The microprints git dep now allows phoenix_live_view ~> 1.2, so the
app can take the CVE-2026-64941 fix (open redirect in
validate_local_url!/2, fixed in 1.2.9). No 1.1.x backport existed.
blogex test lock follows to 1.2.12 so the library is tested against
the version the app ships with. mix deps.get now reports zero
security advisories.
- Restore HTML link extraction in LinkValidator (removed in a83634d
under the false premise that post bodies are raw markdown; they
are HTML rendered by NimblePublisher at compile time). The missing
regex made extract_links/1 find zero links, silently disabling
compile-time validation.
- Support /blog/{blog_id}/tag/{tag} links: validate blog ID,
require non-empty tag (tags are user-defined, e.g. pi.dev).
- Fix invalid links in two posts: tag/Pi.dev -> tag/pi.dev,
2026-07-13-synthetic-tdd.md -> synthetic-tdd.
- Fix test warnings: use Plug.Test deprecation, unused import,
runtime-defined TestBlogValid module.
- Add regression tests for HTML extraction and tag page links.
External links in post bodies now open in a new tab and show a
box-with-arrow marker icon, so readers can tell at a glance which
links leave the site.
- blogex: new Blogex.ExternalLinks.rewrite/1 marks up anchors with
http(s) hrefs at compile time with target="_blank", rel="noopener"
and class="blogex-external" (idempotent, merges into existing
class/rel values, leaves relative, mailto: and #anchor links alone)
- blogex: Post.build/3 applies the rewrite, so every blog gets it
- app: CSS in .blogex-post-body draws the marker via a mask so it
inherits the link colour; empty ::after content stays invisible
to screen readers
- make test now also runs the blogex suite; it is currently red
with 3 pre-existing blog_integration_test failures caused by the
vacuous link validator (parked yak
link-validator-never-sees-compiled-html-...)
Replace the broadcast-style SVG icon with the traditional RSS
symbol (dot + two concentric arcs) — the standard feed icon
used across browsers and feed readers.
- Add <.rss_icon> inline SVG component in core_components.ex
- Inject RSS <link> tags into <head> on blog pages for auto-discovery
- Show RSS icon next to blog title on index and tag pages
- Show RSS icon on post pages next to back-link
- Add Subscribe section in footer with links to both feeds
- Wire feed URL through blog controller (index, show, tag actions)
174 tests pass, credo clean.
- Add missing 'do' keyword on describe block (SyntaxError)
- Replace brittle SVG rect DOM selector with direct render_click event
trigger to avoid AmbiguousError from multi-segment rects
- Fix layout test: render/1 returns LV inner HTML only, not the
layout wrapper — check for content actually present in output
- Use and instead of hardcoded zinc colors in EditorDashboardLive
- Apply same fix to MicroprintsLive description paragraph
- All titles now respect the active theme and remain readable in both light and dark modes