Журнал изменений

Журнал изменений

Фильтр и поиск

Всего: 1091 Доступных коммитов | Отфильтровано: 1091 Коммиты | Страница: 17 / 110
25.06.2026
Refactor: consistent op=liste behavior across listing modules
Автор: Eduard Laas | Дата: 15:56 25.06.2026

Align the alphabetical listing (op=liste) across all eight modules that provide it: empty results now return a proper 404 page, the letter filter is case-insensitive, and the unreachable empty_alert is removed.

Core changes:

  1. Empty list -> 404 (modules/{faq,files,help,links,media,news,pages,shop}/index.php):
  2. liste(): "if (!$rows) setError(404)" replaces the partial "num > 1" guard

    • Empty letter filter (e.g. let=w) now yields the branded 404 page like num=99
  3. Case-insensitive letter filter:
  4. Both the result query and the pager count query use UCASE(title) LIKE BINARY UCASE(:let)

    • let=p and let=P (and Cyrillic) now match identically
    • Fixes result/pager parity (pager previously did not UCASE the title)
  5. Dead code removal:
  6. Dropped the now-unreachable 'empty_alert' key from the liste() content-list call (empty result is caught by the 404 before the list renders)

Also folds a minor pre-existing spacing fix in the file upload note (_ADDFNOTE2).

Benefits:

  • Predictable 404 semantics for missing/empty listings
  • Letter filter works regardless of case; count and results stay consistent
Feature: branded static error page on the .sl-alert standard
Автор: Eduard Laas | Дата: 15:56 25.06.2026

Bring the self-contained 502/504 fallback page in line with the unified .sl-alert component and make its recovery links work even while the local server is down.

Core changes:

  1. Error markup (error.html):
  2. Error text now uses .sl-alert sl-alert-warn with an inline SVG icon

    • Self-contained: no icon font or external CSS (page must render when PHP is down)
    • Solid exclamation-triangle icon, soft tinted box, accent left bar, subtle shake
  3. Recovery links (brand, home, search) point to the always-up vendor site so they remain usable during an outage of the local server

Benefits:

  • Error page matches the rest of the system visually
  • Links stay functional when the user's server is unavailable
Feature: unified .sl-alert notification component across lite, admin and parser
Автор: Eduard Laas | Дата: 15:56 25.06.2026

Replace the divergent per-theme alert styles (.sl-warn/.sl-info and the admin-only .sl-callout-*) with a single .sl-alert component shared by both themes and the Markdown parser, add a 5-second flash auto-hide, and emit the favicon link for the admin area as well.

Core changes:

  1. Alert component (templates/lite/assets/css/theme.css, templates/admin/assets/css/theme.css):
  2. One .sl-alert vocabulary with five tones (info, success, warn, error, accent)

    • Icon via ::before, tone-bound looping animation, prefers-reduced-motion guard
    • Identical class names in both themes; theme keeps its own visual style
  3. Removed dead legacy alert CSS

    • Dropped admin .sl-callout-* and the legacy .sl-warn/.sl-info component
    • Dropped unused .sl-table-block
  4. Fragments (templates/lite|admin/fragments/alert.html, blockquote.html):
  5. Alert fragment renders .sl-alert with type/is_warn fallback (contract preserved)
  6. Blockquote GFM callouts render as .sl-alert sl-alert-<tone>
  7. Parser (core/classes/parser.php):
  8. Map callout kind to semantic tone (NOTE->info, TIP->success, IMPORTANT->accent, WARNING->warn, CAUTION->error); styled fallback when no template engine

  9. Flash auto-hide (templates/admin/assets/js/alerts.js, core/helpers.php, core/system.php):
  10. Timer reduced from 15s to 5s (JS default and data-sl-autohide callers)
  11. Branded head (core/system.php, favicon.ico):
  12. setHead() now emits the favicon link for admin too (was frontend-only)
  13. Added root favicon.ico generated from the theme favicon for legacy probes
  14. Editor plugin (plugins/editors/toastui/assets/slaed-upload.js):
  15. Upload status messages use .sl-alert sl-alert-warn / -info

Benefits:

  • Single alert vocabulary reused everywhere, less duplicated CSS
  • Consistent alert/callout look and behavior across themes and content
  • Favicon served on every surface; no more /favicon.ico fallback miss

Breaking: .sl-callout-* classes removed (no external consumers).

