diff --git a/build/Dockerfile b/build/Dockerfile
index c85c3b9..45bd809 100644
--- a/build/Dockerfile
+++ b/build/Dockerfile
@@ -13,9 +13,9 @@ WORKDIR /src
# Version stamped into both binaries; MUST match the image tag (spec 7.5.A).
ARG VERSION=dev
-# Module metadata first for layer caching. No go.sum yet — Phase 1 has no
-# third-party dependencies.
-COPY go.mod ./
+# Module metadata first for layer caching. go.sum arrived in Phase 2 with the
+# SQLite driver and bcrypt.
+COPY go.mod go.sum ./
RUN go mod download
COPY cmd ./cmd
@@ -69,11 +69,13 @@ COPY --from=build /out/selfpost-backup /usr/local/bin/selfpost-backup
COPY build/opendkim.conf /etc/opendkim.conf
COPY build/postfix-wrapper.sh /usr/local/bin/postfix-wrapper.sh
COPY build/crashexit.py /usr/local/bin/crashexit.py
+COPY build/entrypoint.sh /usr/local/bin/entrypoint.sh
COPY build/supervisord.conf /etc/supervisor/supervisord.conf
-RUN chmod +x /usr/local/bin/postfix-wrapper.sh /usr/local/bin/crashexit.py
+RUN chmod +x /usr/local/bin/postfix-wrapper.sh /usr/local/bin/crashexit.py /usr/local/bin/entrypoint.sh
# 8080 panel; 25 outbound; 465/587 inbound submission (used from Phase 5).
EXPOSE 8080 25 465 587
-# supervisord is PID 1 and owns process supervision + ordering (spec 4).
-CMD ["/usr/bin/supervisord", "-c", "/etc/supervisor/supervisord.conf"]
+# The entrypoint fixes /data ownership (bind mount) as root, then execs
+# supervisord, which becomes PID 1 and owns process supervision (spec 4).
+ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
diff --git a/build/entrypoint.sh b/build/entrypoint.sh
new file mode 100644
index 0000000..b9d14ee
--- /dev/null
+++ b/build/entrypoint.sh
@@ -0,0 +1,17 @@
+#!/bin/sh
+# Container entrypoint (runs as root, PID 1 until it execs supervisord).
+#
+# The persistent root /data is a host bind mount (spec 9), so it arrives owned
+# by the host user (typically root), not by the unprivileged panel user that
+# actually writes the SQLite database, setup token and DKIM keys (spec 7.6.8).
+# Fix its ownership here — the one place still running as root — before handing
+# off to supervisord, which starts the panel as the panel user.
+set -e
+
+chown panel:panel /data
+# Restored backups or previously-created state may contain panel-owned files
+# under /data; make sure they stay writable without disturbing anything that a
+# later phase deliberately hands to another service.
+find /data -mindepth 1 -maxdepth 1 ! -user panel -exec chown -R panel:panel {} +
+
+exec /usr/bin/supervisord -c /etc/supervisor/supervisord.conf
diff --git a/cmd/panel/httpserver.go b/cmd/panel/httpserver.go
index 8e55203..4c6672e 100644
--- a/cmd/panel/httpserver.go
+++ b/cmd/panel/httpserver.go
@@ -6,19 +6,35 @@ import (
"log"
"net/http"
"time"
+
+ "codeberg.org/mix/selfpost/internal/store"
+ "codeberg.org/mix/selfpost/internal/web"
)
-// serveHTTP runs the panel's HTTP server until ctx is cancelled. Phase 1 serves
-// only a placeholder page and a health check; the login flow and real UI arrive
-// in Phase 2.
-func serveHTTP(ctx context.Context, addr string) error {
- mux := http.NewServeMux()
- mux.HandleFunc("/healthz", handleHealth)
- mux.HandleFunc("/", handleIndex)
+// serveHTTP opens the panel database and runs the control-panel HTTP server
+// until ctx is cancelled. From Phase 2 this serves the real setup, login and
+// authenticated panel surface (spec 7.6).
+func serveHTTP(ctx context.Context, cfg config) error {
+ st, err := store.Open(cfg.dbPath)
+ if err != nil {
+ return err
+ }
+ defer st.Close()
+
+ srvApp, err := web.New(st, web.Config{
+ Hostname: cfg.hostname,
+ CookieSecure: cfg.cookieSecure,
+ }, cfg.setupTokenPath)
+ if err != nil {
+ return err
+ }
+ if err := srvApp.Start(); err != nil {
+ return err
+ }
srv := &http.Server{
- Addr: addr,
- Handler: mux,
+ Addr: cfg.httpAddr,
+ Handler: srvApp.Handler(),
ReadHeaderTimeout: 10 * time.Second,
}
@@ -30,38 +46,9 @@ func serveHTTP(ctx context.Context, addr string) error {
_ = srv.Shutdown(shutdownCtx)
}()
- log.Printf("http panel listening on %s", addr)
+ log.Printf("http panel listening on %s", cfg.httpAddr)
if err := srv.ListenAndServe(); err != nil && !errors.Is(err, http.ErrServerClosed) {
return err
}
return nil
}
-
-func handleHealth(w http.ResponseWriter, _ *http.Request) {
- w.Header().Set("Content-Type", "text/plain; charset=utf-8")
- w.WriteHeader(http.StatusOK)
- _, _ = w.Write([]byte("ok\n"))
-}
-
-func handleIndex(w http.ResponseWriter, r *http.Request) {
- if r.URL.Path != "/" {
- http.NotFound(w, r)
- return
- }
- w.Header().Set("Content-Type", "text/html; charset=utf-8")
- _, _ = w.Write([]byte(indexHTML))
-}
-
-const indexHTML = `
-
-
-
-
-SelfPost
-
-
-SelfPost
-The control panel is starting up. Administrator setup and login arrive in a later build.
-
-
-`
diff --git a/cmd/panel/main.go b/cmd/panel/main.go
index 004a558..d73a89a 100644
--- a/cmd/panel/main.go
+++ b/cmd/panel/main.go
@@ -14,6 +14,7 @@ import (
"log"
"os"
"os/signal"
+ "path/filepath"
"sync"
"syscall"
@@ -43,13 +44,28 @@ type config struct {
httpAddr string
journalSocket string
mailLog string
+
+ dataDir string
+ dbPath string
+ setupTokenPath string
+ hostname string
+ cookieSecure bool
}
func loadConfig() config {
+ dataDir := envDefault("SELFPOST_DATA_DIR", "/data")
return config{
httpAddr: envDefault("PANEL_HTTP_ADDR", ":8080"),
journalSocket: envDefault("JOURNAL_MILTER_SOCKET", "/run/selfpost/journal.sock"),
mailLog: envDefault("MAIL_LOG", "/var/log/mail.log"),
+
+ dataDir: dataDir,
+ dbPath: envDefault("SELFPOST_DB_PATH", filepath.Join(dataDir, "selfpost.db")),
+ setupTokenPath: envDefault("SELFPOST_SETUP_TOKEN_FILE", filepath.Join(dataDir, "setup-token")),
+ hostname: os.Getenv("SELFPOST_HOSTNAME"),
+ // Secure cookies by default (spec 7.6.6); PANEL_COOKIE_SECURE=false is a
+ // development-only escape hatch for testing over plain HTTP.
+ cookieSecure: envDefault("PANEL_COOKIE_SECURE", "true") != "false",
}
}
@@ -79,7 +95,7 @@ func run() error {
name string
fn func(context.Context) error
}{
- {"http", func(ctx context.Context) error { return serveHTTP(ctx, cfg.httpAddr) }},
+ {"http", func(ctx context.Context) error { return serveHTTP(ctx, cfg) }},
{"journal-milter", func(ctx context.Context) error { return serveJournalStub(ctx, cfg.journalSocket) }},
{"log-tailer", func(ctx context.Context) error { return tailMailLog(ctx, cfg.mailLog) }},
}
diff --git a/docs/progress.md b/docs/progress.md
index eb38955..40a62f2 100644
--- a/docs/progress.md
+++ b/docs/progress.md
@@ -46,10 +46,19 @@
## Текущее состояние
-- **Текущая фаза:** 1 ✅ закрыта → следующая **Фаза 2** (SQLite + setup-link + вход админа)
-- **Модель для Фазы 2:** Opus (безопасность 7.6: крипто-токен, сессии, bcrypt)
-- **Статус:** образ собирается и проверен на сервере; три процесса живы, холодный старт и crashexit подтверждены
-- **Следующий шаг (Фаза 2):** SQLite-схема + миграции (домены, приложения, админ, `send_log`, лимиты, настройки, флаг «настройка завершена»/setup-токен), единый корень `/data`; **setup secret-link** (токен ≥128 бит `crypto/rand`, TTL 10 мин с перегенерацией, rate-limit маршрута, `subtle.ConstantTimeCompare`, неудачи НЕ инвалидируют токен, одноразовая форма создания админа, инвалидация навсегда после успеха → `/setup/*` 404); bcrypt-хэш пароля админа; логин + сессии (крипто-токен, cookie `HttpOnly`/`Secure`/`SameSite`), rate-limit логина; базовый layout `html/template` + вендоренный HTMX + auth-middleware. Выбрать драйвер `modernc.org/sqlite` (первая сторонняя зависимость — появится `go.sum`). Проверка: первый запуск печатает setup-ссылку, админ создаётся один раз, повторный `/setup` → 404, вход/выход работают.
+- **Текущая фаза:** 2 ✅ закрыта → следующая **Фаза 3** (домены + OpenDKIM)
+- **Модель для Фазы 3:** Opus (генерация конфигов + exec-safety 7.6.3–4, валидация имени домена 7.6.2)
+- **Статус:** SQLite-персистентность, setup secret-link и вход админа реализованы и проверены на сервере (`go vet`/`build`/`test` зелёные, docker-образ собирается, контейнер поднимает три процесса и создаёт БД под `panel`)
+- **Следующий шаг (Фаза 3):** добавить/список/удалить домен (при удалении — предупреждение о каскаде приложений, ТЗ 7.2.4); генерация DKIM-ключа + селектор per-domain (дефолт из `DKIM_SELECTOR_DEFAULT`), ключи в `/data/...` переживают рестарт (ТЗ 6, 9); `KeyTable`/`SigningTable` + reload OpenDKIM (сейчас `opendkim.conf` в Mode `v` без ключей — перевести в `s` + KeyTable); показ DKIM TXT-записи per-domain (ТЗ 7.2.10). **Безопасность:** строгая валидация имени домена (whitelist, 7.6.2), безопасная запись конфигов с экранированием (7.6.4), `os/exec` без shell и без интерполяции ввода (7.6.3). Таблицы `domains`/`applications`/`application_addresses` уже в схеме (миграция 0001).
+
+### Сделано в Фазе 2
+- **SQLite-персистентность** (`internal/store`): драйвер `modernc.org/sqlite` (чистый Go, без cgo — статик-бинарник сохранён; первые сторонние зависимости → появились `go.mod` require + `go.sum`), WAL + `foreign_keys(ON)` + `busy_timeout` через DSN `_pragma`, `MaxOpenConns(1)`. Встроенные (`embed`) нумерованные миграции с версионированием через `PRAGMA user_version`; миграция `0001_init.sql` заводит всю схему ТЗ 9: `admin` (одна строка, `CHECK id=1`), `settings`, `domains`, `applications`, `application_addresses`, `send_log` (+индексы), `rate_limits`. Запросы `AdminExists/CreateAdmin/GetAdmin`.
+- **Setup secret-link** (`internal/web/setup.go`, ТЗ 7.6.1): токен 128 бит из `crypto/rand` (base64url), ссылка `https:///setup/` печатается в лог **и** пишется в `/data/setup-token` (0600); TTL 10 мин с перегенерацией при истечении/рестарте (пока нет админа); сравнение `subtle.ConstantTimeCompare`; **неудачи НЕ инвалидируют токен**; «настройка завершена» = наличие строки `admin` (источник истины), поэтому после успеха токен сгорает навсегда и весь `/setup/*` → 404. Форма создания админа — одноразовая; гонка двух POST безопасна (`CHECK id=1` + проверка существования).
+- **Пароль админа** — только `bcrypt` (`golang.org/x/crypto/bcrypt`, DefaultCost); серверная валидация (username whitelist 7.6.2, пароль ≥12).
+- **Логин + сессии** (`internal/web/handlers_auth.go`, `session.go`): вход сверяет username + bcrypt (bcrypt считается всегда — timing-инвариантно), сессии в памяти (не в списке ТЗ 9 на персист — рестарт просто разлогинивает), крипто-токен 256 бит; cookie `HttpOnly`/`Secure`/`SameSite=Lax` (`Secure` по умолчанию, отключается `PANEL_COOKIE_SECURE=false` только для dev-HTTP); rate-limit логина (`ratelimit.go`, 10/15мин по IP) и отдельный на `/setup` (10/мин); auth-middleware защищает панель.
+- **Front-end**: базовый layout `html/template` (автоэкранирование, 7.6.7) + страницы setup/login/dashboard (`embed`); вендоренный `htmx.min.js` 2.0.4 (`internal/web/static`, отдаётся с `/static/`).
+- **Entrypoint для bind-mount** (`build/entrypoint.sh`): `/data` — host bind mount → приходит от root, а панель работает под непривилегированным `panel` (uid 999). Точка входа под root чинит владельца `/data` перед `exec supervisord` (иначе SQLite `unable to open database file`). Найдено и исправлено при контейнерной проверке.
