forked from retoor/devplacepy
Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ffdb25739c |
File diff suppressed because one or more lines are too long
@@ -93,6 +93,36 @@ def get_recent_comments_by_target_uids(target_type, target_uids, limit=3, user=N
|
|||||||
raw = _drop_blocked(raw, user)
|
raw = _drop_blocked(raw, user)
|
||||||
if not raw:
|
if not raw:
|
||||||
return {}
|
return {}
|
||||||
|
|
||||||
|
# Fetch missing parent comments so the threaded hierarchy is preserved even
|
||||||
|
# when a parent is outside the row-number limit.
|
||||||
|
if "comments" in db.tables:
|
||||||
|
comments_table = db["comments"]
|
||||||
|
current_uids = {c["uid"] for c in raw}
|
||||||
|
seen = set(current_uids)
|
||||||
|
to_fetch = []
|
||||||
|
for c in raw:
|
||||||
|
puid = c.get("parent_uid")
|
||||||
|
if puid and puid not in seen:
|
||||||
|
seen.add(puid)
|
||||||
|
to_fetch.append(puid)
|
||||||
|
if to_fetch:
|
||||||
|
ancestors = []
|
||||||
|
queue = list(to_fetch)
|
||||||
|
fetched = set()
|
||||||
|
while queue:
|
||||||
|
uid = queue.pop(0)
|
||||||
|
if uid in fetched or uid in current_uids:
|
||||||
|
continue
|
||||||
|
row = comments_table.find_one(uid=uid, deleted_at=None)
|
||||||
|
if row:
|
||||||
|
ancestors.append(row)
|
||||||
|
fetched.add(uid)
|
||||||
|
grandparent = row.get("parent_uid")
|
||||||
|
if grandparent and grandparent not in fetched and grandparent not in current_uids:
|
||||||
|
queue.append(grandparent)
|
||||||
|
raw.extend(ancestors)
|
||||||
|
|
||||||
items = _build_comment_items(raw, user)
|
items = _build_comment_items(raw, user)
|
||||||
by_target = defaultdict(list)
|
by_target = defaultdict(list)
|
||||||
for c in raw:
|
for c in raw:
|
||||||
|
|||||||
@@ -11,6 +11,7 @@ from devplacepy.utils import (
|
|||||||
create_session,
|
create_session,
|
||||||
get_current_user,
|
get_current_user,
|
||||||
safe_next,
|
safe_next,
|
||||||
|
cookie_secure,
|
||||||
)
|
)
|
||||||
from devplacepy.seo import base_seo_context
|
from devplacepy.seo import base_seo_context
|
||||||
from devplacepy.models import LoginForm
|
from devplacepy.models import LoginForm
|
||||||
@@ -102,7 +103,7 @@ async def login(request: Request, data: Annotated[LoginForm, Depends(json_or_for
|
|||||||
max_age=max_age,
|
max_age=max_age,
|
||||||
httponly=True,
|
httponly=True,
|
||||||
samesite="lax",
|
samesite="lax",
|
||||||
secure=False,
|
secure=cookie_secure(request),
|
||||||
)
|
)
|
||||||
logger.info(f"User {user['username']} logged in")
|
logger.info(f"User {user['username']} logged in")
|
||||||
audit.record(
|
audit.record(
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ from devplacepy.utils import (
|
|||||||
create_session,
|
create_session,
|
||||||
get_current_user,
|
get_current_user,
|
||||||
register_account_async,
|
register_account_async,
|
||||||
|
cookie_secure,
|
||||||
)
|
)
|
||||||
from devplacepy.seo import base_seo_context
|
from devplacepy.seo import base_seo_context
|
||||||
from devplacepy.models import SignupForm
|
from devplacepy.models import SignupForm
|
||||||
@@ -100,7 +101,7 @@ async def signup(request: Request, data: Annotated[SignupForm, Depends(json_or_f
|
|||||||
max_age=max_age,
|
max_age=max_age,
|
||||||
httponly=True,
|
httponly=True,
|
||||||
samesite="lax",
|
samesite="lax",
|
||||||
secure=False,
|
secure=cookie_secure(request),
|
||||||
)
|
)
|
||||||
logger.info(f"User {username} signed up")
|
