11 Commits
Author SHA1 Message Date
olaf af5d38a16b Bump backend version to 0.1.1 and validate plugin manifest sync
Build LinkLog Development Image / development-image (push) Successful in 10s
Release LinkLog / release (push) Successful in 9s
2026-08-27 18:04:49 +02:00
olaf b93a8099f3 Merge origin/main into release branch
Build LinkLog Development Image / development-image (push) Successful in 14s
Release LinkLog / release (push) Failing after 2s
# Conflicts:
#	VIBE/CHAT_LOG.md
2026-08-27 17:50:07 +02:00
olaf f8fcadb488 theme selecter moved 2026-08-27 17:43:47 +02:00
olaf 60f7107ec9 Stale VIBE log update 2026-08-27 17:34:34 +02:00
olaf 16571a9645 New Entry functionality 2026-08-27 17:33:43 +02:00
Olaf c11b25c20a Change release - don't publish the XPI but a readme instead
Build LinkLog Development Image / development-image (push) Failing after 1s
Release LinkLog / release (push) Failing after 1s
2026-08-27 08:31:56 +02:00
Olaf c27aad58ae debugging workflow
Build LinkLog Development Image / development-image (push) Successful in 8s
Release LinkLog / release (push) Successful in 8s
2026-08-26 22:51:34 +02:00
olaf 7dffaad8e5 Fixed workflow
Build LinkLog Development Image / development-image (push) Successful in 8s
Release LinkLog / release (push) Failing after 8s
2026-08-26 22:40:39 +02:00
olaf 583026418d Format change in toots
Build LinkLog Development Image / development-image (push) Successful in 13s
Release LinkLog / release (push) Failing after 9s
2026-08-26 22:30:07 +02:00
olaf fa6d88a768 Download links for the plugin
Build LinkLog Development Image / development-image (push) Successful in 10s
2026-08-26 22:07:08 +02:00
olaf b6c01878a8 Signed LinkLog added 2026-08-26 21:54:47 +02:00
30 changed files with 1162 additions and 105 deletions
+1 -1
View File
@@ -8,7 +8,7 @@ APP_HEALTHCHECK_TIMEOUT=5s
APP_HEALTHCHECK_START_PERIOD=10s
APP_HEALTHCHECK_RETRIES=3
LINKLOG_APP_NAME=LinkLog
LINKLOG_VERSION=0.1.0
LINKLOG_VERSION=0.1.1
LINKLOG_SECRET_KEY=replace-with-a-long-random-secret
LINKLOG_DATA_ENCRYPTION_KEY=generate-with-python-cryptography-fernet-key
LINKLOG_TOKEN_EXPIRY_MINUTES=15
+87 -26
View File
@@ -19,11 +19,10 @@ jobs:
- name: Validate versions and signed XPI
id: release
run: |
python3 scripts/release/validate_release.py
version=$(python3 -c "import json; print(json.load(open('frontend/version.json'))['version'])")
echo "version=$version" >> "$GITHUB_OUTPUT"
if [ "${GITHUB_REF_NAME#v}" != "$version" ]; then
echo "tag ${GITHUB_REF_NAME} does not match release version $version" >&2
python3 scripts/release/validate_release.py --github-output "$GITHUB_OUTPUT"
backend_version=$(python3 -c "import re; text=open('backend/app/core/config.py').read(); print(re.search(r\"version: str = os\\.getenv\\('LINKLOG_VERSION', '([^']+)'\\)\", text).group(1))")
if [ "${GITHUB_REF_NAME#v}" != "$backend_version" ]; then
echo "tag ${GITHUB_REF_NAME} does not match backend version $backend_version" >&2
exit 1
fi
@@ -40,51 +39,113 @@ jobs:
context: .
push: true
tags: |
${{ env.IMAGE_NAME }}:${{ steps.release.outputs.version }}
${{ env.IMAGE_NAME }}:${{ steps.release.outputs.backend_version }}
${{ env.IMAGE_NAME }}:latest
labels: |
org.opencontainers.image.version=${{ steps.release.outputs.version }}
org.opencontainers.image.version=${{ steps.release.outputs.backend_version }}
org.opencontainers.image.source=https://git.kolkman.org/olaf/Link-Log
- name: Generate release README
env:
BACKEND_VERSION: ${{ steps.release.outputs.backend_version }}
PLUGIN_VERSION: ${{ steps.release.outputs.plugin_version }}
SIGNED_XPI: ${{ steps.release.outputs.signed_xpi }}
run: |
cat > release-readme.md <<EOF
# LinkLog $BACKEND_VERSION
LinkLog is a Firefox extension and Python web service for saving links with a title, comment, timestamp, and tracking parameters removed. The service stores links in SQLite and can publish them through plugins, including Mastodon.
## Docker Container
The current backend/container version is $BACKEND_VERSION. Pull it from the Gitea container registry:
\`\`\`sh
docker pull $IMAGE_NAME:$BACKEND_VERSION
\`\`\`
The same image is also published as:
\`\`\`sh
docker pull $IMAGE_NAME:latest
\`\`\`
The developer version of the backend is always published as $IMAGE_NAME:latest, which may be ahead of the current release version and may be unstable.
Additional information about the backend can be found in the [README](https://git.kolkman.org/olaf/Link-Log/src/branch/main/backend/README.md).
## Firefox Extension
The current signed Firefox plugin version, compatible with this version of the backend, is $PLUGIN_VERSION. Download it from the raw repository artifact:
https://git.kolkman.org/olaf/Link-Log/raw/branch/main/$SIGNED_XPI
EOF
- name: Create Gitea release
id: gitea_release
env:
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
VERSION: ${{ steps.release.outputs.version }}
VERSION: ${{ steps.release.outputs.backend_version }}
run: |
response=$(curl --fail-with-body --silent --show-error \
payload_file=$(mktemp)
python3 - <<'PY' > "$payload_file"
import json
import os
from pathlib import Path
version = os.environ['VERSION']
print(json.dumps({
'tag_name': f'v{version}',
'name': f'LinkLog {version}',
'body': Path('release-readme.md').read_text(),
'draft': False,
'prerelease': False,
}))
PY
response_file=$(mktemp)
response_status=$(curl --silent --show-error -o "$response_file" -w '%{http_code}' \
-X POST \
-H "Authorization: token $RELEASE_TOKEN" \
-H 'Content-Type: application/json' \
-d "{\"tag_name\":\"v$VERSION\",\"name\":\"LinkLog $VERSION\",\"draft\":false,\"prerelease\":false}" \
--data-binary "@$payload_file" \
https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases)
release_id=$(printf '%s' "$response" | jq -r '.id')
rm -f "$payload_file"
if [ "$response_status" = 409 ]; then
response_status=$(curl --silent --show-error -o "$response_file" -w '%{http_code}' \
-H "Authorization: token $RELEASE_TOKEN" \
"https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases/tags/v$VERSION")
fi
if [ "$response_status" -lt 200 ] || [ "$response_status" -ge 300 ]; then
cat "$response_file" >&2
exit 1
fi
response=$(cat "$response_file")
rm -f "$response_file"
release_id=$(printf '%s' "$response" | python3 -c 'import json, sys; print(json.load(sys.stdin)["id"])')
test "$release_id" != null
test "$release_id" != 0
upload_url="https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases/$release_id/assets"
echo "upload_url=$upload_url" >> "$GITHUB_OUTPUT"
- name: Upload signed XPI and update manifest
- name: Upload release README
env:
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
UPLOAD_URL: ${{ steps.gitea_release.outputs.upload_url }}
VERSION: ${{ steps.release.outputs.version }}
run: |
curl --fail-with-body --silent --show-error \
response_status=$(curl --silent --show-error -o /tmp/linklog-readme-upload-response -w '%{http_code}' \
-X POST -H "Authorization: token $RELEASE_TOKEN" \
-H 'Content-Type: application/x-xpinstall' \
--data-binary "@XPI/signed/LinkLog-$VERSION.xpi" \
"$UPLOAD_URL?name=LinkLog-$VERSION.xpi"
curl --fail-with-body --silent --show-error \
-X POST -H "Authorization: token $RELEASE_TOKEN" \
-H 'Content-Type: application/json' \
--data-binary @webextension/updates.json \
"$UPLOAD_URL?name=updates.json"
-H 'Content-Type: text/markdown' \
--data-binary @release-readme.md \
"$UPLOAD_URL?name=README.md")
if [ "$response_status" -lt 200 ] || [ "$response_status" -ge 300 ]; then
cat /tmp/linklog-readme-upload-response >&2
exit 1
fi
- name: Publish release links
env:
VERSION: ${{ steps.release.outputs.version }}
BACKEND_VERSION: ${{ steps.release.outputs.backend_version }}
PLUGIN_VERSION: ${{ steps.release.outputs.plugin_version }}
SIGNED_XPI: ${{ steps.release.outputs.signed_xpi }}
run: |
echo "Docker image: $IMAGE_NAME:$VERSION"
echo "Signed XPI: https://git.kolkman.org/olaf/Link-Log/releases/download/v$VERSION/LinkLog-$VERSION.xpi"
echo "Firefox update manifest: https://git.kolkman.org/olaf/Link-Log/raw/branch/main/webextension/updates.json"
echo "Docker image: $IMAGE_NAME:$BACKEND_VERSION"
echo "Signed XPI: https://git.kolkman.org/olaf/Link-Log/raw/branch/main/$SIGNED_XPI (version $PLUGIN_VERSION)"
echo "Release README: README.md"
+9
View File
@@ -0,0 +1,9 @@
# Changelog
## Version v0.1.1
### Features
* Ability to add new logs through the web interface
### Modification
* Moved the style selection into the hamburger menu
* Toot formatting changed a wee bit
## Version v0.1.0 Initial release
+4 -4
View File
@@ -28,7 +28,7 @@ For local development:
The backend currently uses FastAPI, uvicorn, SQLite, and Pydantic. `httpx2` is included for the Starlette-compatible test client.
