34 Commits

Author SHA1 Message Date
renovate-bot 6e21eb2d4b Update dependency lucide-static to v1.48.0
CI / full-gate (push) Successful in 3m18s
Mirror / github-mirror (push) Successful in 3s
Release-Bump: minor
2026-09-25 04:18:38 +00:00
renovate-bot d8a31def52 Update renovate/renovate Docker tag to v44.111.4
CI / full-gate (push) Successful in 4m5s
Mirror / github-mirror (push) Successful in 4s
2026-09-24 04:18:07 +00:00
renovate-bot 5b49bce690 Update renovate/renovate Docker tag to v44.108.2
CI / full-gate (push) Successful in 2m55s
Mirror / github-mirror (push) Successful in 3s
2026-09-23 04:18:13 +00:00
renovate-bot 584a383d22 Update renovate/renovate Docker tag to v44.106.0
CI / full-gate (push) Successful in 2m54s
Mirror / github-mirror (push) Successful in 4s
2026-09-22 04:18:10 +00:00
renovate-bot 28dbc1a0ff Update renovate/renovate Docker tag to v44.104.2
CI / full-gate (push) Successful in 2m55s
Mirror / github-mirror (push) Successful in 3s
2026-09-21 04:17:58 +00:00
renovate-bot 0f0a842f34 Update axllent/mailpit Docker tag to v1.31.2
CI / full-gate (push) Successful in 2m51s
Mirror / github-mirror (push) Successful in 3s
2026-09-20 04:17:54 +00:00
renovate-bot 88c5357268 Update dependency @types/node to v24.13.6
CI / full-gate (push) Successful in 3m54s
Mirror / github-mirror (push) Successful in 3s
2026-09-19 04:18:32 +00:00
renovate-bot 3bd9adc73b Update dependency lucide-static to v1.47.0
CI / full-gate (push) Successful in 3m3s
Mirror / github-mirror (push) Successful in 2s
Release-Bump: minor
2026-09-18 04:18:38 +00:00
renovate-bot 51c95b32c1 Update renovate/renovate Docker tag to v44.95.0
CI / full-gate (push) Successful in 3m45s
Mirror / github-mirror (push) Successful in 2s
2026-09-17 04:18:20 +00:00
renovate-bot 3593b39e43 Update dependency @types/node to v24.13.5
CI / full-gate (push) Successful in 3m4s
Mirror / github-mirror (push) Successful in 2s
2026-09-16 04:18:00 +00:00
lilleman 5f9d74ae4f Record that state lives in the URL or on the server, never in a cookie
CI / full-gate (push) Successful in 2s
Mirror / github-mirror (push) Successful in 3s
2026-09-15 14:21:44 +02:00
renovate-bot 79cee25b66 Update dependency lucide-static to v1.46.0
CI / full-gate (push) Successful in 3m3s
Mirror / github-mirror (push) Successful in 3s
Release-Bump: minor
2026-09-15 04:18:12 +00:00
lilleman 2993b462a1 Ask for dependent form fields in steps, one GET form each
CI / full-gate (push) Successful in 2s
Mirror / github-mirror (push) Successful in 3s
2026-09-14 17:06:03 +02:00
renovate-bot 7645f0302a Update renovate/renovate Docker tag to v44.83.2
CI / full-gate (push) Successful in 2m51s
Mirror / github-mirror (push) Successful in 2s
2026-09-14 04:18:17 +00:00
renovate-bot e5531a44cd Update renovate/renovate Docker tag to v44.82.5
CI / full-gate (push) Successful in 2m49s
Mirror / github-mirror (push) Successful in 2s
2026-09-13 04:17:52 +00:00
renovate-bot 3b1cd891ed Update dependency lucide-static to v1.45.0
CI / full-gate (push) Successful in 3m52s
Mirror / github-mirror (push) Successful in 2s
Release-Bump: minor
2026-09-12 04:18:26 +00:00
renovate-bot f06040b511 Update dependency lucide-static to v1.44.0
CI / full-gate (push) Successful in 3m4s
Mirror / github-mirror (push) Successful in 3s
Release-Bump: minor
2026-09-11 04:18:09 +00:00
lilleman 58767cb53e Say what the comment is for, not what the bug was
