* building again
* still building
* still building
* stuck
* Suzanne Holmes on the case
* make report content a button not a link
* revert to link
* add tests
* revert changes made trying to get ModCenter to work
* hide nonworking actions_panel btns in Mod Center
* nudge Travis
* incorporate PR comments
Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
* building again
* still building
* still building
* stuck
* Suzanne Holmes on the case
* make report content a button not a link
* revert to link
* add tests
* revert changes made trying to get ModCenter to work
* hide nonworking actions_panel btns in Mod Center
* nudge Travis
* incorporate PR comments
Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
* Refactoring questions asked of user
In this pull request, I'm extracting and normalizing role-based
questions asked of the user.
Prior to this commit, our codebase has asked two very similar questions
of our user model:
- `user.has_role?(:admin)`
- `user.admin?`
In asking `has_role?(:admin)` we are relying on implementation details
of the rolify gem. In addition, the `has_role?` question asked
throughout controllers or views means that it's harder to create
hieararchies of permissions.
In favoring `user.admin?` as our question, we can use that indirection
as an opportunity to discuss and decide "Should someone with the
`:super_admin` role be `user.admin? == true`?"
The details of this commit is to do three primary things:
1. Ask the `has_role?` questions in "one place" in the code (e.g. the
`Authorizer` module)
2. Extract the role based questions that are on the `User` model and
provde backwards compatable delegation.
3. Structure the code so that it's harder to accidentally call
`user.has_role?` (e.g., make `User#has_role?` and `User#has_any_role?`
private).
This is related to #15624 and the updates are informed by discussion in
PR #15691. This commit supplants #15691.
* Refactoring the liquid tag policy tests
* Fixing typo
* Bump for travis
* User decorator (and spec) should use `trusted?`
Fixes a few issues seen in an rspec run that show as:
DEPRECATION WARNING: User#trusted is deprecated, favor
User#trusted? (called from config_body_class at
/opt/apps/forem/app/decorators/user_decorator.rb:58)
And here:
/opt/apps/forem/spec/decorators/user_decorator_spec.rb:112
/opt/apps/forem/spec/decorators/user_decorator_spec.rb:121
/opt/apps/forem/spec/decorators/user_decorator_spec.rb:130
/opt/apps/forem/spec/decorators/user_decorator_spec.rb:139
* prefer User trusted? to trusted
DEPRECATION WARNING: User#trusted is deprecated, favor
User#trusted? (called from permissions at
/opt/apps/forem/app/models/rating_vote.rb:25)
* Prefer trusted? to trusted in user spec
* Use warned? rather than warned in admin article partial
* use trusted? rather than trusted in moderator requests spec
* Prefer trusted? to trusted in moderations controller
* Prefer trusted? to trusted in moderations view
* User auditable? should call trusted? and not trusted
Deprecations go rolling right along.
* Invert guard clause logic to be positive
The original "return unless multiple negated conditions hold" guard
was cumbersome.
Invert to return if any of the exceptions apply, namely:
- this is a comment or readinglist rating (rather than explicit),
allowed for all
- this rating is from a moderator/trusted user (allowed)
- this rating is offered by the article's author (allowed)
I had intended to also remove the safe navigation operators (since it
wasn't clear why there would be a null user or null article, as
rating_vote joins users to articles with a score), but the builtin
validation tests (is expected to validate ...) build objects with
missing attributes, and raise errors when the spec is run.
* Remove Connect
* Remove more Connect specs
* Remove a lot more Connect code
* 🚮
* It all has to go
* Explicitly add httpclient
* Update application layout
* Remove messages association from User
* Start fixing specs
* reintroduce util function and refactor references
* Remove Connect Cypress test
* Fix more specs
* Remove Connect from listings
* Ignore contact_via_connect column on listings
* Remove contact_via_connect usages
* Ignore mod_chat_channel_id on tags
* Drop Connect tables
* Remove email_connect_messages from user notification settings
* Re-add httpclient 2.8.3
This was mistakenly removed as a merge conflict
* Don't need to exclude removed chat channel file
* Remove unneeded style for chat channels
* Remove unneeded channel list prop type
* Remove chat channels index/connect-link from getPageEntries
* Re-add comment from httpclient in Gemfile
* Remove connect references from mailers
Tag Moderators no longer have a chat channel
No longer will users be notified about new messages (there won't be
any)
No longer will users be notified about channel invites (you can't
invite anyone anymore)
* Don't configure Pusher and remove PUSHER_* from .env_sample
since it's removed from gemfile, the Pusher constant will not resolve, if this is
configured in the environment variables we'll fail to boot.
