Compare commits

..
3 Commits
23 changed files with 265 additions and 110 deletions
+2 -2
View File
@@ -4,5 +4,5 @@ TRAEFIK_NETWORK=internal
TRAEFIK_CERT_RESOLVER=netcup TRAEFIK_CERT_RESOLVER=netcup
# Keep these two values paired when deploying a newer published toolbox release. # Keep these two values paired when deploying a newer published toolbox release.
TOOLBOX_RELEASE_VERSION=0.9.1 TOOLBOX_RELEASE_VERSION=0.10.0
TOOLBOX_RELEASE_SHA256=e9dc6a949f1348694099baf62a7b86aa6fea1805bca794de7dfab5dd2040e062 TOOLBOX_RELEASE_SHA256=de6f1afc3f0ec08ee1a8afd80d874832cbf905d0d50f62060e6985be9f5e0019
+1 -1
View File
@@ -1 +1 @@
@add-ideas:registry=https://git.add-ideas.de/api/packages/zemion/npm/ @add-ideas:registry=https://git.add-ideas.de/api/packages/lotobo/npm/
+4 -3
View File
@@ -2,9 +2,9 @@ ARG NGINX_IMAGE=nginxinc/nginx-unprivileged:1.31.3-alpine@sha256:18d67281256ded3
FROM ${NGINX_IMAGE} AS release FROM ${NGINX_IMAGE} AS release
ARG TOOLBOX_RELEASE_VERSION=0.9.1 ARG TOOLBOX_RELEASE_VERSION=0.10.0
ARG TOOLBOX_RELEASE_SHA256=e9dc6a949f1348694099baf62a7b86aa6fea1805bca794de7dfab5dd2040e062 ARG TOOLBOX_RELEASE_SHA256=de6f1afc3f0ec08ee1a8afd80d874832cbf905d0d50f62060e6985be9f5e0019
ARG TOOLBOX_RELEASE_BASE_URL=https://git.add-ideas.de/zemion/toolbox-portal/releases/download ARG TOOLBOX_RELEASE_BASE_URL=https://git.add-ideas.de/lotobo/toolbox-portal/releases/download
RUN set -eu; \ RUN set -eu; \
archive="add-ideas-toolbox-${TOOLBOX_RELEASE_VERSION}.zip"; \ archive="add-ideas-toolbox-${TOOLBOX_RELEASE_VERSION}.zip"; \
@@ -23,6 +23,7 @@ RUN set -eu; \
test -f /tmp/toolbox/apps/onenote/toolbox-app.json; \ test -f /tmp/toolbox/apps/onenote/toolbox-app.json; \
test -f /tmp/toolbox/apps/av/toolbox-app.json; \ test -f /tmp/toolbox/apps/av/toolbox-app.json; \
test -f /tmp/toolbox/apps/regex/toolbox-app.json; \ test -f /tmp/toolbox/apps/regex/toolbox-app.json; \
test -f /tmp/toolbox/apps/svg/toolbox-app.json; \
rm "/tmp/${archive}" rm "/tmp/${archive}"
FROM ${NGINX_IMAGE} FROM ${NGINX_IMAGE}
+31 -28
View File
@@ -1,7 +1,7 @@
# add·ideas Toolbox Portal # add·ideas Toolbox Portal
`toolbox-portal` is the static launcher and release assembler for the add·ideas `toolbox-portal` is the static launcher and release assembler for the add·ideas
browser toolbox. Version `0.2.9` reads one same-origin catalogue, shows each app browser toolbox. Version `0.2.12` reads one same-origin catalogue, shows each app
as a compact launch tile, and keeps personal pins, drag-and-drop ordering, as a compact launch tile, and keeps personal pins, drag-and-drop ordering,
visibility, and appearance in the current browser. Pinned tools have their own visibility, and appearance in the current browser. Pinned tools have their own
section; search, category, and clickable tag filters stay close to the tool section; search, category, and clickable tag filters stay close to the tool
@@ -30,14 +30,14 @@ npm run build
npm run dev npm run dev
``` ```
The package lock resolves the `^0.2.2` SDK ranges to the published `0.2.2` The package lock resolves the `^0.2.3` SDK ranges to the published `0.2.3`
packages. A sibling SDK checkout is only needed when intentionally developing packages. A sibling SDK checkout is only needed when intentionally developing
the SDK and portal together. the SDK and portal together.
Vite uses `base: './'`, so the built portal works at `/` or a nested static path. Vite uses `base: './'`, so the built portal works at `/` or a nested static path.
The development catalogue at `public/toolbox.catalog.json` points to assembled The development catalogue at `public/toolbox.catalog.json` points to assembled
paths (`./apps/pdf/`, `./apps/xslt/`, `./apps/onenote/`, `./apps/av/`, and paths (`./apps/pdf/`, `./apps/xslt/`, `./apps/onenote/`, `./apps/av/`,
`./apps/regex/`). `./apps/regex/`, and `./apps/svg/`).
Those manifests will correctly appear as unavailable until an assembled release Those manifests will correctly appear as unavailable until an assembled release
is being served. is being served.
@@ -69,7 +69,7 @@ privacy and executable-code warning. Light, dark, and system modes are supported
## Production deployment behind Traefik ## Production deployment behind Traefik
The committed `compose.yaml` is the shortest production path. Its release The committed `compose.yaml` is the shortest production path. Its release
container downloads the immutable Toolbox 0.9.1 ZIP during the image build, container downloads the immutable Toolbox 0.10.0 ZIP during the image build,
verifies SHA-256 before extracting it, and then copies only the verified static verifies SHA-256 before extracting it, and then copies only the verified static
files into the pinned unprivileged nginx image. Node.js and a local portal files into the pinned unprivileged nginx image. Node.js and a local portal
assembly are not required on the deployment host. assembly are not required on the deployment host.
@@ -86,7 +86,7 @@ Prerequisites:
Deploy a fresh clone with: Deploy a fresh clone with:
```sh ```sh
git clone https://git.add-ideas.de/zemion/toolbox-portal.git git clone https://git.add-ideas.de/lotobo/toolbox-portal.git
cd toolbox-portal cd toolbox-portal
docker compose up -d --build docker compose up -d --build
docker compose ps docker compose ps
@@ -121,9 +121,9 @@ The app release should also publish a matching `.sha256` sidecar. The manifest
must declare the pinned reverse-DNS id and version. Application and portal must declare the pinned reverse-DNS id and version. Application and portal
versions are independent. versions are independent.
