Официальный сайт SLAED CMS
Журнал изменений
Step 37 of the roadmap, EDITOR batch 10: every frame of the shell can show what the reader will see, a file template filled with sample files of the panel theme and a text rendered by the parser through a POST route, both in a sandboxed frame. The screenshot rig that guards such changes now walks the manifest in parallel, shoots only the states a change can reach, and no longer reports the live figures of the stand as theme changes.
Core changes:
- Preview data and route (core/classes/editor.php, core/helpers.php, public/index.php):
previewis a key of the page likevars: 'text' or the sample values of a template with an address to open- getPageData() validates it, getViewData() hands the frame its route, token, module and store, or the values
- getTplTextarea() passes 'text' for every field
getEditorPreview() answers go=1 on the site and go=5 in the panel, POST only (405 otherwise)
- the save filter of the format and checkEditorTextRoom() run first, as a save runs them
- an attachment of a closed owner is drawn in the context of an unsaved text, [getUploadOwner($mod), 0]
- the answer ends there, so the debug block of the door stays out of the frame
- File template samples (admin/modules/uploads.php, core/classes/filemanager.php, public/templates/admin/assets/samples/):
- getTemplateSample() fills the variables as the parser does for one file: picture, sound, video, PDF, archive
- four bundled samples, 24 KB together; a PDF falls back to its link in the sandbox and the pane links the sample
- FileManager::getFileKind() becomes public and static for it
- Shell and runtime (public/plugins/system/editor.js, editor-frame.html and editor-kit.html of both themes):
- the eye in the capsule and a palette row; the pane under the text, beside it on the full screen
- the page is written by srcdoc with the stylesheets and colour mode of the page, sandbox="allow-same-origin" without scripts
- an older answer is dropped, the frame height follows the page through a ResizeObserver
- Theme (theme.css of both themes, tools/ui-contract.php, lang/*.php):
- pane, sheet and side-by-side full screen rules on existing tokens; --sl-d-view-height registered
- _EDITOR_SAMPLE in six locales
- Screenshot rig (tools/ui-shots.mjs, tools/ui-shots.json, package.json):
- the viewport is stretched to the document once instead of a full-page shot per try, which fired a resize every time
- a pool of four slots, each with its own PHP session, saved between runs
a DOM snapshot beside every picture; a check shoots only a state whose DOM moved, which loaded a public file changed since the capture, or which a changed CSS rule still matches; a DIFF names the elements that moved
- PNG comparison in Node through pngjs with the former metric; noise floors kept between runs and measured from a fresh load
- masks after a step that navigates, no focus in a base state, list boxes scrolled alike
- the footer timing of the panel and the live rings, bars and charts of the presentation are masked
Benefits:
- an author sees the rendered text or template before saving, in every engine of the shell
- a full before takes about 3.5 to 4 minutes and an after about 3, against 10 to 15 for each before
- the false differences of the front page, the presentation and the file block code state are gone
Technical notes:
- new route op getEditorPreview in go=1 and go=5; no schema change
- new dev dependency pngjs 7.0.0
- tests: EditorFormatTest::previewFollowsItsCaller; ui:gates green, phpstan and php-cs-fixer clean
- the 11 failing NodeProfileTest methods fail on the clean HEAD as well (installer probe)
Plain Plus and CodeMirror now take the variables of a template from their caller with a list, a hint at the caret and marks, check an html template with a badge, a list and fixes of one click, and compare the present text with the loaded one in a window of the canon. Roadmap steps 34 to 36 (editor plan batches 7 to 9); the schema plan for 8.0 joins the roadmap as steps 51 to 58.