Co-authored-by: Suzanne Aitchison <suzanne@forem.com>
Co-authored-by: Dan Uber <dan@forem.com>
* Enable new Rails/* cops and use autocorrect on them
* Fixed Rails/PluckInWhere leftovers
* Fix Rails/DefaultScope
* Enable and fix Rails/PluckId
* Fix manual mistake with forcing autocorrection on Rails/PluckId
* Apply PR feedback to remove Rails/PluckId inline disables
* Apply PR feedback to get rid of Rails/PluckInWhere inline
* Make FlagUserModal show up on click
* Explain extra div
* Make sure "Vomit All" reaction fires accurately
* Make test-file comment clearer
* Fix bug when 2 articles are open and the FlagUser modal does not open for the first article
* Still working it out ...
* Tests broken; need help
* Get rid of debugging alerts
* Fixed broken tests for <SingleArticle />
* Write tests for ModerationArticles component
* Complete tests for ModerationArticles component
* Employ safer Preact testing techniques
* Query all articles using "data-testid"
* Revert changes
* Got it working with portals for non-iframe implementation.
* wip tests
* Got mod tools flag user modal wprking on article page again.
* Added some documentation the code.
* Now confirm is disabled until you select an item in the flag user modal.
* Revert "wip tests"
This reverts commit fb7a0825039fd377cad04d9dedad9d1146b03978.
* test prep
* Fixed broken test.
* Refactored to use useRef hook.
* Rename a variable
* remove unnecessary comments
Co-authored-by: Nick Taylor <nick@dev.to>
* db
* Add an iframe to host mod actions menu
This iframe is probably the fastest way to get a working mod actions
menu without rewriting existing code. We may eventually re-write this,
but based on Ben's recommendation we are going to go with an iframe
because it gets us a working feature quickly and it seems to be serving
us well in other parts of the application.
* Add the mod actions menu button to articles
When the user is "trusted" they will see a small badge on the lower
right-hand side of the screen. Clicking the icon reveals the mod actions
menu.
* Add header to actions panel (#7395)
* Update iframe border
* Add 'Moderate Post' header and button
* Use inline SVG over <img src='svg'>
* Use Crayons variables for units
* Use flexbox to center chevron
* Add accidentally deleted positioning
* Add chevron-right.svg
* Use a partial for actions panel and revert /mod page
* Load actions panel in iframe and not /mod
* Style UpVote, DownVote and Vomit buttons (#7421)
* Add a iframe to host mod actions menu
* Up and Downvote Icons
* Starting with vomit button
* Completed UI; interactions pending
* Incorporated Andy changes; making mod action-panel
* space reactions away from header
* UI tweaks and corrections 1
* Fixing styles to match crayons
* choose pure white color css variable
* Add thumbs-up emoji; address Lisa comments
* Trying to fix reactions interactions
* remove clearThumbReactions function
Co-authored-by: jacobherrington <jacobherringtondeveloper@gmail.com>
* Add bottom layout for actions panel (#7501)
* WIP for Lisa
* Finalize mod actions bottom section
* Use showing instead of hidden for transition
* Add new optimized SVGs
* Fix weird height issues for actions panel
* Move hover styles below the cascade, yo
* Use margin-top for sticky footer over height: 100%
* Move initialize actions panel button to Webpack (#7506)
* Move actions panel JS code to webpack
* Refactor and use destructuring
Thanks @nickytonline!