`release/toolbox.lock.json` is the reviewed v0.9.1 lock. Its URLs and checksums `release/toolbox.lock.json` is the reviewed v0.10.0 lock. Its URLs and checksums
pin the published PDF Tools 0.4.3, XSLT Tools 0.4.2, OneNote Tools 0.3.3, pin the published PDF Tools 0.4.4, XSLT Tools 0.4.3, OneNote Tools 0.3.4,
Audio & Video Tools 0.2.0, and Regex Tools 0.4.1 release bytes. Use Audio & Video Tools 0.3.0, Regex Tools 0.4.2, and SVG Tools 0.1.0 release bytes. Use
`release/toolbox.lock.example.json` as the template for a future release and `release/toolbox.lock.example.json` as the template for a future release and
verify every downloaded asset before committing updated values. Artifacts may be: verify every downloaded asset before committing updated values. Artifacts may be:
@@ -144,7 +144,7 @@ npm run assemble -- \
--lock release/toolbox.lock.json \ --lock release/toolbox.lock.json \
--portal-dist dist \ --portal-dist dist \
--output build/toolbox \ --output build/toolbox \
--archive build/add-ideas-toolbox-0.9.1.zip --archive build/add-ideas-toolbox-0.10.0.zip
``` ```
Existing output is refused. Pass `--force` only when replacing those exact Existing output is refused. Pass `--force` only when replacing those exact
@@ -164,10 +164,11 @@ build/toolbox/
├── xslt/ ├── xslt/
├── onenote/ ├── onenote/
├── av/ ├── av/
── regex/ ── regex/
└── svg/
build/add-ideas-toolbox-0.9.1.zip build/add-ideas-toolbox-0.10.0.zip
build/add-ideas-toolbox-0.9.1.zip.sha256 build/add-ideas-toolbox-0.10.0.zip.sha256
``` ```
The assembler verifies SHA-256 before opening an artifact, validates every app The assembler verifies SHA-256 before opening an artifact, validates every app
@@ -188,7 +189,7 @@ directory separately:
```sh ```sh
npm run package:static -- \ npm run package:static -- \
--input build/toolbox \ --input build/toolbox \
--output artifacts/add-ideas-toolbox-0.9.1.zip --output artifacts/add-ideas-toolbox-0.10.0.zip
``` ```
This also emits a `.sha256` sidecar. This also emits a `.sha256` sidecar.
@@ -197,9 +198,11 @@ This also emits a `.sha256` sidecar.
`Containerfile` serves only the assembled files with unprivileged nginx on port 8080. It adds restrictive browser headers, same-origin isolation, explicit `Containerfile` serves only the assembled files with unprivileged nginx on port 8080. It adds restrictive browser headers, same-origin isolation, explicit
`application/javascript` for `.mjs` engine modules and `application/wasm`, `application/javascript` for `.mjs` engine modules and `application/wasm`,
immutable caching only for Vite-hashed assets and narrowly immutable caching only for Vite-hashed assets and narrowly matched
matched semver-versioned FFmpeg core files, and revalidation for all other semver-versioned FFmpeg core files, and revalidation for all other files. The
files. Assemble first, then: opaque-origin SVG preview iframe loads its packaged controller with a URI-exact
CORS and cross-origin resource-policy exception; all other files retain the
same-origin policy and every normal security header. Assemble first, then:
The packaged policy intentionally does not grant CSP `unsafe-eval`. SaxonJS's The packaged policy intentionally does not grant CSP `unsafe-eval`. SaxonJS's
`ixsl:eval()` extension is therefore unsupported in this deployment profile; `ixsl:eval()` extension is therefore unsupported in this deployment profile;
@@ -207,9 +210,9 @@ normal local XML/XSLT transformations do not require that permission.
```sh ```sh
podman build -f Containerfile \ podman build -f Containerfile \
-t git.add-ideas.de/zemion/toolbox:0.9.1 . -t git.add-ideas.de/lotobo/toolbox:0.10.0 .
podman run --rm -p 8080:8080 \ podman run --rm -p 8080:8080 \
git.add-ideas.de/zemion/toolbox:0.9.1 git.add-ideas.de/lotobo/toolbox:0.10.0
``` ```
For a direct-port local deployment after assembly, use the separate example: For a direct-port local deployment after assembly, use the separate example:
@@ -226,8 +229,8 @@ docker login git.add-ideas.de
docker buildx build \ docker buildx build \
--platform linux/amd64,linux/arm64 \ --platform linux/amd64,linux/arm64 \
--file Containerfile.release \ --file Containerfile.release \
--tag git.add-ideas.de/zemion/toolbox:0.9.1 \ --tag git.add-ideas.de/lotobo/toolbox:0.10.0 \
--tag git.add-ideas.de/zemion/toolbox:0.9 \ --tag git.add-ideas.de/lotobo/toolbox:0.10 \
--push . --push .
``` ```
@@ -240,7 +243,7 @@ notes.
No credentials belong in this repository. The publishing workstation or runner No credentials belong in this repository. The publishing workstation or runner
needs permission to push code, releases, and container packages to needs permission to push code, releases, and container packages to
`zemion/toolbox-portal`. `lotobo/toolbox-portal`.
1. Run `npm ci`, `npm test`, `npm run lint`, and `npm run build` from a clean 1. Run `npm ci`, `npm test`, `npm run lint`, and `npm run build` from a clean
checkout of the intended portal tag. checkout of the intended portal tag.
@@ -249,11 +252,11 @@ needs permission to push code, releases, and container packages to
3. Verify downloaded app assets with `sha256sum -c <asset>.sha256`; copy those 3. Verify downloaded app assets with `sha256sum -c <asset>.sha256`; copy those
exact values into a reviewed toolbox lock. exact values into a reviewed toolbox lock.
4. Run the assembler and serve `build/toolbox` from a nested test path. Open 4. Run the assembler and serve `build/toolbox` from a nested test path. Open
all five apps, switch between them, and confirm the encoded `toolbox` all six apps, switch between them, and confirm the encoded `toolbox`
context. context.
5. Verify the distribution with 5. Verify the distribution with
`(cd build && sha256sum -c add-ideas-toolbox-0.9.1.zip.sha256)`. `(cd build && sha256sum -c add-ideas-toolbox-0.10.0.zip.sha256)`.
6. Commit the reviewed lock, tag the toolbox release (for example `v0.9.1`), and 6. Commit the reviewed lock, tag the toolbox release (for example `v0.10.0`), and
push the branch and tag to Gitea. push the branch and tag to Gitea.
7. In Gitea, open **Releases → New release**, select the tag, and upload the 7. In Gitea, open **Releases → New release**, select the tag, and upload the
static ZIP plus its `.sha256` file. Do not use a mutable “latest” URL in a static ZIP plus its `.sha256` file. Do not use a mutable “latest” URL in a
@@ -273,8 +276,9 @@ must not re-resolve app versions or substitute a newer release.