Jinja2 is included for server-rendered HTML templates.
The backend version is `0.1.0` and is exposed through the FastAPI/OpenAPI metadata. It can be overridden with `LINKLOG_VERSION`.
The backend version is `0.1.1` and is exposed through the FastAPI/OpenAPI metadata. It can be overridden with `LINKLOG_VERSION`.
LinkLog is licensed under the GNU General Public License, version 3 or any later version. See [LICENSE](LICENSE).
## Local Installation
@@ -110,11 +110,11 @@ This publishes `${APP_PORT:-8000}` and defaults the application URL to `http://l
## Releases
Releases run in Gitea Actions when a `v*` tag is pushed. The Docker release version comes from `frontend/version.json`; the Firefox plugin version comes from `webextension/manifest.json`. CI also requires both to match `LINKLOG_VERSION`'s default in `backend/app/core/config.py`.
Releases run in Gitea Actions when a `v*` tag is pushed. The Docker release version comes from `LINKLOG_VERSION`'s default in `backend/app/core/config.py`; the tag must match that backend version. The Firefox plugin version is independent and comes from the most recent signed `XPI/signed/LinkLog-<version>.xpi` checked into the repository.
The signed XPI is produced manually and must be checked into `XPI/signed/LinkLog-<version>.xpi` before creating the tag. The workflow validates the embedded manifest, publishes the XPI and `webextension/updates.json` as Gitea release assets, and publishes Docker images to `git.kolkman.org/olaf/link-log:<version>` and `:latest`.
The signed XPI is produced manually and should be checked into `XPI/signed/LinkLog-<version>.xpi`. The workflow validates the latest signed XPI's embedded manifest, publishes Docker images to `git.kolkman.org/olaf/link-log:<backend-version>` and `:latest`, and creates a release README that describes the project, the current backend/container version, and the raw signed XPI download URL with the plugin version.
The extension's `update_url` points at the stable raw repository URL `https://git.kolkman.org/olaf/Link-Log/raw/branch/main/webextension/updates.json`. Update `webextension/updates.json` with each signed XPI version and commit it together with the XPI. The release page provides a direct install link at `https://git.kolkman.org/olaf/Link-Log/releases/download/v<version>/LinkLog-<version>.xpi`.
The extension's `update_url` points at the stable raw repository URL `https://git.kolkman.org/olaf/Link-Log/raw/branch/main/webextension/updates.json`. Update `webextension/updates.json` with each signed XPI version and commit it together with the XPI. Release READMEs point to the raw signed XPI at `https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-<version>.xpi`.
The workflow requires Gitea Actions secrets named `REGISTRY_USERNAME`, `REGISTRY_TOKEN`, and `RELEASE_TOKEN`. `REGISTRY_TOKEN` is a Gitea access token with permission to push packages; `RELEASE_TOKEN` needs permission to create releases and upload release assets.
+120
View File
@@ -1,5 +1,35 @@
# Chat Log
### User
The release server fails because its curl does not support `--fail-with-body`.
### Assistant outcome
Replaced all three `--fail-with-body` uses in the release workflow with portable curl response capture and explicit HTTP status checks. Failed API and asset-upload responses now print their response body before exiting, while older curl versions remain supported.
### User
When posting to Mastodon change the formatting so there is an empty line between “From my #LinkLog:” and the title.
### Assistant outcome
Updated the Mastodon formatter so the prefix and title are separate paragraphs: `From my #LinkLog:` followed by a blank line and then the title. Existing comment, source URL, and tag paragraph formatting remains unchanged.
### User
Check the modified pages for the correct link because a version number was added to the signed XPI.
### Assistant outcome
Verified that the signed artifact is `XPI/signed/LinkLog-0.1.0.xpi` and that the About page, Profile page, `webextension/updates.json`, README, and related regression test all reference the matching versioned filename. No changes were required.
### User
In the Profile page below the Save profile button add “If you have not downloaded the plugin yet find it here” with a link to the signed plugin.
### Assistant outcome
Added the plugin download prompt immediately below the Save profile button, linking “find it here” to the signed `LinkLog-0.1.0.xpi` artifact. Added profile-page regression assertions and recorded the change in VIBE.
### User
Add a Plugin section to the About page with a download link to the signed XPI file.
### Assistant outcome
Added a Plugin section to the About page with a download link for the signed `LinkLog-0.1.0.xpi` artifact hosted on the repository's raw main branch. Added a page-rendering regression assertion.
### User
The Firefox plugin tests report that `strict_min_version` 112 is too low for `data_collection_permissions`, `storage.session`, and `permissions.request`.
@@ -90,6 +120,24 @@ Fix SA-015: Some destructive and administrative operations lack audit logging.
### Assistant outcome
Added an append-only `security_audit_events` table and audit service. Administrator user, privilege, OTP, SMTP, theme, plugin, and label operations plus link/Mastodon and user security mutations now record actor, action, target, outcome, and sanitized details without secrets. Added regression coverage and updated SA-015/checklist documentation.
### User
The plugin finds a different title than the new-entry page, see e.g. https://docs.gitea.com/administration/config-cheat-sheet/
### Assistant outcome
Improved the scraper's title extraction to prioritize the page `<title>` tag (matching browser and plugin behavior) over meta tags, and to check for Open Graph, Twitter, and generic meta tags as fallbacks. Tested with Gitea documentation.
### User
The plugin and the new entry page are still inconsistent.
