Официальный сайт SLAED CMS
Журнал изменений
Plain Plus and CodeMirror share one editor shell with a runtime, a capsule and the window standard of the panel; CodeMirror is now also a text editor that stores Markdown, offered to members and administrators. Code shown on the site and in the panel reads one mono face and the token tones of the theme, and every code block, BB or fenced, carries its language, a copy button and a fold for long code.
Core changes:
- Editor shell and runtime (core/classes/editor.php, public/plugins/system/editor.js, fragments editor-frame.html and editor-kit.html):
- Plain Plus and CodeMirror render one frame: tab, capsule, status line, draft of the tab in sessionStorage
- CodeMirror loads as a core and one grammar per frame when it comes into view; the textarea keeps carrying the value
- The floor of CodeMirror is the measured height of its field, so a form does not jump when it mounts
- An empty required text under CodeMirror marks the frame and takes the focus instead of blocking silently
- A whole-text replacement raises input like typing, so dirty forms and save bars notice it
- The capsule is lifted, movable by its grip and uses the window standard: move, expand and collapse labels and icons
- CodeMirror as a text editor (public/plugins/editors/codemirror/*):
- One getWidget() serves ContentDriver and CodeDriver; the manifest declares type ["content", "code"]
- Formats markdown, plain, html with Markdown stored, as Toast UI stores it; listed after Toast UI for both roles
- Text keeps spell check and the face of the page and has no line numbers (textSetup); Tab moves to the next field
Split build: core, lang-* files and shared chunks; Markdown on the GitHub base, INI from the official legacy modes, and own grammars for Apache and robots.txt
The editor screen highlights .htaccess as Apache and robots.txt as TXT; the file manager opens md as Markdown, ini as INI and robots.txt with its grammar
- Themes (templates admin and lite, base.css, theme.css, presentation.css):
- The rail of the frame is the left border of tab and card, running top to bottom with no line crossing it
- Lite gained the CodeMirror rules for a text; keyword and string tones raised to hold AA on the card
--sl-face-mono and --sl-face-quote declared in both themes; code, kbd, samp, pre, [code] and the presentation read them; Georgia, Courier and the old mono stacks are gone; the code editor sets 14px
- The window head and every grip take the grab and grabbing hand; collapse of a window reads "collapse"
- Dead .sl-editor-area rules and the is_editor_area branch removed; --sl-editor-height is the fallback floor
- Font ladder 12/13/14 in the contract and the rules, following the owner's micro and small sizes
- Code blocks (core/classes/parser.php, fragment code-block.html, public/plugins/system/slaed.js):
[code], [php], fenced and indented code render one block: the language, a copy button without line numbers, a fold above 25 lines, a body that takes the keyboard focus and scrolls
The highlight.js styling moved from the plugin into both themes on the CodeMirror tones, with dark mode; plugins/highlightjs/slaed-theme.css and its css_f default removed
- Highlight modes 0 and 1 no longer show the <?php prefix PHP 8.3+ leaves; the first line of code keeps its indent
- Copying a share address and a code block is one setCopyText()
- Panel screens and texts (admin/modules/template.php, editor.php, config.php, admin/info, lang/*):
- The template screen shows file and date in the editor tab and drops the separate row
- Plain Textarea is shown as Plain Plus; the help lists CodeMirror among the content editors
- Constants: _COPY, _COPYDONE, _SHOWALL, _COLLAPSE added; _ERESTORE reads collapse; editor-only copies removed
- Plans and stand (docs/, public/demo/):
- Roadmap step 31 done; editor plan records batch 4 and its decisions; pager plan, core 2027 plan and pager stand pages
Benefits:
- One editor standard and one window standard across both engines and both themes
- Code reads the same everywhere, follows the dark scheme and copies cleanly
Technical notes:
- Stored content is unchanged; CodeMirror as text stores Markdown like Toast UI
- css_f defaults to empty; an old path to the removed plugin stylesheet is skipped by getAssetList()
- Gates: ui:gates and the parser, editor, language and file format tests pass; the audit baseline is stored
Steps 28 and 29 of docs/ROADMAP-2026.md (batches 1 and 2 of docs/4-EDITOR-2026.md). The code editor is painted by the theme tokens in place of One Dark and speaks the locale in its panels; one check in Editor reads the manifest field type as a string or a list, so one plugin can serve as a text and a code editor; and the build writes the core and every language as files of their own, which the runtime of batch 3 loads on demand.