CI / full-gate (push) Successful in 2m49s
Mirror / github-mirror (push) Successful in 3s
Release / retag-image (push) Successful in 17s
Release / publish-overview (push) Successful in 3s
2026-09-10 16:16:35 +02:00
lilleman 16873662b9 Keep the reader in place when the drawer closes, and stop the CSS promising a header it deleted 2026-09-10 16:16:35 +02:00
lilleman 53ab35bfb8 A page is a document: drop the sticky chrome and the bounded-frame opt-out 2026-09-10 16:16:35 +02:00
lilleman 60aa8a888e Point the contract doc at a heading that exists, and let the table say which axes it scrolls 2026-09-10 16:16:35 +02:00
lilleman 2f29853121 Make the scroll-lock test able to fail, and name the tell a broken chain actually shows 2026-09-10 16:16:35 +02:00
lilleman 41aa59d05d One home per fact: cut the copied rationale, and give the seam test room to mean something 2026-09-10 16:16:35 +02:00
lilleman cb4f8d6e98 Name the table's local after the class it applies, and let a broken chain show itself 2026-09-10 16:16:35 +02:00
lilleman 696da397e7 Split the fill seam where ownership splits: the shell bounds, the page fills 2026-09-10 16:16:35 +02:00
lilleman 7f2c0cc2c2 Name the bounded frame: fill:true on the shell, and the contract minor that ships it 2026-09-10 16:16:35 +02:00
lilleman b9129fba08 Scroll the document by default; a bounded region is a page's own opt-in 2026-09-10 16:16:35 +02:00
lilleman cb4468ff77 Regenerate the icon sprite: lucide 1.39.0 redraws circle-check
CI / full-gate (push) Successful in 2m57s
Mirror / github-mirror (push) Successful in 3s
2026-09-10 16:16:31 +02:00
renovate-bot 5ffa682fe7 Update dependency lucide-static to v1.39.0
Release-Bump: minor
2026-09-10 16:16:31 +02:00
renovate-bot fbc1633a1a Update renovate/renovate Docker tag to v44.75.1
CI / full-gate (push) Successful in 2m48s
Mirror / github-mirror (push) Successful in 3s
2026-09-10 16:14:07 +02:00
renovate-bot bebefeafde Update Node.js to v24.21.0
CI / full-gate (push) Successful in 3m2s
Mirror / github-mirror (push) Successful in 3s
Release-Bump: minor
2026-09-10 04:18:10 +00:00
renovate-bot 465055e699 Update renovate/renovate Docker tag to v44.69.13
CI / full-gate (push) Successful in 2m48s
Mirror / github-mirror (push) Successful in 3s
2026-09-09 04:18:05 +00:00
renovate-bot db56a32e29 Update renovate/renovate Docker tag to v44.69.7
CI / full-gate (push) Successful in 2m49s
Mirror / github-mirror (push) Successful in 3s
2026-09-08 04:18:04 +00:00
renovate-bot 51219a3ee5 Update renovate/renovate Docker tag to v44.65.5
CI / full-gate (push) Successful in 2m48s
Mirror / github-mirror (push) Successful in 3s
2026-09-07 04:17:57 +00:00
12 changed files with 41 additions and 28 deletions
+1 -1
View File
@@ -19,4 +19,4 @@ jobs:
run: |
docker run --rm -v "$PWD:/repo" -w /repo \
-e REGISTRY_TOKEN -e REGISTRY_USER -e REPO_TOKEN -e REPOSITORY -e SERVER_URL \
node:24.20.0-alpine3.24 node registry-cleanup/cleanup.ts
node:24.21.0-alpine3.24 node registry-cleanup/cleanup.ts
+3 -3
View File
@@ -21,7 +21,7 @@ jobs:
GIT_TAG: ${{ github.ref_name }}
run: |
set -euo pipefail
docker run --rm -v "$PWD:/repo" -w /repo node:24.20.0-alpine3.24 \
docker run --rm -v "$PWD:/repo" -w /repo node:24.21.0-alpine3.24 \
node release-tooling/contract-version.ts "$GIT_TAG" src/plugin-host/plugin.ts
- name: Promote the commit-hash image to semver + latest
env:
@@ -98,9 +98,9 @@ jobs:
