diff --git a/.gitignore b/.gitignore
index 532dbc8..8c12c70 100644
--- a/.gitignore
+++ b/.gitignore
@@ -1,4 +1,4 @@
sessions/*
-conf/conf.local.php
ignore
+kanban/
.pi-tasks
diff --git a/README.md b/README.md
index a1d4e21..36f1b16 100644
--- a/README.md
+++ b/README.md
@@ -10,34 +10,25 @@ www.apfab.com
Zap stands for 'Zapped Artificial Picture', a collage made from Internet images. A Zap translates a set of words or a text into an image which reflects the visual representation of the words on the Internet.
-This web application, Zap Machine, needs a number of words as input. It then takes the most relevant image that search engine Brave comes up with. After having collected all images the Zap Machine creates a given number of different collages from those images.
+This web application, Zap Machine, needs a number of words as input. It then takes the most relevant image that search engine Yahoo comes up with. After having collected all images the Zap Machine creates a given number of different collages from those images.
## installation
-First you need to run a server with PHP. The application is developed and tested on Linux and macOS; Windows is not recommended.
+First you need to run a server with PHP. Please do not use a Windows machine for this purpose, while Windows suck. ApFab recommends Linux or Mac;)
ApFab Zap Machine needs some PHP extensions:
- JSON (default installed)
- CUrl (default installed)
- Imagick (Image Magick image processing Class)
-You need to acquire the following API key:
+You need to acquire the following API key and put it into `conf/conf.php`:
1. **Brave Search API Key** - https://api.search.brave.com/
-Then set up your configuration:
+See `conf/conf.php` for the exact constant names to use.
-```bash
-# Create your local config from the template
-cp conf/conf.local.php.dist conf/conf.local.php
-# Edit it with your real keys
-nano conf/conf.local.php
-```
-
-`conf/conf.local.php` is gitignored so your secrets stay safe. You can also set the `BRAVE_API_KEY` environment variable as an alternative.
-
-Adjust permission (chmod 777) for 'sessions' folder, then run index.php in the www/ directory, fill in the form and voila.
+Adjust permission (chmod 777) for 'sessions' folder, run index.php in the www/ directory, fill in the form and voila.
# yet to come
- Logfile also generated in imgProcess Class (0.9.2)
diff --git a/cli_scripts/reset.php b/cli_scripts/reset.php
index 2cc6f1c..6cd3f1f 100755
--- a/cli_scripts/reset.php
+++ b/cli_scripts/reset.php
@@ -1,80 +1,28 @@
-#!/usr/bin/env php
session reset
';
-require_once __DIR__ . '/../conf/init.php';
-
-// Start a session so reset/destroy have something to work with
-if (session_status() === PHP_SESSION_NONE) {
- session_start();
-}
-
-// --- Session reset ---
-Session::reset();
-
-echo 'Session reset.' . PHP_EOL;
-
-// --- Optional: purge all session folders ---
-$purgeAll = in_array('--all', $argv);
-
-if ($purgeAll) {
- $force = in_array('-f', $argv);
-
- if (!$force) {
- echo 'WARNING: This will permanently delete ALL session folders.' . PHP_EOL;
- echo 'Are you sure? (type "yes" to confirm): ';
- $handle = fopen('php://stdin', 'r');
- $input = trim(fgets($handle));
- fclose($handle);
-
- if (strtolower($input) !== 'yes') {
- echo 'Aborted.' . PHP_EOL;
- exit(0);
- }
- }
-
- $sessionsDir = ZAP_APP_BASE_DIR . DIRECTORY_SEPARATOR . ZAP_SESSIONS_DIR;
- $folders = glob($sessionsDir . DIRECTORY_SEPARATOR . '*');
- $count = 0;
-
- foreach ($folders as $folder) {
- if (!is_dir($folder)) {
- continue;
- }
- $files = glob($folder . DIRECTORY_SEPARATOR . '*');
- foreach ($files as $file) {
- if (is_file($file)) {
- unlink($file);
- }
+if ($_GET['allcollages'] == 'clear') {
+ $sessions = glob('./Sessions/*');
+ foreach($sessions as $folder){
+ $files = glob($folder.'/*');
+ foreach($files as $fileToDelete){
+ echo "$fileToDelete deleted ";
+ unlink($fileToDelete);
}
+ echo "$folder deleted ";
rmdir($folder);
- $count++;
}
-
- echo "Purged $count session folder(s)." . PHP_EOL;
}
+echo '
';
-// Only destroy if a session was actually started
-if (session_status() === PHP_SESSION_ACTIVE) {
- Session::destroy();
- echo 'Session destroyed.' . PHP_EOL;
-}
-
-exit(0);
\ No newline at end of file
+session_destroy();
+?>
\ No newline at end of file
diff --git a/cli_scripts/test.php b/cli_scripts/test.php
index bb1b29b..3a618cd 100755
--- a/cli_scripts/test.php
+++ b/cli_scripts/test.php
@@ -85,10 +85,9 @@ function testImgSearch() {
return;
}
- $suffix = bin2hex(random_bytes(4));
- $folder = ZAP_APP_BASE_DIR . DIRECTORY_SEPARATOR . ZAP_SESSIONS_DIR . DIRECTORY_SEPARATOR . 'search_test_' . ZAP_MOMENT . '_' . $suffix;
+ $folder = ZAP_APP_BASE_DIR . DIRECTORY_SEPARATOR . ZAP_SESSIONS_DIR . DIRECTORY_SEPARATOR . 'search_test_' . ZAP_MOMENT;
if (!is_dir($folder)) {
- mkdir($folder, 0777, true);
+ @mkdir($folder, 0777, true);
}
echo "\nQuery: '$word'\n\n";
diff --git a/conf/conf.local.php.dist b/conf/conf.local.php.dist
deleted file mode 100644
index a0c9fdb..0000000
--- a/conf/conf.local.php.dist
+++ /dev/null
@@ -1,10 +0,0 @@
- environment variable > placeholder
- */
-define('BRAVE_API_KEY', 'your-real-api-key-here');
\ No newline at end of file
diff --git a/conf/conf.php b/conf/conf.php
index 67f380a..f213c65 100755
--- a/conf/conf.php
+++ b/conf/conf.php
@@ -6,9 +6,6 @@
define('MAX_WORDS', 4);
define('MAX_ZAPS', 9);
-define('ZAP_DEFAULT_WIDTH', 1067);
-define('ZAP_DEFAULT_HEIGHT', 600);
-
define('ZAP_CURL_TIMEOUT', 12);
define('ZAP_IMG_TYPE', 'jpg');
define('ZAP_CANVAS_NAME', 'collage');
@@ -16,13 +13,12 @@ define('ZAP_CANVAS_NAME', 'collage');
define('ZAP_DELETE_SOURCE', false);
define('ZAP_ADULT', false);
define('ZAP_LOG', true);
-define('ZAP_DEBUG', false);
+define('ZAP_DEBUG', true);
// Brave Search API
// Get your API key: https://api.search.brave.com/
-// Put your key in conf/conf.local.php (gitignored) or set BRAVE_API_KEY env var
-// See conf/conf.local.php.dist for a template
+define('BRAVE_API_KEY', 'your api key');
define('BRAVE_BASE', 'https://api.search.brave.com/res/v1/images/search');
$search_engines = array('brave');
diff --git a/conf/init.php b/conf/init.php
index f2a6078..ed0dbc1 100755
--- a/conf/init.php
+++ b/conf/init.php
@@ -1,21 +1,10 @@
\ No newline at end of file
diff --git a/docs/ZapHandler.md b/docs/ZapHandler.md
deleted file mode 100644
index b6c6e9a..0000000
--- a/docs/ZapHandler.md
+++ /dev/null
@@ -1,16 +0,0 @@
-# ZAPHandler Interface
-
-| File | Change |
-|------|--------|
-| **`lib/ZAPHandler.interface.php`** | **Created** — defines `ZAPHandler` interface with `public function getContent()` |
-| **`lib/ZAPHome.class.php`** | Added `implements ZAPHandler` |
-| **`lib/ZAPDisplay.class.php`** | Added `implements ZAPHandler` |
-| **`lib/ZAPZap.class.php`** | Added `implements ZAPHandler` |
-| **`lib/ZAPController.class.php`** | Added `instanceof ZAPHandler` guard inside `fetch()` before calling `getContent()` |
-
-### How it works
-
-- Any class named `ZAP{Mode}` in `lib/` is autoloaded and instantiated by `ZAPController`
-- The controller now checks `$this->action instanceof ZAPHandler` **before** calling `getContent()`
-- If a handler forgets to implement the interface, you get a clear `die()` message instead of a cryptic runtime error
-- The interface file uses the `.interface.php` naming convention, which the existing autoloader already handles (it checks `.interface.php` first, then `.class.php`)
\ No newline at end of file
diff --git a/docs/framework_guide.md b/docs/framework_guide.md
index 4fb7aa6..4bff8d8 100644
--- a/docs/framework_guide.md
+++ b/docs/framework_guide.md
@@ -212,7 +212,7 @@ Key differences from the web entry point:
### Logging
-The `Log` class (`utils/Log.class.php`) writes timestamped messages to a session folder. It is used by `ImgSearch` (controlled by the `ZAP_LOG` constant in `conf/conf.php`). Each log call appends to both `log.txt` (plain text) and `log.html` (HTML-friendly) in the session's output directory.
