Commit graph

10497 commits

Author SHA1 Message Date
Michael Kohl
84a45b3583
Remove Doorkeeper and webhook tables (#15854) 2021-12-29 10:09:14 +07:00
dependabot[bot]
470bb17d6a
Bump lint-staged from 12.1.2 to 12.1.4 (#15882)
Bumps [lint-staged](https://github.com/okonet/lint-staged) from 12.1.2 to 12.1.4.
- [Release notes](https://github.com/okonet/lint-staged/releases)
- [Commits](https://github.com/okonet/lint-staged/compare/v12.1.2...v12.1.4)

---
updated-dependencies:
- dependency-name: lint-staged
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-28 15:49:42 -06:00
Mac Siri
0b0902d81d
Add catch to trackFifteenSecondsOnPage() (#15886) 2021-12-28 12:44:36 -05:00
Michael Kohl
5da625cadb
Rubocop fixes (#15892)
* Add missing spaces

* Use filter_map over map + reject/compact

* Simplify FactoryBot calls

* Use to_h with block instead of map + to_h

* Use guard clause
2021-12-28 09:11:41 -06:00
Anna Buianova
c460cce85e
Mock omniauth payload before creating identities (#15893) 2021-12-28 09:06:17 -06:00
Anna Buianova
792cd68786
Fixed setting Identity#auth_data_dump in seeds and factory (#15874)
* Fixed setting Identity#auth_data_dump in seeds and factory

* Mock omniauth providers in the Identity spec
2021-12-28 09:02:15 +03:00
Michael Kohl
06d6b68d9d
Remove webhooks and related code (#15827) 2021-12-28 10:56:37 +07:00
dependabot[bot]
ec9e9053d5
Bump rubocop-rspec from 2.6.0 to 2.7.0 (#15884)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-28 10:51:48 +07:00
dependabot[bot]
dd4eef5733
Bump i18n-tasks from 0.9.36 to 0.9.37 (#15887)
Bumps [i18n-tasks](https://github.com/glebm/i18n-tasks) from 0.9.36 to 0.9.37.
- [Release notes](https://github.com/glebm/i18n-tasks/releases)
- [Changelog](https://github.com/glebm/i18n-tasks/blob/main/CHANGES.md)
- [Commits](https://github.com/glebm/i18n-tasks/compare/v0.9.36...v0.9.37)

---
updated-dependencies:
- dependency-name: i18n-tasks
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-27 16:06:24 -06:00
dependabot[bot]
2fb02027fe
Bump kaminari from 1.2.1 to 1.2.2 (#15889)
Bumps [kaminari](https://github.com/kaminari/kaminari) from 1.2.1 to 1.2.2.
- [Release notes](https://github.com/kaminari/kaminari/releases)
- [Changelog](https://github.com/kaminari/kaminari/blob/master/CHANGELOG.md)
- [Commits](https://github.com/kaminari/kaminari/compare/v1.2.1...v1.2.2)

---
updated-dependencies:
- dependency-name: kaminari
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-27 16:04:35 -06:00
Daniel Uber
648062d69a
Require parameter string before matching time for youtube video ids (#15890)
We are seeing test failures when an id like "aaabbbcccdd1m" match with
"1m" as the time parameter. I think we only want to match the time
when a ?t= or ?start= (and the permissive &t= or &start=, which might
only be part of the larger REGISTRY_REGEXP and either not effective or
not needed for the video id pattern)

The goal here is these should be valid

"aaabbbcccdd"
"aaabbbcccdd?t=1"
"aaabbbcccdd?start=1h23m55s"
"aaabbbcccdd&t=1"

but not these

"aaabbbcccddt=1"
"aaabbbcccddstart=1"
"aaabbbcccdd123456h"

The same logic may be appropriate to backfill into the prior regexp as
well, my immediate concern is with randomly generated 12-15 character
strings from Fake getting matched during testing (where they were
expected to raise an error during id parsing).
2021-12-27 15:04:40 -06:00
Daniel Uber
c879c5b3d8
Remove slash characters from user name search term (#15867)
* Remove slash characters from user supplied user search input

Prevents an error when the search term includes '\'

    PG::SyntaxError: ERROR:  syntax error in tsquery

https://app.honeybadger.io/projects/66984/faults/79391397

I had originally thought to add this cleanup to Search::Username but
decided to move it as close to the generated (invalid) query as
possible to prevent alternate paths finding their way here.

