Журнал изменений

Журнал изменений

Фильтр и поиск

Всего: 1173 Доступных коммитов | Отфильтровано: 1173 Коммиты | Страница: 69 из 118
07.04.2026
Feature: extend admin template fragments with new rendering attributes
Автор: Eduard Laas | Дата: 23:04 07.04.2026

Add optional rendering attributes to core admin fragments to support richer module UI without PHP-level HTML construction.

Core changes:

  1. alert.html:
  2. Add 'lines' array support: renders each line in a <div> inside the alert

    • Usable alongside or instead of 'text'
  3. input.html:
  4. Add 'is_config' flag: appends class="sl-select-config" when set
  5. textarea.html:
  6. Add 'is_config' flag: appends class="sl-select-config" when set
  7. Add 'is_required' flag: appends required attribute
  8. form.html:
  9. Guard 'rows' block with {% if rows %} to allow forms with no table rows
  10. Add 'content_html' slot: raw HTML rendered after rows (before submit)
  11. tabs.html:
  12. Add 'init_attr' slot: raw HTML attributes injected into root <div>

    • Used to pass data-sl-tabs-index from PHP
  13. tabs-link.html:
  14. Add 'link_attr' slot: raw HTML attributes injected into <a> tag

    • Used for data-sl-tab-info-link on info navigation links

Benefits:

  • Reduces ad-hoc HTML string construction in PHP modules
  • Enables tab index persistence and info-link URL sync via data attributes
Fix: auto-select last tab in setTplAdminInfoPage; remove hardcoded tab index
Автор: Eduard Laas | Дата: 23:04 07.04.2026

Previously admin info pages required callers to pass 'tab' explicitly to select the active tab (e.g. 'tab' => 3). This was brittle: adding or reordering tabs broke the highlight silently.

Core changes:

  1. Fix default tab selection (core/helpers.php):
  2. setTplAdminInfoPage: if 'tab' not provided, default to last tab index

    • Was: $tab = (int)($data['tab'] ?? 0) — always selected first tab
    • Now: auto-selects last tab ($tabs ? count($tabs) - 1 : 0)
  3. Remove hardcoded 'tab' from admin modules:
  4. admins.php: remove 'tab' => 2 from info()
  5. blocks.php: remove 'tab' => 5 from info(); expand inline call to multiline
  6. comments.php: remove 'tab' => 3 from info()
  7. content/admin/index.php: remove 'tab' => 3 and inline $ops variable

Benefits:

  • Info tab auto-highlights without manual index tracking
  • Immune to tab reordering: callers no longer need to count tabs

Technical notes:

  • 'tab' key still accepted if caller needs to override default
  • blocks.php inline expanded to multiline for readability only
Chore: remove block-error.js legacy JS error suppressor
Автор: Eduard Laas | Дата: 23:03 07.04.2026

block-error.js used window.onerror = () => true to silently suppress all JS errors globally — a pattern common in CMS code circa 2005-2012, now considered an antipattern that blocks error monitoring tools.

Core changes:

  1. Remove JS error suppressor (plugins/system/block-error.js):
  2. Delete block-error.js file entirely

    • SymError / window.onerror global suppression removed
  3. Clean up runtime injection (core/system.php):
  4. Remove conditional array_merge that injected block-error.js into script list
  5. Remove error_java setting (config/security.php, admin/modules/security.php):
  6. Drop error_java key from config defaults
  7. Remove config() field row and configsave() handler for error_java
  8. Remove hardcoded tab index from info()
  9. Remove _SEC_VIEW_JAVA lang constant (admin/lang/*.php):
  10. Deleted from all 6 language files (de, en, fr, pl, ru, uk)

Benefits:

  • Removes antipattern that silently hid JS errors in production
  • Allows error monitoring tools (Sentry etc.) to work correctly
  • Simplifies security config: one less setting to maintain

Technical notes:

  • No backward-compatibility concern: setting was opt-in, default was suppression-on
  • Admin UI no longer shows the JS error toggle
Refactor: migrate admins, blocks, categories, comments modules to new fragment API
Автор: Eduard Laas | Дата: 15:18 07.04.2026

Continues the systematic migration of admin modules to the canonical new/* fragment layer, replacing all legacy helper functions and old fragment names with the new unified API. Adds CSRF token protection to all state-changing operations and introduces new template fragments for comments and pagination.