+- **Проверено на сервере** (selfpost.example.com): `go vet`/`go build`/`go test`/`gofmt -l` чисто; функциональный e2e (curl): setup-ссылка печатается+в файл, `GET /setup/`→200, неверный/просроченный→404, `POST /setup` создаёт админа→303, повторный `/setup`→404, файл токена удалён; плохой логин→401, хороший→303 с cookie `HttpOnly; Secure; SameSite=Lax`, `/`→200, logout→303, после logout `/`→303; рестарт с существующим админом не печатает setup. Docker-образ собирается; контейнер с `-v ./data:/data`: три процесса, БД+токен создаются под `panel`, токен 0600.
### Сделано в Фазе 1
- **Образ** `build/Dockerfile` (bookworm-slim): многостадийная статическая сборка Go (`CGO_ENABLED=0`, `go vet` в сборке); рантайм — postfix, opendkim(+tools), cyrus-sasl (`sasl2-bin`, `libsasl2-modules`), supervisor, logrotate, ca-certificates; `maillog_file=/var/log/mail.log`; непривилегированный пользователь `panel` (ТЗ 7.6.8); `.dockerignore` (dev/ и docs/ не попадают в контекст).
@@ -82,3 +91,4 @@
- **Фаза 0** (2026-07-11, Opus) — каркас проекта + build-пайплайн + спайк go-milter (риск ТЗ 7.3 снят). Коммиты `4e589e1` (каркас), `87388b4` (план).
- **Фаза 1** (2026-07-11, Opus) — Docker-образ + supervisord + три процесса, холодный старт (обёртка ждёт milter-сокеты) и crashexit проверены на сервере. Коммит `ed9e942`.
+- **Фаза 2** (2026-07-11, Opus) — SQLite (`modernc.org/sqlite`, миграции, схема ТЗ 9), setup secret-link (128-бит токен, TTL 10м, const-time, одноразово), bcrypt-админ, логин/сессии/cookie-флаги, rate-limit setup+логина, html/template + вендоренный HTMX, auth-middleware; entrypoint чинит владельца bind-mount `/data`. Проверено на сервере (e2e curl + docker run).
diff --git a/go.mod b/go.mod
index 33f9c2a..ed5d954 100644
--- a/go.mod
+++ b/go.mod
@@ -1,3 +1,20 @@
module codeberg.org/mix/selfpost
go 1.26
+
+require (
+ golang.org/x/crypto v0.54.0
+ modernc.org/sqlite v1.53.0
+)
+
+require (
+ github.com/dustin/go-humanize v1.0.1 // indirect
+ github.com/google/uuid v1.6.0 // indirect
+ github.com/mattn/go-isatty v0.0.20 // indirect
+ github.com/ncruces/go-strftime v1.0.0 // indirect
+ github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
+ golang.org/x/sys v0.47.0 // indirect
+ modernc.org/libc v1.73.4 // indirect
+ modernc.org/mathutil v1.7.1 // indirect
+ modernc.org/memory v1.11.0 // indirect
+)
diff --git a/go.sum b/go.sum
new file mode 100644
index 0000000..5456856
--- /dev/null
+++ b/go.sum
@@ -0,0 +1,53 @@
+github.com/dustin/go-humanize v1.0.1 h1:GzkhY7T5VNhEkwH0PVJgjz+fX1rhBrR7pRT3mDkpeCY=
+github.com/dustin/go-humanize v1.0.1/go.mod h1:Mu1zIs6XwVuF/gI1OepvI0qD18qycQx+mFykh5fBlto=
+github.com/google/pprof v0.0.0-20250317173921-a4b03ec1a45e h1:ijClszYn+mADRFY17kjQEVQ1XRhq2/JR1M3sGqeJoxs=
+github.com/google/pprof v0.0.0-20250317173921-a4b03ec1a45e/go.mod h1:boTsfXsheKC2y+lKOCMpSfarhxDeIzfZG1jqGcPl3cA=
+github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
+github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
+github.com/hashicorp/golang-lru/v2 v2.0.7 h1:a+bsQ5rvGLjzHuww6tVxozPZFVghXaHOwFs4luLUK2k=
+github.com/hashicorp/golang-lru/v2 v2.0.7/go.mod h1:QeFd9opnmA6QUJc5vARoKUSoFhyfM2/ZepoAG6RGpeM=
+github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
+github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
+github.com/ncruces/go-strftime v1.0.0 h1:HMFp8mLCTPp341M/ZnA4qaf7ZlsbTc+miZjCLOFAw7w=
+github.com/ncruces/go-strftime v1.0.0/go.mod h1:Fwc5htZGVVkseilnfgOVb9mKy6w1naJmn9CehxcKcls=
+github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94icq4NjY3clb7Lk8O1qJ8BdBEF8z0ibU0rE=
+github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo=
+golang.org/x/crypto v0.54.0 h1:YLIA59K4fiNzHzjnZt2tUJQjQtUWfWbeHBqKtk3eScw=
+golang.org/x/crypto v0.54.0/go.mod h1:KWL8ny2AZdGR2cWmzeHrp2azQPGogOv+HeQaVEXC2dk=
+golang.org/x/mod v0.36.0 h1:JJjpVx6myfUsUdAzZuOSTTmRE0PfZeNWzzvKrP7amb4=
+golang.org/x/mod v0.36.0/go.mod h1:moc6ELqsWcOw5Ef3xVprK5ul/MvtVvkIXLziUOICjUQ=
+golang.org/x/sync v0.20.0 h1:e0PTpb7pjO8GAtTs2dQ6jYa5BWYlMuX047Dco/pItO4=
+golang.org/x/sync v0.20.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
+golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
+golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
+golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
+golang.org/x/tools v0.45.0 h1:18qN3FAooORvApf5XjCXgsuayZOEtXf6JK18I3+ONa8=
+golang.org/x/tools v0.45.0/go.mod h1:LuUGqqaXcXMEFEruIVJVm5mgDD8vww/z/SR1gQ4uE/0=
+modernc.org/cc/v4 v4.28.4 h1:Hd/4Es+MBj+/7hSdZaisNyu6bv3V0Dp2MdllyfqaH+c=
+modernc.org/cc/v4 v4.28.4/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI=
+modernc.org/ccgo/v4 v4.34.4 h1:OVnSOWQjVKOYkFxoHYB+qQmSHK5gqMqARM+K9DpR/Ws=
+modernc.org/ccgo/v4 v4.34.4/go.mod h1:qdKqE8FNIYyysougB1RX9MxCzp5oJOcQXSobANJ4TuE=
+modernc.org/fileutil v1.4.0 h1:j6ZzNTftVS054gi281TyLjHPp6CPHr2KCxEXjEbD6SM=
+modernc.org/fileutil v1.4.0/go.mod h1:EqdKFDxiByqxLk8ozOxObDSfcVOv/54xDs/DUHdvCUU=
+modernc.org/gc/v2 v2.6.5 h1:nyqdV8q46KvTpZlsw66kWqwXRHdjIlJOhG6kxiV/9xI=
+modernc.org/gc/v2 v2.6.5/go.mod h1:YgIahr1ypgfe7chRuJi2gD7DBQiKSLMPgBQe9oIiito=
+modernc.org/gc/v3 v3.1.3 h1:6QAplYyVO+KdPW3pGnqmJDUxtkec8ooEWvks/hhU3lc=
+modernc.org/gc/v3 v3.1.3/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY=
+modernc.org/goabi0 v0.2.0 h1:HvEowk7LxcPd0eq6mVOAEMai46V+i7Jrj13t4AzuNks=
+modernc.org/goabi0 v0.2.0/go.mod h1:CEFRnnJhKvWT1c1JTI3Avm+tgOWbkOu5oPA8eH8LnMI=
+modernc.org/libc v1.73.4 h1:+ra4Ui8ngyt8HDcO1FTDPWlkAh6yOdaO2yAoh8MddQA=
+modernc.org/libc v1.73.4/go.mod h1:DXZ3eO8qMCNn2SnmTNCiC71nJ9Rcq3PsnpU6Vc4rWK8=
+modernc.org/mathutil v1.7.1 h1:GCZVGXdaN8gTqB1Mf/usp1Y/hSqgI2vAGGP4jZMCxOU=
+modernc.org/mathutil v1.7.1/go.mod h1:4p5IwJITfppl0G4sUEDtCr4DthTaT47/N3aT6MhfgJg=
+modernc.org/memory v1.11.0 h1:o4QC8aMQzmcwCK3t3Ux/ZHmwFPzE6hf2Y5LbkRs+hbI=
+modernc.org/memory v1.11.0/go.mod h1:/JP4VbVC+K5sU2wZi9bHoq2MAkCnrt2r98UGeSK7Mjw=
+modernc.org/opt v0.2.0 h1:tGyef5ApycA7FSEOMraay9SaTk5zmbx7Tu+cJs4QKZg=
+modernc.org/opt v0.2.0/go.mod h1:03fq9lsNfvkYSfxrfUhZCWPk1lm4cq4N+Bh//bEtgns=
+modernc.org/sortutil v1.2.1 h1:+xyoGf15mM3NMlPDnFqrteY07klSFxLElE2PVuWIJ7w=
+modernc.org/sortutil v1.2.1/go.mod h1:7ZI3a3REbai7gzCLcotuw9AC4VZVpYMjDzETGsSMqJE=
+modernc.org/sqlite v1.53.0 h1:20WG8N9q4ji/dEqGk4uiI0c6OPjSeLTNYGFCc3+7c1M=
+modernc.org/sqlite v1.53.0/go.mod h1:xoEpOIpGrgT48H5iiyt/YXPCZPEzlfmfFwtk8Lklw8s=
+modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0=
+modernc.org/strutil v1.2.1/go.mod h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A=
+modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y=
+modernc.org/token v1.1.0/go.mod h1:UGzOrNV1mAFSEB63lOFHIpNRUVMvYTc6yu1SMY/XTDM=
diff --git a/internal/store/admin.go b/internal/store/admin.go
new file mode 100644
index 0000000..062e526
--- /dev/null
+++ b/internal/store/admin.go
@@ -0,0 +1,61 @@
+package store
+
+import (
+ "database/sql"
+ "errors"
+ "fmt"
+ "time"
+)
+
+// ErrNoAdmin is returned by GetAdmin when primary setup has not happened yet.
+var ErrNoAdmin = errors.New("no administrator account")
+
+// Admin is the single panel administrator (spec 7.6.1).
+type Admin struct {
+ Username string
+ PasswordHash string
+ CreatedAt time.Time
+}
+
+// AdminExists reports whether the administrator account has been created. This
+// doubles as the "primary setup complete" flag: once true, the /setup route is
+// permanently gone (spec 7.6.1).
+func (s *Store) AdminExists() (bool, error) {
+ var n int
+ if err := s.db.QueryRow("SELECT COUNT(*) FROM admin").Scan(&n); err != nil {
+ return false, fmt.Errorf("count admin: %w", err)
+ }
+ return n > 0, nil
+}
+
+// CreateAdmin inserts the administrator row. It fails if one already exists,
+// which — combined with the id=1 constraint — makes admin creation one-shot
+// even under a race between two setup submissions.
+func (s *Store) CreateAdmin(username, passwordHash string) error {
+ _, err := s.db.Exec(
+ "INSERT INTO admin (id, username, password_hash, created_at) VALUES (1, ?, ?, ?)",
+ username, passwordHash, time.Now().UTC().Format(time.RFC3339),
+ )
+ if err != nil {
+ return fmt.Errorf("create admin: %w", err)
+ }
+ return nil
+}
+
+// GetAdmin returns the administrator account, or ErrNoAdmin if setup is pending.
+func (s *Store) GetAdmin() (Admin, error) {
+ var (
+ a Admin
+ createdAt string
+ )
+ err := s.db.QueryRow("SELECT username, password_hash, created_at FROM admin WHERE id = 1").
+ Scan(&a.Username, &a.PasswordHash, &createdAt)
+ if errors.Is(err, sql.ErrNoRows) {
+ return Admin{}, ErrNoAdmin
+ }
+ if err != nil {
+ return Admin{}, fmt.Errorf("get admin: %w", err)
+ }
+ a.CreatedAt, _ = time.Parse(time.RFC3339, createdAt)
+ return a, nil
+}
diff --git a/internal/store/migrations/0001_init.sql b/internal/store/migrations/0001_init.sql
new file mode 100644
index 0000000..d8ae924
--- /dev/null
+++ b/internal/store/migrations/0001_init.sql
@@ -0,0 +1,76 @@
+-- Initial SelfPost schema (spec 9). One SQLite file under /data holds the whole
+-- panel state so a single directory backup/restore is sufficient (spec 7.5.A).
+
+-- Single administrator account (spec 7.6.1). Exactly one row is allowed; the
+-- presence of that row is what marks primary setup as complete, which is why
+-- the /setup route disappears once it exists.
+CREATE TABLE admin (
+ id INTEGER PRIMARY KEY CHECK (id = 1),
+ username TEXT NOT NULL,
+ password_hash TEXT NOT NULL,
+ created_at TEXT NOT NULL
+);
+
+-- Free-form key/value panel settings (retention overrides, misc flags).
+CREATE TABLE settings (
+ key TEXT PRIMARY KEY,
+ value TEXT NOT NULL
+);
+
+-- Sending domains managed through the panel (spec 4.1). DKIM keys themselves
+-- live on disk under /data; this row records the selector and metadata.
+CREATE TABLE domains (
+ id INTEGER PRIMARY KEY AUTOINCREMENT,
+ name TEXT NOT NULL UNIQUE,
+ dkim_selector TEXT NOT NULL,
+ created_at TEXT NOT NULL
+);
+
+-- Applications bound to a domain (spec 4.1). address_mode is either the domain
+-- wildcard or an explicit address list; the SASL login is globally unique.
