Skip to content
CAI
Software that uses CAICheck a score

maxcom/lorsource

47.1

Weak · 20 September 2026

31.6k

lines of production code

Scala

with Java, JavaScript

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a community forum and content platform that manages user accounts, topics, comments, galleries, and polls. It features a robust content rendering engine supporting LORCODE, Markdown, and BBCode, with integrated search via OpenSearch and asynchronous processing using Apache Pekko. The application enforces strict security and moderation workflows, including CSRF protection, permission-based access control, and a warning system for user violations.

How it got here

2007–2012 — Modernization and architectural refactoring

35 changes.

This period focused on modernizing the application's core infrastructure by migrating to Jakarta EE 6.1, upgrading to Spring Security 6, and replacing legacy components with Apache Pekko and Scala 3 tooling. Significant effort was dedicated to refactoring the BBCode and LORCODE parsers into modular, node-based structures while introducing comprehensive security hardening, including CSRF protection and secure authentication mechanisms. The work also involved restructuring the web layer with new JSP tag libraries, responsive themes, and centralized exception handling to improve maintainability and user experience.

2013–2015 — Scala migration and modernization

31 changes.

The codebase underwent a comprehensive migration of core modules, including topics, tags, users, and authentication, from Java to Scala, accompanied by a shift from Akka to Apache Pekko. This period also saw significant infrastructure updates, such as replacing Elasticsearch with OpenSearch and refactoring the styling architecture to use Sass modules and CSS Grid. Concurrently, new visual themes were introduced, and security controls were strengthened through enhanced validation and HTTPS enforcement.

2016–2026 — Scala migration and security hardening

43 changes.

This period focused on migrating core application logic, controllers, and data access layers from Java to Scala, while introducing ScalikeJDBC for database interactions. Significant security enhancements were implemented, including HTML sanitization, strict permission checks with detailed denial reasons, and CSRF protection. The work also expanded feature sets with new reaction systems, warning notifications, and Telegram integration, supported by comprehensive test coverage using MUnit.

Features

Added Docker-based development environment with PostgreSQL and OpenSearch

Developers can now use VS Code Dev Containers to run the project locally with a pre-configured environment. The setup includes a Maven-based application container, a PostgreSQL 16 database, and an OpenSearch 3.6.0 instance. An initialization script automatically creates required database users, sets up the 'lor' database with necessary extensions, loads the demo schema, and runs Liquibase migrations. VS Code extensions for Scala, Java, and Maven are pre-installed to support the development workflow.

.devcontainer · high confidence

Added IR\_Black syntax highlighting theme

A new CSS stylesheet for the 'black' location has been introduced, implementing the IR\_Black syntax highlighting theme. This adds specific color definitions for code elements such as keywords, strings, comments, and numbers, allowing users to view code snippets with this distinct dark-themed color scheme.

src/main/webapp/black · high confidence

Added Tango syntax highlighting theme

A new CSS file (syntax.css) has been added to the Tango webapp to define syntax highlighting styles for code blocks. This theme maps various code elements (keywords, strings, comments, etc.) to specific CSS variables, enabling consistent visual styling for highlighted code within the application.

src/main/webapp/tango · high confidence

Automated posting of hot topics to Telegram

A new scheduled service now automatically posts selected 'hot' forum topics to the @best\_of\_lor Telegram channel. The system identifies topics with at least 15 distinct active users and a score of 100+ within the last 5 hours, excluding those with excessive warnings, deleted status, or specific hide flags. Posts include the topic title, tags, and a link, and are sent via the Telegram Bot API with automatic retry logic using an HTTP proxy if the direct connection fails. The service also handles cleanup by deleting Telegram messages when the corresponding forum topics are removed or demoted.

src/main/scala/ru/org/linux/telegram · high confidence

Functional transaction demarcation support added

A new \TransactionManagement\ trait has been introduced in the \org.springframework.scala.transaction.support\ package, providing a \transactional\ function for functional-style transaction handling. This allows users to execute code blocks within a transaction context without explicit transaction management boilerplate, supporting configuration for propagation, isolation, read-only status, qualifiers, and timeouts.

src/main/scala/org · high confidence

An immutable TopicLinkBuilder has been introduced to handle the construction of topic URLs. This component allows for the fluent configuration of link parameters such as page number, deletion visibility, last modification status, specific comments, and filters, ensuring that generated links are consistent and correctly formatted via URI components.

src/main/java/ru/org/linux/topic · high confidence

Introduction of AbstractRomeView for syndication feeds

A new base class, AbstractRomeView, has been added to the Spring configuration package to standardize the generation of RSS/Atom syndication feeds. This component handles the common logic for setting feed encoding, determining feed types (such as RSS), and outputting the final XML via the Rometools library, allowing specific feed implementations to focus solely on populating the feed data model.

src/main/java/ru/org/linux/spring · high confidence

Introduction of Edit History Object Type enumeration

A new enum, EditHistoryObjectTypeEnum, has been added to the edit history module to categorize edit history entries by object type, specifically supporting TOPIC and COMMENT types.

src/main/java/ru/org/linux/edithistory · high confidence

Introduction of Liquibase for database schema management

The project now uses Liquibase to manage database schema changes, replacing ad-hoc SQL updates with a structured migration system. This change introduces the Liquibase configuration files (liquibase.config, main.xml) and a .gitignore rule to exclude the production Liquibase configuration file. A new demo database dump (demo.db) is also provided, establishing the initial schema state for the application.

sql · high confidence

Introduction of a dedicated comment handling package

The application now organizes comment-related logic into a new \ru.org.linux.comment\ package. This introduces a \CommentRequest\ model to structure input data, a \CommentRequestValidator\ to enforce rules such as preventing empty messages and ensuring comments are not added to deleted or expired topics, and supporting classes like \CommentFilter\, \DeleteCommentResult\, and \ReplyInfo\ to manage filtering, deletion outcomes, and reply context.

