diff --git a/README.md b/README.md index 8917e5a2..df41ab83 100644 --- a/README.md +++ b/README.md @@ -68,6 +68,7 @@ devplacepy/ | `/gists` | Code gist listing, detail, creation, and editing; left panel offers language filtering and free-text `search` (title, description, and author username), public read | | `/comments` | Comment creation, owner editing (`POST /comments/edit/{comment_uid}`), deletion | | `/projects` | Project listing (left panel offers type filtering and free-text `search` over title, description, and author username), creation, owner editing (`POST /projects/edit/{slug}`), and per-project visibility toggles: `POST /projects/{slug}/private` (owner-only visibility) and `POST /projects/{slug}/readonly` (immutable files). A project hidden by a member stays visible to administrators, but a project hidden by an administrator is visible only to that owner administrator - other administrators cannot see it, its files, or its containers (web UI and REST API alike). The primary administrator (the first Admin account) is the single exception and retains full visibility | +| `/projects/{slug}` | Dedicated project page: one encompassing card with a cover banner and project logo (owner-uploaded through the standard attachment uploader), the title overlaid on the banner, status/type/platform chips, owner-set Website and Repository links, section tabs (Overview, Devlog, Screenshots, Comments, Files), an About section, the Devlog timeline of every post linked to the project (owners post updates straight from the page via the shared composer preset to the `devlog` topic), a Screenshots gallery built from image attachments (owners add more from the More menu), and a sidebar with links, stats and the author card | | `/projects/{slug}/files` | Per-project filesystem: directory and file CRUD, upload, inline editing, and line-range operations (`lines` read, `replace-lines`, `insert-lines`, `delete-lines`, `append`) for surgical edits to large text files (public read, owner write; all writes refused while the project is read-only) | | `/zips` | Zip job status (`/zips/{uid}`) and archive download (`/zips/{uid}/download`); archives are queued via `/projects/{slug}/zip` and `/projects/{slug}/files/zip` | | `/forks` | Fork job status (`/forks/{uid}`); forks are queued via `/projects/{slug}/fork`. Any signed-in user can fork a project they can view into a new project they own; once the job finishes the response carries the new project URL | diff --git a/devplacepy/content.py b/devplacepy/content.py index 25fc306c..597f9e65 100644 --- a/devplacepy/content.py +++ b/devplacepy/content.py @@ -854,6 +854,10 @@ def enrich_items( return enriched +def count_project_devlog(project_uid: str) -> int: + return get_table("posts").count(project_uid=project_uid, deleted_at=None) + + def get_project_devlog( project_uid: str, before: str | None = None, viewer: dict | None = None ) -> tuple[list, str | None]: diff --git a/devplacepy/docs_api/groups/content.py b/devplacepy/docs_api/groups/content.py index fac43470..61cc1680 100644 --- a/devplacepy/docs_api/groups/content.py +++ b/devplacepy/docs_api/groups/content.py @@ -362,7 +362,7 @@ four ways to sign requests. method="GET", path="/projects/{project_slug}", title="View a project", - summary="Render a project with comments. Returns an HTML page.", + summary="Render the project overview with its devlog, screenshots and comments. Returns an HTML page.", auth="public", interactive=True, params=[ @@ -373,7 +373,42 @@ four ways to sign requests. True, "PROJECT_SLUG", "Slug or UID of the project.", - ) + ), + field( + "before", + "query", + "string", + False, + "", + "Devlog pagination cursor (devlog_next_cursor from the previous page).", + ), + ], + ), + endpoint( + id="projects-screenshots", + method="POST", + path="/projects/{project_slug}/screenshots", + title="Add screenshots to a project", + summary="Link uploaded image attachments to an owned project's Screenshots gallery. Redirects to the gallery.", + auth="user", + encoding="form", + params=[ + field( + "project_slug", + "path", + "string", + True, + "my-project-1a2b3c4d", + "Project slug or uid.", + ), + field( + "attachment_uids", + "form", + "string", + True, + "ATTACHMENT_UID", + "Comma-separated attachment uids from POST /uploads/upload or /uploads/upload-url.", + ), ], ), endpoint( @@ -443,6 +478,38 @@ four ways to sign requests. "31/12/2026", "Optional demo date in DD/MM/YYYY format.", ), + field( + "website_url", + "form", + "string", + False, + "https://myproject.dev", + "Optional official website URL (http/https).", + ), + field( + "repo_url", + "form", + "string", + False, + "https://github.com/me/project", + "Optional source repository URL (http/https).", + ), + field( + "cover_attachment_uid", + "form", + "string", + False, + "ATTACHMENT_UID", + "Optional attachment uid of an uploaded cover image.", + ), + field( + "logo_attachment_uid", + "form", + "string", + False, + "ATTACHMENT_UID", + "Optional attachment uid of an uploaded project logo.", + ), ], ), endpoint( @@ -520,6 +587,38 @@ four ways to sign requests. "31/12/2026", "Optional demo date in DD/MM/YYYY format.", ), + field( + "website_url", + "form", + "string", + False, + "https://myproject.dev", + "Optional official website URL (http/https).", + ), + field( + "repo_url", + "form", + "string", + False, + "https://github.com/me/project", + "Optional source repository URL (http/https).", + ), + field( + "cover_attachment_uid", + "form", + "string", + False, + "ATTACHMENT_UID", + "Optional attachment uid of an uploaded cover image.", + ), + field( + "logo_attachment_uid", + "form", + "string", + False, + "ATTACHMENT_UID", + "Optional attachment uid of an uploaded project logo.", + ), ], ), endpoint( diff --git a/devplacepy/models.py b/devplacepy/models.py index f1ce4687..c0ef24b1 100644 --- a/devplacepy/models.py +++ b/devplacepy/models.py @@ -5,7 +5,7 @@ import re from datetime import datetime from typing import Literal, Optional -from urllib.parse import urlsplit +from urllib.parse import urlsplit, urlparse from pydantic import BaseModel, Field, field_validator, model_validator from devplacepy.constants import TOPICS from devplacepy.rendering import is_single_emoji @@ -33,6 +33,20 @@ def normalize_european_date(value): raise ValueError("Date must be in DD/MM/YYYY format") +def normalize_website_url(value): + if not value: + return "" + text = str(value).strip() + if not text: + return "" + if not text.lower().startswith(("http://", "https://")): + text = f"https://{text}" + parsed = urlparse(text) + if parsed.scheme not in ("http", "https") or not parsed.hostname or "." not in parsed.hostname: + raise ValueError("Website must be a valid http(s) URL") + return