Core changes:
- Variables and the hint (core/classes/editor.php, public/plugins/system/editor.js, fragments editor-kit.html and editor-frame.html):
vars is a map of a word in brackets to its description; Editor::getPageData() reads it for getCode() and getContent() and getFrame() empties it, so the interfaces keep their signatures and the next frame starts clean
The frame hands the pairs over as data-sl-editor-vars; the capsule gains the list and the hint (Ctrl+Space), the palette a group of its own with one row a variable
One list .sl-editor-hint serves Plain Plus at the caret and every engine under the capsule button: arrows choose, Enter, Tab or a click insert as one step of undo, a used variable is ticked
- CodeMirror marks the known variables and completes them after a bracket through one language data source
- The status line counts the variables used
- Template check and format (core/classes/editor.php, public/plugins/system/editor.js, fragments):
lint is a key like vars, kept only for html; getIssues() is one check for every engine: unknown variable with the nearest known one, a tag left open or closed twice, img without alt, _blank without noopener, a value without quotes, a template without [src]
A textarea checks after a pause, CodeMirror through linter() with its gutter; both write the badge, the rail and one list from the kit, a row selects the place, its button applies the fix found again in the present text
"Tag on a line" and "join into one line" need the check, in the capsule and in the palette under Format; Ctrl+Shift+M opens the findings, F8 steps through them in CodeMirror
- Comparison (fragments editor-kit.html and editor-frame.html, public/plugins/system/editor.js, theme.css):
A dialog.sl-modal.sl-modal-lg in the kit, cloned once per page: the views "together" and "side by side", the count of units gone and new, "restore before" and "keep after"; it opens from the capsule, the palette and the dirty mark of the status line, which became a button
Computed only when opened and written as text nodes with del and ins; the shared head and tail are cut first, the middle is aligned by its longest common subsequence up to four million cells, else by lines and the changed lines by units; an 80 KB text with three edits opens in about 100 ms
- "Restore before" writes the loaded text after the window has closed, one step of undo
- Callers and texts (admin/modules/uploads.php, admin/lang/, lang/):
- tplconfig is the first caller: it passes its variables and asks for the check
_TPINFO and the markup it carried leave the admin locales; ten UPLOADS* constants describe the variables and the alert above the form lists them, which fixes the French and Polish lines naming the wrong variables
- Thirty EDITOR* constants in six locales for the variables, the check, its fixes and the comparison
- Themes (templates admin and lite, theme.css, tools/ui-contract.php, tools/ui-audit-baseline.json):
Rules of the hint, the findings, the badge and the comparison in both themes on their own tokens; the fix button and the selected row of list and CodeMirror share one rule
The editor tab gives way to the capsule and cuts its words instead of wrapping, so a capsule unseen at rest never makes an editor taller
- The resets of the palette and the comparison bodies outrank the canon spacing of the window body, which overrode them
- --sl-d-hint-x and --sl-d-hint-y registered; the audit baseline is stored
- Tests and plans (tests/Unit/EditorFormatTest.php, docs/*):
- EditorFormatTest checks the variables, the check and the comparison through both doors, the kit and the runtime
- The editor plan records batches 7 to 9 and decision 13; WINDOW.md lists the editor comparison
docs/7-SCHEMA-2026.md plans one set of column domains, the time rule, the connection contract, the collation, unique email and keys that serve queries; the roadmap ticks steps 34 to 36 and adds the schema steps
Benefits:
- A template is written with its variables at hand and checked before it is saved
- Every change can be seen against the loaded text before the form is sent, at any length of text
Technical notes:
- Stored content and the editor interfaces are unchanged; no schema, address or API change
- Rows of editors with a long tab are one line now, 29 px lower where the capsule used to wrap above the tab
- Gates: ui:gates and the editor and file format tests pass; the audit baseline is stored
Plain Plus and CodeMirror as text now insert files and emoji as Toast UI does, through one adapter of the shell runtime, and both engines carry the capsule of the final face with only the commands each one serves, a command palette that is a window of the canon, the Markdown commands with a list continued by Enter, and a counter of the room the text column leaves. Roadmap steps 32 and 33 (editor plan batches 5 and 6).
