Renders Markdown to HTML and sends as multipart/alternative
with raw Markdown as the plain-text body. When body_md is
provided, body becomes optional. body_md cannot be combined
with body_html.
Rename the misspelled `stmp_*` configuration options to `smtp_*`
and add a new `smtp_tls_mode` option (`starttls`, `tls`, `none`)
to control encryption when connecting to the SMTP server. Reject
credentials in plaintext mode.
Change `sqlpage.send_mail` to return its JSON argument unchanged
on success and update the example to use a local Mailpit SMTP
server via Docker Compose.
### Motivation
- Provide a built-in `sqlpage.send_mail(...)` SQL function so pages can send plain-text emails from SQL code.
- Allow the SMTP server to be configured via an environment / configuration option so the function can target a deployable SMTP endpoint.
### Description
- Added a new function implementation at `src/webserver/database/sqlpage_functions/functions/send_mail.rs` implementing `sqlpage.send_mail(json)` which accepts a JSON object with required `recipient`, `subject`, and `body` and optional `sender` and `reply_to`, sends the message and returns `sent` on success.
- Registered the function in the SQLPage function registry by adding `send_mail` to `src/webserver/database/sqlpage_functions/functions.rs`.
- Added a configuration option `stmp_host: Option<String>` to `AppConfig` in `src/app_config.rs`, with `parse_stmp_host`/`validate_stmp_host` helpers that accept either `host` or `host:port` and default to port 25 when none is provided; validation is run from `AppConfig::validate`.
- Added `lettre` to `Cargo.toml` and updated `Cargo.lock` to enable SMTP sending, and added official-site documentation and a migration at `examples/official-site/sqlpage/migrations/75_send_mail.sql` describing usage and parameters.
- Documented the `stmp_host` option in `configuration.md`.
### Testing
- Ran `cargo fmt --all`, which completed successfully.
- Ran `git diff --check` which reported no immediate style errors.
- Attempted `cargo clippy --all-targets --all-features -- -D warnings`, but it was blocked by a toolchain/build issue (a dependency `libsqlite3-sys` build script uses the unstable `cfg_select` feature) and did not complete.
- Attempted `cargo test`, but it was similarly blocked by the same `libsqlite3-sys` build-script error and did not complete.
SQLPage functions that are the whole value of a selected column now
execute after the database query, once per returned row. If the query
returns no rows, the function is not called. This ensures deterministic
behavior and prevents expensive or side-effectful operations from
running unnecessarily.
Document that the folder/destination_folder argument of
sqlpage.persist_uploaded_file must be chosen by the app author and never
derived from untrusted request data. It is joined directly to the web
root, so a value containing '..' or an absolute path would write the
uploaded file outside the web root. Docs-only clarification of existing
intended behavior; no logic change.
* get_path_segment and is_path_matching sqlpage functions
* Fix for an error in example.
* If a segment in the pattern is ''%d'', it will match any non-empty segment that is an integer. If a segment in the pattern is ''%s'', it will match any non-empty segment in the path
---------
Co-authored-by: Olivier Auverlot <olivier.auverlot@icloud.com>
* add OpenTelemetry distributed tracing support
When OTEL_EXPORTER_OTLP_ENDPOINT is set, enables full tracing pipeline
with OTLP export, W3C traceparent propagation, and spans for HTTP
requests, SQL file execution, DB pool acquire, and query execution.
