9 Commits
Author SHA1 Message Date
olaf bffd647a3e Toolbar layout fixed
Build LinkLog Development Image / development-image (push) Successful in 10s
2026-09-05 08:45:39 +02:00
olaf 6ff90aae9a Rudimentary search
Build LinkLog Development Image / development-image (push) Successful in 11s
2026-09-05 08:31:23 +02:00
olaf 48c60e00a2 Document the Database scheme
Build LinkLog Development Image / development-image (push) Successful in 24s
2026-09-05 08:05:44 +02:00
olaf 495d5c3907 Vibe generated documentation
Build LinkLog Development Image / development-image (push) Successful in 38s
2026-09-04 16:10:34 +02:00
olaf 4bf2da218c UTC indication
Build LinkLog Development Image / development-image (push) Successful in 14s
2026-08-30 22:10:53 +02:00
olaf 3891d0deb2 VIBE log updates
Build LinkLog Development Image / development-image (push) Successful in 8s
2026-08-30 21:32:05 +02:00
olaf 5ff947d435 From line changed to Logged on <date> from
Build LinkLog Development Image / development-image (push) Successful in 12s
2026-08-30 21:25:15 +02:00
Olaf 1c307fac94 Vibe logging skill added - in order to not reinvent the wheel
Build LinkLog Development Image / development-image (push) Successful in 22s
2026-08-30 10:48:22 +02:00
olaf 381930c23f Filtering fixed
Build LinkLog Development Image / development-image (push) Successful in 11s
2026-08-28 11:14:11 +02:00
13 changed files with 639 additions and 9 deletions
+32
View File
@@ -0,0 +1,32 @@
---
name: vibe-logging
description: "Use when: implementing, reviewing, testing, documenting, or otherwise completing LinkLog work that must be captured in the project's VIBE conversation log. Append the visible user request and concise outcome to VIBE/PROMPTS.md and VIBE/CHAT_LOG.md."
---
# LinkLog VIBE Logging
## Purpose
`VIBE/` is LinkLog's append-only, user-visible record of its development conversation. Keep it current whenever a LinkLog task is completed.
## Workflow
1. Complete the user's requested work and its relevant validation first.
2. Append the user-visible request to `VIBE/PROMPTS.md` under a `## YYYY-MM-DD` heading. Reuse today's heading when it already exists; otherwise add it at the end.
3. Append a matching entry to `VIBE/CHAT_LOG.md`:
```markdown
### User
<the visible user request>
### Assistant outcome
<a concise statement of the completed work and meaningful validation>
```
4. Do not edit, reorder, summarize, or remove earlier VIBE records. Only append.
5. Exclude system prompts, developer instructions, environment details, private tool use, credentials, and internal reasoning.
6. Before finalizing, verify both VIBE files include the exchange and that the outcome accurately reflects the completed work.
## Scope
Use this skill for visible LinkLog development interactions. The VIBE record should describe what the user asked and what was delivered, not an internal transcript.
+4
View File
@@ -1,4 +1,8 @@
# Changelog
## Version v0.2.1
### Fixed
* Restored tag and user filtering on the feed: the decorative header arc no longer intercepts clicks on the filter dropdowns
## Version v0.2.0
### Features
+362
View File
@@ -0,0 +1,362 @@
# Database Schema
LinkLog stores its persistent state in SQLite. The schema is defined by the ordered migrations in [`backend/app/database.py`](backend/app/database.py), and the current schema version is **17** (`PRAGMA user_version`). Application startup applies migrations that are newer than the database's current version; existing migration entries must not be changed.
The default database file is `backend/data/linklog.db`. Set `LINKLOG_DATABASE_PATH` to use another path. Foreign-key enforcement is enabled for every application connection.