24.06.2026
Fix: drop CDATA wrapper in error.html inline logo SVG
Автор: Eduard Laas | Дата: 22:17 24.06.2026

Remove the XML <![CDATA[ ]]> markers around the inlined logo's inner <style>. They are unnecessary in an HTML document (style content is already raw text) and were flagged by the HTML validator. The logo renders identically since the .fil* rules remain in the <style> block.

Feature: self-contained error page and consistent branded error responses
Автор: Eduard Laas | Дата: 22:12 24.06.2026

Route every web-server error code to the SLAED branded page and add a fully self-contained static fallback for 502/504, so visitors always get the themed error UI instead of a bare nginx/Apache page even when PHP is down. Several modules that silently fell back to the home page now return SEO-correct 404s.

Core changes:

  1. Static 502/504 fallback (error.html):
  2. New self-contained page served by the web server when PHP is unavailable

    • Inline CSS (theme rules), inline SVG logo and icons, no external file
    • Inline JS sets the current year; 2026 is the no-JS fallback
    • noindex; renders identically to the live branded error page
  3. ?error= contract and status reasons (core/security.php):
  4. Whitelist ?error= codes 400 401 402 403 404 500 502 503 504

    • Forged or unknown codes fall through and cannot emit arbitrary statuses
  5. Extend the setError() status-reason map (401, 402, 502, 504)
  6. SEO-correct 404s instead of soft home redirects:
  7. index.php: unknown, inactive or unservable module now setError(404)
  8. modules/changelog/index.php: out-of-range page now setError(404)
  9. Web-server wiring and documentation:
  10. .htaccess: ErrorDocument 502/504 to /error.html for Apache parity
  11. docs/PERFORMANCE.md and admin/info/editor/ru.md: nginx/Apache recipes, fastcgi_intercept_errors off, the ?error= whitelist and the static page

  12. Error-page card styling (templates/lite/assets/css/theme.css):
  13. Adjust .sl-msg-search and .sl-msg-foot widths and spacing to fit the card
  14. Regression guard (tests/ErrorPageContractTest.php):
  15. Assert error.html is self-contained (no external CSS/JS/img) and branded
  16. Assert the ?error= whitelist is fully covered by setError() reasons

Benefits:

  • Correct HTTP status on every error path, improving SEO and crawler signals
  • Branded, no-store error UI even during a PHP-FPM outage
  • One error-rendering contract shared by nginx and Apache

Technical notes:

  • error.html is generated from the lite theme with only used rules and tokens
  • nginx still serves real 502/504 from the static file; 502/504 are whitelisted only so a manual ?error= still renders when PHP is alive

  • No database or schema changes; backward compatible
Feature: consistent gated responses for uncaught errors and DB failure
Автор: Eduard Laas | Дата: 15:49 24.06.2026

Uncaught exceptions, fatal errors, and the DB-connection failure now produce a consistent response: the full error detail in debug mode, a clean 500 in production, and never an HTML page inside a non-HTML response. Detail goes to the log; nothing internal is shown to visitors in production.

