Compare commits

...
17 Commits
83 changed files with 2109 additions and 129 deletions
+3 -2
View File
@@ -10,7 +10,8 @@ export { Analytics } from '../modules/analytics/client.js';
*/
export { ConsentProvider, CookieBanner, CookieButton, useConsent, useConsentContext, } from '../modules/consent/client.js';
export type { CookieBannerClassNames } from '../modules/consent/client.js';
export { Turnstile } from '../modules/turnstile/client.js';
export type { TurnstileProps } from '../modules/turnstile/client.js';
export { resolveFormMessage } from '../modules/notifications/resolveFormMessage.js';
export type { FormNotificationTexts } from '../modules/notifications/types.js';
export { Turnstile } from '../modules/turnstile/client.js';
export { TurnstileProvider, useTurnstile } from '../modules/turnstile/client.js';
export type { TurnstileProps } from '../modules/turnstile/client.js';
+2 -1
View File
@@ -9,7 +9,8 @@ export { Analytics } from '../modules/analytics/client.js';
* components. Kept separate from the main entry so server bundles don't pull in
* client-only code.
*/ export { ConsentProvider, CookieBanner, CookieButton, useConsent, useConsentContext } from '../modules/consent/client.js';
export { Turnstile } from '../modules/turnstile/client.js';
export { resolveFormMessage } from '../modules/notifications/resolveFormMessage.js';
export { Turnstile } from '../modules/turnstile/client.js';
export { TurnstileProvider, useTurnstile } from '../modules/turnstile/client.js';
//# sourceMappingURL=client.js.map
+1 -1
View File
@@ -1 +1 @@
{"version":3,"sources":["../../src/exports/client.ts"],"sourcesContent":["'use client'\nexport { MaskedField } from '../globals/SiteIntegrations/components/MaskedField.js'\nexport { TestEmailButton } from '../globals/SiteIntegrations/components/TestEmailButton.js'\nexport { Analytics } from '../modules/analytics/client.js'\n/**\n * Entry point: ipal-kit/client\n *\n * Client-side ('use client') exports — React hooks, providers, and UI\n * components. Kept separate from the main entry so server bundles don't pull in\n * client-only code.\n */\nexport {\n ConsentProvider,\n CookieBanner,\n CookieButton,\n useConsent,\n useConsentContext,\n} from '../modules/consent/client.js'\nexport type { CookieBannerClassNames } from '../modules/consent/client.js'\nexport { Turnstile } from '../modules/turnstile/client.js'\nexport type { TurnstileProps } from '../modules/turnstile/client.js'\n\nexport { resolveFormMessage } from '../modules/notifications/resolveFormMessage.js'\nexport type { FormNotificationTexts } from '../modules/notifications/types.js'\n"],"names":["MaskedField","TestEmailButton","Analytics","ConsentProvider","CookieBanner","CookieButton","useConsent","useConsentContext","Turnstile","resolveFormMessage"],"mappings":"AAAA;AACA,SAASA,WAAW,QAAQ,wDAAuD;AACnF,SAASC,eAAe,QAAQ,4DAA2D;AAC3F,SAASC,SAAS,QAAQ,iCAAgC;AAC1D;;;;;;CAMC,GACD,SACEC,eAAe,EACfC,YAAY,EACZC,YAAY,EACZC,UAAU,EACVC,iBAAiB,QACZ,+BAA8B;AAErC,SAASC,SAAS,QAAQ,iCAAgC;AAG1D,SAASC,kBAAkB,QAAQ,iDAAgD"}
{"version":3,"sources":["../../src/exports/client.ts"],"sourcesContent":["'use client'\nexport { MaskedField } from '../globals/SiteIntegrations/components/MaskedField.js'\nexport { TestEmailButton } from '../globals/SiteIntegrations/components/TestEmailButton.js'\nexport { Analytics } from '../modules/analytics/client.js'\n/**\n * Entry point: ipal-kit/client\n *\n * Client-side ('use client') exports — React hooks, providers, and UI\n * components. Kept separate from the main entry so server bundles don't pull in\n * client-only code.\n */\nexport {\n ConsentProvider,\n CookieBanner,\n CookieButton,\n useConsent,\n useConsentContext,\n} from '../modules/consent/client.js'\nexport type { CookieBannerClassNames } from '../modules/consent/client.js'\nexport { resolveFormMessage } from '../modules/notifications/resolveFormMessage.js'\nexport type { FormNotificationTexts } from '../modules/notifications/types.js'\nexport { Turnstile } from '../modules/turnstile/client.js'\nexport { TurnstileProvider, useTurnstile } from '../modules/turnstile/client.js'\nexport type { TurnstileProps } from '../modules/turnstile/client.js'\n"],"names":["MaskedField","TestEmailButton","Analytics","ConsentProvider","CookieBanner","CookieButton","useConsent","useConsentContext","resolveFormMessage","Turnstile","TurnstileProvider","useTurnstile"],"mappings":"AAAA;AACA,SAASA,WAAW,QAAQ,wDAAuD;AACnF,SAASC,eAAe,QAAQ,4DAA2D;AAC3F,SAASC,SAAS,QAAQ,iCAAgC;AAC1D;;;;;;CAMC,GACD,SACEC,eAAe,EACfC,YAAY,EACZC,YAAY,EACZC,UAAU,EACVC,iBAAiB,QACZ,+BAA8B;AAErC,SAASC,kBAAkB,QAAQ,iDAAgD;AAEnF,SAASC,SAAS,QAAQ,iCAAgC;AAC1D,SAASC,iBAAiB,EAAEC,YAAY,QAAQ,iCAAgC"}
+2 -2
View File
@@ -6,11 +6,11 @@ import { notificationsFields } from './fields.js';
*/ export function buildNotifications() {
return {
slug: 'notifications',
label: 'Notifications',
access: {
read: ()=>true
},
fields: notificationsFields
fields: notificationsFields,
label: 'Notifications'
};
}
+1 -1
View File
@@ -1 +1 @@
{"version":3,"sources":["../../../src/globals/Notifications/index.ts"],"sourcesContent":["import type { GlobalConfig } from 'payload'\nimport { notificationsFields } from './fields.js'\n\n/**\n * Builds the Notifications global — localized action-result texts. Readable by\n * any authenticated panel user; server-side helpers read it with overrideAccess\n * so the frontend can resolve texts without a session.\n */\nexport function buildNotifications(): GlobalConfig {\n return {\n slug: 'notifications',\n label: 'Notifications',\n access: {\n read: () => true, // texts are public-facing (shown to end users)\n },\n fields: notificationsFields,\n }\n}\n"],"names":["notificationsFields","buildNotifications","slug","label","access","read","fields"],"mappings":"AACA,SAASA,mBAAmB,QAAQ,cAAa;AAEjD;;;;CAIC,GACD,OAAO,SAASC;IACd,OAAO;QACLC,MAAM;QACNC,OAAO;QACPC,QAAQ;YACNC,MAAM,IAAM;QACd;QACAC,QAAQN;IACV;AACF"}
{"version":3,"sources":["../../../src/globals/Notifications/index.ts"],"sourcesContent":["import type { GlobalConfig } from 'payload'\n\nimport { notificationsFields } from './fields.js'\n\n/**\n * Builds the Notifications global — localized action-result texts. Readable by\n * any authenticated panel user; server-side helpers read it with overrideAccess\n * so the frontend can resolve texts without a session.\n */\nexport function buildNotifications(): GlobalConfig {\n return {\n slug: 'notifications',\n access: {\n read: () => true, // texts are public-facing (shown to end users)\n },\n fields: notificationsFields,\n label: 'Notifications',\n }\n}\n"],"names":["notificationsFields","buildNotifications","slug","access","read","fields","label"],"mappings":"AAEA,SAASA,mBAAmB,QAAQ,cAAa;AAEjD;;;;CAIC,GACD,OAAO,SAASC;IACd,OAAO;QACLC,MAAM;QACNC,QAAQ;YACNC,MAAM,IAAM;QACd;QACAC,QAAQL;QACRM,OAAO;IACT;AACF"}
+10 -3
View File
@@ -16,25 +16,32 @@ export type { PanelSmtpAdapterArgs } from './modules/email/panelSmtpAdapter.js';
export { buildFormsPlugin } from './modules/forms/formsPluginConfig.js';
export type { FormsCollectionOverrides, FormsFieldsOverride, FormsOption, } from './modules/forms/types.js';
export { createContentHelpers } from './modules/frontend/index.js';
export { buildPreventDeleteSystemPage, buildRevalidateHook, buildValidateUniqueRole, setPublishedAtHook, trackSlugHistoryHook, } from './modules/hooks/index.js';
export type { I18nConfig, LocaleDefinition, LocalizedSlugs } from './modules/i18n/index.js';
export { buildLocalizedPath, getDefaultLocale, getLocaleCodes, getLocaleDefinition, getLocalizedSlugs, isValidLocale, LOCALE_COOKIE_NAME, matchAcceptLanguage, negotiateLocale, switchLocalePath, } from './modules/i18n/index.js';
export type { LocaleMiddlewareResult } from './modules/i18n/index.js';
export { createLocaleMiddleware, DEFAULT_MIDDLEWARE_MATCHER } from './modules/i18n/index.js';
export { normalizeFilename, normalizeFilenameHook } from './modules/media/index.js';
export { getNotificationTexts, NOTIFICATION_FALLBACK, resolveFormMessage, } from './modules/notifications/index.js';
export type { FormNotificationTexts, NotificationsData, NotificationTexts, } from './modules/notifications/index.js';
export type { FormNotificationTexts, NotificationTexts } from './modules/notifications/index.js';
export type { PagesOption, SystemPageRole } from './modules/pages/index.js';
export { ALL_SYSTEM_PAGE_ROLES, getSystemPagePath } from './modules/pages/index.js';
export type { GlobalQueryOptions } from './modules/payload/index.js';
export { getGlobal, getSiteIntegrations, getSiteSettings, SITE_INTEGRATIONS_SLUG, SITE_SETTINGS_SLUG, } from './modules/payload/index.js';
export { buildSecurityHeaders } from './modules/security/index.js';
export { buildCsp } from './modules/security/index.js';
export type { BuildCspArgs } from './modules/security/index.js';
export type { BuildSecurityHeadersArgs, SecurityHeader } from './modules/security/index.js';
export { buildArticleJsonLd, buildFaqJsonLd, buildIconsMetadata, buildLlmsTxt, buildLocalBusinessJsonLd, buildOrganizationJsonLd, buildServiceJsonLd, validateFaviconField, } from './modules/seo/index.js';
export { buildBreadcrumbJsonLd, buildSiteNavigationJsonLd, buildWebSiteJsonLd, } from './modules/seo/index.js';
export type { PageMetadata, SeoMeta, SeoOption } from './modules/seo/index.js';
export { buildHreflangAlternates, buildMetadata, composeTitle } from './modules/seo/index.js';
export type { AutoFillMapping, RobotsRules, SitemapEntry } from './modules/seo/index.js';
export { buildAutoFillMetaHook, buildRobots, buildSitemapEntries, createMetadataGenerator, createPageMetadata, injectAutoFillMeta, } from './modules/seo/index.js';
export { buildIconsMetadata, buildOrganizationJsonLd, validateFaviconField, } from './modules/seo/index.js';
export { buildBreadcrumbJsonLd, buildSiteNavigationJsonLd, buildWebSiteJsonLd, } from './modules/seo/index.js';
export { buildFaqJsonLd, buildLocalBusinessJsonLd, buildServiceJsonLd, } from './modules/seo/index.js';
export { buildArticleJsonLd } from './modules/seo/index.js';
export { buildSitemapXml } from './modules/seo/index.js';
export { buildLlmsTxt } from './modules/seo/index.js';
export { buildSlugField, toSlug } from './modules/slug/index.js';
export { buildR2Storage } from './modules/storage/index.js';
export { ipalKit } from './plugin.js';
+9 -6
View File
@@ -10,22 +10,25 @@ export { mailAdapter } from './modules/email/mailAdapter.js';
export { panelSmtpAdapter } from './modules/email/panelSmtpAdapter.js';
export { buildFormsPlugin } from './modules/forms/formsPluginConfig.js';
export { createContentHelpers } from './modules/frontend/index.js';
export { buildPreventDeleteSystemPage, buildRevalidateHook, buildValidateUniqueRole, setPublishedAtHook, trackSlugHistoryHook } from './modules/hooks/index.js';
export { buildLocalizedPath, getDefaultLocale, getLocaleCodes, getLocaleDefinition, getLocalizedSlugs, isValidLocale, LOCALE_COOKIE_NAME, matchAcceptLanguage, negotiateLocale, switchLocalePath } from './modules/i18n/index.js';
export { createLocaleMiddleware, DEFAULT_MIDDLEWARE_MATCHER } from './modules/i18n/index.js';
// Media — filename normalization hook for upload collections (Media).
export { normalizeFilename, normalizeFilenameHook } from './modules/media/index.js';
export { getNotificationTexts, NOTIFICATION_FALLBACK, resolveFormMessage } from './modules/notifications/index.js';
export { ALL_SYSTEM_PAGE_ROLES, getSystemPagePath } from './modules/pages/index.js';
export { getGlobal, getSiteIntegrations, getSiteSettings, SITE_INTEGRATIONS_SLUG, SITE_SETTINGS_SLUG } from './modules/payload/index.js';
export { buildSecurityHeaders } from './modules/security/index.js';
export { buildArticleJsonLd, buildFaqJsonLd, buildIconsMetadata, buildLlmsTxt, buildLocalBusinessJsonLd, buildOrganizationJsonLd, buildServiceJsonLd, validateFaviconField } from './modules/seo/index.js';
// Structured data (schema.org JSON-LD) — brand/sitelink signals for Google.
// WebSite (+ optional SearchAction), BreadcrumbList (per page), SiteNavigation.
export { buildBreadcrumbJsonLd, buildSiteNavigationJsonLd, buildWebSiteJsonLd } from './modules/seo/index.js';
export { buildCsp } from './modules/security/index.js';
export { buildHreflangAlternates, buildMetadata, composeTitle } from './modules/seo/index.js';
export { buildAutoFillMetaHook, buildRobots, buildSitemapEntries, createMetadataGenerator, createPageMetadata, injectAutoFillMeta } from './modules/seo/index.js';
export { buildIconsMetadata, buildOrganizationJsonLd, validateFaviconField } from './modules/seo/index.js';
export { buildBreadcrumbJsonLd, buildSiteNavigationJsonLd, buildWebSiteJsonLd } from './modules/seo/index.js';
// Local SEO structured data — LocalBusiness (map pack), Service (offering), FAQPage.
export { buildFaqJsonLd, buildLocalBusinessJsonLd, buildServiceJsonLd } from './modules/seo/index.js';
export { buildArticleJsonLd } from './modules/seo/index.js';
export { buildSitemapXml } from './modules/seo/index.js';
export { buildLlmsTxt } from './modules/seo/index.js';
export { buildSlugField, toSlug } from './modules/slug/index.js';
// Storage — Cloudflare R2 media offload, configured from .env.
export { buildR2Storage } from './modules/storage/index.js';
export { ipalKit } from './plugin.js';
+1 -1
View File
File diff suppressed because one or more lines are too long
+22 -16
View File
@@ -1,8 +1,14 @@
import type { BasePayload, SanitizedConfig } from 'payload';
import type { ContentOption, ResolvedRoute, ArchiveEntries } from '../content/index.js';
import type { ArchiveEntries, ContentOption, ResolvedRoute } from '../content/index.js';
import type { I18nConfig } from '../i18n/index.js';
import type { SitemapEntry, RobotsRules } from '../seo/index.js';
import type { RobotsRules, SitemapEntry } from '../seo/index.js';
type CreateContentHelpersArgs = {
/**
* Absolute site origin for sitemap/robots URLs. Falls back to
* NEXT_PUBLIC_SERVER_URL, then to a relative origin (which most crawlers
* reject, so set one in production).
*/
baseUrl?: string;
/**
* The client's payload config promise (the default export of payload.config).
* Passed in because the plugin never imports the client's config directly.
@@ -10,21 +16,15 @@ type CreateContentHelpersArgs = {
config: Promise<SanitizedConfig> | SanitizedConfig;
/** Archive-backed collections, same value as the plugin option. */
content?: ContentOption;
/** SiteSettings global slug. Defaults to 'site-settings'. */
settingsSlug?: string;
/** Pages collection slug. Defaults to 'pages'. */
pagesSlug?: string;
/**
* i18n config. Required only if you want the ready-made `sitemap` / `robots`
* handlers — they need the locale list to emit hreflang.
*/
i18n?: I18nConfig;
/**
* Absolute site origin for sitemap/robots URLs. Falls back to
* NEXT_PUBLIC_SERVER_URL, then to a relative origin (which most crawlers
* reject, so set one in production).
*/
baseUrl?: string;
/** Pages collection slug. Defaults to 'pages'. */
pagesSlug?: string;
/** SiteSettings global slug. Defaults to 'site-settings'. */
settingsSlug?: string;
};
/**
* Bundles the per-request data helpers a frontend needs — the same cached
@@ -52,13 +52,19 @@ type CreateContentHelpersArgs = {
* a URL is, fetching gets the listing. Metadata generation needs the first and
* not the second, and a page component composes them in two obvious lines.
*/
export declare function createContentHelpers({ config, content, settingsSlug, pagesSlug, i18n, baseUrl, }: CreateContentHelpersArgs): {
export declare function createContentHelpers({ baseUrl, config, content, i18n, pagesSlug, settingsSlug, }: CreateContentHelpersArgs): {
generateStaticParams: () => Promise<Array<{
locale: string;
slug: string[];
} | {
slug: string[];
}>>;
getCachedPayload: () => Promise<BasePayload>;
getConfiguredLocales: () => Promise<string[]>;
getSettings: (locale: string) => Promise<import("payload").JsonObject>;
resolveRoute: (locale: string, segments: string[] | undefined, page: number) => Promise<ResolvedRoute | null>;
getEntries: (collection: string, locale: string, page: number, perPage: number) => Promise<ArchiveEntries>;
sitemap: () => Promise<SitemapEntry[]>;
getSettings: (locale: string) => Promise<import("payload").JsonObject>;
resolveRoute: (locale: string, segments: string[] | undefined, page: number) => Promise<null | ResolvedRoute>;
robots: () => RobotsRules;
sitemap: () => Promise<SitemapEntry[]>;
};
export {};
+125 -16
View File
@@ -1,7 +1,7 @@
import { cache } from 'react';
import { getPayload } from 'payload';
import { resolveRoute as resolveRouteRaw, getArchiveEntries } from '../content/index.js';
import { buildSitemapEntries, buildRobots } from '../seo/index.js';
import { cache } from 'react';
import { getArchiveEntries, resolveRoute as resolveRouteRaw } from '../content/index.js';
import { buildRobots, buildSitemapEntries } from '../seo/index.js';
/**
* Bundles the per-request data helpers a frontend needs — the same cached
* wrappers every project was writing by hand (getPayload, settings, locale
@@ -27,7 +27,7 @@ import { buildSitemapEntries, buildRobots } from '../seo/index.js';
* `resolveRoute` and `getEntries` are separate on purpose: routing decides what
* a URL is, fetching gets the listing. Metadata generation needs the first and
* not the second, and a page component composes them in two obvious lines.
