Compare commits
19
Commits
9ec2349cd6
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
bb22c368ba | ||
|
|
143ec135c0 | ||
|
|
e106da0206 | ||
|
|
cfe070efec | ||
|
|
3250ad366a | ||
|
|
4450bd6eec | ||
|
|
28bbd41868 | ||
|
|
d57041d316 | ||
|
|
b02f27f559 | ||
|
|
6398542845 | ||
|
|
e79275a3ab | ||
|
|
f9ab3b1561 | ||
|
|
1f4e2aeba5 | ||
|
|
cdae34a706 | ||
|
|
285e61573e | ||
|
|
5edaf3ee1e | ||
|
|
829325c9c7 | ||
|
|
a517331d1b | ||
|
|
01c3e72c8f |
@@ -6,9 +6,9 @@ Rules, gotchas, and entry points — the things that must change what you do *be
|
||||
|---|---|
|
||||
| How the site hangs together — stack, plugin roles, templates, partial contracts, data flows | [`docs/reference/architecture.md`](docs/reference/architecture.md) |
|
||||
| Domain vocabulary — Trip, Entry, Story, Active Trip | [`CONCEPTS.md`](CONCEPTS.md) |
|
||||
| Doing something operational — posting, GPX, switching trips, local setup, deploying | [`docs/guides/`](docs/guides/) |
|
||||
| Doing something operational — posting, writing stories, GPX, switching trips, local setup, deploying | [`docs/guides/`](docs/guides/) |
|
||||
| Test suite layout and conventions | [`docs/reference/testing.md`](docs/reference/testing.md) |
|
||||
| A bug or workflow trap already hit and written up | [`docs/solutions/`](docs/solutions/) — check when working in a documented area |
|
||||
| A bug or workflow trap already hit and written up | [`docs/solutions/`](docs/solutions/) — grep the `module`/`tags`/`problem_type` frontmatter; check when working in a documented area |
|
||||
| Folder map, prerequisites, the full `make` command list | [`README.md`](README.md) |
|
||||
|
||||
The site is Grav (flat-file PHP CMS, no database) in Docker, with content and theme in the `user/` submodule.
|
||||
@@ -18,9 +18,10 @@ The site is Grav (flat-file PHP CMS, no database) in Docker, with content and th
|
||||
- **Only ever write inside `travel-blog-intotheeast/`** or its subfolders.
|
||||
- **Never read `.env`, `.env.prod`, `.env.test`** — they hold credentials. Pass them to commands (`make`, `docker compose`) but never read them; ask the user if you need a value.
|
||||
- **Never SSH to a server directly** — use the `make remote-*` targets, since credentials live in `.env`. If no target covers what you need, ask the user to run it or propose a new target.
|
||||
- **Never hand-edit build output**, and know which files those are — sources and outputs share folders under `user/themes/intotheeast/` (all paths below are relative to it). `make build-assets` is mandatory after editing any source, and it writes:
|
||||
- **Generated (never edit):** `js/main.js`, `js/map.js`, `js/feed-actions.js`, `js/trip-publish.js`, `js/post/`, `css-compiled/`, `fonts/`, and `templates/partials/weather-icons.html.twig`.
|
||||
- **Hand-authored sources:** everything in `js/src/`, plus `js/maplibre-utils.js` and `js/nav.js` (which sit *next to* the bundles in `js/`), `css/style.css`, `css/tokens.css`, and `scripts/gen-weather-icons.js`.
|
||||
- **Never hand-edit build output** — sources and outputs share folders under `user/themes/intotheeast/` (paths below are relative to it), so know which is which. Run `make build-assets` after editing any source.
|
||||
- Everything in `js/` is **generated** *except* `js/src/`, `js/maplibre-utils.js` and `js/nav.js`.
|
||||
- `css-compiled/` and `fonts/` are generated by esbuild from the `js/src/` entrypoints' CSS and font imports (fontsource, photoswipe, maplibre-gl) — **not** from `css/`. `css/style.css` and `css/tokens.css` are hand-authored and served directly (`partials/base.html.twig`), so editing them needs no rebuild.
|
||||
- `templates/partials/weather-icons.html.twig` is generated (source: `scripts/gen-weather-icons.js`).
|
||||
- **Never toggle dev↔prod mode mid-session.** If a caching or config issue appears, fix it at the application level (plugin, template logic) rather than flipping a mode flag — mode switches leave inconsistent state and make bugs harder to reproduce.
|
||||
|
||||
## Dev environment
|
||||
@@ -44,7 +45,8 @@ The site is Grav (flat-file PHP CMS, no database) in Docker, with content and th
|
||||
|
||||
Trip and home render the same map and feed chrome through two shared partials, both included `with {…} only`. Parameter contracts: [`docs/reference/architecture.md`](docs/reference/architecture.md) → "Shared partial contracts". What must not break:
|
||||
|
||||
- **`partials/entry-map.html.twig` is the only map path** — the engine is `MapUtils.initEntryMap(opts)` in `js/maplibre-utils.js` (a hand-authored file, imported by `js/src/map.js`). Do not add a second map implementation; an older three-variant setup was deliberately consolidated away.
|
||||
- **`partials/entry-map.html.twig` is the only path for a *display* map** — the engine is `MapUtils.initEntryMap(opts)` in `js/maplibre-utils.js` (a hand-authored file, imported by `js/src/map.js`). Do not add another display-map implementation; an older three-variant setup was deliberately consolidated away.
|
||||
- **One sanctioned exception: `js/src/location-map.js`**, the `/post` form's pin *editor* (one draggable marker, no popups/GPX/bounds-fitting, `maplibre-gl` lazy-imported so a GPS-only submit never fetches it). It shares exactly one thing with the display path — `MAP_STYLE` from `js/src/map-style.js`, imported by both so the basemap cannot drift. Do not fold it into `initEntryMap`, and do not add a *third* path.
|
||||
- It must keep assigning **`window.tripMap` / `window.homeMap`** — the Playwright map specs assert those globals.
|
||||
- **Keep `trip-feed-col.html.twig` single-purpose.** Its sibling `partials/home-predeparture.html.twig` is the home-only "Coming soon" state — do **not** fold the pre-departure branch back into it.
|
||||
|
||||
|
||||
@@ -54,9 +54,15 @@ $(foreach t,$(REMOTE_TARGETS),$(foreach e,$(ENVS),$(eval $(call make-env-target,
|
||||
GRAV_TEST_USER ?= testrunner
|
||||
GRAV_TEST_PASS ?= Testpass1234
|
||||
|
||||
# The password is handed to the container through `docker exec -e` (the bare
|
||||
# form, which forwards the already-exported variable) rather than interpolated
|
||||
# into the `sh -c` string. Interpolating it meant any shell-special character in
|
||||
# GRAV_TEST_PASS was re-parsed by the container's shell — a `.env` password
|
||||
# containing one produced `sh: 2: <fragment>: not found` and no test account.
|
||||
# The recipe is now indifferent to the password's contents.
|
||||
test-account:
|
||||
@docker exec $(GRAV_CONTAINER) sh -c 'test -f /var/www/html/user/accounts/$(GRAV_TEST_USER).yaml \
|
||||
|| php bin/plugin login new-user -u $(GRAV_TEST_USER) -p "$(GRAV_TEST_PASS)" \
|
||||
@docker exec -e GRAV_TEST_PASS $(GRAV_CONTAINER) sh -c 'test -f /var/www/html/user/accounts/$(GRAV_TEST_USER).yaml \
|
||||
|| php bin/plugin login new-user -u $(GRAV_TEST_USER) -p "$$GRAV_TEST_PASS" \
|
||||
-e $(GRAV_TEST_USER)@example.test -N "Test Runner" -P b --admin-type both -s enabled -n'
|
||||
|
||||
test-config:
|
||||
@@ -65,6 +71,13 @@ test-config:
|
||||
test-post: test-account
|
||||
@bash scripts/test-post.sh
|
||||
|
||||
# Pinned to THIS checkout's port, not playwright.config.js's :8081 default. In a
|
||||
# worktree that default silently pointed the suite at the main checkout's server,
|
||||
# so entries were created in main's user/ while the specs asserted and cleaned up
|
||||
# in the worktree's — leaving ui-test entries behind in real trip content.
|
||||
# tests/global-setup.js now also hard-fails on that mismatch.
|
||||
GRAV_BASE_URL ?= http://localhost:$(GRAV_PORT)
|
||||
|
||||
test-ui: test-account
|
||||
@npx playwright test
|
||||
|
||||
@@ -98,8 +111,18 @@ build-assets:
|
||||
-w /app node:20-alpine \
|
||||
sh -c "npm install && npm run build"
|
||||
|
||||
# In a worktree this degrades to start-grav. The travel-memories service declares
|
||||
# `env_file: .env`, and worktree-new does not create a .env, so a plain
|
||||
# `docker compose up -d` there dies with "env file ... not found" — leaving the
|
||||
# worktree with no server at all, which is how test runs ended up silently
|
||||
# targeting the main checkout.
|
||||
start:
|
||||
docker compose up -d
|
||||
@if [ -f .worktree-env ]; then \
|
||||
echo "→ worktree: starting the grav service only (travel-memories needs a .env, which worktrees have none)"; \
|
||||
docker compose up -d grav; \
|
||||
else \
|
||||
docker compose up -d; \
|
||||
fi
|
||||
|
||||
# Grav service only — used by `make worktree-new` (a worktree rarely needs the
|
||||
# travel-memories service, and this keeps its footprint minimal).
|
||||
@@ -177,6 +200,12 @@ worktree-rm: guard-name
|
||||
-git -C "$(WT_DIR)" submodule deinit -f user
|
||||
git worktree remove --force "$(WT_DIR)"
|
||||
git worktree prune
|
||||
# The deinit above is required (a populated user/ blocks `worktree remove`),
|
||||
# but worktrees SHARE .git/config — so it also strips submodule.user.url for
|
||||
# the MAIN checkout, leaving `git submodule status` there showing `-` (not
|
||||
# initialised) even though user/ is intact. Re-register it; init is
|
||||
# idempotent and touches config only, never the working tree.
|
||||
git submodule init
|
||||
@echo "Removed $(WT_DIR). If feat/$(NAME) is merged, drop it: git branch -d feat/$(NAME)"
|
||||
|
||||
# ── Demo content ──────────────────────────────────────────────────────────────
|
||||
@@ -185,6 +214,13 @@ demo-load:
|
||||
# Load every fixture trip under docs/demo/trips/ into the pages tree.
|
||||
# Source uses dailies/ + 04.stories/; dailies/ maps to 01.dailies/ on copy.
|
||||
# All copies are `|| true` so a fixture absent from an older user/ is skipped.
|
||||
#
|
||||
# ⚠️ A fixture whose folder name matches a REAL trip's slug is copied straight
|
||||
# over that live page — docs/demo/trips/italy-2025/ collides with the real
|
||||
# italy-2025 trip on purpose (the fixture supplies its GPX + dailies). So any
|
||||
# field the fixture's trip.md omits gets silently deleted from real content on
|
||||
# every test run: it had been dropping the trip's tagline that way. Keep a
|
||||
# colliding fixture's trip.md byte-identical to the live page.
|
||||
docker exec $(GRAV_CONTAINER) bash -c 'for src in /var/www/html/user/docs/demo/trips/*/; do \
|
||||
slug=$$(basename "$$src"); dst=/var/www/html/user/pages/01.trips/$$slug; \
|
||||
mkdir -p "$$dst/01.dailies" "$$dst/04.stories"; \
|
||||
|
||||
@@ -27,7 +27,7 @@ Two git repos:
|
||||
| `tests/` | Playwright suite — see [`docs/reference/testing.md`](docs/reference/testing.md) |
|
||||
| `php/` | Local PHP ini overrides |
|
||||
| `docs/` | All project documentation — start at [`docs/README.md`](docs/README.md) |
|
||||
| `docs/guides/` | Operational how-tos (posting, GPX, trip switching, setup, deploy cycle) |
|
||||
| `docs/guides/` | Operational how-tos (posting, story authoring, GPX, trip switching, setup, deploy cycle) |
|
||||
| `docs/reference/` | Stable facts: architecture, design system, testing |
|
||||
| `docs/solutions/` | Write-ups of bugs and workflow traps already hit, with YAML frontmatter (`module`, `tags`, `problem_type`) |
|
||||
| `docs/working/` | Specs, plans, backlog, QA — work in flight |
|
||||
|
||||
@@ -13,6 +13,13 @@ services:
|
||||
volumes:
|
||||
- ./user:/var/www/html/user
|
||||
- ./php/php-local.ini:/usr/local/etc/php/conf.d/php-local.ini
|
||||
# Grav stages form uploads in tmp/forms/<session>/ before the submit moves
|
||||
# them into the page folder. The image declares /var/www/html as a VOLUME,
|
||||
# so without this it lives in an ANONYMOUS volume that is discarded on any
|
||||
# `docker compose up` that recreates the container — dropping the photos of
|
||||
# a post that was filled in but not yet submitted. Naming it gives the
|
||||
# staging area its own lifecycle.
|
||||
- grav_tmp:/var/www/html/tmp
|
||||
restart: unless-stopped
|
||||
|
||||
travel-memories:
|
||||
@@ -24,3 +31,6 @@ services:
|
||||
- ./user/pages:/app/pages
|
||||
env_file: .env
|
||||
user: "${UID}:${GID}"
|
||||
|
||||
volumes:
|
||||
grav_tmp:
|
||||
|
||||
@@ -0,0 +1,228 @@
|
||||
# Writing a Story
|
||||
|
||||
A Story is a long-form, hand-crafted piece with an immersive layout — distinct from an Entry, which is a quick dated post from the road (see [`CONCEPTS.md`](../../CONCEPTS.md)). Stories get a Ken Burns hero, scroll-driven sections, galleries and pull quotes.
