Skip to content

0.8.0-rc.2: complete restyle, mobile collections and catalogue fixes - #462

Open
fabiodalez-dev wants to merge 50 commits into
mainfrom
release/0.8.0-rc.1
Open

fabiodalez-dev wants to merge 50 commits into
mainfrom
release/0.8.0-rc.1

Conversation

@fabiodalez-dev

@fabiodalez-dev fabiodalez-dev commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Prepares PHP 0.8.0-rc.2 with the complete current Pinakes #458 branch and the coordinated server contracts consumed by Android #41 (1.6.0/17). The already published rc.1 tag/assets are retained; this PR now prepares the next candidate on the existing release branch.

Includes the 2026 public/account restyle, all subsequent review fixes, responsive navigation and accessible themes, complete artwork and readable missing-cover bindings. Reconciles Uwe's catalogue, publisher, genre, language, article/PDF, citation, digital-file and archive-search requests. Adds authenticated Archives and library Desiderata, verified-account donation proposals with consent, account-scoped deduplication/recovery, and complete analytic article/book responses. The changelog records the entire final scope.

Backend dependencies shipped together: Mobile API 1.5.0, Desiderata 1.2.0, Emeroteca 1.13.0 and Archives 1.5.1. Desiderata's plugin upgrade adds nullable mobile user/request/hash fields and an account/request unique index; it is additive and idempotent. Run the normal updater/plugin upgrade before testing Android's new collections. Administrative editing remains on protected PHP pages.

Validation on the functional source: 50 collection database checks, 191 Emeroteca checks, 9 HTTP contracts, 36 targeted browser regressions, 17 PHP suites and PHPStan level 5. Android passed 185 unit/19 Compose tests and debug/R8 builds with zero lint errors. All 35 current CI checks pass on candidate head 2fa76a1e33126c9caf1f9e5cdcd49bd545177c2c, including worktree packaging and all browser regression shards. CodeRabbit’s aggregate review limitation is recorded below. The Uwe matrix and browser/Android QA evidence are committed under docs/reviews/.

The PR remains open; no tag or release publication is performed by this update. FBI/DBC #52 requires external access and is not implemented; QNAP YAZ #57 is an environment request; no production-device ANR fix is claimed. CodeRabbit has skipped the aggregate release review because of its file limit; this is not treated as an executed review.

Release packaging regression: Git worktrees use a .git file, which the previous directory-only filter included. Both distribution filters now exclude Git metadata in either form, and the builder fails on forbidden root paths of any type. CI builds and audits a real worktree ZIP with tests/release-worktree.test.sh; the local regression passed.

The final rc.2 package was built twice with identical bytes and passed the complete ZIP audit (4,469 entries). It is a local validation artifact; no GitHub release/tag or production deployment was created.

This remains a prerelease candidate. The stable updater channel must not offer rc.2 as a stable release. Pullfrog reports no new issues on the final head; CodeRabbit’s file/capacity limit prevented a fresh aggregate review.

Home, catalogue and book page follow the 2026 mockup; every other public page, the sign-in pages and the account pages use the same design system (public/assets/pinakes-2026.css, pinakes-2026.js), with Geist and Newsreader self-hosted.

- One book card for the home, the catalogue and related books (partials/pk-book-card.php): the cover as a 3D book on a panel tinted from the cover, with every element the old card had (availability, live badge, digital-content icons, wanted badge, media badge, subtitle, publisher, Details) plus a wishlist heart.
- Hero without a background image: the CMS picks the latest covers or up to four chosen books; the first cover is preloaded as the LCP image.
- Catalogue: filter column, author finder, Grid/List toggle remembered per visitor.
- Book page: cover beside the identity, availability box with copies, quick facts, inline citation with Copy and RIS.
- Theme colours drive every surface: a filled surface always carries its paired text colour (button/button_text).
- frontend-layouts.css is no longer linked on public and account pages; its functional rules (mobile filters toggle) are ported.
- Source-level tests updated to the new markup, asserting the same guarantees (escaping, pending badge, 44px search target, mobile collapse of an empty publisher line).
Book page
- The availability box holds only loan and favourites, status and copies on the left; the plugins' buttons (digital files, "Cerca su") move under the quick facts, as in the design.
- Quick facts read Anno / Pagine for books; other media keep their own labels.
- Digital Library shows one card per file (type tile, name, kind, Leggi PDF / Scarica, the audio player in its card); the PDF opens under its card, one audio plays at a time.
- GoodLib "Cerca su" as a line of small chips; share buttons as labelled chips; keyword chips in sentence case; the Cite dialog button joins the citation actions row.
- The hero wash comes from the theme's accent, not from the cover; the favourites heart is outlined until the book is added.

