Официальный сайт SLAED CMS
Журнал изменений
The confirmation an admin screen shows after a save was compared in eight faces before one went into the theme. The series stays on the stand beside the others, so the choice can be seen against what it was chosen from.
Core changes:
- The series (demo/flash-01-stamp.html ... demo/flash-08-orbit.html):
One stage in all eight: the head of the blocks module, the flash where module-head.html prints it, the info alert of the live page under it, a desk that replays the flash, and the four tones side by side
- Each face changes the arrival, the countdown, the exit and the success tick, and nothing else
- The faces stand on the bar the theme had before the ring, which their shared styles restore
- Stand behaviours (demo/assets/demo.js, demo/assets/demo.css):
- DEMO_FLASH manifest and its place in DEMO_SERIES, so the gallery shows the series by itself
data-demo-flash replays a template into data-demo-flash-host and lets the theme's htmx:afterSwap hook arm the autohide; data-demo-flash-loop plays it again after the exit
- data-demo-about fills the card of a face from its manifest entry
- Reference (demo/README.md):
- The sixth series, its table of faces, and the note that 03 Ring lives in the admin theme
Benefits:
- The countdown and the exit on the stand are those of slaed.js, not an imitation
Technical notes:
- The stand does not ship; nothing outside demo/ changes
The favourite star already had a burst - a pop, a ring wave and sparks. The rating stars now share it: once the counted rating is swapped in, the stars up to the chosen one burst in a row. The toast a refused vote raises turned white in the dark scheme, and the repeated-vote message ended in a bare number of days.
Core changes:
- One burst for two owners (plugins/system/slaed.js):
- setBurst(node, turn) pops one node and staggers it by --sl-d-turn; the favourite star calls it as before
A star vote is remembered in htmx:configRequest with its target and value; htmx:afterSwap of that target bursts the stars up to the value, and a refused vote forgets it
- Burst and toast styles (templates/lite/assets/css/theme.css):
- .sl-is-burst is no longer bound to .sl-fav; a rating star takes the round the ring needs only while it bursts
- The sparks stay hidden until their star's turn; keyframes renamed sl-burst-pop, -ring and -spark
- The toast is an inverse band, as the top bar is: --sl-bg-inverse with --sl-band-text in both schemes
- The repeated-vote message (core/system.php, lang/*.php, docs/RATINGS.md):
_RATINGS_WAIT names the date the next vote opens, in _DATESTRING, in all six locales
- a date reads without plural forms, which a bare count of days could not
Benefits:
- The rating answers a vote with the same gesture the favourite star does, from one mechanism
- The toast reads on either page, and the message says when rather than a number of what
Technical notes:
- The --sl-fav-* tokens keep their names: the API is frozen, so the rating stars read them as they are
- Retry-After still carries seconds; only the text changed
- tools/ui-audit-baseline.json and tools/ui-contrast.json are stored for the whole series of three commits
The flash an admin screen prints after an action was an info alert that counted down with two hair lines, and the success tick and the accent megaphone pulsed exactly as the info letter did. A confirmation is now a success alert, the flash springs in and counts down on a ring round its tick, and the success and accent glyphs have motion of their own in both themes.
Core changes:
- The flash is a success (core/system.php, core/helpers.php):
- getFlashHtml() passes type success, or warn for a refusal, instead of is_warn
- The saved-help notice of a module passes type success as well
- The ring countdown (templates/admin/fragments/alert.html, templates/admin/assets/css/theme.css):
sl-alert-flash-bar holds an SVG circle with pathLength 100; stroke-dashoffset runs it out over --sl-flash-dur
- the ring is centred on the tick, its track an inset shadow of --sl-flash-mix of the tone
- The flash springs in with sl-alert-pop and leaves scaled down; the two hair lines and sl-alert-flash-frame are gone
- Tone glyphs (templates/admin and templates/lite, assets/css/theme.css):
- Success: sl-alert-land, a turn in, then sl-alert-glow
- Accent: the megaphone tips up from its grip (sl-alert-announce) and two arcs of voice leave its bell (sl-alert-voice)
- Info keeps its pulse, warn its shake, error its beat
- Tokens and contract (base.css of both themes, tools/ui-contract.php):
- --sl-alert-ease in both themes, --sl-flash-ring and --sl-flash-mix in admin
- The divergence reasons of .sl-alert-flash and .sl-alert-flash-bar describe the ring
Benefits:
- A confirmation reads as a success at a glance, and no two tones share a motion
- The countdown uses no registered property, so it animates the same in every browser
Technical notes:
- The fragment markup of a flash gains one SVG; the autohide of slaed.js is unchanged
- Motion stands under prefers-reduced-motion; the reduce rules also stop the arc and the ring
This commit also restores four lines of the previous one that its hunk-wise staging put a few lines off, among them the text colour of a toolbar item in hand
In the dark scheme the tone tokens turn into light tints: right for a glyph, glaring as the fill of a whole bar. Every solid surface of the admin theme now reads its own --sl-solid-* tokens, which hold the light scheme's tone in light and that tone under a seventy per cent shade in dark, so the bars read the same in both and in every browser.
