Официальный сайт SLAED CMS
Журнал изменений
Steps 22 to 24 of docs/ROADMAP-2026.md (batches 2 to 4 of the asset cache plan): the web server gives a style or script with v= in its address a year and any other static file a week, every head script is printed defer in its order, and the reference takes over from the plan, which is deleted. The commit also carries the stand pages and the plans of the Node list header, the 2027 plans of the connector and Vine Monitor, and a toggle that remembers nothing.
Core changes:
- Lifetimes (public/.htaccess, nginx.conf.example):
mod_headers sets public, max-age=31536000, immutable on a CSS or JS request with v= in the query and public, max-age=604800 on any other static kind; the mod_expires block is gone
nginx chooses the same by a server-level $asset_cache on $arg_v, since an if inside a location would drop its try_files, and turns gzip on for the types the .htaccess deflates
Deferred head scripts (core/system.php, core/classes/editor.php, core/classes/parser.php, public/plugins/editors/toastui/driver.php):
- doScript() prints every head script defer in the order of getAssetList(); setHead() always prints it
Editor::getInitScript() waits for DOMContentLoaded while window.SlaedEditors is missing, so an editor of a page load registers its teardown
The editor skin and the toastui emoji file ask the version map instead of the disk; the highlight versions are part of the parser cache key
Settings (config/global.php, admin/modules/config.php, admin/lang/*.php, admin/info/config/ru.md, public/update.php):
script_a (async) and script_b (scripts at the end of the page) leave the shipped configuration, the settings screen, the six admin locales and the help; update.php drops both from a carried 6.2 configuration
Reference (docs/PERFORMANCE.md, docs/TEMPLATES.md, docs/VERSIONS.md, admin/info/editor/ru.md, docs/3-ASSET-CACHE-2026.md, docs/ROADMAP-2026.md):
PERFORMANCE.md describes the versions, the lifetimes by kind, the Apache and nginx rules, the defer order, the compression and the measurement repeated on the stand; TEMPLATES.md the versioned addresses of a theme
- The help of the server files shows the shipped mod_headers and nginx rules instead of mod_expires
VERSIONS.md records the change with the baseline comparison; the plan is deleted, the roadmap ticks steps 22-24 and gains steps 38-46 of the Node head plan
- Toggle scope (public/plugins/system/slaed.js):
- data-sl-toggle-scope="none" keeps no state in localStorage; "path" and the site-wide default stay as they were
Plans and stand pages (docs/5-NODE-HEAD-2026.md, docs/2027-CONNECTOR.md, docs/2027-VINE-MONITOR.md, public/demo/nh-10-unified.html, public/demo/nh-11-full.html, public/demo/nh-12-views.html, public/demo/nh-13-calm.html, public/demo/assets/demo.js):
The Node head plan carries the approved header of nh-13, views by type, the RSS channel, a live list and search hints; the 2027 plans describe the connector and the Vine Monitor module, nothing implemented
- The stand pages nh-10 to nh-13 and their shared script
Tests (tests/Unit/AssetVersionTest.php, tests/Unit/NginxConfigTest.php, tests/Unit/UpdateConfigTest.php, tests/Support/asset_probe.php, tests/Support/update_probe.php):
Every file of public/ is walked through both server files; the head scripts are deferred in the shipped order; neither switch survives a saved form, a rebuilt local.php or the 6.2 update
Benefits:
- A returning visitor fetches only the files whose address changed; a warm page costs one network request
- Script order holds without async tricks; no editor instance leaks its teardown
Technical notes:
Breaking: script_a and script_b are gone from configuration and settings; an Apache without mod_headers sends no lifetime; a theme or plugin file replaced by hand needs config/local.php rebuilt to reach the browsers
- Not checked: Apache without mod_headers and LiteSpeed reading the <If> block
Batch 1 of docs/3-ASSET-CACHE-2026.md (step 21 of docs/ROADMAP-2026.md). A stylesheet or script is printed as file?v=<first ten hex characters of its SHA-1>, so batch 2 can give a versioned file a year in the browser and a changed file still reaches every visitor on the next page. The versions are computed once with config/local.php; a request hashes nothing and stats no asset file.