text + + def normalize_poll_options(value): if value is None: return [] @@ -241,6 +255,10 @@ class ProjectForm(BaseModel): ) platforms: str = Field(default="", max_length=500) status: str = Field(default="In Development", max_length=100) + website_url: str = Field(default="", max_length=500) + repo_url: str = Field(default="", max_length=500) + cover_attachment_uid: str = Field(default="", max_length=64) + logo_attachment_uid: str = Field(default="", max_length=64) is_private: bool = False attachment_uids: list[str] = [] @@ -249,6 +267,11 @@ class ProjectForm(BaseModel): def normalize_dates(cls, value): return normalize_european_date(value) + @field_validator("website_url", "repo_url") + @classmethod + def valid_link_url(cls, value): + return normalize_website_url(value) + class ProjectEditForm(BaseModel): title: str = Field(min_length=1, max_length=200) @@ -260,12 +283,21 @@ class ProjectEditForm(BaseModel): ) platforms: str = Field(default="", max_length=500) status: str = Field(default="In Development", max_length=100) + website_url: str = Field(default="", max_length=500) + repo_url: str = Field(default="", max_length=500) + cover_attachment_uid: str = Field(default="", max_length=64) + logo_attachment_uid: str = Field(default="", max_length=64) @field_validator("release_date", "demo_date", mode="before") @classmethod def normalize_dates(cls, value): return normalize_european_date(value) + @field_validator("website_url", "repo_url") + @classmethod + def valid_link_url(cls, value): + return normalize_website_url(value) + class BackupRunForm(BaseModel): target: Literal["database", "uploads", "keys", "full"] = "full" @@ -290,6 +322,10 @@ class ProjectFlagForm(BaseModel): value: bool = False +class ProjectScreenshotsForm(BaseModel): + attachment_uids: list[str] = [] + + class CustomizationToggleForm(BaseModel): value: bool = False diff --git a/devplacepy/routers/projects/CLAUDE.md b/devplacepy/routers/projects/CLAUDE.md index 4e30f085..137e42fa 100644 --- a/devplacepy/routers/projects/CLAUDE.md +++ b/devplacepy/routers/projects/CLAUDE.md @@ -9,6 +9,8 @@ This file documents the project detail page, the per-project virtual filesystem, Each project card links to `/projects/{project_uid}` showing full project details, author info, platforms, star count, delete-for-owner, and (for the owner) Private/Read-only toggle buttons plus badges (see **Project visibility and read-only** below). The route is `GET /projects/{project_uid}` in `routers/projects/index.py` and 404s when the viewer cannot see a private project. The sitemap generator links to this URL (not the old `?user_uid=` query param). The detail page also links to the project filesystem at `/projects/{slug}/files`. +**Project overview page.** The detail page is a dedicated project showcase: one encompassing dark card (`.project-shell`, the site `--bg-card` surface with clipped corners) wraps the hero, the section tab bar and the two-column body, and every inner panel (tab bar, sidebar cards, devlog post cards, empty state, comments section) sits one elevation lighter on `--bg-secondary`. The hero's cover banner is the attachment referenced by `projects.cover_attachment_uid`, falling back to the first image attachment (brand-gradient band when neither exists); the title block, type/platform chips and author row render OVERLAID on the banner behind a bottom scrim (dark text-shadow for readability) beside the optional `projects.logo_attachment_uid` tile, with an owner-set **Visit Website** CTA (`projects.website_url`). Cover and logo ride the ONE existing upload pipeline: `dp-upload` widgets (`name="cover_attachment_uid"`/`"logo_attachment_uid"`, `max-files="1"`) in the create/edit modals upload to `/uploads/upload`, the route validates each uid via `database.get_user_attachment` (must exist, belong to the actor, be an image - `_hero_attachment_uid`) and links it to the project through `attachments.link_attachments`; an empty value on edit keeps the current image (no removal control). `website_url`/`repo_url` are normalized by `models.normalize_website_url` (scheme-less input gets `https://`, non-http(s) rejected) and render with `rel="noopener nofollow"`. Below the hero an anchor **section tab bar** (`.project-tabs`, underline style, Overview `.active`) links `#about` / `#devlog` / `#screenshots` (only when gallery images exist) / `#comments` / the Files page - server-rendered anchors, no JS tab state. The main column holds **About** (description + non-image attachments), the **Devlog** (every post whose `project_uid` points at the project via `_post_card.html` - the template loads `feed.css` for the card styles alongside `post.css`, the same rule as `news.html`) with `devlog_count` (`content.count_project_devlog`) and an owner **Post update** button (`.project-devlog-post-btn`) opening the shared composer preset to `topic=devlog` + this project (the form lives ONCE in `templates/_post_composer_form.html`, locals `_composer_topic`/`_composer_project`, included by `feed.html` and `project_detail.html` - never fork a second copy), a **Screenshots** gallery (image attachments minus the cover/logo, thumbnails, `data-lightbox`, capped at 12 rendered), and the comment thread; the sidebar holds Links (website/repository/files/fork source), the Stats card (5 `.project-stat` entries + a last-update line) and the Author card. Owners add gallery images via the More-menu **Add screenshots** modal: `_attachment_form.html` uploads, then `POST /projects/{slug}/screenshots` (`ProjectScreenshotsForm`, owner-only, audit `project.screenshots.add`) links the uids through the same `link_attachments` choke point; Devii action `project_add_screenshots`, docs id `projects-screenshots`. `comment_count`/`devlog_count` ride `ProjectDetailOut`; the new project fields ride `ProjectOut`; the page og:image prefers the cover attachment. **Locator discipline:** the page has several `Files` anchors (action row, tab bar, sidebar) and, for owners, a second hidden `textarea[name='content']`/Post button inside the composer modal - tests MUST scope (`.project-detail-actions a:has-text('Files')`, `.comment-form textarea[name='content']`). + **Action row overflow.