Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
50 commits
Select commit Hold shift + click to select a range
acb9e85
Restyle the public site and the account pages (2026 design)
fabiodalez-dev Oct 6, 2026
7fbfa30
Match the book page to the design; hero and card style as theme options
fabiodalez-dev Oct 7, 2026
4f8946d
Make the catalogue list view a real list
fabiodalez-dev Oct 7, 2026
2d41036
Fix the public site on phones: hero order, folded filters, profile fi…
fabiodalez-dev Oct 7, 2026
f8aa632
Let the hero books' shadow fall past the fan when it is stacked
fabiodalez-dev Oct 7, 2026
7540e43
Wanted books with real covers, genre rows aligned, archive year field…
fabiodalez-dev Oct 7, 2026
59a2049
Show the book's genre path as the first row of its details
fabiodalez-dev Oct 7, 2026
bab76e8
Give every public form field a soft fill and a thin rule tinted by th…
fabiodalez-dev Oct 7, 2026
c599873
Bring the wishlist page into the 2026 design
fabiodalez-dev Oct 7, 2026
6b3edf3
Lay the footer out on a grid and fix its Seguici column
fabiodalez-dev Oct 7, 2026
29242ee
List the footer's social profiles in four rows, level with Menu and A…
fabiodalez-dev Oct 7, 2026
9e6b8fd
Send readers to the dashboard in the install's language
fabiodalez-dev Oct 7, 2026
1dad80b
Bring the loans and reservations cards into the 2026 design
fabiodalez-dev Oct 7, 2026
c747259
Merge main (0.7.94) into the 2026 restyle
fabiodalez-dev Oct 7, 2026
211add6
Keep the catalogue list a list after paging
fabiodalez-dev Oct 7, 2026
e40d34f
Rebuild main.css from the current views
fabiodalez-dev Oct 7, 2026
b5c8938
Make theme-coloured text readable on every theme
fabiodalez-dev Oct 7, 2026
b736319
Apply the custom CSS, custom scripts and cookie banner on every publi…
fabiodalez-dev Oct 7, 2026
f86575f
Let the home's events section title be edited
fabiodalez-dev Oct 7, 2026
53d6e5f
Raise the admin counters and card notes to AA contrast
fabiodalez-dev Oct 7, 2026
0f55a26
Let the admin take Emeroteca and Archive out of the public menu
fabiodalez-dev Oct 7, 2026
2a7b67e
Check the theme CSS sanitisation in its shared partial
fabiodalez-dev Oct 7, 2026
37d233c
Bring two browser specs in line with the 2026 footer and the CI database
fabiodalez-dev Oct 7, 2026
2069d62
Keep site scripts off the auth pages and retire the dead restyle left…
fabiodalez-dev Oct 7, 2026
76bfbd3
Make the 2026 design readable and operable on every theme
fabiodalez-dev Oct 7, 2026
ad33b4e
Close the remaining review findings: escaping, media types, hero, cat…
fabiodalez-dev Oct 7, 2026
ffc398e
Make the hero covers spec independent of the catalogue it finds
fabiodalez-dev Oct 7, 2026
24500a4
Merge branch 'pr-460' into verify-460
fabiodalez-dev Oct 7, 2026
9f0bc64
Set the accent's text shade too when the field test switches theme
fabiodalez-dev Oct 7, 2026
9415eef
Show an article's image in the header search suggestions (#453)
fabiodalez-dev Oct 7, 2026
2113ab6
Use Fraunces as the serif instead of Newsreader
fabiodalez-dev Oct 7, 2026
7b1bd47
Draw form fields white, and one border per search box
fabiodalez-dev Oct 7, 2026
f948d57
chore(release): prepare 0.8.0-rc.1
fabiodalez-dev Oct 7, 2026
7a58ff5
Keep 404s and routine plugin saves out of the error log
fabiodalez-dev Oct 7, 2026
6f296a5
Merge branch 'design/restyling-2026' into release/0.8.0-rc.1
fabiodalez-dev Oct 7, 2026
dc87eaf
docs(changelog): error log and Open Library key fixes in 0.8.0-rc.1
fabiodalez-dev Oct 7, 2026
3e534ba
Run the book details and keywords across the whole width
fabiodalez-dev Oct 8, 2026
6fa337f
Preserve author searches across facet rebuilds and show complete covers
fabiodalez-dev Oct 8, 2026
a3418d0
Fix catalog navigation and staff article PDF access (#461)
fabiodalez-dev Oct 8, 2026
afcf2ca
Close restyle review findings and keep theme hover contrast readable
fabiodalez-dev Oct 8, 2026
a75562e
test: keep article genre regression aligned with open drill-down
fabiodalez-dev Oct 8, 2026
84a023a
Polish missing book covers with coordinated cloth bindings
fabiodalez-dev Oct 8, 2026
45a7b8f
Complete mobile collection APIs and reconcile Uwe catalogue requests
fabiodalez-dev Oct 8, 2026
f23c2b9
Match localized catalogue language facets to analytic ISO codes
fabiodalez-dev Oct 8, 2026
f561684
Keep article detail independent of mobile middleware loading and tran…
fabiodalez-dev Oct 8, 2026
5fbe76e
Record final Uwe parity validation
fabiodalez-dev Oct 8, 2026
f1a68e8
Preserve release review evidence for mobile and Android parity
fabiodalez-dev Oct 8, 2026
22e25ec
Prepare 0.8.0-rc.2 with the complete restyle and Android API changes
fabiodalez-dev Oct 8, 2026
a14ac7b
Exclude worktree Git metadata from release ZIPs and verify real packa…
fabiodalez-dev Oct 8, 2026
83a99db
Include verified worktree packaging in the complete rc.2 candidate
fabiodalez-dev Oct 8, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .distignore
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
# ========================================