*/ export function createContentHelpers({ config, content, settingsSlug = 'site-settings', pagesSlug = 'pages', i18n, baseUrl }) {
*/ export function createContentHelpers({ baseUrl, config, content, i18n, pagesSlug = 'pages', settingsSlug = 'site-settings' }) {
const origin = baseUrl ?? process.env.NEXT_PUBLIC_SERVER_URL ?? '';
const getCachedPayload = cache(async ()=>getPayload({
config: await config
@@ -40,29 +40,29 @@ import { buildSitemapEntries, buildRobots } from '../seo/index.js';
const payload = await getCachedPayload();
return payload.findGlobal({
slug: settingsSlug,
locale: locale,
depth: 2
depth: 2,
locale: locale
});
});
/** What does this URL point at? Routing only — no listing data. */ const resolveRoute = cache(async (locale, segments, page)=>{
const payload = await getCachedPayload();
return resolveRouteRaw({
payload,
locale,
segments,
page,
content,
locale,
page,
pagesSlug,
payload,
segments,
settingsSlug
});
});
/** One page of a collection's entries, for an archive listing. */ const getEntries = cache(async (collection, locale, page, perPage)=>{
const payload = await getCachedPayload();
return getArchiveEntries({
payload,
collection,
locale,
page,
payload,
perPage
});
});
@@ -92,11 +92,11 @@ import { buildSitemapEntries, buildRobots } from '../seo/index.js';
}
try {
return await buildSitemapEntries({
payload: await getCachedPayload(),
config: i18n,
baseUrl: origin,
config: i18n,
content,
pagesSlug,
payload: await getCachedPayload(),
settingsSlug
});
} catch (error) {
@@ -117,14 +117,123 @@ import { buildSitemapEntries, buildRobots } from '../seo/index.js';
*/ const robots = ()=>buildRobots({
baseUrl: origin
});
/**
* Next.js generateStaticParams for the [[...slug]] route (or
* [locale]/[[...slug]]). Returns every routable page as a params object, so
* Next PRE-RENDERS them as static (SSG) instead of dynamic.
*
* Why this matters beyond convenience: an optional catch-all with no
* generateStaticParams is treated as a DYNAMIC route (ƒ), which streams
* metadata into <body> (crawlers miss it). Providing generateStaticParams
* compiles routes as SSG (●) — the <head> is synchronous and complete. This is
* the strongest fix for the metadata-in-head problem (stronger than ISR alone).
*
* Handles automatically:
* - pages collection + content collections (with their archive prefix)
* - excludes the homepage (maps to { slug: [] } — the root)
* - excludes drafts and 404/500/system slugs
* - KEEPS noindex pages (they must still render — noindex controls indexing,
* not existence; skipping them would force dynamic rendering)
* - localized slugs (string or per-locale map) both handled
* - single-locale → { slug }[]; multi-locale → { locale, slug }[]
*
* Wire it in the project:
* // app/(frontend)/[[...slug]]/page.tsx (or [locale]/[[...slug]])
* export { generateStaticParams } from '@/lib/content'
*/ const generateStaticParams = async ()=>{
try {
const payload = await getCachedPayload();
const locales = i18n ? i18n.locales.map((l)=>l.code) : [
undefined
];
const singleLocale = !i18n || i18n.locales.length === 1;
// Home slug per locale, to exclude the homepage (it's the root, slug []).
const settings = await payload.findGlobal({
slug: settingsSlug,
depth: 1,
locale: 'all'
}).catch(()=>null);
const homeId = settings?.homepage?.id;
const EXCLUDED = new Set([
'404',
'500',
'error',
'not-found'
]);
const params = [];
for (const locale of locales){
// NO where:{_status} filter — collections without drafts enabled don't
// register the _status field, and querying it throws
// "path cannot be queried: _status". We filter drafts in memory below,
// which is safe for every collection (with or without drafts).
const result = await payload.find({
collection: pagesSlug,
depth: 0,
limit: 1000,
locale: locale ?? 'all'
});
for (const raw of result.docs){
// Draft filter in memory (safe whether or not the collection has drafts).
if (raw._status && raw._status !== 'published') {
continue;
}
// NOTE: unlike the sitemap, we do NOT skip meta.noindex here. A noindex
// page (privacy, cookies, terms) still needs to render — users reach it
// from the footer and crawlers read its <meta robots=noindex>. Pre-render
// it as SSG so it's fast and its <head> is complete; noindex controls
// INDEXING, not whether the page exists. Skipping it would force dynamic
// rendering (the very streaming problem we're avoiding).
if (homeId && raw.id === homeId) {
// Homepage → root. Emit an empty-slug param so '/' (or '/pl') builds.
const empty = singleLocale ? {
slug: []
} : {
slug: [],
locale: locale
};
if (!params.some((p)=>JSON.stringify(p) === JSON.stringify(empty))) {
params.push(empty);
}
continue;
}
// Slug may be a plain string OR a localized map ({ pl: 'kontakt' }) when
// read with locale:'all' or left unflattened. Handle both, or localized
// pages get silently dropped.
const rawSlug = raw.slug;
const slug = typeof rawSlug === 'string' ? rawSlug : rawSlug && typeof rawSlug === 'object' ? rawSlug[locale ?? ''] ?? Object.values(rawSlug)[0] : undefined;
if (!slug || EXCLUDED.has(slug)) {
continue;
}
// Multi-level slugs ('atrakcje/telefon') → array segments.
const segments = String(slug).split('/').filter(Boolean);
params.push(singleLocale ? {
slug: segments
} : {
slug: segments,
locale: locale
});
}
}
return params;
} catch (err) {
// DB unreachable — typically a container build (Docker/Coolify/CI) with no
// database network. Return [] so the build doesn't crash: Next falls back
// to on-demand rendering for the routes, which fill in once the DB is
// reachable at runtime. Without this every project would need its own
// try/catch here. (Same graceful-degradation as the sitemap handler.)
console.warn('[ipal] generateStaticParams: database not reachable during build ' + '(Docker/CI) — returning empty params; routes render on-demand at runtime:', err);
return [];
}
};
return {
generateStaticParams,
getCachedPayload,
getConfiguredLocales,
getEntries,
getSettings,
resolveRoute,
getEntries,
sitemap,
robots
robots,
sitemap
};
}
File diff suppressed because one or more lines are too long
+35
View File
@@ -0,0 +1,35 @@
import type { CollectionAfterChangeHook, CollectionAfterDeleteHook } from 'payload';
import type { I18nConfig } from '../i18n/index.js';
type RevalidateFn = (path: string) => void;
type BuildRevalidateHookArgs = {
config: I18nConfig;
/** Home slug (string or per-locale map) — home revalidates the root. */
homeSlug?: Record<string, string> | string;
/**
* next/cache revalidatePath, INJECTED by the project. The plugin never imports
* next/cache itself — that would crash when Payload runs as plain Node
* (generate:importmap). The project passes it: `revalidatePath` from 'next/cache'.
*/
revalidatePath: RevalidateFn;
};
/**
* Builds afterChange + afterDelete hooks that revalidate a page's ISR cache when
* an editor saves or deletes it — so changes appear immediately instead of
* waiting for the revalidate window. Without this, ISR means editors wait; with
* it, ISR is usable for a CMS.
*
* Handles every locale, the root (home), AND a changed slug (revalidates both the
* old and new path so neither goes stale). revalidatePath is injected — the
* plugin never imports next/cache (safe under generate:importmap / plain Node).
*
* // in your Media/Pages collection config, from a project file that CAN import next/cache:
* import { revalidatePath } from 'next/cache'
* import { buildRevalidateHook } from '@intecion/ipal-kit'
* const { afterChange, afterDelete } = buildRevalidateHook({ revalidatePath, config: i18nConfig })
* // hooks: { afterChange: [afterChange], afterDelete: [afterDelete] }
*/
export declare function buildRevalidateHook({ config, homeSlug, revalidatePath, }: BuildRevalidateHookArgs): {
afterChange: CollectionAfterChangeHook;
afterDelete: CollectionAfterDeleteHook;
};
export {};
+71
View File
@@ -0,0 +1,71 @@
import { buildLocalizedPath, getLocaleCodes } from '../i18n/index.js';
/** Resolve a doc's path in one locale (root for home). Null if no slug there. */ function pathForLocale(doc, locale, config, homeSlug) {
const slugField = doc.slug;
const slug = typeof slugField === 'string' ? slugField : slugField && typeof slugField === 'object' ? slugField[locale] : undefined;
if (!slug) {
return null;
}
return buildLocalizedPath({
config,
homeSlug,
locale,
slugs: {
[locale]: slug
}
}) ?? null;
}
/**
* Builds afterChange + afterDelete hooks that revalidate a page's ISR cache when
* an editor saves or deletes it — so changes appear immediately instead of
* waiting for the revalidate window. Without this, ISR means editors wait; with
* it, ISR is usable for a CMS.
*
* Handles every locale, the root (home), AND a changed slug (revalidates both the
* old and new path so neither goes stale). revalidatePath is injected — the
* plugin never imports next/cache (safe under generate:importmap / plain Node).
*
* // in your Media/Pages collection config, from a project file that CAN import next/cache:
* import { revalidatePath } from 'next/cache'
* import { buildRevalidateHook } from '@intecion/ipal-kit'
* const { afterChange, afterDelete } = buildRevalidateHook({ revalidatePath, config: i18nConfig })
* // hooks: { afterChange: [afterChange], afterDelete: [afterDelete] }
*/ export function buildRevalidateHook({ config, homeSlug, revalidatePath }) {
const locales = getLocaleCodes(config);
const afterChange = ({ doc, previousDoc })=>{
const seen = new Set();
for (const locale of locales){
// New path.
const newPath = pathForLocale(doc, locale, config, homeSlug);
if (newPath && !seen.has(newPath)) {
revalidatePath(newPath);
seen.add(newPath);
}
// Old path, if the slug changed — so the old URL doesn't serve stale content.
if (previousDoc) {
const oldPath = pathForLocale(previousDoc, locale, config, homeSlug);
if (oldPath && oldPath !== newPath && !seen.has(oldPath)) {
revalidatePath(oldPath);
seen.add(oldPath);
}
}
}
return doc;
};
const afterDelete = ({ doc })=>{
const seen = new Set();
for (const locale of locales){
const path = pathForLocale(doc, locale, config, homeSlug);
if (path && !seen.has(path)) {
revalidatePath(path);
seen.add(path);
}
}
return doc;
};
return {
afterChange,
afterDelete
};
}
//# sourceMappingURL=buildRevalidateHook.js.map
File diff suppressed because one or more lines are too long
+7
View File
@@ -0,0 +1,7 @@
export { normalizeFilenameHook } from '../media/index.js';
export { buildAutoFillMetaHook, validateFaviconField } from '../seo/index.js';
export { buildRevalidateHook } from './buildRevalidateHook.js';
export { buildPreventDeleteSystemPage } from './preventDeleteSystemPage.js';
export { setPublishedAtHook } from './setPublishedAt.js';
export { trackSlugHistoryHook } from './trackSlugHistory.js';
export { buildValidateUniqueRole } from './validateUniqueRole.js';
+11
View File
@@ -0,0 +1,11 @@
// Re-eksport hooków domenowych (mieszkają w swoich modułach, tu dla przeglądu —
// żeby był jeden katalog "wszystkie hooki pluginu"). Źródło prawdy to ich moduły.
export { normalizeFilenameHook } from '../media/index.js';
export { buildAutoFillMetaHook, validateFaviconField } from '../seo/index.js';
export { buildRevalidateHook } from './buildRevalidateHook.js';
export { buildPreventDeleteSystemPage } from './preventDeleteSystemPage.js';
export { setPublishedAtHook } from './setPublishedAt.js';
export { trackSlugHistoryHook } from './trackSlugHistory.js';
export { buildValidateUniqueRole } from './validateUniqueRole.js';
//# sourceMappingURL=index.js.map
+1
View File
@@ -0,0 +1 @@
{"version":3,"sources":["../../../src/modules/hooks/index.ts"],"sourcesContent":["// Re-eksport hooków domenowych (mieszkają w swoich modułach, tu dla przeglądu —\n// żeby był jeden katalog \"wszystkie hooki pluginu\"). Źródło prawdy to ich moduły.\nexport { normalizeFilenameHook } from '../media/index.js'\nexport { buildAutoFillMetaHook, validateFaviconField } from '../seo/index.js'\nexport { buildRevalidateHook } from './buildRevalidateHook.js'\nexport { buildPreventDeleteSystemPage } from './preventDeleteSystemPage.js'\nexport { setPublishedAtHook } from './setPublishedAt.js'\n\nexport { trackSlugHistoryHook } from './trackSlugHistory.js'\nexport { buildValidateUniqueRole } from './validateUniqueRole.js'\n"],"names":["normalizeFilenameHook","buildAutoFillMetaHook","validateFaviconField","buildRevalidateHook","buildPreventDeleteSystemPage","setPublishedAtHook","trackSlugHistoryHook","buildValidateUniqueRole"],"mappings":"AAAA,gFAAgF;AAChF,kFAAkF;AAClF,SAASA,qBAAqB,QAAQ,oBAAmB;AACzD,SAASC,qBAAqB,EAAEC,oBAAoB,QAAQ,kBAAiB;AAC7E,SAASC,mBAAmB,QAAQ,2BAA0B;AAC9D,SAASC,4BAA4B,QAAQ,+BAA8B;AAC3E,SAASC,kBAAkB,QAAQ,sBAAqB;AAExD,SAASC,oBAAoB,QAAQ,wBAAuB;AAC5D,SAASC,uBAAuB,QAAQ,0BAAyB"}
+15
View File
@@ -0,0 +1,15 @@
import type { CollectionBeforeDeleteHook } from 'payload';
/**
* Blocks deletion of a page assigned a System Page role (homepage,
* privacyPolicy, cookiePolicy, termsOfService). An editor deleting the privacy
* policy or homepage by accident would break routing and compliance links; this
* stops it with a clear error. They must unassign the role first (deliberate).
*
* Reads the role assignments from SiteSettings (which page holds which role).
*
* hooks: { beforeDelete: [buildPreventDeleteSystemPage({ settingsSlug: 'site-settings' })] }
*/
export declare function buildPreventDeleteSystemPage(args?: {
roleFields?: string[];
settingsSlug?: string;
}): CollectionBeforeDeleteHook;
+37
View File
@@ -0,0 +1,37 @@
import { APIError } from 'payload';
/**
* Blocks deletion of a page assigned a System Page role (homepage,
* privacyPolicy, cookiePolicy, termsOfService). An editor deleting the privacy
* policy or homepage by accident would break routing and compliance links; this
* stops it with a clear error. They must unassign the role first (deliberate).
*
* Reads the role assignments from SiteSettings (which page holds which role).
*
* hooks: { beforeDelete: [buildPreventDeleteSystemPage({ settingsSlug: 'site-settings' })] }
*/ export function buildPreventDeleteSystemPage(args = {}) {
const settingsSlug = args.settingsSlug ?? 'site-settings';
const roleFields = args.roleFields ?? [
'homepage',
'privacyPolicy',
'cookiePolicy',
'termsOfService'
];
return async ({ id, req })=>{
const settings = await req.payload.findGlobal({
slug: settingsSlug,
depth: 0
}).catch(()=>null);
if (!settings) {
return;
}
for (const field of roleFields){
const assigned = settings[field];
const assignedId = assigned && typeof assigned === 'object' ? assigned.id : assigned;
if (assignedId != null && String(assignedId) === String(id)) {
throw new APIError(`Nie można usunąć strony przypisanej do roli systemowej "${field}". ` + `Najpierw odłącz rolę w Site Settings.`, 400);
}
}
};
}
//# sourceMappingURL=preventDeleteSystemPage.js.map
+1
View File
@@ -0,0 +1 @@
{"version":3,"sources":["../../../src/modules/hooks/preventDeleteSystemPage.ts"],"sourcesContent":["import type { CollectionBeforeDeleteHook } from 'payload'\n\nimport { APIError } from 'payload'\n\n/**\n * Blocks deletion of a page assigned a System Page role (homepage,\n * privacyPolicy, cookiePolicy, termsOfService). An editor deleting the privacy\n * policy or homepage by accident would break routing and compliance links; this\n * stops it with a clear error. They must unassign the role first (deliberate).\n *\n * Reads the role assignments from SiteSettings (which page holds which role).\n *\n * hooks: { beforeDelete: [buildPreventDeleteSystemPage({ settingsSlug: 'site-settings' })] }\n */\nexport function buildPreventDeleteSystemPage(\n args: { roleFields?: string[]; settingsSlug?: string } = {},\n): CollectionBeforeDeleteHook {\n const settingsSlug = args.settingsSlug ?? 'site-settings'\n const roleFields = args.roleFields ?? [\n 'homepage',\n 'privacyPolicy',\n 'cookiePolicy',\n 'termsOfService',\n ]\n\n return async ({ id, req }) => {\n const settings = (await req.payload\n .findGlobal({ slug: settingsSlug as never, depth: 0 })\n .catch(() => null)) as null | Record<string, unknown>\n if (!settings) {return}\n\n for (const field of roleFields) {\n const assigned = settings[field]\n const assignedId =\n assigned && typeof assigned === 'object' ? (assigned as { id?: unknown }).id : assigned\n if (assignedId != null && String(assignedId) === String(id)) {\n throw new APIError(\n `Nie można usunąć strony przypisanej do roli systemowej \"${field}\". ` +\n `Najpierw odłącz rolę w Site Settings.`,\n 400,\n )\n }\n }\n }\n}\n"],"names":["APIError","buildPreventDeleteSystemPage","args","settingsSlug","roleFields","id","req","settings","payload","findGlobal","slug","depth","catch","field","assigned","assignedId","String"],"mappings":"AAEA,SAASA,QAAQ,QAAQ,UAAS;AAElC;;;;;;;;;CASC,GACD,OAAO,SAASC,6BACdC,OAAyD,CAAC,CAAC;IAE3D,MAAMC,eAAeD,KAAKC,YAAY,IAAI;IAC1C,MAAMC,aAAaF,KAAKE,UAAU,IAAI;QACpC;QACA;QACA;QACA;KACD;IAED,OAAO,OAAO,EAAEC,EAAE,EAAEC,GAAG,EAAE;QACvB,MAAMC,WAAY,MAAMD,IAAIE,OAAO,CAChCC,UAAU,CAAC;YAAEC,MAAMP;YAAuBQ,OAAO;QAAE,GACnDC,KAAK,CAAC,IAAM;QACf,IAAI,CAACL,UAAU;YAAC;QAAM;QAEtB,KAAK,MAAMM,SAAST,WAAY;YAC9B,MAAMU,WAAWP,QAAQ,CAACM,MAAM;YAChC,MAAME,aACJD,YAAY,OAAOA,aAAa,WAAW,AAACA,SAA8BT,EAAE,GAAGS;YACjF,IAAIC,cAAc,QAAQC,OAAOD,gBAAgBC,OAAOX,KAAK;gBAC3D,MAAM,IAAIL,SACR,CAAC,wDAAwD,EAAEa,MAAM,GAAG,CAAC,GACnE,CAAC,qCAAqC,CAAC,EACzC;YAEJ;QACF;IACF;AACF"}
+13
View File
@@ -0,0 +1,13 @@
import type { CollectionBeforeChangeHook } from 'payload';
/**
* Sets `publishedAt` to now the first time a document transitions to published,
* if it isn't already set. Saves editors from filling the date manually and
* keeps blog/article dates accurate for Article JSON-LD and sitemaps.
*
* Attach to collections with drafts enabled (blog, articles):
* hooks: { beforeChange: [setPublishedAtHook] }
*
* Only sets on the published transition; never overwrites an existing date
* (an editor can still backdate manually).
*/
export declare const setPublishedAtHook: CollectionBeforeChangeHook;
+19
View File
@@ -0,0 +1,19 @@
/**
* Sets `publishedAt` to now the first time a document transitions to published,
* if it isn't already set. Saves editors from filling the date manually and
* keeps blog/article dates accurate for Article JSON-LD and sitemaps.
*
* Attach to collections with drafts enabled (blog, articles):
* hooks: { beforeChange: [setPublishedAtHook] }
*
* Only sets on the published transition; never overwrites an existing date
* (an editor can still backdate manually).