Core changes:
- Version map and address (core/classes/template.php):
- Template::getAssetVersions() maps every CSS and JS file below templates/ and plugins/ to its version
Template::getAssetUrl() prints an address with the version from $conf['derived']['version']
- dev_mode and a run without the map (setup.php, update.php) hash the file per request
- A file the map does not know stays a plain address
- The companion assets of a template go through it
- Derived configuration and the page head (core/system.php):
- getConfig() stores the map under $conf['derived']['version']; cache_version 5 rebuilds an older local.php
- doCss() and doScript() print the versioned addresses and no longer call file_exists() per file
Other printers (core/classes/editor.php, core/classes/parser.php, core/classes/captcha.php, core/security.php, modules/presentation/index.php, public/setup.php, public/update.php):
Editor::getAssetTags() versions its lists before the page and the htmx branch, so the client loader compares the same address the page carries and an engine is fetched once
- The highlight scripts, the altcha loader, presentation.js, the error page and the installer and updater pages
- Robots screen (admin/modules/editor.php):
- getRobotsButton() drops its own tag of editor-robots.js, which the admin package prints on every panel page
Tests and plans (tests/Unit/AssetVersionTest.php, tests/Support/asset_probe.php, docs/3-ASSET-CACHE-2026.md, docs/ROADMAP-2026.md):
Every head tag of both themes carries the version of its file; a changed file changes its address; the head is printed from the map for a file that does not exist; page and fragment name the same editor address
- The plan's status line records batch 1; the roadmap ticks step 21
Benefits:
- A release reaches returning visitors at once, whatever lifetime batch 2 sets
- No asset stat per request in the page head
Technical notes:
- getAssetList() keeps answering plain addresses; the theme lists and every other printer share one map
Adding or changing a theme or plugin asset needs a config rebuild, as theme assets did before; dev_mode shows it at once
- No schema change, no route change
Batch 0 of docs/3-ASSET-CACHE-2026.md (step 20 of docs/ROADMAP-2026.md). Before any asset address carries a version, the plan lists every place that prints one, every inline script that depends on a loaded file, and a cold and warm measurement of three pages on the stand, so the later batches change a known set and are measured against the same figures.
Core changes:
- Inventory (docs/3-ASSET-CACHE-2026.md):
Every printer of an asset address with its files, its attribute today and what batches 1 and 3 do to it
- doCss(), doScript(), Editor::getAssetTags(), SlaedEditors, Template::getAssetTag(), Parser, Captcha,
the robots screen, the presentation partial, setExit(), setup.php and update.php
- The inline scripts that call a function of a loaded file, and the one real conflict of defer: getInitScript()
- The root .htaccess reference corrected to public/.htaccess
- Baseline (docs/3-ASSET-CACHE-2026.md):
- Start page, list and view, cold and warm, median of three runs: requests, bytes, FCP, DCL and load
- The warm hits come from the heuristic freshness of RFC 9111, not from a header
- Roadmap (docs/ROADMAP-2026.md):
- Step 20 ticked
Benefits:
- Batch 1 versions a known, complete set of printers
- Batch 4 repeats the same measurement against the same figures
Technical notes:
- Documentation only, no code changed
Item 2 of docs/2-PROD-FINDINGS-2026.md (step 19 of docs/ROADMAP-2026.md). addFile() took its second argument as a source file or as the data and told them apart with is_file(), so every new visitor of the statistics probed a path that open_basedir logged as a warning; it now writes data only. The lasting part of the plan moves into VERSIONS.md and the plan file is deleted.
