Commit graph

6077 commits

Author SHA1 Message Date
Jeremy Friesen
a40efc6bbd
Refactoring questions asked of user (#15762)
* Refactoring questions asked of user

In this pull request, I'm extracting and normalizing role-based
questions asked of the user.

Prior to this commit, our codebase has asked two very similar questions
of our user model:

- `user.has_role?(:admin)`
- `user.admin?`

In asking `has_role?(:admin)` we are relying on implementation details
of the rolify gem.  In addition, the `has_role?` question asked
throughout controllers or views means that it's harder to create
hieararchies of permissions.

In favoring `user.admin?` as our question, we can use that indirection
as an opportunity to discuss and decide "Should someone with the
`:super_admin` role be `user.admin? == true`?"

The details of this commit is to do three primary things:

1. Ask the `has_role?` questions in "one place" in the code (e.g. the
   `Authorizer` module)
2. Extract the role based questions that are on the `User` model and
   provde backwards compatable delegation.
3. Structure the code so that it's harder to accidentally call
   `user.has_role?` (e.g., make `User#has_role?` and `User#has_any_role?`
   private).

This is related to #15624 and the updates are informed by discussion in
PR #15691.  This commit supplants #15691.

* Refactoring the liquid tag policy tests

* Fixing typo

* Bump for travis
2021-12-21 12:45:12 -05:00
Suzanne Aitchison
5fd1f94e85
Add comment notification test to Cypress, including a11y improvements to notification page (#15842)
* changes to accessible names on notification comment box, cypress specs

* add reply to comment test, delete old specs

* tweak to seeds
2021-12-21 15:42:13 +00:00
dependabot[bot]
c2659d38df
Bump eslint-config-preact from 1.2.0 to 1.3.0 (#15834)
* Bump eslint-config-preact from 1.2.0 to 1.3.0

Bumps [eslint-config-preact](https://github.com/preactjs/eslint-config-preact) from 1.2.0 to 1.3.0.
- [Release notes](https://github.com/preactjs/eslint-config-preact/releases)
- [Commits](https://github.com/preactjs/eslint-config-preact/compare/1.2.0...v1.3.0)

---
updated-dependencies:
- dependency-name: eslint-config-preact
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>

* apply new lint fixes after version bump

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2021-12-21 14:42:20 +00:00
yheuhtozr
5253717797
fix character limits i18n (#15830) 2021-12-21 07:15:21 -05:00
Michael Kohl
872b007c30
Remove Doorkeeper gem (#15749) 2021-12-21 12:29:58 +07:00
yheuhtozr
021ed9708e
restore i18n key _footer.html.erb (#15831) 2021-12-20 16:33:41 -06:00
Daniel Uber
032378b3bd
Disable dash replacement filter in markdown fixer (#15839)
* Remove modify_hr_tags method definition

this breaks things that call it.

* Remove direct uses of modify_hr_tags fixer method

Remove from class METHODS lists, remove test cases about this behavior, and remove from
methods lists in test cases.

* Remove hr tag modification spec

Still don't understand what problem this was fixing, but I've removed
the test case.
2021-12-20 15:39:55 -06:00
ludwiczakpawel
d125617e13
CSS Variables cleanup (#15828)
* variables cleanup

* little fix
2021-12-20 15:42:40 +01:00
ludwiczakpawel
5e098df276
fix (#15829) 2021-12-20 13:38:29 +01:00
Anna Buianova
9f688be406
Moved setting old_username from before_validation to Users::Update (#15782)
* Moved setting old_username from before_validation to Users::Update

* Removed unused code

* Fixed specs after moving setting old_usernames
2021-12-20 11:08:09 +03:00
ludwiczakpawel
9b7503fde3
Update left sidebar links with new Crayons components (#15757)
* update