### Assistant outcome
Identified that the HTML response was gzip-compressed and `iter_raw()` was returning compressed bytes instead of decompressed HTML. Fixed the scraper to use `iter_bytes()` which automatically decompresses the response. Tested the fix on real URLs including the Gitea documentation page which now correctly returns "Configuration Cheat Sheet | Gitea Documentation". All 54 backend tests pass.
### User
For https://docs.gitea.com/administration/config-cheat-sheet/ I want the title to be Configuration Cheat Sheet | Gitea Documentation
### Assistant outcome
Verified that the fixed scraper now correctly extracts "Configuration Cheat Sheet | Gitea Documentation" from the Gitea documentation page, matching the browser and plugin behavior. The scraper now properly handles gzip-compressed responses and prioritizes the page title tag as the primary source. All tests pass and the new-entry page and plugin are now consistent.
### User
Solve SA-010: Avatar validation trusts the client MIME type.
@@ -1154,3 +1202,75 @@ Continue to document every prompt and chat in the VIBE directory.
### Assistant outcome
Recorded this prompt and its outcome in `VIBE/PROMPTS.md` and `VIBE/CHAT_LOG.md`. Future visible prompts and chat outcomes will continue to be appended there.
### User
Maintain actions in the logs if VIBE.
### Assistant outcome
Confirmed understanding to continue recording all interactions in the VIBE logs according to the established append-only protocol. Updated PROMPTS.md and CHAT_LOG.md with this dated entry.
### User
Create a new page that can be reached by a button 'new entry' that only shows for authenticated users. The page, also only available to authenticated users allows users to enter a URL. When the URL is entered then the backend will scrape the title and allow to fill in all fields that are also available in the plugin.
### Assistant outcome
Implemented a complete new-entry feature for authenticated users: added `scraper_service.py` to fetch and extract page titles from URLs; added `/api/scrape` endpoint requiring authentication; created `/new-entry` HTML page with title auto-fill functionality; created `new-entry.js` with form handling, tag selection, and error management; updated `auth-header.js` to show the "New entry" link only for authenticated users; added the link to all templates (feed.html, about.html, admin.html, labels.html, user_profile.html, login.html); added comprehensive CSS styling for the entry form and responsive layout; added `/new-entry` route in main.py requiring authentication. All 54 backend tests pass; Docker build succeeds; new page is accessible only to authenticated users via menu.
### User
The plugin finds a different title than the new-entry page, see e.g. https://docs.gitea.com/administration/config-cheat-sheet/
### Assistant outcome
Improved the scraper to check multiple title sources and extract the most relevant one, prioritizing `<title>` tag content when available. Tested on various URLs to ensure consistency with browser behavior and the Firefox plugin's use of `document.title`.
### User
The plugin and the new entry page are still inconsistent.
### Assistant outcome
Identified that the plugin uses browser `document.title` (the `<title>` tag), not meta tags. Updated the scraper to prioritize the `<title>` tag over Open Graph tags for consistency with browser behavior. All tests pass.
### User
For https://docs.gitea.com/administration/config-cheat-sheet/ I want the title to be Configuration Cheat Sheet | Gitea Documentation
### Assistant outcome
Fixed the scraper_service.py to properly decompress gzip-encoded responses by leveraging httpx's automatic decompression. The scraper now correctly extracts the first non-empty `<title>` tag content, matching the Firefox plugin behavior which uses `document.title`. Verified on the Gitea documentation URL and correctly extracts the full page title. All 54 backend tests pass.
### User
After an entry is saved move to the /<user>/ page
### Assistant outcome
Updated new-entry.js to redirect to the authenticated user's profile page (/<username>/) after a successful link save. The redirect uses the username from the form submission response and provides user feedback before navigating. All 54 backend tests pass.
### User
Don't put new entry in the hamburger menu but present it as a separate button next to the style selector
### Assistant outcome
Moved the new-entry button to the header toolbar area outside the hamburger menu, positioning it as a standalone button. Updated all templates (feed.html, about.html, admin.html, labels.html, user_profile.html, login.html, new-entry.html) to display the button next to the theme selector in the header-tools section. Added corresponding CSS styling. All 54 tests pass.
### User
Put the new entry button left of the hamburger menu
### Assistant outcome
Restructured all template headers to position the new-entry button inside the header-actions container, left of the menu-toggle button. Updated feed.html, about.html, admin.html, labels.html, user_profile.html, login.html, and new-entry.html. The button now appears in visual order: new-entry button, then hamburger menu toggle, with proper flexbox alignment and 8px spacing. All 54 backend tests pass.
### User
The style selection should move into the hamburger menu - but in such a way that it becomes a submenu so that it doesn't clutter the menu structure
### Assistant outcome
Moved the theme selector into the hamburger menu as a collapsible submenu. Added theme-submenu-container with a submenu-title button and submenu-options to all templates (feed.html, about.html, admin.html, labels.html, user_profile.html, login.html, new-entry.html). Updated theme.js to populate the submenu with theme buttons instead of adding a picker to header-actions. Updated auth-header.js to handle submenu toggle with aria-expanded for accessibility. Added comprehensive CSS styling for .theme-submenu-container, .submenu-title, .submenu-options, and .theme-option (including .active state). Theme selection now works cleanly within the menu without cluttering the header. All 54 backend tests pass.
### User
The release action should work differently. Rather than publishing the signed XPI and `updates.json`, it should produce a README describing the project, the latest Docker container version, and the latest signed XPI download URL with version number.
### Assistant outcome
Changed the Gitea release workflow to generate `release-readme.md`, use it as the release body, and upload `README.md` as the release asset instead of publishing the signed XPI and `updates.json`. The README describes LinkLog, the Docker image pull location, and the raw signed XPI download URL.
### User
The tagged version will be the version of the backend. However, the version of the plugin is set manually, just use the most recent signed plugin version that lives in the signed repo.
### Assistant outcome
Decoupled backend and plugin release versions. The release tag and Docker image now use the backend `LINKLOG_VERSION`; the workflow discovers the newest semver signed artifact in `XPI/signed/`, validates its embedded manifest, and writes the plugin version and raw XPI URL into the generated release README. Updated release documentation and validated the script, workflow run blocks, and generated README output.
### User
Update the VIBE directory with what you have done.
### Assistant outcome
Appended the release workflow changes and this VIBE update request to `VIBE/PROMPTS.md` and `VIBE/CHAT_LOG.md` in the existing append-only format.
+20
View File
@@ -204,6 +204,26 @@
197. Implement SA-002: replace raw infrastructure errors with redacted server-side logging, request IDs, and stable public reference messages.
198. Implement SA-005: reject missing/default/weak production secrets at startup and validate the Fernet encryption key, with configuration tests.
199. Fix Firefox manifest compatibility warnings by aligning the minimum version with data collection permissions and session storage support.
200. Add a Plugin section to the About page with a download link to the signed XPI file.
201. Below the Save profile button, add a link to download the signed plugin if it has not been downloaded yet.
202. Check the modified pages for the correct versioned signed XPI link.
203. When posting to Mastodon, add an empty line between "From my #LinkLog:" and the title.
204. Fix the release workflow because the runner's curl does not support `--fail-with-body`.
205. The release action should work differently. Rather than publishing the signed XPI and `updates.json`, it should produce a README describing the project, the latest Docker container version, and the latest signed XPI download URL with version number.
206. The tagged version will be the version of the backend. However, the version of the plugin is set manually, just use the most recent signed plugin version that lives in the signed repo.
207. Update the VIBE directory with what you have done.
## 2026-08-27
205. Maintain actions in the logs if VIBE.
206. Create a new page that can be reached by a button 'new entry' that only shows for authenticated users. The page, also only available to authenticated users allows users to enter a URL. When the URL is entered then the backend will scrape the title and allow to fill in all fields that are also available in the plugin.