* Add spec

Since there's no existing tests for the scope - I put the test code on
the caller (Search::Username) rather than the model (User), this seems reasonable.

* When the term is empty (or only slashes) just return null relation

* Handle nil input (search for nothing) correctly

One of the request specs sends a username search with no query, so we
can't call nil.delete or nil.empty?, use blank? of empty?
2021-12-27 12:30:36 -06:00
Daniel Uber
4d40ea18a2
When returning a json error, don't use a raw unescaped string (#15879)
The 400 and 403 error pages show json parsing errors in most browsers,
since "Error: Bad Request" is not a valid json body ('"Error: Bad
Request"' would be, or the object with key error and value of the
string which I've selected is _also_ valid).

Do we have frontend code that's looking for this body before it parses
for some reason, or was this just a mistaken copying from the api
controller in the initial PRs (#2293 for not_authorized, and #6248 for
the bad_request method, which may have just replicated the decision
for not_authorized)?
2021-12-27 11:39:15 -06:00
Jeremy Friesen
0b8c09851c
Favoring constant over magic string (#15852) 2021-12-27 11:31:29 -05:00
dependabot[bot]
2bf13cab00
Bump shoulda-matchers from 5.0.0 to 5.1.0 (#15871)
Bumps [shoulda-matchers](https://github.com/thoughtbot/shoulda-matchers) from 5.0.0 to 5.1.0.
- [Release notes](https://github.com/thoughtbot/shoulda-matchers/releases)
- [Changelog](https://github.com/thoughtbot/shoulda-matchers/blob/main/CHANGELOG.md)
- [Commits](https://github.com/thoughtbot/shoulda-matchers/compare/v5.0.0...v5.1.0)

---
updated-dependencies:
- dependency-name: shoulda-matchers
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-27 09:41:03 -06:00
dependabot[bot]
6fba63d224
Bump honeycomb-beeline from 2.7.1 to 2.8.0 (#15870)
Bumps [honeycomb-beeline](https://github.com/honeycombio/beeline-ruby) from 2.7.1 to 2.8.0.
- [Release notes](https://github.com/honeycombio/beeline-ruby/releases)
- [Changelog](https://github.com/honeycombio/beeline-ruby/blob/main/CHANGELOG.md)
- [Commits](https://github.com/honeycombio/beeline-ruby/compare/v2.7.1...v2.8.0)

---
updated-dependencies:
- dependency-name: honeycomb-beeline
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-27 09:13:56 -06:00
dependabot[bot]
2d98e3346b
Bump rubocop from 1.23.0 to 1.24.0 (#15872)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Michael Kohl <me@citizen428.net>
2021-12-27 10:04:59 -05:00
dependabot[bot]
159c9c9b45
Bump flipper, flipper-active_record, flipper-active_support_cache_store and flipper-ui (#15875)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-27 09:52:22 -05:00
Jeremy Friesen
c7902a3261
Favor destroy_by over where.first&.destroy (#15868)
* Favor `destroy_by` over `where.first&.destroy`

We can use [ActiveRecord::Relation.destroy_by][1] instead of the method
chain.

[1]:https://api.rubyonrails.org/classes/ActiveRecord/Relation.html#method-i-destroy_by

* Restoring custom behavior

Those constants are not ActiveRecord::Base objects, so don't implement
the method.
2021-12-22 23:55:52 -05:00
Jeremy Friesen
6d37f4303c
Favoring single SQL and computation over enum (#15865)
* Favoring single SQL and computation over enum

Prior to this commit, we ran a SQL statement to generate a list of
articles then applied some minor randomization.

With this commit, I'm removing the randomization in favor of expected
values, and collapsing the result set into a single inline SQL and some
post query simple arithmatic.

