Ajustes del sitio, menús anidados editables y redirecciones gestionables sin bucles ni open redirect
Instalar
genpm add @core/siteQué obtienes
- Código en src/lib/site/, 10 archivos. (19,3 kB)
- Reglas de IA en src/lib/site/AGENTS.md, más archivos de reglas para tu IDE.
- Variables añadidas a .env.example: SITE_URL, SITE_REDIRECT_HOSTS.
- Resuelve @core/content, @core/contracts, @core/db por ti.
README
Este paquete no tiene README.
Esto es exactamente lo que lee tu IA cuando trabaja en src/lib/site. No se añade nada más a su contexto.
@core/site — rules for AI agents
Purpose
What every site has: settings (name, logo, contact, social profiles, legal page paths) as a @core/content singleton,
editable menus up to 3 levels as a content collection (slug = location: header, footer), and redirects managed
from the admin with loop detection, safe targets (site paths or https to allowed hosts) and hit counters.
No page content, no SEO tags (@core/seo reads these settings).
Map
index.ts— public API:getSiteSettings,getMenu,upsertRedirect(byfrom),updateRedirect(by id),resolveRedirect,redirectResponse,siteAdminResources.content.ts—siteSettings,menusand their schemas.redirects.ts— redirect logic.links.ts— link validation.adapters/hono.ts—redirectMiddleware.adapters/next.ts—redirectFor(req).
Integration
- Env:
SITE_URL(https://example.com), optionalSITE_REDIRECT_HOSTS(comma-separated external hosts allowed as redirect targets). Migrations as insrc/lib/db/AGENTS.md. - Import this module once at startup (it registers the
site_settingsandmenuscontent definitions). - Seed initial values with
seedEntry(@core/content): settings and theheader/footermenus, using the site's current ones. - Render:
const settings = await getSiteSettings({ locale }),const items = await getMenu('header', { locale }). - Redirects: Hono
app.use(redirectMiddleware); Next.jsmiddleware.tswithruntime: 'nodejs'callingredirectFor(req). - Add
...siteAdminResources()tosrc/genpm/admin.ts. - Verify: create a redirect
/old → /newand request/old(301 to/new).
Conventions
- Menu links are site paths,
https://,mailto:ortel:; open external links withrel="noopener". - Redirect sources are exact paths without query; the incoming query string is preserved.
- Permissions:
site_settings:*,menus:*,redirects:read|create|update|delete.
Don't
- Don't hardcode the site name, logo or menus in components once this module is installed.
- Don't build redirects from user input; only from the admin through
upsertRedirect/updateRedirect. Editing changes that row by id and fails withinvalid_path(422) if the newfrombelongs to another redirect. - Don't put legal text here; only the paths of the legal pages.
# @core/site — rules for AI agents
## Purpose
What every site has: settings (name, logo, contact, social profiles, legal page paths) as a @core/content singleton,
editable menus up to 3 levels as a content collection (slug = location: `header`, `footer`), and redirects managed
from the admin with loop detection, safe targets (site paths or https to allowed hosts) and hit counters.
No page content, no SEO tags (@core/seo reads these settings).
## Map
- `index.ts` — public API: `getSiteSettings`, `getMenu`, `upsertRedirect` (by `from`), `updateRedirect` (by id), `resolveRedirect`, `redirectResponse`, `siteAdminResources`.
- `content.ts` — `siteSettings`, `menus` and their schemas. `redirects.ts` — redirect logic. `links.ts` — link validation.
- `adapters/hono.ts` — `redirectMiddleware`. `adapters/next.ts` — `redirectFor(req)`.
## Integration
1. Env: `SITE_URL` (`https://example.com`), optional `SITE_REDIRECT_HOSTS` (comma-separated external hosts allowed as redirect targets). Migrations as in `src/lib/db/AGENTS.md`.
2. Import this module once at startup (it registers the `site_settings` and `menus` content definitions).
3. Seed initial values with `seedEntry` (@core/content): settings and the `header`/`footer` menus, using the site's current ones.
4. Render: `const settings = await getSiteSettings({ locale })`, `const items = await getMenu('header', { locale })`.
5. Redirects: Hono `app.use(redirectMiddleware)`; Next.js `middleware.ts` with `runtime: 'nodejs'` calling `redirectFor(req)`.
6. Add `...siteAdminResources()` to `src/genpm/admin.ts`.
7. Verify: create a redirect `/old → /new` and request `/old` (301 to `/new`).
## Conventions
- Menu links are site paths, `https://`, `mailto:` or `tel:`; open external links with `rel="noopener"`.
- Redirect sources are exact paths without query; the incoming query string is preserved.
