trellis_shelf 0.11.1
trellis_shelf: ^0.11.1 copied to clipboard
Shelf integration for the Trellis template engine — middleware, HTMX helpers, and security defaults.
Changelog #
0.11.1 #
Added #
htmxSource()returns the id of the element that triggered the request on both HTMX 2 (HX-Triggerrequest header, bare id) and HTMX 4 (HX-Source,tag#id).
Changed #
htmxTarget()also returns the target element's id under HTMX 4, extracting it from thetag#idvalue HTMX 4 sends inHX-Target. Unchanged under HTMX 2.
Deprecated #
htmxTrigger()– usehtmxSource(). HTMX 4 reservesHX-Triggerfor responses. The old name keeps working and readsHX-Sourceas well.
Fixed #
- README install snippet pinned
trellis_shelf: ^0.1.0(andtrellis: ^0.8.0); no published version of the package matches^0.1.0, so a copied snippet faileddart pub get. Both now track the lockstep version andtool/version_lockstep.shkeeps them current.
0.11.0 #
Changed #
- Lockstep version bump to keep all Trellis SDK packages on a single shared version. No functional changes in this package.
0.10.2 #
Changed #
- Lockstep version bump to keep all Trellis SDK packages on a single shared version. No functional changes in this package.
0.10.1 #
Changed #
- Lockstep version bump to keep all Trellis SDK packages on a single shared version. No functional changes in this package.
0.10.0 #
Changed #
- Lockstep version bump to keep all Trellis SDK packages on a single shared version. No functional changes in this package.
0.9.1 #
Changed #
- Lockstep version bump to keep all Trellis SDK packages on a single shared version. No functional changes in this package.
0.9.0 #
Changed #
- Lockstep version bump to keep all Trellis SDK packages on a single shared version. No functional changes in this package.
0.8.2 #
Changed #
- Lockstep version bump to keep all Trellis SDK packages on a single shared version. No functional changes in this package.
0.8.1 #
Changed #
- Lockstep version bump to keep all Trellis SDK packages on a single shared version. No functional changes in this package.
0.8.0 #
Changed #
- Version aligned to the unified Trellis SDK lockstep versioning scheme — all SDK packages now share a single version number and are released together. No functional changes since 0.1.0.
0.1.0 #
Added #
trellisEngine()middleware for injecting aTrellisengine into the Shelf request context.getEngine()for retrieving the engine from request context inside handlers and utilities.renderPage(),renderFragment(), andrenderOobFragments()response helpers that merge request-scoped values likecsrfToken.- HTMX request helpers:
isHtmxRequest(),htmxTarget(),htmxTrigger(), andisHtmxBoosted(). htmlResponse()fortext/html; charset=utf-8responses.
Security #
trellisSecurityHeaders()middleware with configurableX-Content-Type-Options,X-Frame-Options,Referrer-Policy,X-XSS-Protection, andContent-Security-Policy.CspBuilderfor composing Content-Security-Policy directives with sensible defaults.trellisCsrf()middleware implementing HMAC-SHA256 double-submit cookie CSRF protection.csrfToken()for reading the current request token in handlers or templates.