logger.info(f"User {username} signed up")
|
||||||
audit.record(
|
audit.record(
|
||||||
|
|||||||
@@ -1,18 +0,0 @@
|
|||||||
# retoor <retoor@molodetz.nl>
|
|
||||||
|
|
||||||
import requests
|
|
||||||
from tests.conftest import BASE_URL
|
|
||||||
|
|
||||||
|
|
||||||
def test_login_session_cookie_missing_secure_flag(seeded_db):
|
|
||||||
s = requests.Session()
|
|
||||||
r = s.post(
|
|
||||||
f"{BASE_URL}/auth/login",
|
|
||||||
data={"email": "alice@test.devplace", "password": "secret123"},
|
|
||||||
allow_redirects=False,
|
|
||||||
)
|
|
||||||
set_cookie = r.headers.get("Set-Cookie", "")
|
|
||||||
assert "session=" in set_cookie, f"session cookie not found in Set-Cookie: {set_cookie}"
|
|
||||||
assert "HttpOnly" in set_cookie, f"HttpOnly not found in Set-Cookie: {set_cookie}"
|
|
||||||
assert "SameSite=Lax" in set_cookie, f"SameSite=Lax not found in Set-Cookie: {set_cookie}"
|
|
||||||
assert "Secure" not in set_cookie, f"Secure flag should be absent from Set-Cookie: {set_cookie}"
|
|
||||||
@@ -959,3 +959,72 @@ def test_feed_scroll_not_restored_on_fresh_visit(alice):
|
|||||||
page.goto(f"{BASE_URL}/feed", wait_until="domcontentloaded")
|
page.goto(f"{BASE_URL}/feed", wait_until="domcontentloaded")
|
||||||
page.wait_for_timeout(600)
|
page.wait_for_timeout(600)
|
||||||
assert page.evaluate("window.scrollY") < 60
|
assert page.evaluate("window.scrollY") < 60
|
||||||
|
|
||||||
|
|
||||||
|
def _seed_post_with_orphaned_parent():
|
||||||
|
owner = str(uuid4())
|
||||||
|
get_table("users").insert(
|
||||||
|
{
|
||||||
|
"uid": owner,
|
||||||
|
"username": f"opseed_{owner[:8]}",
|
||||||
|
"email": f"{owner[:8]}@op.seed",
|
||||||
|
"password_hash": "x",
|
||||||
|
"role": "Member",
|
||||||
|
"is_active": True,
|
||||||
|
"created_at": datetime.now(timezone.utc).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
post_uid = str(uuid4())
|
||||||
|
marker = f"oppost-{post_uid[:8]}"
|
||||||
|
get_table("posts").insert(
|
||||||
|
{
|
||||||
|
"deleted_at": None,
|
||||||
|
"deleted_by": None,
|
||||||
|
"uid": post_uid,
|
||||||
|
"user_uid": owner,
|
||||||
|
"slug": make_combined_slug(marker, post_uid),
|
||||||
|
"title": None,
|
||||||
|
"content": marker,
|
||||||
|
"topic": "devlog",
|
||||||
|
"project_uid": None,
|
||||||
|
"image": None,
|
||||||
|
"stars": 0,
|
||||||
|
"created_at": datetime.now(timezone.utc).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
orphan_parent = str(uuid4())
|
||||||
|
base = datetime.now(timezone.utc)
|
||||||
|
rows = [
|
||||||
|
(f"{marker}-orphan-parent", orphan_parent, None, -3),
|
||||||
|
(f"{marker}-older", str(uuid4()), None, -2),
|
||||||
|
(f"{marker}-flat", str(uuid4()), None, -1),
|
||||||
|
(f"{marker}-reply", str(uuid4()), orphan_parent, 0),
|
||||||
|
]
|
||||||
|
comments = get_table("comments")
|
||||||
|
for content, cuid, par, off in rows:
|
||||||
|
comments.insert(
|
||||||
|
{
|
||||||
|
"deleted_at": None,
|
||||||
|
"deleted_by": None,
|
||||||
|
"uid": cuid,
|
||||||
|
"target_type": "post",
|
||||||
|
"target_uid": post_uid,
|
||||||
|
"post_uid": post_uid,
|
||||||
|
"user_uid": owner,
|
||||||
|
"content": content,
|
||||||
|
"parent_uid": par,
|
||||||
|
"created_at": (base + timedelta(seconds=off)).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return marker
|
||||||
|
|
||||||
|
|
||||||
|
def test_feed_preserves_comment_hierarchy_with_orphaned_parent(page, app_server):
|
||||||
