-
Notifications
You must be signed in to change notification settings - Fork 0
Routes and Features
homepage with dynamic latest feed, latest journal, and music cards.
- list/search/paginate feed posts from
data/feed/*.txt - feed and journal pagination measures the available content width to show as many background-free page controls as fit on one line, expanding across the row only when enough pages exist to fill it and otherwise shrink-wrapping at the center; it retains previous/next, first/last, current-page context, and ellipses across remaining gaps, while selecting a page pins the viewport to the bottom through delayed image loading and layout changes
- create visibility depends on admin or
allowedPagescontainingfeed - create composer supports recorded voice notes; accepted recordings request browser noise suppression, echo cancellation, and auto gain when available, are previewed before posting, capped at 2 minutes, transcoded to compressed
.m4a, stored underdata/audio/voice/, and played with inline controls that include a1x/1.5x/2xspeed toggle - the attach-media control keeps the existing URL-or-upload flow and accepts images, audio, and video; uploaded audio uses the voice-note player, while uploaded video uses a compact native player; file-extension detection covers mobile file providers that omit the browser MIME type, while the server still verifies the media container before saving it
- the first time a browser submits a new feed post, an in-site popup asks whether to enable browser notifications for replies
- deleting a feed post removes voice note files referenced by the post body and its replies
- writes derived
index.toml -
@mentionsin BBCode are highlighted client-side for notification-aware feed posts - plain YouTube, Vimeo, and Dailymotion video URLs render as responsive embedded players and the original link text is hidden; URLs inside any rendered BBCode element remain unchanged
Related:
/feed/create/feed/edit/feed/posts/{id}
- requires admin or
allowedPagescontainingfeed - hardcoded
toastsees a Groq-powered post generator before the BBCode editor - Toast generation can be random or prompt-guided, uses already-published non-Toast feed posts only as weak text style samples, has a 5-step length slider from one-liner to trauma dump, then fills and unlocks the editor
- if a non-Toast post mentions
@toast, Toast may automatically add a reply to that post using the post as context after a 1 minute delay
- single-post thread view for a feed item
- logged-in users can reply to the post or to an individual comment with BBCode, image/audio/video uploads, and recorded voice notes using the same inline speed-toggle playback controls
- guests can reply to the post or to an individual comment without creating feed posts; they are identified by plaintext IP, may enter an optional display name that falls back to italic
Anonymous, cannot use a registered account username as that display name, can link media but cannot upload files or voice notes, and do not get heading or tooltip BBCode controls; guest display names and reply bodies are filtered through/feed/filters/*.txt, matching body text is replaced with★plus the tooltipthis phrase was automatically filtered., and the BBCode preview shows the same filtering - the first time a browser submits a comment, an in-site popup asks whether to enable browser notifications for replies to comments
- guest replies that are mostly filter-list terms are rejected, and guest replies containing filtered text cannot be edited by guests after posting
- reply edit/delete is allowed for the reply author, same-IP guest replies, admins, the original post owner, or accounts with
allowedPagescontainingcomments - replies persist under
data/feed/replies/{postId}.json; comment replies stay in the same flat list with optionalparentIdmetadata and render directly beneath their parent comment - guest replies can store a same-browser notification token so logged-out visitors can receive browser notifications when someone replies to their comments
- deleting a reply removes voice note files referenced by that reply
- admin IP moderation actions appear beside guest reply edit/delete icons; admins can ban an IP or purge guest replies by exact plaintext IP without deleting the feed post or changing the IP ban list
- when a non-Toast user replies to a Toast-owned post or mentions
@toastin a reply, Toast may automatically reply after a 1 minute delay with a short old-style Twitter-sized response and starts by mentioning that user
- list/search/paginate journal posts from
data/journal/*.txt - create visibility depends on admin or
allowedPagescontainingjournal - published journal bodies are trusted HTML
- preview/edit flows support draft files and optional
FORMAT:html - the journal BBCode composer uses the same attach-media URL/upload flow and media rendering as feed posts; its eye button toggles an inline preview so pending image uploads can be right-clicked and drag-cropped before saving or publishing
- plain YouTube, Vimeo, and Dailymotion video URLs render as responsive embedded players in previews and published posts; URLs contained by BBCode-generated HTML elements remain unchanged
Related:
/journal/create/journal/create/preview/journal/edit/journal/edit/preview/journal/posts/{id}