- Permissions: `site_settings:*`, `menus:*`, `redirects:read|create|update|delete`.
## Don't
- Don't hardcode the site name, logo or menus in components once this module is installed.
- Don't build redirects from user input; only from the admin through `upsertRedirect` / `updateRedirect`. Editing changes that row by id and fails with `invalid_path` (422) if the new `from` belongs to another redirect.
- Don't put legal text here; only the paths of the legal pages.
El árbol exacto que se inyectará, tras aplicar .genpmignore. Anclado a
// Recursos de panel: ajustes y menús (vía @core/content) y redirecciones.
import { asc, count, eq, ilike, or } from 'drizzle-orm';
import { z } from 'zod';
import { contentAdminResource } from '../content/index.ts';
import type { AdminContext, AdminResource } from '../contracts/index.ts';
import { getDb } from '../db/index.ts';
import { SiteError } from './links.ts';
import { deleteRedirect, REDIRECT_STATUSES, updateRedirect, upsertRedirect } from './redirects.ts';
import { type Redirect, redirects } from './schema.ts';
const RedirectInput = z.object({
from: z.string(),
to: z.string(),
status: z.coerce.number().pipe(z.union(REDIRECT_STATUSES.map((s) => z.literal(s)) as [z.ZodLiteral<301>, z.ZodLiteral<302>, z.ZodLiteral<307>, z.ZodLiteral<308>])).optional(),
});
async function need(ctx: AdminContext, action: string) {
if (!(await ctx.can(`redirects:${action}`))) throw new SiteError('forbidden', `forbidden: redirects:${action}`);
}
export const redirectsAdminResource: AdminResource<Redirect> = {
name: 'redirects',
label: { singular: 'Redirect', plural: 'Redirects' },
group: 'Settings',
fields: [
{ name: 'fromPath', label: 'From', type: 'text', required: true, list: true },
{ name: 'to', label: 'To', type: 'text', required: true, list: true },
{ name: 'status', label: 'Status', type: 'select', list: true, options: REDIRECT_STATUSES.map((s) => ({ value: String(s), label: String(s) })) },
{ name: 'hits', label: 'Hits', type: 'number', readOnly: true, list: true },
],
input: RedirectInput,
title: (r) => `${r.fromPath} → ${r.to}`,
async list(q, ctx) {
await need(ctx, 'read');
const where = q.search ? or(ilike(redirects.fromPath, `%${q.search}%`), ilike(redirects.to, `%${q.search}%`)) : undefined;
const [total] = await getDb().select({ n: count() }).from(redirects).where(where);
const rows = await getDb().select().from(redirects).where(where).orderBy(asc(redirects.fromPath)).limit(q.pageSize).offset((Math.max(q.page, 1) - 1) * q.pageSize);
return { rows, total: total?.n ?? 0 };
},
async get(id, ctx) {
await need(ctx, 'read');
const [row] = await getDb().select().from(redirects).where(eq(redirects.id, id));
return row ?? null;
},
async create(input, ctx) {
await need(ctx, 'create');
return upsertRedirect(RedirectInput.parse(input));
},
async update(id, input, ctx) {
await need(ctx, 'update');
return updateRedirect(id, RedirectInput.parse(input));
},
async delete(id, ctx) {
await need(ctx, 'delete');
await deleteRedirect(id);
},
};
/** Los tres recursos de este paquete, para `src/genpm/admin.ts`. */
export const siteAdminResources = () => [contentAdminResource('site_settings'), contentAdminResource('menus'), redirectsAdminResource];
Este paquete no declara servidores MCP.
| Versión | Commit | Publicado | Escaneo |
|---|---|---|---|
| 1.1.0 | b7c13fa | hace 3 horas | escaneo superado |
- npm
- zod ^4.0.0
- propuesta
- GenPM propone el comando npm y solo lo ejecuta si dices que sí.
- Usado por (2)
- @core/kit-cms ^1.0.0@core/seo ^1.0.0
- escaneo
- escaneo superado · 0 hallazgos
- commit
- v1.1.0 → b7c13fa9b316c9880bceb62d510ee9661a76ae08 · verificado tras la descarga
- scripts
- Ninguno. GenPM nunca ejecuta código del paquete.
- licencia
- MIT
- Calidad
- 100/100
- Licencia reconocidacumplido
- AGENTS.md explica su propósitocumplido
- AGENTS.md tiene pasos de integracióncumplido
- AGENTS.md lista convenciones o prohibicionescumplido
- Incluye testscumplido
- Escaneo de seguridad superadocumplido
- Publicado en los últimos 6 mesescumplido
- Publicador verificadocumplido
- Resumen y palabras clavecumplido
- reporte
- ¿Ves algo raro?