removed kanban from gitignore
This commit is contained in:
parent
e96b8e5563
commit
ffab9dc4da
28 changed files with 522 additions and 1 deletions
13
kanban/tasks/001-pixabay-api.md
Normal file
13
kanban/tasks/001-pixabay-api.md
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
---
|
||||
id: 1
|
||||
title: pixabay api
|
||||
status: backlog
|
||||
priority: high
|
||||
created: 2026-07-15T14:55:51.243108541+02:00
|
||||
updated: 2026-07-15T14:56:56.735673124+02:00
|
||||
tags:
|
||||
- search
|
||||
class: standard
|
||||
---
|
||||
|
||||
Add Pixabay api as search engine
|
||||
13
kanban/tasks/002-pexels-api.md
Normal file
13
kanban/tasks/002-pexels-api.md
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
---
|
||||
id: 2
|
||||
title: Pexels api
|
||||
status: backlog
|
||||
priority: high
|
||||
created: 2026-07-15T14:58:10.597616484+02:00
|
||||
updated: 2026-07-15T14:58:27.252246225+02:00
|
||||
tags:
|
||||
- search
|
||||
class: standard
|
||||
---
|
||||
|
||||
Use pexels api as a seach engine
|
||||
13
kanban/tasks/003-random-words.md
Normal file
13
kanban/tasks/003-random-words.md
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
---
|
||||
id: 3
|
||||
title: random words
|
||||
status: backlog
|
||||
priority: high
|
||||
created: 2026-07-15T15:00:10.530100379+02:00
|
||||
updated: 2026-07-15T15:00:10.530100379+02:00
|
||||
tags:
|
||||
- search
|
||||
class: standard
|
||||
---
|
||||
|
||||
random word version (https://random-words-api.kushcreates.com/)
|
||||
13
kanban/tasks/004-search-for-original-images.md
Normal file
13
kanban/tasks/004-search-for-original-images.md
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
---
|
||||
id: 4
|
||||
title: search for original images
|
||||
status: backlog
|
||||
priority: low
|
||||
created: 2026-07-15T15:02:31.107843015+02:00
|
||||
updated: 2026-07-15T15:02:43.402550141+02:00
|
||||
tags:
|
||||
- search
|
||||
class: standard
|
||||
---
|
||||
|
||||
input number and search for a fresh photo with a camera filename like 'img####.jpg'
|
||||
14
kanban/tasks/005-image-processing.md
Normal file
14
kanban/tasks/005-image-processing.md
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
---
|
||||
id: 5
|
||||
title: image processing
|
||||
status: backlog
|
||||
priority: critical
|
||||
created: 2026-07-15T15:13:21.131166647+02:00
|
||||
updated: 2026-07-17T03:51:00.175266589+02:00
|
||||
started: 2026-07-15T15:23:14.91034394+02:00
|
||||
tags:
|
||||
- image_processing
|
||||
class: standard
|
||||
---
|
||||
|
||||
Put back the original image processing from the old Zap Machine
|
||||
14
kanban/tasks/006-full-screen-gui.md
Normal file
14
kanban/tasks/006-full-screen-gui.md
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
---
|
||||
id: 6
|
||||
title: full screen gui
|
||||
status: backlog
|
||||
priority: critical
|
||||
created: 2026-07-15T15:15:54.325695132+02:00
|
||||
updated: 2026-07-17T03:50:56.343336322+02:00
|
||||
started: 2026-07-15T15:23:07.894599552+02:00
|
||||
tags:
|
||||
- gui
|
||||
class: standard
|
||||
---
|
||||
|
||||
Full screen GUI with the collage covering the background and a partly transparen control panel and feedback screen on the right
|
||||
14
kanban/tasks/007-ai-generated-images-for-input.md
Normal file
14
kanban/tasks/007-ai-generated-images-for-input.md
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
---
|
||||
id: 7
|
||||
title: ai generated images for input
|
||||
status: backlog
|
||||
priority: medium
|
||||
created: 2026-07-15T15:17:54.953039352+02:00
|
||||
updated: 2026-07-15T15:17:54.953039352+02:00
|
||||
tags:
|
||||
- search
|
||||
- source
|
||||
class: standard
|
||||
---
|
||||
|
||||
use a scraper (brightdata) or write one ourselves to scrape for ai genarated images as sources
|
||||
14
kanban/tasks/008-automatic-mode.md