Falls back to env_logger when unset.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix OTel example: tracing init, Dockerfile, Tempo config
- Fix tracing-log bridge initialization order (set subscriber first,
then LogTracer) to avoid double-set panic
- Add dedicated Dockerfile for example using release profile (avoids
OOM with superoptimized LTO in Docker)
- Use debian:trixie-slim runtime for glibc compatibility
- Fix nginx image to nginx:otel (official image with OTel module)
- Fix nginx.conf: move otel_trace directives into location block
- Pin Tempo to 2.6.1 (latest has partition ring issues in single-node)
- Fix otel-collector exporter alias (otlp → otlp_grpc)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* propagate trace context to PostgreSQL via application_name
After acquiring a DB connection, set the W3C traceparent as the
PostgreSQL application_name (or MySQL session variable). This makes
trace IDs visible in pg_stat_activity and PostgreSQL logs, enabling
direct correlation between Grafana Tempo traces and database-side
monitoring.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* rewrite OTel example README with setup guides for all major providers
Comprehensive documentation covering:
- Step-by-step quick start for the Docker Compose example
- How OpenTelemetry works (spans, collectors, backends)
- Setup guides for Grafana Tempo, Jaeger, Grafana Cloud, Datadog,
Honeycomb, New Relic, and Axiom with exact env vars and doc links
- PostgreSQL trace correlation via application_name
- Environment variable reference
- Troubleshooting section
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix todo example: use :title (POST variable) instead of $title
The form submits via POST, so the title field must be referenced with
the : prefix (POST parameter) rather than $ (GET parameter).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* set code.filepath and code.lineno span attributes to user SQL files
OTel span attributes now reference the user's .sql file path and line
number instead of the SQLPage Rust source code. Also improves span
naming, adds JSON log formatting, custom root span builder, and
Grafana dashboard provisioning for the OTel example.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* npm run fix
* use stable OTel semantic convention attribute names
- code.filepath → code.file.path, code.lineno → code.line.number
- db.statement → db.query.text, db.system → db.system.name
- Disable auto code location (.with_location(false)) so spans
reference user SQL files, not SQLPage Rust source
- Remove redundant sqlpage.file attribute (code.file.path suffices)
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* use OTel semantic convention values for db.system.name
Use well-known values from the OpenTelemetry registry instead of raw
DBMS name strings. Cast line numbers to i64 for correct span recording.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* remove json-subscriber dependency
The custom logfmt layer in telemetry.rs replaces it with zero extra
dependencies and precise control over field selection and ordering.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* add Loki + Promtail log aggregation to OTel example
Adds two new services (Loki, Promtail) to scrape SQLPage container logs
and display them in Grafana alongside traces. The home dashboard now
shows a logs panel with trace_id derived fields linking to Tempo.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* add OTel spans for request parsing, rendering, sqlpage functions, and OIDC
Add targeted spans to account for previously untraced time:
- http.parse_request: request/form parsing before SQL execution
- render: template rendering and response streaming
- subprocess: sqlpage.exec() with process.command attribute
- http.client: sqlpage.fetch()/fetch_with_meta() with OTel HTTP client
semantic conventions (http.request.method, url.full, http.response.status_code)
- sqlpage.file: sqlpage.run_sql() nested file execution
- oidc.callback + http.client: OIDC token exchange
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* add oidc.jwt.verify span for OIDC token verification
This span covers JWT signature verification and claims validation,
which runs on every authenticated request via get_token_claims().
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* add enduser.id attribute to oidc.jwt.verify span
Records the OIDC subject claim (sub) as enduser.id after successful
JWT verification, following OTel semantic conventions.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* add OTel user.* attributes to oidc.jwt.verify span
Record user.id (sub), user.name (preferred_username), user.full_name
(name), and user.email from OIDC claims after JWT verification.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* add sqlpage.file.load span and attributes to http.parse_request
The gap before http.parse_request was the SQL file cache lookup -
now covered by the sqlpage.file.load span with code.file.path.
http.parse_request now records http.request.method and content_type,
which helps identify slow multipart/form-data parsing.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Fix clippy pedantic warnings
* unify log format: logfmt with colors, no OTel noise
Use the custom logfmt layer for both OTel and non-OTel modes instead
of falling back to env_logger. This eliminates the tracing→log bridge
dumping all span fields (user agents, otel.kind, request_id, etc.)
and only shows: ts, level, target, msg, method, path, status,
file, client_ip, and trace_id (when valid).
Adds terminal color support (bold red for errors, green for info,
dim for timestamps/targets). Emits one log line per completed
successful request. Errors are logged once by the error handler.
Suppresses trace_id=000...0 when no real trace context exists.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* use .instrument() instead of .entered() for async spans
Span guards from .entered() do not propagate correctly across await
points. Switch to tracing::Instrument to ensure spans are properly
associated with their async tasks throughout their lifetime.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* preserve multi-line error formatting in terminal log output
When stderr is a terminal and the log message contains newlines
(e.g. SQL syntax errors with source highlighting and arrows),
print the metadata on the first line and the message below with
its original formatting. Machine output (non-terminal) remains
single-line logfmt.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* use root Dockerfile for OTel example, add CARGO_PROFILE build arg
Remove the example's custom Dockerfile and use the main one with a
CARGO_PROFILE=release build arg to avoid OOM from fat LTO in
memory-constrained Docker environments. The build scripts now
read CARGO_PROFILE from the environment, defaulting to
superoptimized for backward compatibility.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* add db.query.parameter and db.response.returned_rows span attributes
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Add official blog post about tracing
* add http.request.body.size and url.query span attributes
Add http.request.body.size to HTTP client spans (fetch, fetch_with_meta)
and to the server-side http.parse_request span (from Content-Length header).