*/ export const setPublishedAtHook = ({ data, originalDoc })=>{
const becomingPublished = data._status === 'published' && originalDoc?._status !== 'published';
if (becomingPublished && !data.publishedAt) {
data.publishedAt = new Date().toISOString();
}
return data;
};
//# sourceMappingURL=setPublishedAt.js.map
+1
View File
@@ -0,0 +1 @@
{"version":3,"sources":["../../../src/modules/hooks/setPublishedAt.ts"],"sourcesContent":["import type { CollectionBeforeChangeHook } from 'payload'\n\n/**\n * Sets `publishedAt` to now the first time a document transitions to published,\n * if it isn't already set. Saves editors from filling the date manually and\n * keeps blog/article dates accurate for Article JSON-LD and sitemaps.\n *\n * Attach to collections with drafts enabled (blog, articles):\n * hooks: { beforeChange: [setPublishedAtHook] }\n *\n * Only sets on the published transition; never overwrites an existing date\n * (an editor can still backdate manually).\n */\nexport const setPublishedAtHook: CollectionBeforeChangeHook = ({ data, originalDoc }) => {\n const becomingPublished = data._status === 'published' && originalDoc?._status !== 'published'\n if (becomingPublished && !data.publishedAt) {\n data.publishedAt = new Date().toISOString()\n }\n return data\n}\n"],"names":["setPublishedAtHook","data","originalDoc","becomingPublished","_status","publishedAt","Date","toISOString"],"mappings":"AAEA;;;;;;;;;;CAUC,GACD,OAAO,MAAMA,qBAAiD,CAAC,EAAEC,IAAI,EAAEC,WAAW,EAAE;IAClF,MAAMC,oBAAoBF,KAAKG,OAAO,KAAK,eAAeF,aAAaE,YAAY;IACnF,IAAID,qBAAqB,CAACF,KAAKI,WAAW,EAAE;QAC1CJ,KAAKI,WAAW,GAAG,IAAIC,OAAOC,WAAW;IAC3C;IACA,OAAON;AACT,EAAC"}
+17
View File
@@ -0,0 +1,17 @@
import type { CollectionBeforeChangeHook } from 'payload';
/**
* When a document's slug changes, appends the OLD slug to a `slugHistory` array
* field. The project reads slugHistory to serve a 301 redirect from old URLs to
* the current one — so changing a slug doesn't 404 the old address (a real SEO
* loss / audit finding).
*
* Requires a `slugHistory` field on the collection:
* { name: 'slugHistory', type: 'array', fields: [{ name: 'slug', type: 'text' }],
* admin: { readOnly: true } }
*
* hooks: { beforeChange: [trackSlugHistoryHook] }
*
* The project then, in resolveRoute or a redirect check, looks up slugHistory and
* 301s to the current slug. See docs/hooks.md.
*/
export declare const trackSlugHistoryHook: CollectionBeforeChangeHook;
+33
View File
@@ -0,0 +1,33 @@
/**
* When a document's slug changes, appends the OLD slug to a `slugHistory` array
* field. The project reads slugHistory to serve a 301 redirect from old URLs to
* the current one — so changing a slug doesn't 404 the old address (a real SEO
* loss / audit finding).
*
* Requires a `slugHistory` field on the collection:
* { name: 'slugHistory', type: 'array', fields: [{ name: 'slug', type: 'text' }],
* admin: { readOnly: true } }
*
* hooks: { beforeChange: [trackSlugHistoryHook] }
*
* The project then, in resolveRoute or a redirect check, looks up slugHistory and
* 301s to the current slug. See docs/hooks.md.
*/ export const trackSlugHistoryHook = ({ data, originalDoc })=>{
const oldSlug = originalDoc?.slug;
const newSlug = data.slug;
if (typeof oldSlug === 'string' && typeof newSlug === 'string' && oldSlug !== newSlug && oldSlug.length > 0) {
const history = Array.isArray(data.slugHistory) ? data.slugHistory : Array.isArray(originalDoc?.slugHistory) ? originalDoc.slugHistory : [];
// Avoid duplicates; don't record the new slug itself.
if (!history.some((h)=>h?.slug === oldSlug)) {
data.slugHistory = [
...history,
{
slug: oldSlug
}
];
}
}
return data;
};
//# sourceMappingURL=trackSlugHistory.js.map
+1
View File
@@ -0,0 +1 @@
{"version":3,"sources":["../../../src/modules/hooks/trackSlugHistory.ts"],"sourcesContent":["import type { CollectionBeforeChangeHook } from 'payload'\n\n/**\n * When a document's slug changes, appends the OLD slug to a `slugHistory` array\n * field. The project reads slugHistory to serve a 301 redirect from old URLs to\n * the current one — so changing a slug doesn't 404 the old address (a real SEO\n * loss / audit finding).\n *\n * Requires a `slugHistory` field on the collection:\n * { name: 'slugHistory', type: 'array', fields: [{ name: 'slug', type: 'text' }],\n * admin: { readOnly: true } }\n *\n * hooks: { beforeChange: [trackSlugHistoryHook] }\n *\n * The project then, in resolveRoute or a redirect check, looks up slugHistory and\n * 301s to the current slug. See docs/hooks.md.\n */\nexport const trackSlugHistoryHook: CollectionBeforeChangeHook = ({ data, originalDoc }) => {\n const oldSlug = originalDoc?.slug\n const newSlug = data.slug\n if (\n typeof oldSlug === 'string' &&\n typeof newSlug === 'string' &&\n oldSlug !== newSlug &&\n oldSlug.length > 0\n ) {\n const history: Array<{ slug: string }> = Array.isArray(data.slugHistory)\n ? data.slugHistory\n : Array.isArray(originalDoc?.slugHistory)\n ? originalDoc.slugHistory\n : []\n // Avoid duplicates; don't record the new slug itself.\n if (!history.some((h) => h?.slug === oldSlug)) {\n data.slugHistory = [...history, { slug: oldSlug }]\n }\n }\n return data\n}\n"],"names":["trackSlugHistoryHook","data","originalDoc","oldSlug","slug","newSlug","length","history","Array","isArray","slugHistory","some","h"],"mappings":"AAEA;;;;;;;;;;;;;;CAcC,GACD,OAAO,MAAMA,uBAAmD,CAAC,EAAEC,IAAI,EAAEC,WAAW,EAAE;IACpF,MAAMC,UAAUD,aAAaE;IAC7B,MAAMC,UAAUJ,KAAKG,IAAI;IACzB,IACE,OAAOD,YAAY,YACnB,OAAOE,YAAY,YACnBF,YAAYE,WACZF,QAAQG,MAAM,GAAG,GACjB;QACA,MAAMC,UAAmCC,MAAMC,OAAO,CAACR,KAAKS,WAAW,IACnET,KAAKS,WAAW,GAChBF,MAAMC,OAAO,CAACP,aAAaQ,eACzBR,YAAYQ,WAAW,GACvB,EAAE;QACR,sDAAsD;QACtD,IAAI,CAACH,QAAQI,IAAI,CAAC,CAACC,IAAMA,GAAGR,SAASD,UAAU;YAC7CF,KAAKS,WAAW,GAAG;mBAAIH;gBAAS;oBAAEH,MAAMD;gBAAQ;aAAE;QACpD;IACF;IACA,OAAOF;AACT,EAAC"}
+16
View File
@@ -0,0 +1,16 @@
import type { FieldHook } from 'payload';
/**
* Field hook for a System Page role relationship in SiteSettings: ensures a page
* isn't assigned to two roles at once (e.g. the same page as both homepage and
* privacyPolicy), which would make routing ambiguous.
*
* Attach to each role field's beforeValidate. `siblingFields` are the OTHER role
* field names to check against.
*
* hooks: { beforeValidate: [buildValidateUniqueRole({
* siblingFields: ['privacyPolicy', 'cookiePolicy', 'termsOfService'],
* })] }
*/
export declare function buildValidateUniqueRole(args: {
siblingFields: string[];
}): FieldHook;
+31
View File
@@ -0,0 +1,31 @@
import { APIError } from 'payload';
/**
* Field hook for a System Page role relationship in SiteSettings: ensures a page
* isn't assigned to two roles at once (e.g. the same page as both homepage and
* privacyPolicy), which would make routing ambiguous.
*
* Attach to each role field's beforeValidate. `siblingFields` are the OTHER role
* field names to check against.
*
* hooks: { beforeValidate: [buildValidateUniqueRole({
* siblingFields: ['privacyPolicy', 'cookiePolicy', 'termsOfService'],
* })] }
*/ export function buildValidateUniqueRole(args) {
return ({ field, siblingData, value })=>{
if (value == null) {
return value;
}
const thisId = typeof value === 'object' ? value.id : value;
for (const sibling of args.siblingFields){
const other = siblingData?.[sibling];
const otherId = other && typeof other === 'object' ? other.id : other;
if (otherId != null && String(otherId) === String(thisId)) {
const name = typeof field === 'object' && 'name' in field ? field.name : 'ta rola';
throw new APIError(`Ta sama strona jest przypisana do "${name}" i "${sibling}". ` + `Każda rola systemowa musi wskazywać inną stronę.`, 400);
}
}
return value;
};
}
//# sourceMappingURL=validateUniqueRole.js.map
+1
View File
@@ -0,0 +1 @@
{"version":3,"sources":["../../../src/modules/hooks/validateUniqueRole.ts"],"sourcesContent":["import type { FieldHook } from 'payload'\n\nimport { APIError } from 'payload'\n\n/**\n * Field hook for a System Page role relationship in SiteSettings: ensures a page\n * isn't assigned to two roles at once (e.g. the same page as both homepage and\n * privacyPolicy), which would make routing ambiguous.\n *\n * Attach to each role field's beforeValidate. `siblingFields` are the OTHER role\n * field names to check against.\n *\n * hooks: { beforeValidate: [buildValidateUniqueRole({\n * siblingFields: ['privacyPolicy', 'cookiePolicy', 'termsOfService'],\n * })] }\n */\nexport function buildValidateUniqueRole(args: { siblingFields: string[] }): FieldHook {\n return ({ field, siblingData, value }) => {\n if (value == null) {return value}\n const thisId = typeof value === 'object' ? (value as { id?: unknown }).id : value\n for (const sibling of args.siblingFields) {\n const other = (siblingData as Record<string, unknown>)?.[sibling]\n const otherId = other && typeof other === 'object' ? (other as { id?: unknown }).id : other\n if (otherId != null && String(otherId) === String(thisId)) {\n const name = typeof field === 'object' && 'name' in field ? field.name : 'ta rola'\n throw new APIError(\n `Ta sama strona jest przypisana do \"${name}\" i \"${sibling}\". ` +\n `Każda rola systemowa musi wskazywać inną stronę.`,\n 400,\n )\n }\n }\n return value\n }\n}\n"],"names":["APIError","buildValidateUniqueRole","args","field","siblingData","value","thisId","id","sibling","siblingFields","other","otherId","String","name"],"mappings":"AAEA,SAASA,QAAQ,QAAQ,UAAS;AAElC;;;;;;;;;;;CAWC,GACD,OAAO,SAASC,wBAAwBC,IAAiC;IACvE,OAAO,CAAC,EAAEC,KAAK,EAAEC,WAAW,EAAEC,KAAK,EAAE;QACnC,IAAIA,SAAS,MAAM;YAAC,OAAOA;QAAK;QAChC,MAAMC,SAAS,OAAOD,UAAU,WAAW,AAACA,MAA2BE,EAAE,GAAGF;QAC5E,KAAK,MAAMG,WAAWN,KAAKO,aAAa,CAAE;YACxC,MAAMC,QAASN,aAAyC,CAACI,QAAQ;YACjE,MAAMG,UAAUD,SAAS,OAAOA,UAAU,WAAW,AAACA,MAA2BH,EAAE,GAAGG;YACtF,IAAIC,WAAW,QAAQC,OAAOD,aAAaC,OAAON,SAAS;gBACzD,MAAMO,OAAO,OAAOV,UAAU,YAAY,UAAUA,QAAQA,MAAMU,IAAI,GAAG;gBACzE,MAAM,IAAIb,SACR,CAAC,mCAAmC,EAAEa,KAAK,KAAK,EAAEL,QAAQ,GAAG,CAAC,GAC5D,CAAC,gDAAgD,CAAC,EACpD;YAEJ;QACF;QACA,OAAOH;IACT;AACF"}
+46
View File
@@ -0,0 +1,46 @@
export type BuildCspArgs = {
/** Google Analytics / GTM — adds googletagmanager + google-analytics. */
analytics?: boolean;
/** Extra sources per directive, merged with the built-ins. */
extra?: Partial<Record<CspDirective, string[]>>;
/** Google Maps embeds — adds maps.google.com / *.gstatic.com. */
googleMaps?: boolean;
/** 'enforce' → Content-Security-Policy; 'report-only' → …-Report-Only header. */
mode?: 'enforce' | 'report-only';
/** Media/R2 public URL (from R2_PUBLIC_URL) — added to img-src. */
r2Url?: string;
/** Cloudflare Turnstile — adds challenges.cloudflare.com to script/frame/connect. */
turnstile?: boolean;
/** YouTube embeds — adds youtube to frame-src. */
youtube?: boolean;
};
type CspDirective = 'base-uri' | 'connect-src' | 'default-src' | 'font-src' | 'form-action' | 'frame-ancestors' | 'frame-src' | 'img-src' | 'media-src' | 'object-src' | 'script-src' | 'style-src' | 'worker-src';
/**
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
* directives baked in, and opt-in sources for common third parties. Solves the
* real risk of hand-writing raw CSP per project and forgetting `base-uri 'self'`
* or `object-src 'none'`.
*
* CSP still lives in the project (it lists the project's own domains), but this
* helper standardizes the skeleton so every project's CSP has the same hardened
* base — you only flip flags for what the project actually loads.
*
* Returns { key, value } ready for buildSecurityHeaders `additional`:
*
* import { buildCsp, buildSecurityHeaders } from '@intecion/ipal-kit'
* const csp = buildCsp({
* mode: 'report-only', // start here; switch to 'enforce' when clean
* r2Url: process.env.R2_PUBLIC_URL,
* turnstile: true, analytics: true,
* })
* const headers = buildSecurityHeaders({ hsts: prod, additional: [csp] })
*
* Deploy CSP carefully: start with mode:'report-only', check the console for
* violations across the whole site (forms/Turnstile, gallery/R2, embeds), add
* missing sources via `extra`, THEN switch to 'enforce'. See docs/security.md.
*/
export declare function buildCsp(args?: BuildCspArgs): {
key: string;
value: string;
};
export {};
+109
View File
@@ -0,0 +1,109 @@
/**
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
* directives baked in, and opt-in sources for common third parties. Solves the
* real risk of hand-writing raw CSP per project and forgetting `base-uri 'self'`
* or `object-src 'none'`.
*
* CSP still lives in the project (it lists the project's own domains), but this
* helper standardizes the skeleton so every project's CSP has the same hardened
* base — you only flip flags for what the project actually loads.
*
* Returns { key, value } ready for buildSecurityHeaders `additional`:
*
* import { buildCsp, buildSecurityHeaders } from '@intecion/ipal-kit'
* const csp = buildCsp({
* mode: 'report-only', // start here; switch to 'enforce' when clean
* r2Url: process.env.R2_PUBLIC_URL,
* turnstile: true, analytics: true,
* })
* const headers = buildSecurityHeaders({ hsts: prod, additional: [csp] })
*
* Deploy CSP carefully: start with mode:'report-only', check the console for
* violations across the whole site (forms/Turnstile, gallery/R2, embeds), add
* missing sources via `extra`, THEN switch to 'enforce'. See docs/security.md.
*/ export function buildCsp(args = {}) {
const { analytics, extra = {}, googleMaps, mode = 'enforce', r2Url, turnstile, youtube } = args;
const src = {
'default-src': [
"'self'"
],
// 'unsafe-inline' is hard to avoid with Next/analytics; 'unsafe-eval' is NOT
// added by default (weakens CSP) — add via extra only if a library needs it.
'connect-src': [
"'self'"
],
'font-src': [
"'self'",
'https://fonts.gstatic.com',
'data:'
],
'form-action': [
"'self'"
],
'frame-src': [],
'img-src': [
"'self'",
'data:',
'blob:'
],
'media-src': [],
'script-src': [
"'self'",
"'unsafe-inline'"
],
'style-src': [
"'self'",
"'unsafe-inline'",
'https://fonts.googleapis.com'
],
'worker-src': [],
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
'base-uri': [
"'self'"
],
'frame-ancestors': [
"'none'"
],
'object-src': [
"'none'"
]
};
if (r2Url) {
src['img-src'].push(r2Url);
}
if (turnstile) {
src['script-src'].push('https://challenges.cloudflare.com');
src['frame-src'].push('https://challenges.cloudflare.com');
src['connect-src'].push('https://challenges.cloudflare.com');
}
if (analytics) {
src['script-src'].push('https://www.googletagmanager.com');
src['connect-src'].push('https://www.google-analytics.com', 'https://www.googletagmanager.com');
src['img-src'].push('https://www.google-analytics.com', 'https://www.googletagmanager.com');
}
if (youtube) {
src['frame-src'].push('https://www.youtube.com', 'https://www.youtube-nocookie.com');
}
if (googleMaps) {
src['frame-src'].push('https://www.google.com', 'https://maps.google.com');
src['script-src'].push('https://maps.googleapis.com');
src['img-src'].push('https://maps.gstatic.com', 'https://*.googleapis.com');
}
// Merge caller extras.
for (const [dir, values] of Object.entries(extra)){
if (values && values.length) {
src[dir] = [
...src[dir] ?? [],
...values
];
}
}
const value = Object.entries(src).filter(([, values])=>values.length > 0).map(([dir, values])=>`${dir} ${values.join(' ')}`).join('; ');
const key = mode === 'report-only' ? 'Content-Security-Policy-Report-Only' : 'Content-Security-Policy';
return {
key,
value
};
}
//# sourceMappingURL=buildCsp.js.map
File diff suppressed because one or more lines are too long
+8
View File
@@ -13,6 +13,14 @@ export type BuildSecurityHeadersArgs = {
* domains (scripts, images, fonts, analytics). Keep CSP in your project.
*/
additional?: SecurityHeader[];
/**
* Cross-Origin-Opener-Policy. Default 'same-origin' — isolates the browsing
* context so a malicious page can't hold a window.opener reference (protects
* against XS-Leaks / Spectre-class attacks). Project-independent, so it's a
* default. Use 'same-origin-allow-popups' if you open OAuth/payment popups
* that need window.opener; false to omit.
