#211: classification through feeds, public API, search and the no-JS shell
Some checks failed
CI / Lint, typecheck, test (pull_request) Successful in 6m38s
CI / Build container images (pull_request) Successful in 4m14s
CI / Auth e2e pack (pull_request) Successful in 9m7s
CI / Import/export fidelity gate (pull_request) Successful in 1m6s
CD / Deploy to Test (push) Blocked by required conditions
CD / Smoke tests against Test (push) Blocked by required conditions
CD / Promote to Int (push) Blocked by required conditions
CI / Auth e2e pack (push) Blocked by required conditions
CI / Import/export fidelity gate (push) Blocked by required conditions
CI / Build container images (push) Blocked by required conditions
CD / Build and push images (push) Has been cancelled
CI / Lint, typecheck, test (push) Has been cancelled
Some checks failed
CI / Lint, typecheck, test (pull_request) Successful in 6m38s
CI / Build container images (pull_request) Successful in 4m14s
CI / Auth e2e pack (pull_request) Successful in 9m7s
CI / Import/export fidelity gate (pull_request) Successful in 1m6s
CD / Deploy to Test (push) Blocked by required conditions
CD / Smoke tests against Test (push) Blocked by required conditions
CD / Promote to Int (push) Blocked by required conditions
CI / Auth e2e pack (push) Blocked by required conditions
CI / Import/export fidelity gate (push) Blocked by required conditions
CI / Build container images (push) Blocked by required conditions
CD / Build and push images (push) Has been cancelled
CI / Lint, typecheck, test (push) Has been cancelled
Feeds: classified entries carry a standard Atom <category> (term=level, scheme=urn:dorfteich:classification, label=the fixed wording); the feed document states the highest contained level once; all-open feeds carry none. Public API: page representations (list+get) gain the classification field, OpenAPI + public-api.md documented. Search: every hit carries the level and the palette renders the marking with the snippet (compact form of the banner, text token only). No-JS shell: banner above and below the content, own markup for the separate render path; unclassified pages unchanged everywhere. One test per channel (feed categories + count, public API list/get with the switch on, search hit levels, shell top+bottom). Also: fidelity CI sidecars get per-job container names — the fixed names collided across parallel runs on the shared host (run 547's red fidelity job; a fixed-name cleanup could even kill a sibling's live sidecars). Co-Authored-By: Claude Fable 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
68497046e9
commit
521ea514b4
@ -674,13 +674,16 @@ jobs:
|
|||||||
# image has no iproute2). Sharing the netns means no published ports.
|
# image has no iproute2). Sharing the netns means no published ports.
|
||||||
- name: Start pinned pandoc + Gotenberg sidecars
|
- name: Start pinned pandoc + Gotenberg sidecars
|
||||||
run: |
|
run: |
|
||||||
# Clear any leftovers from an earlier interrupted run so the named
|
# Sidecar names carry THIS job container's id: parallel runs on the
|
||||||
# containers never collide, and nothing leaks on the shared host.
|
# shared host must not collide on a fixed name (a fixed-name rm -f
|
||||||
docker rm -f fidelity-pandoc fidelity-gotenberg 2>/dev/null || true
|
# here even killed a sibling run's live sidecars — run 547).
|
||||||
JOB_ID=$(cat /etc/hostname)
|
JOB_ID=$(cat /etc/hostname)
|
||||||
docker run -d --name fidelity-pandoc \
|
echo "PANDOC_NAME=fidelity-pandoc-${JOB_ID}" >> "$GITHUB_ENV"
|
||||||
|
echo "GOTENBERG_NAME=fidelity-gotenberg-${JOB_ID}" >> "$GITHUB_ENV"
|
||||||
|
docker rm -f "fidelity-pandoc-${JOB_ID}" "fidelity-gotenberg-${JOB_ID}" 2>/dev/null || true
|
||||||
|
docker run -d --name "fidelity-pandoc-${JOB_ID}" \
|
||||||
--network "container:${JOB_ID}" pandoc/core:3.6 server
|
--network "container:${JOB_ID}" pandoc/core:3.6 server
|
||||||
docker run -d --name fidelity-gotenberg \
|
docker run -d --name "fidelity-gotenberg-${JOB_ID}" \
|
||||||
--network "container:${JOB_ID}" gotenberg/gotenberg:8
|
--network "container:${JOB_ID}" gotenberg/gotenberg:8
|
||||||
for i in $(seq 1 30); do
|
for i in $(seq 1 30); do
|
||||||
curl -sf http://localhost:3030/version >/dev/null && break
|
curl -sf http://localhost:3030/version >/dev/null && break
|
||||||
@ -704,15 +707,15 @@ jobs:
|
|||||||
- name: Dump sidecar logs on failure
|
- name: Dump sidecar logs on failure
|
||||||
if: failure()
|
if: failure()