Core changes:

  1. Admin module — admins (admin/modules/admins.php):
  2. Replace getTplAdminNavi() → getTplAdminTabs() throughout
  3. Migrate all form fields to new/input, new/checkbox, new/select, new/textarea
  4. Inline getAdminself() and getAdminmods() into call sites; remove dead functions
  5. Add checkSiteToken() guard to save() and delete()
  6. Switch delete() from POST aid to GET req with token validation
  7. Migrate table head to array format for new/table fragment
  8. Admin module — blocks (admin/modules/blocks.php):
  9. Replace all getTplAdminNavi() → getTplAdminTabs()
  10. Migrate all form rows to new/form with row array structure
  11. Add checkSiteToken() guard to addsave() and filecode()
  12. Validate bfile via regex before use; sanitize filenames in filecode()
  13. Fix block-file code extraction regex (cleaner preg_replace approach)
  14. Pass getSiteToken() into getAdminBlockList()
  15. Admin module — categories (admin/modules/categories.php):
  16. Same API migration pattern as admins/blocks
  17. Admin module — comments (admin/modules/comments.php):
  18. Same API migration pattern; new comment and bulk-action fragments
  19. System layer (core/system.php):
  20. Supporting changes for new fragment API helpers
  21. New template fragments:
  22. templates/admin/fragments/comment-bulk-actions.html
  23. templates/admin/fragments/comment.html
  24. templates/admin/fragments/new/label-item.html
  25. templates/admin/fragments/pagenum.html
  26. templates/admin/fragments/pager-link.html
  27. Updated fragments:
  28. admin-admins-delete-form.html — adapted to new API shape
  29. admin-admins-permission-cell.html — adapted to new API shape
  30. templates/admin/assets/css/new.css — style adjustments

Benefits:

  • CSRF protection on all mutating admin operations
  • Uniform new/* fragment API across all migrated modules
  • Input validation tightened (bfile, lang filters)

Technical notes:

  • getAdminself() and getAdminmods() removed; logic inlined at call sites
  • delete() now reads aid from req (GET) instead of POST
  • Backward compatibility with old fragment names dropped intentionally
06.04.2026
Chore: add helpers-old.php backup before consolidation
Автор: Eduard Laas | Дата: 23:01 06.04.2026

Backup of core/helpers.php prior to legacy function removal. Kept for reference during the migration wave.

Refactor: add new fragment layer and migrate content/security modules
Автор: Eduard Laas | Дата: 23:00 06.04.2026

Establishes the canonical new/* fragment base layer for the admin panel and migrates modules/content and admin/modules/security to the new API. Also consolidates core/helpers.php by removing legacy helper functions.

Core changes:

  1. New fragment base layer (templates/admin/fragments/new/):
  2. Added 30+ structural fragments: form, div-row, div, input, textarea, select, checkbox, radio, button, submit, hidden, label-hint, title-tip, alert, edit-tip, pager, pager-link, pager-dots, table, table-row, table-row-content, th, tabs, tabs-link, tabs-panel, module-head, user-search, row-actions, radio-group, div-collapse

  3. Added new.css with full sl-* class definitions for all new fragments
  4. Added box.html partial as canonical content box wrapper
  5. Content module (modules/content/admin/index.php):
  6. Migrated all functions to new fragment API
  7. Replaced setArticleNumbers() with getTplPager() helper
  8. rows passed as arrays, not string concatenation
  9. Prepared SQL with named placeholders throughout
  10. Security module (admin/modules/security.php):
  11. Further alignment with new fragment contracts
  12. Updated language constants across all 6 lang files
  13. Core consolidation (core/helpers.php, core/system.php):
  14. Removed legacy helper functions migrated to fragments
  15. Reduced helpers.php by ~1200 lines

Benefits:

  • Unified admin output through neutral structural fragment contracts
  • sl-* CSS naming convention enforced throughout new layer
  • Legacy sl_* calls replaced in migrated modules

Technical notes:

  • system.css pruned of styles now covered by new.css
  • tabs.js updated to data-* runtime contract
  • getTplPager() replaces setArticleNumbers() for admin pagination
03.04.2026
Refactor: migrate security module to canonical fragment API
Автор: Eduard Laas | Дата: 00:30 03.04.2026

Complete the admin fragment refactor for security.php: replace the monolithic admin-security-ban-user-form fragment and getTplAdminForm calls with typed sub-fragments (add-div-input, add-div-textarea, add-div-check, add-div-collapse, add-div-user-search, tabs-panels). Delete stale planning docs now superseded by .agents/ + .rules/.

