Commit graph

11473 commits

Author SHA1 Message Date
Arit Amana
5648782ec0
Sharpen RegEx that matches Forem-specific links (#17500)
* first iteration of solution

* fix oversight

* cover pathless and invalid forem links

* more test cases

* more readable regex 🥳
2022-04-29 11:34:32 -04:00
Ridhwana
994a121c62
feat: add search by email back (#17511) 2022-04-29 09:59:10 -04:00
Jeremy Friesen
b808843564
Updating documentation for the relevancy feed (#17503)
* Updating documentation for the relevancy feed

This looks to remove the chatter of the document and instead point folks
to locations within the code.

Closes forem/forem#17245

* Update app/models/articles/feeds/README.md

Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>

* Update app/models/articles/feeds/README.md

Co-authored-by: Arit Amana <32520970+msarit@users.noreply.github.com>

* Update app/models/articles/feeds/README.md

Co-authored-by: Arit Amana <32520970+msarit@users.noreply.github.com>

* Update app/models/articles/feeds/README.md

Co-authored-by: Arit Amana <32520970+msarit@users.noreply.github.com>

* Update app/models/articles/feeds/README.md

Co-authored-by: Arit Amana <32520970+msarit@users.noreply.github.com>

* Update app/models/articles/feeds/README.md

Co-authored-by: Arit Amana <32520970+msarit@users.noreply.github.com>

* Update app/models/articles/feeds/README.md

Co-authored-by: Arit Amana <32520970+msarit@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: Arit Amana <32520970+msarit@users.noreply.github.com>

* Update app/models/articles/feeds/README.md

Co-authored-by: Arit Amana <32520970+msarit@users.noreply.github.com>

Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>
Co-authored-by: Arit Amana <32520970+msarit@users.noreply.github.com>
2022-04-29 09:50:05 -04:00
Suzanne Aitchison
648c86c612
Add prop for user-defined selections in MultiSelectAutocomplete (#17402)
* add new prop and update specs

* update storybook
2022-04-29 09:39:25 +01:00
Arit Amana
0d023163ba
Hide 'Save' button on posts that belong to the current user (#17293)
* implement change

* struggling with tests

* extend implementation to relevant views

* update Article.test.jsx snapshot

* fix failing specs

* query userData more robustly

* default saveable value in SaveButton component

* fix spec

* fetch currentUser async
2022-04-28 12:33:01 -04:00
YOSHIDA Katsuhiko
89fcd84f9f
Replace git.io URL (#17501) 2022-04-28 07:34:33 -06:00
Jeremy Friesen
7e62d8098f
Removing conditional for AdminMenu's spaces (#17162)
When we merge this, Forem admins will see the "Admin > Content Manager >
Spaces" section in their Admin area.  This will then allow them to
toggle on and off spaces.

Closes forem/forem#17161
2022-04-28 08:49:59 -04:00
Daniel Uber
42aad1d7e0
fix typo (#17497) 2022-04-27 16:52:28 -05:00
Mac Siri
4b37f2384c
Refactor OnboardingsController (#17329)
* Refactor OnboardingsController

* Fix broken spec

* Update policy

* Fix spec

* Update config/routes.rb

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

* Touchup

* Update routes

* Screw it, let's move notification_settings too

* Revert "Screw it, let's move notification_settings too"

This reverts commit aead8c05f4dda62cbc46cdd033afd0acdef2ad73.

* Temp .travis.yml changes

* Revert "Temp .travis.yml changes"

This reverts commit c26109843ba027f9a524e66282a9b01f0341f836.

