Skip to content

Repository files navigation

Padline

URL-first, no-account, real-time collaborative pads. A modern Dontpad successor.

License: MIT Deployed on Cloudflare Workers PRs Welcome

Live at padline.page — open any URL and start typing.

Open a URL → it's a pad. Share the link → you're collaborating. A pad is a lightweight Notion-style page with live cursors, presence, offline resilience, and snapshot history. No accounts, no onboarding, no friction.

Features

  • ✏️ Rich collaborative editing — Notion-style blocks (BlockNote) over Yjs CRDTs; simultaneous edits merge conflict-free
  • 👥 Presence — live cursors, selections, and auto-generated identities ("Mellow Otter") you can rename
  • 🔗 URL-first — padline.page/anything-you-like is the pad; empty pads cost nothing until the first keystroke
  • 🔒 PIN protection — optional per-pad PIN gates both viewing and editing, enforced server-side with brute-force backoff
  • 👁️ Read-only links — share a view-only capability URL; rotate it anytime to revoke old copies
  • 🕘 Snapshot history — automatic snapshots; restoring is itself an undoable edit, never a rollback
  • 📴 Offline resilience — every visited pad is cached in IndexedDB; brief disconnections lose nothing
  • 📊 Status line — live word, character, block, and reading-time counts beside a labelled sync indicator
  • 📤 Markdown export — copy or download; your content is never trapped
  • 🚩 Reporting & moderation — a Turnstile-gated report form, cases, evidence with retention, freeze/block/remove, totals and exports, all in a tamper-evident log (ADR-0018)
  • 🛡️ Abuse invariants — document size caps, connection caps, message limits, per-IP caps (ADR-0008, ADR-0009)

Documentation

User guide Using pads: sharing, PINs, read-only links, history, export, limits, reporting
Self-hosting Local dev, deploying, secrets, edge rules, upgrades, troubleshooting
Operating a public instance Your legal responsibility, and what's specific to Brazil
Moderation guide Handling reports end to end, evidence, totals, exports
Reference CLI · HTTP & WebSocket API · Configuration & limits
Architecture Modules, flows, storage, security boundaries, tests
ADRs · CONTEXT.md Why each decision was made · the domain vocabulary

All of it is indexed in docs/.

How it works

The whole app is one Cloudflare Worker: static assets, an HTTP API, one Durable Object room per pad, and one moderation ledger.

flowchart LR
    B[Browser<br/>React + BlockNote + Yjs] -->|"WebSocket (Yjs sync + awareness)"| W[Cloudflare Worker]
    B -->|"HTTP ops and reports"| W
    W --> DO["Durable Object per pad<br/>(y-partyserver room)"]
    W --> L["Moderation ledger<br/>(one Durable Object)"]
    L -->|takedowns| DO
    B <-->|offline cache| IDB[(IndexedDB)]
Loading

Authorization happens before any document bytes are sent, every takedown goes through the ledger and is recorded, and there is no list of pads by design. The architecture page walks through each flow.

Stack: React 19 · Vite · Tailwind v4 · shadcn/ui · BlockNote · Yjs · y-indexeddb · Hono · Cloudflare Workers · Durable Objects (SQLite) · y-partyserver · Turnstile

Quickstart

git clone https://github.com/idcesares/padline.git
cd padline
npm install
npm run dev        # http://127.0.0.1:8788

Open http://127.0.0.1:8788/my-first-pad in two tabs and type in one. For local secrets, tests, and the Windows notes, see Self-hosting.

Deploy your own

npx wrangler login
npm run deploy

Padline runs on the Cloudflare free tier. Before opening an instance to the public, point wrangler.jsonc at your own domain, set the moderation secrets, and read Operating a public instance — the legal responsibility is yours, and this repository's policies were written for padline.page's operator under Brazilian law. The full checklist is in Self-hosting.

Contributing

Contributions are welcome — see CONTRIBUTING.md for setup, verification, and the PR flow. Security issues: see SECURITY.md. A report about a pad's content is a moderation matter, not a vulnerability — use the report form.

Policies

The deployed service publishes its Terms of Use, Privacy Policy, and Content Policy, served by the app itself (src/routes/legal.tsx). If you self-host, rewrite them for your own deployment and jurisdiction.

SEO & discoverability

public/robots.txt, public/sitemap.xml, and public/llms.txt document the crawling and AI-assistant-citation policy — see ADR-0012.

How this is built

Padline is written by AI coding agents under human product direction. Product decisions, architecture, and trade-offs are human-owned and human-reviewed; the agents do implementation, refactoring, and test coverage against specs written for them.

That split is auditable rather than asserted. docs/adr/ carries a numbered ADR for every non-obvious decision — what was chosen, what was rejected, and why — and AGENTS.md is the working contract the agents follow.

This describes how the software is written, not how it runs. Padline ships no AI features and makes no model calls. Pad content stays between your browser and its Room and is never sent to a model — AI features are explicitly deferred (see CONTEXT.md).

License & author

MIT © Isaac D'Césares — created and directed by a human, implemented with AI assistance.

About

Real-time collaborative pads. Open a URL, start writing, share the link. No accounts, no friction. A modern Dontpad successor.

Topics

Resources

Contributing

Security policy

Stars

1 star

Watchers

0 watching

Forks

Contributors

Languages