Compare commits
28
Commits
Generated
+1
-1
@@ -2948,7 +2948,7 @@ dependencies = [
|
||||
|
||||
[[package]]
|
||||
name = "portal"
|
||||
version = "0.3.18"
|
||||
version = "0.3.31"
|
||||
dependencies = [
|
||||
"anyhow",
|
||||
"arc-swap",
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
[package]
|
||||
name = "portal"
|
||||
version = "0.3.18"
|
||||
version = "0.3.32"
|
||||
edition = "2021"
|
||||
|
||||
[lib]
|
||||
|
||||
+68
-17
@@ -1,5 +1,5 @@
|
||||
use leptos::prelude::*;
|
||||
use leptos_meta::{provide_meta_context, HashedStylesheet, MetaTags, Title};
|
||||
use leptos_meta::{provide_meta_context, HashedStylesheet, Html, Link, MetaTags, Stylesheet, Title};
|
||||
use leptos_router::{
|
||||
components::{Route, Router, Routes},
|
||||
hooks::{use_location, use_navigate, use_query_map},
|
||||
@@ -10,6 +10,7 @@ use serde::{Deserialize, Serialize};
|
||||
use crate::answers::{Answer, SelfTransitionAnswer, TransitionAnswers, TransitionItem};
|
||||
use crate::auth::{current_user, User};
|
||||
use crate::content::{is_qualified, render_inline_markdown, Alternative, Question, Responsible, SiteConfig, Transition};
|
||||
use crate::i18n::t;
|
||||
use crate::resource::{get_requirement_binding, get_requirement_options, get_resource};
|
||||
|
||||
/// The visible site name/wordmark - "portal" is just this codebase's
|
||||
@@ -68,8 +69,39 @@ pub fn App() -> impl IntoView {
|
||||
// context instead of fetching their own copy.
|
||||
let site = Resource::new(|| (), |_| get_site());
|
||||
provide_context(site);
|
||||
// The chrome's language, from site.yaml (default "en"); content
|
||||
// speaks for itself. Components read this via context for t().
|
||||
let lang = Memo::new(move |_| {
|
||||
site.get()
|
||||
.and_then(|r| r.ok())
|
||||
.and_then(|s| s.lang)
|
||||
.unwrap_or_else(|| "en".to_string())
|
||||
});
|
||||
provide_context(Lang(lang));
|
||||
|
||||
// A content-shipped stylesheet (site.yaml `stylesheet:`) layered
|
||||
// after the default one - leptos_meta appends it at the MetaTags
|
||||
// slot, which the shell places after HashedStylesheet, so content
|
||||
// rules win at equal specificity.
|
||||
let custom_css = Memo::new(move |_| {
|
||||
site.get()
|
||||
.and_then(|r| r.ok())
|
||||
.and_then(|s| s.stylesheet)
|
||||
.map(|p| format!("/site/{p}"))
|
||||
});
|
||||
// A content-shipped favicon overrides the built-in one; injected
|
||||
// into the head after the static defaults, so it wins.
|
||||
let favicon = Memo::new(move |_| {
|
||||
site.get()
|
||||
.and_then(|r| r.ok())
|
||||
.and_then(|s| s.favicon)
|
||||
.map(|p| format!("/site/{p}"))
|
||||
});
|
||||
|
||||
view! {
|
||||
<Html attr:lang=move || lang.get()/>
|
||||
{move || custom_css.get().map(|href| view! { <Stylesheet id="site-custom" href=href/> })}
|
||||
{move || favicon.get().map(|href| view! { <Link rel="icon" href=href/> })}
|
||||
<Suspense fallback=|| ()>
|
||||
{move || {
|
||||
site.get()
|
||||
@@ -88,6 +120,15 @@ pub fn App() -> impl IntoView {
|
||||
}
|
||||
}
|
||||
|
||||
/// The site's chrome language as a context signal - see App.
|
||||
#[derive(Clone, Copy)]
|
||||
pub struct Lang(pub Memo<String>);
|
||||
|
||||
/// The current chrome language, for `t()` calls inside views.