Let's check my math.  For each article we sum:

* `article.score`
* `article.comments_count` * 14
* a random number between 0 and 5 (`rand(6)`) with expected value of 2.5
* the tag's (taggings_count + 1) / 2

The new SQL query sums the `article.score` and the
`article.comments_count` * 14.  I then reduce the remainder of the
equation.  From "for each article sum `(rand(5) + (taggings_count + 1) /
2)`" we have the following:

`article_count * (2.5 + (taggings_count + 1) / 2)`

Which is equivalent to:

`article_count * ((taggings_count + 1 + (2.5 * 2)) / 2)`

Which is equivalent to:

`article_count * ((taggings_count + 6) / 2)`

This change reduces computation time by favoring expected values.

* Fixing broken behavior and adding comments
2021-12-22 14:59:37 -05:00
Mac Siri
ea037a127a
Add catch to trackAdImpression() (#15864) 2021-12-22 13:12:37 -05:00
Josh Puetz
10c13078cb
User correct username in mobile mention notifications (#15861) 2021-12-22 10:31:22 -06:00
Jeremy Friesen
c75dd69d09
Favoring common method not previously available (#15855)
With this refactor, I'm adding documentation and favoring using a common
method that wasn't available at the time of implementation.

In [this commit][1] we had logic that said "if we have a singular tag
use the cache" otherwise use the join.  At that time, the implementation
of [Article.cached_tag_with][previous] was as follows, allowing only a
singular tag:

```ruby
scope :cached_tagged_with, ->(tag) { where("cached_tag_list ~* ?",
"^#{tag},| #{tag},|, #{tag}$|^#{tag}$") }
```

The [current implementation][current], as of writing this, allows for
multiple tags and is as follows:

```ruby
scope :cached_tagged_with, lambda { |tag|
  case tag
  when String, Symbol
    # In Postgres regexes, the [[:<:]] and [[:>:]] are equivalent to "start of
    # word" and "end of word", respectively. They're similar to `\b` in Perl-
    # compatible regexes (PCRE), but that matches at either end of a word.
    # They're more comparable to how vim's `\<` and `\>` work.
    where("cached_tag_list ~ ?", "[[:<:]]#{tag}[[:>:]]")
  when Array
    tag.reduce(self) { |acc, elem| acc.cached_tagged_with(elem) }
  when Tag
    cached_tagged_with(tag.name)
  else
    raise TypeError, "Cannot search tags for: #{tag.inspect}"
  end
}
```

Given that we are content to use the cached tag in the singular tag
case, it seems safe to say that we're comfortable using it in the
multiple tag case.

[1]:af5a391429 (diff-24503fd25ed68e6ebceee4951bc4f9b255b197278d4aa9d86ef9d5afe3f26bea)
[previous]:af5a391429/app/models/article.rb (L151)
[current]:98e97e7aa8/app/models/article.rb (L212-L227)
2021-12-22 11:00:54 -05:00
dependabot[bot]
98e97e7aa8
Bump js-routes from 2.1.2 to 2.2.0 (#15845)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-21 14:53:11 -05:00
dependabot[bot]
5b162d42b6
Bump jbuilder from 2.11.4 to 2.11.5 (#15847)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-21 14:52:48 -05:00
dependabot[bot]
f7ddd807b3
Bump view_component from 2.46.0 to 2.47.0 (#15846)
Bumps [view_component](https://github.com/github/view_component) from 2.46.0 to 2.47.0.
- [Release notes](https://github.com/github/view_component/releases)
- [Changelog](https://github.com/github/view_component/blob/main/docs/CHANGELOG.md)
- [Commits](https://github.com/github/view_component/compare/v2.46.0...v2.47.0)

---
updated-dependencies:
- dependency-name: view_component
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-21 13:29:07 -05:00
dependabot[bot]
01ec04a9b9
Bump i18n-tasks from 0.9.35 to 0.9.36 (#15844)
Bumps [i18n-tasks](https://github.com/glebm/i18n-tasks) from 0.9.35 to 0.9.36.
- [Release notes](https://github.com/glebm/i18n-tasks/releases)
- [Changelog](https://github.com/glebm/i18n-tasks/blob/main/CHANGES.md)
- [Commits](https://github.com/glebm/i18n-tasks/compare/v0.9.35...v0.9.36)

---
updated-dependencies:
- dependency-name: i18n-tasks
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-21 12:21:47 -06:00
Jeremy Friesen
a40efc6bbd
Refactoring questions asked of user (#15762)
* Refactoring questions asked of user

In this pull request, I'm extracting and normalizing role-based
questions asked of the user.