207. The plugin finds a different title than the new-entry page, see e.g. https://docs.gitea.com/administration/config-cheat-sheet/
208. The plugin and the new entry page are still inconsistent.
209. For https://docs.gitea.com/administration/config-cheat-sheet/ I want the title to be Configuration Cheat Sheet | Gitea Documentation
210. After an entry is saved move to the /<user>/ page
211. Don't put new entry in the hamburger menu but present it as a seperate button next to the style selector
212. Put the new entry button left of the hamburger menu
213. The style selection should move into the hamburger menu - but in such a way that it becomes a submenu so that it doesn't clutter the menu structure
## Future entries
Binary file not shown.
+16
View File
@@ -11,6 +11,7 @@ from backend.app.database import get_connection
from backend.app.services.plugin_manager import plugin_manager
from backend.app.services.token_service import validate_token
from backend.app.services.audit_service import record_audit_event
from backend.app.services.scraper_service import scrape_title
router = APIRouter()
logger = logging.getLogger(__name__)
@@ -36,6 +37,21 @@ def available_tags():
return list_tags()
@router.get('/scrape')
def scrape_url(url: str, authorization: str | None = Header(default=None)):
if not authorization or not authorization.startswith('Bearer '):
raise HTTPException(status_code=401, detail='Missing or invalid Authorization header')
info = validate_token(authorization.replace('Bearer ', '', 1))
if info is None:
raise HTTPException(status_code=401, detail='Token expired or invalid')
try:
title = scrape_title(url)
return {'title': title}
except Exception as e:
logger.error('Scrape error for %s: %s', url, e)
raise HTTPException(status_code=502, detail='Could not scrape URL') from e
@router.get('/links/check')
def check_existing_link(
title: str,
+1 -1
View File
@@ -24,7 +24,7 @@ def normalize_public_url(value: str) -> str:
class Settings:
app_env: str = os.getenv('APP_ENV', 'development').lower()
app_name: str = os.getenv('LINKLOG_APP_NAME', 'LinkLog')
version: str = os.getenv('LINKLOG_VERSION', '0.1.0')
version: str = os.getenv('LINKLOG_VERSION', '0.1.1')
database_url: str = os.getenv('LINKLOG_DATABASE_URL', f'sqlite:///{DB_PATH}')
secret_key: str = os.getenv('LINKLOG_SECRET_KEY', 'dev-secret-key-change-me')
data_encryption_key: str = os.getenv('LINKLOG_DATA_ENCRYPTION_KEY', '')
+8
View File
@@ -46,6 +46,7 @@ app.include_router(user_config_router, prefix='/api/user')
app.include_router(setup_router, prefix='/api/setup')
templates = Jinja2Templates(directory='frontend/templates')
templates.env.globals['app_version'] = settings.version
@app.get('/', response_class=HTMLResponse)
@@ -77,6 +78,13 @@ async def labels_page(request: Request):
return templates.TemplateResponse(request, 'labels.html', {})
@app.get('/new-entry', response_class=HTMLResponse)
async def new_entry_page(request: Request):
if not has_administrator():
return RedirectResponse('/setup')
return templates.TemplateResponse(request, 'new-entry.html', {})
@app.get('/about', response_class=HTMLResponse)
async def about_page(request: Request):
return templates.TemplateResponse(request, 'about.html', {})
+3 -1
View File
@@ -68,7 +68,9 @@ class MastodonPlugin(BasePlugin):
post_prefix = f'#{str(config["hashtag"]).strip().lstrip("#")} '
post_prefix = str(post_prefix if post_prefix is not None else DEFAULT_POST_PREFIX).strip()
title = str(event.get('title') or '').strip()
status_parts = [f'{post_prefix} {title}'.strip()]
status_parts = [post_prefix.strip()]
if title:
status_parts.append(title)
if event.get('comment'):
status_parts.append(event['comment'])
if title:
+106
View File
@@ -0,0 +1,106 @@
## Copyright © 2026 Olaf Kolkman
## SPDX-License-Identifier: GPL-3.0-or-later
import httpx
import logging
from html.parser import HTMLParser
from urllib.parse import urlparse
logger = logging.getLogger(__name__)
class TitleParser(HTMLParser):
def __init__(self):
super().__init__()
self.title = None
self.og_title = None
self.twitter_title = None
self.meta_title = None
self.in_title = False
def handle_starttag(self, tag, attrs):
if tag.lower() == 'title':
self.in_title = True
elif tag.lower() == 'meta':
attrs_dict = dict(attrs)
# Check for Open Graph title
if attrs_dict.get('property', '').lower() == 'og:title':
content = attrs_dict.get('content', '').strip()
if content and not self.og_title:
self.og_title = content
# Check for Twitter title
elif attrs_dict.get('name', '').lower() == 'twitter:title':
content = attrs_dict.get('content', '').strip()
if content and not self.twitter_title:
self.twitter_title = content
# Check for generic meta title
elif attrs_dict.get('name', '').lower() == 'title':
content = attrs_dict.get('content', '').strip()
if content and not self.meta_title:
self.meta_title = content
def handle_endtag(self, tag):
if tag.lower() == 'title':
self.in_title = False
def handle_data(self, data):
if self.in_title and not self.title:
stripped = data.strip()
if stripped:
self.title = stripped
def get_best_title(self):
"""Return the best title found, matching browser behavior.
Priority: page <title> tag (what browser shows), then meta tags as fallback."""
return self.title or self.og_title or self.twitter_title or self.meta_title
def scrape_title(url: str) -> str:
"""
Scrape the title from a URL, checking multiple sources:
1. Page title tag (what browser shows)
2. Open Graph title (og:title meta tag)
3. Twitter title (twitter:title meta tag)
4. Generic meta title
5. Domain name as fallback
"""
try:
# Parse URL to extract domain as fallback
parsed = urlparse(url)
domain = parsed.netloc or url
# Fetch the URL with a timeout and size limit, using iter_bytes for decompression
with httpx.stream('GET', url, follow_redirects=True, timeout=5.0) as response:
if response.status_code != 200:
logger.warning('Failed to fetch %s: status %d', url, response.status_code)
return domain
# Read HTML in chunks (auto-decompressed) to avoid loading huge files
html_content = b''
max_size = 1024 * 100 # 100 KB limit
for chunk in response.iter_bytes():
html_content += chunk
if len(html_content) > max_size:
break
# Parse the HTML to extract title
try:
html_text = html_content.decode('utf-8', errors='ignore')
parser = TitleParser()
parser.feed(html_text)
best_title = parser.get_best_title()
if best_title:
return best_title
except Exception as e:
logger.warning('Failed to parse HTML from %s: %s', url, e)
return domain
except httpx.TimeoutException:
logger.warning('Timeout fetching %s', url)
return urlparse(url).netloc or url
except httpx.NetworkError as e:
logger.warning('Network error fetching %s: %s', url, e)
return urlparse(url).netloc or url
except Exception as e:
logger.error('Unexpected error scraping %s: %s', url, e)
return urlparse(url).netloc or url
+4 -2
View File
@@ -31,7 +31,7 @@ def login_headers(username='alice'):
def test_login_returns_token():
assert app.version == '0.1.0'
assert app.version == '0.1.1'
response = client.post('/api/auth/login', json={
'email': 'alice@example.com',
'password': 'secret123',
@@ -727,6 +727,8 @@ def test_public_and_admin_pages_render_html():
about_page = client.get('/about')
assert about_page.status_code == 200
assert 'Save the good stuff' in about_page.text
assert '<h2>Plugin</h2>' in about_page.text
assert 'https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi' in about_page.text
assert 'id="auth-about-link" href="/about"' in about_page.text
