Commit Graph
157 Commits
Author SHA1 Message Date
kpcto 5ea4c2c2da Remove tests/mailto.test.js 2026-08-26 22:36:28 +00:00
kpcto def9940c5e Remove tests/contact.test.js 2026-08-26 22:36:23 +00:00
kpcto 2001d1c10d Remove reading.html 2026-08-26 22:36:18 +00:00
kpcto 05cb7af9b7 Remove package.json 2026-08-26 22:36:14 +00:00
kpcto 6407e7df34 Remove newsletter.html 2026-08-26 22:36:10 +00:00
kpcto d55eeca7d4 Remove js/reading-list.js 2026-08-26 22:36:06 +00:00
kpcto 7e290c5f04 Remove js/newsletter.js 2026-08-26 22:36:01 +00:00
kpcto 1e14fc106b Remove js/newsletter-config.js 2026-08-26 22:35:57 +00:00
kpcto c61d77e1b3 Remove js/mailto.js 2026-08-26 22:35:52 +00:00
kpcto 657c2e7d43 Remove js/contact.js 2026-08-26 22:35:48 +00:00
kpcto 3de742c8ed Remove index.html 2026-08-26 22:35:43 +00:00
kpcto 55af0d92c3 Remove data/reading-list.js 2026-08-26 22:35:39 +00:00
kpcto b32ddb1eed Remove css/style.css 2026-08-26 22:35:35 +00:00
kpcto d673d05d80 Remove contact.html 2026-08-26 22:35:31 +00:00
kpcto 39f51a322f Remove README.md 2026-08-26 22:35:26 +00:00
kpcto 66659c8d41 Remove .gitignore 2026-08-26 22:35:21 +00:00
kpcto c955a30a50 Remove .gitea/workflows/ci.yml 2026-08-26 22:34:50 +00:00
kpcto 2a321ad677 Merge pull request '[Story] Git-ignore local secrets and environment files' (#20) from feature/19 into main
CI / Run tests (push) Successful in 19s
CI / Secret scan (gitleaks) (push) Successful in 56s
Reviewed-on: #20
2026-08-26 21:37:38 +00:00
implementer e186faeb44 Add root .gitignore for local env files and node_modules
CI / Run tests (pull_request) Successful in 29s
CI / Secret scan (gitleaks) (pull_request) Successful in 57s
Ignores .env, .env.*, and node_modules/ at any depth so local secrets and dependency directories can never be committed accidentally. Single-file hygiene change; no tracked files affected. Closes #19.
2026-08-26 19:34:37 +00:00
kpcto 25caf810bc Merge pull request 'Update .gitea/workflows/ci.yml' (#18) from kpcto-patch-1 into main
CI / Run tests (push) Successful in 21s
CI / Secret scan (gitleaks) (push) Successful in 56s
Reviewed-on: #18
2026-08-26 18:18:00 +00:00
kpcto 94c1019a6f Update .gitea/workflows/ci.yml
CI / Run tests (pull_request) Successful in 21s
CI / Secret scan (gitleaks) (pull_request) Successful in 57s
2026-08-26 18:17:41 +00:00
kpcto c33614e3e5 Merge pull request 'Update .gitea/workflows/ci.yml' (#17) from kpcto-patch-2 into main
CI / Run tests (push) Successful in 33s
CI / Secret scan (gitleaks) (push) Failing after 13s
Reviewed-on: #17
2026-08-26 18:02:20 +00:00
kpcto 39587532c6 Update .gitea/workflows/ci.yml
CI / Run tests (pull_request) Successful in 28s
CI / Secret scan (gitleaks) (pull_request) Failing after 13s
2026-08-26 18:02:07 +00:00
kpcto 9f1a065529 Merge pull request 'Update .gitea/workflows/ci.yml' (#16) from kpcto-patch-1 into main
CI / Run tests (push) Failing after 21s
CI / Secret scan (gitleaks) (push) Failing after 13s
Reviewed-on: #16
2026-08-26 17:57:19 +00:00
kpcto d7740e3819 Update .gitea/workflows/ci.yml
CI / Run tests (pull_request) Failing after 21s
CI / Secret scan (gitleaks) (pull_request) Failing after 13s
2026-08-26 17:56:07 +00:00
kpcto 6620510bfb Merge pull request '[Story] Newsletter signup (serverless)' (#15) from feature/14 into main
CI / Run tests (push) Successful in 15s
CI / Secret scan (gitleaks) (push) Failing after 12s
Reviewed-on: #15
2026-08-26 11:44:09 +00:00
implementer 32c81d8b91 test: add 3xx-redirect failure and no-credential-header/URL checks
CI / Run tests (pull_request) Successful in 16s
CI / Secret scan (gitleaks) (pull_request) Failing after 13s
Extends the newsletter suite with two boundary cases: redirects (301/302/307/
308) must be treated as failures with the user-safe error, and the POST must
carry no credential of any kind — no api-key/auth-token/cookie headers, and no
token/secret in the body or URL.
2026-08-26 11:31:54 +00:00
implementer 86aa3afbbf refactor: newsletter signup posts no credential (SEC-14-R1 option a)
CI / Secret scan (gitleaks) (pull_request) Failing after 12s
CI / Run tests (pull_request) Successful in 15s
Rework PR #15 per security review SEC-14-R1: the client no longer carries
an API token. js/newsletter-config.js ships only the non-secret endpoint,
enforced https-only at config load time via validateEndpoint() (mirroring
the protocol allowlist in js/reading-list.js); js/newsletter.js POSTs
email-only with no Authorization header. Failure paths keep the single
user-safe message that never leaks token, endpoint, status, or raw body;
success still shows the confirmation. CI gains a gitleaks step that fails
on any secret hit; README documents the server-side token, the residual
signup-abuse risk, and the authoritative server-side validation follow-up.
