Compare commits

..

81 commits

Author SHA1 Message Date
blankie
6554330bed chore: remove pre-release schema migrations 2026-07-03 02:02:46 +00:00
blankie
5b79f2f83f docs(contributing): expand with setup, conventions, and PR guidelines 2026-07-02 23:54:07 +00:00
blankie
b932ca03c3 security: replace personal email with confidential issue reporting 2026-07-02 23:32:58 +00:00
blankie
61408ec955 readme: add RNS browsing to features, update storage estimates for cleaned-text model 2026-07-02 23:27:42 +00:00
blankie
a4322737f9 rns: store cleaned text instead of raw HTML body 2026-07-02 23:27:05 +00:00
blankie
68a92a677a base tag + LRU cache for RNS browse, sync status fixes 2026-06-19 02:17:11 +00:00
blankie
025db00858 rns browser, standalone site server, unified add form
- /rns/<hash>/<path> proxies pages over RNS with link rewriting
- fetch_remote_page() in rns_client.py for generic RNS page fetching
- mesh_sites table for persisting saved hashes
- standalone site_server.py with its own RNS identity
- tinyweb-site/index.html: SPA with RSS-aware nav (/rns/<hash>/ prefix)
- unified /add form: single input accepts URL or 32-char RNS hash
- RNS add indexes into pages table (fetch root page, extract title/desc)
- rns:<hash> URLs displayed in browse/search, linked to /rns/<hash>/
- expand RNS whitelist: allow GET /, /about, /pages, /tags, /share
2026-06-18 20:38:42 +00:00
blankie
4999675ff6 forum trust circle: trust-gated content exchange via subscription graph 2026-06-17 20:16:30 +00:00
blankie
4ac22a472b fix: app.py gateway import alias (broken since src layout migration) 2026-06-17 20:16:06 +00:00
blankie
4fbf36779a forum trust circle: trust-gated content exchange via subscription graph 2026-06-17 20:15:50 +00:00
blankie
257be691ed readme: update project structure to reflect src layout 2026-06-17 05:16:34 +00:00
blankie
3e30678e21 src layout: move core code into src/tinyweb/ package
- Moved app.py, db.py, gateway.py, templates.py, embeddings.py,
  rns_client.py, and handlers/ into src/tinyweb/
- Created root app.py shim (adds src/ to sys.path, imports main)
- Created pyproject.toml with setuptools config (where = ["src"])
- Added src/tinyweb/__init__.py
- Updated all internal imports to use tinyweb. prefix (73 occurrences)
- Removed sys.path.insert hack from conftest.py
- Updated Dockerfile: pip install -e /app before running
- Updated gateway.py usage message: python -m tinyweb.gateway
- Updated README.md gateway usage instructions
2026-06-17 05:03:23 +00:00
blankie
60aa4b274a junimo theme: use {{site_name}} and {{forum_link}} placeholders 2026-06-16 05:23:24 +00:00
blankie
66a9fafd26 remove demo pages, rename themes, add Content-Length header 2026-06-16 05:11:37 +00:00
blankie
0f614c88f8 auto-save: settings save on change via /style/field, noscript fallback button 2026-06-14 08:46:21 +00:00
blankie
1dc87ac449 customize: split into separate settings and template forms 2026-06-14 08:14:43 +00:00
blankie
38860de7d2 customize: move save button above html textarea, add unsaved changes indicator 2026-06-14 08:12:10 +00:00
blankie
f4e5c7efd1 template: remove forum css from DEFAULT_TEMPLATE (injected at render time) 2026-06-14 08:05:20 +00:00
blankie
d9e89e8124 template: add {{nav}} placeholder, separate from {{content}} 2026-06-14 08:00:57 +00:00
blankie
71c1175df8 docker: fix data persistence with TINYWEB_DATA_DIR env var 2026-06-14 07:48:34 +00:00
blankie
af6ad6d391 bookmarklet: use dynamic host and scheme from request headers 2026-06-14 07:43:26 +00:00
blankie
96603da142 simplify: move subscribe form to GET /subscriptions/add 2026-06-14 07:36:37 +00:00
blankie
a008bc7aed Revert "simplify: move subscribe form to GET /subscriptions/add"
This reverts commit 25e24efbfa.
2026-06-14 07:33:38 +00:00
blankie
492f98fed9 simplify: move subscribe form to GET /subscriptions/add 2026-06-14 07:32:58 +00:00
blankie
faa28005e3 readme: remove duplicate forum section 2026-06-09 05:58:55 +00:00
blankie
1962e3e1b6 search: match by tag; add: handle ssl errors with manual entry 2026-06-09 05:35:54 +00:00
blankie
613e43e925 restructure README: expand getting started, demote Docker 2026-06-09 03:18:23 +00:00
blankie
ad26f71a9c add CONTRIBUTING.md and issue template 2026-06-09 03:15:55 +00:00
blankie
f06afa4cfb add SECURITY.md 2026-06-09 03:11:43 +00:00
blankie
8ca4d90416 README: add transparency sections, TOC, update project structure 2026-06-09 03:06:38 +00:00
blankie
16dacbf7ed split handlers.py into handlers/ package
- _helpers.py: CSRF, FTS sanitizer, pagination, response helpers, tag helpers
- search.py: BM25 + hybrid search, trusted/remote result rendering
- pages.py: add/edit/delete/bulk/bookmark handlers
- subscriptions.py: sync, share preview, API sites, subscription CRUD
- customize.py: settings form, about page
- tags.py: tag list and tag browse handlers
- data.py: export, import, semantic reindex handlers
- __init__.py: dispatch, re-exports, forum_plugin, _request_local

