* test: whitespace unicode characters cannot be used as titles or tags * feat: add localized error message * refactor: use localized error message * fix: whitespace unicode characters cannot be used as titles or tags * chore: fix locale after merge * refactor: fix indentation * Fix spelling of prohibited in method names Additionally, rubocop removed a redundant user_id validation since Article belongs to user. * Fix spelling Missed one method call on the same line (fixed the first of two instances needing changes) * add failing test cases The reorganization to remove let was due to a limit on nesting rspec contexts (it inside context inside describe inside describe when trying to use different titles in let blocks in contexts) The first test was clarified (the "U+202D" string that looks like the code for a unicode point is valid, but the character \u202d is expected to be invalid The remaining two tests are based on the feedback I'd given in the PR, failing because we don't assert title is present after removing unicode whitespace, and we don't actually set the title (gsub is non-destructive, returning a value). * Set title to sanitized title contains_prohibitied_unicode_characters? was using == (which is not a good match for strings to regexes), use =~ instead Change invalid example characters in titles from \u202d (bidi override) to \u200a (hair space) Assert that the empty title is blank and can't be blank (even though it contains no prohibitd characters after replacement) * change the definition of prohibited characters From the description, it looks like "unicode space characters" was the desired rejection set. It was unclear what the existing regex was matching on (I couldn't get the expected examples to match correctly). Given the intent, I select "unicode space property, except the ascii space character", which may _also_ be incorrect but passed the tests. * Remove now-invalid expectation for presence of user id Since this was redundant (belongs_to user), we no longer will validate presence of user id, and we should not test for it. * Only reject bidirectional text controls The original issue pointed to the BIDI controls as problematic. While they called out other "whitespace" characters, as we accept a wider range of input languages, the need to handle non-printing punctuation (for example a group separating space for some asian languages). It's possible a wider list of characters should be added - if that's the case I suggest this regex and the sanitization be moved to a standalone class, and each of the recommendations in https://www.w3.org/TR/unicode-xml/#Charlist be checked for applicability. * Check for blank title after sanitizing disallowed characters Since validate_title modifies the title, and doesn't set error messages on the model itself, check for non-empty title _after_ potentially removing any disallowed characters. * Remove invalid characters before validation Remove the validate_title and contains_prohibited_characters methods, and center all logic on the remove prohibitied unicode characters method. Remove unneeded and unused arguments (input string is always title, replacement is always removal/empty string). * handle case when validating null title If the title's nil, we don't want to call match? since it will fail. Title will sometimes be nil when validating. Co-authored-by: Ben Halpern <bendhalpern@gmail.com> Co-authored-by: Dan Uber <dan@forem.com> |
||
|---|---|---|
| .buildkite | ||
| .gems | ||
| .github | ||
| .husky | ||
| .vscode | ||
| .yarn/releases | ||
| app | ||
| bin | ||
| config | ||
| cypress | ||
| datadog | ||
| db | ||
| lib | ||
| log | ||
| public | ||
| scripts | ||
| spec | ||
| vendor | ||
| .codeclimate.yml | ||
| .dockerignore | ||
| .editorconfig | ||
| .env_sample | ||
| .erb-lint.yml | ||
| .eslintignore | ||
| .eslintrc.js | ||
| .gitattributes | ||
| .gitignore | ||
| .gitpod.dockerfile | ||
| .gitpod.yml | ||
| .lintstagedrc.js | ||
| .nvmrc | ||
| .postcssrc.yml | ||
| .prettierignore | ||
| .prettierrc.json | ||
| .rspec | ||
| .rubocop.yml | ||
| .rubocop_todo.yml | ||
| .ruby-version | ||
| .simplecov | ||
| .slugignore | ||
| .travis.yml | ||
| .yardopts | ||
| .yarnclean | ||
| .yarnrc | ||
| babel.config.js | ||
| CHANGELOG.md | ||
| CODE_OF_CONDUCT.md | ||
| config.ru | ||
| container-compose.yml | ||
| Containerfile | ||
| CONTRIBUTING.md | ||
| customJsDomEnvironment.js | ||
| cypress.dev.json | ||
| cypress.json | ||
| docker-compose.yml | ||
| Dockerfile | ||
| empty-module.js | ||
| Gemfile | ||
| Gemfile.lock | ||
| gitpod-init.sh | ||
| Guardfile | ||
| jest.config.js | ||
| jsconfig.json | ||
| LICENSE.md | ||
| package.json | ||
| postcss.config.js | ||
| Procfile | ||
| Procfile.dev | ||
| Procfile.dev-hot | ||
| Rakefile | ||
| README.md | ||
| release-tasks.sh | ||
| SECURITY.md | ||
| svgo.config.js | ||
| testSetup.js | ||
| yarn.lock | ||
Forem 🌱
For Empowering CommunityWelcome to the Forem codebase, the platform that powers dev.to. We are so excited to have you. With your help, we can build out Forem’s usability, scalability, and stability to better serve our communities.
