Commit Graph

282 Commits

Author SHA1 Message Date
Ben Busby
91dd677e22
Remove inline onclicks, fix svg sizing 2021-04-02 17:21:38 -04:00
Ben Busby
91bbf9c0fa
Merge remote-tracking branch 'origin/develop' into custom-css-tweaks 2021-04-02 15:35:37 -04:00
Ben Busby
b1227bde01
Bump version to 0.3.2 2021-04-02 13:24:11 -04:00
Ben Busby
72637df213
Use svg logo w/ custom styling on results pages 2021-04-02 11:38:38 -04:00
Ben Busby
666a7ceac4
Split whoogle-accent into whoogle-element-bg and whoogle-logo
See discussion on #247
2021-04-02 11:10:37 -04:00
Ben Busby
b1c024f9e1
Add missing config vars to app.json 2021-04-02 08:53:58 -04:00
Ben Busby
e2114bc698
Revert heroku app https upgrade fix 2021-04-02 08:53:41 -04:00
Ben Busby
a0110fda8d
Switch to single Fernet key per session
This moves away from the previous (messy) approach of using two separate
keys for decrypting text and element URLs separately and regenerating
them for new searches. The current implementation of sessions is not very
reliable, which lead to keys being regenerated too soon, which would
break page navigation. Until that can be addressed, the single
key per session approach should work a lot better.

Fixes #250

Fixes #90
2021-04-01 00:23:30 -04:00
Ben Busby
86ae2bda3e
Hotfix: Upgrade heroku apps to https for all endpoints
The previous implementation of the is_heroku check in
search.needs_https() was implemented to only match URLs ending in
'.herokuapp.com', and skipped upgrading to HTTPS for other endpoints.
2021-03-31 12:14:38 -04:00
Ben Busby
fb863b5b52
Hotfix: Set EU consent cookie to pending for all requests
See discussion on #243
2021-03-31 09:50:13 -04:00
Ben Busby
7002b3c2b9
Add new public instance to readme
See https://whooglesearch.net/
2021-03-30 12:17:07 -04:00
Ben Busby
9c01c15c39
Allow defining initial config state w/ env vars
This introduces a set of environment variables that can be used for
defining initial config state, to expedite the process of
destroying/relaunching instances quickly with the same settings every
time.

Closes #228

Closes #195
2021-03-28 14:24:57 -04:00
Ben Busby
baf7757f3e
Revert debug flag in run script 2021-03-28 13:27:39 -04:00
Shimul
9a5b095305
Allow setting environment variables in whoogle.env (#237)
This allows the user to enable their preferred settings in a variety of
ways, depending on their deployment preference. Values added to
whoogle.env can be enabled using WHOOGLE_DOTENV=1, in which case all
values in the env var file will overwrite defaults or user provided
settings.

Co-authored-by: Ben Busby <benbusby@protonmail.com>
2021-03-28 13:27:08 -04:00
Nico
271782bead
Add Garuda Linux public instance (#241)
Co-authored-by: Ben Busby <benbusby@protonmail.com>
2021-03-28 12:29:17 -04:00
Ben Busby
9a097d79d4
Add custom builder image to buildx action
Also added debug to list architectures for buildx. Needless to say,
the buildx action is super flakey (as evidenced by a change to the
README breaking the entire build somehow).
2021-03-25 10:43:05 -04:00
Ben Busby
fba8e3d9f8
Remove public instance from readme
I've received multiple reports that the Whoogle instance hosted at 
whoogle.tormentasolar.win is spam, so it has been removed from the
readme.
2021-03-25 10:04:41 -04:00
Ben Busby
f4a087303d
Improve static typing throughout repo
Eventually this should be part of a separate mypy ci build, but right
now it's just a general guideline. Future commits and PRs should be
validated for static typing wherever possible.