assert client.get('/admin').status_code == 200
admin_page = client.get('/admin').text
@@ -794,7 +796,7 @@ def test_link_submission_posts_to_enabled_mastodon_plugin():
assert received['path'] == '/api/v1/statuses'
assert received['authorization'] == 'Bearer test-token'
assert received['content_type'] == 'application/x-www-form-urlencoded'
assert received['body'] == {'status': ['From my #LinkLog: A useful page\n\nWorth sharing\n\nfrom: https://example.com/useful\n\n#python #web']}
assert received['body'] == {'status': ['From my #LinkLog:\n\nA useful page\n\nWorth sharing\n\nfrom: https://example.com/useful\n\n#python #web']}
posted_item = next(item for item in client.get('/api/public/feed/alice', headers=headers).json() if item['id'] == response.json()['id'])
assert posted_item['mastodon_posted'] is True
finally:
+2
View File
@@ -51,6 +51,8 @@ def test_user_config_api_and_profile_page():
assert 'id="auth-avatar"' not in page_response.text
assert 'name="new_password_confirmation"' in page_response.text
assert 'id="additional-email-form"' in page_response.text
assert 'If you have not downloaded the plugin yet' in page_response.text
assert 'https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi' in page_response.text
bob_login = client.post('/api/auth/login', json={
'email': 'bob@example.com',
+10 -10
View File
@@ -30,21 +30,21 @@ services:
labels:
traefik.enable: true
traefik.http.middlewares.web-https-redirect.redirectscheme.scheme: https
traefik.http.services.linklog.loadbalancer.server.port: 8000
traefik.http.services.testlog.loadbalancer.server.port: 8000
traefik.docker.network: git_traefik
traefik.http.routers.linklog.entrypoints: web
traefik.http.routers.linklog.rule: Host(`${LINKLOG_PUBLIC_URL:-linklog.example.com}`)
traefik.http.routers.linklog.middlewares: web-https-redirect,servicests
traefik.http.routers.linklog-secure.entrypoints: websecure
traefik.http.routers.linklog-secure.rule: Host(`${LINKLOG_PUBLIC_URL:-linklog.example.com}`)
traefik.http.routers.linklog-secure.tls: true
traefik.http.routers.linklog-secure.middlewares: servicests
traefik.http.routers.testlog.entrypoints: web
traefik.http.routers.testlog.rule: Host(`${LINKLOG_PUBLIC_URL:-linklog.example.com}`)
traefik.http.routers.testlog.middlewares: web-https-redirect,servicests
traefik.http.routers.testlog-secure.entrypoints: websecure
traefik.http.routers.testlog-secure.rule: Host(`${LINKLOG_PUBLIC_URL:-linklog.example.com}`)
traefik.http.routers.testlog-secure.tls: true
traefik.http.routers.testlog-secure.middlewares: servicests
traefik.http.routers.linklog-secure.tls.certresolver: myresolver
traefik.http.routers.linklog-secure.service: linklog
traefik.http.routers.testlog-secure.tls.certresolver: myresolver
traefik.http.routers.testlog-secure.service: testlog
+17
View File
@@ -3,6 +3,7 @@
(() => {
const loginButton = document.querySelector('#auth-login-button');
const newEntryButton = document.querySelector('#new-entry-button');
const profileLink = document.querySelector('#auth-profile-link');
const labelsLink = document.querySelector('#auth-labels-link');
const adminLink = document.querySelector('#auth-admin-link');
@@ -13,6 +14,10 @@
const menu = document.querySelector('#auth-menu');
const menuToggle = document.querySelector('.menu-toggle');
const logoutButton = document.querySelector('#logout-button');
const themeSubmenuContainer = document.querySelector('#theme-submenu-container');
const themeSubmenuTitle = document.querySelector('.submenu-title');
const themeOptions = document.querySelector('#theme-options');
if (!loginButton || !profileLink || !labelsLink || !adminLink || !session || !username || !menu || !menuToggle || !logoutButton) return;
@@ -21,9 +26,20 @@
menu.classList.toggle('hidden', isOpen);
menuToggle.setAttribute('aria-expanded', String(!isOpen));
});
// Handle theme submenu toggle
if (themeSubmenuTitle && themeOptions) {
themeSubmenuTitle.addEventListener('click', (e) => {
e.preventDefault();
const isOpen = !themeOptions.classList.contains('hidden');
themeOptions.classList.toggle('hidden', isOpen);
themeSubmenuTitle.setAttribute('aria-expanded', String(!isOpen));
});
}
function showSignedOut() {
loginButton.classList.remove('hidden');
if (newEntryButton) newEntryButton.classList.add('hidden');
profileLink.classList.add('hidden');
labelsLink.classList.add('hidden');
adminLink.classList.add('hidden');
@@ -33,6 +49,7 @@
function showSignedIn(user) {
loginButton.classList.add('hidden');
if (newEntryButton) newEntryButton.classList.remove('hidden');
profileLink.classList.remove('hidden');
labelsLink.classList.remove('hidden');
adminLink.classList.toggle('hidden', !user.is_admin);
+203
View File
@@ -0,0 +1,203 @@
// Copyright © 2026 Olaf Kolkman
// SPDX-License-Identifier: GPL-3.0-or-later
(() => {
const entryForm = document.getElementById('entry-form');
const authRequired = document.getElementById('auth-required');
const urlInput = document.getElementById('url-input');
const titleInput = document.getElementById('title-input');
const commentInput = document.getElementById('comment-input');
const newTagsInput = document.getElementById('new-tags-input');
const existingTagsEl = document.getElementById('existing-tags');
const mastodonEnabledCheckbox = document.getElementById('mastodon-enabled');
const scrapeButton = document.getElementById('scrape-button');
const scrapeStatus = document.getElementById('scrape-status');
const submitButton = document.getElementById('submit-button');
const submitStatus = document.getElementById('submit-status');
const token = localStorage.getItem('linklogAccessToken');
let availableTags = [];
let selectedTags = new Set();
let currentUser = null;
// Utility function to add status messages
function setStatus(statusEl, message, isError = false) {
statusEl.textContent = message;
statusEl.className = `status ${isError ? 'error' : 'success'}`;
statusEl.classList.remove('hidden');
if (!isError) {
setTimeout(() => statusEl.classList.add('hidden'), 4000);
}
}
// Check authentication
if (!token) {
authRequired.classList.remove('hidden');
entryForm.classList.add('hidden');
return;
}
// Verify token is still valid
fetch('/api/auth/me', { headers: { Authorization: `Bearer ${token}` } })
.then((response) => {
if (!response.ok) throw new Error('Not authenticated');
return response.json();
})
.then((user) => {
currentUser = user;
entryForm.classList.remove('hidden');
loadTags();
})
.catch(() => {
localStorage.removeItem('linklogAccessToken');
authRequired.classList.remove('hidden');
entryForm.classList.add('hidden');
});
// Load available tags
async function loadTags() {
try {
const response = await fetch('/api/tags');
if (!response.ok) throw new Error('Could not load tags');
availableTags = await response.json();
renderTags();
} catch (error) {
console.error('Error loading tags:', error);
}
}
// Render tag checkboxes
function renderTags() {
existingTagsEl.innerHTML = '';
availableTags.forEach((tag) => {
const label = document.createElement('label');
label.className = 'tag-checkbox';
const checkbox = document.createElement('input');
checkbox.type = 'checkbox';
checkbox.value = tag;
checkbox.checked = selectedTags.has(tag);
checkbox.addEventListener('change', () => {
if (checkbox.checked) {
selectedTags.add(tag);
} else {
selectedTags.delete(tag);
}
});
label.appendChild(checkbox);
label.append(` ${tag}`);
existingTagsEl.appendChild(label);
});
}
// Scrape URL for title
scrapeButton.addEventListener('click', async (e) => {
e.preventDefault();
