A43 (les 4 items sont clos) :
- `__CSRF_PLACEHOLDER__` supprimé : ContextVar CSRF_TOKEN posée par
CSRFMiddleware avant call_next (même mécanique que le nonce CSP),
global `{{ csrf_token() }}` dans templating, base.html rend
`{"X-CSRF-Token":{{ csrf_token()|tojson }}}` — vide si cookie absent,
`htmx:configRequest` re-lit le cookie à chaque appel → plus jamais de
jeton factice servi.
- Palette : `fetch('/api/search…')` SANS header (GET ∈ SAFE_METHODS →
CSRF inapplicable) — le JSON.parse du body-attr par frappe disparaît.
- utcnow déprécié = 0 dans app/**.py ; health loggé (A25) + booléens db/
gitea = raison ; probe réseau = voulu (test de connectivité).
A38 phase 1 (CSRF unifié) :
- `window.getCsrf()` unique dans le <head> de base.html.
- 76 lectures brutes du cookie → getCsrf() dans 13 fichiers (47 formes
`(…||[])[1]||''`, 25 déclarations `const X = match(…)` avec conversion
de leurs usages `X?X[1]:''` → `X` (noms collectés PAR FICHIER, jamais
de règle globale), 4 formes espacées).
- Définitions dupliquées supprimées : card_detail.html (multi-lignes),
database_table.js (1 ligne dans IIFE → chute sur le global).
- Les 3 variantes de base.html (IIFE getCsrf + 2 getCsrfToken) →
`return getCsrf()`.
- welcome.html garde sa lecture locale (page autonome sans base) ;
reste exactement 1 raw dans base.html (la déf head) + 2 dans welcome.
Test : test_csrf_server_rendered_no_placeholder (pas de placeholder +
token du hx-headers == cookie csrf_token).
suite **1092/1092** · ruff OK · node --check vert · docs à jour
97 lines
3.8 KiB
HTML
97 lines
3.8 KiB
HTML
{% extends "base.html" %}
|
|
{% block page_icon %}{{ fd_icon("trash",18) }}{% endblock %}
|
|
{% block page_title %}Trash{% endblock %}
|
|
{% block title_prefix %}Trash{% endblock %}
|
|
|
|
{% block content %}
|
|
<div class="page-title-area">
|
|
<div class="page-title">
|
|
<span class="page-icon-lg">{{ fd_icon("trash",24) }}</span>
|
|
<h1>Trash</h1>
|
|
</div>
|
|
</div>
|
|
|
|
<div x-data="trashData()" style="padding: 0 24px; max-width: 800px;">
|
|
<!-- Search -->
|
|
<div style="position:relative; margin-bottom:12px;">
|
|
<span style="position:absolute; left:12px; top:50%; transform:translateY(-50%); color:var(--text-dim);">{{ fd_icon("search",14) }}</span>
|
|
<input type="text" placeholder="Search pages in Trash" x-model="search"
|
|
style="width:100%; padding:8px 12px 8px 36px; background:var(--bg-tertiary); border:1px solid var(--border); border-radius:6px; color:var(--text-primary); font-size:14px; outline:none; box-sizing:border-box;">
|
|
</div>
|
|
|
|
<!-- Filters -->
|
|
<div style="display:flex; gap:8px; margin-bottom:16px;">
|
|
<button class="trash-filter active">
|
|
<span style="color:var(--accent);">{{ fd_icon("user",14) }}</span> Last edited by ▾
|
|
</button>
|
|
<button class="trash-filter">
|
|
<span>{{ fd_icon("folder",14) }}</span> In ▾
|
|
</button>
|
|
</div>
|
|
|
|
<!-- Items -->
|
|
<div style="min-height:200px;">
|
|
<template x-for="item in filteredItems" :key="item.id">
|
|
<div class="trash-item">
|
|
<span class="trash-item-icon" x-text="item.icon"></span>
|
|
<div class="trash-item-info">
|
|
<span class="trash-item-name" x-text="item.name"></span>
|
|
<span class="trash-item-path" x-text="item.path"></span>
|
|
</div>
|
|
<button class="trash-item-btn" title="Restore" @click="restore(item.id)">
|
|
↩️
|
|
</button>
|
|
<button class="trash-item-btn" title="Delete permanently" @click="deleteForever(item.id)">
|
|
{{ fd_icon("trash",14) }}
|
|
</button>
|
|
</div>
|
|
</template>
|
|
<div x-show="filteredItems.length === 0" class="lib-empty">
|
|
<div style="font-size:48px;margin-bottom:16px;">{{ fd_icon("trash",14) }}</div>
|
|
<h3>Trash is empty</h3>
|
|
<p>Deleted pages will appear here for 30 days.</p>
|
|
</div>
|
|
</div>
|
|
|
|
<!-- Info -->
|
|
<div style="padding:12px 16px; margin-top:16px; background:var(--bg-tertiary); border-radius:8px; font-size:13px; color:var(--text-dim); display:flex; align-items:center; gap:8px;">
|
|
<span>Once a page has been in Trash for 30 days, it will be automatically deleted</span>
|
|
<span style="font-size:16px;">ⓘ</span>
|
|
</div>
|
|
</div>
|
|
{% endblock %}
|
|
|
|
{% block scripts %}
|
|
<script data-cfasync="false" nonce="{{ csp_nonce() }}">
|
|
function trashData() {
|
|
return {
|
|
search: '',
|
|
items: [],
|
|
async init() {
|
|
const csrf = getCsrf();;
|
|
const token = csrf;
|
|
try {
|
|
const r = await fetch('/board/api/trash', { headers: { 'X-CSRF-Token': token } });
|
|
this.items = await r.json();
|
|
} catch(e) { this.items = []; }
|
|
},
|
|
get filteredItems() {
|
|
const q = this.search.toLowerCase();
|
|
return this.items.filter(i => !q || i.name.toLowerCase().includes(q) || (i.path||'').toLowerCase().includes(q));
|
|
},
|
|
async restore(id) {
|
|
const csrf = getCsrf();;
|
|
const r = await fetch(`/board/api/trash/${id}/restore`, { method: 'POST', headers: { 'X-CSRF-Token': csrf?.[1] || '' } });
|
|
if (r.ok) { this.items = this.items.filter(i => i.id !== id); }
|
|
},
|
|
async deleteForever(id) {
|
|
if (!confirm('Permanently delete this page? This cannot be undone.')) return;
|
|
const csrf = getCsrf();;
|
|
const r = await fetch(`/board/api/trash/${id}`, { method: 'DELETE', headers: { 'X-CSRF-Token': csrf?.[1] || '' } });
|
|
if (r.ok) { this.items = this.items.filter(i => i.id !== id); }
|
|
}
|
|
};
|
|
}
|
|
</script>
|
|
{% endblock %}
|