|
marker = _seed_post_with_orphaned_parent()
|
||||||
|
page.goto(f"{BASE_URL}/feed", wait_until="domcontentloaded")
|
||||||
|
card = page.locator(".post-card").filter(has_text=marker).first
|
||||||
|
card.wait_for(state="visible")
|
||||||
|
expect(card.locator(".post-card-comments")).to_contain_text(f"{marker}-orphan-parent")
|
||||||
|
expect(card.locator(".post-card-comments")).to_contain_text(f"{marker}-reply")
|
||||||
|
nested = card.locator(".post-card-comments .comment-replies .comment-text")
|
||||||
|
expect(nested).to_contain_text(f"{marker}-reply")
|
||||||
|
|||||||
@@ -468,3 +468,70 @@ def test_gists_list_preserves_comment_hierarchy(page, app_server):
|
|||||||
expect(card.locator(".post-card-comments")).not_to_contain_text(f"{marker}-excluded")
|
expect(card.locator(".post-card-comments")).not_to_contain_text(f"{marker}-excluded")
|
||||||
nested = card.locator(".post-card-comments .comment-replies .comment-text")
|
nested = card.locator(".post-card-comments .comment-replies .comment-text")
|
||||||
expect(nested).to_contain_text(f"{marker}-reply")
|
expect(nested).to_contain_text(f"{marker}-reply")
|
||||||
|
|
||||||
|
|
||||||
|
def _seed_gist_with_orphaned_parent():
|
||||||
|
owner = str(uuid4())
|
||||||
|
get_table("users").insert(
|
||||||
|
{
|
||||||
|
"uid": owner,
|
||||||
|
"username": f"gopseed_{owner[:8]}",
|
||||||
|
"email": f"{owner[:8]}@gop.seed",
|
||||||
|
"password_hash": "x",
|
||||||
|
"role": "Member",
|
||||||
|
"is_active": True,
|
||||||
|
"created_at": datetime.now(timezone.utc).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
uid = str(uuid4())
|
||||||
|
marker = f"gistop-{uid[:8]}"
|
||||||
|
get_table("gists").insert(
|
||||||
|
{
|
||||||
|
"deleted_at": None,
|
||||||
|
"deleted_by": None,
|
||||||
|
"uid": uid,
|
||||||
|
"user_uid": owner,
|
||||||
|
"slug": make_combined_slug(marker, uid),
|
||||||
|
"title": marker,
|
||||||
|
"description": "Gist with orphaned parent hierarchy.",
|
||||||
|
"source_code": "print('x')",
|
||||||
|
"language": "python",
|
||||||
|
"stars": 0,
|
||||||
|
"created_at": datetime.now(timezone.utc).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
orphan_parent = str(uuid4())
|
||||||
|
base = datetime.now(timezone.utc)
|
||||||
|
rows = [
|
||||||
|
(f"{marker}-orphan-parent", orphan_parent, None, -3),
|
||||||
|
(f"{marker}-older", str(uuid4()), None, -2),
|
||||||
|
(f"{marker}-flat", str(uuid4()), None, -1),
|
||||||
|
(f"{marker}-reply", str(uuid4()), orphan_parent, 0),
|
||||||
|
]
|
||||||
|
comments = get_table("comments")
|
||||||
|
for content, cuid, par, off in rows:
|
||||||
|
comments.insert(
|
||||||
|
{
|
||||||
|
"deleted_at": None,
|
||||||
|
"deleted_by": None,
|
||||||
|
"uid": cuid,
|
||||||
|
"target_type": "gist",
|
||||||
|
"target_uid": uid,
|
||||||
|
"user_uid": owner,
|
||||||
|
"content": content,
|
||||||
|
"parent_uid": par,
|
||||||
|
"created_at": (base + timedelta(seconds=off)).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return marker
|
||||||
|
|
||||||
|
|
||||||
|
def test_gists_list_preserves_comment_hierarchy_with_orphaned_parent(page, app_server):
|
||||||
|
marker = _seed_gist_with_orphaned_parent()
|
||||||
|
page.goto(f"{BASE_URL}/gists", wait_until="domcontentloaded")
|
||||||
|
card = page.locator(".gist-card").filter(has_text=marker).first
|
||||||
|
card.wait_for(state="visible")
|
||||||
|
