# @platform-modules/content

## 0.3.1

### Patch Changes

- @platform-modules/db@0.2.1
- @platform-modules/search@0.0.3

## 0.3.0

### Minor Changes

- a24b674: U4 hierarchical taxonomy — relational `content_terms` (self-FK parent, stored depth, COALESCE sibling-slug uniqueness) + `content_entry_terms` M:N join, replacing the flat jsonb `category`/`tag` columns on `content_entries` and `content_revisions` (revisions now snapshot `term_ids`).

  BREAKING (pre-1.0.0, no compat tax): `ContentEntry.taxonomy.{category,tag}` → `ContentEntry.terms: TermRef[]`; `ContentInput.taxonomy` → `ContentInput.termIds?: string[]`; `list()` `{category,tag}` filter → `{term, includeDescendants}`. New `./taxonomy` + `./taxonomy/migrate` subpaths: createTerm/updateTerm/moveTerm/deleteTerm/listTerms/assignTerms/termsForEntry, MAX_TERM_DEPTH=6, typed errors (TermConflict/TermCycle/TermHasChildren/TermNotFound/TermValidation), `contentTaxonomyMigrationSql`/`contentTaxonomyBackfillSql`.

  `moveTerm` requires a `TransactionalDatabase` (per-taxonomy advisory lock serializes concurrent reparents to prevent cycles) and is unavailable on `neon-http`; all other term ops run on `Querier`.

- 4ff8dca: Content revisions subpath (`@platform-modules/content/revisions`): append-only per-entry snapshot history with `snapshotRevision`, `listRevisions`, `getRevision`, `restoreRevision`, and `contentRevisionsMigrationSql`. FK cascade purges revisions on permanent delete.
- ba342c2: Add content full-text search provider (`createContentSearchProvider`), FTS migration SQL (`contentSearchMigrationSql`), and `ContentSearchCtx` for `@platform-modules/search` registry wiring.
- be159e4: content: trash/remove now require `canPublish` to take a LIVE (published/scheduled) entry offline — closes the take-offline bypass of `unpublish`'s authz. Non-live (draft/trashed) entries unchanged (canModify only). restore unchanged.

## 0.2.0

### Minor Changes

- e6db44b: Lifecycle axis: `promoteScheduled` runner (promote due scheduled entries — fixes scheduled posts never publishing) + `trash`/`restore` soft-delete (`'trashed'` status, excluded from default `list`). Zero-DDL.

## 0.1.0

### Minor Changes

- d323ab5: Add the visibility/access read-authz axis (`public` | `private` | `members`) enforced in SQL at the store seam.

  **BREAKING (0.x minor convention):** `list` and `getBySlug` gain an optional `viewer?: Actor | null` parameter before `opts`. Anonymous/missing viewers now see only `status='published' AND visibility='public'` — admin draft lists must pass a `canEditAny` viewer. `ContentEntry` gains `visibility`. New exports: `setVisibility`, `contentVisibilityMigrationSql`, `ContentVisibility` type. `Actor` gains optional `canViewMembers`.

- 5cd9136: W2 capability extensions — three new subpaths on `@platform-modules/content`:

  - `./settings` — typed KV site-options store (`createDbSettingsStore`, `settingsTableSql`, `SETTINGS_KEYS`, `SettingsValidationError`, `settingsSchema`). Prototype-pollution floor: rejects `__proto__`/`constructor`/`prototype` keys; null-proto result objects; 256-char key cap; parse-tolerant reads.
  - `./privacy` — consent parser + policy generator (`parseConsent`, `generatePrivacyPolicy`, `defaultConsent`). `parseConsent` forces `categories.necessary:true` even when the attacker-controlled blob sets it false (trust boundary).
  - `./migrate` — backup-restore data half (`exportContent`, `importContent`, `ContentArchive`, `ContentMigrateError`). **Admin-gated AT THE SEAM:** export requires `actor.canEditAny` (fail-closed full dump — info-disclosure floor); import requires `actor.canEditAny && actor.canPublish` (writes published state — closes force-publish-via-restore escalation). Restore validates + sanitizes each entry (XSS floor); `replace` mode requires a `TransactionalDatabase` (atomic delete+insert — data-loss floor); status-literal + UUID-id validation; DoS caps; generic error messages (no driver-error leak).

  - `getById(db, id, viewer?, opts?)` — new core read primitive (peer of `getBySlug`, keyed on the stable `content_entries.id` PK; first consumer: the mod-cms admin editor). Applies the IDENTICAL `visibilityPredicate(viewer)` in SQL → admin loads any status/visibility; a non-permitted viewer gets `null` with no existence oracle (read-authz info-disclosure floor, enforced in-store).

  Additive: `'read'` added to the `ContentAction` union (for the export authz error). No change to existing exports.

### Patch Changes

- Updated dependencies [f895518]
  - @platform-modules/db@0.2.0