Prior to this commit, our codebase has asked two very similar questions
of our user model:

- `user.has_role?(:admin)`
- `user.admin?`

In asking `has_role?(:admin)` we are relying on implementation details
of the rolify gem.  In addition, the `has_role?` question asked
throughout controllers or views means that it's harder to create
hieararchies of permissions.

In favoring `user.admin?` as our question, we can use that indirection
as an opportunity to discuss and decide "Should someone with the
`:super_admin` role be `user.admin? == true`?"

The details of this commit is to do three primary things:

1. Ask the `has_role?` questions in "one place" in the code (e.g. the
   `Authorizer` module)
2. Extract the role based questions that are on the `User` model and
   provde backwards compatable delegation.
3. Structure the code so that it's harder to accidentally call
   `user.has_role?` (e.g., make `User#has_role?` and `User#has_any_role?`
   private).

This is related to #15624 and the updates are informed by discussion in
PR #15691.  This commit supplants #15691.

* Refactoring the liquid tag policy tests

* Fixing typo

* Bump for travis
2021-12-21 12:45:12 -05:00
Suzanne Aitchison
5fd1f94e85
Add comment notification test to Cypress, including a11y improvements to notification page (#15842)
* changes to accessible names on notification comment box, cypress specs

* add reply to comment test, delete old specs

* tweak to seeds
2021-12-21 15:42:13 +00:00
dependabot[bot]
c2659d38df
Bump eslint-config-preact from 1.2.0 to 1.3.0 (#15834)
* Bump eslint-config-preact from 1.2.0 to 1.3.0

Bumps [eslint-config-preact](https://github.com/preactjs/eslint-config-preact) from 1.2.0 to 1.3.0.
- [Release notes](https://github.com/preactjs/eslint-config-preact/releases)
- [Commits](https://github.com/preactjs/eslint-config-preact/compare/1.2.0...v1.3.0)

---
updated-dependencies:
- dependency-name: eslint-config-preact
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

* apply new lint fixes after version bump

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2021-12-21 14:42:20 +00:00
yheuhtozr
5253717797
fix character limits i18n (#15830) 2021-12-21 07:15:21 -05:00
dependabot[bot]
7d80475f1a
Bump core-js from 3.19.3 to 3.20.0 (#15837) 2021-12-21 07:11:51 -05:00
Michael Kohl
872b007c30
Remove Doorkeeper gem (#15749) 2021-12-21 12:29:58 +07:00
yheuhtozr
021ed9708e
restore i18n key _footer.html.erb (#15831) 2021-12-20 16:33:41 -06:00
Daniel Uber
032378b3bd
Disable dash replacement filter in markdown fixer (#15839)
* Remove modify_hr_tags method definition

this breaks things that call it.

* Remove direct uses of modify_hr_tags fixer method

Remove from class METHODS lists, remove test cases about this behavior, and remove from
methods lists in test cases.

* Remove hr tag modification spec

Still don't understand what problem this was fixing, but I've removed
the test case.
2021-12-20 15:39:55 -06:00
dependabot[bot]
5219409bc1
Bump debug from 1.3.4 to 1.4.0 (#15835)
Bumps [debug](https://github.com/ruby/debug) from 1.3.4 to 1.4.0.
- [Release notes](https://github.com/ruby/debug/releases)
- [Commits](https://github.com/ruby/debug/compare/v1.3.4...v1.4.0)

---
updated-dependencies:
- dependency-name: debug
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-20 14:43:49 -06:00
dependabot[bot]
2f47b47c32
Bump bullet from 6.1.5 to 7.0.0 (#15833)
Bumps [bullet](https://github.com/flyerhzm/bullet) from 6.1.5 to 7.0.0.
- [Release notes](https://github.com/flyerhzm/bullet/releases)
- [Changelog](https://github.com/flyerhzm/bullet/blob/master/CHANGELOG.md)
- [Commits](https://github.com/flyerhzm/bullet/compare/6.1.5...7.0.0)