Core changes:
CodeMirror in the theme (public/plugins/editors/codemirror/driver.php, public/plugins/editors/codemirror/assets/cm6.css, public/templates/admin/assets/css/base.css, public/templates/admin/assets/css/theme.css, public/templates/lite/assets/css/theme.css, public/templates/admin/fragments/editor-mount.html, public/templates/lite/fragments/editor-mount.html):
The driver writes syntaxHighlighting(classHighlighter), so the theme colours the tok-* classes and the code follows the scheme; One Dark leaves the driver and the build
- The mount of a code editor carries the shell name sl-editor in place of sl-code-editor in both themes
--sl-face-mono and --sl-editor-max-height (50vh) join the admin API block; the height floor stands on .cm-content and .cm-gutter, and cm6.css keeps only the focus outline instead of a fixed 400 px
- The Tahoma rule on .cm-content and the doubled height of a second editor are gone
Line numbers and comments take --sl-text-muted, tags --sl-primary-strong, and the current node of the file tree --sl-primary-strong, so each holds AA
- Phrases of the panels (lang/de.php, lang/en.php, lang/fr.php, lang/pl.php, lang/ru.php, lang/uk.php):
Twenty-five EDITOR* constants for search, fold, go to line, lint, completion and the screen reader announcements; with _ALL, _CLOSE, _EDITOR_PREV and _EDITOR_NEXT the driver hands them to EditorState.phrases
- Manifest type (core/classes/editor.php, admin/index.php, public/plugins/editors/codemirror/manifest.json):
Editor::checkType() answers whether a manifest serves a type given as one string or a list, and replaces the comparisons of getCode(), checkManifest() and getEditorList()
isValidEditor() of admin/index.php, a copy of Editor::isValidEditor() with its own string comparison, is removed; the new administrator and the editor switch of the panel call the class
Editor::getManifest() takes over the one check only the copy made: a manifest whose id differs from its directory is refused, so no key reaches a manifest or a driver outside its own folder
The CodeMirror manifest declares type as ["code"]; content, the user role and the text formats join with its ContentDriver in batch 4, so no list offers a text editor that renders Plain
Split build (public/plugins/editors/codemirror/build/build.mjs, build/core.js, build/entry.js, build/package.json, public/plugins/editors/codemirror/assets/*.js):
ES modules with splitting: core.js, lang-<key>.js for php, html, css, js, json, sql, xml and markdown, each exporting language, and shared chunk-<hash>.js files named by their content
- The build refuses a language file that imports core.js, which a versioned core address would load a second time
- entry.js re-exports core.js and still builds cm6.bundle.js for the current driver until batch 3
- @codemirror/lang-markdown and the packages the exports name join package.json; theme-one-dark leaves
- Tests and registries (tests/Unit/EditorFormatTest.php, tools/ui-audit-baseline.json, tools/ui-contrast.json):
Code editors are handed to the theme as classes and speak the locale; both forms of type and a key leaving its folder; the three lists of getSelect(); a split file for every language of the manifest with no import of the core entry
- The audit baseline counts the two new tokens; the contrast registry is regenerated over the new screens
- Plans (docs/4-EDITOR-2026.md, docs/ROADMAP-2026.md):
Batches 1 and 2 record what was done and measured; batch 3 retires the bundle and the CM6.editors readers; batch 4 completes the manifest; the roadmap ticks steps 28 and 29
Benefits:
- Code follows the light and dark scheme of the panel and is readable at AA
A code screen will load the core and one grammar: 151.8 KB gzip for css or sql, 223.5 KB for php, against 239.5 KB of the bundle on every screen; the core alone is 130.5 KB
- One manifest check for the class and the panel
Technical notes:
- The split files have no user before batch 3; the bundle keeps its size and changes only minifier names
- Chunks are requested without v= and live a week in the browser, safe because their names follow their content
- No schema, address or API changes
Steps 25 to 27 of docs/ROADMAP-2026.md. The private data plan hands its lasting part to the reference and is deleted; batch 0 of the editor plan records the owner's answers, pins the lost <br> to the mount and takes the screenshot baseline; and the mount of getTplTextarea() no longer deletes every stored <br>, which made each save of the account settings strip the signature and the custom menu of every member writing in Markdown.