*/
coop?: 'same-origin' | 'same-origin-allow-popups' | false;
/**
* X-Frame-Options value. 'DENY' (default) blocks all framing; 'SAMEORIGIN'
* allows same-origin framing. Note: CSP frame-ancestors supersedes this in
+8 -1
View File
@@ -26,7 +26,7 @@
* },
* }
*/ export function buildSecurityHeaders(args = {}) {
const { additional = [], frameOptions = 'DENY', hsts = true, hstsIncludeSubDomains = true, hstsMaxAge = 63072000, hstsPreload = false, permissionsPolicy = 'camera=(), microphone=(), geolocation=()', referrerPolicy = 'strict-origin-when-cross-origin' } = args;
const { additional = [], coop = 'same-origin', frameOptions = 'DENY', hsts = true, hstsIncludeSubDomains = true, hstsMaxAge = 63072000, hstsPreload = false, permissionsPolicy = 'camera=(), microphone=(), geolocation=()', referrerPolicy = 'strict-origin-when-cross-origin' } = args;
const headers = [];
if (hsts) {
const parts = [
@@ -66,6 +66,13 @@
value: permissionsPolicy
});
}
// COOP — isolates the browsing context (XS-Leaks / Spectre protection).
if (coop) {
headers.push({
key: 'Cross-Origin-Opener-Policy',
value: coop
});
}
// Merge additional: same-key entries override the defaults above.
for (const extra of additional){
const i = headers.findIndex((h)=>h.key.toLowerCase() === extra.key.toLowerCase());
File diff suppressed because one or more lines are too long
+3 -1
View File
@@ -1,2 +1,4 @@
export { buildCsp } from './buildCsp.js';
export type { BuildCspArgs } from './buildCsp.js';
export { buildSecurityHeaders } from './buildSecurityHeaders.js';
export type { BuildSecurityHeadersArgs, SecurityHeader } from './buildSecurityHeaders.js';
export type { BuildSecurityHeadersArgs, SecurityHeader, } from './buildSecurityHeaders.js';
+1
View File
@@ -1,3 +1,4 @@
export { buildCsp } from './buildCsp.js';
export { buildSecurityHeaders } from './buildSecurityHeaders.js';
//# sourceMappingURL=index.js.map
+1 -1
View File
@@ -1 +1 @@
{"version":3,"sources":["../../../src/modules/security/index.ts"],"sourcesContent":["export { buildSecurityHeaders } from './buildSecurityHeaders.js'\nexport type { BuildSecurityHeadersArgs, SecurityHeader } from './buildSecurityHeaders.js'\n"],"names":["buildSecurityHeaders"],"mappings":"AAAA,SAASA,oBAAoB,QAAQ,4BAA2B"}
{"version":3,"sources":["../../../src/modules/security/index.ts"],"sourcesContent":["export { buildCsp } from './buildCsp.js'\nexport type { BuildCspArgs } from './buildCsp.js'\nexport { buildSecurityHeaders } from './buildSecurityHeaders.js'\nexport type { BuildSecurityHeadersArgs, SecurityHeader, } from './buildSecurityHeaders.js'\n"],"names":["buildCsp","buildSecurityHeaders"],"mappings":"AAAA,SAASA,QAAQ,QAAQ,gBAAe;AAExC,SAASC,oBAAoB,QAAQ,4BAA2B"}
+6 -6
View File
@@ -37,16 +37,16 @@ import { buildLocalizedPath } from '../i18n/index.js';
});
const name = settings.siteName?.trim() || 'Website';
const description = settings.siteDescription?.trim();
// NO where:{_status} filter — collections without drafts enabled don't
// register the _status field, and querying it throws
// "path cannot be queried: _status" (a real bug report). Draft filtering
// happens in memory below, which is safe for every collection. Same as
// buildSitemapEntries and generateStaticParams.
const result = await payload.find({
collection: pagesSlug,
depth: 0,
limit: 1000,
locale: loc,
where: {
_status: {
not_equals: 'draft'
}
}
locale: loc
});
const lines = [
`# ${name}`,
File diff suppressed because one or more lines are too long
+33
View File
@@ -0,0 +1,33 @@
import type { SitemapEntry } from './buildSitemapEntries.js';
/**
* Serializes sitemap entries to an XML STRING with an XSL stylesheet reference,
* so /sitemap.xml renders as a readable table in the browser (not raw XML) while
* staying a valid sitemap for crawlers.
*
* Why this exists alongside the Next MetadataRoute sitemap: Next's app/sitemap.ts
* (returning SitemapEntry[]) does NOT let you inject <?xml-stylesheet?>. To get
* the styled table, serve a custom route that returns this string instead:
*
* // app/sitemap.xml/route.ts
* import { buildSitemapXml } from '@intecion/ipal-kit'
* import { sitemap } from '@/lib/content' // your entries source
* export const dynamic = 'force-dynamic'
* export async function GET() {
* const entries = await sitemap()
* const xml = buildSitemapXml(entries, { stylesheetUrl: '/sitemap.xsl' })
* return new Response(xml, {
* headers: { 'Content-Type': 'application/xml; charset=utf-8' },
* })
* }
*
* Put sitemap.xsl in the project's /public (copy from the plugin's assets, or
* serve it from a route). The <?xml-stylesheet?> points browsers at it; crawlers
* ignore it and read the XML. Include hreflang alternates as <xhtml:link>.
*
* NOTE: if you use this custom route, DON'T also keep app/sitemap.ts — pick one
* (the styled route OR the Next MetadataRoute). Two sitemaps at different paths
* confuse crawlers.
*/
export declare function buildSitemapXml(entries: SitemapEntry[], opts?: {
stylesheetUrl?: string;
}): string;
+57
View File
@@ -0,0 +1,57 @@
/**
* Serializes sitemap entries to an XML STRING with an XSL stylesheet reference,
* so /sitemap.xml renders as a readable table in the browser (not raw XML) while
* staying a valid sitemap for crawlers.
*
* Why this exists alongside the Next MetadataRoute sitemap: Next's app/sitemap.ts
* (returning SitemapEntry[]) does NOT let you inject <?xml-stylesheet?>. To get
* the styled table, serve a custom route that returns this string instead:
*
* // app/sitemap.xml/route.ts
* import { buildSitemapXml } from '@intecion/ipal-kit'
* import { sitemap } from '@/lib/content' // your entries source
* export const dynamic = 'force-dynamic'
* export async function GET() {
* const entries = await sitemap()
* const xml = buildSitemapXml(entries, { stylesheetUrl: '/sitemap.xsl' })
* return new Response(xml, {
* headers: { 'Content-Type': 'application/xml; charset=utf-8' },
* })
* }
*
* Put sitemap.xsl in the project's /public (copy from the plugin's assets, or
* serve it from a route). The <?xml-stylesheet?> points browsers at it; crawlers
* ignore it and read the XML. Include hreflang alternates as <xhtml:link>.
*
* NOTE: if you use this custom route, DON'T also keep app/sitemap.ts — pick one
* (the styled route OR the Next MetadataRoute). Two sitemaps at different paths
* confuse crawlers.
*/ export function buildSitemapXml(entries, opts = {}) {
const { stylesheetUrl } = opts;
const esc = (s)=>s.replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;').replace(/"/g, '&quot;').replace(/'/g, '&apos;');
const urls = entries.map((e)=>{
const parts = [
` <loc>${esc(e.url)}</loc>`
];
if (e.lastModified) {
const iso = e.lastModified instanceof Date ? e.lastModified.toISOString() : String(e.lastModified);
parts.push(` <lastmod>${esc(iso)}</lastmod>`);
}
if (e.changeFrequency) parts.push(` <changefreq>${e.changeFrequency}</changefreq>`);
if (typeof e.priority === 'number') parts.push(` <priority>${e.priority}</priority>`);
// hreflang alternates
const alternates = e.alternates?.languages;
if (alternates) {
for (const [lang, href] of Object.entries(alternates)){
if (typeof href === 'string') {
parts.push(` <xhtml:link rel="alternate" hreflang="${esc(lang)}" href="${esc(href)}"/>`);
}
}
}
return ` <url>\n${parts.join('\n')}\n </url>`;
}).join('\n');
const stylesheet = stylesheetUrl ? `<?xml-stylesheet type="text/xsl" href="${esc(stylesheetUrl)}"?>\n` : '';
return `<?xml version="1.0" encoding="UTF-8"?>\n` + stylesheet + `<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" ` + `xmlns:xhtml="http://www.w3.org/1999/xhtml">\n` + urls + `\n</urlset>`;
}
//# sourceMappingURL=buildSitemapXml.js.map
+1
View File
@@ -0,0 +1 @@
{"version":3,"sources":["../../../src/modules/seo/buildSitemapXml.ts"],"sourcesContent":["import type { SitemapEntry } from './buildSitemapEntries.js'\n\n/**\n * Serializes sitemap entries to an XML STRING with an XSL stylesheet reference,\n * so /sitemap.xml renders as a readable table in the browser (not raw XML) while\n * staying a valid sitemap for crawlers.\n *\n * Why this exists alongside the Next MetadataRoute sitemap: Next's app/sitemap.ts\n * (returning SitemapEntry[]) does NOT let you inject <?xml-stylesheet?>. To get\n * the styled table, serve a custom route that returns this string instead:\n *\n * // app/sitemap.xml/route.ts\n * import { buildSitemapXml } from '@intecion/ipal-kit'\n * import { sitemap } from '@/lib/content' // your entries source\n * export const dynamic = 'force-dynamic'\n * export async function GET() {\n * const entries = await sitemap()\n * const xml = buildSitemapXml(entries, { stylesheetUrl: '/sitemap.xsl' })\n * return new Response(xml, {\n * headers: { 'Content-Type': 'application/xml; charset=utf-8' },\n * })\n * }\n *\n * Put sitemap.xsl in the project's /public (copy from the plugin's assets, or\n * serve it from a route). The <?xml-stylesheet?> points browsers at it; crawlers\n * ignore it and read the XML. Include hreflang alternates as <xhtml:link>.\n *\n * NOTE: if you use this custom route, DON'T also keep app/sitemap.ts — pick one\n * (the styled route OR the Next MetadataRoute). Two sitemaps at different paths\n * confuse crawlers.\n */\nexport function buildSitemapXml(\n entries: SitemapEntry[],\n opts: { stylesheetUrl?: string } = {},\n): string {\n const { stylesheetUrl } = opts\n\n const esc = (s: string): string =>\n s\n .replace(/&/g, '&amp;')\n .replace(/</g, '&lt;')\n .replace(/>/g, '&gt;')\n .replace(/\"/g, '&quot;')\n .replace(/'/g, '&apos;')\n\n const urls = entries\n .map((e) => {\n const parts = [` <loc>${esc(e.url)}</loc>`]\n if (e.lastModified) {\n const iso =\n e.lastModified instanceof Date ? e.lastModified.toISOString() : String(e.lastModified)\n parts.push(` <lastmod>${esc(iso)}</lastmod>`)\n }\n if (e.changeFrequency) parts.push(` <changefreq>${e.changeFrequency}</changefreq>`)\n if (typeof e.priority === 'number') parts.push(` <priority>${e.priority}</priority>`)\n // hreflang alternates\n const alternates = e.alternates?.languages\n if (alternates) {\n for (const [lang, href] of Object.entries(alternates)) {\n if (typeof href === 'string') {\n parts.push(\n ` <xhtml:link rel=\"alternate\" hreflang=\"${esc(lang)}\" href=\"${esc(href)}\"/>`,\n )\n }\n }\n }\n return ` <url>\\n${parts.join('\\n')}\\n </url>`\n })\n .join('\\n')\n\n const stylesheet = stylesheetUrl\n ? `<?xml-stylesheet type=\"text/xsl\" href=\"${esc(stylesheetUrl)}\"?>\\n`\n : ''\n\n return (\n `<?xml version=\"1.0\" encoding=\"UTF-8\"?>\\n` +\n stylesheet +\n `<urlset xmlns=\"http://www.sitemaps.org/schemas/sitemap/0.9\" ` +\n `xmlns:xhtml=\"http://www.w3.org/1999/xhtml\">\\n` +\n urls +\n `\\n</urlset>`\n )\n}\n"],"names":["buildSitemapXml","entries","opts","stylesheetUrl","esc","s","replace","urls","map","e","parts","url","lastModified","iso","Date","toISOString","String","push","changeFrequency","priority","alternates","languages","lang","href","Object","join","stylesheet"],"mappings":"AAEA;;;;;;;;;;;;;;;;;;;;;;;;;;;;CA4BC,GACD,OAAO,SAASA,gBACdC,OAAuB,EACvBC,OAAmC,CAAC,CAAC;IAErC,MAAM,EAAEC,aAAa,EAAE,GAAGD;IAE1B,MAAME,MAAM,CAACC,IACXA,EACGC,OAAO,CAAC,MAAM,SACdA,OAAO,CAAC,MAAM,QACdA,OAAO,CAAC,MAAM,QACdA,OAAO,CAAC,MAAM,UACdA,OAAO,CAAC,MAAM;IAEnB,MAAMC,OAAON,QACVO,GAAG,CAAC,CAACC;QACJ,MAAMC,QAAQ;YAAC,CAAC,SAAS,EAAEN,IAAIK,EAAEE,GAAG,EAAE,MAAM,CAAC;SAAC;QAC9C,IAAIF,EAAEG,YAAY,EAAE;YAClB,MAAMC,MACJJ,EAAEG,YAAY,YAAYE,OAAOL,EAAEG,YAAY,CAACG,WAAW,KAAKC,OAAOP,EAAEG,YAAY;YACvFF,MAAMO,IAAI,CAAC,CAAC,aAAa,EAAEb,IAAIS,KAAK,UAAU,CAAC;QACjD;QACA,IAAIJ,EAAES,eAAe,EAAER,MAAMO,IAAI,CAAC,CAAC,gBAAgB,EAAER,EAAES,eAAe,CAAC,aAAa,CAAC;QACrF,IAAI,OAAOT,EAAEU,QAAQ,KAAK,UAAUT,MAAMO,IAAI,CAAC,CAAC,cAAc,EAAER,EAAEU,QAAQ,CAAC,WAAW,CAAC;QACvF,sBAAsB;QACtB,MAAMC,aAAaX,EAAEW,UAAU,EAAEC;QACjC,IAAID,YAAY;YACd,KAAK,MAAM,CAACE,MAAMC,KAAK,IAAIC,OAAOvB,OAAO,CAACmB,YAAa;gBACrD,IAAI,OAAOG,SAAS,UAAU;oBAC5Bb,MAAMO,IAAI,CACR,CAAC,0CAA0C,EAAEb,IAAIkB,MAAM,QAAQ,EAAElB,IAAImB,MAAM,GAAG,CAAC;gBAEnF;YACF;QACF;QACA,OAAO,CAAC,SAAS,EAAEb,MAAMe,IAAI,CAAC,MAAM,UAAU,CAAC;IACjD,GACCA,IAAI,CAAC;IAER,MAAMC,aAAavB,gBACf,CAAC,uCAAuC,EAAEC,IAAID,eAAe,KAAK,CAAC,GACnE;IAEJ,OACE,CAAC,wCAAwC,CAAC,GAC1CuB,aACA,CAAC,4DAA4D,CAAC,GAC9D,CAAC,6CAA6C,CAAC,GAC/CnB,OACA,CAAC,WAAW,CAAC;AAEjB"}
+1
View File
@@ -14,6 +14,7 @@ export type { RobotsRules } from './buildRobots.js';
export { buildServiceJsonLd } from './buildServiceJsonLd.js';
export { buildSitemapEntries } from './buildSitemapEntries.js';
export type { SitemapEntry } from './buildSitemapEntries.js';
export { buildSitemapXml } from './buildSitemapXml.js';
export { buildSiteNavigationJsonLd } from './buildSiteNavigationJsonLd.js';
export { buildWebSiteJsonLd } from './buildWebSiteJsonLd.js';
export { composeTitle } from './composeTitle.js';
+1
View File
@@ -10,6 +10,7 @@ export { buildOrganizationJsonLd } from './buildOrganizationJsonLd.js';
export { buildRobots } from './buildRobots.js';
export { buildServiceJsonLd } from './buildServiceJsonLd.js';
export { buildSitemapEntries } from './buildSitemapEntries.js';
export { buildSitemapXml } from './buildSitemapXml.js';
export { buildSiteNavigationJsonLd } from './buildSiteNavigationJsonLd.js';
export { buildWebSiteJsonLd } from './buildWebSiteJsonLd.js';
export { composeTitle } from './composeTitle.js';
+1 -1
View File
@@ -1 +1 @@
{"version":3,"sources":["../../../src/modules/seo/index.ts"],"sourcesContent":["export { buildAutoFillMetaHook } from './autoFillMeta.js'\nexport type { AutoFillMapping } from './autoFillMeta.js'\nexport { buildArticleJsonLd } from './buildArticleJsonLd.js'\nexport { buildBreadcrumbJsonLd } from './buildBreadcrumbJsonLd.js'\nexport { buildFaqJsonLd } from './buildFaqJsonLd.js'\nexport { buildIconsMetadata } from './buildIconsMetadata.js'\nexport { buildLlmsTxt } from './buildLlmsTxt.js'\nexport { buildLocalBusinessJsonLd } from './buildLocalBusinessJsonLd.js'\nexport { buildMetadata } from './buildMetadata.js'\nexport type { PageMetadata } from './buildMetadata.js'\nexport { buildOrganizationJsonLd } from './buildOrganizationJsonLd.js'\nexport { buildRobots } from './buildRobots.js'\nexport type { RobotsRules } from './buildRobots.js'\nexport { buildServiceJsonLd } from './buildServiceJsonLd.js'\nexport { buildSitemapEntries } from './buildSitemapEntries.js'\nexport type { SitemapEntry } from './buildSitemapEntries.js'\nexport { buildSiteNavigationJsonLd } from './buildSiteNavigationJsonLd.js'\nexport { buildWebSiteJsonLd } from './buildWebSiteJsonLd.js'\nexport { composeTitle } from './composeTitle.js'\nexport type { TitleOrder } from './composeTitle.js'\nexport { createMetadataGenerator } from './createMetadataGenerator.js'\nexport { createPageMetadata } from './createPageMetadata.js'\nexport { buildHreflangAlternates } from './hreflang.js'\nexport { injectAutoFillMeta } from './injectAutoFillMeta.js'\nexport { injectSeoTabs } from './injectSeoTabs.js'\nexport { readSiteMetaConfig } from './readSiteMetaConfig.js'\nexport type { SiteMetaConfig } from './readSiteMetaConfig.js'\nexport { buildSeoPlugin } from './seoPluginConfig.js'\nexport { slugsAcrossLocales } from './slugsAcrossLocales.js'\nexport type { SeoMeta, SeoOption } from './types.js'\nexport { validateFaviconField } from './validateFavicon.js'\n"],"names":["buildAutoFillMetaHook","buildArticleJsonLd","buildBreadcrumbJsonLd","buildFaqJsonLd","buildIconsMetadata","buildLlmsTxt","buildLocalBusinessJsonLd","buildMetadata","buildOrganizationJsonLd","buildRobots","buildServiceJsonLd","buildSitemapEntries","buildSiteNavigationJsonLd","buildWebSiteJsonLd","composeTitle","createMetadataGenerator","createPageMetadata","buildHreflangAlternates","injectAutoFillMeta","injectSeoTabs","readSiteMetaConfig","buildSeoPlugin","slugsAcrossLocales","validateFaviconField"],"mappings":"AAAA,SAASA,qBAAqB,QAAQ,oBAAmB;AAEzD,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,qBAAqB,QAAQ,6BAA4B;AAClE,SAASC,cAAc,QAAQ,sBAAqB;AACpD,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,YAAY,QAAQ,oBAAmB;AAChD,SAASC,wBAAwB,QAAQ,gCAA+B;AACxE,SAASC,aAAa,QAAQ,qBAAoB;AAElD,SAASC,uBAAuB,QAAQ,+BAA8B;AACtE,SAASC,WAAW,QAAQ,mBAAkB;AAE9C,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,mBAAmB,QAAQ,2BAA0B;AAE9D,SAASC,yBAAyB,QAAQ,iCAAgC;AAC1E,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,YAAY,QAAQ,oBAAmB;AAEhD,SAASC,uBAAuB,QAAQ,+BAA8B;AACtE,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,uBAAuB,QAAQ,gBAAe;AACvD,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,aAAa,QAAQ,qBAAoB;AAClD,SAASC,kBAAkB,QAAQ,0BAAyB;AAE5D,SAASC,cAAc,QAAQ,uBAAsB;AACrD,SAASC,kBAAkB,QAAQ,0BAAyB;AAE5D,SAASC,oBAAoB,QAAQ,uBAAsB"}
{"version":3,"sources":["../../../src/modules/seo/index.ts"],"sourcesContent":["export { buildAutoFillMetaHook } from './autoFillMeta.js'\nexport type { AutoFillMapping } from './autoFillMeta.js'\nexport { buildArticleJsonLd } from './buildArticleJsonLd.js'\nexport { buildBreadcrumbJsonLd } from './buildBreadcrumbJsonLd.js'\nexport { buildFaqJsonLd } from './buildFaqJsonLd.js'\nexport { buildIconsMetadata } from './buildIconsMetadata.js'\nexport { buildLlmsTxt } from './buildLlmsTxt.js'\nexport { buildLocalBusinessJsonLd } from './buildLocalBusinessJsonLd.js'\nexport { buildMetadata } from './buildMetadata.js'\nexport type { PageMetadata } from './buildMetadata.js'\nexport { buildOrganizationJsonLd } from './buildOrganizationJsonLd.js'\nexport { buildRobots } from './buildRobots.js'\nexport type { RobotsRules } from './buildRobots.js'\nexport { buildServiceJsonLd } from './buildServiceJsonLd.js'\nexport { buildSitemapEntries } from './buildSitemapEntries.js'\nexport type { SitemapEntry } from './buildSitemapEntries.js'\nexport { buildSitemapXml } from './buildSitemapXml.js'\nexport { buildSiteNavigationJsonLd } from './buildSiteNavigationJsonLd.js'\nexport { buildWebSiteJsonLd } from './buildWebSiteJsonLd.js'\nexport { composeTitle } from './composeTitle.js'\nexport type { TitleOrder } from './composeTitle.js'\nexport { createMetadataGenerator } from './createMetadataGenerator.js'\nexport { createPageMetadata } from './createPageMetadata.js'\nexport { buildHreflangAlternates } from './hreflang.js'\nexport { injectAutoFillMeta } from './injectAutoFillMeta.js'\nexport { injectSeoTabs } from './injectSeoTabs.js'\nexport { readSiteMetaConfig } from './readSiteMetaConfig.js'\nexport type { SiteMetaConfig } from './readSiteMetaConfig.js'\nexport { buildSeoPlugin } from './seoPluginConfig.js'\nexport { slugsAcrossLocales } from './slugsAcrossLocales.js'\nexport type { SeoMeta, SeoOption } from './types.js'\nexport { validateFaviconField } from './validateFavicon.js'\n"],"names":["buildAutoFillMetaHook","buildArticleJsonLd","buildBreadcrumbJsonLd","buildFaqJsonLd","buildIconsMetadata","buildLlmsTxt","buildLocalBusinessJsonLd","buildMetadata","buildOrganizationJsonLd","buildRobots","buildServiceJsonLd","buildSitemapEntries","buildSitemapXml","buildSiteNavigationJsonLd","buildWebSiteJsonLd","composeTitle","createMetadataGenerator","createPageMetadata","buildHreflangAlternates","injectAutoFillMeta","injectSeoTabs","readSiteMetaConfig","buildSeoPlugin","slugsAcrossLocales","validateFaviconField"],"mappings":"AAAA,SAASA,qBAAqB,QAAQ,oBAAmB;AAEzD,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,qBAAqB,QAAQ,6BAA4B;AAClE,SAASC,cAAc,QAAQ,sBAAqB;AACpD,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,YAAY,QAAQ,oBAAmB;AAChD,SAASC,wBAAwB,QAAQ,gCAA+B;AACxE,SAASC,aAAa,QAAQ,qBAAoB;AAElD,SAASC,uBAAuB,QAAQ,+BAA8B;AACtE,SAASC,WAAW,QAAQ,mBAAkB;AAE9C,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,mBAAmB,QAAQ,2BAA0B;AAE9D,SAASC,eAAe,QAAQ,uBAAsB;AACtD,SAASC,yBAAyB,QAAQ,iCAAgC;AAC1E,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,YAAY,QAAQ,oBAAmB;AAEhD,SAASC,uBAAuB,QAAQ,+BAA8B;AACtE,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,uBAAuB,QAAQ,gBAAe;AACvD,SAASC,kBAAkB,QAAQ,0BAAyB;AAC5D,SAASC,aAAa,QAAQ,qBAAoB;AAClD,SAASC,kBAAkB,QAAQ,0BAAyB;AAE5D,SAASC,cAAc,QAAQ,uBAAsB;AACrD,SAASC,kBAAkB,QAAQ,0BAAyB;AAE5D,SAASC,oBAAoB,QAAQ,uBAAsB"}
+36
View File
@@ -0,0 +1,36 @@
/**
* Provides the Turnstile site key once for the whole app, like ConsentProvider
* for cookies. The project reads the key server-side and passes it here in the
* layout; forms then use <TurnstileWidget /> + useTurnstile() with NO per-form
* key wiring.