|
||||||
run: |
|
run: |
|
||||||
echo '--- pandoc ---'; docker logs fidelity-pandoc 2>&1 | tail -30 || true
|
echo '--- pandoc ---'; docker logs "$PANDOC_NAME" 2>&1 | tail -30 || true
|
||||||
echo '--- gotenberg ---'; docker logs fidelity-gotenberg 2>&1 | tail -30 || true
|
echo '--- gotenberg ---'; docker logs "$GOTENBERG_NAME" 2>&1 | tail -30 || true
|
||||||
|
|
||||||
# Always tear the sidecars down — they run on the shared runner host, so a
|
# Always tear the sidecars down — they run on the shared runner host, so a
|
||||||
# leaked (especially Chromium-backed Gotenberg) container would waste its
|
# leaked (especially Chromium-backed Gotenberg) container would waste its
|
||||||
# memory until the next run and break re-runs on the container name.
|
# memory until the next run.
|
||||||
- name: Stop sidecars
|
- name: Stop sidecars
|
||||||
if: always()
|
if: always()
|
||||||
run: docker rm -f fidelity-pandoc fidelity-gotenberg 2>/dev/null || true
|
run: docker rm -f "$PANDOC_NAME" "$GOTENBERG_NAME" 2>/dev/null || true
|
||||||
|
|
||||||
images:
|
images:
|
||||||
name: Build container images
|
name: Build container images
|
||||||
|
|||||||
@ -101,6 +101,13 @@ export function buildOpenApiDocument(): object {
|
|||||||
properties: {
|
properties: {
|
||||||
slug: { type: 'string' },
|
slug: { type: 'string' },
|
||||||
title: { type: 'string' },
|
title: { type: 'string' },
|
||||||
|
classification: {
|
||||||
|
type: 'string',
|
||||||
|
enum: ['unclassified', 'vs_nfd'],
|
||||||
|
description:
|
||||||
|
'VS-NfD marking level (ADR 0022). A marking, not access control; ' +
|
||||||
|
'consumers re-publishing content are expected to carry it onward.',
|
||||||
|
},
|
||||||
parent: {
|
parent: {
|
||||||
type: ['string', 'null'],
|
type: ['string', 'null'],
|
||||||
description:
|
description:
|
||||||
@ -118,6 +125,14 @@ export function buildOpenApiDocument(): object {
|
|||||||
slug: { type: 'string' },
|
slug: { type: 'string' },
|
||||||
title: { type: 'string' },
|
title: { type: 'string' },
|
||||||
pondSlug: { type: 'string' },
|
pondSlug: { type: 'string' },
|
||||||
|
classification: {
|
||||||
|
type: 'string',
|
||||||
|
enum: ['unclassified', 'vs_nfd'],
|
||||||
|
description:
|
||||||
|
'VS-NfD marking level (ADR 0022). A marking, not access control; ' +
|
||||||
|
'consumers re-publishing content are expected to carry it onward.',
|
||||||
|
},
|
||||||
|
|
||||||
parent: {
|
parent: {
|
||||||
type: ['string', 'null'],
|
type: ['string', 'null'],
|
||||||
description: 'Parent page slug; see PageListItem.parent.',
|
description: 'Parent page slug; see PageListItem.parent.',
|
||||||
|
|||||||
@ -327,6 +327,35 @@ describe.skipIf(!hasTestDb)('public api v1 (e2e, issue #104)', () => {
|
|||||||
.expect(404);
|
.expect(404);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it('includes the classification in page representations (issue #211)', async () => {
|
||||||
|
const created = await pub()
|
||||||
|
.post(`/api/public/v1/ponds/${pondSlug}/pages`)
|
||||||
|
.set('Authorization', bearer('editor'))
|
||||||
|
.send({ title: `Classified Api Page ${suffix}`, markdown: 'classified body' })
|
||||||
|
.expect(201);
|
||||||
|
const slug = (created.body as { slug: string }).slug;
|
||||||
|
expect((created.body as { classification: string }).classification).toBe('unclassified');
|
||||||
|
await prisma.page.updateMany({
|
||||||
|
where: { slug, pond: { slug: pondSlug } },
|
||||||
|
data: { classification: 'VS_NFD' },
|
||||||
|
});
|
||||||
|
|
||||||
|
const fetched = await pub()
|
||||||
|
.get(`/api/public/v1/ponds/${pondSlug}/pages/${slug}`)
|
||||||
|
.set('Authorization', bearer('editor'))
|
||||||
|
.expect(200);
|
||||||
|
expect((fetched.body as { classification: string }).classification).toBe('vs_nfd');
|
||||||
|
|
||||||
|
const list = await pub()
|
||||||
|
.get(`/api/public/v1/ponds/${pondSlug}/pages`)
|
||||||
|
.set('Authorization', bearer('editor'))
|
||||||
|
.expect(200);
|
||||||
|
const listed = (list.body as { slug: string; classification: string }[]).find(
|
||||||
|
(p) => p.slug === slug,
|
||||||
|
);
|
||||||
|
expect(listed?.classification).toBe('vs_nfd');
|
||||||
|
});
|
||||||
|
|
||||||
it('round-trips a page through Markdown, replaces content via the collab path', async () => {
|
it('round-trips a page through Markdown, replaces content via the collab path', async () => {
|
||||||
const markdown = '# Heading\n\nHello **world** from the API.\n';
|
const markdown = '# Heading\n\nHello **world** from the API.\n';
|
||||||
const created = await pub()
|
const created = await pub()
|
||||||
|
|||||||
@ -7,6 +7,7 @@ import {
|
|||||||
pondFeatureEnabled,
|
pondFeatureEnabled,
|
||||||
pondSettingsSchema,
|
pondSettingsSchema,
|
||||||
type CommentListFilter,
|
type CommentListFilter,
|
||||||
|
type PageClassification,
|
||||||
type PageListQuery,
|
type PageListQuery,
|
||||||
type CreateCommentInput,
|
type CreateCommentInput,
|
||||||
type CreateLabelInput,
|
type CreateLabelInput,
|
||||||
@ -110,6 +111,7 @@ export class PublicApiService {
|
|||||||
return items.map((item) => ({
|
return items.map((item) => ({
|
||||||
slug: item.slug,
|
slug: item.slug,
|
||||||
title: item.title,
|
title: item.title,
|
||||||
|
classification: item.classification,
|
||||||
parent: (item.parentId && slugById.get(item.parentId)) || null,
|
parent: (item.parentId && slugById.get(item.parentId)) || null,
|
||||||
labels: item.labelIds.map((id) => labelNames.get(id) ?? id).sort(),
|
labels: item.labelIds.map((id) => labelNames.get(id) ?? id).sort(),
|
||||||
createdAt: item.createdAt,
|
createdAt: item.createdAt,
|
||||||
@ -129,6 +131,9 @@ export class PublicApiService {
|
|||||||
slug: page.slug,
|
slug: page.slug,
|
||||||
title: page.title,
|
title: page.title,
|
||||||
pondSlug,
|
pondSlug,
|
||||||
|
// VS-NfD level (#211): part of the versioned representation so API
|
||||||
|
// consumers can carry the marking onward.