VERSION=${INPUT_VERSION:-${GIT_TAG#v}}
VERSION=${VERSION#v}
# An empty dispatch input falls back to the branch name, so gate this like a tag.
docker run --rm -v "$PWD:/repo" -w /repo node:24.20.0-alpine3.24 \
docker run --rm -v "$PWD:/repo" -w /repo node:24.21.0-alpine3.24 \
node release-tooling/contract-version.ts "$VERSION" src/plugin-host/plugin.ts
docker run --rm -v "$PWD:/repo" -w /repo \
-e DOCKERHUB_REPO -e DOCKERHUB_TOKEN -e DOCKERHUB_USER \
node:24.20.0-alpine3.24 \
node:24.21.0-alpine3.24 \
node release-tooling/dockerhub-overview.ts "$VERSION"
+3 -3
View File
@@ -21,7 +21,7 @@ jobs:
-e RENOVATE_PLATFORM=gitea \
-e RENOVATE_REPOSITORIES=${{ github.repository }} \
-e RENOVATE_TOKEN \
renovate/renovate:44.61.6
renovate/renovate:44.111.4
# After the renovate job, cut ONE tag covering the renovate-bot commits merged to main since the
# last tag (batch per run). Targets origin/main — the real post-merge tip; the checkout SHA is the
@@ -58,11 +58,11 @@ jobs:
if [ -z "$BUMPS" ]; then
echo "Renovate commits since ${LATEST}, but none carry Release-Bump — nothing reached a running Plainpages; skipping"; exit 0
fi
NEXT=$(docker run --rm -v "$PWD:/repo" -w /repo node:24.20.0-alpine3.24 \
NEXT=$(docker run --rm -v "$PWD:/repo" -w /repo node:24.21.0-alpine3.24 \
node release-tooling/next-version.ts "$LATEST" $BUMPS)
# Read the constant off origin/main, not the checkout, which lags the merges this run made.
git show origin/main:src/plugin-host/plugin.ts \
| docker run -i --rm -v "$PWD:/repo" -w /repo node:24.20.0-alpine3.24 \
| docker run -i --rm -v "$PWD:/repo" -w /repo node:24.21.0-alpine3.24 \
node release-tooling/contract-version.ts "$NEXT" -
echo "Releasing $LATEST -> $NEXT"
git tag "$NEXT" origin/main
+6 -3
View File
@@ -447,9 +447,12 @@ one-time setup. A file-map or table row gets a clause, not a paragraph.
same rule in their own language. An unmapped Kratos id renders Kratos' own wording — map the id when
it matters. **Held by the author, never by a test:** slightly different wording is often the right
call, and a build-failing check takes that judgment away.
- Use well formed, standard compliant, rich URIs. Prefer state in the URL over POSTing it, for
example on list pages with filters and pagination. Do `ids=x&ids=y`, not `ids[]=x&ids[]=y` and not
`ids=x,y`.
- Use well formed, standard compliant, rich URIs. **State lives in the URL or on the server, never in
a cookie.** Prefer state in the URL over POSTing it, for example on list pages with filters and
pagination. A message for the page a redirect lands on rides its query string — `info-msg`,
`warn-msg`, `error-msg` — since a fragment never reaches the server. A cookie carries only what
must be bound to the browser: the session (`plainpages_jwt`) and the CSRF token (`plainpages_csrf`).
Do `ids=x&ids=y`, not `ids[]=x&ids[]=y` and not `ids=x,y`.
## Comments
+1 -1
View File
@@ -1,5 +1,5 @@
# Node 24 runs TypeScript directly (type stripping) — no build step. Pinned exact tag.
FROM node:24.20.0-alpine3.24
FROM node:24.21.0-alpine3.24
# Above WORKDIR so dev's `.:/app` bind mount can't shadow them; a volume at /app/node_modules
# instead leaves a root-owned dir in the checkout (the daemon creates mount destinations as root).
+10
View File
@@ -961,6 +961,16 @@ underneath it — cramped, but nothing is unreachable. List state
(`?q=…&status=…&sort=…&page=…`) lives **in the URL**, so a view is bookmarkable and shareable; the
URL is the only state the UI keeps.