|
||||
|
||||
The admin editor gives you a **plain markdown textarea** for the body. There is no block picker — the layout vocabulary is a set of shortcodes you type by hand. This guide is that vocabulary; the story edit form also carries a condensed copy of it on its **Blocks** tab, so you don't need this file open while writing.
|
||||
|
||||
Admin lives at **`/admin`** (the plugin slug is `admin2`, but the route is `/admin`). A story's edit URL looks like `/admin/pages/edit/trips/<trip>/stories/<slug>`.
|
||||
|
||||
Stories live at:
|
||||
|
||||
```
|
||||
user/pages/01.trips/<trip>/04.stories/<slug>/story.md
|
||||
```
|
||||
|
||||
`04.stories/stories.md` is a `routable: false` container — its children are aggregated onto the trip page. There is no standalone `/stories` view; don't create one.
|
||||
|
||||
---
|
||||
|
||||
## 1. Create the page
|
||||
|
||||
1. Admin → **Pages** → add a page under the trip's **Stories** folder
|
||||
2. Set page template to **story** — this loads [`user/themes/intotheeast/blueprints/story.yaml`](../../user/themes/intotheeast/blueprints/story.yaml). You get the story-specific **Content / Blocks / Location / Publishing** tabs plus the inherited **Options / Advanced / Security** tabs
|
||||
3. Fill in Title and Start Date (both required)
|
||||
|
||||
---
|
||||
|
||||
## 2. Upload the images first
|
||||
|
||||
Upload every image the story needs via the **Images** field at the bottom of the Content tab, before writing the body.
|
||||
|
||||
> There is no separate *Media* tab — the uploader is a field on the Content tab, labelled **Images**. It arrives via inheritance: `story.yaml` declares `'@extends': {type: default, context: blueprints://pages}`, which merges in Grav's default page form. `story.yaml` and `trip.yaml` did not originally extend it, so neither form could upload anything, which is why the demo story images had to be placed on the filesystem. Both now inherit, matching [`entry.yaml`](../../user/themes/intotheeast/blueprints/entry.yaml). `home.yaml` is still standalone, deliberately — the home page has no per-page media.
|
||||
|
||||
Every shortcode refers to images by **bare filename** — the `story-blocks` plugin prefixes the page URL at render time ([`story-blocks.php:22`](../../user/plugins/story-blocks/story-blocks.php)), so you write:
|
||||
|
||||
```
|
||||
image="photo-1.jpg" ✅
|
||||
image="/images/photo-1.jpg" ❌ don't path it
|
||||
```
|
||||
|
||||
The demo stories use a `hero.jpg` / `photo-1.jpg` / `photo-2.jpg` naming convention. Worth copying — it keeps the shortcodes readable.
|
||||
|
||||
---
|
||||
|
||||
## 3. Frontmatter fields
|
||||
|
||||
All of these come from the form tabs, so you rarely type them by hand. Listed here because the body shortcodes are *not* the whole story — the hero in particular is frontmatter, not a tag.
|
||||
|
||||
| Field | Tab | Notes |
|
||||
|---|---|---|
|
||||
| `title` | Content | Required |
|
||||
| `date` | Content | Required. Start date |
|
||||
| `end_date` | Content | Optional — leave blank for a single-day story |
|
||||
| `hero_image` | Content | **The hero. Filename only**, from the Images field. Missing → grey placeholder, story still renders |
|
||||
| `hero_alt` | Content | Falls back to the title if empty |
|
||||
| `location_name`, `location_country` | Location | Shown in the hero meta line and the opener |
|
||||
| `lat`, `lng` | Location | Decimal degrees — places the story marker on the trip map |
|
||||
| `transport_mode` | Location | walking / bicycle / bus / train / car |
|
||||
| `force_connect` | Location | Always draw a connector line from the previous marker |
|
||||
| `published` | Options | Grav's standard toggle, from the inherited form |
|
||||
| `featured` | Publishing | Show as a homepage highlight when not travelling |
|
||||
|
||||
The Ken Burns pan on the hero is automatic — no parameter for it.
|
||||
|
||||
If you hand-write frontmatter, use `date: '2026-09-03'`. Admin2 saves its own serialization (`29-07-2026 19:51`); both parse fine.
|
||||
|
||||
---
|
||||
|
||||
## 4. The body: six shortcodes
|
||||
|
||||
Defined in [`user/plugins/story-blocks/shortcodes/`](../../user/plugins/story-blocks/shortcodes/). Plain prose between them renders as a normal reading column — you don't need a shortcode to write paragraphs.
|
||||
|
||||
### Wrapping tags
|
||||
|
||||
**`scrolly-section`** — text panels scroll over a pinned, slowly panning image. The centrepiece block.
|
||||
|
||||
```
|
||||
[scrolly-section image="hero.jpg" alt="Description of the image" caption="Optional caption"]
|
||||
The first panel. Scrolls into view over the image.
|
||||
|
||||
---
|
||||
|
||||
The second panel. A markdown `---` starts a new panel.
|
||||
[/scrolly-section]
|
||||
```
|
||||
|
||||
Panels are split on the `<hr>` that `---` produces ([`story.html.twig:234`](../../user/themes/intotheeast/templates/story.html.twig)). `caption` is optional. Under `prefers-reduced-motion` all panels render active with no pinning.
|
||||
|
||||
**`pull-quote`** — large extracted quote, optionally over a background image.
|
||||
|
||||
```
|
||||
[pull-quote image="photo-1.jpg" alt="Description of the image"]
|
||||
The quote itself. Markdown works in here.
|
||||
[/pull-quote]
|
||||
```
|
||||
|
||||
Drop `image`/`alt` entirely for the plain no-image variant.
|
||||
|
||||
### Self-closing tags
|
||||
|
||||
Note the ` /]` — these take no content.
|
||||
|
||||
**`chapter-break`** — full-width section transition over a background image.
|
||||
|
||||
```
|
||||
[chapter-break image="photo-1.jpg" title="After Dark" number="II" alt="Description" /]
|
||||
```
|
||||
|
||||
`number` is optional; the demo stories use roman numerals.
|
||||
|
||||
**`snap-gallery`** — swipeable multi-image carousel with dots.
|
||||
|
||||
```
|
||||
[snap-gallery images="hero.jpg,photo-1.jpg" captions="First caption,Second caption" alts="First alt,Second alt" /]
|
||||
```
|
||||
|
||||
⚠️ See the comma gotcha below.
|
||||
|
||||
**`full-bleed`** — single image edge-to-edge, as a visual pause.
|
||||
|
||||
```
|
||||
[full-bleed image="photo-2.jpg" alt="Description" caption="Optional" credit="Optional" /]
|
||||
```
|
||||
|
||||
**`image-caption`** — photo at a chosen width with caption beneath.
|
||||
|
||||
```
|
||||
[image-caption image="photo-2.jpg" alt="Description" caption="Optional" credit="Optional" width="column" /]
|
||||
```
|
||||
|
||||
`width` accepts `column` (default), `full`, `bleed`. Anything else falls back to `column`.
|
||||
|
||||
`full-bleed` and `image-caption` are implemented but not yet used by any story — the demos only exercise the other four.
|
||||
|
||||
---
|
||||
|
||||
## Gotchas
|
||||
|
||||
### snap-gallery splits on commas — captions cannot contain them
|
||||
|
||||
`images`, `captions` and `alts` are each split on `,` and zipped by index. **A comma inside a caption shifts every caption after it.**
|
||||
|
||||
This is already live in the demo content. `04.stories/04.florence-without-a-map/story.md` has:
|
||||
|
||||
```
|
||||
captions="The Arno at noon — greener than expected, the bridges older than you remember,Via dei Servi: …"
|
||||
```
|
||||
|
||||
Two images, but three comma-separated pieces — so slide 1 gets "The Arno at noon — greener than expected", slide 2 gets " the bridges older than you remember", and the Via dei Servi text is silently dropped.
|
||||
|
||||
Use em dashes or semicolons in gallery captions. There is no escaping mechanism.
|
||||
|
||||
### Self-closing tags need the space before `/]`
|
||||
|
||||
`[chapter-break … /]` — not `[chapter-break …/]` or `[chapter-break …]`.
|
||||
|
||||
### A typo'd shortcode fails silently
|
||||
|
||||
An unrecognised tag name or a malformed parameter list renders as literal text or vanishes — no error, no warning. Preview the page after every block; there is no in-editor validation.
|
||||
|
||||
### `---` outside a scrolly-section is just a horizontal rule
|
||||
|
||||
The panel-splitting behaviour only applies *inside* `[scrolly-section]`.
|
||||
|
||||
---
|
||||
|
||||
## Worked example
|
||||
|
||||
The best reference to copy from is [`user/pages/01.trips/italy-2026-demo/04.stories/01.sorano-rock-and-time/story.md`](../../user/pages/01.trips/italy-2026-demo/04.stories/01.sorano-rock-and-time/story.md) — it combines `scrolly-section`, `chapter-break` and `pull-quote` in one story.
|
||||
|
||||
```markdown
|
||||
---
|
||||
title: 'Sorano: Rock and Time'
|
||||
date: '2026-09-03'
|
||||
location_name: Sorano
|
||||
location_country: Italy
|
||||
lat: 42.683
|
||||
lng: 11.715
|
||||
hero_image: hero.jpg
|
||||
hero_alt: Medieval town of Sorano clinging to pale tufa cliffs at dusk
|
||||
published: true
|
||||
---
|
||||
|
||||
Opening prose. Renders as a normal reading column.
|
||||
|
||||
[scrolly-section image="hero.jpg" alt="Sorano seen from the approach road" caption="Sorano — tufa cliff town"]
|
||||
First panel over the pinned image.
|
||||
|
||||
---
|
||||
|
||||
Second panel.
|
||||
[/scrolly-section]
|
||||
|
||||
More prose between blocks.
|
||||
|
||||
[chapter-break image="photo-1.jpg" title="After Dark" number="II" alt="Narrow medieval alley at dusk" /]
|
||||
|
||||
[pull-quote image="photo-1.jpg" alt="Stone alley lit by a single lantern"]
|
||||
A town built on rock, carved from rock, returning slowly to rock.