Theme options
- The layout variants (editorial, workspace, command, soft), inert since the 2026 design, are replaced by two options: hero style (covers / centred) and card style (classic / tinted). A theme without them, as every fresh install and every upgrade has, gets covers + classic.
- tests/public-style-defaults.spec.js checks the defaults through the admin and the home.

Also
- No fade-in on cards or sections anywhere.
- "Pulisci tutti i filtri" also at the top of the filter column (catalogue and the shared filter sidebar).
- Form fields without a border.
Each book is one row: a small cover, the title, then author and publisher on one line, and on the right the availability, the digital editions with their name, the media type and the wishlist heart. Nothing the card shows is hidden any more.

The row alignment of the grid stops in the list and runs again when the view changes, so heights measured in the list no longer clip the grid's titles. The script's cache-busting version now follows the newer of the stylesheet and the script.
…elds

The home hero stacks with the books above the title once they no longer fit beside it; a phone rule that zeroed the fan in the column is gone.

Folded catalogue filters keep no room under their bar. The closed mobile menu is clipped inside its overlay, so it never widens the page.

Profile: main.css gave the page 4rem of padding on phones, leaving about 200px for the fields; the form grid now fits narrow cards and the page uses the site gutter, which also lets the admin's session list read on one line. Fields on white cards take the soft fill, since they have no border.

Archive units whose cover file is missing show the level icon instead of a broken image.
Stacked above the title, the fan clipped its own bottom edge and cut the books' shadow in a straight line. It now clips only the sides, the books sit a little higher, and the text paints above the shadow.
…s in place

Desiderata: on a phone a cover fills the row as a 2:3 book; on a desktop it grows from 48 to 96px. A book without a cover (or whose image fails) shows a blank book with its title instead of a grey box, in the server-rendered list and in the search results alike.

Genre carousel: at 768px and below the arrows sit under the track, so the heading drops the side indent and the cards start at the left edge instead of a centred single card.

Archive filters: the two year fields no longer overflow the sidebar.
In a grid cell the three-level path wrapped mid-name around raw '>' signs. It now takes the whole first row of the details grid, reads as a breadcrumb with the page's separator, and wraps only between levels.

The session-fixes check for the 'Cerca su' row now asserts the invariant (full width, nothing beside it) instead of the old #book-action-buttons structure the 2026 page moved it out of.
…e theme

Fields had no border and a white fill, so on the near-white page they barely showed. They now share one look across the public pages and the standalone auth pages: a soft fill and a thin rule, both mixed from the theme accent, a stronger rule on hover, and the accent with its ring on focus. Checkboxes and radios take the accent too.
Its styles in account-pages.css were scoped to the old layout-variant body classes, gone since the hero/card style options replaced them, so the page fell back to its legacy inline look. It now uses the account page head, a summary card with the three counters, the standard quick-search field, and the catalogue's book cards with status, availability line, Details and the remove button. Every element it had is kept.