** The detail page has more actions than fit one line, so `project_detail.html` keeps the engagement actions inline (Files, Share, star vote, bookmark, reactions) and collapses the rest behind a single **More** button (`.project-actions-more`) that opens the shared `app.contextMenu`. The secondary actions (Workspace, Containers, Download zip, Fork, the owner Edit/Private/Read-only/Delete controls) live as real elements inside a hidden `.project-actions-overflow` container, each tagged `data-menu-action` plus `data-menu-icon`/`data-menu-label`. `static/js/ProjectActionsMenu.js` builds the menu from those elements and each item's `onSelect` simply `.click()`s the real element, so all existing wiring is reused unchanged - `app.zipDownloader` (`data-zip-download`), `app.projectForker` (`data-fork-project`), `data-share`, the `data-modal` Edit trigger, and the delegated `data-confirm`/`data-confirm-danger` dialog on the owner forms. The open handler must `stopPropagation()` because `app.contextMenu`'s document-level close listener would otherwise dismiss it on the same click (every other caller opens it from a right-click `attach`, not a left-click). Reuse this pattern - a `More` trigger over `[data-menu-action]` real elements - for any future action row that overflows; do not duplicate controller logic into menu callbacks. **Owner editing.** Mirrors post editing exactly: an owner-only **Edit** menu item (`data-modal="edit-project-modal"`) opens the `modal()` macro's `edit-project-modal`, a plain `POST` form to `/projects/edit/{slug}` (route `edit_project` in `routers/projects/index.py`, body `ProjectEditForm`, owner-gated through the shared `content.edit_content_item` which returns 403 JSON / redirect for non-owners and stamps `updated_at`). The modal is the create modal pre-filled from the `project` row (title, description, type/status radios pre-checked, dates via `format_date()` back to DD/MM/YYYY). `is_private`/`read_only` are NOT edited here - they stay on their dedicated toggles. The platforms tag widget reuses the create modal's `platforms-input`/`platforms`/`platforms-tags` ids; `ProfileEditor.initPlatformTags` now **seeds existing tags** from the hidden `#platforms` value on load, so both the empty create form and the pre-filled edit form work from the same code. Devii tool `edit_project`; documented in `docs_api.py` (`projects-edit`). diff --git a/devplacepy/routers/projects/index.py b/devplacepy/routers/projects/index.py index 681c6e70..bc516617 100644 --- a/devplacepy/routers/projects/index.py +++ b/devplacepy/routers/projects/index.py @@ -4,9 +4,15 @@ import logging from typing import Annotated from sqlalchemy import or_ from fastapi import Depends, APIRouter, Request -from devplacepy.models import ProjectForm, ProjectEditForm, ProjectFlagForm, ForkForm +from devplacepy.models import ( + ProjectForm, + ProjectEditForm, + ProjectFlagForm, + ProjectScreenshotsForm, + ForkForm, +) from fastapi.responses import HTMLResponse, RedirectResponse, JSONResponse -from devplacepy.attachments import get_attachments_batch +from devplacepy.attachments import get_attachments_batch, link_attachments from devplacepy.database import ( get_table, get_users_by_uids, @@ -25,6 +31,7 @@ from devplacepy.database import ( get_fork_parent, count_forks, get_top_authors, + get_user_attachment, ) from devplacepy.project_files import count_files from devplacepy.services.jobs import queue @@ -41,6 +48,7 @@ from devplacepy.content import ( can_view_project_containers, can_open_workspace, get_project_devlog, + count_project_devlog, ) from devplacepy.utils import ( get_current_user, @@ -196,6 +204,18 @@ def _editor_launch(project: dict, user: dict) -> dict: } +def _hero_attachment_uid(user: dict, raw_uid: str) -> str | None: + uid = (raw_uid or "").strip() + if not uid: + return None + attachment = get_user_attachment(uid) + if not attachment or attachment.get("user_uid") != user["uid"]: + return None + if not attachment.get("is_image"): + return None + return uid + + @router.get("/{project_slug}", response_class=HTMLResponse) async def project_detail(request: Request, project_slug: str, before: str = None): user = get_current_user(request) @@ -215,13 +235,21 @@ async def project_detail(request: Request, project_slug: str, before: str = None base = site_url(request) robots = "noindex,nofollow" if project.get("is_private") else "index,follow" + cover_url = next( + ( + a["url"] + for a in detail["attachments"] + if a["uid"] == project.get("cover_attachment_uid") and a.get("is_image") + ), + None, + ) seo_ctx = base_seo_context( request, title=project.get("title", "Project"), description=project.get("description", ""), seo_target=("project", project["uid"]), robots=robots, - og_image=first_image_url(project, detail["attachments"]), + og_image=cover_url or first_image_url(project, detail["attachments"]), breadcrumbs=[ {"name": "Home", "url": "/feed"}, {"name": "Projects", "url": "/projects"}, @@ -292,8 +320,14 @@ async def project_detail(request: Request, project_slug: str, before: str = None "forked_from": forked_from, "fork_count": count_forks(project["uid"]), "file_count": count_files(project["uid"]), + "comment_count": get_table("comments").count( + target_type="project", + target_uid=project["uid"], + deleted_at=None, + ), "devlog_posts": devlog_posts, "devlog_next_cursor": devlog_next_cursor, + "devlog_count": count_project_devlog(project["uid"]), }, ), model=ProjectDetailOut, @@ -409,6 +443,8 @@ async def create_project(request: Request, data: Annotated[ProjectForm, Depends( user = require_user(request) title = data.title.strip() description = data.description.strip() + cover_uid = _hero_attachment_uid(user, data.cover_attachment_uid) + logo_uid = _hero_attachment_uid(user, data.logo_attachment_uid) uid, project_slug = create_content_item( "projects", @@ -422,6 +458,10 @@ async def create_project(request: Request, data: Annotated[ProjectForm, Depends( "project_type": data.project_type, "platforms": data.platforms.strip(), "status": data.status, + "website_url": data.website_url or None, + "repo_url": data.repo_url or None, + "cover_attachment_uid": cover_uid, + "logo_attachment_uid": logo_uid, "is_private": 1 if data.is_private else 0, "read_only": 0, }, @@ -432,6 +472,7 @@ async def create_project(request: Request, data: Annotated[ProjectForm, Depends( data.attachment_uids, request, ) + link_attachments([u for u in (cover_uid, logo_uid) if u], "project", uid) url = f"/projects/{project_slug}" return action_result( request, url, data={"uid": uid, "slug": project_slug, "url": url} @@ -442,23 +483,71 @@ async def edit_project( request: Request, project_slug: str, data: Annotated[ProjectEditForm, Depends(json_or_form(ProjectEditForm))] ): user = require_user(request) - return edit_content_item( + fields = { + "title": data.title.strip(), + "description": data.description.strip(), + "release_date": data.release_date or None, + "demo_date": data.demo_date or None, + "project_type": data.project_type, + "platforms": data.platforms.strip(), + "status": data.status, + "website_url": data.website_url or None, + "repo_url": data.repo_url or None, + } + hero_uids = [] + for field in ("cover_attachment_uid", "logo_attachment_uid"): + uid = _hero_attachment_uid(user, getattr(data, field)) + if uid: + fields[field] = uid + hero_uids.append(uid) + result = edit_content_item( request, "projects", user, project_slug, - { - "title": data.title.strip(), - "description": data.description.strip(), - "release_date": data.release_date or None, - "demo_date": data.demo_date or None, - "project_type": data.project_type, - "platforms": data.platforms.strip(), - "status": data.status, - }, + fields, "/projects", target_type="project", ) + if hero_uids: + project = resolve_by_slug(get_table("projects"), project_slug) + if project and is_owner(project, user): + link_attachments(hero_uids, "project", project["uid"]) + return result + +@router.post("/{project_slug}/screenshots") +async def add_project_screenshots( + request: Request, + project_slug: str, + data: Annotated[ProjectScreenshotsForm, Depends(json_or_form(ProjectScreenshotsForm))], +): + user = require_user(request) + project = resolve_by_slug(get_table("projects"), project_slug) + if not project: + raise not_found("Project not found") + if not is_owner(project, user): + if wants_json(request): + return json_error(403, "Not allowed") + return RedirectResponse(url=f"/projects/{project_slug}", status_code=302) + link_attachments(data.attachment_uids, "project", project["uid"]) + audit.record( + request, + "project.screenshots.add", + user=user, + target_type="project", + target_uid=project["uid"], + target_label=project.get("title"), + metadata={"attachment_count": len(data.attachment_uids)}, + summary=f"{user['username']} added {len(data.attachment_uids)} screenshot(s) to project {project.get('title')}", + links=[audit.target("project", project["uid"], project.get("title"))], + ) + url = f"/projects/{project['slug'] or project['uid']}#screenshots" + return action_result( + request, + url, + data={"uid": project["uid"], "linked": len(data.attachment_uids), "url": url}, + ) + _FLAG_EVENTS = { ("is_private", True): "project.visibility.private", diff --git a/devplacepy/schemas/content.py b/devplacepy/schemas/content.py index 8f8c79a1..1be90e70 100644 --- a/devplacepy/schemas/content.py +++ b/devplacepy/schemas/content.py @@ -121,6 +121,10 @@ class ProjectOut(_Out): read_only: Optional[bool] = None release_date: Optional[str] = None demo_date: Optional[str] = None + website_url: Optional[str] = None + repo_url: Optional[str] = None + cover_attachment_uid: Optional[str] = None + logo_attachment_uid: Optional[str] = None created_at: Optional[str] = None updated_at: Optional[str] = None diff --git a/devplacepy/schemas/listings.py b/devplacepy/schemas/listings.py index ab77b31e..dcc0d44f 100644 --- a/devplacepy/schemas/listings.py +++ b/devplacepy/schemas/listings.py @@ -175,8 +175,10 @@ class ProjectDetailOut(_Out): forked_from: Optional[dict] = None fork_count: int = 0 file_count: int = 0 + comment_count: int = 0 devlog_posts: list[FeedItemOut] = [] devlog_next_cursor: Optional[str] = None + devlog_count: int = 0 class GistsOut(_Out): diff --git a/devplacepy/services/devii/actions/catalog/projects.py b/devplacepy/services/devii/actions/catalog/projects.py index b6f0aae6..14b1db60 100644 --- a/devplacepy/services/devii/actions/catalog/projects.py +++ b/devplacepy/services/devii/actions/catalog/projects.py @@ -47,6 +47,10 @@ PROJECTS_ACTIONS: tuple[Action, ...] = ( body("project_type", "Project type."), body("platforms", "Supported platforms."), body("status", "Project status."), + body("website_url", "Official website URL (http/https)."), + body("repo_url", "Source repository URL (http/https)."), + body("cover_attachment_uid", "Attachment uid of an uploaded cover image (upload_file/attach_url first)."), + body("logo_attachment_uid", "Attachment uid of an uploaded project logo (upload_file/attach_url first)."), body("attachment_uids", ATTACHMENTS), ), ), @@ -67,6 +71,23 @@ PROJECTS_ACTIONS: tuple[Action, ...] = ( body("project_type", "Updated project type."), body("platforms", "Updated supported platforms."), body("status", "Updated project status."), + body("website_url", "Updated official website URL (http/https)."), + body("repo_url", "Updated source repository URL (http/https)."), + body("cover_attachment_uid", "Attachment uid of a new cover image; empty keeps the current one."), + body("logo_attachment_uid", "Attachment uid of a new project logo; empty keeps the current one."), + ), + ), + Action( + name="project_add_screenshots", + method="POST", + path="/projects/{project_slug}/screenshots", + summary="Add screenshots to an owned project (upload first via upload_file or attach_url, then pass the attachment uids)", + params=( + path( + "project_slug", + "Exact project slug copied from a /projects/... link in a listing response; do not build it from the title.", + ), + body("attachment_uids", ATTACHMENTS, required=True), ), ), Action( diff --git a/devplacepy/static/css/projects.css b/devplacepy/static/css/projects.css index f6204e54..e65ef093 100644 --- a/devplacepy/static/css/projects.css +++ b/devplacepy/static/css/projects.css @@ -223,16 +223,327 @@ } } -.project-detail-page { - max-width: 720px; +.project-page { + max-width: var(--max-content); margin: 0 auto; } -.project-detail { + +.project-shell { background: var(--bg-card); border: 1px solid var(--border); border-radius: var(--radius-lg); + overflow: hidden; + box-shadow: var(--shadow-sm); +} + +.project-shell > .project-tabs, +.project-shell > .project-columns { + margin-left: 1.5rem; + margin-right: 1.5rem; +} + +.project-shell > .project-columns { + margin-bottom: 1.5rem; +} + +.project-shell .project-tabs, +.project-shell .project-sidebar-card, +.project-shell .post-card, +.project-shell .empty-state, +.project-shell .comments-section { + background: var(--bg-secondary); +} + +.project-cover { + position: relative; + min-height: 320px; + display: flex; + align-items: flex-end; + background: var(--bg-secondary); +} + +.project-cover-img { + position: absolute; + inset: 0; + width: 100%; + height: 100%; + object-fit: cover; +} + +.project-cover-fallback { + min-height: 200px; + background: var(--accent-gradient); +} + +.project-cover-fallback::before { + content: ""; + position: absolute; + inset: 0; + background: var(--overlay-dark); +} + +.project-cover-scrim { + position: absolute; + inset: 0; + background: linear-gradient(180deg, rgba(0, 0, 0, 0) 30%, rgba(0, 0, 0, 0.78) 100%); +} + +.project-hero-overlay { + position: relative; + z-index: 1; + display: flex; + align-items: flex-end; + gap: 1.25rem; + width: 100%; padding: 1.5rem; } + +.project-logo { + width: 112px; + height: 112px; + object-fit: cover; + border-radius: var(--radius-lg); + border: 2px solid var(--border-light); + background: var(--bg-card); + box-shadow: var(--shadow); + flex-shrink: 