|
||||
fn lang() -> Memo<String> {
|
||||
expect_context::<Lang>().0
|
||||
}
|
||||
|
||||
/// Every server-fn resource the pages read, created exactly once for
|
||||
/// the app's lifetime and handed down via context. Wrapper structs
|
||||
/// because a bare `Resource<T>` context is claimed by whoever provides
|
||||
@@ -241,7 +282,7 @@ fn QuestionView(
|
||||
/>
|
||||
<div class="alternatives">
|
||||
<section class="alt-card gate-card">
|
||||
<p>"This page follows from an answer you don't seem to carry yet."</p>
|
||||
<p>{move || t(&lang().get(), "follows_answer")}</p>
|
||||
<a class="alt-submit" href=target>
|
||||
{label}
|
||||
</a>
|
||||
@@ -269,7 +310,7 @@ fn QuestionView(
|
||||
<div class="alternatives">
|
||||
<section class="alt-card gate-card">
|
||||
{if signed_in {
|
||||
view! { <p>"This part of the site is for organizational owners — sign in with that account to take a look."</p> }
|
||||
view! { <p>{move || t(&lang().get(), "owners_only")}</p> }
|
||||
.into_any()
|
||||
} else {
|
||||
view! {
|
||||
@@ -278,7 +319,7 @@ fn QuestionView(
|
||||
href=format!("/auth/login?redirect={question_id}")
|
||||
rel="external"
|
||||
>
|
||||
"Sign in"
|
||||
{move || t(&lang().get(), "sign_in")}
|
||||
</a>
|
||||
}
|
||||
.into_any()
|
||||
@@ -371,7 +412,7 @@ fn QuestionNav(current_id: String, has_chain: bool) -> impl IntoView {
|
||||
.collect();
|
||||
(!others.is_empty()).then(|| view! {
|
||||
<nav class="question-nav">
|
||||
<span class="question-nav-lead">"Also worth asking"</span>
|
||||
<span class="question-nav-lead">{move || t(&lang().get(), "also_worth_asking")}</span>
|
||||
<For
|
||||
each=move || others.clone()
|
||||
key=|(id, _)| id.clone()
|
||||
@@ -399,7 +440,7 @@ fn Announcements(current_id: String) -> impl IntoView {
|
||||
let current_id = current_id.clone();
|
||||
announcements.get().and_then(|res| res.ok()).map(|items| {
|
||||
(!items.is_empty()).then(|| view! {
|
||||
<nav class="announce" aria-label="Announcements">
|
||||
<nav class="announce" aria-label=move || t(&lang().get(), "announcements")>
|
||||
<For
|
||||
each=move || items.clone()
|
||||
key=|a| a.id.clone()
|
||||
@@ -459,11 +500,11 @@ fn ResponsibleNote(responsible: Responsible) -> impl IntoView {
|
||||
|
||||
view! {
|
||||
<small class="question-responsible">
|
||||
"Asked by " {responsible.name.clone()} " — "
|
||||
{move || t(&lang().get(), "asked_by")} {responsible.name.clone()} " — "
|
||||
<a data-user=user data-domain=domain on:mouseover=assemble on:click=assemble>
|
||||
"contact them"
|
||||
{move || t(&lang().get(), "contact_them")}
|
||||
</a>
|
||||
" if you get stuck."
|
||||
{move || t(&lang().get(), "if_stuck")}
|
||||
</small>
|
||||
}
|
||||
}
|
||||
@@ -555,7 +596,17 @@ fn Hero(title: String, description: String, landing: bool, site: SiteConfig, cur
|
||||
None
|
||||
};
|
||||
let has_module = module.is_some();
|
||||
// Light theme can invert a white-stroke wordmark to ink. Default:
|
||||
// only the built-in house mark inverts; a content-shipped logo
|
||||
// keeps its colours unless site.yaml opts in with wordmark_invert.
|
||||
let house_wordmark = site.wordmark_invert.unwrap_or(site.wordmark.is_none());
|
||||
let wordmark = site.wordmark.clone().unwrap_or_else(|| "/wordmark.svg".to_string());
|
||||
// Clamped server-side too, but belt and braces for the inline style.
