- ops/install.sh now installs to /opt/theta42/proxy (was /var/www/proxy)
and seeds /etc/proxy/secrets.js from secrets.js.example on first run
(never overwritten on later runs), instead of requiring a manual
nodejs/conf/secrets.js edit inside the repo checkout.
- ops/proxy.service points at the new install path and sets
CONF_SECRETS=/etc/proxy/secrets.js (requires @simpleworkjs/conf >=
1.2.0, already the pinned version) so the app picks up the secrets
file with no symlink into the repo checkout.
- install.sh now prints the version it's updating from/to (or "Already
up to date") on every run, instead of a silent update.
- Updated README/DEPLOYMENT/installation docs to match the new paths.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- New docs/concepts-{hosts,dns,access,api-tokens}.md -- plain-language
guides aimed at less technical readers, each linking onward to the
existing system-design-level doc for anyone who wants that detail.
Card help links (Proxy List, Add/Edit host, DNS Provider cards,
Users/Permissions/Groups cards) now point here instead of straight at
Installation/Architecture.
- The "New API Token" card had no help link at all -- added, pointing to
the new API Tokens doc.
- Fixed the in-app docs viewer rendering every docs/*.md page with a
garbled heading + stray <hr> at the top: Jekyll front matter (meant
only for the GitHub Pages build) was never stripped before being
handed to the markdown renderer.
- Fixed cross-doc links never resolving in-app, since this viewer serves
docs at /docs/<slug> with no .html suffix: rewritten to the correct
in-app URL, first by registered slug, falling back to the doc's real
filename (the correct, working link form on the Jekyll/GitHub Pages
build) -- same idea as the existing image-path fix, and lets one link
written in a doc work on both targets.
Bumps to v1.1.13.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KDEx8ghuZR61pqPXc6da9C
Same treatment as the sso-manager-node companion PR: replaced the
generic jekyll-theme-cayman theme with a custom layout mirroring the
actual app UI -- dark fixed navbar with the theta42 logo, Bootstrap 5
+ Font Awesome (same stack the app uses), content in a card, dark
footer matching bottom.ejs. Keeps this repo's own favicon.svg
(confirmed genuinely distinct SVG artwork from the shared theta42
logo, not a duplicate) as the browser-tab icon.
- New cross-page nav (Home/Installation/Architecture/API/Docker/
Contributing/Changelog).
- SEO: jekyll-seo-tag + jekyll-sitemap, per-page meta description,
OG/Twitter card tags, canonical URLs, JSON-LD, sitemap.xml,
robots.txt.
- Mobile: Bootstrap's responsive grid + collapsible navbar; the
screenshot pairs in index.md stack to full-width below 576px.
Verified with a real Jekyll build (jekyll/jekyll Docker image) +
Playwright: desktop and mobile (375px) screenshots, mobile nav
toggle, active-link highlighting, zero console/page errors, and
confirmed real SEO output + the correct (non-shared) favicon via curl
against the served site.
Prepares the docs for the public release announcement: removes obsolete/dead
material, fixes drift between the API reference and the actual routes, and
standardizes on the default GitHub Pages URL.
- Remove Vagrant entirely: delete Vagrantfile, docs/dev_setup.md, and stale
vagrant references in .gitignore/.dockerignore; rewrite openresty/README.md
to describe the actual (currently unused) directory and point to
ops/nginx_conf/ for the real OpenResty config.
- Delete docs/Update 4.11.md (personal scratch changelog) and drop both its
and dev_setup.md's references from docs/README.md's Legacy Documentation
section.
- Remove checkmark emoji from docs/contributing.md's PR Requirements list.
- Bring the auth model docs up to date with the code: document
GET /api/auth/oidc/start + /callback, the /api/permission and /api/group
RBAC routers, the /api/dns/dynamic/* sub-API, and /api/api-token (self
-service PATs) in both nodejs/api.md and docs/api.md; add the missing
"Clear Host Cache" section; drop the invite-token/SSH-key endpoints that no
longer exist in nodejs/routes/user.js; note admin-only routes. Mention
OIDC/LDAP/RBAC as core features in README.md.
- Keep nodejs/api.md and docs/api.md fully in sync (same body, differing only
in Jekyll front matter / relative links) instead of letting them drift.
- Fix Node.js version references (20.x -> 22.x) in README.md and
docs/installation.md to match ops/install.sh and the Dockerfile.
- Note that the manual nginx-conf/systemd install steps in README.md and
docs/installation.md won't auto-track repo changes the way install.sh's
symlink approach does, and recommend install.sh.
- Update the stale test/unit file lists in docs/contributing.md and
nodejs/test/README.md to match the actual directory contents.
- Add npm run test:integration to README.md's Running Tests section.
- Add nodejs/conf/, nodejs/controller/, and nodejs/migrations/ to the project
structure diagrams in README.md, docs/architecture.md, and
docs/contributing.md.
- Standardize "CloudFlare" -> "Cloudflare" everywhere to match the actual API
value in nodejs/models/dns_provider.js.
- Add the missing app_auth__adminGroups row to DEPLOYMENT.md's app_* table.
- Delete docs/CNAME (custom domain) so GitHub Pages serves from the default
https://theta42.github.io/proxy/, matching docs/README.md.
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
Follow-up to #121: the repo line still used the live codename + "main", but
the openresty.org Debian tree only publishes up to bookworm (no trixie) and
uses the "openresty" component, not "main". Verified against the repo:
/package/debian/dists/ -> bookworm bullseye buster jessie stretch (no trixie)
bookworm Release -> Components: openresty
/package/ubuntu/dists/ -> noble jammy focal ... ; Components: main
So:
- Debian: distro = host codename when published (jessie..bookworm), else
bookworm (binary-compatible with trixie, same OpenSSL 3 era); component
"openresty".
- Ubuntu/Mint: distro = host codename; component "main" (unchanged).
Produces the working line on a trixie host:
deb [...] http://openresty.org/package/debian bookworm openresty
docs/installation.md manual steps updated to match.
Co-authored-by: Claude <noreply@anthropic.com>
Two issues on Debian 13 (Trixie):
1. apt's sequoia GPG backend now rejects SHA-1 signatures, and the OpenResty
repo signing key is still SHA-1 — so `apt-get update` fails to verify the
repo. When /usr/share/apt/default-sequoia.config is present (Debian 13+),
install a back-end override that extends the SHA-1 acceptance window to
2028 (the OpenResty key is expected to rotate to a stronger algorithm;
revisit before then). No-op on older Debian/Ubuntu. Idempotent on re-run.
2. The repo path was hardcoded to /package/ubuntu with the host codename,
which worked on older Debian by coincidence. trixie lives under
/package/debian, so pick the tree by distro ID (debian -> /package/debian,
else -> /package/ubuntu).
docs/installation.md: mirror both changes in the manual install steps, with a
note that install.sh applies the sequoia override automatically.
Co-authored-by: Claude <noreply@anthropic.com>