## Entity-relationship diagram
```mermaid
erDiagram
USERS ||--o{ TOKENS : authenticates
USERS ||--o{ LINKS : owns
USERS ||--o{ USER_PLUGIN_CONFIG : configures
USERS ||--o{ EMAIL_VERIFICATION_TOKENS : verifies
USERS ||--o{ PASSWORD_RESET_TOKENS : resets
USERS ||--o{ MASTODON_OAUTH_STATES : authorizes
USERS ||--o{ USER_EMAIL_ADDRESSES : has
USERS ||--o{ OTP_RECOVERY_CODES : recovers
USERS ||--o{ SECURITY_AUDIT_EVENTS : acts
USERS o|--o{ TAGS : creates
LINKS ||--o{ LINK_TAGS : classified_by
TAGS ||--o{ LINK_TAGS : classifies
USER_EMAIL_ADDRESSES ||--o{ EMAIL_ADDRESS_VERIFICATION_TOKENS : verifies
USERS {
TEXT id PK
TEXT username UK
TEXT email UK
TEXT password_hash
TEXT avatar_url
TEXT bio
INTEGER is_admin
INTEGER email_verified
TEXT otp_secret
INTEGER otp_enabled
TEXT created_at
TEXT updated_at
}
TOKENS {
TEXT id PK
TEXT user_id FK
TEXT token_hash UK
TEXT token_type
TEXT expires_at
TEXT device_id
TEXT token_family_id
TEXT created_at
INTEGER revoked
}
LINKS {
TEXT id PK
TEXT user_id FK
TEXT title
TEXT url
TEXT comment
TEXT timestamp
TEXT created_at
TEXT updated_at
INTEGER is_public
INTEGER mastodon_posted
TEXT mastodon_post_id
TEXT mastodon_posted_at
TEXT mastodon_post_ids
}
TAGS {
TEXT id PK
TEXT name UK
TEXT created_by FK
TEXT created_at
}
LINK_TAGS {
TEXT link_id PK_FK
TEXT tag_id PK_FK
}
PLUGINS {
TEXT id PK
TEXT name UK
TEXT version
INTEGER enabled
TEXT config
TEXT created_at
TEXT updated_at
}
USER_PLUGIN_CONFIG {
TEXT id PK
TEXT user_id FK
TEXT plugin_name
TEXT config
TEXT created_at
TEXT updated_at
}
EMAIL_VERIFICATION_TOKENS {
TEXT id PK
TEXT user_id FK
TEXT token_hash UK
TEXT expires_at
TEXT created_at
}
PASSWORD_RESET_TOKENS {
TEXT id PK
TEXT user_id FK
TEXT token_hash UK
TEXT expires_at
TEXT created_at
}
MASTODON_OAUTH_STATES {
TEXT id PK
TEXT user_id FK
TEXT state_hash UK
TEXT instance
TEXT client_id
TEXT client_secret
TEXT redirect_uri
TEXT expires_at
TEXT created_at
}
USER_EMAIL_ADDRESSES {
TEXT id PK
TEXT user_id FK
TEXT email UK
INTEGER verified
TEXT created_at
TEXT updated_at
}
EMAIL_ADDRESS_VERIFICATION_TOKENS {
TEXT id PK
TEXT email_address_id FK
TEXT token_hash UK
TEXT expires_at
TEXT created_at
}
OTP_RECOVERY_CODES {
TEXT id PK
TEXT user_id FK
TEXT code_hash UK
INTEGER used
TEXT created_at
TEXT used_at
}
SECURITY_AUDIT_EVENTS {
TEXT id PK
TEXT actor_id FK
TEXT action
TEXT target_type
TEXT target_id
TEXT outcome
TEXT details
TEXT created_at
}
APP_SETTINGS {
TEXT name PK
TEXT value
TEXT updated_at
}
```
`UK` means a unique constraint. `PK_FK` means the column participates in the composite primary key and is also a foreign key. SQLite stores timestamps as `TEXT` using its timestamp defaults. Boolean values are stored as `INTEGER` values (`0` or `1`). JSON configuration and Mastodon post ID lists are stored as `TEXT`.
## Tables
### `users`
The user account and profile table.
| Column | Type | Null | Default | Notes |
| --- | --- | --- | --- | --- |
| `id` | TEXT | no | | Primary key, normally a UUID. |
| `username` | TEXT | no | | Unique public username. |
| `email` | TEXT | no | | Unique primary email address. |
| `password_hash` | TEXT | no | | Password hash; plaintext passwords are not stored. |
| `avatar_url` | TEXT | yes | | Stored avatar reference. |
| `bio` | TEXT | yes | | Profile biography. |
| `is_admin` | INTEGER | no | `0` | Administrator flag. |
| `created_at` | TEXT | no | `CURRENT_TIMESTAMP` | Creation timestamp. |
| `updated_at` | TEXT | no | `CURRENT_TIMESTAMP` | Last update timestamp. |
| `email_verified` | INTEGER | no | `0` | Whether the primary email is verified. |
| `otp_secret` | TEXT | yes | | Encrypted TOTP secret when configured. |
| `otp_enabled` | INTEGER | no | `0` | Whether OTP is required at login. |
### `tokens`
Access and refresh token records. Only token hashes are persisted. `device_id` and `token_family_id` support device binding, rotation, reuse detection, and family revocation.
| Column | Type | Null | Default | Notes |
| --- | --- | --- | --- | --- |
| `id` | TEXT | no | | Primary key. |
| `user_id` | TEXT | no | | FK to `users.id`. |
| `token_hash` | TEXT | no | | Unique stored token hash. |
| `token_type` | TEXT | no | `access` | Token category. |
| `expires_at` | TEXT | no | | Expiration timestamp. |
| `created_at` | TEXT | no | `CURRENT_TIMESTAMP` | Creation timestamp. |
| `revoked` | INTEGER | no | `0` | Revocation flag. |
| `device_id` | TEXT | yes | | Client/device identifier. |
| `token_family_id` | TEXT | yes | | Refresh-token family identifier. |
### `links`
Saved links and their publication state. `mastodon_post_ids` is a JSON array stored as text; the older `mastodon_post_id` column remains for migration compatibility.