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2022-04-27 16:17:02 -04:00
dependabot[bot]
8e9eb7dbb4
Bump jest-watch-typeahead from 1.0.0 to 1.1.0 (#17427)
Bumps [jest-watch-typeahead](https://github.com/jest-community/jest-watch-typeahead) from 1.0.0 to 1.1.0.
- [Release notes](https://github.com/jest-community/jest-watch-typeahead/releases)
- [Changelog](https://github.com/jest-community/jest-watch-typeahead/blob/main/CHANGELOG.md)
- [Commits](https://github.com/jest-community/jest-watch-typeahead/compare/v1.0.0...v1.1.0)

---
updated-dependencies:
- dependency-name: jest-watch-typeahead
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-27 13:05:27 -04:00
Daniel Uber
913ca720a8
Don't create podcast episodes without any media (#17449)
* Don't create podcast episodes without a media_url

There is an early return from add_media_url to prevent using an empty
enclosure_url, which avoids errors in
`GetMediaUrl.call(a_blank_value)`, however there's also a not null
constraint on podcast_episodes.media_url in the database, which causes
upsert to raise an error.

Returning early here avoids the error (which had halted the worker).

See also
https://app.honeybadger.io/projects/66984/faults/80833402

This error happens regularly, 96 times per day in DEV, it looks like at least
one podcast feed_url is for an rss feed filtered by /tag/podcast/,
(and at least one post was tagged "podcast" but didn't include any
media to get).

My understanding is at worst we'll ignore the error silently.

* Add test cases

given a blog post (not a podcast episode, no media url), don't raise
any error, don't create any episode.

Included codepunk.io feed that was showing this issue initially.
2022-04-27 11:21:03 -05:00
Mahmoud Harmouch
e4af0ad549
Fixed a grammatical error. (#17413)
* Fixed a grammatical error.

Signed-off-by: Harmouch101 <eng.mahmoudharmouch@gmail.com>

* Updated a test case.

Signed-off-by: Harmouch101 <eng.mahmoudharmouch@gmail.com>
2022-04-27 08:24:57 -06:00
dependabot[bot]
2bc63d6650
Bump focus-trap from 6.7.3 to 6.8.1 (#17425)
* Bump focus-trap from 6.7.3 to 6.8.1

Bumps [focus-trap](https://github.com/focus-trap/focus-trap) from 6.7.3 to 6.8.1.
- [Release notes](https://github.com/focus-trap/focus-trap/releases)
- [Changelog](https://github.com/focus-trap/focus-trap/blob/master/CHANGELOG.md)
- [Commits](https://github.com/focus-trap/focus-trap/compare/v6.7.3...v6.8.1)

---
updated-dependencies:
- dependency-name: focus-trap
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

* mock tabbable in jest

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2022-04-27 08:09:21 -06:00
Daniel Uber
060e426389
validate sort direction (#17439)
* Prefer compact_blank! to delete_if blank

Rubocop suggested this. Why would I argue.

* When sort_direction is anything other than asc or desc, remove it

There is initializer code in the search/query classes that handles nil
sort_direction by adding a default value, so deleting the sort
direction is reasonable here.

* Set a default sort direction for articles of :desc

* Only sort if sort_direction and sort_by are present

* Add test case for article search with invalid parameter
2022-04-27 08:59:13 -05:00
Jeremy Friesen
4bc181503f
Removing WeightedQueryStrategy; use VariantQuery now (#17420)
You had a good ride, but your successor, the
`Articles::Feeds::VariantQuery`, is doing well in production.  And has
been for quite awhile.

You helped us get to a better spot in regards to the feed algorithm, but
your time has come to rest as a memory in our git history.
2022-04-27 09:19:09 -04:00
Jeremy Friesen
daee1f95f4
Updating Rails dependency per CVE (#17440)
https://rubyonrails.org/2022/4/26/Rails-7-0-2-4-6-1-5-1-6-0-4-8-and-5-2-7-1-have-been-released
2022-04-27 07:33:14 -04:00
yheuhtozr
ef290a5120
controllers/admin i18n (#17085)
* admin controllers i18n

* remove ja.yml

* fix for spec

* fix for spec 2

* Apply suggestions from code review

Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>

* Update config/locales/controllers/admin/fr.yml

Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>

Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>
2022-04-26 09:40:09 -06:00
Andy Zhao
0fca6a6f35
Permanently delete users from Mailchimp automatically (#17395)
* Rename unsubscribe to remove_from_mailchimp_newsletters

* Permanently delete from mailchimp instead of unsubscribing

* Rename method and remove comment

* Don't use i18n because of error message

We don't want to use i18n here because e.title comes from the error response. If a Forem
was using a different locale and Mailchimp for newsletters, they would still receive the
error response in English (because of Mailchimp).

