Журнал изменений

Официальный сайт SLAED CMS

Журнал изменений

Фильтр и поиск

Всего: 1216 Доступных коммитов | Отфильтровано: 1216 Коммиты | Страница: 1 из 122
Сегодня (02.10.2026)
Feature: The installer plan closes with its tests and help, setup.php keeps its token in the session and only refuses an installed site, and site mail leaves as multipart with a site sender
Автор: Eduard Laas | Дата: 11:31 02.10.2026

The last two batches of the installer plan land: the probes walk the new setup.php end to end, the help moves into the permanent references and the plan file is deleted. The installer stops deleting itself on an installed site, which a development copy needs, and its CSRF token moves from storage/install.php into the session. Site mail is sent as multipart/alternative from the site address, with Date and Message-ID on every transport.

Core changes:

  1. Installer (setup.php, templates/admin/pages/setup.html, templates/admin/assets/css/theme.css):
  2. setSetupShut() answers an installed site with the refusal only: no form, no write and no delete

    • The installer deletes itself only on the closing stop of its own installation
    • A file that stays keeps the _DELSETUP warning of the panel
  3. The CSRF token is a random value in the session of the installing browser

    • storage/install.php, getSetupToken() and its two unlink() calls are gone
    • A token of another browser is refused like none
  4. Zip and Zlib are optional: a missing one is a warning row (is_warn, .sl-is-warn) that lets the server stop pass

    • mbstring, PDO MySQL and JSON still hold the stop
  5. Mail (core/classes/mail.php, core/system.php, core/user.php, modules/account, modules/forum, admin/modules/config.php):
  6. Every message is multipart/alternative: a plain-text part derived from the HTML, then the HTML part
  7. Date and Message-ID are written for every transport; X-Priority stays normal
  8. From is the configured identity, else the site address; a form visitor becomes Reply-To, never the sender
  9. getMailFrame() wraps a text into the plain-text mtemp frame; every caller goes through it
  10. addQueue() stores the body through getOutputHtml()
  11. Languages (admin/lang/*.php):
  12. _SETUP_NOOPT for a missing optional extension
  13. _SETUP_ZIP and _SETUP_ZLIB name the ZIP and GZ archives they serve
  14. Tests (tests/Support/, tests/Unit/):
  15. The install probe walks the seven stops over HTTP, checks the refusals with the own and a foreign token, and expects a shut installer to stay in place

  16. Mail tests cover the frame, the queued body format, the sender, Reply-To, Date and Message-ID
  17. Docs and housekeeping (docs/*, README.md, SECURITY.md, UPGRADING.md, CONTRIBUTING.md, .htaccess, robots.txt, admin/modules/editor.php, core/classes/filemanager.php, .gitignore, demo/*):

  18. docs/SETUP-2026.md is deleted; the installer lives in docs/ARCHITECTURE.md "Installation", the 6.3 update in docs/NODE.md "The 6.3 update"

  19. UPGRADING.md states that the release does not update a 6.2 site
  20. The setup/ directory rules and the setup.php entry of the critical files of the file manager are dropped

Benefits:

  • A development copy of an installed site keeps its installer
  • The installer writes nothing outside config/ before the run and leaves no token file behind
  • A server without Zip or Zlib installs
  • Site mail passes SPF and DMARC of the site domain and carries the headers filters score

Technical notes:

  • No schema change
  • storage/install.php is no longer written; an existing one is unused
  • An installed site with setup.php left in the root shows the panel warning until the file is deleted
Вчера (01.10.2026)
Fix: The sitemap lists only the forum categories and topics a guest may open, and the forum takes part in the map again
Автор: Eduard Laas | Дата: 23:44 01.10.2026

The XML sitemap listed every forum topic and category, including those whose read right is closed to guests, so the map advertised addresses a search engine could only answer with a refusal.

Core changes:

  1. Sitemap task (core/system.php, addSitemapTask()):
  2. A forum topic enters the map only when the read right of its category opens to a guest
  3. A forum category enters the map only when its view right opens to a guest
  4. The guest branch follows is_acess(): level 0, no group, and an empty right stays closed
  5. Configuration and output (config/sitemap.php, sitemap.xml):
  6. The modules of the map include forum
  7. sitemap.xml is generated again on this rule: 3385 addresses, 2221 of them in the forum

Benefits:

  • The map names only pages a crawler can read

Technical notes:

  • Node types keep their own sitemap integration, read as a guest of the site language
Docs: The Node help explains every screen of the materials section to the operator, with callouts for what is irreversible, required or unsafe
Автор: Eduard Laas | Дата: 23:43 01.10.2026

The help tab of the materials section grew from one page of notes into a full operator guide, written as the current state of the system and checked against modules/node/admin/index.php, the Node classes and docs/NODE.md.

