Commit Graph

24 Commits

Author SHA1 Message Date
Erik Thiele
11eb770c8b Add a collapsible Markdown cheat sheet to the prompt input
A short, native <details>/<summary> reference (no JS) next to the
hint text, listing the basic syntax the new markdown rendering
supports: headings, bold/italic, lists, quotes, inline code, code
blocks, links.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-30 14:55:59 +02:00
Erik Thiele
78c95b522d Add a Prompts library alongside Links, bump to v2.0.0
New /prompts section extends the existing database (new Prompt model,
same SQLite file) and mirrors the Links experience: add a prompt, get
it auto-categorized and tagged by AI, filter by category, full-text
search, sort, edit, or have the AI re-categorize it. A header nav
switch ("Links" / "Prompts") toggles between the two collections; the
shared topbar/menu markup was factored into _topbar.html and
_topbar_actions.html so both pages (and settings) stay in sync.

Each prompt card has a dedicated copy-to-clipboard icon next to
edit/delete, so a stored prompt can be reused immediately. Copying
uses the raw markdown source (not the rendered HTML) so structure
survives when pasted into another AI tool. The copy handler tries the
async Clipboard API first and falls back to a hidden-textarea +
execCommand('copy') for plain-http/non-secure contexts, with clear
success/failure icon feedback either way.

Prompt content supports Markdown and is rendered server-side
(app/mdrender.py) for the card preview. Since this is user-supplied
HTML-adjacent content, rendering goes through two defenses: the raw
text is escaped (only '<' and '&', not '>', so blockquotes keep
working) before conversion so no raw tag can survive, and the
resulting HTML is passed through bleach with a tag/attribute/protocol
allowlist so Markdown-generated links can't carry a javascript: URL.
Verified against raw <script>, <img onerror>, and javascript: link
payloads. The edit form always shows the raw Markdown source, never
the rendered HTML.

Also bumps the default APP_VERSION (shown in the footer) from 1.0.0
to 2.0.0 to mark this feature addition.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-30 14:45:30 +02:00
Erik Thiele
7262aee63d Add settings page with CSV export, SQL dump export/import
New /settings page (linked from the header's burger menu) offers:
- CSV export of the user's links, for spreadsheet apps.
- SQL dump export as INSERT INTO links (...) statements, scoped to
  the current user only — never a raw full-database dump, since that
  would leak other accounts' password hashes and data. Embeddings are
  excluded (regenerated via "KI neu beschreiben lassen" if needed).
- SQL import that re-adds a previously exported dump to the current
  account (additive, doesn't touch existing links).

Import safety (app/backup.py): uploaded SQL is never executed against
the real database. Each non-comment line is required to start with
"insert into links" and is run one statement at a time against an
isolated in-memory SQLite database with only a whitelisted `links`
schema (no id/user_id columns) — sqlite3.execute() also rejects
multiple statements per call. Only after that succeeds are rows
copied into the real DB via the ORM, with user_id forced to the
logged-in user. Verified this rejects DROP TABLE, ATTACH DATABASE,
stacked statements, cross-table subqueries, and user_id injection.
Upload is capped at 2 MB.

Also adds download/upload icons and a proper file-input styling
pattern (visually-hidden input + <label> trigger + filename readout),
since the browser's ::file-selector-button pseudo-element didn't
render reliably in testing.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-20 23:25:27 +02:00
Erik Thiele
4f99d51f9e Redesign header: theme toggle, user avatar, burger menu
The app was dark-only with the email shown as plain text and a bare
"Abmelden" button. Header now has:

- A light/dark theme toggle (sun/moon icon). Choice persists via
  localStorage and is applied before first paint (inline script in
  <head>) to avoid a flash of the wrong theme; falls back to the
  system preference on first visit. Added a light CSS variable set
  alongside the existing dark palette.
- A circular user icon (head-and-shoulders) showing the email as a
  tooltip, replacing the plain-text address.
- A burger-menu dropdown with the email, disabled placeholder items
  ("Tags verwalten", "Einstellungen" — marked "bald") to make room
  for future features, and the actual Abmelden action.

Dropdown opens/closes via a small vanilla-JS handler in base.html
(click outside or Escape closes it), consistent with the project's
no-build-step, mostly-HTMX frontend.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-20 23:01:22 +02:00
Erik Thiele
dca6033c40 Replace emoji icons with a monochrome SVG icon set
Emoji (📚 🔖 🏷️ ✎ ✕ 🕓  🤖 ⚠️ 🔍) rendered in each platform's own
colorful style and looked inconsistent. Add app/templates/_icons.html
with small inline SVG macros (Lucide-style, MIT-licensed path data,
stroke=currentColor) and use them throughout instead, so icons pick
up the muted/accent text colors like the rest of the UI.

The needs-review bookmark toggle now uses an outline vs. filled icon
for its two states instead of swapping emoji.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-20 22:50:52 +02:00
Erik Thiele
b6a236527e Add a "needs review" flag with a sidebar filter
Links can be bookmarked for a later look via a toggle button on the
card (🏷️/🔖), shown with a yellow border while flagged. A new
sidebar section "Merkliste" links to /?review=1, filtering to just
the flagged links; the count updates live via the existing facets
query.

