Compare commits

..
Author SHA1 Message Date
Typosaurus a8ed5b690f ticket #106 attempt 1 2026-07-23 02:33:42 +00:00
6 changed files with 58 additions and 93 deletions
File diff suppressed because one or more lines are too long
-31
View File
@@ -360,37 +360,6 @@ def create_comment_record(
comment_url,
)
if target_type == "post":
posts_table = get_table("posts")
post_record = posts_table.find_one(uid=target_uid)
if not post_record:
post_record = posts_table.find_one(slug=target_uid)
commenter_uids = set()
for c in get_table("comments").find(
target_type="post", target_uid=target_uid, deleted_at=None
):
commenter_uids.add(c["user_uid"])
commenter_uids.discard(user["uid"])
if post_record:
commenter_uids.discard(post_record["user_uid"])
if parent_uid:
parent_comment = get_table("comments").find_one(
uid=parent_uid, deleted_at=None
)
if parent_comment and parent_comment["user_uid"] != user["uid"]:
commenter_uids.discard(parent_comment["user_uid"])
for commenter_uid in commenter_uids:
create_notification(
commenter_uid,
"thread_comment",
f"{user['username']} also commented on a post you commented on",
user["uid"],
comment_url,
)
create_mention_notifications(content, user["uid"], comment_url)
schedule_correction(user, "comments", comment_uid, request)
schedule_modification(user, "comments", comment_uid, request)
-1
View File
@@ -19,7 +19,6 @@ NOTIFICATION_TYPES = [
{"key": "harvest_stolen", "label": "Farm raids", "description": "Someone steals a ready build from your Code Farm"},
{"key": "award", "label": "Awards", "description": "Someone gives you an award on your profile"},
{"key": "system", "label": "System alerts", "description": "Platform infrastructure alerts (e.g. the AI gateway going down)"},
{"key": "thread_comment", "label": "Thread comments", "description": "Someone else comments on a post you commented on"},
]
+10
View File
@@ -470,9 +470,19 @@ class SeoRunForm(BaseModel):
text = value.strip()
if not text:
raise ValueError("A URL is required")
if "://" in text:
scheme = text.split("://", 1)[0]
if scheme not in ("http", "https"):
raise ValueError(f"Only http and https URLs are allowed; got '{scheme}://'")
else:
text = f"https://{text}"
if not SEO_URL_PATTERN.match(text):
raise ValueError("URL must be a valid http or https source location")
return text
SEO_URL_PATTERN = re.compile(r"^https?://[a-zA-Z0-9][\w./:@~^?&#%=;-]*$")
ISSLOP_URL_PATTERN = re.compile(r"^(https?://|git://|ssh://|git@)[\w./:@~^-]+$", re.IGNORECASE)
ISSLOP_SINGLE_SLASH_PATTERN = re.compile(r"^(https?|git|ssh):/(?!/)", re.IGNORECASE)
ISSLOP_SCHEME_PATTERN = re.compile(r"^[a-z][a-z0-9+.-]*://", re.IGNORECASE)
+47
View File
@@ -89,6 +89,53 @@ def test_run_clamps_max_pages_above_cap(app_server):
_clear_seo_jobs()
def test_run_rejects_malformed_scheme(app_server):
r = requests.post(
f"{BASE_URL}/tools/seo/run",
headers=_json_headers(),
data={"url": "ahttps://devplace.net/sitem", "mode": "url"},
allow_redirects=False,
)
assert r.status_code in (400, 422), r.text
def test_run_rejects_relative_path(app_server):
r = requests.post(
f"{BASE_URL}/tools/seo/run",
headers=_json_headers(),
data={"url": "/feed", "mode": "url"},
allow_redirects=False,
)
assert r.status_code in (400, 422), r.text
def test_run_normalizes_missing_scheme(app_server):
try:
r = requests.post(
f"{BASE_URL}/tools/seo/run",
headers=_json_headers(),
data={"url": "example.com", "mode": "url", "max_pages": "5"},
)
assert r.status_code == 200, r.text
uid = r.json()["uid"]
refresh_snapshot()
job = queue.get_job(uid)
assert job is not None
assert job["payload"]["url"] == "https://example.com"
finally:
_clear_seo_jobs()
def test_run_rejects_non_http_scheme(app_server):
r = requests.post(
f"{BASE_URL}/tools/seo/run",
headers=_json_headers(),
data={"url": "ftp://example.com", "mode": "url"},
allow_redirects=False,
)
assert r.status_code in (400, 422), r.text
def test_run_enforces_one_active_job_per_owner(app_server):
try:
first = requests.post(
-60
View File
@@ -384,66 +384,6 @@ def test_comment_notification_on_post(app_server, browser, seeded_db):
ctx_b.close()
def test_thread_comment_notification(app_server, browser, seeded_db):
from tests.conftest import login_user
ctx_a = browser.new_context(viewport={"width": 1400, "height": 900})
ctx_b = browser.new_context(viewport={"width": 1400, "height": 900})
pa = ctx_a.new_page()
pb = ctx_b.new_page()
pa.set_default_timeout(15000)
pb.set_default_timeout(15000)
login_user(pa, seeded_db["alice"])
login_user(pb, seeded_db["bob"])
pa.goto(f"{BASE_URL}/feed", wait_until="domcontentloaded")
pa.locator(".feed-fab").first.wait_for(state="visible", timeout=10000)
pa.locator(".feed-fab").first.click()
pa.fill("#post-content", "Post for thread comment notification test")
pa.locator("#create-post-modal button.btn-primary:has-text('Post')").click()
pa.wait_for_url("**/posts/*", timeout=10000, wait_until="domcontentloaded")
post_url = pa.url
pb.goto(post_url, wait_until="domcontentloaded")
pb.wait_for_timeout(1000)
comment_textarea = pb.locator("form.comment-form textarea[name='content']").first
comment_textarea.wait_for(state="visible", timeout=10000)
comment_textarea.fill("Bob's top-level comment")
pb.locator("button.comment-form-submit").first.click()
pb.wait_for_timeout(1500)
pb_body = pb.locator("body").text_content()
assert "Internal Server Error" not in pb_body, f"Bob got 500: {pb_body[:300]}"
pa.goto(post_url, wait_until="domcontentloaded")
pa.wait_for_timeout(1000)
comment_textarea = pa.locator("form.comment-form textarea[name='content']").first
comment_textarea.wait_for(state="visible", timeout=10000)
comment_textarea.fill("Alice also comments on her own post")
pa.locator("button.comment-form-submit").first.click()
pa.wait_for_timeout(1500)
pa_body = pa.locator("body").text_content()
assert "Internal Server Error" not in pa_body, f"Alice got 500: {pa_body[:300]}"
pb.goto(f"{BASE_URL}/notifications", wait_until="domcontentloaded")
pb.wait_for_timeout(2000)
body = pb.locator("body").text_content()
assert "Internal Server Error" not in body, (
f"Got 500 error on notifications: {body[:500]}"
)
assert "alice_test" in body, (
f"Expected 'alice_test' in notifications, got: {body[:500]}"
)
assert "also commented" in body, (
f"Expected 'also commented' in notifications, got: {body[:500]}"
)
ctx_a.close()
ctx_b.close()
def test_follow_notification(app_server, browser, seeded_db):
from tests.conftest import login_user