|
||||
[/pull-quote]
|
||||
```
|
||||
|
||||
---
|
||||
|
||||
## Publish
|
||||
|
||||
1. Set **Published** on the Publishing tab
|
||||
2. Optionally set **Featured highlight** to surface it on the homepage between trips
|
||||
3. Push the content:
|
||||
|
||||
```bash
|
||||
make content-push
|
||||
```
|
||||
|
||||
That commits and pushes `user/` to Gitea, which triggers the production pull. See [`deploy-cycle.md`](deploy-cycle.md).
|
||||
|
||||
---
|
||||
|
||||
## The Blocks tab
|
||||
|
||||
The story edit form has a **Blocks** tab holding a paste-ready example of each shortcode plus the comma warning. It's built from `type: spacer` fields in `story.yaml`, whose `text` admin2 renders as HTML (confirmed against admin2 2.0.12 — see its CHANGELOG entry for issue #91).
|
||||
|
||||
If you edit those fields, note two things: the `text` values are YAML double-quoted scalars, so HTML attribute quotes must be escaped (`\"`) — and `<h4>` is flattened by admin2's CSS reset, which is why the headings use `<strong>` in a styled `<p>` instead. Long `<pre>` content needs `white-space:pre-wrap`, or it overflows underneath the Page Info sidebar.
|
||||
|
||||
---
|
||||
|
||||
## Why it's a raw textarea
|
||||
|
||||
The admin2 story editor is a plain markdown field by design-so-far, not by limitation. Background and the options considered: [`docs/research/story-editing.md`](../research/story-editing.md). Note that its conclusion that admin2 cannot host a custom editor is **out of date** — admin-next ships a plugin field-component surface (`admin-next/fields/{type}.js` + `onApiBlueprintResolved`) that the installed api 1.0.9 / admin2 2.0.12 support. Nobody has built it yet.
|
||||
@@ -0,0 +1,203 @@
|
||||
---
|
||||
title: CLAUDE.md content tiering — rules stay, descriptions move out
|
||||
date: 2026-07-24
|
||||
category: conventions
|
||||
module: documentation
|
||||
problem_type: convention
|
||||
component: documentation
|
||||
severity: medium
|
||||
applies_when:
|
||||
- "Deciding whether new content belongs in CLAUDE.md or a docs/ subfolder"
|
||||
- "CLAUDE.md has grown and needs a reduction pass"
|
||||
- "Writing a rule that references specific file paths, bundle names, or other enumerable facts"
|
||||
- "Extracting descriptive content out of CLAUDE.md into docs/reference or docs/guides"
|
||||
tags: [claude-md, documentation-conventions, context-management, staleness, tiering, agent-instructions]
|
||||
---
|
||||
|
||||
# CLAUDE.md content tiering — rules stay, descriptions move out
|
||||
|
||||
## Context
|
||||
|
||||
`CLAUDE.md` at the root of this repo is loaded into every single session, before any file is opened. It had grown to 255 lines of mixed content: rules, stack version numbers, plugin role tables, `make` command tables, folder maps, template hierarchies, and descriptions of how the asset pipeline worked. Nobody had ever asked whether a line earned its place in permanent context.
|
||||
|
||||
Four rounds of work over one session took it to 74 lines. The interesting part was not the size reduction — it was what the audits revealed about *which kinds of sentences go stale*, and the fact that the first honest audit made the file **bigger**.
|
||||
|
||||
| Round | Commit | Lines | What happened |
|
||||
|---|---|---|---|
|
||||
| 1 | `2fbfc88` | 255 → **305** | Audit scored the file 76/100, fixed 4 stale facts, and *added* genuinely missing sections (testing, dev commands, plugin patches) |
|
||||
| 2 | `ed6e43a` | 305 → **179** | Descriptive content extracted to `docs/` |
|
||||
| 3 | `839a4d0` | 179 → **74** (17,057 → 8,544 chars) | Rules-only cut; created `docs/reference/testing.md`, grew `README.md` |
|
||||
| — | `9ec2349` | +52 | `docs/working/README.md` added; the plan-status *rule* stayed in CLAUDE.md, the *explanation* moved out |
|
||||
| 4 | `285e615` | 74 → **74** | Build-output rule restated as an invariant. 3 lines → 3 lines, 156 chars saved. Not a size change — a staleness fix |
|
||||
|
||||
The four stale facts from round 1, verbatim from `2fbfc88`'s commit body:
|
||||
|
||||
- `active_trip: japan-korea-2026` — the committed value was `/trips/denmark-2026` and **no `japan-korea` trip folder existed**
|
||||
- `Admin2 v2.0.10` — installed version was `v2.0.12`
|
||||
- `make demo-load` described as italy-only — the Makefile loops over every fixture under `user/docs/demo/trips/`
|
||||
- the `user/` gitignore claim omitted the three un-ignored site-owned plugins and the secret/`env/` exclusions
|
||||
|
||||
## Guidance
|
||||
|
||||
### 1. Apply the operational test to every line
|
||||
|
||||
> **Does this line change what Claude does on a task where it wouldn't otherwise open the relevant file?**
|
||||
|
||||
If no, it is a *description* — move it to `docs/`. Claude reads the code anyway; prose about the code just drifts alongside it.
|
||||
|
||||
Corollary: **version numbers are pure drift with no behavioral payload.** `Grav 2.0.7`, `Admin2 v2.0.12`, and the GPM-channel paragraph were all dropped. What survived is version-free:
|
||||
|
||||
> The site is Grav (flat-file PHP CMS, no database) in Docker, with content and theme in the `user/` submodule.
|
||||
|
||||
"No database" stays because it *does* change behavior — an agent that believes there is a database goes looking for migrations, an ORM, and a query layer that do not exist.
|
||||
|
||||
### 2. Tier content by when it gets read
|
||||
|
||||
| Content | Home | Why |
|
||||
|---|---|---|
|
||||
| Rules, gotchas, invariants | `CLAUDE.md` | Worthless unless already in context |
|
||||
| How the code works | `docs/reference/` | Claude reads the code anyway; prose drifts |
|
||||
| How to do a task | `docs/guides/` | Read at task start, on demand |
|
||||
| A trap already hit, with symptoms | `docs/solutions/` | Retrieved by symptom, indexed by frontmatter |
|
||||
| Setup, folder map, commands | `README.md` | For humans; Claude has the Makefile |
|
||||
|
||||
CLAUDE.md keeps a six-row entry-point table pointing at each destination — the routing is a rule, the content behind it is not.
|
||||
|
||||
### 3. Gotchas are the one category that cannot be extracted
|
||||
|
||||
Every other content type has a natural trigger that opens the file:
|
||||
|
||||
| Type | Trigger that gets it read |
|
||||
|---|---|
|
||||
| Description | Agent opens the code |
|
||||
| Procedure | Agent starts the task |
|
||||
| Incident write-up | Agent recognizes a symptom |
|
||||
| **Gotcha / exception** | **none — it must already be in context** |
|
||||
|
||||
A file you only open once you suspect an exception exists is a file you open **too late**. A proposed `docs/exceptions/` directory was therefore recommended against. Supporting arithmetic: the whole rules surface is ~40 lines / ~2,200 tokens, so a second file saves ~1k tokens while adding a lookup step, and `docs/solutions/` (indexed by `module` / `tags` / `problem_type`) already fills the read-on-demand role for "have we hit this before?".
|
||||
|
||||
### 4. State invariants, not enumerations
|
||||
|
||||
An enumerated list is falsified by the next addition, silently. An inverted statement of the same fact survives it. This is what `285e615` did — same three lines, no size change, but now staleness-proof.
|
||||
|
||||
### 5. Verify the destination before extracting
|
||||
|
||||
Every extraction target was confirmed to already exist and already cover the topic:
|
||||
|
||||
- pointer bumps and worktree mechanics → `docs/solutions/architecture-patterns/dual-repo-submodule-workflow.md` (already covered them)
|
||||
- the `user/env/<host>/` override tree → `docs/guides/deploy-cycle.md` (already covered it)
|
||||
- source→output asset table → `docs/reference/architecture.md` → "Asset pipeline" (section added to receive it, lines 69-82)
|
||||
- test-suite descriptions → `docs/reference/testing.md` (**created**, 67 lines — no destination existed)
|
||||
- folder map + `make` tables → `README.md` (179 → 227 lines)
|
||||
|
||||
Nothing extracted became homeless. Related fix in the same pass: `docs/working/git-sync-notes.md` pointed at "CLAUDE.md §1", a section number that no longer existed after renumbering — **cross-references into an instruction file must point at stable headings, never numbers.**
|
||||
|
||||
### 6. Know when to stop
|
||||
|
||||
At 74 lines the section sizes were even — Hard rules 9, Dev environment 8, Content and trips 7, Two shared partials 7, Dual-repo submodule 7, Testing 7, Working docs 7, intro + entry-point table 15. No fat pocket remained. Roughly 8 more lines *could* have gone (the `travel-memories` :8082 port, a parenthetical Twig-recompile aside, tightening two bullets) for ~250 tokens out of ~2,200 — while deleting actual rules.
|
||||
|
||||
**The trim is strongly positive while what leaves is descriptions, and turns negative once only rules remain.** Round 3 therefore ended with a "we're at the floor" verdict plus one robustness fix (`285e615`), not another cut.
|
||||
|
||||
## Why This Matters
|
||||
|
||||
**Every stale fact found across all four rounds was a description of code or config. Not one was a rule.** Two of them had been written by Claude itself days earlier. Descriptions drift because the code moves and the prose does not; rules do not drift because they encode intent rather than state. The tiering above is not an aesthetic preference — it is the only conclusion the evidence supports.
|
||||
|
||||
**A wrong path in an always-loaded file is worse than an absent one.** CLAUDE.md claimed the map engine lived at `js/src/maplibre-utils.js`. That file does not exist. The real path is `user/themes/intotheeast/js/maplibre-utils.js` — a hand-authored source sitting *next to* the generated bundles in `js/`, imported by `js/src/map.js` as `../maplibre-utils.js`. The wrong path survived rounds 1 and 2 (`2fbfc88` line 76, `ed6e43a` line 64) and was only fixed in `839a4d0`.
|
||||
|
||||
An absent fact makes an agent go look. A wrong fact makes it act confidently in the wrong place. Here the wrong place was `js/map.js` — a minified esbuild bundle. The failure mode is a hand-edit that survives until the next `make build-assets` silently reverts it.
|
||||
|
||||
This is also the decisive argument against `docs/exceptions/`: **the maplibre-utils mistake happened because the path was wrong, not because it was missing.** Had that rule lived in `docs/exceptions/assets.md`, the bundle would have been hand-edited with the agent never knowing the file existed.
|
||||
|
||||
**What survived the cut is the sanity check on the criterion.** A rule stays when being wrong about it is expensive *and* the correct behavior is not derivable from reading a file:
|
||||
|
||||
- the Admin plugin slug is `admin2`, not `admin` — nothing in the tree announces this before you've already guessed wrong
|
||||
- `plugins.txt` is hand-maintained; installing a plugin via Admin does **not** update it
|
||||
- once `user/env/<hostname>/` exists on a server, Grav's Admin writes **all** config there — system *and* plugin — and env wins, so server config must be read from both trees
|
||||
- `active_trip` is a **route** (`/trips/denmark-2026`), not a bare slug
|
||||
- never re-add a `pageconfig.parent` to `post-form.md` — a static parent overrides the `active_trip`-derived write target and reintroduces a silent-desync bug
|
||||
- the standalone `/dailies`, `/map`, `/stats`, `/stories` trip views were deleted 2026-07-04 and must not be re-created or linked
|
||||
|
||||
Each of those is a landmine an agent steps on *before* it has cause to open the relevant file.
|
||||
|
||||
## When to Apply
|
||||
|
||||
- Auditing or editing any always-loaded instruction file — `CLAUDE.md`, `AGENTS.md`, system prompts, agent definitions
|
||||
- When a stale fact is found in an instruction file: fix it, then ask why that *category* of sentence was there at all
|
||||
- Before adding a line to `CLAUDE.md` — run the operational test first, and route to the tiering table if it fails
|
||||
- Before writing an enumerated list of files, paths, plugins, or bundles into an instruction file — try inverting it into an invariant and verify the inverted form against the actual directory listing
|
||||
- Before extracting content out of an instruction file — confirm the destination exists and covers the topic, or create it in the same commit
|
||||
- When tempted to create a new read-on-demand directory for exceptions or gotchas — don't; they only work in-context
|
||||
- When a reduction pass stops finding descriptions and starts deleting rules — stop and record a floor verdict instead of cutting further
|
||||
|
||||
## Examples
|
||||
|
||||
### Enumerated list → invariant (`285e615`)
|
||||
|
||||
**Before** — 3 lines, falsified by adding a fifth bundle:
|
||||
|
||||
```markdown
|
||||
- **Never hand-edit build output**, and know which files those are — sources and outputs
|
||||
share folders under `user/themes/intotheeast/` (all paths below are relative to it).