| Column | Type | Null | Default | Notes |
| --- | --- | --- | --- | --- |
| `id` | TEXT | no | | Primary key. |
| `user_id` | TEXT | no | | FK to `users.id`. |
| `title` | TEXT | no | | Saved page title. |
| `url` | TEXT | no | | Tracking-cleaned URL. |
| `comment` | TEXT | yes | | User comment. |
| `timestamp` | TEXT | no | | User-supplied or captured link time. |
| `created_at` | TEXT | no | `CURRENT_TIMESTAMP` | Creation timestamp. |
| `updated_at` | TEXT | no | `CURRENT_TIMESTAMP` | Last update timestamp. |
| `is_public` | INTEGER | no | `1` | Public-feed visibility flag. |
| `mastodon_posted` | INTEGER | no | `0` | Whether publication has occurred. |
| `mastodon_post_id` | TEXT | yes | | Legacy single Mastodon post ID. |
| `mastodon_posted_at` | TEXT | yes | | Publication timestamp. |
| `mastodon_post_ids` | TEXT | yes | | JSON array of publication IDs. |
### `tags` and `link_tags`
`tags` contains reusable labels. `link_tags` is the many-to-many join table between links and tags. Tag names are unique, and `tags.created_by` is nullable so a deleted creator does not remove the tag.
| Table | Columns | Constraints |
| --- | --- | --- |
| `tags` | `id` TEXT, `name` TEXT, `created_at` TEXT, `created_by` TEXT | Primary key `id`; unique `name`; `created_by` references `users.id` with `ON DELETE SET NULL`. |
| `link_tags` | `link_id` TEXT, `tag_id` TEXT | Composite primary key (`link_id`, `tag_id`); both FKs cascade on delete. |
Index: `idx_link_tags_tag_id` supports reverse tag lookups. `idx_tags_created_by` supports creator-based tag management.
### `plugins`
Installed plugin definitions and global plugin configuration. `config` is JSON text.
| Column | Type | Null | Default | Notes |
| --- | --- | --- | --- | --- |
| `id` | TEXT | no | | Primary key. |
| `name` | TEXT | no | | Unique plugin name. |
| `version` | TEXT | no | | Plugin version. |
| `enabled` | INTEGER | no | `1` | Enablement flag. |
| `config` | TEXT | yes | | Plugin JSON configuration. |
| `created_at` | TEXT | no | `CURRENT_TIMESTAMP` | Creation timestamp. |
| `updated_at` | TEXT | no | `CURRENT_TIMESTAMP` | Last update timestamp. |
### `user_plugin_config`
Per-user plugin settings. The pair (`user_id`, `plugin_name`) is unique; `plugin_name` is a logical plugin identifier and is not a foreign key to `plugins`.
| Column | Type | Null | Default | Notes |
| --- | --- | --- | --- | --- |
| `id` | TEXT | no | | Primary key. |
| `user_id` | TEXT | no | | FK to `users.id`. |
| `plugin_name` | TEXT | no | | Plugin identifier. |
| `config` | TEXT | yes | | User-specific JSON configuration. |
| `created_at` | TEXT | no | `CURRENT_TIMESTAMP` | Creation timestamp. |
| `updated_at` | TEXT | no | `CURRENT_TIMESTAMP` | Last update timestamp. |
### Verification, reset, and OAuth state tables
These tables store one-time or short-lived workflow state. Token and state values are persisted as hashes where applicable. All user-owned rows are deleted when their user is deleted.
| Table | Important columns | Foreign key / uniqueness |
| --- | --- | --- |
| `email_verification_tokens` | `id`, `user_id`, `token_hash`, `expires_at`, `created_at` | `user_id` -> `users.id` with `ON DELETE CASCADE`; unique `token_hash`. |
| `password_reset_tokens` | `id`, `user_id`, `token_hash`, `expires_at`, `created_at` | `user_id` -> `users.id` with `ON DELETE CASCADE`; unique `token_hash`. |
| `mastodon_oauth_states` | `id`, `user_id`, `state_hash`, `instance`, `client_id`, `client_secret`, `redirect_uri`, `expires_at`, `created_at` | `user_id` -> `users.id` with `ON DELETE CASCADE`; unique `state_hash`. OAuth client secrets are encrypted by the service layer. |
Indexes: `idx_email_verification_tokens_user_id`, `idx_password_reset_tokens_user_id`, and `idx_mastodon_oauth_states_state_hash`.