Core changes:
- Solid bar tokens (templates/admin/assets/css/base.css):
--sl-solid-bg, -border, -text and -shadow for the primary bar
- -good-, -warn- and -bad- variants carry the success, warning and danger fills and borders
- -link-text is the glyph of a link on a solid band in hand
- --sl-footer-border, and the footer stripe gradient reads the shaded tone in dark
- --sl-beam-width, -dur, -bg and --sl-pointer-width for the motion layer
- Solid surfaces (templates/admin/assets/css/theme.css):
- Panel heads, sidebar block heads in all their tones, the toolbar item in hand, the footer band and the login footer
The toned buttons sl-but-blue, -green and -red, and the mini buttons in hand, pressed or leading, with the dial toggle
- the four mini rules shared one body and are one selector list
- the muted and disabled mini hover set the whole background, so the gradient never shows through
- A beam crosses each head once a cycle, staggered by --sl-d-turn, and at once under the hand
- A soft light follows the pointer over the page, as on the presentation page
- Behaviour (templates/admin/assets/js/admin-ui.js):
- setBeamTurns() writes each head's place in the beam order
- The pointer is written once a frame; touch and reduced motion get no light
- Contract (tools/ui-contract.php):
- Components pointer, solid, solid-bad, solid-good, solid-link, solid-warn
- --sl-d-turn registered; --sl-d-pointer-x/-y also written by admin-ui.js
Benefits:
- One colour principle for every solid surface of the panel, light and dark from one token
- No @property or color-scheme pinning, so Firefox renders the dark bars exactly as Chromium does
Technical notes:
- The light scheme is unchanged: each token's light half reads the semantic tone it replaced
- All motion stands under prefers-reduced-motion: no-preference
- The audit baseline and the contrast registry are stored with the rating commit that closes this series
Release 8.0 no longer ships these six modules. Removing their directories alone would have left the core answering for them: a cart route, a shop scope in three shared subsystems, a points action, an extra-field area, feeds, sitemap and search sources, admin counters and eight tables in the installation schema. All of it goes, and the 6.3 update leaves the tables of these modules on an old site untouched.
Core changes:
- Removed files:
modules/{auto_links,clients,money,order,shop,whois}, blocks/auto_links.php, their config files and uploads/{auto_links,clients,shop}
- templates/lite/fragments/shop-invoice.html, templates/lite/partials/money-calc-scripts.html
- Core hooks (core/system.php, core/user.php, core/admin.php, core/helpers.php, index.php, core/security.php):
The cart helpers and the go=2 route; the shop feed, sitemap section, letter index, rating map and alphabet query; the newsletter audiences of the three client lists; the admin counters of new clients, partners and whois requests; the cabinet links to clients and partners; shop favorites
getCategoryCounts(), which counted shop products only, and catmids(), whose last caller was the shop branch of Comment; getMailAudience() reads accounts only
- The module and icon names of the removed modules; the editor stores of their columns
- The referer log no longer links a visitor to an auto_links entry and writes no lid
- Shared subsystems (core/classes/comment.php, rating.php, point.php, node/service.php):
- Comment targets are account and voting; rating scopes are account, forum and node.<name>
- Point::ACTIONS loses order (fourteen actions); a Node category may not take a forum category in use
- Favorites keep forum and Node types
- Administration (admin/modules/*.php, modules/search, modules/voting, modules/account, modules/presentation):
- The setting amod is gone: nothing read it and three of its four options were removed modules
- Extra fields serve account and forum; ratings list account, forum and the Node types
- Search, newsletter, voting and the profile favorites lose their shop branches
- Schema and update (setup/sql/table.sql, setup/sql/table_update6_3.sql, setup/index.php):
table.sql drops auto_links, clients, clients_down, money, order, partners, products, whois and _referer.lid; the update file no longer touches those tables and drops lid
The update preflight, the ratings unit and the fields unit forget order, clients, products and shop; a 6.2 shop rule counts as dropped, shop votes as foreign, and order fields stay positional
- The update drops amod from the site configuration and expects fourteen points actions
- Shipped configuration, language and themes:
- config/modules, uploads, search, ratings, points, fields and global lose the removed modules
- 46 language constants that only the removed code read leave all six locales
The lite theme loses the cart and shop hooks of its fragments, their CSS, the product, WebMoney and domain check menu items; the invoice tokens leave the frozen API roster by decision
- Tests, tools and documentation:
Tests that used the shop as a sample target move to voting, forum or a Node type; tests of the removed features are deleted; skipped tests fall from 28 to 4
- Label and theme baselines, upload route check, SEO audit and comment recount follow the tree
UPGRADING.md gains a section on the removed modules; NODE, POINTS, RATINGS, TESTS and VERSIONS describe the current system
Benefits:
- The core carries no code for modules it does not ship
- An update from 6.2 no longer fails on a missing shop, order or whois table
Technical notes:
- Breaking: a site that needs these modules stays on its current release; the core has no hooks for them
- Breaking: the lite tokens --sl-invoice-width and --sl-invoice-logo-width are gone from the API
Breaking: _referer.lid and the global setting amod are dropped; the tables of the removed modules stay on an updated site and are never read
The label baseline still carried three defects after the last store. Two were one bug on the ban list page, the third was a hint the crawl could not place. All three are gone, and the baseline holds no violation, so any new label defect turns ui:label red.