What is Forem?
Forem is open source software for building communities. Communities for your peers, customers, fanbases, families, friends, and any other time and space where people need to come together to be part of a collective. See our announcement post for a high-level overview of what Forem is.
dev.to (or just DEV) is hosted by Forem. It is a community of software developers who write articles, take part in discussions, and build their professional profiles. We value supportive and constructive dialogue in the pursuit of great code and career growth for all members. The ecosystem spans from beginner to advanced developers, and all are welcome to find their place within our community. ❤️
Table of Contents
- What is Forem?
- Table of Contents
- Community
- Contributing
- Getting Started
- Developer Documentation
- Core team
- Vulnerability disclosure
- License
Community
For a place to have open discussions on features, voice your ideas, or get help with general questions please visit our community at forem.dev.
Contributing
We encourage you to contribute to Forem! Please check out the Contributing to Forem guide for guidelines about how to proceed.
Getting Started
This section provides a high-level quick start guide. If you're looking for a more thorough installation guide (for example with macOS, you'll want to refer to our complete Developer Documentation.
We run on a Rails backend, and we are currently transitioning to a Preact-first frontend.
A more complete overview of our stack is available in our docs.
Prerequisites
Local
- Ruby: we recommend using rbenv to install the Ruby version listed on the badge.
- Yarn 1.x: please refer to their installation guide.
- PostgreSQL 11 or higher.
- ImageMagick: please refer to ImageMagick's installation instructions.
- Redis 4 or higher.
Containers
Linux
- Podman 1.9.2 or higher
- Podman Compose 0.1.5 or higher
OS X
Installation Documentation
Please see our installation guides, such as the one for macOS.
Developer Documentation
Check out our dedicated docs page for more technical documentation.
Core team
- @benhalpern
- @jessleenyc
- @peterkimfrank
- @maestromac
- @zhao-andy
- @lightalloy
- @atsmith813
- @citizen428
- @nickytonline
- @joshpuetz
- @juliannatetreault
- @ridhwana
- @fdoxyz
- @msarit
- @jdoss
- @cmgorton
- @andygeorge
- @phannon716
- @s_aitchison
- @jgaskins
- @djuber
- @rt4914
- @jeremyf
- @dscottS3
Vulnerability disclosure
Forem is the open source software which powers DEV.
We welcome security research on DEV under the terms of our vulnerability disclosure policy.
Acknowledgments
Thank you to the Twemoji project for the usage of their emojis.
License
This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. Please see the LICENSE file in our repository for the full text.
Like many open source projects, we require that contributors provide us with a Contributor License Agreement (CLA). By submitting code to the Forem project, you are granting us a right to use that code under the terms of the CLA.
Our version of the CLA was adapted from the Microsoft Contributor License Agreement, which they generously made available to the public domain under Creative Commons CC0 1.0 Universal.
Any questions, please refer to our license FAQ doc or email yo@dev.to.
Happy Coding ❤️