- list entries from
data/guestbook/*.txt - one-post-per-IP gate via
data/guestbook/ip_index.json - new entries store an
IP:metadata line; IPs in the shared feed ban list cannot submit guestbook posts - owner/admin edit and delete flow
- admins can ban an entry IP or password-confirm a purge of both feed replies and guestbook posts associated with that IP
Related:
/guestbook/create/guestbook/edit
- builds album grids from
data/music/frdg3/*.jsonanddata/music/cactile/*.json - songs reference
data/audio/* - integrates with the shared mini player; album and other multi-track release clicks open an on-site popup track picker, while single-track releases play directly
- admins see upload buttons for each artist;
/music/uploadsaves audio files todata/audio/and creates release JSON in that artist'sdata/music/{artist}/folder -
/music/uploadsupportssingle,remix, andalbumrelease types; all release types can add multiple track rows and reorder them before saving, can optionally set a scheduled publish date/time, and release order is assigned automatically from the current highest order for the selected artist
- paginated listing of
data/images/*; the grid lazily loads cached, center-cropped 500×500 JPEG thumbnails generated with PHP GD or ffmpeg, while the image viewer loads the original full-resolution file only after a thumbnail is clicked - gallery pagination uses the same adaptive, bottom-pinned single-line control as feed, journal, and guestbook
- admin delete actions call
/api/gallery/delete
- their static
content.htmlpost-card lists are discovered automatically and split into pages of at most 10 cards - when more than one page exists, both listings use the shared adaptive paginator and bottom-position preservation
- server-rendered bookmark listing for logged-in users
- client-side localStorage enhancement for anonymous users
- supports feed and journal bookmark ids; legacy
newsletter:*ids are ignored
- displayed as
serverless upload; the route remains stable for existing transfer links - browser-to-browser encrypted file transfer using WebRTC data channels
- accounts with
postingRestrictedand clients on the shared banned-IP list cannot create, join, or signal upload rooms; the page disables its controls and every API action independently enforces the restriction - PHP stores only short-lived room/signaling metadata under
data/upload/rooms.json; uploaded file bytes are never stored server-side - creating a room chooses whether the creator is the sender or receiver, then produces a
/tools/upload/?r={token}share link - access is limited to the creator browser plus the first guest browser through the HttpOnly
fridg3_upload_peercookie; later browsers receiveroom_full - peers exchange ephemeral ECDH public keys through signaling and encrypt file chunks with AES-GCM before sending
- plaintext chunks are kept below WebRTC's common 64 KiB message edge after encryption overhead to avoid truncated or dropped data-channel frames
- sender and receiver compute a streaming SHA-256 checksum; the receiver only sends the success ack when file size, chunk count, and checksum match
- enforces a 100 GB client-side file limit; browsers with File System Access API support stream received chunks to disk, while fallback browsers download after completion
- both peers see transfer progress; sender progress reaches 100% only after the receiver confirms completion, and receiver progress reaches 100% after the file is written or downloaded, so either side can close the page once their bar is full
- rooms end when either peer closes the tab via a close beacon, with a short heartbeat timeout fallback for crashed or disconnected tabs
- UI shell only
- persistence handled by
/api/settings - changing a settings control marks the page dirty; link navigation to another page uses an in-site confirmation popup whose primary action saves before continuing, while saving and refreshing the current page never prompt
- successful saves briefly change the main button label to
saved!; theme or mobile-view changes then reload automatically using the newly persisted preference - includes accessibility toggles for mobile view and reduced motion, notification toggles for feed events and new journal posts, plus theme selection, a text glow toggle, optional cursor cat, and an in-site title-animation picker with live previews, always-playing mode, and default-on character desync
- title animation controls and previews are disabled with an explanatory message whenever reduced motion or mobile view is active; mobile view also disables the title gradient
- browser notifications use the Notification API while the site is open; logged-in users can receive feed mention/reply events matching Toast Discord feed DMs, guests can receive replies to comments made from the same browser, and both can receive new journal post alerts; logged-in notification events are deduped server-side so a fresh browser login does not replay old matching events
- developer mode can bootstrap a blank-password
admin/Administratoraccount when no admin accounts exist, and can download the latest sanitized developer data zip, delete localdata/, and install the new copy - shows a Discord linking action for logged-in users and disables it once
