v2.6.1 (Lyra): Welcome page, 404 handling, installatie docs, opschoning

Nieuwe features:
- Welkomstpagina bij lege content-map (nieuwe installatie detectie)
- 404-afhandeling binnen actieve theme via admin/static/404.html
- HTTP 404 status bij onbekende pagina's en missende taalprefix

Opschoning:
- Verwijderd: package.json, src/scss/, root .htaccess, themes/demo/
- Verwijderde vendor packages: php-mqtt/client, mustache/mustache
- AGENTS.md samengevoegd naar root, development/AGENTS.md verwijderd
- .gitignore opgeschoond (NPM/node_modules/.sass-cache verwijderd)

Documentatie:
- Installatie instructies toegevoegd aan README (Apache2/Nginx/PHP/composer)
- README en guide versie referenties bijgewerkt naar 2.6.1
- Release notes: docs/release-notes/v2.6.1.md

Tests:
- Pentest: 30/30 geslaagd, 0 vulnerabilities
- WCAG 2.1 AA: 25/25 geslaagd, 100% compliance
- Test scripts gebruiken Apache-URL i.p.v. localhost:8080
This commit is contained in:
root
2026-08-17 14:48:46 +00:00
parent e0e6e28dcc
commit 2d9ffaa942
53 changed files with 576 additions and 3964 deletions
+132 -4
View File
@@ -4,13 +4,13 @@
A lightweight, file-based content management system built with PHP (≥8.0).
**Version:** 2.5.1 | **License:** AGPL v3 / Commercial
**Version:** 2.6.1 | **License:** AGPL v3 / Commercial
## ✨ Features
- 📝 **Multi-format Content** - Markdown, PHP and HTML files
- 🧭 **Dynamic Navigation** - Automatic menu generation
- 🌍 **Multi-language** - NL/EN/DE/FR support
- 🌍 **Multi-language** - NL/EN/DE support
- 🔍 **Search** - Full-text search
- 📱 **Responsive** - Bootstrap 5 themes
- 🔒 **Security** - 100/100 pentest score
@@ -27,13 +27,141 @@ A lightweight, file-based content management system built with PHP (≥8.0).
# Install dependencies
composer install
# Start server with router for clean URLs
# Start server with router for clean URLs (local only)
php -S localhost:8080 cms/router.php
```
**Website:** `http://localhost:8080`
**Admin:** `http://localhost:8080/admin` (login: `admin` / `admin`)
## 📦 Installation
### Requirements
- **PHP** ≥ 8.0 with extensions: `json`, `mbstring`
- **Composer** (PHP dependency manager)
- Web server: **Apache 2.4+** with `mod_rewrite` or **Nginx** with PHP-FPM
- Optional: `opcache` (recommended for performance), `git` (for content versioning), `zip` extension (for ZIP backup/restore)
### Step 1 — Code and dependencies
```bash
git clone <repository-url> codepress
cd codepress
composer install
```
### Step 2 — Configuration
```bash
cp config.json.example config.json
cp admin/config/admin.json.example admin/config/admin.json
```
Edit `config.json` with your site title, language and plugins. Change the admin password in `admin/config/admin.json` (default `admin`/`admin`).
### Step 3a — Apache 2.4+
The webroot is the `public/` directory. Example vhost (`/etc/apache2/sites-available/codepress.conf`):
```apache
<VirtualHost *:80>
ServerName example.com
DocumentRoot /var/www/codepress/public
<Directory /var/www/codepress/public>
AllowOverride All
Require all granted
</Directory>
ErrorLog ${APACHE_LOG_DIR}/codepress_error.log
CustomLog ${APACHE_LOG_DIR}/codepress_access.log combined
</VirtualHost>
```
Required Apache modules:
```bash
sudo a2enmod rewrite headers
sudo systemctl restart apache2
```
- `mod_rewrite` — for clean URLs (`/nl/page`) and asset-serving
- `mod_headers` — for security headers
- `AllowOverride All` — so the `.htaccess` in `public/` is applied
### Step 3b — Nginx
Example server block (`/etc/nginx/sites-available/codepress`):
```nginx
server {
listen 80;
server_name example.com;
root /var/www/codepress/public;
index index.php;
# Clean URLs: language-prefixed pages
location ~ ^/(nl|en|de)(/(.+))?$ {
try_files $uri /index.php?lang=$1&page=$2;
}
# Admin routes
location /admin {
try_files $uri /admin.php?$args;
}
# Asset-serving via asset.php (themes/plugins/admin outside webroot)
location ~ ^/(themes|plugins)/([^/]+)/assets/(.+)$ {
try_files $uri /asset.php;
}
location ~ ^/admin/assets/(.+)$ {
try_files $uri /asset.php;
}
# PHP via FPM
location ~ \.php$ {
fastcgi_pass unix:/run/php/php8.0-fpm.sock;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
include fastcgi_params;
}
# Security: block access to sensitive directories
location ~ ^/(content|cms|admin/src|admin/config|admin/storage|var|vendor)/ {
deny all;
return 403;
}
location ~ /\.(git|htaccess) {
deny all;
}
}
```
**Note:** Nginx does not use `.htaccess`. Security headers must be set in the Nginx config:
```nginx
add_header X-Content-Type-Options nosniff;
add_header X-Frame-Options SAMEORIGIN;
add_header X-XSS-Protection "1; mode=block";
add_header Referrer-Policy strict-origin-when-cross-origin;
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self';";
```
### Step 4 — Directory permissions
Make sure the web server has write access to the runtime directories:
```bash
chown -R www-data:www-data var/ admin/storage/ content/
chmod -R 755 .
```
### Step 5 — Test
Open the website in your browser. With an empty content directory you'll see a welcome page. The admin console is available at `/admin` (login `admin`/`admin`).
## 📚 Documentation
See **[guide/](guide/)** for extensive documentation per role:
@@ -68,6 +196,7 @@ codepress/
├── admin/ # Admin console
│ ├── config/ # Admin configuration (admin.json)
│ ├── src/AdminAuth.php # Authentication, roles, permissions
│ ├── static/ # Static files (404.html)
│ ├── storage/ # Logs, cache, geoip
│ └── theme/default/ # Admin theme
│ ├── assets/ # CSS, JS, fonts, codemirror
@@ -80,7 +209,6 @@ codepress/
│ │ ├── *.twig # Layout templates
│ │ ├── partials/ # Header, navigation, footer
│ │ └── assets/ # SCSS, CSS, JS, img
│ └── demo/ # Demo theme
├── plugins/ # Plugins
│ ├── HTMLBlock/ # Example sidebar plugin
│ └── Navigation/ # Essential navigation plugin (protected)