Core changes:
- File window for every text engine (core/helpers.php, core/classes/editor.php, public/plugins/system/editor.js, filemanager.js):
getEditorFileKit() works out the options and draws the file window, the gallery and the insert options once for Plain Plus, CodeMirror and Toast UI; the window ids are <id>_fm* for every engine
- A text whose field names an upload place carries the options as data-sl-editor-files; code takes none
The adapter getPort() answers focus(), insertText(), exec('addImage'), getMarkdown() and addHook('addImageBlobHook'); SlaedFileManager.addUpload() binds it on first use and api.addPanel opens the window
- A picture is written in the format of the field: Markdown for markdown, the [img] tag otherwise
- A pasted or dropped image goes to the window as Toast UI's hook sends it; a paste carrying text/rtf stays text
- The forum's insert of a name reaches a text under CodeMirror through SlaedEditor.getEditor()
- Emoji in the shared runtime (public/plugins/system/emoji.js, emoji/<locale>.js, partials emoji-panel.html):
- Script, six word files, templates and rules leave the Toast UI plugin and skins; SlaedEmoji replaces SlaedToastUi
Editor::getEmojiPanel() prints the panel once per answer; Plain Plus and CodeMirror load it on the first press, Toast UI with its page; every text offers it, code never
- Capsule and palette (fragments editor-kit.html and editor-frame.html, public/plugins/system/editor.js):
The capsule stands in groups, each command marked with what it needs (cm, code, text, markdown, files); the runtime drops what the frame cannot serve and an empty group, the theme draws the line between groups
The capsule keeps to one line within --sl-capsule-max-width and scrolls the rest, so a capsule unseen at rest never makes an editor taller; under 900 points the folds leave it, under 560 copy and reset
The palette is a modal dialog.sl-modal inside the kit, cloned once per page: groups Edit, Format, Insert, View, a filter by letters in their order with the matches marked, the last command raised with the word of the locale, the keys of the engine under the list, Esc closing at once over a typed search
- A command runs once the palette has closed and given the focus back, once per choice however often it is pressed
- Ctrl+K is heard only inside a frame; Ctrl+B and Ctrl+I only in the text of a Markdown field
- Markdown commands and counter (public/plugins/system/editor.js, core/classes/editor.php):
Bold, italic, code, link, list and quote put their mark around the selection or take it away; code over several lines becomes a fence; a link selects url to be typed over, a selected address becomes the target
A textarea continues a bullet, numbered, task and quote list by Enter and ends it on an empty item; CodeMirror does that through its Markdown grammar
- The commands follow the format of the field: CodeMirror as text has them, Plain Plus only on a markdown field
data-sl-editor-room carries the room of a text column; the status line says what is left in bytes and turns to _ETEXTLONG once the text no longer fits; mediumtext columns and code show no counter
- Themes (templates admin and lite, base.css, theme.css, editor skins):
- Palette, capsule groups, counter and emoji panel rules byte-identical in both themes; Toast UI skins lose the panel
- --sl-capsule-max-width declared in both API blocks; component capsule declared in tools/ui-contract.php
- .sl-editor-sep gone, the line between groups is a pseudo-element
- Texts, tests and plans (lang/, tests/Unit/, docs/*):
- Thirty-one EDITOR* constants in six locales; _CODE, _URL, _LIST, _QUOTE, _EFULLSCREEN and _EDITOR_NONE reused
EditorFormatTest checks the capsule, the palette and the counter of the column; the file manager tests follow the resolver, which opens md as Markdown and ini as INI since the batch that added those grammars
Editor plan records batches 5 and 6 and decisions 8 to 12; WINDOW.md lists the editor palette; roadmap steps 32 and 33 done
Benefits:
- One shell gives every text engine the same file window, emoji, commands and keys
- Every command stays reachable from the palette, whatever the width of the row
Technical notes:
- Stored content is unchanged; Plain Plus still stores plain, so its Markdown commands wait for a markdown field
- The counter measures the raw text; the server measures the filtered value, which a plain text makes longer
Gates: ui:gates, the editor, language, file manager and asset version tests pass; the audit baseline is stored; NodeProfileTest stays red as on the previous commit (the install probe)
Plain Plus and CodeMirror share one editor shell with a runtime, a capsule and the window standard of the panel; CodeMirror is now also a text editor that stores Markdown, offered to members and administrators. Code shown on the site and in the panel reads one mono face and the token tones of the theme, and every code block, BB or fenced, carries its language, a copy button and a fold for long code.