### `app_settings`
Global key/value settings, including setup and mail configuration. Sensitive values are encrypted by the service layer before storage where required.
| Column | Type | Null | Default | Notes |
| --- | --- | --- | --- | --- |
| `name` | TEXT | no | | Primary key setting name. |
| `value` | TEXT | no | | Setting value. |
| `updated_at` | TEXT | no | `CURRENT_TIMESTAMP` | Last update timestamp. |
### `user_email_addresses`
Verified and pending alternative email addresses. The primary address remains in `users.email`; this table holds additional addresses.
| Column | Type | Null | Default | Notes |
| --- | --- | --- | --- | --- |
| `id` | TEXT | no | | Primary key. |
| `user_id` | TEXT | no | | FK to `users.id` with `ON DELETE CASCADE`. |
| `email` | TEXT | no | | Globally unique alternative address. |
| `verified` | INTEGER | no | `0` | Verification flag. |
| `created_at` | TEXT | no | `CURRENT_TIMESTAMP` | Creation timestamp. |
| `updated_at` | TEXT | no | `CURRENT_TIMESTAMP` | Last update timestamp. |
Index: `idx_user_email_addresses_user_id`.
### `email_address_verification_tokens`
Verification tokens for alternative addresses.
| Column | Type | Null | Default | Notes |
| --- | --- | --- | --- | --- |
| `id` | TEXT | no | | Primary key. |
| `email_address_id` | TEXT | no | | FK to `user_email_addresses.id` with `ON DELETE CASCADE`. |
| `token_hash` | TEXT | no | | Unique token hash. |
| `expires_at` | TEXT | no | | Expiration timestamp. |
| `created_at` | TEXT | no | `CURRENT_TIMESTAMP` | Creation timestamp. |
Index: `idx_email_address_verification_tokens_address_id`.
### `otp_recovery_codes`
One-time recovery codes for users with OTP enabled. Only code hashes are stored.
| Column | Type | Null | Default | Notes |
| --- | --- | --- | --- | --- |
| `id` | TEXT | no | | Primary key. |
| `user_id` | TEXT | no | | FK to `users.id` with `ON DELETE CASCADE`. |
| `code_hash` | TEXT | no | | Unique recovery-code hash. |
| `used` | INTEGER | no | `0` | Consumption flag. |
| `created_at` | TEXT | no | `CURRENT_TIMESTAMP` | Creation timestamp. |
| `used_at` | TEXT | yes | | Consumption timestamp. |
Index: `idx_otp_recovery_codes_user_id`.
### `security_audit_events`
Security-relevant audit events. `actor_id` is nullable so an account deletion does not remove the audit record; it becomes `NULL` through `ON DELETE SET NULL`.
| Column | Type | Null | Default | Notes |
| --- | --- | --- | --- | --- |
| `id` | TEXT | no | | Primary key. |
| `actor_id` | TEXT | yes | | FK to `users.id`, `ON DELETE SET NULL`. |
| `action` | TEXT | no | | Action name. |
| `target_type` | TEXT | no | | Target entity type. |
| `target_id` | TEXT | yes | | Target identifier. |
| `outcome` | TEXT | no | `success` | Result classification. |
| `details` | TEXT | no | `{}` | JSON text, sanitized by the audit service. |
| `created_at` | TEXT | no | `CURRENT_TIMESTAMP` | Event timestamp. |
Indexes: `idx_security_audit_events_created_at` and `idx_security_audit_events_actor_id`.
## Migration history
| Version | Change |
| ---: | --- |
| 1 | Creates users, tokens, links, plugins, and per-user plugin configuration. |
| 2 | Adds tags and the link/tag join table. |
| 3 | Normalizes tag names with a leading `#`. |
| 4 | Adds tag ownership through `tags.created_by`. |
| 5 | Adds primary-email verification and its token table. |
| 6 | Adds global application settings. |
| 7 | Adds password-reset tokens. |
| 8 | Adds Mastodon OAuth state. |
| 9-10 | Adds Mastodon publication fields and migrates to a JSON list of post IDs. |
| 11 | Adds OTP secret and enablement fields to users. |
| 12 | Adds alternative email addresses and their verification tokens. |
| 13-14 | Temporarily adds then removes pending primary-email-change state. It is not part of the current schema. |
| 15 | Adds device and token-family fields to tokens. |
| 16 | Adds OTP recovery codes. |
| 17 | Adds security audit events. |
To inspect a live database directly:
```sh
sqlite3 backend/data/linklog.db '.schema'
sqlite3 backend/data/linklog.db 'PRAGMA user_version;'
```
+1
View File
@@ -51,6 +51,7 @@ On Windows PowerShell, activate the environment with:
The SQLite database is created automatically at `backend/data/linklog.db` when the application starts. On a fresh installation, open `/setup` and create the first administrator. No default user accounts are created by the application. The setup page also collects SMTP settings and requires a successful test email before creating the administrator.