Core changes:
- Ban list forms (admin/modules/security.php):
The account ban form named its time and reason fields f-time and f-info, the ids of the address ban form on the same page
- Its fields are f-utime and f-uinfo, so every label points at the field beside it
- Label crawl rows (tools/label-audit.mjs):
.sl-opt-tile is the fourth row shape: a tile holding one group, the avatar gallery, carries the group's description as its text, so the tile is the row its hint belongs to
- Label baseline (tools/label-audit-baseline.json):
- The three recorded violations are removed; coverage is unchanged
Benefits:
- A click on a ban form label focuses the field it names
- ui:label starts from zero violations
Technical notes:
- No stored data, route or interface changes
The label crawl had been red since before Node: its baseline predated every Node page, so no new label defect could be told apart from the old ones. Three defects behind it are fixed and the baseline is taken again over the routes that exist today.
Core changes:
- One id key for the select fragment (templates/lite/fragments/select.html, callers):
The lite fragment read input_id while the admin one reads selectid, so a caller naming selectid left the site select without an id and its label pointing nowhere
- Node categories, extra fields of Field and getTplCatSelect() on the site were affected
- Both fragments read selectid; account, contact, rss, Node and the category select pass it
- TemplateValidationTest holds both fragments and refuses input_id at any select caller
- Hints of the Node admin forms (modules/node/admin/index.php):
The poll, publish date, type name, extension and view mode hints carry an id, and their field names it in aria-describedby, as every other admin form already does
- Accessible name of the code editor (core/classes/editor.php, plugins/editors/codemirror/driver.php):
- Editor::getCode() takes a label and falls back to _TEXT, as the content editors do
CodeDriver::getWidget() receives it; CodeMirror writes it as aria-label of its content through EditorView.contentAttributes, JSON-encoded so a file path cannot close the inline script
- All nine code editors of the panel name their file, template, block, query or log
- EditorFormatTest drives the driver and refuses a caller without a label
- Label baseline (tools/label-audit-baseline.json):
Taken again as a first store: the routes of the removed modules no longer exist, which the crawl counts as fallen coverage and refuses to overwrite; 20 entries become 3
- Kept: two duplicate ids of the security ban list, and the avatar hint of the settings tile,
which is referenced by its radio group but sits outside the rows the crawl knows
Benefits:
- A click on a label focuses its select, and a screen reader announces field names and hints
- ui:label is green and can report the next regression
Technical notes:
Breaking: CodeDriver::getWidget() takes a sixth argument string $label; a code editor driver of a third party must add it (UPGRADING.md, docs/EDITORS.md)
- The select fragment of the site no longer reads input_id
65ce7687 shipped config/fields.php without its account and forum sections. The fields unit of the 6.3 update reads a named file as the 6.3 format and requires each of its three areas to be a definition list, so a 6.2 site without a field configuration of its own stopped with a refusal before its schema ran.
Core changes:
- Shipped field definitions (config/fields.php):
account and forum ship as empty definition lists instead of being absent
- The demo fields stay removed; order keeps its example with field1 not required
Benefits:
- The 6.2 update finishes on the first run again (UpdateSiteTest)
- A clean installation carries no demo profile or forum fields
Technical notes:
- Configuration only; setUpdateFields() in setup/index.php is unchanged
- The stand keeps its own config/fields.php, only the shipped copy changes
docs/NODE-FINDINGS-2026.md planned the records the Node plan left open. All ten batches are in the previous commit, so the plan document goes; what outlives it is already in docs/NODE.md, docs/POINTS.md, docs/RATINGS.md, docs/TEMPLATES.md and in the tests that hold each fix.
