Files
CodePress/AGENTS.md
T
E.Noorlander 6333bc410f CMS 2.0 - Theme engine, logging, admin improvements
Major changes:
- New ThemeManager with Twig templating and SCSS compilation
- Dynamic themes system (themes/default, themes/demo)
- LogManager with SQLite storage and syslog forwarding
- RequestLogger with static helper methods
- Admin UI overhaul (Bootstrap 5, dark mode)
- Admin config page with logging and theme settings
- Admin logs page with filters and search
- Removed legacy Mustache templates
- Removed test plugin and theme
- Composer dependencies: Twig, scssphp, CommonMark, MaxMind GeoIP
2026-08-08 18:02:14 +02:00

7.5 KiB

Agent Instructions for CodePress CMS

AI Model

  • Huidig model: claude-opus-4-6 (OpenCode / opencode/claude-opus-4-6)
  • Sessie gestart: 16 feb 2026

Build & Run

  • Run Server: php -S localhost:8080 cms/router.php (router nodig voor clean URLs)
  • Lint PHP: find . -name "*.php" -not -path "./vendor/*" -exec php -l {} \;
  • Dependencies: Composer vereist voor CommonMark, Twig en scssphp. Geen NPM.
  • Admin Console: Toegankelijk op /admin.php (standaard login: admin / admin)

Project Structuur

codepress/
├── cms/                            # Core CMS engine
│   ├── core/
│   │   ├── class/
│   │   │   ├── CodePressCMS.php    # Hoofd CMS class
│   │   │   ├── ThemeManager.php    # Thema-resolver + Twig render + SCSS compile
│   │   │   ├── Logger.php          # Logging systeem
│   │   │   └── SimpleTemplate.php  # Legacy Mustache-style engine (niet meer gebruikt)
│   │   ├── plugin/
│   │   │   ├── PluginManager.php   # Plugin loader
│   │   │   └── CMSAPI.php          # API voor plugins
│   │   ├── config.php              # Config loader (leest config.json)
│   │   └── index.php               # Bootstrap (autoloader, requires)
│   ├── lang/                       # Taalbestanden (nl.php, en.php)
│   └── router.php                  # PHP dev server router (serveert ook /themes/)
├── themes/                         # Dynamische thema's (volledig zelfstandig)
│   ├── default/                    # Standaard thema
│   │   ├── theme.json              # { title, default_layout, layout→.twig mapping, kleuren }
│   │   ├── base.twig               # Hoofd layout (head, header, nav, footer)
│   │   ├── full_content.twig       # Layout: volledige breedte
│   │   ├── left_sidebar.twig       # Layout: sidebar links
│   │   ├── right_sidebar.twig      # Layout: sidebar rechts
│   │   ├── custom1.twig             # Layout: custom
│   │   ├── partials/               # header.twig, navigation.twig, footer.twig
│   │   ├── css/theme.scss          # SCSS bron (runtime gecompileerd)
│   │   └── js/theme.js             # Thema JavaScript
│   ├── demo/                       # Demo thema (zelfde structuur, andere look)
│   └── test/                        # Test thema
├── admin/                          # Admin paneel
│   ├── config/
│   │   ├── app.php                # Admin app configuratie
│   │   └── admin.json             # Gebruikers & security (file-based)
│   ├── src/
│   │   └── AdminAuth.php          # Authenticatie (sessies, bcrypt, CSRF, lockout)
│   ├── templates/
│   │   ├── login.php              # Login pagina
│   │   ├── layout.php             # Admin layout met sidebar
│   │   └── pages/
│   │       ├── dashboard.php
│   │       ├── content.php
│   │       ├── content-edit.php
│   │       ├── content-new.php
│   │       ├── content-dir-form.php
│   │       ├── config.php
│   │       ├── plugins.php
│   │       ├── plugin-config.php
│   │       ├── theme.php
│   │       └── users.php
│   └── storage/logs/              # Admin logs
├── cli/                            # CLI scripts & tests
│   └── test/
│       ├── accessibility.sh        # WCAG 2.1 AA test suite
│       ├── enhanced-suite.sh       # Enhanced test suite
│       ├── functional/             # Functionele testen
│       └── pentest/                # Penetratietesten
├── plugins/                        # CMS plugins
│   ├── HTMLBlock/
│   └── MQTTTracker/
├── public/                         # Web root
│   ├── assets/css/js/
│   ├── index.php                  # Website entry point
│   └── admin.php                  # Admin entry point + router
├── content/                        # Content bestanden
├── guide/                          # Handleidingen (nl/en)
├── docs/                           # Documentatie
├── config.json                     # Site configuratie
└── AGENTS.md                       # Dit bestand

