Publik webbsajt för Bitborg. https://www.bitborg.se/
  • TypeScript 63.7%
  • Astro 21.6%
  • JavaScript 10.7%
  • SCSS 3.5%
  • Dockerfile 0.5%
Hitta en fil
Kodförråd filer (senaste incheckning först)
Filnamn Senaste incheckningsmeddelande Senaste incheckningsdatum
Johannes Axner 20bc36205b
Alla kontroller lyckades
ci / ci (push) Successful in 1m52s
deploy / build-and-push (push) Successful in 2m14s
fix: point security.txt at bitborg.se (#281)
## What

`public/.well-known/security.txt` named the pre-rename `gitborg.se` host. Now:

- Contact: `mailto:info@bitborg.se` (same address as the contact and security pages)
- Canonical: `https://www.bitborg.se/.well-known/security.txt`
- Policy: `https://www.bitborg.se/contact` (the security page covers data processing, not disclosure; the contact page has the disclosure text)
- Expires `2027-08-01` kept: in the future and under a year.
- Preferred-Languages `sv, en` unchanged.

Version 1.15.1 to 1.15.2.

## Test

New `src/lib/security-txt.test.ts`: no `gitborg` string, required fields on bitborg.se, Expires in the future. It fails on the old file and will fail after 2027-08-01 until renewed.

pnpm test: 492 passed, 3 skipped. pnpm check: 0 errors. pnpm lint: clean.

## Open questions

None. Remaining `gitborg` strings in src/ are deliberate (reserved account names, comments and a test about the old mail domain).

Reviewed-on: #281
2026-10-03 00:15:39 +00:00
.forgejo/workflows ci: run the database tests against postgres (#277) 2026-10-02 20:50:45 +00:00
.vscode fix(renovate): disable major updates (#67) 2026-07-19 12:35:07 +00:00
docs docs: absorb sign-up, navigation and claims knowledge from planning docs (#278) 2026-10-02 22:17:45 +00:00
drizzle feat(account): withdrawal function and start-at-once consent (#273) 2026-09-30 21:08:23 +00:00
public fix: point security.txt at bitborg.se (#281) 2026-10-03 00:15:39 +00:00
scripts ci: run the database tests against postgres (#277) 2026-10-02 20:50:45 +00:00
src fix: point security.txt at bitborg.se (#281) 2026-10-03 00:15:39 +00:00
.dockerignore chore: initial commit 2026-06-14 20:50:39 +02:00
.env.example feat(account): withdrawal function and start-at-once consent (#273) 2026-09-30 21:08:23 +00:00
.gitignore chore(test): replace nightwatch with playwright as the end-to-end framework (#244) 2026-09-21 10:08:09 +00:00
.markdownlint-cli2.jsonc style: adjust & apply linting (#46) 2026-07-17 07:23:55 +00:00
.prettierignore chore(test): replace nightwatch with playwright as the end-to-end framework (#244) 2026-09-21 10:08:09 +00:00
.stylelintignore chore(test): replace nightwatch with playwright as the end-to-end framework (#244) 2026-09-21 10:08:09 +00:00
astro.config.mjs chore(deps): update astro to 7.2.1 and drop the unused session runtime (#217) 2026-08-13 07:19:02 +00:00
Containerfile chore(deps): update toolchain (#233) 2026-09-18 23:23:11 +00:00
CONTRIBUTING.md docs: absorb sign-up, navigation and claims knowledge from planning docs (#278) 2026-10-02 22:17:45 +00:00
drizzle.config.ts chore: initial commit 2026-06-14 20:50:39 +02:00
eslint.config.mjs chore(test): replace nightwatch with playwright as the end-to-end framework (#244) 2026-09-21 10:08:09 +00:00
lefthook.json chore(test): replace nightwatch with playwright as the end-to-end framework (#244) 2026-09-21 10:08:09 +00:00
package.json fix: point security.txt at bitborg.se (#281) 2026-10-03 00:15:39 +00:00
playwright.config.ts chore(test): replace nightwatch with playwright as the end-to-end framework (#244) 2026-09-21 10:08:09 +00:00
pnpm-lock.yaml fix(deps): update dependency cap-widget to v0.1.58 (#265) 2026-09-29 10:28:20 +00:00
pnpm-workspace.yaml chore(deps): update dependency serialize-javascript@<=7.0.2 to v7.1.2 (#253) 2026-09-24 07:33:03 +00:00
postcss.config.cjs refactor: improve performance and security 2026-06-15 21:52:55 +02:00
README.md feat(account): withdrawal function and start-at-once consent (#273) 2026-09-30 21:08:23 +00:00
renovate.json docs(renovate): record why the portal does not automerge dependency prs (#206) 2026-08-09 19:57:44 +00:00
stylelint.config.mjs chore: initial commit 2026-06-14 20:50:39 +02:00
tsconfig.json perf: overhaul performance & a11y (#13) 2026-06-26 19:32:20 +00:00
vitest.config.ts feat(gdpr): purge expired email-change requests and invite codes (#275) 2026-10-02 09:52:51 +00:00