For reference, the testing commands used for this commit were:

mypy --ignore-missing-imports --pretty --disallow-untyped-calls app/
mypy --ignore-missing-imports --pretty --disallow-untyped-calls test/
2021-03-24 15:13:52 -04:00
Shimul
c893f5d7a2
Configure PWA for mobile browsers (#234)
Fix PWA issue for mobile phones
Fix icon loading issue
Update app/static/img/favicon/manifest.json

Co-authored-by: Ben Busby <benbusby@pm.me>
2021-03-22 13:04:29 -04:00
Ben Busby
d81b232248
Re-add search css to results page
The results page search css was removed during the refactor to allow for
user defined css. This adds that back.
2021-03-22 10:59:32 -04:00
fredster33
bba3c32313
Reformat public instance links in readme (#224)
Co-authored-by: Ben Busby <benbusby@protonmail.com>
2021-03-22 10:19:58 -04:00
Shimul
dc20de6fed
Fixing typo in Dockerfile (#235) 2021-03-22 10:16:24 -04:00
Ben Busby
56258a16b0
Return 503 if response is blocked by captcha
Also added in a slight modification to the dark theme style, which
should only apply the border radius in the header.

Closes #226
2021-03-20 21:51:24 -04:00
Ben Busby
c0f4ba99cf
Allow user-defined CSS/theming (#227)
* Add custom CSS field to config

This allows users to set/customize an instance's theme and appearance to
their liking. The config CSS field is prepopulated with all default CSS
variable values to allow quick editing.

Note that this can be somewhat of a "footgun" if someone updates the
CSS to hide all fields/search/etc. Should probably add some sort of
bandaid "admin" feature for public instances to employ until the whole
cookie/session issue is investigated further.

* Symlink all app static files to test dir

* Refactor app/misc/*.json -> app/static/settings/*.json

The country/language json files are used for user config settings, so
the "misc" name didn't really make sense. Also moved these to the static
folder to make testing easier.

* Fix light theme variables in dark theme css

* Minor style tweaking
2021-03-20 21:21:41 -04:00
Shimul
e4299f7a72
Handle manifest-src in CSP (#231) 2021-03-20 19:52:06 -04:00
dependabot[bot]
d9dcbfccb9
Bump jinja2 from 2.10.3 to 2.11.3 (#229)
Bumps [jinja2](https://github.com/pallets/jinja) from 2.10.3 to 2.11.3.
- [Release notes](https://github.com/pallets/jinja/releases)
- [Changelog](https://github.com/pallets/jinja/blob/master/CHANGES.rst)
- [Commits](https://github.com/pallets/jinja/compare/2.10.3...2.11.3)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-03-19 23:47:29 -04:00
FireMasterK
5da53fb50f
Add new public instances (#223) 2021-03-18 09:59:59 -04:00
Ben Busby
8e0fffc181
Use bash for heroku-regen 2021-03-17 12:44:30 -04:00
Ben Busby
fea76c927d
Add heroku-regen script, rename config/ -> misc/
Introduces a new script for quickly regenerating a Heroku instance
(typically with a new IP) to handle the rare circumstances where an
instance is flagged by Google and prompted for a captcha.

The config/ dir was renamed to misc/ to avoid confusion with the Docker
mounted config volume, and to more closely match its intended purpose
(which is to contain all miscellaneous features/scripts/etc that add
functionality to Whoogle, but are not critical for general use).
2021-03-17 12:27:08 -04:00
Ben Busby
f4b8b7bc2d
Add UI requests note to feature template
The feature request template should not be used for requesting updates to the UI.

There's already a pinned issue for UI customization, and all requests should go there.
2021-03-09 10:12:35 -05:00
Ben Busby
e2080f0592
Update heroku quick deploy branch, env vars in readme
The Heroku quick deploy branch has been changed from heroku-app to
heroku-app-beta, since a lot of users want to use features from develop
in their heroku instances.

The environment variables in the readme were updated to include the
reddit redirect var.
2021-03-08 17:08:55 -05:00
Ben Busby
ba7493a846
Add healthcheck to Dockerfile
See #184
2021-03-08 12:38:40 -05:00
Ben Busby
d447e5009f
Improve naming of *_utils files, update fn/class doc
The app/utils/*_utils weren't named very well, and all have been updated
to have more accurate names.

