Commit graph

10436 commits

Author SHA1 Message Date
Jeremy Friesen
aa7712a80e
Extracting container for allowed tags & attrs (#15338)
* Extracting container for allowed tags & attrs

Prior to this commit, we had several different locations in which we
specified ALLOWED_TAGS and ALLOWED_ATTRIBUTES for HTML rendering and
sanitization.

Curious to see how these either intersected or didn't, I opted to
create a container module that allows for us to more readily normalize
these allowed tags and attributes.  It's possible that we won't do any
normalization, but this work helps make that easier.

Ideally, I'd love us to contextualize "why did we choose the
tags/attributes we chose?"  But for now, I think consolidating these
tags and attributes will help make adding a `details` and `summary` tag
easier.

This relates to forem/rfcs#296

See [Google Sheet][1] for analysis of what tags/attributes are used, the
intersection and union.

[1]:https://docs.google.com/spreadsheets/d/1yj-a1qus1o0o4cj-_gOMP5yteeg-_f3s5z7kvK0Y7RM/edit#gid=0

* Fixing misnamed constant

* Fixing misnamed constant

* Extracting additional HtmlRendering use cases

* Adding comparative documentation for HTML tags

* Fixing broken parameter signature

* Moving constants into MarkdownProcessor
2021-12-16 12:24:45 -05:00
Josh Puetz
731849a068
Mobile mention notifications (#15780) 2021-12-16 11:06:54 -06:00
Josh Puetz
3fd03b5ed6
Remove line break after linking username mentions (#15788) 2021-12-16 10:39:07 -06:00
Mac Siri
dfb0d0300c
Monkey-patch instead of forking cypress-rails gem (#15797) 2021-12-16 11:36:45 -05:00
Michael Kohl
b22ad4c976
Remove Doorkeeper from API (#15750)
Co-authored-by: Dan Uber <dan@forem.com>
2021-12-16 09:57:26 -06:00
Nick Taylor
2063d73459
Changed members only copy for radio button label to invite only. (#15795) 2021-12-16 08:31:31 -05:00
Nick Taylor
70e233953c
Disabled Spring for E2E databse when run locally (#15793) 2021-12-15 15:58:13 -05:00
Arit Amana
19d8cad1e9
Implement IG unified embed; add specs (#15792) 2021-12-15 15:35:43 -05:00
ludwiczakpawel
0cce606938
Error message after authentication failure due to email address not being whitelisted (#15779)
* cosmetics

* cosmetics

* Build restart

* generator failing build?

* generator failing build?
2021-12-15 21:25:27 +01:00
ludwiczakpawel
a96d69faab
✂️✂️✂️ Drop PWA (#15781)
* drop pwa stuff

* this was breaking the build... shrug.gif

* Update app/assets/javascripts/initializers/runtime.js

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* shorthand for if

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2021-12-15 21:25:04 +01:00
ludwiczakpawel
2e82b92435
fix (#15783) 2021-12-15 20:39:15 +01:00
Nick Taylor
6df9309284
Added the logo upload to the admin -> customization -> config -> images section. (#15729)
Co-authored-by: Michael Kohl <citizen428@forem.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
Co-authored-by: Mac Siri <mac@forem.com>
Co-authored-by: Ridhwana <Ridhwana.Khan16@gmail.com>
2021-12-15 14:10:27 -05:00
Jamie Gaskins
cde4e08534
Automatically create user profile if it's missing (#15787)
I don't know how it's nil, but it is, so we can remediate that here
2021-12-15 14:03:51 -05:00
dependabot[bot]
9f6419ca6b
Bump devise_invitable from 2.0.5 to 2.0.6 (#15790)
Bumps [devise_invitable](https://github.com/scambra/devise_invitable) from 2.0.5 to 2.0.6.
- [Release notes](https://github.com/scambra/devise_invitable/releases)
- [Changelog](https://github.com/scambra/devise_invitable/blob/master/CHANGELOG.md)
- [Commits](https://github.com/scambra/devise_invitable/compare/v2.0.5...v2.0.6)

---
updated-dependencies:
- dependency-name: devise_invitable
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-15 12:22:14 -06:00
Jeremy Friesen
fa093b0a92
Refactoring instance variable usage in tagged articles controller (#15687)
* Refactoring away from instance variables

Having both `@tag` and `@tag_model` as variable names can be confusing.

