Files
CodePress/README.md
T
root c2cf08955b v2.6.1 (Lyra): Welcome page, 404 handling, installatie docs, opschoning
Nieuwe features:
- Welkomstpagina bij lege content-map (nieuwe installatie detectie)
- 404-afhandeling binnen actieve theme via admin/static/404.html
- HTTP 404 status bij onbekende pagina's en missende taalprefix

Opschoning:
- Verwijderd: package.json, src/scss/, root .htaccess, themes/demo/
- Verwijderde vendor packages: php-mqtt/client, mustache/mustache
- AGENTS.md samengevoegd naar root, development/AGENTS.md verwijderd
- .gitignore opgeschoond (NPM/node_modules/.sass-cache verwijderd)

Documentatie:
- Installatie instructies toegevoegd aan README (Apache2/Nginx/PHP/composer)
- README en guide versie referenties bijgewerkt naar 2.6.1
- Release notes: docs/release-notes/v2.6.1.md

Tests:
- Pentest: 30/30 geslaagd, 0 vulnerabilities
- WCAG 2.1 AA: 25/25 geslaagd, 100% compliance
- Test scripts gebruiken Apache-URL i.p.v. localhost:8080
2026-08-17 14:48:46 +00:00

11 KiB

CodePress CMS

🇳🇱 Nederlands | 🇬🇧 English

Een lichtgewicht, file-based content management systeem gebouwd met PHP (≥8.0).

Versie: 2.6.1 | Licentie: AGPL v3 / Commercial

Features

  • 📝 Multi-format Content - Markdown, PHP en HTML bestanden
  • 🧭 Dynamic Navigation - Automatische menu generatie
  • 🌍 Multi-language - NL/EN/DE ondersteuning
  • 🔍 Search - Volledige tekst zoekfunctie
  • 📱 Responsive - Bootstrap 5 thema's
  • 🔒 Security - 100/100 pentest score
  • 🛡️ Admin Console - CodeMirror editor, media beheer, thema's, plugins
  • 👥 Gebruikersrollen - Admin, Content Beheerder, BI Beheerder, Site Admin
  • 📊 Analytics - Bezoekersstatistieken met GeoIP
  • 🤖 BotGuard - Bot/AI bescherming
  • 📈 Logging - Uitgebreid logging systeem
  • 🔌 Plugin Systeem - Sidebar plugins met eigen CSS/SCSS, Twig templates

🚀 Quick Start

# Installeer dependencies
composer install

# Start server met router voor schone URLs (alleen lokaal)
php -S localhost:8080 cms/router.php

Website: http://localhost:8080
Admin: http://localhost:8080/admin (login: admin / admin)

📦 Installatie

Vereisten

  • PHP ≥ 8.0 met extensies: json, mbstring
  • Composer (PHP dependency manager)
  • Webserver: Apache 2.4+ met mod_rewrite of Nginx met PHP-FPM
  • Optioneel: opcache (aanbevolen voor performance), git (voor content versioning), zip extensie (voor ZIP backup/restore)

Stap 1 — Code en dependencies

git clone <repository-url> codepress
cd codepress
composer install

Stap 2 — Configuratie

cp config.json.example config.json
cp admin/config/admin.json.example admin/config/admin.json

Pas config.json aan met je site titel, taal en plugins. Wijzig het admin wachtwoord in admin/config/admin.json (standaard admin/admin).

