Skip to content
HisarBlok
Menu
TR

HisarBlok · documentation

Modules

Blog, forum, forms, members: every large piece of HisarBlok is a module, switched on or off per site. Core's own modules use exactly the same interface as one you would write.

All docs

For version 0.13.1.

The modules in the box

ModuleWhat it doesOn by default
pagesPages written in Markdown or built from blocksyes
blocksThe standard block types pages are built fromyes
mediaImage library: re-encoding, metadata removal, resizing, WebPyes
redirectsKeeps old addresses alive; exports real 301 rulesyes
announcementsShort announcements on the home pageyes
blogDated posts, tags, a paged index, feedsno
menuEditing the site menu from the adminno
searchA static index searched in the browserno
formsContact and sign-up forms as blocksno
commentsComments under pages and posts, approved firstno
forumCategories, topics, replies; static pagesno
membersVisitor accounts with a verified emailno
downloadsProducts, releases, files, counted links, checksumsno

Switching on and off

Every module is switched on or off per site on the admin's Modules screen. A module that is off is not loaded, registers no hooks and serves nothing; the files it wrote to the site are removed. Its data stays: switching it back on picks up where it left off. The site root, a language's root, the uploaded media, the theme's files and another module's area are never removed along the way.

Roles: replacing a module

forum, members and downloads are roles. Only one module may hold a role on a site: switching on a module of your own that provides the same role switches off the one that held it. So two download managers never publish over each other, and a site can replace one of our modules with its own.

A module of your own

A module is a folder in modules/ with a module.json manifest:

modules/mything/
  module.json            manifest (required)
  src/module.php         loaded only while the module is on for the site
  migrations/001-x.sql   applied once each, in order
  migrations/001-x.mysql.sql   the same schema for MySQL/MariaDB
  themes/block-x.php     templates for the module's blocks; any theme can override them by name
  lang/tr.json           translations of the module's own strings

The manifest says which tables and paths the module touches, which files it produces, which modules it needs and which role it provides. hisarblok make:module <name> writes a working skeleton of all of it: the manifest, a panel screen with a form and a delete that asks first, one table in both SQL dialects, a hook, a Turkish table and its own test.

What a module can do:

  • add an admin screen and a menu group (every screen declares a capability; role names are never tested),
  • add a page block,
  • write pages and files (honouring the site's ownership rules),
  • take a form from visitors: only through go.php, behind the shared protections,
  • give visitors a counted link: through get.php,
  • take part in core's behaviour through hooks, and write to the audit log.

Rules that keep a site safe

  • Everything a visitor sends is untrusted: escape it with h(), turn text into HTML only with markdown(), and build links with the helper that refuses javascript: and data: addresses.
  • Admin forms carry a CSRF token and the handler checks it first.
  • Work only on the site being worked on, and check in the query that an id from the request belongs to it. An account may be limited to some sites.
  • A visitor endpoint has no session: use the rate limits, recognise a visitor by a salted digest rather than the address, and store totals rather than logs where you can.
  • Files written into a document root are served as they are: accept nothing a web server would execute.