+The `Log` class (`utils/Log.class.php`) writes timestamped messages to a session folder. It is used by `ImgSearch` (controlled by the `ZAP_LOG` constant in `conf/conf.php`). Each log call appends to both `log.txt` (plain text) and `log.xml` (XML-friendly) in the session's output directory.
```php
if (ZAP_LOG == true) {
diff --git a/docs/framework_review.md b/docs/framework_review.md
deleted file mode 100644
index 2865e02..0000000
--- a/docs/framework_review.md
+++ /dev/null
@@ -1,39 +0,0 @@
-# ZAP Framework Review
-
-Task #10 — *“Check if the framework is the optimal, most simple and flexible way to go. If not: suggest some changes.”*
-
-This review audits the internal ZapMachine PHP framework (documented in `docs/framework_guide.md`) against three criteria — **optimal**, **simple**, and **flexible** — based on a full read of the current source on branch `optimize-framework` (commit `d971512`).
-
-**Scope:** audit + recommendations only. **No source files are modified in this deliverable.** Every recommendation below is a proposal that should get its own kanban task and separate approval before implementation.
-
----
-
-## Verdict
-
-The framework’s **architecture is genuinely simple and flexible** for its scope. Adding a new page (`?mode=`) is a one-class + one-template operation with zero registration. Adding a new search engine is a one-class operation behind a clean interface. PHP-native templating means no build step and no engine dependency. These are real strengths and should be preserved.
-
-It is **not optimal**, however, because:
-
-1. **Three P0 correctness bugs** silently degrade the core search pipeline (Brave `size`/`offset` params never sent; query double-URL-encoded; autoloader path split hardcodes `':'`).
-2. **Unsafe / committed config defaults** (`ZAP_DEBUG=true`, placeholder API key in git-tracked `conf/conf.php`, `chmod 777`).
-3. **Several loose abstraction boundaries** make the “framework contract” described in the guide looser than the code actually enforces (no `ZAPHandler` interface, inconsistent `extract()` template pattern, raw `$_SESSION` access beside a `Session` wrapper).
-
-None of these require replacing the architecture. They are bug fixes, a config-hygiene pass, and a few small interface tightenings. Recommended effort: a handful of small, well-scoped tasks — **not** a rewrite.
-
----
-
-
-## Strengths worth preserving
-
-| Aspect | Why it’s good |
-|---|---|
-| Front-controller + naming convention (`ZAP` + ucfirst(mode)) | Zero-config routing. A new mode = one class in `lib/` + one `.tpl`. No route table, no registration. Very flexible, very simple. (`lib/ZAPController.class.php`) |
-| `spl_autoload_register` over the include path | No manual `require_once` for library classes; drop a `.class.php` in the right dir and it loads. (`conf/init.php`) |
-| `Search` interface plugin system | Engines are interchangeable behind a 3-method contract and a universal result-array shape. Adding `Pixabay`/`Pexels` (tasks #1/#2) is a clean drop-in. (`resource/Search.interface.php`, `resource/Brave.class.php`) |
-| PHP-native templates (`ob_start`/`include`/`extract`/`ob_get_clean`) | No template engine, no compilation step, no extra dependency. Simplest possible rendering. |
-| `Config` singleton | Decouples runtime config (e.g. registered engines) from individual classes. (`conf/Config.class.php`) |
-| Clear layering | routing / handlers / search / imaging / utils are in separate dirs with single responsibilities. |
-
-These answer the “simple and flexible” part of the brief affirmatively. The rest of this document is about getting to “optimal.”
-
----
diff --git a/kanban/.lock b/kanban/.lock
deleted file mode 100644
index e69de29..0000000
diff --git a/kanban/activity.jsonl b/kanban/activity.jsonl
deleted file mode 100644
index 3352de4..0000000
--- a/kanban/activity.jsonl
+++ /dev/null
@@ -1,95 +0,0 @@
-{"timestamp":"2026-07-15T14:55:51.244024579+02:00","action":"create","task_id":1,"detail":"pixabay api"}
-{"timestamp":"2026-07-15T14:56:56.736534944+02:00","action":"edit","task_id":1,"detail":"pixabay api"}
-{"timestamp":"2026-07-15T14:58:10.598825995+02:00","action":"create","task_id":2,"detail":"Pexels api"}
-{"timestamp":"2026-07-15T14:58:27.253134741+02:00","action":"edit","task_id":2,"detail":"Pexels api"}
-{"timestamp":"2026-07-15T15:00:10.532523584+02:00","action":"create","task_id":3,"detail":"random words"}
-{"timestamp":"2026-07-15T15:02:31.109387111+02:00","action":"create","task_id":4,"detail":"search for original images"}
-{"timestamp":"2026-07-15T15:02:43.403448994+02:00","action":"edit","task_id":4,"detail":"search for original images"}
-{"timestamp":"2026-07-15T15:13:21.132728219+02:00","action":"create","task_id":5,"detail":"image processing"}
-{"timestamp":"2026-07-15T15:15:54.327404411+02:00","action":"create","task_id":6,"detail":"full screen gui"}
-{"timestamp":"2026-07-15T15:17:54.955029144+02:00","action":"create","task_id":7,"detail":"ai generated images for input"}
-{"timestamp":"2026-07-15T15:20:29.077954887+02:00","action":"create","task_id":8,"detail":"automatic mode"}
-{"timestamp":"2026-07-15T15:22:18.569491561+02:00","action":"create","task_id":9,"detail":"library guide"}
-{"timestamp":"2026-07-15T15:22:33.368044405+02:00","action":"move","task_id":9,"detail":"backlog -\u003e todo"}
-{"timestamp":"2026-07-15T15:23:07.895052923+02:00","action":"move","task_id":6,"detail":"backlog -\u003e todo"}
-{"timestamp":"2026-07-15T15:23:14.910744836+02:00","action":"move","task_id":5,"detail":"backlog -\u003e todo"}
-{"timestamp":"2026-07-17T00:46:24.790499349+02:00","action":"edit","task_id":9,"detail":"framework guide"}
-{"timestamp":"2026-07-17T01:14:23.984206626+02:00","action":"move","task_id":9,"detail":"todo -\u003e in-progress"}
-{"timestamp":"2026-07-17T02:16:23.061670813+02:00","action":"create","task_id":10,"detail":"check framework"}
-{"timestamp":"2026-07-17T02:16:52.676988996+02:00","action":"move","task_id":9,"detail":"in-progress -\u003e done"}
-{"timestamp":"2026-07-17T02:54:59.922251442+02:00","action":"move","task_id":10,"detail":"todo -\u003e in-progress"}
-{"timestamp":"2026-07-17T03:04:14.08873263+02:00","action":"priority","task_id":10,"detail":"high -\u003e medium"}
-{"timestamp":"2026-07-17T03:04:15.072297537+02:00","action":"priority","task_id":10,"detail":"medium -\u003e low"}
