Skip to content

barakoBrew 1.2.0

Choose a tag to compare

@github-actions github-actions released this 14 Sep 07:20
· 47 commits to master since this release
4fd13f1

Works against barakoCMS 4.1.0, and speaks API contracts 1 to 3. The grouped action picker below
needs a barakoCMS release that includes BaryoDev/barakoCMS#783, which reports a group for each
workflow action kind. That is merged and not yet released. On 4.1.0 the picker shows the flat list
it showed before, and nothing else depends on it.

Added

  • Files shows a thumbnail for each image. It is the API's 160px copy (?w=160), never the
    original, so a page of uploads costs kilobytes rather than megabytes. A public image loads from
    the anonymous route with a srcset; a private one is fetched with the session's token in a header
    and shown from a local object URL, so the token never appears in a URL. PDF, GIF and AVIF files,
    which the API does not resize, show an icon instead of downloading the original. The console
    still has no image optimiser and ships no image binary (#80).
  • A navigation menu is reordered without editing JSON. The Items field of a menu entry is
    a list now: add and remove items, move them up and down, nest one under the item above and move it
    back out, all from the keyboard. The saved value keeps each item's keys and casing and changes only
    order and nesting, one level deep, which is what public.menu() in the client reads. A value the
    list cannot show without losing part of it stays in the JSON editor. The shape and the naming
    convention are in docs/menus.md (#86).
  • Files has a screen. /files lists the tenant's uploads 20 at a time with name, type, size,
    visibility and upload date. Upload states the API's rules (PNG, JPEG, GIF, WebP, AVIF or PDF, up
    to 10 MB) and refuses a file that breaks them before sending it; a refusal from the server, such
    as the virus scanner's, is shown in the dialog. Delete asks first, and when entries still use the
    file it names them and deletes only on "Delete anyway". A public file has a copy link button.
    Delete is offered on a file to its uploader, Admin and SuperAdmin, which is who the API allows.
    An account the API refuses the list to is told so, with no upload control. The rail lists Files
    under Modules for Admin and SuperAdmin (#3).
  • A content type that holds one entry is edited on one screen, not a list. barakoCMS 4.1.0
    marks such a type with isSingleton and refuses a second create. The console now lists each one
    in the rail under Entries and opens it at /content/singleton/{type}. With no entry yet, the first
    save creates it; after that the same screen edits it, with schedule and history. Links that used
    to open the list or the new entry form for such a type (the type's own page, /content?type=,
    /content/new?type=) land on that screen instead, and a type can be created with the flag on
    (#89).
  • A markdown field is a composer with a preview, not a bare textarea. Write and Preview tabs,
    a toolbar for bold, italic, heading, link, list and code, and a word count. The preview renders
    with barakoPress's rules, so raw HTML shows as text and a link that is not http, https, mailto or
    relative keeps its words and loses its destination. The saved value is the text as typed; toggling
    the preview never writes to it. text and richtext fields are unchanged (#85).
  • A webhook workflow can be built from the new workflow form. Published is offered as a
    trigger next to Created, Updated and the type's transitions. An action's optional parameters get
    inputs marked "(optional)", read from the example configuration the API publishes with each
    action, which is where the Webhook action names Secret. A parameter the API redacts on read
    (secret, token, password, API key and the like) is a password input with a hint that it will not
    be shown again, and a blank optional parameter is left out of the request rather than sent empty.
    The saved workflow says "Secret: set, not shown". The API never returns the value and has no
    update endpoint, so replacing a Secret means recreating the workflow. The trigger selects and the
    action picker have accessible names (part of #87).
  • The action picker groups kinds under Content, Delivery, Comms, Data and Flow. The console no
    longer keeps its own list of action kinds: it shows what GET /api/workflows/actions returns,
    keeps the API's order inside a group, leaves out empty groups, and puts a missing or unknown group
    under Other, last. An API that sends no group, barakoCMS 4.1.0 included, gets the flat list with
    no headings. The Request action is drawn with the connector icon rather than the fallback (part
    of #50).

Changed

  • The image is published as ghcr.io/baryodev/barako-brew. It was the last place the old name
    survived. Every tag (latest, <version>, dev, dev-<sha>, playground,
    playground-<version>) is also pushed as ghcr.io/baryodev/barako-admin pointing at the same
    digest, and the publish job fails if the two names disagree. barako-admin stops at 2.0.0;
    move compose files and deploy scripts to barako-brew before then. Tags already pulled under the
    old name stay resolvable (#84).
  • The unmocked pack runs against a pinned API image on pull requests, the merge queue and pushes
    (barako-cms:4.1.0, read from .github/barako-api-version), and against barako-cms:master
    nightly and on demand. A failed nightly opens or comments on one tracking issue.
    scripts/smoke-check.sh defaults to the same pin (#58).
  • CodeQL runs on merge queue batches and on every pull request, markdown-only ones included, so it
    can be a required check (part of #26).
  • Every third-party action in the workflows is pinned to a commit SHA, with its tag in a comment
    (#59).
  • Every accessibility scan checks that reduced motion is on and waits for animations to settle
    before it audits the page (#92).
  • CodeRabbit no longer reviews every pull request on its own, matching barakoCMS. Commenting
    @coderabbitai full review still asks for one (#60).

Fixed

  • Import a spreadsheet sends the file. The shared API client defaults to a JSON content type,
    and axios turned the upload form into JSON, so the analyze request reached the API with no file.
    The client now drops that default for any form body, so the browser sends multipart form data
    with its boundary. File uploads used to work around this on their own request and now rely on the
    same rule (#119).

Image: ghcr.io/baryodev/barako-brew:1.2.0, linux/amd64 and linux/arm64. Also pushed as ghcr.io/baryodev/barako-admin:1.2.0 until 2.0.0.