_page.text assert 'id="auth-about-link" href="/about"' in about_page.text
assert client.get('/admin').status_code == 200 assert client.get('/admin').status_code == 200
admin_page = client.get('/admin').text admin_page = client.get('/admin').text
@@ -624,12 +820,23 @@ def test_public_and_admin_pages_render_html():
assert 'id="auth-menu" class="auth-menu hidden"' in admin_page assert 'id="auth-menu" class="auth-menu hidden"' in admin_page
assert 'id="auth-home-link" href="/">Home</a>' in admin_page assert 'id="auth-home-link" href="/">Home</a>' in admin_page
assert '<a id="auth-username" class="user-name" href="/">' in admin_page assert '<a id="auth-username" class="user-name" href="/">' in admin_page
assert 'admin.js?v=5' in admin_page assert 'class="panel-toggle-btn"' in admin_page
assert 'admin.js?v=7' in admin_page
assert client.get('/profile').status_code == 200
profile_page = client.get('/profile').text
assert 'Profile' in profile_page
assert 'class="link-item settings-panel minimized"' in profile_page
assert 'class="panel-toggle-btn"' in profile_page
assert 'profile.js?v=6' in profile_page
feed_script = client.get('/static/feed.js?v=7').text feed_script = client.get('/static/feed.js?v=7').text
assert 'if (item.is_owner && !showIdentity)' in feed_script assert 'if (item.is_owner && !showIdentity)' in feed_script
assert 'deleteEntry(item, deleteButton)' in feed_script assert 'deleteEntry(item, deleteButton)' in feed_script
assert 'postToMastodon(item, mastodonButton)' in feed_script assert 'postToMastodon(item, mastodonButton)' in feed_script
assert 'tag.toLowerCase() === pref.tag.toLowerCase()' in feed_script assert 'tag.toLowerCase() === activeTag.toLowerCase()' in feed_script
assert 'loadFeed(event.target.value)' in feed_script
assert 'Promise.all([loadUsers(), loadTags()]).then(() => loadFeed())' in feed_script
assert "fetch('/api/tags', {" in feed_script
assert 'Authorization: `Bearer ${accessToken}`' in feed_script
assert 'return `${date.getFullYear()} ${months[date.getMonth()]} ${date.getDate()} - ${hours}:${minutes}`' in feed_script assert 'return `${date.getFullYear()} ${months[date.getMonth()]} ${date.getDate()} - ${hours}:${minutes}`' in feed_script
assert "entryMeta.className = 'entry-meta'" in feed_script assert "entryMeta.className = 'entry-meta'" in feed_script
assert "meta.className = 'meta'" in feed_script assert "meta.className = 'meta'" in feed_script
@@ -638,6 +845,9 @@ def test_public_and_admin_pages_render_html():
assert 'edit-tag-options' in feed_script assert 'edit-tag-options' in feed_script
assert 'new_tags' in feed_script assert 'new_tags' in feed_script
assert 'A link can have at most 10 tags.' in feed_script assert 'A link can have at most 10 tags.' in feed_script
style_sheet = client.get('/static/style.css').text
assert "@import url('/static/fonts/fonts.css');" in style_sheet
assert 'fonts.googleapis.com' not in style_sheet
def test_link_submission_posts_to_enabled_mastodon_plugin(): def test_link_submission_posts_to_enabled_mastodon_plugin():
@@ -682,7 +892,7 @@ def test_link_submission_posts_to_enabled_mastodon_plugin():
assert received['path'] == '/api/v1/statuses' assert received['path'] == '/api/v1/statuses'
assert received['authorization'] == 'Bearer test-token' assert received['authorization'] == 'Bearer test-token'
assert received['content_type'] == 'application/x-www-form-urlencoded' assert received['content_type'] == 'application/x-www-form-urlencoded'
assert received['body'] == {'status': ['From my #LinkLog: A useful page\n\nWorth sharing\n\nfrom: https://example.com/useful\n\n#python #web']} assert received['body'] == {'status': ['From my #LinkLog:\n\nA useful page\n\nWorth sharing\n\nfrom: https://example.com/useful\n\n#python #web']}
posted_item = next(item for item in client.get('/api/public/feed/alice', headers=headers).json() if item['id'] == response.json()['id']) posted_item = next(item for item in client.get('/api/public/feed/alice', headers=headers).json() if item['id'] == response.json()['id'])
assert posted_item['mastodon_posted'] is True assert posted_item['mastodon_posted'] is True
finally: finally:
@@ -691,6 +901,18 @@ def test_link_submission_posts_to_enabled_mastodon_plugin():
server.server_close() server.server_close()
def test_link_submission_can_skip_mastodon_posting():
with patch('backend.app.api.links.plugin_manager.dispatch', return_value=[]) as dispatch:
response = client.post('/api/links', headers=login_headers(), json={
'title': 'Private share',
'url': 'https://example.com/private-share',
'post_to_mastodon': False,
})
assert response.status_code == 201
assert dispatch.call_args.args[0]['post_to_mastodon'] is False
def test_mastodon_post_without_title_omits_source_line(): def test_mastodon_post_without_title_omits_source_line():
from backend.app.services.plugin_manager import MastodonPlugin from backend.app.services.plugin_manager import MastodonPlugin
@@ -724,6 +946,7 @@ def test_plugin_config_can_be_saved_for_mastodon():
payload = client.get('/api/user/plugins/mastodon', headers=headers).json() payload = client.get('/api/user/plugins/mastodon', headers=headers).json()
assert payload['instance'] == 'mastodon.social' assert payload['instance'] == 'mastodon.social'
assert payload['post_prefix'] == 'From my #LinkLog: ' assert payload['post_prefix'] == 'From my #LinkLog: '
assert payload['configured'] is True
admin_update = client.put('/api/admin/plugins/mastodon', headers=headers, json={ admin_update = client.put('/api/admin/plugins/mastodon', headers=headers, json={
'enabled': True, 'enabled': True,
+44
View File
@@ -0,0 +1,44 @@
import re
from pathlib import Path
import pytest
from backend.app.core.config import Settings, validate_configuration
ROOT = Path(__file__).resolve().parents[2]
def test_production_configuration_rejects_missing_or_default_secret():
with pytest.raises(RuntimeError, match='LINKLOG_SECRET_KEY'):
validate_configuration(Settings(app_env='production', secret_key='', data_encryption_key=''))
with pytest.raises(RuntimeError, match='LINKLOG_SECRET_KEY'):
validate_configuration(Settings(app_env='production', secret_key='dev-secret-key-change-me', data_encryption_key=''))
def test_production_configuration_rejects_weak_or_missing_encryption_key():
with pytest.raises(RuntimeError, match='entropy'):
validate_configuration(Settings(app_env='production', secret_key='A' * 32, data_encryption_key=''))
with pytest.raises(RuntimeError, match='DATA_ENCRYPTION_KEY'):
validate_configuration(Settings(app_env='production', secret_key='A1b2C3d4E5f6G7h8I9j0K1l2M3n4O5p6', data_encryption_key='invalid'))
def test_production_configuration_accepts_strong_secrets():
values = Settings(
app_env='production',
secret_key='A1b2C3d4E5f6G7h8I9j0K1l2M3n4O5p6',
data_encryption_key='L5M4sQYVjD1N7pT2Xk8R0aBcDeFgHiJkLmNoPqRsTuV=',
)
validate_configuration(values)
def test_production_compose_configuration_matches_settings_environment_keys():
compose = (ROOT / 'docker-compose.yml').read_text()
settings = (ROOT / 'backend' / 'app' / 'core' / 'config.py').read_text()
database = (ROOT / 'backend' / 'app' / 'database.py').read_text()
compose_keys = set(re.findall(r'\b(LINKLOG_[A-Z0-9_]+):', compose))
settings_keys = set(re.findall(r"os\.getenv\('([^']+)'", settings + database))
assert {'LINKLOG_TOKEN_EXPIRY_MINUTES', 'LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS'} <= compose_keys
assert compose_keys & settings_keys == compose_keys
assert 'LINKLOG_TOKEN_EXPIRY_DAYS' not in compose_keys
+2 -2
View File
@@ -10,7 +10,7 @@ def test_database_migrations_are_versioned_and_idempotent():
connection = sqlite3.connect(':memory:') connection = sqlite3.connect(':memory:')
apply_migrations(connection) apply_migrations(connection)
assert get_schema_version(connection) == 14 assert get_schema_version(connection) == 17
tables = { tables = {
row[0] row[0]
for row in connection.execute( for row in connection.execute(
@@ -27,6 +27,6 @@ def test_database_migrations_are_versioned_and_idempotent():
assert set(DEFAULT_TAGS) <= seeded_tags assert set(DEFAULT_TAGS) <= seeded_tags
apply_migrations(connection) apply_migrations(connection)
assert get_schema_version(connection) == 14 assert get_schema_version(connection) == 17
connection.close() connection.close()
+35 -2
View File
@@ -3,7 +3,7 @@
from unittest.mock import patch from unittest.mock import patch
from backend.app.services.email_service import send_test_email, send_verification_email from backend.app.services.email_service import send_password_reset_email, send_test_email, send_verification_email
def test_send_verification_email_uses_smtp_settings(monkeypatch): def test_send_verification_email_uses_smtp_settings(monkeypatch):
@@ -15,6 +15,7 @@ def test_send_verification_email_uses_smtp_settings(monkeypatch):
monkeypatch.setattr(settings, 'smtp_username', 'mailer') monkeypatch.setattr(settings, 'smtp_username', 'mailer')
monkeypatch.setattr(settings, 'smtp_password', 'secret') monkeypatch.setattr(settings, 'smtp_password', 'secret')
monkeypatch.setattr(settings, 'smtp_use_tls', True) monkeypatch.setattr(settings, 'smtp_use_tls', True)
monkeypatch.setattr(settings, 'public_url', 'https://linklog.example')
with patch('backend.app.services.email_service.SMTP') as smtp_class: with patch('backend.app.services.email_service.SMTP') as smtp_class:
smtp = smtp_class.return_value.__enter__.return_value smtp = smtp_class.return_value.__enter__.return_value
@@ -25,7 +26,22 @@ def test_send_verification_email_uses_smtp_settings(monkeypatch):
smtp.login.assert_called_once_with('mailer', 'secret') smtp.login.assert_called_once_with('mailer', 'secret')
message = smtp.send_message.call_args.args[0] message = smtp.send_message.call_args.args[0]
assert message['To'] == 'user@example.com' assert message['To'] == 'user@example.com'
assert 'https://linklog.example/verify' in message.get_content() assert 'https://linklog.example/verify' in message.get_body(preferencelist=('plain',)).get_content()
html = message.get_body(preferencelist=('html',)).get_content()
assert 'cid:linklog-logo' in html
assert 'width="50" height="50"' in html
assert 'font-family:\'Asset\',Georgia,serif' in html
assert 'Hello, a message from' in html
assert 'vertical-align:top' in html
assert 'padding:20px 0 20px 12px' in html
assert 'font-size:18px' in html
assert 'href="https://linklog.example"' in html
assert '>linklog.example</a>' in html
assert any(
part.get_content_type() == 'image/svg+xml'
and part['Content-ID'] == '<linklog-logo>'
for part in message.walk()
)
def test_send_test_email_uses_configured_recipient(monkeypatch): def test_send_test_email_uses_configured_recipient(monkeypatch):
@@ -40,6 +56,23 @@ def test_send_test_email_uses_configured_recipient(monkeypatch):
message = smtp.send_message.call_args.args[0] message = smtp.send_message.call_args.args[0]
assert message['To'] == 'admin@example.com' assert message['To'] == 'admin@example.com'
assert message['Subject'] == 'LinkLog SMTP test' assert message['Subject'] == 'LinkLog SMTP test'
assert message.get_body(preferencelist=('html',)) is not None
def test_password_reset_email_escapes_html_and_includes_logo(monkeypatch):
from backend.app.core.config import settings
monkeypatch.setattr(settings, 'smtp_host', 'smtp.example.com')
monkeypatch.setattr(settings, 'smtp_from', 'LinkLog <no-reply@example.com>')
with patch('backend.app.services.email_service.SMTP') as smtp_class:
smtp = smtp_class.return_value.__enter__.return_value
send_password_reset_email('user@example.com', '<User>', 'https://linklog.example/reset?x=1&y=2')
message = smtp.send_message.call_args.args[0]
html = message.get_body(preferencelist=('html',)).get_content()
assert '&lt;User&gt;' in html
assert 'x=1&amp;y=2' in html
assert 'cid:linklog-logo' in html
def test_smtp_password_is_encrypted_at_rest(): def test_smtp_password_is_encrypted_at_rest():
+48 -3
View File
@@ -1,7 +1,10 @@
## Copyright © 2026 Olaf Kolkman ## Copyright © 2026 Olaf Kolkman
## SPDX-License-Identifier: GPL-3.0-or-later ## SPDX-License-Identifier: GPL-3.0-or-later
from io import BytesIO
from fastapi.testclient import TestClient from fastapi.testclient import TestClient
from PIL import Image
from unittest.mock import patch from unittest.mock import patch
from backend.app.main import app from backend.app.main import app
@@ -48,6 +51,8 @@ def test_user_config_api_and_profile_page():
assert 'id="auth-avatar"' not in page_response.text assert 'id="auth-avatar"' not in page_response.text
assert 'name="new_password_confirmation"' in page_response.text assert 'name="new_password_confirmation"' in page_response.text
assert 'id="additional-email-form"' in page_response.text assert 'id="additional-email-form"' in page_response.text
assert 'If you have not downloaded the plugin yet' in page_response.text
assert 'https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi' in page_response.text
bob_login = client.post('/api/auth/login', json={ bob_login = client.post('/api/auth/login', json={
'email': 'bob@example.com', 'email': 'bob@example.com',
@@ -68,15 +73,29 @@ def test_user_config_api_and_profile_page():
'new_password': 'secret123', 'new_password': 'secret123',
}, headers=bob_headers).status_code == 200 }, headers=bob_headers).status_code == 200
image_buffer = BytesIO()
Image.new('RGB', (2, 2), 'red').save(image_buffer, format='JPEG')
upload_response = client.post( upload_response = client.post(
'/api/user/avatar', '/api/user/avatar',
headers=headers, headers=headers,
files={'avatar': ('avatar.png', b'fake-png-data', 'image/png')}, files={'avatar': ('avatar.jpg', image_buffer.getvalue(), 'image/jpeg')},
) )
assert upload_response.status_code == 200 assert upload_response.status_code == 200
avatar_url = upload_response.json()['avatar_url'] avatar_url = upload_response.json()['avatar_url']
assert avatar_url.startswith('/media/user-1.png') assert avatar_url.startswith('/media/user-1.png')
assert client.get(avatar_url).content == b'fake-png-data' stored_avatar = client.get(avatar_url)
assert stored_avatar.status_code == 200
assert stored_avatar.headers['content-type'] == 'image/png'
with Image.open(BytesIO(stored_avatar.content)) as image:
assert image.format == 'PNG'
assert image.size == (2, 2)
rejected_upload = client.post(
'/api/user/avatar',
headers=headers,
files={'avatar': ('avatar.png', b'fake-png-data', 'image/png')},
)
assert rejected_upload.status_code == 415
updated_profile = client.get('/api/user/me', headers=headers).json() updated_profile = client.get('/api/user/me', headers=headers).json()
assert updated_profile['avatar_url'] == avatar_url assert updated_profile['avatar_url'] == avatar_url
@@ -89,6 +108,8 @@ def test_user_can_enable_and_use_otp():
assert setup.status_code == 200 assert setup.status_code == 200
secret = setup.json()['secret'] secret = setup.json()['secret']
assert setup.json()['otpauth_url'].startswith('otpauth://totp/') assert setup.json()['otpauth_url'].startswith('otpauth://totp/')
recovery_codes = setup.json()['recovery_codes']
assert len(recovery_codes) == 10
enabled = client.post('/api/user/otp', headers=headers, json={ enabled = client.post('/api/user/otp', headers=headers, json={
'action': 'enable', 'code': current_code(secret), 'action': 'enable', 'code': current_code(secret),
@@ -103,12 +124,36 @@ def test_user_can_enable_and_use_otp():
assert otp_login.status_code == 200 assert otp_login.status_code == 200
disabled = client.post('/api/user/otp', headers=headers, json={ disabled = client.post('/api/user/otp', headers=headers, json={
'action': 'disable', 'code': current_code(secret), 'action': 'disable', 'code': current_code(secret), 'current_password': 'secret123',
}) })
assert disabled.status_code == 200 assert disabled.status_code == 200
assert disabled.json()['enabled'] is False assert disabled.json()['enabled'] is False
def test_otp_recovery_code_requires_password_and_is_single_use():
login = client.post('/api/auth/login', json={'email': 'alice@example.com', 'password': 'secret123'}).json()
headers = {'Authorization': f"Bearer {login['access_token']}"}
setup = client.post('/api/user/otp/setup', headers=headers)
secret = setup.json()['secret']
recovery_code = setup.json()['recovery_codes'][0]
assert client.post('/api/user/otp', headers=headers, json={
'action': 'enable', 'code': current_code(secret),
}).status_code == 200
rejected = client.post('/api/user/otp/recover', headers=headers, json={
'current_password': 'wrong-password', 'recovery_code': recovery_code,
})
assert rejected.status_code == 400
recovered = client.post('/api/user/otp/recover', headers=headers, json={
'current_password': 'secret123', 'recovery_code': recovery_code,
})
assert recovered.status_code == 200
reused = client.post('/api/user/otp/recover', headers=headers, json={
'current_password': 'secret123', 'recovery_code': recovery_code,
})
assert reused.status_code == 400
def test_verified_alternative_can_become_primary(): def test_verified_alternative_can_become_primary():
login = client.post('/api/auth/login', json={'email': 'alice@example.com', 'password': 'secret123'}).json() login = client.post('/api/auth/login', json={'email': 'alice@example.com', 'password': 'secret123'}).json()
headers = {'Authorization': f"Bearer {login['access_token']}"} headers = {'Authorization': f"Bearer {login['access_token']}"}
+3 -4
View File
@@ -2,10 +2,8 @@
services: services:
app: app:
image: git.kolkman.org/olaf/link-log:development # or :latest or a version-tag image: git.kolkman.org/olaf/link-log:${LINKLOG_VERSION:-latest} # or :development or a :version-tag
container_name: ${APP_CONTAINER_NAME:-linklog-app} container_name: ${APP_CONTAINER_NAME:-linklog-app}
ports:
- "${APP_PORT:-8000}:8000"
volumes: volumes:
- ./linklog_data:/app/backend/data - ./linklog_data:/app/backend/data
environment: environment:
@@ -13,7 +11,8 @@ services:
LINKLOG_APP_NAME: ${LINKLOG_APP_NAME:-LinkLog} LINKLOG_APP_NAME: ${LINKLOG_APP_NAME:-LinkLog}
LINKLOG_DATABASE_PATH: ${LINKLOG_DATABASE_PATH:-/app/backend/data/linklog.db} LINKLOG_DATABASE_PATH: ${LINKLOG_DATABASE_PATH:-/app/backend/data/linklog.db}
LINKLOG_SECRET_KEY: ${LINKLOG_SECRET_KEY:?Set LINKLOG_SECRET_KEY in .env} LINKLOG_SECRET_KEY: ${LINKLOG_SECRET_KEY:?Set LINKLOG_SECRET_KEY in .env}
LINKLOG_TOKEN_EXPIRY_DAYS: ${LINKLOG_TOKEN_EXPIRY_DAYS:-30} LINKLOG_TOKEN_EXPIRY_MINUTES: ${LINKLOG_TOKEN_EXPIRY_MINUTES:-15}
LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS: ${LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS:-30}
LINKLOG_PUBLIC_URL: ${LINKLOG_PUBLIC_URL:-linklog.example.com} LINKLOG_PUBLIC_URL: ${LINKLOG_PUBLIC_URL:-linklog.example.com}
LINKLOG_SMTP_HOST: ${LINKLOG_SMTP_HOST:-smtp.example.com} LINKLOG_SMTP_HOST: ${LINKLOG_SMTP_HOST:-smtp.example.com}
