fen
5dba356264
Merge pull request 'Settings spacing between sections ( #161 )' ( #165 ) from fix-161 into dev
CI / test (push) Successful in 31s
CI / docker (push) Successful in 39s
2026-09-10 15:10:37 +00:00
fen
4683b8b542
new paste tab: rework number box submenus ( #157 )
...
CI / test (push) Successful in 31s
CI / docker (push) Successful in 37s
Fixes #157
2026-09-10 14:45:50 +00:00
fen
16cad8796f
new paste tab: rework number box submenus ( #157 )
...
CI / test (pull_request) Successful in 32s
CI / docker (pull_request) Skipped
Give the custom expiry and readable N times submenus a shared boxed
container with proper padding, indent them under their parent option,
and style the number inputs and unit select with palette vars, the
existing radius scale, and the select chevron. No em dashes, no hard
coded colors in new rules.
2026-09-10 09:45:31 -05:00
fen
317ed2137a
Settings: more padding between sections ( #161 )
...
CI / test (pull_request) Successful in 37s
CI / docker (pull_request) Skipped
Add margin under the dark mode toggle and between section headings
(theme/editor) on /settings via CSS classes, no inline styles (CSP).
2026-09-10 09:41:45 -05:00
fen
93fea6ad1c
Merge pull request 'Fix #163 : /new Create button broken (stale iscan/createCan path)' ( #164 ) from fix-163 into dev
CI / test (push) Successful in 32s
CI / docker (push) Successful in 40s
2026-09-10 14:40:52 +00:00
fen
0787871f2b
Fix #163 : remove dead iscan/createCan path breaking /new Create
CI / test (pull_request) Successful in 31s
CI / docker (pull_request) Skipped
2026-09-10 09:33:49 -05:00
fen
85dcaea522
Merge pull request 'Fix #142 : long unbroken paste title caused double horizontal scrollbar at mobile width' ( #162 ) from fix-142 into dev
CI / test (push) Successful in 32s
CI / docker (push) Successful in 37s
2026-09-10 14:33:28 +00:00
fen
c4d55cb196
Fix #142 : break long unbroken paste titles instead of forcing horizontal scroll
...
CI / test (pull_request) Successful in 34s
CI / docker (pull_request) Skipped
Add word-break: normal; overflow-wrap: anywhere to .paste-title-bar h1 so
a >120-char unbroken title wraps inside the title card at mobile width
instead of producing an internal + page-level horizontal scrollbar.
2026-09-10 09:33:15 -05:00
fen
5a227e2feb
Merge pull request 'Fix #139 : drop unsafe-inline from script-src and style-src' ( #159 ) from fix-139 into dev
CI / test (push) Successful in 31s
CI / docker (push) Successful in 36s
2026-09-10 09:11:00 -05:00
fen
7a74ff3e74
Fix #139 : drop unsafe-inline from script-src and style-src ( #139 )
...
CI / test (pull_request) Successful in 30s
CI / docker (pull_request) Skipped
- Move all inline <script> blocks (layout head/theme, topbar dark toggle,
foot, paste, new, history, mine, settings, admin, unlock) to external
files under internal/web/static/. Page data reaches scripts via data-*
attributes (data-paste-id, data-default-dark) instead of template vars.
- Replace inline onclick handlers (copy, delete, stats toggle) with
addEventListener wiring.
- Convert inline style="" attributes to CSS utility classes; swatch
colors are now set via CSSOM/DOM APIs instead of innerHTML strings.
- script-src/style-src are now plain 'self'; img-src data: stays for the
SVG data-URI backgrounds. Verified with headless chromium: zero CSP
violations on all pages in dark and light presets, theme swatches,
admin lock, tables and paste view render correctly.
2026-09-10 09:08:17 -05:00
fen
fc07d8b9d7
Merge pull request 'Wrap: break long words, no horizontal scroll while wrap enabled' ( #155 ) from fix-152 into dev
CI / test (push) Successful in 30s
CI / docker (push) Successful in 36s
2026-09-10 13:51:27 +00:00
fen
b30d41b87d
Wrap ON breaks long tokens mid-word; no horizontal scroll while wrap enabled ( #152 )
...
CI / test (pull_request) Successful in 30s
CI / docker (pull_request) Skipped
- codebody/editor: overflow-wrap anywhere + word-break break-all + overflow-x hidden under html[data-wrap]
- code container and mobile .float also hidden overflow with wrap on
- topbar mobile: tighten gap/padding/nav link padding so nothing overflows at 375px
Fixes #152
2026-09-10 08:51:13 -05:00
fen
ca77250cce
Merge pull request 'Fix #138 : add Secure attribute to viewer cookie (vwr)' ( #154 ) from fix-138 into dev
CI / test (push) Successful in 30s
CI / docker (push) Successful in 35s
2026-09-10 13:43:21 +00:00
fen
521b6f8011
#138 : add Secure attribute to viewer cookie (vwr)
CI / test (pull_request) Successful in 29s
CI / docker (pull_request) Skipped
2026-09-10 08:42:12 -05:00
fen
fe75dfc746
Merge pull request 'Remove ?token= deletion-token path ( #143 )' ( #153 ) from fix-143 into dev
CI / test (push) Successful in 29s
CI / docker (push) Successful in 36s
2026-09-10 13:38:15 +00:00
fen
00aaafeb3c
#143 : set tok_<id> cookie in create handlers so the created banner can show the token (QA)
CI / test (pull_request) Successful in 29s
CI / docker (pull_request) Skipped
2026-09-10 08:37:07 -05:00
fen
d7b51f02b6
Remove ?token= deletion-token path ( #143 )
...
The deletion token was accepted via the ?token= query parameter on both
DELETE /api/pastes/{id} and /redeem, and round-tripped through the paste
URL after creation. URL-carried bearer secrets leak into reverse-proxy
access logs and browser history.
- API: deletion tokens are now accepted only via the Authorization header
(Bearer/Token/bare); query params are ignored on both endpoints
- Web create flow: token moves to the browser via a short-lived tok_<id>
HttpOnly cookie instead of the redirect URL; the paste view reads it
from the cookie, never from ?token=
- Web view: the delete button calls redeem() which takes the token from
sessionStorage and sends it as an Authorization header
- Tests: correct token in query must be rejected (403/400); header path
still deletes/redeems; extraction unit cases updated
Fixes #143
2026-09-10 08:37:07 -05:00
fen
b0a58d6ca5
Merge pull request 'Settings: dark toggle above theme list; midnight card light/dark rows swapped' ( #134 ) from fix-settings-order into dev
CI / test (push) Successful in 28s
CI / docker (push) Successful in 41s
2026-09-10 13:23:29 +00:00
fen
747eba7064
Settings: dark toggle above theme list; midnight card light row on top ( #132 )
CI / test (pull_request) Successful in 29s
CI / docker (pull_request) Skipped
2026-09-10 08:21:49 -05:00
fen
33ccfd373a
Merge pull request 'Fix invisible select chevron in all presets ( #136 )' ( #151 ) from fix-136-select-chevron into dev
CI / test (push) Successful in 28s
CI / docker (push) Successful in 39s
2026-09-10 04:31:27 +00:00
fen
72dbfb1b3c
Fix invisible select chevron in all presets ( #136 )
...
CI / test (pull_request) Successful in 28s
CI / docker (pull_request) Skipped
Two compounding causes:
- CSP img-src fell back to default-src (self), blocking the data: URI
chevron image on all served pages, so no select ever painted it.
- .editor-head select used the background shorthand, wiping the
background-image set by the later select rule.
Chevron stroke is now a per-preset --chevron token (light stroke for
dark presets, dark for light presets) instead of hardcoded #888 .
CSP gains img-src 'self' data: so the data-URI icons can load.
2026-09-09 23:25:15 -05:00
fen
d44e4d1587
Merge pull request 'Secrets via headers only: drop ?key= and ?password= query fallbacks ( #137 , #141 )' ( #150 ) from fix-137-141-drop-query-secrets into dev
CI / test (push) Successful in 27s
CI / docker (push) Successful in 38s
2026-09-10 04:23:27 +00:00
fen
d013f3965f
Require secrets via headers only: drop ?key= and ?password= query fallbacks ( #137 , #141 )
...
CI / test (pull_request) Successful in 28s
CI / docker (pull_request) Skipped
Query strings leak into Traefik access logs, browser history, and Referer
headers. Admin key is now accepted only via X-Admin-Key; paste and can
passwords only via X-Paste-Password (or the POST unlock form). Tests
updated; new negative cases assert 401 for the query paths.