| **`pdf-tools`** | Existing; dedicated repository | Merge, split, reorder, rotate and export PDF pages | Thumbnail workspace; multi-document operations; ZIP and PDF output; saved local workspace | Workers and IndexedDB; large-document memory control; future signature inspection through `crypto-tools`; metadata and safe-sharing through `privacy-tools` | | **`pdf-tools`** | Existing; dedicated repository | Merge, split, reorder, rotate and export PDF pages | Thumbnail workspace; multi-document operations; ZIP and PDF output; saved local workspace | Workers and IndexedDB; large-document memory control; future signature inspection through `crypto-tools`; metadata and safe-sharing through `privacy-tools` |
| **`xslt-tools`** | Existing; dedicated repository | Develop, test and run XSLT transformations | XML/XSLT editors; transformation results; local files; saved projects; validation and diagnostics | Lazy SaxonJS loading; relocatable assets; useful handoffs to `data-tools`, `schema-tools` and `diff-tools` | | **`xslt-tools`** | Existing; dedicated repository | Develop, test and run XSLT transformations | XML/XSLT editors; transformation results; local files; saved projects; validation and diagnostics | Lazy SaxonJS loading; relocatable assets; useful handoffs to `data-tools`, `schema-tools` and `diff-tools` |
| **`onenote-tools`** | Existing rich-reader release; dedicated repository | Open, browse, inspect and export OneNote sections and packages locally | Desktop/unfragmented FSSHTTPB `.one`/`.onetoc2`; none/LZX/MSZIP/Quantum and multi-cabinet `.onepkg`; trees, rich text, images, tables, ink, attachments and export | Native TypeScript worker with no Wasm; bounded parsing, rendering and export; fragmented FSSHTTP fails safely; no editing or pixel-perfect fidelity | | **`onenote-tools`** | Existing rich-reader release; dedicated repository | Open, browse, inspect and export OneNote sections and packages locally | Desktop/unfragmented FSSHTTPB `.one`/`.onetoc2`; none/LZX/MSZIP/Quantum and multi-cabinet `.onepkg`; trees, rich text, images, tables, ink, attachments and export | Native TypeScript worker with no Wasm; bounded parsing, rendering and export; fragmented FSSHTTP fails safely; no editing or pixel-perfect fidelity |
| **`av-tools`** | Existing local-first v0.2.0 release; dedicated repository | Convert and lightly edit audio and video locally in the browser | Quick conversion; trim, split and crossfade concatenate; crop, resize, normalize, fades, waveform, metadata, chapters, subtitles, scene thumbnails/contact sheets, presets and export | Reviewed ffmpeg.wasm 0.12.10 ST/MT build with verified Opus and bundled label font; bounded queue, temporary storage and resource policy; isolation enables MT with automatic ST fallback; versioned core assets are immutable | | **`av-tools`** | Existing local-first v0.3.0 release; dedicated repository | Convert and lightly edit audio and video locally in the browser | Immediate native playback and basic file information; progressive stream inspection on demand; quick conversion; trim, split and crossfade concatenate; crop, resize, normalize, fades, waveform, metadata, chapters, subtitles, scene thumbnails/contact sheets, presets and export | Reviewed ffmpeg.wasm 0.12.10 ST/MT build with verified Opus and bundled label font; bounded queue, temporary storage and resource policy; isolation enables MT with automatic ST fallback; versioned core assets are immutable |
| **`regex-tools`** | Current local-first v0.4.1 release; dedicated repository | Develop, explain, test and apply JavaScript, PCRE2, PHP, Perl, Python, Ruby, Java, C++, Go, .NET, Rust and Scala/JVM-compatible regular expressions | Deterministic syntax trees; engine-native matching, captures and bounded replacement; stable double-buffered live results; PCRE2 tracing and C17 generation; comparison; corpus apply; tests; risk/growth/benchmark analysis; generated cases; bounded minimization; validated ECMAScript formatting; project import/export and optional local persistence | Open-source regexpp and pinned local WebAssembly runtimes for PCRE2, PHP preg, legacy Perl, CPython, CRuby, TeaVM Java/Scala compatibility, libc++ C++, Go, .NET and Rust in killable workers; explicit source/licence inventories, resource limits and engine-specific offset semantics | | **`regex-tools`** | Current local-first v0.4.2 release; dedicated repository | Develop, explain, test and apply JavaScript, PCRE2, PHP, Perl, Python, Ruby, Java, C++, Go, .NET, Rust and Scala/JVM-compatible regular expressions | Deterministic syntax trees; engine-native matching, captures and bounded replacement; stable double-buffered live results; PCRE2 tracing and C17 generation; comparison; corpus apply; tests; risk/growth/benchmark analysis; generated cases; bounded minimization; validated ECMAScript formatting; project import/export and optional local persistence | Open-source regexpp and pinned local WebAssembly runtimes for PCRE2, PHP preg, legacy Perl, CPython, CRuby, TeaVM Java/Scala compatibility, libc++ C++, Go, .NET and Rust in killable workers; explicit source/licence inventories, resource limits and engine-specific offset semantics |
| **`svg-tools`** | Initial local-first v0.1.0 release; dedicated repository | Inspect and edit SVG source, structure, geometry, references and accessibility locally | Synchronized source/tree/canvas/inspector; path and transform tools; reference analysis; optimization; CSS animation preview; exact, sanitized, raster and project export | Untrusted SVG is sanitized into an opaque-origin sandbox; bounded parsing and decompression, explicit security findings and a URI-scoped controller header exception; later milestone slices remain intentionally tracked in the app repository |
## Planned tools ## Planned tools
@@ -282,7 +286,6 @@ must not re-resolve app versions or substitute a newer release.
| -------------------- | --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | -------------------- | --------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **`flow-tools`** | Later platform layer | Compose local processing operations across tools | Example: CSV → filter → QR generation → SVG template → PDF → ZIP; reusable recipes; typed inputs and outputs; progress and cancellation | Do not load complete React applications into one runtime; expose separate worker-safe operation packages only after several apps have stable operations | | **`flow-tools`** | Later platform layer | Compose local processing operations across tools | Example: CSV → filter → QR generation → SVG template → PDF → ZIP; reusable recipes; typed inputs and outputs; progress and cancellation | Do not load complete React applications into one runtime; expose separate worker-safe operation packages only after several apps have stable operations |
| **`file-tools`** | High priority; dedicated repository | Identify, inspect and organize local files | Magic-byte detection; hex view; decoded strings; checksums; directory manifests; split/join; duplicate detection; trailing-data detection; batch-rename preview | All inputs are untrusted; format inspectors require strict size and nesting limits; natural entry point to archive, privacy, crypto and package tools | | **`file-tools`** | High priority; dedicated repository | Identify, inspect and organize local files | Magic-byte detection; hex view; decoded strings; checksums; directory manifests; split/join; duplicate detection; trailing-data detection; batch-rename preview | All inputs are untrusted; format inspectors require strict size and nesting limits; natural entry point to archive, privacy, crypto and package tools |
| **`svg-tools`** | Planned; dedicated repository | Source and visual SVG editing | Synchronized DOM tree, code and canvas; optimization; path simplification; symbols; accessibility; animation; sanitization | SVG is potentially active content; previews require sanitization or sandboxing; integrate with `colour-tools`, `token-tools`, `image-tools` and `label-tools` |
| **`image-tools`** | High priority; dedicated repository | Edit and batch-process raster images | Crop, resize, rotate, compress, convert, contact sheets, sprites, responsive sets, favicon generation, metadata removal and visual quality comparison | Use workers and off-main-thread rendering; preserve or deliberately remove colour profiles; integrate with colour, SVG, PDF and privacy tools | | **`image-tools`** | High priority; dedicated repository | Edit and batch-process raster images | Crop, resize, rotate, compress, convert, contact sheets, sprites, responsive sets, favicon generation, metadata removal and visual quality comparison | Use workers and off-main-thread rendering; preserve or deliberately remove colour profiles; integrate with colour, SVG, PDF and privacy tools |
| **`subtitle-tools`** | Medium priority; dedicated repository | Edit, validate and synchronize captions | SRT, WebVTT and ASS; timing shifts; stretching; frame-rate conversion; overlap and reading-speed checks; waveform synchronization; revision comparison | Direct integration with `av-tools`; preserve style information when supported and disclose conversion losses | | **`subtitle-tools`** | Medium priority; dedicated repository | Edit, validate and synchronize captions | SRT, WebVTT and ASS; timing shifts; stretching; frame-rate conversion; overlap and reading-speed checks; waveform synchronization; revision comparison | Direct integration with `av-tools`; preserve style information when supported and disclose conversion losses |
| **`midi-tools`** | Medium specialist app | MIDI event inspection and editing; transpose, quantize, tempo maps and controller data; device access should remain optional | | | **`midi-tools`** | Medium specialist app | MIDI event inspection and editing; transpose, quantize, tempo maps and controller data; device access should remain optional | |
+1 -1
View File
@@ -3,7 +3,7 @@ services:
build: build:
context: . context: .
dockerfile: Containerfile dockerfile: Containerfile
image: git.add-ideas.de/zemion/toolbox:0.9.1 image: git.add-ideas.de/lotobo/toolbox:0.10.0
restart: unless-stopped restart: unless-stopped
read_only: true read_only: true
ports: ports:
+3 -3
View File
@@ -6,9 +6,9 @@ services:
context: . context: .