The query now carries the main author: the card shows it, and book_url() builds the canonical address with it (the slug fell back to "autore" before).
The columns sat content-wide in a cluster with wide gaps. They now share the full width on a grid: the brand on the widest track, then Menu, Account and Seguici; on tablets the brand takes its own row with the columns below; on phones Menu and Account pair up and Seguici spans the row. Seguici lists its profiles in two columns, as plain links with the brand icon like the other columns, instead of the legacy grey tiles, and X uses its current icon.
…ccount

The profiles fill a column of four, then flow into a second one, so Seguici has the same four rows as the columns beside it. Each item is a flex box: a grid cell around an inline-flex link kept a 0.8px baseline gap that drifted the rows off Menu's.
After login a reader landed on /user/dashboard, and the header menus linked there too: the English path answers, but on an Italian install the canonical one is /utente/bacheca. Login and both menus now use the translated route, and the mobile menu's "Dashboard" label is translatable.

The empty wishlist's "back to the dashboard" link pointed at /dashboard, which is a 404; it now leads to the reader's dashboard.
The reader's loans, requests and reservations used fixed purple, green and blue badges, full-width red and pink buttons and a grey box for a missing cover. They are now account cards: the cover as a book (a blank one when there is none), status and dates as quiet pills with a coloured dot only for the state (lateness keeps its red), and the review and cancel actions as compact pills in the theme's button colour and an outlined red.
Brings in 0.7.94 (article admin page, update outcome per attempt). The only conflicts were the five locale files, where both sides had added different keys; they are merged as the union of the two.
The catalogue showed the cards it fetched for another page by setting display: grid inline on the container, which beat the list view's display: flex: after a page change the list became a grid of narrow cards with no room for the title. The container now goes back to its stylesheet display.
The committed build no longer matched the views, which failed the reproducible-assets check.
The accent was used as a text colour everywhere (links, "Details", the active menu entry, labels), but on half the bundled themes it does not reach WCAG AA as text: Ocean, Forest, Sunset, Teal and Coral read at 3.2-4.1:1 even on white, and Pinakes Classic falls to 4.4:1 on its own tint. The theme palette now carries primary_text, the accent darkened only as far as AA on its soft tint needs (dark accents come back unchanged; Classic moves from #d70161 to #ce015d), exposed as --primary-text and used wherever the accent is a text colour. Backgrounds, borders and buttons keep the theme's own colour.

Also, from an axe sweep of every public and account page on all ten themes:
- the 2026 faint grey (#8d8590, 3.4:1) is now #6f6873; the availability filter descriptions lose their 0.8 opacity;
- the home story band's eyebrow and caption read at AA on every theme's secondary colour;
- the reader dashboard's availability badges, and the profile's empty values and session list, reach AA; the profile's blue session highlight follows the theme;
- the profile's card details are a real <dl>;
- related cards on the book page no longer put their aria-hidden cover link back in the tab order;
- the year range thumbs and the card "Details" links get a 24px target;
- the shadow under the book page's availability box and the login card is mixed from the theme instead of a fixed pink.
…c page

A sweep of every customisable setting against the pages that should show it found three that stopped short:

- The reader's account pages (dashboard, profile, wishlist, reservations) loaded neither the theme's custom CSS nor the site's, ran none of the custom scripts, and had no cookie banner, so visitors could not give or change consent there and analytics never counted those pages.
- The login, registration and password pages applied the site's custom CSS but not the theme's, and ran no custom scripts.
- The analytics and marketing scripts never ran anywhere, even after consent: the loader injects them as new <script> elements, and the nonce-based CSP refused them. The injected script now carries the loader's nonce.

The theme's custom CSS and the custom scripts are now shared partials, included by the public layout, the account layout and the auth pages.
The home showed the events section's title and subtitle from the database, but the homepage editor offered no field for them: the seeded "Eventi in Programma" could not be changed. The editor now has the section's title, subtitle and visibility, like the genre carousel.
With data in the tables, axe found white counters on blue-500 and purple-500 (3.7 and 4.0:1) on the dashboard, the wanted-books pages and the sidebar, grey-400 notes under the dashboard cards and the ISBN line in the books list, and unlabelled row checkboxes there. Counters use the 600 shades, the notes grey-500, and each row checkbox is named after its book.
Events could already be hidden from the menu; Emeroteca and Archive could not, short of deactivating the plugin. Each plugin's admin page now has the same visibility card as the Events page, stored as cms.emeroteca_in_menu and cms.archives_in_menu. Only the menu entry goes, on the desktop, mobile and account menus: the pages stay reachable, since catalogue and search results link to them.