discordUserIdis already linked - when logged in as hardcoded
toast, shows a JSON editor for shared Toast personalities stored indata/etc/toast-personality.json - admins can open a dedicated system diagnostics subsection in
/settingsto jump into/settings/sysinfo - admins can open
/settings/guests, labeled as manage guests, to review guest feed replies and IP-backed guestbook posts grouped by IP, search by IP or username, individually delete either content type, ban or unban IPs across both posting surfaces, or purge all guest content from an IP after password confirmation - admins can open
/settings/banned-ipsto edit the separate hard-ban IP list; valid IPv4 and IPv6 addresses may be separated by spaces or newlines, and nginx redirects matching clients away from all pages and static files to/error/blacklisted; the access debug log also supports right-click hard-ban and exact-IP whitelist actions; whitelist entries override manual, source-list, and identity hard bans; a durable first-party browser identifier carries an active ban to later IPs, while removing the original manually banned IP releases its associated IPs - admins can open
/settings/noticesto independently create or clear banner and one-time popup notices for logged-in users and guests, globally or for one exact page path; page-notice audience checkboxes allow logged-in users, guests, or both, page notices override the matching global notice type on that page, banners may be dismissible, popups can include a site-relative custom-link button, and every editor section is collapsible and closed by default -
/error/blacklistedreturns the stripped Blackprint denial page only to an actively hard-banned IP or associated browser identity; other direct visitors receive a server-side redirect to/ - admins can open
/settings/sysinfoto see live system diagnostics, PHP/runtime details, storage usage, website state, and key content counts in a dashboard-style view
currently just redirects:
- logged in ->
/ - logged out ->
/account/login
- secure session config
- CSRF protection
- login throttling via
data/accounts/login_attempts.json - reads
data/accounts/accounts.json - sets session user payload and
is_admincookie - session cookies use the
fridg3_sessionname, last 90 days, useSameSite=Lax, and are shared acrossfridge.dev,www.fridge.dev,m.fridge.dev, and other*.fridge.devhosts so mobile/desktop host switches do not look like a logout - successful login/logout clears the legacy
PHPSESSIDcookie on both the shared domain and current host so stale host-only cookies cannot shadow the shared session - username
toastis reserved for a hardcoded virtual account; it prompts for admin credentials, then logs in as non-admin Toast with fixedfeedandcommentspermissions - users with
mustResetPasswordare redirected into the password-change flow before using the rest of the site
destroys session and auth cookies, then redirects back to login.
admin-only account creation flow that writes to data/accounts/accounts.json.
- can seed
discordUserId - can seed an optional
emailAddressfor fridge.dev mailboxes - can grant
commentsandchatpermissions - can create the account with
postingRestrictedalready enabled - newly created accounts are flagged with
mustResetPassword - username
toastis reserved and cannot be created as a normal account - if a Discord id is provided, it asks the local toast bot to DM the invite credentials
- if that DM fails, the account is still created and the UI now shows the bot's concrete failure reason instead of a generic HTTP 500
- local dev mode shows a random dev-account generator that creates
userXXXX/User #XXXXwith feed/comment permissions, a blank password, no forced password reset, and no Discord invite
both update the current user password hash in accounts.json.
- first-login forced password reset lands here via
?first_login=1
- logged-in-only Discord linking flow
- validates the Discord user id, checks uniqueness across accounts, and asks the local toast bot to verify the member is in the server
- stores
discordUserIdon the account and assigns the Discordregisteredrole through the bot
not covered in the older references, but very real.
- admin-only account directory
- reads all accounts and renders permission badges
- links to per-account edit page
- admin-only account editor
- supports rename, display-name change, optional
emailAddress, permission changes, reset password, and delete - delete confirmation plays a centered rip-in-half account card animation before the destructive POST continues
- the
purge user contentdanger button must purge all user-owned content; currently this includes feed posts, attached images, voice notes, and reply data - preserves unknown extra account fields through an editable JSON object field
- blocks deleting the currently logged-in account
- includes
commentsandchatas grantableallowedPagespermissions - includes a
restricted from postingcheckbox backed bypostingRestricted; restricted accounts retain their page permissions and deletion/moderation access, but cannot create or edit posts, replies, chat messages, or guestbook entries - password resets now preserve the account and flip
mustResetPasswordback on
Helpers live in account/admin/helpers.php.