All 58 external symbols re-exported. No changes to app.py, conftest.py,
or any test file.
2026-06-09 02:34:04 +00:00
blankie
395beff0fc add .env.example for environment configuration 2026-06-09 02:14:17 +00:00
blankie
a15b1ebcc8 point repo URLs to Codeberg instead of self-hosted Gitea 2026-06-09 01:41:41 +00:00
blankie
e173e23087 clean up: remove unused start.sh/pyinstaller.spec, deduplicate constants, update .gitignore 2026-06-09 01:16:54 +00:00
blankie
608abb0501 remove forgejo CI workflow (no releases) 2026-06-09 01:08:39 +00:00
blankie
304f1eedf9 threaded HTTP server, rate limiting, remove slow-web rhetoric 2026-06-09 01:07:36 +00:00
blankie
63610145ee rewrite README — descriptive tone, remove releases/philosophy sections 2026-06-09 01:07:09 +00:00
blankie
d60abcfce1 move forum layout CSS to main site template system
- Remove FORUM_CSS_DEFAULT/KODAMA2 and _forum_css() from forum handlers
- Add FORUM_CSS constant to templates.py with layout-only forum CSS
- Inject forum CSS into any template's <head> via wrap_page()
- Add forum layout styles to kodama2.html theme
- Update database custom template
2026-06-06 01:41:41 +00:00
blankie
bfde52a697 added tinyweb-site theme 2026-06-05 05:29:36 +00:00
blankie
6174153612 added site_name placeholder to templates 2026-06-05 05:29:36 +00:00
blankie
ea87a848e0 hid forum link when disabled 2026-06-05 05:29:36 +00:00
blankie
29934dcf1b updated forum README with auto-discovery 2026-06-05 05:29:36 +00:00
blankie
20a84dfa26 integrated the forum plugin 2026-06-05 05:29:36 +00:00
blankie
d23751acb6 reworked to distribute via clone, not registry 2026-06-05 05:29:36 +00:00
blankie
7aaebd8021 fixed Docker socket mount 2026-06-05 05:29:36 +00:00
blankie
01164b6ab6 switched to host-mode Docker 2026-06-05 05:29:36 +00:00
blankie
676777a721 fixed CI: Docker in container 2026-06-05 05:29:36 +00:00
blankie
c848af47cd fixed CI: install jq for release 2026-06-05 05:29:36 +00:00
blankie
f60566cc86 fixed CI: --break-system-packages 2026-06-05 05:29:36 +00:00
blankie
3862b5690a fixed CI: use apt-get for Python 2026-06-05 05:29:36 +00:00
blankie
d6f418d27c added pytest test suite (174 tests)
174 tests covering URL normalization, FTS5 query sanitization, SSRF/CSRF
guards, sharing-mode logic, DB schema and upsert paths, handler
end-to-end flows, and gateway body-size / mesh-whitelist guards. Each
recent bug-fix commit (6ffd38d, 1bc695f, 8dffd8c) has an explicit
regression test in test_regressions.py. One xfail documents a minor
latent bug in clean_url where port 80 is not stripped from upgraded
https URLs.
2026-06-05 05:29:36 +00:00
blankie
5936610e33 added data-loss guards + first-run state
- Bulk delete now routes through a server-rendered confirmation page
  listing the selected titles; a `confirmed=1` form field is required
  before pages are actually deleted. Mirrors the single-delete flow.
- Reset-template button gains a JS confirm() so stray clicks don't wipe
  the custom template.
- Homepage shows a short, neutral empty-state block when the index has
  zero pages and no query — just names what tinyweb is and links to
  /add, /style, and /subscriptions as equal options.
- /about gains a "your data" section explaining what lives in
  ~/.tinyweb/ (identity file, index.db), what losing each costs, and
  how /export differs from a full backup.
- README gains a "Backups" subsection mirroring the /about copy.
2026-06-05 05:29:36 +00:00
blankie
5cb3b8407c tightened network defaults, squashed bugs
Security:
- Bind HTTP gateway to 127.0.0.1 by default; add --bind for LAN opt-in
- Restrict Reticulum mesh surface to GET /api/sites only (CSRF cannot
  authenticate mesh callers, so gate by whitelist)
- Cap request body size at 16 MiB to prevent memory DoS
- Redact /bookmark query strings from request logs so the bookmark token
  and URLs do not land in stdout / docker / journal logs
- Tighten FTS5 sanitizer: strip colon, drop AND/OR/NOT/NEAR operator words
- Expand .dockerignore; document trust model in README