src/main/java/ru/org/linux/comment · high confidence

Introduction of the Waltz theme

A new visual theme named 'Waltz' is now available, defined by a new set of SCSS files in the \src/main/webapp/sass/waltz\ directory. The theme establishes a distinct look and feel by introducing a dedicated color palette (including specific background, text, link, and button colors) and applying custom typography (using 'Open Sans' for headings and 'Arial' for body text). It also includes specific styling for UI components such as news entries, boxlets, and forum tables, utilizing CSS custom properties to manage the color scheme.

src/main/webapp/sass/waltz · high confidence

Markdown rendering engine rewritten in Scala with new content features

The markdown rendering engine in src/main/scala/ru/org/linux/util/markdown has been rewritten in Scala, introducing support for topic and comment links, user mentions, and fenced code blocks. Users can now use the \>\>\> and \<\<\< markers to create collapsible content cuts, while @mentions are automatically resolved to user profiles. The renderer also enforces security by suppressing dangerous link schemes and adding nofollow attributes to external links.

src/main/scala/ru/org/linux/util/markdown · high confidence

New CSRF protection mechanism

The application now includes a new package ru.org.linux.csrf containing a CSRFHandlerInterceptor, CSRFProtectionService, and CSRFNoAuto annotation. This introduces automatic CSRF token validation for POST requests, with the ability to disable it per method via the @CSRFNoAuto annotation. The service generates secure tokens stored in cookies and validated against form inputs, enhancing security against cross-site request forgery attacks.

src/main/java/ru/org/linux/csrf · high confidence

The site now includes dedicated JSP boxlet components for the Gallery, Polls, Tag Cloud, and Topic List sections. The Gallery boxlet displays images with lazy loading and responsive sizing, while the Poll boxlet integrates a voting form and result links, handling both single and multi-select options. The Tag Cloud boxlet renders clickable tags with weight-based styling, and the Topic List boxlet presents recent topics with pagination and comment counts. All boxlets are configured with session="false" and updated copyright headers.

src/main/webapp/WEB-INF/jsp/boxlets · high confidence

New JSP tag for rendering post tags with HTML escaping

A new \TagsTag\ JSP component has been added to render a list of tags associated with a post. It generates an HTML paragraph containing tag links (if URLs are available) or plain text spans, ensuring all tag names are HTML-escaped via \StringUtil.escapeHtml\ to prevent injection issues. When the \deletable\ flag is enabled, it also renders delete links for each tag.

src/main/scala/ru/org/linux/site/tags · high confidence

New JSP tag library for comments, polls, and reactions

The site now uses a new set of JSP tags in src/main/webapp/WEB-INF/tags to render comments, polls, and reactions. The comment.tag displays comments with proper deletion reasons, reply chains, and edit history, while commentForm.tag provides a unified form for posting and editing with markup help and lazy captcha support. Polls are rendered via poll.tag and poll-form.tag, showing results with percentages and handling unconfirmed polls. Reactions are managed through reactions.tag, allowing users to interact with and view reaction counts. Additional tags like captcha.tag, csrf.tag, and date.tag support security, validation, and date formatting across these components.

src/main/webapp/WEB-INF/tags · high confidence

New JSP tags for title formatting and userpic display

Added three new JSP custom tags to the site's tag library: \TitleTag\ for processing page titles using \StringUtil.processTitle\, \MakeTitleTag\ for formatting titles using \StringUtil.makeTitle\, and \TagUserpic\ for rendering user profile pictures with specific width and height attributes. These tags provide reusable components for consistent title handling and userpic presentation across JSP views.

src/main/java/ru/org/linux/site/tags · high confidence

New JSP templates for action results, activation, and topic submission

The web application now includes dedicated JSP views for key user workflows: action-done.jsp displays generic success messages with optional continuation links; activate.jsp provides a form for account activation (supporting both anonymous and logged-in users with CAPTCHA); add-done-moderated.jsp informs users when their post is in a protected section awaiting moderation; add-section.jsp allows users to select a forum section or group for posting; and add.jsp is the primary form for creating new topics, including preview, tag autocomplete, and limit checks.

src/main/webapp/WEB-INF/jsp · high confidence

New PagesInfo model for pagination data

Added a new PagesInfo class in the paginator package to encapsulate pagination state, including page links, current page index, and previous/next navigation URLs. This model provides a structured way to represent pagination information, separating the data logic from view rendering.

src/main/java/ru/org/linux/paginator · high confidence

New Scala-based edit history controller for topics and comments

A new EditHistoryController has been added in Scala to handle edit history views for topics and comments across news, forum, gallery, polls, and articles sections. The controller enforces view permissions before displaying edit histories and restricts the ability to restore edits to topics only (comments show canRestore=false). It also integrates group and user services to resolve context and permissions.

src/main/scala/ru/org/linux/edithistory · high confidence

New SpringDB integration layer for ScalikeJDBC

A new SpringDB component has been added to bridge Spring JDBC sessions with ScalikeJDBC, providing run and localTx methods to execute database operations within existing Spring transaction contexts. This includes support for HStore data types and proper exception unwrapping for UndeclaredThrowableException.

src/main/scala/ru/org/linux/scalikejdbc · high confidence

New Zomg Ponies theme with CSS custom properties

A new 'Zomg Ponies' visual theme has been added to the web application. The theme defines its color palette and layout styles using CSS custom properties (variables) scoped to the :root element, allowing for consistent styling across components like the header, articles, tables, and syntax highlighting. The theme includes specific styling for the main background, navigation, and notification badges, and is wired up via a new main.scss entry point that imports the color definitions, reset, common styles, and theme-specific styles.