Core changes:
- Line breaks on mount (core/helpers.php, docs/EDITORS.md, docs/VERSIONS.md):
getTplTextarea() mounts a stored <br>, with the line end after it, as a line end for plain, which nl2br() of the save restores, and as a Markdown hard break, two spaces and a line end, for markdown; html mounts as it is
- replace_break() is no longer part of the mount and keeps its other callers
Measured through one save of the account settings in the browser: the custom menu went from 1475 bytes with 22 tags to 1431 bytes with 22 hard breaks instead of 1387 bytes with none, and a second save changed no byte
EDITORS.md replaces the open defect with "Line Breaks on Mount", the contract with the measurements; VERSIONS.md records the change
- Tests (tests/Unit/EditorBreakTest.php, tests/Support/break_probe.php):
Stored values go through the shipped mount, the browser submit and the save of both formats: the bytes written, a second save that changes nothing, the signature render before and after, and the escaped render of markdown
- The test fails on the old mount in three of its five methods
Private data reference (docs/ARCHITECTURE.md, README.md, UPGRADING.md, docs/VERSIONS.md, admin/info/security/ru.md, docs/2027-CONNECTOR.md, docs/0-PRIVATE-DATA-2026.md, tests/Unit/JournalNameTest.php, tests/Unit/JournalSecretTest.php, tests/Unit/SelfCheckTest.php, tests/Support/check_probe.php, tests/Support/journal_probe.php):
- ARCHITECTURE.md gains "Private Data Boundary": the public/ tree, the two modes, the self-check and the journals
- The security help lists every journal by file and what it holds, and describes the self-check
README.md names the public folders of uploads/ and the self-check; UPGRADING.md describes the self-check, the journals without secrets and their new names; VERSIONS.md records the whole plan, the document root included
- The plan is deleted; the comments of the journal and self-check tests and probes point at the reference
- Editor plan, batch 0 (docs/4-EDITOR-2026.md, tools/ui-shots.json):
- The seven open decisions are answered and settled under "Answered decisions", and the batches follow them
- The screenshot manifest gains the tplconfig, system file, block file, template style and new member screens
- The plan notes that the <br> defect was the mount and is repaired by item 1
- Roadmap (docs/ROADMAP-2026.md):
- Steps 25 to 27 are ticked; step 27, the repair of the <br> defect, was added by the owner before editor batch 1
Benefits:
- No member loses the breaks of a signature or a custom menu by saving an unrelated setting
A markdown break renders as <br> in the escaped render of comments and the forum too, where a stored <br> printed as text
- CodeMirror as a text editor mounts through the same function and does not inherit the loss
Technical notes:
Stored form: a value saved in markdown holds two spaces where it held <br>, two bytes less per break; a line of nothing but a <br> becomes an empty line, so the lines around it render as two paragraphs
Not fixed here: the WYSIWYG mode of Toast UI writes a hard break back as nothing and a <br> as a bare line end; the forward and quote of a private message are still stripped the old way, where only an inline <br> is lost
- No schema, address or API changes
Steps 22 to 24 of docs/ROADMAP-2026.md (batches 2 to 4 of the asset cache plan): the web server gives a style or script with v= in its address a year and any other static file a week, every head script is printed defer in its order, and the reference takes over from the plan, which is deleted. The commit also carries the stand pages and the plans of the Node list header, the 2027 plans of the connector and Vine Monitor, and a toggle that remembers nothing.