2026-08-26 11:27:11 +00:00
bot-implementer cb9cf703a8 docs: document the newsletter page and its config in the README
CI / Run tests (pull_request) Successful in 16s
2026-08-25 19:15:56 +00:00
bot-implementer 49690a7934 test: component + unit tests for the newsletter signup
Covers the issue test plan: form renders and posts to the endpoint; token is
read from config, never hardcoded in source; a failed-token response shows a
user-safe error without leaking the secret; confirmation on success.
2026-08-25 19:15:56 +00:00
bot-implementer 24db5b8a50 feat: add serverless newsletter signup page
Adds newsletter.html with an email signup form that POSTs to a configured
serverless endpoint. The endpoint and API token live in
js/newsletter-config.js (token defaults to an empty deploy-time placeholder,
never hardcoded in page logic). Missing/invalid tokens and network failures
surface a fixed user-safe error; successful signups show a confirmation.
Links the page from the site navigation on all pages.
2026-08-25 19:15:56 +00:00
kpcto e24ba8916d Merge pull request '[Story] Update home page intro copy' (#13) from feature/12 into main
CI / Run tests (push) Has been cancelled
Reviewed-on: #13
2026-08-25 18:59:48 +00:00
bot-implementer a93b860cda Update home page intro copy: recipe → road trip
CI / Run tests (pull_request) Successful in 1m26s
2026-08-25 18:53:06 +00:00
kpcto f40b66d5cc Merge pull request '[Story] Reading list page' (#11) from feature/10 into main
CI / Run tests (push) Has been cancelled
Reviewed-on: #11
2026-08-25 17:14:31 +00:00
bot-implementer fb62194d40 feat: harden external reading links with rel="noopener noreferrer"
CI / Run tests (pull_request) Has been cancelled
All reading list links point at external http(s) URLs, so each rendered
anchor now carries rel="noopener noreferrer" as a hardening best
practice. Renderer test updated for the new attribute and asserts every
rendered link carries it.
2026-08-25 15:15:31 +00:00
kpcto 5bd86f3f9b Merge pull request '[Story] Reading list page' (#9) from feature/8 into main
CI / Run tests (push) Has been cancelled
Reviewed-on: #9
2026-08-25 12:33:20 +00:00
bot-implementer e4a192baab docs: document the reading list page and data file in the README
CI / Run tests (pull_request) Has been cancelled
2026-08-25 12:30:10 +00:00
bot-implementer f278df1214 test: component + unit tests for the reading list page
Covers: page wiring and nav reachability, data-file integrity, grouped
rendering, valid hrefs, optional notes, HTML escaping, invalid-entry
skipping, data-only extensibility, and a 500-entry fixture (counts,
grouping, and a generous render-time bound).
2026-08-25 12:30:10 +00:00
bot-implementer dfaaeaf7f4 feat: add reading list page and link it from site navigation
New reading.html renders the data file into a #reading-list container and
marks itself as the current page. Home and contact pages gain a Reading nav
link. CSS adds responsive category/list styles (two columns on wide
screens) so long lists stay scannable.
2026-08-25 12:30:09 +00:00
bot-implementer ffdcd35cea feat: add reading list renderer module
Renders the data file as category-grouped HTML. Pure string builder with
guarded browser wiring so it is unit-testable in Node; escapes all text,
skips invalid entries, and handles duplicate category slugs.
2026-08-25 12:30:06 +00:00
bot-implementer 05cfbad4ad feat: add curated reading list data file
Single source of truth for the reading list page. Entries carry a title,
url, category, and an optional one-line note; adding a link means editing
this file only.
2026-08-25 12:30:06 +00:00
bot-implementer 37f2c9a2f2 chore: use default test discovery so npm test works across node builds
`node --test <dir>` treats a directory argument as a module path on some
Node builds (reproduced on v22.23.2), so `npm test` failed before running
any tests. `node --test` with no args discovers the same tests/ files
portably.
2026-08-25 12:30:06 +00:00
kpcto c1c26e7d0e Merge pull request 'feature/5' (#7) from feature/5 into main
CI / Run tests (push) Has been cancelled
Reviewed-on: #7
2026-08-25 11:17:55 +00:00
bot-implementer fdc306ac33 feat: link the contact page from the home page navigation
CI / Run tests (pull_request) Has been cancelled
2026-08-25 10:45:45 +00:00
bot-implementer d94e769806 test: component + unit tests for the contact page 2026-08-25 10:45:36 +00:00
bot-implementer 2f5c522cc3 test: unit tests for the mailto URL builder 2026-08-25 10:45:28 +00:00
bot-implementer 0d76bc01fe feat: wire contact form submit to open mail client via mailto 2026-08-25 10:45:23 +00:00
bot-implementer b99c1b27d0 feat: add pure mailto URL builder 2026-08-25 10:45:17 +00:00
bot-implementer b7692551e1 feat: add contact page with name, email, and message fields 2026-08-25 10:45:12 +00:00
bot-implementer f77720c10b chore: add scaffold smoke test
CI / Run tests (push) Has been cancelled
2026-08-25 10:44:19 +00:00