Core changes:

  1. Ban form (admin/modules/security.php):
  2. Replace getTplAdminForm/getTplAdminFormRow with add-div fragment

    • IP/CIDR ban form migrated to typed row data arrays
    • User ban form replaces admin-security-ban-user-form monolith
    • mail/collapse row uses new add-div-collapse + add-div-check
  3. Fix getVar key: 'name' -> 'uname' in user ban lookup
  4. Replace admin-uploads-config-tabs with tabs-panels fragment
  5. New canonical fragments (templates/admin/fragments/):
  6. add-div-check.html, add-div-collapse.html, add-div-input.html
  7. add-div-submit.html, add-div-textarea.html, add-div-user-search.html
  8. tabs-panels.html, tabs-panels-item.html
  9. Removed legacy fragments:
  10. admin-conf-save.html, admin-security-ban-user-form.html, form-submit.html
  11. Docs cleanup:
  12. Delete ADMIN_PLAN.md, FRONTEND_PLAN.md, RAW_SLOTS_ADMIN.md
  13. Update TEMPLATES.md and TEMPLATE_STATUS.md to reflect new fragment set

Benefits:

  • All admin forms now use a uniform typed-row API
  • Monolithic per-form fragments replaced by composable sub-fragments
  • Stale planning docs removed; authoritative specs live in .agents/.rules/
02.04.2026
Refactor: migrate admin modules and content module to new fragment API
Автор: Eduard Laas | Дата: 17:41 02.04.2026

Update security.php, database.php, and modules/content/admin/index.php to use the canonical input/label-hint/table/edit-tip fragments and add CSRF token verification to all mutating operations in the security module.

Core changes:

  1. Security module CSRF hardening (admin/modules/security.php):
  2. bansave(), passsave(), configsave(), delete(): add checkSiteToken() guard at function entry; render _TOKENMISS alert and return early on failure

  3. All delete action URLs now include &token=getSiteToken() query parameter
  4. banlist() ban-add form: hidden token field added via getTplHiddenInput()
  5. passwd() form: hidden token field added
  6. config() configsave form: hidden array now passed to config-div.html loop
  7. Fragment migration (admin/modules/security.php):
  8. getTplAdminHintLabel() → $tpl->getHtmlFrag('label-hint', [...]) for IP/CIDR, admin file, and dump-skip labels

  9. getTplTextInput() → $tpl->getHtmlFrag('input', [...]) for blocker_cookie and afile text inputs

  10. Database module (admin/modules/database.php):
  11. getHtmlFrag('admin-input', [...]) → getHtmlFrag('input', [...]) for both submit buttons in dump()

  12. Content module (modules/content/admin/index.php):
  13. content(): list view migrated from getTplAdminTableHead/getTplAdminTableRow to $tpl->getHtmlFrag('table', [...]) with head array of column descriptors

  14. Row rendering migrated to getHtmlFrag('table-row') + getHtmlFrag('table-row-content')
  15. Action menu migrated to getHtmlFrag('edit-tip', [...]) with CSRF token on delete URL
  16. Title cell migrated to getHtmlFrag('title-tip', ['items' => [...]]) + cutstr()
  17. add(): form rows converted to array-based descriptor format; input/label-hint fragments used for title and RSS URL fields; getTplRefreshTimeSelect() for refresh select; getTplAddDateTime() for date picker; fields_in() replaced by getTplAddFieldRows(); body preview replaced by getTplPreviewContent()

  18. Field input normalised: getVar('post', 'field[]', 'raw') + filterFields()

Benefits:

  • CSRF coverage extended to all mutating security module operations
  • Consistent fragment usage eliminates module-specific HTML builders
  • content/add form now uses the same add-div layout as other modules

Technical notes:

  • checkSiteToken() added to bansave (ids 1/2/3), passsave, configsave, delete
  • config-div.html hidden loop expects array of ['nameattr', 'valueattr'] maps
  • field[] input now read as raw array and normalised via filterFields()
Refactor: migrate ad_save(), preview(), and cutstr() to new helper API
Автор: Eduard Laas | Дата: 17:40 02.04.2026

Update three core utility functions in core/system.php to delegate to the canonical helper functions introduced in helpers.php, removing inline HTML construction and aligning with the array-based template API.