The account pages' menu also lacked the Archive entry the public menu has; it now lists it under the same conditions.
The render-time sanitisation of the theme's custom CSS moved from the frontend layout into the partial every public layout now includes. The guard reads it there, and also checks that the frontend, account and auth layouts all include it.
social-links looked for the old Twitter bird; the footer shows X's logo (fa-x-twitter) since the restyle, and prints the six profiles from one list in a loop, so the two source checks now verify that every profile is in the list and that the loop's href is escaped. The spec is serial, so the first failure skipped the 24 checks after it.

home-hero-covers-2026 reached MySQL through the socket only, which the CI runner does not have; it now uses the host and port when they are set, like the other specs.
…overs

- The login, registration and password-reset pages no longer run the
  custom scripts from Settings > Advanced: a third-party snippet could read
  the password field or send the reset token in the URL elsewhere.
- The theme CSS sanitiser repeats until nothing changes, so a tag split by
  another (</sty<style>le>) can no longer be rebuilt.
- window.PK carries a CSRF token only for a signed-in reader, so anonymous
  pages stay token-free and cacheable (#387).
- The hero background photo is retired: the CMS no longer accepts an
  upload and it is no longer the og:image / twitter:image fallback.
- user_layout.php (rendered by no controller), account-pages.css and
  frontend-layouts.css (their selectors need body.layout-*, which the 2026
  body no longer has) are removed, with the dead layout-* rules in
  archive-pages.css and book-detail.css. The reservations' section icons
  stay hidden through pinakes-2026.css.
- fonts.css uses URLs relative to itself, so the fonts load under a
  subfolder install, and the OFL licences ship next to the fonts.
- Filled surfaces carry their text at AA: ThemeColorizer::readableSurface()
  moves the button and dark colours only as far as 4.5:1 needs, and
  readableOnDark() gives the story band's links an accent that reads on it.
  The accent-strong text colour is derived from the readable accent.
- One solid focus ring in the readable accent; the header and hero search
  fields and the filter search boxes show it.
- Form field rules reach 3:1 on the field and the page (WCAG 1.4.11).
- Reduced motion stops every transition and hover lift on public pages.
- The story title wraps on phones instead of being cut; the header stays
  on one row between tablet and desktop; the mobile header padding applies;
  filter search fields are 16px on phones so iOS does not zoom.
- Status colours are tokens; rules for classes no view uses are removed.
- main.css: the settings-panel phone rule leaves @layer components, so
  Tailwind no longer nests it inside min-width queries where it never
  applied.
…alogue a11y, cite, PDF, tests

- Views escape with htmlspecialchars instead of HtmlHelper::e; the CMS
  cover search ignores stale responses.
- Book cards and the book page read the media type through MediaLabels.
- Hero: covers only for the split hero, ordered like "latest books",
  locale-aware thousands, the genre counter from the database.
- The story figure is lifted only from a "tradizione ... N anni" sentence.
- Catalogue availability and facet filters expose their pressed state;
  the author count has a singular form.
- Cite box: unique tab ids, ARIA tabs, a live status and a copy fallback.
- Digital library "Leggi PDF" works without JavaScript.
- Wishlist author lists only principal and co-authors.
- Tests restore the state they change and stop hiding failures as skips.
In CI the spec stopped on is_desiderata, a column the desiderata plugin adds, and would then have found no book with a cover, since the seeded catalogue has none. It now filters on the column only where it exists, lends a searchable book a cover for the run when there is none and gives it back afterwards, and picks the book by its whole title, since a prefix can match another edition listed first.
The field rule is now mixed from --primary-text, the accent's readable text shade, so changing only --primary-color left the border as it was. A theme sets both; the test now does the same.
Books came with their covers and articles with a generic icon. The suggestion now carries the article's image by the rule its page already follows (its own cover, else its issue's, else the masthead's logo, ContributionService::coverUrl()) and shows it sized like a book cover; an article with no image keeps the newspaper icon, in a frame of the same size so the rows line up.
The display serif (--pk-serif on the public site and account pages, --serif on the auth pages) is now Fraunces, still self-hosted. Its upright files are variable, so one face per subset covers weights 100-900 and the duplicate 500/600 files go; the Newsreader files and licence go with them. The layout preloads the Fraunces latin file in place of Newsreader's.
Fields in the public pages and on the auth pages are now white with a thin rule tinted by the theme accent, instead of a pink-grey fill; the auth rule takes the same stronger shade as the public one so a white field still stands out on its white card.