_src/main/webapp/sass/zomg\ponies · high confidence

A new GalleryBoxlet controller has been added to the application, exposing the /gallery.boxlet endpoint to render a view of recent gallery items. This component integrates with the ImageService to fetch and prepare a list of up to three gallery items, which are then passed to the boxlet view for display, effectively introducing a new UI widget for showcasing gallery content.

src/main/java/ru/org/linux/gallery · high confidence

New help page controller with Markdown rendering

A new HelpController has been introduced to serve help pages located in the /help directory. It maps URL paths like /help/{page} to specific Markdown files (such as lorcode.md, markdown.md, and rules.md) and renders their content into HTML using the MarkdownFormatter service. This replaces the previous static JSP-based approach with a dynamic controller that supports custom 404 handling for missing pages.

src/main/scala/ru/org/linux/help · high confidence

New reaction management and viewing features

Users can now add reactions to topics and comments via new controller endpoints, with rate limiting applied to prevent excessive usage. A dedicated 'My Reactions' page allows users to view their own activity, while moderators can view reactions on other users' content. The feature includes support for viewing reactions directed at a specific user ('reactions on me') and handles visibility rules for deleted content.

src/main/scala/ru/org/linux/reaction · high confidence

New static 502 error page added

A new static HTML page (502.html) has been added to the /qrerror directory to handle 502 Bad Gateway errors. This page displays a localized error message in Russian and English, includes the site's navigation menu, and links to the forum rules via a .md file. It also retains the legacy Google Analytics tracking script.

src/main/webapp/qrerror · high confidence

New theme and API metadata classes introduced

The site now includes new Java classes to support theming and API responses. The Theme class defines available visual themes (including tango, tango-light, tango-auto, black, white2, waltz, and zomg\_ponies) with support for deprecation flags, while the Template class provides JSP-accessible helpers to retrieve the current user's theme, format mode, and authorization status. Additionally, the ApiDeleteInfo class has been added to structure deletion metadata returned by the API, containing the user's nickname and the reason for deletion.

src/main/java/ru/org/linux/site · high confidence

New warning notification system for moderators and correctors

This change introduces a new warning system allowing authorized moderators and correctors to issue warnings to users for specific violations. The system supports multiple warning types (Rule, Group, Tags, Spelling) and can be applied to either a topic or a specific comment. Moderators and correctors are notified of new warnings, and the system enforces a rate limit of five warnings per hour per moderator to prevent abuse. The implementation includes a new Spring MVC controller, service layer, and data access objects using ScalikeJDBC, along with a new database table for storing warning records.

src/main/scala/ru/org/linux/warning · high confidence

Project initialization with Apache 2.0 license, Scala 3 tooling, and Maven wrapper

The repository is initialized with foundational project files: an Apache License 2.0 header, a comprehensive development guide (AGENTS.md) specifying a Java 25 + Scala 3.9 stack with Maven builds, and a \.scalafmt.conf\ enforcing Scala 3 formatting rules. A Maven wrapper (\mvnw\) is added to ensure consistent build environments, and an \install\_www\ script is provided for production deployment to Tomcat. Additionally, \.gitattributes\ is configured to treat \.less\ files as text, and \.gitignore\ is set up to exclude IDE and build artifacts.

(repo-wide) · high confidence

Tag management request model introduced

A new TagRequest class has been added to the tag package to structure data for tag operations. It defines nested Change and Delete models, where the Delete model specifically includes a createSynonym flag to support creating synonyms when a tag is removed, enabling the backend to handle tag renaming and synonym creation workflows.

src/main/java/ru/org/linux/tag · high confidence

Tango theme now supports automatic and manual dark mode

The Tango skin has been refactored to support both light and dark color schemes. A new 'auto' variant automatically switches between light and dark modes based on the user's system preference, while explicit 'light' and 'dark' variants allow for manual selection. This is achieved by extracting color definitions into CSS custom properties and using Sass mixins to apply the appropriate palette, ensuring consistent styling across the interface regardless of the active theme.

src/main/webapp/sass/tango · high confidence

Security

Security hardening and utility improvements in site utilities

This change introduces several security and robustness improvements to the site's utility layer. A new BinderControllerAdvice restricts Spring MVC data binding to prevent object injection attacks by disallowing specific class-related field patterns. Password generation now utilizes SecureRandom for better cryptographic strength, and activation/reset codes have been upgraded from MD5 to SHA-256 with backward-compatible verification. Additionally, the URL parsing logic (LorURL) has been hardened to handle unparseable IDs gracefully without crashing, and invalid XML characters are now stripped from RSS feeds to ensure data integrity.

src/main/java/ru/org/linux/util · high confidence

Architecture

Refactored frontend JavaScript into modular components

The monolithic \lor.js\ file has been split into distinct modules within the \src/main/webapp/js/lor/\ directory (including \ads.js\, \forms.js\, \notifications.js\, \reactions.js\, \theme.js\, and others) to improve code organization and maintainability. This refactoring preserves existing functionality, such as AJAX-based form submissions, notification handling, and theme switching, while preparing the codebase for modular bundling.

src/main/webapp/js/lor · high confidence

Behavioural changes

14 commits (1 fix) modifying src/main/webapp/tango/img

A change to existing behaviour in src/main/webapp/tango/img — 14 commits (1 fix), 43 files.

src/main/webapp/tango/img · medium confidence · unverified

Auth module migrated to Scala with enhanced security controls

The authentication and authorization components in src/main/scala/ru/org/linux/auth have been rewritten in Scala, introducing stricter access enforcement and modern security standards. User profile images (userpics) are now restricted so that only the owner or moderators can view non-current versions, while gallery images are gated by topic-level view permissions. Login security has been improved with a 30-minute attempt cache that triggers CAPTCHA on repeated failures, and logout now explicitly clears CSRF and session cookies. Security headers including HSTS and a tightened Content Security Policy are enforced via the new HSTS interceptor, and password handling has shifted to bcrypt with a legacy Jasypt fallback to ensure compatibility during migration.