-{"timestamp":"2026-07-17T03:04:23.967707693+02:00","action":"priority","task_id":10,"detail":"low -\u003e medium"}
-{"timestamp":"2026-07-17T03:04:24.575872692+02:00","action":"priority","task_id":10,"detail":"medium -\u003e high"}
-{"timestamp":"2026-07-17T03:25:58.441011923+02:00","action":"edit","task_id":10,"detail":"check framework"}
-{"timestamp":"2026-07-17T03:26:01.636755342+02:00","action":"move","task_id":10,"detail":"in-progress -\u003e review"}
-{"timestamp":"2026-07-17T03:26:18.979779542+02:00","action":"edit","task_id":10,"detail":"check framework"}
-{"timestamp":"2026-07-17T03:26:18.979863107+02:00","action":"release","task_id":10,"detail":"tui@mcBookje"}
-{"timestamp":"2026-07-17T03:50:56.347742215+02:00","action":"move","task_id":6,"detail":"todo -\u003e backlog"}
-{"timestamp":"2026-07-17T03:51:00.178032766+02:00","action":"move","task_id":5,"detail":"todo -\u003e backlog"}
-{"timestamp":"2026-07-17T03:57:00.446052295+02:00","action":"create","task_id":11,"detail":"Fix Brave request building: lazy URL + single encode"}
-{"timestamp":"2026-07-17T03:57:06.830184988+02:00","action":"create","task_id":12,"detail":"Fix autoloader: use PATH_SEPARATOR instead of hardcoded ':'"}
-{"timestamp":"2026-07-17T03:57:13.889026673+02:00","action":"create","task_id":13,"detail":"Config hygiene: ZAP_DEBUG=false, secrets in git-ignored local file, sessions perms"}
-{"timestamp":"2026-07-17T03:57:20.700148188+02:00","action":"create","task_id":14,"detail":"Add CSRF protection to word-input form"}
-{"timestamp":"2026-07-17T03:57:28.29860719+02:00","action":"create","task_id":15,"detail":"Replace die('Wrong parameter') with proper 404/error handler"}
-{"timestamp":"2026-07-17T03:57:35.273661605+02:00","action":"create","task_id":16,"detail":"Fix and secure cli_scripts/reset.php"}
-{"timestamp":"2026-07-17T03:57:50.885872288+02:00","action":"create","task_id":17,"detail":"Make session folder names unique, stop suppressing mkdir errors"}
-{"timestamp":"2026-07-17T03:57:59.05551049+02:00","action":"create","task_id":18,"detail":"Introduce ZAPHandler interface for getContent()"}
-{"timestamp":"2026-07-17T03:58:05.367581371+02:00","action":"create","task_id":19,"detail":"Single source of truth for word count + cleanup handleWords"}
-{"timestamp":"2026-07-17T03:58:11.989024488+02:00","action":"create","task_id":20,"detail":"Consistent template rendering pattern across all handlers"}
-{"timestamp":"2026-07-17T03:58:20.432255313+02:00","action":"create","task_id":21,"detail":"Consolidate duplicated screen-size constants"}
-{"timestamp":"2026-07-17T03:58:30.405465201+02:00","action":"create","task_id":22,"detail":"Fix convertGifsToPng extension + rename/fix log.xml"}
-{"timestamp":"2026-07-17T03:58:37.159090865+02:00","action":"create","task_id":23,"detail":"Anchor ZAP_APP_BASE_DIR to __DIR__, make getZAPTemplate throw"}
-{"timestamp":"2026-07-17T03:58:43.664420067+02:00","action":"create","task_id":24,"detail":"Refresh README (Yahoo→Brave, drop outdated roadmap, fix tone)"}
-{"timestamp":"2026-07-17T12:26:07.265732515+02:00","action":"move","task_id":10,"detail":"review -\u003e done"}
-{"timestamp":"2026-07-17T12:26:29.348995723+02:00","action":"move","task_id":11,"detail":"todo -\u003e in-progress"}
-{"timestamp":"2026-07-17T12:26:34.350031444+02:00","action":"edit","task_id":11,"detail":"Fix Brave request building: lazy URL + single encode"}
-{"timestamp":"2026-07-17T12:26:38.760178641+02:00","action":"move","task_id":11,"detail":"in-progress -\u003e review"}
-{"timestamp":"2026-07-17T12:26:38.760294679+02:00","action":"handoff","task_id":11,"detail":"Fix Brave request building: lazy URL + single encode"}
-{"timestamp":"2026-07-17T12:26:38.760385873+02:00","action":"release","task_id":11,"detail":"Fix Brave request building: lazy URL + single encode"}
-{"timestamp":"2026-07-17T12:27:40.64656083+02:00","action":"move","task_id":12,"detail":"todo -\u003e in-progress"}
-{"timestamp":"2026-07-17T12:27:53.052811022+02:00","action":"edit","task_id":12,"detail":"Fix autoloader: use PATH_SEPARATOR instead of hardcoded ':'"}
-{"timestamp":"2026-07-17T12:27:53.056394858+02:00","action":"move","task_id":12,"detail":"in-progress -\u003e review"}
-{"timestamp":"2026-07-17T12:27:53.056484271+02:00","action":"handoff","task_id":12,"detail":"Fix autoloader: use PATH_SEPARATOR instead of hardcoded ':'"}
-{"timestamp":"2026-07-17T12:27:53.056530205+02:00","action":"release","task_id":12,"detail":"Fix autoloader: use PATH_SEPARATOR instead of hardcoded ':'"}
-{"timestamp":"2026-07-17T21:40:38.025770941+02:00","action":"move","task_id":13,"detail":"todo -\u003e in-progress"}
-{"timestamp":"2026-07-17T21:54:34.996015797+02:00","action":"move","task_id":13,"detail":"in-progress -\u003e review"}
-{"timestamp":"2026-07-17T22:27:10.995630482+02:00","action":"move","task_id":13,"detail":"review -\u003e done"}
-{"timestamp":"2026-07-18T11:42:51.254205784+02:00","action":"move","task_id":18,"detail":"todo -\u003e in-progress"}
-{"timestamp":"2026-07-18T11:50:59.773873861+02:00","action":"edit","task_id":18,"detail":"Introduce ZAPHandler interface for getContent()"}
-{"timestamp":"2026-07-18T11:51:03.257951319+02:00","action":"edit","task_id":18,"detail":"Introduce ZAPHandler interface for getContent()"}
-{"timestamp":"2026-07-18T11:51:03.258056745+02:00","action":"release","task_id":18,"detail":"tui@mcBookje"}
-{"timestamp":"2026-07-18T11:51:03.28154522+02:00","action":"move","task_id":18,"detail":"in-progress -\u003e done"}
-{"timestamp":"2026-07-19T19:06:12.923187222+02:00","action":"edit","task_id":17,"detail":"Make session folder names unique, stop suppressing mkdir errors"}
-{"timestamp":"2026-07-19T19:06:12.930146038+02:00","action":"claim","task_id":17,"detail":"rain-raven"}
-{"timestamp":"2026-07-19T19:06:58.839482716+02:00","action":"move","task_id":17,"detail":"todo -\u003e done"}
-{"timestamp":"2026-07-19T20:09:41.967705512+02:00","action":"edit","task_id":16,"detail":"Fix and secure cli_scripts/reset.php"}
-{"timestamp":"2026-07-19T20:09:41.967823882+02:00","action":"claim","task_id":16,"detail":"rain-raven"}
-{"timestamp":"2026-07-19T20:09:41.988956545+02:00","action":"move","task_id":16,"detail":"todo -\u003e done"}
-{"timestamp":"2026-07-19T20:20:19.991872348+02:00","action":"edit","task_id":15,"detail":"Replace die('Wrong parameter') with proper 404/error handler"}