Core changes:
- Editor shell and runtime (core/classes/editor.php, public/plugins/system/editor.js, fragments editor-frame.html and editor-kit.html):
- Plain Plus and CodeMirror render one frame: tab, capsule, status line, draft of the tab in sessionStorage
- CodeMirror loads as a core and one grammar per frame when it comes into view; the textarea keeps carrying the value
- The floor of CodeMirror is the measured height of its field, so a form does not jump when it mounts
- An empty required text under CodeMirror marks the frame and takes the focus instead of blocking silently
- A whole-text replacement raises input like typing, so dirty forms and save bars notice it
- The capsule is lifted, movable by its grip and uses the window standard: move, expand and collapse labels and icons
- CodeMirror as a text editor (public/plugins/editors/codemirror/*):
- One getWidget() serves ContentDriver and CodeDriver; the manifest declares type ["content", "code"]
- Formats markdown, plain, html with Markdown stored, as Toast UI stores it; listed after Toast UI for both roles
- Text keeps spell check and the face of the page and has no line numbers (textSetup); Tab moves to the next field
Split build: core, lang-* files and shared chunks; Markdown on the GitHub base, INI from the official legacy modes, and own grammars for Apache and robots.txt
The editor screen highlights .htaccess as Apache and robots.txt as TXT; the file manager opens md as Markdown, ini as INI and robots.txt with its grammar
- Themes (templates admin and lite, base.css, theme.css, presentation.css):
- The rail of the frame is the left border of tab and card, running top to bottom with no line crossing it
- Lite gained the CodeMirror rules for a text; keyword and string tones raised to hold AA on the card
--sl-face-mono and --sl-face-quote declared in both themes; code, kbd, samp, pre, [code] and the presentation read them; Georgia, Courier and the old mono stacks are gone; the code editor sets 14px
- The window head and every grip take the grab and grabbing hand; collapse of a window reads "collapse"
- Dead .sl-editor-area rules and the is_editor_area branch removed; --sl-editor-height is the fallback floor
- Font ladder 12/13/14 in the contract and the rules, following the owner's micro and small sizes
- Code blocks (core/classes/parser.php, fragment code-block.html, public/plugins/system/slaed.js):
[code], [php], fenced and indented code render one block: the language, a copy button without line numbers, a fold above 25 lines, a body that takes the keyboard focus and scrolls
The highlight.js styling moved from the plugin into both themes on the CodeMirror tones, with dark mode; plugins/highlightjs/slaed-theme.css and its css_f default removed
- Highlight modes 0 and 1 no longer show the <?php prefix PHP 8.3+ leaves; the first line of code keeps its indent
- Copying a share address and a code block is one setCopyText()
- Panel screens and texts (admin/modules/template.php, editor.php, config.php, admin/info, lang/*):
- The template screen shows file and date in the editor tab and drops the separate row
- Plain Textarea is shown as Plain Plus; the help lists CodeMirror among the content editors
- Constants: _COPY, _COPYDONE, _SHOWALL, _COLLAPSE added; _ERESTORE reads collapse; editor-only copies removed
- Plans and stand (docs/, public/demo/):
- Roadmap step 31 done; editor plan records batch 4 and its decisions; pager plan, core 2027 plan and pager stand pages
Benefits:
- One editor standard and one window standard across both engines and both themes
- Code reads the same everywhere, follows the dark scheme and copies cleanly
Technical notes:
- Stored content is unchanged; CodeMirror as text stores Markdown like Toast UI
- css_f defaults to empty; an old path to the removed plugin stylesheet is skipped by getAssetList()
- Gates: ui:gates and the parser, editor, language and file format tests pass; the audit baseline is stored
Steps 28 and 29 of docs/ROADMAP-2026.md (batches 1 and 2 of docs/4-EDITOR-2026.md). The code editor is painted by the theme tokens in place of One Dark and speaks the locale in its panels; one check in Editor reads the manifest field type as a string or a list, so one plugin can serve as a text and a code editor; and the build writes the core and every language as files of their own, which the runtime of batch 3 loads on demand.
