summaryrefslogtreecommitdiff
path: root/cmd
diff options
context:
space:
mode:
authorLukasz Kasprzak <lukas@labunix.xyz>2026-07-23 14:39:31 +0200
committerLukasz Kasprzak <lukas@labunix.xyz>2026-07-23 14:39:31 +0200
commit4de7f7dca7485c9a6c94f6f86a53d01a974fce54 (patch)
treebcdc1ea366a068310e460804c4a5f04df3ae20f4 /cmd
parentb72b81c410c161797eb525a6231b0517b4def993 (diff)
downloadlectio-4de7f7dca7485c9a6c94f6f86a53d01a974fce54.tar.gz
lectio-4de7f7dca7485c9a6c94f6f86a53d01a974fce54.zip
web: HTMX server + lectio-web binary
NewServer wires B1's RenderReadings/Themes/themeCSS/embedded static+ templates FS into an http.ServeMux: GET / (full page), GET /readings (HTMX reading-pane fragment), GET /lookup (bible.Lookup passage search fragment), GET /theme.css (theme stylesheet, falling back through cfg.WebTheme to the built-in default on an unknown name), GET /static/. Run listens on cfg.WebPort (0 = OS-picked free port), prints the URL, best-effort opens a browser, then serves. cmd/lectio-web is the binary entry point (config.Load -> web.Run). Fold-in from the B1 review: hardened themeCSS's name guard to an explicit ^[A-Za-z0-9_-]+$ allowlist (the old filepath.Base/ContainsAny check let ".." through), plus guard-rejection and HTML-escaping regression tests -- B2 is what makes /theme.css?name=<raw> reachable from the network, so it owns closing this out.
Diffstat (limited to 'cmd')
-rw-r--r--cmd/lectio-web/main.go21
1 files changed, 21 insertions, 0 deletions
diff --git a/cmd/lectio-web/main.go b/cmd/lectio-web/main.go
new file mode 100644
index 0000000..44845b8
--- /dev/null
+++ b/cmd/lectio-web/main.go
@@ -0,0 +1,21 @@
+package main
+
+import (
+ "fmt"
+ "os"
+
+ "github.com/lukaszkasprzak/lectio/internal/config"
+ "github.com/lukaszkasprzak/lectio/internal/web"
+)
+
+func main() {
+ cfg, err := config.Load()
+ if err != nil {
+ fmt.Fprintln(os.Stderr, err)
+ os.Exit(1)
+ }
+ if err := web.Run(cfg); err != nil {
+ fmt.Fprintln(os.Stderr, err)
+ os.Exit(1)
+ }
+}