Commit graph

10485 commits

Author SHA1 Message Date
Daniel Uber
4d40ea18a2
When returning a json error, don't use a raw unescaped string (#15879)
The 400 and 403 error pages show json parsing errors in most browsers,
since "Error: Bad Request" is not a valid json body ('"Error: Bad
Request"' would be, or the object with key error and value of the
string which I've selected is _also_ valid).

Do we have frontend code that's looking for this body before it parses
for some reason, or was this just a mistaken copying from the api
controller in the initial PRs (#2293 for not_authorized, and #6248 for
the bad_request method, which may have just replicated the decision
for not_authorized)?
2021-12-27 11:39:15 -06:00
Jeremy Friesen
0b8c09851c
Favoring constant over magic string (#15852) 2021-12-27 11:31:29 -05:00
dependabot[bot]
2bf13cab00
Bump shoulda-matchers from 5.0.0 to 5.1.0 (#15871)
Bumps [shoulda-matchers](https://github.com/thoughtbot/shoulda-matchers) from 5.0.0 to 5.1.0.
- [Release notes](https://github.com/thoughtbot/shoulda-matchers/releases)
- [Changelog](https://github.com/thoughtbot/shoulda-matchers/blob/main/CHANGELOG.md)
- [Commits](https://github.com/thoughtbot/shoulda-matchers/compare/v5.0.0...v5.1.0)

---
updated-dependencies:
- dependency-name: shoulda-matchers
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-27 09:41:03 -06:00
dependabot[bot]
6fba63d224
Bump honeycomb-beeline from 2.7.1 to 2.8.0 (#15870)
Bumps [honeycomb-beeline](https://github.com/honeycombio/beeline-ruby) from 2.7.1 to 2.8.0.
- [Release notes](https://github.com/honeycombio/beeline-ruby/releases)
- [Changelog](https://github.com/honeycombio/beeline-ruby/blob/main/CHANGELOG.md)
- [Commits](https://github.com/honeycombio/beeline-ruby/compare/v2.7.1...v2.8.0)

---
updated-dependencies:
- dependency-name: honeycomb-beeline
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-27 09:13:56 -06:00
dependabot[bot]
2d98e3346b
Bump rubocop from 1.23.0 to 1.24.0 (#15872)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Michael Kohl <me@citizen428.net>
2021-12-27 10:04:59 -05:00
dependabot[bot]
159c9c9b45
Bump flipper, flipper-active_record, flipper-active_support_cache_store and flipper-ui (#15875)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-27 09:52:22 -05:00
Jeremy Friesen
c7902a3261
Favor destroy_by over where.first&.destroy (#15868)
* Favor `destroy_by` over `where.first&.destroy`

We can use [ActiveRecord::Relation.destroy_by][1] instead of the method
chain.

[1]:https://api.rubyonrails.org/classes/ActiveRecord/Relation.html#method-i-destroy_by

* Restoring custom behavior

Those constants are not ActiveRecord::Base objects, so don't implement
the method.
2021-12-22 23:55:52 -05:00
Jeremy Friesen
6d37f4303c
Favoring single SQL and computation over enum (#15865)
* Favoring single SQL and computation over enum

Prior to this commit, we ran a SQL statement to generate a list of
articles then applied some minor randomization.

With this commit, I'm removing the randomization in favor of expected
values, and collapsing the result set into a single inline SQL and some
post query simple arithmatic.

Let's check my math.  For each article we sum:

* `article.score`
* `article.comments_count` * 14
* a random number between 0 and 5 (`rand(6)`) with expected value of 2.5
* the tag's (taggings_count + 1) / 2

The new SQL query sums the `article.score` and the
`article.comments_count` * 14.  I then reduce the remainder of the
equation.  From "for each article sum `(rand(5) + (taggings_count + 1) /
2)`" we have the following:

`article_count * (2.5 + (taggings_count + 1) / 2)`

Which is equivalent to:

`article_count * ((taggings_count + 1 + (2.5 * 2)) / 2)`

Which is equivalent to:

`article_count * ((taggings_count + 6) / 2)`

This change reduces computation time by favoring expected values.

* Fixing broken behavior and adding comments
2021-12-22 14:59:37 -05:00
Mac Siri
ea037a127a
Add catch to trackAdImpression() (#15864) 2021-12-22 13:12:37 -05:00
Josh Puetz
10c13078cb
User correct username in mobile mention notifications (#15861) 2021-12-22 10:31:22 -06:00
Jeremy Friesen
c75dd69d09
Favoring common method not previously available (#15855)
With this refactor, I'm adding documentation and favoring using a common
method that wasn't available at the time of implementation.