**A field whose options depend on another field is asked for in steps, one GET form each**, so every
choice is in the URL, and nothing typed is lost to one because nothing is typed until they are made.
Once the query names a value, that field renders read-only (`field` with `readonly`, and a `link` back
to the URL without it) above the next step's form, which carries the earlier choices as hidden inputs,
plus `locale` from `localeParam`. The form that writes comes last and posts to the URL naming every
choice, so its handler reads them from `ctx.query`, never from the body; a value the query names that
the step does not offer is that step's error, never a silent fallback. Don't redraw a half-filled form
through a submit that writes nothing instead: a `required` field blocks it, and the choice never
reaches the URL.
Plugins that genuinely need it — live dashboards, bulk actions, client-side validation — may **opt
into progressive enhancement** (htmx, Alpine, vanilla JS) on top of working server-rendered HTML.
The baseline never depends on it.
+2 -2
View File
@@ -49,7 +49,7 @@ services:
# backs it (PLUGIN_SETTING_SCHEDULING_UPSTREAM above points here). Stand-in for the customer's real service —
# stdlib-only, in-memory, no auth. Prod points PLUGIN_SETTING_SCHEDULING_UPSTREAM at the real backend instead.
shifts-upstream:
image: node:24.20.0-alpine3.24
image: node:24.21.0-alpine3.24
command: node /srv/server.ts
restart: unless-stopped
volumes:
@@ -58,7 +58,7 @@ services:
# Dev mail catcher — Kratos recovery/verification emails land here (web UI on 8025).
# kratos.yml points the courier at smtp://mailpit:1025; prod uses a real SMTP via env.
mailpit:
image: axllent/mailpit:v1.31.1
image: axllent/mailpit:v1.31.2
ports:
- "8025:8025"
restart: unless-stopped
+3 -3
View File
@@ -53,7 +53,7 @@ services:
# The reference plugin's upstream (examples/shifts-upstream) so /scheduling/shifts shows real rows.
shifts-upstream:
image: node:24.20.0-alpine3.24
image: node:24.21.0-alpine3.24
command: ["node", "/server.ts"]
volumes:
- ./examples/shifts-upstream/server.ts:/server.ts:ro
@@ -66,7 +66,7 @@ services:
# Mock OIDC provider for the SSO login test — stdlib Node, auto-approves, signs an id_token Kratos
# verifies via its jwks. Reachable as the same host (mock-oidc:9000) by both the browser and Kratos.
mock-oidc:
image: node:24.20.0-alpine3.24
image: node:24.21.0-alpine3.24
command: ["node", "/mock-oidc.ts"]
environment:
ISSUER: http://mock-oidc:9000
@@ -81,7 +81,7 @@ services:
