No description
Find a file
Jeremy Friesen 3253ba2c7a
Patching ERB rendering of the data-info JSON (#16067)
Prior to this commit, we were somewhat naively rendering Hash style data
attributes in our ERB templates.  By rendering each hash attribute
separately, we were rendering characters that could break the
javascript (e.g. double hack or backslash `"` or `\`).

By moving to this view_object rendering, we leverage Rails's `to_json`
behavior to ensure properly escaped values.  As part of this exercise, I
generalized the method to allow for other places to benefit from this
behavior.

This generalization also helps ensure that we have a more conformant
rendering (e.g. we should always have an :id, :className, and :name
value in our data-info hash).

_Note: I've updated the user's names for Cypress tests as they are more
likely to catch the particular issue than anything else.  I assume that
I'm going to break some cypress tests and will need some help fixing
them._

Closes #15916, #14704

Supersedes #15983

How to test locally:

Assuming you have seeded database (e.g. `rails db:seed`), checkout the
"main" branch.  Then in `rails console` find a user that's written articles:

```ruby
user = Article.last.user

user.update(name: "\\: #{user.name}")

user.articles.each(&:save)
```

Now, again on the "main" branch, start your application (e.g.,
`bin/startup`).

Then get a logged in and a logged out browser session going.  Open your
web inspector and open console.  Then go to the local instances homepage
(e.g., http://localhost:3000) and look for JS errors.

On the main branch, you should see an exception around
`JSON.parse(button.data.info)` (assuming that the `user`'s article is
rendered on the homepage).

Then go to the user's page (e.g. https://localhost:3000/:user-slug) and
look for JS parse errors.

On this PR's branch (e.g.,
`jeremyf/take-two-at-resolving-gh-15916`)
you shouldn't see those console errors.