expect(card.locator(".post-card-comments")).to_contain_text(f"{marker}-orphan-parent")
|
||||||
|
expect(card.locator(".post-card-comments")).to_contain_text(f"{marker}-reply")
|
||||||
|
nested = card.locator(".post-card-comments .comment-replies .comment-text")
|
||||||
|
expect(nested).to_contain_text(f"{marker}-reply")
|
||||||
|
|||||||
@@ -387,3 +387,75 @@ def test_news_list_preserves_comment_hierarchy(page, app_server):
|
|||||||
expect(card.locator(".post-card-comments")).not_to_contain_text(f"{marker}-excluded")
|
expect(card.locator(".post-card-comments")).not_to_contain_text(f"{marker}-excluded")
|
||||||
nested = card.locator(".post-card-comments .comment-replies .comment-text")
|
nested = card.locator(".post-card-comments .comment-replies .comment-text")
|
||||||
expect(nested).to_contain_text(f"{marker}-reply")
|
expect(nested).to_contain_text(f"{marker}-reply")
|
||||||
|
|
||||||
|
|
||||||
|
def _seed_news_with_orphaned_parent():
|
||||||
|
owner = str(uuid4())
|
||||||
|
get_table("users").insert(
|
||||||
|
{
|
||||||
|
"uid": owner,
|
||||||
|
"username": f"nopseed_{owner[:8]}",
|
||||||
|
"email": f"{owner[:8]}@nop.seed",
|
||||||
|
"password_hash": "x",
|
||||||
|
"role": "Member",
|
||||||
|
"is_active": True,
|
||||||
|
"created_at": datetime.now(timezone.utc).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
uid = str(uuid4())
|
||||||
|
marker = f"newsop-{uid[:8]}"
|
||||||
|
get_table("news").insert(
|
||||||
|
{
|
||||||
|
"deleted_at": None,
|
||||||
|
"deleted_by": None,
|
||||||
|
"uid": uid,
|
||||||
|
"slug": make_combined_slug(marker, uid),
|
||||||
|
"title": marker,
|
||||||
|
"description": "News with orphaned parent hierarchy.",
|
||||||
|
"content": "Body.",
|
||||||
|
"url": "https://example.com/nop",
|
||||||
|
"source_name": "NOPSource",
|
||||||
|
"external_id": f"nop_{uid[:8]}",
|
||||||
|
"status": "published",
|
||||||
|
"show_on_landing": 0,
|
||||||
|
"grade": 10,
|
||||||
|
"synced_at": datetime.now(timezone.utc).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
orphan_parent = str(uuid4())
|
||||||
|
base = datetime.now(timezone.utc)
|
||||||
|
rows = [
|
||||||
|
(f"{marker}-orphan-parent", orphan_parent, None, -3),
|
||||||
|
(f"{marker}-older", str(uuid4()), None, -2),
|
||||||
|
(f"{marker}-flat", str(uuid4()), None, -1),
|
||||||
|
(f"{marker}-reply", str(uuid4()), orphan_parent, 0),
|
||||||
|
]
|
||||||
|
comments = get_table("comments")
|
||||||
|
for content, cuid, par, off in rows:
|
||||||
|
comments.insert(
|
||||||
|
{
|
||||||
|
"deleted_at": None,
|
||||||
|
"deleted_by": None,
|
||||||
|
"uid": cuid,
|
||||||
|
"target_type": "news",
|
||||||
|
"target_uid": uid,
|
||||||
|
"user_uid": owner,
|
||||||
|
"content": content,
|
||||||
|
"parent_uid": par,
|
||||||
|
"created_at": (base + timedelta(seconds=off)).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return marker
|
||||||
|
|
||||||
|
|
||||||
|
def test_news_list_preserves_comment_hierarchy_with_orphaned_parent(page, app_server):
|
||||||
|
from playwright.sync_api import expect
|
||||||
|
|
||||||
|
marker = _seed_news_with_orphaned_parent()
|
||||||
|
page.goto(f"{BASE_URL}/news", wait_until="domcontentloaded")
|
||||||
|
card = page.locator(".news-card").filter(has_text=marker).first
|
||||||
|
card.wait_for(state="visible")
|
||||||
|
expect(card.locator(".post-card-comments")).to_contain_text(f"{marker}-orphan-parent")
|
||||||
|
expect(card.locator(".post-card-comments")).to_contain_text(f"{marker}-reply")