*
* // layout.tsx (server) → read key, pass to provider
* import { TurnstileProvider } from '@intecion/ipal-kit/client'
* const siteKey = await getTurnstileSiteKey() // your server helper
* <TurnstileProvider siteKey={siteKey}>{children}</TurnstileProvider>
*
* When siteKey is null (Turnstile not configured), widgets render nothing and
* token stays null — forms should treat "no Turnstile" as allowed in dev.
*/
export declare function TurnstileProvider({ siteKey, children, }: {
siteKey: string | null;
children: React.ReactNode;
}): import("react/jsx-runtime").JSX.Element;
/**
* Hook giving a form the Turnstile token + a widget bound to the provider's key.
* No per-form siteKey plumbing — the provider supplies it.
*
* const { token, TurnstileWidget, reset } = useTurnstile()
* // in JSX: <TurnstileWidget />
* // at submit: submitForm({ ..., turnstileToken: token })
* // after submit: reset() // clear for the next submission
*/
export declare function useTurnstile(): {
token: string | null;
TurnstileWidget: (props?: {
theme?: 'light' | 'dark' | 'auto';
}) => React.ReactNode;
reset: () => void;
/** True when Turnstile is configured (site key present). */
enabled: boolean;
};
+66
View File
@@ -0,0 +1,66 @@
'use client';
import { jsx as _jsx } from "react/jsx-runtime";
import { createContext, useCallback, useContext, useState } from 'react';
import { Turnstile } from './Turnstile.js';
const TurnstileContext = /*#__PURE__*/ createContext(null);
/**
* Provides the Turnstile site key once for the whole app, like ConsentProvider
* for cookies. The project reads the key server-side and passes it here in the
* layout; forms then use <TurnstileWidget /> + useTurnstile() with NO per-form
* key wiring.
*
* // layout.tsx (server) → read key, pass to provider
* import { TurnstileProvider } from '@intecion/ipal-kit/client'
* const siteKey = await getTurnstileSiteKey() // your server helper
* <TurnstileProvider siteKey={siteKey}>{children}</TurnstileProvider>
*
* When siteKey is null (Turnstile not configured), widgets render nothing and
* token stays null — forms should treat "no Turnstile" as allowed in dev.
*/ export function TurnstileProvider({ siteKey, children }) {
const [token, setToken] = useState(null);
return /*#__PURE__*/ _jsx(TurnstileContext.Provider, {
value: {
siteKey,
token,
setToken
},
children: children
});
}
/**
* Hook giving a form the Turnstile token + a widget bound to the provider's key.
* No per-form siteKey plumbing — the provider supplies it.
*
* const { token, TurnstileWidget, reset } = useTurnstile()
* // in JSX: <TurnstileWidget />
* // at submit: submitForm({ ..., turnstileToken: token })
* // after submit: reset() // clear for the next submission
*/ export function useTurnstile() {
const ctx = useContext(TurnstileContext);
if (!ctx) {
throw new Error('useTurnstile must be used within <TurnstileProvider>');
}
const { siteKey, token, setToken } = ctx;
const reset = useCallback(()=>setToken(null), [
setToken
]);
const TurnstileWidget = useCallback((props)=>{
if (!siteKey) return null;
return /*#__PURE__*/ _jsx(Turnstile, {
siteKey: siteKey,
onToken: setToken,
theme: props?.theme
});
}, [
siteKey,
setToken
]);
return {
token,
TurnstileWidget,
reset,
enabled: Boolean(siteKey)
};
}
//# sourceMappingURL=TurnstileProvider.js.map
+1
View File
@@ -0,0 +1 @@
{"version":3,"sources":["../../../src/modules/turnstile/TurnstileProvider.tsx"],"sourcesContent":["'use client'\n\nimport { createContext, useCallback, useContext, useState } from 'react'\nimport { Turnstile } from './Turnstile.js'\n\ntype TurnstileContextValue = {\n /** Public site key from the provider (read server-side, passed once). */\n siteKey: string | null\n /** Current token (null until solved / after expiry). */\n token: string | null\n setToken: (t: string | null) => void\n}\n\nconst TurnstileContext = createContext<TurnstileContextValue | null>(null)\n\n/**\n * Provides the Turnstile site key once for the whole app, like ConsentProvider\n * for cookies. The project reads the key server-side and passes it here in the\n * layout; forms then use <TurnstileWidget /> + useTurnstile() with NO per-form\n * key wiring.\n *\n * // layout.tsx (server) → read key, pass to provider\n * import { TurnstileProvider } from '@intecion/ipal-kit/client'\n * const siteKey = await getTurnstileSiteKey() // your server helper\n * <TurnstileProvider siteKey={siteKey}>{children}</TurnstileProvider>\n *\n * When siteKey is null (Turnstile not configured), widgets render nothing and\n * token stays null — forms should treat \"no Turnstile\" as allowed in dev.\n */\nexport function TurnstileProvider({\n siteKey,\n children,\n}: {\n siteKey: string | null\n children: React.ReactNode\n}) {\n const [token, setToken] = useState<string | null>(null)\n return (\n <TurnstileContext.Provider value={{ siteKey, token, setToken }}>\n {children}\n </TurnstileContext.Provider>\n )\n}\n\n/**\n * Hook giving a form the Turnstile token + a widget bound to the provider's key.\n * No per-form siteKey plumbing — the provider supplies it.\n *\n * const { token, TurnstileWidget, reset } = useTurnstile()\n * // in JSX: <TurnstileWidget />\n * // at submit: submitForm({ ..., turnstileToken: token })\n * // after submit: reset() // clear for the next submission\n */\nexport function useTurnstile(): {\n token: string | null\n TurnstileWidget: (props?: { theme?: 'light' | 'dark' | 'auto' }) => React.ReactNode\n reset: () => void\n /** True when Turnstile is configured (site key present). */\n enabled: boolean\n} {\n const ctx = useContext(TurnstileContext)\n if (!ctx) {\n throw new Error('useTurnstile must be used within <TurnstileProvider>')\n }\n const { siteKey, token, setToken } = ctx\n\n const reset = useCallback(() => setToken(null), [setToken])\n\n const TurnstileWidget = useCallback(\n (props?: { theme?: 'light' | 'dark' | 'auto' }) => {\n if (!siteKey) return null\n return <Turnstile siteKey={siteKey} onToken={setToken} theme={props?.theme} />\n },\n [siteKey, setToken],\n )\n\n return { token, TurnstileWidget, reset, enabled: Boolean(siteKey) }\n}\n"],"names":["createContext","useCallback","useContext","useState","Turnstile","TurnstileContext","TurnstileProvider","siteKey","children","token","setToken","Provider","value","useTurnstile","ctx","Error","reset","TurnstileWidget","props","onToken","theme","enabled","Boolean"],"mappings":"AAAA;;AAEA,SAASA,aAAa,EAAEC,WAAW,EAAEC,UAAU,EAAEC,QAAQ,QAAQ,QAAO;AACxE,SAASC,SAAS,QAAQ,iBAAgB;AAU1C,MAAMC,iCAAmBL,cAA4C;AAErE;;;;;;;;;;;;;CAaC,GACD,OAAO,SAASM,kBAAkB,EAChCC,OAAO,EACPC,QAAQ,EAIT;IACC,MAAM,CAACC,OAAOC,SAAS,GAAGP,SAAwB;IAClD,qBACE,KAACE,iBAAiBM,QAAQ;QAACC,OAAO;YAAEL;YAASE;YAAOC;QAAS;kBAC1DF;;AAGP;AAEA;;;;;;;;CAQC,GACD,OAAO,SAASK;IAOd,MAAMC,MAAMZ,WAAWG;IACvB,IAAI,CAACS,KAAK;QACR,MAAM,IAAIC,MAAM;IAClB;IACA,MAAM,EAAER,OAAO,EAAEE,KAAK,EAAEC,QAAQ,EAAE,GAAGI;IAErC,MAAME,QAAQf,YAAY,IAAMS,SAAS,OAAO;QAACA;KAAS;IAE1D,MAAMO,kBAAkBhB,YACtB,CAACiB;QACC,IAAI,CAACX,SAAS,OAAO;QACrB,qBAAO,KAACH;YAAUG,SAASA;YAASY,SAAST;YAAUU,OAAOF,OAAOE;;IACvE,GACA;QAACb;QAASG;KAAS;IAGrB,OAAO;QAAED;QAAOQ;QAAiBD;QAAOK,SAASC,QAAQf;IAAS;AACpE"}
+1
View File
@@ -1,2 +1,3 @@
export { Turnstile } from './Turnstile.js';
export type { TurnstileProps } from './Turnstile.js';
export { TurnstileProvider, useTurnstile } from './TurnstileProvider.js';
+1
View File
@@ -2,5 +2,6 @@
// Client-only exports — the Turnstile widget. Kept separate from index.ts so
// the server-only verify never leaks into a browser bundle.
export { Turnstile } from './Turnstile.js';
export { TurnstileProvider, useTurnstile } from './TurnstileProvider.js';
//# sourceMappingURL=client.js.map
+1 -1
View File
@@ -1 +1 @@
{"version":3,"sources":["../../../src/modules/turnstile/client.ts"],"sourcesContent":["'use client'\n// Client-only exports — the Turnstile widget. Kept separate from index.ts so\n// the server-only verify never leaks into a browser bundle.\nexport { Turnstile } from './Turnstile.js'\nexport type { TurnstileProps } from './Turnstile.js'\n"],"names":["Turnstile"],"mappings":"AAAA;AACA,6EAA6E;AAC7E,4DAA4D;AAC5D,SAASA,SAAS,QAAQ,iBAAgB"}
{"version":3,"sources":["../../../src/modules/turnstile/client.ts"],"sourcesContent":["'use client'\n// Client-only exports — the Turnstile widget. Kept separate from index.ts so\n// the server-only verify never leaks into a browser bundle.\nexport { Turnstile } from './Turnstile.js'\nexport type { TurnstileProps } from './Turnstile.js'\nexport { TurnstileProvider, useTurnstile } from './TurnstileProvider.js'\n"],"names":["Turnstile","TurnstileProvider","useTurnstile"],"mappings":"AAAA;AACA,6EAA6E;AAC7E,4DAA4D;AAC5D,SAASA,SAAS,QAAQ,iBAAgB;AAE1C,SAASC,iBAAiB,EAAEC,YAAY,QAAQ,yBAAwB"}
+1
View File
@@ -1 +1,2 @@
export { TurnstileProvider, useTurnstile } from './TurnstileProvider.js';
export { verifyTurnstile } from './verify.js';
+1
View File
@@ -1,3 +1,4 @@
export { TurnstileProvider, useTurnstile } from './TurnstileProvider.js';
// Server-only exports. verify.ts imports 'server-only', so this must never be
// imported from a client component — use ./client for the widget instead.
export { verifyTurnstile } from './verify.js';
+1 -1
View File
@@ -1 +1 @@
{"version":3,"sources":["../../../src/modules/turnstile/index.ts"],"sourcesContent":["// Server-only exports. verify.ts imports 'server-only', so this must never be\n// imported from a client component — use ./client for the widget instead.\nexport { verifyTurnstile } from './verify.js'\n"],"names":["verifyTurnstile"],"mappings":"AAAA,8EAA8E;AAC9E,0EAA0E;AAC1E,SAASA,eAAe,QAAQ,cAAa"}
{"version":3,"sources":["../../../src/modules/turnstile/index.ts"],"sourcesContent":["export { TurnstileProvider, useTurnstile } from './TurnstileProvider.js'\n// Server-only exports. verify.ts imports 'server-only', so this must never be\n// imported from a client component — use ./client for the widget instead.\nexport { verifyTurnstile } from './verify.js'\n"],"names":["TurnstileProvider","useTurnstile","verifyTurnstile"],"mappings":"AAAA,SAASA,iBAAiB,EAAEC,YAAY,QAAQ,yBAAwB;AACxE,8EAA8E;AAC9E,0EAA0E;AAC1E,SAASC,eAAe,QAAQ,cAAa"}
+8 -1
View File
@@ -103,11 +103,17 @@ export default buildConfig({
| Moduł | Opis | Dok |
|---|---|---|
| i18n | Lokalizacja, negocjacja locale, ścieżki URL | [i18n.md](./i18n.md) |
| i18n | Lokalizacja, negocjacja locale, ścieżki URL, strona jednojęzyczna | [i18n.md](./i18n.md) |
| hooks | Hooki: revalidate ISR, slug history 301, ochrona stron systemowych | [hooks.md](./hooks.md) |
| kolekcje-katalog | Jakie kolekcje budować, kiedy, jak wpiąć (minimum nie maksimum) | [kolekcje-katalog.md](./kolekcje-katalog.md) |
| fundamenty-projektu | Struktura katalogów, nazewnictwo, konwencje | [fundamenty-projektu.md](./fundamenty-projektu.md) |
| deployment | Zmienne .env, ISR/SSG, force-dynamic, Coolify/Docker | [deployment.md](./deployment.md) |
| pages | System pages (homepage/privacy/cookies) → ścieżki | [pages.md](./pages.md) |
| access | Role admin > editor > user, kontrola dostępu | [access.md](./access.md) |
| payload-helpers | getSiteSettings / getSiteIntegrations | [payload-helpers.md](./payload-helpers.md) |
| seo | Metadata, hreflang, auto-fill, plugin-seo | [seo.md](./seo.md) |
| wymagania-prawne | **Polityki, regulaminy, baner cookies, RODO (compliance)** | [wymagania-prawne.md](./wymagania-prawne.md) |
| standardy-kodu | **Dobre praktyki senior: typy, architektura, antywzorce** | [standardy-kodu.md](./standardy-kodu.md) |
| architektura-tresci | **Jak budować, żeby klient wszystko edytował** (filozofia CMS) | [architektura-tresci.md](./architektura-tresci.md) |
| blocks | RenderBlocks — silnik renderowania bloków | [blocks.md](./blocks.md) |
| consent | Banner cookies GDPR, Google Consent Mode | [consent.md](./consent.md) |
@@ -117,6 +123,7 @@ export default buildConfig({
| analytics | GA4 / GTM spięte z Consent Mode | [analytics.md](./analytics.md) |
| slug | Auto-slug z tytułu, per locale | [slug.md](./slug.md) |
| notifications | Teksty wyników akcji (formularz) per język | [notifications.md](./notifications.md) |
| storage | Media na Cloudflare R2 (offload z .env) | [storage.md](./storage.md) |
| security | Nagłówki bezpieczeństwa HTTP (HSTS, X-Frame...) | [security.md](./security.md) |
| content | Blog/archiwa: kolekcje pod stroną-archiwum, listing, paginacja | [content.md](./content.md) |
+23
View File
@@ -145,6 +145,29 @@ sitemap/robots → force-dynamic (bo generują przy żądaniu). Nie mieszaj na j
trasie. Treść z panelu: ISR = redaktor czeka do rewalidacji; rozważ on-demand
revalidation (hook afterChange → revalidatePath). Patrz seo.md, HOOKS.md.
## 3a3. SSG a dostęp do bazy przy buildzie (WAŻNE dla SEO)
`generateStaticParams` (z lib/content) prerenderuje strony jako SSG — head
synchroniczny, SEO 100/100. ALE żeby prerenderować, **build musi mieć dostęp do
bazy** (generateStaticParams czyta strony z bazy w czasie buildu).
- **Build MA dostęp do bazy** (baza w tej samej sieci Docker, dostępna w build
stage) → strony prerenderowane jako SSG (`●`), head synchroniczny → SEO OK ✓
- **Build NIE MA dostępu** (izolowany build stage) → generateStaticParams zwraca
`[]` (plugin łapie błąd, build nie pada), ale strony renderują się on-demand
(dynamicznie) → head może streamować do body → problem SEO wraca ✗
Plugin zabezpiecza build przed CRASHEM (try/catch → `[]`), ale to NIE zastępuje
dostępu do bazy. **Dla pełnego SSG/SEO zapewnij, że build kontenerowy widzi bazę.**
W Coolify/Docker: baza (Mongo/Postgres) powinna być dostępna podczas `pnpm build`,
nie tylko w runtime. Jeśli build jest w izolowanej sieci — rozważ:
- uruchom bazę w tej samej sieci Docker co build stage, albo
- build z DATABASE_URI wskazującym na dostępną bazę (nie wewnętrzny host niedostępny w buildzie).
Weryfikacja: po buildzie `pnpm build` pokazuje trasy jako `●` (SSG), nie `ƒ`
(Dynamic). Jeśli `ƒ` mimo generateStaticParams → build nie miał dostępu do bazy.
