fen
f6e81de2a3
Fix README: build path ./cmd/palette, Go 1.27+, design-doc wiki link ( #110 )
CI / test (pull_request) Successful in 21s
CI / docker (pull_request) Skipped
2026-09-09 19:15:44 -05:00
fen
e17ea4f8c2
Move docs to Gitea wiki; point README links at wiki
CI / test (push) Successful in 21s
CI / docker (push) Skipped
2026-09-09 18:52:41 -05:00
fen
5afe81f34c
README: AI-built disclaimer before feature list
CI / test (push) Successful in 21s
CI / docker (push) Skipped
2026-09-09 18:46:15 -05:00
poslop
097ffb7971
Update README.md
CI / test (push) Successful in 21s
CI / docker (push) Skipped
2026-09-09 23:44:37 +00:00
poslop
815635a973
Update README.md
CI / test (push) Successful in 28s
CI / docker (push) Skipped
2026-09-09 23:42:06 +00:00
fen
df73d56e32
Merge remote-tracking branch 'origin/fix-93-version-label' into dev
CI / test (push) Successful in 28s
CI / docker (push) Successful in 49s
2026-09-09 18:41:26 -05:00
fen
9d89995c91
Merge pull request 'store: burn_after_reads>0 implies burn-after-read ( #82 )' ( #107 ) from fix-82-burn-implies-budget into dev
CI / test (push) Successful in 24s
CI / docker (push) Successful in 37s
2026-09-09 23:40:22 +00:00
fen
805cc3ff2b
web: restore persisted theme on page load ( #100 )
CI / test (pull_request) Successful in 24s
CI / docker (pull_request) Skipped
2026-09-09 18:40:09 -05:00
poslop
f37cc932c4
store: burn_after_reads>0 implies burn-after-read mode ( #82 )
CI / test (pull_request) Successful in 24s
CI / docker (pull_request) Skipped
2026-09-09 18:28:00 -05:00
agent
65ed0c7043
Show actual version in topbar instead of hardcoded beta ( Fixes #93 )
CI / test (pull_request) Successful in 26s
CI / docker (pull_request) Skipped
2026-09-09 18:27:57 -05:00
poslop
8ecf5338d5
CI: build dev image on dev branch pushes (palette-dev deploy)
CI / test (push) Successful in 25s
CI / docker (push) Successful in 42s
2026-09-09 18:22:31 -05:00
poslop
69da340224
Settings page: theme switcher with live preview ( #100 )
CI / test (push) Successful in 23s
CI / docker (push) Skipped
2026-09-09 18:21:45 -05:00
poslop
b1af398bea
Update README.md
CI / test (push) Successful in 20s
CI / docker (push) Skipped
2026-09-09 22:56:50 +00:00
poslop
15f199b2fe
README: trim to brief front page + retake themed screenshots ( #106 )
...
CI / test (push) Successful in 20s
CI / docker (push) Skipped
- Cut Admin walkthrough and API curl block to one-liners pointing at docs
- Keep Configuration table, features, Get Started, doc links
- Retake all screenshots against current UI, one theme each:
/new midnight, /history pastel-lavender, paste view pastel-peach,
/mine pastel-cloud; remove superseded stale previews
2026-09-09 17:30:54 -05:00
poslop
9df6224a27
Result box: color-code by status + friendly error messages from error codes ( #105 )
...
CI / test (push) Successful in 23s
CI / docker (push) Skipped
- Backend create/can validation paths emit machine-readable error codes
(slug_taken, slug_invalid, content_empty, content_too_large,
expiry_invalid, rate_limited, ...) alongside the human message
- new.html JS maps codes to plain-language guidance with generic fallback
- Result card colored via --ok/--err/--warn left border (result-ok/err/warn)
- docs/API.md error section documents the code field
- Tests assert the code on every validation path
2026-09-09 17:28:25 -05:00
poslop
c35531e03e
Settings page: small muted Admin link ( #102 )
CI / test (push) Successful in 22s
CI / docker (push) Skipped
2026-09-09 17:17:00 -05:00
poslop
be2b4fb47f
Sort arrows: left of label, further spaced, vertically centered, no label shift ( #101 )
...
Arrow is absolutely positioned at left:8px in the th, label padding-left
24px; translateY(-50%) keeps it centered regardless of row height, and
being out of flow the label never moves between sorted/unsorted states.
2026-09-09 17:17:00 -05:00
poslop
064f05536a
Admin page: validate key before persisting to sessionStorage ( #99 )
...
Panel was already display:none-gated until auth; tightened so a wrong
submitted key is never stored in sessionStorage — the typed key is
validated via the settings API first, and only persisted on 200.