src/main/scala/ru/org/linux/auth · high confidence

Black theme header layout and navigation overhaul

The black theme's header has been redesigned with two new JSP templates (head-main.jsp and head.jsp) that introduce a mobile-friendly viewport meta tag, update the site logo, and restructure the navigation menu. The new layout includes a dedicated 'Articles' section, moves the 'About' link to '/about', and adjusts the user authentication UI (login/register links) to align with the updated visual style.

src/main/webapp/WEB-INF/jsp/black · high confidence

Black theme refactored to use CSS custom properties

The Black theme's styling has been restructured to replace hardcoded SASS color variables with CSS custom properties (e.g., --text-color, --main-background). This change centralizes color definitions in a new \_colors.scss file and updates the theme's style rules to reference these variables, ensuring consistent theming and easier maintenance of the visual appearance.

src/main/webapp/sass/black, src/main/webapp/sass/white2 · high confidence

Centralized exception handling with secure error reporting

The application now uses a centralized ExceptionResolver to manage error pages and HTTP status codes. This change ensures that unexpected server errors return a proper 500 status instead of 200, and prevents sensitive exception details from being displayed to users by showing a generic 'internal server error' message for unhandled exceptions. Additionally, unexpected errors are automatically reported via email, while specific exceptions like script errors or rejected requests are logged and handled with appropriate user-facing messages.

src/main/java/ru/org/linux/exception · high confidence

Comment system logic migrated to Scala

The core comment handling logic—including creation, reading, editing, deletion, and cleanup—has been rewritten from Java to Scala. This migration introduces new administrative tools for bulk deletion by IP address and finding users by IP, adds a scheduled job to permanently purge old deleted comments from inactive users, and implements a new interface for viewing deleted comments.

src/main/scala/ru/org/linux/comment · high confidence

Database schema migrations for forum features and performance

This update applies a series of Liquibase database migrations to the schema. It introduces new tables and columns to support user tags, comment edit history, image management, and user remarks, while adding indexes to optimize tag search and topic loading. The changes also include refactoring group statistics by removing unused columns, updating stored procedures for better performance, and adjusting permissions for wiki and moderation roles.

sql/updates · high confidence

Email notifications now include login alerts and use HTTPS

Users will now receive an email notification when a new login is detected on their account, adding a security layer to the existing registration and password-reset emails. Additionally, all email links and the sender address have been migrated to HTTPS, ensuring secure communication for account activation and password recovery actions.

src/main/scala/ru/org/linux/email · high confidence

The gallery image handling logic has been migrated from Java to Scala, introducing a more robust lifecycle for image files. Users will see that deleting an image now properly records the action in the edit history and updates the topic's modification timestamp. Additionally, the system now enforces stricter validation on uploaded images (rejecting those that are too narrow or wide) and automatically purges physical files for images associated with deleted topics or soft-deleted images older than three years, ensuring disk space is reclaimed efficiently.

src/main/scala/ru/org/linux/gallery · high confidence

Group module migrated to Scala with tag filtering and caching

The group-related controllers, services, and data access objects have been rewritten in Scala. This migration introduces a Caffeine-based cache for group lookups to improve performance and adds the ability to filter forum topics by tags, including handling 404 errors for non-existent tags. Additionally, group information rendering now supports Markdown formatting for long descriptions, and URL name validation has been strengthened to prevent invalid characters.

src/main/scala/ru/org/linux/group · high confidence

HTTP firewall and image access control updates

The application now uses a StrictHttpFirewall that allows all header values, relaxing previous restrictions on HTTP headers. Additionally, image and gallery resource access is now protected by new permission interceptors (GalleryPermissionInterceptor and UserpicPermissionInterceptor) that enforce access rules based on user, topic, and group permissions, while also integrating an Akka-based actor for advertising counter tracking.

src/main/scala/ru/org/linux · high confidence

Introduction of dedicated request models for user registration and profile editing

The user module now uses specific request data classes to handle input for account creation and profile updates. A new \RegisterRequest\ class manages registration fields (email, nickname, password, and rules acceptance), while a new \EditProfileRequest\ class handles profile update fields (email, name, URL, town, bio, nickname, and password changes). Additionally, \UserConstants\ defines shared configuration such as the maximum nickname length (19 characters) and the anonymous user ID.

src/main/java/ru/org/linux/user · high confidence

Logging configuration updated for Pekko migration and debug control

The application now uses a new logging setup in src/main/resources to support the migration from Akka to Pekko and to refine log verbosity. A new application.conf sets Pekko's log level to DEBUG, while log4j2.xml introduces two rolling file appenders (lor-new.log and lor-debug-new.log) with 100 MB size-based rotation. Specific loggers are tuned: Spring, Apache HTTP, and HikariCP are set to INFO, while authentication token generation is set to DEBUG and WebSocket handshake logs are suppressed. The root logger remains at DEBUG, directing general output to the debug file and INFO-level output to the main log file.

src/main/resources · high confidence

LorCodeService migrated to Scala 3 with enum-based mode handling

The LorCodeService implementation in the bbcode utility package has been rewritten in Scala 3. This change introduces a new \Mode\ enum (Plain, Ulb, Lorcode) to control text preparation logic, replacing previous implementation details. The service now explicitly handles different formatting modes for comments and topics, ensuring consistent HTML rendering and plain text extraction based on the selected mode.

src/main/scala/ru/org/linux/util/bbcode · high confidence

Migrate actor infrastructure from Akka to Apache Pekko

The application's actor system has been replaced with Apache Pekko, a community-driven fork of Akka. This change is implemented via a new \PekkoConfiguration\ class that initializes the \ActorSystem\ and \Scheduler\ as Spring beans, and updates actor implementations (such as the advertisement counter) to use the Pekko API. This migration ensures the platform remains on a supported actor framework while maintaining existing asynchronous processing behaviors.