dockerfile: Containerfile.release dockerfile: Containerfile.release
args: args:
TOOLBOX_RELEASE_VERSION: "${TOOLBOX_RELEASE_VERSION:-0.9.1}" TOOLBOX_RELEASE_VERSION: "${TOOLBOX_RELEASE_VERSION:-0.10.0}"
TOOLBOX_RELEASE_SHA256: "${TOOLBOX_RELEASE_SHA256:-e9dc6a949f1348694099baf62a7b86aa6fea1805bca794de7dfab5dd2040e062}" TOOLBOX_RELEASE_SHA256: "${TOOLBOX_RELEASE_SHA256:-de6f1afc3f0ec08ee1a8afd80d874832cbf905d0d50f62060e6985be9f5e0019}"
image: "git.add-ideas.de/zemion/toolbox:${TOOLBOX_RELEASE_VERSION:-0.9.1}" image: "git.add-ideas.de/lotobo/toolbox:${TOOLBOX_RELEASE_VERSION:-0.10.0}"
restart: unless-stopped restart: unless-stopped
read_only: true read_only: true
tmpfs: tmpfs:
+12 -1
View File
@@ -4,6 +4,16 @@ map $uri $toolbox_cache_control {
"~^/apps/[a-z0-9][a-z0-9-]*/vendor/ffmpeg/(?:(?:0|[1-9][0-9]*)\.(?:0|[1-9][0-9]*)\.(?:0|[1-9][0-9]*)|0\.12\.10-reviewed-stack5m\.1)/(?:version\.json|(?:st|mt)/ffmpeg-core\.(?:js|wasm)|mt/ffmpeg-core\.worker\.js)$" "public, max-age=31536000, immutable"; "~^/apps/[a-z0-9][a-z0-9-]*/vendor/ffmpeg/(?:(?:0|[1-9][0-9]*)\.(?:0|[1-9][0-9]*)\.(?:0|[1-9][0-9]*)|0\.12\.10-reviewed-stack5m\.1)/(?:version\.json|(?:st|mt)/ffmpeg-core\.(?:js|wasm)|mt/ffmpeg-core\.worker\.js)$" "public, max-age=31536000, immutable";
} }
map $uri $toolbox_resource_policy {
default "same-origin";
"/apps/svg/canvas-frame-controller.js" "cross-origin";
}
map $uri $toolbox_access_control_allow_origin {
default "";
"/apps/svg/canvas-frame-controller.js" "*";
}
server { server {
listen 8080; listen 8080;
listen [::]:8080; listen [::]:8080;
@@ -19,7 +29,8 @@ server {
add_header X-Frame-Options "DENY" always; add_header X-Frame-Options "DENY" always;
add_header Cross-Origin-Opener-Policy "same-origin" always; add_header Cross-Origin-Opener-Policy "same-origin" always;
add_header Cross-Origin-Embedder-Policy "require-corp" always; add_header Cross-Origin-Embedder-Policy "require-corp" always;
add_header Cross-Origin-Resource-Policy "same-origin" always; add_header Cross-Origin-Resource-Policy $toolbox_resource_policy always;
add_header Access-Control-Allow-Origin $toolbox_access_control_allow_origin always;
add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=()" always; add_header Permissions-Policy "camera=(), microphone=(), geolocation=(), payment=(), usb=()" always;
add_header Content-Security-Policy "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; media-src 'self' blob:; font-src 'self' data:; connect-src 'self'; worker-src 'self' blob:; manifest-src 'self'" always; add_header Content-Security-Policy "default-src 'self'; base-uri 'self'; object-src 'none'; frame-ancestors 'none'; form-action 'self'; script-src 'self' 'wasm-unsafe-eval'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; media-src 'self' blob:; font-src 'self' data:; connect-src 'self'; worker-src 'self' blob:; manifest-src 'self'" always;
add_header Cache-Control $toolbox_cache_control always; add_header Cache-Control $toolbox_cache_control always;
+11 -11
View File
@@ -1,16 +1,16 @@
{ {
"name": "@add-ideas/toolbox-portal", "name": "@add-ideas/toolbox-portal",
"version": "0.2.9", "version": "0.2.12",
"lockfileVersion": 3, "lockfileVersion": 3,
"requires": true, "requires": true,
"packages": { "packages": {
"": { "": {
"name": "@add-ideas/toolbox-portal", "name": "@add-ideas/toolbox-portal",
"version": "0.2.9", "version": "0.2.12",
"license": "AGPL-3.0-only", "license": "AGPL-3.0-only",
"dependencies": { "dependencies": {
"@add-ideas/toolbox-contract": "^0.2.2", "@add-ideas/toolbox-contract": "^0.2.3",
"@add-ideas/toolbox-shell-react": "^0.2.2", "@add-ideas/toolbox-shell-react": "^0.2.3",
"@dnd-kit/core": "^6.3.1", "@dnd-kit/core": "^6.3.1",
"@dnd-kit/sortable": "^10.0.0", "@dnd-kit/sortable": "^10.0.0",
"@dnd-kit/utilities": "^3.2.2", "@dnd-kit/utilities": "^3.2.2",
@@ -44,18 +44,18 @@
} }
}, },
"node_modules/@add-ideas/toolbox-contract": { "node_modules/@add-ideas/toolbox-contract": {
"version": "0.2.2", "version": "0.2.3",
"resolved": "https://git.add-ideas.de/api/packages/zemion/npm/%40add-ideas%2Ftoolbox-contract/-/0.2.2/toolbox-contract-0.2.2.tgz", "resolved": "https://git.add-ideas.de/api/packages/lotobo/npm/%40add-ideas%2Ftoolbox-contract/-/0.2.3/toolbox-contract-0.2.3.tgz",
"integrity": "sha512-VcZ8j4O2PgFaIYgxs6r9u0uPxA+hHKwhCW+omfeVCtbjAAYhH2KhRlBGm0ERVVYcK5kchyzZLXrC4LKWRotVzg==", "integrity": "sha512-T0PVSuMT40GjTDfQJhEEY3ZawQq8zz1/ry95JdKI6W39CdLacaRXdGnEpDCMHt+jUbf1Jz7Nat/M5dFCgKVM9A==",
"license": "Apache-2.0" "license": "Apache-2.0"
}, },
"node_modules/@add-ideas/toolbox-shell-react": { "node_modules/@add-ideas/toolbox-shell-react": {
"version": "0.2.2", "version": "0.2.3",
"resolved": "https://git.add-ideas.de/api/packages/zemion/npm/%40add-ideas%2Ftoolbox-shell-react/-/0.2.2/toolbox-shell-react-0.2.2.tgz", "resolved": "https://git.add-ideas.de/api/packages/lotobo/npm/%40add-ideas%2Ftoolbox-shell-react/-/0.2.3/toolbox-shell-react-0.2.3.tgz",
"integrity": "sha512-w/xbLCd50a2Jq7vQ9Z9ygUOuqlOCRkIYlk4vSJx0mf4REJNeMYi3PE2MbaLUC4DkQWyrmatsa5HNT89o0l91BA==", "integrity": "sha512-DT5lQDH48BFkFcmFLZnQh7+Cm73JzBPcmp5WzUXypfkUXpEyDYHzaXgmW4kZ0edSwh4RK4sPmx+JPtK0X4aKCQ==",
"license": "Apache-2.0", "license": "Apache-2.0",
"dependencies": { "dependencies": {
"@add-ideas/toolbox-contract": "0.2.2" "@add-ideas/toolbox-contract": "0.2.3"
}, },
"peerDependencies": { "peerDependencies": {
"react": ">=18 <20", "react": ">=18 <20",
+11 -3
View File
@@ -1,6 +1,6 @@
{ {
"name": "@add-ideas/toolbox-portal", "name": "@add-ideas/toolbox-portal",
"version": "0.2.9", "version": "0.2.12",
"license": "AGPL-3.0-only", "license": "AGPL-3.0-only",
"private": true, "private": true,
"type": "module", "type": "module",
@@ -21,8 +21,8 @@
"package:static": "node scripts/package-static.mjs" "package:static": "node scripts/package-static.mjs"