LINKLOG_SMTP_PORT: ${LINKLOG_SMTP_PORT:-587} LINKLOG_SMTP_PORT: ${LINKLOG_SMTP_PORT:-587}
+30
View File
@@ -0,0 +1,30 @@
# Local development only. The production compose file intentionally does not publish port 8000.
services:
app:
build:
context: .
dockerfile: Dockerfile
container_name: ${APP_CONTAINER_NAME:-linklog-app-local}
ports:
- "${APP_PORT:-8000}:8000"
volumes:
- ./linklog_data:/app/backend/data
environment:
APP_ENV: ${APP_ENV:-development}
LINKLOG_APP_NAME: ${LINKLOG_APP_NAME:-LinkLog}
LINKLOG_DATABASE_PATH: ${LINKLOG_DATABASE_PATH:-/app/backend/data/linklog.db}
LINKLOG_SECRET_KEY: ${LINKLOG_SECRET_KEY:?Set LINKLOG_SECRET_KEY in .env}
LINKLOG_DATA_ENCRYPTION_KEY: ${LINKLOG_DATA_ENCRYPTION_KEY:?Set LINKLOG_DATA_ENCRYPTION_KEY in .env}
LINKLOG_PUBLIC_URL: ${LINKLOG_PUBLIC_URL:-http://localhost:8000}
LINKLOG_TOKEN_EXPIRY_MINUTES: ${LINKLOG_TOKEN_EXPIRY_MINUTES:-15}
LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS: ${LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS:-30}
LINKLOG_LOG_LEVEL: ${LINKLOG_LOG_LEVEL:-DEBUG}
LINKLOG_TRACKING_PARAMS: ${LINKLOG_TRACKING_PARAMS:-}
restart: ${APP_RESTART_POLICY:-unless-stopped}
healthcheck:
test: ["CMD", "python", "-c", "from urllib.request import urlopen; urlopen('http://127.0.0.1:8000/health', timeout=3)"]
interval: ${APP_HEALTHCHECK_INTERVAL:-30s}
timeout: ${APP_HEALTHCHECK_TIMEOUT:-5s}
start_period: ${APP_HEALTHCHECK_START_PERIOD:-10s}
retries: ${APP_HEALTHCHECK_RETRIES:-3}
+13 -14
View File
@@ -7,8 +7,6 @@ services:
context: . context: .
dockerfile: Dockerfile dockerfile: Dockerfile
container_name: ${APP_CONTAINER_NAME:-linklog-app} container_name: ${APP_CONTAINER_NAME:-linklog-app}
ports:
- "${APP_PORT:-8000}:8000"
volumes: volumes:
- ./linklog_data:/app/backend/data - ./linklog_data:/app/backend/data
environment: environment:
@@ -17,9 +15,10 @@ services:
LINKLOG_DATABASE_PATH: ${LINKLOG_DATABASE_PATH:-/app/backend/data/linklog.db} LINKLOG_DATABASE_PATH: ${LINKLOG_DATABASE_PATH:-/app/backend/data/linklog.db}
LINKLOG_SECRET_KEY: ${LINKLOG_SECRET_KEY:?Set LINKLOG_SECRET_KEY in .env} LINKLOG_SECRET_KEY: ${LINKLOG_SECRET_KEY:?Set LINKLOG_SECRET_KEY in .env}
LINKLOG_DATA_ENCRYPTION_KEY: ${LINKLOG_DATA_ENCRYPTION_KEY:?Set LINKLOG_DATA_ENCRYPTION_KEY in .env} LINKLOG_DATA_ENCRYPTION_KEY: ${LINKLOG_DATA_ENCRYPTION_KEY:?Set LINKLOG_DATA_ENCRYPTION_KEY in .env}
LINKLOG_PUBLIC_URL: ${LINKLOG_PUBLIC_URL:-localhost} LINKLOG_PUBLIC_URL: ${LINKLOG_PUBLIC_URL:-linklog.example.com}
LINKLOG_LOG_LEVEL: ${LINKLOG_LOG_LEVEL:-INFO} LINKLOG_LOG_LEVEL: ${LINKLOG_LOG_LEVEL:-INFO}
LINKLOG_TOKEN_EXPIRY_DAYS: ${LINKLOG_TOKEN_EXPIRY_DAYS:-30} LINKLOG_TOKEN_EXPIRY_MINUTES: ${LINKLOG_TOKEN_EXPIRY_MINUTES:-15}
LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS: ${LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS:-30}
LINKLOG_TRACKING_PARAMS: ${LINKLOG_TRACKING_PARAMS:-} LINKLOG_TRACKING_PARAMS: ${LINKLOG_TRACKING_PARAMS:-}
restart: ${APP_RESTART_POLICY:-unless-stopped} restart: ${APP_RESTART_POLICY:-unless-stopped}
healthcheck: healthcheck:
@@ -31,21 +30,21 @@ services:
labels: labels:
traefik.enable: true traefik.enable: true
traefik.http.middlewares.web-https-redirect.redirectscheme.scheme: https traefik.http.middlewares.web-https-redirect.redirectscheme.scheme: https
traefik.http.services.linklog.loadbalancer.server.port: 8000 traefik.http.services.testlog.loadbalancer.server.port: 8000
traefik.docker.network: git_traefik traefik.docker.network: git_traefik
traefik.http.routers.linklog.entrypoints: web traefik.http.routers.testlog.entrypoints: web
traefik.http.routers.linklog.rule: Host(`${LINKLOG_PUBLIC_URL:-localhost}`) traefik.http.routers.testlog.rule: Host(`${LINKLOG_PUBLIC_URL:-linklog.example.com}`)
traefik.http.routers.linklog.middlewares: web-https-redirect,servicests traefik.http.routers.testlog.middlewares: web-https-redirect,servicests
traefik.http.routers.linklog-secure.entrypoints: websecure traefik.http.routers.testlog-secure.entrypoints: websecure
traefik.http.routers.linklog-secure.rule: Host(`${LINKLOG_PUBLIC_URL:-localhost}`) traefik.http.routers.testlog-secure.rule: Host(`${LINKLOG_PUBLIC_URL:-linklog.example.com}`)
traefik.http.routers.linklog-secure.tls: true traefik.http.routers.testlog-secure.tls: true
traefik.http.routers.linklog-secure.middlewares: servicests traefik.http.routers.testlog-secure.middlewares: servicests
traefik.http.routers.linklog-secure.tls.certresolver: myresolver traefik.http.routers.testlog-secure.tls.certresolver: myresolver
traefik.http.routers.linklog-secure.service: linklog traefik.http.routers.testlog-secure.service: testlog
+142 -7
View File
@@ -12,7 +12,7 @@ const smtpForm = document.querySelector('#smtp-form');
const smtpTestButton = document.querySelector('#smtp-test-button'); const smtpTestButton = document.querySelector('#smtp-test-button');
const smtpStatus = document.querySelector('#smtp-status'); const smtpStatus = document.querySelector('#smtp-status');
const themesForm = document.querySelector('#themes-form'); const themesForm = document.querySelector('#themes-form');
const themeOptions = document.querySelector('#theme-options'); const themeOptions = document.querySelector('#admin-theme-options');
const themeStatus = document.querySelector('#theme-status'); const themeStatus = document.querySelector('#theme-status');
let smtpNextAllowedAt = null; let smtpNextAllowedAt = null;
let smtpTimerHandle = null; let smtpTimerHandle = null;
@@ -57,21 +57,85 @@ function renderLabels(labels) {
adminLabelList.replaceChildren(...labels.map((label) => { adminLabelList.replaceChildren(...labels.map((label) => {
const row = document.createElement('div'); const row = document.createElement('div');
row.className = 'plugin-row'; row.className = 'plugin-row';
const text = document.createElement('span'); const text = document.createElement('span');
text.textContent = `${label.name}${label.creator ? ` (${label.creator})` : ' (default)'}`; text.textContent = `${label.name}${label.creator ? ` (${label.creator})` : ' (default)'}`;
const button = document.createElement('button');
button.type = 'button'; const actions = document.createElement('div');
button.className = 'danger-button'; actions.style.display = 'flex';
button.textContent = 'Delete'; actions.style.gap = '8px';
button.addEventListener('click', async () => {
const editButton = document.createElement('button');
editButton.type = 'button';
editButton.textContent = 'Edit';
editButton.addEventListener('click', () => {
showAdminInlineLabelEdit(row, label);
});
const deleteButton = document.createElement('button');
deleteButton.type = 'button';
deleteButton.className = 'danger-button';
deleteButton.textContent = 'Delete';
deleteButton.addEventListener('click', async () => {
if (!confirm(`Are you sure you want to delete "${label.name}"?`)) return;
const response = await fetch(`/api/admin/labels/${label.id}`, {method: 'DELETE', headers: authHeaders()}); const response = await fetch(`/api/admin/labels/${label.id}`, {method: 'DELETE', headers: authHeaders()});
if (response.ok) loadLabels(); if (response.ok) loadLabels();
}); });
row.append(text, button);
actions.append(editButton, deleteButton);
row.append(text, actions);
return row; return row;
})); }));
} }
function showAdminInlineLabelEdit(rowContainer, label) {
rowContainer.replaceChildren();
const editForm = document.createElement('form');
editForm.style.display = 'flex';
editForm.style.gap = '8px';
editForm.style.width = '100%';
editForm.style.alignItems = 'center';
const input = document.createElement('input');
input.type = 'text';
input.value = label.name;
input.required = true;
input.style.flex = '1';
const saveButton = document.createElement('button');
saveButton.type = 'submit';
saveButton.textContent = 'Save';
const cancelButton = document.createElement('button');
cancelButton.type = 'button';
cancelButton.textContent = 'Cancel';
cancelButton.addEventListener('click', () => {
loadLabels();
});
editForm.append(input, saveButton, cancelButton);
editForm.addEventListener('submit', async (e) => {
e.preventDefault();
const newName = input.value.trim();
if (!newName) return;
const response = await fetch(`/api/admin/labels/${label.id}`, {
method: 'PUT',
headers: authHeaders(true),
body: JSON.stringify({ name: newName }),
});
if (response.ok) {
loadLabels();
} else {
alert(await responseError(response, 'Could not update label'));
}
});
rowContainer.appendChild(editForm);
input.focus();
}
async function loadLabels() { async function loadLabels() {
const response = await fetch('/api/admin/labels', {headers: authHeaders()}); const response = await fetch('/api/admin/labels', {headers: authHeaders()});
if (!response.ok) throw new Error('Could not load labels'); if (!response.ok) throw new Error('Could not load labels');
@@ -152,6 +216,11 @@ function renderUsers(users) {
privilegeLabel.append(privilegeCheckbox, document.createTextNode(' Administrator')); privilegeLabel.append(privilegeCheckbox, document.createTextNode(' Administrator'));
row.append(label, privilegeLabel); row.append(label, privilegeLabel);
if (!isCurrentUser) { if (!isCurrentUser) {
const otpButton = document.createElement('button');
otpButton.type = 'button';
otpButton.textContent = 'Reset OTP';
otpButton.addEventListener('click', () => resetUserOtp(user, otpButton));
row.append(otpButton);
const button = document.createElement('button'); const button = document.createElement('button');
button.type = 'button'; button.type = 'button';
button.className = 'danger-button'; button.className = 'danger-button';
@@ -163,15 +232,78 @@ function renderUsers(users) {
})); }));
} }
async function resetUserOtp(user, button) {
if (!window.confirm(`Disable OTP for ${user.username}?`)) return;
button.disabled = true;
const status = document.querySelector('#user-status');
try {
const response = await fetch(`/api/admin/users/${encodeURIComponent(user.id)}/otp/reset`, {
method: 'POST',
headers: authHeaders(),
});
if (!response.ok) {
throw new Error(await responseError(response, `Request failed (${response.status})`));
}
status.textContent = `OTP disabled for ${user.username}.`;
status.style.color = '#94e2d5';
} catch (error) {
status.textContent = `Could not reset OTP for ${user.username}: ${error.message}`;
status.style.color = '#f38ba8';
button.disabled = false;
}
}
async function loadUsers() { async function loadUsers() {
const response = await fetch('/api/admin/users', {headers: authHeaders()}); const response = await fetch('/api/admin/users', {headers: authHeaders()});
if (!response.ok) throw new Error('Could not load users'); if (!response.ok) throw new Error('Could not load users');
renderUsers(await response.json()); renderUsers(await response.json());
} }
function initPanelToggles() {
const panels = document.querySelectorAll('#admin-controls .settings-panel');
panels.forEach((panel) => {
panel.classList.add('minimized');
const h2 = panel.querySelector('h2');
if (!h2) return;
let btn = h2.querySelector('.panel-toggle-btn');
if (!btn) {
const titleText = h2.textContent.trim();
h2.replaceChildren();
btn = document.createElement('button');
btn.type = 'button';
btn.className = 'panel-toggle-btn';
btn.setAttribute('aria-expanded', 'false');
const textSpan = document.createElement('span');
textSpan.textContent = titleText;
const iconSpan = document.createElement('span');
iconSpan.className = 'panel-toggle-icon';
iconSpan.setAttribute('aria-hidden', 'true');
iconSpan.textContent = '▼';
btn.append(textSpan, iconSpan);
h2.appendChild(btn);
} else {
btn.setAttribute('aria-expanded', 'false');
}
if (h2.dataset.initialized) return;
h2.dataset.initialized = 'true';
h2.addEventListener('click', (e) => {
e.preventDefault();
const isMinimized = panel.classList.toggle('minimized');
if (btn) {
btn.setAttribute('aria-expanded', String(!isMinimized));
}
});
});
}
function showAdminState(isAdmin) { function showAdminState(isAdmin) {
adminControls.classList.toggle('hidden', !isAdmin); adminControls.classList.toggle('hidden', !isAdmin);
adminAuthNotice.classList.toggle('hidden', isAdmin); adminAuthNotice.classList.toggle('hidden', isAdmin);
if (isAdmin) {
initPanelToggles();
}
} }
function showSignedOutState() { function showSignedOutState() {
@@ -356,4 +488,7 @@ loadAdminState().catch((error) => {
smtpForm.reset(); smtpForm.reset();
themesForm.reset(); themesForm.reset();
}); });
document.addEventListener('DOMContentLoaded', initPanelToggles);
initPanelToggles();
})(); })();
+17
View File
@@ -3,6 +3,7 @@
(() => { (() => {
const loginButton = document.querySelector('#auth-login-button'); const loginButton = document.querySelector('#auth-login-button');
const newEntryButton = document.querySelector('#new-entry-button');
const profileLink = document.querySelector('#auth-profile-link'); const profileLink = document.querySelector('#auth-profile-link');
const labelsLink = document.querySelector('#auth-labels-link'); const labelsLink = document.querySelector('#auth-labels-link');
const adminLink = document.querySelector('#auth-admin-link'); const adminLink = document.querySelector('#auth-admin-link');
@@ -14,6 +15,10 @@
const menuToggle = document.querySelector('.menu-toggle'); const menuToggle = document.querySelector('.menu-toggle');
const logoutButton = document.querySelector('#logout-button'); const logoutButton = document.querySelector('#logout-button');
const themeSubmenuContainer = document.querySelector('#theme-submenu-container');
const themeSubmenuTitle = document.querySelector('.submenu-title');
const themeOptions = document.querySelector('#theme-options');
if (!loginButton || !profileLink || !labelsLink || !adminLink || !session || !username || !menu || !menuToggle || !logoutButton) return; if (!loginButton || !profileLink || !labelsLink || !adminLink || !session || !username || !menu || !menuToggle || !logoutButton) return;
menuToggle.addEventListener('click', () => { menuToggle.addEventListener('click', () => {
@@ -22,8 +27,19 @@
menuToggle.setAttribute('aria-expanded', String(!isOpen)); menuToggle.setAttribute('aria-expanded', String(!isOpen));
}); });
// Handle theme submenu toggle
if (themeSubmenuTitle && themeOptions) {
themeSubmenuTitle.addEventListener('click', (e) => {
e.preventDefault();
const isOpen = !themeOptions.classList.contains('hidden');
themeOptions.classList.toggle('hidden', isOpen);
themeSubmenuTitle.setAttribute('aria-expanded', String(!isOpen));
});
}
function showSignedOut() { function showSignedOut() {
loginButton.classList.remove('hidden'); loginButton.classList.remove('hidden');
if (newEntryButton) newEntryButton.classList.add('hidden');
profileLink.classList.add('hidden'); profileLink.classList.add('hidden');
labelsLink.classList.add('hidden'); labelsLink.classList.add('hidden');
adminLink.classList.add('hidden'); adminLink.classList.add('hidden');
@@ -33,6 +49,7 @@
function showSignedIn(user) { function showSignedIn(user) {
loginButton.classList.add('hidden'); loginButton.classList.add('hidden');
if (newEntryButton) newEntryButton.classList.remove('hidden');
profileLink.classList.remove('hidden'); profileLink.classList.remove('hidden');
labelsLink.classList.remove('hidden'); labelsLink.classList.remove('hidden');
adminLink.classList.toggle('hidden', !user.is_admin); adminLink.classList.toggle('hidden', !user.is_admin);
+9 -6