Co-Authored-By: Nick Taylor <nick@iamdeveloper.com>
* Rename file
Co-authored-by: Nick Taylor <nick@iamdeveloper.com>
* Configure Experience Level options for Mod Action Panel (#7507)
* Add a iframe to host mod actions menu
* Click interactions (no toggle of dropdowns yet)
Co-authored-by: jacobherrington <jacobherringtondeveloper@gmail.com>
* Fix the iframe's path (#7509)
* Toggle the 'Set Experience Level' menu on button-click (#7529)
* Add a iframe to host mod actions menu
* Add set-exp dropdown functionality
* WIP: making exp level updates async
* Completes async implementation
* Fix controller for "actions_panel" and "/mod"
Co-authored-by: jacobherrington <jacobherringtondeveloper@gmail.com>
* Add close button interaction (#7552)
* Rename actions panel pack file
* Add close button toggle to actions panel
* DB update
* Move more code to Webpack and add conditional tag adjustments section (#7652)
* Move JS code to Webpack
* Clean up a few style issues
* Add styling for tag adjustments
* Add active/inactive functionality
* Add conditional rendering for tag adjustments section
* Add missing variable oops (#7673)
* update with upstream
* Add missing subtract svg (#7695)
* Create 'Flag User' modal (#7626)
* Add a iframe to host mod actions menu
* Starting task
* Phase 1
* Fix "Close Modal" icon
* Implement open modal
* Working on all "Close Modal" actions
* Almost-complete implementation
* Remove Abuse Report snackbar
* Delete unneeded JS code
* Remove "How does this work?" links
* Link to Community Moderation page
* Addressing code review corrections
* Update api call to use "request" method
* Make else path clearer in api call
Co-authored-by: jacobherrington <jacobherringtondeveloper@gmail.com>
* Mod Actions Panel: Prevent nonsensical reaction pairs (#7699)
* Still implementing
* Completed Implementation
* Address code review feednack; refactor "create" method
* Move scss variables to native-css (for ModPanel code only)
* Correct missing native css
* update to native-css again
* More sccs -> native-css fixes
* Adjust ModPanel Button position on mobile (#7744)
* Adjusted ModPanel position on mobile
* Better adjustment
* Fix phantom schema.rb changes
* Fix phantom schema.rb changes
* Finalize tag adjustments (#7740)
* Finalize tag adjustments and flow
* Fix logic for rendering adjust tags options
* Clean up alert response
* Rename user to trusted user
* Use new CSS variables
* Add/remove tag on article's tag section after adjusting
* Fix logic for admin tag input and some other niceties
* Final bug fixes mod panel (#7772)
* Use correct boolean statement
* Clear the value of the textarea not div
* Use the correct attribute
* Use actions panel for /mod page (#7775)
* Fix loading logic with tag adjust button conditional render
* Link to tag moderation for adjust tags section
* Use top over window.parent
Thanks @nickytonline!
Co-authored-by: Nick Taylor <nick@iamdeveloper.com>
* Use Webpack alias to import
Co-authored-by: Nick Taylor <nick@iamdeveloper.com>
* Use place-items shorthand over align-items + justify-content
Thanks @nickytonline!
Co-authored-by: Nick Taylor <nick@iamdeveloper.com>
* Fix typo for utilities
* Add new line to end of file
* Disable linter for use for top function
* Use align-items and justify-content center
* Update SVGs to spec
* Remove unnecessary height and use spacing units for open button
* Remove accidentally added comment
* Error handling when selecting reactions; optimize "reactions.each" loop
* Add comment about clearing innerHTML
* Revert schema back to master
* Use each since there should only be two reactions
* Fix typo oops
* Add missing height oops
* Return if there are no reactions to be destroyed
* Center path with GUI tool shrug
* chose more appropriate name for JS pack; rewrote api calls using async-await
* Rename variables and methods and check categories before clearing
* Use addSnackbarItem instead of hardcoded version
* Place articleModerationTools pack behind user_signed_in
* Correct omission
* Implement dynamic imports for ModPanel tools
* Implemented async/await; added snackbar message for null response use-case
* Fix the "/article/mod" page; make sure all reactions, vomit-user and exp-level working as expected
* Update language to reflect new UI
* Close the modal after the "Confirm Action" button is clicked
* Change text for Spam/Abuse button
* Fix schema to use with master
* Update schema to master again
* Use crayons button for actions panel button
* UI tweak to play nicer with site themes
* Make actions panel work for dev.to/mod
* Add snackbar for reactions
* Update how does this work links
* Add "thumbsup" reactions to logging
* Add thumbsup to categories
* Add external link icon
* Changes to reflect "Privileged" and not "Negative" reactions; spec changes pending
* Updated instance variable
* Starting to update the specs
* Update "thumbsup" points from 10 to 5
* Still working on both requests
* Embracing an easier implemantation (thanks Andy!)