bitborg-web

The public web portal for bitborg (a Swedish, self-hosted Forgejo git service). Served at https://www.bitborg.se; the Forgejo app itself lives at https://git.bitborg.se.

It provides:

  • Marketing + legal pages — landing, Terms of Service, Privacy Policy. Swedish by default, English auto-detected (Accept-Language) with a visible switcher.
  • Open sign-up — creates a participant account (a way to take part in others' projects; hosting comes with the paid account) by provisioning a person into Kanidm; the Forgejo account is created on first OIDC login (Forgejo's own public registration stays disabled). Gated by a self-hosted proof-of-work captcha and a SIGNUPS_OPEN kill switch (ADR 0029).
  • Transactional email — sign-up welcome, sent via Sweego's HTTP API in the recipient's language. Every message is From no-reply@email.bitborg.se (fixed in src/lib/email.ts); content lives in src/i18n/emails.ts. Set SWEEGO_API_KEY to enable; unset, the handlers degrade gracefully and send nothing.

Built with Astro (Node adapter, server output) + TypeScript + Drizzle (PostgreSQL). Deployed as a container by bitborg-infra behind Caddy.

Why Astro (not SvelteKit/Next): content-first site with a few server actions, FOSS, and not tied to a single hosting vendor. See ADR 0010 and 0011 in bitborg-docs.

Develop

Local SSL is necessary for running the local development server.

We sugguest using mkcert for this.

cp .env.example .env        # fill FORGEJO_*, DATABASE_URL
mkcert -install             # Install CA trust
mkcert localhost            # Generate certificate files
npm install
npm run dev                 # https://localhost:4321

Useful scripts: npm run check (astro/type check), npm run build (standalone server into dist/), npm run db:generate / npm run db:migrate (Drizzle).

Testing

pnpm test runs the Vitest unit suite. pnpm test:e2e runs the Playwright end-to-end suite (src/test/e2e/) against a built copy of the site on chromium, webkit and mobile-safari; add E2E_FULL_MATRIX=true to also run firefox. pnpm test:e2e:ui opens Playwright's UI mode; pnpm test:e2e:report opens the last HTML report.

Layout

Path Purpose
src/pages/ sv pages at /, English under /en/; api/ server endpoints
src/layouts/Base.astro, Legal.astro shared shell; Legal wraps Markdown pages
src/i18n/ui.ts UI string dictionaries (sv/en) + useTranslations helper
src/pages/{terms,privacy}.md, en/*.md long-form ToS/privacy copy (Markdown, per language)
src/lib/forgejo.ts Forgejo admin API client (user provisioning)
src/lib/email.ts, src/i18n/emails.ts Sweego email sender + localized email content (sv/en)
scripts/migrate.mjs, drizzle/ runtime migrator + generated SQL migrations
src/lib/db.ts, src/db/schema.ts Drizzle client + schema (sign-up consent audit)

Configuration

All via environment (see .env.example): PUBLIC_SITE_URL, PUBLIC_GIT_APP_URL, FORGEJO_BASE_URL, FORGEJO_ADMIN_TOKEN, DATABASE_URL, SWEEGO_API_KEY (email; blank disables sending), BILLING_API_URL and BILLING_API_TOKEN (billing service; an unset URL hides the withdrawal section). Secrets are never committed; in production they come from podman secrets via bitborg-infra.