0; +} + +.project-hero-headline { + min-width: 0; + flex: 1; +} + +.project-hero-overlay .project-detail-title, +.project-hero-overlay .project-detail-author { + text-shadow: 0 1px 2px rgba(0, 0, 0, 0.9), 0 2px 12px rgba(0, 0, 0, 0.6); +} + +.project-hero-overlay .project-detail-header { + margin-bottom: 0.5rem; + justify-content: flex-start; + gap: 0.75rem; + align-items: center; +} + +.project-hero-chips { + margin-bottom: 0.625rem; +} + +.project-hero-overlay .project-detail-author { + margin-bottom: 0; + padding-bottom: 0; + border-bottom: none; +} + +.project-hero-ctas { + flex-shrink: 0; +} + +.project-hero-body { + padding: 1rem 1.5rem 1.25rem; +} + +.project-tabs { + display: flex; + gap: 0.25rem; + margin: 1rem 0; + border: 1px solid var(--border); + border-radius: var(--radius-lg); + padding: 0 0.5rem; + flex-wrap: wrap; +} + +.project-tab { + display: inline-flex; + align-items: center; + gap: 0.375rem; + padding: 0.75rem 1rem; + border-bottom: 2px solid transparent; + font-size: 0.8125rem; + font-weight: 600; + color: var(--text-secondary); +} + +.project-tab:hover { + color: var(--text-primary); +} + +.project-tab.active { + color: var(--text-primary); + border-bottom-color: var(--accent); +} + +.project-tab-count { + font-size: 0.6875rem; + font-weight: 700; + padding: 0.0625rem 0.375rem; + border-radius: 999px; + background: var(--overlay-light); + border: 1px solid var(--border); + color: var(--text-muted); +} + +.project-columns { + display: grid; + grid-template-columns: minmax(0, 1fr) 300px; + gap: 1.25rem; + align-items: start; +} + +.project-main { + min-width: 0; +} + +.project-sidebar { + display: flex; + flex-direction: column; + gap: 1rem; +} + +.project-sidebar-card { + border: 1px solid var(--border); + border-radius: var(--radius-lg); + padding: 1rem 1.25rem; +} + +.project-link-list { + list-style: none; + display: flex; + flex-direction: column; + gap: 0.5rem; + font-size: 0.875rem; +} + +.project-link-list a { + color: var(--text-secondary); +} + +.project-link-list a:hover { + color: var(--accent); +} + +.project-stats { + display: grid; + grid-template-columns: repeat(2, minmax(0, 1fr)); + gap: var(--space-sm) var(--space-lg); + font-size: 0.8125rem; + color: var(--text-muted); +} + +.project-stat a { + color: var(--text-muted); +} + +.project-stat a:hover { + color: var(--accent); +} + +.project-stat-value { + font-weight: 700; + color: var(--text-primary); +} + +.project-last-update { + margin-top: 0.5rem; + font-size: 0.75rem; + color: var(--text-muted); +} + +.project-author-card { + display: flex; + align-items: center; + gap: 0.75rem; +} + +.project-author-meta { + display: flex; + flex-direction: column; + gap: 0.125rem; + font-size: 0.8125rem; +} + +.project-about { + margin-bottom: 1.5rem; +} + +.project-devlog { + margin-top: 1.5rem; +} + +.project-devlog-header { + display: flex; + align-items: center; + gap: var(--space-md); + margin-bottom: 0.75rem; +} + +.project-devlog-header .project-section-label { + margin-bottom: 0; +} + +.project-devlog-count { + font-size: 0.75rem; + color: var(--text-muted); +} + +.project-devlog-post-btn { + margin-left: auto; +} + +.project-screenshots { + margin-top: 1.5rem; +} + +.project-screenshot-grid { + display: grid; + grid-template-columns: repeat(auto-fill, minmax(180px, 1fr)); + gap: 0.75rem; +} + +.project-screenshot { + width: 100%; + aspect-ratio: 16 / 10; + object-fit: cover; + border-radius: var(--radius); + border: 1px solid var(--border); + cursor: zoom-in; +} + +.project-screenshot-more { + margin-top: 0.5rem; + font-size: 0.75rem; + color: var(--text-muted); +} + +.project-comments { + margin-top: 1.5rem; +} + +@media (max-width: 1024px) { + .project-columns { + grid-template-columns: minmax(0, 1fr); + } + .project-cover { + min-height: 240px; + } +} + +@media (max-width: 768px) { + .project-hero-overlay { + flex-wrap: wrap; + align-items: flex-start; + gap: 0.75rem; + } + .project-logo { + width: 72px; + height: 72px; + } + .project-cover { + min-height: 200px; + } +} + .project-detail-header { display: flex; align-items: flex-start; @@ -304,14 +615,6 @@ color: var(--warning); } -.project-platforms { - margin-bottom: 1.5rem; -} - -.project-devlog { - margin-top: 1.5rem; -} - .project-section-label { font-size: 0.75rem; font-weight: 700; diff --git a/devplacepy/templates/CLAUDE.md b/devplacepy/templates/CLAUDE.md index c9cd74e1..d9e5ab31 100644 --- a/devplacepy/templates/CLAUDE.md +++ b/devplacepy/templates/CLAUDE.md @@ -65,6 +65,7 @@ Do NOT hand-write the overlay/header markup. Use the shared macro in `templates/ Reuse these via `{% set _x = ... %}{% include %}` (the `_avatar_link.html` convention) instead of copy-pasting markup: +- `_post_composer_form.html` - the create-post form (topic selector, content/title, project select, attachments, poll builder, footer). Locals: `_composer_topic` (preselected topic, default `random`), `_composer_project` (preselected project uid or `""`). Wrapped in the `modal()` macro by `feed.html` (Create New Post) and `project_detail.html` (owner-only Post an update, preset to `devlog` + the project). Never fork a second copy of this form. - `_post_votes.html` - post +/- vote bar. Locals: `_uid`, `_my_vote`, `_count`. - `_star_vote.html` - project/gist star button. Locals: `_type` (`project`|`gist`), `_uid`, `_my_vote`, `_count`, `_btn_class`, optional `_stop` (adds `data-stop-propagation`). The star glyph (`☆`→`★` when `.voted`) comes from the `vote-star` CSS class via `::before` (`base.css`) - do not put a literal star in markup. - `_post_header.html` - post author/avatar/time header (`.post-header`). Locals: `_author`, `_time`. diff --git a/devplacepy/templates/_post_composer_form.html b/devplacepy/templates/_post_composer_form.html new file mode 100644 index 00000000..c29943ff --- /dev/null +++ b/devplacepy/templates/_post_composer_form.html @@ -0,0 +1,48 @@ +
+ {% set _topics = TOPICS %}{% set _selected = _composer_topic or 'random' %}{% include "_topic_selector.html" %} + +
+ + + 0/125000 +
+ +
+ + + 0/500 +
+ +
+ + +
+ +
+ + {% include "_attachment_form.html" %} +
+ +
+ +
+ + + +
diff --git a/devplacepy/templates/feed.html b/devplacepy/templates/feed.html index 47cb5016..608bd9fe 100644 --- a/devplacepy/templates/feed.html +++ b/devplacepy/templates/feed.html @@ -160,54 +160,7 @@ + {% call modal('create-post-modal', 'Create New Post') %} -
- {% set _topics = TOPICS %}{% set _selected = 'random' %}{% include "_topic_selector.html" %} - -
- - - 0/125000 -
- -
- - - 0/500 -
- -
- - -
- -
- - {% include "_attachment_form.html" %} -
- -
- -
- - - -