* Refactor and rename a bit

* Rename methods in tests accordingly

* Remove now moot test

* Rename method in other places it was previously called

* Remove unused translation, see 62fee247ee2565e4d3d14919a8636a76ce5ecc9f

* Fix typo and report error if not 404
2022-04-26 09:48:50 -04:00
dependabot[bot]
d5e14f8286
Bump core-js from 3.22.1 to 3.22.2 (#17428)
Bumps [core-js](https://github.com/zloirock/core-js) from 3.22.1 to 3.22.2.
- [Release notes](https://github.com/zloirock/core-js/releases)
- [Changelog](https://github.com/zloirock/core-js/blob/master/CHANGELOG.md)
- [Commits](https://github.com/zloirock/core-js/compare/v3.22.1...v3.22.2)

---
updated-dependencies:
- dependency-name: core-js
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-26 09:41:28 +01:00
dependabot[bot]
a366f75d89
Bump autoprefixer from 10.4.4 to 10.4.5 (#17424)
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 10.4.4 to 10.4.5.
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/autoprefixer/compare/10.4.4...10.4.5)

---
updated-dependencies:
- dependency-name: autoprefixer
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-26 09:26:41 +01:00
dependabot[bot]
92d7cccee3
Bump babel-jest from 27.5.1 to 28.0.0 (#17423)
Bumps [babel-jest](https://github.com/facebook/jest/tree/HEAD/packages/babel-jest) from 27.5.1 to 28.0.0.
- [Release notes](https://github.com/facebook/jest/releases)
- [Changelog](https://github.com/facebook/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/jest/commits/v28.0.0/packages/babel-jest)

---
updated-dependencies:
- dependency-name: babel-jest
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-26 09:26:06 +01:00
dependabot[bot]
b0f1452666
Bump github/codeql-action from 1 to 2 (#17421)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 1 to 2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v1...v2)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-25 13:29:57 -06:00
dependabot[bot]
d89c42c96a
Bump @faker-js/faker from 6.1.2 to 6.2.0 (#17426)
Bumps [@faker-js/faker](https://github.com/faker-js/faker) from 6.1.2 to 6.2.0.
- [Release notes](https://github.com/faker-js/faker/releases)
- [Changelog](https://github.com/faker-js/faker/blob/main/CHANGELOG.md)
- [Commits](https://github.com/faker-js/faker/compare/v6.1.2...v6.2.0)

---
updated-dependencies:
- dependency-name: "@faker-js/faker"
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-25 13:04:20 -06:00
dependabot[bot]
cb5173d64a
Bump cypress from 9.5.4 to 9.6.0 (#17422)
Bumps [cypress](https://github.com/cypress-io/cypress) from 9.5.4 to 9.6.0.
- [Release notes](https://github.com/cypress-io/cypress/releases)
- [Changelog](https://github.com/cypress-io/cypress/blob/develop/.releaserc.base.js)
- [Commits](https://github.com/cypress-io/cypress/compare/v9.5.4...v9.6.0)

---
updated-dependencies:
- dependency-name: cypress
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-25 13:03:04 -06:00
Suzanne Aitchison
e6c4e3ba2e
ignore fetched suggestions if input already cleared (#17419) 2022-04-25 16:03:36 +01:00
Jeremy Friesen
a514ca39b8
Removing unused instance variable (#17414)
As I was looking into the implementation details of the `/t/:tag_name`
relevancy feed I noticed an instance variable that we do not need.