-{"timestamp":"2026-07-19T20:20:19.991950864+02:00","action":"claim","task_id":15,"detail":"rain-raven"}
-{"timestamp":"2026-07-19T20:20:20.013428274+02:00","action":"move","task_id":15,"detail":"todo -\u003e done"}
-{"timestamp":"2026-07-19T21:23:27.794040982+02:00","action":"edit","task_id":14,"detail":"Add CSRF protection to word-input form"}
-{"timestamp":"2026-07-19T21:23:27.794120976+02:00","action":"claim","task_id":14,"detail":"rain-raven"}
-{"timestamp":"2026-07-19T21:23:27.819566153+02:00","action":"move","task_id":14,"detail":"todo -\u003e done"}
-{"timestamp":"2026-07-19T21:31:14.49434419+02:00","action":"edit","task_id":24,"detail":"Refresh README (Yahoo→Brave, drop outdated roadmap, fix tone)"}
-{"timestamp":"2026-07-19T21:31:14.494474852+02:00","action":"claim","task_id":24,"detail":"rain-raven"}
-{"timestamp":"2026-07-19T21:31:14.518300878+02:00","action":"move","task_id":24,"detail":"todo -\u003e done"}
-{"timestamp":"2026-07-19T21:39:02.761552753+02:00","action":"edit","task_id":23,"detail":"Anchor ZAP_APP_BASE_DIR to __DIR__, make getZAPTemplate throw"}
-{"timestamp":"2026-07-19T21:39:02.761712873+02:00","action":"claim","task_id":23,"detail":"rain-raven"}
-{"timestamp":"2026-07-19T21:39:02.783567342+02:00","action":"move","task_id":23,"detail":"todo -\u003e done"}
-{"timestamp":"2026-07-19T21:42:54.751029245+02:00","action":"edit","task_id":22,"detail":"Fix convertGifsToPng extension + rename/fix log.xml"}
-{"timestamp":"2026-07-19T21:42:54.751140546+02:00","action":"claim","task_id":22,"detail":"rain-raven"}
-{"timestamp":"2026-07-19T21:42:54.773029003+02:00","action":"move","task_id":22,"detail":"todo -\u003e done"}
-{"timestamp":"2026-07-19T21:49:54.312195218+02:00","action":"edit","task_id":21,"detail":"Consolidate duplicated screen-size constants"}
-{"timestamp":"2026-07-19T21:49:54.312297605+02:00","action":"claim","task_id":21,"detail":"rain-raven"}
-{"timestamp":"2026-07-19T21:49:54.334491216+02:00","action":"move","task_id":21,"detail":"todo -\u003e done"}
-{"timestamp":"2026-07-19T22:54:27.983080764+02:00","action":"edit","task_id":20,"detail":"Consistent template rendering pattern across all handlers"}
-{"timestamp":"2026-07-19T22:54:27.98319541+02:00","action":"claim","task_id":20,"detail":"rain-raven"}
-{"timestamp":"2026-07-19T22:54:28.007952955+02:00","action":"move","task_id":20,"detail":"todo -\u003e done"}
-{"timestamp":"2026-07-20T01:09:23.947300407+02:00","action":"edit","task_id":19,"detail":"Single source of truth for word count + cleanup handleWords"}
-{"timestamp":"2026-07-20T01:09:23.947430566+02:00","action":"claim","task_id":19,"detail":"rain-raven"}
-{"timestamp":"2026-07-20T01:09:23.97076796+02:00","action":"move","task_id":19,"detail":"todo -\u003e done"}
-{"timestamp":"2026-07-20T14:15:55.814485137+02:00","action":"move","task_id":12,"detail":"review -\u003e done"}
-{"timestamp":"2026-07-20T14:15:59.830512648+02:00","action":"move","task_id":11,"detail":"review -\u003e done"}
diff --git a/kanban/config.yml b/kanban/config.yml
deleted file mode 100644
index eb9fd78..0000000
--- a/kanban/config.yml
+++ /dev/null
@@ -1,47 +0,0 @@
-version: 10
-board:
- name: ZapMachine
-tasks_dir: tasks
-statuses:
- - name: backlog
- show_duration: false
- - name: todo
- - name: in-progress
- require_claim: true
- - name: review
- require_claim: true
- - name: done
- show_duration: false
- - name: archived
- show_duration: false
-priorities:
- - low
- - medium
- - high
- - critical
-defaults:
- status: backlog
- priority: medium
- class: standard
-claim_timeout: 1m
-classes:
- - name: expedite
- wip_limit: 1
- bypass_column_wip: true
- - name: fixed-date
- - name: standard
- - name: intangible
-tui:
- title_lines: 2
- age_thresholds:
- - after: 0s
- color: "242"
- - after: 1h
- color: "34"
- - after: 24h
- color: "226"
- - after: 72h
- color: "208"
- - after: 168h
- color: "196"
-next_id: 25
diff --git a/kanban/tasks/001-pixabay-api.md b/kanban/tasks/001-pixabay-api.md
deleted file mode 100644
index 85e9e35..0000000
--- a/kanban/tasks/001-pixabay-api.md
+++ /dev/null
@@ -1,13 +0,0 @@
----
-id: 1
-title: pixabay api
-status: backlog
-priority: high
-created: 2026-07-15T14:55:51.243108541+02:00
-updated: 2026-07-15T14:56:56.735673124+02:00
-tags:
- - search
-class: standard
----
-
-Add Pixabay api as search engine
diff --git a/kanban/tasks/002-pexels-api.md b/kanban/tasks/002-pexels-api.md
deleted file mode 100644
index 3d8f41b..0000000
--- a/kanban/tasks/002-pexels-api.md
+++ /dev/null
@@ -1,13 +0,0 @@
----
-id: 2
-title: Pexels api
-status: backlog
-priority: high
-created: 2026-07-15T14:58:10.597616484+02:00
-updated: 2026-07-15T14:58:27.252246225+02:00
-tags:
- - search
-class: standard
----
-
-Use pexels api as a seach engine
diff --git a/kanban/tasks/003-random-words.md b/kanban/tasks/003-random-words.md
deleted file mode 100644
index 28991e1..0000000
--- a/kanban/tasks/003-random-words.md
+++ /dev/null
@@ -1,13 +0,0 @@
----
-id: 3
-title: random words
-status: backlog
-priority: high
-created: 2026-07-15T15:00:10.530100379+02:00
-updated: 2026-07-15T15:00:10.530100379+02:00
-tags:
- - search
-class: standard
----
-
-random word version (https://random-words-api.kushcreates.com/)
diff --git a/kanban/tasks/004-search-for-original-images.md b/kanban/tasks/004-search-for-original-images.md
deleted file mode 100644
index 0cb420b..0000000
--- a/kanban/tasks/004-search-for-original-images.md
+++ /dev/null
@@ -1,13 +0,0 @@
----
-id: 4
-title: search for original images
-status: backlog
-priority: low
-created: 2026-07-15T15:02:31.107843015+02:00
-updated: 2026-07-15T15:02:43.402550141+02:00
-tags:
- - search
-class: standard
----
-
-input number and search for a fresh photo with a camera filename like 'img####.jpg'
diff --git a/kanban/tasks/005-image-processing.md b/kanban/tasks/005-image-processing.md
deleted file mode 100644
index c472770..0000000
--- a/kanban/tasks/005-image-processing.md
+++ /dev/null
@@ -1,14 +0,0 @@
----
-id: 5
-title: image processing
-status: backlog
-priority: critical
-created: 2026-07-15T15:13:21.131166647+02:00
-updated: 2026-07-17T03:51:00.175266589+02:00
-started: 2026-07-15T15:23:14.91034394+02:00
-tags:
- - image_processing
-class: standard
----
-
-Put back the original image processing from the old Zap Machine