View File
@@ -73,7 +73,9 @@ async function loadUsers() {
} }
async function loadTags() { async function loadTags() {
const response = await fetch('/api/tags'); const response = await fetch('/api/tags', {
headers: accessToken ? {Authorization: `Bearer ${accessToken}`} : {},
});
if (!response.ok) throw new Error('Could not load tags'); if (!response.ok) throw new Error('Could not load tags');
const tags = await response.json(); const tags = await response.json();
availableTags = tags; availableTags = tags;
@@ -254,7 +256,7 @@ function showEditForm(article, item) {
article.appendChild(form); article.appendChild(form);
} }
async function loadFeed() { async function loadFeed(selectedTag = null) {
const routeUser = document.body.dataset.userFilter; const routeUser = document.body.dataset.userFilter;
const endpoint = routeUser const endpoint = routeUser
? `/api/public/feed/${encodeURIComponent(routeUser)}` ? `/api/public/feed/${encodeURIComponent(routeUser)}`
@@ -266,13 +268,14 @@ async function loadFeed() {
let items = data || []; let items = data || [];
const pref = readPreferences(); const pref = readPreferences();
const activeTag = selectedTag ?? pref.tag;
if (pref.user && !routeUser) { if (pref.user && !routeUser) {
items = items.filter((item) => (item.user?.username || '').toLowerCase() === pref.user.toLowerCase()); items = items.filter((item) => (item.user?.username || '').toLowerCase() === pref.user.toLowerCase());
} }
if (pref.tag) { if (activeTag) {
items = items.filter((item) => item.tags?.some((tag) => tag.toLowerCase() === pref.tag.toLowerCase())); items = items.filter((item) => item.tags?.some((tag) => tag.toLowerCase() === activeTag.toLowerCase()));
} }
if (pref.sort === 'oldest') { if (pref.sort === 'oldest') {
@@ -304,9 +307,9 @@ function syncPreferences() {
tagFilter.addEventListener('change', (event) => { tagFilter.addEventListener('change', (event) => {
const next = { ...readPreferences(), tag: event.target.value }; const next = { ...readPreferences(), tag: event.target.value };
writePreferences(next); writePreferences(next);
loadFeed(); loadFeed(event.target.value);
}); });
} }
syncPreferences(); syncPreferences();
Promise.all([loadUsers(), loadTags()]).then(loadFeed).catch(() => loadFeed()); Promise.all([loadUsers(), loadTags()]).then(() => loadFeed()).catch(() => loadFeed());
+209
View File
@@ -0,0 +1,209 @@
// Copyright © 2026 Olaf Kolkman
// SPDX-License-Identifier: GPL-3.0-or-later
(() => {
const labelAuthNotice = document.querySelector('#label-auth-notice');
const labelControls = document.querySelector('#label-controls');
const labelForm = document.querySelector('#label-form');
const labelNameInput = document.querySelector('#label-name');
const labelStatus = document.querySelector('#label-status');
const labelList = document.querySelector('#label-list');
const accessToken = localStorage.getItem('linklogAccessToken');
let currentUserId = null;
function authHeaders(includeJson = false) {
return {
...(includeJson ? {'Content-Type': 'application/json'} : {}),
...(accessToken ? {Authorization: `Bearer ${accessToken}`} : {}),
};
}
function setStatus(message, isError = false) {
if (!labelStatus) return;
labelStatus.textContent = message;
labelStatus.style.color = isError ? '#b91c1c' : '#166534';
}
async function responseError(response, fallback) {
try {
const result = await response.json();
return result.detail || result.message || fallback;
} catch {
return fallback;
}
}
function renderLabels(labels) {
if (!labelList) return;
if (!labels || labels.length === 0) {
labelList.innerHTML = '<p>No labels found.</p>';
return;
}
labelList.replaceChildren(...labels.map((label) => {
const row = document.createElement('div');
row.className = 'plugin-row';
const isOwned = label.created_by === currentUserId;
const contentContainer = document.createElement('div');
contentContainer.style.display = 'flex';
contentContainer.style.alignItems = 'center';
contentContainer.style.justifySpaceBetween = 'space-between';
contentContainer.style.width = '100%';
const text = document.createElement('span');
text.textContent = `${label.name}${isOwned ? '' : (label.creator ? ` (${label.creator})` : ' (default)')}`;
contentContainer.appendChild(text);
if (isOwned) {
const actions = document.createElement('div');
actions.style.display = 'flex';
actions.style.gap = '8px';
const editButton = document.createElement('button');
editButton.type = 'button';
editButton.textContent = 'Edit';
editButton.addEventListener('click', () => {
showInlineEdit(row, label);
});
const deleteButton = document.createElement('button');
deleteButton.type = 'button';
deleteButton.className = 'danger-button';
deleteButton.textContent = 'Delete';
deleteButton.addEventListener('click', async () => {
if (!confirm(`Are you sure you want to delete "${label.name}"?`)) return;
setStatus('');
const response = await fetch(`/api/user/labels/${label.id}`, {
method: 'DELETE',
headers: authHeaders(),
});
if (response.ok) {
setStatus(`Deleted label ${label.name}`);
loadLabels();
} else {
setStatus(await responseError(response, 'Could not delete label'), true);
}
});
actions.append(editButton, deleteButton);
contentContainer.appendChild(actions);
}
row.appendChild(contentContainer);
return row;
}));
}
function showInlineEdit(rowContainer, label) {
rowContainer.replaceChildren();
const editForm = document.createElement('form');
editForm.style.display = 'flex';
editForm.style.gap = '8px';
editForm.style.width = '100%';
editForm.style.alignItems = 'center';
const input = document.createElement('input');
input.type = 'text';
input.value = label.name;
input.required = true;
input.style.flex = '1';
const saveButton = document.createElement('button');
saveButton.type = 'submit';
saveButton.textContent = 'Save';
const cancelButton = document.createElement('button');
cancelButton.type = 'button';
cancelButton.textContent = 'Cancel';
cancelButton.addEventListener('click', () => {
loadLabels();
});
editForm.append(input, saveButton, cancelButton);
editForm.addEventListener('submit', async (e) => {
e.preventDefault();
const newName = input.value.trim();
if (!newName) return;
setStatus('');
const response = await fetch(`/api/user/labels/${label.id}`, {
method: 'PUT',
headers: authHeaders(true),
body: JSON.stringify({ name: newName }),
});
if (response.ok) {
setStatus(`Updated label to ${newName}`);
loadLabels();
} else {
setStatus(await responseError(response, 'Could not update label'), true);
}
});
rowContainer.appendChild(editForm);
input.focus();
}
async function loadLabels() {
try {
const response = await fetch('/api/user/labels', { headers: authHeaders() });
if (!response.ok) throw new Error('Could not load labels');
const labels = await response.json();
renderLabels(labels);
} catch (error) {
setStatus('Error loading labels', true);
}
}
async function init() {
if (!accessToken) {
if (labelAuthNotice) labelAuthNotice.classList.remove('hidden');
if (labelControls) labelControls.classList.add('hidden');
return;
}
if (labelAuthNotice) labelAuthNotice.classList.add('hidden');
if (labelControls) labelControls.classList.remove('hidden');
try {
const meResponse = await fetch('/api/auth/me', { headers: authHeaders() });
if (meResponse.ok) {
const me = await meResponse.json();
currentUserId = me.id;
}
} catch {
// Proceed if me fails
}
await loadLabels();
if (labelForm) {
labelForm.addEventListener('submit', async (e) => {
e.preventDefault();
const name = labelNameInput.value.trim();
if (!name) return;
setStatus('');
const response = await fetch('/api/user/labels', {
method: 'POST',
headers: authHeaders(true),
body: JSON.stringify({ name }),
});
if (response.ok) {
labelNameInput.value = '';
setStatus(`Added label ${name}`);
loadLabels();
} else {
setStatus(await responseError(response, 'Could not add label'), true);
}
});
}
}
document.addEventListener('DOMContentLoaded', init);
if (document.readyState !== 'loading') {
init();
}
})();
+1 -2
View File
@@ -12,8 +12,7 @@ logoutButton.addEventListener('click', async () => {
if (token) { if (token) {
await fetch('/api/auth/logout', { await fetch('/api/auth/logout', {
method: 'POST', method: 'POST',
headers: {'Content-Type': 'application/json'}, headers: {Authorization: `Bearer ${token}`},
body: JSON.stringify({token}),
}).catch(() => undefined); }).catch(() => undefined);
} }
+289
View File
@@ -0,0 +1,289 @@
// Copyright © 2026 Olaf Kolkman
// SPDX-License-Identifier: GPL-3.0-or-later
(() => {
const entryForm = document.getElementById('entry-form');
const authRequired = document.getElementById('auth-required');
const urlInput = document.getElementById('url-input');
const titleInput = document.getElementById('title-input');
const commentInput = document.getElementById('comment-input');
const newTagsInput = document.getElementById('new-tags-input');
const existingTagsEl = document.getElementById('existing-tags');
const mastodonPublishing = document.getElementById('mastodon-publishing');
const mastodonEnabledCheckbox = document.getElementById('mastodon-enabled');
const scrapeStatus = document.getElementById('scrape-status');
const duplicateStatus = document.getElementById('duplicate-status');
const refetchTitleButton = document.getElementById('refetch-title-button');
const submitButton = document.getElementById('submit-button');
const submitStatus = document.getElementById('submit-status');
const token = localStorage.getItem('linklogAccessToken');
let availableTags = [];
let selectedTags = new Set();
let currentUser = null;
// Utility function to add status messages; splits on \n into real <br> line breaks without using innerHTML.
function setStatus(statusEl, message, isError = false) {
const lines = message.split('\n');
statusEl.replaceChildren(
...lines.flatMap((line, index) => (
index === 0 ? [document.createTextNode(line)] : [document.createElement('br'), document.createTextNode(line)]
)),
);
statusEl.className = `status ${isError ? 'error' : 'success'}`;
statusEl.classList.remove('hidden');
if (!isError) {
setTimeout(() => statusEl.classList.add('hidden'), 4000);
}
}
// Check authentication
if (!token) {
authRequired.classList.remove('hidden');
entryForm.classList.add('hidden');
return;
}
// Verify token is still valid
fetch('/api/auth/me', { headers: { Authorization: `Bearer ${token}` } })
.then((response) => {
if (!response.ok) throw new Error('Not authenticated');
return response.json();
})
.then((user) => {
currentUser = user;
entryForm.classList.remove('hidden');
Promise.all([loadTags(), loadMastodonPublishing()]);
})
.catch(() => {
localStorage.removeItem('linklogAccessToken');
authRequired.classList.remove('hidden');
entryForm.classList.add('hidden');
});
// Load available tags
async function loadTags() {
try {
const response = await fetch('/api/tags');
if (!response.ok) throw new Error('Could not load tags');
availableTags = await response.json();
renderTags();
} catch (error) {
console.error('Error loading tags:', error);
}
}
async function loadMastodonPublishing() {
try {
const response = await fetch('/api/user/plugins/mastodon', {
headers: { Authorization: `Bearer ${token}` },
});
if (!response.ok) return;
const config = await response.json();
mastodonEnabledCheckbox.checked = Boolean(config.configured);
mastodonPublishing.classList.toggle('hidden', !config.configured);
} catch (error) {
console.error('Could not load Mastodon configuration:', error);
}
}
// Render tag checkboxes
function renderTags() {
existingTagsEl.innerHTML = '';
availableTags.forEach((tag) => {
const label = document.createElement('label');
label.className = 'tag-checkbox';
const checkbox = document.createElement('input');
checkbox.type = 'checkbox';
checkbox.value = tag;
checkbox.checked = selectedTags.has(tag);
checkbox.addEventListener('change', () => {
if (checkbox.checked) {
selectedTags.add(tag);
} else {
selectedTags.delete(tag);
}
});
label.appendChild(checkbox);
label.append(` ${tag}`);
existingTagsEl.appendChild(label);
});
}
// Strip known tracking parameters so duplicate detection and scraping ignore them, mirroring the browser extension.
function removeKnownTrackingParams(urlString) {
try {
const url = new URL(urlString);
const known = new Set([
'utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',
'utm_id', 'utm_name', 'gclid', 'fbclid', 'dclid', 'msclkid',
]);
for (const key of known) {
url.searchParams.delete(key);
}
return url.toString();
} catch (error) {
return urlString;
}
}
// Fetch the page title for the given URL and fill it in, unless the user already typed one.
let lastScrapedUrl = null;
async function fetchTitle(url, { force = false } = {}) {
if (!url || (!force && (titleInput.value.trim() || url === lastScrapedUrl))) return;
setStatus(scrapeStatus, 'Looking up title...', false);
try {
const response = await fetch(`/api/scrape?url=${encodeURIComponent(url)}`, {
headers: { Authorization: `Bearer ${token}` },
});
if (!response.ok) {
if (response.status === 401) {
localStorage.removeItem('linklogAccessToken');
location.reload();
return;
}
throw new Error(`HTTP ${response.status}`);
}
lastScrapedUrl = url;
const data = await response.json();
if (data.title) {
titleInput.value = data.title;
setStatus(scrapeStatus, 'Title loaded!', false);
} else {
setStatus(scrapeStatus, 'No title found', true);
}
} catch (error) {
console.error('Scrape error:', error);
setStatus(scrapeStatus, `Error: ${error.message}`, true);
}
}
urlInput.addEventListener('blur', async () => {
await fetchTitle(removeKnownTrackingParams(urlInput.value.trim()));
checkDuplicate();
});
refetchTitleButton.addEventListener('click', (e) => {
e.preventDefault();
const url = removeKnownTrackingParams(urlInput.value.trim());
if (!url) {
setStatus(scrapeStatus, 'Please enter a URL', true);
return;
}
titleInput.value = '';
fetchTitle(url, { force: true });
});
// Warn when the URL/title combination already exists for this user, mirroring the browser extension.
titleInput.addEventListener('blur', checkDuplicate);
urlInput.addEventListener('input', () => duplicateStatus.classList.add('hidden'));
titleInput.addEventListener('input', () => duplicateStatus.classList.add('hidden'));
async function checkDuplicate() {
const url = removeKnownTrackingParams(urlInput.value.trim());
const title = titleInput.value.trim();
if (!url || !title) return;
try {
const response = await fetch(`/api/links/check?${new URLSearchParams({ title, url })}`, {
headers: { Authorization: `Bearer ${token}` },
});
if (!response.ok) return;
const data = await response.json();
if (data.exists) {
// Re-derive the match locally: browser URL normalization (e.g. trailing slashes) can
// make the server's raw string comparison disagree even when the URLs are equivalent.
const urlMatches = data.url_matches || (data.stored_url && removeKnownTrackingParams(data.stored_url) === url);
let message = 'This link already exists. ';
if (!urlMatches) {
message += 'But, the stored link has a different URL (missing or different parameters).';
message += '\nWhen you save the entry you risk a duplicate entry.';
} else {
message += '\nYou can still save the entry, which will update the existing entry\'s comment and or tags.';
}
setStatus(duplicateStatus, message, true);
} else {
duplicateStatus.classList.add('hidden');
}
} catch (error) {
// Duplicate checking is advisory; submission remains available.