Core changes:

  1. Help (modules/node/admin/info/ru.md):
  2. Terms: type, material, resource and its role, extension, profile
  3. The list: filters, the five states and the allowed moves, the trash, what a permanent deletion removes, the version check

  4. The material form: fields by the features of the type, deferred publication and the nodepublish job, editor attachments [attach=...], concurrent editing, reports on resources

  5. Types: life of a type, the nginx rule for uploads/<type>, records of removed sections, every setting of a type with tables of the seven display modes, the twelve features and the six display modes of a resource role

  6. The ten shipped types, the support extension (queue, working card, states, mail) and the sync extension (source, period, manual check, back-off after errors), the four limits with their defaults, the rights

  7. 14 callouts of the five kinds the parser knows; the nginx rule stands under its callout, because a fence inside a callout is dropped

Benefits:

  • An operator finds the answer on the tab instead of in the developer reference

Technical notes:

  • Russian only, as every help page of the panel; renders cleanly on the stand
Fix: One cron or pseudo-cron call runs every due job in priority order, so a job due every minute no longer keeps the jobs behind it waiting, and the scheduler help describes the scheduler as it is
Автор: Eduard Laas | Дата: 23:42 01.10.2026

A call of the scheduler endpoint ran only the first due job. nodepublish is due every minute, so on a site called once a minute the jobs further down the priority list hardly ever got a turn: on the stand monitor had not run for twenty days, nodesync never, and maildrain ran only now and then although all mail of the site goes through it.

Core changes:

  1. Runner (core/system.php):
  2. addSchedulerBatch() walks the jobs in priority order and runs each due one at most once

    • A job another process holds is passed over, the rest of the call still runs
    • No further job starts once the call has spent 60 per cent of max_execution_time, or 120 s without a limit
  3. Returns status done or idle with the list of jobs it ran
  4. Endpoint (index.php):
  5. A cron or pseudo call without job= runs addSchedulerBatch(); with job= it still runs that one job
  6. Tests (tests/Support/scheduler_probe.php, tests/Unit/SchedulerLockTest.php):
  7. oneCallRunsEveryDueJobOnce: two due jobs run in one call in priority order, a second call finds nothing, and a job held by a second process is passed over while the other one runs

  8. Help (admin/info/scheduler/ru.md):
  9. All nine system jobs with key, schedule and priority, including nodepublish, nodesync and monitor
  10. How a call runs, real cron each minute, the pseudo-cron and when it steps aside, the six top-level settings of config/scheduler.php, the form and its limits, the labels as the screen shows them

Benefits:

  • Every job runs on its own schedule
  • The work per unit of time is the configured one; the runner itself adds a few file reads per call

Technical notes:

  • Manual runs from the panel are unchanged
  • The JSON answer of a call without job= carries jobs[] instead of a single job key; nothing reads it
Refactor: The help tab of every panel section reads its own constant _MANUAL, _DOCS stays the title of the documentation type, and two mislabelled controls get their right words
Автор: Eduard Laas | Дата: 23:42 01.10.2026

The help tab op=info borrowed _DOCS, which is also the title of the Node type docs. With the type named "Документация" every help tab of the panel said so too. The tab gets a constant of its own, and the two places that used _DOCS for something else get labels that say what they do.

Core changes:

  1. Constant (admin/lang/*.php, lang/ru.php, lang/uk.php):
  2. _MANUAL in all six admin dictionaries: Help, Hilfe, Aide, Pomoc, Справка, Довідка
  3. _DOCS reads Документация in ru and Документація in uk, the title of the docs type in every locale
  4. pl _NO_SICHT reads Niewidoczny w bloku modułów instead of Niewiem w bloku modułów
  5. Help tabs (admin/index.php, admin/modules/.php, modules//admin/index.php):
  6. Every op=info tab and link and the help item of a module menu read _MANUAL
  7. Two tab calls of admin/modules/groups.php wrap to stay inside 180 characters
  8. Labels (admin/modules/security.php, admin/modules/modules.php):
  9. The log view of the security section reads _SHOW
  10. The module list tip reads _STATUS: Invisible in the block of modules
  11. The title of a module name carries the plain name instead of the markup of its tip
  12. Usage audit (tests/LanguageConstantsUsageTest.php):
  13. Constants named by a module profile modules//profiles/.json count as used, so _DOCS, _NODE_CAST and the other field titles of the Node profiles leave the list of unused constants

Benefits:

  • One constant, one meaning: help is help, the docs type is documentation
  • The unused count of the audit names only what is really unused

Technical notes:

  • No constant removed; _MANUAL is new in admin/lang only, where every user of it runs
  • LanguageValidation, LanguageConstantsUsage and ModuleStructure are green
Test: The suite stops asserting the removed setup/ directory, drops two placeholder tests, and the route probe serves rewritten configuration at once
Автор: Eduard Laas | Дата: 23:41 01.10.2026

Work ahead of batch 6 of docs/SETUP-2026.md: the tests that still read the old installer lose what only it had, and two tests that could never fail leave the suite.

