8 Commits

Author SHA1 Message Date
renovate-bot 3400658d1c Update renovate/renovate Docker tag to v44.93.5
CI / full-gate (push) Successful in 2m59s
2026-09-16 04:18:02 +00:00
lilleman 5f9d74ae4f Record that state lives in the URL or on the server, never in a cookie
CI / full-gate (push) Successful in 2s
Mirror / github-mirror (push) Successful in 3s
2026-09-15 14:21:44 +02:00
renovate-bot 79cee25b66 Update dependency lucide-static to v1.46.0
CI / full-gate (push) Successful in 3m3s
Mirror / github-mirror (push) Successful in 3s
Release-Bump: minor
2026-09-15 04:18:12 +00:00
lilleman 2993b462a1 Ask for dependent form fields in steps, one GET form each
CI / full-gate (push) Successful in 2s
Mirror / github-mirror (push) Successful in 3s
2026-09-14 17:06:03 +02:00
renovate-bot 7645f0302a Update renovate/renovate Docker tag to v44.83.2
CI / full-gate (push) Successful in 2m51s
Mirror / github-mirror (push) Successful in 2s
2026-09-14 04:18:17 +00:00
renovate-bot e5531a44cd Update renovate/renovate Docker tag to v44.82.5
CI / full-gate (push) Successful in 2m49s
Mirror / github-mirror (push) Successful in 2s
2026-09-13 04:17:52 +00:00
renovate-bot 3b1cd891ed Update dependency lucide-static to v1.45.0
CI / full-gate (push) Successful in 3m52s
Mirror / github-mirror (push) Successful in 2s
Release-Bump: minor
2026-09-12 04:18:26 +00:00
renovate-bot f06040b511 Update dependency lucide-static to v1.44.0
CI / full-gate (push) Successful in 3m4s
Mirror / github-mirror (push) Successful in 3s
Release-Bump: minor
2026-09-11 04:18:09 +00:00
5 changed files with 22 additions and 9 deletions
+1 -1
View File
@@ -21,7 +21,7 @@ jobs:
-e RENOVATE_PLATFORM=gitea \ -e RENOVATE_PLATFORM=gitea \
-e RENOVATE_REPOSITORIES=${{ github.repository }} \ -e RENOVATE_REPOSITORIES=${{ github.repository }} \
-e RENOVATE_TOKEN \ -e RENOVATE_TOKEN \
renovate/renovate:44.75.1 renovate/renovate:44.93.5
# After the renovate job, cut ONE tag covering the renovate-bot commits merged to main since the # After the renovate job, cut ONE tag covering the renovate-bot commits merged to main since the
# last tag (batch per run). Targets origin/main — the real post-merge tip; the checkout SHA is the # last tag (batch per run). Targets origin/main — the real post-merge tip; the checkout SHA is the
+6 -3
View File
@@ -447,9 +447,12 @@ one-time setup. A file-map or table row gets a clause, not a paragraph.
same rule in their own language. An unmapped Kratos id renders Kratos' own wording — map the id when same rule in their own language. An unmapped Kratos id renders Kratos' own wording — map the id when
it matters. **Held by the author, never by a test:** slightly different wording is often the right it matters. **Held by the author, never by a test:** slightly different wording is often the right
call, and a build-failing check takes that judgment away. call, and a build-failing check takes that judgment away.
- Use well formed, standard compliant, rich URIs. Prefer state in the URL over POSTing it, for - Use well formed, standard compliant, rich URIs. **State lives in the URL or on the server, never in
example on list pages with filters and pagination. Do `ids=x&ids=y`, not `ids[]=x&ids[]=y` and not a cookie.** Prefer state in the URL over POSTing it, for example on list pages with filters and
`ids=x,y`. pagination. A message for the page a redirect lands on rides its query string — `info-msg`,
`warn-msg`, `error-msg` — since a fragment never reaches the server. A cookie carries only what
must be bound to the browser: the session (`plainpages_jwt`) and the CSRF token (`plainpages_csrf`).
Do `ids=x&ids=y`, not `ids[]=x&ids[]=y` and not `ids=x,y`.
## Comments ## Comments
+10
View File
@@ -961,6 +961,16 @@ underneath it — cramped, but nothing is unreachable. List state
(`?q=…&status=…&sort=…&page=…`) lives **in the URL**, so a view is bookmarkable and shareable; the (`?q=…&status=…&sort=…&page=…`) lives **in the URL**, so a view is bookmarkable and shareable; the
URL is the only state the UI keeps. URL is the only state the UI keeps.
**A field whose options depend on another field is asked for in steps, one GET form each**, so every
choice is in the URL, and nothing typed is lost to one because nothing is typed until they are made.
Once the query names a value, that field renders read-only (`field` with `readonly`, and a `link` back
to the URL without it) above the next step's form, which carries the earlier choices as hidden inputs,
plus `locale` from `localeParam`. The form that writes comes last and posts to the URL naming every
choice, so its handler reads them from `ctx.query`, never from the body; a value the query names that
the step does not offer is that step's error, never a silent fallback. Don't redraw a half-filled form
through a submit that writes nothing instead: a `required` field blocks it, and the choice never
reaches the URL.
Plugins that genuinely need it — live dashboards, bulk actions, client-side validation — may **opt Plugins that genuinely need it — live dashboards, bulk actions, client-side validation — may **opt
into progressive enhancement** (htmx, Alpine, vanilla JS) on top of working server-rendered HTML. into progressive enhancement** (htmx, Alpine, vanilla JS) on top of working server-rendered HTML.
The baseline never depends on it. The baseline never depends on it.
+4 -4
View File
@@ -8,7 +8,7 @@
"dependencies": { "dependencies": {
"@larvit/log": "2.3.0", "@larvit/log": "2.3.0",
"ejs": "6.0.1", "ejs": "6.0.1",
"lucide-static": "1.39.0", "lucide-static": "1.46.0",
"postgres": "3.4.9" "postgres": "3.4.9"
}, },
"devDependencies": { "devDependencies": {
@@ -399,9 +399,9 @@
} }
}, },
"node_modules/lucide-static": { "node_modules/lucide-static": {
"version": "1.39.0", "version": "1.46.0",
"resolved": "https://registry.npmjs.org/lucide-static/-/lucide-static-1.39.0.tgz", "resolved": "https://registry.npmjs.org/lucide-static/-/lucide-static-1.46.0.tgz",
"integrity": "sha512-TaDiwNFZ78c+HrZRNWHoR+LVkIOL8ebYOyNYvytdPkaLWE29G9umks6p1aeCE8kSEIoifnlNLPxMvvE3zqT/YA==", "integrity": "sha512-kq1lP/78BxG28VG3Ut2FxMeQElereTrrRwTBeXH7+olxATGcDbsuKRB/v/VKLhPrEu8BvNi6Uh2GvbH3pQcYhg==",
"license": "ISC" "license": "ISC"
}, },
"node_modules/postgres": { "node_modules/postgres": {
+1 -1
View File
@@ -18,7 +18,7 @@
"dependencies": { "dependencies": {
"@larvit/log": "2.3.0", "@larvit/log": "2.3.0",
"ejs": "6.0.1", "ejs": "6.0.1",
"lucide-static": "1.39.0", "lucide-static": "1.46.0",
"postgres": "3.4.9" "postgres": "3.4.9"
}, },
"devDependencies": { "devDependencies": {