Since the project has no migration framework, add a minimal
startup check that ALTER TABLEs in the needs_review column for
existing SQLite databases (create_all only creates missing tables).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-20 22:41:40 +02:00
Erik Thiele
8e9b49e57b Suggest existing categories/manufacturers when editing
The category and manufacturer fields in the edit form now offer the
already-used values via a datalist dropdown, while still allowing a
new value to be typed. Both edit entry points (open edit form and AI
re-describe) pass the current lists.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-20 22:13:08 +02:00
Erik Thiele
fdfddf8ccf Restyle link cards as a uniform tile grid
Cards previously had ragged heights because summaries vary in length.
Follow the community-scripts.org card pattern instead: fixed-height
title and summary blocks (clamped to 2 and 3 lines with an ellipsis),
a colored letter avatar derived from the domain, category and
manufacturer as badges in the header, tags in a single clipped row,
and domain plus added-date in a footer.

The avatar color is derived locally from the domain, so no external
favicon requests are made.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-20 15:34:27 +02:00
Erik Thiele
4d96dfb9ac Use full page width with a responsive link grid
The layout was capped at 1200px and listed links in a single column.
Drop the cap and lay the cards out in a grid: three per row on wide
screens, two from 1000px, one below that.

To make the narrower cards work, shorten the edit action to an icon
button so the title and URL keep their room, and let the edit form's
field and button rows wrap.

Also fixes pre-existing horizontal overflow on phone widths by
stacking the sidebar above the content and letting the add-link form
wrap. Grid tracks use minmax(0, 1fr) so cards can shrink below their
content's intrinsic width instead of pushing the page wider.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-20 14:56:42 +02:00
Erik Thiele
097125e7db Document editing, sorting, date display, and footer
The feature list was missing the recently added link editing, AI
re-description, sorting, and added-date display. Also document
APP_VERSION, which controls the version shown in the footer.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 22:06:40 +02:00
Erik Thiele
148074e24c Add sorting by date or name
Adds a sort dropdown offering newest/oldest first and name A-Z/Z-A.
Sorting applies to plain listings, text search, and semantic search
results, and the sidebar facet links preserve the current choice.
Invalid sort values fall back to the default.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 22:05:22 +02:00
Erik Thiele
6a35769943 Show the date a link was added
The created_at timestamp was already stored but never displayed. Add
a "datum" Jinja filter that converts the stored UTC value to local
time and render it on both the link card and the edit form.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 22:02:09 +02:00
Erik Thiele
a0db3e5147 Add link editing, AI re-description, and footer
Links can now be edited manually (title, summary, category,
manufacturer, tags) via an inline edit form, with a "KI neu
beschreiben lassen" action that re-fetches the URL and lets the AI
regenerate all fields. Editing recomputes the search embedding.

Also adds an app footer showing author, version, and hostname.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 21:54:01 +02:00
Erik Thiele
cc10776734 Fix 'dubious ownership' error in update script
pct exec runs as root while /opt/linkvault is owned by the linkvault
user, so newer git versions refuse to operate on it. Mark the
directory as safe before running git pull.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 20:45:20 +02:00
Erik Thiele
a1b12a3f77 Simplify install/update commands now that the repo is public
Drop the Authorization header/GIT_TOKEN requirement from the default
examples since the repo is no longer private; keep it documented as
a fallback for if the repo is made private again.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 20:43:48 +02:00
Erik Thiele
fade8928b6 Clarify local-checkout alternative for update script
Make explicit that the plain "bash scripts/proxmox/update-linkvault.sh"
form only works if the repo was cloned onto the Proxmox host itself and
you're running it from within that checkout — this was the cause of a
"No such file or directory" error when tried directly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 20:40:55 +02:00
Erik Thiele
39058d09e2 Fix update instructions: set GIT_TOKEN before curl call
The example was missing "export GIT_TOKEN=...", causing an empty
Authorization header when copy-pasted as-is.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 20:39:45 +02:00
Erik Thiele
0d2e33f899 Add update script for Proxmox LXC containers
Adds scripts/proxmox/update-linkvault.sh to pull the latest git
changes, refresh dependencies, and restart the systemd service on an
existing container. Documents usage in the README.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 20:33:14 +02:00
Erik Thiele
468f9872c1 Fix Proxmox script: detect debian-12 template dynamically
The hardcoded template version (12.7-1) no longer exists on the
mirror, causing "no such template" errors. Resolve the latest
available debian-12-standard template instead of pinning a version.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 19:34:08 +02:00
Erik Thiele
a7c5866a24 Support private repo access via Gitea token in Proxmox script
The repo is private, so unauthenticated curl/git clone returns 404.
Add GIT_TOKEN support for both the raw-file download and the git
clone inside the container, and document it in the README.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 19:29:42 +02:00
Erik Thiele
620f275595 Document Proxmox LXC installation in README
Add usage instructions, raw-link one-liner, config table, and
post-install steps for the helper script.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 19:14:58 +02:00
Erik Thiele
fc9033d89a Add Proxmox LXC helper-script for automated installation
Creates a Debian 12 LXC container and sets up LinkVault as a systemd
service inside it, following the tteck/community-scripts pattern.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-19 19:11:47 +02:00
Erik Thiele
47685f0d34 Initial commit: LinkVault – KI-gestützte Link-Sammlung
FastAPI + HTMX Web-App zum Speichern von Links mit automatischer
KI-Kategorisierung, Zusammenfassung und semantischer Suche (OpenAI).
Mehrbenutzer mit Login, SQLite-Persistenz, Docker/Docker-Compose-Setup.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-13 22:07:05 +02:00
Erik Thiele
ff8c9f5141 first commit 2026-07-13 22:02:55 +02:00