* Add tests for actions panel
* Add some basic tests for actions panel
* Change to flag to admins
* Indicate that 'Reason for Tag adjust' is required
Co-authored-by: Mac Siri <krairit.siri@gmail.com>
* Rename negative_reactions to privileged
* Update rating level to use correct values
* Use a different display value than backend value
* Don't show adjust tags for trusted users
* Add specs for moderation_routes for admin and super_admin
Co-authored-by: Arit Amana <msarit@gmail.com>
Co-authored-by: jacobherrington <jacobherringtondeveloper@gmail.com>
Co-authored-by: Arit Amana <32520970+msarit@users.noreply.github.com>
Co-authored-by: Nick Taylor <nick@iamdeveloper.com>
Co-authored-by: Mac Siri <krairit.siri@gmail.com>
* mod view form changes
* add error validation for removal tag
* add error validation to tag_list count
* re-render tag_adjustment form errors
* refactor admin delete adjusted tags form
* add prompt to tag adjustment form select
* front end validations to add/remove tag_adjustment
* allow tag_mod to undo own tag adjustment
* update/add specs
* update send spec
* update tag adjustment spec
* added tests to specs
* added view logic
* added controller/model functionality
* minor tweak to tagadjustment view
* adjusted mod view to reduce query
* added instance variables to controller
* show already adjusted tags in mod view
* removed unnecessary ifs from mods controller
* catch and display errors to tag adjustment forms
* update specs and refactor
* Preload organization, not user
* Preload users only when needed
* Pre-load podcasts for podcast episodes in API
* Avoid eager loading error by loading rating votes separately
* Preload associations for moderation
* Preload user comments in trees
* Preload organization for non org dashboard and cleanup queries
* Optimize ArticleSuggester to only load N articles at need
* Remove eager loading and pass variables to partials for easier debug
* Reorganize tags validation code and ignore actsastaggableon eager loading issues
* Remove unused eager loading and bring up comments relation
* Preload podcasts when loading podcast episodes
* Fix views specs
* Make sure ArticleSuggester never returns duplicates
* Remove commented code
* Re-trigger build
* Move suggested articles back to view to respect fragment caching
* Use published scope for articles
* Fix variable name
* The sequencing in the union query matters
* Fix spec
* Restore a published: true condition
* This test is actually misleading due to the union
* Revert this change, not sure why it's not a relation
* Fix useless diff
* added organization policy + spec
* user specs for is_org_admin?
* added authroize to organization controller
* admin policy + specs
* deleted enforce admin due to pundit policy redundancy
* applied admin policy to entire admin namespace
* refactoring analytics controller WIP - wanna test codeship
* Add protection against reactions to unpublished articles (#473)
* Add chat channel policy and spec (#474)
* Add comment policy and specs (#475)
* Fix edge case with apostrophes
* Add comment policy and specs
* Add login for deleting comment spec
* Change test to raise pundit error instead of 404
* Clean up comment destroy request specs
* Remove redundant raise
* Whitelist columns on to_json call (#477)
* Add pundit policy for several controllers (#476)
* Add pundit policy for several controllers
* Adjust video spec
* Fix tag request specs
* Add proper twilio tokens request specs
* Remove puts statements
* Add a couple basic request specs (#478)
* Add a few tests and fix user tag color bug (#482)
* Refactor handle_tag_index in stories_controller (#481)
* Modify valid_request_origin? (#483)
* Add misc specs and remove banned attribute from user model (#484)
* Fix missing Cloudinary tags and misc specs (#486)
* removing current_user_is_admin? to use .is_admin? method
* added missing org policy routes
* Add comment for all public controllers
* Fix edge case for test
* Authorize mod controller and add specs
* Refactor methods via inheritance and use only super_admin role
* Create policy method for analytics via article_policy and refactor
* Capitalize all buttons in dashboard page
* Fix org tests and remove old admin test
* Use only happy path for analytics
* Fix tests to use Pundit error
* Update org_policy spec