Core changes:

  1. Installer contract (tests/Unit/NodeProfileTest.php):
  2. onlyANewInstallationLeavesTheMark is gone, it grepped the update branches of setup/index.php
  3. theUnlockedInstallerRefusesBeforeItWrites becomes theInstallerRefusesBeforeItWrites without the step and code rows; its other rows stay the contract setup.php must meet

  4. Tree walk (tests/Unit/PointOwnersTest.php):
  5. setup/ leaves the directories the point owners are searched in
  6. Route probe (tests/Support/route_probe.php):
  7. The built-in server runs with opcache.revalidate_freq=0, because the probe rewrites the scratch configuration between requests and a file cached two seconds longer served old values to NodeGuardTest and NodeIntegrityTest

  8. Placeholders (tests/Unit/ExampleTest.php, tests/LanguageValidationTest.php, docs/TESTS.md):
  9. ExampleTest asserted only that PHPUnit runs; testNoUnusedConstants was skipped unconditionally since the usage audit of LanguageConstantsUsageTest replaced it

Benefits:

  • No test fails on a directory that no longer exists
  • Every remaining test can fail

Technical notes:

  • NodeProfileTest stays red until batch 6 drives the new stops of setup.php
Feature: setup.php installs a clean site in seven stops, runs the installation in parts the card shows as they happen, creates the first administrator and deletes itself
Автор: Eduard Laas | Дата: 23:40 01.10.2026

Batch 4 of docs/SETUP-2026.md: the new installer is one file in the site root on the admin theme. It installs a new site only, keeps its answers in the session, writes the configuration, the tables, the data and the administrator as separate requests, and removes itself and its token with the closing stop. Batch 5 is dropped: the empty-table recovery form of admin.php stays as the way back into a panel that lost its last administrator.

Core changes:

  1. Installer (setup.php):
  2. Stops: language, server checks, database, site, administrator, run, done
  3. Boots without the core; every function carries a name the core does not declare
  4. An installed site - config/db.php names a database holding an _admins row or not answering - is refused and the file tries to delete itself; only the browser that started the run passes

  5. A one-time token in storage/install.php guards every form; the answers live in the session under {user_c}-setup
  6. The run: configuration, table.sql in groups of seven, every statement of insert.sql alone, the administrator; a part is marked busy before it runs, so a repeated request fails the run instead of running it twice

  7. Only the administrator part boots the core; it creates the account, imports the Node profiles and sets the core language cookie

  8. Panel (admin/index.php, core/admin.php, templates/admin/partials/auth-form.html):
  9. addNodeProfiles() moves to core/admin.php, where setup.php can load it; admin/index.php keeps calling it
  10. An administrator password is hashed as typed; the login checks it as typed and falls back to the old form of the login, so an older hash still opens the panel

  11. The recovery form carries a token of scope add_admin
  12. Driver (templates/admin/assets/js/admin-ui.js):
  13. Posts go=part until the run reports no more parts or a reply breaks, then submits go=next for the closing stop
  14. Repository (.gitignore, docs/SETUP-2026.md):
  15. storage/install.php is ignored; the plan records batches 3 and 4 as landed and batch 5 as dropped

Benefits:

  • One file to upload, no setup/ directory, no installer left on a live site
  • A failed part is reported with its reason and resumes from the database stop

Technical notes:

  • The release carries a new installation only; updating a 6.3 site is update.php, which is not shipped
  • Batch 6 (installer tests) is next; NodeProfileTest stays red until it lands
Feature: The admin theme carries the installer - one page on the login card, a road of seven stops, the run and the seal, built on the parts the theme already has
Автор: Eduard Laas | Дата: 23:39 01.10.2026

Batch 3 of docs/SETUP-2026.md: the look of the stand face demo/setup-09-motion.html moves into the admin theme as one page whose stop is data, so setup.php prints no markup and no style of its own.