+CREATE TABLE applications (
+ id INTEGER PRIMARY KEY AUTOINCREMENT,
+ domain_id INTEGER NOT NULL REFERENCES domains(id) ON DELETE CASCADE,
+ login TEXT NOT NULL UNIQUE,
+ address_mode TEXT NOT NULL CHECK (address_mode IN ('wildcard', 'list')),
+ created_at TEXT NOT NULL
+);
+
+-- Explicit sender addresses for applications in 'list' mode. Each address must
+-- belong to the application's domain (validated in the panel, spec 7.6.2).
+CREATE TABLE application_addresses (
+ id INTEGER PRIMARY KEY AUTOINCREMENT,
+ application_id INTEGER NOT NULL REFERENCES applications(id) ON DELETE CASCADE,
+ address TEXT NOT NULL,
+ UNIQUE (application_id, address)
+);
+
+-- Structured send log (spec 7.3). One row per (queue-id, recipient); the
+-- log-tailer advances status from queued to a final state.
+CREATE TABLE send_log (
+ id INTEGER PRIMARY KEY AUTOINCREMENT,
+ queue_id TEXT,
+ domain TEXT,
+ app_login TEXT,
+ from_addr TEXT,
+ to_addr TEXT,
+ subject TEXT,
+ status TEXT NOT NULL,
+ created_at TEXT NOT NULL,
+ updated_at TEXT NOT NULL
+);
+CREATE INDEX idx_send_log_queue_id ON send_log (queue_id);
+CREATE INDEX idx_send_log_domain ON send_log (domain);
+CREATE INDEX idx_send_log_created_at ON send_log (created_at);
+
+-- Differentiated rate limits per domain/application (spec 7.4). Both the IP
+-- binding and the message limit are optional.
+CREATE TABLE rate_limits (
+ id INTEGER PRIMARY KEY AUTOINCREMENT,
+ scope TEXT NOT NULL CHECK (scope IN ('domain', 'application')),
+ ref_id INTEGER NOT NULL,
+ allowed_ips TEXT,
+ max_messages INTEGER,
+ window_seconds INTEGER,
+ UNIQUE (scope, ref_id)
+);
diff --git a/internal/store/store.go b/internal/store/store.go
new file mode 100644
index 0000000..e9b22c0
--- /dev/null
+++ b/internal/store/store.go
@@ -0,0 +1,100 @@
+// Package store owns the SelfPost SQLite database: the single file under /data
+// that persists the administrator account, sending domains and applications,
+// the send log and rate-limit settings (spec 9). It exposes typed queries so
+// the rest of the panel never builds SQL by hand.
+package store
+
+import (
+ "database/sql"
+ "embed"
+ "fmt"
+ "io/fs"
+ "sort"
+
+ _ "modernc.org/sqlite" // pure-Go SQLite driver (no cgo), keeps the static build
+)
+
+//go:embed migrations/*.sql
+var migrationsFS embed.FS
+
+// Store wraps the database connection pool.
+type Store struct {
+ db *sql.DB
+}
+
+// Open opens (creating if needed) the SQLite database at path, enables WAL and
+// foreign keys, and applies any pending migrations. The caller owns Close.
+func Open(path string) (*Store, error) {
+ // _pragma parameters are applied on every pooled connection by the driver,
+ // so foreign-key enforcement and WAL survive connection churn.
+ dsn := fmt.Sprintf("file:%s?_pragma=journal_mode(WAL)&_pragma=busy_timeout(5000)&_pragma=foreign_keys(ON)", path)
+ db, err := sql.Open("sqlite", dsn)
+ if err != nil {
+ return nil, fmt.Errorf("open database: %w", err)
+ }
+ // modernc's driver serializes writes anyway; a small pool avoids
+ // "database is locked" surprises under WAL.
+ db.SetMaxOpenConns(1)
+
+ s := &Store{db: db}
+ if err := s.migrate(); err != nil {
+ db.Close()
+ return nil, err
+ }
+ return s, nil
+}
+
+// Close closes the underlying database.
+func (s *Store) Close() error {
+ return s.db.Close()
+}
+
+// migrate applies embedded migrations in filename order, tracking progress via
+// SQLite's PRAGMA user_version so each migration runs at most once.
+func (s *Store) migrate() error {
+ entries, err := fs.ReadDir(migrationsFS, "migrations")
+ if err != nil {
+ return fmt.Errorf("read migrations: %w", err)
+ }
+ names := make([]string, 0, len(entries))
+ for _, e := range entries {
+ if !e.IsDir() {
+ names = append(names, e.Name())
+ }
+ }
+ sort.Strings(names)
+
+ var version int
+ if err := s.db.QueryRow("PRAGMA user_version").Scan(&version); err != nil {
+ return fmt.Errorf("read schema version: %w", err)
+ }
+
+ for i, name := range names {
+ target := i + 1
+ if target <= version {
+ continue
+ }
+ sqlBytes, err := migrationsFS.ReadFile("migrations/" + name)
+ if err != nil {
+ return fmt.Errorf("read migration %s: %w", name, err)
+ }
+ tx, err := s.db.Begin()
+ if err != nil {
+ return fmt.Errorf("begin migration %s: %w", name, err)
+ }
+ if _, err := tx.Exec(string(sqlBytes)); err != nil {
+ tx.Rollback()
+ return fmt.Errorf("apply migration %s: %w", name, err)
+ }
+ // PRAGMA does not accept a bound parameter, and target is a trusted
+ // loop index, so formatting it in is safe.
+ if _, err := tx.Exec(fmt.Sprintf("PRAGMA user_version = %d", target)); err != nil {
+ tx.Rollback()
+ return fmt.Errorf("bump schema version for %s: %w", name, err)
+ }
+ if err := tx.Commit(); err != nil {
+ return fmt.Errorf("commit migration %s: %w", name, err)
+ }
+ }
+ return nil
+}
diff --git a/internal/web/handlers_auth.go b/internal/web/handlers_auth.go
new file mode 100644
index 0000000..6213b3d
--- /dev/null
+++ b/internal/web/handlers_auth.go
@@ -0,0 +1,113 @@
+package web
+
+import (
+ "errors"
+ "net/http"
+ "strings"
+
+ "codeberg.org/mix/selfpost/internal/store"
+ "golang.org/x/crypto/bcrypt"
+)
+
+// sessionCookie is the name of the panel session cookie.
+const sessionCookie = "selfpost_session"
+
+// handleLogin serves the login form (GET) and authenticates (POST). Until an
+// administrator exists there is nobody to log in, so it points at setup.
+func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
+ exists, err := s.store.AdminExists()
+ if err != nil {
+ http.Error(w, "internal error", http.StatusInternalServerError)
+ return
+ }
+ if !exists {
+ // No admin yet: login is meaningless. Send a clear message rather than
+ // a failing form.
+ s.render(w, http.StatusOK, "login", map[string]any{
+ "Title": "SelfPost — Sign in",
+ "SetupHint": true,
+ })
+ return
+ }
+
+ switch r.Method {
+ case http.MethodGet:
+ s.renderLogin(w, http.StatusOK, "")
+ case http.MethodPost:
+ s.submitLogin(w, r)
+ default:
+ w.Header().Set("Allow", "GET, POST")
+ http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
+ }
+}
+
+func (s *Server) renderLogin(w http.ResponseWriter, status int, formErr string) {
+ s.render(w, status, "login", map[string]any{
+ "Title": "SelfPost — Sign in",
+ "Error": formErr,
+ })
+}
+
+func (s *Server) submitLogin(w http.ResponseWriter, r *http.Request) {
+ // Brute-force throttle by client IP (spec 7.6.5).
+ if !s.loginLimiter.Allow(clientIP(r)) {
+ s.renderLogin(w, http.StatusTooManyRequests, "Too many attempts. Please wait and try again.")
+ return
+ }
+ if err := r.ParseForm(); err != nil {
+ s.renderLogin(w, http.StatusBadRequest, "Invalid form submission.")
+ return
+ }
+ username := strings.TrimSpace(r.PostFormValue("username"))
+ password := r.PostFormValue("password")
+
+ admin, err := s.store.GetAdmin()
+ if err != nil {
+ if !errors.Is(err, store.ErrNoAdmin) {
+ logf("panel: login: get admin failed: %v", err)
+ }
+ s.renderLogin(w, http.StatusUnauthorized, "Invalid username or password.")
+ return
+ }
+
+ // Always run bcrypt so timing does not distinguish "wrong user" from
+ // "wrong password", and compare the username too.
+ pwErr := bcrypt.CompareHashAndPassword([]byte(admin.PasswordHash), []byte(password))
+ if username != admin.Username || pwErr != nil {
+ s.renderLogin(w, http.StatusUnauthorized, "Invalid username or password.")
+ return
+ }
+
+ token := s.sessions.Create(admin.Username)
+ http.SetCookie(w, &http.Cookie{
+ Name: sessionCookie,
+ Value: token,
+ Path: "/",
+ HttpOnly: true,
+ Secure: s.cfg.CookieSecure,
+ SameSite: http.SameSiteLaxMode,
+ })
+ http.Redirect(w, r, "/", http.StatusSeeOther)
+}
+
+// handleLogout destroys the session and clears the cookie.
+func (s *Server) handleLogout(w http.ResponseWriter, r *http.Request) {
+ if r.Method != http.MethodPost {
+ w.Header().Set("Allow", "POST")
+ http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
+ return
+ }
+ if c, err := r.Cookie(sessionCookie); err == nil {
+ s.sessions.Destroy(c.Value)
+ }
+ http.SetCookie(w, &http.Cookie{
+ Name: sessionCookie,
+ Value: "",
+ Path: "/",
+ MaxAge: -1,
+ HttpOnly: true,
+ Secure: s.cfg.CookieSecure,
+ SameSite: http.SameSiteLaxMode,
+ })
+ http.Redirect(w, r, "/login", http.StatusSeeOther)
+}
diff --git a/internal/web/handlers_setup.go b/internal/web/handlers_setup.go
new file mode 100644
index 0000000..6e26257
--- /dev/null
+++ b/internal/web/handlers_setup.go
@@ -0,0 +1,98 @@
+package web
+
+import (
+ "net/http"
+ "strings"
+
+ "golang.org/x/crypto/bcrypt"
+)
+
+// handleSetup serves the one-time administrator creation flow at
+// /setup/ (spec 7.6.1). Once an administrator exists the whole route
+// returns 404; an invalid or expired token is indistinguishable from a missing
+// page, also 404.
+func (s *Server) handleSetup(w http.ResponseWriter, r *http.Request) {
+ // Route-specific rate limit, separate from login (spec 7.6.1).
+ if !s.setupLimiter.Allow(clientIP(r)) {
+ http.Error(w, "too many requests", http.StatusTooManyRequests)
+ return
+ }
+
+ token := strings.TrimPrefix(r.URL.Path, "/setup/")
+ // Reject nested/garbage paths outright.
+ if token == "" || strings.Contains(token, "/") {
+ http.NotFound(w, r)
+ return
+ }
+ if !s.setup.validate(token) {
+ http.NotFound(w, r)
+ return
+ }
+
+ switch r.Method {
+ case http.MethodGet:
+ s.renderSetupForm(w, http.StatusOK, token, "")
+ case http.MethodPost:
+ s.submitSetup(w, r, token)
+ default:
+ w.Header().Set("Allow", "GET, POST")
+ http.Error(w, "method not allowed", http.StatusMethodNotAllowed)
+ }
+}
+
+func (s *Server) renderSetupForm(w http.ResponseWriter, status int, token, formErr string) {
+ s.render(w, status, "setup", map[string]any{
+ "Title": "SelfPost — Create administrator",
+ "Token": token,
+ "Error": formErr,
+ })
+}
+
+func (s *Server) submitSetup(w http.ResponseWriter, r *http.Request, token string) {
+ if err := r.ParseForm(); err != nil {
+ s.renderSetupForm(w, http.StatusBadRequest, token, "Invalid form submission.")
+ return
+ }
+ username := strings.TrimSpace(r.PostFormValue("username"))
+ password := r.PostFormValue("password")
+ confirm := r.PostFormValue("password_confirm")
+
+ if err := validateUsername(username); err != nil {
+ s.renderSetupForm(w, http.StatusBadRequest, token, err.Error())
+ return
+ }
+ if password != confirm {
+ s.renderSetupForm(w, http.StatusBadRequest, token, "Passwords do not match.")
+ return
+ }
+ if err := validateAdminPassword(password); err != nil {
+ s.renderSetupForm(w, http.StatusBadRequest, token, err.Error())
+ return
+ }
+
+ hash, err := bcrypt.GenerateFromPassword([]byte(password), bcrypt.DefaultCost)
+ if err != nil {
+ logf("panel: setup: hashing password failed: %v", err)
+ s.renderSetupForm(w, http.StatusInternalServerError, token, "Internal error. Please try again.")
+ return
+ }
+
+ if err := s.store.CreateAdmin(username, string(hash)); err != nil {
+ // A concurrent submission may have already created the admin; the
+ // id=1 / non-empty-table guard makes this the second writer. Treat it
+ // as "setup already done" rather than an error.
+ if exists, _ := s.store.AdminExists(); exists {
+ s.setup.complete()
+ http.Redirect(w, r, "/login", http.StatusSeeOther)
+ return
+ }
+ logf("panel: setup: create admin failed: %v", err)
+ s.renderSetupForm(w, http.StatusInternalServerError, token, "Internal error. Please try again.")
+ return
+ }
+
+ // Setup is now permanently complete: burn the token (spec 7.6.1).
+ s.setup.complete()
+ logf("panel: administrator %q created; setup link is now disabled", username)
+ http.Redirect(w, r, "/login", http.StatusSeeOther)
+}
diff --git a/internal/web/middleware.go b/internal/web/middleware.go
new file mode 100644
index 0000000..3259012
--- /dev/null
+++ b/internal/web/middleware.go
@@ -0,0 +1,51 @@
+package web
+
+import (
+ "context"
+ "net/http"
+)
+
+type ctxKey int
+
+const usernameKey ctxKey = 0
+
+// requireAuth wraps a handler so only requests with a valid session cookie
+// reach it; everyone else is redirected to the login page. The authenticated
+// username is stashed in the request context for downstream handlers.