repository · high confidence

Migrate core site components and error handling to Scala

This change moves several core site components from Java to Scala, including the date formatting logic (DateFormats), user profile defaults (DefaultProfile), and HTTP error controllers (HttpErrorController). It also introduces new Scala-based exception classes (BadInputException, BadParameterException, MessageNotFoundException, MissingParameterException, ScriptErrorException) to replace previous Java implementations. For users, this ensures consistent date formatting using java.time and Moscow time zone, maintains existing profile settings (with Tango theme as default), and preserves standard error handling for missing messages or bad inputs, while improving internal code maintainability through Scala 3 syntax.

src/main/scala/ru/org/linux/site · high confidence

Migrate message and user-agent data access to ScalikeJDBC

The data access layer for message content and user agents in the message base module has been rewritten to use ScalikeJDBC instead of the previous Spring JDBC approach. This change updates MsgbaseDao and UserAgentDao to leverage ScalikeJDBC's SQL interpolation and result mapping, while still operating within Spring-managed database sessions via the SpringDB wrapper. For users, this ensures consistent transactional behavior and potentially improved performance for message retrieval and user-agent tracking operations.

src/main/scala/ru/org/linux/msgbase · high confidence

Migrate section management logic to Scala

The section management components (controller, service, DAO, and enums) have been rewritten from Java to Scala. This migration introduces lazy initialization for section data lookups to defer database access until needed, replaces the legacy JdbcTemplate with scalikejdbc for database operations, and updates exception handling to use Scala-specific error classes. Users will see no functional change, but the underlying implementation is now more idiomatic and maintainable within the Scala ecosystem.

src/main/scala/ru/org/linux/section · high confidence

The utility package has been rewritten in Scala, introducing new exception classes such as BadDateException, BadImageException, and ServletParameterException to replace previous Java implementations. This change also adds a new URL utility (URLUtil) that includes a strict validation mechanism for links, explicitly blocking dangerous schemes like javascript:, data:, and vbscript: to prevent security issues in markdown rendering, alongside helper methods for URL normalization and host extraction.

src/main/scala/ru/org/linux/util · high confidence

Migrated advertising counter to Pekko and ScalikeJDBC

The advertising counter implementation has been refactored to use the Pekko actor system instead of Akka for handling count updates, and the data access layer now uses ScalikeJDBC via a new AdvCounterDao. This change introduces an AdvCounterInterceptor that sends count messages to the actor, replacing the previous synchronous database operations with an asynchronous, buffered approach.

src/main/scala/ru/org/linux/adv · high confidence

Migrated boxlet controllers to Scala

The ArticlesBoxlet and TopTenBoxlet controllers have been rewritten from Java to Scala. This change updates the implementation of the articles column and the top 10 topics list on the main page to use Scala syntax and Spring annotations, while preserving the existing user-facing behavior for displaying these content lists.

src/main/scala/ru/org/linux/boxlets · high confidence

Migrated exception handling and scheduled task error reporting to Scala with Pekko integration

The exception handling infrastructure has been rewritten in Scala, introducing a new ExceptionController to route request-level errors and an ExceptionHandlingConfiguration that registers a task scheduler. This configuration now leverages the Pekko actor system (via ActorSystem) to send detailed error reports for failed periodic tasks, ensuring that scheduled job failures are logged and reported through the exception mailing actor rather than being silently ignored or handled by legacy mechanisms.

src/main/scala/ru/org/linux/exception · high confidence

Migration of Spring configuration and controllers to Scala

The application's Spring configuration layer and several key controllers have been rewritten from Java to Scala. This includes the introduction of a Circe-based JSON message converter for handling @ResponseBody serialization, the migration of the main page logic to display a curated list of news items, and the porting of server info and site configuration services. These changes modernize the codebase while maintaining existing functionality for user-facing features like the homepage layout and site settings.

src/main/scala/ru/org/linux/spring · high confidence

Migration to Jakarta EE 6.1 and Spring Security stateless authentication

The application has been upgraded to the Jakarta EE 6.1 web profile, replacing the legacy Servlet 2.5 specification. This migration introduces stateless session management for security, meaning user sessions are no longer stored server-side, and updates the security configuration to use a custom authentication entry point and a generation-based token for 'remember me' functionality. Additionally, the deployment descriptor now explicitly defines error pages for 404 and 403 statuses, configures a standard servlet multipart resolver for file uploads, and registers interceptors for performance monitoring, CSRF protection, and HTTP Strict Transport Security (HSTS).

src/main/webapp/WEB-INF · high confidence

Migration to Spring Security 6 authentication components

The authentication module has been updated to support Spring Security 6, introducing new implementation classes for core security functions. This includes a custom AuthenticationEntryPoint, a UserDetailsImpl that wraps user and profile data, and a GenerationBasedTokenRememberMeServices that utilizes SHA-256 for token signatures and supports session invalidation via token generation tracking.

src/main/java/ru/org/linux/auth · high confidence

Modernized comment forms with live preview and upgraded syntax highlighting

The comment and topic submission experience is improved with a new \add-form.js\ module that introduces a tabbed Editor/Preview interface, keyboard accessibility for switching tabs, and a spinner with button disabling during submission. A warning is now shown if the user attempts to leave the page with unsaved changes. Syntax highlighting for code blocks has been updated to Highlight.js v11.12.0, and the tag autocomplete feature now uses the \autoComplete.js\ library instead of the deprecated jQuery UI autocomplete.

src/main/webapp/js · high confidence

New IntelliJ IDEA-style syntax highlighting and Tango icon integration

The white2 theme now includes a new CSS stylesheet that applies an IntelliJ IDEA-inspired color scheme to syntax-highlighted code blocks, and it switches the theme's icon set to use Tango icons via a new symbolic link in the img directory.

src/main/webapp/white2 · high confidence

New Tango site header with mobile-responsive navigation and notification badge

The tango theme now uses a new head-main.jsp component that renders a responsive header layout. This includes a mobile-friendly viewport meta tag, a notification bell icon that displays an unread count badge when events exist, and a user profile link using an icon instead of text. The navigation menu has been reorganized to include Articles and Polls sections, with registration and login links appearing for unauthenticated users. The header also implements session=false for better performance and includes a flush call to ensure proper HTML head output.

src/main/webapp/WEB-INF/jsp/tango · high confidence

New site header with pony-themed branding and updated navigation

The site header has been replaced with a new layout featuring a 'PONY.ORG.RU' logo (using twilight\_logo.png) and an updated navigation menu that includes a link to the 'Articles' section (/articles/) while removing the 'Wiki' link. The header now displays a personalized greeting for logged-in users and provides registration/login links for guests, all within a session-less JSP template.