|
||||||
|
classification: page.classification.toLowerCase() as PageClassification,
|
||||||
parent,
|
parent,
|
||||||
markdown: cache?.markdown ?? '',
|
markdown: cache?.markdown ?? '',
|
||||||
html: cache?.html ?? '',
|
html: cache?.html ?? '',
|
||||||
|
|||||||
@ -145,6 +145,40 @@ describe.skipIf(!hasTestDb)('atom feeds (e2e, issue #149)', () => {
|
|||||||
expect(res.text).toContain(`/api/v1/public/${pondSlug}/newer-${suffix}`);
|
expect(res.text).toContain(`/api/v1/public/${pondSlug}/newer-${suffix}`);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it('marks classified entries and states the highest level at feed level (issue #211)', async () => {
|
||||||
|
// Unclassified feed: no category element at all (ADR 0022 — no noise).
|
||||||
|
const open = await api().get(`/api/v1/public/${pondSlug}/feed.xml`).expect(200);
|
||||||
|
expect(open.text).not.toContain('urn:dorfteich:classification');
|
||||||
|
|
||||||
|
await prisma.page.updateMany({
|
||||||
|
where: { pondId, slug: `newer-${suffix}` },
|
||||||
|
data: { classification: 'VS_NFD' },
|
||||||
|
});
|
||||||
|
try {
|
||||||
|
const res = await api().get(`/api/v1/public/${pondSlug}/feed.xml`).expect(200);
|
||||||
|
// The classified entry carries the documented category element…
|
||||||
|
expect(res.text).toContain(
|
||||||
|
'<category term="vs_nfd" scheme="urn:dorfteich:classification" ' +
|
||||||
|
'label="VS – NUR FÜR DEN DIENSTGEBRAUCH"/>',
|
||||||
|
);
|
||||||
|
// …and the feed document states the highest contained level once:
|
||||||
|
// 1 feed-level + 1 entry-level = exactly two categories (the open
|
||||||
|
// entry carries none).
|
||||||
|
expect(res.text.split('urn:dorfteich:classification').length - 1).toBe(2);
|
||||||
|
|
||||||
|
// The page feed of a classified page marks its entries and itself too.
|
||||||
|
const pageFeed = await api()
|
||||||
|
.get(`/api/v1/public/${pondSlug}/newer-${suffix}/feed.xml`)
|
||||||
|
.expect(200);
|
||||||
|
expect(pageFeed.text).toContain('urn:dorfteich:classification');
|
||||||
|
} finally {
|
||||||
|
await prisma.page.updateMany({
|
||||||
|
where: { pondId, slug: `newer-${suffix}` },
|
||||||
|
data: { classification: 'UNCLASSIFIED' },
|
||||||
|
});
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
it('serves a page feed built from the version history', async () => {
|
it('serves a page feed built from the version history', async () => {
|
||||||
const res = await api().get(`/api/v1/public/${pondSlug}/newer-${suffix}/feed.xml`).expect(200);
|
const res = await api().get(`/api/v1/public/${pondSlug}/newer-${suffix}/feed.xml`).expect(200);
|
||||||
expect(res.text).toContain('<title>Newer Page — Feed Pond</title>');
|
expect(res.text).toContain('<title>Newer Page — Feed Pond</title>');
|
||||||
|
|||||||
@ -1,4 +1,9 @@
|
|||||||
import { Injectable, NotFoundException } from '@nestjs/common';
|
import { Injectable, NotFoundException } from '@nestjs/common';
|
||||||
|
import {
|
||||||
|
PageClassification,
|
||||||
|
classificationMarking,
|
||||||
|
highestClassification,
|
||||||
|
} from '@dorfteich/shared';
|
||||||
import { Pond, User } from '@prisma/client';
|
import { Pond, User } from '@prisma/client';
|
||||||
|
|
||||||
import { PagesService } from '../pages/pages.service';
|
import { PagesService } from '../pages/pages.service';
|
||||||
@ -10,12 +15,18 @@ import { escapeHtml } from './html-shell';
|
|||||||
/** How many entries a feed carries — plenty for readers polling regularly. */
|
/** How many entries a feed carries — plenty for readers polling regularly. */
|
||||||
const FEED_ENTRIES = 30;
|
const FEED_ENTRIES = 30;
|
||||||
|
|
||||||
|
/** The documented scheme URI of the classification `<category>` element
|
||||||
|
* (issue #211, ADR 0022; see docs/self-hosting/public-api.md §Feeds). */
|
||||||
|
const CLASSIFICATION_SCHEME = 'urn:dorfteich:classification';
|
||||||
|
|
||||||
interface FeedEntry {
|
interface FeedEntry {
|
||||||
id: string;
|
id: string;
|
||||||
title: string;
|
title: string;
|
||||||
link: string;
|
link: string;
|
||||||