## 3b. Pułapka: prerender tras zależnych od bazy (KONIECZNE)
Next domyślnie **prerenderuje** trasy typu `sitemap.ts` w czasie `next build` —
+150
View File
@@ -0,0 +1,150 @@
# Hooki pluginu — automatyzacja tworzenia stron
Plugin dostarcza hooki, które zdejmują z projektów powtarzalną robotę. Wpinasz je
w kolekcje; działają automatycznie. Wszystkie gotowe do użycia (import z pluginu).
Powiązane: [pages.md](./pages.md), [seo.md](./seo.md), [wymagania-prawne.md](./wymagania-prawne.md).
---
## buildRevalidateHook — ISR odświeżany po zapisie (NAJWAŻNIEJSZY)
Bez tego ISR ma haczyk: redaktor zapisuje stronę i CZEKA na revalidate (do
godziny). Z tym — zapisuje i OD RAZU widzi zmianę. To warunek, żeby ISR był
używalny dla CMS.
```ts
// kolekcja Pages — z pliku projektu, który MOŻE importować next/cache
import { revalidatePath } from 'next/cache'
import { buildRevalidateHook } from '@intecion/ipal-kit'
import { i18nConfig } from '@/i18n.config'
const { afterChange, afterDelete } = buildRevalidateHook({
revalidatePath, // wstrzykiwany — plugin NIE importuje next/cache
config: i18nConfig,
})
export const Pages: CollectionConfig = {
slug: 'pages',
hooks: { afterChange: [afterChange], afterDelete: [afterDelete] },
// ...
}
```
**Dlaczego revalidatePath wstrzykiwany:** plugin nie importuje `next/cache` (to
by wywaliło Payload przy generate:importmap / czystym Node). Projekt podaje.
Obsługuje: wszystkie języki, root (home), zmianę slug (rewaliduje stary I nowy
path — stary URL nie serwuje starej treści), delete.
---
## setPublishedAtHook — auto-data publikacji
Ustawia `publishedAt` na teraz przy pierwszej publikacji (jeśli puste). Redaktor
nie wpisuje daty ręcznie; data jest dokładna dla Article JSON-LD i sitemap.
```ts
import { setPublishedAtHook } from '@intecion/ipal-kit'
// kolekcja z draftami (blog, artykuły):
hooks: { beforeChange: [setPublishedAtHook] }
```
Ustawia tylko przy przejściu na published; nie nadpisuje istniejącej daty
(redaktor może backdatować ręcznie).
---
## buildPreventDeleteSystemPage — ochrona stron systemowych
Blokuje usunięcie strony przypisanej do roli (homepage, privacyPolicy,
cookiePolicy, termsOfService). Redaktor nie usunie przypadkiem polityki
prywatności albo strony głównej → nie rozbije routingu i linków compliance.
```ts
import { buildPreventDeleteSystemPage } from '@intecion/ipal-kit'
hooks: { beforeDelete: [buildPreventDeleteSystemPage({ settingsSlug: 'site-settings' })] }
```
Żeby usunąć — najpierw odłącz rolę w Site Settings (świadoma decyzja).
---
## buildValidateUniqueRole — jedna strona = jedna rola
Zapobiega przypisaniu tej samej strony do dwóch ról systemowych (np. homepage I
privacyPolicy naraz → niejednoznaczny routing).
```ts
import { buildValidateUniqueRole } from '@intecion/ipal-kit'
// na polu roli w SiteSettings:
{
name: 'privacyPolicy',
type: 'relationship',
relationTo: 'pages',
hooks: { beforeValidate: [buildValidateUniqueRole({
siblingFields: ['homepage', 'cookiePolicy', 'termsOfService'],
})] },
}
```
---
## trackSlugHistoryHook — auto-redirect 301 przy zmianie slug
Gdy slug się zmienia, zapisuje STARY slug do pola `slugHistory`. Projekt czyta to
i robi 301 ze starego URL na nowy → zmiana adresu nie daje 404 (realna strata SEO
z audytu).
```ts
import { trackSlugHistoryHook } from '@intecion/ipal-kit'
export const Pages: CollectionConfig = {
fields: [
// ...
{ name: 'slugHistory', type: 'array', admin: { readOnly: true },
fields: [{ name: 'slug', type: 'text' }] },
],
hooks: { beforeChange: [trackSlugHistoryHook] },
}
```
Projekt w resolveRoute / sprawdzeniu redirectów: jeśli żądany slug jest w
slugHistory jakiejś strony → 301 na jej aktualny slug. Przykład:
```ts
// w page.tsx, gdy resolveRoute nie znajdzie strony po slug:
const byHistory = await payload.find({
collection: 'pages',
where: { 'slugHistory.slug': { equals: requestedSlug } },
limit: 1,
})
if (byHistory.docs[0]) {
redirect(`/${locale}/${byHistory.docs[0].slug}`) // 301 na aktualny
}
```
---
## KOLEJNOŚĆ hooków (ważne)
W jednej kolekcji hooki tej samej fazy uruchamiają się po kolei. Typowa Media:
```ts
hooks: {
beforeOperation: [normalizeFilenameHook], // czyste nazwy
afterChange: [afterChange], // revalidate
afterDelete: [afterDelete],
}
```
Typowa Pages:
```ts
hooks: {
beforeChange: [setPublishedAtHook, trackSlugHistoryHook],
beforeDelete: [buildPreventDeleteSystemPage(...)],
afterChange: [afterChange], // revalidate
afterDelete: [afterDelete],
}
```
Które hooki wpiąć zależy od kolekcji — nie każda potrzebuje wszystkich (blog:
setPublishedAt; wszystkie z URL: revalidate + slugHistory; Pages: + preventDelete).
+61 -1
View File
@@ -52,4 +52,64 @@ stopce / bannerze cookies bierzesz z `getSystemPagePath({ role: privacyPolicy })
```ts
import { ALL_SYSTEM_PAGE_ROLES } from '@intecion/ipal-kit'
// ['homepage', 'privacyPolicy', 'cookiePolicy']
```
```
## KRYTYCZNE: generateStaticParams dla [[...slug]] (SEO + head)
Trasa `[[...slug]]` (opcjonalny catch-all) BEZ `generateStaticParams` jest przez
Next traktowana jako **dynamiczna** (`ƒ Dynamic`). W trybie dynamicznym z React 19
serwer wysyła pusty `<head>`, a metadata streamuje na końcu `<body>` — crawlery
(Lighthouse, Screaming Frog) nie widzą `<meta description>` w head → SEO spada.
**Z `generateStaticParams` trasa kompiluje się jako SSG (`●`)** → synchroniczny,
kompletny `<head>` → SEO 100/100. To najsilniejsze rozwiązanie problemu
metadata-w-head (mocniejsze niż samo ISR/htmlLimitedBots).
Plugin dostarcza gotowy generateStaticParams przez createContentHelpers:
```ts
// lib/content.ts — dodaj do destrukturyzacji
export const {
getCachedPayload, getSettings, resolveRoute,
generateStaticParams, // ← z pluginu
sitemap, robots,
} = createContentHelpers({ config, content: contentConfig, i18n: i18nConfig, baseUrl })
// app/(frontend)/[[...slug]]/page.tsx (albo [locale]/[[...slug]])
export { generateStaticParams } from '@/lib/content'
```
Helper automatycznie: pobiera pages + kolekcje treści, wyklucza homepage (→ root),
drafty, 404/500; zwraca `{slug}[]` (jednojęzyczny) albo `{locale, slug}[]`
(wielojęzyczny). Obsługuje slugi wielopoziomowe (`a/b` → `['a','b']`) oraz
zlokalizowane (string albo mapa per język).
**Strony noindex SĄ renderowane** (nie pomijane jak w sitemap). Strona prawna
(polityka, cookies) z noindex nadal musi się wyświetlić — użytkownik wchodzi z
stopki, crawler czyta jej `<meta robots=noindex>`. noindex kontroluje
INDEKSOWANIE, nie istnienie strony. Pominięcie wymusiłoby dynamiczne renderowanie
(ten sam problem streamingu, którego unikamy).
Helper NIE filtruje `_status` w zapytaniu (`where`) — kolekcje bez włączonych
draftów nie mają tego pola i zapytanie by rzuciło błąd. Drafty odfiltrowane w
pamięci (bezpieczne dla każdej kolekcji).
## PUŁAPKA: await searchParams deoptymalizuje ISR
W Next 15/16 `searchParams` to Promise. Odczyt `const { page } = await searchParams`
w komponencie strony **deoptymalizuje ISR** — wymusza dynamiczne renderowanie dla
tego requestu (traci cały zysk SSG/ISR + wraca problem metadata w body).
- **Strona BEZ paginacji** → NIE przekazuj/nie czytaj `searchParams` wcale:
```ts
export default async function Page({ params }) { // bez searchParams
const { locale, slug } = await params
const route = await resolveRoute(locale, slug ?? []) // bez page
}
```
- **Strona Z paginacją** (archiwum) → czytaj searchParams, ale świadomie (ta trasa
będzie dynamiczna). Rozważ osobną trasę dla archiwum z paginacją, żeby zwykłe
strony zostały SSG.
Reguła: `searchParams` tylko tam, gdzie NAPRAWDĘ potrzebujesz (paginacja). Wszędzie
indziej pomiń — inaczej tracisz SSG i SEO.
+61 -2
View File
@@ -71,7 +71,44 @@ analytics, Turnstile, fonty). Generyczny CSP byłby albo za luźny (`*` =
bezużyteczny), albo psułby stronę. Więc plugin daje mechanizm (`additional`),
projekt dostarcza CSP dopasowany do siebie.
### Budowa CSP — domeny z env, nie hardkod
### buildCsp — generator CSP (zalecane zamiast ręcznego)
Zamiast pisać surowy CSP w każdym projekcie (ryzyko pominięcia base-uri,
object-src), użyj `buildCsp` — ma twarde reguły OWASP/Lighthouse wbudowane, a Ty
włączasz tylko flagi tego, co projekt ładuje:
```ts
// next.config.ts
import { buildCsp, buildSecurityHeaders } from '@intecion/ipal-kit'
const csp = buildCsp({
mode: 'report-only', // zacznij tu; 'enforce' gdy konsola czysta
r2Url: process.env.R2_PUBLIC_URL, // media R2 → img-src
turnstile: true, // challenges.cloudflare.com → script/frame/connect
analytics: true, // GTM + GA
youtube: true, // youtube → frame-src
googleMaps: true, // mapy Google
// extra: { 'script-src': ['https://inny-skrypt.pl'] }, // dodatkowe źródła
})
const securityHeaders = buildSecurityHeaders({
hsts: process.env.NODE_ENV === 'production',
additional: [csp],
})
```
**Twarde reguły wbudowane** (zawsze, nie da się zapomnieć): `base-uri 'self'`,
`object-src 'none'`, `frame-ancestors 'none'`. To te, które Lighthouse/OWASP
wymagają, a łatwo je pominąć pisząc CSP ręcznie.
`buildCsp` NIE dodaje `'unsafe-eval'` (osłabia CSP) — dodaj przez `extra` tylko
jeśli biblioteka tego wymaga. `mode: 'report-only'` daje nagłówek
`…-Report-Only`; `'enforce'` daje `Content-Security-Policy`.
CSP dalej „w projekcie" (Ty wybierasz flagi wg tego, co ładujesz), ale skeleton
jest z pluginu — każdy projekt ma ten sam zahardowany fundament.
### Budowa CSP — ręcznie (jeśli potrzebujesz pełnej kontroli)
Domenę mediów czytaj z `R2_PUBLIC_URL` (env), nie zaszywaj. Resztę źródeł
dopasuj do tego, co projekt faktycznie ładuje:
@@ -138,4 +175,26 @@ wpięte i czy Cloudflare (jeśli przed aplikacją) nie filtruje nagłówków.
> Uwaga Cloudflare: jeśli CF jest przed aplikacją, może nadpisywać/filtrować
> nagłówki. Wtedy ustaw je też w CF (Transform Rules → Modify Response Header)
> albo upewnij się, że CF przepuszcza nagłówki z origin.
> albo upewnij się, że CF przepuszcza nagłówki z origin.
## COOP (Cross-Origin-Opener-Policy) — domyślnie włączony
buildSecurityHeaders wysyła domyślnie `Cross-Origin-Opener-Policy: same-origin` —
izoluje kontekst przeglądarki (ochrona przed XS-Leaks / Spectre, wyciekiem
window.opener). Uniwersalny nagłówek, więc z automatu.
- Domyślnie `same-origin` (najbezpieczniejsze)
- `coop: 'same-origin-allow-popups'` — jeśli otwierasz popupy OAuth/płatności
wymagające window.opener
- `coop: false` — wyłącz (rzadko potrzebne)
## Trusted Types — NIE wdrażać (na teraz)
NIE wymuszaj `require-trusted-types-for 'script'`. Powód:
- Audyt Lighthouse to „Bez oceny" (informacyjny/eksperymentalny w Chromium)
- Wymuszenie bez kompleksowego silnika polityk w Next/React powoduje `TypeError`
przy zewnętrznych skryptach manipulujących DOM stringami (Turnstile, GA)
- Zysk bezpieczeństwa nie równoważy ryzyka zepsucia strony
Zostaw Trusted Types poza CSP, dopóki Next/React nie da natywnego wsparcia.
+44 -1
View File
@@ -884,4 +884,47 @@ pomija drafty i noindex. Poprawia widoczność w wyszukiwaniach AI (GEO —
Generative Engine Optimization) i audytach „Agentic Browsing”.
Wymaga wypełnionego siteDescription i sensownych meta.description stron
(inaczej llms.txt będzie ubogi).
(inaczej llms.txt będzie ubogi).
## Sitemap jako czytelna tabela (XSL stylesheet)
Domyślny `/sitemap.xml` to surowy XML — Google go czyta, ale człowiek widzi
„ścianę tagów". Można ostylować przez XSL (przeglądarka renderuje tabelę),
zachowując poprawność dla crawlerów.
### Ograniczenie Next
Standardowy `app/sitemap.ts` (Next MetadataRoute) **nie pozwala** wstrzyknąć
`<?xml-stylesheet?>`. Żeby mieć styl, serwuj sitemap własnym route przez
`buildSitemapXml` (string XML z odwołaniem do XSL):
```ts
// app/sitemap.xml/route.ts (zamiast app/sitemap.ts)
import { buildSitemapXml } from '@intecion/ipal-kit'
import { sitemap } from '@/lib/content'
export const dynamic = 'force-dynamic'
export async function GET() {
const entries = await sitemap()
const xml = buildSitemapXml(entries, { stylesheetUrl: '/sitemap.xsl' })
return new Response(xml, {
headers: { 'Content-Type': 'application/xml; charset=utf-8' },
})
}
```
### Plik XSL w /public
Skopiuj `sitemap.xsl` (z pluginu: `node_modules/@intecion/ipal-kit/dist/modules/seo/assets/sitemap.xsl`)
do `public/sitemap.xsl` w projekcie. Zawiera responsywną tabelę (numer, URL,
data, języki) z dark mode. `stylesheetUrl: '/sitemap.xsl'` wskazuje na niego.
### WAŻNE — jeden sitemap, nie dwa
Jeśli używasz route `app/sitemap.xml/route.ts` (styled), **USUŃ** `app/sitemap.ts`
(MetadataRoute). Dwa sitemapy pod różnymi ścieżkami mylą crawlery. Wybierz jeden:
- **styled** (`sitemap.xml/route.ts` + buildSitemapXml + XSL) — ładna tabela
- **prosty** (`sitemap.ts` + reeksport z lib/content) — bez stylu, mniej kodu
Styl to kosmetyka (Google czyta oba tak samo) — rób, jeśli klient/audyt tego chce.
+70 -1
View File
@@ -58,4 +58,73 @@ Zwraca `false` na każdy problem (brak klucza, sieć, odrzucenie) — traktuj
trafi do bundla przeglądarki.
> W formularzach zwykle nie wołasz `verifyTurnstile` wprost — robi to
> `submitForm` (patrz [forms.md](./forms.md)).
> `submitForm` (patrz [forms.md](./forms.md)).
## Uproszczone wpięcie — TurnstileProvider + useTurnstile (zalecane)
Jak CookieBanner: siteKey raz w layoutcie, formularze biorą z kontekstu. Koniec
przekazywania siteKey do każdego formularza.
### 1. Provider w layoutcie (raz, siteKey z serwera)
```tsx
// app/(frontend)/[locale]/layout.tsx (server)
import { TurnstileProvider } from '@intecion/ipal-kit/client'
import { getTurnstileSiteKey } from '@/lib/payload' // Twój helper server-side
export default async function Layout({ children }) {
const siteKey = await getTurnstileSiteKey() // z panelu (SiteIntegrations)
return (
<html>
<body>
<TurnstileProvider siteKey={siteKey}>
{children}
</TurnstileProvider>
</body>
</html>
)
}
```
### 2. Formularz — useTurnstile (zero plumbingu siteKey)
```tsx
'use client'
import { useTurnstile } from '@intecion/ipal-kit/client'
function ContactForm() {
const { token, TurnstileWidget, reset, enabled } = useTurnstile()
async function handleSubmit(data) {
const result = await submitForm({ ...data, turnstileToken: token })
if (result.ok) reset() // wyczyść token na następne wysłanie
}
return (
<form onSubmit={...}>
{/* pola formularza */}
<TurnstileWidget /> {/* widget tam, gdzie ma być */}
<button type="submit">Wyślij</button>
</form>
)
}
```
`token` → do submitForm. `TurnstileWidget` → wstaw gdzie ma być. `reset()` → po
wysłaniu. `enabled` → false gdy brak klucza (dev bez Turnstile).
### Dlaczego Turnstile NIE jest w pełni "wstaw i zapomnij" jak CookieBanner
CookieBanner jest samodzielny (renderuje się, zarządza zgodą, zero interakcji).
Turnstile z natury jest CZĘŚCIĄ formularza — zwraca token, który formularz musi
wysłać przy submit i zweryfikować server-side. Nie da się go „wstawić
gdziekolwiek" — musi być w formularzu, przy jego logice wysyłki.
Provider+hook to maksimum uproszczenia: siteKey raz (jak CookieBanner), a w
formularzu tylko `<TurnstileWidget/>` + `token`. Reszta (weryfikacja) dzieje się
w submitForm automatycznie.
### Stary sposób (nadal działa)
`<Turnstile siteKey={...} onToken={...} />` bezpośrednio — jeśli potrzebujesz
pełnej kontroli albo masz nietypowy przypadek. Provider to warstwa wygody nad tym.