In [this commit][1] we had logic that said "if we have a singular tag
use the cache" otherwise use the join.  At that time, the implementation
of [Article.cached_tag_with][previous] was as follows, allowing only a
singular tag:

```ruby
scope :cached_tagged_with, ->(tag) { where("cached_tag_list ~* ?",
"^#{tag},| #{tag},|, #{tag}$|^#{tag}$") }
```

The [current implementation][current], as of writing this, allows for
multiple tags and is as follows:

```ruby
scope :cached_tagged_with, lambda { |tag|
  case tag
  when String, Symbol
    # In Postgres regexes, the [[:<:]] and [[:>:]] are equivalent to "start of
    # word" and "end of word", respectively. They're similar to `\b` in Perl-
    # compatible regexes (PCRE), but that matches at either end of a word.
    # They're more comparable to how vim's `\<` and `\>` work.
    where("cached_tag_list ~ ?", "[[:<:]]#{tag}[[:>:]]")
  when Array
    tag.reduce(self) { |acc, elem| acc.cached_tagged_with(elem) }
  when Tag
    cached_tagged_with(tag.name)
  else
    raise TypeError, "Cannot search tags for: #{tag.inspect}"
  end
}
```

Given that we are content to use the cached tag in the singular tag
case, it seems safe to say that we're comfortable using it in the
multiple tag case.

[1]:af5a391429 (diff-24503fd25ed68e6ebceee4951bc4f9b255b197278d4aa9d86ef9d5afe3f26bea)
[previous]:af5a391429/app/models/article.rb (L151)
[current]:98e97e7aa8/app/models/article.rb (L212-L227)
2021-12-22 11:00:54 -05:00
dependabot[bot]
98e97e7aa8
Bump js-routes from 2.1.2 to 2.2.0 (#15845)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-21 14:53:11 -05:00
dependabot[bot]
5b162d42b6
Bump jbuilder from 2.11.4 to 2.11.5 (#15847)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-21 14:52:48 -05:00
dependabot[bot]
f7ddd807b3
Bump view_component from 2.46.0 to 2.47.0 (#15846)
Bumps [view_component](https://github.com/github/view_component) from 2.46.0 to 2.47.0.
- [Release notes](https://github.com/github/view_component/releases)
- [Changelog](https://github.com/github/view_component/blob/main/docs/CHANGELOG.md)
- [Commits](https://github.com/github/view_component/compare/v2.46.0...v2.47.0)

---
updated-dependencies:
- dependency-name: view_component
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-21 13:29:07 -05:00
dependabot[bot]
01ec04a9b9
Bump i18n-tasks from 0.9.35 to 0.9.36 (#15844)
Bumps [i18n-tasks](https://github.com/glebm/i18n-tasks) from 0.9.35 to 0.9.36.
- [Release notes](https://github.com/glebm/i18n-tasks/releases)
- [Changelog](https://github.com/glebm/i18n-tasks/blob/main/CHANGES.md)
- [Commits](https://github.com/glebm/i18n-tasks/compare/v0.9.35...v0.9.36)

---
updated-dependencies:
- dependency-name: i18n-tasks
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-21 12:21:47 -06:00
Jeremy Friesen
a40efc6bbd
Refactoring questions asked of user (#15762)
* Refactoring questions asked of user

In this pull request, I'm extracting and normalizing role-based
questions asked of the user.

Prior to this commit, our codebase has asked two very similar questions
of our user model:

- `user.has_role?(:admin)`
- `user.admin?`

In asking `has_role?(:admin)` we are relying on implementation details
of the rolify gem.  In addition, the `has_role?` question asked
throughout controllers or views means that it's harder to create
hieararchies of permissions.

In favoring `user.admin?` as our question, we can use that indirection
as an opportunity to discuss and decide "Should someone with the
`:super_admin` role be `user.admin? == true`?"

The details of this commit is to do three primary things:

1. Ask the `has_role?` questions in "one place" in the code (e.g. the
   `Authorizer` module)
2. Extract the role based questions that are on the `User` model and
   provde backwards compatable delegation.
3. Structure the code so that it's harder to accidentally call
   `user.has_role?` (e.g., make `User#has_role?` and `User#has_any_role?`
   private).

This is related to #15624 and the updates are informed by discussion in
PR #15691.  This commit supplants #15691.

