Wiki Phase 1: categories, drafts/publish, HTML sanitization
Foundation & safety phase of the wiki upgrade (see WIKI_UPGRADE.md). Schema (additive, idempotent via ensureSchema): - new wiki_categories table; wiki_pages gains category_id, excerpt, published, published_at, sort_order, and a FULLTEXT index - migration ALTERs guarded with IF NOT EXISTS for existing databases - seed reworked into 4 sections with the 8 starter pages assigned Security: - new utils/sanitizeHtml.js (sanitize-html allowlist); wiki bodies are sanitized on every save, and the article renders through DOMPurify - strips <script>, event handlers (onerror), and javascript: URLs Backend: - public: published-only list with ?category filter + /wiki/categories - admin: extended page CRUD, PATCH publish toggle, category CRUD; drafts visible to admin, hidden from public - all writes logged to activity_log Frontend: - data-driven public wiki index (sections + real descriptions; removed hardcoded blurbs/Roman numerals) with ?category filtering - article: category breadcrumb + sanitized render - admin: Section/Status columns, draft/publish + section + excerpt in the editor, and a Manage sections modal Verified end-to-end against MariaDB 11: migration clean, XSS neutralized, drafts hidden, client builds, server boots. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -284,7 +284,7 @@ phase if preferred). Do not merge a phase that hasn't been verified.
|
|||||||
### Phase 0 — Branch & scaffolding ✅ (this doc)
|
### Phase 0 — Branch & scaffolding ✅ (this doc)
|
||||||
- `wiki-upgrade` branch created; this spec committed.
|
- `wiki-upgrade` branch created; this spec committed.
|
||||||
|
|
||||||
### Phase 1 — Foundation & safety (highest value)
|
### Phase 1 — Foundation & safety (highest value) ✅
|
||||||
- Schema: add `wiki_categories`, alter `wiki_pages` (category_id, excerpt, published,
|
- Schema: add `wiki_categories`, alter `wiki_pages` (category_id, excerpt, published,
|
||||||
published_at, sort_order, FULLTEXT), update `seed.js`.
|
published_at, sort_order, FULLTEXT), update `seed.js`.
|
||||||
- Server: server-side sanitization on save; drafts/publish endpoints; categories CRUD;
|
- Server: server-side sanitization on save; drafts/publish endpoints; categories CRUD;
|
||||||
@@ -293,6 +293,11 @@ phase if preferred). Do not merge a phase that hasn't been verified.
|
|||||||
`WikiArticle.jsx`; draft/publish + category in the (still-textarea) admin editor.
|
`WikiArticle.jsx`; draft/publish + category in the (still-textarea) admin editor.
|
||||||
- **Exit check**: existing pages still render; XSS payload in body is neutralized;
|
- **Exit check**: existing pages still render; XSS payload in body is neutralized;
|
||||||
draft pages hidden from the public list/article.
|
draft pages hidden from the public list/article.
|
||||||
|
- **Verified** (2026-06-27): schema migration ran clean on MariaDB 11; XSS payload
|
||||||
|
(`<script>`, `onerror=`, `javascript:`) stripped server-side; drafts return 404 on
|
||||||
|
the public API and are absent from the public list while visible in admin; public
|
||||||
|
index is data-driven (categories + sections); article shows category breadcrumb;
|
||||||
|
client builds and server boots with no errors.
|
||||||
|
|
||||||
### Phase 2 — Authoring UX
|
### Phase 2 — Authoring UX
|
||||||
- TipTap editor replaces the textarea; generalized `/admin/uploads`; inline images.
|
- TipTap editor replaces the textarea; generalized `/admin/uploads`; inline images.
|
||||||
|
|||||||
Reference in New Issue
Block a user