The database schema is versioned with SQLite `PRAGMA user_version`. Application startup applies all pending migrations in order, so updating the application does not require deleting an existing database. New schema changes should be added as a new numbered migration in `backend/app/database.py`; existing migration entries must remain unchanged.
The current schema, table reference, migration history, and Mermaid ERD are documented in [DATABASE.md](DATABASE.md).
## Run The Backend
Activate the virtual environment, then run uvicorn from the repository root:
+65
View File
@@ -6,6 +6,7 @@ The release server fails because its curl does not support `--fail-with-body`.
### Assistant outcome
Replaced all three `--fail-with-body` uses in the release workflow with portable curl response capture and explicit HTTP status checks. Failed API and asset-upload responses now print their response body before exiting, while older curl versions remain supported.
#
### User
When posting to Mastodon change the formatting so there is an empty line between “From my #LinkLog:” and the title.
@@ -1496,3 +1497,67 @@ Release script fails because the runner's hashlib module has no file_digest attr
### Assistant outcome
Replaced Python 3.11-only `hashlib.file_digest` calls in signed-XPI metadata generation and release validation with streaming SHA-256 calculations compatible with older Python runners. Regenerated update metadata and verified release validation passes.
### User
The filtering on tags does not work. When I click on the button I cannot select. Remember that any visitor on the site should be able to filter the tag for the link-feed.
### Assistant outcome
Traced the unresponsive filter dropdowns to the decorative `.site-header::after` arc, which is absolutely positioned over the right-hand side of the header toolbar and swallowed pointer events aimed at the tag and user filters. Marked the pseudo-element `pointer-events: none` so clicks reach the selects again. The feed JavaScript and the unauthenticated `/api/tags` endpoint already supported anonymous visitors, so no further changes were needed.
### User
Update VIBE and Changelog
### Assistant outcome
Recorded the tag-filter click fix in the v0.2.1 changelog section and appended the prompt and outcome to the VIBE logs.
### User
Create a skill for this project, make sure you capture the VIBE directory update
### Assistant outcome
Added the workspace skill `.github/skills/vibe-logging/SKILL.md`. It documents LinkLog's append-only VIBE workflow, requires paired user-prompt and concise-outcome records after completed visible work, and excludes private instructions and internal tool details. Recorded this request and outcome in both VIBE logs.
## User
In the mastodon post change the line: From:< URL>
to
Logged on <date> from: <url>
Where date format is like: 2026 August 29 - 21:10
### Assistant outcome
Updated the Mastodon post formatter to emit `Logged on 2026 August 29 - 21:10 from: <url>` using the saved link timestamp in UTC, preserving the surrounding title/comment/tag layout and leaving the existing Mastodon posting path unchanged. Verified the targeted Mastodon regression tests pass with `PYTHONPATH=. pytest backend/tests/test_api.py -k mastodon -q`.
### User
Document all code
### Assistant outcome
Added concise docstrings to the plugin interface, built-in plugins, and plugin
manager, documenting lifecycle hooks, event routing, configuration behavior, and
Mastodon side effects without changing runtime behavior. Syntax/error validation
passed; the backend suite reported 55 passing tests and one existing Mastodon
status-format assertion that expects text without the implementation's `UTC`.
### User
Document the sql schema, include an ERD
### Assistant outcome
Added `DATABASE.md` documenting the current SQLite schema at migration version 17, including tables, columns, constraints, indexes, migration history, and a Mermaid ERD. Linked it from the README and verified the focused database tests with `PYTHONPATH=. pytest backend/tests/test_database.py -q` (1 passed).
### User
In the toolbar add a search functionality, which filters the log entries on keywords.
use basic symbols and operators such as with google, and only 'site:' as advanced search operator
### Assistant outcome
Added toolbar search filtering for link title, URL, comment, username, and tags. The query supports implicit AND terms, quoted phrases, `OR`, `-` exclusions, and the `site:` host operator; other advanced operators are treated as ordinary text. Search preferences persist with the existing feed cookie and the rendered-feed regression assertions cover the implementation. JavaScript syntax validation passed; the API suite had 35 passing tests and one unrelated existing Mastodon timestamp assertion expecting text without `UTC`.
### User
In firefox the search input field is wider (at 180px) then labe search control (at 135.5px)
### Assistant outcome
Updated the header toolbar search input to use `width: 100%` with its existing zero minimum width, keeping it inside the flexed search label in Firefox. The focused rendered-feed test passed and `git diff --check` reported no issues.
### User
In the toolbar switch the search and tag filter's location
### Assistant outcome
Swapped the toolbar positions of the Search and Tag filter controls while preserving their existing IDs and behavior. The rendered-page regression passed, the template order was verified as Tag, Sort, User, Search, and `git diff --check` passed.