Given that in the prior implementation `@tag_model.name == @tag`, I
figured I would refactor the controller to remove an instance variable.

In addition, this refactor addresses the temporal coupling of methods;
that is to say we call a method which sets an instance variable then
call another dependent on that instance variable.

Yes, ivars are useful to allow for implicit state.  However, by favoring
parameters its easier to notice temporal dependencies in method calls.

This helps ensure that we're calling methods in the right order.

Futher, we have a guard clause in place, so let's avoid setting any
additional instance variables that aren't needed if the guard clause
executes.

Related to #15359

* Update app/controllers/stories/tagged_articles_controller.rb

Co-authored-by: Michael Kohl <citizen428@forem.com>

* Favoring constants and Rails where constructs

Prior to this commit, we had a magic array.  That magic array was a
duplicate of the Timeframe constant.  Likewise, we had a magic string.

This change removes that duplication.

Furthermore, this change favors the `where(key: range..)` construct
instead of "raw" SQL and parameter substition.

Co-authored-by: Michael Kohl <citizen428@forem.com>
2021-12-15 10:49:50 -05:00
Jeremy Friesen
a5058d3744
Consolidating role query logic (#15773)
* Consolidating role query logic

Prior to this commit, we had two logically identical chunks of code.

With this commit, we consolidate that logic into a single method.  In
addition, we remove one place where the application knows about the
roles implementation.

Loosely related to #15624.

* Bump for travis
2021-12-15 10:49:32 -05:00
Ridhwana
0c51185232
Bust cache after we update the Settings in the Creator Onboarding (#15785)
* feat: bust caches after th create actionon the creator_settings

* spec: update to make sure that we update the cache key
2021-12-15 16:27:58 +02:00
Mac Siri
a5de970341
Bump Rails to 6.1.4.3 (#15784) 2021-12-15 08:54:02 -05:00
dependabot[bot]
15e6e56c39
Bump postcss from 8.4.4 to 8.4.5 (#15752)
Bumps [postcss](https://github.com/postcss/postcss) from 8.4.4 to 8.4.5.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](https://github.com/postcss/postcss/compare/8.4.4...8.4.5)

---
updated-dependencies:
- dependency-name: postcss
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-15 13:46:59 +00:00
dependabot[bot]
361ff1c287
Bump @babel/plugin-transform-react-jsx from 7.16.0 to 7.16.5 (#15767)
Bumps [@babel/plugin-transform-react-jsx](https://github.com/babel/babel/tree/HEAD/packages/babel-plugin-transform-react-jsx) from 7.16.0 to 7.16.5.
- [Release notes](https://github.com/babel/babel/releases)
- [Changelog](https://github.com/babel/babel/blob/main/CHANGELOG.md)
- [Commits](https://github.com/babel/babel/commits/v7.16.5/packages/babel-plugin-transform-react-jsx)

---
updated-dependencies:
- dependency-name: "@babel/plugin-transform-react-jsx"
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-15 06:44:21 -07:00
Mac Siri
aac9569a84
Replace honeybadger-js with @honeybadger-io/js (#15770) 2021-12-15 08:39:08 -05:00
Suzanne Aitchison
0295dbeabf
Update a11y of ButtonGroup component (#15765) 2021-12-15 12:52:33 +00:00
dependabot[bot]
0669ebbfa3
Bump preact from 10.6.2 to 10.6.4 (#15771)
Bumps [preact](https://github.com/preactjs/preact) from 10.6.2 to 10.6.4.
- [Release notes](https://github.com/preactjs/preact/releases)
- [Commits](https://github.com/preactjs/preact/compare/10.6.2...10.6.4)