Below are the results of looking for the instance_variable
`@article_index` or a potential `article_index` local variable or method name.

```shell
❯ rg "@?article_index"
app/controllers/stories_controller.rb
28:    @article_index = true
131:    @article_index = true
162:    @organization_article_index = true

app/controllers/stories/tagged_articles_controller.rb
18:      @article_index = true

app/controllers/stories/articles_search_controller.rb
7:      @article_index = true

app/views/articles/_single_story.html.erb
26:          <% if story.cached_organization && !@organization_article_index %>
32:          <a href="/<%= story.cached_user.username %>" class="crayons-avatar <% if story.cached_organization && !@organization_article_index %> crayons-avatar--s absolute -right-2 -bottom-2 border-solid border-2 border-base-inverted <% else %> crayons-avatar--l <% end %> ">
79:            <% if story.cached_organization && !@organization_article_index %>
```
2022-04-25 10:43:21 -04:00
Mac Siri
8d45c7377c
Create new feed-variant 20220422 (#17406) 2022-04-25 09:55:33 -04:00
Ridhwana
d9ca26b521
DO NOT MERGE: Remove the Member Index View Feature Flags + old code (#17388)
* feat: remove feature flag on the member index view and re-arrange some partials

* feat: remove Feature Flag for the invitations view

* feat: remove Feature Flag for the gdpr view

* feat: remove Feature Flag for the controls

* feat: remove the feature flag in the tests

* remove extra queries that we no longer use

* Update app/views/admin/invitations/index.html.erb

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* Update app/views/admin/invitations/index.html.erb

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* Update app/views/admin/users/index/_controls.html.erb

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* Update app/views/admin/users/gdpr_delete_requests/index.html.erb

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* Update cypress/integration/seededFlows/adminFlows/users/userIndexView.spec.js

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* Update cypress/integration/seededFlows/adminFlows/users/userIndexView.spec.js

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* Update app/views/admin/users/gdpr_delete_requests/index.html.erb

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* feat: attempt to fix Cypress test

* fix: soem other cypress tests

* fix: search bar

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2022-04-25 14:49:34 +02:00
Jeremy Friesen
8b37e3aca9
Tidying up the Articles::Feeds::VariantQuery (#17396)
This commit does three things:

1.  Breaks the inheritance of the VariantQuery.
2.  Revisits the in-line documentation to better reflect current state.
3.  Removes branching logic that we don't need.

My goal is to have a VariantQuery that is what we need, conforms to the
method interface of WeightedQueryStrategy but does not rely on it.

After we merge this, we can observe if things break on DEV and fallback
to WeightedQueryStrategy if this doesn't work.  Once the
`Articles::Feeds::VariantQuery` has fledged on it's own, we can remove
the feature flag and then finally remove the weighted query strategy.

But that's the future steps.

Related to forem/forem#17393
2022-04-22 15:26:37 -04:00
Jeremy Friesen
b62ecad9ca
Adjusting copy per guidance (#17407)
Closes forem/forem#17322
2022-04-22 15:15:42 -04:00
Suzanne Aitchison
ece0cbbba8
remove redundant feat flag (#17405) 2022-04-22 16:14:16 +01:00
Suzanne Aitchison
33eb6070f4
Reference checkboxes by name (#17403) 2022-04-22 10:44:25 -04:00
Suzanne Aitchison
866546b031
disable creator onboarding feature flag (#17404) 2022-04-22 15:44:07 +01:00
Takuya N
1cb86b973a
Update Bootstrap from 4.4.1 to 4.5.3 (#17391)
Signed-off-by: Takuya Noguchi <takninnovationresearch@gmail.com>
2022-04-22 07:37:12 -04:00
Takuya N
d3dca99dd7
Update @testing-library/cypress from 7.0.7 to 8.0.2 (#17400)
Signed-off-by: Takuya Noguchi <takninnovationresearch@gmail.com>
2022-04-22 07:36:18 -04:00
Takuya N
aed1b9f8c8
Remove @storybook/addon-notes 5 (#17399)
Signed-off-by: Takuya Noguchi <takninnovationresearch@gmail.com>
2022-04-22 07:35:00 -04:00
Anshuman Bhardwaj
a48940772b
Update sort to have nulls at last (#17317)
* Update sort to have nulls at last

* Updating Article.sorting by published to only include published

Co-authored-by: Jeremy Friesen <jeremy.n.friesen@gmail.com>
2022-04-21 12:25:39 -04:00
Daniel Uber
6bf3e2aea9
Skip rescoring draft articles (#17379)
* Skip rescoring draft articles

* add spec for worker
2022-04-21 10:56:59 -05:00
Daniel Uber
de1e1ea7b8
Confirm signout happened by looking for Log in link (#17392)
Similar to checking that "Unpin post" is shown after pinning, wait for
"Log in" to show after signing out before checking that signed out
users can see a pinned post.

