Target names, URLs and log lines reach the page as text (closes #29)
check / check (push) Successful in 3m32s
check / check (push) Successful in 3m32s
A host row escapes the name and URL it writes into its markup with a new escapeHTML function, and the debug log builds each line as an element whose text is set, so neither is read as HTML once targets can be configured. A unit test builds the row of a target whose name and URL hold < > " & and ' and checks each comes out escaped; hostRowHTML is exported for it. README.md stops calling CONFIG frozen: the interval menu sets updateInterval, and the timeouts, history span and axis ticks are computed from it. AppState declares _recoveryProbeId and _recoveryProbeChecks, the sparkline axis functions drop the parameters they never used, and HostState's history comment names both entry shapes. Model: opus-5-5
This commit is contained in:
@@ -23,6 +23,15 @@ latest run passes.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04: a target's name and URL and a debug log message show as the
|
||||
characters they are and are never read as HTML (issue #29): a host row escapes
|
||||
the name and URL it writes into its markup, and the debug log sets each line
|
||||
as text. A unit test checks a target whose name and URL hold `<`, `>`, `"`,
|
||||
`&` and `'`. `README.md` no longer calls `CONFIG` frozen: the interval menu
|
||||
sets its `updateInterval`, and the values computed from it follow. `AppState`
|
||||
declares the recovery probe's two properties, the sparkline axis functions
|
||||
lose the parameters they did not use, and the comment on a target's history
|
||||
names both kinds of entry it holds. Nothing the page does changed
|
||||
- 2026-10-04: the backend serves Prometheus metrics (issue #94). With
|
||||
`METRICS_USERNAME` and `METRICS_PASSWORD` both set, it records request
|
||||
duration and response size through `go-http-metrics` and serves them, with
|
||||
|
||||
Reference in New Issue
Block a user