---
updated-dependencies:
- dependency-name: preact
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 13:59:24 -07:00
dependabot[bot]
1fdd2e9534
Bump prettier from 2.5.0 to 2.5.1 (#15761)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 15:56:32 -05:00
Nick Taylor
33e7deee55
Put back default community name. (#15777) 2021-12-14 13:48:38 -07:00
dependabot[bot]
c17bb4877c
Bump ahoy_email from 2.1.0 to 2.1.1 (#15774)
Bumps [ahoy_email](https://github.com/ankane/ahoy_email) from 2.1.0 to 2.1.1.
- [Release notes](https://github.com/ankane/ahoy_email/releases)
- [Changelog](https://github.com/ankane/ahoy_email/blob/master/CHANGELOG.md)
- [Commits](https://github.com/ankane/ahoy_email/compare/v2.1.0...v2.1.1)

---
updated-dependencies:
- dependency-name: ahoy_email
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 13:46:55 -07:00
Arit Amana
7d8fe9440a
Implement Unified Embed for Forem Article/Post URLs (#15745)
* Implementation & Specs

* Fix broken spec - yay! 🎉

* Address PR review comments

* Fix my mess

* restart CI
2021-12-14 14:56:51 -05:00
Jamie Gaskins
9e0570968e
Strip surrounding whitespace from HTMLVariant name (#15776) 2021-12-14 14:42:06 -05:00
dependabot[bot]
9970a57841
Bump stripe from 5.41.0 to 5.42.0 (#15775)
Bumps [stripe](https://github.com/stripe/stripe-ruby) from 5.41.0 to 5.42.0.
- [Release notes](https://github.com/stripe/stripe-ruby/releases)
- [Changelog](https://github.com/stripe/stripe-ruby/blob/master/CHANGELOG.md)
- [Commits](https://github.com/stripe/stripe-ruby/compare/v5.41.0...v5.42.0)

---
updated-dependencies:
- dependency-name: stripe
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 11:38:14 -07:00
dependabot[bot]
262b68f09f
Bump @testing-library/jest-dom from 5.15.1 to 5.16.1 (#15766) 2021-12-14 12:05:41 -05:00
dependabot[bot]
d77d7bad95
Bump @babel/preset-env from 7.16.4 to 7.16.5 (#15763)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 11:23:56 -05:00
dependabot[bot]
e0f2ffcf37
Bump @babel/core from 7.16.0 to 7.16.5 (#15760)
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 11:18:25 -05:00
Ridhwana
8f27cd4cbe
Logo style updates (#15732)
* feat: update logo if, else if

* logo fixes

* .

* Update app/views/layouts/_logo.html.erb

Co-authored-by: Michael Kohl <citizen428@forem.com>

* object fit

Co-authored-by: Paweł Ludwiczak <ludwiczakpawel@gmail.com>
Co-authored-by: Michael Kohl <citizen428@forem.com>
2021-12-14 18:02:24 +02:00
Suzanne Aitchison
c6868795cd
add cypress-pipe, fix flaky test (#15756) 2021-12-14 09:46:00 -06:00
Daniel Uber
1d26485c36
Clear changes to settings after checking form saves them (#15746)
* Clear the cached community name before loading new page

When the creator settings form had been run before the create new page
spec, the community name would be changed from the default
"DEV(local)" to "Climbing Life". Since the application helper can
memoize this value - and the database will not - ensure these are in
sync by clearing the settings cache before requesting the page (which
will be prefilled based on the setting).

This "fix" should probably be moved into the test introducing the
change, rather than the one impacted by it.