Stap 3a — Apache 2.4+

De webroot is de public/ map. Voorbeeld vhost (/etc/apache2/sites-available/codepress.conf):

<VirtualHost *:80>
    ServerName example.com
    DocumentRoot /var/www/codepress/public

    <Directory /var/www/codepress/public>
        AllowOverride All
        Require all granted
    </Directory>

    ErrorLog ${APACHE_LOG_DIR}/codepress_error.log
    CustomLog ${APACHE_LOG_DIR}/codepress_access.log combined
</VirtualHost>

Benodigde Apache modules:

sudo a2enmod rewrite headers
sudo systemctl restart apache2
  • mod_rewrite — voor clean URLs (/nl/pagina) en asset-serving
  • mod_headers — voor security headers
  • AllowOverride All — zodat .htaccess in public/ wordt toegepast

Stap 3b — Nginx

Voorbeeld server block (/etc/nginx/sites-available/codepress):

server {
    listen 80;
    server_name example.com;
    root /var/www/codepress/public;
    index index.php;

    # Clean URLs: taal-prefixed pagina's
    location ~ ^/(nl|en|de)(/(.+))?$ {
        try_files $uri /index.php?lang=$1&page=$2;
    }

    # Admin routes
    location /admin {
        try_files $uri /admin.php?$args;
    }

    # Asset-serving via asset.php (themes/plugins/admin buiten webroot)
    location ~ ^/(themes|plugins)/([^/]+)/assets/(.+)$ {
        try_files $uri /asset.php;
    }
    location ~ ^/admin/assets/(.+)$ {
        try_files $uri /asset.php;
    }

    # PHP via FPM
    location ~ \.php$ {
        fastcgi_pass unix:/run/php/php8.0-fpm.sock;
        fastcgi_index index.php;
        fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;
        include fastcgi_params;
    }

    # Beveiliging: blokkeer toegang tot gevoelige mappen
    location ~ ^/(content|cms|admin/src|admin/config|admin/storage|var|vendor)/ {
        deny all;
        return 403;
    }

    location ~ /\.(git|htaccess) {
        deny all;
    }
}

Let op: Nginx gebruikt geen .htaccess. De security headers moeten in de Nginx config worden gezet:

add_header X-Content-Type-Options nosniff;
add_header X-Frame-Options SAMEORIGIN;
add_header X-XSS-Protection "1; mode=block";
add_header Referrer-Policy strict-origin-when-cross-origin;
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; font-src 'self';";

Stap 4 — Mappen rechten

Zorg dat de webserver schrijfrechten heeft op de runtime mappen:

chown -R www-data:www-data var/ admin/storage/ content/
chmod -R 755 .

Stap 5 — Test

Open de website in je browser. Bij een lege content-map zie je een welkomstpagina. De admin console is bereikbaar via /admin (login admin/admin).

📚 Handleidingen

Zie guide/ voor uitgebreide documentatie per rol:

Rol Handleiding
📝 Redacteur Content Beheerder
⚙️ Administrator Admin Beheerder
🎨 Theme bouwer Theme Developer
💻 Developer CodePress Developer

Elke handleiding heeft sub-onderdelen in aparte mappen met een zijbalknavigatie.

👥 Gebruikersrollen

Rol Permissies
Admin Volledige toegang (alles)
Content Beheerder Content beheer, handleiding
BI Beheerder Statistieken, logs, handleiding
Site Admin Thema, plugins, statistieken, logs, update, handleiding

