21 Commits
Author SHA1 Message Date
Firehose Bot 310a5c0afd Bump phoenix_live_view to 1.2.12, closing last security advisory
The microprints git dep now allows phoenix_live_view ~> 1.2, so the
app can take the CVE-2026-64941 fix (open redirect in
validate_local_url!/2, fixed in 1.2.9). No 1.1.x backport existed.

blogex test lock follows to 1.2.12 so the library is tested against
the version the app ships with. mix deps.get now reports zero
security advisories.
2026-10-08 09:50:49 +01:00
Firehose Bot 3eec05b1d3 Update dependencies with security advisories
Bump all Hex deps with OSV advisories to fixed versions:
bandit 1.12.5, phoenix 1.8.15, plug 1.20.3, plug_crypto 2.2.0,
postgrex 0.22.4, decimal 3.1.1 (via ecto/ecto_sql 3.14), swoosh 1.28.1,
mint 1.11.0, hpax 1.1.0, finch 0.24.0, req 0.7.5, lazy_html 0.1.13.

Constraint changes: ecto_sql ~> 3.14 (ecto 3.14 requires decimal ~> 3.0),
req ~> 0.7.

phoenix_live_view stays at 1.1.27 (CVE-2026-64941, LOW): the fix landed
in 1.2.9 with no 1.1.x backport, and the microprints git dep pins
~> 1.1.0. Tracked in a follow-up yak.
2026-10-08 09:49:04 +01:00
Firehose Bot c5db0cbda8 Fix compile-time link validation and add tag page links
- Restore HTML link extraction in LinkValidator (removed in a83634d
  under the false premise that post bodies are raw markdown; they
  are HTML rendered by NimblePublisher at compile time). The missing
  regex made extract_links/1 find zero links, silently disabling
  compile-time validation.
- Support /blog/{blog_id}/tag/{tag} links: validate blog ID,
  require non-empty tag (tags are user-defined, e.g. pi.dev).
- Fix invalid links in two posts: tag/Pi.dev -> tag/pi.dev,
  2026-07-13-synthetic-tdd.md -> synthetic-tdd.
- Fix test warnings: use Plug.Test deprecation, unused import,
  runtime-defined TestBlogValid module.
- Add regression tests for HTML extraction and tag page links.
2026-10-08 08:43:51 +01:00
Willem van den Ende 127eb474d2 External link marker: new tab + icon on links leaving the blog
External links in post bodies now open in a new tab and show a
box-with-arrow marker icon, so readers can tell at a glance which
links leave the site.

- blogex: new Blogex.ExternalLinks.rewrite/1 marks up anchors with
  http(s) hrefs at compile time with target="_blank", rel="noopener"
  and class="blogex-external" (idempotent, merges into existing
  class/rel values, leaves relative, mailto: and #anchor links alone)
- blogex: Post.build/3 applies the rewrite, so every blog gets it
- app: CSS in .blogex-post-body draws the marker via a mask so it
  inherits the link colour; empty ::after content stays invisible
  to screen readers
- make test now also runs the blogex suite; it is currently red
  with 3 pre-existing blog_integration_test failures caused by the
  vacuous link validator (parked yak
  link-validator-never-sees-compiled-html-...)
2026-10-02 12:11:10 +00:00
Firehose Bot 4885c94b72 old conflicts and version update 2026-07-13 15:01:19 +01:00
Firehose Bot 51ba85d492 upgrade nimble_publisher to 2.0 for mdex_native (replaces deprecated earmark) 2026-07-06 18:18:12 +01:00
mostalive 061787e897 Feature: OG Social media cards
Not Original Gangsta, but ObjectGraph

Reason: images were showing on LinkedIn, but small.
2026-05-10 21:34:07 +01:00
Firehose Bot a83634da36 refactor(Blogex.LinkValidator): simplify dead code and naming
- Drop redundant :ok return in _validate_links/2 (blog.ex)
- Remove dead HTML link regex from extract_links/1 (body is raw markdown)
- Rename slug_slug_end/1 to slug_end/1
- Simplify parse_blog_link/1 to return {blog_id, slug}, removing
  parse_query_fragment/1 and dead case branches
2026-05-07 13:24:11 +01:00
Firehose Bot 2b7cf0a3b9 chore: apply mix format to blogex test files and router 2026-05-07 11:57:17 +01:00
Firehose Bot ab7a520e9e Add compile-time link validation for blog post internal links
- Add Blogex.LinkValidator module to validate /blog/{id}/{slug} semantics
- Add Blogex.LinkError exception with actionable error messages
- Integrate validation into Blogex.Blog via @before_compile callback
- Add unit tests (34) and integration tests (4) for link validation
- Add test fixtures (valid/invalid posts) in blogex/priv/blog/test/

Closes: validate-internal-link-semantics-in-blog-post-markdown-bodies-at-compile-time-h3hb
Closes: define-link-semantic-validation-logic-in-blogex-7syv
Closes: write-tests-for-link-semantic-validation-y30h
Closes: integrate-link-validation-into-blogexblog-compile-time-macro-1205
2026-05-07 11:56:54 +01:00
Willem van den Ende 8d40e09e90 Verify router respects date filtering on all endpoints 2026-04-01 21:46:59 +00:00
Willem van den Ende 20f12847d6 Allow direct access to draft and scheduled posts by slug 2026-04-01 20:39:19 +00:00
Willem van den Ende 370275f7b5 Verify feeds exclude future-dated posts 2026-04-01 20:37:27 +00:00
Willem van den Ende 0577ceced0 Filter future-dated posts from public views and add unfiltered post access
- all_posts/0 now excludes posts where date > today
- all_tags/0 computed at runtime from filtered posts
- posts_by_tag/1 and recent_posts/1 inherit date filtering
- Add unfiltered_posts/0 to Blog macro and FakeBlog
- Add all_posts_unfiltered/0 to Registry for dashboard use
2026-04-01 20:30:27 +00:00
Willem van den Ende 037e9f86ff Add post visibility and days_until_live helpers 2026-04-01 20:24:33 +00:00
Firehose Bot 17a0f2709c Add current_tag attribute to post_index component 2026-03-24 14:56:54 +00:00
Willem van den Ende 9426582abc Refactor conn aliasing in controller tests to use pipe chains
Applied refactor_conn_aliasing.sh to eliminate conn shadowing.

Show draft posts in test and dev
2026-03-20 21:36:08 +00:00
Firehose Bot 671add15bb fix blog tag clicks, and new post 2026-03-19 22:14:19 +00:00
mostalive 9be7c1774b Dokku setup script did not work that well, fixed by hand 2026-03-18 14:38:45 +00:00
Willem van den Ende 24847ca7fd Clearly mark sample posts as generated 2026-03-18 12:11:28 +00:00
Your Name bc14696f57 Static blog with front page summary
Goal: have a personal blog, and try out another point in the 'modular
app design with elixir' space.

Designing OTP systems with elixir had some interesting ideas.
2026-03-17 11:17:21 +00:00