}, },
"dependencies": { "dependencies": {
"@add-ideas/toolbox-contract": "^0.2.2", "@add-ideas/toolbox-contract": "^0.2.3",
"@add-ideas/toolbox-shell-react": "^0.2.2", "@add-ideas/toolbox-shell-react": "^0.2.3",
"@dnd-kit/core": "^6.3.1", "@dnd-kit/core": "^6.3.1",
"@dnd-kit/sortable": "^10.0.0", "@dnd-kit/sortable": "^10.0.0",
"@dnd-kit/utilities": "^3.2.2", "@dnd-kit/utilities": "^3.2.2",
@@ -53,5 +53,13 @@
}, },
"engines": { "engines": {
"node": ">=22" "node": ">=22"
},
"repository": {
"type": "git",
"url": "git+https://git.add-ideas.de/lotobo/toolbox-portal.git"
},
"homepage": "https://git.add-ideas.de/lotobo/toolbox-portal",
"bugs": {
"url": "https://git.add-ideas.de/lotobo/toolbox-portal/issues"
} }
} }
+2 -2
View File
@@ -1,8 +1,8 @@
# Corresponding source # Corresponding source
The source code corresponding to add·ideas Toolbox Portal 0.2.9 is available at: The source code corresponding to add·ideas Toolbox Portal 0.2.12 is available at:
https://git.add-ideas.de/zemion/toolbox-portal/src/tag/v0.9.1 https://git.add-ideas.de/lotobo/toolbox-portal/src/tag/v0.10.0
Each bundled application contains its own `SOURCE.md`, license, and third-party Each bundled application contains its own `SOURCE.md`, license, and third-party
license materials. The application sources are also linked from the portal. license materials. The application sources are also linked from the portal.
+5 -1
View File
@@ -1,5 +1,5 @@
{ {
"$schema": "https://git.add-ideas.de/zemion/toolbox-sdk/raw/branch/main/schemas/toolbox-catalog.v1.schema.json", "$schema": "https://git.add-ideas.de/lotobo/toolbox-sdk/raw/branch/main/schemas/toolbox-catalog.v1.schema.json",
"schemaVersion": 1, "schemaVersion": 1,
"id": "de.add-ideas.toolbox", "id": "de.add-ideas.toolbox",
"name": "add·ideas Toolbox", "name": "add·ideas Toolbox",
@@ -28,6 +28,10 @@
{ {
"manifest": "./apps/regex/toolbox-app.json", "manifest": "./apps/regex/toolbox-app.json",
"enabled": true "enabled": true
},
{
"manifest": "./apps/svg/toolbox-app.json",
"enabled": true
} }
] ]
} }
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"$schema": "https://json-schema.org/draft/2020-12/schema", "$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://git.add-ideas.de/zemion/toolbox-portal/raw/branch/main/release/toolbox-release-lock.schema.json", "$id": "https://git.add-ideas.de/lotobo/toolbox-portal/raw/branch/main/release/toolbox-release-lock.schema.json",
"title": "add·ideas Toolbox release lock v1", "title": "add·ideas Toolbox release lock v1",
"description": "Pins the exact portal and checksummed application archives used to assemble one static toolbox release.", "description": "Pins the exact portal and checksummed application archives used to assemble one static toolbox release.",
"type": "object", "type": "object",
+24 -17
View File
@@ -1,8 +1,8 @@
{ {
"$schema": "./toolbox-release-lock.schema.json", "$schema": "./toolbox-release-lock.schema.json",
"schemaVersion": 1, "schemaVersion": 1,
"releaseVersion": "0.9.1", "releaseVersion": "0.10.0",
"portalVersion": "0.2.9", "portalVersion": "0.2.12",
"catalogue": { "catalogue": {
"id": "de.add-ideas.toolbox", "id": "de.add-ideas.toolbox",
"name": "add·ideas Toolbox", "name": "add·ideas Toolbox",
@@ -15,38 +15,45 @@
"apps": [ "apps": [
{ {
"id": "de.add-ideas.pdf-tools", "id": "de.add-ideas.pdf-tools",
"version": "0.4.3", "version": "0.4.4",
"artifact": "https://git.add-ideas.de/zemion/pdf-tools/releases/download/v0.4.3/pdf-tools-0.4.3.zip", "artifact": "https://git.add-ideas.de/lotobo/pdf-tools/releases/download/v0.4.4/pdf-tools-0.4.4.zip",
"sha256": "f2dfd3bade49a4b8be9c0c54c6c2bf1bbb153fc0505a38af14de5ab52d5183cf", "sha256": "fa93c4c004be74d6a1f68f62a0f64f44c99218f387441ca3630a7f5af3c09d7d",
"target": "pdf" "target": "pdf"
}, },
{ {
"id": "de.add-ideas.xslt-tools", "id": "de.add-ideas.xslt-tools",
"version": "0.4.2", "version": "0.4.3",
"artifact": "https://git.add-ideas.de/zemion/xslt-tools/releases/download/v0.4.2/xslt-tools-0.4.2.zip", "artifact": "https://git.add-ideas.de/lotobo/xslt-tools/releases/download/v0.4.3/xslt-tools-0.4.3.zip",
"sha256": "daaa821c10c6c6285f97128ba3d923e48efa24449f1fb0a21bf478abaf27499f", "sha256": "e44012af214d24e3d97d10a6017fa3d9dbf063de36673ab04dd15a0a8643afcc",
"target": "xslt" "target": "xslt"
}, },
{ {
"id": "de.add-ideas.onenote-tools", "id": "de.add-ideas.onenote-tools",
"version": "0.3.3", "version": "0.3.4",
"artifact": "https://git.add-ideas.de/zemion/onenote-tools/releases/download/v0.3.3/onenote-tools-0.3.3.zip", "artifact": "https://git.add-ideas.de/lotobo/onenote-tools/releases/download/v0.3.4/onenote-tools-0.3.4.zip",
"sha256": "37c0ef7cdc7f435d0d4f5a341523f4e522118d5b258c374b5a7ef7b8e6c27cec", "sha256": "c0ed791d1ae64fdf6a90bceebf97a7a3252989f2434204d009f87f5a2d1cc341",
"target": "onenote" "target": "onenote"
}, },
{ {
"id": "de.add-ideas.av-tools", "id": "de.add-ideas.av-tools",
"version": "0.2.0", "version": "0.3.0",
"artifact": "https://git.add-ideas.de/zemion/av-tools/releases/download/v0.2.0/av-tools-0.2.0.zip", "artifact": "https://git.add-ideas.de/lotobo/av-tools/releases/download/v0.3.0/av-tools-0.3.0.zip",
"sha256": "40f9e7f48617930ddcba25538bd12d0a24197c7c4824989f20fd23fd25349a54", "sha256": "3476c5d43ae43ce66b5aeebe8c11334f7cd4d153586348b72f10bfbdbada9be7",
"target": "av" "target": "av"
}, },
{ {
"id": "de.add-ideas.regex-tools", "id": "de.add-ideas.regex-tools",
"version": "0.4.1", "version": "0.4.2",
"artifact": "https://git.add-ideas.de/zemion/regex-tools/releases/download/v0.4.1/regex-tools-0.4.1.zip", "artifact": "https://git.add-ideas.de/lotobo/regex-tools/releases/download/v0.4.2/regex-tools-0.4.2.zip",
"sha256": "a298d0c578ee5f3e80c036b1c6be308f0277052e770c000fdda8505e5a305815", "sha256": "a3e7342d1f0746aa9c88e6568e7fbc04ab429c94604ba5fb1094ffdb096a54fe",