+ {% set _composer_topic = 'random' %}{% set _composer_project = '' %}{% include "_post_composer_form.html" %} {% endcall %} {% else %} + diff --git a/devplacepy/templates/project_detail.html b/devplacepy/templates/project_detail.html index 1f0ea927..a21fbb3e 100644 --- a/devplacepy/templates/project_detail.html +++ b/devplacepy/templates/project_detail.html @@ -3,137 +3,261 @@ {% block extra_head %} + {% endblock %} {% block content %} -
+{% set project_url = "/projects/" ~ (project['slug'] or project['uid']) %} +{% set cover = attachments | selectattr('uid', 'equalto', project.get('cover_attachment_uid', '')) | selectattr('is_image') | list | first %} +{% set logo = attachments | selectattr('uid', 'equalto', project.get('logo_attachment_uid', '')) | selectattr('is_image') | list | first %} +{% set hero_uids = [(cover or {}).get('uid'), (logo or {}).get('uid')] %} +{% set gallery = attachments | selectattr('is_image') | rejectattr('uid', 'in', hero_uids) | list %} +{% set other_attachments = attachments | rejectattr('is_image') | list %} +{% set cover_src = (cover or {}).get('url') or ((gallery | first or {}).get('url')) %} +
← Back to Projects -
-
-

{{ render_title(project['title'], author_is_admin=is_admin(author)) }}

-
- ● {{ project.get('status', 'In Development') }} -
-
- - {% if is_private or read_only %} -
- {% if is_private %}Private{% endif %} - {% if read_only %}Read-only{% endif %} -
- {% endif %} - -
- {{ project.get('project_type', 'software').replace('_', ' ') }} - {% if project.get('release_date') %} - 📅 Released: {{ format_date(project['release_date']) }} +
+
+
+ {% if cover_src %} + {{ project['title'] }} cover image {% endif %} - {% if project.get('demo_date') %} - 🎭 Demo: {{ format_date(project['demo_date']) }} - {% endif %} -
- - {% if forked_from %} - - {% endif %} - -
- {% set _size = 32 %}{% set _size_class = "sm" %}{% set _user = author %}{% include "_avatar_link.html" %} -
- {% set _user = author %}{% set _class = none %}{% include "_user_link.html" %} - · Level {{ author.get('level', 1) if author else 1 }} -
-
- - {% if maturity_hidden(maturity, user) %} - {% set _level = maturity %}{% include "_maturity_gate.html" %} - {% else %} -
{{ render_content(project.get('description', ''), author_is_admin=is_admin(author)) }}
- {% endif %} - - {% if attachments %} - {% include "_attachment_display.html" %} - {% endif %} - - {% if platforms %} -
- -
- {% for plat in platforms %} - {{ plat.strip() }} - {% endfor %} -
-
- {% endif %} - -
- 📁 Files ({{ file_count }} files) - {% if workspace_editor_url %} - {% set _url = workspace_editor_url %} - {% set _uid = project['uid'] %} - {% set _class = "project-star-btn" %} - {% set _icon = "💻"|safe %} - {% set _mode = workspace_editor_mode %} - {% set _width = workspace_editor_width %} - {% set _height = workspace_editor_height %} - {% set _label = "Editor" %} - {% include "_editor_open.html" %} - {% endif %} - - {% if user %} - {% set _type = "project" %}{% set _uid = project['uid'] %}{% set _my_vote = my_vote %}{% set _count = star_count %}{% set _btn_class = "project-star-btn" %}{% include "_star_vote.html" %} - {% endif %} - {% set _type = "project" %}{% set _uid = project['uid'] %}{% set _bookmarked = bookmarked %}{% include "_bookmark_button.html" %} - {% set _type = "project" %}{% set _uid = project['uid'] %}{% set _reactions = reactions %}{% include "_reaction_bar.html" %} - {% set _type = "project" %}{% set _uid = project['uid'] %}{% set _owner = project['user_uid'] %}{% set _owner_name = (author or {}).get('username', '') %}{% set _class = "project-star-btn" %}{% include "_report_button.html" %} - - - +
+ {% if project.get('release_date') or project.get('demo_date') or forked_from %} +
+ {% if project.get('release_date') %} + 📅 Released: {{ format_date(project['release_date']) }} + {% endif %} + {% if project.get('demo_date') %} + 🎭 Demo: {{ format_date(project['demo_date']) }} + {% endif %} + {% if forked_from %} + ⑂ Forked from {{ render_title(forked_from['title']) }} + {% endif %} +
+ {% endif %} + +
+ 📁 Files ({{ file_count }} files) + {% if workspace_editor_url %} + {% set _url = workspace_editor_url %} + {% set _uid = project['uid'] %} + {% set _class = "project-star-btn" %} + {% set _icon = "💻"|safe %} + {% set _mode = workspace_editor_mode %} + {% set _width = workspace_editor_width %} + {% set _height = workspace_editor_height %} + {% set _label = "Editor" %} + {% include "_editor_open.html" %} + {% endif %} + {% if user %} - - {% endif %} - {% if is_owner %} - -
- - -
-
- - -
- {% endif %} - {% if is_owner or is_admin(user) %} -
- -
+ {% set _type = "project" %}{% set _uid = project['uid'] %}{% set _my_vote = my_vote %}{% set _count = star_count %}{% set _btn_class = "project-star-btn" %}{% include "_star_vote.html" %} {% endif %} + {% set _type = "project" %}{% set _uid = project['uid'] %}{% set _bookmarked = bookmarked %}{% include "_bookmark_button.html" %} + {% set _type = "project" %}{% set _uid = project['uid'] %}{% set _reactions = reactions %}{% include "_reaction_bar.html" %} + {% set _type = "project" %}{% set _uid = project['uid'] %}{% set _owner = project['user_uid'] %}{% set _owner_name = (author or {}).get('username', '') %}{% set _class = "project-star-btn" %}{% include "_report_button.html" %} + + +
-
- - {% if devlog_posts %} - {% for item in devlog_posts %} - {% set _author = item.author %}{% set _time = item.time_ago %}{% set _show_share = false %}{% set _show_comment_form = false %}{% include "_post_card.html" %} - {% endfor %} - {% set next_cursor = devlog_next_cursor %}{% include "_load_more.html" %} - {% else %} -

No devlog posts yet.

+
+ Comments {{ comment_count }} + Files {{ file_count }} + + +
+
+
+ + {% if maturity_hidden(maturity, user) %} + {% set _level = maturity %}{% include "_maturity_gate.html" %} + {% else %} +
{{ render_content(project.get('description', ''), author_is_admin=is_admin(author)) }}
+ {% endif %} + {% if other_attachments %} + {% set attachments = other_attachments %} + {% include "_attachment_display.html" %} + {% endif %} +
+ +
+
+ + {{ devlog_count }} update{{ '' if devlog_count == 1 else 's' }} + {% if is_owner %} + + {% endif %} +
+ {% if devlog_posts %} + {% for item in devlog_posts %} + {% set _author = item.author %}{% set _time = item.time_ago %}{% set _show_share = false %}{% set _show_comment_form = false %}{% include "_post_card.html" %} + {% endfor %} + {% set next_cursor = devlog_next_cursor %}{% include "_load_more.html" %} + {% else %} +

No devlog posts yet.{% if is_owner %} Share your first update to give this project a public build log.{% endif %}

+ {% endif %} +
+ + {% if gallery %} +
+ +
+ {% for shot in gallery[:12] %} + {{ project['title'] }} screenshot {{ loop.index }} + {% endfor %} +
+ {% if gallery | length > 12 %} +

Showing 12 of {{ gallery | length }} screenshots.