+func (s *Server) requireAuth(next http.Handler) http.Handler {
+ return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
+ c, err := r.Cookie(sessionCookie)
+ if err != nil {
+ http.Redirect(w, r, "/login", http.StatusSeeOther)
+ return
+ }
+ username, ok := s.sessions.Lookup(c.Value)
+ if !ok {
+ http.Redirect(w, r, "/login", http.StatusSeeOther)
+ return
+ }
+ ctx := context.WithValue(r.Context(), usernameKey, username)
+ next.ServeHTTP(w, r.WithContext(ctx))
+ })
+}
+
+// currentUser returns the authenticated username from the request context.
+func currentUser(r *http.Request) string {
+ if v, ok := r.Context().Value(usernameKey).(string); ok {
+ return v
+ }
+ return ""
+}
+
+// handleDashboard is the authenticated landing page. Phase 2 shows a minimal
+// shell; domains, applications and the send log arrive in later phases.
+func (s *Server) handleDashboard(w http.ResponseWriter, r *http.Request) {
+ if r.URL.Path != "/" {
+ http.NotFound(w, r)
+ return
+ }
+ s.render(w, http.StatusOK, "dashboard", map[string]any{
+ "Title": "SelfPost",
+ "User": currentUser(r),
+ })
+}
diff --git a/internal/web/ratelimit.go b/internal/web/ratelimit.go
new file mode 100644
index 0000000..c0dde2b
--- /dev/null
+++ b/internal/web/ratelimit.go
@@ -0,0 +1,62 @@
+package web
+
+import (
+ "sync"
+ "time"
+)
+
+// rateLimiter is a simple fixed-window per-key counter used to throttle the
+// setup and login routes (spec 7.6.1, 7.6.5). Keys are client IPs. It is not a
+// precise sliding window — a coarse backstop against brute-force and log noise
+// is all these routes need.
+type rateLimiter struct {
+ max int
+ window time.Duration
+
+ mu sync.Mutex
+ buckets map[string]*rlBucket
+}
+
+type rlBucket struct {
+ count int
+ windowEnds time.Time
+}
+
+func newRateLimiter(max int, window time.Duration) *rateLimiter {
+ return &rateLimiter{
+ max: max,
+ window: window,
+ buckets: make(map[string]*rlBucket),
+ }
+}
+
+// Allow records an attempt for key and reports whether it is within the limit.
+// The current window is reset lazily once it elapses.
+func (r *rateLimiter) Allow(key string) bool {
+ now := time.Now()
+ r.mu.Lock()
+ defer r.mu.Unlock()
+
+ b := r.buckets[key]
+ if b == nil || now.After(b.windowEnds) {
+ r.buckets[key] = &rlBucket{count: 1, windowEnds: now.Add(r.window)}
+ r.sweep(now)
+ return true
+ }
+ if b.count >= r.max {
+ return false
+ }
+ b.count++
+ return true
+}
+
+// sweep drops expired buckets so the map cannot grow without bound. Called
+// under the lock while a window is being reset, which is often enough given the
+// low request volume of these routes.
+func (r *rateLimiter) sweep(now time.Time) {
+ for k, b := range r.buckets {
+ if now.After(b.windowEnds) {
+ delete(r.buckets, k)
+ }
+ }
+}
diff --git a/internal/web/session.go b/internal/web/session.go
new file mode 100644
index 0000000..e85cf83
--- /dev/null
+++ b/internal/web/session.go
@@ -0,0 +1,62 @@
+package web
+
+import (
+ "sync"
+ "time"
+)
+
+// sessionTTL bounds how long a login lasts before re-authentication is needed.
+const sessionTTL = 12 * time.Hour
+
+// sessionStore keeps active sessions in memory. Sessions are deliberately not
+// persisted (spec 9 lists what must survive restart; sessions are not on it):
+// a restart simply logs the admin out, which is acceptable and avoids storing
+// bearer tokens on disk. Tokens are crypto-random (spec 7.6.6).
+type sessionStore struct {
+ mu sync.Mutex
+ sessions map[string]session
+}
+
+type session struct {
+ username string
+ expiresAt time.Time
+}
+
+func newSessionStore() *sessionStore {
+ return &sessionStore{sessions: make(map[string]session)}
+}
+
+// Create issues a new session for username and returns its token.
+func (s *sessionStore) Create(username string) string {
+ token := randomToken(32)
+ s.mu.Lock()
+ defer s.mu.Unlock()
+ s.sessions[token] = session{username: username, expiresAt: time.Now().Add(sessionTTL)}
+ return token
+}
+
+// Lookup returns the session username for a token if it exists and is unexpired.
+func (s *sessionStore) Lookup(token string) (string, bool) {
+ if token == "" {
+ return "", false
+ }
+ now := time.Now()
+ s.mu.Lock()
+ defer s.mu.Unlock()
+ sess, ok := s.sessions[token]
+ if !ok {
+ return "", false
+ }
+ if now.After(sess.expiresAt) {
+ delete(s.sessions, token)
+ return "", false
+ }
+ return sess.username, true
+}
+
+// Destroy invalidates a session token (logout).
+func (s *sessionStore) Destroy(token string) {
+ s.mu.Lock()
+ defer s.mu.Unlock()
+ delete(s.sessions, token)
+}
diff --git a/internal/web/setup.go b/internal/web/setup.go
new file mode 100644
index 0000000..e386cdf
--- /dev/null
+++ b/internal/web/setup.go
@@ -0,0 +1,136 @@
+package web
+
+import (
+ "crypto/subtle"
+ "fmt"
+ "os"
+ "sync"
+ "time"
+
+ "codeberg.org/mix/selfpost/internal/store"
+)
+
+// setupTokenTTL is the lifetime of a setup token (spec 7.6.1). After it
+// elapses the token is regenerated and re-announced on the next /setup hit.
+const setupTokenTTL = 10 * time.Minute
+
+// setupManager owns the one-time administrator setup token. The token itself is
+// ephemeral (regenerated on restart or expiry) and lives only in memory; the
+// persistent "setup complete" fact is the presence of the admin row in the
+// store, so once that exists the token is gone for good (spec 7.6.1).
+type setupManager struct {
+ store *store.Store
+ hostname string
+ tokenPath string
+
+ mu sync.Mutex
+ token string
+ expiresAt time.Time
+}
+
+func newSetupManager(st *store.Store, hostname, tokenPath string) *setupManager {
+ return &setupManager{store: st, hostname: hostname, tokenPath: tokenPath}
+}
+
+// bootstrap runs once at startup. If setup is already complete it clears any
+// stale token file; otherwise it mints and announces the first token.
+func (m *setupManager) bootstrap() error {
+ done, err := m.store.AdminExists()
+ if err != nil {
+ return err
+ }
+ if done {
+ m.clearTokenFile()
+ return nil
+ }
+ m.mu.Lock()
+ defer m.mu.Unlock()
+ m.regenerateLocked()
+ return nil
+}
+
+// activeToken returns the current valid setup token, regenerating and
+// re-announcing it if none exists or it has expired. It returns ("", false)
+// once setup is complete — callers must treat that as "route gone" (404).
+func (m *setupManager) activeToken() (string, bool) {
+ done, err := m.store.AdminExists()
+ if err != nil {
+ logf("panel: setup: admin check failed: %v", err)
+ return "", false
+ }
+ if done {
+ return "", false
+ }
+ m.mu.Lock()
+ defer m.mu.Unlock()
+ if m.token == "" || time.Now().After(m.expiresAt) {
+ m.regenerateLocked()
+ }
+ return m.token, true
+}
+
+// validate reports whether provided matches the active token, using a
+// constant-time comparison to avoid leaking a correct prefix via timing
+// (spec 7.6.1). A mismatch does NOT regenerate or invalidate the token: failed
+// attempts must not let an attacker DoS a legitimate setup (spec 7.6.1).
+func (m *setupManager) validate(provided string) bool {
+ token, ok := m.activeToken()
+ if !ok {
+ return false
+ }
+ return subtle.ConstantTimeCompare([]byte(provided), []byte(token)) == 1
+}
+
+// complete marks setup as finished: the admin row now exists, so drop the
+// in-memory token and remove the on-disk copy.
+func (m *setupManager) complete() {
+ m.mu.Lock()
+ m.token = ""
+ m.expiresAt = time.Time{}
+ m.mu.Unlock()
+ m.clearTokenFile()
+}
+
+// regenerateLocked mints a fresh token, announces it and mirrors it to disk.
+// Caller holds m.mu.
+func (m *setupManager) regenerateLocked() {
+ m.token = randomToken(16) // 128 bits of entropy (spec 7.6.1)
+ m.expiresAt = time.Now().Add(setupTokenTTL)
+ m.announce(m.token)
+}
+
+// announce prints the setup link to the container log and writes it to the
+// token file so it can be read either way (spec 7.6.1).
+func (m *setupManager) announce(token string) {
+ url := m.setupURL(token)
+ logf("panel: ==================================================================")
+ logf("panel: SelfPost first-run setup — open this one-time link within %s:", setupTokenTTL)
+ logf("panel: %s", url)
+ logf("panel: (also written to %s)", m.tokenPath)
+ logf("panel: ==================================================================")
+
+ if m.tokenPath == "" {
+ return
+ }
+ // 0600: the token is a bearer secret for creating the admin.
+ if err := os.WriteFile(m.tokenPath, []byte(url+"\n"), 0o600); err != nil {
+ logf("panel: setup: could not write token file %s: %v", m.tokenPath, err)
+ }
+}
+
+func (m *setupManager) setupURL(token string) string {
+ host := m.hostname
+ if host == "" {
+ host = "localhost"
+ }
+ return fmt.Sprintf("https://%s/setup/%s", host, token)
+}
+
+func (m *setupManager) clearTokenFile() {
+ if m.tokenPath == "" {
+ return
+ }
+ if err := os.Remove(m.tokenPath); err != nil && !os.IsNotExist(err) {
+ logf("panel: setup: could not remove token file %s: %v", m.tokenPath, err)
+ }
+}
diff --git a/internal/web/static/htmx.min.js b/internal/web/static/htmx.min.js
new file mode 100644
index 0000000..59937d7
--- /dev/null
+++ b/internal/web/static/htmx.min.js
@@ -0,0 +1 @@
+var htmx=function(){"use strict";const Q={onLoad:null,process:null,on:null,off:null,trigger:null,ajax:null,find:null,findAll:null,closest:null,values:function(e,t){const n=cn(e,t||"post");return n.values},remove:null,addClass:null,removeClass:null,toggleClass:null,takeClass:null,swap:null,defineExtension:null,removeExtension:null,logAll:null,logNone:null,logger:null,config:{historyEnabled:true,historyCacheSize:10,refreshOnHistoryMiss:false,defaultSwapStyle:"innerHTML",defaultSwapDelay:0,defaultSettleDelay:20,includeIndicatorStyles:true,indicatorClass:"htmx-indicator",requestClass:"htmx-request",addedClass:"htmx-added",settlingClass:"htmx-settling",swappingClass:"htmx-swapping",allowEval:true,allowScriptTags:true,inlineScriptNonce:"",inlineStyleNonce:"",attributesToSettle:["class","style","width","height"],withCredentials:false,timeout:0,wsReconnectDelay:"full-jitter",wsBinaryType:"blob",disableSelector:"[hx-disable], [data-hx-disable]",scrollBehavior:"instant",defaultFocusScroll:false,getCacheBusterParam:false,globalViewTransitions:false,methodsThatUseUrlParams:["get","delete"],selfRequestsOnly:true,ignoreTitle:false,scrollIntoViewOnBoost:true,triggerSpecsCache:null,disableInheritance:false,responseHandling:[{code:"204",swap:false},{code:"[23]..",swap:true},{code:"[45]..",swap:false,error:true}],allowNestedOobSwaps:true},parseInterval:null,_:null,version:"2.0.4"};Q.onLoad=j;Q.process=kt;Q.on=ye;Q.off=be;Q.trigger=he;Q.ajax=Rn;Q.find=u;Q.findAll=x;Q.closest=g;Q.remove=z;Q.addClass=K;Q.removeClass=G;Q.toggleClass=W;Q.takeClass=Z;Q.swap=$e;Q.defineExtension=Fn;Q.removeExtension=Bn;Q.logAll=V;Q.logNone=_;Q.parseInterval=d;Q._=e;const n={addTriggerHandler:St,bodyContains:le,canAccessLocalStorage:B,findThisElement:Se,filterValues:hn,swap:$e,hasAttribute:s,getAttributeValue:te,getClosestAttributeValue:re,getClosestMatch:o,getExpressionVars:En,getHeaders:fn,getInputValues:cn,getInternalData:ie,getSwapSpecification:gn,getTriggerSpecs:st,getTarget:Ee,makeFragment:P,mergeObjects:ce,makeSettleInfo:xn,oobSwap:He,querySelectorExt:ae,settleImmediately:Kt,shouldCancel:ht,triggerEvent:he,triggerErrorEvent:fe,withExtensions:Ft};const r=["get","post","put","delete","patch"];const H=r.map(function(e){return"[hx-"+e+"], [data-hx-"+e+"]"}).join(", ");function d(e){if(e==undefined){return undefined}let t=NaN;if(e.slice(-2)=="ms"){t=parseFloat(e.slice(0,-2))}else if(e.slice(-1)=="s"){t=parseFloat(e.slice(0,-1))*1e3}else if(e.slice(-1)=="m"){t=parseFloat(e.slice(0,-1))*1e3*60}else{t=parseFloat(e)}return isNaN(t)?undefined:t}function ee(e,t){return e instanceof Element&&e.getAttribute(t)}function s(e,t){return!!e.hasAttribute&&(e.hasAttribute(t)||e.hasAttribute("data-"+t))}function te(e,t){return ee(e,t)||ee(e,"data-"+t)}function c(e){const t=e.parentElement;if(!t&&e.parentNode instanceof ShadowRoot)return e.parentNode;return t}function ne(){return document}function m(e,t){return e.getRootNode?e.getRootNode({composed:t}):ne()}function o(e,t){while(e&&!t(e)){e=c(e)}return e||null}function i(e,t,n){const r=te(t,n);const o=te(t,"hx-disinherit");var i=te(t,"hx-inherit");if(e!