2026-09-09 17:17:00 -05:00
poslop
4175ffef3e
CSS: inline sort arrow with uniform 8px gap ( #103 ), full-pill slug roundness ( #104 )
CI / test (push) Successful in 22s
CI / docker (push) Skipped
2026-09-09 17:10:24 -05:00
poslop
ea9edc211a
UI: consistent sort arrow gap, uniform pill roundness (slug -> radius-sm)
CI / test (push) Successful in 22s
CI / docker (push) Skipped
2026-09-09 16:50:06 -05:00
poslop
6d467312af
Merge minor fixes: #92-#98, #100 theme switcher + cans work
CI / test (push) Successful in 22s
CI / docker (push) Skipped
2026-09-09 16:40:53 -05:00
poslop
b21be29daa
minor fixes: version label ( #93 ), view dedupe tests ( #95 )
2026-09-09 16:40:53 -05:00
poslop
cd70dd0b0e
Merge origin/main (license, compose, #65 leak guard) into cans work
CI / test (push) Failing after 6s
CI / docker (push) Skipped
2026-09-09 16:39:14 -05:00
poslop
5b9be808ed
Merge origin/main: keep can listing rows with #65 password-metadata leak guard
2026-09-09 16:36:55 -05:00
poslop
19804d47a3
Cans UI + parity: unlock-cookie flow, /can page, listings badge, custom slug, delete, sweeper; #32 perf notes ( #4 , #32 )
2026-09-09 16:34:51 -05:00
poslop
ffc10c2b86
README: link to docker-compose example
CI / test (push) Successful in 19s
CI / docker (push) Skipped
2026-09-09 16:16:28 +00:00
poslop
bf5a79878f
add example docker-compose.yml documenting all env vars
CI / test (push) Successful in 19s
CI / docker (push) Skipped
2026-09-09 16:16:15 +00:00
poslop
60200ac14b
README: license section with as-is / no-liability disclaimer
CI / test (push) Successful in 19s
CI / docker (push) Skipped
2026-09-09 16:12:41 +00:00
poslop
49f7b6e7a4
add AGPLv3 license with copyright and warranty disclaimer notice
CI / test (push) Successful in 19s
CI / docker (push) Skipped
2026-09-09 16:12:19 +00:00
poslop
959a83be1e
Merge pull request 'Bound title and language at create time ( #86 )' ( #91 ) from fix-86-field-bounds into main
CI / test (push) Successful in 24s
CI / docker (push) Successful in 42s
v0.2.2
2026-09-09 15:59:32 +00:00
poslop
5b068faf8f
Merge pull request 'ratelimit: rightmost untrusted-hop-safe client IP ( fixes #85 )' ( #89 ) from fix-85-xff into main
CI / test (push) Successful in 27s
CI / docker (push) Skipped
2026-09-09 15:59:29 +00:00
poslop
b0360af79c
Merge pull request 'Fix #83 : create API ignores boolean public field' ( #88 ) from fix-83-public-false into main
CI / test (push) Successful in 26s
CI / docker (push) Skipped
2026-09-09 15:59:26 +00:00
poslop
806798fae6
Merge pull request 'Rate-limit all password verification attempts ( #81 )' ( #90 ) from fix-81-password-ratelimit into main
CI / test (push) Successful in 26s
CI / docker (push) Skipped
2026-09-09 15:59:24 +00:00
poslop
8977c05cda
Merge pull request 'fix #84 : security headers were silently dropped (set pre-handler)' ( #87 ) from fix-84-headers-prewrite into main
CI / test (push) Successful in 21s
CI / docker (push) Skipped
2026-09-09 15:59:21 +00:00
fen
389e4d333f
Bound title and language at create time ( #86 )
...
CI / test (pull_request) Successful in 21s
CI / docker (pull_request) Skipped
Titles are trimmed and truncated to 200 characters; language must be
blank or match ^[a-zA-Z0-9+#-]{1,40}$ (max 40 chars) or the create is
rejected with a clear 400. Regression tests cover truncation, malformed
and oversized language values, valid identifiers, and blank metadata.
2026-09-09 10:58:34 -05:00
fen
99a044e8a2
Rate-limit all password verification attempts ( #81 )
...
CI / test (pull_request) Successful in 22s
CI / docker (pull_request) Skipped
GET ?password= and X-Paste-Password header checks in handleGetPaste were
unlimited (pentest2: 8 wrong = 8x401, no 429). Gate every password
verification on the same per-IP+paste unlock limiter (5/min, 429 with
Retry-After) already used by the POST unlock form path.