* Refactoring the liquid tag policy tests

* Fixing typo

* Bump for travis
2021-12-21 12:45:12 -05:00
Suzanne Aitchison
5fd1f94e85
Add comment notification test to Cypress, including a11y improvements to notification page (#15842)
* changes to accessible names on notification comment box, cypress specs

* add reply to comment test, delete old specs

* tweak to seeds
2021-12-21 15:42:13 +00:00
dependabot[bot]
c2659d38df
Bump eslint-config-preact from 1.2.0 to 1.3.0 (#15834)
* Bump eslint-config-preact from 1.2.0 to 1.3.0

Bumps [eslint-config-preact](https://github.com/preactjs/eslint-config-preact) from 1.2.0 to 1.3.0.
- [Release notes](https://github.com/preactjs/eslint-config-preact/releases)
- [Commits](https://github.com/preactjs/eslint-config-preact/compare/1.2.0...v1.3.0)

---
updated-dependencies:
- dependency-name: eslint-config-preact
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

* apply new lint fixes after version bump

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2021-12-21 14:42:20 +00:00
yheuhtozr
5253717797
fix character limits i18n (#15830) 2021-12-21 07:15:21 -05:00
dependabot[bot]
7d80475f1a
Bump core-js from 3.19.3 to 3.20.0 (#15837) 2021-12-21 07:11:51 -05:00
Michael Kohl
872b007c30
Remove Doorkeeper gem (#15749) 2021-12-21 12:29:58 +07:00
yheuhtozr
021ed9708e
restore i18n key _footer.html.erb (#15831) 2021-12-20 16:33:41 -06:00
Daniel Uber
032378b3bd
Disable dash replacement filter in markdown fixer (#15839)
* Remove modify_hr_tags method definition

this breaks things that call it.

* Remove direct uses of modify_hr_tags fixer method

Remove from class METHODS lists, remove test cases about this behavior, and remove from
methods lists in test cases.

* Remove hr tag modification spec

Still don't understand what problem this was fixing, but I've removed
the test case.
2021-12-20 15:39:55 -06:00
dependabot[bot]
5219409bc1
Bump debug from 1.3.4 to 1.4.0 (#15835)
Bumps [debug](https://github.com/ruby/debug) from 1.3.4 to 1.4.0.
- [Release notes](https://github.com/ruby/debug/releases)
- [Commits](https://github.com/ruby/debug/compare/v1.3.4...v1.4.0)

---
updated-dependencies:
- dependency-name: debug
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-20 14:43:49 -06:00
dependabot[bot]
2f47b47c32
Bump bullet from 6.1.5 to 7.0.0 (#15833)
Bumps [bullet](https://github.com/flyerhzm/bullet) from 6.1.5 to 7.0.0.
- [Release notes](https://github.com/flyerhzm/bullet/releases)
- [Changelog](https://github.com/flyerhzm/bullet/blob/master/CHANGELOG.md)
- [Commits](https://github.com/flyerhzm/bullet/compare/6.1.5...7.0.0)

---
updated-dependencies:
- dependency-name: bullet
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-20 14:21:50 -06:00
dependabot[bot]
a2f324a2dc
Bump rouge from 3.26.1 to 3.27.0 (#15791)
Bumps [rouge](https://github.com/rouge-ruby/rouge) from 3.26.1 to 3.27.0.
- [Release notes](https://github.com/rouge-ruby/rouge/releases)
- [Changelog](https://github.com/rouge-ruby/rouge/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rouge-ruby/rouge/compare/v3.26.1...v3.27.0)

---
updated-dependencies:
- dependency-name: rouge
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-20 11:09:31 -05:00
ludwiczakpawel
d125617e13
CSS Variables cleanup (#15828)
* variables cleanup

* little fix
2021-12-20 15:42:40 +01:00
ludwiczakpawel
5e098df276
fix (#15829) 2021-12-20 13:38:29 +01:00
Anna Buianova
9f688be406
Moved setting old_username from before_validation to Users::Update (#15782)
* Moved setting old_username from before_validation to Users::Update

* Removed unused code

* Fixed specs after moving setting old_usernames
2021-12-20 11:08:09 +03:00
ludwiczakpawel
9b7503fde3
Update left sidebar links with new Crayons components (#15757)
* update

* hamburger fix

* Update app/views/shared/_hamburger.html.erb

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* updates

* spec

* social media icons

* reading list counter

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2021-12-20 08:46:30 +01:00
Andy Zhao
8a7e5a5566
Escape periods and display the group name properly (#15819)
* Escape periods and display the group name properly

* Rename method to dom_safe_name and move to admin helper

* Replace beginning of string digit with underscore then digit
2021-12-17 17:35:42 -05:00
Andy Zhao
6335f9a7e9
Remove profile when banish (#15818)
* Clear profile when banishing user

* Add test for clearing profile when banishing

* Also clear any social usernames
2021-12-17 15:36:35 -05:00
Jamie Gaskins
329f33448f
Disallow null user agent and obsolete browser (#15817)
We were previously disallowing empty user agents, but we weren't
blocking requests where the User-Agent header wasn't set at all. This
commit blocks those requests.