==t){if(Q.config.disableInheritance){if(i&&(i==="*"||i.split(" ").indexOf(n)>=0)){return r}else{return null}}if(o&&(o==="*"||o.split(" ").indexOf(n)>=0)){return"unset"}}return r}function re(t,n){let r=null;o(t,function(e){return!!(r=i(t,ue(e),n))});if(r!=="unset"){return r}}function h(e,t){const n=e instanceof Element&&(e.matches||e.matchesSelector||e.msMatchesSelector||e.mozMatchesSelector||e.webkitMatchesSelector||e.oMatchesSelector);return!!n&&n.call(e,t)}function T(e){const t=/<([a-z][^\/\0>\x20\t\r\n\f]*)/i;const n=t.exec(e);if(n){return n[1].toLowerCase()}else{return""}}function q(e){const t=new DOMParser;return t.parseFromString(e,"text/html")}function L(e,t){while(t.childNodes.length>0){e.append(t.childNodes[0])}}function A(e){const t=ne().createElement("script");se(e.attributes,function(e){t.setAttribute(e.name,e.value)});t.textContent=e.textContent;t.async=false;if(Q.config.inlineScriptNonce){t.nonce=Q.config.inlineScriptNonce}return t}function N(e){return e.matches("script")&&(e.type==="text/javascript"||e.type==="module"||e.type==="")}function I(e){Array.from(e.querySelectorAll("script")).forEach(e=>{if(N(e)){const t=A(e);const n=e.parentNode;try{n.insertBefore(t,e)}catch(e){O(e)}finally{e.remove()}}})}function P(e){const t=e.replace(/]*)?>[\s\S]*?<\/head>/i,"");const n=T(t);let r;if(n==="html"){r=new DocumentFragment;const i=q(e);L(r,i.body);r.title=i.title}else if(n==="body"){r=new DocumentFragment;const i=q(t);L(r,i.body);r.title=i.title}else{const i=q(''+t+"");r=i.querySelector("template").content;r.title=i.title;var o=r.querySelector("title");if(o&&o.parentNode===r){o.remove();r.title=o.innerText}}if(r){if(Q.config.allowScriptTags){I(r)}else{r.querySelectorAll("script").forEach(e=>e.remove())}}return r}function oe(e){if(e){e()}}function t(e,t){return Object.prototype.toString.call(e)==="[object "+t+"]"}function k(e){return typeof e==="function"}function D(e){return t(e,"Object")}function ie(e){const t="htmx-internal-data";let n=e[t];if(!n){n=e[t]={}}return n}function M(t){const n=[];if(t){for(let e=0;e=0}function le(e){return e.getRootNode({composed:true})===document}function F(e){return e.trim().split(/\s+/)}function ce(e,t){for(const n in t){if(t.hasOwnProperty(n)){e[n]=t[n]}}return e}function S(e){try{return JSON.parse(e)}catch(e){O(e);return null}}function B(){const e="htmx:localStorageTest";try{localStorage.setItem(e,e);localStorage.removeItem(e);return true}catch(e){return false}}function U(t){try{const e=new URL(t);if(e){t=e.pathname+e.search}if(!/^\/$/.test(t)){t=t.replace(/\/+$/,"")}return t}catch(e){return t}}function e(e){return vn(ne().body,function(){return eval(e)})}function j(t){const e=Q.on("htmx:load",function(e){t(e.detail.elt)});return e}function V(){Q.logger=function(e,t,n){if(console){console.log(t,e,n)}}}function _(){Q.logger=null}function u(e,t){if(typeof e!=="string"){return e.querySelector(t)}else{return u(ne(),e)}}function x(e,t){if(typeof e!=="string"){return e.querySelectorAll(t)}else{return x(ne(),e)}}function E(){return window}function z(e,t){e=y(e);if(t){E().setTimeout(function(){z(e);e=null},t)}else{c(e).removeChild(e)}}function ue(e){return e instanceof Element?e:null}function $(e){return e instanceof HTMLElement?e:null}function J(e){return typeof e==="string"?e:null}function f(e){return e instanceof Element||e instanceof Document||e instanceof DocumentFragment?e:null}function K(e,t,n){e=ue(y(e));if(!e){return}if(n){E().setTimeout(function(){K(e,t);e=null},n)}else{e.classList&&e.classList.add(t)}}function G(e,t,n){let r=ue(y(e));if(!r){return}if(n){E().setTimeout(function(){G(r,t);r=null},n)}else{if(r.classList){r.classList.remove(t);if(r.classList.length===0){r.removeAttribute("class")}}}}function W(e,t){e=y(e);e.classList.toggle(t)}function Z(e,t){e=y(e);se(e.parentElement.children,function(e){G(e,t)});K(ue(e),t)}function g(e,t){e=ue(y(e));if(e&&e.closest){return e.closest(t)}else{do{if(e==null||h(e,t)){return e}}while(e=e&&ue(c(e)));return null}}function l(e,t){return e.substring(0,t.length)===t}function Y(e,t){return e.substring(e.length-t.length)===t}function ge(e){const t=e.trim();if(l(t,"<")&&Y(t,"/>")){return t.substring(1,t.length-2)}else{return t}}function p(t,r,n){if(r.indexOf("global ")===0){return p(t,r.slice(7),true)}t=y(t);const o=[];{let t=0;let n=0;for(let e=0;e"){t--}}if(n0){const r=ge(o.shift());let e;if(r.indexOf("closest ")===0){e=g(ue(t),ge(r.substr(8)))}else if(r.indexOf("find ")===0){e=u(f(t),ge(r.substr(5)))}else if(r==="next"||r==="nextElementSibling"){e=ue(t).nextElementSibling}else if(r.indexOf("next ")===0){e=pe(t,ge(r.substr(5)),!!n)}else if(r==="previous"||r==="previousElementSibling"){e=ue(t).previousElementSibling}else if(r.indexOf("previous ")===0){e=me(t,ge(r.substr(9)),!!n)}else if(r==="document"){e=document}else if(r==="window"){e=window}else if(r==="body"){e=document.body}else if(r==="root"){e=m(t,!!n)}else if(r==="host"){e=t.getRootNode().host}else{s.push(r)}if(e){i.push(e)}}if(s.length>0){const e=s.join(",");const c=f(m(t,!!n));i.push(...M(c.querySelectorAll(e)))}return i}var pe=function(t,e,n){const r=f(m(t,n)).querySelectorAll(e);for(let e=0;e=0;e--){const o=r[e];if(o.compareDocumentPosition(t)===Node.DOCUMENT_POSITION_FOLLOWING){return o}}};function ae(e,t){if(typeof e!=="string"){return p(e,t)[0]}else{return p(ne().body,e)[0]}}function y(e,t){if(typeof e==="string"){return u(f(t)||document,e)}else{return e}}function xe(e,t,n,r){if(k(t)){return{target:ne().body,event:J(e),listener:t,options:n}}else{return{target:y(e),event:J(t),listener:n,options:r}}}function ye(t,n,r,o){Vn(function(){const e=xe(t,n,r,o);e.target.addEventListener(e.event,e.listener,e.options)});const e=k(n);return e?n:r}function be(t,n,r){Vn(function(){const e=xe(t,n,r);e.target.removeEventListener(e.event,e.listener)});return k(n)?n:r}const ve=ne().createElement("output");function we(e,t){const n=re(e,t);if(n){if(n==="this"){return[Se(e,t)]}else{const r=p(e,n);if(r.length===0){O('The selector "'+n+'" on '+t+" returned no matches!");return[ve]}else{return r}}}}function Se(e,t){return ue(o(e,function(e){return te(ue(e),t)!=null}))}function Ee(e){const t=re(e,"hx-target");if(t){if(t==="this"){return Se(e,"hx-target")}else{return ae(e,t)}}else{const n=ie(e);if(n.boosted){return ne().body}else{return e}}}function Ce(t){const n=Q.config.attributesToSettle;for(let e=0;e0){s=e.substring(0,e.indexOf(":"));n=e.substring(e.indexOf(":")+1)}else{s=e}o.removeAttribute("hx-swap-oob");o.removeAttribute("data-hx-swap-oob");const r=p(t,n,false);if(r){se(r,function(e){let t;const n=o.cloneNode(true);t=ne().createDocumentFragment();t.appendChild(n);if(!Re(s,e)){t=f(n)}const r={shouldSwap:true,target:e,fragment:t};if(!he(e,"htmx:oobBeforeSwap",r))return;e=r.target;if(r.shouldSwap){qe(t);_e(s,e,e,t,i);Te()}se(i.elts,function(e){he(e,"htmx:oobAfterSwap",r)})});o.parentNode.removeChild(o)}else{o.parentNode.removeChild(o);fe(ne().body,"htmx:oobErrorNoTarget",{content:o})}return e}function Te(){const e=u("#--htmx-preserve-pantry--");if(e){for(const t of[...e.children]){const n=u("#"+t.id);n.parentNode.moveBefore(t,n);n.remove()}e.remove()}}function qe(e){se(x(e,"[hx-preserve], [data-hx-preserve]"),function(e){const t=te(e,"id");const n=ne().getElementById(t);if(n!=null){if(e.moveBefore){let e=u("#--htmx-preserve-pantry--");if(e==null){ne().body.insertAdjacentHTML("afterend","");e=u("#--htmx-preserve-pantry--")}e.moveBefore(n,null)}else{e.parentNode.replaceChild(n,e)}}})}function Le(l,e,c){se(e.querySelectorAll("[id]"),function(t){const n=ee(t,"id");if(n&&n.length>0){const r=n.replace("'","\\'");const o=t.tagName.replace(":","\\:");const e=f(l);const i=e&&e.querySelector(o+"[id='"+r+"']");if(i&&i!==e){const s=t.cloneNode();Oe(t,i);c.tasks.push(function(){Oe(t,s)})}}})}function Ae(e){return function(){G(e,Q.config.addedClass);kt(ue(e));Ne(f(e));he(e,"htmx:load")}}function Ne(e){const t="[autofocus]";const n=$(h(e,t)?e:e.querySelector(t));if(n!=null){n.focus()}}function a(e,t,n,r){Le(e,n,r);while(n.childNodes.length>0){const o=n.firstChild;K(ue(o),Q.config.addedClass);e.insertBefore(o,t);if(o.nodeType!==Node.TEXT_NODE&&o.nodeType!==Node.COMMENT_NODE){r.tasks.push(Ae(o))}}}function Ie(e,t){let n=0;while(n0}function $e(e,t,r,o){if(!o){o={}}e=y(e);const i=o.contextElement?m(o.contextElement,false):ne();const n=document.activeElement;let s={};try{s={elt:n,start:n?n.selectionStart:null,end:n?n.selectionEnd:null}}catch(e){}const l=xn(e);if(r.swapStyle==="textContent"){e.textContent=t}else{let n=P(t);l.title=n.title;if(o.selectOOB){const u=o.selectOOB.split(",");for(let t=0;t0){E().setTimeout(c,r.settleDelay)}else{c()}}function Je(e,t,n){const r=e.getResponseHeader(t);if(r.indexOf("{")===0){const o=S(r);for(const i in o){if(o.hasOwnProperty(i)){let e=o[i];if(D(e)){n=e.target!==undefined?e.target:n}else{e={value:e}}he(n,i,e)}}}else{const s=r.split(",");for(let e=0;e0){const s=o[0];if(s==="]"){e--;if(e===0){if(n===null){t=t+"true"}o.shift();t+=")})";try{const l=vn(r,function(){return Function(t)()},function(){return true});l.source=t;return l}catch(e){fe(ne().body,"htmx:syntax:error",{error:e,source:t});return null}}}else if(s==="["){e++}if(tt(s,n,i)){t+="(("+i+"."+s+") ? ("+i+"."+s+") : (window."+s+"))"}else{t=t+s}n=o.shift()}}}function C(e,t){let n="";while(e.length>0&&!t.test(e[0])){n+=e.shift()}return n}function rt(e){let t;if(e.length>0&&Ye.test(e[0])){e.shift();t=C(e,Qe).trim();e.shift()}else{t=C(e,v)}return t}const ot="input, textarea, select";function it(e,t,n){const r=[];const o=et(t);do{C(o,w);const l=o.length;const c=C(o,/[,\[\s]/);if(c!==""){if(c==="every"){const u={trigger:"every"};C(o,w);u.pollInterval=d(C(o,/[,\[\s]/));C(o,w);var i=nt(e,o,"event");if(i){u.eventFilter=i}r.push(u)}else{const a={trigger:c};var i=nt(e,o,"event");if(i){a.eventFilter=i}C(o,w);while(o.length>0&&o[0]!==","){const f=o.shift();if(f==="changed"){a.changed=true}else if(f==="once"){a.once=true}else if(f==="consume"){a.consume=true}else if(f==="delay"&&o[0]===":"){o.shift();a.delay=d(C(o,v))}else if(f==="from"&&o[0]===":"){o.shift();if(Ye.test(o[0])){var s=rt(o)}else{var s=C(o,v);if(s==="closest"||s==="find"||s==="next"||s==="previous"){o.shift();const h=rt(o);if(h.length>0){s+=" "+h}}}a.from=s}else if(f==="target"&&o[0]===":"){o.shift();a.target=rt(o)}else if(f==="throttle"&&o[0]===":"){o.shift();a.throttle=d(C(o,v))}else if(f==="queue"&&o[0]===":"){o.shift();a.queue=C(o,v)}else if(f==="root"&&o[0]===":"){o.shift();a[f]=rt(o)}else if(f==="threshold"&&o[0]===":"){o.shift();a[f]=C(o,v)}else{fe(e,"htmx:syntax:error",{token:o.shift()})}C(o,w)}r.push(a)}}if(o.length===l){fe(e,"htmx:syntax:error",{token:o.shift()})}C(o,w)}while(o[0]===","&&o.shift());if(n){n[t]=r}return r}function st(e){const t=te(e,"hx-trigger");let n=[];if(t){const r=Q.config.triggerSpecsCache;n=r&&r[t]||it(e,t,r)}if(n.length>0){return n}else if(h(e,"form")){return[{trigger:"submit"}]}else if(h(e,'input[type="button"], input[type="submit"]')){return[{trigger:"click"}]}else if(h(e,ot)){return[{trigger:"change"}]}else{return[{trigger:"click"}]}}function lt(e){ie(e).cancelled=true}function ct(e,t,n){const r=ie(e);r.timeout=E().setTimeout(function(){if(le(e)&&r.cancelled!