|
||||
let wordmark_style = site
|
||||
.wordmark_height
|
||||
.filter(|h| (0.5..=6.0).contains(h))
|
||||
.map(|h| format!("height: {h}rem"))
|
||||
.unwrap_or_default();
|
||||
let site_title = site.title.clone().unwrap_or_else(|| SITE_NAME.to_string());
|
||||
|
||||
let piece_ref: NodeRef<leptos::html::Div> = NodeRef::new();
|
||||
@@ -641,11 +692,11 @@ fn Hero(title: String, description: String, landing: bool, site: SiteConfig, cur
|
||||
}
|
||||
})}
|
||||
<div class="hero-copy">
|
||||
<a class="wordmark" href="/">
|
||||
<img src=wordmark alt=site_title/>
|
||||
<a class="wordmark" class:wordmark-house=house_wordmark href="/">
|
||||
<img src=wordmark alt=site_title style=wordmark_style/>
|
||||
</a>
|
||||
<h1>{title}</h1>
|
||||
<p>{description}</p>
|
||||
<p inner_html=render_inline_markdown(&description)></p>
|
||||
</div>
|
||||
</header>
|
||||
}
|
||||
@@ -727,7 +778,7 @@ fn AlternativeCard(
|
||||
</button>
|
||||
}
|
||||
.into_any(),
|
||||
Some(Ok(())) => view! { <p>"Done."</p> }.into_any(),
|
||||
Some(Ok(())) => view! { <p>{move || t(&lang().get(), "done")}</p> }.into_any(),
|
||||
Some(Err(e)) => view! { <p class="resource-error">{e.to_string()}</p> }.into_any(),
|
||||
}
|
||||
}}
|
||||
@@ -922,7 +973,7 @@ fn AlternativeCard(
|
||||
.consequence
|
||||
.first()
|
||||
.cloned()
|
||||
.unwrap_or_else(|| "Send".to_string());
|
||||
.unwrap_or_else(|| t(&lang().get(), "send").to_string());
|
||||
|
||||
view! {
|
||||
<section class="alt-card">
|
||||
@@ -1412,7 +1463,7 @@ fn ResourceFeature(
|
||||
{move || {
|
||||
let feature_name = feature_name.clone();
|
||||
let transitions = transitions.clone();
|
||||
let empty = empty.clone().unwrap_or_else(|| "Nothing here yet.".to_string());
|
||||
let empty = empty.clone().unwrap_or_else(|| t(&lang().get(), "nothing_here_yet").to_string());
|
||||
data.get()
|
||||
.map(|res| match res {
|
||||
Ok(value) => {
|
||||
@@ -1881,8 +1932,8 @@ fn format_ms(ms: i64) -> String {
|
||||
fn NotFound() -> impl IntoView {
|
||||
view! {
|
||||
<main class="not-found">
|
||||
<h1>"Nothing here"</h1>
|
||||
<a href="/">"back to the start"</a>
|
||||
<h1>{move || t(&lang().get(), "nothing_here")}</h1>
|
||||
<a href="/">{move || t(&lang().get(), "back_to_start")}</a>
|
||||
</main>
|
||||
}
|
||||
}
|
||||
|
||||
+165
-3
@@ -183,6 +183,7 @@ pub fn render_inline_markdown(text: &str) -> String {
|
||||
use pulldown_cmark::{html, Event, Options, Parser, Tag, TagEnd};
|
||||
let parser = Parser::new_ext(text, Options::empty());
|
||||
let mut in_link = 0usize;
|
||||
let mut in_dropped_image = 0usize;
|
||||
let filtered = parser.filter_map(|event| match event {
|
||||
Event::Html(_) | Event::InlineHtml(_) => None,
|
||||
Event::Start(Tag::Paragraph) | Event::End(TagEnd::Paragraph) => None,
|
||||
@@ -190,6 +191,7 @@ pub fn render_inline_markdown(text: &str) -> String {
|
||||
Event::Start(Tag::Link { dest_url, .. })
|
||||
if !(dest_url.starts_with("https://")
|
||||
|| dest_url.starts_with("mailto:")
|
||||
|| dest_url.starts_with("tel:")
|
||||
|| dest_url.starts_with('/')) =>
|
||||
{
|
||||
in_link += 1;
|
||||
@@ -199,11 +201,92 @@ pub fn render_inline_markdown(text: &str) -> String {
|
||||
in_link -= 1;
|
||||
None
|
||||
}
|
||||
// Images take the same gate as links: https or same-origin
|
||||
// only - no data:, no plain http. Unlike a dropped link (whose
|
||||
// label is real text worth keeping), a dropped image's alt
|
||||
// text is a caption for something that isn't there - swallow it.