This commit also blocks Chrome 74. It's a 2.5-year-old version of an
evergreen browser that releases every 6 weeks, so this is clearly a bot
spoofing this header.
2021-12-17 15:02:30 -05:00
Dwight Scott
325a9f9e3f
Add me (Dwight) to readme :) (#15816) 2021-12-17 14:50:45 -05:00
dependabot[bot]
fb758a3bbe
Bump strong_migrations from 0.7.8 to 0.7.9 (#15812)
Bumps [strong_migrations](https://github.com/ankane/strong_migrations) from 0.7.8 to 0.7.9.
- [Release notes](https://github.com/ankane/strong_migrations/releases)
- [Changelog](https://github.com/ankane/strong_migrations/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ankane/strong_migrations/compare/v0.7.8...v0.7.9)

---
updated-dependencies:
- dependency-name: strong_migrations
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-17 13:31:53 -05:00
dependabot[bot]
c6ed3b6a2b
Bump field_test from 0.5.1 to 0.5.2 (#15813)
Bumps [field_test](https://github.com/ankane/field_test) from 0.5.1 to 0.5.2.
- [Release notes](https://github.com/ankane/field_test/releases)
- [Changelog](https://github.com/ankane/field_test/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ankane/field_test/compare/v0.5.1...v0.5.2)

---
updated-dependencies:
- dependency-name: field_test
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-17 13:29:57 -05:00
dependabot[bot]
c047dd2631
Bump jbuilder from 2.11.3 to 2.11.4 (#15815)
Bumps [jbuilder](https://github.com/rails/jbuilder) from 2.11.3 to 2.11.4.
- [Release notes](https://github.com/rails/jbuilder/releases)
- [Changelog](https://github.com/rails/jbuilder/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rails/jbuilder/compare/v2.11.3...v2.11.4)

---
updated-dependencies:
- dependency-name: jbuilder
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-17 12:28:36 -06:00
Arit Amana
dee0b36981
Implement Unified Embed for CodeSandbox URLs (#15808)
* Implement embed and write specs

* fix slight regex ommision

* remove error over invalid options; add specs to cover

* account for missing options when using embed keyword

* no videos, no ns video_id 🤦🏾‍♀️
2021-12-17 12:12:54 -05:00
Daniel Uber
4b93684dab
Don't raise error when empty community emoji setting submitted (#15723)
* Don't raise NoMethodError when validating emoji settings

Cargo culted the unique cross model slug validator setup (which is why
value is called name here in the validatable).

Don't raise an error when validating a nil emoji, and assert nil and
empty string are permitted values.

This expects no non-emoji characters (so an empty string would be
permitted), and nil should be permitted.

I believe this might have been introduced by the string settings
cleaner (exchanging "" for nil in form inputs).

* Update app/validators/emoji_only_validator.rb

guard for value, and then validate value
2021-12-17 09:29:55 -06:00
Daniel Uber
7b5d90d252
Add DISABLE_SPRING environment variable to gitpod forem server task (#15807)
https://www.gitpod.io/docs/environment-variables#terminal-specific-environment-variables

Without this I'm seeing the ENV["APP_DOMAIN"] not set when spring is
loaded (this prevents browsing the site from within gitpod).
2021-12-16 15:24:22 -06:00
dependabot[bot]
d2bf8e9b77
Bump brakeman from 5.1.2 to 5.2.0 (#15805)
Bumps [brakeman](https://github.com/presidentbeef/brakeman) from 5.1.2 to 5.2.0.
- [Release notes](https://github.com/presidentbeef/brakeman/releases)
- [Changelog](https://github.com/presidentbeef/brakeman/blob/main/CHANGES.md)
- [Commits](https://github.com/presidentbeef/brakeman/compare/v5.1.2...v5.2.0)