* hamburger fix

* Update app/views/shared/_hamburger.html.erb

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* updates

* spec

* social media icons

* reading list counter

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2021-12-20 08:46:30 +01:00
Andy Zhao
8a7e5a5566
Escape periods and display the group name properly (#15819)
* Escape periods and display the group name properly

* Rename method to dom_safe_name and move to admin helper

* Replace beginning of string digit with underscore then digit
2021-12-17 17:35:42 -05:00
Andy Zhao
6335f9a7e9
Remove profile when banish (#15818)
* Clear profile when banishing user

* Add test for clearing profile when banishing

* Also clear any social usernames
2021-12-17 15:36:35 -05:00
Arit Amana
dee0b36981
Implement Unified Embed for CodeSandbox URLs (#15808)
* Implement embed and write specs

* fix slight regex ommision

* remove error over invalid options; add specs to cover

* account for missing options when using embed keyword

* no videos, no ns video_id 🤦🏾‍♀️
2021-12-17 12:12:54 -05:00
Daniel Uber
4b93684dab
Don't raise error when empty community emoji setting submitted (#15723)
* Don't raise NoMethodError when validating emoji settings

Cargo culted the unique cross model slug validator setup (which is why
value is called name here in the validatable).

Don't raise an error when validating a nil emoji, and assert nil and
empty string are permitted values.

This expects no non-emoji characters (so an empty string would be
permitted), and nil should be permitted.

I believe this might have been introduced by the string settings
cleaner (exchanging "" for nil in form inputs).

* Update app/validators/emoji_only_validator.rb

guard for value, and then validate value
2021-12-17 09:29:55 -06:00
Alex
51f2bf7aab
Add article and comment count to instance API (#15794) 2021-12-16 13:05:49 -05:00
Arit Amana
5c13d9d8fd
Implement embed tag and specs (#15801) 2021-12-16 12:58:43 -05:00
Jeremy Friesen
aa7712a80e
Extracting container for allowed tags & attrs (#15338)
* Extracting container for allowed tags & attrs

Prior to this commit, we had several different locations in which we
specified ALLOWED_TAGS and ALLOWED_ATTRIBUTES for HTML rendering and
sanitization.

Curious to see how these either intersected or didn't, I opted to
create a container module that allows for us to more readily normalize
these allowed tags and attributes.  It's possible that we won't do any
normalization, but this work helps make that easier.

Ideally, I'd love us to contextualize "why did we choose the
tags/attributes we chose?"  But for now, I think consolidating these
tags and attributes will help make adding a `details` and `summary` tag
easier.

This relates to forem/rfcs#296

See [Google Sheet][1] for analysis of what tags/attributes are used, the
intersection and union.

[1]:https://docs.google.com/spreadsheets/d/1yj-a1qus1o0o4cj-_gOMP5yteeg-_f3s5z7kvK0Y7RM/edit#gid=0

* Fixing misnamed constant

* Fixing misnamed constant

* Extracting additional HtmlRendering use cases

* Adding comparative documentation for HTML tags

* Fixing broken parameter signature

* Moving constants into MarkdownProcessor
2021-12-16 12:24:45 -05:00
Josh Puetz
731849a068
Mobile mention notifications (#15780) 2021-12-16 11:06:54 -06:00
Josh Puetz
3fd03b5ed6
Remove line break after linking username mentions (#15788) 2021-12-16 10:39:07 -06:00
Michael Kohl
b22ad4c976
Remove Doorkeeper from API (#15750)
Co-authored-by: Dan Uber <dan@forem.com>
2021-12-16 09:57:26 -06:00
Nick Taylor
2063d73459
Changed members only copy for radio button label to invite only. (#15795) 2021-12-16 08:31:31 -05:00
Arit Amana
19d8cad1e9
Implement IG unified embed; add specs (#15792) 2021-12-15 15:35:43 -05:00
ludwiczakpawel
0cce606938
Error message after authentication failure due to email address not being whitelisted (#15779)
* cosmetics

* cosmetics

* Build restart

* generator failing build?