Core changes:
CodeMirror in the theme (public/plugins/editors/codemirror/driver.php, public/plugins/editors/codemirror/assets/cm6.css, public/templates/admin/assets/css/base.css, public/templates/admin/assets/css/theme.css, public/templates/lite/assets/css/theme.css, public/templates/admin/fragments/editor-mount.html, public/templates/lite/fragments/editor-mount.html):
The driver writes syntaxHighlighting(classHighlighter), so the theme colours the tok-* classes and the code follows the scheme; One Dark leaves the driver and the build
- The mount of a code editor carries the shell name sl-editor in place of sl-code-editor in both themes
--sl-face-mono and --sl-editor-max-height (50vh) join the admin API block; the height floor stands on .cm-content and .cm-gutter, and cm6.css keeps only the focus outline instead of a fixed 400 px
- The Tahoma rule on .cm-content and the doubled height of a second editor are gone
Line numbers and comments take --sl-text-muted, tags --sl-primary-strong, and the current node of the file tree --sl-primary-strong, so each holds AA
- Phrases of the panels (lang/de.php, lang/en.php, lang/fr.php, lang/pl.php, lang/ru.php, lang/uk.php):
Twenty-five EDITOR* constants for search, fold, go to line, lint, completion and the screen reader announcements; with _ALL, _CLOSE, _EDITOR_PREV and _EDITOR_NEXT the driver hands them to EditorState.phrases
- Manifest type (core/classes/editor.php, admin/index.php, public/plugins/editors/codemirror/manifest.json):
Editor::checkType() answers whether a manifest serves a type given as one string or a list, and replaces the comparisons of getCode(), checkManifest() and getEditorList()
isValidEditor() of admin/index.php, a copy of Editor::isValidEditor() with its own string comparison, is removed; the new administrator and the editor switch of the panel call the class
Editor::getManifest() takes over the one check only the copy made: a manifest whose id differs from its directory is refused, so no key reaches a manifest or a driver outside its own folder
The CodeMirror manifest declares type as ["code"]; content, the user role and the text formats join with its ContentDriver in batch 4, so no list offers a text editor that renders Plain
Split build (public/plugins/editors/codemirror/build/build.mjs, build/core.js, build/entry.js, build/package.json, public/plugins/editors/codemirror/assets/*.js):
ES modules with splitting: core.js, lang-<key>.js for php, html, css, js, json, sql, xml and markdown, each exporting language, and shared chunk-<hash>.js files named by their content
- The build refuses a language file that imports core.js, which a versioned core address would load a second time
- entry.js re-exports core.js and still builds cm6.bundle.js for the current driver until batch 3
- @codemirror/lang-markdown and the packages the exports name join package.json; theme-one-dark leaves
- Tests and registries (tests/Unit/EditorFormatTest.php, tools/ui-audit-baseline.json, tools/ui-contrast.json):
Code editors are handed to the theme as classes and speak the locale; both forms of type and a key leaving its folder; the three lists of getSelect(); a split file for every language of the manifest with no import of the core entry
- The audit baseline counts the two new tokens; the contrast registry is regenerated over the new screens
- Plans (docs/4-EDITOR-2026.md, docs/ROADMAP-2026.md):
Batches 1 and 2 record what was done and measured; batch 3 retires the bundle and the CM6.editors readers; batch 4 completes the manifest; the roadmap ticks steps 28 and 29
Benefits:
- Code follows the light and dark scheme of the panel and is readable at AA
A code screen will load the core and one grammar: 151.8 KB gzip for css or sql, 223.5 KB for php, against 239.5 KB of the bundle on every screen; the core alone is 130.5 KB
- One manifest check for the class and the panel
Technical notes:
- The split files have no user before batch 3; the bundle keeps its size and changes only minifier names
- Chunks are requested without v= and live a week in the browser, safe because their names follow their content
- No schema, address or API changes
Steps 25 to 27 of docs/ROADMAP-2026.md. The private data plan hands its lasting part to the reference and is deleted; batch 0 of the editor plan records the owner's answers, pins the lost <br> to the mount and takes the screenshot baseline; and the mount of getTplTextarea() no longer deletes every stored <br>, which made each save of the account settings strip the signature and the custom menu of every member writing in Markdown.