}
}
// Handle form submission
entryForm.addEventListener('submit', async (e) => {
e.preventDefault();
const url = removeKnownTrackingParams(urlInput.value.trim());
const title = titleInput.value.trim();
const comment = commentInput.value.trim();
const newTags = newTagsInput.value.trim();
if (!url || !title) {
setStatus(submitStatus, 'URL and title are required', true);
return;
}
// Combine selected tags and new tags
const tags = Array.from(selectedTags);
if (newTags) {
const newTagsList = newTags
.split(',')
.map((t) => t.trim())
.filter((t) => t);
tags.push(...newTagsList);
}
submitButton.disabled = true;
setStatus(submitStatus, 'Saving...', false);
try {
const response = await fetch('/api/links', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
Authorization: `Bearer ${token}`,
},
body: JSON.stringify({
title,
url,
comment,
tags,
post_to_mastodon: mastodonEnabledCheckbox.checked,
}),
});
if (!response.ok) {
if (response.status === 401) {
localStorage.removeItem('linklogAccessToken');
location.reload();
return;
}
const error = await response.json().catch(() => ({}));
throw new Error(error.detail || `HTTP ${response.status}`);
}
const data = await response.json();
setStatus(submitStatus, `Link saved to LinkLog${data.duplicate ? ' (updated)' : ''}!`, false);
// Redirect to user page after 1 second
if (currentUser) {
setTimeout(() => {
window.location.href = `/${encodeURIComponent(currentUser.username)}/`;
}, 1000);
}
} catch (error) {
console.error('Submit error:', error);
setStatus(submitStatus, `Error: ${error.message}`, true);
} finally {
submitButton.disabled = false;
}
});
})();
+65 -1
View File
@@ -12,11 +12,13 @@ const mastodonConnectButton = document.querySelector('#mastodon-connect');
const otpSetupButton = document.querySelector('#otp-setup'); const otpSetupButton = document.querySelector('#otp-setup');
const otpEnableButton = document.querySelector('#otp-enable'); const otpEnableButton = document.querySelector('#otp-enable');
const otpDisableButton = document.querySelector('#otp-disable'); const otpDisableButton = document.querySelector('#otp-disable');
const otpRecoverButton = document.querySelector('#otp-recover');
const otpProvisioning = document.querySelector('#otp-provisioning'); const otpProvisioning = document.querySelector('#otp-provisioning');
const otpDisabled = document.querySelector('#otp-disabled'); const otpDisabled = document.querySelector('#otp-disabled');
const otpEnabled = document.querySelector('#otp-enabled'); const otpEnabled = document.querySelector('#otp-enabled');
const otpSecret = document.querySelector('#otp-secret'); const otpSecret = document.querySelector('#otp-secret');
const otpUri = document.querySelector('#otp-uri'); const otpUri = document.querySelector('#otp-uri');
const otpRecoveryCodes = document.querySelector('#otp-recovery-codes');
const otpStatus = document.querySelector('#otp-status'); const otpStatus = document.querySelector('#otp-status');
const emailAddressList = document.querySelector('#email-address-list'); const emailAddressList = document.querySelector('#email-address-list');
const additionalEmailForm = document.querySelector('#additional-email-form'); const additionalEmailForm = document.querySelector('#additional-email-form');
@@ -131,6 +133,7 @@ otpSetupButton.addEventListener('click', async () => {
} }
otpSecret.textContent = result.secret; otpSecret.textContent = result.secret;
otpUri.href = result.otpauth_url; otpUri.href = result.otpauth_url;
otpRecoveryCodes.textContent = result.recovery_codes.join('\n');
otpProvisioning.classList.remove('hidden'); otpProvisioning.classList.remove('hidden');
setOtpStatus('Enter a code from your authenticator app to confirm setup.'); setOtpStatus('Enter a code from your authenticator app to confirm setup.');
}); });
@@ -153,8 +156,9 @@ otpEnableButton.addEventListener('click', async () => {
otpDisableButton.addEventListener('click', async () => { otpDisableButton.addEventListener('click', async () => {
const code = document.querySelector('#otp-disable-code').value.trim(); const code = document.querySelector('#otp-disable-code').value.trim();
const currentPassword = document.querySelector('#otp-current-password').value;
const response = await fetch('/api/user/otp', { const response = await fetch('/api/user/otp', {
method: 'POST', headers: authHeaders(true), body: JSON.stringify({action: 'disable', code}), method: 'POST', headers: authHeaders(true), body: JSON.stringify({action: 'disable', code, current_password: currentPassword}),
}); });
const result = await response.json(); const result = await response.json();
if (!response.ok) { if (!response.ok) {
@@ -167,6 +171,24 @@ otpDisableButton.addEventListener('click', async () => {
setOtpStatus('One-time password disabled.'); setOtpStatus('One-time password disabled.');
}); });
otpRecoverButton.addEventListener('click', async () => {
const currentPassword = document.querySelector('#otp-current-password').value;
const recoveryCode = document.querySelector('#otp-recovery-code').value.trim();
const response = await fetch('/api/user/otp/recover', {
method: 'POST', headers: authHeaders(true), body: JSON.stringify({current_password: currentPassword, recovery_code: recoveryCode}),
});
const result = await response.json();
if (!response.ok) {
setOtpStatus(result.detail || 'Could not recover one-time password access.', true);
return;
}
otpDisabled.classList.remove('hidden');
otpEnabled.classList.add('hidden');
document.querySelector('#otp-current-password').value = '';
document.querySelector('#otp-recovery-code').value = '';
setOtpStatus('One-time password access recovered.');
});
async function loadProfile() { async function loadProfile() {
const response = await fetch('/api/user/me', {headers: authHeaders()}); const response = await fetch('/api/user/me', {headers: authHeaders()});
if (!response.ok) throw new Error('Could not load profile'); if (!response.ok) throw new Error('Could not load profile');
@@ -288,6 +310,48 @@ passwordForm.addEventListener('submit', async (event) => {
if (response.ok) passwordForm.reset(); if (response.ok) passwordForm.reset();
}); });
function initPanelToggles() {
const panels = document.querySelectorAll('.settings-panel');
panels.forEach((panel) => {
panel.classList.add('minimized');
const h2 = panel.querySelector('h2');
if (!h2) return;
let btn = h2.querySelector('.panel-toggle-btn');
if (!btn) {
const titleText = h2.textContent.trim();
h2.replaceChildren();
btn = document.createElement('button');
btn.type = 'button';
btn.className = 'panel-toggle-btn';
btn.setAttribute('aria-expanded', 'false');
const textSpan = document.createElement('span');
textSpan.textContent = titleText;
const iconSpan = document.createElement('span');
iconSpan.className = 'panel-toggle-icon';
iconSpan.setAttribute('aria-hidden', 'true');
iconSpan.textContent = '▼';
btn.append(textSpan, iconSpan);
h2.appendChild(btn);
} else {
btn.setAttribute('aria-expanded', 'false');
}
if (h2.dataset.initialized) return;
h2.dataset.initialized = 'true';
h2.addEventListener('click', (e) => {
e.preventDefault();
const isMinimized = panel.classList.toggle('minimized');
if (btn) {
btn.setAttribute('aria-expanded', String(!isMinimized));
}
});
});
}
document.addEventListener('DOMContentLoaded', initPanelToggles);
initPanelToggles();
Promise.all([loadProfile(), loadMastodonConfig(), loadOtp(), loadEmailAddresses()]).catch((error) => { Promise.all([loadProfile(), loadMastodonConfig(), loadOtp(), loadEmailAddresses()]).catch((error) => {
setStatus('#profile-status', accessToken ? error.message : 'Please sign in first.', true); setStatus('#profile-status', accessToken ? error.message : 'Please sign in first.', true);
}); });
+433 -13
View File
@@ -1,7 +1,7 @@
/* Copyright © 2026 Olaf Kolkman */ /* Copyright © 2026 Olaf Kolkman */
/* SPDX-License-Identifier: GPL-3.0-or-later */ /* SPDX-License-Identifier: GPL-3.0-or-later */
@import url('https://fonts.googleapis.com/css2?family=Asset&family=DM+Sans:wght@400;500;600;700&family=Space+Grotesk:wght@500;600;700&display=swap'); @import url('/static/fonts/fonts.css');
:root { :root {
--base: #1e1e2e; --base: #1e1e2e;
@@ -95,6 +95,15 @@
--border: rgba(7, 54, 66, 0.18); --shadow: 0 18px 50px rgba(7, 54, 66, 0.14); --border: rgba(7, 54, 66, 0.18); --shadow: 0 18px 50px rgba(7, 54, 66, 0.14);
} }
:root[data-theme='red'] {
--base: #fffafa; --mantle: #ffedef; --crust: #fbd6da;
--surface-0: #ffffff; --surface-1: #ffe2e6; --surface-2: #f4bbc4;
--text: #350810; --subtext: #5c1724; --muted: #8c4653;
--mauve: #9e1737; --lavender: #86132d; --blue: #216f91;
--teal: #087567; --peach: #b84324; --red: #a70d2d;
--border: rgba(83, 10, 25, 0.2); --shadow: 0 18px 50px rgba(122, 8, 33, 0.2);
}
*, *,
*::before, *::before,
*::after { *::after {
@@ -169,7 +178,7 @@ body::selection {
object-position: left center; object-position: left center;
} }
.site-header .site-logo + h1, .site-header .site-logo-link + h1,
.feed-link { .feed-link {
font-family: 'Asset', 'Space Grotesk', sans-serif; font-family: 'Asset', 'Space Grotesk', sans-serif;
} }
@@ -223,17 +232,6 @@ body::selection {
position: relative; position: relative;
} }
.theme-picker {
width: auto;
min-width: 132px;
padding: 8px 10px;
border: 1px solid var(--surface-2);
border-radius: 7px;
background: var(--surface-0);
color: var(--text);
font: inherit;
}
.menu-toggle { .menu-toggle {
min-width: 0; min-width: 0;
padding: 10px 13px; padding: 10px 13px;
@@ -248,6 +246,31 @@ body::selection {
font-size: 1.1em; font-size: 1.1em;
} }
.new-entry-button {
padding: 10px 13px;
border: 1px solid var(--mauve);
border-radius: 7px;
background: var(--mauve);
color: var(--crust);
font-weight: 600;
cursor: pointer;
transition: all 0.2s ease;
}
.new-entry-button:hover {
background: var(--lavender);
border-color: var(--lavender);
}
.new-entry-button a {
color: inherit;
text-decoration: none;
}
.new-entry-button.hidden {
display: none;
}
.auth-menu { .auth-menu {
position: absolute; position: absolute;
z-index: 30; z-index: 30;
@@ -314,6 +337,86 @@ body::selection {
color: var(--red); color: var(--red);
} }
.theme-submenu-container {
border-top: 1px solid var(--border);
margin-top: 6px;
padding-top: 6px;
}
.theme-submenu-container.hidden {
display: none;
}
.submenu-title {
display: block;
width: 100%;
min-width: 0;
padding: 9px 10px;
border: 0;
border-radius: 6px;
background: transparent;
color: var(--text);
text-align: left;
font-weight: 600;
cursor: pointer;
transition: all 0.2s ease;
}
.submenu-title:hover {
background: var(--surface-1);
color: var(--lavender);
}
.submenu-title::after {
content: ' ▼';
font-size: 0.7em;
opacity: 0.7;
}
.submenu-title[aria-expanded='true']::after {
transform: rotate(-180deg);
display: inline-block;
}
.submenu-options {
display: flex;
flex-direction: column;
gap: 4px;
padding: 4px 8px;
margin-top: 4px;
border-radius: 6px;
background: var(--surface-1);
}
.submenu-options.hidden {
display: none;
}
.theme-option {
padding: 8px 10px;
border: 1px solid var(--border);
border-radius: 5px;
background: transparent;
color: var(--text);
text-align: left;
cursor: pointer;
transition: all 0.2s ease;
font-size: 0.9rem;
}
.theme-option:hover {
background: var(--surface-0);
border-color: var(--lavender);
color: var(--lavender);
}
.theme-option.active {
background: var(--mauve);
border-color: var(--mauve);
color: var(--crust);
font-weight: 600;
}
main.container { main.container {
position: relative; position: relative;
z-index: 1; z-index: 1;
@@ -357,6 +460,108 @@ main.container {
margin-bottom: 0; margin-bottom: 0;
} }
#admin-controls {
display: grid;
gap: 16px;
}
.settings-panel + .settings-panel {
margin-top: 16px;
}
.settings-panel h2 {
margin: 0 0 12px;
padding: 10px 14px;
border-radius: 8px;
cursor: pointer;
transition: background-color 0.2s ease, margin 0.2s ease;
}
.settings-panel h2:hover {
filter: brightness(1.08);
}
.settings-panel:nth-of-type(5n+1) h2 {
color: var(--mauve);
background: var(--surface-1);
background: color-mix(in srgb, var(--mauve) 14%, transparent);
border-left: 4px solid var(--mauve);
}
.settings-panel:nth-of-type(5n+2) h2 {
color: var(--teal);
background: var(--surface-1);
background: color-mix(in srgb, var(--teal) 14%, transparent);
border-left: 4px solid var(--teal);
}
.settings-panel:nth-of-type(5n+3) h2 {
color: var(--peach);
background: var(--surface-1);
background: color-mix(in srgb, var(--peach) 14%, transparent);
border-left: 4px solid var(--peach);
}
.settings-panel:nth-of-type(5n+4) h2 {
color: var(--blue);
background: var(--surface-1);
background: color-mix(in srgb, var(--blue) 14%, transparent);
border-left: 4px solid var(--blue);
}
.settings-panel:nth-of-type(5n+5) h2 {
color: var(--lavender);
background: var(--surface-1);
background: color-mix(in srgb, var(--lavender) 14%, transparent);
border-left: 4px solid var(--lavender);
}
.settings-panel.minimized h2 {
margin: 0;
}
.panel-toggle-btn {
display: flex !important;
align-items: center !important;
justify-content: space-between !important;
width: 100% !important;
min-width: 0 !important;
padding: 0 !important;
border: none !important;
background: transparent !important;
color: inherit !important;
font: inherit !important;
font-size: 1rem !important;
font-weight: inherit !important;
cursor: pointer !important;
text-align: left !important;
box-shadow: none !important;
}
.panel-toggle-btn > * {
pointer-events: none;
}
.panel-toggle-btn:focus-visible {
outline: 2px solid var(--lavender) !important;
outline-offset: 2px !important;
}
.panel-toggle-icon {
font-size: 0.75rem;
transition: transform 0.2s ease;
margin-left: 8px;
color: var(--subtext);
}
.settings-panel.minimized .panel-toggle-icon {
transform: rotate(-90deg);
}
.settings-panel.minimized > *:not(h2) {
display: none !important;
}
.toolbar label, .toolbar label,
.settings-panel label { .settings-panel label {
display: grid; display: grid;
@@ -768,6 +973,216 @@ button:disabled {
margin-top: 14px; margin-top: 14px;
} }
/* Entry form styling */
.entry-form {
max-width: 600px;
margin: 0 auto;
display: grid;
gap: 24px;
}
.entry-form.hidden,
#auth-required.hidden {
display: none;
}
#auth-required {
max-width: 600px;
margin: 40px auto;
padding: 16px;
background: var(--surface-0);
border: 1px solid var(--border);
border-radius: 12px;
border-left: 4px solid var(--red);
}
#auth-required p {
margin: 0;
color: var(--text);
}
#auth-required a {
color: var(--lavender);
text-decoration: underline;
}
#auth-required a:hover {
color: var(--mauve);
}
.form-section {
display: grid;
gap: 8px;
}
.form-section.hidden {
display: none;
}
.form-section label {
display: grid;
gap: 6px;
}
.form-section > legend {
font-weight: 600;
color: var(--text);
font-size: 0.95rem;
margin: 0;
padding: 0;
}
.form-section input[type='url'],
.form-section input[type='text'],
.form-section textarea {
padding: 10px 12px;
background: var(--mantle);
border: 1px solid var(--border);
border-radius: 8px;
color: var(--text);
font-family: inherit;
font-size: 0.95rem;
line-height: 1.4;
}
.form-section textarea {
resize: vertical;
min-height: 100px;
}
.form-section input[type='url']:focus,
.form-section input[type='text']:focus,
.form-section textarea:focus {
outline: none;
border-color: var(--lavender);
box-shadow: 0 0 0 3px rgba(180, 190, 254, 0.1);
}
.tag-options {
display: flex;
flex-wrap: wrap;
gap: 8px 10px;
padding: 12px;
background: var(--mantle);
border: 1px solid var(--border);
border-radius: 8px;
}
.tag-checkbox {
display: flex;
align-items: center;
gap: 6px;
color: var(--subtext);
font-size: 0.9rem;
cursor: pointer;
user-select: none;
}
.form-section label.tag-checkbox {
display: inline-flex;
}
.tag-checkbox input {
width: auto;
min-width: 0;
flex: 0 0 auto;
margin: 0;
cursor: pointer;
}
.form-section fieldset {
border: 1px solid var(--border);
border-radius: 8px;
padding: 12px;
margin: 0;
}
.form-section fieldset legend {
margin: 0;
padding: 0 6px;
}
.form-section fieldset label {
gap: 6px;
}
.form-section fieldset input[type='text'] {
width: 100%;
}
.form-section fieldset input[type='checkbox'] {
width: auto;
margin-right: 6px;
cursor: pointer;
}
.form-actions {
display: grid;
grid-template-columns: 1fr auto;
gap: 12px;
}
.form-actions button,
.form-actions a {
padding: 10px 16px;
border-radius: 8px;
font-weight: 600;
text-align: center;
text-decoration: none;
cursor: pointer;
transition: all 0.2s ease;
}
.form-actions button[type='submit'] {
background: var(--mauve);
border: 1px solid var(--mauve);
color: var(--crust);
}