"target": "regex" "target": "regex"
},
{
"id": "de.add-ideas.svg-tools",
"version": "0.1.0",
"artifact": "https://git.add-ideas.de/lotobo/svg-tools/releases/download/v0.1.0/svg-tools-0.1.0.zip",
"sha256": "364f14c88c4934d9c847bf76de70b89dcf564a405afd58c6703363a95fbfb6ae",
"target": "svg"
} }
] ]
} }
+24 -17
View File
@@ -1,8 +1,8 @@
{ {
"$schema": "./toolbox-release-lock.schema.json", "$schema": "./toolbox-release-lock.schema.json",
"schemaVersion": 1, "schemaVersion": 1,
"releaseVersion": "0.9.1", "releaseVersion": "0.10.0",
"portalVersion": "0.2.9", "portalVersion": "0.2.12",
"catalogue": { "catalogue": {
"id": "de.add-ideas.toolbox", "id": "de.add-ideas.toolbox",
"name": "add·ideas Toolbox", "name": "add·ideas Toolbox",
@@ -15,38 +15,45 @@
"apps": [ "apps": [
{ {
"id": "de.add-ideas.pdf-tools", "id": "de.add-ideas.pdf-tools",
"version": "0.4.3", "version": "0.4.4",
"artifact": "https://git.add-ideas.de/zemion/pdf-tools/releases/download/v0.4.3/pdf-tools-0.4.3.zip", "artifact": "https://git.add-ideas.de/lotobo/pdf-tools/releases/download/v0.4.4/pdf-tools-0.4.4.zip",
"sha256": "f2dfd3bade49a4b8be9c0c54c6c2bf1bbb153fc0505a38af14de5ab52d5183cf", "sha256": "fa93c4c004be74d6a1f68f62a0f64f44c99218f387441ca3630a7f5af3c09d7d",
"target": "pdf" "target": "pdf"
}, },
{ {
"id": "de.add-ideas.xslt-tools", "id": "de.add-ideas.xslt-tools",
"version": "0.4.2", "version": "0.4.3",
"artifact": "https://git.add-ideas.de/zemion/xslt-tools/releases/download/v0.4.2/xslt-tools-0.4.2.zip", "artifact": "https://git.add-ideas.de/lotobo/xslt-tools/releases/download/v0.4.3/xslt-tools-0.4.3.zip",
"sha256": "daaa821c10c6c6285f97128ba3d923e48efa24449f1fb0a21bf478abaf27499f", "sha256": "e44012af214d24e3d97d10a6017fa3d9dbf063de36673ab04dd15a0a8643afcc",
"target": "xslt" "target": "xslt"
}, },
{ {
"id": "de.add-ideas.onenote-tools", "id": "de.add-ideas.onenote-tools",
"version": "0.3.3", "version": "0.3.4",
"artifact": "https://git.add-ideas.de/zemion/onenote-tools/releases/download/v0.3.3/onenote-tools-0.3.3.zip", "artifact": "https://git.add-ideas.de/lotobo/onenote-tools/releases/download/v0.3.4/onenote-tools-0.3.4.zip",
"sha256": "37c0ef7cdc7f435d0d4f5a341523f4e522118d5b258c374b5a7ef7b8e6c27cec", "sha256": "c0ed791d1ae64fdf6a90bceebf97a7a3252989f2434204d009f87f5a2d1cc341",
"target": "onenote" "target": "onenote"
}, },
{ {
"id": "de.add-ideas.av-tools", "id": "de.add-ideas.av-tools",
"version": "0.2.0", "version": "0.3.0",
"artifact": "https://git.add-ideas.de/zemion/av-tools/releases/download/v0.2.0/av-tools-0.2.0.zip", "artifact": "https://git.add-ideas.de/lotobo/av-tools/releases/download/v0.3.0/av-tools-0.3.0.zip",
"sha256": "40f9e7f48617930ddcba25538bd12d0a24197c7c4824989f20fd23fd25349a54", "sha256": "3476c5d43ae43ce66b5aeebe8c11334f7cd4d153586348b72f10bfbdbada9be7",
"target": "av" "target": "av"
}, },
{ {
"id": "de.add-ideas.regex-tools", "id": "de.add-ideas.regex-tools",
"version": "0.4.1", "version": "0.4.2",
"artifact": "https://git.add-ideas.de/zemion/regex-tools/releases/download/v0.4.1/regex-tools-0.4.1.zip", "artifact": "https://git.add-ideas.de/lotobo/regex-tools/releases/download/v0.4.2/regex-tools-0.4.2.zip",
"sha256": "a298d0c578ee5f3e80c036b1c6be308f0277052e770c000fdda8505e5a305815", "sha256": "a3e7342d1f0746aa9c88e6568e7fbc04ab429c94604ba5fb1094ffdb096a54fe",
"target": "regex" "target": "regex"
},
{
"id": "de.add-ideas.svg-tools",
"version": "0.1.0",
"artifact": "https://git.add-ideas.de/lotobo/svg-tools/releases/download/v0.1.0/svg-tools-0.1.0.zip",
"sha256": "364f14c88c4934d9c847bf76de70b89dcf564a405afd58c6703363a95fbfb6ae",
"target": "svg"
} }
] ]
} }
+1 -1
View File
@@ -83,7 +83,7 @@ function makeLock(artifact: string, sha256: string) {
return { return {
schemaVersion: 1, schemaVersion: 1,
releaseVersion: '0.1.0', releaseVersion: '0.1.0',
portalVersion: '0.2.9', portalVersion: '0.2.12',
catalogue: { catalogue: {
id: 'de.add-ideas.toolbox', id: 'de.add-ideas.toolbox',
name: 'Test Toolbox', name: 'Test Toolbox',
+26 -2
View File
@@ -62,7 +62,7 @@ describe('production deployment', () => {
/^TOOLBOX_RELEASE_SHA256=([a-f0-9]{64})$/mu /^TOOLBOX_RELEASE_SHA256=([a-f0-9]{64})$/mu
)?.[1]; )?.[1];
const localImageVersion = composeExample.match( const localImageVersion = composeExample.match(
/^\s+image: git\.add-ideas\.de\/zemion\/toolbox:(\S+)$/mu /^\s+image: git\.add-ideas\.de\/lotobo\/toolbox:(\S+)$/mu
)?.[1]; )?.[1];
expect(containerVersion).toBe(releaseLock.releaseVersion); expect(containerVersion).toBe(releaseLock.releaseVersion);
@@ -85,7 +85,7 @@ describe('production deployment', () => {
expect(containerfile).toContain( expect(containerfile).toContain(
'COPY --from=release --chown=101:101 /tmp/toolbox/' 'COPY --from=release --chown=101:101 /tmp/toolbox/'
); );
for (const app of ['pdf', 'xslt', 'onenote', 'av', 'regex']) { for (const app of ['pdf', 'xslt', 'onenote', 'av', 'regex', 'svg']) {
expect(containerfile).toContain( expect(containerfile).toContain(
`test -f /tmp/toolbox/apps/${app}/toolbox-app.json` `test -f /tmp/toolbox/apps/${app}/toolbox-app.json`
); );
@@ -214,4 +214,28 @@ describe('production deployment', () => {
expect(nginxConfig).toContain("media-src 'self' blob:"); expect(nginxConfig).toContain("media-src 'self' blob:");
expect(nginxConfig).not.toContain("'unsafe-eval'"); expect(nginxConfig).not.toContain("'unsafe-eval'");
}); });
it('grants only the sandboxed SVG canvas controller cross-origin loading headers', () => {
expect(nginxConfig).toMatch(
/map \$uri \$toolbox_resource_policy\s*\{\s*default "same-origin";\s*"\/apps\/svg\/canvas-frame-controller\.js" "cross-origin";\s*\}/mu
);
expect(nginxConfig).toMatch(
/map \$uri \$toolbox_access_control_allow_origin\s*\{\s*default "";\s*"\/apps\/svg\/canvas-frame-controller\.js" "\*";\s*\}/mu