Normal file
14
kanban/tasks/008-automatic-mode.md
Normal file
|
|
@ -0,0 +1,14 @@
|
|||
---
|
||||
id: 8
|
||||
title: automatic mode
|
||||
status: backlog
|
||||
priority: medium
|
||||
created: 2026-07-15T15:20:29.075465548+02:00
|
||||
updated: 2026-07-15T15:20:29.075465548+02:00
|
||||
tags:
|
||||
- gui
|
||||
- mode
|
||||
class: standard
|
||||
---
|
||||
|
||||
if one or more people are watching automatically generate a zap layer every 21 seconds
|
||||
13
kanban/tasks/009-framework-guide.md
Normal file
13
kanban/tasks/009-framework-guide.md
Normal file
|
|
@ -0,0 +1,13 @@
|
|||
---
|
||||
id: 9
|
||||
title: framework guide
|
||||
status: done
|
||||
priority: critical
|
||||
created: 2026-07-15T15:22:18.567355625+02:00
|
||||
updated: 2026-07-17T02:16:52.6730631+02:00
|
||||
started: 2026-07-15T15:22:33.367755161+02:00
|
||||
completed: 2026-07-17T02:16:52.676581649+02:00
|
||||
class: standard
|
||||
---
|
||||
|
||||
add the usage of the framework in the README. How does this framework work, how to add templates with interactive elements
|
||||
16
kanban/tasks/010-check-framework.md
Normal file
16
kanban/tasks/010-check-framework.md
Normal file
|
|
@ -0,0 +1,16 @@
|
|||
---
|
||||
id: 10
|
||||
title: check framework
|
||||
status: done
|
||||
priority: high
|
||||
created: 2026-07-17T02:16:23.059189291+02:00
|
||||
updated: 2026-07-17T12:26:07.258170416+02:00
|
||||
started: 2026-07-17T12:26:07.265125164+02:00
|
||||
completed: 2026-07-17T12:26:07.265125164+02:00
|
||||
class: standard
|
||||
---
|
||||
|
||||
Check if the framework is the optimal, most simple and flexible way to go. If not: suggest some changes.
|
||||
|
||||
[[2026-07-17]] Fri 03:25
|
||||
Framework review committed: docs/framework_review.md (commit 2f61b07). Verdict: architecture is simple/flexible (zero-config routing, autoloader, Search plugin interface, native templates) — keep as-is. Not optimal due to 3 P0 correctness bugs (Brave size/offset params never sent because setQuery builds URL before setParam; query double-URL-encoded; autoloader hardcodes ':' vs PATH_SEPARATOR), P1 config/security (ZAP_DEBUG=true & placeholder key committed, no CSRF, die() routing, unsafe reset.php, second-resolution session folder collisions), P2 consistency. NO source edits — deliverable is docs-only. Includes recommended-task table for follow-up fixes (each independently approvable). Handing to review for Fabian's approval before any code changes.
|
||||
|
|
@ -0,0 +1,22 @@
|
|||
---
|
||||
id: 11
|
||||
title: 'Fix Brave request building: lazy URL + single encode'
|
||||
status: review
|
||||
priority: high
|
||||
created: 2026-07-17T03:57:00.444816503+02:00
|
||||
updated: 2026-07-17T12:26:38.759875442+02:00
|
||||
tags:
|
||||
- search
|
||||
- bug
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md). Two-part fix in resource/Brave.class.php + lib/ImgSearch.class.php:
|
||||
1. Move URL construction from setQuery() to getData() so setParam('start'/'size') values are applied (currently size defaults to 3 instead of 16, offset is never sent).
|
||||
2. Remove double urlencode: ImgSearch passes urlencode(word) into Brave::setQuery which urlencodes again → %2520 for spaces. Fix: pass raw word from ImgSearch; engine owns encoding.
|
||||
|
||||
[[2026-07-17]] Fri 12:26
|
||||
P0-1: Moved URL construction from setQuery() to new buildRequest() called from getData() — size/offset now use setParam() values (resource/Brave.class.php). P0-2: Removed urlencode() call from ImgSearch::getImageData() — raw word passed to engine, single encode in Brave (lib/ImgSearch.class.php). Both pass php -l.
|
||||
|
||||
[[2026-07-17]] Fri 12:26
|
||||
P0-1 + P0-2 implemented. Changes to resource/Brave.class.php and lib/ImgSearch.class.php. Both pass php -l. Ready for your commit.