The input inside a search box (catalogue search, author finder, periodicals and archive search) lost to the generic field rule, which is more specific, and drew its own rule and fill inside the box's. The box rule now outranks it. The layout spec guards both.
Release candidate for the 2026 design of the public site and the account pages (PR #458): bump version.json and add the [0.8.0-rc.1] changelog section. No migration.
@pullfrog

pullfrog Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Run failed. View the logs →

Pullfrog  | Rerun failed job ➔ | View workflow run | via Pullfrog | 𝕏

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 167 files, which is 67 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration
  • Configuration used: Repository: fabiodalez-dev/Pinakes/.coderabbit.yaml
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 1f199655-ef06-4322-bacf-025df18c9f16
📥 Commits

Reviewing files that changed from the base of the PR and between 49a9c68 and 83a99db.

⛔ Files ignored due to path filters (20)
  • docs/reviews/mobile-parity-2026-10-08/android-archive.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/android-article.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/android-catalog.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/android-citation.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/android-desiderata.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/android-home.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/web-archive.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/web-article.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/web-catalog.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/web-citation.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/web-desiderata.png is excluded by !**/*.png
  • docs/reviews/mobile-parity-2026-10-08/web-home.png is excluded by !**/*.png
  • public/assets/fonts/Fraunces-10.woff2 is excluded by !**/*.woff2
  • public/assets/fonts/Fraunces-11.woff2 is excluded by !**/*.woff2
  • public/assets/fonts/Fraunces-12.woff2 is excluded by !**/*.woff2
  • public/assets/fonts/Fraunces-7.woff2 is excluded by !**/*.woff2
  • public/assets/fonts/Fraunces-8.woff2 is excluded by !**/*.woff2
  • public/assets/fonts/Fraunces-9.woff2 is excluded by !**/*.woff2
  • public/assets/fonts/Geist-normal-latin-ext.woff2 is excluded by !**/*.woff2
  • public/assets/fonts/Geist-normal-latin.woff2 is excluded by !**/*.woff2
📒 Files selected for processing (167)
  • .distignore
  • .github/workflows/ci-browser-security.yml
  • .github/workflows/ci-database-compatibility.yml
  • .github/workflows/ci-deep-regression.yml
  • .github/workflows/ci-e2e.yml
  • .github/workflows/ci-quality.yml
  • .github/workflows/ci-real-upgrade.yml
  • .github/workflows/ci-security-supply-chain.yml
  • .github/workflows/ci-upgrade-smoke.yml
  • .github/workflows/release.yml
  • .github/workflows/test-migrations.yml
  • .rsync-filter
  • CHANGELOG.md
  • app/Controllers/AuthController.php
  • app/Controllers/CmsController.php
  • app/Controllers/FrontendController.php
  • app/Controllers/PluginController.php
  • app/Controllers/ThemeController.php
  • app/Controllers/UserWishlistController.php