Features:
- Add sharing mode toggle (share everything except private vs share only
  public-tagged) with /share/preview so users can see what subscribers
  would receive before enabling sharing

Bugs:
- handle_export() crashed on every call (missing query kwarg)
- Dead float16 decompression branch in embeddings.py silently corrupted
  the HNSW index when compress_embeddings was on
- GATEWAY_PORT staleness: --port and find_available_port had no effect
  on the actual bind
- semantic_search default mismatched between db.py ("1") and the rest of
  the app ("0"), causing embeddings to be generated when the UI said off
- Connection pool returned connections with uncommitted transactions to
  the next consumer
- Gateway POST body decode 502'd on non-UTF-8 input
- ensure_rns_config clobbered user-edited ~/.reticulum/config; now only
  rewrites files it authored (sentinel-tagged)
2026-06-05 05:29:36 +00:00
blankie
306c728f97 added LoRa sync with settings UI
- Progressive retry in rns_client.py: fast timeout (15s) then slow (60s+)
  for LoRa/multi-hop links, with automatic fallback
- Background sync threads so subscriptions page returns immediately
  with syncing/error status indicators per subscription
- LoRa RNode configuration in settings page with serial port and
  expandable advanced radio settings (frequency, bandwidth, etc.)
- Internet transport now toggleable alongside LoRa — users can
  enable one, the other, or both
- Reticulum config auto-generated from settings on startup
2026-06-05 05:29:36 +00:00
blankie
2ebf1d8705 fixed edge-case domains 2026-06-05 05:29:36 +00:00
blankie
6676c8ff1e added public/private toggle 2026-06-05 05:29:36 +00:00
blankie
d386831530 optimized storage, updated readme 2026-06-05 05:29:36 +00:00
blankie
8e9233966f added Docker setup docs 2026-06-05 05:29:36 +00:00
blankie
e49b8667fc squashed a bunch of workflow build bugs 2026-06-05 05:29:36 +00:00
blankie
c0fde557a8 added bulk ops + orphaned tag cleanup
- Bulk delete and retag from browse page with checkboxes
- Select all / deselect all toggle
- Delete confirmation shows count of selected pages
- Auto-cleanup orphaned tags on delete, edit, and bulk actions
2026-06-05 05:29:36 +00:00
blankie
15c61dc6c2 privacy pass: degoogle, CSP, referrer
- Replace Google Fonts with system font stacks across all themes
- Add Referrer-Policy, X-Content-Type-Options, X-Frame-Options, CSP headers
- Add rel="noreferrer noopener" on all outbound links
- Add no-referrer and dns-prefetch-control meta tags to all themes
- Clean tracking params on outbound links from trusted/remote sources
- Remove Google domains from CSP whitelists
2026-06-05 05:29:36 +00:00
blankie
63a17b5769 added kodama2 theme
Adds pagination, meta, and success message styles, plus input
selectors for new form fields (edit page, manual entry, transport node).
2026-06-05 05:29:36 +00:00
blankie
c5787f5fc0 disabled semantic search by default 2026-06-05 05:29:36 +00:00
blankie
693a2a28fe added PyInstaller builds, AGPLv3, transport config
- Add pyinstaller.spec and GitHub/Forgejo CI workflows for cross-platform builds
- Add AGPLv3 license
- Move data storage to ~/.tinyweb/
- Add --version and --port CLI flags
- Add transport node selection in /style (smart regeneration preserves Reticulum config)
- Add discover more nodes link to rmap.world
2026-06-05 05:29:36 +00:00
blankie
b06c81f441 tightened up the add form spacing 2026-06-05 05:29:36 +00:00
blankie
94598a120c swapped to radio toggle for URL vs hash 2026-06-05 05:29:36 +00:00
blankie
e5a599c854 added dropdown to switch add/subscribe 2026-06-05 05:29:36 +00:00
blankie
b2e3d7f98e added reticulum hash option to add page 2026-06-05 05:29:36 +00:00
blankie
79a7d514bd added manual URL entry 2026-06-05 05:29:35 +00:00
blankie
4acbe61c5c made semantic search optional, use meta snippets
- Add semantic_search setting to toggle AI-powered search on/off
- Skip embedding generation, hybrid search, and model preloading when disabled
- Use site owner's meta description as snippet instead of heuristic extraction
- Remove _generate_summary() and snippet() - no more generated snippets
- Show reranker/reindex controls grayed out when semantic search is off
- AI dependencies (onnxruntime, hnswlib, etc.) are now fully optional
2026-06-05 05:29:35 +00:00
blankie
16315b2354 improved snippet extraction (heuristic)
- Case-insensitive meta description extraction (fixes sites like Lemmy
  with capitalized "Description" meta name)
- Strip aside and noscript tags for cleaner body text
- Extract paragraph text separately for better sentence quality
- Prefer sentences mentioning the site name, then first quality
  paragraph, then title as fallback
- Skip meta descriptions under 20 chars (e.g. just "Lemmy")
- Remove embedding/centroid dependency from summary generation
2026-06-05 05:29:35 +00:00
blankie
6ec8a04c67 stripped noscript tags from pages
Lemmy and other JS-heavy sites include noscript fallback text like
"Javascript is disabled" that pollutes the stored body text and
generated snippets/summaries.
2026-06-05 05:29:35 +00:00
blankie
937a4fd041 fixed reindex, preserved summaries
Previously reindex skipped pages that already had chunks, leaving stale
embeddings in place. It also overwrote good meta description summaries
with auto-generated ones. Now it clears all chunks first so everything
is re-embedded, and only generates summaries for pages missing one.
2026-06-05 05:29:35 +00:00
blankie
6a28ccef83 added junimo theme, bumped browse to 50 2026-06-05 05:29:35 +00:00
blankie
72f94a8da7 added hybrid semantic search with reranking
Implements a three-stage search pipeline:
1. BM25 keyword search via FTS5 with column weights
2. Semantic search via Snowflake arctic-embed-s bi-encoder + HNSW index
3. Optional cross-encoder reranking (on by default, toggleable in settings)