Add url.query to the http.parse_request span.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* Replace Promtail with the OpenTelemetry Collector
* Refactor telemetry logging helpers
* Clamp traced fetch body size
* Clamp traced fetch_with_meta body size
* Silence noisy PostgreSQL collector logs
* make startup logs parseable
* update terminal log formats
* Ingest real PostgreSQL logs with trace IDs
* Use raw traceparent for PostgreSQL tracing
* Update opentelemetry example for PostgreSQL query events
* Add nginx logs to opentelemetry example
* Parse nginx error log severity correctly
* Log all span fields when debug logging is enabled
* Rename telemetry example directory
* Fix PostgreSQL Loki log ingestion
* `LOG_LEVEL` is now the primary environment variable for configuring SQLPage's log filter. `RUST_LOG` remains supported as an alias.
* Skip empty trace IDs in logs
* add db errors to otel traces
* add healthcheck
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
* Add optional mode argument to persist_uploaded_file
This change adds an optional `mode` argument to the `persist_uploaded_file` function, allowing users to specify the Unix file permissions in octal notation when saving uploaded files.
- Updated `sqlpage.persist_uploaded_file` signature to include `mode`.
- Implemented permission setting logic using `std::os::unix::fs::PermissionsExt` (on Unix platforms).
- Default permission is set to "600" (octal `0o600`).
- Added documentation for the new parameter in `examples/official-site/sqlpage/migrations/39_persist_uploaded_file.sql`, including an explanation of octal notation and a link to Wikipedia.
- Added a unit test `test_set_file_mode` to verify the permission setting logic.
Co-authored-by: lovasoa <552629+lovasoa@users.noreply.github.com>
* Address PR feedback: Add integrated test for persist_uploaded_file mode
- Removed unit test from `functions.rs` and added an integrated test in `tests/uploads/mod.rs`.
- Created `tests/uploads/persist_with_mode.sql` for the integrated test.
- Refactored `set_file_mode` to use `#[cfg(unix)]` and `#[cfg(not(unix))]` on the entire function.
- Replied to PR comments.
Co-authored-by: lovasoa <552629+lovasoa@users.noreply.github.com>
* Fix Windows CI: Normalize paths and improve tests
- Normalized `persist_uploaded_file` return path to use forward slashes for URL compatibility.
- Updated `test_persist_uploaded_file_mode` to handle platform-specific path separators.
- Fixed clippy warning `expect_fun_call` in tests.
Co-authored-by: lovasoa <552629+lovasoa@users.noreply.github.com>
* Address PR feedback: Assert file contents and ignore test uploads
- Added assertion to verify persisted file contents in `test_persist_uploaded_file_mode`.
- Removed accidental test file from git and added `tests_uploads/` to `.gitignore`.
- Replied to PR comments.
Co-authored-by: lovasoa <552629+lovasoa@users.noreply.github.com>
* Address PR feedback: Revert breaking change to return value
- Reverted normalization of `persist_uploaded_file` return value to avoid a breaking change.
- Reverted corresponding test changes that relied on normalized paths.
- Replied to PR comments.
Co-authored-by: lovasoa <552629+lovasoa@users.noreply.github.com>
* Address PR feedback: Query results as JSON in integrated test
- Updated `test_persist_uploaded_file_mode` to directy request and verify JSON results.
- Replied to PR comments.
Co-authored-by: lovasoa <552629+lovasoa@users.noreply.github.com>
* Fix Windows CI: Robust path handling in tests
- Improved integrated test to correctly request JSON results.
- Added platform-specific path normalization when verifying files on disk.
- Ensured `persist_uploaded_file` return value remains OS-specific to avoid breaking changes.
Co-authored-by: lovasoa <552629+lovasoa@users.noreply.github.com>
* Address PR feedback: Delete leftover test file
- Deleted accidental leftover test file `tests_uploads/2026-03-13_15h47m26s_6JaXODDK.txt`.
- Replied to PR comments.
Co-authored-by: lovasoa <552629+lovasoa@users.noreply.github.com>
---------
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
The `sqlpage.variables()` function previously allowed duplicate keys
when GET, POST, and SET variables of the same name were present. This
commit ensures that the returned JSON object contains only unique keys,
with precedence given to SET variables, then POST, then GET.
* Checkpoint before follow-up message
Co-authored-by: contact <contact@ophir.dev>
* Checkpoint before follow-up message
Co-authored-by: contact <contact@ophir.dev>
* Checkpoint before follow-up message
Co-authored-by: contact <contact@ophir.dev>
* Checkpoint before follow-up message
Co-authored-by: contact <contact@ophir.dev>
* feat: Add OIDC logout functionality
This commit introduces the `oidc_logout_url` function, allowing users to securely log out of OIDC-authenticated applications. It includes CSRF protection and handles redirection to the OIDC provider's logout endpoint.