# Version control
.git/
.git
.gitignore
.gitattributes

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ci-browser-security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ jobs:
done < <(find /etc/php -type d -path '*/conf.d' | sort -u)

- name: Setup PHP 8.2 tooling
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, pdo_mysql, mbstring, curl, intl, xml, zip, gd, apcu
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ci-database-compatibility.yml
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,7 @@ jobs:
persist-credentials: false

- name: Setup PHP 8.2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, pdo_mysql, mbstring, curl, intl, xml
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/ci-deep-regression.yml
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@ jobs:
done < <(find /etc/php -type d -path '*/conf.d' | sort -u)

- name: Setup PHP 8.2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, mbstring, json, curl, openssl, zip, gd, intl, xml, apcu
Expand Down Expand Up @@ -300,7 +300,7 @@ jobs:
[ -z "${php_module}" ] || sudo a2enmod "${php_module}"
sudo a2dissite 000-default || true
- name: Setup PHP and Node
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, mbstring, curl, zip, gd, intl, xml
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ci-e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -78,7 +78,7 @@ jobs:

# ── PHP 8.2 CLI for Composer and tooling ────────────────────────────────
- name: Setup PHP 8.2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, mbstring, json, curl, openssl, zip, gd, intl, xml, apcu
Expand Down
5 changes: 3 additions & 2 deletions .github/workflows/ci-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ jobs:
persist-credentials: false

- name: Setup PHP
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, pdo_mysql
Expand Down Expand Up @@ -351,6 +351,7 @@ jobs:
env:
CI_STRICT_TESTS: '1'
run: |
php tests/mobile-collections.integration.php
php tests/desiderata.integration.php
php tests/desiderata-visibility.integration.php
php tests/desiderata-extended.integration.php
Expand Down Expand Up @@ -385,7 +386,7 @@ jobs:
with:
persist-credentials: false
- name: Setup PHP ${{ matrix.php }}
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: ${{ matrix.php }}
extensions: mysqli, pdo_mysql, mbstring, curl, intl, xml
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ci-real-upgrade.yml
Original file line number Diff line number Diff line change
Expand Up @@ -102,7 +102,7 @@ jobs:
done < <(find /etc/php -type d -path '*/conf.d' | sort -u)

- name: Setup PHP 8.2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, mbstring, json, curl, openssl, zip, gd, intl, xml, apcu
Expand Down
5 changes: 4 additions & 1 deletion .github/workflows/ci-security-supply-chain.yml
Original file line number Diff line number Diff line change
Expand Up @@ -119,7 +119,7 @@ jobs:
persist-credentials: false

- name: Setup PHP 8.2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, pdo_mysql, mbstring, curl, intl, xml, zip
Expand All @@ -146,6 +146,9 @@ jobs:
- name: Verify generated assets match the commit
run: git diff --exit-code -- public/assets

- name: Verify packaging from a Git worktree
run: bash tests/release-worktree.test.sh

