mirror of
https://github.com/hugo-fixit/FixIt.git
synced 2026-08-24 07:18:57 +00:00
a96ba665ac
* refactor(assets)!: rewrite content encryption with AES-256-GCM and PBKDF2
- Remove legacy Base64 obfuscation layer (content-encryption.html)
- Replace <cipher-text> with <template> for inert content storage
- Single-layer AES-256-GCM encryption via post-build script
- PBKDF2 key derivation (100k iterations) for encryption
- PBKDF2-protected password verification (data-verify-salt)
- Depth-tracking parser for nested shortcode support
- Dev mode: plaintext content used directly without encryption
- Remove crypto-js and xxhash-wasm vendored dependencies
* feat(post-encrypt): prepare package for npm publishing
- Add bin entry, build script, and dist output for npx usage
- Replace @hugo-fixit/shared with standalone implementations
- Add CLI shebang for direct execution
- Add package README with usage documentation
- Remove FIXIT_ENCRYPT_INPUT env var (redundant with --input)
- Add encryption detection warning in assets.html
- Remove Post-build Encryption sections from READMEs
* chore: integrate post-encrypt into build pipeline and use consola
- Replace console with consola for post-encrypt logging
- Improve verification messages (no templates, count, etc.)
- Simplify build scripts: encrypt runs as part of main build
- Update encryption detection warning to use npx command
* feat(assets): add encryption dev warning admonition
- Add danger admonition in single.html for full-page encryption (dev mode only)
- Add encryption detection warning in assets.html console
- Improve post-encrypt verification messages with template count
* feat(assets): improve encryption i18n, cache security, and error handling
- Add encryptionWarning and encryptionCommand i18n keys for all 16 languages
- Store PBKDF2 verification hash in localStorage cache for better security
- Show decryption errors via flashTooltip instead of console only
- Add FixItDecryptor type definitions in global.ts
- Move encryption detection to init/detection-encryption.html with batched warning
- Remove redundant per-page warning from assets.html
* feat(assets): redesign fixit-decryptor UI with card layout
- Page-level: card form with lock icon header, password input with key icon, primary-colored unlock button, circular re-encrypt button
- Shortcode-level: connected input+button design (search bar style) with focus ring sync
- Remove loading spinner, use display:none/flex toggle via .initialized class
- Move lock icon styling to UnoCSS (text-primary text-xl)
- Initialize CellTooltip on re-encrypt button
- Fix JSDoc @param warnings in global.ts
* refactor(assets): unify TOC template and decryptor animations
- TOC always rendered in `<template data-toc>`, containers populated by initToc()
- Moved TOC scroll/resize handling from events.ts to toc.ts (syncTocLayout, syncTocActiveState)
- Removed EventsModule toc dependency, updated public-api.ts constructor
- Removed visibility:hidden from #toc-auto
- Decryptor: form always visible, @starting-style for fade-in on init
- Decryptor: content expand/collapse animation using height + opacity
- Removed encrypted-hidden from TOC elements in single.html
* refactor(assets): add target to fixit:decrypted event and simplify handlers
- Add { target: Element } payload to fixit:decrypted in event-bus.ts
- Remove $content closure from fixit-decryptor init(), use detail.target
- Update content.ts and toc.ts to use detail.target from event
* fix(assets): use eventBus for TOC scroll/resize listeners and eliminate redundant template parsing
- Replace raw window scroll/resize listeners in TocModule with eventBus
subscriptions (fixit:scroll/fixit:resize), reusing EventsModule's
throttle and debounce instead of duplicating un-throttled handlers.
- Refactor hasUnencryptedTemplate in post-encrypt to accept the already-
computed matches array, avoiding a redundant findEncryptionTemplates
call on the same HTML content.
- Remove crypto-js and xxhash-wasm from README credits.