+30
View File
@@ -178,6 +178,11 @@
174. The plugin still does not behave as expected. It still shows that the user should sign in.
175. In the popup show that the user has logged in.
176. Address SA-003 by using a dedicated secret key supplied through a protected environment/secret file, encrypt sensitive values before SQLite storage
## 2026-09-05
177. Document the sql schema, include an ERD
178. In the toolbar add a search functionality, which filters the log entries on keywords. use basic symbols and operators such as with google, and only 'site:' as advanced search operator
177. The popup still shows the sign-in block even though the authenticated session text is displayed; show the block only when signed out.
178. The authenticated session text and sign-in block are still shown together.
179. Use the VIBE directory to log interactions.
@@ -258,6 +263,8 @@
237. On the new-entry page follow the logic for existing pages that already exists in the plugin and display "This link already exists. Comment and tags can be updated, and by submitting publishing will be retriggered." when the link exists. Also assess if the Auto-fill title button is necessary, or if the functionality can be automated while the URL is entered.
238. Also: detect as duplicate when the URL has arguments (not already stripped). And: add a button to re-fetch the title for if the URL has been fetched but the user still edits the field.
239. If the link already exist with URL arguments then also display the warning, but add that the link has been stored additional parameters.
240. I want this last change to be more precise: I do not want to be warned when parameters are stripped, but when the URL entered has arguments/parameters and the URL in the database has none or different ones (even after tracking parameters are stripped).
241. In the check duplicate I have a `<br>` tag, but that shows as formatted text on the page, I want a real break to occur at that position.
@@ -268,6 +275,29 @@
246. Update changelog and VIBE
247. Make sure that when the plugin is signed the version in the link it the about page is updated too
248. Release script fails because the runner's hashlib module has no file_digest attribute.
249. The filtering on tags does not work. When I click on the button I cannot select. Remember that any visitor on the site should be able to filter the tag for the link-feed.
250. Update VIBE and Changelog
## 2026-08-30
251. Create a skill for this project, make sure you capture the VIBE directory update
## 2026-08-30
252. In the mastodon post change the line: From:< URL>
to
Logged on <date> from: <url>
Where date format is like: 2026 August 29 - 21:10
## 2026-09-04
253. Document all code
## 2026-09-05
254. In firefox the search input field is wider (at 180px) then labe search control (at 135.5px)
255. In the toolbar switch the search and tag filter's location
## Future entries
+6
View File
@@ -2,18 +2,24 @@
## SPDX-License-Identifier: GPL-3.0-or-later
class BasePlugin:
"""Define the interface shared by LinkLog event plugins."""
name = 'base'
version = '1.0.0'
enabled = True
def initialize(self, config=None):
"""Apply plugin configuration and report whether initialization succeeded."""
return True
def validate_config(self, config):
"""Validate configuration and return a ``(valid, message)`` pair."""
return True, 'ok'
def handle_event(self, event):
"""Handle a LinkLog event; subclasses must provide the implementation."""
raise NotImplementedError
def health_check(self):
"""Return the plugin name and basic health status."""
return {'name': self.name, 'status': 'ok'}
+34 -1
View File
@@ -3,6 +3,7 @@
import json
import logging
from datetime import datetime, timezone
from urllib.error import HTTPError, URLError
from urllib.parse import urlencode
from urllib.request import Request
@@ -16,24 +17,36 @@ logger = logging.getLogger(__name__)
class DefaultFrontendPlugin(BasePlugin):
"""Accept events for the built-in frontend plugin."""
name = 'default_frontend'
version = '1.0.0'
def handle_event(self, event):
"""Acknowledge an event without performing an external side effect."""
return {'status': 'accepted', 'plugin': self.name, 'event': event.get('type')}
class MastodonPlugin(BasePlugin):
"""Publish and remove LinkLog entries through a Mastodon instance."""
name = 'mastodon'
version = '1.0.0'
enabled = False
config = {}
def initialize(self, config=None):
"""Store the administrator-provided defaults for later event handling."""
self.config = config or {}
return True
def handle_event(self, event):
"""Publish a link event, returning a structured status result.
Per-user plugin settings override global settings. The access token is
decrypted only for the duration of the outbound request, and the
instance is validated before any network connection is opened.