Core changes:
- Plan document (docs/NODE-FINDINGS-2026.md):
- Removed after its last batch
Benefits:
- No plan document describes work that is already done
Technical notes:
- Documentation only, no code or behaviour change
The Node plan left open records outside its acceptance: defects of shop, order, forum, account, the core and the installer that its windows met and were not allowed to fix. This commit closes all of them in ten batches, each with a test that fails without its fix, and widens the gates so the code rules and the tooling hold.
Core changes:
- Shipped configuration and admin security (config/, admin/modules/.php, modules//admin/index.php):
- The debug panel ships closed (var_view 0) and getVariables() escapes every value
- The test bans of the stand leave config/security.php; the demo fields of account and forum leave config/fields.php
Every state-changing admin handler checks checkAdminPost() with its module scope; row actions post
- GET, header and query tokens are refused, AdminGuardTest scans every admin file
- The admin file rename accepts a plain name only and reports a failed rename
- Form fields named name are renamed, category parents refuse cycles, setForumLast() ends on a stored cycle
- Shop, order, forum and contact (modules/shop, order, forum, money, contact):
- The checkout reads the cart through getCartCookie() and clears it with setCookiesDelete()
- getTplPager() takes a known count; the product list qualifies p.status; mass actions split categories and modes
- Point compensations roll the owner back on false, as docs/POINTS.md now describes
- The CSV import leaves votes and comments alone, opens only files of its own directory, and stops repeating the id
- Settings texts of shop, order, money and contact use the editor field and the breaks format, so a save is stable
- Core writes, cache and templates (core/classes/template.php, pdo.php, cache.php, comment.php, core/system.php):
- Compiled templates and scheduler state files are written through a temporary file and a rename under a lock
- The panel bumps the page cache on its first write and once more at shutdown; _session writes no longer bump
- Comment::updateBody() and the deferred recount run under the write guard; silent failures log their reason
- Cache::setDirPath() creates every cache directory and tolerates a lost mkdir race
- Node (core/classes/node/*.php, modules/node/):
- getTreeRows() limits replies per root in one light walk; batch sizes follow NodeQuery::getTargetSize()
- Comment::getThread() reads a support thread at once; stored types normalise a late rule on read
- view.mode is a closed list, the report switch follows the mode, categories and sitemap follow the language
- A non-moderator without pre-moderation gets no external address field; import failures answer their reason
- Installer and the 6.3 update (setup/index.php, setup/sql/table_update6_3.sql):
- Duplicate rating rows are removed before the unique key, the 6.2 loader is replaced by the shipped panel
- checkSetupCode() counts failures under a lock and removes the key after the fifth
The update carries an early 6.2 schema, NULL addresses, negative balances and MySQL 8 zero dates
- New fixture tests/Fixtures/update62early; the fixtures' site.sql is kept by .gitignore
- Interface and language (templates/, lang/, plugins/system/slaed.js):
- Favourite buttons post without an href, POST-only ops answer 405, the admin pager shows its total
- _BACK means back in Polish and Ukrainian; the rating widget reads the checked rule and answers blocked scopes
- The forum repair of counters is a POST button; auto_links reads banners of the site theme
- Code rules sweep (whole tree, tests/PhpFileFormatTest.php, .php-cs-fixer.dist.php):
- Comments leave function bodies, one line above a class, no period, no Cyrillic, 180 characters per line
- list_syntax and indentation_type join the fixer; shop and whois are indented with spaces
- Gate tooling (tools/ui-shots.mjs, tests/Support/tree_walk.php, tests/bootstrap.php, tools/upload-route-check.php):
- ui-shots signs the modes in one after another with one retry; --before --only keeps the rest of the pair
- Every source gate walks the tree through getTreeFiles(), which never enters storage or a scratch theme
- In-process tests log into a directory of their run instead of the site log of the stand
- setFailTrigger() is defined again; PointTest and RatingTest fail on a broken probe instead of skipping
Benefits:
- A clean installation no longer exposes cookies and sessions or carries test bans
- Admin state changes need a POST of their own scope
- The full suite and ui:gates can run side by side without false failures
Technical notes:
- Schema: table_update6_3.sql removes duplicate _rating rows and aligns the early 6.2 column shapes
API: getTplPager() accepts count, NodeQuery::getTargetSize(), NodeQuery::MODES, Comment::getThread(), Rating::getRule() and the blocked code 503, Point::$active readable, checkCatRight() replaces checkCatRead()
Breaking: admin handlers refuse tokens outside a POST of their scope; a stored forum or category cycle is refused on save; view.mode support requires the support extension