.form-actions button[type='submit']:hover:not(:disabled) {
background: var(--lavender);
border-color: var(--lavender);
}
.form-actions button[type='submit']:disabled {
opacity: 0.6;
cursor: not-allowed;
}
.form-actions a {
background: var(--surface-1);
border: 1px solid var(--border);
color: var(--text);
}
.form-actions a:hover {
background: var(--surface-2);
border-color: var(--text);
}
.status {
padding: 12px;
border-radius: 8px;
font-size: 0.9rem;
line-height: 1.4;
}
.status.success {
background: rgba(131, 165, 152, 0.2);
border: 1px solid var(--teal);
color: var(--teal);
}
.status.error {
background: rgba(243, 139, 168, 0.2);
border: 1px solid var(--red);
color: var(--red);
}
.status.hidden {
display: none;
}
@media (max-width: 600px) { @media (max-width: 600px) {
.container { .container {
padding: 0 14px; padding: 0 14px;
@@ -815,6 +1230,11 @@ button:disabled {
font-size: 0.9rem; font-size: 0.9rem;
} }
.new-entry-button {
padding: 8px 11px;
font-size: 0.9rem;
}
.logout-button { .logout-button {
font-size: 0.9rem; font-size: 0.9rem;
} }
+32 -11
View File
@@ -11,18 +11,39 @@ async function loadAvailableThemes() {
? localStorage.getItem(themePreference) ? localStorage.getItem(themePreference)
: themes[0]?.id; : themes[0]?.id;
if (selected) document.documentElement.dataset.theme = selected; if (selected) document.documentElement.dataset.theme = selected;
const headerActions = document.querySelector('.header-actions');
if (!headerActions || !themes.length) return; const submenuContainer = document.querySelector('#theme-submenu-container');
const picker = document.createElement('select'); const themeOptions = document.querySelector('#theme-options');
picker.className = 'theme-picker'; const submenuTitle = document.querySelector('.submenu-title');
picker.setAttribute('aria-label', 'Theme');
picker.replaceChildren(...themes.map((theme) => new Option(theme.label, theme.id))); if (!submenuContainer || !themeOptions || !themes.length) return;
picker.value = selected || themes[0].id;
picker.addEventListener('change', () => { // Show the submenu container
localStorage.setItem(themePreference, picker.value); submenuContainer.classList.remove('hidden');
document.documentElement.dataset.theme = picker.value;
// Create theme buttons
const buttons = themes.map((theme) => {
const button = document.createElement('button');
button.type = 'button';
button.className = 'theme-option';
button.dataset.themeId = theme.id;
button.textContent = theme.label;
if (theme.id === selected) {
button.classList.add('active');
}
button.addEventListener('click', () => {
localStorage.setItem(themePreference, theme.id);
document.documentElement.dataset.theme = theme.id;
// Update active state
document.querySelectorAll('.theme-option').forEach((btn) => {
btn.classList.remove('active');
});
button.classList.add('active');
});
return button;
}); });
headerActions.prepend(picker);
themeOptions.replaceChildren(...buttons);
} }
loadAvailableThemes(); loadAvailableThemes();
+13 -2
View File
@@ -13,11 +13,12 @@
<div class="container"> <div class="container">
<div class="header-row"> <div class="header-row">
<div> <div>
<img class="site-logo" src="/static/logo.svg" alt="LinkLog" /> <a class="site-logo-link" href="/" aria-label="LinkLog home"><img class="site-logo" src="/static/logo.svg" alt="LinkLog" /></a>
<h1>About</h1> <h1>About</h1>
<p>A quiet place for the links worth keeping.</p> <p>A quiet place for the links worth keeping.</p>
</div> </div>
<div class="header-actions"> <div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button> <button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu"> <nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a> <a id="auth-home-link" href="/">Home</a>
@@ -28,6 +29,10 @@
<a id="auth-admin-link" class="hidden" href="/admin">Admin</a> <a id="auth-admin-link" class="hidden" href="/admin">Admin</a>
<div id="auth-session" class="auth-session hidden"><a id="auth-username" class="user-name" href="/"></a></div> <div id="auth-session" class="auth-session hidden"><a id="auth-username" class="user-name" href="/"></a></div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button> <button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav> </nav>
</div> </div>
</div> </div>
@@ -52,8 +57,14 @@
<p>LinkLog is open source software. You can run your own instance, or contribute to the project on <p>LinkLog is open source software. You can run your own instance, or contribute to the project on
<a href="https://git.kolkman.org/olaf/Link-Log">my repository</a>.</p> <a href="https://git.kolkman.org/olaf/Link-Log">my repository</a>.</p>
</section> </section>
<section class="link-item">
<h2>Plugin</h2>
<p>Install the Firefox plugin to save links directly from your browser. <a
href="https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.2.0.xpi"
download>Download and install the Plugin</a>.</p>
</section>
</main> </main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer> <footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script> <script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=3"></script> <script src="/static/logout.js?v=3"></script>
<script src="/static/theme.js?v=1"></script> <script src="/static/theme.js?v=1"></script>
+44 -14
View File
@@ -13,11 +13,12 @@
<div class="container"> <div class="container">
<div class="header-row"> <div class="header-row">
<div> <div>
<img class="site-logo" src="/static/logo.svg" alt="LinkLog" /> <a class="site-logo-link" href="/" aria-label="LinkLog home"><img class="site-logo" src="/static/logo.svg" alt="LinkLog" /></a>
<h1>Admin</h1> <h1>Admin</h1>
<p>Manage users and plugin configuration</p> <p>Manage users and plugin configuration</p>
</div> </div>
<div class="header-actions"> <div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button> <button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu"> <nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a> <a id="auth-home-link" href="/">Home</a>
@@ -30,6 +31,10 @@
<a id="auth-username" class="user-name" href="/"></a> <a id="auth-username" class="user-name" href="/"></a>
</div> </div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button> <button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav> </nav>
</div> </div>
</div> </div>
@@ -39,8 +44,13 @@
<main class="container"> <main class="container">
<p id="admin-auth-notice" class="auth-notice hidden"></p> <p id="admin-auth-notice" class="auth-notice hidden"></p>
<div id="admin-controls" class="hidden"> <div id="admin-controls" class="hidden">
<section class="link-item settings-panel"> <section class="link-item settings-panel minimized">
<h2>Users</h2> <h2>
<button type="button" class="panel-toggle-btn" aria-expanded="false">
<span>Users</span>
<span class="panel-toggle-icon" aria-hidden="true">▼</span>
</button>
</h2>
<form id="user-form"> <form id="user-form">
<label> <label>
Username Username
@@ -64,16 +74,31 @@
<div id="user-list" class="plugin-list" aria-live="polite">Loading users...</div> <div id="user-list" class="plugin-list" aria-live="polite">Loading users...</div>
</section> </section>
<section class="link-item settings-panel"> <section class="link-item settings-panel minimized">
<h2>Plugins</h2> <h2>
<button type="button" class="panel-toggle-btn" aria-expanded="false">
<span>Plugins</span>
<span class="panel-toggle-icon" aria-hidden="true">▼</span>
</button>
</h2>
<div id="plugin-list" class="plugin-list" aria-live="polite">Loading plugins...</div> <div id="plugin-list" class="plugin-list" aria-live="polite">Loading plugins...</div>
</section> </section>
<section class="link-item settings-panel"> <section class="link-item settings-panel minimized">
<h2>Labels</h2> <h2>
<button type="button" class="panel-toggle-btn" aria-expanded="false">
<span>Labels</span>
<span class="panel-toggle-icon" aria-hidden="true">▼</span>
</button>
</h2>
<div id="admin-label-list" class="plugin-list" aria-live="polite">Loading labels...</div> <div id="admin-label-list" class="plugin-list" aria-live="polite">Loading labels...</div>
</section> </section>
<section class="link-item settings-panel"> <section class="link-item settings-panel minimized">
<h2>SMTP settings</h2> <h2>
<button type="button" class="panel-toggle-btn" aria-expanded="false">
<span>SMTP settings</span>
<span class="panel-toggle-icon" aria-hidden="true">▼</span>
</button>
</h2>
<form id="smtp-form"> <form id="smtp-form">
<label> <label>
SMTP host SMTP host
@@ -104,21 +129,26 @@
</form> </form>
</section> </section>
<section class="link-item settings-panel"> <section class="link-item settings-panel minimized">
<h2>Available themes</h2> <h2>
<button type="button" class="panel-toggle-btn" aria-expanded="false">
<span>Available themes</span>
<span class="panel-toggle-icon" aria-hidden="true">▼</span>
</button>
</h2>
<p>Choose the themes visitors may use.</p> <p>Choose the themes visitors may use.</p>
<form id="themes-form"> <form id="themes-form">
<div id="theme-options" class="theme-options" aria-live="polite">Loading themes...</div> <div id="admin-theme-options" class="theme-options" aria-live="polite">Loading themes...</div>
<button type="submit">Save themes</button> <button type="submit">Save themes</button>
<p id="theme-status" class="status" role="status"></p> <p id="theme-status" class="status" role="status"></p>
</form> </form>
</section> </section>
</div> </div>
</main> </main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer> <footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script> <script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=2"></script> <script src="/static/logout.js?v=2"></script>
<script src="/static/theme.js?v=1"></script> <script src="/static/theme.js?v=1"></script>
<script src="/static/admin.js?v=5"></script> <script src="/static/admin.js?v=7"></script>
</body> </body>
</html> </html>
+8 -3
View File
@@ -13,11 +13,12 @@
<div class="container"> <div class="container">
<div class="header-row"> <div class="header-row">
<div> <div>
<img class="site-logo" src="/static/logo.svg" alt="LinkLog" /> <a class="site-logo-link" href="/" aria-label="LinkLog home"><img class="site-logo" src="/static/logo.svg" alt="LinkLog" /></a>
<p>Public link feed</p> <p>Public link feed</p>
</div> </div>
<div class="header-tools"> <div class="header-tools">
<div class="header-actions"> <div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button> <button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu"> <nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a> <a id="auth-home-link" href="/">Home</a>
@@ -30,6 +31,10 @@
<a id="auth-username" class="user-name" href="/"></a> <a id="auth-username" class="user-name" href="/"></a>
</div> </div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button> <button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav> </nav>
</div> </div>
<section class="toolbar"> <section class="toolbar">
@@ -76,11 +81,11 @@
{% endif %} {% endif %}
<section id="feed" class="feed" aria-live="polite"></section> <section id="feed" class="feed" aria-live="polite"></section>
</main> </main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer> <footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script> <script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=3"></script> <script src="/static/logout.js?v=3"></script>
<script src="/static/theme.js?v=1"></script> <script src="/static/theme.js?v=1"></script>
<script src="/static/feed.js?v=9"></script> <script src="/static/feed.js?v=12"></script>
</body> </body>
</html> </html>
+7 -2
View File
@@ -13,11 +13,12 @@
<div class="container"> <div class="container">
<div class="header-row"> <div class="header-row">
<div> <div>
<img class="site-logo" src="/static/logo.svg" alt="LinkLog" /> <a class="site-logo-link" href="/" aria-label="LinkLog home"><img class="site-logo" src="/static/logo.svg" alt="LinkLog" /></a>
<h1>Labels</h1> <h1>Labels</h1>
<p>Manage your link labels</p> <p>Manage your link labels</p>
</div> </div>
<div class="header-actions"> <div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button> <button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu"> <nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a> <a id="auth-home-link" href="/">Home</a>
@@ -28,6 +29,10 @@
<a id="auth-admin-link" class="hidden" href="/admin">Admin</a> <a id="auth-admin-link" class="hidden" href="/admin">Admin</a>
<div id="auth-session" class="auth-session hidden"><a id="auth-username" class="user-name" href="/"></a></div> <div id="auth-session" class="auth-session hidden"><a id="auth-username" class="user-name" href="/"></a></div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button> <button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav> </nav>
</div> </div>
</div> </div>
@@ -44,7 +49,7 @@
<div id="label-list" class="plugin-list"></div> <div id="label-list" class="plugin-list"></div>
</section> </section>
</main> </main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer> <footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script> <script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=3"></script> <script src="/static/logout.js?v=3"></script>
<script src="/static/theme.js?v=1"></script> <script src="/static/theme.js?v=1"></script>
+7 -2
View File
@@ -13,10 +13,11 @@
<div class="container"> <div class="container">
<div class="header-row"> <div class="header-row">
<div> <div>
<img class="site-logo" src="/static/logo.svg" alt="LinkLog" /> <a class="site-logo-link" href="/" aria-label="LinkLog home"><img class="site-logo" src="/static/logo.svg" alt="LinkLog" /></a>
<p>Access your LinkLog settings</p> <p>Access your LinkLog settings</p>
</div> </div>
<div class="header-actions"> <div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button> <button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu"> <nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a> <a id="auth-home-link" href="/">Home</a>
@@ -29,6 +30,10 @@
<a id="auth-username" class="user-name" href="/"></a> <a id="auth-username" class="user-name" href="/"></a>
</div> </div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button> <button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav> </nav>
</div> </div>
</div> </div>
@@ -55,7 +60,7 @@
</form> </form>
</section> </section>
</main> </main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer> <footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script> <script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=3"></script> <script src="/static/logout.js?v=3"></script>
<script src="/static/theme.js?v=1"></script> <script src="/static/theme.js?v=1"></script>
+108
View File
@@ -0,0 +1,108 @@
<!DOCTYPE html>
<!-- Copyright © 2026 Olaf Kolkman -->
<!-- SPDX-License-Identifier: GPL-3.0-or-later -->
<html lang="en">
<head>
<meta charset="utf-8" />
<title>New Entry - LinkLog</title>
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="stylesheet" href="/static/style.css" />
</head>
<body>
<header class="site-header">
<div class="container">
<div class="header-row">
<div>
<a class="site-logo-link" href="/" aria-label="LinkLog home"><img class="site-logo" src="/static/logo.svg" alt="LinkLog" /></a>
<p>New Entry</p>
</div>
<div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a>
<a id="auth-about-link" href="/about">About</a>
<a id="auth-login-button" href="/login">Sign in</a>
<a id="auth-profile-link" class="hidden" href="/profile">Profile</a>
<a id="auth-labels-link" class="hidden" href="/labels">Labels</a>
<a id="auth-admin-link" class="hidden" href="/admin">Admin</a>
<div id="auth-session" class="auth-session hidden">
<a id="auth-username" class="user-name" href="/"></a>
</div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav>
</div>
</div>
</div>
</div>
</header>
<main class="container">
<div id="auth-required" class="error-message hidden">
<p>You must be signed in to create a new entry. <a href="/login">Sign in here</a>.</p>
</div>
<form id="entry-form" class="entry-form hidden">
<div class="form-section">
<label>
<span>URL</span>
<input id="url-input" name="url" type="url" required placeholder="https://example.com" />
</label>
<div id="scrape-status" class="status hidden" aria-live="polite"></div>
</div>
<div class="form-section">
<label>
<span>Title</span>
<input id="title-input" name="title" type="text" required />
</label>
<button id="refetch-title-button" class="secondary" type="button">Re-fetch Title</button>
</div>