Core changes:
- Lifetimes (public/.htaccess, nginx.conf.example):
mod_headers sets public, max-age=31536000, immutable on a CSS or JS request with v= in the query and public, max-age=604800 on any other static kind; the mod_expires block is gone
nginx chooses the same by a server-level $asset_cache on $arg_v, since an if inside a location would drop its try_files, and turns gzip on for the types the .htaccess deflates
Deferred head scripts (core/system.php, core/classes/editor.php, core/classes/parser.php, public/plugins/editors/toastui/driver.php):
- doScript() prints every head script defer in the order of getAssetList(); setHead() always prints it
Editor::getInitScript() waits for DOMContentLoaded while window.SlaedEditors is missing, so an editor of a page load registers its teardown
The editor skin and the toastui emoji file ask the version map instead of the disk; the highlight versions are part of the parser cache key
Settings (config/global.php, admin/modules/config.php, admin/lang/*.php, admin/info/config/ru.md, public/update.php):
script_a (async) and script_b (scripts at the end of the page) leave the shipped configuration, the settings screen, the six admin locales and the help; update.php drops both from a carried 6.2 configuration
Reference (docs/PERFORMANCE.md, docs/TEMPLATES.md, docs/VERSIONS.md, admin/info/editor/ru.md, docs/3-ASSET-CACHE-2026.md, docs/ROADMAP-2026.md):
PERFORMANCE.md describes the versions, the lifetimes by kind, the Apache and nginx rules, the defer order, the compression and the measurement repeated on the stand; TEMPLATES.md the versioned addresses of a theme
- The help of the server files shows the shipped mod_headers and nginx rules instead of mod_expires
VERSIONS.md records the change with the baseline comparison; the plan is deleted, the roadmap ticks steps 22-24 and gains steps 38-46 of the Node head plan
- Toggle scope (public/plugins/system/slaed.js):
- data-sl-toggle-scope="none" keeps no state in localStorage; "path" and the site-wide default stay as they were
Plans and stand pages (docs/5-NODE-HEAD-2026.md, docs/2027-CONNECTOR.md, docs/2027-VINE-MONITOR.md, public/demo/nh-10-unified.html, public/demo/nh-11-full.html, public/demo/nh-12-views.html, public/demo/nh-13-calm.html, public/demo/assets/demo.js):
The Node head plan carries the approved header of nh-13, views by type, the RSS channel, a live list and search hints; the 2027 plans describe the connector and the Vine Monitor module, nothing implemented
- The stand pages nh-10 to nh-13 and their shared script
Tests (tests/Unit/AssetVersionTest.php, tests/Unit/NginxConfigTest.php, tests/Unit/UpdateConfigTest.php, tests/Support/asset_probe.php, tests/Support/update_probe.php):
Every file of public/ is walked through both server files; the head scripts are deferred in the shipped order; neither switch survives a saved form, a rebuilt local.php or the 6.2 update
Benefits:
- A returning visitor fetches only the files whose address changed; a warm page costs one network request
- Script order holds without async tricks; no editor instance leaks its teardown
Technical notes:
Breaking: script_a and script_b are gone from configuration and settings; an Apache without mod_headers sends no lifetime; a theme or plugin file replaced by hand needs config/local.php rebuilt to reach the browsers
- Not checked: Apache without mod_headers and LiteSpeed reading the <If> block
Batch 1 of docs/3-ASSET-CACHE-2026.md (step 21 of docs/ROADMAP-2026.md). A stylesheet or script is printed as file?v=<first ten hex characters of its SHA-1>, so batch 2 can give a versioned file a year in the browser and a changed file still reaches every visitor on the next page. The versions are computed once with config/local.php; a request hashes nothing and stats no asset file.