|
||||
Event::Start(Tag::Image { dest_url, .. })
|
||||
if !(dest_url.starts_with("https://") || dest_url.starts_with('/')) =>
|
||||
{
|
||||
in_dropped_image += 1;
|
||||
None
|
||||
}
|
||||
Event::End(TagEnd::Image) if in_dropped_image > 0 => {
|
||||
in_dropped_image -= 1;
|
||||
None
|
||||
}
|
||||
Event::Text(_) if in_dropped_image > 0 => None,
|
||||
other => Some(other),
|
||||
});
|
||||
let mut out = String::new();
|
||||
html::push_html(&mut out, filtered);
|
||||
out.trim().to_string()
|
||||
apply_image_hints(out.trim())
|
||||
}
|
||||
|
||||
/// Translate a markdown image's title (``)
|
||||
/// into layout: `left`/`right` float via a class, a bare number
|
||||
/// (optionally with `rem`) into a validated `max-width`. Unknown
|
||||
/// tokens are ignored; the title attribute is dropped either way.
|
||||
/// Only touches `<img>` tags in our own render output, and only ever
|
||||
/// emits a numeric max-width - no arbitrary CSS reaches the page.
|
||||
fn apply_image_hints(html: &str) -> String {
|
||||
let mut out = String::new();
|
||||
let mut rest = html;
|
||||
while let Some(pos) = rest.find("<img ") {
|
||||
out.push_str(&rest[..pos]);
|
||||
let after = &rest[pos..];
|
||||
let end = after.find('>').map(|e| e + 1).unwrap_or(after.len());
|
||||
out.push_str(&rewrite_img_tag(&after[..end]));
|
||||
rest = &after[end..];
|
||||
}
|
||||
out.push_str(rest);
|
||||
out
|
||||
}
|
||||
|
||||
fn rewrite_img_tag(tag: &str) -> String {
|
||||
// Pull the title value, if any.
|
||||
let title = tag
|
||||
.find("title=\"")
|
||||
.map(|i| &tag[i + 7..])
|
||||
.and_then(|r| r.find('"').map(|e| &r[..e]))
|
||||
.unwrap_or("");
|
||||
|
||||
let mut class = String::new();
|
||||
let mut max_rem: Option<f32> = None;
|
||||
for tok in title.split_whitespace() {
|
||||
match tok {
|
||||
"left" => class = "md-float-left".into(),
|
||||
"right" => class = "md-float-right".into(),
|
||||
other => {
|
||||
if let Ok(n) = other.trim_end_matches("rem").parse::<f32>() {
|
||||
if n > 0.0 && n <= 60.0 {
|
||||
max_rem = Some(n);
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Strip the title attribute from the tag.
|
||||
let mut cleaned = tag.to_string();
|
||||
if let Some(i) = cleaned.find(" title=\"") {
|
||||
if let Some(e) = cleaned[i + 8..].find('"') {
|
||||
cleaned.replace_range(i..i + 8 + e + 1, "");
|
||||
}
|
||||
}
|
||||
|
||||
// Inject class/style right after `<img`.
|
||||
let mut attrs = String::new();
|
||||
if !class.is_empty() {
|
||||
attrs.push_str(&format!(" class=\"{class}\""));
|
||||
}
|
||||
if let Some(n) = max_rem {
|
||||
attrs.push_str(&format!(" style=\"max-width:{n}rem\""));
|
||||
}
|
||||
if attrs.is_empty() {
|
||||
return cleaned;
|
||||
}
|
||||
cleaned.replacen("<img", &format!("<img{attrs}"), 1)
|
||||
}
|
||||
|
||||
/// Directory-scoped defaults: a `_section.yaml` file applies to every
|
||||
@@ -430,6 +513,12 @@ pub struct Requirement {
|
||||
/// `ResourceSpec` mechanism a `Feature.resource` uses.