- name: Build the release twice and require byte-for-byte reproducibility
run: |
bash bin/build-release.sh --skip-build
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/ci-upgrade-smoke.yml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ jobs:
persist-credentials: false

- name: Setup PHP
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, curl, zip, mbstring
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ jobs:
run: bash scripts/ci-verify-release-source.sh

- name: Setup PHP 8.2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, pdo_mysql, mbstring, curl, intl, xml, zip, gd
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/test-migrations.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ jobs:
persist-credentials: false

- name: Setup PHP
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
coverage: none
Expand Down Expand Up @@ -84,7 +84,7 @@ jobs:
persist-credentials: false

- name: Setup PHP
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli
Expand Down Expand Up @@ -218,7 +218,7 @@ jobs:
persist-credentials: false

- name: Setup PHP
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # v2
uses: shivammathur/setup-php@f3e473d116dcccaddc5834248c87452386958240 # 2.37.2
with:
php-version: '8.2'
extensions: mysqli, pdo_mysql
Expand Down
2 changes: 1 addition & 1 deletion .rsync-filter
Original file line number Diff line number Diff line change
Expand Up @@ -87,7 +87,7 @@
# ========================================

# Version control
- .git/
- .git
- .gitignore
- .gitattributes
- .gitmodules
Expand Down
52 changes: 52 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,58 @@

Full version-by-version history for Pinakes. The README shows only the latest release; everything older lives here.

## [0.8.0-rc.2]

The second candidate includes the complete 2026 restyle from rc.1 and the subsequent review fixes and coordinated Android 1.6.0 API work. The published rc.1 tag and assets are unchanged.

### Added
- **Archives and library Desiderata in the authenticated mobile API.** Archives expose hierarchy, signed-year filters, public descriptions, authorities, documents and exports. Desiderata has a separate list and detail, verified-account donation proposals with consent, account-scoped UUID deduplication and outcome recovery. A proposal does not create an inventory copy or alter the personal wishlist.
- **Complete book and analytic article data for Android:** every digital attachment and publisher, edition and publication place, complete genre ancestry, shared author identities, anthology metadata, five citation styles, rich HTML, RIS/MARCXML and protected staff-management links. Issue details distinguish catalogued contributions from the printed table of contents and link to the complete paginated list.
- **Release review evidence in the repository:** the Uwe requirements matrix, browser/Android comparison with disposable records, and recorded validation counts under `docs/reviews/`.

### Changed
- **Missing book covers become readable typeset bindings**, with title, author and publisher; original artwork remains complete. Wanted-book cover metadata includes the publisher.
- **Catalogue filters and collection search agree across clients.** Publisher lookup follows author lookup; genres reach every depth; localized language names match analytic ISO codes. Archives remain alongside matching books after AJAX updates. Circulation availability applies only to inventory books.
- Mobile API is **1.5.0**, Desiderata **1.2.0**, Emeroteca **1.13.0**, and Archives **1.5.1**. Android 1.6.0 uses advertised capabilities; earlier clients retain existing circulation routes.

### Fixed
- **Release ZIPs built from Git worktrees exclude the `.git` metadata file**, as well as ordinary Git directories. The builder rejects every forbidden root path regardless of its type; a CI regression builds and audits a real worktree package.
- **Clearing catalogue filters cancels obsolete requests** and restores the correct search state. The book detail and keywords use the available width; cover and hero regressions are covered by browser checks.
- **Article PDFs remain reachable for authorized staff** through protected routes, while public resources keep reader access. Article details do not depend on the mobile middleware class loader. Newly introduced API errors are translated in all five server locales.
- **Review findings across themes and responsive pages:** escaping and media types, keyboard and screen-reader access, readable accent/hover contrast, citation controls and published resource actions.

### Upgrade and validation
- Desiderata's plugin upgrade adds nullable mobile user/request/hash fields and an account/request unique index to its offers table. The upgrade is additive and idempotent; existing offers and website submission flows remain valid. Use the normal application/plugin updater so the bundled plugin upgrade runs.
- The functional changes passed 50 database collection checks, 191 Emeroteca behavioral checks, 9 HTTP contracts, 36 targeted browser regressions, 17 PHP suites and PHPStan level 5. The matching Android client passed 185 unit and 19 Compose tests, debug/R8 builds and lint with zero errors. The complete PR CI must pass on the candidate's final commit before publication.
- Staff editing and uploads remain on protected PHP pages. FBI/DBC import (#52) and the QNAP YAZ environment (#57) are not declared implemented by this candidate; no production-device ANR fix is claimed.

