petrbalvin
599c63e5bc
feat: add JSON Feed endpoint at /api/volumen/feed.json
...
Implements jsonfeed.org version 1.1 with title, home_page_url, feed_url,
description, language, and items with content_html and date_published.
2026-06-25 22:06:49 +02:00
petrbalvin
73be893bf8
feat: add scheduled publishing with publish_at frontmatter field
...
Posts with a future publish_at date are hidden from the public API
and feeds, same as drafts. The admin form exposes a Publish at field.
2026-06-25 22:06:49 +02:00
petrbalvin
52be2bb996
security: CORS preflight, session invalidation, CSRF on preview, symlink containment, and hardening
...
- Add OPTIONS /api/volumen/* for CORS preflight (S-22).
- Invalidate session in require_login! when user no longer exists (S-8).
- Add check_csrf! to POST /admin/preview (S-1).
- Use File.realpath for symlink-safe containment in media_file (S-2).
- Memoize Users#all with mtime-based invalidation (S-12).
- Document that empty permitted_hosts means allow-all (S-5).
- Warn and fall back to random when session_key is too short (S-20).
2026-06-25 22:06:49 +02:00
petrbalvin
5b8236c0a4
test: add sitemap.xml endpoint test
...
Verify content type, urlset structure, post URL presence, and draft exclusion.
2026-06-25 22:06:49 +02:00
petrbalvin
263e794669
security: hide draft posts from public detail endpoint
...
Add post.draft? check to GET /api/volumen/posts/:slug so guessing a
draft slug returns 404 like the list endpoint already does.
2026-06-25 22:06:49 +02:00
petrbalvin
4597c685da
test: add RSS feed endpoint tests
...
Verify content type, RSS structure, draft exclusion, and language
element.
2026-06-25 21:41:19 +02:00
petrbalvin
dd3efe870e
feat: initial release of volumen — a file-based Markdown blog engine
2026-06-21 13:15:06 +02:00