|
||||
`make build-assets` is mandatory after editing any source, and it writes:
|
||||
- **Generated (never edit):** `js/main.js`, `js/map.js`, `js/feed-actions.js`,
|
||||
`js/trip-publish.js`, `js/post/`, `css-compiled/`, `fonts/`, and
|
||||
`templates/partials/weather-icons.html.twig`.
|
||||
- **Hand-authored sources:** everything in `js/src/`, plus `js/maplibre-utils.js` and
|
||||
`js/nav.js` (which sit *next to* the bundles in `js/`), `css/style.css`,
|
||||
`css/tokens.css`, and `scripts/gen-weather-icons.js`.
|
||||
```
|
||||
|
||||
**After** — 3 lines, 156 chars shorter, still true after the next bundle is added:
|
||||
|
||||
```markdown
|
||||
- **Never hand-edit build output** — sources and outputs share folders under
|
||||
`user/themes/intotheeast/` (paths below are relative to it), so know which is which.
|
||||
Run `make build-assets` after editing any source.
|
||||
- Everything in `js/` is **generated** *except* `js/src/`, `js/maplibre-utils.js` and `js/nav.js`.
|
||||
- `css-compiled/` and `fonts/` are generated (sources: `css/style.css`, `css/tokens.css`);
|
||||
so is `templates/partials/weather-icons.html.twig` (source: `scripts/gen-weather-icons.js`).
|
||||
```
|
||||
|
||||
Verification that made this safe: `ls js/` returns exactly the 4 bundles + `post/` + `maplibre-utils.js` + `nav.js` + `src/`. The inverted form is exactly true today and stays true as bundles are added. The full enumerated source→output table now lives in `docs/reference/architecture.md` → "Asset pipeline", where drift is cheap because the table is read next to the code it describes.
|
||||
|
||||
### Description → extracted; rule → kept
|
||||
|
||||
**Before** (round 1 addition, later cut) — a description of the build, in permanent context:
|
||||
|
||||
```markdown
|
||||
**`make build-assets` is mandatory after editing anything in
|
||||
`user/themes/intotheeast/js/src/`.** Sources live in `js/src/`; esbuild writes the
|
||||
committed bundles — `js/main.js`, `js/map.js`, `js/feed-actions.js`,
|
||||
`js/trip-publish.js`, `js/post/`, and the CSS extracted into `css-compiled/`.
|
||||
**Never hand-edit those.** By contrast `css/style.css` and `css/tokens.css` are
|
||||
hand-authored sources, not build outputs. `build-assets` runs as your host UID
|
||||
(`--user`) so the outputs in the bind-mounted `user/` tree are not root-owned.
|
||||
```
|
||||
|
||||
**After** — the `--user` mechanism and the esbuild pipeline moved to `docs/reference/architecture.md` line 71; only the never-edit rule and the source/output discriminator remain in `CLAUDE.md`.
|
||||
|
||||
### Wrong path → right path (`839a4d0`)
|
||||
|
||||
```diff
|
||||
-The engine is `MapUtils.initEntryMap(opts)` in `js/src/maplibre-utils.js`.
|
||||
+the engine is `MapUtils.initEntryMap(opts)` in `js/maplibre-utils.js`
|
||||
+(a hand-authored file, imported by `js/src/map.js`)
|
||||
```
|
||||
|
||||
`js/src/maplibre-utils.js` never existed. The parenthetical is not padding — it is the whole reason the rule is in an always-loaded file: `js/` is the bundle directory, so a hand-authored source living there is exactly the fact an agent cannot infer.
|
||||
|
||||
### Rule stays, explanation leaves (`9ec2349`)
|
||||
|
||||
The plan-status convention needed both a machine-actionable rule and a human-readable explanation of the five states. They went to different files:
|
||||
|
||||
- `CLAUDE.md` keeps the one-line rule — every plan needs a `**Status:**` line immediately after its title, plus what to surface when asked what's open, plus set `✅ Complete (YYYY-MM-DD)` before closing a session
|
||||
- `docs/working/README.md` (52 lines) holds the explanation of the states, the directory layout, and the human-facing reference
|
||||
|
||||
Same convention, split by *when each half needs to be in context*.
|
||||
|
||||
## Related
|
||||
|
||||
- [`docs/README.md`](../../README.md) — the existing "always-loaded rules → CLAUDE.md" vs "stable facts → reference/" split that this learning sharpens into an actionable test
|
||||
- [`docs/working/plans/2026-06-21-documentation-restructure.md`](../../working/plans/2026-06-21-documentation-restructure.md) — the prior restructure that created the extraction destinations (`reference/architecture.md` and siblings) this pass relied on and re-applied
|
||||
- [`docs/solutions/integration-issues/stale-grav-version-blocks-api-plugin-install.md`](../integration-issues/stale-grav-version-blocks-api-plugin-install.md) — sibling instance of version numbers rotting, in the deploy-config domain rather than the instruction-file domain
|
||||
- [`docs/reference/architecture.md`](../../reference/architecture.md) → "Asset pipeline" — where the enumerated source→output table now lives
|
||||
@@ -11,7 +11,22 @@ execution: code
|
||||
|
||||
# Post Form Location Override - Plan
|
||||
|
||||
**Status:** 📋 Not started
|
||||
**Status:** ✅ Complete (2026-07-24) — U1–U6 shipped, then hardened by a multi-agent code review the same day. The review found the design's stated server-side safety net (`cleanCoordinate()`) had never been committed, so it landed here; replaced a prefix-parsing coordinate check that accepted `48abc` / `48,85` / `35.0116S` (hemisphere silently flipped); closed three paths that bypassed the submit gate (draft restore, edit-mode prefill, map-load failure) because the gate read a CSS class no code set at init; added pin removal on blanked fields; made the geocode failure visible; and rewrote the U5 guard spec, which asserted only instantly-passing conditions and so could not fail. R8 and R13 above are revised accordingly.
|
||||
|
||||
**Verified by a green run (2026-07-24).** The suite now executes end-to-end: `test-config` 22/22, `test-post` 6/6 (the `scripts/test-post.sh` shell suite — *not* the Playwright specs under `tests/ui/post/`, which is a separate set), and `location-override.spec.js` **20/20** — so the verifications below are no longer by inspection alone. Reaching that took fixing `make test-account` (the password was interpolated into an `sh -c` string, so a shell metacharacter in it killed every UI run), pinning `test-ui` to this checkout's own port, and repairing test cleanup, which had never been able to delete the root-owned entries Grav's Apache creates. See the commit `fix(test): close the test-entry leak into real trip content`.
|
||||
|
||||
Also landed after the review: maplibre's stylesheet is now lazy-`<link>`ed at panel-open instead of statically bundled, cutting `post-form.css` from 92,244 to 26,784 raw bytes (14,528 → 5,631 gzip) on every `/post` load, with a new spec asserting both halves of that boundary.
|
||||
|
||||
**Merged to `main` 2026-07-24** — `user/` at `dd19995`, outer at `4450bd6`, pin bumped. On merged `main`: `test-config` **22/22** and `tests/ui/post/` + `tests/ui/map` **69 passed / 1 failed** (DEL4 only, a pre-existing regression unrelated to this feature — see below). `user/` is still **unpushed by choice**; push `user/` first, then the outer repo.
|
||||
|
||||
**Notes carried forward:**
|
||||
- The `user/` submodule commits remain **unpushed by choice** (git-sync would deploy to prod). Merged to `main` locally on 2026-07-24 and the pin bumped; pushing `user/` — then the outer repo, in that order — is the remaining step and is deliberately left to the user to time.
|
||||
- **DEL4 is a real, pre-existing regression and the one thing still red on `main`** (`tests/ui/post/delete-flow.spec.js:44`, reproducible in isolation). Deleting an entry works: the card leaves the DOM and the folder leaves disk (both asserted and both pass). But a fresh load of the trip page makes the server re-emit the card — an image-less ghost of a page whose content is gone. That is precisely the bug the spec's own header says was already fixed once, so the invalidation has regressed. `cache-on-save` clears the page-tree cache on form *submit*; the delete path evidently does not do the equivalent. Practical impact: delete a bad post from the road, reload, and it is back. Worth its own branch.
|
||||
- ~~This worktree's `user/` branch has diverged from `user/`'s `main`~~ **Done** — `user/main` merged in (`7903432`). It was ahead on both content and theme fixes; `denmark-2026 published: true` came with it, so the local testing flip is gone. The one conflict was `js/post/post-form.js`, a generated bundle, resolved by rebuilding rather than hand-merging minified output.
|
||||
- ~~The `~/Projects` clone's `user/` carries two commits this clone cannot see~~ **Done** — merged in (`8a5cc52`). There is no second clone: `~/Projects` is a symlink to `~/Nextcloud/Projects`. What differs is the **submodule git dir** — a worktree gets `.git/worktrees/<name>/modules/user`, not the checkout's `.git/modules/user` — so `user/main` read `4721af6` here while the checkout's read `285ae37`, and the leg-connection map fix and U+200E strip were unreachable until a local `git fetch` between the two paths. Worth remembering: submodule commits made from the main checkout do not appear in a worktree until fetched, and a local fetch carries them without a push, so git-sync never fires.
|
||||
- **Retracted: the "`owner_username` cluster" diagnosis was wrong.** The worktree showed 6 failures (AN2, DEL1–4, ES1) and they were attributed to `site.yaml` pinning `owner_username: mischa` while the suite authenticates as `testrunner`. On merged `main` only DEL4 fails, with byte-identical `site.yaml` and content — so auth was not the cause. The difference is environmental: the isolated worktree's `user/plugins/` was incomplete (missing `admin`, `markdown-notices`, `migrate-grav`, since `plugins/` is git-ignored and populated per-checkout by `make install-plugins`). Lesson: treat a worktree's UI failures as suspect until reproduced in the main checkout, because the worktree's plugin set is not guaranteed to match.
|
||||
- ~~Every `make` target aborts with `.env:6: *** missing separator`~~ **Fixed by the user (2026-07-24)** — `make` now parses in the checkout. Worth keeping in mind: the env layering is intentional (`.env` global, `-include .env.$(ENV)` per-environment, `ENV` set by the generated env-suffixed remote targets like `make remote-install-prod`), but because `.env` is pulled in with `-include` it must be valid **makefile** syntax as well as valid dotenv — so a leading tab, a multi-line value, or a line without `=` takes down every target at once. Worktrees mask it, since `worktree-new` creates no `.env` and the include silently skips.
|
||||
- **UG1, UG2 and LD1 under `tests/ui/post/` now pass** — they had been failing only because this branch predated `e17a5dc` ("block submit on unfinished photo uploads; un-squeeze EXIF portraits in lightbox"). Merging `user/main` in brought the upload gate and the oriented-derivative slide dims those specs assert, and all three went green with no product change. A first pass mistook them for live defects; the lesson is to check the submodule branch point before reading a red spec on a feature branch as a real bug.
|
||||
|
||||
## Goal Capsule
|
||||
|
||||
@@ -45,7 +60,7 @@ The only way to set a coordinate today is the GPS button (reads live position) o
|
||||
- R5. Lookup is explicit-click only. While in flight, the button shows a disabled "Searching…" state that always re-enables on response, no-match, or network failure.
|
||||
- R6. Clicking with both City and Country empty is treated as a no-match: an inline hint asks for a city or country first, and no request is sent.
