Conversation
- Delete _data/blogposts.yml, unused since the move to _posts/ (OpenIdentityPlatform#227) - Delete the "... copy.md" redirect post, which showed up as an empty card on /blog/page10/ and in sitemap.xml - Rename the OpenDJ 5.0.3 post to drop the space before .md (URL unchanged) - Use the HTTPS Twitter intent and Facebook sharer endpoints and URL-encode the shared link Fixes OpenIdentityPlatform#238
The button was wrapped in {% if page.image %}, which no page sets, so it
never rendered, and it passed an empty url. Render it when the page has
an imageurl and pass the page URL, the image and the title, URL-encoded.
maximthomas
left a comment
There was a problem hiding this comment.
praise: The cleanup removes only dead weight and every URL that is still live stays the same.
_data/blogposts.ymlhas no reader: at the base,site.datais used only forproducts,product_linksandvendors, and an org-wide code search finds no other consumer.- The rename keeps
/blog/2026-02-04-opendj-5-0-3-released: Jekyll 3.9.3's prettyUtils.slugifyturns the trailing space into-and then strips it (lib/jekyll/utils.rb:222). url_encodekeeps the new share URLs safe inside the single-quotedonclickstrings ('→%27,&→%26).
issue (non-blocking): The Pinterest button now appears on six OpenIDM posts whose imageurl file does not exist.
_includes/share-buttons.html:40, _posts/2024-09-10-openidm-ad-idm.md, _posts/2024-11-13-openidm-can-your-idm-play-chess.md, _posts/2025-05-13-openidm-two-way-ad-opendj.md, _posts/2025-07-16-openidm-6-3-0-released.md, _posts/2025-11-05-openidm-getting-started.md, _posts/2026-02-05-openidm-7-0-2-released.md
These posts set imageurl: 'openidm-og.png', but assets/img/ has only openidm-logo.png, and openidm-og.png has never been in the repository. The old page.image guard hid the button on these pages; the new guard shows it, so a click sends Pinterest media=…%2Fassets%2Fimg%2Fopenidm-og.png, which returns 404 on the live site (openidm-logo.png returns 200). The same missing file already breaks og:image (_includes/header.html:4) and the JSON-LD image (_includes/structured-data.html:120) on these pages.
# front matter of each of the six posts
imageurl: 'openidm-logo.png'Or: add assets/img/openidm-og.png, which fixes Pinterest, og:image and JSON-LD at once and keeps a proper preview image.
suggestion (non-blocking): Encode the LinkedIn share URL like the other three.
_includes/share-buttons.html:39
Line 39 still builds &url={{ site.url }}{{ pageurl }}, while Facebook, Twitter and Pinterest now pipe the URL through url_encode, and the description says the shared URL is URL-encoded. Post URLs contain only [A-Za-z0-9-], so nothing breaks today; a URL with &, # or ' would cut LinkedIn's url= or break the JS string.
onclick="window.open('https://www.linkedin.com/shareArticle?mini=true&url={{ site.url | append: pageurl | url_encode }}&title=&summary=&source=');"suggestion (non-blocking): Open the share windows with noopener.
_includes/share-buttons.html:37-40
All four window.open('…') calls pass no window features, so the Facebook, X, LinkedIn and Pinterest pages get window.opener and can navigate the openidentityplatform.org tab. The pattern predates this PR, but three of the four lines are rewritten here. noopener on its own does not request a popup, so the share page still opens in a tab.
onclick="window.open('https://twitter.com/intent/tweet?url={{ site.url | append: pageurl | url_encode }}', '_blank', 'noopener');"suggestion (non-blocking): No CI step checks the rendered share URLs.
.github/workflows/build.yml:19-30, _includes/share-buttons.html:37-40
The build runs jekyll build and htmlproofer --checks Links with every external https URL ignored, and html-proofer does not read onclick anyway. Dropping | url_encode, going back to twitter.com/home?status=, sharer.php → share.php, or a wrong /assets/img/ prefix all stay green; only a Liquid syntax error fails the build.
- name: Check share-button URLs
run: |
f=_site/blog/2025-12-18-openam-vs-keycloak.html
u='https%3A%2F%2Fwww.openidentityplatform.org%2Fblog%2F2025-12-18-openam-vs-keycloak'
grep -qF "https://www.facebook.com/sharer/sharer.php?u=$u'" "$f"
grep -qF "https://twitter.com/intent/tweet?url=$u'" "$f"
grep -qF "https://www.pinterest.com/pin/create/button/?url=$u&media=https%3A%2F%2Fwww.openidentityplatform.org%2Fassets%2Fimg%2Fopenam-og.png&description=OpenAM+vs+Keycloak'" "$f"Pin: each grep -qF fails the step under Actions' bash -e unless its URL is rendered exactly this way, which kills the url_encode, endpoint and image-prefix mutants.