  • app/Support/ConfigStore.php
  • app/Support/ContentCache.php
  • app/Support/ContentSanitizer.php
  • app/Support/ThemeColorizer.php
  • app/Support/ThemeManager.php
  • app/Views/admin/partials/layout-variant-selector.php
  • app/Views/admin/partials/menu-visibility-toggle.php
  • app/Views/admin/partials/public-style-selector.php
  • app/Views/admin/theme-customize.php
  • app/Views/admin/themes.php
  • app/Views/auth/forgot-password.php
  • app/Views/auth/login.php
  • app/Views/auth/partials/auth-theme.php
  • app/Views/auth/partials/theme-custom-css.php
  • app/Views/auth/register.php
  • app/Views/auth/register_success.php
  • app/Views/auth/reset-password.php
  • app/Views/cms/edit-home.php
  • app/Views/dashboard/index.php
  • app/Views/frontend/book-detail.php
  • app/Views/frontend/catalog-grid.php
  • app/Views/frontend/catalog.php
  • app/Views/frontend/contact.php
  • app/Views/frontend/home-books-grid.php
  • app/Views/frontend/home-sections/cta.php
  • app/Views/frontend/home-sections/features_title.php
  • app/Views/frontend/home-sections/hero.php
  • app/Views/frontend/home-sections/latest_books_title.php
  • app/Views/frontend/home-sections/text_content.php
  • app/Views/frontend/home.php
  • app/Views/frontend/layout.php
  • app/Views/frontend/partials/article-card.php
  • app/Views/frontend/partials/breadcrumb.php
  • app/Views/frontend/partials/catalog-archive-results.php
  • app/Views/frontend/partials/catalog-hero.php
  • app/Views/frontend/partials/filters-sidebar.php
  • app/Views/frontend/partials/pk-book-card.php
  • app/Views/frontend/partials/social-sharing.php
  • app/Views/frontend/partials/static-page-css.php
  • app/Views/libri/index.php
  • app/Views/partials/cite-inline.php
  • app/Views/partials/custom-js.php
  • app/Views/profile/index.php
  • app/Views/profile/reservations.php
  • app/Views/profile/wishlist.php
  • app/Views/user_dashboard/index.php
  • app/Views/user_dashboard/prenotazioni.php
  • app/Views/user_layout.php
  • bin/build-release.sh
  • docs/reviews/issue-412-verifica.md
  • docs/reviews/mobile-parity-2026-10-08/README.md
  • docs/reviews/mobile-parity-2026-10-08/verification.json
  • docs/reviews/uwe-android-parity-2026-10-08.md
  • frontend/css/input.css
  • locale/da_DK.json
  • locale/de_DE.json
  • locale/en_US.json
  • locale/fr_FR.json
  • locale/it_IT.json
  • public/assets/account-pages.css
  • public/assets/archive-pages.css
  • public/assets/book-detail.css
  • public/assets/catalog-pages.css
  • public/assets/css/swal-theme.css
  • public/assets/fonts/OFL-Fraunces.txt
  • public/assets/fonts/OFL-Geist.txt
  • public/assets/fonts/OFL-InstrumentSans.txt
  • public/assets/fonts/fonts.css
  • public/assets/frontend-layouts.css
  • public/assets/main.css
  • public/assets/pinakes-2026.css
  • public/assets/pinakes-2026.js
  • public/index.php
  • storage/plugins/archives/ArchivesPlugin.php
  • storage/plugins/archives/assets/css/archives-public.css
  • storage/plugins/archives/plugin.json
  • storage/plugins/archives/views/index.php
  • storage/plugins/archives/views/public/index.php
  • storage/plugins/book-club/views/partials/book_quotes.php
  • storage/plugins/book-club/views/public/affinity.php