# Same-origin gateway: Kratos-owned paths → kratos, everything else → web (e2e-tests/proxy.ts).
proxy:
image: node:24.20.0-alpine3.24
image: node:24.21.0-alpine3.24
command: ["node", "/proxy.ts"]
depends_on:
web:
+8 -8
View File
@@ -8,12 +8,12 @@
"dependencies": {
"@larvit/log": "2.3.0",
"ejs": "6.0.1",
"lucide-static": "1.34.0",
"lucide-static": "1.48.0",
"postgres": "3.4.9"
},
"devDependencies": {
"@types/ejs": "3.1.5",
"@types/node": "24.13.3",
"@types/node": "24.13.6",
"typescript": "7.0.2"
},
"engines": {
@@ -37,9 +37,9 @@
"license": "MIT"
},
"node_modules/@types/node": {
"version": "24.13.3",
"resolved": "https://registry.npmjs.org/@types/node/-/node-24.13.3.tgz",
"integrity": "sha512-Dh8vAsV36ig5wa9OX4pXvMc9D3Veibfw2wix0CUwYODLD8nkj9UsLjASr49nPg+2eKzxhBV+v7L8pXvT4e639Q==",
"version": "24.13.6",
"resolved": "https://registry.npmjs.org/@types/node/-/node-24.13.6.tgz",
"integrity": "sha512-SGrw/h3KPFshy3OE6ZL53LMBG5vGQQ8/gIpiqz/kRZhPJ7HgwCEs8LBuNtWLa8dvGZVpSF7+Bf+c11HUrCb/yg==",
"dev": true,
"license": "MIT",
"dependencies": {
@@ -399,9 +399,9 @@
}
},
"node_modules/lucide-static": {
"version": "1.34.0",
"resolved": "https://registry.npmjs.org/lucide-static/-/lucide-static-1.34.0.tgz",
"integrity": "sha512-pSUvFhfhvDnhXN1fXerZEMgKLQQ3DneKwFYlqB5ji8OEAN0iPi/qgwQvCkcL519QgMeR66IpS/pT342VyT/g4g==",
"version": "1.48.0",
"resolved": "https://registry.npmjs.org/lucide-static/-/lucide-static-1.48.0.tgz",
"integrity": "sha512-ZUGgZ4rzlLfVbhN2Zi37TMrTaSpXAbWx6Y/xZxKSDLPiqxtTK7Mw2M+oBJa0gjV8p3+CWBHh48u+IC9+jKlUjA==",
"license": "ISC"
},
"node_modules/postgres": {
+2 -2
View File
@@ -18,12 +18,12 @@
"dependencies": {
"@larvit/log": "2.3.0",
"ejs": "6.0.1",
"lucide-static": "1.34.0",
"lucide-static": "1.48.0",
"postgres": "3.4.9"
},
"devDependencies": {
"@types/ejs": "3.1.5",
"@types/node": "24.13.3",
"@types/node": "24.13.6",
"typescript": "7.0.2"
}
}
+1 -1
View File
@@ -131,7 +131,7 @@ services:
# Catches Kratos' recovery/verification emails — UI on http://localhost:8025
mailpit:
image: axllent/mailpit:v1.31.1
image: axllent/mailpit:v1.31.2
ports:
- "8025:8025"
restart: unless-stopped
+1 -1
View File
@@ -6,7 +6,7 @@
<symbol id="i-box" viewBox="0 0 24 24"><path d="M21 8a2 2 0 0 0-1-1.73l-7-4a2 2 0 0 0-2 0l-7 4A2 2 0 0 0 3 8v8a2 2 0 0 0 1 1.73l7 4a2 2 0 0 0 2 0l7-4A2 2 0 0 0 21 16Z" /><path d="m3.3 7 8.7 5 8.7-5" /><path d="M12 22V12" /></symbol>
<symbol id="i-cal" viewBox="0 0 24 24"><path d="M8 2v3" /><path d="M16 2v3" /><rect x="3" y="3" width="18" height="18" rx="2" /><path d="M3 9h18" /></symbol>
<symbol id="i-chart" viewBox="0 0 24 24"><path d="M5 21v-6" /><path d="M12 21V3" /><path d="M19 21V9" /></symbol>
<symbol id="i-check-circle" viewBox="0 0 24 24"><circle cx="12" cy="12" r="10" /><path d="m9 12 2 2 4-4" /></symbol>
<symbol id="i-check-circle" viewBox="0 0 24 24"><circle cx="12" cy="12" r="10" /><path d="m16 9-5.5 5.5L8 12" /></symbol>
<symbol id="i-chev" viewBox="0 0 24 24"><path d="m9 18 6-6-6-6" /></symbol>
<symbol id="i-cols" viewBox="0 0 24 24"><rect width="18" height="18" x="3" y="3" rx="2" /><path d="M9 3v18" /><path d="M15 3v18" /></symbol>
<symbol id="i-copy" viewBox="0 0 24 24"><rect width="14" height="14" x="8" y="8" rx="2" ry="2" /><path d="M4 16c-1.1 0-2-.9-2-2V4c0-1.1.9-2 2-2h10c1.1 0 2 .9 2 2" /></symbol>