---
updated-dependencies:
- dependency-name: bullet
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-20 14:21:50 -06:00
dependabot[bot]
a2f324a2dc
Bump rouge from 3.26.1 to 3.27.0 (#15791)
Bumps [rouge](https://github.com/rouge-ruby/rouge) from 3.26.1 to 3.27.0.
- [Release notes](https://github.com/rouge-ruby/rouge/releases)
- [Changelog](https://github.com/rouge-ruby/rouge/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rouge-ruby/rouge/compare/v3.26.1...v3.27.0)

---
updated-dependencies:
- dependency-name: rouge
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-20 11:09:31 -05:00
ludwiczakpawel
d125617e13
CSS Variables cleanup (#15828)
* variables cleanup

* little fix
2021-12-20 15:42:40 +01:00
ludwiczakpawel
5e098df276
fix (#15829) 2021-12-20 13:38:29 +01:00
Anna Buianova
9f688be406
Moved setting old_username from before_validation to Users::Update (#15782)
* Moved setting old_username from before_validation to Users::Update

* Removed unused code

* Fixed specs after moving setting old_usernames
2021-12-20 11:08:09 +03:00
ludwiczakpawel
9b7503fde3
Update left sidebar links with new Crayons components (#15757)
* update

* hamburger fix

* Update app/views/shared/_hamburger.html.erb

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* updates

* spec

* social media icons

* reading list counter

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2021-12-20 08:46:30 +01:00
Andy Zhao
8a7e5a5566
Escape periods and display the group name properly (#15819)
* Escape periods and display the group name properly

* Rename method to dom_safe_name and move to admin helper

* Replace beginning of string digit with underscore then digit
2021-12-17 17:35:42 -05:00
Andy Zhao
6335f9a7e9
Remove profile when banish (#15818)
* Clear profile when banishing user

* Add test for clearing profile when banishing

* Also clear any social usernames
2021-12-17 15:36:35 -05:00
Jamie Gaskins
329f33448f
Disallow null user agent and obsolete browser (#15817)
We were previously disallowing empty user agents, but we weren't
blocking requests where the User-Agent header wasn't set at all. This
commit blocks those requests.

This commit also blocks Chrome 74. It's a 2.5-year-old version of an
evergreen browser that releases every 6 weeks, so this is clearly a bot
spoofing this header.
2021-12-17 15:02:30 -05:00
Dwight Scott
325a9f9e3f
Add me (Dwight) to readme :) (#15816) 2021-12-17 14:50:45 -05:00
dependabot[bot]
fb758a3bbe
Bump strong_migrations from 0.7.8 to 0.7.9 (#15812)
Bumps [strong_migrations](https://github.com/ankane/strong_migrations) from 0.7.8 to 0.7.9.
- [Release notes](https://github.com/ankane/strong_migrations/releases)
- [Changelog](https://github.com/ankane/strong_migrations/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ankane/strong_migrations/compare/v0.7.8...v0.7.9)

---
updated-dependencies:
- dependency-name: strong_migrations
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-17 13:31:53 -05:00
dependabot[bot]
c6ed3b6a2b
Bump field_test from 0.5.1 to 0.5.2 (#15813)
Bumps [field_test](https://github.com/ankane/field_test) from 0.5.1 to 0.5.2.
- [Release notes](https://github.com/ankane/field_test/releases)
- [Changelog](https://github.com/ankane/field_test/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ankane/field_test/compare/v0.5.1...v0.5.2)

---
updated-dependencies:
- dependency-name: field_test
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-17 13:29:57 -05:00
dependabot[bot]
c047dd2631
Bump jbuilder from 2.11.3 to 2.11.4 (#15815)
Bumps [jbuilder](https://github.com/rails/jbuilder) from 2.11.3 to 2.11.4.
- [Release notes](https://github.com/rails/jbuilder/releases)
- [Changelog](https://github.com/rails/jbuilder/blob/master/CHANGELOG.md)
- [Commits](https://github.com/rails/jbuilder/compare/v2.11.3...v2.11.4)

---
updated-dependencies:
- dependency-name: jbuilder
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-17 12:28:36 -06:00
Arit Amana
dee0b36981
Implement Unified Embed for CodeSandbox URLs (#15808)
* Implement embed and write specs

* fix slight regex ommision

* remove error over invalid options; add specs to cover

* account for missing options when using embed keyword

* no videos, no ns video_id 🤦🏾‍♀️
2021-12-17 12:12:54 -05:00