More importantly, the Follow buttons should work.
2022-01-14 08:30:49 -05:00
.buildkite Removes this dupe container block since we are going to run this pipeline (#11506) 2020-11-19 15:05:49 -06:00
.gems Bugfix for #7663 and refactor of container setup (#7747) 2020-05-28 12:11:51 -05:00
.github Update dependabot config (#15987) 2022-01-10 11:35:48 +07:00
.husky [15 min fix] Updated husky package and configuration/pre-commit hook (#14346) 2021-07-27 15:39:00 -04:00
.vscode Added the MDX extension for VS Code. (#12816) 2021-02-25 10:22:18 +01:00
.yarn/releases Update to latest yarn version (#10441) 2020-09-28 13:24:35 -04:00
app Patching ERB rendering of the data-info JSON (#16067) 2022-01-14 08:30:49 -05:00
bin Copy .env_sample to .env in bin/setup (#16005) 2022-01-10 21:33:08 +07:00
config app/helpers i18n (#16003) 2022-01-13 11:46:32 -05:00
cypress Implementing new buttons (#15843) 2022-01-14 10:28:31 +01:00
datadog Declare DD_VERSION in prerun.sh 2nd try (#13258) 2021-04-05 17:10:46 -04:00
db Patching ERB rendering of the data-info JSON (#16067) 2022-01-14 08:30:49 -05:00
lib Fixing Rubocop's auto-correct recommendations (#16098) 2022-01-13 21:40:19 -05:00
log Initial commit 2018-02-28 16:11:08 -05:00
public Make podcast-playback to be controllable via keyboard (#14139) 2021-08-20 12:45:53 +02:00
scripts Don't write a \n at the end of the release version (#15659) 2021-12-03 13:08:27 -05:00
spec Patching ERB rendering of the data-info JSON (#16067) 2022-01-14 08:30:49 -05:00
vendor Bump octokit from 4.21.0 to 4.22.0 (#16096) 2022-01-13 14:00:07 -05:00
.codeclimate.yml Upgrade to Ruby 3.0.2 (#12103) 2021-08-25 14:26:33 -04:00
.dockerignore Remove docs from repo ✂✂✂ (#14579) 2021-08-23 17:23:42 -04:00
.editorconfig Export articles/posts (#576) 2018-11-21 11:13:36 -05:00
.env_sample Skip google analytics when ga_tracking_id is nil (#15967) 2022-01-06 12:21:07 -05:00
.erb-lint.yml Upgrade Rails to 6.1.3.1 (#11333) 2021-04-05 10:39:48 -04:00
.eslintignore Remove non application files from frontend code coverage (#11752) 2020-12-04 20:00:20 -05:00
.eslintrc.js Bump eslint from 7.32.0 to 8.6.0 (#15926) 2022-01-05 13:47:40 -05:00
.gitattributes Enable union merges for translations (#15061) 2021-10-14 10:51:09 +07:00
.gitignore Add .pryrc to gitignore (#14844) 2021-09-28 18:03:02 +02:00
.gitpod.dockerfile Update to node version 16 (#15522) 2022-01-03 10:23:07 -06:00
.gitpod.yml Add DISABLE_SPRING environment variable to gitpod forem server task (#15807) 2021-12-16 15:24:22 -06:00
.lintstagedrc.js Create .lintstagedrc.js (#15209) 2021-10-27 12:40:59 -04:00
.nvmrc Update to node version 16 (#15522) 2022-01-03 10:23:07 -06:00
.postcssrc.yml Initial commit 2018-02-28 16:11:08 -05:00
.prettierignore Use yarn 1.21.1 (#5786) 2020-02-05 17:04:06 -05:00
.prettierrc.json Extracting prettier config (#10847) 2020-10-14 22:28:31 -04:00
.rspec [deploy] Spec Speedup: Use Knapsack to Run Parallel Builds (#8390) 2020-06-11 10:27:11 -05:00
.rubocop.yml Proposing a new feed experiment (#15789) 2022-01-03 14:38:14 -05:00
.rubocop_todo.yml ✂✂✂ Remove Connect (#14734) 2021-11-18 08:21:00 -06:00
.ruby-version Upgrade to Ruby 3.0.2 (#12103) 2021-08-25 14:26:33 -04:00
.simplecov Remove resource_admin dashboards (Administrate) (#11792) 2020-12-08 12:38:13 -06:00
.slugignore Remove docs from repo ✂✂✂ (#14579) 2021-08-23 17:23:42 -04:00
.travis.yml Data Update Script to migrate logo_svg contents to png file (Will be merged and deployed on 10/01) (#15710) 2022-01-10 16:09:34 +02:00
.yardopts Adds Ruby source code documentation to docs.dev.to (#2656) 2019-05-02 13:50:58 -04:00
.yarnclean Remove assets folder from .yarnclean (#13869) 2021-05-27 10:39:59 -04:00
.yarnrc Update to latest yarn version (#10441) 2020-09-28 13:24:35 -04:00
babel.config.js Added the babel-inline-react-svg plugin (#15461) 2021-11-23 12:24:50 -05:00
CHANGELOG.md Add support for versioned releases (#13750) 2021-07-28 10:10:33 -04:00
CODE_OF_CONDUCT.md Replace ban/banned with suspend/suspended in user facing text (#5816) [deploy] 2020-02-10 10:12:53 -05:00
config.ru Upgrade Rails to 6.1.3.1 (#11333) 2021-04-05 10:39:48 -04:00
container-compose.yml Remove Elasticsearch ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ (#13606) 2021-05-03 11:09:45 -04:00
Containerfile use newly-built Fedora-35-based quay.io/forem/ruby:3.0.2 container (#15938) 2022-01-03 15:31:42 -06:00
CONTRIBUTING.md Fix broken links (#14588) 2021-08-24 16:59:56 -04:00
customJsDomEnvironment.js Bump jsdom from 16.7.0 to 18.0.0 (#15047) 2021-10-12 14:32:30 -06:00
cypress.dev.json Cleaning Test Runs for End to End (E2E) Tests (#12143) 2021-01-29 13:34:01 +01:00
cypress.json add retries for cypress ci tests (#14241) 2021-07-15 12:34:30 +01:00
docker-compose.yml Update docker-compose.yml file to permit login (#13792) 2021-05-24 20:03:36 -05:00
Dockerfile Bugfix for #7663 and refactor of container setup (#7747) 2020-05-28 12:11:51 -05:00
empty-module.js Initial commit 2018-02-28 16:11:08 -05:00
Gemfile Bump octokit from 4.21.0 to 4.22.0 (#16096) 2022-01-13 14:00:07 -05:00
Gemfile.lock Bump octokit from 4.21.0 to 4.22.0 (#16096) 2022-01-13 14:00:07 -05:00
gitpod-init.sh Made GitHub CLI install permanent in Gitpod (#14787) 2021-09-21 15:27:39 -04:00
Guardfile Upgrade rubocop* packages to the latest version and fix violations (#11972) 2020-12-21 18:29:43 +01:00
jest.config.js Crayons: Buttons vs CTAs (#15311) 2021-11-30 20:40:32 +01:00
jsconfig.json Added the babel-inline-react-svg plugin (#15461) 2021-11-23 12:24:50 -05:00
LICENSE.md Ran all markdown files through prettier to fix a handful. (#4599) 2019-10-28 08:20:53 -04:00
package.json Storybook improvements (#15860) 2022-01-14 11:06:42 +01:00
postcss.config.js Suppress Postcss warnings & Re-enable Benhalpern deploy (#11521) 2020-11-20 11:27:49 -05:00
Procfile remove rake jobs:work references from code (#6082) [deploy] 2020-02-14 15:18:08 -05:00
Procfile.dev Adapt dev env to run on a remote box (#8232) 2020-06-18 13:01:49 +02:00
Procfile.dev-hot Initial commit 2018-02-28 16:11:08 -05:00
Rakefile Remove fix-db-schema-conflicts gem (#12432) 2021-01-26 10:52:38 -05:00
README.md Add me (Dwight) to readme :) (#15816) 2021-12-17 14:50:45 -05:00
release-tasks.sh Remove Elasticsearch ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ ✂️ (#13606) 2021-05-03 11:09:45 -04:00
SECURITY.md [deploy] 🚀 Feature: Chat channel membership manager component (#8945) 2020-07-20 08:08:31 -04:00
svgo.config.js svgo: update configuration for 2.4 syntax (#14524) 2021-08-17 18:54:10 +02:00
testSetup.js workaround getComputedStyle issues in all jest tests (#14737) 2021-09-21 10:52:54 +01:00
yarn.lock Storybook improvements (#15860) 2022-01-14 11:06:42 +01:00