updated: Date;
|
updated: Date;
|
||||||
summary?: string;
|
summary?: string;
|
||||||
|
/** VS-NfD level (#211) — rendered as an Atom `<category>` when classified. */
|
||||||
|
classification?: PageClassification;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@ -60,6 +71,7 @@ export class FeedService {
|
|||||||
? `${baseUrl}/api/v1/public/${pond.slug}/${page.slug}`
|
? `${baseUrl}/api/v1/public/${pond.slug}/${page.slug}`
|
||||||
: `${baseUrl}/p/${pond.slug}/${page.slug}`,
|
: `${baseUrl}/p/${pond.slug}/${page.slug}`,
|
||||||
updated: new Date(page.updatedAt),
|
updated: new Date(page.updatedAt),
|
||||||
|
classification: page.classification,
|
||||||
}));
|
}));
|
||||||
return atomDocument({
|
return atomDocument({
|
||||||
id: `${baseUrl}/api/v1/public/${pond.slug}/feed.xml`,
|
id: `${baseUrl}/api/v1/public/${pond.slug}/feed.xml`,
|
||||||
@ -79,7 +91,7 @@ export class FeedService {
|
|||||||
const pond = await this.requireVisiblePond(user, pondSlug);
|
const pond = await this.requireVisiblePond(user, pondSlug);
|
||||||
const page = await this.prisma.page.findFirst({
|
const page = await this.prisma.page.findFirst({
|
||||||
where: { pondId: pond.id, slug: pageSlug, deletedAt: null },
|
where: { pondId: pond.id, slug: pageSlug, deletedAt: null },
|
||||||
select: { id: true, pondId: true, slug: true, title: true },
|
select: { id: true, pondId: true, slug: true, title: true, classification: true },
|
||||||
});
|
});
|
||||||
if (!page || !(await this.permissions.canAccessPage(user, page, 'read'))) {
|
if (!page || !(await this.permissions.canAccessPage(user, page, 'read'))) {
|
||||||
throw new NotFoundException();
|
throw new NotFoundException();
|
||||||
@ -94,11 +106,13 @@ export class FeedService {
|
|||||||
user === null
|
user === null
|
||||||
? `${baseUrl}/api/v1/public/${pond.slug}/${page.slug}`
|
? `${baseUrl}/api/v1/public/${pond.slug}/${page.slug}`
|
||||||
: `${baseUrl}/p/${pond.slug}/${page.slug}`;
|
: `${baseUrl}/p/${pond.slug}/${page.slug}`;
|
||||||
|
const pageLevel = page.classification.toLowerCase() as PageClassification;
|
||||||
const entries = versions.map((version) => ({
|
const entries = versions.map((version) => ({
|
||||||
id: `urn:dorfteich:version:${version.id}`,
|
id: `urn:dorfteich:version:${version.id}`,
|
||||||
title: version.label ?? version.trigger.toLowerCase(),
|
title: version.label ?? version.trigger.toLowerCase(),
|
||||||
link,
|
link,
|
||||||
updated: version.createdAt,
|
updated: version.createdAt,
|
||||||
|
classification: pageLevel,
|
||||||
}));
|
}));
|
||||||
return atomDocument({
|
return atomDocument({
|
||||||
id: `${baseUrl}/api/v1/public/${pond.slug}/${page.slug}/feed.xml`,
|
id: `${baseUrl}/api/v1/public/${pond.slug}/${page.slug}/feed.xml`,
|
||||||
@ -118,6 +132,18 @@ export class FeedService {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/** The classification as a standard Atom `<category>` (issue #211): `term` =
|
||||||
|
* the machine-readable level, `label` = the fixed marking wording. Only
|
||||||
|
* classified content carries one (ADR 0022: unclassified shows no marking). */
|
||||||
|
function categoryTag(classification: PageClassification | undefined, indent: string): string {
|
||||||
|
const marking = classification ? classificationMarking(classification) : null;
|
||||||
|
if (!classification || !marking) return '';
|
||||||
|
return (
|
||||||
|
`${indent}<category term="${escapeHtml(classification)}" ` +
|
||||||
|
`scheme="${CLASSIFICATION_SCHEME}" label="${escapeHtml(marking)}"/>\n`
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
function atomDocument(feed: {
|
function atomDocument(feed: {
|
||||||
id: string;
|
id: string;
|
||||||
title: string;
|
title: string;
|
||||||
@ -125,6 +151,10 @@ function atomDocument(feed: {
|
|||||||
entries: FeedEntry[];
|
entries: FeedEntry[];
|
||||||
}): string {
|
}): string {
|
||||||
const updated = feed.entries[0]?.updated ?? new Date();
|
const updated = feed.entries[0]?.updated ?? new Date();
|
||||||
|
// The feed document states the highest level it contains (issue #211).