const url = urlInput.value.trim();
if (!url) {
setStatus(scrapeStatus, 'Please enter a URL', true);
return;
}
scrapeButton.disabled = true;
setStatus(scrapeStatus, 'Scraping...', false);
try {
const response = await fetch(`/api/scrape?url=${encodeURIComponent(url)}`, {
headers: { Authorization: `Bearer ${token}` },
});
if (!response.ok) {
if (response.status === 401) {
localStorage.removeItem('linklogAccessToken');
location.reload();
return;
}
throw new Error(`HTTP ${response.status}`);
}
const data = await response.json();
if (data.title) {
titleInput.value = data.title;
setStatus(scrapeStatus, 'Title loaded!', false);
} else {
setStatus(scrapeStatus, 'No title found', true);
}
} catch (error) {
console.error('Scrape error:', error);
setStatus(scrapeStatus, `Error: ${error.message}`, true);
} finally {
scrapeButton.disabled = false;
}
});
// Handle form submission
entryForm.addEventListener('submit', async (e) => {
e.preventDefault();
const url = urlInput.value.trim();
const title = titleInput.value.trim();
const comment = commentInput.value.trim();
const newTags = newTagsInput.value.trim();
if (!url || !title) {
setStatus(submitStatus, 'URL and title are required', true);
return;
}
// Combine selected tags and new tags
const tags = Array.from(selectedTags);
if (newTags) {
const newTagsList = newTags
.split(',')
.map((t) => t.trim())
.filter((t) => t);
tags.push(...newTagsList);
}
submitButton.disabled = true;
setStatus(submitStatus, 'Saving...', false);
try {
const response = await fetch('/api/links', {
method: 'POST',
headers: {
'Content-Type': 'application/json',
Authorization: `Bearer ${token}`,
},
body: JSON.stringify({
title,
url,
comment,
tags,
}),
});
if (!response.ok) {
if (response.status === 401) {
localStorage.removeItem('linklogAccessToken');
location.reload();
return;
}
const error = await response.json().catch(() => ({}));
throw new Error(error.detail || `HTTP ${response.status}`);
}
const data = await response.json();
setStatus(submitStatus, `Link saved to LinkLog${data.duplicate ? ' (updated)' : ''}!`, false);
// Redirect to user page after 1 second
if (currentUser) {
setTimeout(() => {
window.location.href = `/${encodeURIComponent(currentUser.username)}/`;
}, 1000);
}
} catch (error) {
console.error('Submit error:', error);
setStatus(submitStatus, `Error: ${error.message}`, true);
} finally {
submitButton.disabled = false;
}
});
})();
+325 -11
View File
@@ -223,17 +223,6 @@ body::selection {
position: relative;
}
.theme-picker {
width: auto;
min-width: 132px;
padding: 8px 10px;
border: 1px solid var(--surface-2);
border-radius: 7px;
background: var(--surface-0);
color: var(--text);
font: inherit;
}
.menu-toggle {
min-width: 0;
padding: 10px 13px;
@@ -248,6 +237,31 @@ body::selection {
font-size: 1.1em;
}
.new-entry-button {
padding: 10px 13px;
border: 1px solid var(--mauve);
border-radius: 7px;
background: var(--mauve);
color: var(--crust);
font-weight: 600;
cursor: pointer;
transition: all 0.2s ease;
}
.new-entry-button:hover {
background: var(--lavender);
border-color: var(--lavender);
}
.new-entry-button a {
color: inherit;
text-decoration: none;
}
.new-entry-button.hidden {
display: none;
}
.auth-menu {
position: absolute;
z-index: 30;
@@ -314,6 +328,86 @@ body::selection {
color: var(--red);
}
.theme-submenu-container {
border-top: 1px solid var(--border);
margin-top: 6px;
padding-top: 6px;
}
.theme-submenu-container.hidden {
display: none;
}
.submenu-title {
display: block;
width: 100%;
min-width: 0;
padding: 9px 10px;
border: 0;
border-radius: 6px;
background: transparent;
color: var(--text);
text-align: left;
font-weight: 600;
cursor: pointer;
transition: all 0.2s ease;
}
.submenu-title:hover {
background: var(--surface-1);
color: var(--lavender);
}
.submenu-title::after {
content: ' ▼';
font-size: 0.7em;
opacity: 0.7;
}
.submenu-title[aria-expanded='true']::after {
transform: rotate(-180deg);
display: inline-block;
}
.submenu-options {
display: flex;
flex-direction: column;
gap: 4px;
padding: 4px 8px;
margin-top: 4px;
border-radius: 6px;
background: var(--surface-1);
}
.submenu-options.hidden {
display: none;
}
.theme-option {
padding: 8px 10px;
border: 1px solid var(--border);
border-radius: 5px;
background: transparent;
color: var(--text);
text-align: left;
cursor: pointer;
transition: all 0.2s ease;
font-size: 0.9rem;
}
.theme-option:hover {
background: var(--surface-0);
border-color: var(--lavender);
color: var(--lavender);
}
.theme-option.active {
background: var(--mauve);
border-color: var(--mauve);
color: var(--crust);
font-weight: 600;
}
main.container {
position: relative;
z-index: 1;
@@ -768,6 +862,221 @@ button:disabled {
margin-top: 14px;
}
/* Entry form styling */
.entry-form {
max-width: 600px;
margin: 0 auto;
display: grid;
gap: 24px;
}
.entry-form.hidden,
#auth-required.hidden {
display: none;
}
#auth-required {
max-width: 600px;
margin: 40px auto;
padding: 16px;
background: var(--surface-0);
border: 1px solid var(--border);
border-radius: 12px;
border-left: 4px solid var(--red);
}
#auth-required p {
margin: 0;
color: var(--text);
}
#auth-required a {
color: var(--lavender);
text-decoration: underline;
}
#auth-required a:hover {
color: var(--mauve);
}
.form-section {
display: grid;
gap: 8px;
}
.form-section label {
display: grid;
gap: 6px;
}
.form-section > legend {
font-weight: 600;
color: var(--text);
font-size: 0.95rem;
margin: 0;
padding: 0;
}
.form-section input[type='url'],
.form-section input[type='text'],
.form-section textarea {
padding: 10px 12px;
background: var(--mantle);
border: 1px solid var(--border);
border-radius: 8px;
color: var(--text);
font-family: inherit;
font-size: 0.95rem;
line-height: 1.4;
}
.form-section textarea {
resize: vertical;
min-height: 100px;
}
.form-section input[type='url']:focus,
.form-section input[type='text']:focus,
.form-section textarea:focus {
outline: none;
border-color: var(--lavender);
box-shadow: 0 0 0 3px rgba(180, 190, 254, 0.1);
}
.tag-options {
display: flex;
flex-wrap: wrap;
gap: 8px 10px;
padding: 12px;
background: var(--mantle);
border: 1px solid var(--border);
border-radius: 8px;
}
.tag-checkbox {
display: flex;
align-items: center;
gap: 6px;
color: var(--subtext);
font-size: 0.9rem;
cursor: pointer;
user-select: none;
}
.tag-checkbox input {
cursor: pointer;
}
.form-section fieldset {
border: 1px solid var(--border);
border-radius: 8px;
padding: 12px;
margin: 0;
}
.form-section fieldset legend {
margin: 0;
padding: 0 6px;
}
.form-section fieldset label {
gap: 6px;
}
.form-section fieldset input[type='text'] {
width: 100%;
}
.form-section fieldset input[type='checkbox'] {
width: auto;
margin-right: 6px;
cursor: pointer;
}
.form-actions {
display: grid;
grid-template-columns: 1fr auto;
gap: 12px;
}
.form-actions button,
.form-actions a {
padding: 10px 16px;
border-radius: 8px;
font-weight: 600;
text-align: center;
text-decoration: none;
cursor: pointer;
transition: all 0.2s ease;
}
.form-actions button[type='submit'],
#scrape-button:not(:disabled) {
background: var(--mauve);
border: 1px solid var(--mauve);
color: var(--crust);
}
.form-actions button[type='submit']:hover:not(:disabled) {
background: var(--lavender);
border-color: var(--lavender);
}
.form-actions button[type='submit']:disabled {
opacity: 0.6;
cursor: not-allowed;
}
#scrape-button {
background: var(--surface-1);
border: 1px solid var(--border);
color: var(--text);
}
#scrape-button:not(:disabled):hover {
background: var(--surface-2);
border-color: var(--text);
}