## Summary > **Merge after #244** — 20 OpenIDM posts point at `openidm-og.png`, which #244 adds. - **Logo strip → OG card (28 posts)** — `imageurl` switched from the ~700×172 `*-logo.png` to the matching 1024×512 `*-og.png`: OpenIDM 12, OpenDJ 9, OpenAM 6, OpenIG 1. - **Product posts without an image (21 posts)** — each gets its product's card: the first entry of `products:`, or the product in the file name for posts without `products:` (OpenAM JEE agents, OpenIDM 7.0.1 / 7.1.0). - **General articles (6 posts)** — a new `assets/img/oip-og.png`, built from `oip-star.png` on a white 1024×512 canvas, for `stateless-vs-stateful-authentication`, `adaptive-authentication`, `passwordless-authentication-methods`, `sso-seamless-authentication-enterprise-client-services`, `llm-in-access-management` and `how-to-auth-via-esia`. - **ESIA article title** — `landing-title` / `landing-title2` had the home page's "Welcome to Open Identity Platform Community" copied into them; they now use the article's own heading, "Аутентификация через госуслуги (ЕСИА)". With #239 this also becomes the page `<title>`. Left to other PRs, as noted in the issue: the OpenICF posts (#244), the redirect `… copy.md` (#242) and the empty `imageurl: ''` (#239). Fixes #245 ## Verification Built the site with `bundle exec jekyll build` (Ruby 3.1, as in CI) and ran the workflow's `htmlproofer` internal-link check: no errors. `og:image` across the built posts: `openam-og.png` 85, `opendj-og.png` 44, `openig-og.png` 24, `openidm-og.png` 20, `oip-og.png` 6. The rest are exactly the posts handled elsewhere: 10 `openicf-logo.png` + 3 GitHub avatar (OpenICF, #244) and 1 empty value (#239). On this branch alone `openidm-og.png` does not exist yet — hence the merge order above. `git merge-tree` against the branches of #239–#244: no conflicts. ## Preview 
|
Missing LinkedIn URL — done in da7fb51: it goes through
CI check of the share URLs — not in this PR. The proposed step pins one post's title and image, so editing that post would fail the build without anything being wrong with the buttons. The same kind of check was suggested for the head meta in #239 and was not added there either; if we want checks on rendered HTML, I'd rather open one issue that covers both than add them PR by PR. |
Summary
Cleanups from #238:
_data/blogposts.yml(778 lines). Nothing references it: no template, page ormigrate-to-posts.py; it predates the move to_posts/(Migrate to Jelyll _posts directory to use paging and page dates. #227)._posts/2024-06-20-How-To-Protect-Web-Services-with-OpenIG copy.md, alayout: redirectpost pointing at/blog/2025-11-05-openig-getting-started. It was not in the issue, but it was visible: an empty card "How To Protect Web Services With Openig copy" on/blog/page10/, and anoindexURL listed insitemap.xml. Nothing links to its…-OpenIG-copyURL; the original2024-06-20-How-To-Protect-Web-Services-with-OpenIGarticle is kept._posts/2026-02-04-opendj-5-0-3-released .mdto2026-02-04-opendj-5-0-3-released.md. The URL stays/blog/2026-02-04-opendj-5-0-3-released._includes/share-buttons.htmlnow useshttps://twitter.com/intent/tweet?url=…instead of the deprecatedhttp://twitter.com/home?status=…, andhttps://www.facebook.com/sharer/sharer.php?u=…instead ofhttp://…/share.php; the shared URL is URL-encoded on all four buttons, LinkedIn included. Every share window opens withwindow.open(url, '_blank', 'noopener'), so the social site gets nowindow.openerback to this tab.{% if page.image %}, which no page sets, so it never rendered (and it passed an emptyurl=). It now renders when the page has a non-emptyimageurland passes the page URL,/assets/img/<imageurl>and the title (landing-titleortitle), all URL-encoded, tohttps://www.pinterest.com/pin/create/button/. The six OpenIDM posts point atopenidm-og.png, which [#232] Add the missing OpenIDM and OpenICF Open Graph images #244 adds; until it is merged their Pinterest image, like theirog:image, is a 404.The fourth item of the issue (empty
imageurl: '') is fixed in #239.Fixes #238
Verification
Built the site with
bundle exec jekyll build(Ruby 3.1, as in CI) and ran the samehtmlprooferinternal-link check as the workflow: no errors.master, the only removed output file isblog/2024-06-20-How-To-Protect-Web-Services-with-OpenIG-copy.html;blog/2026-02-04-opendj-5-0-3-released.htmlkeeps its path.sitemap.xmland the blog pages no longer mention the-copyURL.https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.openidentityplatform.org%2Fblog%2F2025-12-18-openam-vs-keycloakandhttps://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.openidentityplatform.org%2Fblog%2F2025-12-18-openam-vs-keycloak&title=&summary=&source=.window.open(…)calls (135 pages × 3 buttons + 108 Pinterest buttons) pass'_blank', 'noopener'.imageurl, so there is no image to pin. Example:https://www.pinterest.com/pin/create/button/?url=https%3A%2F%2Fwww.openidentityplatform.org%2Fblog%2F2025-12-18-openam-vs-keycloak&media=https%3A%2F%2Fwww.openidentityplatform.org%2Fassets%2Fimg%2Fopenam-og.png&description=OpenAM+vs+Keycloak.