diff --git a/kanban/tasks/006-full-screen-gui.md b/kanban/tasks/006-full-screen-gui.md
deleted file mode 100644
index 4c107a0..0000000
--- a/kanban/tasks/006-full-screen-gui.md
+++ /dev/null
@@ -1,14 +0,0 @@
----
-id: 6
-title: full screen gui
-status: backlog
-priority: critical
-created: 2026-07-15T15:15:54.325695132+02:00
-updated: 2026-07-17T03:50:56.343336322+02:00
-started: 2026-07-15T15:23:07.894599552+02:00
-tags:
- - gui
-class: standard
----
-
-Full screen GUI with the collage covering the background and a partly transparen control panel and feedback screen on the right
diff --git a/kanban/tasks/007-ai-generated-images-for-input.md b/kanban/tasks/007-ai-generated-images-for-input.md
deleted file mode 100644
index 0680553..0000000
--- a/kanban/tasks/007-ai-generated-images-for-input.md
+++ /dev/null
@@ -1,14 +0,0 @@
----
-id: 7
-title: ai generated images for input
-status: backlog
-priority: medium
-created: 2026-07-15T15:17:54.953039352+02:00
-updated: 2026-07-15T15:17:54.953039352+02:00
-tags:
- - search
- - source
-class: standard
----
-
-use a scraper (brightdata) or write one ourselves to scrape for ai genarated images as sources
diff --git a/kanban/tasks/008-automatic-mode.md b/kanban/tasks/008-automatic-mode.md
deleted file mode 100644
index b71b059..0000000
--- a/kanban/tasks/008-automatic-mode.md
+++ /dev/null
@@ -1,14 +0,0 @@
----
-id: 8
-title: automatic mode
-status: backlog
-priority: medium
-created: 2026-07-15T15:20:29.075465548+02:00
-updated: 2026-07-15T15:20:29.075465548+02:00
-tags:
- - gui
- - mode
-class: standard
----
-
-if one or more people are watching automatically generate a zap layer every 21 seconds
diff --git a/kanban/tasks/009-framework-guide.md b/kanban/tasks/009-framework-guide.md
deleted file mode 100644
index 7b5abd3..0000000
--- a/kanban/tasks/009-framework-guide.md
+++ /dev/null
@@ -1,13 +0,0 @@
----
-id: 9
-title: framework guide
-status: done
-priority: critical
-created: 2026-07-15T15:22:18.567355625+02:00
-updated: 2026-07-17T02:16:52.6730631+02:00
-started: 2026-07-15T15:22:33.367755161+02:00
-completed: 2026-07-17T02:16:52.676581649+02:00
-class: standard
----
-
-add the usage of the framework in the README. How does this framework work, how to add templates with interactive elements
diff --git a/kanban/tasks/010-check-framework.md b/kanban/tasks/010-check-framework.md
deleted file mode 100644
index f2fe51f..0000000
--- a/kanban/tasks/010-check-framework.md
+++ /dev/null
@@ -1,16 +0,0 @@
----
-id: 10
-title: check framework
-status: done
-priority: high
-created: 2026-07-17T02:16:23.059189291+02:00
-updated: 2026-07-17T12:26:07.258170416+02:00
-started: 2026-07-17T12:26:07.265125164+02:00
-completed: 2026-07-17T12:26:07.265125164+02:00
-class: standard
----
-
-Check if the framework is the optimal, most simple and flexible way to go. If not: suggest some changes.
-
-[[2026-07-17]] Fri 03:25
-Framework review committed: docs/framework_review.md (commit 2f61b07). Verdict: architecture is simple/flexible (zero-config routing, autoloader, Search plugin interface, native templates) — keep as-is. Not optimal due to 3 P0 correctness bugs (Brave size/offset params never sent because setQuery builds URL before setParam; query double-URL-encoded; autoloader hardcodes ':' vs PATH_SEPARATOR), P1 config/security (ZAP_DEBUG=true & placeholder key committed, no CSRF, die() routing, unsafe reset.php, second-resolution session folder collisions), P2 consistency. NO source edits — deliverable is docs-only. Includes recommended-task table for follow-up fixes (each independently approvable). Handing to review for Fabian's approval before any code changes.
diff --git a/kanban/tasks/011-fix-brave-request-building-lazy-url-single-encode.md b/kanban/tasks/011-fix-brave-request-building-lazy-url-single-encode.md
deleted file mode 100644
index 88f61cc..0000000
--- a/kanban/tasks/011-fix-brave-request-building-lazy-url-single-encode.md
+++ /dev/null
@@ -1,24 +0,0 @@
----
-id: 11
-title: 'Fix Brave request building: lazy URL + single encode'
-status: done
-priority: high
-created: 2026-07-17T03:57:00.444816503+02:00
-updated: 2026-07-20T14:15:59.825243496+02:00
-started: 2026-07-20T14:15:59.830054903+02:00
-completed: 2026-07-20T14:15:59.830054903+02:00
-tags:
- - search
- - bug
-class: standard
----
-
-From framework review (docs/framework_review.md). Two-part fix in resource/Brave.class.php + lib/ImgSearch.class.php:
-1. Move URL construction from setQuery() to getData() so setParam('start'/'size') values are applied (currently size defaults to 3 instead of 16, offset is never sent).
-2. Remove double urlencode: ImgSearch passes urlencode(word) into Brave::setQuery which urlencodes again → %2520 for spaces. Fix: pass raw word from ImgSearch; engine owns encoding.
-
-[[2026-07-17]] Fri 12:26
-P0-1: Moved URL construction from setQuery() to new buildRequest() called from getData() — size/offset now use setParam() values (resource/Brave.class.php). P0-2: Removed urlencode() call from ImgSearch::getImageData() — raw word passed to engine, single encode in Brave (lib/ImgSearch.class.php). Both pass php -l.
-
-[[2026-07-17]] Fri 12:26
-P0-1 + P0-2 implemented. Changes to resource/Brave.class.php and lib/ImgSearch.class.php. Both pass php -l. Ready for your commit.
diff --git a/kanban/tasks/012-fix-autoloader-use-path-separator-instead-of.md b/kanban/tasks/012-fix-autoloader-use-path-separator-instead-of.md
deleted file mode 100644
index 54fd574..0000000
--- a/kanban/tasks/012-fix-autoloader-use-path-separator-instead-of.md
+++ /dev/null
@@ -1,22 +0,0 @@
----
-id: 12
-title: 'Fix autoloader: use PATH_SEPARATOR instead of hardcoded '':'''
-status: done
-priority: high
-created: 2026-07-17T03:57:06.82901804+02:00
-updated: 2026-07-20T14:15:55.809367918+02:00
-started: 2026-07-20T14:15:55.814059562+02:00
-completed: 2026-07-20T14:15:55.814059562+02:00
-tags:
- - framework
- - bug
-class: standard
----
-
-From framework review (docs/framework_review.md). conf/init.php uses explode(':', get_include_path()) but the include path separator is ':' on Unix and ';' on Windows. Makes the autoloader fail on Windows. Fix: explode(PATH_SEPARATOR, get_include_path()).
-
-[[2026-07-17]] Fri 12:27
-Changed explode(':', ...) to explode(PATH_SEPARATOR, ...) in conf/init.php. PHP passes php -l.