Core changes:
- Line breaks on mount (core/helpers.php, docs/EDITORS.md, docs/VERSIONS.md):
getTplTextarea() mounts a stored <br>, with the line end after it, as a line end for plain, which nl2br() of the save restores, and as a Markdown hard break, two spaces and a line end, for markdown; html mounts as it is
- replace_break() is no longer part of the mount and keeps its other callers
Measured through one save of the account settings in the browser: the custom menu went from 1475 bytes with 22 tags to 1431 bytes with 22 hard breaks instead of 1387 bytes with none, and a second save changed no byte
EDITORS.md replaces the open defect with "Line Breaks on Mount", the contract with the measurements; VERSIONS.md records the change
- Tests (tests/Unit/EditorBreakTest.php, tests/Support/break_probe.php):
Stored values go through the shipped mount, the browser submit and the save of both formats: the bytes written, a second save that changes nothing, the signature render before and after, and the escaped render of markdown
- The test fails on the old mount in three of its five methods
Private data reference (docs/ARCHITECTURE.md, README.md, UPGRADING.md, docs/VERSIONS.md, admin/info/security/ru.md, docs/2027-CONNECTOR.md, docs/0-PRIVATE-DATA-2026.md, tests/Unit/JournalNameTest.php, tests/Unit/JournalSecretTest.php, tests/Unit/SelfCheckTest.php, tests/Support/check_probe.php, tests/Support/journal_probe.php):
- ARCHITECTURE.md gains "Private Data Boundary": the public/ tree, the two modes, the self-check and the journals
- The security help lists every journal by file and what it holds, and describes the self-check
README.md names the public folders of uploads/ and the self-check; UPGRADING.md describes the self-check, the journals without secrets and their new names; VERSIONS.md records the whole plan, the document root included
- The plan is deleted; the comments of the journal and self-check tests and probes point at the reference
- Editor plan, batch 0 (docs/4-EDITOR-2026.md, tools/ui-shots.json):
- The seven open decisions are answered and settled under "Answered decisions", and the batches follow them
- The screenshot manifest gains the tplconfig, system file, block file, template style and new member screens
- The plan notes that the <br> defect was the mount and is repaired by item 1
- Roadmap (docs/ROADMAP-2026.md):
- Steps 25 to 27 are ticked; step 27, the repair of the <br> defect, was added by the owner before editor batch 1
Benefits:
- No member loses the breaks of a signature or a custom menu by saving an unrelated setting
A markdown break renders as <br> in the escaped render of comments and the forum too, where a stored <br> printed as text
- CodeMirror as a text editor mounts through the same function and does not inherit the loss
Technical notes:
Stored form: a value saved in markdown holds two spaces where it held <br>, two bytes less per break; a line of nothing but a <br> becomes an empty line, so the lines around it render as two paragraphs
Not fixed here: the WYSIWYG mode of Toast UI writes a hard break back as nothing and a <br> as a bare line end; the forward and quote of a private message are still stripped the old way, where only an inline <br> is lost
- No schema, address or API changes
Steps 22 to 24 of docs/ROADMAP-2026.md (batches 2 to 4 of the asset cache plan): the web server gives a style or script with v= in its address a year and any other static file a week, every head script is printed defer in its order, and the reference takes over from the plan, which is deleted. The commit also carries the stand pages and the plans of the Node list header, the 2027 plans of the connector and Vine Monitor, and a toggle that remembers nothing.