* generator failing build?
2021-12-15 21:25:27 +01:00
ludwiczakpawel
a96d69faab
✂️✂️✂️ Drop PWA (#15781)
* drop pwa stuff

* this was breaking the build... shrug.gif

* Update app/assets/javascripts/initializers/runtime.js

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* shorthand for if

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
2021-12-15 21:25:04 +01:00
ludwiczakpawel
2e82b92435
fix (#15783) 2021-12-15 20:39:15 +01:00
Nick Taylor
6df9309284
Added the logo upload to the admin -> customization -> config -> images section. (#15729)
Co-authored-by: Michael Kohl <citizen428@forem.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
Co-authored-by: Mac Siri <mac@forem.com>
Co-authored-by: Ridhwana <Ridhwana.Khan16@gmail.com>
2021-12-15 14:10:27 -05:00
Jamie Gaskins
cde4e08534
Automatically create user profile if it's missing (#15787)
I don't know how it's nil, but it is, so we can remediate that here
2021-12-15 14:03:51 -05:00
Jeremy Friesen
fa093b0a92
Refactoring instance variable usage in tagged articles controller (#15687)
* Refactoring away from instance variables

Having both `@tag` and `@tag_model` as variable names can be confusing.

Given that in the prior implementation `@tag_model.name == @tag`, I
figured I would refactor the controller to remove an instance variable.

In addition, this refactor addresses the temporal coupling of methods;
that is to say we call a method which sets an instance variable then
call another dependent on that instance variable.

Yes, ivars are useful to allow for implicit state.  However, by favoring
parameters its easier to notice temporal dependencies in method calls.

This helps ensure that we're calling methods in the right order.

Futher, we have a guard clause in place, so let's avoid setting any
additional instance variables that aren't needed if the guard clause
executes.

Related to #15359

* Update app/controllers/stories/tagged_articles_controller.rb

Co-authored-by: Michael Kohl <citizen428@forem.com>

* Favoring constants and Rails where constructs

Prior to this commit, we had a magic array.  That magic array was a
duplicate of the Timeframe constant.  Likewise, we had a magic string.

This change removes that duplication.

Furthermore, this change favors the `where(key: range..)` construct
instead of "raw" SQL and parameter substition.

Co-authored-by: Michael Kohl <citizen428@forem.com>
2021-12-15 10:49:50 -05:00
Jeremy Friesen
a5058d3744
Consolidating role query logic (#15773)
* Consolidating role query logic

Prior to this commit, we had two logically identical chunks of code.

With this commit, we consolidate that logic into a single method.  In
addition, we remove one place where the application knows about the
roles implementation.

Loosely related to #15624.

* Bump for travis
2021-12-15 10:49:32 -05:00
Ridhwana
0c51185232
Bust cache after we update the Settings in the Creator Onboarding (#15785)
* feat: bust caches after th create actionon the creator_settings

* spec: update to make sure that we update the cache key
2021-12-15 16:27:58 +02:00
Mac Siri
aac9569a84
Replace honeybadger-js with @honeybadger-io/js (#15770) 2021-12-15 08:39:08 -05:00
Suzanne Aitchison
0295dbeabf
Update a11y of ButtonGroup component (#15765) 2021-12-15 12:52:33 +00:00
Nick Taylor
33e7deee55
Put back default community name. (#15777) 2021-12-14 13:48:38 -07:00
Arit Amana
7d8fe9440a
Implement Unified Embed for Forem Article/Post URLs (#15745)
* Implementation & Specs

* Fix broken spec - yay! 🎉

* Address PR review comments

* Fix my mess

* restart CI
2021-12-14 14:56:51 -05:00
Jamie Gaskins
9e0570968e
Strip surrounding whitespace from HTMLVariant name (#15776) 2021-12-14 14:42:06 -05:00
Ridhwana
8f27cd4cbe
Logo style updates (#15732)
* feat: update logo if, else if

* logo fixes

* .

