Журнал изменений
Every frontend list now renders the moderator gear menu before the number anchor in one cell and moves the date column into the info tip before the title, freeing ~120px for titles.
Core changes:
- Generic list row (table-row.html, table.html):
Moderator popover merged into the sl-table-col-num cell, the separate "Functions" column and its col_func header removed
Date cell replaced by a report tip before the title link; data-sort keeps tablesort clean; col_date header removed
- List modules (files, pages, news, links, media, faq, help, shop):
- time_text/time_iso/time_label replaced by one getTplTitleTip call
- col_func / col_date dropped from table_open
- Voting and content:
- voting-home.html: gear menu ordered before the number anchor
content: cells reordered to match the header (title, number) fixing the header/body column misalignment
Benefits:
- Identical gear+number pattern across all modules
- Header and body columns always match for guests and moderators
The toolbar classifier measured a mid-parse column width and never re-ran, so icons spilled over the sidebar; the editor mount div also shrink-wrapped to the toolbar instead of matching the other fields.
Core changes:
- Toolbar refit (slaed-tags.js):
Pin the toolbar to the real remaining row width (minus md tabs) so the native ResizeObserver reclassifies against honest numbers
- Re-run on window load, window resize and editor changeMode
- Editor sizing and reflash (slaed-icons.css):
Mount div gets flex basis / width 100% like every .sl-field input, in both markdown and wysiwyg modes
overflow-x clip on the toolbar row keeps the brief all-icons re-render inside the frame; dropdown and popups stay visible
Benefits:
- Icons never paint over the sidebar at any viewport width
- Surplus icons land in the native "..." dropdown as designed
The voting button relied on HTMX implicitly including the enclosing form's token; make it explicit like the other form-based ajax actions (addComment, addPrivateMessage).
Core changes:
- Voting widget (core/system.php):
- Pass hx_include => '#form'.$votid to the vote action so the form (token + answers) is included
- Action fragment (templates/{lite,admin}/fragments/comment-action-ajax.html):
- Render an optional hx-include attribute when provided (no-op for other callers)
A stale or missing CSRF token on a go=1/2/5 request died with a raw "Illegal file access". Return the localized alert instead, and make the token constant available on the front end where the gate runs.
Core changes:
- Ajax gate (index.php):
- On token mismatch return the _TOKENMISS alert fragment instead of a bare die()
- Language constants:
- Add _TOKENMISS to all front-end lang files (loaded first at bootstrap, before the gate)
- Remove the now-duplicate _TOKENMISS from admin lang files
Callouts nested inside list items were emitted as raw "> [!...]" text instead of rendering as alert blocks.
Core changes:
- auto_links / changelog admin help (modules/*/admin/info/ru.md):
- Move the [!TIP]/[!IMPORTANT] callouts to top level so they render as .sl-alert
The *NN smiley rule matched the digits of bold markup and longer numbers, rendering a stray smiley (e.g. 12 ... produced smiley 12).
Core changes:
- BB block parser (core/classes/parser.php):
- Match smilies as (?<!\)\(0[1-9]|1[0-8])(?!\d): not after another asterisk, not inside a longer number
- Bold like 12 and numbers like *180 stay as text;
..
still render
Remove the redundant control-panel path from the first line of every admin help page, and restructure the ratings help so a non-technical admin can grasp all the rules at a glance.
Core changes:
- All admin help (admin/info/, modules//admin/info/*):
- Strip the "(
admin.php?name=xxx)" reference from the section intro (44 pages) - Reword the search help sentence that spelled out the path
- Ratings help (admin/info/ratings/ru.md):
- Group the content into: where rating works, the three per-module settings, and anti-farm protection
- Document the built-in protections (self-vote block, existing/published target only, no points for profile rating, daily point cap, 1-5 clamp)
- Move callouts to top level so they render, and drop bold that collided with the smiley syntax
The BB smiley rule turned any asterisk followed by two digits into an <img smilies/NN.gif>, but only icons 01-18 exist. Codes like 19-99 (and the leading digits of bold such as 30) rendered as a broken image anywhere user text is parsed (forum, comments, help docs).
Core changes:
- BB block parser (core/classes/parser.php):
- Narrow the smiley match from \(\d{2}) to \(0[1-9]|1[0-8])
- Out-of-range *NN now stays as plain text instead of a broken image
Overhaul how contribution points are earned and harden the rating endpoint against inflation, with a naming-compliance rename of the points primitives. No schema changes.
Core changes:
- Points primitives (core/system.php):
- Rename update_points -> updatePoints, addActionPoint -> addPointsAction (camelCase per .rules naming)
- addPointsAction: credit repeatable-action points once per (event, item, user/ip) within the retention window, reusing the _rating dedup table
- setContentActive: atomically promote pending content to active and credit submission points to the AUTHOR; replaces addPointsAuthor + a manual status flip
- Award timing moved submit -> approval (modules//index.php, modules//admin/index.php):
- Drop the immediate submit-time credit in news/pages/media/jokes/faq/links/files
- Credit the author via setContentActive on every promote-to-active path (full-edit save, single approve, batch activate)
- Repeatable-action dedup at call sites (modules/auto_links, files, links):
- auto_links view and file/link download now go through addPointsAction (no more unlimited farming by reloading the URL)
- Rating hardening (core/system.php getRatingView, core/helpers.php, index.php):
- Block rating your own account
- Accept votes only for an existing, visible target (status != 0) -> kills farming via non-existent ids
- Account rating awards no points; per-voter daily cap (<=30) on rating-earned points
- Keep the 0..5 rate clamp; wrap the vote in a transaction; number_format the average
- Narrow the go=1/2/5 CSRF-token exemption so only go=4 uploads may defer the token
Benefits:
- Removes point-inflation and group-escalation vectors (URL farming, rating id enumeration, self-rating)
- One forget-proof approval helper instead of 12 scattered award+flip sites
- Consistent camelCase points API
Technical notes:
- Reuses the existing _rating table for dedup and the per-voter cap; no schema change
- Behavior change: contribution points now appear when a moderator approves the item, not on submission