Store tests (21 tests):
- Session: create, validate, delete, delete-all, expiry
- Signup requests: create, duplicate, list pending, approve
(creates user with must-reset), reject, double-approve/reject
- Existing: user CRUD, auth, fave CRUD, tags, pagination
Middleware tests (9 tests):
- Real IP extraction from trusted/untrusted proxies
- Base path stripping (with prefix, empty prefix)
- Rate limiter (per-IP, exhaustion, different IPs)
- Panic recovery (returns 500)
- Security headers (CSP, X-Frame-Options, etc.)
- RequireLogin redirect
- MustResetPasswordGuard (static path passthrough)
Handler integration tests (14 tests):
- Health endpoint
- Login page rendering, successful login, wrong password
- Fave list requires auth, works when authenticated
- Private fave hidden from other users, visible to owner
- Admin panel requires admin role, works for admin
- Tag search endpoint
- Global Atom feed
- Public profile with display name
- Limited profile hides bio
Also fixes template bugs: profile.html and fave_detail.html used
$.IsOwner which fails inside {{with}} blocks ($ = root PageData,
not .Data map). Fixed with $d variable capture pattern.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
74 lines
2.7 KiB
HTML
74 lines
2.7 KiB
HTML
{{define "head"}}
|
|
{{with .Data}}{{with .Fave}}
|
|
{{if eq .Privacy "public"}}
|
|
<meta property="og:title" content="{{truncate 70 .Description}}">
|
|
<meta property="og:description" content="En favoritt av {{.DisplayName}} på {{$.SiteName}}">
|
|
<meta property="og:type" content="article">
|
|
{{if $.ExternalURL}}
|
|
<meta property="og:url" content="{{$.ExternalURL}}/faves/{{.ID}}">
|
|
{{if .ImagePath}}
|
|
<meta property="og:image" content="{{$.ExternalURL}}/uploads/{{.ImagePath}}">
|
|
<meta name="twitter:card" content="summary_large_image">
|
|
{{else}}
|
|
<meta name="twitter:card" content="summary">
|
|
{{end}}
|
|
{{end}}
|
|
<meta property="og:site_name" content="{{$.SiteName}}">
|
|
{{range .Tags}}
|
|
<meta property="article:tag" content="{{.Name}}">
|
|
{{end}}
|
|
{{end}}
|
|
{{end}}{{end}}
|
|
{{end}}
|
|
|
|
{{define "content"}}
|
|
{{with .Data}}
|
|
{{$d := .}}
|
|
<article>
|
|
{{with .Fave}}
|
|
{{if .ImagePath}}
|
|
<img src="{{basePath}}/uploads/{{.ImagePath}}"
|
|
alt="Bilde for: {{.Description}}">
|
|
{{end}}
|
|
|
|
<header>
|
|
<h1>{{.Description}}</h1>
|
|
<p>
|
|
Av <a href="{{basePath}}/u/{{.Username}}">{{.DisplayName}}</a>
|
|
{{if eq .Privacy "private"}}
|
|
— <small class="badge-private" aria-label="Privat">Privat</small>
|
|
{{end}}
|
|
</p>
|
|
</header>
|
|
|
|
{{if .URL}}
|
|
<p><a href="{{.URL}}" target="_blank" rel="noopener noreferrer">{{.URL}}</a></p>
|
|
{{end}}
|
|
|
|
{{if .Tags}}
|
|
<p>
|
|
{{range .Tags}}
|
|
<a href="{{basePath}}/tags/{{.Name}}" class="tag-chip">{{.Name}}</a>
|
|
{{end}}
|
|
</p>
|
|
{{end}}
|
|
|
|
<footer>
|
|
<small>Lagt til {{.CreatedAt.Format "02.01.2006"}}</small>
|
|
{{if $d.IsOwner}}
|
|
<nav class="fave-actions">
|
|
<a href="{{basePath}}/faves/{{.ID}}/edit" role="button" class="outline">Rediger</a>
|
|
<button
|
|
hx-delete="{{basePath}}/faves/{{.ID}}"
|
|
hx-confirm="Er du sikker på at du vil slette denne favoritten?"
|
|
hx-headers='{"X-CSRF-Token": "{{$.CSRFToken}}"}'
|
|
class="outline secondary"
|
|
data-redirect="{{basePath}}/faves"
|
|
>Slett</button>
|
|
</nav>
|
|
{{end}}
|
|
</footer>
|
|
{{end}}
|
|
</article>
|
|
{{end}}
|
|
{{end}}
|