Core changes:
- Version map and address (core/classes/template.php):
- Template::getAssetVersions() maps every CSS and JS file below templates/ and plugins/ to its version
Template::getAssetUrl() prints an address with the version from $conf['derived']['version']
- dev_mode and a run without the map (setup.php, update.php) hash the file per request
- A file the map does not know stays a plain address
- The companion assets of a template go through it
- Derived configuration and the page head (core/system.php):
- getConfig() stores the map under $conf['derived']['version']; cache_version 5 rebuilds an older local.php
- doCss() and doScript() print the versioned addresses and no longer call file_exists() per file
Other printers (core/classes/editor.php, core/classes/parser.php, core/classes/captcha.php, core/security.php, modules/presentation/index.php, public/setup.php, public/update.php):
Editor::getAssetTags() versions its lists before the page and the htmx branch, so the client loader compares the same address the page carries and an engine is fetched once
- The highlight scripts, the altcha loader, presentation.js, the error page and the installer and updater pages
- Robots screen (admin/modules/editor.php):
- getRobotsButton() drops its own tag of editor-robots.js, which the admin package prints on every panel page
Tests and plans (tests/Unit/AssetVersionTest.php, tests/Support/asset_probe.php, docs/3-ASSET-CACHE-2026.md, docs/ROADMAP-2026.md):
Every head tag of both themes carries the version of its file; a changed file changes its address; the head is printed from the map for a file that does not exist; page and fragment name the same editor address
- The plan's status line records batch 1; the roadmap ticks step 21
Benefits:
- A release reaches returning visitors at once, whatever lifetime batch 2 sets
- No asset stat per request in the page head
Technical notes:
- getAssetList() keeps answering plain addresses; the theme lists and every other printer share one map
Adding or changing a theme or plugin asset needs a config rebuild, as theme assets did before; dev_mode shows it at once
- No schema change, no route change
Batch 0 of docs/3-ASSET-CACHE-2026.md (step 20 of docs/ROADMAP-2026.md). Before any asset address carries a version, the plan lists every place that prints one, every inline script that depends on a loaded file, and a cold and warm measurement of three pages on the stand, so the later batches change a known set and are measured against the same figures.
Core changes:
- Inventory (docs/3-ASSET-CACHE-2026.md):
Every printer of an asset address with its files, its attribute today and what batches 1 and 3 do to it
- doCss(), doScript(), Editor::getAssetTags(), SlaedEditors, Template::getAssetTag(), Parser, Captcha,
the robots screen, the presentation partial, setExit(), setup.php and update.php
- The inline scripts that call a function of a loaded file, and the one real conflict of defer: getInitScript()
- The root .htaccess reference corrected to public/.htaccess
- Baseline (docs/3-ASSET-CACHE-2026.md):
- Start page, list and view, cold and warm, median of three runs: requests, bytes, FCP, DCL and load
- The warm hits come from the heuristic freshness of RFC 9111, not from a header
- Roadmap (docs/ROADMAP-2026.md):
- Step 20 ticked
Benefits:
- Batch 1 versions a known, complete set of printers
- Batch 4 repeats the same measurement against the same figures
Technical notes:
- Documentation only, no code changed
Item 2 of docs/2-PROD-FINDINGS-2026.md (step 19 of docs/ROADMAP-2026.md). addFile() took its second argument as a source file or as the data and told them apart with is_file(), so every new visitor of the statistics probed a path that open_basedir logged as a warning; it now writes data only. The lasting part of the plan moves into VERSIONS.md and the plan file is deleted.
Core changes:
- File writer (core/system.php):
addFile(string $file, string $data, string $mode = 'w'): bool writes or appends exactly the data
- A short write fails and an incomplete append is rolled back, as before
- The unused compression branch leaves with $comp, $del and $max
- updateStatsTrack() calls the new signature for ips.log and user.log
- Tests and probes (tests/Unit/StatsContractTest.php, tests/Support/contract_probe.php):
The append contract reads bool results; data that names an existing file is appended as text, and an address appended under open_basedir raises no warning
- Repeated hits of one signed-in user enter the user set once and the user counter follows the set
- Changelog and plans (docs/VERSIONS.md, docs/ROADMAP-2026.md, docs/2-PROD-FINDINGS-2026.md):
- VERSIONS.md 2026-10-07 records both findings of the plan and the breaking change of addFile()
- The roadmap ticks step 19; docs/2-PROD-FINDINGS-2026.md is deleted
Benefits:
- The statistics no longer fill the PHP log with an open_basedir warning per new visitor
- Data that happens to name a file can never append that file's content
Technical notes:
Breaking: addFile() returns bool instead of the codes 0-3 and drops $comp, $del and $max; a caller that copied a file reads it first
- No schema change
Batch 5 of docs/0-PRIVATE-DATA-2026.md (step 18 of docs/ROADMAP-2026.md). error_*.log keeps what the system could not do and <meaning>.log what happened; no journal carries a log_ prefix, the file scan takes the name of its job, the rotation archives follow the journal names, and the locks leave storage/logs/ for storage/cache/locks/.