_src/main/webapp/WEB-INF/jsp/zomg\ponies · high confidence

New syntax highlighting theme for code blocks

A new CSS stylesheet (syntax.css) has been added to the Waltz web application, providing an IntelliJ Idea-like visual style for syntax-highlighted code. This change updates the appearance of code snippets to use specific colors for keywords, strings, comments, and other elements, improving readability and consistency with the IntelliJ aesthetic.

src/main/webapp/waltz · high confidence

New web server configuration and SEO files added

The webapp root now includes an .htaccess file that configures custom 404 error pages, redirects legacy info and RSS URLs, rewrites profile paths, and sets one-week caching for images. A robots.txt file has been added to disallow crawling of administrative, editing, and API endpoints (such as /edit.jsp, /api/, /reactions, and /people/\*/settings). Additionally, a Google site verification file and a manifest.json for Yandex Tableau integration have been introduced.

src/main/webapp · high confidence

Poll voting logic now rejects votes for unconfirmed or expired polls

The VoteController in the poll module now explicitly validates poll status before accepting votes. Users can no longer vote in polls that have not yet been confirmed by moderators (throwing a BadVoteException) or polls that have expired. This behavioral change ensures that voting is only permitted for active, confirmed polls, addressing previous issues where votes could be cast in invalid states.

src/main/scala/ru/org/linux/poll · high confidence

Redesigned white2 header with SVG logo and updated navigation

The white2 theme's main header component has been replaced with a new layout that features the Tux penguin logo as an SVG image in the top-left corner. The navigation menu now includes a dedicated 'Articles' section, and the user greeting logic has been updated to display a welcome message with a profile link for authorized users, while unauthenticated users see registration and login links. The layout uses a clearfix div to ensure proper rendering of the floated elements.

src/main/webapp/WEB-INF/jsp/white2 · high confidence

Refactored BBCode parser to use configurable parameters and immutable tag definitions

The BBCode parsing logic has been restructured to separate parser configuration from the core engine. A new \ParserParameters\ interface and \DefaultParserParameters\ implementation now define tag behaviors (such as inline vs. block-level, allowed list parameters, and auto-linking contexts) using Guava's \ImmutableSet\ and \ImmutableMap\. The \Parser\ class now accepts these parameters, allowing for more modular and thread-safe tag processing. This change also introduces \NodeUtils\ for node inspection and standardizes the handling of paragraph breaks and tag nesting rules within the LORCODE-to-HTML conversion.

src/main/java/ru/org/linux/util/bbcode · high confidence

Refactored BBCode tag rendering into dedicated classes

The BBCode rendering logic has been restructured from a monolithic implementation into individual classes for each tag (such as CodeTag, CutTag, QuoteTag, and UrlTag). This change introduces a new Tag base class and specific renderers that handle HTML generation, syntax highlighting language mapping, and parameter processing. Users will see improved handling of code blocks with expanded language support, more robust quote formatting, and updated link rendering logic, all while maintaining backward compatibility with existing content.

src/main/java/ru/org/linux/util/bbcode/tags · high confidence

Refactored LORCODE parser and added search indexing queue support

The LORCODE parsing engine has been refactored to use a new class-based node structure (TagNode, TextNode, HtmlEquivTag) that improves how tags are rendered to XHTML, BBCode, and Open Graph formats, including fixes for attribute iteration and handling of self-closing tags. Additionally, a new SearchQueueSender component has been introduced to manage asynchronous search re-indexing tasks via JMS, supporting granular updates for messages, comments, and monthly batches with configurable priority levels.

lor · high confidence

Refactored LORCODE parser into a node-based tree structure

The LORCODE parsing engine has been restructured from a flat processing model into a hierarchical node tree, introducing new classes in the \ru.org.linux.util.bbcode.nodes\ package. \Node\ serves as the base class for the parse tree, \RootNode\ manages parser context (such as cut options, RSS mode, and nofollow link attributes), and \TextCodeNode\ handles code block rendering. This change enables more robust handling of nested tags, consistent HTML escaping within code blocks, and better support for generating Open Graph metadata and RSS excerpts by traversing the node structure rather than relying on static, stateful parsing logic.

src/main/java/ru/org/linux/util/bbcode/nodes · high confidence

Refactored boxlet architecture to use Spring MVC controllers

The boxlet system has been restructured to leverage Spring MVC, introducing an abstract base controller that standardizes request handling and edit-mode detection. Specific boxlets, such as the Tag Cloud, are now implemented as annotated Spring controllers, allowing for cleaner separation of concerns and easier integration with the Spring framework.

src/main/java/ru/org/linux/boxlets · high confidence

Refactored image processing with APNG support and transparency handling

The image utility module has been refactored to introduce new classes (ImageInfo, ImageParam, ImageUtil) that replace previous ad-hoc parsing. This change adds support for validating animated PNG (APNG) avatars and ensures that transparency is removed from preview images before saving as JPEG, preventing potential rendering or compatibility issues with OpenJDK.

