This website requires JavaScript.
Explore
Forum
Sponsor
coffeylabs.org
↗
Help
Register
Sign In
coffey-labs
/
hotdog-cms
Watch
1
Star
0
Fork
0
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
1
Wiki
Activity
Sponsor
Files
v0.1.0
hotdog-cms
/
internal
/
build
T
History
jcoffey-dev
f650a5c5fd
ci / go (push)
Failing after 13s
Details
ci / editor-ui (push)
Failing after 1m18s
Details
Starter footer: copyright_url links the copyright holder
2026-10-10 22:45:20 -07:00
..
static
E6: consent banner and consent-gated analytics wizard, privacy notice built from the site's settings
2026-10-10 18:19:31 -07:00
assets.go
Rename to HotDog CMS: hotdog-cms command and module, HOTDOG_ settings, hotdog- site hooks, brand assets, branded editor
2026-10-10 15:57:07 -07:00
build_test.go
Pagination in the starter: numbered page links, prev/next in the head, page number in titles; docs
2026-10-10 19:28:37 -07:00
build.go
A collection's feed is written as soon as the collection exists, before its first post
2026-10-10 21:53:04 -07:00
cards.go
Security: never follow symbolic links (git checks them out as files, sites refuse them, editor I/O through os.Root); valid branch names and --end-of-options; maintainers only publish pipeline changes; __Host- cookies and Secure from public_url; strict sign-in return path; real GitLab/Bitbucket permissions; safe page, feed and redirect paths; card logo/font read inside the site with limits; page size cap and safe printf; editor, preview and pull builds in a limited child process without secrets
2026-10-10 20:34:37 -07:00
consent.go
E6: consent banner and consent-gated analytics wizard, privacy notice built from the site's settings
2026-10-10 18:19:31 -07:00
events_test.go
Starter footer: copyright_url links the copyright holder
2026-10-10 22:45:20 -07:00
events.go
Quick posts: banners and alerts (scheduled, data/banners.yaml), news posts, events and front page edits, each posted, checked and published in one step; docs and roadmap
2026-10-10 19:52:19 -07:00
funcs.go
Security: never follow symbolic links (git checks them out as files, sites refuse them, editor I/O through os.Root); valid branch names and --end-of-options; maintainers only publish pipeline changes; __Host- cookies and Secure from public_url; strict sign-in return path; real GitLab/Bitbucket permissions; safe page, feed and redirect paths; card logo/font read inside the site with limits; page size cap and safe printf; editor, preview and pull builds in a limited child process without secrets
2026-10-10 20:34:37 -07:00
icons.go
Security, second batch: pack and icon markup checked by parsing HTML; check runs security rules on redirect pages and flags script links; safe importer slugs and writes; Markdown attributes limited to id and class; plain form subjects; recipient allowlist; IPv6 rate limits per /64, stored submissions capped; bounded, rate-limited search; listener timeouts; bookkeeping files never served; collision-proof discovered ids and one discovery at a time; CI secrets kept from pushable branches; SECURITY.md and docs/security.md
2026-10-10 20:47:41 -07:00
outputs.go
Rename to HotDog CMS: hotdog-cms command and module, HOTDOG_ settings, hotdog- site hooks, brand assets, branded editor
2026-10-10 15:57:07 -07:00
searchengines.go
E6: search engine verification, IndexNow pings after publishing; docs
2026-10-10 18:23:51 -07:00
sections_test.go
editor: sections as cards with forms from each template's fields; front matter edits keep order and unchanged style
2026-10-10 17:31:05 -07:00
sections.go
E10: packs (sections, layouts and styles as files, no code), before/after steps on publish targets, pipeline files maintainer-only in the editor; E6: share links
2026-10-10 19:20:17 -07:00
templates.go
Events and calendars: start/end in the site's time zone, iCalendar feeds (webcal) and per-event files, upcoming/past, schema.org data; calendar pack bundled; packs can add collection settings
2026-10-10 19:41:56 -07:00