3 Commits

Author SHA1 Message Date
renovate-bot 51c95b32c1 Update renovate/renovate Docker tag to v44.95.0
CI / full-gate (push) Successful in 3m45s
Mirror / github-mirror (push) Successful in 2s
2026-09-17 04:18:20 +00:00
renovate-bot 3593b39e43 Update dependency @types/node to v24.13.5
CI / full-gate (push) Successful in 3m4s
Mirror / github-mirror (push) Successful in 2s
2026-09-16 04:18:00 +00:00
lilleman 5f9d74ae4f Record that state lives in the URL or on the server, never in a cookie
CI / full-gate (push) Successful in 2s
Mirror / github-mirror (push) Successful in 3s
2026-09-15 14:21:44 +02:00
4 changed files with 12 additions and 9 deletions
+1 -1
View File
@@ -21,7 +21,7 @@ jobs:
-e RENOVATE_PLATFORM=gitea \
-e RENOVATE_REPOSITORIES=${{ github.repository }} \
-e RENOVATE_TOKEN \
renovate/renovate:44.83.2
renovate/renovate:44.95.0
# After the renovate job, cut ONE tag covering the renovate-bot commits merged to main since the
# last tag (batch per run). Targets origin/main — the real post-merge tip; the checkout SHA is the
+6 -3
View File
@@ -447,9 +447,12 @@ one-time setup. A file-map or table row gets a clause, not a paragraph.
same rule in their own language. An unmapped Kratos id renders Kratos' own wording — map the id when
it matters. **Held by the author, never by a test:** slightly different wording is often the right
call, and a build-failing check takes that judgment away.
- Use well formed, standard compliant, rich URIs. Prefer state in the URL over POSTing it, for
example on list pages with filters and pagination. Do `ids=x&ids=y`, not `ids[]=x&ids[]=y` and not
`ids=x,y`.
- Use well formed, standard compliant, rich URIs. **State lives in the URL or on the server, never in
a cookie.** Prefer state in the URL over POSTing it, for example on list pages with filters and
pagination. A message for the page a redirect lands on rides its query string — `info-msg`,
`warn-msg`, `error-msg` — since a fragment never reaches the server. A cookie carries only what
must be bound to the browser: the session (`plainpages_jwt`) and the CSRF token (`plainpages_csrf`).
Do `ids=x&ids=y`, not `ids[]=x&ids[]=y` and not `ids=x,y`.
## Comments
+4 -4
View File
@@ -13,7 +13,7 @@
},
"devDependencies": {
"@types/ejs": "3.1.5",
"@types/node": "24.13.4",
"@types/node": "24.13.5",
"typescript": "7.0.2"
},
"engines": {
@@ -37,9 +37,9 @@
"license": "MIT"
},
"node_modules/@types/node": {
"version": "24.13.4",
"resolved": "https://registry.npmjs.org/@types/node/-/node-24.13.4.tgz",
"integrity": "sha512-YJ7EqCstVTzIr0fMr7qul/977en+pQHrfmuKIo6Zr9i75Be21dr3MovcfvGtyvi2HAUrRerWps5sMO9I7WaxDw==",
"version": "24.13.5",
"resolved": "https://registry.npmjs.org/@types/node/-/node-24.13.5.tgz",
"integrity": "sha512-TXyindR+lBr22aJIdMQzCFHPHR6cR4js838mRDCSz5hOKWZvZwsXSSiXDmjRj4iJmgl+sR9O+1mkoVBSMadNug==",
"dev": true,
"license": "MIT",
"dependencies": {
+1 -1
View File
@@ -23,7 +23,7 @@
},
"devDependencies": {
"@types/ejs": "3.1.5",
"@types/node": "24.13.4",
"@types/node": "24.13.5",
"typescript": "7.0.2"
}
}