Co-authored-by: contact <contact@ophir.dev>
* Refactor OIDC logout cookie removal
Co-authored-by: contact <contact@ophir.dev>
* feat: Implement OIDC logout with CSRF protection
This commit implements secure OIDC logout by:
- Using sqlpage.oidc_logout_url() to generate the logout URL.
- Ensuring CSRF protection during the logout process.
- Redirecting to the OIDC provider's logout endpoint.
- Redirecting back to the homepage after logout.
- Adding absolute URI for post logout redirect URI.
* refactor: Enhance build_absolute_uri function to accept scheme parameter
This commit modifies the build_absolute_uri function to include a scheme parameter, allowing for more flexible URL construction. The function now dynamically sets the URL scheme based on the request context, improving compatibility with different environments.
* refactor: Simplify OIDC logout processing and enhance logout token handling
This commit refactors the OIDC logout process by introducing a new function, `parse_logout_params`, to streamline the extraction of logout parameters from the request. It also updates the logout token creation and verification logic, improving security by ensuring the signature is computed correctly. Additionally, the `create_logout_url` function is modified to include a timestamp and signature in the generated URL, enhancing the logout flow's integrity.
* refactor: Improve logout URL generation and parameter parsing
This commit refines the `create_logout_url` function to utilize a query string builder for constructing the logout URL, enhancing readability and maintainability. Additionally, the `parse_logout_params` function is updated to use `Query::into_inner`, streamlining the extraction of logout parameters from the request.
* refactor: Streamline cookie removal in OIDC logout process
This commit simplifies the removal of authentication and nonce cookies during the OIDC logout process by consolidating the cookie removal logic into a single method call for each cookie, enhancing code clarity and maintainability.
* refactor: Enhance cookie removal logic in OIDC logout process
This commit updates the cookie removal process during OIDC logout by utilizing the `Cookie::build` method to specify cookie attributes, improving clarity and ensuring proper cookie handling.
* chore: Update CHANGELOG for version 0.40.1
- Added new function `sqlpage.oidc_logout_url(redirect_uri)` to generate secure logout URLs for OIDC users, supporting RP-Initiated Logout.
- Fixed compatibility issues with Auth0 for OpenID-Connect authentication.
* Support JSON responses via Accept header
* no update in migrations
* No UPDATE in official site migrations
- Updated the JSON component description to clarify its integration with external services and the ability to serve both HTML and JSON based on the HTTP Accept header.
- Added examples demonstrating how to request JSON responses using `curl`.
- Removed the obsolete migration file that documented the JSON response format feature, consolidating information into the main documentation.
* revert stupid docs example change
stupid bot
* simplify tests
* avoid string then json in tests, parse as json directly
* changelog
* feat: Add sqlpage.set_variable function
Co-authored-by: contact <contact@ophir.dev>
* Refactor: Fix set_variable serialization and update tests
Co-authored-by: contact <contact@ophir.dev>
* fix tests: no json_extract on mssql
* Refactor: Update URLParameters handling in set_variable function
- Replaced serde_json::Map with a custom URLParameters struct for better management of URL parameters.
- Introduced methods for handling single and vector values in URLParameters.
- Updated tests to reflect changes in the set_variable function's behavior.
* cargo fmt
* clippy
* retsore set var test
* remove redundant test
* ensure set_variable only takes into account GET variables, not SET
* factor url parameter setting code
* v0.40
* sqlpage.set_variable links to "?" when no parameter is present
- Renamed URLParameters module for clarity and removed the deprecated url_parameter_deserializer.
- Updated the set_variable function to return parameters directly instead of appending to a URL.
- Adjusted related function calls to reflect changes in URL parameter management.
---------
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
* Pagination component
* New pagination component
* Some changes
* Adding a warning about the use of LIMIT and OFFSET in the blog post
* Use icon_img for icons
* Correction of the icons size
* enhance pagination docs examples
* update pagination docs
---------
Co-authored-by: Olivier Auverlot <olivier.auverlot@icloud.com>
Co-authored-by: lovasoa <contact@ophir.dev>
* Adding an alias named contents to the html property of the shell-empty component
* Changes for the shell-empty documentation
* improve shell comoonent description
* shell-empty docs clarification
---------
Co-authored-by: Olivier Auverlot <olivier.auverlot@icloud.com>
Co-authored-by: lovasoa <contact@ophir.dev>