-
-[[2026-07-17]] Fri 12:27
-P0-3 fixed. One-line change in conf/init.php. Ready for your commit.
diff --git a/kanban/tasks/013-config-hygiene-zap-debug-false-secrets-in-git.md b/kanban/tasks/013-config-hygiene-zap-debug-false-secrets-in-git.md
deleted file mode 100644
index 0d6ba07..0000000
--- a/kanban/tasks/013-config-hygiene-zap-debug-false-secrets-in-git.md
+++ /dev/null
@@ -1,19 +0,0 @@
----
-id: 13
-title: 'Config hygiene: ZAP_DEBUG=false, secrets in git-ignored local file, sessions perms'
-status: done
-priority: medium
-created: 2026-07-17T03:57:13.88777683+02:00
-updated: 2026-07-17T22:27:10.989415474+02:00
-started: 2026-07-17T22:27:10.994979516+02:00
-completed: 2026-07-17T22:27:10.994979516+02:00
-tags:
- - security
- - config
-class: standard
----
-
-From framework review (docs/framework_review.md), P1-1. conf/conf.php is git-tracked and ships with ZAP_DEBUG=true, BRAVE_API_KEY='your api key' placeholder. Fixes:
-- Default ZAP_DEBUG=false in committed conf.php
-- Add git-ignored conf/conf.local.php loaded by init.php if present, for secrets
-- Tighten sessions/ permissions from 777 to 770 (or document webserver-user group)
diff --git a/kanban/tasks/014-add-csrf-protection-to-word-input-form.md b/kanban/tasks/014-add-csrf-protection-to-word-input-form.md
deleted file mode 100644
index 1dc212c..0000000
--- a/kanban/tasks/014-add-csrf-protection-to-word-input-form.md
+++ /dev/null
@@ -1,17 +0,0 @@
----
-id: 14
-title: Add CSRF protection to word-input form
-status: done
-priority: medium
-created: 2026-07-17T03:57:20.699057952+02:00
-updated: 2026-07-19T21:23:27.817959707+02:00
-started: 2026-07-19T21:23:27.819406405+02:00
-completed: 2026-07-19T21:23:27.819406405+02:00
-tags:
- - security
-claimed_by: rain-raven
-claimed_at: 2026-07-19T21:23:27.817959707+02:00
-class: standard
----
-
-From framework review (docs/framework_review.md), P1-2. tpl/index.tpl POSTs to mode=display which writes session state and triggers image downloads. No CSRF token means a cross-site request can drive the machine. Fix: add session-bound CSRF token to the form, validate in ZAPDisplay.
diff --git a/kanban/tasks/015-replace-die-wrong-parameter-with-proper-404-error.md b/kanban/tasks/015-replace-die-wrong-parameter-with-proper-404-error.md
deleted file mode 100644
index 0119a46..0000000
--- a/kanban/tasks/015-replace-die-wrong-parameter-with-proper-404-error.md
+++ /dev/null
@@ -1,17 +0,0 @@
----
-id: 15
-title: Replace die('Wrong parameter') with proper 404/error handler
-status: done
-priority: medium
-created: 2026-07-17T03:57:28.297533467+02:00
-updated: 2026-07-19T20:20:20.011896223+02:00
-started: 2026-07-19T20:20:20.013282064+02:00
-completed: 2026-07-19T20:20:20.013282064+02:00
-tags:
- - framework
-claimed_by: rain-raven
-claimed_at: 2026-07-19T20:20:20.011896223+02:00
-class: standard
----
-
-From framework review (docs/framework_review.md), P1-3. ZAPController::__construct() calls die('Wrong parameter') when an unknown mode is given — no HTTP status, no HTML, and the polling onerror contract expects ERROR_PREFIX HTML. Fix: return a proper 404 response (or brand error page via ZAPError handler). Also consider mode allowlist.
diff --git a/kanban/tasks/016-fix-and-secure-cli-scripts-reset-php.md b/kanban/tasks/016-fix-and-secure-cli-scripts-reset-php.md
deleted file mode 100644
index 1932343..0000000
--- a/kanban/tasks/016-fix-and-secure-cli-scripts-reset-php.md
+++ /dev/null
@@ -1,23 +0,0 @@
----
-id: 16
-title: Fix and secure cli_scripts/reset.php
-status: done
-priority: medium
-created: 2026-07-17T03:57:35.272402311+02:00
-updated: 2026-07-19T20:09:41.987393047+02:00
-started: 2026-07-19T20:09:41.988806323+02:00
-completed: 2026-07-19T20:09:41.988806323+02:00
-tags:
- - cli
- - security
-claimed_by: rain-raven
-claimed_at: 2026-07-19T20:09:41.987393047+02:00
-class: standard
----
-
-From framework review (docs/framework_review.md), P1-4. cli_scripts/reset.php has multiple issues:
-- Case mismatch: glob('./Sessions/*') vs actual 'sessions/' directory → no-op on case-sensitive FS
-- No auth/CSRF: bare $_GET['allcollages'] == 'clear' triggers destructive unlink/rmdir
-- If web-accessible it's an unauthenticated destructive endpoint
-- Misplaced in cli_scripts/ (uses $_GET like a web script)
-Fix: correct path, add CLI guard (php_sapi_name()), gate destructive branch behind confirmation.
diff --git a/kanban/tasks/017-make-session-folder-names-unique-stop-suppressing.md b/kanban/tasks/017-make-session-folder-names-unique-stop-suppressing.md
deleted file mode 100644
index 746f354..0000000
--- a/kanban/tasks/017-make-session-folder-names-unique-stop-suppressing.md
+++ /dev/null
@@ -1,17 +0,0 @@
----
-id: 17
-title: Make session folder names unique, stop suppressing mkdir errors
-status: done
-priority: medium
-created: 2026-07-17T03:57:50.884126062+02:00
-updated: 2026-07-19T19:06:58.837663313+02:00
-started: 2026-07-19T19:06:58.839287746+02:00
-completed: 2026-07-19T19:06:58.839287746+02:00
-tags:
- - session
-claimed_by: rain-raven
-claimed_at: 2026-07-19T19:06:58.837663313+02:00
-class: standard
----
-
-From framework review (docs/framework_review.md), P1-5. ZAP_MOMENT = date('Y-m-d-H_i_s') has second resolution. Two submissions in the same second collide on mkdir — suppressed with @, returns null folder, silently breaks all downstream operations. Fix: append random suffix to folder name, drop @, add recursive flag.
diff --git a/kanban/tasks/018-introduce-zaphandler-interface-for-getcontent.md b/kanban/tasks/018-introduce-zaphandler-interface-for-getcontent.md
deleted file mode 100644
index 16cde7e..0000000
--- a/kanban/tasks/018-introduce-zaphandler-interface-for-getcontent.md
+++ /dev/null
@@ -1,18 +0,0 @@
----
-id: 18
-title: Introduce ZAPHandler interface for getContent()
-status: done
-priority: medium
-created: 2026-07-17T03:57:59.054256365+02:00
-updated: 2026-07-18T11:51:03.280085523+02:00
-started: 2026-07-18T11:51:03.281402582+02:00
-completed: 2026-07-18T11:51:03.281402582+02:00
-tags:
- - framework
-class: standard
----
-
-From framework review (docs/framework_review.md), P1-7. Currently getContent() is convention-only — no interface enforces it. A handler missing the method fails at runtime, not definition time. Fix: create a ZAPHandler (or ModeHandler) interface with public function getContent(), implement it on all existing handlers, add instanceof check in ZAPController.
