Repository navigation
CHANGELOG: 1.3.0 - #8
Merged
Merged
Conversation
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The change is documentation-only and accurate in substance, with only a minor consistency/linkability tweak suggested for issue references.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds the 1.3.0 release notes to the theme’s changelog so the upcoming tag includes its own entry, reflecting changes that accompany goblog 0.12.0.
Changes:
- Document the move of GitHub login flow handling from the theme into goblog.
- Note the new server-provided GitHub login URL (
.github_login_url) and the resulting installer compatibility requirement. - Record the minimum required goblog version bump to 0.12.0.
| File | Description |
|---|---|
| CHANGELOG.md | Adds the 1.3.0 entry describing GitHub login flow changes and the goblog 0.12.0 requirement. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+3
to
+5
| - Signing in with GitHub is goblog's job now. The button is a plain link to `/login/github`; the theme no longer assembles the authorize URL in an inline script, where `window.location` went into `redirect_uri` unescaped, nor handles the `?code=` that came back. goblog completes the exchange server-side against a `state` it minted, so a code obtained for one account can no longer be replayed into another visitor's browser (goblog #631, #637). | ||
| - The button's own URL comes from the server too, as `.github_login_url`, instead of being built with a template conditional in every theme (goblog #639). | ||
| - **Requires goblog 0.12.0**, and the manifest now says so, so the installer refuses the combination rather than installing a theme whose sign-in button has no URL to point at. Upgrade goblog first. An older version of this theme still signs in on 0.12.0 — goblog restarts the flow when a callback arrives with no state (goblog #640) — but it gets there via a second round trip to GitHub, so update the theme rather than relying on that. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Records the release that follows goblog 0.12.0, before it is tagged — so the tag contains its own entry, unlike the last round where the release had to precede the changelog.
Covers everything since the last release: the GitHub login moving into goblog (goblogplatform/GoBlog#631, #637, #639) and the
min_goblog_versionbump that stops this being installed against a goblog that cannot serve it.Nothing to merge before this except goblog v0.12.0 itself, which is what the entry claims to require.
🤖 Generated with Claude Code