---
updated-dependencies:
- dependency-name: brakeman
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-16 12:31:47 -07:00
dependabot[bot]
12fd5441cb
Bump fastimage from 2.2.5 to 2.2.6 (#15806)
Bumps [fastimage](https://github.com/sdsykes/fastimage) from 2.2.5 to 2.2.6.
- [Release notes](https://github.com/sdsykes/fastimage/releases)
- [Changelog](https://github.com/sdsykes/fastimage/blob/master/CHANGELOG)
- [Commits](https://github.com/sdsykes/fastimage/compare/v2.2.5...v2.2.6)

---
updated-dependencies:
- dependency-name: fastimage
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-16 12:25:05 -07:00
dependabot[bot]
8cba3e54e6
Bump devise from 4.8.0 to 4.8.1 (#15802)
Bumps [devise](https://github.com/heartcombo/devise) from 4.8.0 to 4.8.1.
- [Release notes](https://github.com/heartcombo/devise/releases)
- [Changelog](https://github.com/heartcombo/devise/blob/main/CHANGELOG.md)
- [Commits](https://github.com/heartcombo/devise/compare/v4.8.0...v4.8.1)

---
updated-dependencies:
- dependency-name: devise
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-16 12:08:24 -07:00
dependabot[bot]
ef703219fe
Bump rails from 6.1.4.3 to 6.1.4.4 (#15803)
Bumps [rails](https://github.com/rails/rails) from 6.1.4.3 to 6.1.4.4.
- [Release notes](https://github.com/rails/rails/releases)
- [Commits](https://github.com/rails/rails/compare/v6.1.4.3...v6.1.4.4)

---
updated-dependencies:
- dependency-name: rails
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-16 12:08:09 -07:00
dependabot[bot]
db43fd2a40
Bump pghero from 2.8.1 to 2.8.2 (#15804)
Bumps [pghero](https://github.com/ankane/pghero) from 2.8.1 to 2.8.2.
- [Release notes](https://github.com/ankane/pghero/releases)
- [Changelog](https://github.com/ankane/pghero/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ankane/pghero/compare/v2.8.1...v2.8.2)

---
updated-dependencies:
- dependency-name: pghero
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-16 13:50:30 -05:00
Nick Taylor
780ef90baf
Added some retries to cookie clearing (#15798) 2021-12-16 13:28:40 -05:00
Alex
51f2bf7aab
Add article and comment count to instance API (#15794) 2021-12-16 13:05:49 -05:00
Arit Amana
5c13d9d8fd
Implement embed tag and specs (#15801) 2021-12-16 12:58:43 -05:00
Daniel Uber
57ebd8e0fc
Skip notification interaction with replies spec (#15799)
* Skip notification interaction with replies spec

This had been failing in builds (my assumption is that the state flag
for .reacted was either out of sync or not yet ready/unhidden, I'm
still getting more information about this).

The behavior being tested is that clicking the greyed out heart on a
reply enables the .reacted class, and clicking again disables
it. There's a similar test for an admin clicking heart, thumbsdown,
and monocle/flag/vomit icons one by one and checking the state on the
page.

This is a good candidate to move to a cypress test.

* Skip admin interacting with replies to notifications

Same issue as the user interaction - the .reacted class is not
reliably present after a click event.
2021-12-16 11:54:58 -06:00
Jeremy Friesen
aa7712a80e
Extracting container for allowed tags & attrs (#15338)
* Extracting container for allowed tags & attrs

Prior to this commit, we had several different locations in which we
specified ALLOWED_TAGS and ALLOWED_ATTRIBUTES for HTML rendering and
sanitization.

Curious to see how these either intersected or didn't, I opted to
create a container module that allows for us to more readily normalize
these allowed tags and attributes.  It's possible that we won't do any
normalization, but this work helps make that easier.

Ideally, I'd love us to contextualize "why did we choose the
tags/attributes we chose?"  But for now, I think consolidating these
tags and attributes will help make adding a `details` and `summary` tag
easier.

This relates to forem/rfcs#296

See [Google Sheet][1] for analysis of what tags/attributes are used, the
intersection and union.

[1]:https://docs.google.com/spreadsheets/d/1yj-a1qus1o0o4cj-_gOMP5yteeg-_f3s5z7kvK0Y7RM/edit#gid=0

* Fixing misnamed constant

* Fixing misnamed constant

* Extracting additional HtmlRendering use cases

* Adding comparative documentation for HTML tags

* Fixing broken parameter signature

* Moving constants into MarkdownProcessor
2021-12-16 12:24:45 -05:00