+ {% endif %} +
+ {% endif %} + +
+ {% with target_uid=project['uid'], target_type="project" %} + {% include "_comment_section.html" %} + {% endwith %} +
+
+ + +
+
{% if is_owner %} + {% call modal('create-post-modal', 'Post an update') %} + {% set _composer_topic = 'devlog' %}{% set _composer_project = project['uid'] %}{% include "_post_composer_form.html" %} + {% endcall %} + + {% call modal('add-screenshots-modal', 'Add screenshots') %} +
+
+ + {% include "_attachment_form.html" %} + Images appear in the Screenshots gallery; other files list under About. +
+ +
+ {% endcall %} + {% call modal('edit-project-modal', 'Edit Project') %}
@@ -157,6 +281,28 @@
+
+
+ + +
+
+ + +
+
+ +
+
+ + +
+
+ + +
+
+
@@ -200,10 +346,6 @@ {% endcall %} {% endif %} - - {% with target_uid=project['uid'], target_type="project" %} - {% include "_comment_section.html" %} - {% endwith %}
{% endblock %} {% block extra_js %} @@ -215,6 +357,3 @@ if (actions) { } {% endblock %} - - - diff --git a/devplacepy/templates/projects.html b/devplacepy/templates/projects.html index 966c8e06..a67662c1 100644 --- a/devplacepy/templates/projects.html +++ b/devplacepy/templates/projects.html @@ -126,6 +126,28 @@
+
+
+ + +
+
+ + +
+
+ +
+
+ + +
+
+ + +
+
+
diff --git a/devplacepy/templating.py b/devplacepy/templating.py index b150222a..08134506 100644 --- a/devplacepy/templating.py +++ b/devplacepy/templating.py @@ -13,7 +13,12 @@ from devplacepy.avatar import avatar_url, avatar_seed from devplacepy.utils import format_date as _format_date from devplacepy.utils import time_ago as _time_ago from devplacepy.utils import get_badge, is_admin, is_primary_admin, pretty_json -from devplacepy.attachments import format_file_size, file_icon_emoji +from devplacepy.attachments import ( + IMAGE_EXTENSIONS, + allowed_extensions, + format_file_size, + file_icon_emoji, +) from devplacepy.content import is_owner as _owns from devplacepy.content import maturity_hidden as _maturity_hidden from devplacepy.customization import custom_css_tag, custom_js_tag, page_type_for @@ -224,9 +229,14 @@ def jinja_allowed_file_types() -> str: return get_setting("allowed_file_types", "") +def jinja_allowed_image_types() -> str: + return ",".join(sorted(allowed_extensions() & IMAGE_EXTENSIONS)) + + templates.env.globals["max_upload_size_mb"] = jinja_max_upload_size_mb templates.env.globals["max_attachments_per_resource"] = jinja_max_attachments templates.env.globals["allowed_file_types"] = jinja_allowed_file_types +templates.env.globals["allowed_image_types"] = jinja_allowed_image_types _LANGUAGE_NAMES = { "python": "Python", diff --git a/events.md b/events.md index a9b30d3e..c57f2616 100644 --- a/events.md +++ b/events.md @@ -422,6 +422,7 @@ Every state-changing action in DevPlace records one append-only row through `dev | `project.fork.request` | `routers/projects/index.py` | | `project.readonly.disable` | `routers/projects/index.py` | | `project.readonly.enable` | `routers/projects/index.py` | +| `project.screenshots.add` | `routers/projects/index.py` | | `project.visibility.private` | `routers/projects/index.py` | | `project.visibility.public` | `routers/projects/index.py` | | `project.zip.request` | `routers/projects/index.py` | diff --git a/tests/api/projects/devlog.py b/tests/api/projects/devlog.py index 297f2397..a6ea0abb 100644 --- a/tests/api/projects/devlog.py +++ b/tests/api/projects/devlog.py @@ -271,3 +271,124 @@ def test_devlog_works_for_guest_visitor(app_server): assert "devlog_posts" in body assert body["devlog_posts"] == [] + +def test_devlog_count_and_comment_count_in_json(app_server): + """devlog_count and comment_count ride the detail JSON.""" + session, name = _member() + project = _create_project(session) + slug = project["slug"] or project["uid"] + user = _db_user(name) + + for i in range(3): + _create_post_direct(project["uid"], user["uid"], i) + + r = session.get(f"{BASE_URL}/projects/{slug}", headers=JSON) + assert r.status_code == 200, r.text[:300] + body = r.json() + assert body["devlog_count"] == 3 + assert body["comment_count"] == 0 + + +def _upload_image(session, name="shot.png", color=(30, 60, 120)): + import io + from PIL import Image + + buf = io.BytesIO() + Image.new("RGB", (10, 10), color).save(buf, "PNG") + r = session.post( + f"{BASE_URL}/uploads/upload", + files={"file": (name, buf.getvalue(), "image/png")}, + ) + assert r.status_code == 201, r.text[:300] + return r.json()["uid"] + + +def test_cover_and_logo_attachments_render_in_hero(app_server): + """cover/logo attachment uids resolve to the hero banner and logo tile.""" + session, _ = _member() + cover_uid = _upload_image(session, "cover.png", (10, 20, 90)) + logo_uid = _upload_image(session, "logo.png", (90, 20, 10)) + + r = session.post( + f"{BASE_URL}/projects/create", + headers=JSON, + data={ + "title": _unique("dlhero"), + "description": "Hero art test project", + "project_type": "game", + "status": "In Development", + "platforms": "PC", + "cover_attachment_uid": cover_uid, + "logo_attachment_uid": logo_uid, + }, + ) + assert r.status_code == 200, r.text[:300] + slug = r.json()["data"]["slug"] + + refresh_snapshot() + row = get_table("projects").find_one(slug=slug) + assert row["cover_attachment_uid"] == cover_uid + assert row["logo_attachment_uid"] == logo_uid + + html = session.get(f"{BASE_URL}/projects/{slug}").text + assert 'class="project-cover-img"' in html + assert 'class="project-logo"' in html + assert "project-screenshot-grid" not in html, ( + "Cover and logo must not repeat in the Screenshots gallery" + ) + + +def test_hero_attachment_uid_rejects_foreign_and_missing(app_server): + """A foreign or unknown attachment uid is ignored rather than linked.""" + owner, _ = _member() + other, _ = _member() + foreign_uid = _upload_image(other, "foreign.png") + + r = owner.post( + f"{BASE_URL}/projects/create", + headers=JSON, + data={ + "title": _unique("dlreject"), + "description": "Hero guard test project", + "project_type": "software", + "status": "In Development", + "platforms": "", + "cover_attachment_uid": foreign_uid, + "logo_attachment_uid": "does-not-exist", + }, + ) + assert r.status_code == 200, r.text[:300] + slug = r.json()["data"]["slug"] + refresh_snapshot() + row = get_table("projects").find_one(slug=slug) + assert row["cover_attachment_uid"] is None + assert row["logo_attachment_uid"] is None + + +def test_owner_adds_screenshots_from_the_page(app_server): + """POST /projects/{slug}/screenshots links uploads into the gallery; non-owners are refused.""" + session, _ = _member() + project = _create_project(session) + slug = project["slug"] or project["uid"] + + assert "project-screenshot-grid" not in session.get(f"{BASE_URL}/projects/{slug}").text + + uid = _upload_image(session, "gallery.png", (5, 120, 60)) + r = session.post( + f"{BASE_URL}/projects/{slug}/screenshots", + headers=JSON, + data={"attachment_uids": uid}, + ) + assert r.status_code == 200, r.text[:300] + assert r.json()["data"]["linked"] == 1 + + html = session.get(f"{BASE_URL}/projects/{slug}").text + assert "project-screenshot-grid" in html, "Expected the gallery after linking" + + intruder, _ = _member() + r = intruder.post( + f"{BASE_URL}/projects/{slug}/screenshots", + headers=JSON, + data={"attachment_uids": uid}, + ) + assert r.status_code == 403, r.text[:300] diff --git a/tests/api/projects/edit.py b/tests/api/projects/edit.py index 43144e49..57a22959 100644 --- a/tests/api/projects/edit.py +++ b/tests/api/projects/edit.py @@ -105,6 +105,47 @@ def test_owner_can_edit_project(app_server): assert row["platforms"] == "Linux,Web" +def