Repository navigation
replace next with vite - #5
Merged
Merged
Conversation
Philipinho
commented
Oct 20, 2023
Member
- replace next with vite
- disable react strictmode (it interferes with collaboration in dev mode)
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 20, 2026
… from feat/comments-panel-density into develop
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 20, 2026
…o an admin field Convert the htmlEmbed node from same-origin raw-HTML execution to a sandboxed iframe (sandbox="allow-scripts allow-popups allow-forms", no allow-same-origin, srcdoc) with postMessage auto-resize (validated by event.source) and an optional manual height attr. The block now runs in an opaque origin and cannot reach the viewer's cookies/session/API, so it is safe for any member. Because the block is now harmless, remove the entire admin/role gating apparatus: drop htmlEmbedAllowed/canAuthorHtmlEmbed/stripDisallowedHtmlEmbedNodes/ collectHtmlEmbedSources and every role-based strip on the write paths (collab REST/MCP + socket, page create/duplicate, import x2, transclusion unsync), along with the now-unused WorkspaceRepo/UserRepo injections and the PageService.create callerRole param. Keep one strip: prepareContentForShare still removes htmlEmbed on the anonymous public-share read path when the workspace master toggle is OFF. The workspace settings.htmlEmbed toggle is now a plain feature switch (gates the slash-menu and share rendering); when ON the block is available to all members. Add settings.trackerHead: an admin-only raw HTML/JS analytics snippet injected verbatim into the <head> of public share pages only (ShareSeoController), for trackers that genuinely need same-origin. Admin-gated via the existing CASL Manage/Settings ability; never injected into the authenticated app shell. Closes security-review findings #1, #2, docmost#4, docmost#5, docmost#10 (and #3 as a security issue). Co-Authored-By: Claude Opus 4.8 <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 23, 2026
…ocmost#143 review docmost#5) The agent write-stamp idiom — `...(isAgent ? { <source>: 'agent', <chat>: aiChatId } : {})` — was hand-reimplemented at every REST write site, so each new path risked a wrong literal or a forgotten aiChatId. Extract a single `agentSourceFields(provenance, sourceKey, chatKey)` next to AuthProvenanceData and call it at the 5 uniform spread sites: - comment.service create -> createdSource / aiChatId - page.service create/update/orphan-move/move -> lastUpdatedSource / lastUpdatedAiChatId Sites that must CLEAR the source on a non-agent action keep their own conditional (comment un-resolve writes an explicit null), and the collab persistence path keeps its sticky-window logic — both noted in the helper's doc. Behavior-preserving (the helper returns the identical object/`{}`). Typecheck clean; server comment/page/auth/collab suites 246 pass. Co-Authored-By: Claude Opus 4.8 <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 24, 2026
…ocmost#151 review) Review of docmost#158 (Request changes) — core logic verified correct; addressed the test-coverage + localization items: 1. i18n pluralization: the token-count keys were called with {count} but had one form, so ru-RU always rendered the genitive ("1 токенов"). Added _one/_other (en) and _one/_few/_many (ru: токен/токена/токенов) for both "Thinking… · {{count}} tokens" and "Thinking · {{count}} tokens"; de-duped the PR-added duplicate "Thinking" key. Call sites unchanged. 2. ReasoningBlock: new reasoning-block.test.tsx (4 branches: authoritative count wins / estimate fallback / header-only when count-but-no-text / body render). 3. Reasoning-token attribution: extracted the docmost#151 anti-double-count rule into a pure `reasoningTokensForPart(message)` (single reasoning part -> authoritative turn total; multiple/none -> undefined so each estimates). message-item uses it; removed the now-dead lastReasoningIndex reduce (review docmost#5). Unit-tested. 6. adopt-chat-id.ts: refreshed 3 stale `chatStreamStartMetadata` -> `chatStreamMetadata` comment references. 7. chat-markdown.test.ts: assert the export footer's `reasoning: N` line appears when reasoningTokens>0 and is absent at 0/undefined. Skipped optional docmost#4 (mantine useThrottledCallback): the manual throttle has two distinct exit paths (turn-end revert-to-null + the captured-total trailing emit) with no guarding test; remapping risks the streaming behavior — non-blocking. Client tsc clean; ai-chat suite green (171 tests). Co-Authored-By: Claude Opus 4.8 <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jun 26, 2026
