check / check (push) Successful in 3m19s
A new page at /settings, linked from the navigation bar and behind the login, lists every configuration field the server loaded at startup: its environment variable, the README table's description, and the value in effect. METRICS_PASSWORD and SENTRY_DSN show only as set or not set; their values are replaced before rendering and never reach the template. The route is GET only and its group is built like the other admin page groups. Tests set the credentials one at a time so each value shown is checked against its own field and a set secret never appears in the page. Model: opus-5-5
60 lines
2.8 KiB
HTML
60 lines
2.8 KiB
HTML
{{define "navbar"}}
|
|
<nav class="app-bar" x-data="{ open: false }">
|
|
<div class="max-w-6xl mx-auto flex justify-between items-center">
|
|
<div class="flex items-center gap-3">
|
|
<a href="/" class="text-xl font-medium text-gray-900 hover:text-primary-600 transition-colors">Webhooker</a>
|
|
</div>
|
|
|
|
<!-- Mobile menu button -->
|
|
{{if .User}}
|
|
<button @click="open = !open" class="md:hidden p-2 rounded-md text-gray-500 hover:bg-gray-100">
|
|
<svg class="w-6 h-6" fill="none" stroke="currentColor" viewBox="0 0 24 24">
|
|
<path x-show="!open" stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M4 6h16M4 12h16M4 18h16"/>
|
|
<path x-show="open" x-cloak stroke-linecap="round" stroke-linejoin="round" stroke-width="2" d="M6 18L18 6M6 6l12 12"/>
|
|
</svg>
|
|
</button>
|
|
{{end}}
|
|
|
|
<!-- Desktop navigation -->
|
|
<div class="hidden md:flex items-center gap-4">
|
|
{{if .User}}
|
|
<a href="/hooks" class="btn-text">Webhooks</a>
|
|
<a href="/settings" class="btn-text">Settings</a>
|
|
<a href="/user/{{.User.Username}}" class="btn-text">
|
|
<svg class="w-5 h-5 mr-1" fill="currentColor" viewBox="0 0 16 16">
|
|
<path d="M11 6a3 3 0 1 1-6 0 3 3 0 0 1 6 0z"/>
|
|
<path fill-rule="evenodd" d="M0 8a8 8 0 1 1 16 0A8 8 0 0 1 0 8zm8-7a7 7 0 0 0-5.468 11.37C3.242 11.226 4.805 10 8 10s4.757 1.225 5.468 2.37A7 7 0 0 0 8 1z"/>
|
|
</svg>
|
|
{{.User.Username}}
|
|
</a>
|
|
{{/* An error page can be served before a form token is issued,
|
|
and a logout without one is refused. */}}
|
|
{{if .CSRFToken}}
|
|
<form method="POST" action="/pages/logout" class="inline">
|
|
<input type="hidden" name="csrf_token" value="{{.CSRFToken}}">
|
|
<button type="submit" class="btn-text">Logout</button>
|
|
</form>
|
|
{{end}}
|
|
{{end}}
|
|
</div>
|
|
</div>
|
|
|
|
<!-- Mobile navigation -->
|
|
<div x-show="open" x-cloak x-transition class="md:hidden mt-4 pt-4 border-t border-gray-200">
|
|
<div class="flex flex-col gap-2">
|
|
{{if .User}}
|
|
<a href="/hooks" class="btn-text w-full text-left">Webhooks</a>
|
|
<a href="/settings" class="btn-text w-full text-left">Settings</a>
|
|
<a href="/user/{{.User.Username}}" class="btn-text w-full text-left">Profile</a>
|
|
{{if .CSRFToken}}
|
|
<form method="POST" action="/pages/logout">
|
|
<input type="hidden" name="csrf_token" value="{{.CSRFToken}}">
|
|
<button type="submit" class="btn-text w-full text-left">Logout</button>
|
|
</form>
|
|
{{end}}
|
|
{{end}}
|
|
</div>
|
|
</div>
|
|
</nav>
|
|
{{end}}
|