Recommended by @aitchiss in a comment on #17385 as a way to limit
false negatives (where we check the previously signed in user's view)
2022-04-21 10:34:05 -05:00
Jeremy Friesen
0d0464be2f
Allowing VariantQuery for Feed Generation (#17382)
* Allowing VariantQuery for Feed Generation

Apologies for the breadth of this pull request, I had considered many
small commits, but felt that would've been more effort for the value
provided.

This commit includes the following:

- Documentation updates to the feed variant (though not the final pass)
- Renaming and adding RelevancyLevers that help differentiate
- Adding RelevancyLever#range to provide documentation
- Reducing redundent controller logic by making a
  `Articles::Feeds.feed_for` method.
- Adding some configuration validation for RelevancyLevers
- Adding constants for better clarification
- Testing unhappy paths for feed configuration
- Adjusting the module namespace of some objects
- Exposing top-level configurations for variants (along with their
  defaults)
- Creating the VariantyQuery that at present inherits from the
  `Articles::Feeds::WeightedQueryStrategy`

As implemented, we can deploy this code to production without using the
new VariantQuery.  Once we toggle on the
`:feed_uses_variant_query_feature` FeatureFlag, it will switch to using
the VariantQuery.  The VariantQuery's two variants and the
internal configuration of `Articles::Feeds::WeightedQueryStrategy`
produce the same query.

The goal of this factor is to allow for a quick on and off toggle of the
feed query; to ensure that what we introduce remains performant.

- Closes forem/forem#17272
- Closes forem/forem#17276
- Closes forem/forem#17216

In addition, I will be recording a code-walkthrough and linking that
recording to the pull request.

* Apply suggestions from code review

Co-authored-by: Mac Siri <krairit.siri@gmail.com>

Co-authored-by: Mac Siri <krairit.siri@gmail.com>
2022-04-21 11:07:09 -04:00
Daniel Uber
2f4f98462e
e2e: Reload the page after changing authentication (#17387)
* Reload the config page after changing auth

When testing in Chrome (but not Firefox or Electron) I noticed this
test would fail. The issue appears to have been findByLabelText (used
to check Email enabled, Facebook enabled, etc are not visible) was not
finding the labels when the group was still hidden.

I _think_ there was a time, when this test was first written, that
submitting the form reloaded the page (simple form post), but that may
have been replaced with an xhr submission and some client side
replacement?

I tried not clicking the Authentication after enabling invite only (to
prevent hiding the form content, leaving this section expanded),
however this caused the "Email enabled" check to fail (it was still
visible). I think this means it had been passing because it was not
visible because the section was hidden, not because the label had been
updated properly after the submission.

I'm not sure if fixing the test here papers over a UI issue, but it
would be best if these tests worked consistently across browsers. I
suspect this may have behaved differently in earlier versions of
Chrome, or only been tested interactively in Chrome when the page
still reloaded, and this caused some drift.

* Update cypress/integration/seededFlows/adminFlows/config/authenticationSection.spec.js

prefer reload to calling visit a second time

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2022-04-21 09:46:17 -05:00
Daniel Uber
f6a648c607
Address a flaky spec by waiting (#17385)
We had seen an increase in CI timeouts (no output received for 10
minutes).

Running this example (signed out user sees the pinned article)
repeatedly I was able to reproduce the failure seen in Travis, and
checking the last few times this occurred it appears to be linked to
the pinArticle.spec.js last test, which fails with an
ApplicationPolicy when pinning.

The likeliest source of this issue is the POST (pin the article) is
received concurrently with the session delete (logging the admin user
out), resulting in a race. If/when the signout occurs before the
article policy is checked (does the current user have permission to
pin an article), the cypress running stalls.