src/main/java/ru/org/linux/util/image · high confidence

Refactored text formatting with dedicated typo and code-handling components

The monolithic HTML formatter has been split into specialized components to improve maintainability and fix specific text-rendering issues. A new RuTypoChanger class now handles Russian typography, converting straight quotes to proper guillemets (« ») and double hyphens to em-dashes. ToHtmlFormatter has been updated to integrate this typographic correction and includes a fix to prevent stack exhaustion (ReDoS) when processing very long URL tokens by enforcing a maximum token length. Additionally, ToLorCodeTexFormatter now correctly manages code block escaping and quote nesting levels, ensuring that \[code\] tags and quoted text are preserved accurately when converting to the internal LorCode format.

src/main/java/ru/org/linux/util/formatter · high confidence

Restored legacy header layout for Waltz pages

The Waltz section now uses a restored, older header design (head-main.jsp) instead of the previous theme files. This change reverts the visual structure of the site header, affecting navigation links, user profile display, and login prompts specifically within the Waltz area.

src/main/webapp/WEB-INF/jsp/waltz · high confidence

Restructured permission checks with detailed restriction reasons

The permission logic in the rights module has been refactored to use a unified, composable restriction chain model. New checkers (AddCommentChecker, AddTopicChecker, EditTopicChecker, EditProfileChecker, TopicPublishChecker) and updated utilities (FrozenUserChecker, IpBlockChecker, PostScoreChecker, SlowModeChecker) now enforce posting, editing, and profile rules by chaining specific restrictions. This change provides users with precise, human-readable reasons for access denials (e.g., 'topic deleted', 'score too low', 'IP blocked') instead of generic errors, and centralizes complex logic like score-based restrictions, IP blocking, and moderation cooldowns into these dedicated services.

src/main/scala/ru/org/linux/rights · high confidence

Same-IP detection now filters by user score and merges topics with comments

The Same-IP feature has been rewritten in Scala and migrated to ScalikeJDBC, introducing a new filtering capability that allows restricting results to users below a specific reputation score. Additionally, the view now presents topics and comments from the same IP address in a single, unified list rather than separate sections, and the time window for detecting recent activity has been extended from three days to five days.

src/main/scala/ru/org/linux/sameip · high confidence

Sass stylesheets migrated to modern module syntax and CSS Grid layouts

The site's styling has been refactored from legacy CSS/Sass into a modular Sass architecture using @use imports, replacing older @import patterns. This change introduces CSS Grid layouts for the main page, tag pages, and tracker, replacing previous float or table-based structures. Additionally, the autocomplete widget now has dedicated styling, and the fontello icon set has been updated to include new icons such as Telegram and tag symbols.

src/main/webapp/sass · high confidence

Search backend migrated from Elasticsearch to OpenSearch

The search infrastructure has been replaced with OpenSearch, introducing new Scala-based services (OpenSearchConfiguration, OpenSearchIndexService, OpenSearchIndexCreationService) and a dedicated index schema (MessageIndex) with custom analyzers for Russian and English. This change updates the search client, index creation, and bulk indexing logic to use the OpenSearch Java client, while preserving existing search features like faceting, highlighting, and sorting.

src/main/scala/ru/org/linux/search · high confidence

Slow request logging threshold reduced to 250ms with view timing

The monitoring interceptor in the Scala codebase now logs slow requests when they exceed 250ms, down from the previous 300ms threshold. It also distinguishes between controller execution time and view preparation time, logging warnings for each if they individually exceed the threshold, and ignores slow requests during the first 2 minutes of application startup.

src/main/scala/ru/org/linux/monitoring · high confidence

Standardized error pages with improved security and consistent branding

Error pages (403, 404, 410, bad-parameter, upload-size, user-banned) have been moved to a dedicated errors subdirectory and redesigned with a unified layout featuring the 'good-penguin' branding. Security is improved by enforcing session=false on all error JSPs and using proper HTML escaping (c:out with escapeXml=true) to prevent XSS, particularly in the 403 Forbidden page. The user-banned page now uses a custom date tag for formatting, and the upload-size error includes a functional 'back' link.

src/main/webapp/WEB-INF/jsp/errors · high confidence

Tag management module migrated to Scala

The tag management functionality—including the tag cloud, tag listing, tag page display, and tag modification services—has been rewritten from Java to Scala. This migration introduces support for tag synonyms (allowing aliases for existing tags), updates the tag validation logic to permit single-character tags and enforce a 32-character maximum length, and implements automatic cleanup of unused favorite tags. The change also replaces the underlying database access layer with ScalikeJDBC and updates the tag counter recalculation to run on a scheduled basis.

src/main/scala/ru/org/linux/tag · high confidence

Topic management logic migrated to Scala

The core topic management components in the forum and news sections have been rewritten from Java to Scala. This includes the controllers for adding, editing, deleting, and viewing topics (AddTopicController, EditTopicController, DeleteTopicController, TopicController), the underlying data access layer (TopicDao), and the request validation models (AddTopicRequest, EditTopicRequest). The migration introduces Scala-specific patterns such as case classes, sealed traits, and ScalikeJDBC for database interactions, while preserving the existing user-facing functionality for topic creation, modification, and deletion.

src/main/scala/ru/org/linux/topic · high confidence

Tracker view refactored to use new Scala controller and filter enum

The tracker module has been updated to use a new Scala-based \TrackerController\ and \TrackerFilterEnum\, replacing the previous Java implementation. This change introduces a new tracker view (\tracker-new\) and standardizes filter handling (all, main, notalks, tech) via a Scala 3 enum. The controller now handles URL redirections for legacy paths, manages pagination with offset limits, and exposes moderator-specific data (such as blocked IPs and user statuses) only to authorized moderators, while regular users see an empty set for these fields.