…s share assistant (docmost#159) The anonymous public-share assistant only capped the COUNT of requests (100/hour/workspace), not their cost. One accepted turn runs the agent loop up to stepCountIs(5), re-sending the whole client-held transcript as input on every step, while maxOutputTokens caps only the output; the request window is hourly with no daily ceiling, so a steady stream at the cap sustains ~24x its count per day. Counting requests therefore does not bound the owner's LLM bill (red-team finding docmost#5). Add a second cost contour: a cluster-wide, sliding-window per-workspace TOKEN budget over a rolling day. It is checked read-only BEFORE a turn streams (429, no request slot consumed, nothing spent) and the turn's real usage (totalUsage: input re-sent per step + output, summed across all steps) is recorded once it finishes via streamText onFinish. Fails closed on the check (deny when Redis can't prove we're under budget); best-effort on the record. Env-overridable via SHARE_AI_WORKSPACE_TOKEN_BUDGET_PER_DAY (default 1M/day). Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jul 4, 2026
…docmost#293 canon docmost#5) Move the two "invisible machinery" atoms off the <div data-type="..."> HTML form onto standalone HTML comments on their own line, keeping the markdown human-readable while still round-tripping: subpages -> <!--subpages--> / <!--subpages {"recursive":true}--> pageBreak -> <!--pagebreak--> Adds standaloneCommentFor(name, attrs?) to attached-comment.ts (emits `<!--name-->` when attrs are empty/absent, else `<!--name {compact-json}-->`). The `--`-escaping + compact-JSON logic is factored into a shared internal escapeCommentJson() so standaloneCommentFor and attachedCommentFor cannot drift (verified byte-identical output for attachedCommentFor — no docmost#9 regression). Position determines legality (canon docmost#5): subpages/pagebreak are honored ONLY standalone; the same comment attached after visible text is inert. The parser pass (applyAttachedComments renamed applyCommentDirectives) now also materializes these standalone comments into the schema `<div data-type=...>` element before generateJSON drops the comment node. A LEADING standalone comment is parsed at document level (outside <body>); the pass walks the whole document and re-inserts leading comments into <body> in document order, so block order is preserved. Raw-HTML path: blockToHtml gains explicit subpages/pageBreak cases emitting the `<div data-type=...>` form. Comments are dropped by the DOM parse stage inside columns/cells, so the div-form must stay there — this also fixes a latent default-fallthrough (`<div></div>`) that silently dropped these atoms inside a column. Tests: new machinery-comments.test.ts (primitive, subpages default/recursive exact strings + round-trip, pageBreak, subpages-inside-column div-form, fail-open for attached-position/malformed, and multi-node document-order regression locking the leading/mid/trailing comment ordering). Top-level goldens in markdown-converter-golden/gaps updated deliberately to the comment form; the columns/raw-HTML goldens keep the div-form. package vitest: 477 passed | 1 expected-fail; tsc clean. git-sync: 268 passed. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
vvzvlad
pushed a commit
to vvzvlad/gitmost
that referenced
this pull request
Jul 4, 2026