|
||||
|
|
@ -0,0 +1,20 @@
|
|||
---
|
||||
id: 12
|
||||
title: 'Fix autoloader: use PATH_SEPARATOR instead of hardcoded '':'''
|
||||
status: review
|
||||
priority: high
|
||||
created: 2026-07-17T03:57:06.82901804+02:00
|
||||
updated: 2026-07-17T12:27:53.056263524+02:00
|
||||
tags:
|
||||
- framework
|
||||
- bug
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md). conf/init.php uses explode(':', get_include_path()) but the include path separator is ':' on Unix and ';' on Windows. Makes the autoloader fail on Windows. Fix: explode(PATH_SEPARATOR, get_include_path()).
|
||||
|
||||
[[2026-07-17]] Fri 12:27
|
||||
Changed explode(':', ...) to explode(PATH_SEPARATOR, ...) in conf/init.php. PHP passes php -l.
|
||||
|
||||
[[2026-07-17]] Fri 12:27
|
||||
P0-3 fixed. One-line change in conf/init.php. Ready for your commit.
|
||||
|
|
@ -0,0 +1,19 @@
|
|||
---
|
||||
id: 13
|
||||
title: 'Config hygiene: ZAP_DEBUG=false, secrets in git-ignored local file, sessions perms'
|
||||
status: done
|
||||
priority: medium
|
||||
created: 2026-07-17T03:57:13.88777683+02:00
|
||||
updated: 2026-07-17T22:27:10.989415474+02:00
|
||||
started: 2026-07-17T22:27:10.994979516+02:00
|
||||
completed: 2026-07-17T22:27:10.994979516+02:00
|
||||
tags:
|
||||
- security
|
||||
- config
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P1-1. conf/conf.php is git-tracked and ships with ZAP_DEBUG=true, BRAVE_API_KEY='your api key' placeholder. Fixes:
|
||||
- Default ZAP_DEBUG=false in committed conf.php
|
||||
- Add git-ignored conf/conf.local.php loaded by init.php if present, for secrets
|
||||
- Tighten sessions/ permissions from 777 to 770 (or document webserver-user group)
|
||||
17
kanban/tasks/014-add-csrf-protection-to-word-input-form.md
Normal file
17
kanban/tasks/014-add-csrf-protection-to-word-input-form.md
Normal file
|
|
@ -0,0 +1,17 @@
|
|||
---
|
||||
id: 14
|
||||
title: Add CSRF protection to word-input form
|
||||
status: done
|
||||
priority: medium
|
||||
created: 2026-07-17T03:57:20.699057952+02:00
|
||||
updated: 2026-07-19T21:23:27.817959707+02:00
|
||||
started: 2026-07-19T21:23:27.819406405+02:00
|
||||
completed: 2026-07-19T21:23:27.819406405+02:00
|
||||
tags:
|
||||
- security
|
||||
claimed_by: rain-raven
|
||||
claimed_at: 2026-07-19T21:23:27.817959707+02:00
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P1-2. tpl/index.tpl POSTs to mode=display which writes session state and triggers image downloads. No CSRF token means a cross-site request can drive the machine. Fix: add session-bound CSRF token to the form, validate in ZAPDisplay.
|
||||
|
|
@ -0,0 +1,17 @@
|
|||
---
|
||||
id: 15
|
||||
title: Replace die('Wrong parameter') with proper 404/error handler
|
||||
status: done
|
||||
priority: medium
|
||||
created: 2026-07-17T03:57:28.297533467+02:00
|
||||
updated: 2026-07-19T20:20:20.011896223+02:00
|
||||
started: 2026-07-19T20:20:20.013282064+02:00
|
||||
completed: 2026-07-19T20:20:20.013282064+02:00
|
||||
tags:
|
||||
- framework
|
||||
claimed_by: rain-raven
|
||||
claimed_at: 2026-07-19T20:20:20.011896223+02:00
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P1-3. ZAPController::__construct() calls die('Wrong parameter') when an unknown mode is given — no HTTP status, no HTML, and the polling onerror contract expects ERROR_PREFIX HTML. Fix: return a proper 404 response (or brand error page via ZAPError handler). Also consider mode allowlist.