- shows fridge.dev email web-client and custom-client setup details
- if the logged-in account has a valid
emailAddress, the page shows that assigned fridge.dev address near the top - shared shell rendering swaps the footer Discord button to this route only for accounts with a valid
emailAddress
one-time private conversation manager.
- requires admin or
allowedPagescontainingchat - creates conversations with a recipient label
- lists active conversation files from
data/chat/*.json - shows canonical share links shaped like
https://fridge.dev/chat/{conversationId}that copy to clipboard when clicked - can end a conversation through an in-site confirmation popup, which deletes the encrypted JSON file immediately
one-to-one conversation view.
- managers can open without claiming recipient access
- the first non-manager visitor sees a concise chat invite/auth page and receives an HttpOnly recipient cookie
- the recipient's first full chat view shows an in-site security/help popup explaining browser/account locking, encrypted storage, replies, and reactions
- later visits from that browser are allowed through
- if the recipient is logged into an account when they open an unclaimed invite, the chat links to that account instead of a browser cookie
- logged-in recipients with an active linked chat get a sidebar button above the mini-player/sidebar footer and can delete that chat themselves
- other browsers without the matching cookie get a custom access-denied page
- if the backing file is deleted, returning recipients see the ended-conversation page
- messages are stored inside the encrypted per-conversation JSON envelope under
data/chat - image/file attachments up to 8 MB are stored as encrypted per-chat blobs and served only after chat access checks
- the composer
+menu supports file upload or recording a voice note; voice notes are previewed before send, capped at 2 minutes, transcoded to compressed.m4a, and stored as encrypted chat attachments - selecting an attachment shows an attached-file indicator before send; image attachments use the site image viewer, while audio, voice, and video attachments embed with custom themed playback controls inside the chat; audio/voice controls include the
1x/1.5x/2xspeed toggle - messages can visually reply to a previous message, and clicking/tapping a message opens reply/react/delete actions; message deletion uses an in-site confirmation popup, and deleted messages stay in place as dimmed
message deletedplaceholders - reactions are emoji-based, searchable from the message context menu or the desktop-only emoji button beside the composer; the picker loads Emoji 16 Emojibase data from jsDelivr, lazy-renders results as users search/scroll, supports typed or pasted emoji from the search box, and falls back to a tiny local set if unavailable
- both sides send active/away presence heartbeats plus short-lived typing state, and the page live-polls whether the other side is online, away, or offline while showing a non-layout-shifting typing indicator inside the message box
- message sends update the current page immediately, and open chat pages poll for new messages; unfocused/hidden chat tabs play
/chat/alert.oggand prefix the page title with an unread count when the other side sends new messages - message timestamps show time only, with a date divider inserted at the first message for each day
- accounts with
postingRestrictedand clients on the shared banned-IP list cannot submit the public form; the server enforces the restriction and the form renders with its controls disabled - public contact form with name, email, message, and server-side anti-spam checks
- replies are sent manually from
me@fridge.dev - accepted submissions are stored under
data/contact/*.json - after storage, PHP asks the local toast service to send a Discord channel notification
- admin-only contact submission dashboard
- lists submissions newest-first
- supports permanent delete
Retired legacy paths:
-
/emailand/email/*redirect to/contactin nginx - newsletter and mailing-list routes have been removed
simple wrapper page for the Discord community entry point.
simple wrapper page for merch links/content.
misc landing page for routes that do not fit elsewhere.
Subroutes:
/others/firefox-theme/others/off-topic-archive/others/toast-discord-bot/others/fridge-builds-websites
- public page for the fridge.dev blackprint Firefox theme
- explains the two-step install flow: install the signed theme from Mozilla Add-ons, then run the local userChrome setup for square chrome styling
-
build-downloads.shrefreshes the downloadable userChrome setup package and the AMO-ready source zip - the userChrome setup package extracts to a
fridg3-firefox-userchromefolder containinguserChrome.css,install-linux.sh,install-windows.bat, andinstall-windows.ps1 - userChrome setup scripts prompt for install/update or uninstall; uninstall removes only the fridge.dev profile CSS file and import line
-
userChrome.cssremains outside the add-ons upload package because Firefox WebExtension themes cannot install profile chrome stylesheets
developer-facing documentation rendered from Markdown files in /wiki/.