#scrape-button:disabled {
opacity: 0.6;
cursor: not-allowed;
}
.form-actions a {
background: var(--surface-1);
border: 1px solid var(--border);
color: var(--text);
}
.form-actions a:hover {
background: var(--surface-2);
border-color: var(--text);
}
.status {
padding: 12px;
border-radius: 8px;
font-size: 0.9rem;
line-height: 1.4;
}
.status.success {
background: rgba(131, 165, 152, 0.2);
border: 1px solid var(--teal);
color: var(--teal);
}
.status.error {
background: rgba(243, 139, 168, 0.2);
border: 1px solid var(--red);
color: var(--red);
}
.status.hidden {
display: none;
}
@media (max-width: 600px) {
.container {
padding: 0 14px;
@@ -815,6 +1124,11 @@ button:disabled {
font-size: 0.9rem;
}
.new-entry-button {
padding: 8px 11px;
font-size: 0.9rem;
}
.logout-button {
font-size: 0.9rem;
}
+32 -11
View File
@@ -11,18 +11,39 @@ async function loadAvailableThemes() {
? localStorage.getItem(themePreference)
: themes[0]?.id;
if (selected) document.documentElement.dataset.theme = selected;
const headerActions = document.querySelector('.header-actions');
if (!headerActions || !themes.length) return;
const picker = document.createElement('select');
picker.className = 'theme-picker';
picker.setAttribute('aria-label', 'Theme');
picker.replaceChildren(...themes.map((theme) => new Option(theme.label, theme.id)));
picker.value = selected || themes[0].id;
picker.addEventListener('change', () => {
localStorage.setItem(themePreference, picker.value);
document.documentElement.dataset.theme = picker.value;
const submenuContainer = document.querySelector('#theme-submenu-container');
const themeOptions = document.querySelector('#theme-options');
const submenuTitle = document.querySelector('.submenu-title');
if (!submenuContainer || !themeOptions || !themes.length) return;
// Show the submenu container
submenuContainer.classList.remove('hidden');
// Create theme buttons
const buttons = themes.map((theme) => {
const button = document.createElement('button');
button.type = 'button';
button.className = 'theme-option';
button.dataset.themeId = theme.id;
button.textContent = theme.label;
if (theme.id === selected) {
button.classList.add('active');
}
button.addEventListener('click', () => {
localStorage.setItem(themePreference, theme.id);
document.documentElement.dataset.theme = theme.id;
// Update active state
document.querySelectorAll('.theme-option').forEach((btn) => {
btn.classList.remove('active');
});
button.classList.add('active');
});
return button;
});
headerActions.prepend(picker);
themeOptions.replaceChildren(...buttons);
}
loadAvailableThemes();
+12 -1
View File
@@ -18,6 +18,7 @@
<p>A quiet place for the links worth keeping.</p>
</div>
<div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a>
@@ -28,6 +29,10 @@
<a id="auth-admin-link" class="hidden" href="/admin">Admin</a>
<div id="auth-session" class="auth-session hidden"><a id="auth-username" class="user-name" href="/"></a></div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav>
</div>
</div>
@@ -52,8 +57,14 @@
<p>LinkLog is open source software. You can run your own instance, or contribute to the project on
<a href="https://git.kolkman.org/olaf/Link-Log">my repository</a>.</p>
</section>
<section class="link-item">
<h2>Plugin</h2>
<p>Install the Firefox plugin to save links directly from your browser. <a
href="https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi"
download>Download and install the Plugin</a>.</p>
</section>
</main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=3"></script>
<script src="/static/theme.js?v=1"></script>
+6 -1
View File
@@ -18,6 +18,7 @@
<p>Manage users and plugin configuration</p>
</div>
<div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a>
@@ -30,6 +31,10 @@
<a id="auth-username" class="user-name" href="/"></a>
</div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav>
</div>
</div>
@@ -115,7 +120,7 @@
</section>
</div>
</main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=2"></script>
<script src="/static/theme.js?v=1"></script>
+6 -1
View File
@@ -18,6 +18,7 @@
</div>
<div class="header-tools">
<div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a>
@@ -30,6 +31,10 @@
<a id="auth-username" class="user-name" href="/"></a>
</div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav>
</div>
<section class="toolbar">
@@ -76,7 +81,7 @@
{% endif %}
<section id="feed" class="feed" aria-live="polite"></section>
</main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=3"></script>
+6 -1
View File
@@ -18,6 +18,7 @@
<p>Manage your link labels</p>
</div>
<div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a>
@@ -28,6 +29,10 @@
<a id="auth-admin-link" class="hidden" href="/admin">Admin</a>
<div id="auth-session" class="auth-session hidden"><a id="auth-username" class="user-name" href="/"></a></div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav>
</div>
</div>
@@ -44,7 +49,7 @@
<div id="label-list" class="plugin-list"></div>
</section>
</main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=3"></script>
<script src="/static/theme.js?v=1"></script>
+6 -1
View File
@@ -17,6 +17,7 @@
<p>Access your LinkLog settings</p>
</div>
<div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a>
@@ -29,6 +30,10 @@
<a id="auth-username" class="user-name" href="/"></a>
</div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav>
</div>
</div>
@@ -55,7 +60,7 @@
</form>
</section>
</main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=3"></script>
<script src="/static/theme.js?v=1"></script>
+107
View File
@@ -0,0 +1,107 @@
<!DOCTYPE html>
<!-- Copyright © 2026 Olaf Kolkman -->
<!-- SPDX-License-Identifier: GPL-3.0-or-later -->
<html lang="en">
<head>
<meta charset="utf-8" />
<title>New Entry - LinkLog</title>
<meta name="viewport" content="width=device-width, initial-scale=1" />
<link rel="stylesheet" href="/static/style.css" />
</head>
<body>
<header class="site-header">
<div class="container">
<div class="header-row">
<div>
<img class="site-logo" src="/static/logo.svg" alt="LinkLog" />
<p>New Entry</p>
</div>
<div class="header-tools">
<div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a>
<a id="auth-about-link" href="/about">About</a>
<a id="auth-login-button" href="/login">Sign in</a>
<a id="auth-profile-link" class="hidden" href="/profile">Profile</a>
<a id="auth-labels-link" class="hidden" href="/labels">Labels</a>
<a id="auth-admin-link" class="hidden" href="/admin">Admin</a>
<div id="auth-session" class="auth-session hidden">
<a id="auth-username" class="user-name" href="/"></a>
</div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav>
</div>
</div>
</div>
</div>
</header>
<main class="container">
<div id="auth-required" class="error-message hidden">
<p>You must be signed in to create a new entry. <a href="/login">Sign in here</a>.</p>
</div>
<form id="entry-form" class="entry-form hidden">
<div class="form-section">
<label>
<span>URL</span>
<input id="url-input" name="url" type="url" required placeholder="https://example.com" />
</label>
<button id="scrape-button" class="secondary" type="button">Auto-fill Title</button>
<div id="scrape-status" class="status hidden" aria-live="polite"></div>
</div>
<div class="form-section">
<label>
<span>Title</span>
<input id="title-input" name="title" type="text" required />
</label>
</div>
<div class="form-section">
<label>
<span>Comment</span>
<textarea id="comment-input" name="comment" rows="4" placeholder="Optional comment about this link"></textarea>
</label>
</div>