|
||||
23
kanban/tasks/016-fix-and-secure-cli-scripts-reset-php.md
Normal file
23
kanban/tasks/016-fix-and-secure-cli-scripts-reset-php.md
Normal file
|
|
@ -0,0 +1,23 @@
|
|||
---
|
||||
id: 16
|
||||
title: Fix and secure cli_scripts/reset.php
|
||||
status: done
|
||||
priority: medium
|
||||
created: 2026-07-17T03:57:35.272402311+02:00
|
||||
updated: 2026-07-19T20:09:41.987393047+02:00
|
||||
started: 2026-07-19T20:09:41.988806323+02:00
|
||||
completed: 2026-07-19T20:09:41.988806323+02:00
|
||||
tags:
|
||||
- cli
|
||||
- security
|
||||
claimed_by: rain-raven
|
||||
claimed_at: 2026-07-19T20:09:41.987393047+02:00
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P1-4. cli_scripts/reset.php has multiple issues:
|
||||
- Case mismatch: glob('./Sessions/*') vs actual 'sessions/' directory → no-op on case-sensitive FS
|
||||
- No auth/CSRF: bare $_GET['allcollages'] == 'clear' triggers destructive unlink/rmdir
|
||||
- If web-accessible it's an unauthenticated destructive endpoint
|
||||
- Misplaced in cli_scripts/ (uses $_GET like a web script)
|
||||
Fix: correct path, add CLI guard (php_sapi_name()), gate destructive branch behind confirmation.
|
||||
|
|
@ -0,0 +1,17 @@
|
|||
---
|
||||
id: 17
|
||||
title: Make session folder names unique, stop suppressing mkdir errors
|
||||
status: done
|
||||
priority: medium
|
||||
created: 2026-07-17T03:57:50.884126062+02:00
|
||||
updated: 2026-07-19T19:06:58.837663313+02:00
|
||||
started: 2026-07-19T19:06:58.839287746+02:00
|
||||
completed: 2026-07-19T19:06:58.839287746+02:00
|
||||
tags:
|
||||
- session
|
||||
claimed_by: rain-raven
|
||||
claimed_at: 2026-07-19T19:06:58.837663313+02:00
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P1-5. ZAP_MOMENT = date('Y-m-d-H_i_s') has second resolution. Two submissions in the same second collide on mkdir — suppressed with @, returns null folder, silently breaks all downstream operations. Fix: append random suffix to folder name, drop @, add recursive flag.
|
||||
|
|
@ -0,0 +1,18 @@
|
|||
---
|
||||
id: 18
|
||||
title: Introduce ZAPHandler interface for getContent()
|
||||
status: done
|
||||
priority: medium
|
||||
created: 2026-07-17T03:57:59.054256365+02:00
|
||||
updated: 2026-07-18T11:51:03.280085523+02:00
|
||||
started: 2026-07-18T11:51:03.281402582+02:00
|
||||
completed: 2026-07-18T11:51:03.281402582+02:00
|
||||
tags:
|
||||
- framework
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P1-7. Currently getContent() is convention-only — no interface enforces it. A handler missing the method fails at runtime, not definition time. Fix: create a ZAPHandler (or ModeHandler) interface with public function getContent(), implement it on all existing handlers, add instanceof check in ZAPController.
|
||||
|
||||
[[2026-07-18]] Sat 11:50
|
||||
Created ZAPHandler interface with getContent(), implemented on ZAPHome/ZAPDisplay/ZAPZap, added instanceof check in ZAPController::fetch().
|
||||
|
|
@ -0,0 +1,13 @@
|
|||
---
|
||||
id: 19
|
||||
title: Single source of truth for word count + cleanup handleWords
|
||||
status: todo
|
||||
priority: low
|
||||
created: 2026-07-17T03:58:05.365933671+02:00
|
||||
updated: 2026-07-17T03:58:05.365933671+02:00
|
||||
tags:
|
||||
- cleanup
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P2-1/2. MAX_WORDS drives the template loop but handleWords() independently re-scans POST. Also has / typo. Fix: iterate 1..MAX_WORDS in handleWords, clean up variable naming.
|
||||
|
|
@ -0,0 +1,13 @@
|
|||
---
|
||||
id: 20
|
||||
title: Consistent template rendering pattern across all handlers
|
||||
status: todo
|
||||
priority: low
|
||||
created: 2026-07-17T03:58:11.987251314+02:00
|
||||
updated: 2026-07-17T03:58:11.987251314+02:00
|
||||
tags:
|
||||
- cleanup
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P2-3. ZAPHome uses extract(get_object_vars()) (the documented pattern); ZAPDisplay does not — it manually declares local vars and accesses directly in the template. Pick one pattern (extract or explicit) and apply consistently.