📁 Project Structuur

codepress/
├── cms/                        # Core CMS engine
│   ├── core/class/             # CMS classes (CodePressCMS, ThemeManager, etc.)
│   ├── core/plugin/            # Plugin systeem (PluginManager, CMSAPI)
│   └── router.php              # PHP dev server router (schone URLs)
├── language/                   # Taalbestanden (nl/, en/, de/ — elk met site.php + admin.php)
├── admin/                      # Admin console
│   ├── config/                 # Admin configuratie (admin.json)
│   ├── src/AdminAuth.php       # Authenticatie, rollen, permissies
│   ├── static/                 # Statische bestanden (404.html)
│   ├── storage/                # Logs, cache, geoip
│   └── theme/default/          # Admin thema
│       ├── assets/             # CSS, JS, fonts, codemirror
│       ├── views/              # Twig templates (layouts, pages)
│       └── theme.json          # Admin thema configuratie
├── themes/                     # Website thema's
│   ├── default/                # Standaard thema
│   │   ├── theme.json           # Layout mapping, kleuren
│   │   ├── base.twig           # Hoofd layout
│   │   ├── *.twig              # Layout templates
│   │   ├── partials/            # Header, navigation, footer
│   │   └── assets/             # SCSS, CSS, JS, img
├── plugins/                    # Plugins
│   ├── HTMLBlock/               # Voorbeeld sidebar plugin
│   └── Navigation/             # Essentiële navigatie plugin (beschermd)
│       ├── Navigation.php       # Plugin code
│       ├── plugin.json          # Plugin metadata
│       ├── assets/scss/         # Plugin SCSS bron
│       └── assets/css/          # Plugin CSS
├── content/                    # Website content (.md, .php, .html)
├── public/                     # Web root
│   ├── index.php               # Website entry point
│   └── admin.php               # Admin entry point + routing
├── guide/                      # Handleidingen (nl/en)
│   ├── nl/                     # Nederlandse handleidingen
│   └── en/                     # Engelse handleidingen
├── cli/test/                   # Test suites
├── var/                        # Cache (twig)
├── config.json                 # Site configuratie
├── composer.json               # PHP dependencies
└── version.php                 # Versie informatie

⚙️ Configuratie

config.json

{
    "site_title": "CodePress",
    "active_theme": "default",
    "default_page": "auto",
    "language": {
        "default": "nl",
        "available": ["nl", "en"]
    },
    "enabled_plugins": ["HTMLBlock", "Navigation"],
    "features": {
        "search_enabled": true,
        "breadcrumbs_enabled": true
    },
    "security": {
        "block_ai_bots": true,
        "rate_limit_enabled": true
    },
    "analytics": { "enabled": true },
    "logging": { "enabled": true }
}

🔧 Dependencies

  • PHP ≥8.0 met extensies: json, mbstring
  • Composer packages:
    • twig/twig (templating)
    • scssphp/scssphp (SCSS compilatie)
    • league/commonmark (Markdown met HeadingPermalinks)
    • maxmind-db/reader (GeoIP)

🔐 Security

  • XSS preventie (htmlspecialchars)
  • CSRF tokens (admin formulieren)
  • Path traversal preventie (realpath checks)
  • Secure cookies (HttpOnly, SameSite)
  • Security headers (X-Frame-Options, CSP)
  • Bot/AI bescherming (BotGuard)
  • Rate limiting per IP
  • Role-based access control (RBAC)

🔌 Plugins

Plugin structuur

plugins/MijnPlugin/
├── MijnPlugin.php          # Plugin code (naam = pluginnaam)
├── plugin.json             # Plugin metadata
├── assets/scss/            # Plugin SCSS bron
└── assets/css/             # Plugin CSS (na compilatie)

Essentiële plugins

De Navigation plugin is een essentiële plugin en kan niet worden gedeactiveerd, bewerkt of verwijderd. Deze plugin genereert automatisch de zijbalknavigatie voor handleidingen en content.

Plugin CSS

Plugin CSS wordt automatisch geladen na thema CSS, zodat thema's plugin styling kunnen overschrijven.

📝 Content Voorbeelden

Markdown met frontmatter

---
layout: full_content
plugins: HTMLBlock, Navigation
---

# Pagina titel

Content in Markdown formaat...

PHP content

<?php
/** @var ContentAPI $api */
$pages = $api->getAllPages();
echo "<h1>Mijn Pagina</h1>";
echo "<p>Aantal pagina's: " . count($pages) . "</p>";

🧪 Testen

# Penetration tests
cli/test/pentest/security-test.sh

# Accessibility tests (WCAG 2.1 AA)
cli/test/accessibility.sh

# Functionele tests
cli/test/functional/*.sh

📞 Ondersteuning

📄 Licentie

Dual-licensed:

  • AGPL v3 - Voor open-source projecten
  • Commercial - Voor propriëtair gebruik

Zie LICENSE voor details.


CodePress CMS - Gebouwd door E.Noorlander / CodePress Development Team