|
||||
#[serde(default)]
|
||||
pub resource: Option<ResourceSpec>,
|
||||
/// `type: select` only - a static list of options, as an
|
||||
/// alternative to a `resource`. Each string is both the option's
|
||||
/// stored value and its label. Faithful to the ancestor format's
|
||||
/// inline enums.
|
||||
#[serde(default)]
|
||||
pub options: Vec<String>,
|
||||
/// `type: select` only - which field in each item is the option's
|
||||
/// stable id. Defaults to trying `_id` then `id`.
|
||||
#[serde(default)]
|
||||
@@ -501,6 +590,31 @@ pub struct SiteConfig {
|
||||
/// `None` falls back to `/wordmark.svg`.
|
||||
#[serde(default)]
|
||||
pub wordmark: Option<String>,
|
||||
/// Whether to invert the wordmark in light theme. `None` inverts
|
||||
/// only the built-in house wordmark (a white-stroke SVG); a
|
||||
/// content-shipped logo keeps its own colours unless it sets this
|
||||
/// true (e.g. a sibling site's white-stroke mark).
|
||||
#[serde(default)]
|
||||
pub wordmark_invert: Option<bool>,
|
||||
/// Wordmark display height in rem (0.5–6.0). `None` keeps the
|
||||
/// stylesheet's default. Raster logos look best at or below their
|
||||
/// intrinsic pixel height.
|
||||
#[serde(default)]
|
||||
pub wordmark_height: Option<f32>,
|
||||
/// BCP 47-ish language code for the portal's own chrome strings
|
||||
/// ("Asked by", the nav lead...) and the html lang attribute.
|
||||
/// `None` means "en"; unknown codes fall back to English per key.
|
||||
#[serde(default)]
|
||||
pub lang: Option<String>,
|
||||
/// A content-repo-relative CSS file (e.g. "custom.css") layered
|
||||
/// *after* the default stylesheet, so it overrides. Served
|
||||
/// same-origin at `/site/<path>`; plain path only.
|
||||
#[serde(default)]
|
||||
pub stylesheet: Option<String>,
|
||||
/// A content-repo-relative favicon (svg/png/ico), served at
|
||||
/// `/site/<path>` and used in place of the built-in one.
|
||||
#[serde(default)]
|
||||
pub favicon: Option<String>,
|
||||
#[serde(default)]
|
||||
pub hero: HeroConfig,
|
||||
}
|
||||
@@ -556,6 +670,21 @@ impl SiteConfig {
|
||||
}
|
||||
other => anyhow::bail!("site.yaml: hero.kind {other:?} is not one of plain | module"),
|
||||
}
|
||||
if let Some(sheet) = &self.stylesheet {
|
||||
if !is_safe_site_path(sheet) || !sheet.ends_with(".css") {
|
||||
anyhow::bail!(
|
||||
"site.yaml: stylesheet {sheet:?} must be a plain repo-relative .css path"
|
||||
);
|
||||
}
|
||||
}
|
||||
if let Some(icon) = &self.favicon {
|
||||
let ok = [".svg", ".png", ".ico"].iter().any(|e| icon.ends_with(e));
|
||||
if !is_safe_site_path(icon) || !ok {
|
||||
anyhow::bail!(
|
||||
"site.yaml: favicon {icon:?} must be a plain repo-relative .svg/.png/.ico path"
|
||||
);
|
||||
}
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
}
|
||||
@@ -1166,9 +1295,12 @@ pub fn validate_questions(
|
||||
.collect();
|
||||
for feature in &alternative.features {
|
||||
for requirement in &feature.requirements {
|
||||
if requirement.kind == "select" && requirement.resource.is_none() {
|
||||
if requirement.kind == "select"
|
||||
&& requirement.resource.is_none()
|
||||
&& requirement.options.is_empty()
|
||||
{
|
||||
anyhow::bail!(
|
||||