This occurred both interactively (bin/e2e or cypress open) and
headless (cypress run/CI). The error went away reliably after
inserting this guard to check for the "Unpin post" link on the page,
which forces the POST to have completed and redirected back to the
admin page before logging out.

My understanding of this problem is borne out in the local test logs,
where the signout and pin requests arrive concurrently and process out
of order (and the POST gives a 404 instead of a 302).

    Started DELETE "/users/sign_out" for 127.0.0.1 at 2022-04-20 12:09:23 -0500
    Started POST "/admin/content_manager/articles/1/pin" for 127.0.0.1 at 2022-04-20 12:09:23 -0500
    Completed 204 No Content in 42ms (ActiveRecord: 6.2ms | Allocations: 6323)
    Completed 404 Not Found in 4ms (ActiveRecord: 0.4ms | Allocations: 833)
2022-04-21 09:18:08 -05:00
Jeremy Friesen
8fbc2e86d5
Updating Blazer to 2.6.1 (#17390)
Prior to this commit, we were seeing the following:

```console
❯ bundle exec bundle-audit check --update
Updating ruby-advisory-db ...
From https://github.com/rubysec/ruby-advisory-db
 * branch            master     -> FETCH_HEAD
Already up to date.
Updated ruby-advisory-db
ruby-advisory-db:
  advisories:	562 advisories
  last updated:	2022-04-20 14:56:09 -0700
  commit:	1cca55530261d16f4cd16691c1ebbae86c91c28b
Name: blazer
Version: 2.5.0
CVE: CVE-2022-29498
Criticality: Unknown
URL: https://github.com/ankane/blazer/issues/392
Title: SQL injection for certain queries with variables
Solution: upgrade to >= 2.6.0

Vulnerabilities found!
```

Blocking forem/forem#17382
2022-04-21 09:53:00 -04:00
Takuya N
92030f4798
Update cypress from 8.7.0 to 9.5.4 (#17368)
Signed-off-by: Takuya Noguchi <takninnovationresearch@gmail.com>
2022-04-20 20:31:50 -04:00
Takuya N
2b1f92f322
Remove DISABLE_STRING variables after PR#16848 (#17367)
Signed-off-by: Takuya Noguchi <takninnovationresearch@gmail.com>
2022-04-20 14:42:11 -06:00
Jeremy Friesen
f1e9e3ff65
Busting tag cache when space changes (#17384)
We avoid busting a user cache for 15 minutes but the tag cache is 5
hours.  So we want to "nudge things along".

What this is trying to solve is the server side rendering of whether we
hide or show a button.

Related to forem/forem#17324
Related to forem/forem#17119
2022-04-20 16:37:34 -04:00
Suzanne Aitchison
9d9bf8763a
fix bug in search and filter indicators (#17341) 2022-04-20 17:57:57 +01:00
Daniel Uber
4d33486e14
Enable string uuid as namespace (#17309)
* Enable string uuid as namespace

This addresses a noisy deprecation warning showing in specs (it points
to our re-implementation of warden's sign_in_as helper, but I suspect
the issue is within warden since our initializer seems to match the
implementation in the upstream gem).

My understanding of this is that the prior default had been to pass
the provided uuid namespace as-is if it didn't match one of a few
named constants. New behavior is to validate that any string provided
as a namespace looks like a uuid representation or fail).

* Move configuration change to framework defaults
2022-04-20 10:24:25 -05:00
dependabot[bot]
cd9771bc2c
Bump @storybook/preact from 6.4.21 to 6.4.22 (#17380)
Bumps [@storybook/preact](https://github.com/storybookjs/storybook/tree/HEAD/app/preact) from 6.4.21 to 6.4.22.
- [Release notes](https://github.com/storybookjs/storybook/releases)
- [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md)
- [Commits](https://github.com/storybookjs/storybook/commits/v6.4.22/app/preact)

---
updated-dependencies:
- dependency-name: "@storybook/preact"
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-04-20 16:11:22 +01:00
ludwiczakpawel
a6584ffc09
toggle fix for spaces (#17343) 2022-04-20 16:45:34 +02:00