Core changes:
- Lifetimes (public/.htaccess, nginx.conf.example):
mod_headers sets public, max-age=31536000, immutable on a CSS or JS request with v= in the query and public, max-age=604800 on any other static kind; the mod_expires block is gone
nginx chooses the same by a server-level $asset_cache on $arg_v, since an if inside a location would drop its try_files, and turns gzip on for the types the .htaccess deflates
Deferred head scripts (core/system.php, core/classes/editor.php, core/classes/parser.php, public/plugins/editors/toastui/driver.php):
- doScript() prints every head script defer in the order of getAssetList(); setHead() always prints it
Editor::getInitScript() waits for DOMContentLoaded while window.SlaedEditors is missing, so an editor of a page load registers its teardown
The editor skin and the toastui emoji file ask the version map instead of the disk; the highlight versions are part of the parser cache key
Settings (config/global.php, admin/modules/config.php, admin/lang/*.php, admin/info/config/ru.md, public/update.php):
script_a (async) and script_b (scripts at the end of the page) leave the shipped configuration, the settings screen, the six admin locales and the help; update.php drops both from a carried 6.2 configuration
Reference (docs/PERFORMANCE.md, docs/TEMPLATES.md, docs/VERSIONS.md, admin/info/editor/ru.md, docs/3-ASSET-CACHE-2026.md, docs/ROADMAP-2026.md):
PERFORMANCE.md describes the versions, the lifetimes by kind, the Apache and nginx rules, the defer order, the compression and the measurement repeated on the stand; TEMPLATES.md the versioned addresses of a theme
- The help of the server files shows the shipped mod_headers and nginx rules instead of mod_expires
VERSIONS.md records the change with the baseline comparison; the plan is deleted, the roadmap ticks steps 22-24 and gains steps 38-46 of the Node head plan
- Toggle scope (public/plugins/system/slaed.js):
- data-sl-toggle-scope="none" keeps no state in localStorage; "path" and the site-wide default stay as they were
Plans and stand pages (docs/5-NODE-HEAD-2026.md, docs/2027-CONNECTOR.md, docs/2027-VINE-MONITOR.md, public/demo/nh-10-unified.html, public/demo/nh-11-full.html, public/demo/nh-12-views.html, public/demo/nh-13-calm.html, public/demo/assets/demo.js):
The Node head plan carries the approved header of nh-13, views by type, the RSS channel, a live list and search hints; the 2027 plans describe the connector and the Vine Monitor module, nothing implemented
- The stand pages nh-10 to nh-13 and their shared script
Tests (tests/Unit/AssetVersionTest.php, tests/Unit/NginxConfigTest.php, tests/Unit/UpdateConfigTest.php, tests/Support/asset_probe.php, tests/Support/update_probe.php):
Every file of public/ is walked through both server files; the head scripts are deferred in the shipped order; neither switch survives a saved form, a rebuilt local.php or the 6.2 update
Benefits:
- A returning visitor fetches only the files whose address changed; a warm page costs one network request
- Script order holds without async tricks; no editor instance leaks its teardown
Technical notes:
Breaking: script_a and script_b are gone from configuration and settings; an Apache without mod_headers sends no lifetime; a theme or plugin file replaced by hand needs config/local.php rebuilt to reach the browsers
- Not checked: Apache without mod_headers and LiteSpeed reading the <If> block
Batch 1 of docs/3-ASSET-CACHE-2026.md (step 21 of docs/ROADMAP-2026.md). A stylesheet or script is printed as file?v=<first ten hex characters of its SHA-1>, so batch 2 can give a versioned file a year in the browser and a changed file still reaches every visitor on the next page. The versions are computed once with config/local.php; a request hashes nothing and stats no asset file.