- uses the site shell while hiding normal navigation so the docs can use a full-height two-column layout
- sidebar ordering follows
_Sidebar.md, with any extra Markdown pages appended after the listed pages - renderer supports headings, paragraphs, links, inline code, fenced code blocks, blockquotes, horizontal rules, and simple ordered/unordered lists
- blackprint-specific styling lives in
wiki/content.html, with a sticky sidebar, constrained reading width, themed code blocks, and a compact mobile page grid
tools and utilities landing page.
Subroutes:
/tools/mdpaste
Any current or future tool that creates, uploads, or shares user content must enforce both the account postingRestricted flag and the shared data/feed/banned_ips.json list in every write/API handler. Disabled controls and notices are only the UI layer and must not be the sole enforcement. Read-only tool pages may remain available.
standalone markdown paste service for sharing notes without exposing a whole vault.
- accepts pasted markdown or client-loaded
.md/.txtfiles - live previews markdown before publishing
- supports normal markdown images plus Obsidian-style
![[image.png]]embeds that point at/data/images - optional hard-break mode keeps single line breaks in formatted paragraphs
-
POST /tools/mdpaste/writes temporary paste JSON underdata/mdpaste - accounts with
postingRestrictedand clients on the shared banned-IP list cannot create pastes; the editor controls are disabled and the JSON endpoint independently returns403 - optional password mode encrypts the markdown with AES-256-GCM before storage
- shared links render from
/tools/mdpaste/s/{pasteId} - pastes expire after 30 days
frontend archive viewer backed by data/etc/off-topic-archive.json.
UI shell for toast bot status, controls, and stream playback.
The bot also exposes localhost-only service endpoints on 127.0.0.1:8765, including contact submission notifications to Discord channel 1503931489560301609.
It also scans /feed activity for linked Discord accounts and sends DMs for post mentions, reply mentions, and replies to a user's own feed posts.
It also receives deploy-time patch notices, posts the fully formatted patch notice preview to approval channel 1526075637096255548, and posts to update channel 1455194403642802309 with role 1408064850688475197 only after an admin approves with ✅. Pending approvals survive bot restarts, and reactions on older uncached Toast approval messages are handled as well.
Admins can also use /shareupdate latest or /shareupdate <commit ID> in Discord to manually post a patch notice for the deployed HEAD commit or a specific commit SHA.
- admin-only DM inbox/sender for toast with a thread inbox and full-page conversation view with a back button
- renders through the normal site template and mobile/desktop theme selection instead of a standalone Discord-style shell
- reads tracked DM history, resolves linked website usernames to Discord ids, and can send outbound DMs through the local bot service
- inbound user DMs are logged and can receive Groq-powered Toast replies using the local
personality.json; when users ask about fridge.dev, the bot can include small relevant snippets from the wiki and explain them in plain language - rapid inbound DMs from the same user are batched into one AI prompt; if Toast is still generating or pacing an unsent reply chunk when another DM arrives, it cancels the unfinished reply and regenerates from the queued messages
- admins can toggle an "air them" state per thread; aired users are still logged, but Toast does not generate AI replies for them
- if the Discord user is linked to a fridge.dev account, AI replies also receive compact context from that account's own recent feed posts and replies
- image and GIF DMs are sent to Groq's configured vision model as Discord attachment URLs, capped at 5 images and 20 MB per image
- AI replies are split into natural 2-4 sentence chunks and wait at least 5 seconds before each chunk is sent
- a user can send exactly
CLEARMEMORYin DM to make Toast react and ignore older DM history for future AI context - AI replies are also told about Toast's non-chat duties: radio playback, slash-command radio controls, account-linking support, and automated notification DMs
- AI replies are given an exact slash-command allow-list so website paths like
/feedare not described as Discord commands - guild messages and notification DMs do not trigger AI replies
wrapper/marketing page for custom website work. this exists in code even though the older docs mostly ignored it.
/formatting/formatting/example_page/error/403/error/404/error/50x/error/wip