* Move clearing the settings cache closer to the change

Rather than clearing the cache where we were impacted, clear
immediately after the save spec completes.
2021-12-14 08:39:14 -06:00
Julianna Tetreault
2b34941062
Adjust Width of Creator Settings Form Fields (#15744)
* Adjusts Creator Settings fields to be a max of 480px

* Adjusts crayons-layout to be XS in creator_settings/_new.html.erb
2021-12-14 07:33:25 -07:00
dependabot[bot]
0983d0b40a
Bump babel-jest from 27.4.2 to 27.4.5 (#15759)
Bumps [babel-jest](https://github.com/facebook/jest/tree/HEAD/packages/babel-jest) from 27.4.2 to 27.4.5.
- [Release notes](https://github.com/facebook/jest/releases)
- [Changelog](https://github.com/facebook/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/jest/commits/v27.4.5/packages/babel-jest)

---
updated-dependencies:
- dependency-name: babel-jest
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 14:31:05 +00:00
dependabot[bot]
400dd15cd2
Bump jest from 27.4.2 to 27.4.5 (#15753)
Bumps [jest](https://github.com/facebook/jest) from 27.4.2 to 27.4.5.
- [Release notes](https://github.com/facebook/jest/releases)
- [Changelog](https://github.com/facebook/jest/blob/main/CHANGELOG.md)
- [Commits](https://github.com/facebook/jest/compare/v27.4.2...v27.4.5)

---
updated-dependencies:
- dependency-name: jest
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 06:54:25 -07:00
dependabot[bot]
d07c039851
Bump @storybook/addon-controls from 6.3.12 to 6.4.9 (#15755)
Bumps [@storybook/addon-controls](https://github.com/storybookjs/storybook/tree/HEAD/addons/controls) from 6.3.12 to 6.4.9.
- [Release notes](https://github.com/storybookjs/storybook/releases)
- [Changelog](https://github.com/storybookjs/storybook/blob/next/CHANGELOG.md)
- [Commits](https://github.com/storybookjs/storybook/commits/v6.4.9/addons/controls)

---
updated-dependencies:
- dependency-name: "@storybook/addon-controls"
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 06:54:03 -07:00
dependabot[bot]
c80c64bb94
Bump sass from 1.44.0 to 1.45.0 (#15754)
Bumps [sass](https://github.com/sass/dart-sass) from 1.44.0 to 1.45.0.
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sass/dart-sass/compare/1.44.0...1.45.0)

---
updated-dependencies:
- dependency-name: sass
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 06:53:41 -07:00
dependabot[bot]
b8440c8a83
Bump postcss-cli from 9.0.2 to 9.1.0 (#15751)
Bumps [postcss-cli](https://github.com/postcss/postcss-cli) from 9.0.2 to 9.1.0.
- [Release notes](https://github.com/postcss/postcss-cli/releases)
- [Changelog](https://github.com/postcss/postcss-cli/blob/master/CHANGELOG.md)
- [Commits](https://github.com/postcss/postcss-cli/compare/9.0.2...9.1.0)

---
updated-dependencies:
- dependency-name: postcss-cli
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 06:53:23 -07:00
ludwiczakpawel
878c27f9b0
Crayons: buttons followup (#15720)
* init

* whoops

* components update

* components update

* classes

* variables

* focus

* test

* spec

* test

* adjust colors and variables

* buttons colors

* Update app/javascript/crayons/CTAs/CTA.jsx

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* proptype

* remove duplicated tests now in Cypress, enhance Cypress nav menu tests

* premove unneeded viewport in test

* remove focus check for now

* classnames

* Update app/javascript/crayons/CTAs/__stories__/CTAs.mdx

Co-authored-by: Nick Taylor <nick@iamdeveloper.com>

* Update app/javascript/crayons/CTAs/__stories__/CTAs.mdx

Co-authored-by: Nick Taylor <nick@iamdeveloper.com>

* better contrast

* classname

* add secondary button

* variants + docs

* docs updates

* radius-full

* variants oneof

* the?