Core changes:
- Version map and address (core/classes/template.php):
- Template::getAssetVersions() maps every CSS and JS file below templates/ and plugins/ to its version
Template::getAssetUrl() prints an address with the version from $conf['derived']['version']
- dev_mode and a run without the map (setup.php, update.php) hash the file per request
- A file the map does not know stays a plain address
- The companion assets of a template go through it
- Derived configuration and the page head (core/system.php):
- getConfig() stores the map under $conf['derived']['version']; cache_version 5 rebuilds an older local.php
- doCss() and doScript() print the versioned addresses and no longer call file_exists() per file
Other printers (core/classes/editor.php, core/classes/parser.php, core/classes/captcha.php, core/security.php, modules/presentation/index.php, public/setup.php, public/update.php):
Editor::getAssetTags() versions its lists before the page and the htmx branch, so the client loader compares the same address the page carries and an engine is fetched once
- The highlight scripts, the altcha loader, presentation.js, the error page and the installer and updater pages
- Robots screen (admin/modules/editor.php):
- getRobotsButton() drops its own tag of editor-robots.js, which the admin package prints on every panel page
Tests and plans (tests/Unit/AssetVersionTest.php, tests/Support/asset_probe.php, docs/3-ASSET-CACHE-2026.md, docs/ROADMAP-2026.md):
Every head tag of both themes carries the version of its file; a changed file changes its address; the head is printed from the map for a file that does not exist; page and fragment name the same editor address
- The plan's status line records batch 1; the roadmap ticks step 21
Benefits:
- A release reaches returning visitors at once, whatever lifetime batch 2 sets
- No asset stat per request in the page head
Technical notes:
- getAssetList() keeps answering plain addresses; the theme lists and every other printer share one map
Adding or changing a theme or plugin asset needs a config rebuild, as theme assets did before; dev_mode shows it at once
- No schema change, no route change
Batch 0 of docs/3-ASSET-CACHE-2026.md (step 20 of docs/ROADMAP-2026.md). Before any asset address carries a version, the plan lists every place that prints one, every inline script that depends on a loaded file, and a cold and warm measurement of three pages on the stand, so the later batches change a known set and are measured against the same figures.
Core changes:
- Inventory (docs/3-ASSET-CACHE-2026.md):
Every printer of an asset address with its files, its attribute today and what batches 1 and 3 do to it
- doCss(), doScript(), Editor::getAssetTags(), SlaedEditors, Template::getAssetTag(), Parser, Captcha,
the robots screen, the presentation partial, setExit(), setup.php and update.php
- The inline scripts that call a function of a loaded file, and the one real conflict of defer: getInitScript()
- The root .htaccess reference corrected to public/.htaccess
- Baseline (docs/3-ASSET-CACHE-2026.md):
- Start page, list and view, cold and warm, median of three runs: requests, bytes, FCP, DCL and load
- The warm hits come from the heuristic freshness of RFC 9111, not from a header
- Roadmap (docs/ROADMAP-2026.md):
- Step 20 ticked
Benefits:
- Batch 1 versions a known, complete set of printers
- Batch 4 repeats the same measurement against the same figures
Technical notes:
- Documentation only, no code changed
Item 2 of docs/2-PROD-FINDINGS-2026.md (step 19 of docs/ROADMAP-2026.md). addFile() took its second argument as a source file or as the data and told them apart with is_file(), so every new visitor of the statistics probed a path that open_basedir logged as a warning; it now writes data only. The lasting part of the plan moves into VERSIONS.md and the plan file is deleted.
Core changes:
- File writer (core/system.php):
addFile(string $file, string $data, string $mode = 'w'): bool writes or appends exactly the data
- A short write fails and an incomplete append is rolled back, as before
- The unused compression branch leaves with $comp, $del and $max
- updateStatsTrack() calls the new signature for ips.log and user.log
- Tests and probes (tests/Unit/StatsContractTest.php, tests/Support/contract_probe.php):
The append contract reads bool results; data that names an existing file is appended as text, and an address appended under open_basedir raises no warning
- Repeated hits of one signed-in user enter the user set once and the user counter follows the set
- Changelog and plans (docs/VERSIONS.md, docs/ROADMAP-2026.md, docs/2-PROD-FINDINGS-2026.md):
- VERSIONS.md 2026-10-07 records both findings of the plan and the breaking change of addFile()
- The roadmap ticks step 19; docs/2-PROD-FINDINGS-2026.md is deleted
Benefits:
- The statistics no longer fill the PHP log with an open_basedir warning per new visitor
- Data that happens to name a file can never append that file's content
Technical notes:
Breaking: addFile() returns bool instead of the codes 0-3 and drops $comp, $del and $max; a caller that copied a file reads it first
- No schema change