|
||||
- R7. Multiple matches render as a clickable list (place name, admin region, country), built via `document.createElement` + `.textContent` (no `innerHTML`), matching every other dynamic-content construction already in `post-form.js`. Clicking an entry sets `lat`/`lng` and the pin only — it never writes back to City/Country. The list hides again until the next lookup.
|
||||
- R8. No matches renders an inline hint suggesting a country or manual pin drag; a network failure degrades silently (fields untouched), consistent with the existing reverse-geocode/weather error handling in `post-form.js`.
|
||||
- R8. No matches renders an inline hint suggesting a country or manual pin drag; a network failure (or a non-2xx response) leaves the fields untouched and renders a *distinct* inline hint naming the connection as the problem. **Revised in code review 2026-07-24** from "degrades silently" — silence was indistinguishable from a broken button, and the two failure modes need different messages.
|
||||
|
||||
**Map preview & sync**
|
||||
- R9. A single MapLibre GL map with one draggable marker (≥44×44px touch target) renders in the panel, reusing the site's existing style URL (`MAP_STYLE`, extracted to a shared `user/themes/intotheeast/js/src/map-style.js` module per KTD1). The map instance is created once, on the panel's first open, held in module scope, and reused (with an explicit `.resize()` call) on every subsequent open — the container sits under `display:none` while closed, so the first paint would otherwise get a zero-size canvas.
|
||||
@@ -54,7 +69,7 @@ The only way to set a coordinate today is the GPS button (reads live position) o
|
||||
- R12. No pin is shown until one of the four paths above sets a value for the first time.
|
||||
|
||||
**Error handling & validation boundary**
|
||||
- R13. Invalid manual `lat`/`lng` text is never client-blocked — the visual mismatch flag (R11) is the only feedback. Final enforcement stays server-side in `cleanCoordinate()`, which already throws on a non-blank, still-invalid value after cleaning.
|
||||
- R13. Invalid manual `lat`/`lng` text raises the visual mismatch flag (R11), **and** an unresolved flag blocks submit. **Revised in code review 2026-07-24** from "never client-blocked". The original wording deferred all enforcement to a server-side `cleanCoordinate()` described as already shipped — it was not committed anywhere, so no layer validated coordinates. It now ships in `cache-on-save.php` (both the `/post` form and the Admin2/API save paths) and the client gate stays, giving real defence in depth. The client parse is intentionally stricter than the server's `is_numeric` (whole-value decimals only, so `48,85` / `35.0116S` / `48abc` are rejected rather than prefix-parsed).
|
||||
- R14. Geolocation permission denial keeps its existing, unmodified `#location-status` error behavior.
|
||||
|
||||
### Scope Boundaries
|
||||
|
||||
@@ -64,8 +64,8 @@ Backend sanitization has already been added (`user/plugins/cache-on-save/cache-o
|
||||
### Error handling
|
||||
|
||||
- No search results: inline message under the search box, map/pin untouched.
|
||||
- Search network failure: silent-ish degrade (consistent with existing weather/reverse-geocode error handling in `post-form.js`), fields untouched.
|
||||
- Invalid manual `lat`/`lng` text: no client-side hard block (the map preview and eventual server-side `cleanCoordinate()` are the safety nets); this UI's whole point is to make that failure mode rare in practice, not to duplicate the backend validator client-side.
|
||||
- Search network failure: fields untouched, and an inline hint says the lookup service could not be reached (distinct from the no-results message, which means the service answered). **Revised in code review 2026-07-24** — this originally said "silent-ish degrade", which in practice left the DOM byte-identical to the pre-click state, so a traveller on flaky mobile data could not tell a failed lookup from a broken button. A non-2xx response is also now treated as a failure rather than parsed as an empty result set.
|
||||
- Invalid manual `lat`/`lng` text: the visual mismatch flag is the primary feedback, **and** an unresolved flag blocks submit. **Revised in code review 2026-07-24** — this originally said "no client-side hard block", on the stated grounds that server-side `cleanCoordinate()` was already the safety net. It was not: `cleanCoordinate()` had never been committed, so nothing validated coordinates anywhere. It now ships (`cache-on-save.php`, both the `/post` and Admin2 paths), so the two are genuine defence in depth rather than one imaginary net. Client-side parsing is deliberately *stricter* than the server's `is_numeric` (whole-value decimals only), which is the safe direction for a mismatch.
|
||||
- Geolocation permission denied: unchanged existing behavior (`#location-status` error message).
|
||||
|
||||
## Out of scope / explicitly deferred
|
||||
|
||||
@@ -59,7 +59,10 @@ check_grep "location_country field present" "name: location_country"
|
||||
check_grep "weather_desc field present" "name: weather_desc"
|
||||
check_grep "weather_temp_c field present" "name: weather_temp_c"
|
||||
check_grep "transport_mode field present" "name: transport_mode"
|
||||
check_grep "hero_image field present" "name: hero_image"
|
||||
# No hero_image assertion: the field was deliberately dropped in 8cf1145 —
|
||||
# entries render their hero from the first photo, so an explicit filename was
|
||||
# redundant (see the comment at that spot in post-form.md). This check outlived
|
||||
# the field and had been failing ever since.
|
||||
check_grep "force_connect field present" "name: force_connect"
|
||||
check_grep "featured field present" "name: featured"
|
||||
|
||||
|
||||
@@ -2,6 +2,58 @@ const fs = require('fs');
|
||||
const path = require('path');
|
||||
const { execSync } = require('child_process');
|
||||
|
||||
/**
|
||||
* Fail fast if the server under test does not serve the `user/` tree the specs
|
||||
* read from disk.
|
||||
*
|
||||
* This mismatch is silent and destructive. Every post spec submits through the
|
||||
* live form (the write target is derived server-side from site.yaml
|
||||
* `active_trip`, so there is no per-request override), then asserts and cleans up
|
||||
* on disk via helpers' USER_DIR. Run the specs from a worktree whose own
|
||||
* container is down and baseURL falls back to localhost:8081 — the MAIN
|
||||
* checkout — so entries get created in one content tree while cleanup deletes
|
||||
* from another. The entries are then left behind in real trip content, which is
|
||||
* exactly what happened on 2026-07-24.
|
||||
*
|
||||
* Docker is the only thing that knows the mapping, so this is best-effort: if we
|
||||
* cannot determine it we warn and continue rather than blocking non-Docker runs.
|
||||
* But when we CAN determine it and it disagrees, that is always a bug.
|
||||
*/
|
||||
function assertServerServesUserDir(baseURL, userDir) {
|
||||
const port = new URL(baseURL).port || '80';
|
||||
let mountedUserDir;
|
||||
try {
|
||||
const container = execSync("docker ps --format '{{.Names}}\t{{.Ports}}'", { encoding: 'utf-8' })
|
||||
.split('\n').filter(Boolean)
|
||||
.find(l => l.includes(`:${port}->`));
|
||||
if (!container) {
|
||||
console.warn(`[setup] no running container publishes port ${port} — is the dev server up? (make start)`);
|
||||
return;
|
||||
}
|
||||
const name = container.split('\t')[0];
|
||||
mountedUserDir = execSync(
|
||||
`docker inspect ${name} --format '{{range .Mounts}}{{if eq .Destination "/var/www/html/user"}}{{.Source}}{{end}}{{end}}'`,
|
||||
{ encoding: 'utf-8', stdio: ['pipe', 'pipe', 'ignore'] }
|
||||
).trim();
|
||||
if (!mountedUserDir) return; // no bind mount to compare against
|
||||
} catch (_) {
|
||||
return; // docker unavailable — nothing to check
|
||||
}
|
||||
|
||||
const served = fs.realpathSync(mountedUserDir);
|
||||
const asserted = fs.realpathSync(userDir);
|
||||
if (served !== asserted) {
|
||||
throw new Error(
|
||||
`Test target mismatch — refusing to run.\n` +
|
||||
` baseURL ${baseURL} is served from: ${served}\n` +
|
||||
` but the specs read/clean up: ${asserted}\n` +
|
||||
`Entries would be created in one tree and cleanup would miss them, leaving\n` +
|
||||
`test entries behind in real content. Start this checkout's own server\n` +
|
||||
`(make start) and point the run at it, e.g. GRAV_BASE_URL=http://localhost:<port>.`
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = async function globalSetup() {
|
||||
const envFile = path.join(__dirname, '../.env');
|
||||
if (fs.existsSync(envFile)) {
|
||||
@@ -23,4 +75,9 @@ module.exports = async function globalSetup() {
|
||||
|
||||
// Ensure demo content is loaded (italy-2026-demo trip + stories + GPX files)
|
||||
execSync('make demo-load', { cwd: path.join(__dirname, '..'), stdio: 'inherit' });
|
||||
|
||||
// Required last: helpers.js resolves USER_DIR at require time, and the .env
|
||||
// load above can supply GRAV_USER_DIR.
|
||||
const { USER_DIR } = require('./ui/helpers');
|
||||
assertServerServesUserDir(process.env.GRAV_BASE_URL || 'http://localhost:8081', USER_DIR);
|
||||
};
|
||||
|
||||
+32
-45
@@ -1,57 +1,44 @@
|
||||
const fs = require('fs');
|
||||
const path = require('path');
|
||||
const { execSync } = require('child_process');
|
||||
|
||||
function resolveUserDir() {
|
||||
if (process.env.GRAV_USER_DIR) return process.env.GRAV_USER_DIR;
|
||||
try {
|
||||
const raw = execSync(
|
||||
"docker inspect intotheeast_grav --format '{{range .Mounts}}{{if eq .Destination \"/var/www/html/user\"}}{{.Source}}{{end}}{{end}}'",
|
||||
{ encoding: 'utf-8', stdio: ['pipe', 'pipe', 'ignore'] }
|
||||
).trim();
|
||||
if (raw) return raw;
|
||||
} catch (_) {}
|
||||
return path.join(__dirname, '../user');
|
||||
}
|
||||
// Reuse the specs' own resolution rather than reimplementing it. The previous
|
||||
// version of this file derived the dailies directory from a `parent:` key in
|
||||
// pages/02.post/post-form.md — a key that was deliberately removed (the write
|
||||
// target is injected server-side from site.yaml `active_trip`, and CLAUDE.md
|
||||
// forbids re-adding a static parent). The regex therefore never matched,
|
||||
// dailiesDir was always null, and the dailies sweep below silently did nothing.
|
||||
// That is how ui-test entries survived into the active trip's content.
|
||||
// removeEntryDir handles the root-owned case by deleting through the container —
|
||||
// see its comment. Plain fs.rmSync cannot remove what Grav's Apache wrote.
|
||||
const { USER_DIR, TRACKER_DIR, removeEntryDir } = require('./ui/helpers');
|
||||
|
||||
function sweepUiTestEntries(dir) {
|
||||
if (!fs.existsSync(dir)) return 0;
|
||||
const entries = fs.readdirSync(dir).filter(e => e.includes('ui-test'));
|
||||
entries.forEach(e => fs.rmSync(path.join(dir, e), { recursive: true, force: true }));
|
||||
return entries.length;
|
||||
if (!dir || !fs.existsSync(dir)) return 0;
|
||||
const found = fs.readdirSync(dir).filter(e => e.includes('ui-test'));
|
||||
let removed = 0;
|
||||
found.forEach(e => {
|
||||
const target = path.join(dir, e);
|
||||
try {
|
||||
removeEntryDir(target);
|
||||
removed++;
|
||||
} catch (err) {
|
||||
// Loud, not silent — a swallowed failure here is exactly what let a
|
||||
// ui-test entry survive into the active trip's content.
