- WinterCMS-style shell: header with search and theme toggle, grouped
sidebar, on-page TOC, pager, page actions, callouts, heading
permalinks, footer and a 404 page
- fenced code highlighted at build time by chroma/v2 into tok-* classes,
with a copy button; no inline script, style or handler
- vendored DM Sans/DM Mono fonts and Lucide icons with their licences
- client-side search over search-index.json built with textContent only
- summer docs:serve builds into a temp dir, serves on loopback by default,
returns 404.html with status 404 and rebuilds on change
- Pin River v0.47.0 (riverdatabasesql, rivertype) and tidy the example modules
- lagoon.Migrate runs the summercms.conga set: River schema v7 and summer_jobs
with the apparatus columns plus an internal river_job_id link
- conga.Manager.Dispatch writes the summer_jobs row (status IN_PROGRESS) and the
River job on the caller's *sql.Tx; a rollback leaves neither
- conga.Job wraps typed job functions so plugins never import River
- conga.StartWorker runs one client on riverdatabasesql.NewWithPgxListener with
a single-connection LISTEN pool; the final failed attempt sets ERROR
- TestListenPickupLatency: 30s poll, pickup under 1s; poll-only control 2s miss
- fields.yaml type: partial with a bare path name and config_list.yaml
headerPartial resolve to {ConfigDir}/_{name}.htm, parsed at boot; the
controller must implement pact.AdminPartialData
- html/template render against a curated view model, then x/net/html
ParseFragment and a tag, attribute and URL allowlist with 64 KiB, 2000-node
and depth-32 caps; the model type and trusted template types are refused
- GET .../partials/{name} with optional ?id= loaded through the form scope
- golang.org/x/net becomes a direct requirement (D-18), no new module
- backend.uri prefix (default /backend) mounts the admin API at {prefix}/api/v1
and the embedded SPA shell at {prefix} with an api/ JSON 404 fallback
- cookie transport: an X-Requested-With login sets the HttpOnly summer_admin
cookie and returns no token; the backend guard reads the cookie after Bearer
- CSRF wrapper refuses cookie-only POST/PUT/DELETE without X-Requested-With
- boardwalk package embeds boardwalk/dist, rewrites index.html once per prefix
and sets cache and security headers
- framework admin OpenAPI pipeline (swag, swagger2openapi, openapi-typescript)
with prefix-relative paths and typed envelopes for the tracer routes
- admin/ Vite SPA: login, plugin rail, section panel and read-only list
through the openapi-fetch client typed by the generated schema
- Winter-exact thumb filename and 3x3 partition with lazy imaging resize
- gocloud.dev/blob fileblob/memblob; empty bucket_url fails boot
- lagoon.Migrate runs system_files before every plugin set
- Load mail.* and SUMMER_MAIL__ overrides to pick memory, log, or smtp
- Log headers and text without credentials; SMTP uses explicit TLS and go-mail
- Reject CR/LF headers and invalid addresses and surface driver errors once
Co-authored-by: Cursor <cursoragent@cursor.com>
- Parse Winter INI + == Markdown templates and Goldmark HTML
- Memory driver stores rendered subject, text, and HTML
- Caller selects -en siblings by full dotted name
Co-authored-by: Cursor <cursoragent@cursor.com>
- Use go-i18n only to pick a category label, then substitute :name/:Name/:NAME
- Treat YAML maps as plurals when all keys are locale CLDR categories
- Parse pipe strings with {n} and [a,b]/[a,*] conditions at catalog load
Co-authored-by: Cursor <cursoragent@cursor.com>
Named middleware resolves at boot, HS256 tokens are pinned with required
exp/sub, and both binaries expose a signal-aware serve command.
Co-authored-by: Cursor <cursoragent@cursor.com>
Open one pgx stdlib *sql.DB, hand it to GORM, and run per-plugin
gormigrate sets with isolated history tables after an ICU pl-PL check.
Co-authored-by: Cursor <cursoragent@cursor.com>
- Add a generic tide flow schema with YAML fixture IO and HTTP record/replay
- Register parity:record and parity:replay on the bonfire summer tool
- Diff JSON scalars at $.path and non-JSON bodies at the changed byte offset
Co-authored-by: Cursor <cursoragent@cursor.com>
- Watch app sources with fsnotify, debounce, and one serialized build.App
- Restart the child only after a successful build and print rebuild latency
- Ignore generated app files and reap the child on cancellation
- Inject bonfire.Output from stdin/stdout/stderr with stdlib widgets and x/term
- Degrade spinner, progress, table and prompts without a TTY or color
- Reject plugin command names that are not namespace:verb
- Add party plugin registry with Register-before-Boot activation
- Add backpack, compass, bonfire, and pact capability interfaces
- Add examples/hello with two compiled plugin modules
Records the move from Scala to Go, the compiled-plugin decision, the
Płytarium port as the v1 target, and the Go ecosystem research that
backs the choice. No code yet.