Core changes:
- File writer (core/system.php):
addFile(string $file, string $data, string $mode = 'w'): bool writes or appends exactly the data
- A short write fails and an incomplete append is rolled back, as before
- The unused compression branch leaves with $comp, $del and $max
- updateStatsTrack() calls the new signature for ips.log and user.log
- Tests and probes (tests/Unit/StatsContractTest.php, tests/Support/contract_probe.php):
The append contract reads bool results; data that names an existing file is appended as text, and an address appended under open_basedir raises no warning
- Repeated hits of one signed-in user enter the user set once and the user counter follows the set
- Changelog and plans (docs/VERSIONS.md, docs/ROADMAP-2026.md, docs/2-PROD-FINDINGS-2026.md):
- VERSIONS.md 2026-10-07 records both findings of the plan and the breaking change of addFile()
- The roadmap ticks step 19; docs/2-PROD-FINDINGS-2026.md is deleted
Benefits:
- The statistics no longer fill the PHP log with an open_basedir warning per new visitor
- Data that happens to name a file can never append that file's content
Technical notes:
Breaking: addFile() returns bool instead of the codes 0-3 and drops $comp, $del and $max; a caller that copied a file reads it first
- No schema change
Batch 5 of docs/0-PRIVATE-DATA-2026.md (step 18 of docs/ROADMAP-2026.md). error_*.log keeps what the system could not do and <meaning>.log what happened; no journal carries a log_ prefix, the file scan takes the name of its job, the rotation archives follow the journal names, and the locks leave storage/logs/ for storage/cache/locks/.
Core changes:
- Journal names (core/system.php, core/classes/oauth.php, core/monitor.php):
- log_admin.log and log_user.log become admin.log and user.log, log_oauth.log becomes oauth.log
dump_log.log, dump.log and dump_map.json become filescan.log, filescan_tree.log and filescan.json
- The scan skips its own two journals under the new names
- Both rotations of addCompress() name an archive <name>_<date>.log.<zip|gz|bz2>, or .log.bak without a compressor
- getFailedLoginCountHours() reads admin.log
- Routing by level (core/classes/logger.php, core/classes/upload.php):
- The channel file writes notice and warning to file.log, error and critical to error_file.log, each line once
- The rotation of Logger names its archive <name>_<date>.log.<ext>, as addCompress() does
- A refusal of the remote address policy is a warning and lands in file.log; a missing capability stays an error
- Locks (core/classes/filemanager.php, core/system.php, public/setup.php, public/update.php):
The locks of FileManager live in storage/cache/locks/uploads/, the scheduler locks in storage/cache/locks/scheduler/
- Cache::deleteAll() skips every *.lock, so clearing the cache never removes a held lock
- setup.php and the first stage of update.php define CACHE_DIR for the lock of config/
- Security section and dashboard (admin/modules/security.php, admin/lang/*.php, core/monitor.php):
- The label map covers exactly the journals of the rule
- _SEC_STAT_FILE and _SEC_STAT_OAUTH in the six locales
getErrorLogCountHours() reads the structured line Logger writes and counts warning, error and critical over the four error_*.log; it counted a bracketed format no writer produces and always reported zero
Help and reference (admin/info/uploads/ru.md, modules/account/admin/info/ru.md, docs/ARCHITECTURE.md, docs/NODE.md):
- The uploads help points the address refusals and the file manager operations at file.log
- The OAuth help names oauth.log; ARCHITECTURE.md and NODE.md name the lock folder and CACHE_DIR of the first stage
Tests and probes (tests/Unit/JournalNameTest.php, tests/Unit/JournalSecretTest.php, tests/Unit/UploadContractTest.php, tests/Unit/FileManagerTest.php, tests/bootstrap.php, tests/Support/.php):
JournalNameTest: every channel maps to a journal of the rule and the label map covers every journal; every name the code writes into LOGS_DIR is a journal, a state file or an archive of the rule; a refused operation reaches file.log only and a missing capability error_file.log only; a cache clear leaves a held lock; the error counter counts the problem levels only
JournalSecretTest checks the archive names of both rotations; UploadContractTest the journal of a refusal and of a stranded partial
The test bootstrap keeps CACHE_DIR in the scratch of the run; the upload and scheduler probes redirect it, and the upload probe starts from empty journals
- Plans (docs/0-PRIVATE-DATA-2026.md, docs/ROADMAP-2026.md):
- The plan records batch 5 and the four points its text left open; the roadmap ticks step 18
Benefits:
- A journal name says what the file holds, and an operator reads failures apart from records
- The dashboard counts the errors the journals really hold
- storage/logs/ holds journals, state and rotation archives only, and the locks sit with the cache that spares them
Technical notes:
- Breaking: the journal names change; 8.0 installs from scratch and nothing renames the journals of an existing site
- No schema change
Batch 10 of docs/1-FILES-2026.md (step 17 of docs/ROADMAP-2026.md). What lasts of the plan - the owners and their folders, the go=file route, closing a folder, the writers that bind a name and the unused files filter - is written into ARCHITECTURE.md and NODE.md, VERSIONS.md records the whole plan, and the plan file is deleted. UPGRADING.md keeps saying that the release installs a new site only; the file steps of update.php live in NODE.md.