Core changes:
- Journal names (core/system.php, core/classes/oauth.php, core/monitor.php):
- log_admin.log and log_user.log become admin.log and user.log, log_oauth.log becomes oauth.log
dump_log.log, dump.log and dump_map.json become filescan.log, filescan_tree.log and filescan.json
- The scan skips its own two journals under the new names
- Both rotations of addCompress() name an archive <name>_<date>.log.<zip|gz|bz2>, or .log.bak without a compressor
- getFailedLoginCountHours() reads admin.log
- Routing by level (core/classes/logger.php, core/classes/upload.php):
- The channel file writes notice and warning to file.log, error and critical to error_file.log, each line once
- The rotation of Logger names its archive <name>_<date>.log.<ext>, as addCompress() does
- A refusal of the remote address policy is a warning and lands in file.log; a missing capability stays an error
- Locks (core/classes/filemanager.php, core/system.php, public/setup.php, public/update.php):
The locks of FileManager live in storage/cache/locks/uploads/, the scheduler locks in storage/cache/locks/scheduler/
- Cache::deleteAll() skips every *.lock, so clearing the cache never removes a held lock
- setup.php and the first stage of update.php define CACHE_DIR for the lock of config/
- Security section and dashboard (admin/modules/security.php, admin/lang/*.php, core/monitor.php):
- The label map covers exactly the journals of the rule
- _SEC_STAT_FILE and _SEC_STAT_OAUTH in the six locales
getErrorLogCountHours() reads the structured line Logger writes and counts warning, error and critical over the four error_*.log; it counted a bracketed format no writer produces and always reported zero
Help and reference (admin/info/uploads/ru.md, modules/account/admin/info/ru.md, docs/ARCHITECTURE.md, docs/NODE.md):
- The uploads help points the address refusals and the file manager operations at file.log
- The OAuth help names oauth.log; ARCHITECTURE.md and NODE.md name the lock folder and CACHE_DIR of the first stage
Tests and probes (tests/Unit/JournalNameTest.php, tests/Unit/JournalSecretTest.php, tests/Unit/UploadContractTest.php, tests/Unit/FileManagerTest.php, tests/bootstrap.php, tests/Support/.php):
JournalNameTest: every channel maps to a journal of the rule and the label map covers every journal; every name the code writes into LOGS_DIR is a journal, a state file or an archive of the rule; a refused operation reaches file.log only and a missing capability error_file.log only; a cache clear leaves a held lock; the error counter counts the problem levels only
JournalSecretTest checks the archive names of both rotations; UploadContractTest the journal of a refusal and of a stranded partial
The test bootstrap keeps CACHE_DIR in the scratch of the run; the upload and scheduler probes redirect it, and the upload probe starts from empty journals
- Plans (docs/0-PRIVATE-DATA-2026.md, docs/ROADMAP-2026.md):
- The plan records batch 5 and the four points its text left open; the roadmap ticks step 18
Benefits:
- A journal name says what the file holds, and an operator reads failures apart from records
- The dashboard counts the errors the journals really hold
- storage/logs/ holds journals, state and rotation archives only, and the locks sit with the cache that spares them
Technical notes:
- Breaking: the journal names change; 8.0 installs from scratch and nothing renames the journals of an existing site
- No schema change
Batch 10 of docs/1-FILES-2026.md (step 17 of docs/ROADMAP-2026.md). What lasts of the plan - the owners and their folders, the go=file route, closing a folder, the writers that bind a name and the unused files filter - is written into ARCHITECTURE.md and NODE.md, VERSIONS.md records the whole plan, and the plan file is deleted. UPGRADING.md keeps saying that the release installs a new site only; the file steps of update.php live in NODE.md.