|
||||||
|
const highest = highestClassification(
|
||||||
|
feed.entries.map((entry) => entry.classification ?? 'unclassified'),
|
||||||
|
);
|
||||||
const entries = feed.entries
|
const entries = feed.entries
|
||||||
.map(
|
.map(
|
||||||
(entry) =>
|
(entry) =>
|
||||||
@ -133,6 +163,7 @@ function atomDocument(feed: {
|
|||||||
` <title>${escapeHtml(entry.title)}</title>\n` +
|
` <title>${escapeHtml(entry.title)}</title>\n` +
|
||||||
` <link href="${escapeHtml(entry.link)}"/>\n` +
|
` <link href="${escapeHtml(entry.link)}"/>\n` +
|
||||||
` <updated>${entry.updated.toISOString()}</updated>\n` +
|
` <updated>${entry.updated.toISOString()}</updated>\n` +
|
||||||
|
categoryTag(entry.classification, ' ') +
|
||||||
(entry.summary ? ` <summary>${escapeHtml(entry.summary)}</summary>\n` : '') +
|
(entry.summary ? ` <summary>${escapeHtml(entry.summary)}</summary>\n` : '') +
|
||||||
` </entry>`,
|
` </entry>`,
|
||||||
)
|
)
|
||||||
@ -143,6 +174,7 @@ function atomDocument(feed: {
|
|||||||
` <id>${escapeHtml(feed.id)}</id>\n` +
|
` <id>${escapeHtml(feed.id)}</id>\n` +
|
||||||
` <title>${escapeHtml(feed.title)}</title>\n` +
|
` <title>${escapeHtml(feed.title)}</title>\n` +
|
||||||
` <link rel="self" href="${escapeHtml(feed.selfLink)}"/>\n` +
|
` <link rel="self" href="${escapeHtml(feed.selfLink)}"/>\n` +
|
||||||
|
categoryTag(highest === 'unclassified' ? undefined : highest, ' ') +
|
||||||
` <updated>${updated.toISOString()}</updated>\n` +
|
` <updated>${updated.toISOString()}</updated>\n` +
|
||||||
`${entries}\n` +
|
`${entries}\n` +
|
||||||
`</feed>\n`
|
`</feed>\n`
|
||||||
|
|||||||
@ -42,6 +42,12 @@ export function htmlDocument({
|
|||||||
font-family: system-ui, -apple-system, "Segoe UI", Roboto, sans-serif; line-height: 1.6; }
|
font-family: system-ui, -apple-system, "Segoe UI", Roboto, sans-serif; line-height: 1.6; }
|
||||||
img { max-width: 100%; height: auto; }
|
img { max-width: 100%; height: auto; }
|
||||||
.public-page__pond { color: #64748b; font-size: 0.9rem; }
|
.public-page__pond { color: #64748b; font-size: 0.9rem; }
|
||||||
|
/* VS-NfD marking (issue #211, ADR 0022): same convention as the SPA —
|
||||||
|
bold, centered, ruled band above and below the content. currentColor
|
||||||
|
keeps full contrast in both color schemes. */
|
||||||
|
.classification-banner { margin: 0.75rem 0; padding: 0.25rem 0.5rem;
|
||||||
|
border-top: 2px solid currentColor; border-bottom: 2px solid currentColor;
|
||||||
|
font-weight: 700; letter-spacing: 0.08em; text-align: center; font-size: 0.9rem; }
|
||||||
pre { overflow-x: auto; }
|
pre { overflow-x: auto; }
|
||||||
.public-footer { margin-top: 3rem; padding-top: 1rem; border-top: 1px solid #64748b;
|
.public-footer { margin-top: 3rem; padding-top: 1rem; border-top: 1px solid #64748b;
|
||||||
font-size: 0.9rem; }
|
font-size: 0.9rem; }
|
||||||
|
|||||||
@ -109,6 +109,34 @@ describe.skipIf(!hasTestDb)('public read access (e2e, issue #56)', () => {
|
|||||||
expect((json.body as { html: string }).html).toContain('Hello world');
|
expect((json.body as { html: string }).html).toContain('Hello world');
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it('renders the VS-NfD marking top and bottom in the no-JS shell (issue #211)', async () => {
|
||||||
|
const marking = 'VS – NUR FÜR DEN DIENSTGEBRAUCH';
|
||||||
|
// Unclassified: the shell carries no marking at all.
|
||||||
|
const open = await api().get(`/api/v1/public/${pondSlug}/${pageSlug}`).expect(200);
|
||||||
|
expect(open.text).not.toContain(marking);
|
||||||
|
|
||||||
|
await prisma.page.updateMany({
|
||||||
|
where: { pondId, slug: pageSlug },
|
||||||
|
data: { classification: 'VS_NFD' },
|
||||||
|
});
|
||||||
|
try {
|
||||||
|
const html = await api().get(`/api/v1/public/${pondSlug}/${pageSlug}`).expect(200);
|
||||||
|
// Above AND below the content — the shell is its own render path.
|
||||||
|
expect(html.text.split(`<p class="classification-banner">${marking}</p>`).length - 1).toBe(2);
|
||||||
|
const [before, after] = html.text.split('Hello world from a public page.');
|
||||||
|
expect(before).toContain(marking);
|
||||||
|
expect(after).toContain(marking);
|
||||||
|
// The JSON the SPA renders carries the level too (#206).
|
||||||
|
const json = await api().get(`/api/v1/public/${pondSlug}/${pageSlug}/content`).expect(200);
|
||||||
|
expect((json.body as { classification: string }).classification).toBe('vs_nfd');
|
||||||
|
} finally {
|
||||||
|
await prisma.page.updateMany({
|
||||||
|
where: { pondId, slug: pageSlug },
|
||||||
|
data: { classification: 'UNCLASSIFIED' },
|
||||||
|
});
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
it('never resolves a non-public page for an anonymous visitor', async () => {
|
it('never resolves a non-public page for an anonymous visitor', async () => {
|
||||||
await api().get(`/api/v1/public/${privatePondSlug}/${privatePageSlug}`).expect(404);
|
await api().get(`/api/v1/public/${privatePondSlug}/${privatePageSlug}`).expect(404);
|
||||||
await api().get(`/api/v1/public/${privatePondSlug}/${privatePageSlug}/content`).expect(404);
|
await api().get(`/api/v1/public/${privatePondSlug}/${privatePageSlug}/content`).expect(404);
|
||||||
|
|||||||
@ -1,4 +1,5 @@
|
|||||||
import { Injectable, NotFoundException } from '@nestjs/common';
|
import { Injectable, NotFoundException } from '@nestjs/common';
|
||||||
|
import { classificationMarking } from '@dorfteich/shared';
|
||||||
import type { PageClassification, PageCommentsView } from '@dorfteich/shared';
|
import type { PageClassification, PageCommentsView } from '@dorfteich/shared';
|
||||||
import { Page, Pond, User } from '@prisma/client';
|
import { Page, Pond, User } from '@prisma/client';
|
||||||
|
|
||||||
@ -194,6 +195,12 @@ export class PublicService {
|
|||||||
canonical: string,
|
canonical: string,
|
||||||
): Promise<string> {
|
): Promise<string> {
|
||||||
const content = await this.content(user, pondSlug, pageSlug);
|
const content = await this.content(user, pondSlug, pageSlug);
|
||||||
|
// The VS-NfD marking renders in the same places as the SPA — above and
|
||||||
|
// below the content (issue #211, ADR 0022). The no-JS shell is its own
|
||||||
|
// render path, so it carries its own banner markup; unclassified pages
|
||||||
|
// get none.
|
||||||
|
const marking = classificationMarking(content.classification);
|
||||||
|
const banner = marking ? `<p class="classification-banner">${escapeHtml(marking)}</p>\n` : '';
|
||||||
// No session-dependent content: this document is identical for every viewer
|
// No session-dependent content: this document is identical for every viewer
|
||||||
// who may read the page (crawler-safe, cacheable). The shared shell adds
|
// who may read the page (crawler-safe, cacheable). The shared shell adds
|
||||||
// the legal footer links (issue #82) in the instance default locale.
|
// the legal footer links (issue #82) in the instance default locale.
|
||||||
@ -206,9 +213,10 @@ export class PublicService {
|
|||||||
`/api/v1/public/${encodeURIComponent(pondSlug)}/feed.xml`,
|
`/api/v1/public/${encodeURIComponent(pondSlug)}/feed.xml`,
|
||||||
canonical,
|
canonical,
|
||||||
).toString(),
|
).toString(),
|
||||||
bodyHtml: `<p class="public-page__pond">${escapeHtml(content.pondName)}</p>
|
bodyHtml: `${banner}<p class="public-page__pond">${escapeHtml(content.pondName)}</p>
|
||||||
<h1>${escapeHtml(content.title)}</h1>
|
<h1>${escapeHtml(content.title)}</h1>
|
||||||
${content.html}`,
|
${content.html}
|
||||||
|
${banner}`,
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@ -1,5 +1,6 @@
|
|||||||
import { Injectable } from '@nestjs/common';
|
import { Injectable } from '@nestjs/common';
|
||||||
import {
|
import {
|
||||||
|
PageClassification,
|
||||||
SEARCH_HIGHLIGHT_END,
|
SEARCH_HIGHLIGHT_END,
|
||||||
SEARCH_HIGHLIGHT_START,
|
SEARCH_HIGHLIGHT_START,
|
||||||
SEARCH_RESULT_LIMIT,
|
SEARCH_RESULT_LIMIT,
|
||||||
@ -34,6 +35,7 @@ interface SearchRow {
|
|||||||
pondName: string;
|
pondName: string;
|
||||||
labelIds: string[];
|
labelIds: string[];
|
||||||
snippet: string;
|
snippet: string;
|
||||||
|
classification: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@ -159,6 +161,7 @@ export class PostgresSearchProvider extends SearchProvider {
|
|||||||
|
|
||||||
const rows = await this.prisma.$queryRaw<SearchRow[]>(Prisma.sql`
|
const rows = await this.prisma.$queryRaw<SearchRow[]>(Prisma.sql`
|
||||||
SELECT p.id AS "pageId", p.title, p.slug, p.pond_id AS "pondId",
|
SELECT p.id AS "pageId", p.title, p.slug, p.pond_id AS "pondId",
|
||||||
|
p.classification::text AS classification,
|
||||||
po.slug AS "pondSlug", po.name AS "pondName",
|
po.slug AS "pondSlug", po.name AS "pondName",
|
||||||
COALESCE(
|
COALESCE(
|
||||||
ARRAY(SELECT pl.label_id FROM page_labels pl WHERE pl.page_id = p.id),
|
ARRAY(SELECT pl.label_id FROM page_labels pl WHERE pl.page_id = p.id),
|
||||||
@ -210,6 +213,8 @@ export class PostgresSearchProvider extends SearchProvider {
|
|||||||
pondName: row.pondName,
|
pondName: row.pondName,
|
||||||
labelIds: row.labelIds,
|
labelIds: row.labelIds,
|
||||||
snippet: row.snippet,
|
snippet: row.snippet,
|
||||||
|
// A hit on a classified page is never shown unmarked (#211).
|
||||||
|
classification: row.classification.toLowerCase() as PageClassification,
|
||||||
}));
|
}));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@ -23,6 +23,7 @@ describe('SearchProvider DI seam (issue #49)', () => {
|
|||||||
pondSlug: 'pond',
|
pondSlug: 'pond',
|
||||||
pondName: 'Pond',
|
pondName: 'Pond',
|
||||||
labelIds: [],
|
labelIds: [],
|
||||||
|
classification: 'unclassified',
|
||||||
snippet: 'a snippet',
|
snippet: 'a snippet',
|
||||||
};
|
};
|
||||||
const fake: SearchProvider = {
|
const fake: SearchProvider = {
|
||||||
|
|||||||
@ -90,6 +90,20 @@ describe.skipIf(!hasTestDb)('PostgresSearchProvider (db, issue #49)', () => {
|
|||||||
expect(results[0]!.pageId).toBe(titleHit);
|
expect(results[0]!.pageId).toBe(titleHit);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it('carries the classification with every hit — a classified snippet is never unmarked (issue #211)', async () => {
|
||||||
|
const classifiedId = await makePage(`classified ${term} note`, `secret ${term} content`);
|
||||||
|
await prisma.page.update({
|
||||||
|
where: { id: classifiedId },
|
||||||
|
data: { classification: 'VS_NFD' },
|
||||||
|
});
|
||||||
|
const results = await search.search({ q: term }, owner);
|
||||||
|
const classified = results.find((r) => r.pageId === classifiedId);
|
||||||
|
expect(classified?.classification).toBe('vs_nfd');
|
||||||
|
// Every other hit carries the field too, as `unclassified`.
|
||||||
|
const other = results.find((r) => r.pageId !== classifiedId);
|
||||||
|
expect(other?.classification).toBe('unclassified');
|
||||||
|
});
|
||||||
|
|
||||||
it('highlights the match in the snippet', async () => {
|
it('highlights the match in the snippet', async () => {
|
||||||
const results = await search.search({ q: term }, owner);
|
const results = await search.search({ q: term }, owner);
|
||||||
const bodyHit = results.find((r) => r.snippet.includes(SEARCH_HIGHLIGHT_START));
|
const bodyHit = results.find((r) => r.snippet.includes(SEARCH_HIGHLIGHT_START));
|
||||||
|
|||||||
@ -1,3 +1,4 @@
|
|||||||
|
import { classificationMarking } from '@dorfteich/shared';
|
||||||
import type { PondView, SearchResultView } from '@dorfteich/shared';
|
import type { PondView, SearchResultView } from '@dorfteich/shared';
|
||||||
import { useQuery } from '@tanstack/react-query';
|
import { useQuery } from '@tanstack/react-query';
|
||||||
import { useEffect, useMemo, useRef, useState } from 'react';
|
import { useEffect, useMemo, useRef, useState } from 'react';
|
||||||
@ -43,6 +44,7 @@ function saveRecent(query: string): string[] {
|
|||||||
*/
|
*/
|
||||||
export function SearchPalette({ onClose }: { onClose: () => void }): React.JSX.Element {
|
export function SearchPalette({ onClose }: { onClose: () => void }): React.JSX.Element {
|
||||||
const { t } = useTranslation('search');
|
const { t } = useTranslation('search');
|
||||||
|
const { t: tCommon } = useTranslation('common');
|
||||||
const navigate = useNavigate();
|
const navigate = useNavigate();
|
||||||
const { pondSlug } = useCurrentPondRoute();
|
const { pondSlug } = useCurrentPondRoute();
|
||||||
const inputRef = useRef<HTMLInputElement>(null);
|
const inputRef = useRef<HTMLInputElement>(null);
|
||||||
@ -220,6 +222,14 @@ export function SearchPalette({ onClose }: { onClose: () => void }): React.JSX.E
|
|||||||
onClick={() => open(hit)}
|
onClick={() => open(hit)}
|
||||||
>
|
>
|
||||||
<span className="search-result__title">{hit.title}</span>
|
<span className="search-result__title">{hit.title}</span>
|
||||||
|
{/* A hit on a classified page is never shown unmarked
|
||||||
|
(issue #211, ADR 0022) — fixed wording, not localized. */}
|
||||||
|
{classificationMarking(hit.classification) && (
|
||||||
|
<span className="search-result__classification">
|
||||||
|
<span className="visually-hidden">{tCommon('classification.label')}: </span>
|
||||||
|
{classificationMarking(hit.classification)}
|
||||||
|
</span>
|
||||||
|
)}
|
||||||
<span className="search-result__pond">{t('inPond', { pond: hit.pondName })}</span>
|
<span className="search-result__pond">{t('inPond', { pond: hit.pondName })}</span>
|
||||||
<LabelChips labelIds={hit.labelIds} byId={byId} />
|
<LabelChips labelIds={hit.labelIds} byId={byId} />
|
||||||
<span className="search-result__snippet">
|
<span className="search-result__snippet">
|
||||||
|
|||||||
@ -2809,6 +2809,16 @@ ul[data-type='task_list'] li p:last-of-type {
|
|||||||
font-size: 0.85rem;
|
font-size: 0.85rem;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* VS-NfD marking on a search hit (issue #211, ADR 0022): compact form of the
|
||||||
|
banner — text token only, full contrast in both themes. */
|
||||||
|
.search-result__classification {
|
||||||
|
display: block;
|
||||||
|
color: var(--color-text);
|
||||||
|
font-size: 0.75rem;
|
||||||
|
font-weight: 700;
|
||||||
|
letter-spacing: 0.08em;
|
||||||
|
}
|
||||||
|
|
||||||
.search-result__snippet {
|
.search-result__snippet {
|
||||||
display: block;
|
display: block;
|
||||||
margin-top: 2px;
|
margin-top: 2px;
|
||||||
|
|||||||
@ -52,6 +52,28 @@ curl -H "Authorization: Bearer dt_pat_..." \
|
|||||||
Deliberately not in v1 (stage 2): attachment upload, version endpoints,
|
Deliberately not in v1 (stage 2): attachment upload, version endpoints,
|
||||||
webhooks.
|
webhooks.
|
||||||
|
|
||||||
|
### Classification (VS-NfD marking, issue #211 / ADR 0022)
|
||||||
|
|
||||||
|
Every page representation (`GET …/pages`, `GET …/pages/{pageSlug}`)
|
||||||
|
carries a `classification` field: `"unclassified"` or `"vs_nfd"`. It is a
|
||||||
|
**marking, not access control** — permissions are unchanged by it. API
|
||||||
|
consumers that render or re-publish page content are expected to carry
|
||||||
|
the marking onward (the fixed wording is
|
||||||
|
`VS – NUR FÜR DEN DIENSTGEBRAUCH`).