…omment (docmost#293 canon docmost#8) Ten media/embed node types move their TOP-LEVEL serialization off raw schema HTML onto a readable markdown target plus an always-emitted discriminator comment whose NAME selects the node type. The schema-HTML form is retained on the raw-HTML/columns path (comments are dropped by the DOM parse stage there). image-form <!--name …--> youtube, video, audio, drawio, excalidraw link-form [text](src)<!--name …--> pdf, attachment, embed (text=filename/provider) standalone <!--pageembed …--> / <!--transclusion …--> pageEmbed, transclusionReference The comment NAME is the node-type discriminator and is ALWAYS emitted, even when the attr JSON is empty (`<!--youtube-->`), so a bare `` is never mistaken for an `image` and a bare `[t](u)` stays a plain link — no URL-sniffing. src rides in the markdown target; every other non-default attr (incl. the id links attachmentId/sourcePageId/transclusionId) rides in the comment JSON (stable key order, numerics stringified, align="center" omitted). New src/lib/media-html.ts: byte-exact builders reproducing the schema HTML each old processNode case returned. Both the serializer's raw-HTML path (blockToHtml, now de-delegated from `return processNode(block)` to explicit per-type cases) and the importer call these, so serialize and parse cannot drift. Import (applyCommentDirectives): image-form binds the preceding <img> (src from it), link-form the preceding <a> (src=href, text=filename/provider), standalone replaces the comment (same leading-doc-level handling as docmost#5). Each rebuilds the schema element via the media-html builder, then swaps it in; the empty-<p> hoist is absorbed by stripEmptyParagraphs. Fail-open: wrong element/position/name or malformed JSON -> inert, no throw. Link-form visible text is escaped (escapeLinkText) for the FULL set of CommonMark inline-active punctuation (\ ` * _ ~ [ ] < & ! ( )), not just [ ] \: the label is parsed as inline content, so a filename/provider like `report *v2*.pdf` or `.pdf` would otherwise lose the markup (or fragment the parse) when the importer reads a.textContent back — a data-loss regression vs the old data-attachment-name form. Adversarial round-trip fixtures lock byte- and value-stability for emphasis/code/strike/autolink/entity/image markers and nested-link names. Tests: new media-comments.test.ts (40 cases: per-type exact md + lossless byte-stable round-trip incl. id links, minimal-node discriminator-still-emitted, in-column schema-HTML form, discriminator integrity, fail-open, active-punct filenames). Goldens in media-roundtrip / markdown-converter-golden / markdown-converter / diagram-roundtrip updated to the md+comment form (columns stay schema-HTML). The former known-limitation image-diagrams fixture is now byte- AND canonically-stable (canon docmost#8 omits the diagram align="center" default) and was promoted from an it.fails into the green corpus (11-image-diagrams.json). git-sync stabilize.test.ts: the "diagram materializes data-align=center" fixpoint moved into a column (where the raw-HTML asymmetry still holds), since top level is now byte-stable. package vitest: 540 passed; tsc clean. git-sync: 268 passed. Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]>
PMQ9
referenced
this pull request
in cccvu/docmost
Aug 30, 2026
…ervice) Rebind SearchService -> a fork-owned PdpSearchService subclass (seam #5, a composition/DI edit in core/search/search.module.ts). The subclass makes search structurally filter-then-retrieve: the authorized object set gates retrieval BEFORE limit/offset, fixing authorized-k-under-truncation while reusing the already-PDP-rebound filterAccessiblePageIds gate (bounded, ZedToken-fresh). - authz/search/pdp-search.service.ts: bounded, iterative, authorized-complete fetch over the rank-ordered FTS candidate stream (searchPage + searchSuggestions); a single collectAuthorized loop = the one filter-then-retrieve primitive (RAG blueprint). No total-hit count exposed (no count/score side-channel); scan ceiling logged (no silent truncation). - authz/search/pdp-search.service.spec.ts: truncation-completeness, absence, fail-closed, stable pagination, scan-cap-logged. - authz/leakage/vectors.spec.ts: lock the PdpSearchService overrides so search can't silently regress to upstream retrieve-then-filter. All search-authorization logic lives in fork-owned authz/; the only upstream edit is the one-line provider rebind. Confidentiality already held via the repo rebind; this closes the completeness/truncation gap and makes the guarantee structural. Co-Authored-By: Claude Opus 4.8 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.