## [0.8.0-rc.1]

A release candidate for the 2026 design of the public site and the reader's account pages. Every element the pages had is still there; what changes is how they look.

### Changed
- **The public site and the account pages move to the 2026 design**: one stylesheet (`public/assets/pinakes-2026.css`) for the home, the catalogue, the book page and every other public page, with colours taken from the active theme. The home has a hero with a fan of covers next to the title, the counters, the "Πίνακες" band, latest arrivals, genre carousels and the call to action. The catalogue uses the new book cards, and its List view is a real list, one row per book. The book page has a hero tinted by the theme accent, quick facts, the digital files as cards (read the PDF inline, play the audiobook, download) and labelled share buttons. Dashboard, profile, wishlist and loans share one page head and one kind of card. The footer is a grid, with a "Follow us" column when a social profile is set. The display serif is Fraunces, self-hosted like the other fonts.
- **Form fields look the same everywhere**, the login and registration pages included: a white field with a thin rule tinted by the theme accent. A search box draws one border, with no second field inside it.
- **Two theme options replace the four layout variants** (editorial, workspace, command, soft) in Admin → Themes: the hero style (covers or centred) and the card style (classic or tinted). A theme that never saved them gets covers and classic. The homepage editor can pick up to four covers for the hero, or show the latest ones.
- **The accent stays readable as text on every theme.** On Ocean, Forest, Sunset, Teal and Coral the accent did not reach WCAG AA as text. The theme palette now carries `primary_text`, the accent darkened only as far as AA needs, used wherever the accent is text; backgrounds, borders and buttons keep the theme's colour. An axe sweep of every public and account page, on the ten bundled themes and at phone and desktop width, closed the remaining contrast, label and target-size findings.
- The fade-in animation on cards is gone.

### Added
- **Emeroteca and Archive can leave the public menu**, like Events: a card in their admin pages takes the entry out of the desktop, mobile and account menus, while the pages stay reachable from the catalogue and search. The account menu gains the Archive entry the public menu already had.
- **The home's events section** has a title, subtitle and on/off switch in the homepage editor.
- **The header search suggestions show an article's image** ([#453](https://github.com/fabiodalez-dev/Pinakes/issues/453)): its own cover, else its issue's, else the masthead's logo, sized like a book cover.

### Fixed
- **The account pages, login and registration** now load the theme's and the site's custom CSS, run the custom scripts and show the cookie banner, through the same partials as the public layout.
- **Analytics and marketing scripts run after consent.** The nonce-based CSP refused the script the loader injects; it now carries the loader's nonce.
- **The catalogue List view kept its rows after paging.** Moving to another page turned it into a grid of narrow cards.
- After login a reader on an Italian install landed on `/user/dashboard` instead of `/utente/bacheca`, and the header menus linked there; the empty wishlist linked to `/dashboard`, a 404. Wishlist links to books were missing the author slug.
- On phones the profile's fields overflowed their card and the closed mobile menu widened the page; archive units with a missing cover file showed a broken image, and the archive year filter overflowed its column.
- **A page that does not exist no longer writes an error.** In production every unmatched path, from bots or stale links, wrote `[ERROR]` and a full stack trace to the server's error log, which grew to hundreds of MB and buried the real errors. Only real errors are logged now. Saving a plugin's settings no longer writes trace lines on every save.
- **Saving the Open Library Google Books key reports a failed write.** It said the key was saved even when it was not.

No migration: the new theme options live in the theme's settings JSON.

## [0.7.94]

### Added
Expand Down
5 changes: 4 additions & 1 deletion app/Controllers/AuthController.php
Original file line number Diff line number Diff line change
Expand Up @@ -200,7 +200,10 @@ public function login(Request $request, Response $response, mysqli $db): Respons
} elseif (in_array($row['tipo_utente'], ['admin', 'staff'], true)) {
$redirectUrl = '/admin/dashboard';
} else {
$redirectUrl = '/user/dashboard';
// The dashboard in the reader's language, set just above from their
// profile (/utente/bacheca for an Italian reader), not the English
// path, which also answers but is not canonical there.
$redirectUrl = RouteTranslator::route('user_dashboard');
}

return $response->withHeader('Location', $redirectUrl)->withStatus(302);
Expand Down
Loading
Loading