2026-09-09 23:23:10 -05:00
fen
98222e762f
Merge pull request 'History: pagination survives search/sort, pager pinned to page bottom' ( #140 ) from fix-133-paging into dev
CI / test (push) Successful in 28s
CI / docker (push) Successful in 34s
2026-09-10 04:14:20 +00:00
fen
a95ee57000
Merge pull request 'Split new-paste editor header into title pill and settings pill ( #147 )' ( #149 ) from fix-147-header-split into dev
CI / test (push) Successful in 31s
CI / docker (push) Successful in 33s
2026-09-10 04:12:05 +00:00
fen
b096c2073c
Merge pull request 'Fix result box wrap: word boundaries, keep long-token breaking ( #135 )' ( #145 ) from fix-135-result-wrap into dev
CI / test (push) Successful in 27s
CI / docker (push) Successful in 41s
2026-09-10 04:09:13 +00:00
fen
4d50e644b9
Merge pull request 'Fix #146 : untitled paste ID fallback renders as plain text like titled pastes' ( #148 ) from fix-146-id-fallback-plain into dev
CI / test (push) Successful in 27s
CI / docker (push) Successful in 39s
2026-09-10 04:07:04 +00:00
fen
8abf821ce9
Merge pull request 'Admin lock page: replace explanatory paragraph with centered key input' ( #119 ) from fix-admin-lock-center into dev
CI / test (push) Successful in 27s
CI / docker (push) Successful in 32s
2026-09-10 04:01:45 +00:00
fen
7dc70d62f6
Fix #146 : render untitled paste ID fallback as plain text like titled pastes
...
CI / test (pull_request) Successful in 26s
CI / docker (pull_request) Skipped
The PASTE column fallback for untitled pastes used the .slug class, which
renders as a monospace chip with a background pill. Give it a dedicated
paste-name modifier that strips the chip styling (background, padding,
radius, mono font) so the fallback looks identical to a titled paste
(var(--fg) plain text). The dedicated ID column and URL column chips keep
their existing styling. Applied to both /history and /mine tables.
2026-09-09 22:56:53 -05:00
fen
fa2e9b1bb5
History: keep pagination over filtered/sorted set, pin pager to page bottom ( #133 )
CI / test (pull_request) Successful in 26s
CI / docker (pull_request) Skipped
2026-09-09 22:48:25 -05:00
fen
9f4ed91b8f
Fix result box wrap: word boundaries instead of break-all ( #135 )
CI / test (pull_request) Successful in 26s
CI / docker (pull_request) Skipped
2026-09-09 22:43:30 -05:00
fen
24482abccc
Merge pull request 'Line wrap toggle for editor and paste viewer ( #130 )' ( #131 ) from fix-130-line-wrap into dev
CI / test (push) Successful in 26s
CI / docker (push) Successful in 44s
2026-09-10 03:39:45 +00:00
fen
7cc6a9c706
Add line wrap toggle for editor and paste viewer ( #130 )
...
CI / test (pull_request) Successful in 27s
CI / docker (pull_request) Skipped
Shared client-side preference in localStorage 'palette-wrap', default
off. Toggle button on /new editor head and paste title bar, plus a Line
wrap checkbox in the settings menu; all read/write the same preference.
Active state uses the accent treatment like other toggles. No em dashes
in UI text.
2026-09-09 22:35:49 -05:00
fen
19cb8d1d45
Merge pull request 'Theme pairs with dark mode toggle, gear active state, PALETTE_DEFAULT_DARK' ( #128 ) from fix-theme-pairs-darkmode into dev
CI / test (push) Successful in 25s
CI / docker (push) Successful in 32s
2026-09-10 03:25:35 +00:00
fen
4948ef9f1c
#38 iteration 1: file attachments, 1 file per paste
...
CI / test (pull_request) Successful in 26s
CI / docker (pull_request) Skipped
- internal/store/blob.go: BlobStore interface + fs implementation with
traversal-safe keys (<paste-id>/<sha256>), put/get/stat/delete
- attachments table migration (id, paste_id, filename sanitized to 255,
mime sniffed server-side, size, sha256, created_at)
- POST /api/pastes now accepts multipart/form-data with a 'file' part;
1 file = 1 paste: file replaces text content when both are sent
- 25 MB per-file limit enforced server-side (413 file_too_large)
- GET /f/{attachment-id}/{filename}: stored sniffed mime, nosniff,
inline only for images/pdf, html/svg/xml forced to text/plain (#34 rule)
- paste view renders attachment chip + inline image preview
- /new: dropzone with file picker, drag-and-drop, Ctrl+V file paste,
file chip with name/size/remove, matches pill/radius design
- tests: blob roundtrip/traversal/sanitize; multipart create (mime
sniffing, client mime ignored, size limit, two-file reject, html/svg
forcing, 404s, password/expiry fields)
2026-09-09 22:21:15 -05:00
fen
7ed50087a6
Merge pull request 'UI polish: custom URL placeholder, styled buttons/selects, admin link spacing' ( #125 ) from fix-ui-polish into dev
CI / test (push) Successful in 22s
CI / docker (push) Successful in 35s
2026-09-10 02:49:36 +00:00
fen
8104cdba4c
Remove custom URL reservation note and Can contents menu from new paste page
...
CI / test (pull_request) Successful in 25s
CI / docker (pull_request) Skipped
Fixes #124
2026-09-09 21:47:50 -05:00
fen
be3ff81e5c
base
2026-09-09 21:45:42 -05:00
fen
2ce50a6393
Merge pull request 'Fix #120 : add matching light/dark variant for every theme' ( #121 ) from fix-theme-variants into dev
CI / test (push) Successful in 27s
CI / docker (push) Successful in 35s
2026-09-10 02:36:47 +00:00
fen
0ceeabc810
Merge dev: burn fix, version label, theme persistence, admin/settings UI, theme grid, CSP fix, docs
CI / test (push) Successful in 21s
CI / docker (push) Successful in 47s
2026-09-09 21:32:30 -05:00
fen
8dde83ff68
Admin lock: replace explanation paragraph with centered key input
CI / test (pull_request) Successful in 28s
CI / docker (pull_request) Skipped
2026-09-09 21:28:11 -05:00
fen
aca99bc6d4
Merge pull request 'Fix #116 : allow inline styles in CSP (style-src)' ( #117 ) from fix-116-csp-inline-styles into dev
CI / test (push) Successful in 22s
CI / docker (push) Successful in 36s
2026-09-10 02:20:53 +00:00
fen
073d39ccba
Fix #116 : allow inline styles in CSP (style-src 'self' 'unsafe-inline')
CI / test (pull_request) Successful in 24s
CI / docker (pull_request) Skipped
2026-09-09 21:18:53 -05:00
fen
9ec7d5152e
Merge pull request 'Fix #114 : theme grid empty (t.colors undefined)' ( #115 ) from fix-114-theme-grid-empty into dev
CI / test (push) Successful in 21s
CI / docker (push) Successful in 42s
2026-09-10 02:01:38 +00:00
fen
7a2fa00f4a
Merge pull request 'Fix admin lock-on-load, settings hint, theme swatches ( #112 )' ( #113 ) from fix-112-admin-settings-ui into dev
CI / test (push) Successful in 21s
CI / docker (push) Successful in 34s
2026-09-10 00:54:43 +00:00
fen
7fde147500
Merge pull request 'Fix theme persistence on reload' ( #109 ) from fix-100-theme-persist into dev
CI / test (push) Successful in 23s
CI / docker (push) Successful in 38s
2026-09-10 00:22:04 +00:00
fen
cf8674b898
Merge pull request 'Fix wiki docs accuracy ( #110 )' ( #111 ) from fix-110-docs-accuracy into dev
CI / test (push) Successful in 21s
CI / docker (push) Successful in 32s
2026-09-10 00:20:17 +00:00
fen
f6e81de2a3
Fix README: build path ./cmd/palette, Go 1.27+, design-doc wiki link ( #110 )
CI / test (pull_request) Successful in 21s
CI / docker (pull_request) Skipped
2026-09-09 19:15:44 -05:00
fen
e17ea4f8c2
Move docs to Gitea wiki; point README links at wiki
CI / test (push) Successful in 21s
CI / docker (push) Skipped
2026-09-09 18:52:41 -05:00
fen
5afe81f34c
README: AI-built disclaimer before feature list
CI / test (push) Successful in 21s
CI / docker (push) Skipped
2026-09-09 18:46:15 -05:00
fen
9d89995c91
Merge pull request 'store: burn_after_reads>0 implies burn-after-read ( #82 )' ( #107 ) from fix-82-burn-implies-budget into dev
CI / test (push) Successful in 24s
CI / docker (push) Successful in 37s
2026-09-09 23:40:22 +00:00
fen
805cc3ff2b
web: restore persisted theme on page load ( #100 )
CI / test (pull_request) Successful in 24s
CI / docker (pull_request) Skipped
2026-09-09 18:40:09 -05:00
fen
3d415edbdc
fix #84 : security headers dropped because they were set post-flush; set pre-handler
CI / test (pull_request) Successful in 21s
CI / docker (pull_request) Skipped
2026-09-09 10:54:16 -05:00