src/main/scala/ru/org/linux/tracker · high confidence

Unified markup rendering and HTML sanitization

The system now centralizes text rendering for Markdown, LORCODE, and HTML through a new MessageTextService, ensuring consistent behavior across comments and topics. A key change for users is that HTML content is now sanitized via Jsoup during rendering, stripping out dangerous elements like scripts while preserving safe formatting, which enhances security without breaking existing posts. Additionally, the markup type is now managed via a strict enum, and features like autolinking and nofollow attributes are applied uniformly across all supported markup styles.

src/main/scala/ru/org/linux/markup · high confidence

Updated list of post deletion reasons

The system's predefined list of reasons for deleting posts has been updated. Notably, the reason previously referred to as 'Offtopic' is now labeled 'Офтопик' (Offtopic), and additional rule-based deletion options have been added to the available choices for moderators.

src/main/scala/ru/org/linux/common · high confidence

User management and profile features migrated to Scala

The user-facing components for account management, including registration, profile editing, settings, password recovery, account deregistration, and user remarks, have been rewritten in Scala. This migration introduces stricter validation for profile fields (such as email and URL formats), enforces minimum password lengths, and updates the underlying data access layer to use ScalikeJDBC. Users will experience these changes through the existing profile and settings interfaces, which now rely on the new Scala-based controllers and validators.

src/main/scala/ru/org/linux/user · high confidence

Test coverage

Added Scala MUnit tests for Markdown link security; Added Scala tests for Section DAO and Service; Added Scala-based tests for gallery image management; Added Scala-based tests for group management components; Added Scala/MUnit tests for topic management and deletion logic; Added integration and unit tests for tag management; Added integration and unit tests for the Reaction DAO layer; Added integration tests for OpenSearch search functionality; Added integration tests for PollDao using Scala and Munit; Added integration, unit, and web tests for edit history functionality; Added test coverage for authentication components; Added test coverage for comment preview security, DAO operations, and cleanup logic; Added tests for exception handling and information leakage prevention; Added unit tests for CSRF protection service; Added unit tests for date formatting utilities; Added unit tests for the Help controller; Added unit tests for topic posting and editing permission checkers; Migrate bbcode and image utility tests to Scala MUnit; Migration of utility tests to Scala MUnit; Test infrastructure migrated to Scala and MUnit; User module tests migrated to Scala MUnit and ScalikeJDBC.

Dependencies

Added Maven Wrapper configuration

The project now includes a Maven Wrapper configuration file (.mvn/wrapper/maven-wrapper.properties) that pins the build to Maven version 3.9.13. This ensures that all developers and CI environments use the same specific Maven distribution, improving build consistency and reproducibility across different setups.

.mvn · high confidence

Major dependency upgrades and framework migration

The project's build configuration has been updated to use Java 25 and Scala 3.9.0, with the Akka actor library replaced by Apache Pekko 1.7.0. Spring Framework and Spring Security have been upgraded to versions 6.2.19 and 6.5.11 respectively, and the PostgreSQL JDBC driver is set to 42.7.13. Other significant updates include Log4j 2.26.1, Jackson 2.22.2, Guava 33.7.1, and the addition of Scalikejdbc 4.3.5 for database access.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 47.

Lenses

  • Code Health 42
  • Architecture 93
  • Maturity 63
  • Readiness 36
  • Security 83
  • Accessibility 70

Changes since last survey

  • 300 commits — 284 feature/other, 16 fixes

By area

  • src/main — 243 commits
  • (root) — 25 commits
  • src/test — 25 commits
  • sql/updates — 4 commits
  • deploy/server.xml — 2 commits
  • .github/workflows — 1 commit

Notable commits

  • fix: Fix CommentWebTest: delete comment before topic cleanup
  • fix: Fix MAVEN_BUILD_TIMESTAMP substitution in JSP files
  • fix: Fix MemoriesDaoIntegrationTest: use dynamic topic ID from DB instead of hardcoded value
  • fix: Fix NPE in getDeletedComments when comment deleted with topic, not individually
  • fix: Fix form model attributes in GET controllers
  • fix: Fix hCaptcha render=explicit race condition in dynamic comment form
  • fix: Fix testAddDuplicateIsNoop: use relative assertions to avoid data dependency
  • fix: Revert "css: drop widedesktop scaling"
  • fix: fix StatUpdater sql call
  • fix: fix broken tests
  • fix: fix build
  • fix: fix emoji title
  • fix: fix: TagNotFoundException как RuntimeException, unwrap UndeclaredThrowableException, lock tags_values FOR UPDATE
  • fix: poll images - fix build
  • fix: test: fix compile warning
  • fix: Поэтапная миграция spring-jdbc на scalikejdbc - scalikejdbc в зависимостях - SpringDB.run запускающий scalikejdbc внутри Spring JDBC сеансов - Rewrite IPBlockDao using scalikejdbc with code cleanup - Add IPBlockDaoIntegrationTest - Migrate SectionDao, TagCloudDao, ArchiveDao, BoxletTopicDao, UserAgentDao to scalikejdbc - Make SectionService (sections, nameToSection, idToSection, fuzzyNameToSection), TagService (sectionForum, NonTechNames) lazy val to defer DB access past Spring init - Convert ImageDaoIntegrationTestConfiguration from Java to Scala - UserAgentDao: replace .get on Option with .getOrElse + descriptive exception - TagCloudDao: remove return keyword, use if/else; replace var minc with val + conditional; inline logCounter - ArchiveDao: unify two identical SQL branches using sqls for dynamic groupid clause - Fix race condition in IPBlockDao.blockIP: use INSERT ON CONFLICT instead of SELECT+INSERT/UPDATE
  • change: "лицо клоуна" -> "клоунада" (#1141)
  • change: "по причине: " в удаленных сообщениях
  • change: 1 год в HSTS заголовке
  • change: AES-GCM вместо Jasypt в SecretTokenService
  • …and 280 more

Architecture

  • 0 containers · 2 bounded contexts · 0 dependency edges (baseline)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

maxcom/lorsource was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 5701685e698232dd0a2696667f7277d469b7a629 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.