|
||||
console.error(`[teardown] COULD NOT REMOVE ${target}: ${err.message}`);
|
||||
}
|
||||
});
|
||||
return removed;
|
||||
}
|
||||
|
||||
module.exports = async function globalTeardown() {
|
||||
const userDir = resolveUserDir();
|
||||
|
||||
// Read active trip slug from post-form.md
|
||||
const postFormPath = path.join(userDir, 'pages/02.post/post-form.md');
|
||||
let dailiesDir = null;
|
||||
if (fs.existsSync(postFormPath)) {
|
||||
const content = fs.readFileSync(postFormPath, 'utf-8');
|
||||
const m = content.match(/parent:\s*['"]?\/trips\/([^/'"]+)\/dailies/);
|
||||
if (m) {
|
||||
const tripSlug = m[1];
|
||||
const tripsBase = path.join(userDir, 'pages/01.trips');
|
||||
const tripFolder = fs.readdirSync(tripsBase).find(
|
||||
f => f === tripSlug || f.endsWith('.' + tripSlug) || f.includes(tripSlug)
|
||||
);
|
||||
if (tripFolder) {
|
||||
const dailiesBase = path.join(tripsBase, tripFolder);
|
||||
const dailiesFolder = fs.readdirSync(dailiesBase).find(
|
||||
f => f === 'dailies' || f === '01.dailies' || f.endsWith('.dailies')
|
||||
);
|
||||
if (dailiesFolder) dailiesDir = path.join(dailiesBase, dailiesFolder);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Sweep both the post inbox and the active trip's dailies
|
||||
const postInbox = path.join(userDir, 'pages/02.post');
|
||||
const n1 = sweepUiTestEntries(postInbox);
|
||||
const n2 = dailiesDir ? sweepUiTestEntries(dailiesDir) : 0;
|
||||
// Sweep both the post inbox and the active trip's dailies.
|
||||
const n1 = sweepUiTestEntries(path.join(USER_DIR, 'pages/02.post'));
|
||||
const n2 = sweepUiTestEntries(TRACKER_DIR);
|
||||
|
||||
if (n1 + n2 > 0) {
|
||||
console.log(`[teardown] removed ${n1} ui-test entries from 02.post, ${n2} from dailies`);
|
||||
console.log(
|
||||
`[teardown] removed ${n1} ui-test entries from 02.post, ` +
|
||||
`${n2} from ${path.relative(USER_DIR, TRACKER_DIR)}`
|
||||
);
|
||||
}
|
||||
};
|
||||
|
||||
+59
-2
@@ -170,6 +170,60 @@ async function createPhotoEntry(page, tag, { content, publish = true, created }
|
||||
'Entry posted successfully!', { timeout: 15_000 });
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve the Grav container that serves USER_DIR, so cleanup can delete as root.
|
||||
* Prefers GRAV_CONTAINER (set by .worktree-env / .env), else matches on the bind
|
||||
* mount so a worktree never picks the main checkout's container.
|
||||
*/
|
||||
function resolveGravContainer() {
|
||||
if (process.env.GRAV_CONTAINER) return process.env.GRAV_CONTAINER;
|
||||
try {
|
||||
const want = fs.realpathSync(USER_DIR);
|
||||
const names = execSync("docker ps --format '{{.Names}}'", { encoding: 'utf-8', stdio: ['pipe', 'pipe', 'ignore'] })
|
||||
.split('\n').filter(Boolean);
|
||||
return names.find((n) => {
|
||||
const src = execSync(
|
||||
`docker inspect ${n} --format '{{range .Mounts}}{{if eq .Destination "/var/www/html/user"}}{{.Source}}{{end}}{{end}}'`,
|
||||
{ encoding: 'utf-8', stdio: ['pipe', 'pipe', 'ignore'] }
|
||||
).trim();
|
||||
return src && fs.realpathSync(src) === want;
|
||||
}) || null;
|
||||
} catch (_) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Delete an entry directory, falling back to the container when the host cannot.
|
||||
*
|
||||
* Grav's Apache workers run as root, so every entry the form creates is
|
||||
* root-owned. Removing one recursively needs write permission on that directory,
|
||||
* which the host user does not have — so a plain fs.rmSync throws EACCES and the
|
||||
* entry survives. That is how a ui-test entry ended up committed-adjacent in the
|
||||
* active trip's content on 2026-07-24: cleanup had never actually worked for
|
||||
* form-created entries, it just failed inside a path nothing checked.
|
||||
*
|
||||
* `docker exec … rm -rf` runs as root in the container, which can remove them.
|
||||
*/
|
||||
function removeEntryDir(dir) {
|
||||
try {
|
||||
fs.rmSync(dir, { recursive: true });
|
||||
return true;
|
||||
} catch (err) {
|
||||
if (err.code !== 'EACCES' && err.code !== 'EPERM') throw err;
|
||||
}
|
||||
const container = resolveGravContainer();
|
||||
if (!container) {
|
||||
throw new Error(
|
||||
`Cannot remove ${dir}: it is root-owned (written by Grav in the container) and no ` +
|
||||
`matching container was found to delete it as root. Set GRAV_CONTAINER or remove it manually.`
|
||||
);
|
||||
}
|
||||
execSync(`docker exec ${container} rm -rf '/var/www/html/user/${path.relative(USER_DIR, dir)}'`,
|
||||
{ stdio: ['pipe', 'pipe', 'pipe'] });
|
||||
return true;
|
||||
}
|
||||
|
||||
/**
|
||||
* Find a tracker entry folder by a unique slug fragment, then delete it.
|
||||
*/
|
||||
@@ -179,7 +233,7 @@ function cleanupEntry(slugFragment) {
|
||||
const entries = fs.readdirSync(TRACKER_DIR);
|
||||
const match = entries.find(e => e.includes(slugFragment));
|
||||
if (match) {
|
||||
fs.rmSync(path.join(TRACKER_DIR, match), { recursive: true });
|
||||
removeEntryDir(path.join(TRACKER_DIR, match));
|
||||
}
|
||||
}
|
||||
|
||||
@@ -202,4 +256,7 @@ function readEntryMd(entryDir) {
|
||||
return fs.readFileSync(path.join(entryDir, name), 'utf-8');
|
||||
}
|
||||
|
||||
module.exports = { fillEditor, waitForPhotoUpload, postEntry, createPhotoEntry, cleanupEntry, findEntry, readEntryMd, TEST_PHOTO, TRACKER_DIR, ACTIVE_TRIP_URL };
|
||||
// USER_DIR is exported so global-setup/global-teardown resolve the same tree the
|
||||
// specs assert against, instead of keeping their own (previously divergent) copy
|
||||
// of this logic.
|
||||
module.exports = { fillEditor, waitForPhotoUpload, postEntry, createPhotoEntry, cleanupEntry, removeEntryDir, findEntry, readEntryMd, TEST_PHOTO, USER_DIR, TRACKER_DIR, ACTIVE_TRIP_URL };
|
||||
|
||||
@@ -9,6 +9,10 @@
|
||||
// display EXIF-rotated. For a stored-landscape portrait photo the attrs said
|
||||
// landscape while the pixels rendered portrait → PhotoSwipe squeezed them.
|
||||
//
|
||||
// Fixed in e17a5dc: slides now link a 2000px fit-within derivative and measure
|
||||
// THAT file, and derivatives are re-encoded upright, so the attrs and the
|
||||
// rendered pixels agree.
|
||||
//
|
||||
// The invariant tested here is environment-proof: whatever file the slide
|
||||
// links to, its browser-rendered natural size must equal the data-pswp-*
|
||||
// attrs. (Whether the photo ALSO displays upright depends on the server's
|
||||
@@ -24,10 +28,14 @@ const { test, expect } = require('@playwright/test');
|
||||
const path = require('path');
|
||||
const fs = require('fs');
|
||||
const { execSync } = require('child_process');
|
||||
// USER_DIR comes from helpers so GRAV_USER_DIR is honoured — without it a run
|
||||
// against a checkout detached from the served tree plants the fixture in a
|
||||
// different user/ than Grav renders, and LD1 fails as an opaque "card never
|
||||
// appeared" timeout.
|
||||
const { USER_DIR } = require('../helpers');
|
||||
|
||||
// Stored 800x600 with EXIF Orientation=6: browsers render it 600x800 portrait.
|
||||
const EXIF_PORTRAIT = path.join(__dirname, '../../fixtures/test-photo-exif-portrait.jpg');
|
||||
const USER_DIR = path.join(__dirname, '../../../user');
|
||||
const DEMO_DAILIES = path.join(USER_DIR, 'pages/01.trips/italy-2026-demo/01.dailies');
|
||||
const DEMO_TRIP_URL = '/trips/italy-2026-demo';
|
||||
|
||||
|
||||
@@ -0,0 +1,404 @@
|
||||
// @ts-check
|
||||
// Tests: post form "More location details" — search-by-city lookup + draggable
|
||||
// map pin preview for setting an entry's coordinates without live GPS.
|
||||
// Covers R4-R14. The Open-Meteo geocoding endpoint is mocked via page.route()
|
||||
// so this suite is hermetic (no live third-party call, no rate-limit flakiness).
|
||||
const { test, expect } = require('@playwright/test');
|
||||
const path = require('path');
|
||||
const { fillEditor, waitForPhotoUpload, cleanupEntry, findEntry, readEntryMd, TEST_PHOTO } = require('../helpers');
|
||||
|
||||
const GEOCODE_URL = '**/geocoding-api.open-meteo.com/v1/search**';
|
||||
|
||||
const created = [];
|
||||
test.afterAll(() => { created.forEach(cleanupEntry); });
|
||||
|
||||
// Real-API-shaped fixtures (verified live against geocoding-api.open-meteo.com).
|
||||
const KYOTO_RESULTS = {
|
||||
results: [
|
||||
{ name: 'Kyoto', latitude: 35.0116, longitude: 135.7681, admin1: 'Kyoto Prefecture', country: 'Japan' }
|
||||
]
|
||||
};
|
||||
|
||||
// Mirrors the design doc's verified live Paris query: Île-de-France (France)
|
||||
// first from the API, then five US states — Texas among them, in admin1 (the
|
||||
// API's `country` field is "United States" for all of the US matches, so the
|
||||
// ranking must also check admin1 to disambiguate on a US state name).
|
||||
const PARIS_RESULTS = {
|
||||
results: [
|
||||
{ name: 'Paris', latitude: 48.85341, longitude: 2.3488, admin1: 'Île-de-France Region', country: 'France' },
|
||||
{ name: 'Paris', latitude: 33.66094, longitude: -95.55551, admin1: 'Texas', country: 'United States' },
|
||||
{ name: 'Paris', latitude: 36.302, longitude: -88.32671, admin1: 'Tennessee', country: 'United States' },
|
||||
{ name: 'Paris', latitude: 38.2098, longitude: -84.2529, admin1: 'Kentucky', country: 'United States' },
|
||||
{ name: 'Paris', latitude: 39.6112, longitude: -87.6961, admin1: 'Illinois', country: 'United States' }
|
||||
]
|
||||
};
|
||||
|
||||
function mockGeocode(page, body) {
|
||||
return page.route(GEOCODE_URL, (route) => route.fulfill({
|
||||
status: 200,
|
||||
contentType: 'application/json',
|
||||
body: JSON.stringify(body)
|
||||
}));
|
||||
}
|
||||
|
||||
async function openLocationDetails(page) {
|
||||
await page.locator('.location-details__summary').click();
|
||||
await expect(page.locator('.location-details')).toHaveJSProperty('open', true);
|
||||
}
|
||||
|
||||
// ── Panel closed by default (R1) ────────────────────────────────────────────
|
||||
test('More location details is closed by default and holds the relocated lat/lng fields', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
const details = page.locator('.location-details');
|
||||
await expect(details).toBeAttached();
|
||||
await expect(details).toHaveJSProperty('open', false);
|
||||
await expect(page.locator('.location-details input[name="data[lat]"]')).toBeAttached();
|
||||
await expect(page.locator('.location-details input[name="data[lng]"]')).toBeAttached();
|
||||
});
|
||||
|
||||
// ── R6: empty City + Country sends no request ───────────────────────────────
|
||||
test('R6: clicking lookup with City and Country both empty sends no request', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
let requested = false;
|
||||
await page.route(GEOCODE_URL, (route) => { requested = true; route.abort(); });
|
||||
await openLocationDetails(page);
|
||||
await page.click('#lookup-coords');
|
||||
await expect(page.locator('#location-search-hint')).toContainText(/city or country/i);
|
||||
expect(requested).toBe(false);
|
||||
});
|
||||
|
||||
// ── R7: a search result sets lat/lng only, never City/Country ──────────────
|
||||
test('R7: clicking a search result sets lat/lng and leaves City/Country untouched', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await mockGeocode(page, KYOTO_RESULTS);
|
||||
await page.fill('input[name="data[location_city]"]', 'Kyoto');
|
||||
await openLocationDetails(page);
|
||||
await page.click('#lookup-coords');
|
||||
|
||||
const results = page.locator('.location-search-results li button');
|
||||
await expect(results).toHaveCount(1);
|
||||
await results.first().click();
|
||||
|
||||
await expect(page.locator('input[name="data[lat]"]')).toHaveValue('35.011600');
|
||||
await expect(page.locator('input[name="data[lng]"]')).toHaveValue('135.768100');
|
||||
await expect(page.locator('input[name="data[location_city]"]')).toHaveValue('Kyoto');
|
||||
await expect(page.locator('input[name="data[location_country]"]')).toHaveValue('');
|
||||
// R7: the list hides again until the next lookup.