Core changes:
- Architecture reference (docs/ARCHITECTURE.md):
A new section "File Delivery Boundary": FileAccess and its adapters, the six owners with folder, target and reader
- The route go=file, its preview form, the shared checks of getFilePath() and the one 404 for every refusal
- The parser file context, the writers over checkUploadNames(), closing a folder through getUploadPublic()
- The unused filter of the uploads screen with its covered folders and readers
- Node reference (docs/NODE.md, docs/POINTS.md):
getNodeFile() is described as the code grants: a bare name of a supported type, the go=file addresses of [usehtml], a managed name only for the preview; getTypeFiles() is added; the type folder is uploads/node/<name>
"The 6.3 update" gains setUpdateAttach() among the data units, the table of the 6.2 folder moves and the copies of the profile files; POINTS.md and the intro point there instead of UPGRADING.md
- Upgrade notes (UPGRADING.md, lang/*.php):
- The 6.2 folder table and the update.php paragraphs leave; update.php leaves the list of public entries
- The module folders name profile; custom code asks getUploadFolder() for the folder of an owner
- _NODE_MIGINFO names docs/NODE.md for the folder moves in the six locales
- Changelog and plans (docs/VERSIONS.md, docs/ROADMAP-2026.md, docs/1-FILES-2026.md):
- VERSIONS.md 2026-10-07 records the files plan, the rehearsal figures and its breaking changes
- The roadmap ticks step 17; docs/1-FILES-2026.md is deleted
- Tests (tests/Unit/UpdateAttachTest.php, tests/Unit/UploadIntegrationTest.php):
- Two comments no longer name the deleted plan
Benefits:
- One permanent place answers who receives an uploaded file and how a folder is closed
- The public upgrade notes no longer describe a maintainer tool the release does not ship
Technical notes:
- Documentation, language texts and comments only; no code path and no schema change
Batch 9 of docs/1-FILES-2026.md (step 16 of docs/ROADMAP-2026.md). The foot of a folder an owner covers offers "Unused: N", which keeps the files older than a day that no text, comment, resource or avatar names, read as the file route reads them but from every stored row whatever its state; the marking and the deletion of the browser remove them. The shipped tree loses the three screenshots of uploads/forum/.
Core changes:
The references of a folder (core/admin.php, core/classes/node/service.php, core/classes/comment.php, core/classes/privat.php):
getAdminFileRefs() names the owner folder of a browser path and the paths below it any stored row references
- A Node type, forum, account, profile, voting and the avatar folder are covered; all and presentation are not
- Parser::getAttachList() reads posts, signatures, own blocks, private messages and comments; users.avatar the
avatar folder
- NodeService::getTypeFiles() returns every name the materials of a type and their local resources reference
- Comment::getAttachTexts() reads every target of a module for the id 0
- Privat::getAttachBodies() reads every stored message for $all
The filter (core/admin.php, admin/modules/uploads.php, public/templates/admin/partials/file-browser.html, admin/lang/*.php):
getAdminFileShell() counts the unused files of a covered folder and keeps them alone for unused=1
- A thumb is judged by its original, a file younger than a day is not reported
- unused=1 travels through the filter field and the operations form, so a marked deletion returns to the filter
- _UPLOADS_UNUSED and _UPLOADS_UNUSEDTXT in the six locales
Tests and probes (tests/Unit/FileAccessTest.php, tests/Unit/NodeServiceTest.php, tests/Support/route_probe.php, tests/Support/install_probe.php):
getRouteUnused() covers a named and an unnamed forum file, a thumb, a Node type with an attachment and two resources, the avatars, the messages, the signature and profile comments, a pending and a moderated poll comment, a fresh upload, an uncovered folder and the deletion
- NodeServiceTest knows the signature of getTypeFiles()
- install_probe.php writes the one forum file the post of update62 shows, since the tree ships no upload of a post
- The tree (uploads/forum/):
- The three screenshots slaed_cms_2026-07-13_*.png leave the shipped tree
- Documentation and plans (docs/1-FILES-2026.md, docs/ROADMAP-2026.md):
The files plan records batch 9 and the decisions "The form of the report", "The folders of the report" and "What references a file"; the roadmap ticks step 16
Benefits:
- An operator finds and removes the files no material, post, message, comment or account uses, folder by folder
- A file of a draft, a pending material or a message one side deleted is never reported as unused
Technical notes:
- The scan adds about 100 ms to a listing on the production database
- Each table stays with the class that owns it
- No schema change
Roadmap step 15, the rehearsal of docs/1-FILES-2026.md: update.php of the tree ran both stages over HTTP on a copy of the production dump of 2026-09-30 with the production files, in a scratch tree outside the stand. It found four faults, each fixed here, and that a clean 6.2 site is not migrated; every file address of the stored texts was compared before and after, and the pages that show them were crawled.