Forem 🌱

For Empowering Community

Travis Status for forem/forem GitHub commit activity GitHub issues ready for dev GitPod badge

Welcome to the Forem codebase, the platform that powers dev.to. We are so excited to have you. With your help, we can build out Forems usability, scalability, and stability to better serve our communities.

What is Forem?

Forem is open source software for building communities. Communities for your peers, customers, fanbases, families, friends, and any other time and space where people need to come together to be part of a collective. See our announcement post for a high-level overview of what Forem is.

dev.to (or just DEV) is hosted by Forem. It is a community of software developers who write articles, take part in discussions, and build their professional profiles. We value supportive and constructive dialogue in the pursuit of great code and career growth for all members. The ecosystem spans from beginner to advanced developers, and all are welcome to find their place within our community. ❤️

Table of Contents

Community

For a place to have open discussions on features, voice your ideas, or get help with general questions please visit our community at forem.dev.

Contributing

We encourage you to contribute to Forem! Please check out the Contributing to Forem guide for guidelines about how to proceed.

Getting Started

This section provides a high-level quick start guide. If you're looking for a more thorough installation guide (for example with macOS, you'll want to refer to our complete Developer Documentation.

We run on a Rails backend, and we are currently transitioning to a Preact-first frontend.

A more complete overview of our stack is available in our docs.

Prerequisites

Local

Containers

Linux

OS X

Installation Documentation

Please see our installation guides, such as the one for macOS.

Developer Documentation

Check out our dedicated docs page for more technical documentation.

Core team

Vulnerability disclosure

Forem is the open source software which powers DEV.

We welcome security research on DEV under the terms of our vulnerability disclosure policy.

Acknowledgments

Thank you to the Twemoji project for the usage of their emojis.

License

This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. Please see the LICENSE file in our repository for the full text.

Like many open source projects, we require that contributors provide us with a Contributor License Agreement (CLA). By submitting code to the Forem project, you are granting us a right to use that code under the terms of the CLA.

Our version of the CLA was adapted from the Microsoft Contributor License Agreement, which they generously made available to the public domain under Creative Commons CC0 1.0 Universal.

Any questions, please refer to our license FAQ doc or email yo@dev.to.


Sloan, the sloth mascot
Happy Coding ❤️

⬆ Back to Top