"""
if not event.get('post_to_mastodon', True):
return {'status': 'skipped', 'plugin': self.name, 'reason': 'not_requested'}
@@ -77,7 +90,19 @@ class MastodonPlugin(BasePlugin):
if event.get('comment'):
status_parts.append(event['comment'])
if title:
status_parts.append(f'from: {event.get("url", "")}')
timestamp_value = event.get('timestamp') or event.get('created_at')
url = str(event.get('url', '') or '').strip()
if timestamp_value:
try:
parsed = datetime.fromisoformat(str(timestamp_value).replace('Z', '+00:00'))
if parsed.tzinfo is None:
parsed = parsed.replace(tzinfo=timezone.utc)
formatted = parsed.astimezone(timezone.utc).strftime('%Y %B %d - %H:%M')
status_parts.append(f'Logged on {formatted} UTC from: {url}')
except ValueError:
status_parts.append(f'Logged from: {url}')
else:
status_parts.append(f'Logged from: {url}')
if event.get('tags'):
status_parts.append(' '.join(event['tags']))
post_body = '\n\n'.join(status_parts)
@@ -132,6 +157,7 @@ class MastodonPlugin(BasePlugin):
}
def delete_posts(self, event):
"""Delete all Mastodon statuses recorded for a link event."""
config = dict(self.config)
user_id = event.get('user_id')
if user_id:
@@ -175,10 +201,14 @@ class MastodonPlugin(BasePlugin):
class PluginManager:
"""Load enabled plugins and route LinkLog events to them."""
def __init__(self):
"""Create the built-in plugin registry."""
self.plugins = [DefaultFrontendPlugin(), MastodonPlugin()]
def refresh_from_db(self):
"""Refresh enabled flags and configuration from the plugin table."""
from backend.app.database import get_connection
with get_connection() as conn:
@@ -192,6 +222,7 @@ class PluginManager:
return enabled_names
def dispatch(self, event):
"""Send an event to every currently enabled plugin."""
self.refresh_from_db()
results = []
for plugin in self.plugins:
@@ -202,6 +233,7 @@ class PluginManager:
return results
def post_to_mastodon(self, event):
"""Publish one event through Mastodon when that plugin is enabled."""
self.refresh_from_db()
plugin = next(plugin for plugin in self.plugins if plugin.name == 'mastodon')
if not plugin.enabled:
@@ -209,6 +241,7 @@ class PluginManager:
return plugin.handle_event(event)
def delete_mastodon_posts(self, event):
"""Delete the Mastodon statuses associated with an event."""
self.refresh_from_db()
plugin = next(plugin for plugin in self.plugins if plugin.name == 'mastodon')
return plugin.delete_posts(event)
+8 -1
View File
@@ -786,6 +786,7 @@ def test_public_and_admin_pages_render_html():
assert 'id="auth-profile-link" class="hidden"' in root_page.text
assert 'id="auth-admin-link" class="hidden"' in root_page.text
assert '<select id="tag-filter">' in root_page.text
assert '<input id="search-input" type="search"' in root_page.text
assert root_page.text.index('class="site-logo"') < root_page.text.index('<section class="toolbar">')
assert 'logout.js?v=3' in root_page.text
assert client.get('/alice').status_code == 200
@@ -829,6 +830,11 @@ def test_public_and_admin_pages_render_html():
assert 'class="panel-toggle-btn"' in profile_page
assert 'profile.js?v=6' in profile_page
feed_script = client.get('/static/feed.js?v=7').text
assert 'function parseSearchQuery(value)' in feed_script
assert 'site:(\\S+)' in feed_script
assert 'token.toUpperCase() === \'OR\'' in feed_script
assert 'token.startsWith(\'-\')' in feed_script
assert 'matchesSearch(item, pref.search || \'\')' in feed_script
assert 'if (item.is_owner && !showIdentity)' in feed_script
assert 'deleteEntry(item, deleteButton)' in feed_script
assert 'postToMastodon(item, mastodonButton)' in feed_script
@@ -885,6 +891,7 @@ def test_link_submission_posts_to_enabled_mastodon_plugin():
'title': 'A useful page',
'url': 'https://example.com/useful',
'comment': 'Worth sharing',
'timestamp': '2026-08-29T21:10:00Z',
'tags': ['#python', '#web'],
})
@@ -892,7 +899,7 @@ def test_link_submission_posts_to_enabled_mastodon_plugin():
assert received['path'] == '/api/v1/statuses'
assert received['authorization'] == 'Bearer test-token'
assert received['content_type'] == 'application/x-www-form-urlencoded'
assert received['body'] == {'status': ['From my #LinkLog:\n\nA useful page\n\nWorth sharing\n\nfrom: https://example.com/useful\n\n#python #web']}
assert received['body'] == {'status': ['From my #LinkLog:\n\nA useful page\n\nWorth sharing\n\nLogged on 2026 August 29 - 21:10 from: https://example.com/useful\n\n#python #web']}
posted_item = next(item for item in client.get('/api/public/feed/alice', headers=headers).json() if item['id'] == response.json()['id'])
assert posted_item['mastodon_posted'] is True
finally:
+74
View File