  • storage/plugins/book-club/views/public/ai.php
  • storage/plugins/book-club/views/public/challenges.php
  • storage/plugins/book-club/views/public/club_stats.php
  • storage/plugins/book-club/views/public/dashboard.php
  • storage/plugins/book-club/views/public/discussions.php
  • storage/plugins/book-club/views/public/index.php
  • storage/plugins/book-club/views/public/leaderboard.php
  • storage/plugins/book-club/views/public/lending.php
  • storage/plugins/book-club/views/public/poll.php
  • storage/plugins/book-club/views/public/polls.php
  • storage/plugins/book-club/views/public/quotes.php
  • storage/plugins/book-club/views/public/reading.php
  • storage/plugins/book-club/views/public/show.php
  • storage/plugins/book-club/views/public/sprints.php
  • storage/plugins/book-club/views/public/survey.php
  • storage/plugins/book-club/views/public/surveys.php
  • storage/plugins/book-club/views/public/thread.php
  • storage/plugins/desiderata/DesiderataPlugin.php
  • storage/plugins/desiderata/plugin.json
  • storage/plugins/desiderata/views/admin.php
  • storage/plugins/desiderata/views/dashboard.php
  • storage/plugins/desiderata/views/partials/offer-assets.php
  • storage/plugins/desiderata/views/public.php
  • storage/plugins/digital-library/DigitalLibraryPlugin.php
  • storage/plugins/digital-library/assets/css/digital-library.css
  • storage/plugins/digital-library/views/frontend-attachments.php
  • storage/plugins/emeroteca/EmerotecaPlugin.php
  • storage/plugins/emeroteca/plugin.json
  • storage/plugins/emeroteca/src/Modules/MobileModule.php
  • storage/plugins/emeroteca/src/Views/index.php
  • storage/plugins/emeroteca/src/Views/public/article.php
  • storage/plugins/mobile-api/MobileApiPlugin.php
  • storage/plugins/mobile-api/plugin.json
  • storage/plugins/mobile-api/src/Controllers/CatalogController.php
  • storage/plugins/mobile-api/src/Controllers/CollectionsController.php
  • storage/plugins/mobile-api/src/Controllers/HealthController.php
  • storage/plugins/mobile-api/src/Controllers/OpenApiController.php
  • tests/catalog-facets.spec.js
  • tests/catalog-list-view.spec.js
  • tests/custom-css-injection.unit.php
  • tests/emeroteca-412.unit.php
  • tests/emeroteca-article-pdf-461.unit.php
  • tests/emeroteca-articles-453-455.spec.js
  • tests/emeroteca-articles-page.spec.js
  • tests/frontend-layout-variants.unit.php
  • tests/frontend-partials.unit.php
  • tests/frontend-theme-a11y.unit.php
  • tests/hero-upload-292.spec.js
  • tests/hero-upload-292.unit.php
  • tests/hero-upload-server-292.spec.js
  • tests/home-hero-covers-2026.spec.js
  • tests/hot-dataset-cache-387.unit.php
  • tests/litespeed-edge-cache.unit.php
  • tests/menu-visibility-plugins.spec.js
  • tests/mobile-api-idempotency.spec.js
  • tests/mobile-collections.integration.php
  • tests/mobile-public-layout.spec.js
  • tests/public-style-defaults.spec.js
  • tests/related-books-responsive-278.spec.js
  • tests/release-worktree.test.sh
  • tests/search-article-cover-453.spec.js
  • tests/session-fixes.spec.js
  • tests/session-fixes.unit.php
  • tests/settings-themes-hardening.unit.php
  • tests/social-links.spec.js
  • tests/theme-readable-accent.unit.php
  • tests/uppy-image-preview.spec.js
  • version.json