<div id="duplicate-status" class="status hidden" aria-live="polite"></div>
<div class="form-section">
<label>
<span>Comment</span>
<textarea id="comment-input" name="comment" rows="4" placeholder="Optional comment about this link"></textarea>
</label>
</div>
<fieldset class="form-section">
<legend>Tags</legend>
<div id="existing-tags" class="tag-options"></div>
<label>
<span>Add new tags</span>
<input id="new-tags-input" type="text" pattern="#[^, ]+(,\s*#[^, ]+)*" placeholder="#tag1, #tag2" />
</label>
</fieldset>
<fieldset id="mastodon-publishing" class="form-section hidden">
<legend>Mastodon Publishing</legend>
<label>
<input id="mastodon-enabled" type="checkbox" checked />
Post to Mastodon
</label>
</fieldset>
<div class="form-actions">
<button id="submit-button" type="submit">Save Entry</button>
<a href="/" class="secondary button">Cancel</a>
</div>
<div id="submit-status" class="status hidden" aria-live="polite"></div>
</form>
</main>
<footer class="site-footer">
<span>Copyright © 2026 Olaf Kolkman</span> · <a href="https://git.kolkman.org/olaf/Link-Log">Repository</a>
</footer>
<script src="/static/auth-header.js"></script>
<script src="/static/new-entry.js?v=8"></script>
</body>
</html>
+2 -2
View File
@@ -13,7 +13,7 @@
<div class="container"> <div class="container">
<div class="header-row"> <div class="header-row">
<div> <div>
<img class="site-logo" src="/static/logo.svg" alt="LinkLog" /> <a class="site-logo-link" href="/" aria-label="LinkLog home"><img class="site-logo" src="/static/logo.svg" alt="LinkLog" /></a>
<h1>Configure LinkLog</h1> <h1>Configure LinkLog</h1>
<p>Create the first administrator and test email delivery.</p> <p>Create the first administrator and test email delivery.</p>
</div> </div>
@@ -42,7 +42,7 @@
</form> </form>
</section> </section>
</main> </main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman</footer> <footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman</footer>
<script src="/static/theme.js?v=1"></script> <script src="/static/theme.js?v=1"></script>
<script src="/static/setup.js"></script> <script src="/static/setup.js"></script>
</body> </body>
+50 -13
View File
@@ -15,10 +15,11 @@
<div class="container"> <div class="container">
<div class="header-row"> <div class="header-row">
<div> <div>
<img class="site-logo" src="/static/logo.svg" alt="LinkLog" /> <a class="site-logo-link" href="/" aria-label="LinkLog home"><img class="site-logo" src="/static/logo.svg" alt="LinkLog" /></a>
<h1>Profile</h1> <h1>Profile</h1>
</div> </div>
<div class="header-actions"> <div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button> <button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu"> <nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a> <a id="auth-home-link" href="/">Home</a>
@@ -31,6 +32,10 @@
<a id="auth-username" class="user-name" href="/"></a> <a id="auth-username" class="user-name" href="/"></a>
</div> </div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button> <button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav> </nav>
</div> </div>
</div> </div>
@@ -38,8 +43,13 @@
</header> </header>
<main class="container"> <main class="container">
<section class="link-item settings-panel"> <section class="link-item settings-panel minimized">
<h2>Profile Settings</h2> <h2>
<button type="button" class="panel-toggle-btn" aria-expanded="false">
<span>Profile Settings</span>
<span class="panel-toggle-icon" aria-hidden="true">▼</span>
</button>
</h2>
<form id="profile-form"> <form id="profile-form">
<label> <label>
Username Username
@@ -59,12 +69,18 @@
</label> </label>
<img id="avatar-preview" class="profile-avatar-preview hidden" alt="Avatar preview" /> <img id="avatar-preview" class="profile-avatar-preview hidden" alt="Avatar preview" />
<button type="submit">Save profile</button> <button type="submit">Save profile</button>
<p>If you have not downloaded the plugin yet, <a href="https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi" download>find it here</a>.</p>
<p id="profile-status" class="status" role="status"></p> <p id="profile-status" class="status" role="status"></p>
</form> </form>
</section> </section>
<section class="link-item settings-panel"> <section class="link-item settings-panel minimized">
<h2>Email addresses</h2> <h2>
<button type="button" class="panel-toggle-btn" aria-expanded="false">
<span>Email addresses</span>
<span class="panel-toggle-icon" aria-hidden="true">▼</span>
</button>
</h2>
<div id="email-address-list" class="email-address-list" aria-live="polite">Loading email addresses...</div> <div id="email-address-list" class="email-address-list" aria-live="polite">Loading email addresses...</div>
<form id="additional-email-form"> <form id="additional-email-form">
<label> <label>
@@ -76,8 +92,13 @@
</form> </form>
</section> </section>
<section class="link-item settings-panel"> <section class="link-item settings-panel minimized">
<h2>Password</h2> <h2>
<button type="button" class="panel-toggle-btn" aria-expanded="false">
<span>Password</span>
<span class="panel-toggle-icon" aria-hidden="true">▼</span>
</button>
</h2>
<form id="password-form"> <form id="password-form">
<label> <label>
Current password Current password
@@ -96,8 +117,13 @@
</form> </form>
</section> </section>
<section class="link-item settings-panel"> <section class="link-item settings-panel minimized">
<h2>One-time password</h2> <h2>
<button type="button" class="panel-toggle-btn" aria-expanded="false">
<span>One-time password</span>
<span class="panel-toggle-icon" aria-hidden="true">▼</span>
</button>
</h2>
<p>Use an authenticator app to add a second sign-in step.</p> <p>Use an authenticator app to add a second sign-in step.</p>
<div id="otp-disabled"> <div id="otp-disabled">
<button id="otp-setup" type="button">Set up one-time password</button> <button id="otp-setup" type="button">Set up one-time password</button>
@@ -108,19 +134,30 @@
<label>Verification code <input id="otp-setup-code" inputmode="numeric" <label>Verification code <input id="otp-setup-code" inputmode="numeric"
autocomplete="one-time-code" /></label> autocomplete="one-time-code" /></label>
<button id="otp-enable" type="button">Enable one-time password</button> <button id="otp-enable" type="button">Enable one-time password</button>
<p>Save these recovery codes in a secure place. They are shown only once:</p>
<code id="otp-recovery-codes"></code>
</div> </div>
</div> </div>
<div id="otp-enabled" class="hidden"> <div id="otp-enabled" class="hidden">
<p>One-time password is enabled.</p> <p>One-time password is enabled.</p>
<label>Current password <input id="otp-current-password" type="password" autocomplete="current-password" /></label>
<label>Verification code <input id="otp-disable-code" inputmode="numeric" <label>Verification code <input id="otp-disable-code" inputmode="numeric"
autocomplete="one-time-code" /></label> autocomplete="one-time-code" /></label>
<button id="otp-disable" type="button">Disable one-time password</button> <button id="otp-disable" type="button">Disable one-time password</button>
<p>Lost access to your authenticator? Use a saved recovery code.</p>
<label>Recovery code <input id="otp-recovery-code" type="text" autocomplete="one-time-code" /></label>
<button id="otp-recover" type="button">Recover and disable one-time password</button>
</div> </div>
<p id="otp-status" class="status" role="status"></p> <p id="otp-status" class="status" role="status"></p>
</section> </section>
<section class="link-item settings-panel"> <section class="link-item settings-panel minimized">
<h2>Mastodon</h2> <h2>
<button type="button" class="panel-toggle-btn" aria-expanded="false">
<span>Mastodon</span>
<span class="panel-toggle-icon" aria-hidden="true">▼</span>
</button>
</h2>
<form id="mastodon-form"> <form id="mastodon-form">
<label> <label>
Mastodon server Mastodon server
@@ -138,12 +175,12 @@
</form> </form>
</section> </section>
</main> </main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a <footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a
href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer> href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script> <script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=2"></script> <script src="/static/logout.js?v=2"></script>
<script src="/static/theme.js?v=1"></script> <script src="/static/theme.js?v=1"></script>
<script src="/static/profile.js?v=5"></script> <script src="/static/profile.js?v=6"></script>
</body> </body>
</html> </html>
+1 -1
View File
@@ -1,3 +1,3 @@
{ {
"version": "0.1.0" "version": "0.2.0"
} }
Binary file not shown.

Before

Width:  |  Height:  |  Size: 320 KiB

+95
View File
@@ -0,0 +1,95 @@
## Copyright © 2026 Olaf Kolkman
## SPDX-License-Identifier: GPL-3.0-or-later
from pathlib import Path
from urllib.request import urlopen
FONT_SOURCES = {
'Asset-Regular.ttf': 'https://fonts.gstatic.com/s/asset/v30/SLXGc1na-mM4cWIm.ttf',
'DMSans-Regular.ttf': 'https://fonts.gstatic.com/s/dmsans/v17/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAopxhTg.ttf',
'DMSans-Medium.ttf': 'https://fonts.gstatic.com/s/dmsans/v17/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAkJxhTg.ttf',
'DMSans-SemiBold.ttf': 'https://fonts.gstatic.com/s/dmsans/v17/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwAfJthTg.ttf',
'DMSans-Bold.ttf': 'https://fonts.gstatic.com/s/dmsans/v17/rP2tp2ywxg089UriI5-g4vlH9VoD8CmcqZG40F9JadbnoEwARZthTg.ttf',
'SpaceGrotesk-Medium.ttf': 'https://fonts.gstatic.com/s/spacegrotesk/v22/V8mQoQDjQSkFtoMM3T6r8E7mF71Q-gOoraIAEj7aUUsj.ttf',
'SpaceGrotesk-SemiBold.ttf': 'https://fonts.gstatic.com/s/spacegrotesk/v22/V8mQoQDjQSkFtoMM3T6r8E7mF71Q-gOoraIAEj42Vksj.ttf',
'SpaceGrotesk-Bold.ttf': 'https://fonts.gstatic.com/s/spacegrotesk/v22/V8mQoQDjQSkFtoMM3T6r8E7mF71Q-gOoraIAEj4PVksj.ttf',
}
FONT_CSS = """@font-face {
font-family: 'Asset';
font-style: normal;
font-weight: 400;
font-display: swap;
src: url('Asset-Regular.ttf') format('truetype');
}
@font-face {
font-family: 'DM Sans';
font-style: normal;
font-weight: 400;
font-display: swap;
src: url('DMSans-Regular.ttf') format('truetype');
}
@font-face {
font-family: 'DM Sans';
font-style: normal;
font-weight: 500;
font-display: swap;
src: url('DMSans-Medium.ttf') format('truetype');
}
@font-face {
font-family: 'DM Sans';
font-style: normal;
font-weight: 600;
font-display: swap;
src: url('DMSans-SemiBold.ttf') format('truetype');
}
@font-face {
font-family: 'DM Sans';
font-style: normal;
font-weight: 700;
font-display: swap;
src: url('DMSans-Bold.ttf') format('truetype');
}
@font-face {
font-family: 'Space Grotesk';
font-style: normal;
font-weight: 500;
font-display: swap;
src: url('SpaceGrotesk-Medium.ttf') format('truetype');
}
@font-face {
font-family: 'Space Grotesk';
font-style: normal;
font-weight: 600;
font-display: swap;
src: url('SpaceGrotesk-SemiBold.ttf') format('truetype');
}
@font-face {
font-family: 'Space Grotesk';
font-style: normal;
font-weight: 700;
font-display: swap;
src: url('SpaceGrotesk-Bold.ttf') format('truetype');
}
"""
def main() -> None:
target_dir = Path('frontend/static/fonts')
target_dir.mkdir(parents=True, exist_ok=True)
for filename, url in FONT_SOURCES.items():
with urlopen(url, timeout=30) as response:
(target_dir / filename).write_bytes(response.read())
(target_dir / 'fonts.css').write_text(FONT_CSS, encoding='utf-8')
if __name__ == '__main__':
main()
+103
View File
@@ -0,0 +1,103 @@
#!/usr/bin/env python3
"""Generate Firefox update metadata from LinkLog signed XPI artifacts."""
import hashlib
import json
import re
import sys
import zipfile
from pathlib import Path
ROOT = Path(__file__).resolve().parents[2]
SIGNED_DIR = ROOT / 'XPI' / 'signed'
MANIFEST_PATH = ROOT / 'webextension' / 'manifest.json'
UPDATES_PATH = ROOT / 'webextension' / 'updates.json'
ABOUT_TEMPLATE_PATH = ROOT / 'frontend' / 'templates' / 'about.html'
RAW_BASE_URL = 'https://git.kolkman.org/olaf/Link-Log/raw/branch/main'
XPI_NAME_RE = re.compile(r'LinkLog-(\d+\.\d+\.\d+)\.xpi')
ABOUT_XPI_URL_RE = re.compile(rf'{re.escape(RAW_BASE_URL)}/XPI/signed/LinkLog-\d+\.\d+\.\d+\.xpi')
def fail(message: str) -> None:
raise SystemExit(f'update metadata generation failed: {message}')
def version_key(version: str) -> tuple[int, int, int]:
return tuple(int(part) for part in version.split('.'))
def read_packaged_manifest(xpi_path: Path) -> dict:
try:
with zipfile.ZipFile(xpi_path) as archive:
if archive.testzip() is not None:
fail(f'{xpi_path.relative_to(ROOT)} contains a corrupt member')
return json.loads(archive.read('manifest.json'))
except (OSError, KeyError, json.JSONDecodeError, zipfile.BadZipFile) as error:
fail(f'could not read {xpi_path.relative_to(ROOT)}: {error}')
def sha256_digest(xpi_path: Path) -> str:
digest = hashlib.sha256()
with xpi_path.open('rb') as xpi_file:
for block in iter(lambda: xpi_file.read(1024 * 1024), b''):
digest.update(block)
return digest.hexdigest()
def update_about_plugin_link(xpi_path: Path) -> None:
about_template = ABOUT_TEMPLATE_PATH.read_text()
latest_xpi_url = f'{RAW_BASE_URL}/{xpi_path.relative_to(ROOT).as_posix()}'
updated_template, replacements = ABOUT_XPI_URL_RE.subn(latest_xpi_url, about_template)
if replacements != 1:
fail(f'expected one signed XPI link in {ABOUT_TEMPLATE_PATH.relative_to(ROOT)}; found {replacements}')
ABOUT_TEMPLATE_PATH.write_text(updated_template)
def main() -> None:
source_manifest = json.loads(MANIFEST_PATH.read_text())
addon_id = source_manifest.get('browser_specific_settings', {}).get('gecko', {}).get('id')
if not addon_id:
fail('webextension/manifest.json is missing browser_specific_settings.gecko.id')
releases = []
for xpi_path in SIGNED_DIR.glob('LinkLog-*.xpi'):
match = XPI_NAME_RE.fullmatch(xpi_path.name)
if not match:
continue
version = match.group(1)
manifest = read_packaged_manifest(xpi_path)
if manifest.get('version') != version:
fail(f'{xpi_path.relative_to(ROOT)} manifest version does not match its filename')
gecko = manifest.get('browser_specific_settings', {}).get('gecko', {})
if gecko.get('id') != addon_id:
fail(f'{xpi_path.relative_to(ROOT)} add-on id does not match webextension/manifest.json')
strict_min_version = gecko.get('strict_min_version')
if not strict_min_version:
fail(f'{xpi_path.relative_to(ROOT)} is missing browser_specific_settings.gecko.strict_min_version')
releases.append((version, xpi_path, strict_min_version, sha256_digest(xpi_path)))
if not releases:
fail(f'no signed LinkLog release artifacts found in {SIGNED_DIR.relative_to(ROOT)}')
releases.sort(key=lambda release: version_key(release[0]), reverse=True)
updates = [
{
'version': version,
'update_link': f'{RAW_BASE_URL}/{xpi_path.relative_to(ROOT).as_posix()}',
'update_hash': f'sha256:{digest}',
'applications': {
'gecko': {
'strict_min_version': strict_min_version,
},
},
}
for version, xpi_path, strict_min_version, digest in releases
]
UPDATES_PATH.write_text(json.dumps({'addons': {addon_id: {'updates': updates}}}, indent=2) + '\n')
update_about_plugin_link(releases[0][1])
print(f'updated {UPDATES_PATH.relative_to(ROOT)} with {len(updates)} signed release(s)')
if __name__ == '__main__':
main()
+112 -36
View File
@@ -1,6 +1,7 @@
#!/usr/bin/env python3 #!/usr/bin/env python3
"""Validate the version and checked-in artifacts for a LinkLog release.""" """Validate the version and checked-in artifacts for a LinkLog release."""
import hashlib
import json import json
import re import re
import sys import sys
@@ -9,61 +10,136 @@ from pathlib import Path
ROOT = Path(__file__).resolve().parents[2] ROOT = Path(__file__).resolve().parents[2]
MANIFEST_PATH = ROOT / 'webextension' / 'manifest.json' VERSION_FILE = ROOT / 'frontend' / 'version.json'
FRONTEND_VERSION_PATH = ROOT / 'frontend' / 'version.json'
SETTINGS_PATH = ROOT / 'backend' / 'app' / 'core' / 'config.py'
UPDATES_PATH = ROOT / 'webextension' / 'updates.json'
SIGNED_DIR = ROOT / 'XPI' / 'signed' SIGNED_DIR = ROOT / 'XPI' / 'signed'
MANIFEST_PATH = ROOT / 'webextension' / 'manifest.json'
UPDATES_PATH = ROOT / 'webextension' / 'updates.json'
ABOUT_TEMPLATE_PATH = ROOT / 'frontend' / 'templates' / 'about.html'
RAW_BASE_URL = 'https://git.kolkman.org/olaf/Link-Log/raw/branch/main'
VERSION_RE = re.compile(r'\d+\.\d+\.\d+')
def fail(message: str) -> None: def fail(message: str) -> None:
raise SystemExit(f'release validation failed: {message}') raise SystemExit(f'release validation failed: {message}')
def version_key(version: str) -> tuple[int, int, int]:
return tuple(int(part) for part in version.split('.'))
def find_latest_signed_xpi() -> tuple[str, Path]:
candidates = []
for xpi_path in SIGNED_DIR.glob('LinkLog-*.xpi'):
match = re.fullmatch(r'LinkLog-(\d+\.\d+\.\d+)\.xpi', xpi_path.name)
if match:
candidates.append((match.group(1), xpi_path))
if not candidates:
fail(f'no signed plugin artifacts found in {SIGNED_DIR.relative_to(ROOT)}')
return max(candidates, key=lambda candidate: version_key(candidate[0]))
def sha256_digest(xpi_path: Path) -> str:
digest = hashlib.sha256()
with xpi_path.open('rb') as xpi_file:
for block in iter(lambda: xpi_file.read(1024 * 1024), b''):
digest.update(block)
return digest.hexdigest()
def validate_self_update(source_manifest: dict, extension_version: str, xpi_path: Path) -> None:
gecko_settings = source_manifest.get('browser_specific_settings', {}).get('gecko', {})
addon_id = gecko_settings.get('id')
strict_min_version = gecko_settings.get('strict_min_version')
if not addon_id:
fail('webextension/manifest.json is missing browser_specific_settings.gecko.id')
updates_data = json.loads(UPDATES_PATH.read_text())
addon_entry = updates_data.get('addons', {}).get(addon_id)
if not addon_entry:
fail(f'{UPDATES_PATH.relative_to(ROOT)} has no entry for add-on id {addon_id!r}')
entry = next((u for u in addon_entry.get('updates', []) if u.get('version') == extension_version), None)
if entry is None:
fail(
f'{UPDATES_PATH.relative_to(ROOT)} has no update entry for version {extension_version!r}; '
'add one alongside the signed XPI so the self-update mechanism can find it'
)
expected_link = f'{RAW_BASE_URL}/{xpi_path.relative_to(ROOT).as_posix()}'
if entry.get('update_link') != expected_link:
fail(
f'{UPDATES_PATH.relative_to(ROOT)} update_link {entry.get("update_link")!r} does not match '
f'the expected raw signed XPI URL {expected_link!r}'
)
expected_hash = f'sha256:{sha256_digest(xpi_path)}'
if entry.get('update_hash') != expected_hash:
fail(
f'{UPDATES_PATH.relative_to(ROOT)} update_hash {entry.get("update_hash")!r} does not match '
f'the SHA-256 hash of {xpi_path.relative_to(ROOT)}'
)
entry_min_version = entry.get('applications', {}).get('gecko', {}).get('strict_min_version')
if entry_min_version != strict_min_version:
fail(
f'{UPDATES_PATH.relative_to(ROOT)} applications.gecko.strict_min_version {entry_min_version!r} '
f'does not match webextension/manifest.json strict_min_version {strict_min_version!r}'
)
def validate_about_plugin_link(xpi_path: Path) -> None:
expected_link = f'{RAW_BASE_URL}/{xpi_path.relative_to(ROOT).as_posix()}'
if expected_link not in ABOUT_TEMPLATE_PATH.read_text():
fail(
f'{ABOUT_TEMPLATE_PATH.relative_to(ROOT)} does not link to the latest signed XPI '
f'{xpi_path.relative_to(ROOT)}'
)
def main() -> None: def main() -> None:
manifest = json.loads(MANIFEST_PATH.read_text()) version_data = json.loads(VERSION_FILE.read_text())
extension_version = manifest.get('version') backend_version = version_data.get('version')
if not isinstance(extension_version, str) or not re.fullmatch(r'\d+\.\d+\.\d+', extension_version): if not backend_version:
fail('webextension/manifest.json has no valid three-part version') fail(f'version could not be found in {VERSION_FILE.relative_to(ROOT)}')
if not VERSION_RE.fullmatch(backend_version):
fail(f'backend version {backend_version} is not a valid three-part version')
frontend_version = json.loads(FRONTEND_VERSION_PATH.read_text()).get('version') extension_version, xpi_path = find_latest_signed_xpi()
if frontend_version != extension_version: source_manifest = json.loads(MANIFEST_PATH.read_text())
fail(f'frontend version {frontend_version} does not match extension version {extension_version}') if source_manifest.get('version') != extension_version:
fail(
gecko_settings = manifest.get('browser_specific_settings', {}).get('gecko', {}) f'webextension/manifest.json version {source_manifest.get("version")!r} does not match '
data_permissions = gecko_settings.get('data_collection_permissions') f'the latest signed XPI version {extension_version!r}'
if data_permissions != {'required': ['websiteActivity'], 'optional': []}: )
fail('Firefox data_collection_permissions must require websiteActivity and have no optional categories')
settings = SETTINGS_PATH.read_text()
match = re.search(r"version: str = os\.getenv\('LINKLOG_VERSION', '([^']+)'\)", settings)
if not match:
fail('backend version default could not be found')
backend_version = match.group(1)
if backend_version != extension_version:
fail(f'backend version {backend_version} does not match extension version {extension_version}')
xpi_path = SIGNED_DIR / f'LinkLog-{extension_version}.xpi'
if not xpi_path.is_file():
fail(f'missing manually signed artifact: {xpi_path.relative_to(ROOT)}')
with zipfile.ZipFile(xpi_path) as archive: with zipfile.ZipFile(xpi_path) as archive:
try: try:
packaged_manifest = json.loads(archive.read('manifest.json')) packaged_manifest = json.loads(archive.read('manifest.json'))
except KeyError: except KeyError:
fail('signed XPI does not contain manifest.json') fail('signed XPI does not contain manifest.json')
if packaged_manifest.get('version') != extension_version: if packaged_manifest.get('version') != extension_version:
fail('signed XPI manifest version does not match webextension/manifest.json') fail('signed XPI manifest version does not match its filename')
gecko_settings = packaged_manifest.get('browser_specific_settings', {}).get('gecko', {})
data_permissions = gecko_settings.get('data_collection_permissions')
if data_permissions != {'required': ['websiteActivity'], 'optional': []}:
fail('Firefox data_collection_permissions must require websiteActivity and have no optional categories')
if archive.testzip() is not None: if archive.testzip() is not None:
fail('signed XPI contains a corrupt member') fail('signed XPI contains a corrupt member')
updates = json.loads(UPDATES_PATH.read_text()) validate_self_update(source_manifest, extension_version, xpi_path)
addon_id = gecko_settings['id'] validate_about_plugin_link(xpi_path)
update_entries = updates.get('addons', {}).get(addon_id, {}).get('updates', [])
if not any(entry.get('version') == extension_version for entry in update_entries):
fail(f'webextension/updates.json has no update entry for {extension_version}')
print(f'validated LinkLog release {frontend_version}') signed_xpi = xpi_path.relative_to(ROOT)
print(f'xpi={xpi_path.relative_to(ROOT)}') if len(sys.argv) == 3 and sys.argv[1] == '--github-output':
with Path(sys.argv[2]).open('a') as output:
print(f'backend_version={backend_version}', file=output)
print(f'plugin_version={extension_version}', file=output)
print(f'signed_xpi={signed_xpi}', file=output)
elif len(sys.argv) != 1:
fail('usage: validate_release.py [--github-output <path>]')
print(f'validated LinkLog backend release {backend_version}')
print(f'plugin_version={extension_version}')
print(f'signed_xpi={signed_xpi}')
if __name__ == '__main__': if __name__ == '__main__':
+4 -1
View File
@@ -42,7 +42,10 @@
"submissionFailed": {"message": "Senden fehlgeschlagen"}, "submissionFailed": {"message": "Senden fehlgeschlagen"},
"linkSaved": {"message": "Link auf $URL$ gespeichert.", "placeholders": {"url": {"content": "$1"}}}, "linkSaved": {"message": "Link auf $URL$ gespeichert.", "placeholders": {"url": {"content": "$1"}}},
"linkAlreadyExists": {"message": "Dieser Link existiert bereits. Kommentar und Tags wurden aktualisiert und die Veröffentlichung erneut ausgelöst."}, "linkAlreadyExists": {"message": "Dieser Link existiert bereits. Kommentar und Tags wurden aktualisiert und die Veröffentlichung erneut ausgelöst."},
"duplicateLinkWarning": {"message": "Dieser Link existiert bereits. Kommentar und Tags können aktualisiert werden; beim Absenden wird die Veröffentlichung erneut ausgelöst."}, "duplicateLinkSameUrl": {"message": "Dieser Link existiert bereits.\nDu kannst den Eintrag trotzdem speichern; dabei werden Kommentar und Tags des bestehenden Eintrags aktualisiert."},
"duplicateLinkDifferentUrl": {"message": "Dieser Link existiert bereits. Der gespeicherte Link hat jedoch eine andere URL (fehlende oder andere Parameter).\nWenn du den Eintrag speicherst, riskierst du einen doppelten Eintrag."},
"refetchTitle": {"message": "Titel erneut abrufen"},
"titleFetchFailed": {"message": "Titel konnte nicht abgerufen werden"},
"publishingErrors": {"message": "Fehler bei der Veröffentlichung: $ERRORS$", "placeholders": {"errors": {"content": "$1"}}}, "publishingErrors": {"message": "Fehler bei der Veröffentlichung: $ERRORS$", "placeholders": {"errors": {"content": "$1"}}},
"submissionFailedConnection": {"message": "Senden fehlgeschlagen. Überprüfe die Verbindung zum Backend."}, "submissionFailedConnection": {"message": "Senden fehlgeschlagen. Überprüfe die Verbindung zum Backend."},
"loggedInAt": {"message": "$USERNAME$ ist bei $BACKEND$ angemeldet", "placeholders": {"username": {"content": "$1"}, "backend": {"content": "$2"}}}, "loggedInAt": {"message": "$USERNAME$ ist bei $BACKEND$ angemeldet", "placeholders": {"username": {"content": "$1"}, "backend": {"content": "$2"}}},
+11 -2
View File
@@ -133,8 +133,17 @@
"linkAlreadyExists": { "linkAlreadyExists": {
"message": "This link already exists. Comment and tags were updated, and publishing was retriggered." "message": "This link already exists. Comment and tags were updated, and publishing was retriggered."
}, },
"duplicateLinkWarning": { "duplicateLinkSameUrl": {
"message": "This link already exists. Comment and tags can be updated, and by submitting publishing will be retriggered." "message": "This link already exists.\nYou can still save the entry, which will update the existing entry's comment and or tags."
},
"duplicateLinkDifferentUrl": {
"message": "This link already exists. But, the stored link has a different URL (missing or different parameters).\nWhen you save the entry you risk a duplicate entry."
},
"refetchTitle": {
"message": "Re-fetch title"
},
"titleFetchFailed": {
"message": "Could not fetch title"
}, },
"publishingErrors": { "publishingErrors": {
"message": "Publishing errors: $ERRORS$", "message": "Publishing errors: $ERRORS$",
+4 -1
View File
@@ -42,7 +42,10 @@
"submissionFailed": {"message": "Error al enviar"}, "submissionFailed": {"message": "Error al enviar"},
"linkSaved": {"message": "Enlace guardado en $URL$.", "placeholders": {"url": {"content": "$1"}}}, "linkSaved": {"message": "Enlace guardado en $URL$.", "placeholders": {"url": {"content": "$1"}}},
"linkAlreadyExists": {"message": "Este enlace ya existe. Se actualizaron el comentario y las etiquetas, y se volvió a activar la publicación."}, "linkAlreadyExists": {"message": "Este enlace ya existe. Se actualizaron el comentario y las etiquetas, y se volvió a activar la publicación."},
"duplicateLinkWarning": {"message": "Este enlace ya existe. Puedes actualizar el comentario y las etiquetas; al enviarlo se volverá a activar la publicación."}, "duplicateLinkSameUrl": {"message": "Este enlace ya existe.\nAún puedes guardar la entrada, lo que actualizará el comentario y las etiquetas de la entrada existente."},
"duplicateLinkDifferentUrl": {"message": "Este enlace ya existe. Pero el enlace guardado tiene una URL diferente (parámetros ausentes o distintos).\nSi guardas la entrada, corres el riesgo de crear una entrada duplicada."},
"refetchTitle": {"message": "Volver a obtener el título"},
"titleFetchFailed": {"message": "No se pudo obtener el título"},
"publishingErrors": {"message": "Errores de publicación: $ERRORS$", "placeholders": {"errors": {"content": "$1"}}}, "publishingErrors": {"message": "Errores de publicación: $ERRORS$", "placeholders": {"errors": {"content": "$1"}}},
"submissionFailedConnection": {"message": "Error al enviar. Comprueba la conexión con el servidor."}, "submissionFailedConnection": {"message": "Error al enviar. Comprueba la conexión con el servidor."},
"loggedInAt": {"message": "$USERNAME$ ha iniciado sesión en $BACKEND$", "placeholders": {"username": {"content": "$1"}, "backend": {"content": "$2"}}}, "loggedInAt": {"message": "$USERNAME$ ha iniciado sesión en $BACKEND$", "placeholders": {"username": {"content": "$1"}, "backend": {"content": "$2"}}},
+4 -1
View File
@@ -42,7 +42,10 @@
"submissionFailed": {"message": "Échec de l’envoi"}, "submissionFailed": {"message": "Échec de l’envoi"},
"linkSaved": {"message": "Lien enregistré sur $URL$.", "placeholders": {"url": {"content": "$1"}}}, "linkSaved": {"message": "Lien enregistré sur $URL$.", "placeholders": {"url": {"content": "$1"}}},
"linkAlreadyExists": {"message": "Ce lien existe déjà. Le commentaire et les étiquettes ont été mis à jour et la publication a été relancée."}, "linkAlreadyExists": {"message": "Ce lien existe déjà. Le commentaire et les étiquettes ont été mis à jour et la publication a été relancée."},
"duplicateLinkWarning": {"message": "Ce lien existe déjà. Le commentaire et les étiquettes peuvent être mis à jour ; l’envoi relancera la publication."}, "duplicateLinkSameUrl": {"message": "Ce lien existe déjà.\nVous pouvez tout de même enregistrer l’entrée ; le commentaire et les étiquettes de l’entrée existante seront mis à jour."},
"duplicateLinkDifferentUrl": {"message": "Ce lien existe déjà. Mais le lien enregistré a une URL différente (paramètres manquants ou différents).\nSi vous enregistrez l’entrée, vous risquez de créer un doublon."},
"refetchTitle": {"message": "Récupérer à nouveau le titre"},
"titleFetchFailed": {"message": "Impossible de récupérer le titre"},
"publishingErrors": {"message": "Erreurs de publication : $ERRORS$", "placeholders": {"errors": {"content": "$1"}}}, "publishingErrors": {"message": "Erreurs de publication : $ERRORS$", "placeholders": {"errors": {"content": "$1"}}},
"submissionFailedConnection": {"message": "Échec de l’envoi. Vérifiez la connexion au serveur."}, "submissionFailedConnection": {"message": "Échec de l’envoi. Vérifiez la connexion au serveur."},
"loggedInAt": {"message": "$USERNAME$ est connecté à $BACKEND$", "placeholders": {"username": {"content": "$1"}, "backend": {"content": "$2"}}}, "loggedInAt": {"message": "$USERNAME$ est connecté à $BACKEND$", "placeholders": {"username": {"content": "$1"}, "backend": {"content": "$2"}}},
+4 -1
View File
@@ -42,7 +42,10 @@
"submissionFailed": {"message": "Verzenden mislukt"}, "submissionFailed": {"message": "Verzenden mislukt"},
"linkSaved": {"message": "Koppeling opgeslagen op $URL$.", "placeholders": {"url": {"content": "$1"}}}, "linkSaved": {"message": "Koppeling opgeslagen op $URL$.", "placeholders": {"url": {"content": "$1"}}},
"linkAlreadyExists": {"message": "Deze koppeling bestaat al. De opmerking en tags zijn bijgewerkt en publiceren is opnieuw gestart."}, "linkAlreadyExists": {"message": "Deze koppeling bestaat al. De opmerking en tags zijn bijgewerkt en publiceren is opnieuw gestart."},
"duplicateLinkWarning": {"message": "Deze koppeling bestaat al. De opmerking en tags kunnen worden bijgewerkt; na verzenden wordt publiceren opnieuw gestart."}, "duplicateLinkSameUrl": {"message": "Deze koppeling bestaat al.\nJe kunt de invoer nog steeds opslaan; de opmerking en tags van de bestaande koppeling worden dan bijgewerkt."},
"duplicateLinkDifferentUrl": {"message": "Deze koppeling bestaat al. De opgeslagen koppeling heeft echter een andere URL (ontbrekende of andere parameters).\nAls je de invoer opslaat, loop je het risico op een dubbele koppeling."},
"refetchTitle": {"message": "Titel opnieuw ophalen"},
"titleFetchFailed": {"message": "Titel kon niet worden opgehaald"},
"publishingErrors": {"message": "Publicatiefouten: $ERRORS$", "placeholders": {"errors": {"content": "$1"}}}, "publishingErrors": {"message": "Publicatiefouten: $ERRORS$", "placeholders": {"errors": {"content": "$1"}}},
"submissionFailedConnection": {"message": "Verzenden mislukt. Controleer de verbinding met de backend."}, "submissionFailedConnection": {"message": "Verzenden mislukt. Controleer de verbinding met de backend."},
"loggedInAt": {"message": "$USERNAME$ is ingelogd op $BACKEND$", "placeholders": {"username": {"content": "$1"}, "backend": {"content": "$2"}}}, "loggedInAt": {"message": "$USERNAME$ is ingelogd op $BACKEND$", "placeholders": {"username": {"content": "$1"}, "backend": {"content": "$2"}}},
+5 -2
View File
@@ -1,7 +1,7 @@
{ {
"manifest_version": 3, "manifest_version": 3,
"name": "__MSG_extensionName__", "name": "__MSG_extensionName__",
"version": "0.1.0", "version": "0.2.0",
"description": "__MSG_extensionDescription__", "description": "__MSG_extensionDescription__",
"default_locale": "en-US", "default_locale": "en-US",
"permissions": [ "permissions": [
@@ -12,6 +12,9 @@
"http://*/*", "http://*/*",
"https://*/*" "https://*/*"
], ],
"content_security_policy": {
"extension_pages": "script-src 'self'; object-src 'none'"
},
"action": { "action": {
"default_title": "__MSG_extensionName__", "default_title": "__MSG_extensionName__",
"default_popup": "popup.html", "default_popup": "popup.html",
@@ -27,7 +30,7 @@
"browser_specific_settings": { "browser_specific_settings": {
"gecko": { "gecko": {