-
-[[2026-07-18]] Sat 11:50
-Created ZAPHandler interface with getContent(), implemented on ZAPHome/ZAPDisplay/ZAPZap, added instanceof check in ZAPController::fetch().
diff --git a/kanban/tasks/019-single-source-of-truth-for-word-count-cleanup.md b/kanban/tasks/019-single-source-of-truth-for-word-count-cleanup.md
deleted file mode 100644
index c0685a6..0000000
--- a/kanban/tasks/019-single-source-of-truth-for-word-count-cleanup.md
+++ /dev/null
@@ -1,17 +0,0 @@
----
-id: 19
-title: Single source of truth for word count + cleanup handleWords
-status: done
-priority: low
-created: 2026-07-17T03:58:05.365933671+02:00
-updated: 2026-07-20T01:09:23.968637294+02:00
-started: 2026-07-20T01:09:23.970603129+02:00
-completed: 2026-07-20T01:09:23.970603129+02:00
-tags:
- - cleanup
-claimed_by: rain-raven
-claimed_at: 2026-07-20T01:09:23.968637294+02:00
-class: standard
----
-
-From framework review (docs/framework_review.md), P2-1/2. MAX_WORDS drives the template loop but handleWords() independently re-scans POST. Also has / typo. Fix: iterate 1..MAX_WORDS in handleWords, clean up variable naming.
diff --git a/kanban/tasks/020-consistent-template-rendering-pattern-across-all.md b/kanban/tasks/020-consistent-template-rendering-pattern-across-all.md
deleted file mode 100644
index 9dd7b1d..0000000
--- a/kanban/tasks/020-consistent-template-rendering-pattern-across-all.md
+++ /dev/null
@@ -1,17 +0,0 @@
----
-id: 20
-title: Consistent template rendering pattern across all handlers
-status: done
-priority: low
-created: 2026-07-17T03:58:11.987251314+02:00
-updated: 2026-07-19T22:54:28.006158702+02:00
-started: 2026-07-19T22:54:28.007766996+02:00
-completed: 2026-07-19T22:54:28.007766996+02:00
-tags:
- - cleanup
-claimed_by: rain-raven
-claimed_at: 2026-07-19T22:54:28.006158702+02:00
-class: standard
----
-
-From framework review (docs/framework_review.md), P2-3. ZAPHome uses extract(get_object_vars()) (the documented pattern); ZAPDisplay does not — it manually declares local vars and accesses directly in the template. Pick one pattern (extract or explicit) and apply consistently.
diff --git a/kanban/tasks/021-consolidate-duplicated-screen-size-constants.md b/kanban/tasks/021-consolidate-duplicated-screen-size-constants.md
deleted file mode 100644
index 91ccbdd..0000000
--- a/kanban/tasks/021-consolidate-duplicated-screen-size-constants.md
+++ /dev/null
@@ -1,17 +0,0 @@
----
-id: 21
-title: Consolidate duplicated screen-size constants
-status: done
-priority: low
-created: 2026-07-17T03:58:20.43055577+02:00
-updated: 2026-07-19T21:49:54.332882291+02:00
-started: 2026-07-19T21:49:54.33435439+02:00
-completed: 2026-07-19T21:49:54.33435439+02:00
-tags:
- - cleanup
-claimed_by: rain-raven
-claimed_at: 2026-07-19T21:49:54.332882291+02:00
-class: standard
----
-
-From framework review (docs/framework_review.md), P2-5. ImgIOTools and ImgTools both define $maxScreenWidth/$maxScreenHeight to the same values (1067/600). Drift risk. Consolidate into one place.
diff --git a/kanban/tasks/022-fix-convertgifstopng-extension-rename-fix-log-xml.md b/kanban/tasks/022-fix-convertgifstopng-extension-rename-fix-log-xml.md
deleted file mode 100644
index a0bcc07..0000000
--- a/kanban/tasks/022-fix-convertgifstopng-extension-rename-fix-log-xml.md
+++ /dev/null
@@ -1,19 +0,0 @@
----
-id: 22
-title: Fix convertGifsToPng extension + rename/fix log.xml
-status: done
-priority: low
-created: 2026-07-17T03:58:30.403935395+02:00
-updated: 2026-07-19T21:42:54.771387687+02:00
-started: 2026-07-19T21:42:54.772886896+02:00
-completed: 2026-07-19T21:42:54.772886896+02:00
-tags:
- - cleanup
-claimed_by: rain-raven
-claimed_at: 2026-07-19T21:42:54.771387687+02:00
-class: standard
----
-
-From framework review (docs/framework_review.md), P2-6/7. Two small fixes:
-1. convertGifsToPng produces cat.gif.png (appends .png instead of replacing .gif) — confusing filenames.
-2. Log writes HTML fragments () into log.xml — not valid XML. Rename to log.html or emit proper XML.
diff --git a/kanban/tasks/023-anchor-zap-app-base-dir-to-dir-make-getzaptemplate.md b/kanban/tasks/023-anchor-zap-app-base-dir-to-dir-make-getzaptemplate.md
deleted file mode 100644
index 8bb0a12..0000000
--- a/kanban/tasks/023-anchor-zap-app-base-dir-to-dir-make-getzaptemplate.md
+++ /dev/null
@@ -1,19 +0,0 @@
----
-id: 23
-title: Anchor ZAP_APP_BASE_DIR to __DIR__, make getZAPTemplate throw
-status: done
-priority: low
-created: 2026-07-17T03:58:37.157613187+02:00
-updated: 2026-07-19T21:39:02.781954542+02:00
-started: 2026-07-19T21:39:02.783424942+02:00
-completed: 2026-07-19T21:39:02.783424942+02:00
-tags:
- - cleanup
-claimed_by: rain-raven
-claimed_at: 2026-07-19T21:39:02.781954542+02:00
-class: standard
----
-
-From framework review (docs/framework_review.md), P2-8/9. Two fixes in conf/init.php:
-1. ZAP_APP_BASE_DIR = realpath('.'.DIRECTORY_SEPARATOR.'..') is cwd-dependent — breaks if entry point is not www/ or cli_scripts/. Use realpath(__DIR__ . '/..') instead.
-2. getZAPTemplate returns ERROR_PREFIX . 'No template' string on missing file instead of throwing — inconsistent with other error paths. Make it throw.
diff --git a/kanban/tasks/024-refresh-readme-yahoo-brave-drop-outdated-roadmap.md b/kanban/tasks/024-refresh-readme-yahoo-brave-drop-outdated-roadmap.md
deleted file mode 100644
index 2f8f118..0000000
--- a/kanban/tasks/024-refresh-readme-yahoo-brave-drop-outdated-roadmap.md
+++ /dev/null
@@ -1,17 +0,0 @@
----
-id: 24
-title: Refresh README (Yahoo→Brave, drop outdated roadmap, fix tone)
-status: done
-priority: low
-created: 2026-07-17T03:58:43.662424712+02:00
-updated: 2026-07-19T21:31:14.516637296+02:00
-started: 2026-07-19T21:31:14.51815456+02:00
-completed: 2026-07-19T21:31:14.51815456+02:00
-tags:
- - docs
-claimed_by: rain-raven
-claimed_at: 2026-07-19T21:31:14.516637296+02:00
-class: standard
----
-
-From framework review (docs/framework_review.md), P2-11. README.md still says 'the most relevant image that search engine Yahoo comes up with', tells Windows users 'Windows suck', and lists a roadmap that doesn't map to kanban. Refresh prose to match current state (Brave search, no Yahoo).