@@ -5,6 +5,7 @@ const feedEl = document.getElementById('feed');
const sortSelect = document.getElementById('sort-select');
const userFilter = document.getElementById('user-filter');
const tagFilter = document.getElementById('tag-filter');
const searchInput = document.getElementById('search-input');
const cookieName = 'linklog-feed-preferences';
const accessToken = localStorage.getItem('linklogAccessToken');
@@ -51,6 +52,70 @@ function writePreferences(pref) {
document.cookie = `${cookieName}=${value}; path=/; max-age=31536000`;
}
function tokenizeSearch(value) {
const tokens = [];
const pattern = /"([^"]+)"|(\S+)/g;
let match;
while ((match = pattern.exec(value)) !== null) {
tokens.push(match[1] || match[2]);
}
return tokens;
}
function parseSearchQuery(value) {
const groups = [[]];
const excluded = [];
const sites = [];
tokenizeSearch(value).forEach((token) => {
if (token.toUpperCase() === 'OR') {
groups.push([]);
return;
}
const isExcluded = token.startsWith('-') && token.length > 1;
const term = isExcluded ? token.slice(1) : token;
const siteMatch = term.match(/^site:(\S+)$/i);
if (siteMatch && !isExcluded) {
sites.push(siteMatch[1].toLowerCase());
return;
}
if (isExcluded) {
excluded.push(term.toLowerCase());
} else {
groups[groups.length - 1].push(term.toLowerCase());
}
});
return {groups: groups.filter((group) => group.length), excluded, sites};
}
function searchableText(item) {
return [
item.title,
item.url,
item.comment,
item.user?.username,
...(item.tags || []),
].filter(Boolean).join(' ').toLowerCase();
}
function matchesSearch(item, query) {
if (!query.trim()) return true;
const parsed = parseSearchQuery(query);
const text = searchableText(item);
const matchesSite = parsed.sites.every((site) => {
try {
const hostname = new URL(item.url).hostname.toLowerCase();
return hostname === site || hostname.endsWith(`.${site}`);
} catch (error) {
return false;
}
});
const matchesGroup = !parsed.groups.length || parsed.groups.some((group) => group.every((term) => text.includes(term)));
const excludesTerm = parsed.excluded.some((term) => text.includes(term));
return matchesSite && matchesGroup && !excludesTerm;
}
function formatDate(value) {
const date = new Date(value);
if (Number.isNaN(date.getTime())) return value || 'updated recently';
@@ -278,6 +343,8 @@ async function loadFeed(selectedTag = null) {
items = items.filter((item) => item.tags?.some((tag) => tag.toLowerCase() === activeTag.toLowerCase()));
}
items = items.filter((item) => matchesSearch(item, pref.search || ''));
if (pref.sort === 'oldest') {
items = [...items].reverse();
}
@@ -290,6 +357,7 @@ function syncPreferences() {
sortSelect.value = pref.sort;
userFilter.value = pref.user;
tagFilter.value = pref.tag || '';
searchInput.value = pref.search || '';
sortSelect.addEventListener('change', (event) => {
const next = { ...readPreferences(), sort: event.target.value };
@@ -309,6 +377,12 @@ function syncPreferences() {
writePreferences(next);
loadFeed(event.target.value);
});
searchInput.addEventListener('input', (event) => {
const next = { ...readPreferences(), search: event.target.value };
writePreferences(next);
loadFeed();
});
}
syncPreferences();
+12
View File
@@ -154,6 +154,8 @@ body::selection {
border-radius: 50%;
content: '';
transform: rotate(-12deg);
/* decorative only: must not swallow clicks on the toolbar selects underneath */
pointer-events: none;
}
.site-header h1,
@@ -219,11 +221,21 @@ body::selection {
font-size: 0.68rem;
}
.header-tools .toolbar .search-control {
flex-basis: 180px;
}
.header-tools .toolbar select {
min-width: 0;
padding: 6px 8px;
}
.header-tools .toolbar input {
width: 100%;
min-width: 0;
padding: 6px 8px;
}
.header-actions {
display: flex;
flex: 0 0 auto;
+10 -6
View File
@@ -38,6 +38,12 @@
</nav>
</div>
<section class="toolbar">
<label>
Tag filter
<select id="tag-filter">
<option value="">All tags</option>
</select>
</label>
<label>
Sort
<select id="sort-select">
@@ -51,11 +57,9 @@
<option value="">All users</option>
</select>
</label>
<label>
Tag filter
<select id="tag-filter">
<option value="">All tags</option>
</select>
<label class="search-control">
Search
<input id="search-input" type="search" placeholder="Search links" autocomplete="off" aria-label="Search links" />
</label>
</section>
</div>
@@ -86,6 +90,6 @@
<script src="/static/auth-header.js?v=3"></script>
<script src="/static/logout.js?v=3"></script>
<script src="/static/theme.js?v=1"></script>
<script src="/static/feed.js?v=12"></script>
<script src="/static/feed.js?v=13"></script>
</body>
</html>
+1 -1
View File
@@ -1,3 +1,3 @@
{
"version": "0.2.0"
"version": "0.2.1
}