);
expect(nginxConfig).toContain(
'add_header Cross-Origin-Resource-Policy $toolbox_resource_policy always;'
);
expect(nginxConfig).toContain(
'add_header Access-Control-Allow-Origin $toolbox_access_control_allow_origin always;'
);
expect(nginxConfig).not.toMatch(
/location[^\n{]*canvas-frame-controller[^\n{]*\{/u
);
expect(
nginxConfig.match(/^\s*add_header X-Content-Type-Options /gmu)
).toHaveLength(1);
expect(
nginxConfig.match(/^\s*add_header Content-Security-Policy /gmu)
).toHaveLength(1);
});
}); });
+1 -1
View File
@@ -131,7 +131,7 @@ export function buildCatalogue(lock) {
}; };
return { return {
$schema: $schema:
'https://git.add-ideas.de/zemion/toolbox-sdk/raw/branch/main/schemas/toolbox-catalog.v1.schema.json', 'https://git.add-ideas.de/lotobo/toolbox-sdk/raw/branch/main/schemas/toolbox-catalog.v1.schema.json',
...parseToolboxCatalog(catalogue), ...parseToolboxCatalog(catalogue),
}; };
} }
+9 -5
View File
@@ -42,6 +42,9 @@ describe('portal UI', () => {
expect( expect(
screen.getByTestId('app-card-de.add-ideas.onenote-tools') screen.getByTestId('app-card-de.add-ideas.onenote-tools')
).toHaveTextContent('OneNote'); ).toHaveTextContent('OneNote');
expect(
screen.getByTestId('app-card-de.add-ideas.svg-tools')
).toHaveTextContent('SVG');
expect( expect(
screen.queryByText( screen.queryByText(
'Page-level PDF operations performed locally in the browser.' 'Page-level PDF operations performed locally in the browser.'
@@ -143,9 +146,7 @@ describe('portal UI', () => {
expect(within(card).getByRole('heading', { level: 3 })).toHaveTextContent( expect(within(card).getByRole('heading', { level: 3 })).toHaveTextContent(
'Regex' 'Regex'
); );
expect( expect(within(card).getByText('Explain and test locally.')).toBeVisible();
within(card).getByText('Explain and test regex locally.')
).toBeVisible();
}); });
it('moves the full disclosure into an accessible modal', async () => { it('moves the full disclosure into an accessible modal', async () => {
@@ -181,7 +182,7 @@ describe('portal UI', () => {
}); });
expect(sourceLink).toHaveAttribute( expect(sourceLink).toHaveAttribute(
'href', 'href',
'https://git.add-ideas.de/zemion/pdf-tools' 'https://git.add-ideas.de/lotobo/pdf-tools'
); );
expect(sourceLink).toHaveAttribute('rel', 'noopener noreferrer'); expect(sourceLink).toHaveAttribute('rel', 'noopener noreferrer');
expect( expect(
@@ -409,6 +410,7 @@ describe('portal UI', () => {
'de.add-ideas.pdf-tools', 'de.add-ideas.pdf-tools',
'de.add-ideas.xslt-tools', 'de.add-ideas.xslt-tools',
'de.add-ideas.onenote-tools', 'de.add-ideas.onenote-tools',
'de.add-ideas.svg-tools',
], ],
hidden: [], hidden: [],
theme: 'light', theme: 'light',
@@ -426,6 +428,7 @@ describe('portal UI', () => {
screen.getByTestId('app-card-de.add-ideas.pdf-tools'), screen.getByTestId('app-card-de.add-ideas.pdf-tools'),
screen.getByTestId('app-card-de.add-ideas.xslt-tools'), screen.getByTestId('app-card-de.add-ideas.xslt-tools'),
screen.getByTestId('app-card-de.add-ideas.onenote-tools'), screen.getByTestId('app-card-de.add-ideas.onenote-tools'),
screen.getByTestId('app-card-de.add-ideas.svg-tools'),
]; ];
cards.forEach((card, index) => { cards.forEach((card, index) => {
const rect = { const rect = {
@@ -456,7 +459,7 @@ describe('portal UI', () => {
within(tools) within(tools)
.getAllByRole('heading', { level: 3 }) .getAllByRole('heading', { level: 3 })
.map((heading) => heading.textContent) .map((heading) => heading.textContent)
).toEqual(['XSLT', 'PDF', 'OneNote']); ).toEqual(['XSLT', 'PDF', 'OneNote', 'SVG']);
}); });
expect( expect(
JSON.parse(localStorage.getItem(PREFERENCES_KEY) ?? '{}').order JSON.parse(localStorage.getItem(PREFERENCES_KEY) ?? '{}').order
@@ -464,6 +467,7 @@ describe('portal UI', () => {
'de.add-ideas.xslt-tools', 'de.add-ideas.xslt-tools',
'de.add-ideas.pdf-tools', 'de.add-ideas.pdf-tools',
'de.add-ideas.onenote-tools', 'de.add-ideas.onenote-tools',
'de.add-ideas.svg-tools',
]); ]);
}); });
+3 -3
View File
@@ -28,7 +28,7 @@ import type { LoadedCatalogue, ResolvedApp } from './types';
import { usePreferences } from './usePreferences'; import { usePreferences } from './usePreferences';
const CATALOGUE_HREF = './toolbox.catalog.json'; const CATALOGUE_HREF = './toolbox.catalog.json';
const PORTAL_SOURCE = 'https://git.add-ideas.de/zemion/toolbox-portal'; const PORTAL_SOURCE = 'https://git.add-ideas.de/lotobo/toolbox-portal';
type LoadState = type LoadState =
| { status: 'loading' } | { status: 'loading' }
@@ -489,9 +489,9 @@ export default function App() {
</span> </span>
</p> </p>
<span> <span>
Portal v0.2.9 ·{' '} Portal v0.2.12 ·{' '}
<a <a
href="https://git.add-ideas.de/zemion/toolbox-portal/src/tag/v0.9.1" href="https://git.add-ideas.de/lotobo/toolbox-portal/src/tag/v0.10.0"
target="_blank" target="_blank"
rel="noopener noreferrer" rel="noopener noreferrer"
> >
+3 -2
View File
@@ -10,12 +10,12 @@ describe('catalogue loading', () => {
const loaded = await loadCatalogue('/toolbox.catalog.json'); const loaded = await loadCatalogue('/toolbox.catalog.json');
expect(loaded.catalogue.name).toBe('add·ideas Toolbox'); expect(loaded.catalogue.name).toBe('add·ideas Toolbox');
expect(loaded.homeUrl).toBe('http://localhost:3000/'); expect(loaded.homeUrl).toBe('http://localhost:3000/');
expect(loaded.apps).toHaveLength(3); expect(loaded.apps).toHaveLength(4);
expect(loaded.apps[0]).toMatchObject({ expect(loaded.apps[0]).toMatchObject({
id: 'de.add-ideas.pdf-tools', id: 'de.add-ideas.pdf-tools',
name: 'PDF Workbench', name: 'PDF Workbench',
entryUrl: 'http://localhost:3000/apps/pdf/', entryUrl: 'http://localhost:3000/apps/pdf/',
sourceUrl: 'https://git.add-ideas.de/zemion/pdf-tools', sourceUrl: 'https://git.add-ideas.de/lotobo/pdf-tools',
}); });
}); });