diff --git a/lib/ImgIOTools.class.php b/lib/ImgIOTools.class.php
index 724d091..a41127f 100755
--- a/lib/ImgIOTools.class.php
+++ b/lib/ImgIOTools.class.php
@@ -3,6 +3,9 @@
* Image Input Output Tools
*/
class ImgIOTools {
+ public static $maxScreenWidth = 1067; //screen dimensions
+
+ public static $maxScreenHeight = 600;
/**
* Flushes image to screen
@@ -10,9 +13,9 @@ class ImgIOTools {
* @return void
*/
public static function onScreen(Imagick $img) {
- $img->scaleImage(ZAP_DEFAULT_WIDTH, ZAP_DEFAULT_HEIGHT, true);
+ $img->scaleImage(self::$maxScreenWidth, self::$maxScreenHeight, true);
- //$img = self::scaleByLength($img, ZAP_DEFAULT_WIDTH, ZAP_DEFAULT_HEIGHT);
+ //$img = self::scaleByLength($img, $this->maxScreenWidth, $this->maxScreenHeight);
header('Content-type: image/' . ZAP_IMG_TYPE);
echo $img->getImageBlob();
}
@@ -43,4 +46,5 @@ class ImgIOTools {
$path = $folder . $filename . '.' . ZAP_IMG_TYPE;
return $img->writeImage($path);
}
-}
\ No newline at end of file
+}
+?>
\ No newline at end of file
diff --git a/lib/ImgSearch.class.php b/lib/ImgSearch.class.php
index 9e9d44b..c1aaf46 100755
--- a/lib/ImgSearch.class.php
+++ b/lib/ImgSearch.class.php
@@ -62,7 +62,7 @@ class ImgSearch {
public function getImageData() {
$clazz = ucfirst($this->engine);
$search = new $clazz();
- $search->setQuery($this->word);
+ $search->setQuery(urlencode($this->word));
$search->setParam('start', $this->hitPosition);
$search->setParam('size', $this->numberResults);
diff --git a/lib/ImgTools.class.php b/lib/ImgTools.class.php
index 2cd68b0..995ad9f 100755
--- a/lib/ImgTools.class.php
+++ b/lib/ImgTools.class.php
@@ -3,6 +3,10 @@
* Library of tool functions to manipulate an image
*/
class ImgTools {
+ public static $maxScreenWidth = 1067; //screen dimensions
+
+ public static $maxScreenHeight = 600;
+
public static $minFuzzFactor = 0.08; //minimal factor for $fuzz
public static $maxFuzzFactor = 0.64; //maximal factor for $fuzz
@@ -108,8 +112,10 @@ class ImgTools {
$mimeType = $imgInfo['mime'];
//find gif
if ($mimeType == "image/gif") {
- // Replace .gif extension with .png
- $newFilename = preg_replace('/\.gif$/i', '.png', $filename);
+ $imagetype = 'png';
+ //full image name
+ $Dot = '.';
+ $newFilename = "$filename$Dot$imagetype";
//convert
$img = new Imagick($filename);
@@ -157,7 +163,7 @@ class ImgTools {
public static function scaleByLength(Imagick $img, $maxW, $maxH) {
$width = $img->getImageWidth();
$height = $img->getImageHeight();
- if(($width <= ZAP_DEFAULT_WIDTH) && ($height <= ZAP_DEFAULT_HEIGHT)) {
+ if(($width <= self::$maxScreenWidth) && ($height <= self::$maxScreenHeight)) {
return $img;
} else {
if ($width >= $height) { //horizontal image
diff --git a/lib/ZAPController.class.php b/lib/ZAPController.class.php
index 29df4c8..27214f1 100755
--- a/lib/ZAPController.class.php
+++ b/lib/ZAPController.class.php
@@ -26,9 +26,7 @@ class ZAPController {
$this->mode = ucfirst($mode);
$clazz = $this->prefix . $this->mode;
if (!class_exists($clazz)) {
- http_response_code(404);
- include getZAPTemplate('404');
- die();
+ die('Wrong parameter');
}
$this->action = new $clazz();
}
@@ -37,9 +35,6 @@ class ZAPController {
* @return string content
*/
public function fetch() {
- if (!($this->action instanceof ZAPHandler)) {
- die('Handler does not implement ZAPHandler interface');
- }
return $this->action->getContent();
}
}
diff --git a/lib/ZAPDisplay.class.php b/lib/ZAPDisplay.class.php
index 3be56b0..a1398ab 100755
--- a/lib/ZAPDisplay.class.php
+++ b/lib/ZAPDisplay.class.php
@@ -2,7 +2,7 @@
/**
* Class is responsible for starting up ZAP machine
*/
-class ZAPDisplay implements ZAPHandler {
+class ZAPDisplay {
/**
* Template file
*/
@@ -28,18 +28,6 @@ class ZAPDisplay implements ZAPHandler {
*/
public function __construct() {
ob_start();
-
- // Validate CSRF token
- if (
- empty($_POST['csrf_token'])
- || empty($_SESSION['csrf_token'])
- || !hash_equals($_SESSION['csrf_token'], $_POST['csrf_token'])
- ) {
- http_response_code(400);
- echo '
Invalid or missing security token. Please go back and try again.
';
- die();
- }
-
$this->folder = $this->createFolder();
$this->words = $this->handleWords();
@@ -61,10 +49,9 @@ class ZAPDisplay implements ZAPHandler {
*/
private function createFolder() {
try {
- $suffix = bin2hex(random_bytes(4));
$folder = ZAP_APP_BASE_DIR . DIRECTORY_SEPARATOR
- . ZAP_SESSIONS_DIR . DIRECTORY_SEPARATOR . 'zap_' . ZAP_MOMENT . '_' . $suffix;
- if (!mkdir($folder, 0777, true)) {
+ . ZAP_SESSIONS_DIR . DIRECTORY_SEPARATOR . 'zap_' . ZAP_MOMENT;
+ if (!@mkdir($folder, 0777)) {
throw new Exception('
' . ERROR_PREFIX . 'Unable to create base dir: ' . $folder . '
');
}
return $folder;
@@ -80,11 +67,15 @@ class ZAPDisplay implements ZAPHandler {
*/
private function handleWords() {
$words = array();
- for ($i = 1; $i <= MAX_WORDS; $i++) {
- $key = 'word' . sprintf("%02d", $i);
- if (!empty($_POST[$key])) {
- $words[] = $_POST[$key];
- }
+ $ix = 1;
+ $postix = sprintf("%02d", $ix);
+ $wd = 'word' . $postix;
+
+ while(!empty($_POST[$wd])) {
+ array_push($words, $_POST[$wd]);
+ $ix++;
+ $postfix = sprintf("%02d", $ix);
+ $wd = 'word' . $postfix;
}
return $words;
}
diff --git a/lib/ZAPHandler.interface.php b/lib/ZAPHandler.interface.php
deleted file mode 100644
index 4f38e1a..0000000
--- a/lib/ZAPHandler.interface.php
+++ /dev/null
@@ -1,12 +0,0 @@
-ver = ZAP_VERSION;
+ extract(get_object_vars($this));
+
ob_start();
- $ver = ZAP_VERSION;
include getZAPTemplate($this->template);
$this->tpl .= ob_get_clean();
}
diff --git a/lib/ZAPZap.class.php b/lib/ZAPZap.class.php
index 143fef6..175f10a 100755
--- a/lib/ZAPZap.class.php
+++ b/lib/ZAPZap.class.php
@@ -2,7 +2,7 @@
/**
* ZAP factory
*/
-class ZAPZap implements ZAPHandler {
+class ZAPZap {
private $tpl = '';
private $folder;
private $height;
diff --git a/resource/Brave.class.php b/resource/Brave.class.php
index 74e727e..a55f164 100644
--- a/resource/Brave.class.php
+++ b/resource/Brave.class.php
@@ -21,20 +21,8 @@ class Brave implements Search {
public function setQuery($word) {
$this->word = $word;
- }
- public function getData() {
- $this->buildRequest();
- $return_array = $this->prepareData();
- return $return_array;
- }
-
- /**
- * Build the request URL and cURL handle after all setParam() calls have been made.
- * This ensures start/offset and size are available when constructing the URL.
- */
- private function buildRequest() {
- $request = $this->q_prefix . urlencode($this->word);
+ $request = $this->q_prefix . urlencode($word);
if (isset($this->start)) {
$request .= '&offset=' . $this->start;
}
@@ -50,6 +38,11 @@ class Brave implements Search {
$this->$key = $value;
}
+ public function getData() {
+ $return_array = $this->prepareData();
+ return $return_array;
+ }
+
/**
* Prepare a project wide universal array with results
*/
diff --git a/tpl/404.tpl b/tpl/404.tpl
deleted file mode 100644
index 68649d5..0000000
--- a/tpl/404.tpl
+++ /dev/null
@@ -1,29 +0,0 @@
-
-
-
-
-
404 - ZapMachine
-
-
-
-
-
error 404
-
-
diff --git a/tpl/index.tpl b/tpl/index.tpl
index 68354e2..a5fc6f4 100755
--- a/tpl/index.tpl
+++ b/tpl/index.tpl
@@ -12,11 +12,7 @@