|
||||
|
|
@ -0,0 +1,17 @@
|
|||
---
|
||||
id: 21
|
||||
title: Consolidate duplicated screen-size constants
|
||||
status: done
|
||||
priority: low
|
||||
created: 2026-07-17T03:58:20.43055577+02:00
|
||||
updated: 2026-07-19T21:49:54.332882291+02:00
|
||||
started: 2026-07-19T21:49:54.33435439+02:00
|
||||
completed: 2026-07-19T21:49:54.33435439+02:00
|
||||
tags:
|
||||
- cleanup
|
||||
claimed_by: rain-raven
|
||||
claimed_at: 2026-07-19T21:49:54.332882291+02:00
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P2-5. ImgIOTools and ImgTools both define $maxScreenWidth/$maxScreenHeight to the same values (1067/600). Drift risk. Consolidate into one place.
|
||||
|
|
@ -0,0 +1,19 @@
|
|||
---
|
||||
id: 22
|
||||
title: Fix convertGifsToPng extension + rename/fix log.xml
|
||||
status: done
|
||||
priority: low
|
||||
created: 2026-07-17T03:58:30.403935395+02:00
|
||||
updated: 2026-07-19T21:42:54.771387687+02:00
|
||||
started: 2026-07-19T21:42:54.772886896+02:00
|
||||
completed: 2026-07-19T21:42:54.772886896+02:00
|
||||
tags:
|
||||
- cleanup
|
||||
claimed_by: rain-raven
|
||||
claimed_at: 2026-07-19T21:42:54.771387687+02:00
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P2-6/7. Two small fixes:
|
||||
1. convertGifsToPng produces cat.gif.png (appends .png instead of replacing .gif) — confusing filenames.
|
||||
2. Log writes HTML fragments (<div class="type">) into log.xml — not valid XML. Rename to log.html or emit proper XML.
|
||||
|
|
@ -0,0 +1,19 @@
|
|||
---
|
||||
id: 23
|
||||
title: Anchor ZAP_APP_BASE_DIR to __DIR__, make getZAPTemplate throw
|
||||
status: done
|
||||
priority: low
|
||||
created: 2026-07-17T03:58:37.157613187+02:00
|
||||
updated: 2026-07-19T21:39:02.781954542+02:00
|
||||
started: 2026-07-19T21:39:02.783424942+02:00
|
||||
completed: 2026-07-19T21:39:02.783424942+02:00
|
||||
tags:
|
||||
- cleanup
|
||||
claimed_by: rain-raven
|
||||
claimed_at: 2026-07-19T21:39:02.781954542+02:00
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P2-8/9. Two fixes in conf/init.php:
|
||||
1. ZAP_APP_BASE_DIR = realpath('.'.DIRECTORY_SEPARATOR.'..') is cwd-dependent — breaks if entry point is not www/ or cli_scripts/. Use realpath(__DIR__ . '/..') instead.
|
||||
2. getZAPTemplate returns ERROR_PREFIX . 'No template' string on missing file instead of throwing — inconsistent with other error paths. Make it throw.
|
||||
|
|
@ -0,0 +1,17 @@
|
|||
---
|
||||
id: 24
|
||||
title: Refresh README (Yahoo→Brave, drop outdated roadmap, fix tone)
|
||||
status: done
|
||||
priority: low
|
||||
created: 2026-07-17T03:58:43.662424712+02:00
|
||||
updated: 2026-07-19T21:31:14.516637296+02:00
|
||||
started: 2026-07-19T21:31:14.51815456+02:00
|
||||
completed: 2026-07-19T21:31:14.51815456+02:00
|
||||
tags:
|
||||
- docs
|
||||
claimed_by: rain-raven
|
||||
claimed_at: 2026-07-19T21:31:14.516637296+02:00
|
||||
class: standard
|
||||
---
|
||||
|
||||
From framework review (docs/framework_review.md), P2-11. README.md still says 'the most relevant image that search engine Yahoo comes up with', tells Windows users 'Windows suck', and lists a roadmap that doesn't map to kanban. Refresh prose to match current state (Brave search, no Yahoo).
|
||||
Loading…
Add table
Add a link
Reference in a new issue