Top 20 results are reranked for precision, next 10 appended from RRF
for coverage, giving 30 total results across 3 pages.

- New embeddings.py with ONNX Runtime inference, text chunking, HNSW
  index management, RRF fusion, and cross-encoder reranking
- Meta description extraction for authentic page snippets with centroid
  extractive fallback
- Stopword filtering in FTS5 queries to avoid overly strict matching
- /reindex page for batch embedding of existing pages
- Semantic embedding of remote pages during subscription sync
- ~125MB dependency footprint (onnxruntime, tokenizers, hnswlib, numpy)
- Models: 34MB bi-encoder + 22MB cross-encoder (downloaded on first use)
2026-06-05 05:29:35 +00:00
blankie
e4e9f9526d fixed navbar disappearing on save
Browser textarea submissions convert \n to \r\n, causing the template
comparison against DEFAULT_TEMPLATE to always fail. This saved the bare
skeleton as a custom template, overriding the default navbar.
2026-06-05 05:29:35 +00:00
blankie
7da17e2872 redesigned subscriptions with card layout
Replace cramped table layout with card-based design that works
better in narrow viewports and across different themes.
2026-06-05 05:29:35 +00:00
blankie
cf36bc9849 disabled share_instance for reliable announces
With share_instance = Yes, announces weren't being sent over TCP
in Docker environments. Setting it to No ensures each TinyWeb
instance manages its own Reticulum interfaces directly.
2026-06-05 05:29:35 +00:00
blankie
3ed73bdcf5 added delay before announce for TCP readiness
The announce was firing before the TCP transport connection was fully
established, causing Docker instances to never announce over the mesh.
2026-06-05 05:29:35 +00:00
blankie
c947cd1e16 added default transport node
New TinyWeb instances now auto-connect to rnode.bre.land:4242
so users get internet mesh connectivity out of the box without any
manual Reticulum configuration. Env var overrides still supported.
2026-06-05 05:29:35 +00:00
blankie
7b6364e3ea added entrypoint for Reticulum in Docker
Replaces static CMD with an entrypoint that generates RNS config from
environment variables (RNS_TCP_HOST/PORT), enabling TCP transport for
environments without LAN auto-discovery (e.g. Docker on macOS).
2026-06-05 05:29:35 +00:00

View file

@ -10,7 +10,7 @@ services:
# Required on macOS (Docker can't do LAN auto-discovery). # Required on macOS (Docker can't do LAN auto-discovery).
# On Linux, auto-discovery works with network_mode: host. # On Linux, auto-discovery works with network_mode: host.
# environment: # environment:
# - RNS_TCP_HOST=10.0.0.100 # - RNS_TCP_HOST=your-peer-ip
# - RNS_TCP_PORT=4242 # - RNS_TCP_PORT=4242
volumes: volumes: