Weblog
Johannes Raggam: Less JavaScript: Build Modern, Interactive UIs with HTML and CSS
Talk by Johannes Raggam at Plone Conference 2025 in Jyväskylä, Finland.
Here are the talk slides.
Using less javascript can be good for performance (less big bundles) and accessibility.
Simple example: lazy image loading:
<img `loading="lazy"` src...
date, time, datetime-local inputs have good support on mobile without needing extra javascript:
<input type="datetime-local" ...
With javascript it could look nicer though.
In audio and video tags you can specify sources with different types, and have links or other html as fallback.
The details/summary element avoids the need for special accordeon javascript:
<details>
<summary>More info</summary>
<p>This is additional information, shown when you click the summary.</p>
</details>
If you give the details the open attribute, it will be shown expanded by default. The details element is for example used in the Plone 6.1 resource registries. Previously, if you did something wrong here, the control panel would be broken and you could not fix it here. Now with the plain html it is no problem. You can also use this for form tabbing.
For a slider/carousel there is a lot you can do with CSS. Coming soon: scroll buttons. And the ::scroll-marker element.
Form validation. Add the required attribute to an input, and use this CSS:
input:invalid {
border: 2px solid red;
}
input:valid {
border: 2px solid green;
}
dialog element for modals.
Future: masonry, with nice alignment of images of varying sizes on a page. It is experimental.
Future: maps.
Hanna Paananen and Naomi Woods: Human Perspectives in Cybersecurity
Keynote talk by Hanna Paananen and Naomi Woods at Plone Conference 2025 in Jyväskylä, Finland. How Mental State and Social Interactions Can Affect Cybersecurity Posture.
Naomi Woods
I am Doctor Naomi Woods, Research coordinator in this university. And my colleague doctor Hanna Paananen, University Teacher here. Both on cybersecurity.
Pur research group examines human interaction in the digital world within cybersecurity context. See our research group page.
My background is in psychology. I apply that to the cybersecurity context. Can mental health affect information security behavior.
ISP (Information Security Policy): detail how employees should behave in order to prevent, identify, and respond to security incidents. This is hard to comply with for an "average" employee. Research tries to understand this, and find approaches to improve. There is research about the effect of presuasive security messaging, or awareness of sanctions.
Mental health is an issue for many. Most common: depressive disorder and anxiety disorders. Both types can lead to cognitive slowness and avoidance behavior. Many people have symptoms, but are still able to work professionally. You can be more vulnerable: a more easy victim of social engineering, online harassment, fishing, etc.
We did a study on the effect on deterrence factors: perceived risks of sanctions and shame by an employer or peers. With anxiety there is more intention to comply with ISPs. With depression they are more likely to violate their ISPs.
Neutralization techniques (NT) are used to help individuals rationalize their less desirable or deviant behaviors. It allows them to justify it to themselves. For example rationalization: "My boss expects me to make really long passwords, so I will just use the same password everything." We did a study with four groups with combinations from low anxiety and low depression to medium-higher anxiety and medium-higher depression. The group with medium-higher anxiety and low depression had the highest use of NT to justify intentions to violate ISPs. So an increase in depression has a damping effect on use of NT: they care less.
This means there is no one-size-fits-all approach. With different mental health issues, you need to interact and motivate employees differently. Be inclusive, and do not set users up to fail at security.
Audience question: Would this mean it is better to reserve a part of the cybersecurity budget of your organisation to keep your employees happy?
Interesting question. You need a holistic approach: security is not just technical solutions, you also need to look at what employees can handle in terms of security on top of their already demanding jobs.
Hanna Paananen
Collaboration intoduces cybersecurity risk. There are threats against value chains. There have been lots of examples the last year with malicious code, intrusion attempts, fraud and deception, sabotage. A Russian-backed hack in software to access water treatment systems caused a water tank to overflow in one city in the US But also just errors and omissions, like with the CloudStrike problem earlier this year.
Inter-organisational cybersecurity is a necessity. Regulation and best practice as drivers. The EU cyber strategy tackles value chain threats. Organisations try to control compliance of their partners, with contracts, audits, standards certifications, technical measures, training. But high-level compliance requirements can be more a checklist than working instructions. It may lead to low visibility on actual risk control.
Management practices are needed across organizational boundaries. A company approached us. They focused on their core processes, and outsourced the rest. But they had no control there, so it posed risk.
Building a common understanding with people from other communities can be done in different ways. In one-on-one meetings we may get to know one another and learn. Immersion: visits, an in-house consultant. But the consultant learns about the organisation, but the organisation does not learn much about the consulting firm. Delegations: agreements, conferences. That is good, but does not really support the daily challenges.
Build a community between organisations. This is a way to build collaborative cybersecutiry management practices to match the requirements. It helps you know who to talk to when a jointly used asset is under attack, either to warn them or to get help.
We had three value networks in our project: with energy, water, and transport, all very different in how value was created. What practices should be built?
- Specify goals, reduce barriers.
- Get a mandate for practices: get a boss to allow you to spend time on inter-organisational cybersecurity. Let it be not for one person, but tied to a job, so also for your successor. Connect contracts to practice.
- Competence building. Learning from others. Small companies have different means than a big company.
- Materia for practices. Materia can be a contract, a ritual. "We have meetings, and this is what we do in them." It helps translates meanings. Makes conflict explicit.
So answer this question for yourself: What is my role in building cybersecurity with people from other communities?
Mack Palomäki: AI-Driven Documentation Workflows for Plone & Volto
Talk by Mack Palomäki at Plone Conference 2025 in Jyväskylä, Finland.
Part 1: Collaboration rules. I have a very large file with rules that I use for prompts. For example:
- Rule 1: documentation first. Look in the official docs.
- Rule 11: no false security. Never say "this will work" unless proven.
- Rule 10: success is functional. Claim a success ONLY when there is a fully functional, useful, tested result.
- Rule 8: Loop detection. If the AI is repeating the same pattern, stop.
Part 2: What makes a good documentation prompt?
- Context: what is this code/module/function?
- Constraints: what format/style/standards?
- Output format: docstrings? Markdown? API reference? And can you save intermediate output so you can check the reasoning afterwards?
- Verification: How to check accuracy?
Specify what kind of docs you want? "Generate API docs." "Add verbose comments." "Create an architecture overview." "Compare v1 and v2 of this API and write a migration guide."
There are some tasks an AI can confidently do. Others not. I am a newbie in Plone, and have totally relied on AI for this presentation. I have had about 4000 hours of experience in AI though. It took about 10 minutes to prepare. That it can do well.
I gave it a task: "Create an architecture overview document." This took about 20 minutes. It could then self-critique the result. Some parts it thought it had done fine. But it confessed that performance numbers were made up. It could not have done this kind of self-critique a few months ago.
A documentation workflow:
- Developer writes code and creates prompt.
- AI generates initial docs.
- Developer reviews
- Dev adds missing content.
- AI validates technical claims.
You can create (or find) prompt templates for different doc types.
To reduce hallucinations:
- Require AI to cite sources, actual lines numbers, function names.
- Ask AI to state uncertainties explicitly. It is good to be very verbose about this, be really challenging.
Key takeaways:
- AI generates structure quickly, and then humans add context.
- Follow collaboration rules to avoid loops.
- Good prompts lead to good documentation.
- Documentation as code: part of the PR process.
Closing remark:
There are different AIs out there. I am using every single one of them. They all have different personalities. It is actually addictive in the way that gaming is. You have immediate feedback, visible progress, creative problem solving, that flow state where you lose track of time. That is powerful, because it means developers will actually want to document instead of avoiding it. Just... set a timer, because you can iterate forever!
In your prompt, always start with the collaboration rules.
Elisabeth Donnay: iMio web portals aren't 100% based on Plone. Fake news?
Talk by Elisabeth Donnay at Plone Conference 2025 in Jyväskylä, Finland.
Yes, it is Plone. But no forms, no news items and events. We use react views: single page, speed.
We have a unified citizen portal, 'Publik', using secure authentication, via trusted national digital identity systems. Publik is a Django framework. Citizens can login for administration. They can also make suggestions to the local government.
Ideabox: citizen participation. This uses to be a Plone instance, but now a React view that is talking to the Publik app.
Are the editors happy with the new Plone? Yes, it is better than SmartWeb with Plone 4. There are some restrictions, but that is to keep the mobile experience nice, so it is good.
It is used in different municipalities. Each site has its own layout. We make a template and integration for each city.
We use the Plone restapi to get the json from the backend.
Lightning talks Wednesday
Lightning talks on Wednesday at Plone Conference 2025 in Jyväskylä, Finland.
Mari: Finnish
I study Finnish language at the university here.
Today's lesson: the pivotal 'No niin' for beginners. It can mean: OK, let's go, or meh. It depends on the innotation.
Martin Peeters: Board elections
There are only two nominations for the three seats that open in the board. So no elections this year for now. But you have time until midnight to send your nomination on the website. Contact me if you need help
Erico: State of State
These are some of the talks of today:
- Keynote: State of Plone
- State of Plone 6 backend
- State of Plone restapi
- State and direction of Plone community IT
Come on, we need better talk names!
But this is a community of people who step up and actually do things. You are all invited to my talk, over here, tomorrow 3 pm, on how to create your own conference website.
Astrid: Where in the world is Plone?
When I am in Stellenbosch I sometimes wonder if other people are using Plone. I can tell you, we are not alone. [Showing some screen shots of Matomo.]
If you feel lonely, you can go to community.plone.org, join a team, go on Discord, etc. We have a monthly news letter. Please sign up!
Eric Brehault and Jakob Kahl: France to Finland by train
I went from France to Finland by train. It took 3 days. I know that I am lucky, not everyone can do that. It would have taken 3 hours by plane. But that takes a lot of carbon dioxide, so bad for the planet. So I took responsibility. And I took more Plonistas. And I am trying to plant a seed: if Eric can do that, I can too!
I created some software to show information about my travels, the route and photos. Using GitHub user content, and a Svelte frontend.
And Jakob did the same from Bonn via a different route.
Dante: Plone MCP
Let's see how much the Claude AI can do in five minutes.
MCP is Model Context Protocol. This is a protocol for an AI to interact with other systems. We have on GitHub plone/plone-mcp, very early stages. We can use this to add blocks, create pages. I have a demo which does this.
Andre: Publication with timestamp
This is about https//:deliberations.be, used by Belgian municipal governments. We added publications with ASIC timestamps. Extra behavior. This adds verification so you can check that the document is the original one. This is done with collective.timestamp.
Rikupekka and Rita: Photo competition
Just like in the Eibar conference, we want to do a photo competition. We will add a Discord channel that you can post your photos to, and we will see who gets the most thumbs up, to win a special price.
Mike Metcalfe: Finnish
I was here in Finland in 1988 for a year. I don't know many words, but I know how to pronounce them. Finnish is phonetic: if you see a letter, pronounce it Each letter has one sound, so not in English where you have 'mat' and then an extra 'e' changes how you pronounce the 'a': 'mate'. Not so in Finnish.
'ä' is pronounced as in 'hat', for example 'Jyväskylä'. 'a' is pronounced as in 'art', for example 'Asko' or 'Mari'. The 'r' in 'Rikupekka' is a rolling 'r'.
In 'Kiitos' the 'i' is long.
Sally: Add-on voting
We had an add-ons panel, and they wanted the add-ons competition back. It can be hard to start if you are not that into the community. So fill in the ballot, there will be more on the registration desk tomorrow.