==true){if(!gt(n,e,Mt("hx:poll:trigger",{triggerSpec:n,target:e}))){t(e)}ct(e,t,n)}},n.pollInterval)}function ut(e){return location.hostname===e.hostname&&ee(e,"href")&&ee(e,"href").indexOf("#")!==0}function at(e){return g(e,Q.config.disableSelector)}function ft(t,n,e){if(t instanceof HTMLAnchorElement&&ut(t)&&(t.target===""||t.target==="_self")||t.tagName==="FORM"&&String(ee(t,"method")).toLowerCase()!=="dialog"){n.boosted=true;let r,o;if(t.tagName==="A"){r="get";o=ee(t,"href")}else{const i=ee(t,"method");r=i?i.toLowerCase():"get";o=ee(t,"action");if(o==null||o===""){o=ne().location.href}if(r==="get"&&o.includes("?")){o=o.replace(/\?[^#]+/,"")}}e.forEach(function(e){pt(t,function(e,t){const n=ue(e);if(at(n)){b(n);return}de(r,o,n,t)},n,e,true)})}}function ht(e,t){const n=ue(t);if(!n){return false}if(e.type==="submit"||e.type==="click"){if(n.tagName==="FORM"){return true}if(h(n,'input[type="submit"], button')&&(h(n,"[form]")||g(n,"form")!==null)){return true}if(n instanceof HTMLAnchorElement&&n.href&&(n.getAttribute("href")==="#"||n.getAttribute("href").indexOf("#")!==0)){return true}}return false}function dt(e,t){return ie(e).boosted&&e instanceof HTMLAnchorElement&&t.type==="click"&&(t.ctrlKey||t.metaKey)}function gt(e,t,n){const r=e.eventFilter;if(r){try{return r.call(t,n)!==true}catch(e){const o=r.source;fe(ne().body,"htmx:eventFilter:error",{error:e,source:o});return true}}return false}function pt(l,c,e,u,a){const f=ie(l);let t;if(u.from){t=p(l,u.from)}else{t=[l]}if(u.changed){if(!("lastValue"in f)){f.lastValue=new WeakMap}t.forEach(function(e){if(!f.lastValue.has(u)){f.lastValue.set(u,new WeakMap)}f.lastValue.get(u).set(e,e.value)})}se(t,function(i){const s=function(e){if(!le(l)){i.removeEventListener(u.trigger,s);return}if(dt(l,e)){return}if(a||ht(e,l)){e.preventDefault()}if(gt(u,l,e)){return}const t=ie(e);t.triggerSpec=u;if(t.handledFor==null){t.handledFor=[]}if(t.handledFor.indexOf(l)<0){t.handledFor.push(l);if(u.consume){e.stopPropagation()}if(u.target&&e.target){if(!h(ue(e.target),u.target)){return}}if(u.once){if(f.triggeredOnce){return}else{f.triggeredOnce=true}}if(u.changed){const n=event.target;const r=n.value;const o=f.lastValue.get(u);if(o.has(n)&&o.get(n)===r){return}o.set(n,r)}if(f.delayed){clearTimeout(f.delayed)}if(f.throttle){return}if(u.throttle>0){if(!f.throttle){he(l,"htmx:trigger");c(l,e);f.throttle=E().setTimeout(function(){f.throttle=null},u.throttle)}}else if(u.delay>0){f.delayed=E().setTimeout(function(){he(l,"htmx:trigger");c(l,e)},u.delay)}else{he(l,"htmx:trigger");c(l,e)}}};if(e.listenerInfos==null){e.listenerInfos=[]}e.listenerInfos.push({trigger:u.trigger,listener:s,on:i});i.addEventListener(u.trigger,s)})}let mt=false;let xt=null;function yt(){if(!xt){xt=function(){mt=true};window.addEventListener("scroll",xt);window.addEventListener("resize",xt);setInterval(function(){if(mt){mt=false;se(ne().querySelectorAll("[hx-trigger*='revealed'],[data-hx-trigger*='revealed']"),function(e){bt(e)})}},200)}}function bt(e){if(!s(e,"data-hx-revealed")&&X(e)){e.setAttribute("data-hx-revealed","true");const t=ie(e);if(t.initHash){he(e,"revealed")}else{e.addEventListener("htmx:afterProcessNode",function(){he(e,"revealed")},{once:true})}}}function vt(e,t,n,r){const o=function(){if(!n.loaded){n.loaded=true;he(e,"htmx:trigger");t(e)}};if(r>0){E().setTimeout(o,r)}else{o()}}function wt(t,n,e){let i=false;se(r,function(r){if(s(t,"hx-"+r)){const o=te(t,"hx-"+r);i=true;n.path=o;n.verb=r;e.forEach(function(e){St(t,e,n,function(e,t){const n=ue(e);if(g(n,Q.config.disableSelector)){b(n);return}de(r,o,n,t)})})}});return i}function St(r,e,t,n){if(e.trigger==="revealed"){yt();pt(r,n,t,e);bt(ue(r))}else if(e.trigger==="intersect"){const o={};if(e.root){o.root=ae(r,e.root)}if(e.threshold){o.threshold=parseFloat(e.threshold)}const i=new IntersectionObserver(function(t){for(let e=0;e0){t.polling=true;ct(ue(r),n,e)}else{pt(r,n,t,e)}}function Et(e){const t=ue(e);if(!t){return false}const n=t.attributes;for(let e=0;e", "+e).join(""));return o}else{return[]}}function Tt(e){const t=g(ue(e.target),"button, input[type='submit']");const n=Lt(e);if(n){n.lastButtonClicked=t}}function qt(e){const t=Lt(e);if(t){t.lastButtonClicked=null}}function Lt(e){const t=g(ue(e.target),"button, input[type='submit']");if(!t){return}const n=y("#"+ee(t,"form"),t.getRootNode())||g(t,"form");if(!n){return}return ie(n)}function At(e){e.addEventListener("click",Tt);e.addEventListener("focusin",Tt);e.addEventListener("focusout",qt)}function Nt(t,e,n){const r=ie(t);if(!Array.isArray(r.onHandlers)){r.onHandlers=[]}let o;const i=function(e){vn(t,function(){if(at(t)){return}if(!o){o=new Function("event",n)}o.call(t,e)})};t.addEventListener(e,i);r.onHandlers.push({event:e,listener:i})}function It(t){ke(t);for(let e=0;eQ.config.historyCacheSize){i.shift()}while(i.length>0){try{localStorage.setItem("htmx-history-cache",JSON.stringify(i));break}catch(e){fe(ne().body,"htmx:historyCacheError",{cause:e,cache:i});i.shift()}}}function Vt(t){if(!B()){return null}t=U(t);const n=S(localStorage.getItem("htmx-history-cache"))||[];for(let e=0;e=200&&this.status<400){he(ne().body,"htmx:historyCacheMissLoad",i);const e=P(this.response);const t=e.querySelector("[hx-history-elt],[data-hx-history-elt]")||e;const n=Ut();const r=xn(n);kn(e.title);qe(e);Ve(n,t,r);Te();Kt(r.tasks);Bt=o;he(ne().body,"htmx:historyRestore",{path:o,cacheMiss:true,serverResponse:this.response})}else{fe(ne().body,"htmx:historyCacheMissLoadError",i)}};e.send()}function Wt(e){zt();e=e||location.pathname+location.search;const t=Vt(e);if(t){const n=P(t.content);const r=Ut();const o=xn(r);kn(t.title);qe(n);Ve(r,n,o);Te();Kt(o.tasks);E().setTimeout(function(){window.scrollTo(0,t.scroll)},0);Bt=e;he(ne().body,"htmx:historyRestore",{path:e,item:t})}else{if(Q.config.refreshOnHistoryMiss){window.location.reload(true)}else{Gt(e)}}}function Zt(e){let t=we(e,"hx-indicator");if(t==null){t=[e]}se(t,function(e){const t=ie(e);t.requestCount=(t.requestCount||0)+1;e.classList.add.call(e.classList,Q.config.requestClass)});return t}function Yt(e){let t=we(e,"hx-disabled-elt");if(t==null){t=[]}se(t,function(e){const t=ie(e);t.requestCount=(t.requestCount||0)+1;e.setAttribute("disabled","");e.setAttribute("data-disabled-by-htmx","")});return t}function Qt(e,t){se(e.concat(t),function(e){const t=ie(e);t.requestCount=(t.requestCount||1)-1});se(e,function(e){const t=ie(e);if(t.requestCount===0){e.classList.remove.call(e.classList,Q.config.requestClass)}});se(t,function(e){const t=ie(e);if(t.requestCount===0){e.removeAttribute("disabled");e.removeAttribute("data-disabled-by-htmx")}})}function en(t,n){for(let e=0;en.indexOf(e)<0)}else{e=e.filter(e=>e!==n)}r.delete(t);se(e,e=>r.append(t,e))}}function on(t,n,r,o,i){if(o==null||en(t,o)){return}else{t.push(o)}if(tn(o)){const s=ee(o,"name");let e=o.value;if(o instanceof HTMLSelectElement&&o.multiple){e=M(o.querySelectorAll("option:checked")).map(function(e){return e.value})}if(o instanceof HTMLInputElement&&o.files){e=M(o.files)}nn(s,e,n);if(i){sn(o,r)}}if(o instanceof HTMLFormElement){se(o.elements,function(e){if(t.indexOf(e)>=0){rn(e.name,e.value,n)}else{t.push(e)}if(i){sn(e,r)}});new FormData(o).forEach(function(e,t){if(e instanceof File&&e.name===""){return}nn(t,e,n)})}}function sn(e,t){const n=e;if(n.willValidate){he(n,"htmx:validation:validate");if(!n.checkValidity()){t.push({elt:n,message:n.validationMessage,validity:n.validity});he(n,"htmx:validation:failed",{message:n.validationMessage,validity:n.validity})}}}function ln(n,e){for(const t of e.keys()){n.delete(t)}e.forEach(function(e,t){n.append(t,e)});return n}function cn(e,t){const n=[];const r=new FormData;const o=new FormData;const i=[];const s=ie(e);if(s.lastButtonClicked&&!le(s.lastButtonClicked)){s.lastButtonClicked=null}let l=e instanceof HTMLFormElement&&e.noValidate!==true||te(e,"hx-validate")==="true";if(s.lastButtonClicked){l=l&&s.lastButtonClicked.formNoValidate!==true}if(t!=="get"){on(n,o,i,g(e,"form"),l)}on(n,r,i,e,l);if(s.lastButtonClicked||e.tagName==="BUTTON"||e.tagName==="INPUT"&&ee(e,"type")==="submit"){const u=s.lastButtonClicked||e;const a=ee(u,"name");nn(a,u.value,o)}const c=we(e,"hx-include");se(c,function(e){on(n,r,i,ue(e),l);if(!h(e,"form")){se(f(e).querySelectorAll(ot),function(e){on(n,r,i,e,l)})}});ln(r,o);return{errors:i,formData:r,values:An(r)}}function un(e,t,n){if(e!==""){e+="&"}if(String(n)==="[object Object]"){n=JSON.stringify(n)}const r=encodeURIComponent(n);e+=encodeURIComponent(t)+"="+r;return e}function an(e){e=qn(e);let n="";e.forEach(function(e,t){n=un(n,t,e)});return n}function fn(e,t,n){const r={"HX-Request":"true","HX-Trigger":ee(e,"id"),"HX-Trigger-Name":ee(e,"name"),"HX-Target":te(t,"id"),"HX-Current-URL":ne().location.href};bn(e,"hx-headers",false,r);if(n!==undefined){r["HX-Prompt"]=n}if(ie(e).boosted){r["HX-Boosted"]="true"}return r}function hn(n,e){const t=re(e,"hx-params");if(t){if(t==="none"){return new FormData}else if(t==="*"){return n}else if(t.indexOf("not ")===0){se(t.slice(4).split(","),function(e){e=e.trim();n.delete(e)});return n}else{const r=new FormData;se(t.split(","),function(t){t=t.trim();if(n.has(t)){n.getAll(t).forEach(function(e){r.append(t,e)})}});return r}}else{return n}}function dn(e){return!!ee(e,"href")&&ee(e,"href").indexOf("#")>=0}function gn(e,t){const n=t||re(e,"hx-swap");const r={swapStyle:ie(e).boosted?"innerHTML":Q.config.defaultSwapStyle,swapDelay:Q.config.defaultSwapDelay,settleDelay:Q.config.defaultSettleDelay};if(Q.config.scrollIntoViewOnBoost&&ie(e).boosted&&!dn(e)){r.show="top"}if(n){const s=F(n);if(s.length>0){for(let e=0;e0?o.join(":"):null;r.scroll=u;r.scrollTarget=i}else if(l.indexOf("show:")===0){const a=l.slice(5);var o=a.split(":");const f=o.pop();var i=o.length>0?o.join(":"):null;r.show=f;r.showTarget=i}else if(l.indexOf("focus-scroll:")===0){const h=l.slice("focus-scroll:".length);r.focusScroll=h=="true"}else if(e==0){r.swapStyle=l}else{O("Unknown modifier in hx-swap: "+l)}}}}return r}function pn(e){return re(e,"hx-encoding")==="multipart/form-data"||h(e,"form")&&ee(e,"enctype")==="multipart/form-data"}function mn(t,n,r){let o=null;Ft(n,function(e){if(o==null){o=e.encodeParameters(t,r,n)}});if(o!=null){return o}else{if(pn(n)){return ln(new FormData,qn(r))}else{return an(r)}}}function xn(e){return{tasks:[],elts:[e]}}function yn(e,t){const n=e[0];const r=e[e.length-1];if(t.scroll){var o=null;if(t.scrollTarget){o=ue(ae(n,t.scrollTarget))}if(t.scroll==="top"&&(n||o)){o=o||n;o.scrollTop=0}if(t.scroll==="bottom"&&(r||o)){o=o||r;o.scrollTop=o.scrollHeight}}if(t.show){var o=null;if(t.showTarget){let e=t.showTarget;if(t.showTarget==="window"){e="body"}o=ue(ae(n,e))}if(t.show==="top"&&(n||o)){o=o||n;o.scrollIntoView({block:"start",behavior:Q.config.scrollBehavior})}if(t.show==="bottom"&&(r||o)){o=o||r;o.scrollIntoView({block:"end",behavior:Q.config.scrollBehavior})}}}function bn(r,e,o,i){if(i==null){i={}}if(r==null){return i}const s=te(r,e);if(s){let e=s.trim();let t=o;if(e==="unset"){return null}if(e.indexOf("javascript:")===0){e=e.slice(11);t=true}else if(e.indexOf("js:")===0){e=e.slice(3);t=true}if(e.indexOf("{")!