Core changes:

  1. Page (templates/admin/pages/setup.html):
  2. Extends layouts/bare.html; the road, the head with the step counter, the lead, alerts, language tiles, form rows, check rows, the run and the done stop are blocks shown by the keys a stop passes

  3. The buttons are submits go=back|probe|next in reading order; an unseen default button go=next opens the form, so Enter in a field moves forward while focus walks the row as it stands

  4. Styles (templates/admin/assets/css/theme.css, base.css):
  5. sl-setup-* rules: the 480px card, the road of segments, check rows, the striped run with a glowing head, the seal whose ring and tick draw themselves while ten sparks fly off

    • Every animation runs from the hidden state to the finished one under prefers-reduced-motion: no-preference
    • Every motion is a multiple of one beat --sl-setup-dur
  6. Built on what exists: a language tile is an sl-icon-cell, the spring is --sl-alert-ease, ticks land with sl-alert-land, the seal draws with sl-alert-flash-ring in reverse, the title rises with sl-modal-in, the logo sheen joins the beam rule, and the hint under a field belongs to every login list

  7. New tokens --sl-setup-width, --sl-setup-dur, --sl-setup-shadow, --sl-setup-seal-width
  8. Script (templates/admin/assets/js/admin-ui.js):
  9. The pointer light also writes --sl-d-rim-x / --sl-d-rim-y on the installer card, so the light runs along its rim
  10. The icon picker reads only cells carrying data-sl-icon-name, since a language tile is an icon cell too
  11. Contract (tools/ui-contract.php, tools/ui-audit-baseline.json):
  12. Components setup and setup-seal, data tokens --sl-d-rim-x and --sl-d-rim-y; the baseline is stored again

Benefits:

  • The installer looks like the panel it opens and follows both colour schemes
  • No zoo: seven keyframes of its own, everything else reused

Technical notes:

  • php tools/ui-audit.php shows no grown ratchet count; ui:gates green
  • Checked in Chromium and Firefox: Enter submits go=next, Tab walks back, probe, next
Style: An icon stands apart from its button label, alerts read left aligned, the login foot grows on a phone and every sidebar head sets its tone as one pair
Автор: Eduard Laas | Дата: 23:38 01.10.2026

Four visual faults of the themes are closed at their source rules: a button glued its icon to the label, alerts justified their text into gaps, the striped login foot cut the second line of the licence on a phone, and the sidebar heads of the admin panel took a light blue rim in the dark scheme.

Core changes:

  1. Buttons (templates/admin/assets/css/theme.css):
  2. Every sl-but, sl-but-blue, sl-but-red, sl-but-green, sl-but-foot and sl-but-back carries gap: var(--sl-space-2)

    • The space between an icon and its label collapsed inside the inline-flex box, so every icon touched its text
    • 4 px is the gap the chips already use
  3. Alerts (templates/admin/assets/css/theme.css, templates/lite/assets/css/theme.css):
  4. .sl-alert in admin and .sl-alert-text in lite read text-align: start instead of justify

    • A long address in a narrow alert no longer spreads its words apart
  5. Login card (templates/admin/assets/css/theme.css):
  6. Under 560px the striped foot takes min-height instead of a fixed height and pads the licence line

    • The second line of the licence stays inside the foot
  7. Sidebar heads (templates/admin/assets/css/theme.css):
  8. Each tone sets its fill and its border as one pair in its own rule

    • The default head reads --sl-solid-good-bg with --sl-solid-good-border
    • Blocks 1-2 read --sl-solid-bg with --sl-solid-border, the pair of sl-but-blue and the dashboard heads
    • Blocks 3-4 read --sl-solid-warn-bg with --sl-solid-warn-border
  9. The tight sidebar rule keeps only geometry; its two overrides are gone

    • The blue override read --sl-primary-strong, which turns light blue in the dark scheme

Benefits:

  • A sidebar head matches the Save button in both schemes
  • One address per tone instead of a base rule, a sidebar rule and two overrides

Technical notes:

  • No token added or renamed; php tools/ui-audit.php shows no grown count
  • Visual change on every page with an icon button or an alert, checked with ui:before / ui:after
Chore: The old installer is kept as setup_old/ and two references follow the move of the installer
Автор: Eduard Laas | Дата: 17:56 01.10.2026

The installer of 6.3 stays in the tree as setup_old/ for reference while the new setup.php is written; it is the setup/ directory of e28d3639 byte for byte. Two texts that still named setup/ after the move now say where the code lives.

Core changes:

  1. Old installer (setup_old/):
  2. index.php, lang/, templates/ and the guards of setup/ as they were before the move

    • its .sql files stay out of git, .gitignore keeps *.sql out; the schema lives in storage/update/sql
  3. References (core/admin.php, docs/SETUP-2026.md):
  4. the comment of getSqlbatch() names update.php as the third caller instead of setup/index.php
  5. the plan points at e28d3639 for the removed setup/ and records that setup_old/ is tracked

Benefits:

  • The old validation and texts stay at hand for the new installer

Technical notes:

  • setup_old/index.php dies without SETUP_FILE, so the copy runs nothing on its own
  • No behaviour changes

Страница 1 из 122. Всего: 1216

1 2 3 4 5 6 7 8 9 10 … 122
Хотите опробовать SLAED CMS в действии?
Идеи и предложения
Обратная связь
Подтверждение

Поделиться
QR-код

Предварительный просмотр