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "@intecion/ipal-kit",
"version": "1.2.7",
"version": "1.3.1",
"description": "Intecion Payload Advanced Library — a Payload CMS 3 plugin: i18n, SEO, forms, consent, analytics, blog/archives.",
"license": "MIT",
"repository": {
+3 -3
View File
@@ -17,8 +17,8 @@ export {
useConsentContext,
} from '../modules/consent/client.js'
export type { CookieBannerClassNames } from '../modules/consent/client.js'
export { Turnstile } from '../modules/turnstile/client.js'
export type { TurnstileProps } from '../modules/turnstile/client.js'
export { resolveFormMessage } from '../modules/notifications/resolveFormMessage.js'
export type { FormNotificationTexts } from '../modules/notifications/types.js'
export { Turnstile } from '../modules/turnstile/client.js'
export { TurnstileProvider, useTurnstile } from '../modules/turnstile/client.js'
export type { TurnstileProps } from '../modules/turnstile/client.js'
+2 -1
View File
@@ -1,4 +1,5 @@
import type { GlobalConfig } from 'payload'
import { notificationsFields } from './fields.js'
/**
@@ -9,10 +10,10 @@ import { notificationsFields } from './fields.js'
export function buildNotifications(): GlobalConfig {
return {
slug: 'notifications',
label: 'Notifications',
access: {
read: () => true, // texts are public-facing (shown to end users)
},
fields: notificationsFields,
label: 'Notifications',
}
}
+30 -25
View File
@@ -60,6 +60,13 @@ export type {
FormsOption,
} from './modules/forms/types.js'
export { createContentHelpers } from './modules/frontend/index.js'
export {
buildPreventDeleteSystemPage,
buildRevalidateHook,
buildValidateUniqueRole,
setPublishedAtHook,
trackSlugHistoryHook,
} from './modules/hooks/index.js'
export type { I18nConfig, LocaleDefinition, LocalizedSlugs } from './modules/i18n/index.js'
export {
buildLocalizedPath,
@@ -75,18 +82,13 @@ export {
} from './modules/i18n/index.js'
export type { LocaleMiddlewareResult } from './modules/i18n/index.js'
export { createLocaleMiddleware, DEFAULT_MIDDLEWARE_MATCHER } from './modules/i18n/index.js'
// Media — filename normalization hook for upload collections (Media).
export { normalizeFilename, normalizeFilenameHook } from './modules/media/index.js'
export {
getNotificationTexts,
NOTIFICATION_FALLBACK,
resolveFormMessage,
} from './modules/notifications/index.js'
export type {
FormNotificationTexts,
NotificationsData,
NotificationTexts,
} from './modules/notifications/index.js'
export type { FormNotificationTexts, NotificationTexts } from './modules/notifications/index.js'
export type { PagesOption, SystemPageRole } from './modules/pages/index.js'
export { ALL_SYSTEM_PAGE_ROLES, getSystemPagePath } from './modules/pages/index.js'
export type { GlobalQueryOptions } from './modules/payload/index.js'
@@ -98,24 +100,10 @@ export {
SITE_SETTINGS_SLUG,
} from './modules/payload/index.js'
export { buildSecurityHeaders } from './modules/security/index.js'
export { buildCsp } from './modules/security/index.js'
export type { BuildCspArgs } from './modules/security/index.js'
export type { BuildSecurityHeadersArgs, SecurityHeader } from './modules/security/index.js'
export {
buildArticleJsonLd,
buildFaqJsonLd,
buildIconsMetadata,
buildLlmsTxt,
buildLocalBusinessJsonLd,
buildOrganizationJsonLd,
buildServiceJsonLd,
validateFaviconField,
} from './modules/seo/index.js'
// Structured data (schema.org JSON-LD) — brand/sitelink signals for Google.
// WebSite (+ optional SearchAction), BreadcrumbList (per page), SiteNavigation.
export {
buildBreadcrumbJsonLd,
buildSiteNavigationJsonLd,
buildWebSiteJsonLd,
} from './modules/seo/index.js'
export type { PageMetadata, SeoMeta, SeoOption } from './modules/seo/index.js'
export { buildHreflangAlternates, buildMetadata, composeTitle } from './modules/seo/index.js'
export type { AutoFillMapping, RobotsRules, SitemapEntry } from './modules/seo/index.js'
@@ -127,9 +115,26 @@ export {
createPageMetadata,
injectAutoFillMeta,
} from './modules/seo/index.js'
export {
buildIconsMetadata,
buildOrganizationJsonLd,
validateFaviconField,
} from './modules/seo/index.js'
export {
buildBreadcrumbJsonLd,
buildSiteNavigationJsonLd,
buildWebSiteJsonLd,
} from './modules/seo/index.js'
// Local SEO structured data — LocalBusiness (map pack), Service (offering), FAQPage.
export {
buildFaqJsonLd,
buildLocalBusinessJsonLd,
buildServiceJsonLd,
} from './modules/seo/index.js'
export { buildArticleJsonLd } from './modules/seo/index.js'
export { buildSitemapXml } from './modules/seo/index.js'
export { buildLlmsTxt } from './modules/seo/index.js'
export { buildSlugField, toSlug } from './modules/slug/index.js'
// Storage — Cloudflare R2 media offload, configured from .env.
export { buildR2Storage } from './modules/storage/index.js'
export { ipalKit } from './plugin.js'
export type { IpalOptions } from './types.js'
+144 -27
View File
@@ -1,14 +1,22 @@
import { cache } from 'react'
import type { BasePayload, SanitizedConfig } from 'payload'
import { getPayload } from 'payload'
import type { ContentOption, ResolvedRoute, ArchiveEntries } from '../content/index.js'
import { resolveRoute as resolveRouteRaw, getArchiveEntries } from '../content/index.js'
import { getPayload } from 'payload'
import { cache } from 'react'
import type { ArchiveEntries, ContentOption, ResolvedRoute } from '../content/index.js'
import type { I18nConfig } from '../i18n/index.js'
import type { SitemapEntry, RobotsRules } from '../seo/index.js'
import { buildSitemapEntries, buildRobots } from '../seo/index.js'
import type { RobotsRules, SitemapEntry } from '../seo/index.js'
import { getArchiveEntries, resolveRoute as resolveRouteRaw } from '../content/index.js'
import { buildRobots, buildSitemapEntries } from '../seo/index.js'
type CreateContentHelpersArgs = {
/**
* Absolute site origin for sitemap/robots URLs. Falls back to
* NEXT_PUBLIC_SERVER_URL, then to a relative origin (which most crawlers
* reject, so set one in production).
*/
baseUrl?: string
/**
* The client's payload config promise (the default export of payload.config).
* Passed in because the plugin never imports the client's config directly.
@@ -16,21 +24,15 @@ type CreateContentHelpersArgs = {
config: Promise<SanitizedConfig> | SanitizedConfig
/** Archive-backed collections, same value as the plugin option. */
content?: ContentOption
/** SiteSettings global slug. Defaults to 'site-settings'. */
settingsSlug?: string
/** Pages collection slug. Defaults to 'pages'. */
pagesSlug?: string
/**
* i18n config. Required only if you want the ready-made `sitemap` / `robots`
* handlers — they need the locale list to emit hreflang.
*/
i18n?: I18nConfig
/**
* Absolute site origin for sitemap/robots URLs. Falls back to
* NEXT_PUBLIC_SERVER_URL, then to a relative origin (which most crawlers
* reject, so set one in production).
*/
baseUrl?: string
/** Pages collection slug. Defaults to 'pages'. */
pagesSlug?: string
/** SiteSettings global slug. Defaults to 'site-settings'. */
settingsSlug?: string
}
/**
@@ -60,12 +62,12 @@ type CreateContentHelpersArgs = {
* not the second, and a page component composes them in two obvious lines.
*/
export function createContentHelpers({
baseUrl,
config,
content,
settingsSlug = 'site-settings',
pagesSlug = 'pages',
i18n,
baseUrl,
pagesSlug = 'pages',
settingsSlug = 'site-settings',
}: CreateContentHelpersArgs) {
const origin = baseUrl ?? process.env.NEXT_PUBLIC_SERVER_URL ?? ''
const getCachedPayload = cache(async (): Promise<BasePayload> =>
@@ -79,7 +81,7 @@ export function createContentHelpers({
const getSettings = cache(async (locale: string) => {
const payload = await getCachedPayload()
return payload.findGlobal({ slug: settingsSlug as never, locale: locale as never, depth: 2 })
return payload.findGlobal({ slug: settingsSlug as never, depth: 2, locale: locale as never })
})
/** What does this URL point at? Routing only — no listing data. */
@@ -88,9 +90,9 @@ export function createContentHelpers({
locale: string,
segments: string[] | undefined,
page: number,
): Promise<ResolvedRoute | null> => {
): Promise<null | ResolvedRoute> => {
const payload = await getCachedPayload()
return resolveRouteRaw({ payload, locale, segments, page, content, pagesSlug, settingsSlug })
return resolveRouteRaw({ content, locale, page, pagesSlug, payload, segments, settingsSlug })
},
)
@@ -103,7 +105,7 @@ export function createContentHelpers({
perPage: number,
): Promise<ArchiveEntries> => {
const payload = await getCachedPayload()
return getArchiveEntries({ payload, collection, locale, page, perPage })
return getArchiveEntries({ collection, locale, page, payload, perPage })
},
)
@@ -134,11 +136,11 @@ export function createContentHelpers({
}
try {
return await buildSitemapEntries({
payload: await getCachedPayload(),
config: i18n,
baseUrl: origin,
config: i18n,
content,
pagesSlug,
payload: await getCachedPayload(),
settingsSlug,
})
} catch (error) {
@@ -165,13 +167,128 @@ export function createContentHelpers({
*/
const robots = (): RobotsRules => buildRobots({ baseUrl: origin })
/**
* Next.js generateStaticParams for the [[...slug]] route (or
* [locale]/[[...slug]]). Returns every routable page as a params object, so
* Next PRE-RENDERS them as static (SSG) instead of dynamic.
*
* Why this matters beyond convenience: an optional catch-all with no
* generateStaticParams is treated as a DYNAMIC route (ƒ), which streams
* metadata into <body> (crawlers miss it). Providing generateStaticParams
* compiles routes as SSG (●) — the <head> is synchronous and complete. This is
* the strongest fix for the metadata-in-head problem (stronger than ISR alone).
*
* Handles automatically:
* - pages collection + content collections (with their archive prefix)
* - excludes the homepage (maps to { slug: [] } — the root)
* - excludes drafts and 404/500/system slugs
* - KEEPS noindex pages (they must still render — noindex controls indexing,
* not existence; skipping them would force dynamic rendering)
* - localized slugs (string or per-locale map) both handled
* - single-locale → { slug }[]; multi-locale → { locale, slug }[]
*
* Wire it in the project:
* // app/(frontend)/[[...slug]]/page.tsx (or [locale]/[[...slug]])
* export { generateStaticParams } from '@/lib/content'
*/
const generateStaticParams = async (): Promise<
Array<{ locale: string; slug: string[] } | { slug: string[] }>
> => {
try {
const payload = await getCachedPayload()
const locales = i18n ? i18n.locales.map((l) => l.code) : [undefined]
const singleLocale = !i18n || i18n.locales.length === 1
// Home slug per locale, to exclude the homepage (it's the root, slug []).
const settings = (await payload
.findGlobal({ slug: settingsSlug as never, depth: 1, locale: 'all' as never })
.catch(() => null)) as { homepage?: { id?: number | string; slug?: unknown } } | null
const homeId = settings?.homepage?.id
const EXCLUDED = new Set(['404', '500', 'error', 'not-found'])
const params: Array<{ locale: string; slug: string[] } | { slug: string[] }> = []
for (const locale of locales) {
// NO where:{_status} filter — collections without drafts enabled don't
// register the _status field, and querying it throws
// "path cannot be queried: _status". We filter drafts in memory below,
// which is safe for every collection (with or without drafts).
const result = await payload.find({
collection: pagesSlug as never,
depth: 0,
limit: 1000,
locale: (locale ?? 'all') as never,
})
for (const raw of result.docs as Array<{
_status?: string
id: number | string
meta?: { noindex?: boolean } | null
slug?: unknown
}>) {
// Draft filter in memory (safe whether or not the collection has drafts).
if (raw._status && raw._status !== 'published') {continue}
// NOTE: unlike the sitemap, we do NOT skip meta.noindex here. A noindex
// page (privacy, cookies, terms) still needs to render — users reach it
// from the footer and crawlers read its <meta robots=noindex>. Pre-render
// it as SSG so it's fast and its <head> is complete; noindex controls
// INDEXING, not whether the page exists. Skipping it would force dynamic
// rendering (the very streaming problem we're avoiding).
if (homeId && raw.id === homeId) {
// Homepage → root. Emit an empty-slug param so '/' (or '/pl') builds.
const empty = singleLocale ? { slug: [] } : { slug: [], locale: locale as string }
if (!params.some((p) => JSON.stringify(p) === JSON.stringify(empty))) {params.push(empty)}
continue
}
// Slug may be a plain string OR a localized map ({ pl: 'kontakt' }) when
// read with locale:'all' or left unflattened. Handle both, or localized
// pages get silently dropped.
const rawSlug = raw.slug
const slug =
typeof rawSlug === 'string'
? rawSlug
: rawSlug && typeof rawSlug === 'object'
? (((rawSlug as Record<string, unknown>)[locale ?? ''] as string | undefined) ??
(Object.values(rawSlug as Record<string, unknown>)[0] as string | undefined))
: undefined
if (!slug || EXCLUDED.has(slug)) {continue}
// Multi-level slugs ('atrakcje/telefon') → array segments.
const segments = String(slug).split('/').filter(Boolean)
params.push(
singleLocale ? { slug: segments } : { slug: segments, locale: locale as string },
)
}
}
return params
} catch (err) {
// DB unreachable — typically a container build (Docker/Coolify/CI) with no
// database network. Return [] so the build doesn't crash: Next falls back
// to on-demand rendering for the routes, which fill in once the DB is
// reachable at runtime. Without this every project would need its own
// try/catch here. (Same graceful-degradation as the sitemap handler.)
console.warn(
'[ipal] generateStaticParams: database not reachable during build ' +
'(Docker/CI) — returning empty params; routes render on-demand at runtime:',
err,
)
return []
}
}
return {
generateStaticParams,
getCachedPayload,
getConfiguredLocales,
getEntries,
getSettings,
resolveRoute,
getEntries,
sitemap,
robots,
sitemap,
}
}
+101
View File
@@ -0,0 +1,101 @@
import type { CollectionAfterChangeHook, CollectionAfterDeleteHook } from 'payload'
import type { I18nConfig } from '../i18n/index.js'
import { buildLocalizedPath, getLocaleCodes } from '../i18n/index.js'
type RevalidateFn = (path: string) => void
type BuildRevalidateHookArgs = {
config: I18nConfig
/** Home slug (string or per-locale map) — home revalidates the root. */
homeSlug?: Record<string, string> | string
/**
* next/cache revalidatePath, INJECTED by the project. The plugin never imports
* next/cache itself — that would crash when Payload runs as plain Node
* (generate:importmap). The project passes it: `revalidatePath` from 'next/cache'.
*/
revalidatePath: RevalidateFn
}
type DocWithSlug = { slug?: unknown }
/** Resolve a doc's path in one locale (root for home). Null if no slug there. */
function pathForLocale(
doc: DocWithSlug,
locale: string,
config: I18nConfig,
homeSlug?: Record<string, string> | string,
): null | string {
const slugField = doc.slug
const slug =
typeof slugField === 'string'
? slugField
: slugField && typeof slugField === 'object'
? ((slugField as Record<string, unknown>)[locale] as string | undefined)
: undefined
if (!slug) {return null}
return buildLocalizedPath({ config, homeSlug, locale, slugs: { [locale]: slug } }) ?? null
}
/**
* Builds afterChange + afterDelete hooks that revalidate a page's ISR cache when
* an editor saves or deletes it — so changes appear immediately instead of
* waiting for the revalidate window. Without this, ISR means editors wait; with
* it, ISR is usable for a CMS.
*
* Handles every locale, the root (home), AND a changed slug (revalidates both the
* old and new path so neither goes stale). revalidatePath is injected — the
* plugin never imports next/cache (safe under generate:importmap / plain Node).
*
* // in your Media/Pages collection config, from a project file that CAN import next/cache:
* import { revalidatePath } from 'next/cache'
* import { buildRevalidateHook } from '@intecion/ipal-kit'
* const { afterChange, afterDelete } = buildRevalidateHook({ revalidatePath, config: i18nConfig })
* // hooks: { afterChange: [afterChange], afterDelete: [afterDelete] }
*/
export function buildRevalidateHook({
config,
homeSlug,
revalidatePath,
}: BuildRevalidateHookArgs): {
afterChange: CollectionAfterChangeHook
afterDelete: CollectionAfterDeleteHook
} {
const locales = getLocaleCodes(config)
const afterChange: CollectionAfterChangeHook = ({ doc, previousDoc }) => {
const seen = new Set<string>()
for (const locale of locales) {
// New path.
const newPath = pathForLocale(doc as DocWithSlug, locale, config, homeSlug)
if (newPath && !seen.has(newPath)) {
revalidatePath(newPath)
seen.add(newPath)
}
// Old path, if the slug changed — so the old URL doesn't serve stale content.
if (previousDoc) {
const oldPath = pathForLocale(previousDoc as DocWithSlug, locale, config, homeSlug)
if (oldPath && oldPath !== newPath && !seen.has(oldPath)) {
revalidatePath(oldPath)
seen.add(oldPath)
}
}
}
return doc
}
const afterDelete: CollectionAfterDeleteHook = ({ doc }) => {
const seen = new Set<string>()
for (const locale of locales) {
const path = pathForLocale(doc as DocWithSlug, locale, config, homeSlug)
if (path && !seen.has(path)) {
revalidatePath(path)
seen.add(path)
}
}
return doc
}
return { afterChange, afterDelete }
}
+10
View File
@@ -0,0 +1,10 @@
// Re-eksport hooków domenowych (mieszkają w swoich modułach, tu dla przeglądu —
// żeby był jeden katalog "wszystkie hooki pluginu"). Źródło prawdy to ich moduły.
export { normalizeFilenameHook } from '../media/index.js'
export { buildAutoFillMetaHook, validateFaviconField } from '../seo/index.js'
export { buildRevalidateHook } from './buildRevalidateHook.js'
export { buildPreventDeleteSystemPage } from './preventDeleteSystemPage.js'
export { setPublishedAtHook } from './setPublishedAt.js'
export { trackSlugHistoryHook } from './trackSlugHistory.js'
export { buildValidateUniqueRole } from './validateUniqueRole.js'
@@ -0,0 +1,45 @@
import type { CollectionBeforeDeleteHook } from 'payload'
import { APIError } from 'payload'
/**
* Blocks deletion of a page assigned a System Page role (homepage,
* privacyPolicy, cookiePolicy, termsOfService). An editor deleting the privacy
* policy or homepage by accident would break routing and compliance links; this
* stops it with a clear error. They must unassign the role first (deliberate).
*
* Reads the role assignments from SiteSettings (which page holds which role).
*
* hooks: { beforeDelete: [buildPreventDeleteSystemPage({ settingsSlug: 'site-settings' })] }
*/
export function buildPreventDeleteSystemPage(
args: { roleFields?: string[]; settingsSlug?: string } = {},
): CollectionBeforeDeleteHook {
const settingsSlug = args.settingsSlug ?? 'site-settings'
const roleFields = args.roleFields ?? [
'homepage',
'privacyPolicy',
'cookiePolicy',
'termsOfService',
]
return async ({ id, req }) => {
const settings = (await req.payload
.findGlobal({ slug: settingsSlug as never, depth: 0 })
.catch(() => null)) as null | Record<string, unknown>
if (!settings) {return}
for (const field of roleFields) {
const assigned = settings[field]
const assignedId =
assigned && typeof assigned === 'object' ? (assigned as { id?: unknown }).id : assigned
if (assignedId != null && String(assignedId) === String(id)) {
throw new APIError(
`Nie można usunąć strony przypisanej do roli systemowej "${field}". ` +
`Najpierw odłącz rolę w Site Settings.`,
400,
)
}
}
}
}
+20
View File
@@ -0,0 +1,20 @@
import type { CollectionBeforeChangeHook } from 'payload'
/**
* Sets `publishedAt` to now the first time a document transitions to published,
* if it isn't already set. Saves editors from filling the date manually and
* keeps blog/article dates accurate for Article JSON-LD and sitemaps.
*
* Attach to collections with drafts enabled (blog, articles):
* hooks: { beforeChange: [setPublishedAtHook] }
*
* Only sets on the published transition; never overwrites an existing date
* (an editor can still backdate manually).
*/
export const setPublishedAtHook: CollectionBeforeChangeHook = ({ data, originalDoc }) => {
const becomingPublished = data._status === 'published' && originalDoc?._status !== 'published'
if (becomingPublished && !data.publishedAt) {
data.publishedAt = new Date().toISOString()
}
return data
}
+38
View File
@@ -0,0 +1,38 @@
import type { CollectionBeforeChangeHook } from 'payload'
/**
* When a document's slug changes, appends the OLD slug to a `slugHistory` array
* field. The project reads slugHistory to serve a 301 redirect from old URLs to
* the current one — so changing a slug doesn't 404 the old address (a real SEO
* loss / audit finding).