==0){e="{"+e+"}"}let n;if(t){n=vn(r,function(){return Function("return ("+e+")")()},{})}else{n=S(e)}for(const l in n){if(n.hasOwnProperty(l)){if(i[l]==null){i[l]=n[l]}}}}return bn(ue(c(r)),e,o,i)}function vn(e,t,n){if(Q.config.allowEval){return t()}else{fe(e,"htmx:evalDisallowedError");return n}}function wn(e,t){return bn(e,"hx-vars",true,t)}function Sn(e,t){return bn(e,"hx-vals",false,t)}function En(e){return ce(wn(e),Sn(e))}function Cn(t,n,r){if(r!==null){try{t.setRequestHeader(n,r)}catch(e){t.setRequestHeader(n,encodeURIComponent(r));t.setRequestHeader(n+"-URI-AutoEncoded","true")}}}function On(t){if(t.responseURL&&typeof URL!=="undefined"){try{const e=new URL(t.responseURL);return e.pathname+e.search}catch(e){fe(ne().body,"htmx:badResponseUrl",{url:t.responseURL})}}}function R(e,t){return t.test(e.getAllResponseHeaders())}function Rn(t,n,r){t=t.toLowerCase();if(r){if(r instanceof Element||typeof r==="string"){return de(t,n,null,null,{targetOverride:y(r)||ve,returnPromise:true})}else{let e=y(r.target);if(r.target&&!e||r.source&&!e&&!y(r.source)){e=ve}return de(t,n,y(r.source),r.event,{handler:r.handler,headers:r.headers,values:r.values,targetOverride:e,swapOverride:r.swap,select:r.select,returnPromise:true})}}else{return de(t,n,null,null,{returnPromise:true})}}function Hn(e){const t=[];while(e){t.push(e);e=e.parentElement}return t}function Tn(e,t,n){let r;let o;if(typeof URL==="function"){o=new URL(t,document.location.href);const i=document.location.origin;r=i===o.origin}else{o=t;r=l(t,document.location.origin)}if(Q.config.selfRequestsOnly){if(!r){return false}}return he(e,"htmx:validateUrl",ce({url:o,sameHost:r},n))}function qn(e){if(e instanceof FormData)return e;const t=new FormData;for(const n in e){if(e.hasOwnProperty(n)){if(e[n]&&typeof e[n].forEach==="function"){e[n].forEach(function(e){t.append(n,e)})}else if(typeof e[n]==="object"&&!(e[n]instanceof Blob)){t.append(n,JSON.stringify(e[n]))}else{t.append(n,e[n])}}}return t}function Ln(r,o,e){return new Proxy(e,{get:function(t,e){if(typeof e==="number")return t[e];if(e==="length")return t.length;if(e==="push"){return function(e){t.push(e);r.append(o,e)}}if(typeof t[e]==="function"){return function(){t[e].apply(t,arguments);r.delete(o);t.forEach(function(e){r.append(o,e)})}}if(t[e]&&t[e].length===1){return t[e][0]}else{return t[e]}},set:function(e,t,n){e[t]=n;r.delete(o);e.forEach(function(e){r.append(o,e)});return true}})}function An(o){return new Proxy(o,{get:function(e,t){if(typeof t==="symbol"){const r=Reflect.get(e,t);if(typeof r==="function"){return function(){return r.apply(o,arguments)}}else{return r}}if(t==="toJSON"){return()=>Object.fromEntries(o)}if(t in e){if(typeof e[t]==="function"){return function(){return o[t].apply(o,arguments)}}else{return e[t]}}const n=o.getAll(t);if(n.length===0){return undefined}else if(n.length===1){return n[0]}else{return Ln(e,t,n)}},set:function(t,n,e){if(typeof n!=="string"){return false}t.delete(n);if(e&&typeof e.forEach==="function"){e.forEach(function(e){t.append(n,e)})}else if(typeof e==="object"&&!(e instanceof Blob)){t.append(n,JSON.stringify(e))}else{t.append(n,e)}return true},deleteProperty:function(e,t){if(typeof t==="string"){e.delete(t)}return true},ownKeys:function(e){return Reflect.ownKeys(Object.fromEntries(e))},getOwnPropertyDescriptor:function(e,t){return Reflect.getOwnPropertyDescriptor(Object.fromEntries(e),t)}})}function de(t,n,r,o,i,D){let s=null;let l=null;i=i!=null?i:{};if(i.returnPromise&&typeof Promise!=="undefined"){var e=new Promise(function(e,t){s=e;l=t})}if(r==null){r=ne().body}const M=i.handler||Dn;const X=i.select||null;if(!le(r)){oe(s);return e}const c=i.targetOverride||ue(Ee(r));if(c==null||c==ve){fe(r,"htmx:targetError",{target:te(r,"hx-target")});oe(l);return e}let u=ie(r);const a=u.lastButtonClicked;if(a){const L=ee(a,"formaction");if(L!=null){n=L}const A=ee(a,"formmethod");if(A!=null){if(A.toLowerCase()!=="dialog"){t=A}}}const f=re(r,"hx-confirm");if(D===undefined){const K=function(e){return de(t,n,r,o,i,!!e)};const G={target:c,elt:r,path:n,verb:t,triggeringEvent:o,etc:i,issueRequest:K,question:f};if(he(r,"htmx:confirm",G)===false){oe(s);return e}}let h=r;let d=re(r,"hx-sync");let g=null;let F=false;if(d){const N=d.split(":");const I=N[0].trim();if(I==="this"){h=Se(r,"hx-sync")}else{h=ue(ae(r,I))}d=(N[1]||"drop").trim();u=ie(h);if(d==="drop"&&u.xhr&&u.abortable!==true){oe(s);return e}else if(d==="abort"){if(u.xhr){oe(s);return e}else{F=true}}else if(d==="replace"){he(h,"htmx:abort")}else if(d.indexOf("queue")===0){const W=d.split(" ");g=(W[1]||"last").trim()}}if(u.xhr){if(u.abortable){he(h,"htmx:abort")}else{if(g==null){if(o){const P=ie(o);if(P&&P.triggerSpec&&P.triggerSpec.queue){g=P.triggerSpec.queue}}if(g==null){g="last"}}if(u.queuedRequests==null){u.queuedRequests=[]}if(g==="first"&&u.queuedRequests.length===0){u.queuedRequests.push(function(){de(t,n,r,o,i)})}else if(g==="all"){u.queuedRequests.push(function(){de(t,n,r,o,i)})}else if(g==="last"){u.queuedRequests=[];u.queuedRequests.push(function(){de(t,n,r,o,i)})}oe(s);return e}}const p=new XMLHttpRequest;u.xhr=p;u.abortable=F;const m=function(){u.xhr=null;u.abortable=false;if(u.queuedRequests!=null&&u.queuedRequests.length>0){const e=u.queuedRequests.shift();e()}};const B=re(r,"hx-prompt");if(B){var x=prompt(B);if(x===null||!he(r,"htmx:prompt",{prompt:x,target:c})){oe(s);m();return e}}if(f&&!D){if(!confirm(f)){oe(s);m();return e}}let y=fn(r,c,x);if(t!=="get"&&!pn(r)){y["Content-Type"]="application/x-www-form-urlencoded"}if(i.headers){y=ce(y,i.headers)}const U=cn(r,t);let b=U.errors;const j=U.formData;if(i.values){ln(j,qn(i.values))}const V=qn(En(r));const v=ln(j,V);let w=hn(v,r);if(Q.config.getCacheBusterParam&&t==="get"){w.set("org.htmx.cache-buster",ee(c,"id")||"true")}if(n==null||n===""){n=ne().location.href}const S=bn(r,"hx-request");const _=ie(r).boosted;let E=Q.config.methodsThatUseUrlParams.indexOf(t)>=0;const C={boosted:_,useUrlParams:E,formData:w,parameters:An(w),unfilteredFormData:v,unfilteredParameters:An(v),headers:y,target:c,verb:t,errors:b,withCredentials:i.credentials||S.credentials||Q.config.withCredentials,timeout:i.timeout||S.timeout||Q.config.timeout,path:n,triggeringEvent:o};if(!he(r,"htmx:configRequest",C)){oe(s);m();return e}n=C.path;t=C.verb;y=C.headers;w=qn(C.parameters);b=C.errors;E=C.useUrlParams;if(b&&b.length>0){he(r,"htmx:validation:halted",C);oe(s);m();return e}const z=n.split("#");const $=z[0];const O=z[1];let R=n;if(E){R=$;const Z=!w.keys().next().done;if(Z){if(R.indexOf("?")<0){R+="?"}else{R+="&"}R+=an(w);if(O){R+="#"+O}}}if(!Tn(r,R,C)){fe(r,"htmx:invalidPath",C);oe(l);return e}p.open(t.toUpperCase(),R,true);p.overrideMimeType("text/html");p.withCredentials=C.withCredentials;p.timeout=C.timeout;if(S.noHeaders){}else{for(const k in y){if(y.hasOwnProperty(k)){const Y=y[k];Cn(p,k,Y)}}}const H={xhr:p,target:c,requestConfig:C,etc:i,boosted:_,select:X,pathInfo:{requestPath:n,finalRequestPath:R,responsePath:null,anchor:O}};p.onload=function(){try{const t=Hn(r);H.pathInfo.responsePath=On(p);M(r,H);if(H.keepIndicators!==true){Qt(T,q)}he(r,"htmx:afterRequest",H);he(r,"htmx:afterOnLoad",H);if(!le(r)){let e=null;while(t.length>0&&e==null){const n=t.shift();if(le(n)){e=n}}if(e){he(e,"htmx:afterRequest",H);he(e,"htmx:afterOnLoad",H)}}oe(s);m()}catch(e){fe(r,"htmx:onLoadError",ce({error:e},H));throw e}};p.onerror=function(){Qt(T,q);fe(r,"htmx:afterRequest",H);fe(r,"htmx:sendError",H);oe(l);m()};p.onabort=function(){Qt(T,q);fe(r,"htmx:afterRequest",H);fe(r,"htmx:sendAbort",H);oe(l);m()};p.ontimeout=function(){Qt(T,q);fe(r,"htmx:afterRequest",H);fe(r,"htmx:timeout",H);oe(l);m()};if(!he(r,"htmx:beforeRequest",H)){oe(s);m();return e}var T=Zt(r);var q=Yt(r);se(["loadstart","loadend","progress","abort"],function(t){se([p,p.upload],function(e){e.addEventListener(t,function(e){he(r,"htmx:xhr:"+t,{lengthComputable:e.lengthComputable,loaded:e.loaded,total:e.total})})})});he(r,"htmx:beforeSend",H);const J=E?null:mn(p,r,w);p.send(J);return e}function Nn(e,t){const n=t.xhr;let r=null;let o=null;if(R(n,/HX-Push:/i)){r=n.getResponseHeader("HX-Push");o="push"}else if(R(n,/HX-Push-Url:/i)){r=n.getResponseHeader("HX-Push-Url");o="push"}else if(R(n,/HX-Replace-Url:/i)){r=n.getResponseHeader("HX-Replace-Url");o="replace"}if(r){if(r==="false"){return{}}else{return{type:o,path:r}}}const i=t.pathInfo.finalRequestPath;const s=t.pathInfo.responsePath;const l=re(e,"hx-push-url");const c=re(e,"hx-replace-url");const u=ie(e).boosted;let a=null;let f=null;if(l){a="push";f=l}else if(c){a="replace";f=c}else if(u){a="push";f=s||i}if(f){if(f==="false"){return{}}if(f==="true"){f=s||i}if(t.pathInfo.anchor&&f.indexOf("#")===-1){f=f+"#"+t.pathInfo.anchor}return{type:a,path:f}}else{return{}}}function In(e,t){var n=new RegExp(e.code);return n.test(t.toString(10))}function Pn(e){for(var t=0;t0){E().setTimeout(e,x.swapDelay)}else{e()}}if(f){fe(o,"htmx:responseError",ce({error:"Response Status Error Code "+s.status+" from "+i.pathInfo.requestPath},i))}}const Mn={};function Xn(){return{init:function(e){return null},getSelectors:function(){return null},onEvent:function(e,t){return true},transformResponse:function(e,t,n){return e},isInlineSwap:function(e){return false},handleSwap:function(e,t,n,r){return false},encodeParameters:function(e,t,n){return null}}}function Fn(e,t){if(t.init){t.init(n)}Mn[e]=ce(Xn(),t)}function Bn(e){delete Mn[e]}function Un(e,n,r){if(n==undefined){n=[]}if(e==undefined){return n}if(r==undefined){r=[]}const t=te(e,"hx-ext");if(t){se(t.split(","),function(e){e=e.replace(/ /g,"");if(e.slice(0,7)=="ignore:"){r.push(e.slice(7));return}if(r.indexOf(e)<0){const t=Mn[e];if(t&&n.indexOf(t)<0){n.push(t)}}})}return Un(ue(c(e)),n,r)}var jn=false;ne().addEventListener("DOMContentLoaded",function(){jn=true});function Vn(e){if(jn||ne().readyState==="complete"){e()}else{ne().addEventListener("DOMContentLoaded",e)}}function _n(){if(Q.config.includeIndicatorStyles!==false){const e=Q.config.inlineStyleNonce?` nonce="${Q.config.inlineStyleNonce}"`:"";ne().head.insertAdjacentHTML("beforeend","")}}function zn(){const e=ne().querySelector('meta[name="htmx-config"]');if(e){return S(e.content)}else{return null}}function $n(){const e=zn();if(e){Q.config=ce(Q.config,e)}}Vn(function(){$n();_n();let e=ne().body;kt(e);const t=ne().querySelectorAll("[hx-trigger='restored'],[data-hx-trigger='restored']");e.addEventListener("htmx:abort",function(e){const t=e.target;const n=ie(t);if(n&&n.xhr){n.xhr.abort()}});const n=window.onpopstate?window.onpopstate.bind(window):null;window.onpopstate=function(e){if(e.state&&e.state.htmx){Wt();se(t,function(e){he(e,"htmx:restored",{document:ne(),triggerEvent:he})})}else{if(n){n(e)}}};E().setTimeout(function(){he(e,"htmx:load",{});e=null},0)});return Q}();
\ No newline at end of file
diff --git a/internal/web/templates.go b/internal/web/templates.go
new file mode 100644
index 0000000..a420bf0
--- /dev/null
+++ b/internal/web/templates.go
@@ -0,0 +1,54 @@
+package web
+
+import (
+ "bytes"
+ "fmt"
+ "html/template"
+ "net/http"
+)
+
+// templates holds the parsed page templates. Each page is parsed together with
+// the shared base layout so {{ template "base" . }} works. Rendering goes
+// through html/template, which auto-escapes all interpolated data (spec 7.6.7).