* Update app/views/layouts/_logo.html.erb

Co-authored-by: Michael Kohl <citizen428@forem.com>

* object fit

Co-authored-by: Paweł Ludwiczak <ludwiczakpawel@gmail.com>
Co-authored-by: Michael Kohl <citizen428@forem.com>
2021-12-14 18:02:24 +02:00
Suzanne Aitchison
c6868795cd
add cypress-pipe, fix flaky test (#15756) 2021-12-14 09:46:00 -06:00
Julianna Tetreault
2b34941062
Adjust Width of Creator Settings Form Fields (#15744)
* Adjusts Creator Settings fields to be a max of 480px

* Adjusts crayons-layout to be XS in creator_settings/_new.html.erb
2021-12-14 07:33:25 -07:00
ludwiczakpawel
878c27f9b0
Crayons: buttons followup (#15720)
* init

* whoops

* components update

* components update

* classes

* variables

* focus

* test

* spec

* test

* adjust colors and variables

* buttons colors

* Update app/javascript/crayons/CTAs/CTA.jsx

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>

* proptype

* remove duplicated tests now in Cypress, enhance Cypress nav menu tests

* premove unneeded viewport in test

* remove focus check for now

* classnames

* Update app/javascript/crayons/CTAs/__stories__/CTAs.mdx

Co-authored-by: Nick Taylor <nick@iamdeveloper.com>

* Update app/javascript/crayons/CTAs/__stories__/CTAs.mdx

Co-authored-by: Nick Taylor <nick@iamdeveloper.com>

* better contrast

* classname

* add secondary button

* variants + docs

* docs updates

* radius-full

* variants oneof

* the?

* default values + extra stories

* Apply suggestions from code review

Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>

Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
Co-authored-by: Nick Taylor <nick@iamdeveloper.com>
Co-authored-by: Julianna Tetreault <32834804+juliannatetreault@users.noreply.github.com>
2021-12-14 14:43:41 +01:00
yheuhtozr
65fe8247a6
clean up views i18n entries (#15731)
* clean up views i18n entries

* Update edit.html.erb

* Update edit.html.erb
2021-12-14 09:23:26 +00:00
Jeremy Friesen
509b162cd7
Removing feed experiment for non-logged in user (#15733)
Related to #15240
2021-12-13 15:18:26 -05:00
Nick Taylor
d67d0b4dc9
Made Creator Settings Checkboxes Accessible (#15735) 2021-12-13 10:30:53 -05:00
Mac Siri
13b88e8754
Ignore MtPopUpList on Honeybadger (#15728)
Co-authored-by: Nick Taylor <nick@iamdeveloper.com>
2021-12-13 08:20:55 -05:00
Daniel Uber
421dad2900
Remove reactions to a user when deleting the user (#15724)
* Remove reactions to a user when deleting the user

Fixes #15245

---

I have no idea why `create(:vomit_reaction, reactable: user)` gave a
validation error about category being invalid, but `build().save`
worked fine.

* Move relation details to reaction scope `for_user`

Add a user method to access this by passing self to reaction scope

* Create a moderator when flagging user in factory

This might be a missing requirement in the reactions factory - but
this suppresses an error about invalid category I was getting when
setting a privileged reaction on the user via

    create(:vomit_reaction, reactable: user)

Everywhere else it looks like we do this with `user: moderator` (where
there's a trusted user in the surrounding context).