* style(assets): soften decryptor button background and add form hover shadow
* build(workflow): add post-encrypt step to build script
116 lines
3.1 KiB
Bash
116 lines
3.1 KiB
Bash
#!/usr/bin/env bash
|
|
|
|
#------------------------------------------------------------------------------
|
|
# @file
|
|
# Builds a Hugo site hosted on Vercel.
|
|
#
|
|
# The Vercel build image automatically installs Node.js dependencies.
|
|
#
|
|
# @example
|
|
# chmod a+x build.sh && ./build.sh
|
|
#------------------------------------------------------------------------------
|
|
|
|
# Exit on error, undefined variables, or pipe failures
|
|
set -euo pipefail
|
|
|
|
build_temp_dir=""
|
|
|
|
# Perform cleanup
|
|
cleanup() {
|
|
if [[ -n "${build_temp_dir:-}" && -d "${build_temp_dir}" ]]; then
|
|
rm -rf "${build_temp_dir}"
|
|
fi
|
|
}
|
|
|
|
# Register the cleanup trap
|
|
trap cleanup EXIT SIGINT SIGTERM
|
|
|
|
# Build demo/test with the correct Hugo baseURL on Vercel preview deployments.
|
|
# - demo: https://${VERCEL_URL}
|
|
# - test: https://${VERCEL_URL}/test
|
|
build() {
|
|
local target="$1"
|
|
if [[ ! "${target}" =~ ^(demo|test)$ ]]; then
|
|
echo "Unknown build target: ${target}" >&2
|
|
return 2
|
|
fi
|
|
|
|
if [[ "${VERCEL_ENV:-}" != "preview" ]]; then
|
|
pnpm "build:${target}"
|
|
return
|
|
fi
|
|
|
|
local base_url="https://${VERCEL_URL}"
|
|
if [[ "${target}" == "test" ]]; then
|
|
base_url+="/test"
|
|
fi
|
|
pnpm "build:${target}" --buildDrafts --baseURL "${base_url}"
|
|
}
|
|
|
|
main() {
|
|
# Define tool versions
|
|
# You can also manage these via Environment Variables in the Vercel dashboard.
|
|
if [[ -z "${DART_SASS_VERSION:-}" ]]; then
|
|
DART_SASS_VERSION=1.99.0
|
|
fi
|
|
if [[ -z "${GO_VERSION:-}" ]]; then
|
|
GO_VERSION=1.26.1
|
|
fi
|
|
|
|
# Set the build timezone
|
|
export TZ=Asia/Shanghai
|
|
|
|
# Create and move into a temporary directory for downloads
|
|
build_temp_dir=$(mktemp -d)
|
|
pushd "${build_temp_dir}" > /dev/null
|
|
|
|
# Create the local tools directory
|
|
mkdir -p "${HOME}/.local"
|
|
|
|
# Install Dart Sass
|
|
echo "Installing Dart Sass ${DART_SASS_VERSION}..."
|
|
curl -sLJO "https://github.com/sass/dart-sass/releases/download/${DART_SASS_VERSION}/dart-sass-${DART_SASS_VERSION}-linux-x64.tar.gz"
|
|
tar -C "${HOME}/.local" -xf "dart-sass-${DART_SASS_VERSION}-linux-x64.tar.gz"
|
|
export PATH="${HOME}/.local/dart-sass:${PATH}"
|
|
|
|
# Install Go
|
|
# echo "Installing Go ${GO_VERSION}..."
|
|
# curl -sLJO "https://go.dev/dl/go${GO_VERSION}.linux-amd64.tar.gz"
|
|
# tar -C "${HOME}/.local" -xf "go${GO_VERSION}.linux-amd64.tar.gz"
|
|
# export PATH="${HOME}/.local/go/bin:${PATH}"
|
|
|
|
# Install Go from the package manager
|
|
dnf install -y golang.x86_64
|
|
|
|
# Return to the project root
|
|
popd > /dev/null
|
|
|
|
# Verify installations
|
|
echo "Verifying installations..."
|
|
echo Dart Sass: "$(sass --version)"
|
|
echo Go: "$(go version)"
|
|
echo Hugo: "$(hugo version)"
|
|
echo Node.js: "$(node --version)"
|
|
|
|
# Configure Git
|
|
echo "Configuring Git..."
|
|
git config core.quotepath false
|
|
if [ "$(git rev-parse --is-shallow-repository)" = "true" ]; then
|
|
git fetch --unshallow
|
|
fi
|
|
|
|
# Build the site
|
|
echo "Building the site..."
|
|
build demo & pid_demo=$!
|
|
build test & pid_test=$!
|
|
wait "${pid_demo}" || { echo "build demo failed"; exit 1; }
|
|
wait "${pid_test}" || { echo "build test failed"; exit 1; }
|
|
pnpm -F integration start
|
|
|
|
# Post-process encrypted content and verify encryption output.
|
|
pnpm encrypt
|
|
pnpm encrypt --verify
|
|
}
|
|
|
|
main "$@"
|