P0 blockers: - Fix migration numbering conflict and duplicate indexes - Change comments.post_id FK to ON DELETE CASCADE - Restrict public post detail endpoint to published posts only - Fix rate-limiting IP extraction and fallback to ConnectInfo - Harden HTML sanitizer: deny unknown URL schemes, restrict data URIs - Remove session token from login response body - Enforce image pixel/dimension limits on upload and serving P1 high-risk: - Validate uploads by magic bytes and decode GIF/WebP - Add pagination/rate-limiting to search, tag posts, and comments - Make first-admin registration and slug uniqueness check atomic - HTML-escape comment author fields - Improve HTML minify cache key and skip admin/error responses - Add mobile navigation menu P2 accessibility/quality: - Associate form labels with inputs - Key PostDetail article by slug to re-init scripts on navigation - Improve image viewer keyboard accessibility - Make theme toggle SSR-friendly and add aria-label - Invalidate slug 404 cache on create and pending count on new comment - Deduplicate tags case-insensitively P3 cleanup: - Remove unused tower-http dependency, expand make clean - Configure DB pool timeouts and verified recycling - Run background cleanup tasks immediately on startup - Use SHA-256 for stable disk cache keys - Log DB errors with Display instead of Debug - Update README migration instructions All tests pass (321), clippy clean, dx check clean.
41 lines
901 B
Markdown
41 lines
901 B
Markdown
# Yggdrasil
|
||
|
||
基于 Dioxus 0.7 的全栈博客系统,Rust 单一代码库同时编译为 WASM 前端和原生服务端。
|
||
|
||
## 技术栈
|
||
|
||
- **框架**: Dioxus 0.7 (fullstack)
|
||
- **数据库**: PostgreSQL + tokio-postgres
|
||
- **样式**: Tailwind CSS v4
|
||
- **密码**: Argon2
|
||
- **会话**: UUID token + cookie
|
||
|
||
## 功能
|
||
|
||
- 邮箱注册 / 登录(单管理员模式,首次注册后关闭)
|
||
- 会话管理与自动过期清理
|
||
- 暗色 / 亮色主题切换
|
||
- 后台文章撰写(Tiptap Markdown 编辑器)
|
||
- 文章归档与标签浏览
|
||
|
||
## 开发
|
||
|
||
依赖 Rust 1.95+、wasm32 目标、`dx` CLI、tailwindcss CLI v4 和 PostgreSQL。
|
||
|
||
```bash
|
||
# 配置数据库
|
||
DATABASE_URL=postgres://postgres:postgres@localhost:5432/yggdrasil
|
||
|
||
# 运行迁移(自动创建数据库并按顺序执行 migrations/ 下所有 SQL)
|
||
./migrate.sh
|
||
|
||
# 启动开发服务器
|
||
make dev
|
||
```
|
||
|
||
## 构建
|
||
|
||
```bash
|
||
make build
|
||
```
|