|
||||
await expect(page.locator('.location-search-results li')).toHaveCount(0);
|
||||
});
|
||||
|
||||
// ── R4/KTD2: Paris/Texas disambiguation ranks the Texas match first ─────────
|
||||
test('disambiguation: City "Paris" + Country "Texas" ranks the Texas match first', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
let requestedUrl = null;
|
||||
await page.route(GEOCODE_URL, (route) => {
|
||||
requestedUrl = route.request().url();
|
||||
route.fulfill({ status: 200, contentType: 'application/json', body: JSON.stringify(PARIS_RESULTS) });
|
||||
});
|
||||
await page.fill('input[name="data[location_city]"]', 'Paris');
|
||||
await page.fill('input[name="data[location_country]"]', 'Texas');
|
||||
await openLocationDetails(page);
|
||||
await page.click('#lookup-coords');
|
||||
|
||||
const results = page.locator('.location-search-results li button');
|
||||
await expect(results).toHaveCount(5);
|
||||
await expect(results.first()).toContainText('Texas');
|
||||
|
||||
// R4: Country is never concatenated into the query string.
|
||||
expect(requestedUrl).toContain('name=Paris');
|
||||
expect(requestedUrl).not.toContain('Texas');
|
||||
});
|
||||
|
||||
// ── R8: no matches shows the inline hint, fields untouched ─────────────────
|
||||
test('R8: no matches shows the no-match hint and leaves fields untouched', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await mockGeocode(page, { results: [] });
|
||||
await page.fill('input[name="data[location_city]"]', 'Nowheresville');
|
||||
await openLocationDetails(page);
|
||||
await page.click('#lookup-coords');
|
||||
|
||||
await expect(page.locator('#location-search-hint')).toContainText(/no matches/i);
|
||||
await expect(page.locator('input[name="data[lat]"]')).toHaveValue('');
|
||||
await expect(page.locator('input[name="data[lng]"]')).toHaveValue('');
|
||||
});
|
||||
|
||||
// ── R5: in-flight state shows "Searching…" and always re-enables ───────────
|
||||
test('R5: the lookup button shows a disabled "Searching…" state while in flight', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await page.route(GEOCODE_URL, async (route) => {
|
||||
await new Promise((r) => setTimeout(r, 400));
|
||||
route.fulfill({ status: 200, contentType: 'application/json', body: JSON.stringify(KYOTO_RESULTS) });
|
||||
});
|
||||
await page.fill('input[name="data[location_city]"]', 'Kyoto');
|
||||
await openLocationDetails(page);
|
||||
await page.click('#lookup-coords');
|
||||
|
||||
const btn = page.locator('#lookup-coords');
|
||||
await expect(btn).toBeDisabled();
|
||||
await expect(btn).toHaveText('Searching…');
|
||||
await expect(btn).toBeEnabled({ timeout: 5_000 });
|
||||
await expect(btn).toContainText('Look up coordinates');
|
||||
});
|
||||
|
||||
// ── R8: a network failure degrades silently and re-enables the button ──────
|
||||
test('a network failure degrades silently, leaves fields untouched, and re-enables the button', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await page.route(GEOCODE_URL, (route) => route.abort('failed'));
|
||||
await page.fill('input[name="data[location_city]"]', 'Kyoto');
|
||||
await openLocationDetails(page);
|
||||
await page.click('#lookup-coords');
|
||||
|
||||
await expect(page.locator('#lookup-coords')).toBeEnabled();
|
||||
await expect(page.locator('input[name="data[lat]"]')).toHaveValue('');
|
||||
await expect(page.locator('input[name="data[lng]"]')).toHaveValue('');
|
||||
});
|
||||
|
||||
// ── XSS safety: an API-sourced name containing markup renders as literal text ──
|
||||
test('a result name containing markup renders as literal text, not executed', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await mockGeocode(page, {
|
||||
results: [{ name: '<img src=x onerror="window.__xss=true">', latitude: 1, longitude: 2, country: 'Nowhere' }]
|
||||
});
|
||||
await page.fill('input[name="data[location_city]"]', 'Test');
|
||||
await openLocationDetails(page);
|
||||
await page.click('#lookup-coords');
|
||||
|
||||
const btn = page.locator('.location-search-results li button').first();
|
||||
await expect(btn).toContainText('<img src=x onerror="window.__xss=true">');
|
||||
expect(await btn.evaluate((el) => el.querySelector('img'))).toBeNull();
|
||||
expect(await page.evaluate(() => window.__xss)).toBeUndefined();
|
||||
});
|
||||
|
||||
// ── U4: map renders exactly one canvas, no pin until a coordinate is set ───
|
||||
test('opening the panel renders exactly one map canvas with no initial pin', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await openLocationDetails(page);
|
||||
await expect(page.locator('#location-map canvas.maplibregl-canvas')).toHaveCount(1, { timeout: 10_000 });
|
||||
await expect(page.locator('#location-map .maplibregl-marker')).toHaveCount(0);
|
||||
});
|
||||
|
||||
// ── U4: reopening does not duplicate the canvas; resize keeps it non-zero ──
|
||||
test('reopening the panel a second time leaves exactly one canvas with non-zero size', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await openLocationDetails(page);
|
||||
await page.locator('.location-details__summary').click(); // close
|
||||
await expect(page.locator('.location-details')).toHaveJSProperty('open', false);
|
||||
await openLocationDetails(page); // reopen
|
||||
|
||||
const canvases = page.locator('#location-map canvas.maplibregl-canvas');
|
||||
await expect(canvases).toHaveCount(1, { timeout: 10_000 });
|
||||
const box = await canvases.first().boundingBox();
|
||||
expect(box && box.width).toBeGreaterThan(0);
|
||||
expect(box && box.height).toBeGreaterThan(0);
|
||||
});
|
||||
|
||||
// ── R11: a search pick shows a pin on the map ───────────────────────────────
|
||||
test('a search-result pick renders a pin on the map', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await mockGeocode(page, KYOTO_RESULTS);
|
||||
await page.fill('input[name="data[location_city]"]', 'Kyoto');
|
||||
await openLocationDetails(page);
|
||||
await page.click('#lookup-coords');
|
||||
await page.locator('.location-search-results li button').first().click();
|
||||
|
||||
await expect(page.locator('#location-map .maplibregl-marker')).toHaveCount(1, { timeout: 10_000 });
|
||||
});
|
||||
|
||||
// ── R11: dragging the marker updates lat/lng (rounded to 6dp) ──────────────
|
||||
test('dragging the pin updates lat/lng to the drop location', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await mockGeocode(page, KYOTO_RESULTS);
|
||||
await page.fill('input[name="data[location_city]"]', 'Kyoto');
|
||||
await openLocationDetails(page);
|
||||
await page.click('#lookup-coords');
|
||||
await page.locator('.location-search-results li button').first().click();
|
||||
|
||||
const marker = page.locator('#location-map .maplibregl-marker');
|
||||
await expect(marker).toHaveCount(1, { timeout: 10_000 });
|
||||
const before = await page.locator('input[name="data[lat]"]').inputValue();
|
||||
|
||||
// setPin()'s map.panTo() animates the marker into view — wait for it to
|
||||
// settle so the bounding box grabbed below matches where the marker will
|
||||
// actually be when the mouse events land.
|
||||
await page.waitForTimeout(800);
|
||||
const box = await marker.boundingBox();
|
||||
if (!box) throw new Error('marker has no bounding box');
|
||||
const startX = box.x + box.width / 2;
|
||||
const startY = box.y + box.height / 2;
|
||||
await page.mouse.move(startX, startY);
|
||||
await page.mouse.down();
|
||||
await page.mouse.move(startX + 40, startY + 30, { steps: 5 });
|
||||
await page.mouse.up();
|
||||
|
||||
await expect(async () => {
|
||||
const after = await page.locator('input[name="data[lat]"]').inputValue();
|
||||
expect(after).not.toBe(before);
|
||||
expect(after).toMatch(/^-?\d+\.\d{6}$/);
|
||||
}).toPass({ timeout: 5_000 });
|
||||
});
|
||||
|
||||
// ── R11/R13: typing an invalid value flags the field without crashing ──────
|
||||
test('typing an invalid lat value shows the mismatch flag and clears once fixed', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await openLocationDetails(page);
|
||||
|
||||
const latEl = page.locator('input[name="data[lat]"]');
|
||||
const lngEl = page.locator('input[name="data[lng]"]');
|
||||
await latEl.fill('not-a-number');
|
||||
await lngEl.fill('135.7681');
|
||||
await lngEl.blur();
|
||||
|
||||
await expect(latEl).toHaveClass(/location-field--mismatch/);
|
||||
await expect(latEl).toHaveAttribute('aria-invalid', 'true');
|
||||
await expect(page.locator('#location-map .maplibregl-marker')).toHaveCount(0);
|
||||
|
||||
await latEl.fill('35.0116');
|
||||
await latEl.blur();
|
||||
await expect(latEl).not.toHaveClass(/location-field--mismatch/);
|
||||
await expect(page.locator('#location-map .maplibregl-marker')).toHaveCount(1);
|
||||
});
|
||||
|
||||
// ── U4: rapid close/reopen while the maplibre-gl chunk is still in flight must
|
||||
// not build two Map instances against the same container (code-review fix) ──
|
||||
test('rapid close/reopen before the maplibre-gl chunk resolves still leaves exactly one canvas', async ({ page }) => {
|
||||
await page.route('**/*maplibre-gl*.js', async (route) => {
|
||||
await new Promise((resolve) => setTimeout(resolve, 500));
|
||||
await route.continue();
|
||||
});
|
||||
await page.goto('/post');
|
||||
|
||||
// Open, then immediately close and reopen — both toggles land while the
|
||||
// delayed chunk request above is still pending.
|
||||
await page.locator('.location-details__summary').click();
|
||||
await page.locator('.location-details__summary').click();
|
||||
await page.locator('.location-details__summary').click();
|
||||
await expect(page.locator('.location-details')).toHaveJSProperty('open', true);
|
||||
|
||||
await expect(page.locator('#location-map canvas.maplibregl-canvas')).toHaveCount(1, { timeout: 10_000 });
|
||||
});
|
||||
|
||||
// ── U5: blanking both fields after a mismatch was flagged clears the flag ──
|
||||
test('blanking both lat/lng fields after a mismatch clears the flag', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
await openLocationDetails(page);
|
||||
|
||||
const latEl = page.locator('input[name="data[lat]"]');
|
||||
const lngEl = page.locator('input[name="data[lng]"]');
|
||||
await latEl.fill('not-a-number');
|
||||
await lngEl.blur();
|
||||
await expect(latEl).toHaveClass(/location-field--mismatch/);
|
||||
|
||||
await latEl.fill('');
|
||||
await lngEl.fill('');
|
||||
await lngEl.blur();
|
||||
await expect(latEl).not.toHaveClass(/location-field--mismatch/);
|
||||
await expect(lngEl).not.toHaveClass(/location-field--mismatch/);
|
||||
});
|
||||
|
||||
// ── U5: a flagged, unresolved lat/lng must block submit (code-review fix) ──
|
||||
test('submitting with an unresolved lat/lng mismatch is blocked', async ({ page }) => {
|
||||
const tag = `loc-mismatch-${Date.now()}`;
|
||||
await page.goto('/post');
|
||||
await page.fill('input[name="data[title]"]', `UI Test ${tag}`);
|
||||
await fillEditor(page, 'Location-override mismatch-blocks-submit guard. Safe to delete.');
|
||||
await page.locator('input.filepond--browser').setInputFiles(TEST_PHOTO);
|
||||
await waitForPhotoUpload(page);
|
||||
|
||||
await openLocationDetails(page);
|
||||
const latEl = page.locator('input[name="data[lat]"]');
|
||||
const lngEl = page.locator('input[name="data[lng]"]');
|
||||
await latEl.fill('999');
|
||||
await lngEl.fill('999');
|
||||
await lngEl.blur();
|
||||
await expect(latEl).toHaveClass(/location-field--mismatch/);
|
||||
|
||||
// Register for cleanup BEFORE the click: if the gate ever regresses, the
|
||||
// entry lands on disk and the afterAll hook must still see the tag.
