Files
FixIt/layouts/_partials/plugin/fixit-encryptor.html
Cell a96ba665ac refactor(assets)!: rewrite content encryption with AES-256-GCM and PBKDF2 (#806)
* refactor(assets)!: rewrite content encryption with AES-256-GCM and PBKDF2

- Remove legacy Base64 obfuscation layer (content-encryption.html)
- Replace <cipher-text> with <template> for inert content storage
- Single-layer AES-256-GCM encryption via post-build script
- PBKDF2 key derivation (100k iterations) for encryption
- PBKDF2-protected password verification (data-verify-salt)
- Depth-tracking parser for nested shortcode support
- Dev mode: plaintext content used directly without encryption
- Remove crypto-js and xxhash-wasm vendored dependencies

* feat(post-encrypt): prepare package for npm publishing

- Add bin entry, build script, and dist output for npx usage
- Replace @hugo-fixit/shared with standalone implementations
- Add CLI shebang for direct execution
- Add package README with usage documentation
- Remove FIXIT_ENCRYPT_INPUT env var (redundant with --input)
- Add encryption detection warning in assets.html
- Remove Post-build Encryption sections from READMEs

* chore: integrate post-encrypt into build pipeline and use consola

- Replace console with consola for post-encrypt logging
- Improve verification messages (no templates, count, etc.)
- Simplify build scripts: encrypt runs as part of main build
- Update encryption detection warning to use npx command

* feat(assets): add encryption dev warning admonition

- Add danger admonition in single.html for full-page encryption (dev mode only)
- Add encryption detection warning in assets.html console
- Improve post-encrypt verification messages with template count

* feat(assets): improve encryption i18n, cache security, and error handling

- Add encryptionWarning and encryptionCommand i18n keys for all 16 languages
- Store PBKDF2 verification hash in localStorage cache for better security
- Show decryption errors via flashTooltip instead of console only
- Add FixItDecryptor type definitions in global.ts
- Move encryption detection to init/detection-encryption.html with batched warning
- Remove redundant per-page warning from assets.html

* feat(assets): redesign fixit-decryptor UI with card layout

- Page-level: card form with lock icon header, password input with key icon, primary-colored unlock button, circular re-encrypt button
- Shortcode-level: connected input+button design (search bar style) with focus ring sync
- Remove loading spinner, use display:none/flex toggle via .initialized class
- Move lock icon styling to UnoCSS (text-primary text-xl)
- Initialize CellTooltip on re-encrypt button
- Fix JSDoc @param warnings in global.ts

* refactor(assets): unify TOC template and decryptor animations

- TOC always rendered in `<template data-toc>`, containers populated by initToc()
- Moved TOC scroll/resize handling from events.ts to toc.ts (syncTocLayout, syncTocActiveState)
- Removed EventsModule toc dependency, updated public-api.ts constructor
- Removed visibility:hidden from #toc-auto
- Decryptor: form always visible, @starting-style for fade-in on init
- Decryptor: content expand/collapse animation using height + opacity
- Removed encrypted-hidden from TOC elements in single.html

* refactor(assets): add target to fixit:decrypted event and simplify handlers

- Add { target: Element } payload to fixit:decrypted in event-bus.ts
- Remove $content closure from fixit-decryptor init(), use detail.target
- Update content.ts and toc.ts to use detail.target from event

* fix(assets): use eventBus for TOC scroll/resize listeners and eliminate redundant template parsing

- Replace raw window scroll/resize listeners in TocModule with eventBus
  subscriptions (fixit:scroll/fixit:resize), reusing EventsModule's
  throttle and debounce instead of duplicating un-throttled handlers.
- Refactor hasUnencryptedTemplate in post-encrypt to accept the already-
  computed matches array, avoiding a redundant findEncryptionTemplates
  call on the same HTML content.
- Remove crypto-js and xxhash-wasm from README credits.

* style(assets): soften decryptor button background and add form hover shadow

* build(workflow): add post-encrypt step to build script
2026-07-05 23:26:11 +08:00

44 lines
2.0 KiB
HTML

{{- /*
Encrypted content renderer.
- Renders template placeholder for post-build AES-256-GCM encryption.
- Supports full-page mode and partial mode with isolated target container.
@param {String} .Password - Encryption password
@param {String} .Content - Plaintext content (encrypted by post-build script)
@param {String} [.Message] - Custom input placeholder message
@param {Boolean} [.IsPartial] - Whether current render is partial mode
@param {Object} [.Page] - Current page context (required when IsPartial is true)
*/ -}}
{{- if .Password -}}
{{- /* Generating fixit-encryptor DOM */ -}}
{{- $message := .Message | default (T "single.encryptedMessage") -}}
{{- $id := "fixit-decryptor-input" -}}
{{- if .IsPartial -}}
{{- $id = dict "Page" .Page | partial "function/id.html" -}}
{{- end -}}
<fixit-encryptor data-pagefind-ignore="all">
<div class="fixit-decryptor-container">
<div class="fixit-decryptor-form">
<div class="fixit-decryptor-header">
<i class="fixit-decryptor-icon fa-solid fa-lock"></i>
</div>
<label for="{{ $id }}" class="sr-only">{{ T `single.password` }}</label>
<div class="fixit-decryptor-field">
<i class="fa-solid fa-key"></i>
<input type="password" id="{{ $id }}" class="fixit-decryptor-input max-sm:w-full" placeholder="{{ $message }}" />
</div>
<button class="fixit-decryptor-btn">
{{- dict "Class" "fa-solid fa-unlock-keyhole me-1.5" | partial "plugin/icon.html" }}{{ T "single.enterBtn" -}}
</button>
</div>
{{- if not .IsPartial -}}
<button class="fixit-encryptor-btn" title="{{ T `single.encryptyAgain` }}">
{{- dict "Class" "fa-solid fa-lock" | partial "plugin/icon.html" -}}
</button>
{{- end -}}
</div>
{{- if .IsPartial }}<div class="decryptor-content"></div>{{ end -}}
<template data-password="{{ sha256 .Password }}">{{ .Content }}</template>
</fixit-encryptor>
{{- end -}}