test_owner_can_set_and_clear_link_urls(app_server): + _, _, key = _signup_project_visibility() + slug = _create_project_project_visibility(key, "Website Via Api")["slug"] + r = requests.post( + f"{BASE_URL}/projects/edit/{slug}", + headers=_h_project_visibility(key), + data={ + "title": "Website Via Api", + "description": "has links now", + "website_url": "myproject.dev/docs", + "repo_url": "github.com/me/website-via-api", + }, + allow_redirects=False, + ) + assert r.status_code == 200 and r.json()["ok"] is True + row = get_table("projects").find_one(slug=slug) + assert row["website_url"] == "https://myproject.dev/docs" + assert row["repo_url"] == "https://github.com/me/website-via-api" + + html = requests.get(f"{BASE_URL}/projects/{slug}").text + assert "Visit Website" in html + assert "Repository" in html + + r = requests.post( + f"{BASE_URL}/projects/edit/{slug}", + headers=_h_project_visibility(key), + data={ + "title": "Website Via Api", + "description": "links removed", + "website_url": "", + "repo_url": "", + }, + allow_redirects=False, + ) + assert r.status_code == 200 + row = get_table("projects").find_one(slug=slug) + assert row["website_url"] is None + assert row["repo_url"] is None + assert "Visit Website" not in requests.get(f"{BASE_URL}/projects/{slug}").text + + def test_non_owner_cannot_edit_project(app_server): _, _, owner_key = _signup_project_visibility() slug = _create_project_project_visibility(owner_key, "Owner Edit Guard")["slug"] diff --git a/tests/e2e/project/files.py b/tests/e2e/project/files.py index b84fe66d..a63f0a86 100644 --- a/tests/e2e/project/files.py +++ b/tests/e2e/project/files.py @@ -119,7 +119,7 @@ def _alice_key(): def test_files_link_on_detail(alice): page, _ = alice _make_project_ui(page, "UI Files Link") - link = page.locator("a:has-text('Files')") + link = page.locator(".project-detail-actions a:has-text('Files')") expect(link).to_be_visible() link.click() page.wait_for_url("**/files", wait_until="domcontentloaded") diff --git a/tests/e2e/projects/devlog.py b/tests/e2e/projects/devlog.py index 08850f5b..ec85b58e 100644 --- a/tests/e2e/projects/devlog.py +++ b/tests/e2e/projects/devlog.py @@ -85,7 +85,7 @@ def test_devlog_empty_state_on_project_page(alice): devlog_section = page.locator(".project-devlog") expect(devlog_section).to_be_visible() - expect(devlog_section.locator("h3:has-text('Devlog')")).to_be_visible() + expect(devlog_section.locator("h2:has-text('Devlog')")).to_be_visible() expect(page.locator(".empty-state:has-text('No devlog posts yet.')")).to_be_visible() @@ -187,3 +187,42 @@ def test_devlog_multiple_posts_order(alice): f"Expected newest post first: {markers[-1]}, got: {first_text}" ) + +def test_project_stats_card_visible(alice): + """The sidebar Stats card shows stars, updates, comments, files, forks.""" + page, _ = alice + slug, project_uid, owner_uid = _seed_project() + _seed_project_post(project_uid, owner_uid, 0) + + page.goto(f"{BASE_URL}/projects/{slug}", wait_until="domcontentloaded") + + stats = page.locator(".project-stats") + expect(stats).to_be_visible() + expect(stats.locator(".project-stat")).to_have_count(5) + expect(stats.locator(".project-stat:has-text('update')")).to_contain_text("1") + + +def test_owner_post_update_button_opens_preset_composer(alice): + """The owner's Post update button opens the composer preselected to this project.""" + page, _ = alice + _create_project_ui(page, f"Composer Project {uuid4().hex[:6]}") + + button = page.locator(".project-devlog-post-btn") + expect(button).to_be_visible() + button.click() + + modal = page.locator("#create-post-modal") + expect(modal).to_be_visible() + expect(modal.locator("input[name='topic'][value='devlog']")).to_be_checked() + selected = modal.locator("#project_uid").input_value() + assert selected != "", "Expected the project preselected in the composer" + + +def test_guest_sees_no_post_update_button(app_server): + """Guests and non-owners get no Post update control.""" + import requests + + slug, _, _ = _seed_project() + r = requests.get(f"{BASE_URL}/projects/{slug}") + assert r.status_code == 200 + assert "project-devlog-post-btn" not in r.text diff --git a/tests/e2e/projects/index.py b/tests/e2e/projects/index.py index 0b0a2763..40292d61 100644 --- a/tests/e2e/projects/index.py +++ b/tests/e2e/projects/index.py @@ -767,7 +767,7 @@ def test_project_comments_form_visible(alice): page.wait_for_url(f"{BASE_URL}/projects/*", wait_until="domcontentloaded") assert page.is_visible("text=Comments") assert page.is_visible("text=No comments yet") - assert page.is_visible("textarea[name='content']") + assert page.is_visible(".comment-form textarea[name='content']") def test_project_comment_create(alice): @@ -778,8 +778,8 @@ def test_project_comment_create(alice): page.fill("#description", "Project for creating a comment") page.click("button:has-text('Create Project')") page.wait_for_url(f"{BASE_URL}/projects/*", wait_until="domcontentloaded") - page.fill("textarea[name='content']", "Great project!") - page.click("button:has-text('Post')") + page.fill(".comment-form textarea[name='content']", "Great project!") + page.click(".comment-form button:has-text('Post')") page.wait_for_timeout(500) assert page.is_visible("text=Great project!") @@ -792,8 +792,8 @@ def test_project_comment_reply(alice): page.fill("#description", "Project for testing reply") page.click("button:has-text('Create Project')") page.wait_for_url(f"{BASE_URL}/projects/*", wait_until="domcontentloaded") - page.fill("textarea[name='content']", "First comment") - page.click("button:has-text('Post')") + page.fill(".comment-form textarea[name='content']", "First comment") + page.click(".comment-form button:has-text('Post')") page.wait_for_timeout(500) assert page.is_visible("text=First comment") page.click("button:has-text('Reply')") @@ -812,8 +812,8 @@ def test_project_comment_delete(alice): page.fill("#description", "Project for testing delete") page.click("button:has-text('Create Project')") page.wait_for_url(f"{BASE_URL}/projects/*", wait_until="domcontentloaded") - page.fill("textarea[name='content']", "Comment to delete") - page.click("button:has-text('Post')") + page.fill(".comment-form textarea[name='content']", "Comment to delete") + page.click(".comment-form button:has-text('Post')") page.wait_for_timeout(500) assert page.is_visible("text=Comment to delete") page.locator(".comment-action-btn:has-text('Delete')").click() diff --git a/tests/unit/models.py b/tests/unit/models.py index dc21345e..24b74e3c 100644 --- a/tests/unit/models.py +++ b/tests/unit/models.py @@ -47,6 +47,24 @@ def test_isslop_run_form_normalizes_typos_and_bare_domains(): assert IsslopRunForm(url="http:/x.dev/a").url == "http://x.dev/a" +def test_project_form_link_urls_normalize_and_validate(): + from devplacepy.models import ProjectForm, normalize_website_url + + base = {"title": "T", "description": "D"} + assert ProjectForm(**base).website_url == "" + assert ProjectForm(**base, website_url="myproject.dev").website_url == "https://myproject.dev" + assert ProjectForm(**base, repo_url="github.com/me/x").repo_url == "https://github.com/me/x" + assert ( + ProjectForm(**base, website_url="http://x.dev/a?b=1").website_url + == "http://x.dev/a?b=1" + ) + assert normalize_website_url(" ") == "" + with pytest.raises(ValidationError): + ProjectForm(**base, website_url="javascript:alert(1)") + with pytest.raises(ValidationError): + ProjectForm(**base, repo_url="not a url") + + def test_reaction_form_accepts_any_single_emoji(): from devplacepy.models import ReactionForm