+type templates struct {
+ pages map[string]*template.Template
+}
+
+// pageFiles maps a logical page name to its template file. Every page composes
+// with layout.html.
+var pageFiles = map[string]string{
+ "setup": "templates/setup.html",
+ "login": "templates/login.html",
+ "dashboard": "templates/dashboard.html",
+}
+
+func loadTemplates() (*templates, error) {
+ t := &templates{pages: make(map[string]*template.Template)}
+ for name, file := range pageFiles {
+ tmpl, err := template.New("layout.html").ParseFS(assetsFS, "templates/layout.html", file)
+ if err != nil {
+ return nil, fmt.Errorf("parse template %s: %w", name, err)
+ }
+ t.pages[name] = tmpl
+ }
+ return t, nil
+}
+
+// render writes a page using the base layout. Rendering to a buffer first means
+// a template error yields a clean 500 instead of a half-written page.
+func (s *Server) render(w http.ResponseWriter, status int, page string, data any) {
+ tmpl, ok := s.tmpl.pages[page]
+ if !ok {
+ http.Error(w, "template not found", http.StatusInternalServerError)
+ return
+ }
+ var buf bytes.Buffer
+ if err := tmpl.ExecuteTemplate(&buf, "layout.html", data); err != nil {
+ logf("panel: render %s: %v", page, err)
+ http.Error(w, "internal error", http.StatusInternalServerError)
+ return
+ }
+ w.Header().Set("Content-Type", "text/html; charset=utf-8")
+ w.WriteHeader(status)
+ _, _ = buf.WriteTo(w)
+}
diff --git a/internal/web/templates/dashboard.html b/internal/web/templates/dashboard.html
new file mode 100644
index 0000000..21db85a
--- /dev/null
+++ b/internal/web/templates/dashboard.html
@@ -0,0 +1,15 @@
+{{define "content"}}
+
+
SelfPost
+
+ {{.User}} ·
+
+
+
+
+
You are signed in. Domains, applications and the send log arrive in the
+ next phases.
+
+{{end}}
diff --git a/internal/web/templates/layout.html b/internal/web/templates/layout.html
new file mode 100644
index 0000000..42d4818
--- /dev/null
+++ b/internal/web/templates/layout.html
@@ -0,0 +1,50 @@
+{{define "layout.html"}}
+
+
+
+
+{{.Title}}
+
+
+
+
+
+{{template "content" .}}
+
+
+{{end}}
diff --git a/internal/web/templates/login.html b/internal/web/templates/login.html
new file mode 100644
index 0000000..fd7c416
--- /dev/null
+++ b/internal/web/templates/login.html
@@ -0,0 +1,20 @@
+{{define "content"}}
+Sign in
+
+ {{if .SetupHint}}
+
No administrator has been created yet. Open the one-time
+ setup link printed in the container log to get started.
+ {{else}}
+ {{if .Error}}
{{.Error}}
{{end}}
+
+ {{end}}
+
+{{end}}
diff --git a/internal/web/templates/setup.html b/internal/web/templates/setup.html
new file mode 100644
index 0000000..cfaf015
--- /dev/null
+++ b/internal/web/templates/setup.html
@@ -0,0 +1,20 @@
+{{define "content"}}
+Create administrator
+
+
This one-time link creates the single panel administrator.
+ After you submit, the link stops working for good.
+ {{if .Error}}
{{.Error}}
{{end}}
+
+
+{{end}}
diff --git a/internal/web/token.go b/internal/web/token.go
new file mode 100644
index 0000000..6e9ba7e
--- /dev/null
+++ b/internal/web/token.go
@@ -0,0 +1,20 @@
+package web
+
+import (
+ "crypto/rand"
+ "encoding/base64"
+)
+
+// randomToken returns a URL-safe token with at least nBytes*8 bits of entropy
+// drawn from crypto/rand. Setup and session tokens both use this; the setup
+// token needs >=128 bits (spec 7.6.1), so callers pass nBytes >= 16.
+//
+// It panics if the system RNG fails: that is unrecoverable and must never be
+// papered over with a weak fallback for a security token.
+func randomToken(nBytes int) string {
+ b := make([]byte, nBytes)
+ if _, err := rand.Read(b); err != nil {
+ panic("crypto/rand failed: " + err.Error())
+ }
+ return base64.RawURLEncoding.EncodeToString(b)
+}
diff --git a/internal/web/validate.go b/internal/web/validate.go
new file mode 100644
index 0000000..afd4784
--- /dev/null
+++ b/internal/web/validate.go
@@ -0,0 +1,42 @@
+package web
+
+import (
+ "fmt"
+ "unicode"
+)
+
+// minAdminPasswordLen is the floor for the administrator password. The panel is
+// public (spec 7.6), so this is deliberately not tiny.
+const minAdminPasswordLen = 12
+
+const (
+ minUsernameLen = 3
+ maxUsernameLen = 64
+)
+
+// validateUsername enforces a strict server-side whitelist (spec 7.6.2):
+// letters, digits, dot, dash, underscore. Client validation is never trusted.
+func validateUsername(u string) error {
+ if len(u) < minUsernameLen || len(u) > maxUsernameLen {
+ return fmt.Errorf("username must be %d-%d characters", minUsernameLen, maxUsernameLen)
+ }
+ for _, r := range u {
+ if r > unicode.MaxASCII || (!isASCIILetterOrDigit(r) && r != '.' && r != '-' && r != '_') {
+ return fmt.Errorf("username may contain only letters, digits, '.', '-' and '_'")
+ }
+ }
+ return nil
+}
+
+// validateAdminPassword enforces a minimum length. Composition rules beyond
+// length tend to reduce entropy in practice, so length is the sole gate.
+func validateAdminPassword(p string) error {
+ if len(p) < minAdminPasswordLen {
+ return fmt.Errorf("password must be at least %d characters", minAdminPasswordLen)
+ }
+ return nil
+}
+
+func isASCIILetterOrDigit(r rune) bool {
+ return (r >= 'a' && r <= 'z') || (r >= 'A' && r <= 'Z') || (r >= '0' && r <= '9')
+}
diff --git a/internal/web/web.go b/internal/web/web.go
new file mode 100644
index 0000000..e1b279d
--- /dev/null
+++ b/internal/web/web.go
@@ -0,0 +1,115 @@
+// Package web implements the SelfPost control panel's HTTP surface: the
+// one-time administrator setup flow (spec 7.6.1), login/session handling
+// (spec 7.6.5-6) and the authenticated shell the later phases build on.
+package web
+
+import (
+ "embed"
+ "log"
+ "net"
+ "net/http"
+ "time"
+
+ "codeberg.org/mix/selfpost/internal/store"
+)
+
+//go:embed templates/*.html static/*
+var assetsFS embed.FS
+
+// Config holds the panel's HTTP-facing configuration.
+type Config struct {
+ // Hostname is the server's external hostname, used to build the absolute
+ // setup link shown in the logs (spec 7.6.1, 8: SELFPOST_HOSTNAME).
+ Hostname string
+ // CookieSecure sets the Secure attribute on the session cookie. It defaults
+ // to true (spec 7.6.6); it exists as a knob only so the panel can be tested
+ // over plain HTTP in development, never for production.
+ CookieSecure bool
+}
+
+// Server is the panel HTTP application.
+type Server struct {
+ store *store.Store
+ cfg Config
+ tmpl *templates
+ sessions *sessionStore
+ setup *setupManager
+
+ loginLimiter *rateLimiter
+ setupLimiter *rateLimiter
+}
+
+// New builds the panel server. setupTokenPath is where the current setup token
+// is mirrored on disk (spec 7.6.1).
+func New(st *store.Store, cfg Config, setupTokenPath string) (*Server, error) {
+ tmpl, err := loadTemplates()
+ if err != nil {
+ return nil, err
+ }
+ s := &Server{
+ store: st,
+ cfg: cfg,
+ tmpl: tmpl,
+ sessions: newSessionStore(),
+ // Setup: a handful of attempts per minute per IP is plenty for a
+ // legitimate admin and blunts automated probing (spec 7.6.1).
+ setupLimiter: newRateLimiter(10, time.Minute),
+ // Login: throttle brute-force by IP (spec 7.6.5).
+ loginLimiter: newRateLimiter(10, 15*time.Minute),
+ }
+ s.setup = newSetupManager(st, cfg.Hostname, setupTokenPath)
+ return s, nil
+}
+
+// Start performs first-run bootstrapping: if there is no administrator yet, it
+// generates and announces the setup link (spec 7.6.1). Safe to call once at
+// server startup.
+func (s *Server) Start() error {
+ return s.setup.bootstrap()
+}
+
+// Handler returns the panel's HTTP handler (router).
+func (s *Server) Handler() http.Handler {
+ mux := http.NewServeMux()
+
+ // Health check stays unauthenticated for the container/orchestrator.
+ mux.HandleFunc("/healthz", handleHealth)
+
+ // Vendored static assets (HTMX). Served from the embedded FS.
+ mux.Handle("/static/", http.FileServer(http.FS(assetsFS)))
+
+ // One-time administrator setup (spec 7.6.1).
+ mux.HandleFunc("/setup/", s.handleSetup)
+
+ // Authentication.
+ mux.HandleFunc("/login", s.handleLogin)
+ mux.HandleFunc("/logout", s.handleLogout)
+
+ // Authenticated panel.
+ mux.Handle("/", s.requireAuth(http.HandlerFunc(s.handleDashboard)))
+
+ return mux
+}
+
+func handleHealth(w http.ResponseWriter, _ *http.Request) {
+ w.Header().Set("Content-Type", "text/plain; charset=utf-8")
+ w.WriteHeader(http.StatusOK)
+ _, _ = w.Write([]byte("ok\n"))
+}
+
+// clientIP extracts the peer IP for rate-limiting. It uses the transport peer
+// (RemoteAddr), not client-supplied headers, so it cannot be spoofed; behind a
+// reverse proxy this is the proxy address, which is an acceptable backstop for
+// a single-admin panel.
+func clientIP(r *http.Request) string {
+ host, _, err := net.SplitHostPort(r.RemoteAddr)
+ if err != nil {
+ return r.RemoteAddr
+ }
+ return host
+}
+
+// logf is a thin wrapper so handlers log with a consistent prefix.
+func logf(format string, args ...any) {
+ log.Printf(format, args...)
+}