|
||||||
|
|
||||||
|
The Atom feeds mark classified content with a standard `<category>`
|
||||||
|
element on both levels:
|
||||||
|
|
||||||
|
```xml
|
||||||
|
<category term="vs_nfd" scheme="urn:dorfteich:classification"
|
||||||
|
label="VS – NUR FÜR DEN DIENSTGEBRAUCH"/>
|
||||||
|
```
|
||||||
|
|
||||||
|
Each classified entry carries one, and the feed document itself carries
|
||||||
|
one stating the **highest** level it contains. Unclassified entries and
|
||||||
|
all-open feeds carry none (marking everything trains readers to ignore
|
||||||
|
markings, ADR 0022).
|
||||||
|
|
||||||
## Connect Claude Code / MCP clients
|
## Connect Claude Code / MCP clients
|
||||||
|
|
||||||
The instance ships its own MCP endpoint (Streamable HTTP) at `/api/mcp` —
|
The instance ships its own MCP endpoint (Streamable HTTP) at `/api/mcp` —
|
||||||
|
|||||||
@ -57,7 +57,7 @@ _Meilenstein: `M26 — VS-NfD: classification metadata`_
|
|||||||
- [x] PDF via gotenberg (`pdf-html.ts` Header/Footer-Template) · 1 AT · #208
|
- [x] PDF via gotenberg (`pdf-html.ts` Header/Footer-Template) · 1 AT · #208
|
||||||
- [x] DOCX/ODT via pandoc (Reference-Doc mit Kopf-/Fußzeile) · 2–3 AT · #209
|
- [x] DOCX/ODT via pandoc (Reference-Doc mit Kopf-/Fußzeile) · 2–3 AT · #209
|
||||||
- [x] Markdown-ZIP (Frontmatter + Aufdruck) · 1 AT · #210
|
- [x] Markdown-ZIP (Frontmatter + Aufdruck) · 1 AT · #210
|
||||||
- [ ] Atom-Feeds, Public-API, Suchergebnisse, No-JS-Shell · 2–3 AT · #211
|
- [x] Atom-Feeds, Public-API, Suchergebnisse, No-JS-Shell · 2–3 AT · #211
|
||||||
- [ ] Attachment-Download (Dateiname-Präfix + Begleitdatei) · 1–2 AT · #212
|
- [ ] Attachment-Download (Dateiname-Präfix + Begleitdatei) · 1–2 AT · #212
|
||||||
- [ ] Warnung/Sperre beim Anhängen an eingestufte Seiten · 1 AT · #213
|
- [ ] Warnung/Sperre beim Anhängen an eingestufte Seiten · 1 AT · #213
|
||||||
|
|
||||||
|
|||||||
@ -3,6 +3,7 @@ import { z } from 'zod';
|
|||||||
import type { ApiTokenScope } from './api-tokens';
|
import type { ApiTokenScope } from './api-tokens';
|
||||||
import type { CommentView } from './comments';
|
import type { CommentView } from './comments';
|
||||||
import type { LabelTreeNode, LabelView } from './labels';
|
import type { LabelTreeNode, LabelView } from './labels';
|
||||||
|
import type { PageClassification } from './pages';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Wire types of the public REST API (`/api/public/v1`, issue #104). The
|
* Wire types of the public REST API (`/api/public/v1`, issue #104). The
|
||||||
@ -29,6 +30,8 @@ export interface PublicPondView {
|
|||||||
export interface PublicPageListItemView {
|
export interface PublicPageListItemView {
|
||||||
slug: string;
|
slug: string;
|
||||||
title: string;
|
title: string;
|
||||||
|
/** VS-NfD level (issue #211, ADR 0022) — see `docs/self-hosting/public-api.md`. */
|
||||||
|
classification: PageClassification;
|
||||||
/** Parent page slug in the tree (issue #110), or null at the root — nulled
|
/** Parent page slug in the tree (issue #110), or null at the root — nulled
|
||||||
* as well when the token's user may not read the parent (no existence leak). */
|
* as well when the token's user may not read the parent (no existence leak). */
|
||||||
parent: string | null;
|
parent: string | null;
|
||||||
@ -41,6 +44,8 @@ export interface PublicPageView {
|
|||||||
slug: string;
|
slug: string;
|
||||||
title: string;
|
title: string;
|
||||||
pondSlug: string;
|
pondSlug: string;
|
||||||
|
/** VS-NfD level (issue #211, ADR 0022) — see `docs/self-hosting/public-api.md`. */
|
||||||
|
classification: PageClassification;
|
||||||
/** Parent page slug (issue #110); see {@link PublicPageListItemView.parent}. */
|
/** Parent page slug (issue #110); see {@link PublicPageListItemView.parent}. */
|
||||||
parent: string | null;
|
parent: string | null;
|
||||||
markdown: string;
|
markdown: string;
|
||||||
|
|||||||
@ -1,5 +1,7 @@
|
|||||||
import { z } from 'zod';
|
import { z } from 'zod';
|
||||||
|
|
||||||
|
import type { PageClassification } from './pages';
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Search schemas and views (issue #49/#50, ADR 0010). Full-text search runs on
|
* Search schemas and views (issue #49/#50, ADR 0010). Full-text search runs on
|
||||||
* PostgreSQL behind the `SearchProvider` interface. Diacritic-insensitive
|
* PostgreSQL behind the `SearchProvider` interface. Diacritic-insensitive
|
||||||
@ -49,4 +51,7 @@ export interface SearchResultView {
|
|||||||
labelIds: string[];
|
labelIds: string[];
|
||||||
/** Snippet with matches wrapped in the highlight sentinels above. */
|
/** Snippet with matches wrapped in the highlight sentinels above. */
|
||||||
snippet: string;
|
snippet: string;
|
||||||
|
/** VS-NfD level (issue #211, ADR 0022): a snippet of a classified page is
|
||||||
|
* never shown unmarked — the UI renders the marking with every hit. */
|
||||||
|
classification: PageClassification;
|
||||||
}
|
}
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user