A more informative footer on every page, and still a discreet one #212

Open
opened 2026-09-15 19:35:51 +00:00 by tiagoagueda · 0 comments
Owner

The footer at the bottom of every page says very little, and the little it says is Postulo's own slogan instead of anything about this instance. It should be more informative and still discreet: small, quiet, one or two lines, never a banner.

What it is today

src/postulo/templates/base.html:167-174, drawn on every page, signed in or not:

Postulo — your job search, on your server.    Postulo 0.3.0
  • The slogan is hard-coded, even though the page already has instance_name and instance_tagline (core/context_processors.py:60-61), which an administrator sets under Server settings → Defaults.
  • The version is plain text: nothing says where it came from or what changed in it.
  • There is no link anywhere to the source, the licence, the documentation or the person running the instance.

What it could carry

Candidates only. Picking the few that earn a place is part of the issue:

  • This instance: its name, and optionally its tagline (instead of Postulo's slogan when the administrator has set them).
  • "Powered by Postulo" and the version, with the version linking to its release notes (the Forgejo release or the CHANGELOG entry for that tag). A development build such as 0.2.1-dev.3ac8448 should link to the commit.
  • Source and licence. Postulo is AGPL-3.0-or-later, and README.md:243 tells anybody running a modified Postulo as a network service that they must offer its source to its users. A Source link in the footer is the natural place for that offer. It should point wherever the operator's code lives, not always at the upstream repository. That probably needs an optional setting (e.g. POSTULO_SOURCE_URL, defaulting to upstream).
  • Help: a link to the documentation (the wiki).
  • Who runs this instance: an optional operator contact or legal-notice link (an imprint is a legal requirement in some countries, Germany for one). Configured, never guessed, and absent when unset.
  • Signed in only, perhaps: the language and time zone in force, each linking to Settings → Language and time. Useful when someone wonders why dates look wrong; noise otherwise.

What it must not become

  • No request for money. README.md promises that nothing inside Postulo will ever ask for it, and #172 names the footer explicitly: "not in the footer of the application". The support card stays on Server settings → Overview only.
  • No third-party requests. No badges, no remote images, nothing the CSP would have to allow.
  • Not louder than the page. It keeps the current text-xs and muted colour, and wraps to two lines on a phone rather than growing a block.
  • Nothing about the server a stranger should not see. On signed-out pages (landing, sign-in) show at most the instance name, Powered by Postulo, source and help. Whether the exact version is shown to anonymous visitors is a hardening question (it tells an attacker which advisories apply): decide it, and consider showing the version to signed-in people only.

Constraints from the code

  • Accessibility:
    • a <footer> landmark with its links in a list or a <nav> carrying its own label;
    • link text that makes sense out of context ("Source code", not "here");
    • contrast at WCAG 2.2 AA in both themes for the muted text and its links;
    • external links marked as such (rel="noopener noreferrer external", the way server/plugins.html:235 does).
  • Layout:
    • tests/test_width.py:72 requires the footer to span the screen with no max-w- cap;
    • logical utilities only (tests/test_template_lint.py);
    • <bdi> around the instance name, which is typed text that may be in another script.
  • Translation: every label is translated; the instance name and tagline are not.
  • Tests that pin today's footer:
    • tests/test_release_tools.py:130 looks for Postulo <version>;
    • tests/test_server_settings.py:93 looks for the version on the overview.
      Keep them true, or change them on purpose.
  • Pages: the footer appears on allauth's pages too (sign-in, password reset, MFA), which extend base.html. Check them, and check that rendered documents and print output do not pick it up.

Done when

  • The footer shows the chosen items, signed in and signed out, in both themes and right to left, and the browser suite's axe run stays clean.
  • Anything configurable (source address, operator contact) is documented on the wiki's Configuration page and absent when unset.
The footer at the bottom of every page says very little, and the little it says is Postulo's own slogan instead of anything about this instance. It should be more informative and still discreet: small, quiet, one or two lines, never a banner. ## What it is today `src/postulo/templates/base.html:167-174`, drawn on every page, signed in or not: ``` Postulo — your job search, on your server. Postulo 0.3.0 ``` - The slogan is hard-coded, even though the page already has `instance_name` and `instance_tagline` (`core/context_processors.py:60-61`), which an administrator sets under *Server settings → Defaults*. - The version is plain text: nothing says where it came from or what changed in it. - There is no link anywhere to the source, the licence, the documentation or the person running the instance. ## What it could carry Candidates only. Picking the few that earn a place is part of the issue: - **This instance:** its name, and optionally its tagline (instead of Postulo's slogan when the administrator has set them). - **"Powered by Postulo" and the version,** with the version linking to its release notes (the Forgejo release or the CHANGELOG entry for that tag). A development build such as `0.2.1-dev.3ac8448` should link to the commit. - **Source and licence.** Postulo is AGPL-3.0-or-later, and `README.md:243` tells anybody running a *modified* Postulo as a network service that they must offer its source to its users. A *Source* link in the footer is the natural place for that offer. It should point wherever the operator's code lives, not always at the upstream repository. That probably needs an optional setting (e.g. `POSTULO_SOURCE_URL`, defaulting to upstream). - **Help:** a link to the documentation (the wiki). - **Who runs this instance:** an optional operator contact or legal-notice link (an imprint is a legal requirement in some countries, Germany for one). Configured, never guessed, and absent when unset. - **Signed in only, perhaps:** the language and time zone in force, each linking to *Settings → Language and time*. Useful when someone wonders why dates look wrong; noise otherwise. ## What it must not become - **No request for money.** `README.md` promises that nothing inside Postulo will ever ask for it, and #172 names the footer explicitly: *"not in the footer of the application"*. The support card stays on *Server settings → Overview* only. - **No third-party requests.** No badges, no remote images, nothing the CSP would have to allow. - **Not louder than the page.** It keeps the current `text-xs` and muted colour, and wraps to two lines on a phone rather than growing a block. - **Nothing about the server a stranger should not see.** On signed-out pages (landing, sign-in) show at most the instance name, *Powered by Postulo*, source and help. Whether the exact version is shown to anonymous visitors is a hardening question (it tells an attacker which advisories apply): decide it, and consider showing the version to signed-in people only. ## Constraints from the code - **Accessibility:** - a `<footer>` landmark with its links in a list or a `<nav>` carrying its own label; - link text that makes sense out of context ("Source code", not "here"); - contrast at WCAG 2.2 AA in both themes for the muted text *and* its links; - external links marked as such (`rel="noopener noreferrer external"`, the way `server/plugins.html:235` does). - **Layout:** - `tests/test_width.py:72` requires the footer to span the screen with no `max-w-` cap; - logical utilities only (`tests/test_template_lint.py`); - `<bdi>` around the instance name, which is typed text that may be in another script. - **Translation:** every label is translated; the instance name and tagline are not. - **Tests that pin today's footer:** - `tests/test_release_tools.py:130` looks for `Postulo <version>`; - `tests/test_server_settings.py:93` looks for the version on the overview. Keep them true, or change them on purpose. - **Pages:** the footer appears on allauth's pages too (sign-in, password reset, MFA), which extend `base.html`. Check them, and check that rendered documents and print output do not pick it up. ## Done when - The footer shows the chosen items, signed in and signed out, in both themes and right to left, and the browser suite's axe run stays clean. - Anything configurable (source address, operator contact) is documented on the wiki's *Configuration* page and absent when unset.
tiagoagueda added this to the 0.6.0 milestone 2026-09-15 21:33:33 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Postulo/postulo#212
No description provided.