Core changes:

  1. Error responder (core/security.php):
  2. Add setErrorOut(): recursion-guarded; skips non-HTML requests (go=1/2/3/4/5/asset/captcha/rss/xsl or headers already sent) with a status-only 500; debug shows the detail via setExit() (status 200, so nginx never intercepts it); production renders setError(500)
  3. set_exception_handler() now routes through setErrorOut() and logs the full trace; rendering is decoupled from security.error_log so a clean 500 page appears even with logging off
  4. register_shutdown_function() logs fatals (when enabled) and sets a 500 status without a heavy render (process state may be broken)
  5. setError() status map gains 503 Service Unavailable
  6. Database connection (core/classes/pdo.php):
  7. On PDOException, gate the detail by security.error: debug shows it (setExit), production renders setError(500); the detail is logged in both cases

Technical notes:

  • App-emitted errors render the SLAED page with Cache-Control: no-store; status via http_response_code() (HTTP/2 safe)
  • Debug detail is served as 200 so it survives nginx without fastcgi_intercept_errors off; the full stack trace is written to the log
  • Behavior change: uncaught errors no longer fall through to raw PHP output; production no longer leaks DB internals to the page
Docs: clarify nginx error-page handling for PHP 4xx/5xx
Автор: Eduard Laas | Дата: 15:13 24.06.2026

Document that PHP-generated 404/403/503/500 must pass through (fastcgi_intercept_errors off) so SLAED's branded page and no-store headers reach the client, and separate app-emitted 5xx from infrastructure 5xx (502/504) that only nginx can answer.

Core changes:

  1. Performance guide (docs/PERFORMANCE.md):
  2. New "PHP error pages" subsection under the web-server configuration section
Fix: emit 500/503 instead of 200 for DB failure and maintenance
Автор: Eduard Laas | Дата: 15:13 24.06.2026

A DB-connection failure and the site-closed gate returned 200, which misleads crawlers and monitoring. They now carry the correct status, and the DB error detail is logged instead of shown to visitors.

Core changes:

  1. Database connection (core/classes/pdo.php):
  2. On PDOException, log the detail via Logger and render setError(500) instead of setExit() (was 200; also stops leaking the raw DB message to the page)
  3. Maintenance gate (index.php):
  4. Closed-site response now sends 503 Service Unavailable while keeping the _CLOSE_TEXT page
  5. Error helper (core/security.php):
  6. setError() status map gains 503 Service Unavailable

Technical notes:

  • App-emitted 5xx render the SLAED page (status via http_response_code(), Cache-Control: no-store)
  • captcha JSON 503 left as-is; infra 5xx (502/504) remain nginx's responsibility
Style: brand error page title and drop redirect wording
Автор: Eduard Laas | Дата: 11:10 24.06.2026

Align the error page presentation with the removed auto-redirect.

Core changes:

  1. Error page (templates/lite/pages/message.html):
  2. Render "<title> - <sitename>" when a page title is set
  3. Localization (lang/*.php):
  4. _ERROR_PAGE now invites returning home or using search instead of announcing a redirect (de/en/fr/pl/ru/uk)
Feature: return SEO-correct HTTP 404/403 instead of soft 200/302
Автор: Eduard Laas | Дата: 11:10 24.06.2026

Missing content, out-of-range list pagination and access-restricted pages now emit proper 404/403 instead of redirecting or returning 200, so crawlers stop indexing soft-error pages. Error rendering is consolidated into one setError() helper.

Core changes:

  1. Error helper (core/security.php):
  2. Add setError(int $code): status via http_response_code(), conditional logging, standard error page
  3. Drop the meta-refresh auto-redirect from setExit() (soft-404 / WCAG 2.2.1 anti-pattern)
  4. Route the bootstrap $_GET['error'] handler through setError(), removing the 40-line $http status map
  5. Frontend modules (modules/*/index.php):
  6. view(): 404 when the item does not exist
  7. list/liste(): 404 when a page beyond the first yields no rows
  8. forum: 404 for out-of-range topic pages and unpublished topics, 403 when category read is denied
  9. broken()/loading(): 404 on invalid requests
  10. Module gates (index.php):
  11. view=1 / view=2 access denials now send 403

Technical notes:

  • http_response_code() is HTTP/2-safe; error responses keep Cache-Control: no-store
  • Backward compatible; php -l and phpstan clean

Всего: 1091 на 110 страницах по 10 на каждой странице

1 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 110
Хотите опробовать SLAED CMS в действии?
Идеи и предложения
Обратная связь
Подтверждение

Поделиться
QR-код