Core changes:
- Architecture reference (docs/ARCHITECTURE.md):
A new section "File Delivery Boundary": FileAccess and its adapters, the six owners with folder, target and reader
- The route go=file, its preview form, the shared checks of getFilePath() and the one 404 for every refusal
- The parser file context, the writers over checkUploadNames(), closing a folder through getUploadPublic()
- The unused filter of the uploads screen with its covered folders and readers
- Node reference (docs/NODE.md, docs/POINTS.md):
getNodeFile() is described as the code grants: a bare name of a supported type, the go=file addresses of [usehtml], a managed name only for the preview; getTypeFiles() is added; the type folder is uploads/node/<name>
"The 6.3 update" gains setUpdateAttach() among the data units, the table of the 6.2 folder moves and the copies of the profile files; POINTS.md and the intro point there instead of UPGRADING.md
- Upgrade notes (UPGRADING.md, lang/*.php):
- The 6.2 folder table and the update.php paragraphs leave; update.php leaves the list of public entries
- The module folders name profile; custom code asks getUploadFolder() for the folder of an owner
- _NODE_MIGINFO names docs/NODE.md for the folder moves in the six locales
- Changelog and plans (docs/VERSIONS.md, docs/ROADMAP-2026.md, docs/1-FILES-2026.md):
- VERSIONS.md 2026-10-07 records the files plan, the rehearsal figures and its breaking changes
- The roadmap ticks step 17; docs/1-FILES-2026.md is deleted
- Tests (tests/Unit/UpdateAttachTest.php, tests/Unit/UploadIntegrationTest.php):
- Two comments no longer name the deleted plan
Benefits:
- One permanent place answers who receives an uploaded file and how a folder is closed
- The public upgrade notes no longer describe a maintainer tool the release does not ship
Technical notes:
- Documentation, language texts and comments only; no code path and no schema change
Batch 9 of docs/1-FILES-2026.md (step 16 of docs/ROADMAP-2026.md). The foot of a folder an owner covers offers "Unused: N", which keeps the files older than a day that no text, comment, resource or avatar names, read as the file route reads them but from every stored row whatever its state; the marking and the deletion of the browser remove them. The shipped tree loses the three screenshots of uploads/forum/.
Core changes:
The references of a folder (core/admin.php, core/classes/node/service.php, core/classes/comment.php, core/classes/privat.php):
getAdminFileRefs() names the owner folder of a browser path and the paths below it any stored row references
- A Node type, forum, account, profile, voting and the avatar folder are covered; all and presentation are not
- Parser::getAttachList() reads posts, signatures, own blocks, private messages and comments; users.avatar the
avatar folder
- NodeService::getTypeFiles() returns every name the materials of a type and their local resources reference
- Comment::getAttachTexts() reads every target of a module for the id 0
- Privat::getAttachBodies() reads every stored message for $all
The filter (core/admin.php, admin/modules/uploads.php, public/templates/admin/partials/file-browser.html, admin/lang/*.php):
getAdminFileShell() counts the unused files of a covered folder and keeps them alone for unused=1
- A thumb is judged by its original, a file younger than a day is not reported
- unused=1 travels through the filter field and the operations form, so a marked deletion returns to the filter
- _UPLOADS_UNUSED and _UPLOADS_UNUSEDTXT in the six locales
Tests and probes (tests/Unit/FileAccessTest.php, tests/Unit/NodeServiceTest.php, tests/Support/route_probe.php, tests/Support/install_probe.php):
getRouteUnused() covers a named and an unnamed forum file, a thumb, a Node type with an attachment and two resources, the avatars, the messages, the signature and profile comments, a pending and a moderated poll comment, a fresh upload, an uncovered folder and the deletion
- NodeServiceTest knows the signature of getTypeFiles()
- install_probe.php writes the one forum file the post of update62 shows, since the tree ships no upload of a post
- The tree (uploads/forum/):
- The three screenshots slaed_cms_2026-07-13_*.png leave the shipped tree
- Documentation and plans (docs/1-FILES-2026.md, docs/ROADMAP-2026.md):
The files plan records batch 9 and the decisions "The form of the report", "The folders of the report" and "What references a file"; the roadmap ticks step 16
Benefits:
- An operator finds and removes the files no material, post, message, comment or account uses, folder by folder
- A file of a draft, a pending material or a message one side deleted is never reported as unused
Technical notes:
- The scan adds about 100 ms to a listing on the production database
- Each table stays with the class that owns it
- No schema change