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

In production every path that matched no route wrote [ERROR] and its full stack trace to the error log: on a public site, every bot probe and stale link. The log grew to hundreds of MB and buried the errors worth reading. The handler now logs real errors only.

Saving a plugin's settings wrote six trace lines on every successful save. Those are gone; the failure paths still log. Saving the Open Library Google Books key reported success even when the write failed (only a 'Save result: false' line said otherwise); it now answers with an error.
@pullfrog

pullfrog Bot commented Oct 7, 2026

Copy link
Copy Markdown

Run failed. View the logs →

Pullfrog  | Rerun failed job ➔ | View workflow run | via Pullfrog | 𝕏

@fabiodalez-dev fabiodalez-dev changed the title 0.8.0-rc.1: the 2026 design of the public site and the account pages 0.8.0-rc.2: complete restyle, mobile collections and catalogue fixes Oct 8, 2026

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

This review covers the 12 commits since 9a050e6 (the rc.1 changelog), which turn this into 0.8.0-rc.2. The PR title and body still say rc.1.

  • Catalogue archive hits — FrontendController::collectArchiveResults() now reduces the archive hook output to id, label, reference_code and url, limits it to six hits and logs any hook failure. The new catalog-archive-results.php partial renders these hits on the page and in catalogAPI()'s archive_html, and skips any href that isn't root-relative.
  • Catalogue filters — clearAllFilters() now resets the filters without reloading the page. The genre facet stays open so readers can drill down. The publisher list has its own search box and count, and the facet search boxes re-apply their filter after each re-render.
  • Typeset blank covers — covers that are missing or fail to load now show the author, title and publisher in one of four tones. Real covers use object-fit: contain.
  • Book detail layout — the details and keywords sections moved unchanged into a full-width block.
  • Theme contrast — ThemeColorizer::readableSurface() now tries both darker and lighter shades, and button_hover is a surface checked for AA contrast. tests/theme-readable-accent.unit.php passes 112/112.
  • Staff article PDF — on a public article page, staff get the PDF link through the protected admin route when the PDF isn't public.
  • Mobile API 1.5.0 — added CollectionsController, behind the bearer token:
    • archives and desiderata list, detail and health endpoints
    • native donation proposals, with UUID idempotency, a lock on the user row and a 60 s limit per account
    • more fields on book and article details: attachments, citations, RIS/MARCXML, genre path and author credits
    • new article filters and an author_id search
    • a genre filter that matches every depth
  • Desiderata 1.2.0 schema — added nullable mobile_* columns and a unique index. Both are additive and are repaired at boot through expectedColumns().

I checked these parts against the surrounding code:

  • The archives plugin has no visibility flag for individual records, so the mobile archive endpoints show nothing the public /archives/{id} pages don't already show.
  • The mobile_user attribute that MobileModule reads matches AppAuthMiddleware::ATTR_USER.
  • DesiderataPlugin looks up its plugin id by name when it is built outside the plugin manager.

php -l is clean on every changed PHP file. These checks pass: frontend-partials, frontend-layout-variants, emeroteca-article-pdf-461 and scripts/ci-check-locales.py. emeroteca-412 needs a database and was not run.

Pullfrog  | View workflow run | Using claude-opus-5-5 | 𝕏

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

This review covers the two commits since d6e2191. They stop release ZIPs built from a Git worktree from including the .git file.

  • Distribution filters — .rsync-filter and .distignore now exclude .git, not just .git/. The old rule only matched a directory, so the .git file a worktree creates got into the package.
  • Forbidden-root check — verify_package_contents() in bin/build-release.sh now rejects a forbidden root path whatever its type (-e || -L), where it used to check only for a directory (-d).
  • Worktree regression in CI — tests/release-worktree.test.sh makes a detached worktree of HEAD and builds it with --skip-build into a temporary output directory. It then checks that no .git entry is in the ZIP and runs scripts/ci-verify-release.sh on it. ci-security-supply-chain.yml runs it before the reproducibility build.

I checked the new test against the builder. The build reads the tracked vendor/ and public/assets/vendor.bundle.js, and the tracked vendor/ has no dev packages, so a fresh worktree has everything the required-file and autoload checks need. The job installs jq, zip and unzip, and the test passes an absolute --output path, as the builder's mv into OUTPUT_DIR expects. Because the rsync pattern isn't anchored, - .git also drops nested .git files and directories, as - .git/ already did for directories. I did not run the test here: this checkout's .git is read-only, so git worktree add fails.

Pullfrog  | View workflow run | Using claude-opus-5-5 | 𝕏

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant