aboutsummaryrefslogtreecommitdiff
path: root/http
diff options
context:
space:
mode:
Diffstat (limited to 'http')
-rw-r--r--http/public/do/bcrypt.php57
-rw-r--r--http/src/css/base.uppcss18
-rw-r--r--http/src/css/feed.uppcss3
3 files changed, 74 insertions, 4 deletions
diff --git a/http/public/do/bcrypt.php b/http/public/do/bcrypt.php
new file mode 100644
index 0000000..a61dd9e
--- /dev/null
+++ b/http/public/do/bcrypt.php
@@ -0,0 +1,57 @@
+<?php
+
+const BCRYPT_COST = 12;
+
+$user = $_SERVER['PHP_AUTH_USER'] ?? null;
+$pass = $_SERVER['PHP_AUTH_PW'] ?? null;
+
+// Fallback for CGI / FastCGI SAPIs that don't populate PHP_AUTH_*.
+// Apache: add "CGIPassAuth On" (2.4.13+) or a RewriteRule to expose
+// HTTP_AUTHORIZATION; nginx+php-fpm passes it through by default.
+if ($user === null || $pass === null) {
+ $header = $_SERVER['HTTP_AUTHORIZATION']
+ ?? $_SERVER['REDIRECT_HTTP_AUTHORIZATION']
+ ?? null;
+
+ if (is_string($header) && preg_match('/^Basic\s+(.+)$/i', $header, $m) === 1) {
+ $decoded = base64_decode($m[1], true);
+
+ // Split on the FIRST colon only: passwords may contain colons.
+ if ($decoded !== false && str_contains($decoded, ':')) {
+ [$user, $pass] = explode(':', $decoded, 2);
+ }
+ }
+}
+
+if (!is_string($user) || $user === '' || !is_string($pass) || $pass === '') {
+ header('WWW-Authenticate: Basic realm="Restricted", charset="UTF-8"');
+ http_response_code(401);
+ header('Content-Type: text/plain; charset=utf-8');
+ header('Cache-Control: no-store');
+ echo 'authentication required';
+ exit;
+}
+
+if (strlen($pass) > 72) {
+ http_response_code(422);
+ header('Content-Type: text/plain; charset=utf-8');
+ header('Cache-Control: no-store');
+ echo 'password exceeds the 72-byte bcrypt limit';
+ exit;
+}
+
+$hash = password_hash($pass, PASSWORD_BCRYPT, ['cost' => BCRYPT_COST]);
+
+if ($hash === false) {
+ http_response_code(500);
+ header('Content-Type: text/plain; charset=utf-8');
+ header('Cache-Control: no-store');
+ echo 'hashing failed';
+ exit;
+}
+
+header('Content-Type: text/plain; charset=utf-8');
+header('Cache-Control: no-store, no-cache, must-revalidate');
+header('Pragma: no-cache');
+
+echo $user . ':' . $hash;
diff --git a/http/src/css/base.uppcss b/http/src/css/base.uppcss
index e67e5c0..b7a0e83 100644
--- a/http/src/css/base.uppcss
+++ b/http/src/css/base.uppcss
@@ -73,9 +73,9 @@
--font-size-sm: 1rem;
--font-size-base: 1.125rem;
- --font-size-md: 1.5rem;
- --font-size-lg: 2rem;
- --font-size-xl: 3rem;
+ --font-size-md: 1.3rem;
+ --font-size-lg: 1.6rem;
+ --font-size-xl: 2rem;
--spacing-block-xs: 0.5rem;
--spacing-block-sm: 1.75rem;
@@ -89,6 +89,16 @@
--spacing-inline-xl: 6rem;
}
+@media (min-width: 60rem) {
+ :root {
+ --font-size-sm: 1rem;
+ --font-size-base: 1.25rem;
+ --font-size-md: 1.55rem;
+ --font-size-lg: 1.9rem;
+ --font-size-xl: 2.3rem;
+ }
+}
+
/** Light theme */
@media (prefers-color-scheme: light) {
:root {
@@ -204,7 +214,7 @@ img {
[margin-end grid-end];
--grid-total-width: 80rem;
- --grid-max-content-width: 40rem;
+ --grid-max-content-width: 50rem;
}
}
diff --git a/http/src/css/feed.uppcss b/http/src/css/feed.uppcss
index 81ec8a9..5db8431 100644
--- a/http/src/css/feed.uppcss
+++ b/http/src/css/feed.uppcss
@@ -30,6 +30,9 @@ ul:has(> .h-entry) {
&::marker {
font-size: 1rem;
}
+ :is(h2, h3, h4, h5, h6) {
+ display: inline;
+ }
}
}