* Move trusted user requirement into vomit_reaction factory

* Add a data update script to remove reactions to deleted users

This cleans up the remaining invalid references and should make the
change in #15249 obsolete (i.e. we don't need to limit the view to
exclude items that no longer exist).
2021-12-10 11:24:23 -06:00
Julianna Tetreault
428dd1bd2c
Adjust Creator Settings Form Width (#15725)
* Reduces width of community_name field and finish button

* Slightly adjusts util classes on necessary fields

* Adjusts field widths to be larger for appearance

* Remove util classes entirely from fields
2021-12-10 09:53:14 -07:00
Ridhwana
e250b46ed2
Using a Form Object that will persist for the Creator Settings Form (#15684)
* WIP: add a creatore settings form

* WIP: updat the controller to use the Creator Settings FOREM

* feat: use the creator settings form for the new action

* feat: add some default values for the new action

* a note about form data

* update the initiaize function to set some default values

* feat: update the form to use the model data

* feat: permit adn use the attributes within creator_settings_form

* update the flash error

* refactor: require and permit parameters

* chore: use booleans, set defaults and validate the form

* spec: update all the creator_settings tests

* chore: remove comment

* refactor: use self

* feat: aggregate failures'

* chore: remove the logo uploader in the controller

* refactor: update error handling

* feat: update the wasy the controller handles success and error

* chore: remove the resource errors

* feat: show flash message on new line

* fix: use a redirect so that we can get back to /new

* refactor: pass these values through as they seem to be caching whne setting them as default

* chore: change default values

* spec: update tests

* Fix CreatorSettingsForm specs

* fix: use a boolean for public

* spec: add another test for the success var

* fix: radio button labels to correspond + cyress specs

* spec: update based on new changes

* spec: update the params and the expected output

* spec: update the comments and status

* feat: no need for the initialize as we use Active Record Attributes

* feat: update the tac and coc to be persisted when ticked

* fix: amend spec

* blank space

* Message

Co-authored-by: Michael Kohl <me@citizen428.net>
2021-12-10 17:07:40 +02:00
Anna Buianova
7511ee1fe2
Removed resaving articles after changing username (#15704) 2021-12-10 17:14:46 +03:00
Daniel Uber
9f9594ccdc
role deprecation cleanup (#15717)
* User decorator (and spec) should use `trusted?`

Fixes a few issues seen in an rspec run that show as:

    DEPRECATION WARNING: User#trusted is deprecated, favor
    User#trusted? (called from config_body_class at
    /opt/apps/forem/app/decorators/user_decorator.rb:58)

And here:

/opt/apps/forem/spec/decorators/user_decorator_spec.rb:112
/opt/apps/forem/spec/decorators/user_decorator_spec.rb:121
/opt/apps/forem/spec/decorators/user_decorator_spec.rb:130
/opt/apps/forem/spec/decorators/user_decorator_spec.rb:139

* prefer User trusted? to trusted

DEPRECATION WARNING: User#trusted is deprecated, favor
User#trusted? (called from permissions at
/opt/apps/forem/app/models/rating_vote.rb:25)

* Prefer trusted? to trusted in user spec

* Use warned? rather than warned in admin article partial

* use trusted? rather than trusted in moderator requests spec

* Prefer trusted? to trusted in moderations controller

* Prefer trusted? to trusted in moderations view

* User auditable? should call trusted? and not trusted

Deprecations go rolling right along.

* Invert guard clause logic to be positive

The original "return unless multiple negated conditions hold" guard
was cumbersome.

Invert to return if any of the exceptions apply, namely:

- this is a comment or readinglist rating (rather than explicit),
allowed for all
- this rating is from a moderator/trusted user (allowed)
- this rating is offered by the article's author (allowed)

I had intended to also remove the safe navigation operators (since it
wasn't clear why there would be a null user or null article, as
rating_vote joins users to articles with a score), but the builtin
validation tests (is expected to validate ...) build objects with
missing attributes, and raise errors when the spec is run.
2021-12-09 15:27:45 -06:00
Daniel Uber
09eda6a0cc
Don't show reactions to missing reactables (#15249)
Solves an issue where a moderator 'vomit' action on a subsequently
deleted user causes the privileged reactions page to raise a
NoMethodError accessing the reactable's details.

I tried to accomplish this in the controller but it seems the
`paginate` helper requires a relation rather than an array.
2021-12-09 14:40:17 -06:00