Regression tests: repeated wrong passwords via GET ?password= and via
header must eventually 429; correct password within burst still 200.
Fixes #81
2026-09-09 10:58:21 -05:00
agent
3d1d5ee1fd
ratelimit: key on rightmost X-Forwarded-For entry ( fixes #85 )
CI / test (pull_request) Successful in 21s
CI / docker (pull_request) Skipped
2026-09-09 10:57:59 -05:00
Hermes Agent
ccb22a2d28
#83 : accept boolean public field in create API (false->unlisted, true->public)
CI / test (pull_request) Successful in 23s
CI / docker (pull_request) Skipped
2026-09-09 10:57:56 -05:00
fen
3d415edbdc
fix #84 : security headers dropped because they were set post-flush; set pre-handler
CI / test (pull_request) Successful in 21s
CI / docker (pull_request) Skipped
2026-09-09 10:54:16 -05:00
poslop
7ca1b58362
Merge pull request 'docs: attachments & storage backend design ( #38 , #31 )' ( #69 ) from issue-38-31-storage-design into main
CI / test (push) Successful in 19s
CI / docker (push) Successful in 34s
v0.2.1
2026-09-09 14:27:50 +00:00
poslop
8d0825ac09
Merge pull request 'docs: cookie-based preferences and access keys design ( #30 )' ( #70 ) from issue-30-cookie-design into main
CI / test (push) Successful in 19s
CI / docker (push) Skipped
2026-09-09 14:27:14 +00:00
poslop
4cb8a3e127
Merge pull request 'Search: loading indicator and performance note ( #32 )' ( #72 ) from issue-32-search-indicator into main
CI / test (push) Successful in 30s
CI / docker (push) Skipped
2026-09-09 14:26:25 +00:00
poslop
91dbf6f344
Merge pull request 'fix: input validation gaps ( #68 )' ( #78 ) from issue-68-input-validation into main
CI / test (push) Successful in 23s
CI / docker (push) Skipped
2026-09-09 14:26:19 +00:00
poslop
b600cdf51a
Merge pull request 'Admin key endpoint: per-IP rate limiting and lockout ( #66 )' ( #73 ) from issue-66-admin-ratelimit into main
CI / test (push) Successful in 24s
CI / docker (push) Skipped
2026-09-09 14:26:13 +00:00
poslop
47c9fa6386
Merge pull request 'Clamp expires_in at API boundary ( #60 )' ( #74 ) from issue-60-expiry-clamp into main
CI / test (push) Successful in 23s
CI / docker (push) Skipped
2026-09-09 14:26:07 +00:00
poslop
b7d1119d6d
Merge pull request 'docs: design for optional client-side E2E encryption (issue #39 )' ( #75 ) from issue-39-e2e-design into main
CI / test (push) Successful in 20s
CI / docker (push) Skipped
2026-09-09 14:26:02 +00:00
poslop
44fe3c5772
Merge pull request 'Security headers middleware: CSP, Referrer-Policy, nosniff ( #59 )' ( #76 ) from issue-59-security-headers into main
CI / test (push) Successful in 21s
CI / docker (push) Skipped
2026-09-09 14:26:01 +00:00
poslop
556d0fa2e1
Merge pull request 'fix #63 : require deletion token on DELETE /api/pastes/{id}' ( #79 ) from issue-63-delete-auth into main
CI / test (push) Successful in 18s
CI / docker (push) Skipped
2026-09-09 14:25:40 +00:00
poslop
bdd5235f2e
Merge pull request 'fix: atomic burn-after-read claim ( #58 )' ( #77 ) from issue-58-burn-race into main
CI / test (push) Successful in 18s
CI / docker (push) Skipped
2026-09-09 14:25:06 +00:00
poslop
91568c0598
fix #63 : require deletion token on DELETE /api/pastes/{id}
...
CI / test (pull_request) Successful in 24s
CI / docker (pull_request) Skipped
- DELETE now demands the create-time deletion token (Authorization
header: Bearer/Token/bare, or ?token= query param), compared with
the constant-time store.DeletionTokenEqual. 403 otherwise.
- Creator-browser deletes via the /mine button (matching vwr cookie,
#37 ) remain allowed; other browsers and plain API clients get 403.
- Regression tests: no token, wrong token (header+query), correct
token (header+query), creator-cookie path, token extraction.
- Adapted TestSoftDelete to pass the deletion token.
- docs/API.md delete section updated.
- Based on #58 's SoftDelete (bool, error) signature.
2026-09-09 09:21:28 -05:00