"id": "linklog@kolkman.org", "id": "linklog@kolkman.org",
"strict_min_version": "109.0", "strict_min_version": "142.0",
"data_collection_permissions": { "data_collection_permissions": {
"required": ["websiteActivity"], "required": ["websiteActivity"],
"optional": [] "optional": []
+54 -10
View File
@@ -10,6 +10,7 @@ const otpInput = document.getElementById('otp');
const session = document.getElementById('logged-in'); const session = document.getElementById('logged-in');
const sessionSummary = document.getElementById('session-summary'); const sessionSummary = document.getElementById('session-summary');
const signOutButton = document.getElementById('sign-out'); const signOutButton = document.getElementById('sign-out');
const sessionStore = browser.storage.session;
const t = window.linklogI18n; const t = window.linklogI18n;
@@ -49,15 +50,18 @@ function setStatus(message, isError = false) {
} }
async function loadSettings() { async function loadSettings() {
const settings = await browser.storage.local.get(['backendUrl', 'email', 'username', 'accessToken']); const [settings, sessionSettings] = await Promise.all([
browser.storage.local.get(['backendUrl', 'email', 'username']),
sessionStore.get(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
]);
backendUrlInput.value = settings.backendUrl || ''; backendUrlInput.value = settings.backendUrl || '';
emailInput.value = settings.email || ''; emailInput.value = settings.email || '';
if (settings.accessToken && settings.backendUrl && await hasBackendPermission(settings.backendUrl)) { if (sessionSettings.accessToken && settings.backendUrl && await hasBackendPermission(settings.backendUrl)) {
try { try {
const response = await fetch( const response = await fetch(
`${settings.backendUrl}/api/auth/me`, `${settings.backendUrl}/api/auth/me`,
{headers: {Authorization: `Bearer ${settings.accessToken}`}}, {headers: {Authorization: `Bearer ${sessionSettings.accessToken}`}},
); );
if (response.ok) { if (response.ok) {
const user = await response.json(); const user = await response.json();
@@ -84,7 +88,32 @@ function showLoggedOut() {
} }
async function clearSession() { async function clearSession() {
await browser.storage.local.remove(['accessToken', 'tokenType', 'tokenExpiresAt', 'refreshToken']); await Promise.all([
sessionStore.remove(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
browser.storage.local.remove(['accessToken', 'tokenType', 'tokenExpiresAt', 'refreshToken', 'deviceId']),
]);
}
async function refreshAccessToken(settings) {
if (!settings.backendUrl || !settings.refreshToken || !settings.deviceId) return null;
try {
const response = await fetch(`${settings.backendUrl}/api/auth/refresh`, {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({refresh_token: settings.refreshToken, device_id: settings.deviceId}),
});
if (!response.ok) {
await clearSession();
return null;
}
const data = await response.json();
const refreshed = {accessToken: data.access_token, refreshToken: data.refresh_token,
tokenExpiresAt: data.expires_at, deviceId: data.device_id || settings.deviceId};
await sessionStore.set(refreshed);
return refreshed;
} catch (error) {
return null;
}
} }
async function saveSettingsAndLogin(event) { async function saveSettingsAndLogin(event) {
@@ -116,14 +145,29 @@ async function saveSettingsAndLogin(event) {
} }
const data = await response.json(); const data = await response.json();
if (response.status === 401) {
const refreshed = await refreshAccessToken({...settings, ...sessionSettings});
if (refreshed) {
const retry = await fetch(`${settings.backendUrl}/api/auth/me`, {
headers: {Authorization: `Bearer ${refreshed.accessToken}`},
});
if (retry.ok) {
const user = await retry.json();
showLoggedIn(user.username || settings.email, settings.backendUrl);
return;
}
}
}
await browser.storage.local.set({ await browser.storage.local.set({
backendUrl, backendUrl,
email, email,
username: data.user?.username || email, username: data.user?.username || email,
});
await sessionStore.set({
accessToken: data.access_token, accessToken: data.access_token,
tokenType: data.token_type,
tokenExpiresAt: data.expires_at,
refreshToken: data.refresh_token, refreshToken: data.refresh_token,
tokenExpiresAt: data.expires_at,
deviceId: data.device_id || `device-${crypto.randomUUID()}`,
}); });
showLoggedIn(data.user?.username || email, backendUrl); showLoggedIn(data.user?.username || email, backendUrl);
@@ -136,13 +180,13 @@ async function saveSettingsAndLogin(event) {
} }
async function signOut() { async function signOut() {
const settings = await browser.storage.local.get(['accessToken']); const settings = await browser.storage.local.get(['backendUrl']);
const sessionSettings = await sessionStore.get(['accessToken']);
const backendUrl = normalizeBackendOrigin(backendUrlInput.value.trim()); const backendUrl = normalizeBackendOrigin(backendUrlInput.value.trim());
if (settings.accessToken && await hasBackendPermission(backendUrl)) { if (sessionSettings.accessToken && settings.backendUrl && await hasBackendPermission(backendUrl)) {
await fetch(`${backendUrl}/api/auth/logout`, { await fetch(`${backendUrl}/api/auth/logout`, {
method: 'POST', method: 'POST',
headers: { 'Content-Type': 'application/json' }, headers: {Authorization: `Bearer ${sessionSettings.accessToken}`},
body: JSON.stringify({ token: settings.accessToken }),
}).catch(() => undefined); }).catch(() => undefined);
} }
await clearSession(); await clearSession();
+1
View File
@@ -26,6 +26,7 @@
<span data-i18n="titleLabel">Title</span> <span data-i18n="titleLabel">Title</span>
<input id="title" name="title" type="text" /> <input id="title" name="title" type="text" />
</label> </label>
<button type="button" id="refetch-title" class="secondary" data-i18n="refetchTitle">Re-fetch title</button>
<label> <label>
<span data-i18n="urlLabel">URL</span> <span data-i18n="urlLabel">URL</span>
+123 -17
View File
@@ -13,6 +13,8 @@ const feedLink = document.getElementById('feed-link');
const authWarning = document.getElementById('auth-warning'); const authWarning = document.getElementById('auth-warning');
const warningSettingsButton = document.getElementById('warning-settings'); const warningSettingsButton = document.getElementById('warning-settings');
const authSession = document.getElementById('auth-session'); const authSession = document.getElementById('auth-session');
const refetchTitleButton = document.getElementById('refetch-title');
const sessionStore = browser.storage.session;
const t = window.linklogI18n; const t = window.linklogI18n;
@@ -34,20 +36,63 @@ async function hasBackendPermission(backendUrl) {
return browser.permissions.contains({origins: [`${origin}/*`]}); return browser.permissions.contains({origins: [`${origin}/*`]});
} }
// Splits on \n into real <br> line breaks without using innerHTML.
function setStatus(message, isError = false) { function setStatus(message, isError = false) {
statusEl.textContent = message; const lines = message.split('\n');
statusEl.replaceChildren(
...lines.flatMap((line, index) => (
index === 0 ? [document.createTextNode(line)] : [document.createElement('br'), document.createTextNode(line)]
)),
);
statusEl.classList.remove('hidden'); statusEl.classList.remove('hidden');
statusEl.classList.toggle('error', isError); statusEl.classList.toggle('error', isError);
statusEl.classList.toggle('success', !isError); statusEl.classList.toggle('success', !isError);
} }
async function getSettings() { async function getSettings() {
const result = await browser.storage.local.get([ const [settings, sessionSettings] = await Promise.all([
'backendUrl', browser.storage.local.get(['backendUrl', 'username']),
'accessToken', sessionStore.get(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
'tokenExpiresAt',
]); ]);
return result; return {...settings, ...sessionSettings};
}
async function persistSession(settings) {
await sessionStore.set({
accessToken: settings.accessToken,
refreshToken: settings.refreshToken,
tokenExpiresAt: settings.tokenExpiresAt,
deviceId: settings.deviceId,
});
}
async function clearSession() {
await Promise.all([
sessionStore.remove(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
browser.storage.local.remove(['accessToken', 'tokenType', 'tokenExpiresAt', 'refreshToken', 'deviceId']),
]);
}
async function refreshAccessToken(settings) {
if (!settings.backendUrl || !settings.refreshToken || !settings.deviceId) return null;
try {
const response = await fetch(`${settings.backendUrl}/api/auth/refresh`, {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({refresh_token: settings.refreshToken, device_id: settings.deviceId}),
});
if (!response.ok) {
await clearSession();
return null;
}
const data = await response.json();
const refreshed = {...settings, accessToken: data.access_token, refreshToken: data.refresh_token,
tokenExpiresAt: data.expires_at, deviceId: data.device_id || settings.deviceId};
await persistSession(refreshed);
return refreshed;
} catch (error) {
return null;
}
} }
async function validateSession(settings) { async function validateSession(settings) {
@@ -57,7 +102,16 @@ async function validateSession(settings) {
headers: {'Authorization': `Bearer ${settings.accessToken}`}, headers: {'Authorization': `Bearer ${settings.accessToken}`},
}); });
if (!response.ok) { if (!response.ok) {
await browser.storage.local.remove(['accessToken', 'tokenType', 'tokenExpiresAt', 'refreshToken']); if (response.status === 401) {
const refreshed = await refreshAccessToken(settings);
if (refreshed) {
const retry = await fetch(`${refreshed.backendUrl}/api/auth/me`, {
headers: {'Authorization': `Bearer ${refreshed.accessToken}`},
});
if (retry.ok) return await retry.json();
}
}
await clearSession();
return null; return null;
} }
return await response.json(); return await response.json();
@@ -97,7 +151,7 @@ function showSavedState(message) {
} }
async function updateFeedLink() { async function updateFeedLink() {
const settings = await browser.storage.local.get(['backendUrl', 'username', 'accessToken']); const settings = await getSettings();
if (!settings.backendUrl || !settings.username || !settings.accessToken) return; if (!settings.backendUrl || !settings.username || !settings.accessToken) return;
try { try {
const backend = new URL(settings.backendUrl); const backend = new URL(settings.backendUrl);
@@ -119,9 +173,10 @@ async function loadExistingTags() {
showSignedOutState(); showSignedOutState();
return; return;
} }
showSignedInState(user, settings.backendUrl); const currentSettings = await getSettings();
const response = await fetch(`${settings.backendUrl}/api/tags`, { showSignedInState(user, currentSettings.backendUrl);
headers: {'Authorization': `Bearer ${settings.accessToken}`}, const response = await fetch(`${currentSettings.backendUrl}/api/tags`, {
headers: {'Authorization': `Bearer ${currentSettings.accessToken}`},
}); });
if (!response.ok) { if (!response.ok) {
if (response.status === 401) { if (response.status === 401) {
@@ -177,20 +232,54 @@ async function checkExistingLink() {
const settings = await getSettings(); const settings = await getSettings();
if (!settings.backendUrl || !settings.accessToken || !(await hasBackendPermission(settings.backendUrl)) || !titleInput.value || !urlInput.value) return; if (!settings.backendUrl || !settings.accessToken || !(await hasBackendPermission(settings.backendUrl)) || !titleInput.value || !urlInput.value) return;
try { try {
const url = removeKnownTrackingParams(urlInput.value);
const response = await fetch(`${settings.backendUrl}/api/links/check?${new URLSearchParams({ const response = await fetch(`${settings.backendUrl}/api/links/check?${new URLSearchParams({
title: titleInput.value, title: titleInput.value,
url: removeKnownTrackingParams(urlInput.value), url,
})}`, { })}`, {
headers: {'Authorization': `Bearer ${settings.accessToken}`}, headers: {'Authorization': `Bearer ${settings.accessToken}`},
}); });
if (response.ok && (await response.json()).exists) { if (!response.ok) return;
setStatus(t('duplicateLinkWarning'), true); const data = await response.json();
if (data.exists) {
// Re-derive the match locally: browser URL normalization (e.g. trailing slashes) can
// make the server's raw string comparison disagree even when the URLs are equivalent.
const urlMatches = data.url_matches || (data.stored_url && removeKnownTrackingParams(data.stored_url) === url);
const message = urlMatches ? t('duplicateLinkSameUrl') : t('duplicateLinkDifferentUrl');
setStatus(message, true);
} }
} catch (error) { } catch (error) {
// Duplicate checking is advisory; submission remains available. // Duplicate checking is advisory; submission remains available.
} }
} }
// Re-fetch the title from the backend scraper, for when the URL was edited after the initial tab-based fill.
let lastScrapedUrl = null;
async function fetchTitle(url, { force = false } = {}) {
const settings = await getSettings();
if (!settings.backendUrl || !settings.accessToken || !(await hasBackendPermission(settings.backendUrl))) return;
if (!url || (!force && (titleInput.value.trim() || url === lastScrapedUrl))) return;
try {
const response = await fetch(`${settings.backendUrl}/api/scrape?url=${encodeURIComponent(url)}`, {
headers: {'Authorization': `Bearer ${settings.accessToken}`},
});
if (!response.ok) {
if (force) setStatus(t('titleFetchFailed'), true);
return;
}
lastScrapedUrl = url;
const data = await response.json();
if (data.title) {
titleInput.value = data.title;
} else if (force) {
setStatus(t('titleFetchFailed'), true);
}
} catch (error) {
if (force) setStatus(t('titleFetchFailed'), true);
}
}
async function handleSubmit(event) { async function handleSubmit(event) {
event.preventDefault(); event.preventDefault();
setStatus(t('submitting'), false); setStatus(t('submitting'), false);
@@ -212,12 +301,14 @@ async function handleSubmit(event) {
return; return;
} }
const currentSettings = await getSettings();
try { try {
const response = await fetch(`${backendUrl}/api/links`, { const response = await fetch(`${currentSettings.backendUrl}/api/links`, {
method: 'POST', method: 'POST',
headers: { headers: {
'Content-Type': 'application/json', 'Content-Type': 'application/json',
'Authorization': `Bearer ${token}`, 'Authorization': `Bearer ${currentSettings.accessToken}`,
}, },
body: JSON.stringify({ body: JSON.stringify({
title: titleInput.value, title: titleInput.value,
@@ -240,7 +331,7 @@ async function handleSubmit(event) {
} }
const result = await response.json(); const result = await response.json();
const saveMessage = result.duplicate ? t('linkAlreadyExists') : t('linkSaved', backendUrl); const saveMessage = result.duplicate ? t('linkAlreadyExists') : t('linkSaved', currentSettings.backendUrl);
if (result.plugin_errors?.length) { if (result.plugin_errors?.length) {
const errors = result.plugin_errors.map((error) => `${error.plugin}: ${error.reason}`).join(' '); const errors = result.plugin_errors.map((error) => `${error.plugin}: ${error.reason}`).join(' ');
showSavedState(`${saveMessage} ${t('publishingErrors', errors)}`); showSavedState(`${saveMessage} ${t('publishingErrors', errors)}`);
@@ -255,6 +346,21 @@ async function handleSubmit(event) {
openSettingsButton.addEventListener('click', () => browser.runtime.openOptionsPage()); openSettingsButton.addEventListener('click', () => browser.runtime.openOptionsPage());
warningSettingsButton.addEventListener('click', () => browser.runtime.openOptionsPage()); warningSettingsButton.addEventListener('click', () => browser.runtime.openOptionsPage());
form.addEventListener('submit', handleSubmit); form.addEventListener('submit', handleSubmit);
urlInput.addEventListener('blur', async () => {
await fetchTitle(removeKnownTrackingParams(urlInput.value.trim()));
checkExistingLink();
});
titleInput.addEventListener('blur', checkExistingLink);
refetchTitleButton.addEventListener('click', (e) => {
e.preventDefault();
const url = removeKnownTrackingParams(urlInput.value.trim());
if (!url) {
setStatus(t('titleFetchFailed'), true);
return;
}
titleInput.value = '';
fetchTitle(url, { force: true });
});
populateCurrentTab().then(checkExistingLink); populateCurrentTab().then(checkExistingLink);
loadExistingTags(); loadExistingTags();
updateFeedLink(); updateFeedLink();
+17 -1
View File
@@ -2,9 +2,25 @@
"addons": { "addons": {
"linklog@kolkman.org": { "linklog@kolkman.org": {
"updates": [ "updates": [
{
"version": "0.2.0",
"update_link": "https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.2.0.xpi",
"update_hash": "sha256:86619ec9aa35345c5c2bcad8fa5701762b8bd237ad9457b131404ff68bc2ce6b",
"applications": {
"gecko": {
"strict_min_version": "142.0"
}
}
},
{ {
"version": "0.1.0", "version": "0.1.0",
"update_link": "https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi" "update_link": "https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi",
"update_hash": "sha256:d95e23339facfa2a499bb35f9130d41739f622a3c0ac197ac3fd8cb76d6d6110",
"applications": {
"gecko": {
"strict_min_version": "142.0"
}
}
} }
] ]
} }