Core changes:
- First stage (public/update.php):
The first stage defines UPLOADS_DIR, which setUpdateAttach() reads for the forum and the private messages
- Without it the first forum post with a direct address stopped the update with a fatal error
setUpdateConfig() drops a 6.2 global key that names a configuration area (forum, newsletter, search)
- getConfig() merges the files in name order, so 'forum' => '0' of global.php replaced the whole forum area and
every topic answered a TypeError
- Foreign addresses (public/update.php):
- getMigrateForeign() takes the owner of the file route
setMigrateForeign() points a direct address of uploads/forum/ in any text but a forum post at the go=file address of the first published post that carries the name
- The news #468 and the private message #1665 of production reach their forum files through posts #6235 and #14824
- Order of the operator (UPGRADING.md, docs/NODE.md, lang/*.php):
The upload folders move into uploads/node/<type>/ after the migration and before the site opens
- addNodeType() refuses a type whose folder already holds a file, so a folder moved before the run stopped it
- _NODE_MIGINFO says so in the six locales
NODE.md records the foreign address step, the path constants of the first stage, the dropped global keys and that the migration reads the 6.3 shape of the module tables, which a clean 6.2 site does not have
Tests and probes (tests/Unit/UpdateSiteTest.php, tests/Unit/UpdateConfigTest.php, tests/Unit/UpdateAttachTest.php, tests/Support/install_probe.php, tests/Support/update_probe.php, tests/Fixtures/update62/site.sql):
The update62 fixture seeds a forum post and a private message with direct addresses; the probe reports both texts
- The forum post is one more rating target, so the expected count is 4
- The configuration probe ships forum.php and carries the 6.2 key forum, which must not reach global.php
- UpdateAttachTest covers the forum owner of getMigrateForeign()
- Documentation and plans (docs/1-FILES-2026.md, docs/ROADMAP-2026.md):
The files plan records the rehearsal and the decisions "The rehearsal data", "The folders move after the migration" and "A forum file outside the forum"; the roadmap ticks step 15
Benefits:
- update.php runs through on the production data of slaed.net without a stop
Of 721 file addresses in the stored texts none is lost; the guest crawl of 231 pages saw 1049 file references, all answering 200, and the 12 addresses no guest reads answered 200 to the panel
Technical notes:
- Breaking for the operator: the folder moves of UPGRADING.md now come after update.php, not before
- A clean 6.2 site with sid, hometext and bodytext is not migrated; update.php serves slaed.net alone
- The stand database still carries the two forum addresses of news #3895 and private message #1665 unconverted
- No schema change
Batch 8 of docs/1-FILES-2026.md (step 14 of docs/ROADMAP-2026.md). uploads/archive/ leaves the public list of the light path, and update.php points a direct address a text keeps into the 6.2 folder of a type it does not belong to at the go=file address of a published material of that type which carries the name: one owner and one route per file.
