aboutsummaryrefslogtreecommitdiff
path: root/webmentions_ssg (unfollow)
Commit message (Collapse)Author
2026-08-20docs(core): add docstrings and type annotationsDennis Fink
Document forms, validators, models, and views with PEP 287-style docstrings and complete missing type annotations. Add developer-readable representations for Webmention models and mark the user password property as write-only in its return type.
2026-08-20chore(core): standardize SPDX copyright headersDennis Fink
Add SPDX copyright and license headers to source, test, migration, template, and static files throughout the project. Include the maintainer email in copyright notices and fill in the BSD license copyright holder.
2026-08-19refactor(core): improve typing and test coverageDennis Fink
Restructure database and user CLI commands, make passwords write-only model properties, and use the UTC datetime constant throughout the application. Add PEP 287-style documentation and expand receiver, scanner, sender, and URL security tests to cover error paths and edge cases.
2026-08-17feat(sender): add manual source rescan actionDennis Fink
Add an authenticated action to queue a source rescan from the sent Webmentions overview. Extract the reusable confirmation modal and its JavaScript so received and sent admin actions share the same implementation.
2026-08-16feat(sender): improve sent webmention status displayDennis Fink
Highlight source and Webmention rows based on their current state and use badges for clearer status and activity indicators. Make discovered endpoints and status URLs clickable in the detail view.
2026-08-16refactor(core): remove user credential length limitsDennis Fink
Store usernames and password hashes as text instead of fixed-length strings so their maximum length is not constrained by the database schema. Require every user to have a password hash.
2026-08-15feat(sender): add outgoing Webmention pipelineDennis Fink
Scan generated h-entry documents for Webmention targets and track source revisions and delivery state in the database. Discover target endpoints, send Webmentions asynchronously, and reconcile updated, removed, restored, and deleted sources across scans. Add authenticated views for inspecting sent Webmentions and make the scanner schedule configurable.
2026-08-10feat(core): add received webmention admin actionsDennis Fink
Add authenticated delete and reverify actions to the received webmentions admin view and protect them with CSRF validation. Enable CSRF protection globally while exempting the public Webmention endpoint.
2026-08-10fix(receiver): prevent requests to non-public addressesDennis Fink
Resolve source hostnames before fetching and reject addresses that are not globally routable to prevent SSRF against local or private services. Repeat the check for every HTTP request so redirects cannot bypass the initial source validation. Treat DNS resolution failures during verification as temporary fetch errors.
2026-08-09Implement received Webmention handlingDennis Fink
Add the Flask application setup, database models and migrations, authentication, and configuration for development and testing. Implement asynchronous Webmention verification with Huey, including HTML and plain-text source validation, retries, status tracking, and size limits. Add status, login, and paginated received-Webmention views together with comprehensive tests for forms, views, and receiver tasks.
2026-08-09Implement received Webmention handlingDennis Fink
Add the Flask application setup, database models and migrations, authentication, and configuration for development and testing. Implement asynchronous Webmention verification with Huey, including HTML and plain-text source validation, retries, status tracking, and size limits. Add status, login, and paginated received-Webmention views together with comprehensive tests for forms, views, and receiver tasks.