- TypeScript 63.7%
- Astro 21.6%
- JavaScript 10.7%
- SCSS 3.5%
- Dockerfile 0.5%
| Filnamn | Senaste incheckningsmeddelande | Senaste incheckningsdatum |
|---|---|---|
## What `public/.well-known/security.txt` named the pre-rename `gitborg.se` host. Now: - Contact: `mailto:info@bitborg.se` (same address as the contact and security pages) - Canonical: `https://www.bitborg.se/.well-known/security.txt` - Policy: `https://www.bitborg.se/contact` (the security page covers data processing, not disclosure; the contact page has the disclosure text) - Expires `2027-08-01` kept: in the future and under a year. - Preferred-Languages `sv, en` unchanged. Version 1.15.1 to 1.15.2. ## Test New `src/lib/security-txt.test.ts`: no `gitborg` string, required fields on bitborg.se, Expires in the future. It fails on the old file and will fail after 2027-08-01 until renewed. pnpm test: 492 passed, 3 skipped. pnpm check: 0 errors. pnpm lint: clean. ## Open questions None. Remaining `gitborg` strings in src/ are deliberate (reserved account names, comments and a test about the old mail domain). Reviewed-on: #281 |
||
| .forgejo/workflows | ||
| .vscode | ||
| docs | ||
| drizzle | ||
| public | ||
| scripts | ||
| src | ||
| .dockerignore | ||
| .env.example | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .prettierignore | ||
| .stylelintignore | ||
| astro.config.mjs | ||
| Containerfile | ||
| CONTRIBUTING.md | ||
| drizzle.config.ts | ||
| eslint.config.mjs | ||
| lefthook.json | ||
| package.json | ||
| playwright.config.ts | ||
| pnpm-lock.yaml | ||
| pnpm-workspace.yaml | ||
| postcss.config.cjs | ||
| README.md | ||
| renovate.json | ||
| stylelint.config.mjs | ||
| tsconfig.json | ||
| vitest.config.ts | ||
bitborg-web
The public web portal for bitborg (a Swedish, self-hosted Forgejo git service). Served at
https://www.bitborg.se; the Forgejo app itself lives at https://git.bitborg.se.
It provides:
- Marketing + legal pages — landing, Terms of Service, Privacy Policy. Swedish by
default, English auto-detected (
Accept-Language) with a visible switcher. - Open sign-up — creates a participant account (a way to take part in others' projects;
hosting comes with the paid account) by provisioning a person into Kanidm; the Forgejo
account is created on first OIDC login (Forgejo's own public registration stays disabled).
Gated by a self-hosted proof-of-work captcha and a
SIGNUPS_OPENkill switch (ADR 0029). - Transactional email — sign-up welcome, sent via Sweego's HTTP
API in the recipient's language. Every message is From
no-reply@email.bitborg.se(fixed insrc/lib/email.ts); content lives insrc/i18n/emails.ts. SetSWEEGO_API_KEYto enable; unset, the handlers degrade gracefully and send nothing.
Built with Astro (Node adapter, server output) + TypeScript + Drizzle (PostgreSQL).
Deployed as a container by bitborg-infra behind Caddy.
Why Astro (not SvelteKit/Next): content-first site with a few server actions, FOSS, and not tied to a single hosting vendor. See ADR 0010 and 0011 in bitborg-docs.
Develop
Local SSL is necessary for running the local development server.
We sugguest using mkcert for this.
cp .env.example .env # fill FORGEJO_*, DATABASE_URL
mkcert -install # Install CA trust
mkcert localhost # Generate certificate files
npm install
npm run dev # https://localhost:4321
Useful scripts: npm run check (astro/type check), npm run build (standalone server into
dist/), npm run db:generate / npm run db:migrate (Drizzle).
Testing
pnpm test runs the Vitest unit suite. pnpm test:e2e runs the Playwright end-to-end suite
(src/test/e2e/) against a built copy of the site on chromium, webkit and mobile-safari;
add E2E_FULL_MATRIX=true to also run firefox. pnpm test:e2e:ui opens Playwright's UI mode;
pnpm test:e2e:report opens the last HTML report.
Layout
| Path | Purpose |
|---|---|
src/pages/ |
sv pages at /, English under /en/; api/ server endpoints |
src/layouts/Base.astro, Legal.astro |
shared shell; Legal wraps Markdown pages |
src/i18n/ui.ts |
UI string dictionaries (sv/en) + useTranslations helper |
src/pages/{terms,privacy}.md, en/*.md |
long-form ToS/privacy copy (Markdown, per language) |
src/lib/forgejo.ts |
Forgejo admin API client (user provisioning) |
src/lib/email.ts, src/i18n/emails.ts |
Sweego email sender + localized email content (sv/en) |
scripts/migrate.mjs, drizzle/ |
runtime migrator + generated SQL migrations |
src/lib/db.ts, src/db/schema.ts |
Drizzle client + schema (sign-up consent audit) |
Configuration
All via environment (see .env.example): PUBLIC_SITE_URL, PUBLIC_GIT_APP_URL,
FORGEJO_BASE_URL, FORGEJO_ADMIN_TOKEN, DATABASE_URL, SWEEGO_API_KEY (email; blank
disables sending), BILLING_API_URL and BILLING_API_TOKEN (billing service; an unset URL hides the withdrawal section). Secrets are never committed; in production they come from podman secrets
via bitborg-infra.