Core changes:
- The archive retired (core/stream.php):
- archive is off getUploadPublic(), so every address under uploads/archive/ answers 410, an existing file included
- Addresses of another owner (public/update.php):
getMigrateForeign() rewrites uploads/<dir>/<name> and its thumb into ./index.php?go=file&own=node&id=<id>&key=<name>
- [code] and [php] keep their examples, another host and a name outside the attachment grammar stay
- A name no material carries keeps its address, which answers 410
setMigrateForeign() runs after the data step on every run of the migration over Node texts, comments, the forum, private messages, site messages, newsletters, blocks, signatures, own blocks and polls
- The material is the first published one of the type whose text, [usehtml] address or published comment carries
the name; the own folder of a material and of its comments stays with batch 3
- A text the longer address would push past its column keeps its addresses and is named in the notes of the run
Tests and probes (tests/Unit/UpdateAttachTest.php, tests/Unit/PublicTreeTest.php, tests/Unit/UploadFormatTest.php, tests/Support/format_probe.php):
- UpdateAttachTest covers the pointing, the thumb, the kept example, the other host and the name no material carries
- PublicTreeTest refuses uploads/archive/ and gives it no address; the format probe renders through presentation
- Documentation and plans (docs/*, UPGRADING.md):
The files plan records batch 8, the stand run and the decisions "A file of another owner" and "The stand texts of batch 3"; the roadmap ticks step 14
- UPGRADING.md drops archive from the public folders and describes the pointing of foreign addresses
Benefits:
- No file of the archive is readable by its address any more
A forum post, a message or a newsletter that showed a file of a news or files material keeps showing it to the reader of that material, without a copy
Technical notes:
- Breaking: uploads/archive/<name> answers 410
On the stand the conversion of batch 3 ran again (122 materials, 4 comments) and the pointing reached message #16, newsletter #11 and forum post #2791; no stored text addresses uploads/archive/
- No schema change
Batch 7 of docs/1-FILES-2026.md (step 13 of docs/ROADMAP-2026.md). uploads/voting/ leaves the public list of the light path and the owner comment gets its adapter in FileAccess: a comment grants the [attach] names its body carries to a reader of its poll or profile while it is published, and the comment layer refuses a new name the writer may not bind on every target, Node included.
Core changes:
- The comment adapter (core/stream.php, core/system.php, core/classes/access.php, core/user.php):
- voting is off getUploadPublic(); getUploadOwner() names comment for it
getFileService() wires comment: its target is the id of the comment, its folder the one the comment form of its target uploads into (getCommentPlace(): uploads/voting/, uploads/profile/)
checkCommentFile() serves a name of a published comment whose module page is open to the reader and whose target shows its discussion (Comment::getTargetMode()); a moderator of the module reads every comment
- A comment of a Node material is refused here and keeps its route through the material
- FileAccess::PREVIEW gains comment; own=comment&name=voting serves the own upload of the poll comments
- getCommentBody() renders a comment in ['comment', $id] against the folder of getCommentPlace()
- The profile owner (core/user.php):
checkProfileFile() grants the names of the own block to its owner alone, beside the signature for every reader of the profile
- Writers of a comment (core/classes/comment.php):
Comment::checkAttachNames() refuses the first new [attach] name that is no own upload of the folder, no file for a moderator of it and no name the same target already serves
- A published comment of the target, and for Node NodeService::getNodeFile() of the material
- The new comment, the author edit and the moderator edit (updateBody()) ask it
- Tests and probes (tests/Unit/FileAccessTest.php, tests/Unit/PublicTreeTest.php, tests/Support/route_probe.php):
getRouteComment() covers a published and a pending comment of a poll and of a profile, a hidden poll, a guest, the author, a moderator, closed profiles, the preview, both pages, the own block and the three writers of a poll, a profile and a Node comment
- FileAccessTest the preview address of comment; PublicTreeTest the closed folder of voting
- Documentation and plans (docs/*, UPGRADING.md):
The files plan records batch 7 and the decisions "The poll folder" and "A name in a comment"; the roadmap ticks step 13
- UPGRADING.md and PARSER.md describe the closed poll folder and the file context ['comment', $id]
Benefits:
- A file of a hidden poll or of an unpublished comment is no longer readable by anyone who knows its address
- A comment can no longer publish a file of another account's own block or of an unpublished Node material
Technical notes:
Breaking: uploads/voting/<name> answers 410; no comment of a poll or a profile carries a file on the stand, so nothing was converted
A comment on a profile of a 6.2 site with an [attach] of a file in uploads/account/ needs that file copied into uploads/profile/ (UPGRADING.md)
- No schema change