|
||||||
|
nested = card.locator(".post-card-comments .comment-replies .comment-text")
|
||||||
|
expect(nested).to_contain_text(f"{marker}-reply")
|
||||||
|
|||||||
@@ -1015,3 +1015,71 @@ def test_containers_menu_hidden_for_non_owner_admin_on_member_private_project(pa
|
|||||||
page.goto(f"{BASE_URL}/projects/{slug}", wait_until="domcontentloaded")
|
page.goto(f"{BASE_URL}/projects/{slug}", wait_until="domcontentloaded")
|
||||||
page.locator(".project-actions-more").click()
|
page.locator(".project-actions-more").click()
|
||||||
expect(page.locator(".context-menu-item:has-text('Containers')")).to_have_count(0)
|
expect(page.locator(".context-menu-item:has-text('Containers')")).to_have_count(0)
|
||||||
|
|
||||||
|
|
||||||
|
def _seed_project_with_orphaned_parent():
|
||||||
|
owner = str(uuid4())
|
||||||
|
get_table("users").insert(
|
||||||
|
{
|
||||||
|
"uid": owner,
|
||||||
|
"username": f"popseed_{owner[:8]}",
|
||||||
|
"email": f"{owner[:8]}@pop.seed",
|
||||||
|
"password_hash": "x",
|
||||||
|
"role": "Member",
|
||||||
|
"is_active": True,
|
||||||
|
"created_at": datetime.now(timezone.utc).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
uid = str(uuid4())
|
||||||
|
marker = f"projop-{uid[:8]}"
|
||||||
|
get_table("projects").insert(
|
||||||
|
{
|
||||||
|
"deleted_at": None,
|
||||||
|
"deleted_by": None,
|
||||||
|
"uid": uid,
|
||||||
|
"user_uid": owner,
|
||||||
|
"slug": make_combined_slug(marker, uid),
|
||||||
|
"title": marker,
|
||||||
|
"description": "Project with orphaned parent hierarchy.",
|
||||||
|
"project_type": "software",
|
||||||
|
"platforms": "Linux",
|
||||||
|
"status": "Released",
|
||||||
|
"stars": 0,
|
||||||
|
"created_at": datetime.now(timezone.utc).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
orphan_parent = str(uuid4())
|
||||||
|
base = datetime.now(timezone.utc)
|
||||||
|
rows = [
|
||||||
|
(f"{marker}-orphan-parent", orphan_parent, None, -3),
|
||||||
|
(f"{marker}-older", str(uuid4()), None, -2),
|
||||||
|
(f"{marker}-flat", str(uuid4()), None, -1),
|
||||||
|
(f"{marker}-reply", str(uuid4()), orphan_parent, 0),
|
||||||
|
]
|
||||||
|
comments = get_table("comments")
|
||||||
|
for content, cuid, par, off in rows:
|
||||||
|
comments.insert(
|
||||||
|
{
|
||||||
|
"deleted_at": None,
|
||||||
|
"deleted_by": None,
|
||||||
|
"uid": cuid,
|
||||||
|
"target_type": "project",
|
||||||
|
"target_uid": uid,
|
||||||
|
"user_uid": owner,
|
||||||
|
"content": content,
|
||||||
|
"parent_uid": par,
|
||||||
|
"created_at": (base + timedelta(seconds=off)).isoformat(),
|
||||||
|
}
|
||||||
|
)
|
||||||
|
return marker
|
||||||
|
|
||||||
|
|
||||||
|
def test_projects_list_preserves_comment_hierarchy_with_orphaned_parent(page, app_server):
|
||||||
|
marker = _seed_project_with_orphaned_parent()
|
||||||
|
page.goto(f"{BASE_URL}/projects", wait_until="domcontentloaded")
|
||||||
|
card = page.locator(".project-card").filter(has_text=marker).first
|
||||||
|
card.wait_for(state="visible")
|
||||||
|
expect(card.locator(".post-card-comments")).to_contain_text(f"{marker}-orphan-parent")
|
||||||
|
expect(card.locator(".post-card-comments")).to_contain_text(f"{marker}-reply")
|
||||||
|
nested = card.locator(".post-card-comments .comment-replies .comment-text")
|
||||||
|
expect(nested).to_contain_text(f"{marker}-reply")
|
||||||
|
|||||||
Reference in New Issue
Block a user