Function and class documention for the utils have been updated as well,
as part of the effort to improve overall documentation for the project.
2021-03-08 12:22:04 -05:00
Nico
855b4e8502
Add Arch Linux installation instructions to readme (#217) 2021-03-07 16:50:23 -05:00
Ben Busby
a1134e7633
Send CSP header in all responses
Introduces a new content security policy header for responses to all
requests to reduce the possibility of ip leaks to outside connections.
By default blocks all inline scripts, and only allows content loaded
from Whoogle.

Refactors a few small inline scripting cases in the project to their own
individual scripts.
2021-03-07 14:04:05 -05:00
Ben Busby
e912b8f5e0
Move ssl install to Dockerfile build stage 2021-02-26 12:04:06 -05:00
Ben Busby
08379efa26
Remove auth req for accessing opensearch
Requiring authentication for accessing the opensearch template prevents
the browser from accessing the file when adding as a default search
engine. This removes the authentication requirement from the opensearch
route, which should never provide any sensitive information anyways.
2021-02-26 11:42:42 -05:00
Basti
b3ae0b7594
Use multi-stage container build (#210)
This only adds necessary packages and files from the repo to reduce the image size.

Co-authored-by: pred2k <does@not.exists>
2021-02-26 10:49:40 -05:00
Basti
2e599c0a7e
Update docker-compose security features (#208)
Co-authored-by: Sebastian Forst <sebastian.forst@posteo.de>
2021-02-26 10:33:11 -05:00
Ben Busby
6c85468cd6
Allow bang operator anywhere in query
Bang operator can now be placed anywhere in the query, to allow for peak
efficiency in stream of consciousness querying (i.e. `big !reddit
chungus` will search reddit for big chungus`).

Fixes #196
2021-02-20 15:31:15 -05:00
Ben Busby
e066a19411
Ensure G logo doesn't appear in mobile img results
Adds a separate check to remove all images sourced from www.gstatic.com,
which is where the mobile logo in particular is coming from.
2021-02-20 15:04:32 -05:00
Ben Busby
38f160142e
Add basic keyboard support #202
This adds basic keyboard support on the search results page:

    ArrowUp or k - focus previous result
    ArrowDown or j - focus next result
    / focus search box

Because this just focuses links in the search result items hitting Enter
(or ctrl/cmd + Enter) when an item is focused - will open the search 
result (because the link is already focused and this is browser's default
behaviour).
2021-02-20 14:47:18 -05:00
Tomasz Borychowski
4bbfc8c8f7 fix 'j' and 'k' inside search input 2021-02-19 22:49:32 +00:00
Ben Busby
3958e607de
Merge branch 'develop' into develop 2021-02-19 12:30:27 -05:00
Roman Štefko
c5fdf84635
Do not autocapitalize on index page search bar (#200) 2021-02-19 12:30:05 -05:00
Tomasz Borychowski
04718099f4 add basic keyboard support 2021-02-14 15:50:53 +00:00
Ben Busby
16b3d0f543
List public instances in readme
Note: future public instances should be added with a PR
2021-02-12 10:37:39 -05:00
dependabot[bot]
5689285816
Bump cryptography from 3.2 to 3.3.2 (#193)
Bumps [cryptography](https://github.com/pyca/cryptography) from 3.2 to 3.3.2.
- [Release notes](https://github.com/pyca/cryptography/releases)
- [Changelog](https://github.com/pyca/cryptography/blob/master/CHANGELOG.rst)
- [Commits](https://github.com/pyca/cryptography/compare/3.2...3.3.2)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-02-12 10:28:34 -05:00
Ben Busby
35b555273c
Merge remote-tracking branch 'origin/main' into develop 2021-02-07 18:56:22 -05:00
Ben Busby
0a6575d219
Hotfix: Move language/country json to app dir
Pip installs of whoogle search were missing access to the misc/ folder,
which previously contained the language and country json files. These
have been moved to app/misc, and the previous root level misc/ was
renamed to config/ (since it now only contains the tor config files).

Bump to 0.3.1.
2021-02-07 18:55:27 -05:00