* default values + extra stories

* Apply suggestions from code review

Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
Co-authored-by: Nick Taylor <nick@iamdeveloper.com>
Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>
2021-12-14 14:43:41 +01:00
yheuhtozr
65fe8247a6
clean up views i18n entries (#15731)
* clean up views i18n entries

* Update edit.html.erb

* Update edit.html.erb
2021-12-14 09:23:26 +00:00
dependabot[bot]
2f48cd017f
Bump @reach/combobox from 0.16.4 to 0.16.5 (#15738)
Bumps [@reach/combobox](https://github.com/reach/reach-ui/tree/HEAD/packages/combobox) from 0.16.4 to 0.16.5.
- [Release notes](https://github.com/reach/reach-ui/releases)
- [Commits](https://github.com/reach/reach-ui/commits/v0.16.5/packages/combobox)

---
updated-dependencies:
- dependency-name: "@reach/combobox"
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 09:22:25 +00:00
dependabot[bot]
3c68b513d8
Bump chart.js from 3.6.1 to 3.6.2 (#15739)
Bumps [chart.js](https://github.com/chartjs/Chart.js) from 3.6.1 to 3.6.2.
- [Release notes](https://github.com/chartjs/Chart.js/releases)
- [Commits](https://github.com/chartjs/Chart.js/compare/v3.6.1...v3.6.2)

---
updated-dependencies:
- dependency-name: chart.js
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 09:19:07 +00:00
dependabot[bot]
d0deef0d45
Bump sass-loader from 12.3.0 to 12.4.0 (#15741)
Bumps [sass-loader](https://github.com/webpack-contrib/sass-loader) from 12.3.0 to 12.4.0.
- [Release notes](https://github.com/webpack-contrib/sass-loader/releases)
- [Changelog](https://github.com/webpack-contrib/sass-loader/blob/master/CHANGELOG.md)
- [Commits](https://github.com/webpack-contrib/sass-loader/compare/v12.3.0...v12.4.0)

---
updated-dependencies:
- dependency-name: sass-loader
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 09:14:23 +00:00
dependabot[bot]
8781b85eff
Bump jsdom from 18.1.1 to 19.0.0 (#15742)
Bumps [jsdom](https://github.com/jsdom/jsdom) from 18.1.1 to 19.0.0.
- [Release notes](https://github.com/jsdom/jsdom/releases)
- [Changelog](https://github.com/jsdom/jsdom/blob/master/Changelog.md)
- [Commits](https://github.com/jsdom/jsdom/compare/18.1.1...19.0.0)

---
updated-dependencies:
- dependency-name: jsdom
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-14 09:10:35 +00:00
Jeremy Friesen
509b162cd7
Removing feed experiment for non-logged in user (#15733)
Related to #15240
2021-12-13 15:18:26 -05:00
dependabot[bot]
ae8d78c571
Bump oj from 3.13.9 to 3.13.10 (#15743)
Bumps [oj](https://github.com/ohler55/oj) from 3.13.9 to 3.13.10.
- [Release notes](https://github.com/ohler55/oj/releases)
- [Changelog](https://github.com/ohler55/oj/blob/develop/CHANGELOG.md)
- [Commits](https://github.com/ohler55/oj/compare/v3.13.9...v3.13.10)

---
updated-dependencies:
- dependency-name: oj
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-12-13 14:01:05 -05:00
Daniel Uber
2321fe08cf
Wait for async data in forem mobile cypress test (#15737)
* Use visitAndWaitForUserSideEffects to ensure async responses are in

The `visit(url, options)` call here (rather than the preferred
loginAndVisit), was used in order to pass a custom user agent in the
request (to test for forem mobile responses).

The `loginAndVisit(url)` command calls another command
visitAndWaitForUserSideEffects, which ensures the async requests have
returned before processing the remaining steps, and accepts the needed
options (which `loginAndVisit(url)` does not).

The test had been failing intermittently when user data was not loaded
before being
checked (https://app.travis-ci.com/forem/forem/builds/243352021 most
recently) and was reproducible for me locally.

Pass the runtimeStub in options to the command, waiting for user side effects.

* Wait for userData when logged out before inspecting it

* Add optional argument to visitAndWait when user logged out

This permits handling the base data (for logged out users) without
waiting on notifications or counts.

Remove the now unneeded inlining from the logged out forem mobile test.

* Wait for ForemMobile to be added before accessing it
2021-12-13 11:35:49 -06:00