Code Style & Conventions

  • PHP Standards: Follow PSR-12. Use 4 spaces for indentation.
  • Naming: Classes PascalCase (e.g., CodePressCMS), methods camelCase (e.g., renderMenu), variables camelCase, config keys snake_case.
  • Architecture:
    • Core CMS logic in cms/core/class/CodePressCMS.php
    • Bootstrap/requires in cms/core/index.php
    • Configuration loaded from config.json via cms/core/config.php
    • Public website entry point: public/index.php
    • Admin entry point + routing: public/admin.php
    • Admin authenticatie: admin/src/AdminAuth.php
  • Content: Stored in content/. Supports .md (Markdown), .php (Dynamic), .html (Static).
  • Templating: Twig templates in themes/<naam>/. ThemeManager rendert via Twig en compileert css/theme.scss runtime naar public/themes/<naam>/theme.css. Layout gekozen via frontmatter layout: key; onbekende layouts vallen terug op default_layout in theme.json.
  • Navigation: Auto-generated from directory structure. Folders require an index file to be clickable in breadcrumbs.
  • Security:
    • Always use htmlspecialchars() for outputting user/content data
    • Use realpath() + prefix-check for path traversal prevention
    • Admin forms require CSRF tokens via AdminAuth::verifyCsrf()
    • Passwords stored as bcrypt hashes in admin.json
  • Git: main is the clean CMS core. development is de actieve development branch. e.noorlander bevat persoonlijke content. Niet mixen.

Admin Console

  • File-based: Geen database. Gebruikers opgeslagen in admin/config/admin.json
  • Routing: Via ?route= parameter in public/admin.php
  • Routes: login, logout, dashboard, content, content-edit, content-new, content-delete, config, plugins, plugins-new, plugins-edit, plugins-config, plugins-toggle, plugins-delete, users
  • Auth: Session-based. AdminAuth class handelt login, logout, CSRF, brute-force lockout af
  • Templates: Pure PHP templates in admin/templates/pages/. Layout in layout.php

Important: Title vs File/Directory Name Logic

  • CRITICAL: When user asks for "title" corrections, they usually mean FILE/DIRECTORY NAME WITHOUT LANGUAGE PREFIX AND EXTENSIONS, not the HTML title from content!
  • Examples:
    • nl.test.md → display as "Test" (not content title)
    • nl.test/ directory → display as "Test" (not H1 content)
    • en.php-testen → display as "Php Testen" (not "ICT")
  • Method: Use formatDisplayName() to process file/directory names correctly
  • Priority: Directory names take precedence over file names when both exist
  • Language prefixes: Dynamisch verwijderd op basis van beschikbare talen via getAvailableLanguages()

Bekende aandachtspunten

  • LSP errors over "Undefined function" in PHP files zijn vals-positief (standaard PHP functies worden niet herkend door de LSP). Negeer deze.
  • Zie TODO.md voor alle openstaande verbeteringen en nieuwe features.
  • vendor/ map bevat Composer dependencies (CommonMark, Twig, scssphp, Mustache). Niet handmatig wijzigen.
  • admin/config/admin.json bevat wachtwoord-hashes. Niet committen met echte productie-wachtwoorden.