|
||||
created.push(tag);
|
||||
await page.locator('.btn-post').evaluate((el) => el.click());
|
||||
|
||||
// `.notices` toHaveCount(0) and toHaveURL(/\/post/) both pass instantly and
|
||||
// both also hold for a SUCCESSFUL submit (the form posts to /post and only
|
||||
// renders its notice after the round trip), so neither can distinguish a
|
||||
// working gate from a regressed one. Prove the negative on disk instead,
|
||||
// after giving a regressed submit time to actually write.
|
||||
await page.waitForTimeout(2000);
|
||||
expect(findEntry(tag), 'a flagged coordinate must never reach the server').toBeFalsy();
|
||||
// And prove the block was the gate's doing: still flagged, value untouched.
|
||||
await expect(latEl).toHaveClass(/location-field--mismatch/);
|
||||
await expect(latEl).toHaveValue('999');
|
||||
});
|
||||
|
||||
// ── U4: lazy-load boundary — an ordinary GPS-only submit never fetches maplibre-gl ──
|
||||
// The URL pattern deliberately covers BOTH halves of the lazy boundary: the JS
|
||||
// chunk (js/post/maplibre-gl-*.js) and the stylesheet
|
||||
// (css-compiled/maplibre-gl.css, <link>ed by location-map.js at panel-open —
|
||||
// see its ensureMaplibreCss). Neither may be requested when the panel stays shut.
|
||||
test('an ordinary submit without opening the panel never fetches the maplibre-gl chunk', async ({ page }) => {
|
||||
const chunkRequests = [];
|
||||
page.on('request', (req) => {
|
||||
if (/maplibre-gl/.test(req.url())) chunkRequests.push(req.url());
|
||||
});
|
||||
|
||||
const tag = `loc-nomap-${Date.now()}`;
|
||||
await page.goto('/post');
|
||||
await page.fill('input[name="data[title]"]', `UI Test ${tag}`);
|
||||
await fillEditor(page, 'Location-override lazy-load guard. Safe to delete.');
|
||||
await page.locator('input.filepond--browser').setInputFiles(TEST_PHOTO);
|
||||
await waitForPhotoUpload(page);
|
||||
await page.locator('.btn-post').evaluate((el) => el.click());
|
||||
await expect(page.locator('.notices')).toContainText('Entry posted successfully!', { timeout: 15_000 });
|
||||
created.push(tag);
|
||||
|
||||
expect(chunkRequests, 'neither the maplibre-gl chunk nor its stylesheet may be fetched when the panel is never opened').toHaveLength(0);
|
||||
});
|
||||
|
||||
// ── The other half of that boundary: opening the panel DOES apply the vendor CSS ──
|
||||
// Without this, the guard above could keep passing while the stylesheet silently
|
||||
// stopped loading at all (a broken href, a missed build step), leaving the map
|
||||
// unstyled with nothing to catch it. Asserts the <link> exists AND parsed —
|
||||
// link.sheet is null until the browser has actually applied it.
|
||||
test('opening the panel lazily links maplibre\'s stylesheet and applies it', async ({ page }) => {
|
||||
await page.goto('/post');
|
||||
|
||||
const hrefBefore = await page.evaluate(() => Array.from(document.styleSheets)
|
||||
.map((s) => s.href || '').filter((h) => /maplibre-gl\.css/.test(h)));
|
||||
expect(hrefBefore, 'the vendor stylesheet must not be present before the panel opens').toHaveLength(0);
|
||||
|
||||
await openLocationDetails(page);
|
||||
await expect(page.locator('#location-map canvas.maplibregl-canvas')).toHaveCount(1, { timeout: 10_000 });
|
||||
|
||||
await expect.poll(
|
||||
() => page.evaluate(() => {
|
||||
const link = Array.from(document.querySelectorAll('link[rel="stylesheet"]'))
|
||||
.find((l) => /maplibre-gl\.css/.test(l.href));
|
||||
return link ? link.sheet !== null : false;
|
||||
}),
|
||||
{ message: 'maplibre\'s stylesheet must be linked and applied once the panel opens', timeout: 10_000 }
|
||||
).toBe(true);
|
||||
});
|
||||
|
||||
// ── Full submit: a search-picked location round-trips into the frontmatter ──
|
||||
test('a full submit with a search-picked location saves the expected lat/lng', async ({ page }) => {
|
||||
const tag = `loc-submit-${Date.now()}`;
|
||||
await page.goto('/post');
|
||||
await mockGeocode(page, KYOTO_RESULTS);
|
||||
await page.fill('input[name="data[title]"]', `UI Test ${tag}`);
|
||||
await fillEditor(page, 'Location-override submit test. Safe to delete.');
|
||||
await page.fill('input[name="data[location_city]"]', 'Kyoto');
|
||||
await openLocationDetails(page);
|
||||
await page.click('#lookup-coords');
|
||||
await page.locator('.location-search-results li button').first().click();
|
||||
|
||||
await page.locator('input.filepond--browser').setInputFiles(TEST_PHOTO);
|
||||
await waitForPhotoUpload(page);
|
||||
await page.locator('.btn-post').evaluate((el) => el.click());
|
||||
await expect(page.locator('.notices')).toContainText('Entry posted successfully!', { timeout: 15_000 });
|
||||
created.push(tag);
|
||||
|
||||
const entryDir = findEntry(tag);
|
||||
expect(entryDir, 'Entry folder should exist on disk').toBeTruthy();
|
||||
const md = readEntryMd(entryDir);
|
||||
expect(md).toContain('35.0116');
|
||||
expect(md).toContain('135.7681');
|
||||
});
|
||||
@@ -12,6 +12,12 @@
|
||||
// silent-data-loss path.
|
||||
// post-form.js owns the complete gate (theme code; the form plugin is
|
||||
// GPM-managed and not patchable in-repo).
|
||||
//
|
||||
// The gate lives in e17a5dc: submit is blocked unless EVERY FilePond item is
|
||||
// processing-complete, with distinct messages for the failed and still-uploading
|
||||
// cases. Both assert on .photo-convert-status, which post-form.js's setStatus()
|
||||
// creates via photoStatusEl() — so a passing expectation here proves the THEME
|
||||
// gate fired, not the form plugin's, whose own guard only raises alert().
|
||||
const { test, expect } = require('@playwright/test');
|
||||
const { fillEditor, findEntry, cleanupEntry, TEST_PHOTO } = require('../helpers');
|
||||
|
||||
|
||||
@@ -1,5 +1,5 @@
|
||||
// @ts-check
|
||||
// Tests: S1–S7 — story mode rendering and navigation
|
||||
// Tests: S1–S9 — story mode rendering and navigation
|
||||
// Requires demo data: run `make demo-load` before this suite.
|
||||
const { test, expect } = require('@playwright/test');
|
||||
|
||||
@@ -85,3 +85,74 @@ test('S7: story body back link has back-pill class', async ({ page }) => {
|
||||
await expect(bodyBack).toBeAttached();
|
||||
await expect(bodyBack).toHaveText(/← Back/);
|
||||
});
|
||||
|
||||
// ── S8: Scrolly-section text panels actually render beside the pinned image ───
|
||||
// The server ships the panel text inside .scrolly__steps-content, which CSS hides
|
||||
// (style.css: `display: none`). Only the inline Scrollama block in story.html.twig
|
||||
// splits it into visible .scrolly-step divs — and it early-returns silently if the
|
||||
// main.js bundle (which sets window.scrollama) hasn't executed yet. S3 asserted the
|
||||
// image column exists; nothing asserted the text column was non-empty.
|
||||
test('S8: scrolly-section builds visible step panels from its slot content', async ({ page }) => {
|
||||
await page.goto(STORY_SCROLLY);
|
||||
await expect(page.locator('.story-hero__img')).toBeVisible({ timeout: 8000 });
|
||||
|
||||
// The bundle must have published scrollama before the inline block ran
|
||||
expect(
|
||||
await page.evaluate(() => typeof window.scrollama !== 'undefined'),
|
||||
'window.scrollama published by main.js bundle'
|
||||
).toBe(true);
|
||||
|
||||
// Every scrolly-section must have produced at least one step
|
||||
const sections = page.locator('.scrolly');
|
||||
const sectionCount = await sections.count();
|
||||
expect(sectionCount, 'Two scrolly-sections').toBe(2);
|
||||
|
||||
for (let i = 0; i < sectionCount; i++) {
|
||||
const section = sections.nth(i);
|
||||
const steps = section.locator('.scrolly-step');
|
||||
expect(
|
||||
await steps.count(),
|
||||
`scrolly-section ${i} split its slot content into steps`
|
||||
).toBeGreaterThan(0);
|
||||
}
|
||||
|
||||
// …and the text must be readable, not left hidden in the raw slot.
|
||||
// Scroll each step into view so its reveal transition completes.
|
||||
const firstStep = page.locator('.scrolly').first().locator('.scrolly-step').first();
|
||||
await firstStep.scrollIntoViewIfNeeded();
|
||||
await page.waitForTimeout(800);
|
||||
await expect(firstStep.locator('.scrolly-step__inner')).toBeVisible();
|
||||
const text = (await firstStep.innerText()).trim();
|
||||
expect(text.length, 'First step panel renders non-empty text').toBeGreaterThan(20);
|
||||
});
|
||||
|
||||
// ── S9: Back-to-top is wired once, by main.js, and pushes a history entry ─────
|
||||
// The inline duplicate in story.html.twig was removed; initBackToTop() in
|
||||
// js/src/main.js now solely owns #story-totop. That makes the button depend on
|
||||
// the bundle having loaded, so assert the observable behaviour end to end.
|
||||
test('S9: story back-to-top reveals on scroll, returns to top, and pushes history', async ({ page }) => {
|
||||
await page.goto(STORY_SCROLLY);
|
||||
await expect(page.locator('.story-hero__img')).toBeVisible({ timeout: 8000 });
|
||||
|
||||
const btn = page.locator('#story-totop');
|
||||
await expect(btn).toBeAttached();
|
||||
|
||||
// Hidden until scrolled past the 0.8 * viewport threshold
|
||||
await expect(btn).not.toHaveClass(/is-visible/);
|
||||
|
||||
const historyBefore = await page.evaluate(() => history.length);
|
||||
|
||||
await page.evaluate(() => window.scrollTo(0, window.innerHeight * 2));
|
||||
await expect(btn).toHaveClass(/is-visible/, { timeout: 3000 });
|
||||
|
||||
await btn.click();
|
||||
await expect
|
||||
.poll(() => page.evaluate(() => window.scrollY), { timeout: 3000 })
|
||||
.toBeLessThan(10);
|
||||
|
||||
// main.js's variant pushes a history entry; the removed inline copy did not
|
||||
expect(
|
||||
await page.evaluate(() => history.length),
|
||||
'Back-to-top pushed a history entry'
|
||||
).toBeGreaterThan(historyBefore);
|
||||
});
|
||||
|
||||
@@ -3,5 +3,8 @@
|
||||
{
|
||||
"path": "."
|
||||
}
|
||||
]
|
||||
],
|
||||
"settings": {
|
||||
"makefile.configureOnOpen": false
|
||||
}
|
||||
}
|
||||
+1
-1
Submodule user updated: 02fa4e94a7...1b9e51baf7
Reference in New Issue
Block a user