@@ -40,6 +40,7 @@ describe('catalogue loading', () => {
'de.add-ideas.pdf-tools', 'de.add-ideas.pdf-tools',
'de.add-ideas.xslt-tools', 'de.add-ideas.xslt-tools',
'de.add-ideas.onenote-tools', 'de.add-ideas.onenote-tools',
'de.add-ideas.svg-tools',
]); ]);
expect(loaded.unavailable).toHaveLength(1); expect(loaded.unavailable).toHaveLength(1);
expect(loaded.unavailable[0]?.reason).toMatch(/HTTP 404/); expect(loaded.unavailable[0]?.reason).toMatch(/HTTP 404/);
+39 -4
View File
@@ -30,7 +30,7 @@ export const pdfManifest: ToolboxAppManifest = {
telemetry: false, telemetry: false,
}, },
source: { source: {
repository: 'https://git.add-ideas.de/zemion/pdf-tools', repository: 'https://git.add-ideas.de/lotobo/pdf-tools',
license: 'AGPL-3.0-only', license: 'AGPL-3.0-only',
}, },
}; };
@@ -45,7 +45,7 @@ export const xsltManifest: ToolboxAppManifest = {
categories: ['documents', 'developer'], categories: ['documents', 'developer'],
tags: ['transform', 'xml'], tags: ['transform', 'xml'],
source: { source: {
repository: 'https://git.add-ideas.de/zemion/xslt-tools', repository: 'https://git.add-ideas.de/lotobo/xslt-tools',
license: 'AGPL-3.0-only', license: 'AGPL-3.0-only',
}, },
}; };
@@ -60,7 +60,7 @@ export const onenoteManifest: ToolboxAppManifest = {
categories: ['documents', 'notes'], categories: ['documents', 'notes'],
tags: ['onepkg', 'import'], tags: ['onepkg', 'import'],
source: { source: {
repository: 'https://git.add-ideas.de/zemion/onenote-tools', repository: 'https://git.add-ideas.de/lotobo/onenote-tools',
license: 'AGPL-3.0-only', license: 'AGPL-3.0-only',
}, },
}; };
@@ -82,11 +82,43 @@ export const regexManifest: ToolboxAppManifest = {
crossOriginIsolated: false, crossOriginIsolated: false,
}, },
source: { source: {
repository: 'https://git.add-ideas.de/zemion/regex-tools', repository: 'https://git.add-ideas.de/lotobo/regex-tools',
license: 'GPL-3.0-or-later', license: 'GPL-3.0-or-later',
}, },
}; };
export const svgManifest: ToolboxAppManifest = {
...pdfManifest,
id: 'de.add-ideas.svg-tools',
name: 'SVG Tools',
version: '0.1.0',
description:
'Inspect, edit, optimize and transform SVG documents locally in the browser.',
icon: './favicon.svg',
categories: ['graphics', 'design', 'developer'],
tags: [
'svg',
'vector',
'path',
'xml',
'transform',
'optimize',
'accessibility',
],
requirements: {
secureContext: false,
workers: true,
indexedDb: false,
crossOriginIsolated: false,
topLevelContext: false,
},
source: {
repository: 'https://git.add-ideas.de/lotobo/svg-tools',
license: 'GPL-3.0-or-later',
},
assets: ['./canvas-frame-controller.js'],
};
export const catalogue: ToolboxCatalog = { export const catalogue: ToolboxCatalog = {
schemaVersion: 1, schemaVersion: 1,
id: 'de.add-ideas.toolbox', id: 'de.add-ideas.toolbox',
@@ -97,6 +129,7 @@ export const catalogue: ToolboxCatalog = {
{ manifest: './apps/pdf/toolbox-app.json', enabled: true }, { manifest: './apps/pdf/toolbox-app.json', enabled: true },
{ manifest: './apps/xslt/toolbox-app.json', enabled: true }, { manifest: './apps/xslt/toolbox-app.json', enabled: true },
{ manifest: './apps/onenote/toolbox-app.json', enabled: true }, { manifest: './apps/onenote/toolbox-app.json', enabled: true },
{ manifest: './apps/svg/toolbox-app.json', enabled: true },
], ],
}; };
@@ -118,6 +151,8 @@ export function catalogueFetch(overrides: Record<string, Response> = {}) {
return Response.json(onenoteManifest); return Response.json(onenoteManifest);
if (url.pathname.endsWith('/apps/regex/toolbox-app.json')) if (url.pathname.endsWith('/apps/regex/toolbox-app.json'))
return Response.json(regexManifest); return Response.json(regexManifest);
if (url.pathname.endsWith('/apps/svg/toolbox-app.json'))
return Response.json(svgManifest);
return new Response('Not found', { status: 404 }); return new Response('Not found', { status: 404 });
}; };
} }
+42
View File
@@ -0,0 +1,42 @@
import { describe, expect, it } from 'vitest';
import { shortToolDescription, shortToolTitle } from './toolPresentation';
import type { ResolvedApp } from './types';
function app(id: string, name: string, description: string): ResolvedApp {
return { id, name, description } as ResolvedApp;
}
describe('compact tool presentation', () => {
it('uses the requested Audio & Video tile copy', () => {
const audioVideo = app(
'de.add-ideas.av-tools',
'Audio & Video Tools',
'Convert and lightly edit audio and video locally in the browser.'
);
expect(shortToolTitle(audioVideo)).toBe('Audio & Video');
expect(shortToolDescription(audioVideo)).toBe('Convert and edit locally.');
});
it('uses the requested Regex tile copy', () => {
const regex = app(
'de.add-ideas.regex-tools',
'Regex Tools',
'Develop, explain, test and apply regular expressions locally in the browser.'
);
expect(shortToolTitle(regex)).toBe('Regex');
expect(shortToolDescription(regex)).toBe('Explain and test locally.');
});
it('uses the compact SVG tile copy', () => {
const svg = app(
'de.add-ideas.svg-tools',
'SVG Tools',
'Inspect, edit, optimize and transform SVG documents locally in the browser.'
);
expect(shortToolTitle(svg)).toBe('SVG');
expect(shortToolDescription(svg)).toBe('Inspect and edit vectors locally.');
});
});
+9 -1
View File
@@ -13,9 +13,17 @@ const PRESENTATION: Record<string, { title: string; description: string }> = {
title: 'OneNote', title: 'OneNote',
description: 'Open OneNote files locally.', description: 'Open OneNote files locally.',
}, },
'de.add-ideas.av-tools': {
title: 'Audio & Video',
description: 'Convert and edit locally.',
},
'de.add-ideas.regex-tools': { 'de.add-ideas.regex-tools': {
title: 'Regex', title: 'Regex',
description: 'Explain and test regex locally.', description: 'Explain and test locally.',
},
'de.add-ideas.svg-tools': {
title: 'SVG',
description: 'Inspect and edit vectors locally.',
}, },
}; };