*
* Requires a `slugHistory` field on the collection:
* { name: 'slugHistory', type: 'array', fields: [{ name: 'slug', type: 'text' }],
* admin: { readOnly: true } }
*
* hooks: { beforeChange: [trackSlugHistoryHook] }
*
* The project then, in resolveRoute or a redirect check, looks up slugHistory and
* 301s to the current slug. See docs/hooks.md.
*/
export const trackSlugHistoryHook: CollectionBeforeChangeHook = ({ data, originalDoc }) => {
const oldSlug = originalDoc?.slug
const newSlug = data.slug
if (
typeof oldSlug === 'string' &&
typeof newSlug === 'string' &&
oldSlug !== newSlug &&
oldSlug.length > 0
) {
const history: Array<{ slug: string }> = Array.isArray(data.slugHistory)
? data.slugHistory
: Array.isArray(originalDoc?.slugHistory)
? originalDoc.slugHistory
: []
// Avoid duplicates; don't record the new slug itself.
if (!history.some((h) => h?.slug === oldSlug)) {
data.slugHistory = [...history, { slug: oldSlug }]
}
}
return data
}
+35
View File
@@ -0,0 +1,35 @@
import type { FieldHook } from 'payload'
import { APIError } from 'payload'
/**
* Field hook for a System Page role relationship in SiteSettings: ensures a page
* isn't assigned to two roles at once (e.g. the same page as both homepage and
* privacyPolicy), which would make routing ambiguous.
*
* Attach to each role field's beforeValidate. `siblingFields` are the OTHER role
* field names to check against.
*
* hooks: { beforeValidate: [buildValidateUniqueRole({
* siblingFields: ['privacyPolicy', 'cookiePolicy', 'termsOfService'],
* })] }
*/
export function buildValidateUniqueRole(args: { siblingFields: string[] }): FieldHook {
return ({ field, siblingData, value }) => {
if (value == null) {return value}
const thisId = typeof value === 'object' ? (value as { id?: unknown }).id : value
for (const sibling of args.siblingFields) {
const other = (siblingData as Record<string, unknown>)?.[sibling]
const otherId = other && typeof other === 'object' ? (other as { id?: unknown }).id : other
if (otherId != null && String(otherId) === String(thisId)) {
const name = typeof field === 'object' && 'name' in field ? field.name : 'ta rola'
throw new APIError(
`Ta sama strona jest przypisana do "${name}" i "${sibling}". ` +
`Każda rola systemowa musi wskazywać inną stronę.`,
400,
)
}
}
return value
}
}
+116
View File
@@ -0,0 +1,116 @@
export type BuildCspArgs = {
/** Google Analytics / GTM — adds googletagmanager + google-analytics. */
analytics?: boolean
/** Extra sources per directive, merged with the built-ins. */
extra?: Partial<Record<CspDirective, string[]>>
/** Google Maps embeds — adds maps.google.com / *.gstatic.com. */
googleMaps?: boolean
/** 'enforce' → Content-Security-Policy; 'report-only' → …-Report-Only header. */
mode?: 'enforce' | 'report-only'
/** Media/R2 public URL (from R2_PUBLIC_URL) — added to img-src. */
r2Url?: string
/** Cloudflare Turnstile — adds challenges.cloudflare.com to script/frame/connect. */
turnstile?: boolean
/** YouTube embeds — adds youtube to frame-src. */
youtube?: boolean
}
type CspDirective =
| 'base-uri'
| 'connect-src'
| 'default-src'
| 'font-src'
| 'form-action'
| 'frame-ancestors'
| 'frame-src'
| 'img-src'
| 'media-src'
| 'object-src'
| 'script-src'
| 'style-src'
| 'worker-src'
/**
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
* directives baked in, and opt-in sources for common third parties. Solves the
* real risk of hand-writing raw CSP per project and forgetting `base-uri 'self'`
* or `object-src 'none'`.
*
* CSP still lives in the project (it lists the project's own domains), but this
* helper standardizes the skeleton so every project's CSP has the same hardened
* base — you only flip flags for what the project actually loads.
*
* Returns { key, value } ready for buildSecurityHeaders `additional`:
*
* import { buildCsp, buildSecurityHeaders } from '@intecion/ipal-kit'
* const csp = buildCsp({
* mode: 'report-only', // start here; switch to 'enforce' when clean
* r2Url: process.env.R2_PUBLIC_URL,
* turnstile: true, analytics: true,
* })
* const headers = buildSecurityHeaders({ hsts: prod, additional: [csp] })
*
* Deploy CSP carefully: start with mode:'report-only', check the console for
* violations across the whole site (forms/Turnstile, gallery/R2, embeds), add
* missing sources via `extra`, THEN switch to 'enforce'. See docs/security.md.
*/
export function buildCsp(args: BuildCspArgs = {}): { key: string; value: string } {
const { analytics, extra = {}, googleMaps, mode = 'enforce', r2Url, turnstile, youtube } = args
const src: Record<CspDirective, string[]> = {
'default-src': ["'self'"],
// 'unsafe-inline' is hard to avoid with Next/analytics; 'unsafe-eval' is NOT
// added by default (weakens CSP) — add via extra only if a library needs it.
'connect-src': ["'self'"],
'font-src': ["'self'", 'https://fonts.gstatic.com', 'data:'],
'form-action': ["'self'"],
'frame-src': [],
'img-src': ["'self'", 'data:', 'blob:'],
'media-src': [], // video/audio sources — filled via extra when needed
'script-src': ["'self'", "'unsafe-inline'"],
'style-src': ["'self'", "'unsafe-inline'", 'https://fonts.googleapis.com'],
'worker-src': [], // web workers — filled via extra when needed
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
'base-uri': ["'self'"], // block <base> hijacking
'frame-ancestors': ["'none'"], // clickjacking protection (replaces X-Frame-Options)
'object-src': ["'none'"], // block <object>/<embed> (Flash-era attack surface)
}
if (r2Url) {src['img-src'].push(r2Url)}
if (turnstile) {
src['script-src'].push('https://challenges.cloudflare.com')
src['frame-src'].push('https://challenges.cloudflare.com')
src['connect-src'].push('https://challenges.cloudflare.com')
}
if (analytics) {
src['script-src'].push('https://www.googletagmanager.com')
src['connect-src'].push('https://www.google-analytics.com', 'https://www.googletagmanager.com')
src['img-src'].push('https://www.google-analytics.com', 'https://www.googletagmanager.com')
}
if (youtube) {
src['frame-src'].push('https://www.youtube.com', 'https://www.youtube-nocookie.com')
}
if (googleMaps) {
src['frame-src'].push('https://www.google.com', 'https://maps.google.com')
src['script-src'].push('https://maps.googleapis.com')
src['img-src'].push('https://maps.gstatic.com', 'https://*.googleapis.com')
}
// Merge caller extras.
for (const [dir, values] of Object.entries(extra) as Array<[CspDirective, string[]]>) {
if (values && values.length) {src[dir] = [...(src[dir] ?? []), ...values]}
}
const value = (Object.entries(src) as Array<[CspDirective, string[]]>)
.filter(([, values]) => values.length > 0)
.map(([dir, values]) => `${dir} ${values.join(' ')}`)
.join('; ')
const key =
mode === 'report-only' ? 'Content-Security-Policy-Report-Only' : 'Content-Security-Policy'
return { key, value }
}
@@ -11,6 +11,14 @@ export type BuildSecurityHeadersArgs = {
* domains (scripts, images, fonts, analytics). Keep CSP in your project.
*/
additional?: SecurityHeader[]
/**
* Cross-Origin-Opener-Policy. Default 'same-origin' — isolates the browsing
* context so a malicious page can't hold a window.opener reference (protects
* against XS-Leaks / Spectre-class attacks). Project-independent, so it's a
* default. Use 'same-origin-allow-popups' if you open OAuth/payment popups
* that need window.opener; false to omit.
*/
coop?: 'same-origin' | 'same-origin-allow-popups' | false
/**
* X-Frame-Options value. 'DENY' (default) blocks all framing; 'SAMEORIGIN'
* allows same-origin framing. Note: CSP frame-ancestors supersedes this in
@@ -69,6 +77,7 @@ export type BuildSecurityHeadersArgs = {
export function buildSecurityHeaders(args: BuildSecurityHeadersArgs = {}): SecurityHeader[] {
const {
additional = [],
coop = 'same-origin',
frameOptions = 'DENY',
hsts = true,
hstsIncludeSubDomains = true,
@@ -102,6 +111,11 @@ export function buildSecurityHeaders(args: BuildSecurityHeadersArgs = {}): Secur
headers.push({ key: 'Permissions-Policy', value: permissionsPolicy })
}
// COOP — isolates the browsing context (XS-Leaks / Spectre protection).
if (coop) {
headers.push({ key: 'Cross-Origin-Opener-Policy', value: coop })
}
// Merge additional: same-key entries override the defaults above.
for (const extra of additional) {
const i = headers.findIndex((h) => h.key.toLowerCase() === extra.key.toLowerCase())
+3 -1
View File
@@ -1,2 +1,4 @@
export { buildCsp } from './buildCsp.js'
export type { BuildCspArgs } from './buildCsp.js'
export { buildSecurityHeaders } from './buildSecurityHeaders.js'
export type { BuildSecurityHeadersArgs, SecurityHeader } from './buildSecurityHeaders.js'
export type { BuildSecurityHeadersArgs, SecurityHeader, } from './buildSecurityHeaders.js'
+85
View File
@@ -0,0 +1,85 @@
<?xml version="1.0" encoding="UTF-8"?>
<xsl:stylesheet version="1.0"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:s="http://www.sitemaps.org/schemas/sitemap/0.9"
xmlns:xhtml="http://www.w3.org/1999/xhtml">
<xsl:output method="html" encoding="UTF-8" indent="yes"/>
<xsl:template match="/">
<html lang="pl">
<head>
<meta charset="UTF-8"/>
<meta name="viewport" content="width=device-width, initial-scale=1"/>
<title>Sitemap</title>
<style>
:root { color-scheme: light dark; }
* { box-sizing: border-box; }
body {
font-family: system-ui, -apple-system, Segoe UI, Roboto, sans-serif;
margin: 0; padding: 2rem 1rem; line-height: 1.5;
color: #1a1a1a; background: #f7f7f8;
}
.wrap { max-width: 1100px; margin: 0 auto; }
h1 { font-size: 1.5rem; margin: 0 0 .25rem; }
.meta { color: #666; font-size: .9rem; margin-bottom: 1.5rem; }
.count { font-weight: 600; }
table { width: 100%; border-collapse: collapse; background: #fff;
border-radius: .5rem; overflow: hidden; box-shadow: 0 1px 3px rgba(0,0,0,.08); }
th, td { text-align: left; padding: .65rem .9rem; border-bottom: 1px solid #eee;
font-size: .9rem; }
th { background: #fafafa; font-weight: 600; color: #444;
position: sticky; top: 0; }
tr:last-child td { border-bottom: none; }
tr:hover td { background: #f5f8ff; }
a { color: #2563eb; text-decoration: none; word-break: break-all; }
a:hover { text-decoration: underline; }
.num { color: #999; width: 3rem; text-align: right; font-variant-numeric: tabular-nums; }
.langs { color: #666; font-size: .8rem; }
@media (prefers-color-scheme: dark) {
body { color: #e5e5e5; background: #18181b; }
table { background: #232327; box-shadow: none; }
th { background: #27272a; color: #ccc; }
th, td { border-color: #333; }
tr:hover td { background: #1e293b; }
.meta, .num, .langs { color: #888; }
}
</style>
</head>
<body>
<div class="wrap">
<h1>Mapa witryny (Sitemap)</h1>
<p class="meta">
Ten plik jest odczytywany przez wyszukiwarki.
Adresów: <span class="count"><xsl:value-of select="count(s:urlset/s:url)"/></span>
</p>
<table>
<thead>
<tr>
<th class="num">#</th>
<th>Adres URL</th>
<th>Ostatnia zmiana</th>
<th>Języki</th>
</tr>
</thead>
<tbody>
<xsl:for-each select="s:urlset/s:url">
<tr>
<td class="num"><xsl:value-of select="position()"/></td>
<td>
<a href="{s:loc}"><xsl:value-of select="s:loc"/></a>
</td>
<td><xsl:value-of select="s:lastmod"/></td>
<td class="langs">
<xsl:for-each select="xhtml:link">
<xsl:value-of select="@hreflang"/>
<xsl:if test="position() != last()"><xsl:text>, </xsl:text></xsl:if>
</xsl:for-each>
</td>
</tr>
</xsl:for-each>
</tbody>
</table>
</div>
</body>
</html>
</xsl:template>
</xsl:stylesheet>
+5 -1
View File
@@ -79,12 +79,16 @@ export async function buildLlmsTxt({
const name = settings.siteName?.trim() || 'Website'
const description = settings.siteDescription?.trim()
// NO where:{_status} filter — collections without drafts enabled don't
// register the _status field, and querying it throws
// "path cannot be queried: _status" (a real bug report). Draft filtering
// happens in memory below, which is safe for every collection. Same as
// buildSitemapEntries and generateStaticParams.
const result = await payload.find({
collection: pagesSlug as never,
depth: 0,
limit: 1000,
locale: loc as never,
where: { _status: { not_equals: 'draft' } } as never,
})
const lines: string[] = [`# ${name}`, '']
+83
View File
@@ -0,0 +1,83 @@
import type { SitemapEntry } from './buildSitemapEntries.js'
/**
* Serializes sitemap entries to an XML STRING with an XSL stylesheet reference,
* so /sitemap.xml renders as a readable table in the browser (not raw XML) while
* staying a valid sitemap for crawlers.
*
* Why this exists alongside the Next MetadataRoute sitemap: Next's app/sitemap.ts
* (returning SitemapEntry[]) does NOT let you inject <?xml-stylesheet?>. To get
* the styled table, serve a custom route that returns this string instead:
*
* // app/sitemap.xml/route.ts
* import { buildSitemapXml } from '@intecion/ipal-kit'
* import { sitemap } from '@/lib/content' // your entries source
* export const dynamic = 'force-dynamic'
* export async function GET() {
* const entries = await sitemap()
* const xml = buildSitemapXml(entries, { stylesheetUrl: '/sitemap.xsl' })
* return new Response(xml, {
* headers: { 'Content-Type': 'application/xml; charset=utf-8' },
* })
* }
*
* Put sitemap.xsl in the project's /public (copy from the plugin's assets, or
* serve it from a route). The <?xml-stylesheet?> points browsers at it; crawlers
* ignore it and read the XML. Include hreflang alternates as <xhtml:link>.
*
* NOTE: if you use this custom route, DON'T also keep app/sitemap.ts — pick one
* (the styled route OR the Next MetadataRoute). Two sitemaps at different paths
* confuse crawlers.
*/
export function buildSitemapXml(
entries: SitemapEntry[],
opts: { stylesheetUrl?: string } = {},
): string {
const { stylesheetUrl } = opts
const esc = (s: string): string =>
s
.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&apos;')
const urls = entries
.map((e) => {
const parts = [` <loc>${esc(e.url)}</loc>`]
if (e.lastModified) {
const iso =
e.lastModified instanceof Date ? e.lastModified.toISOString() : String(e.lastModified)
parts.push(` <lastmod>${esc(iso)}</lastmod>`)
}
if (e.changeFrequency) parts.push(` <changefreq>${e.changeFrequency}</changefreq>`)
if (typeof e.priority === 'number') parts.push(` <priority>${e.priority}</priority>`)
// hreflang alternates
const alternates = e.alternates?.languages
if (alternates) {
for (const [lang, href] of Object.entries(alternates)) {
if (typeof href === 'string') {
parts.push(
` <xhtml:link rel="alternate" hreflang="${esc(lang)}" href="${esc(href)}"/>`,
)
}
}
}
return ` <url>\n${parts.join('\n')}\n </url>`
})
.join('\n')
const stylesheet = stylesheetUrl
? `<?xml-stylesheet type="text/xsl" href="${esc(stylesheetUrl)}"?>\n`
: ''
return (
`<?xml version="1.0" encoding="UTF-8"?>\n` +
stylesheet +
`<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" ` +
`xmlns:xhtml="http://www.w3.org/1999/xhtml">\n` +
urls +
`\n</urlset>`
)
}
+1
View File
@@ -14,6 +14,7 @@ export type { RobotsRules } from './buildRobots.js'
export { buildServiceJsonLd } from './buildServiceJsonLd.js'
export { buildSitemapEntries } from './buildSitemapEntries.js'
export type { SitemapEntry } from './buildSitemapEntries.js'
export { buildSitemapXml } from './buildSitemapXml.js'
export { buildSiteNavigationJsonLd } from './buildSiteNavigationJsonLd.js'
export { buildWebSiteJsonLd } from './buildWebSiteJsonLd.js'
export { composeTitle } from './composeTitle.js'
@@ -0,0 +1,78 @@
'use client'
import { createContext, useCallback, useContext, useState } from 'react'
import { Turnstile } from './Turnstile.js'
type TurnstileContextValue = {
/** Public site key from the provider (read server-side, passed once). */
siteKey: string | null
/** Current token (null until solved / after expiry). */
token: string | null
setToken: (t: string | null) => void
}
const TurnstileContext = createContext<TurnstileContextValue | null>(null)
/**
* Provides the Turnstile site key once for the whole app, like ConsentProvider
* for cookies. The project reads the key server-side and passes it here in the
* layout; forms then use <TurnstileWidget /> + useTurnstile() with NO per-form
* key wiring.
*
* // layout.tsx (server) → read key, pass to provider
* import { TurnstileProvider } from '@intecion/ipal-kit/client'
* const siteKey = await getTurnstileSiteKey() // your server helper
* <TurnstileProvider siteKey={siteKey}>{children}</TurnstileProvider>
*
* When siteKey is null (Turnstile not configured), widgets render nothing and
* token stays null — forms should treat "no Turnstile" as allowed in dev.
*/
export function TurnstileProvider({
siteKey,
children,
}: {
siteKey: string | null
children: React.ReactNode
}) {
const [token, setToken] = useState<string | null>(null)
return (
<TurnstileContext.Provider value={{ siteKey, token, setToken }}>
{children}
</TurnstileContext.Provider>
)
}
/**
* Hook giving a form the Turnstile token + a widget bound to the provider's key.
* No per-form siteKey plumbing — the provider supplies it.
*
* const { token, TurnstileWidget, reset } = useTurnstile()
* // in JSX: <TurnstileWidget />
* // at submit: submitForm({ ..., turnstileToken: token })
* // after submit: reset() // clear for the next submission
*/
export function useTurnstile(): {
token: string | null
TurnstileWidget: (props?: { theme?: 'light' | 'dark' | 'auto' }) => React.ReactNode
reset: () => void
/** True when Turnstile is configured (site key present). */
enabled: boolean
} {
const ctx = useContext(TurnstileContext)
if (!ctx) {
throw new Error('useTurnstile must be used within <TurnstileProvider>')
}
const { siteKey, token, setToken } = ctx
const reset = useCallback(() => setToken(null), [setToken])
const TurnstileWidget = useCallback(
(props?: { theme?: 'light' | 'dark' | 'auto' }) => {
if (!siteKey) return null
return <Turnstile siteKey={siteKey} onToken={setToken} theme={props?.theme} />
},
[siteKey, setToken],
)
return { token, TurnstileWidget, reset, enabled: Boolean(siteKey) }
}
+1
View File
@@ -3,3 +3,4 @@
// the server-only verify never leaks into a browser bundle.
export { Turnstile } from './Turnstile.js'
export type { TurnstileProps } from './Turnstile.js'
export { TurnstileProvider, useTurnstile } from './TurnstileProvider.js'
+1
View File
@@ -1,3 +1,4 @@
export { TurnstileProvider, useTurnstile } from './TurnstileProvider.js'
// Server-only exports. verify.ts imports 'server-only', so this must never be
// imported from a client component — use ./client for the widget instead.
export { verifyTurnstile } from './verify.js'