Core changes:

  1. ad_save() (core/system.php):
  2. Replaced inline <select>/<input> HTML with getTplSaveAction()
  3. Passes name, valu, op, noprev as array; logic for preview/delete options is now in getTplSaveAction() and save-action-item.html

  4. preview() (core/system.php):
  5. Replaced manual filterMarkdown + getHtmlPart('preview') call with getTplPreviewContent()
  6. Renamed $textc parameter to $field to match the field-string convention used by getTplPreviewContent() and getTplViewFieldRows()

  7. Returns empty string when all inputs are blank (handled by getTplPreviewContent)
  8. cutstr() (core/system.php):
  9. Replaced if/elseif/elseif chain for $end selection with match expression

Benefits:

  • ad_save() and preview() are now pure data-passthrough wrappers
  • Eliminates duplicate HTML logic between system.php and the new helpers
  • cutstr() match expression is more idiomatic PHP 8+

Technical notes:

  • preview() signature change: $textc → $field; all call sites already pass field strings
  • No behaviour change for any of the three functions
Refactor: add shared template helper functions to core/helpers.php
Автор: Eduard Laas | Дата: 17:40 02.04.2026

Introduce six reusable helper functions that build admin and frontend HTML from prepared data structures and canonical fragments, replacing inline HTML construction scattered across modules.

Core changes:

  1. getTplAddFieldRows() (core/helpers.php):
  2. Parses module field definitions from $conf['fields'][$mod]
  3. Returns array of ['label_html', 'field_html'] rows for add-div layout
  4. Dispatches to add-field fragment for text(1), textarea(2), select(3)
  5. Delegates to getTplAddDateTime() for date(5) and datetime(4) types
  6. getTplAddDateTime() (core/helpers.php):
  7. Renders a date/datetime-local picker paired with a hidden canonical value field
  8. Uses static counter for unique IDs across multiple instances on one page
  9. Returns add-datetime fragment HTML
  10. getTplRefreshTimeSelect() (core/helpers.php):
  11. Renders a fixed-interval <select> (15m/30m/1h/5h/10h/24h)
  12. Uses refresh-select-time fragment; defaults to 3600 when value is empty/zero
  13. getTplViewFieldRows() (core/helpers.php):
  14. Renders read-only labelled rows from field string + module field definitions
  15. Applies filterMarkdown+filterReplaceText for textarea(2) type fields
  16. Returns view-field fragment HTML per visible field
  17. getTplPreviewContent() (core/helpers.php):
  18. Assembles full preview block: title, body_a, body_b, field rows
  19. Uses getHtmlPart('preview-content') for page-level layout
  20. Returns empty string when all inputs are blank
  21. getTplSaveAction() (core/helpers.php):
  22. Renders save/delete/preview <select> + hidden op + submit button
  23. Accepts name, valu, op, noprev keys; conditionally includes delete/preview options
  24. Uses save-action + save-action-item fragments

Benefits:

  • Centralises HTML assembly logic; modules only supply data arrays
  • Eliminates repeated inline HTML for date pickers, field loops, and save controls
  • Consistent escaping and fragment usage across all call sites

Technical notes:

  • getTplAddFieldRows() uses filterFields() to normalise array field input
  • getTplAddDateTime() relies on add-datetime fragment with hidden_id/picker_id pair
  • getTplSaveAction() replaces the ad_save() inline HTML builder in core/system.php

Страница 69 из 118. Всего: 1173

1 64 65 66 67 68 69 70 71 72 73 118
Хотите опробовать SLAED CMS в действии?
Идеи и предложения
Обратная связь
Подтверждение

Поделиться
QR-код

Предварительный просмотр