<fieldset class="form-section">
<legend>Tags</legend>
<div id="existing-tags" class="tag-options"></div>
<label>
<span>Add new tags</span>
<input id="new-tags-input" type="text" pattern="#[^, ]+(,\s*#[^, ]+)*" placeholder="#tag1, #tag2" />
</label>
</fieldset>
<fieldset class="form-section">
<legend>Mastodon Publishing</legend>
<label>
<input id="mastodon-enabled" type="checkbox" />
Post to Mastodon (if configured)
</label>
</fieldset>
<div class="form-actions">
<button id="submit-button" type="submit">Save Entry</button>
<a href="/" class="secondary button">Cancel</a>
</div>
<div id="submit-status" class="status hidden" aria-live="polite"></div>
</form>
</main>
<footer class="site-footer">
<span>Copyright © 2026 Olaf Kolkman</span> · <a href="https://git.kolkman.org/olaf/Link-Log">Repository</a>
</footer>
<script src="/static/auth-header.js"></script>
<script src="/static/new-entry.js"></script>
</body>
</html>
+1 -1
View File
@@ -42,7 +42,7 @@
</form>
</section>
</main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman</footer>
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman</footer>
<script src="/static/theme.js?v=1"></script>
<script src="/static/setup.js"></script>
</body>
+7 -1
View File
@@ -19,6 +19,7 @@
<h1>Profile</h1>
</div>
<div class="header-actions">
<button id="new-entry-button" class="new-entry-button hidden" type="button"><a href="/new-entry">New entry</a></button>
<button class="menu-toggle" type="button" aria-expanded="false" aria-controls="auth-menu">Menu</button>
<nav id="auth-menu" class="auth-menu hidden" aria-label="Account menu">
<a id="auth-home-link" href="/">Home</a>
@@ -31,6 +32,10 @@
<a id="auth-username" class="user-name" href="/"></a>
</div>
<button id="logout-button" class="logout-button hidden" type="button">Sign out</button>
<div id="theme-submenu-container" class="theme-submenu-container hidden">
<button type="button" class="submenu-title" aria-expanded="false" aria-controls="theme-options">Themes</button>
<div id="theme-options" class="submenu-options hidden"></div>
</div>
</nav>
</div>
</div>
@@ -59,6 +64,7 @@
</label>
<img id="avatar-preview" class="profile-avatar-preview hidden" alt="Avatar preview" />
<button type="submit">Save profile</button>
<p>If you have not downloaded the plugin yet, <a href="https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi" download>find it here</a>.</p>
<p id="profile-status" class="status" role="status"></p>
</form>
</section>
@@ -144,7 +150,7 @@
</form>
</section>
</main>
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a
href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
<script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=2"></script>
+1 -1
View File
@@ -1,3 +1,3 @@
{
"version": "0.1.0"
"version": "0.1.1"
}
Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.9 MiB

+42 -30
View File
@@ -9,61 +9,73 @@ from pathlib import Path
ROOT = Path(__file__).resolve().parents[2]
MANIFEST_PATH = ROOT / 'webextension' / 'manifest.json'
FRONTEND_VERSION_PATH = ROOT / 'frontend' / 'version.json'
SETTINGS_PATH = ROOT / 'backend' / 'app' / 'core' / 'config.py'
UPDATES_PATH = ROOT / 'webextension' / 'updates.json'
SIGNED_DIR = ROOT / 'XPI' / 'signed'
MANIFEST_PATH = ROOT / 'webextension' / 'manifest.json'
VERSION_RE = re.compile(r'\d+\.\d+\.\d+')
def fail(message: str) -> None:
raise SystemExit(f'release validation failed: {message}')
def version_key(version: str) -> tuple[int, int, int]:
return tuple(int(part) for part in version.split('.'))
def find_latest_signed_xpi() -> tuple[str, Path]:
candidates = []
for xpi_path in SIGNED_DIR.glob('LinkLog-*.xpi'):
match = re.fullmatch(r'LinkLog-(\d+\.\d+\.\d+)\.xpi', xpi_path.name)
if match:
candidates.append((match.group(1), xpi_path))
if not candidates:
fail(f'no signed plugin artifacts found in {SIGNED_DIR.relative_to(ROOT)}')
return max(candidates, key=lambda candidate: version_key(candidate[0]))
def main() -> None:
manifest = json.loads(MANIFEST_PATH.read_text())
extension_version = manifest.get('version')
if not isinstance(extension_version, str) or not re.fullmatch(r'\d+\.\d+\.\d+', extension_version):
fail('webextension/manifest.json has no valid three-part version')
frontend_version = json.loads(FRONTEND_VERSION_PATH.read_text()).get('version')
if frontend_version != extension_version:
fail(f'frontend version {frontend_version} does not match extension version {extension_version}')
gecko_settings = manifest.get('browser_specific_settings', {}).get('gecko', {})
data_permissions = gecko_settings.get('data_collection_permissions')
if data_permissions != {'required': ['websiteActivity'], 'optional': []}:
fail('Firefox data_collection_permissions must require websiteActivity and have no optional categories')
settings = SETTINGS_PATH.read_text()
match = re.search(r"version: str = os\.getenv\('LINKLOG_VERSION', '([^']+)'\)", settings)
if not match:
fail('backend version default could not be found')
backend_version = match.group(1)
if backend_version != extension_version:
fail(f'backend version {backend_version} does not match extension version {extension_version}')
if not VERSION_RE.fullmatch(backend_version):
fail(f'backend version {backend_version} is not a valid three-part version')
xpi_path = SIGNED_DIR / f'LinkLog-{extension_version}.xpi'
if not xpi_path.is_file():
fail(f'missing manually signed artifact: {xpi_path.relative_to(ROOT)}')
extension_version, xpi_path = find_latest_signed_xpi()
source_manifest = json.loads(MANIFEST_PATH.read_text())
if source_manifest.get('version') != extension_version:
fail(
f'webextension/manifest.json version {source_manifest.get("version")!r} does not match '
f'the latest signed XPI version {extension_version!r}'
)
with zipfile.ZipFile(xpi_path) as archive:
try:
packaged_manifest = json.loads(archive.read('manifest.json'))
except KeyError:
fail('signed XPI does not contain manifest.json')
if packaged_manifest.get('version') != extension_version:
fail('signed XPI manifest version does not match webextension/manifest.json')
fail('signed XPI manifest version does not match its filename')
gecko_settings = packaged_manifest.get('browser_specific_settings', {}).get('gecko', {})
data_permissions = gecko_settings.get('data_collection_permissions')
if data_permissions != {'required': ['websiteActivity'], 'optional': []}:
fail('Firefox data_collection_permissions must require websiteActivity and have no optional categories')
if archive.testzip() is not None:
fail('signed XPI contains a corrupt member')
updates = json.loads(UPDATES_PATH.read_text())
addon_id = gecko_settings['id']
update_entries = updates.get('addons', {}).get(addon_id, {}).get('updates', [])
if not any(entry.get('version') == extension_version for entry in update_entries):
fail(f'webextension/updates.json has no update entry for {extension_version}')
signed_xpi = xpi_path.relative_to(ROOT)
if len(sys.argv) == 3 and sys.argv[1] == '--github-output':
with Path(sys.argv[2]).open('a') as output:
print(f'backend_version={backend_version}', file=output)
print(f'plugin_version={extension_version}', file=output)
print(f'signed_xpi={signed_xpi}', file=output)
elif len(sys.argv) != 1:
fail('usage: validate_release.py [--github-output <path>]')
print(f'validated LinkLog release {frontend_version}')
print(f'xpi={xpi_path.relative_to(ROOT)}')
print(f'validated LinkLog backend release {backend_version}')
print(f'plugin_version={extension_version}')
print(f'signed_xpi={signed_xpi}')
if __name__ == '__main__':