"question {:?} alternative {:?} feature {:?}: requirement {:?} is type: select but declares no resource to select from",
|
||||
"question {:?} alternative {:?} feature {:?}: requirement {:?} is type: select but declares neither a resource nor inline options",
|
||||
question.id, alternative.name, feature.name, requirement.name
|
||||
);
|
||||
}
|
||||
@@ -1416,6 +1548,8 @@ pub async fn site_asset_handler(
|
||||
Some("json") => "application/json",
|
||||
Some("png") => "image/png",
|
||||
Some("webp") => "image/webp",
|
||||
Some("avif") => "image/avif",
|
||||
Some("ico") => "image/x-icon",
|
||||
Some("woff2") => "font/woff2",
|
||||
_ => "application/octet-stream",
|
||||
};
|
||||
@@ -2026,6 +2160,34 @@ alternatives:
|
||||
fn markdown_drops_html_and_unsafe_links() {
|
||||
assert_eq!(render_inline_markdown("x <script>y</script> z"), "x y z");
|
||||
assert_eq!(render_inline_markdown("[bad](javascript:alert(1))"), "bad");
|
||||
assert_eq!(
|
||||
render_inline_markdown("[ring](tel:+4791180485)"),
|
||||
"<a href=\"tel:+4791180485\">ring</a>"
|
||||
);
|
||||
assert_eq!(
|
||||
render_inline_markdown(""),
|
||||
"<img src=\"https://x.no/a.jpg\" alt=\"site\" />"
|
||||
);
|
||||
assert_eq!(render_inline_markdown(""), "");
|
||||
assert_eq!(
|
||||
render_inline_markdown(""),
|
||||
"<img src=\"/images/a.jpg\" alt=\"local\" />"
|
||||
);
|
||||
// Image title hints: float + max-width, title dropped.
|
||||
assert_eq!(
|
||||
render_inline_markdown(""),
|
||||
"<img class=\"md-float-right\" style=\"max-width:9rem\" src=\"https://x.no/j.jpg\" alt=\"J\" />"
|
||||
);
|
||||
assert_eq!(
|
||||
render_inline_markdown(""),
|
||||
"<img style=\"max-width:12rem\" src=\"https://x.no/j.jpg\" alt=\"J\" />"
|
||||
);
|
||||
// Unknown hint tokens are ignored; a safe image with no title
|
||||
// is untouched.
|
||||
assert_eq!(
|
||||
render_inline_markdown(""),
|
||||
"<img src=\"https://x.no/j.jpg\" alt=\"J\" />"
|
||||
);
|
||||
assert_eq!(render_inline_markdown("[ok](/shape)"), "<a href=\"/shape\">ok</a>");
|
||||
assert_eq!(render_inline_markdown("[mail](mailto:bl@uhhm.no)"), "<a href=\"mailto:bl@uhhm.no\">mail</a>");
|
||||
}
|
||||
|
||||
+97
@@ -0,0 +1,97 @@
|
||||
//! Chrome-string translations, selected by `site.yaml`'s `lang`.
|
||||
//!
|
||||
//! Content carries its own language; this covers only the strings the
|
||||
//! portal itself speaks around it ("Asked by", the nav lead, the
|
||||
//! not-found page...). Unknown languages and unknown keys fall back
|
||||
//! to English, so a typo degrades to the default instead of a blank.
|
||||
|
||||
/// Translate `key` for `lang`. `en` is the reference table; every
|
||||
/// other language falls through to it for keys it doesn't carry.
|
||||
pub fn t(lang: &str, key: &str) -> &'static str {
|
||||
if let Some(s) = lookup(lang, key) {
|
||||
return s;
|
||||
}
|
||||
lookup("en", key).unwrap_or(key_missing(key))
|
||||
}
|
||||
|
||||
fn lookup(lang: &str, key: &str) -> Option<&'static str> {
|
||||
Some(match (lang, key) {
|
||||
("en", "also_worth_asking") => "Also worth asking",
|
||||
("en", "asked_by") => "Asked by ",
|
||||
("en", "contact_them") => "contact them",
|
||||
("en", "if_stuck") => " if you get stuck.",
|
||||
("en", "send") => "Send",
|
||||
("en", "sign_in") => "Sign in",
|
||||
("en", "nothing_here_yet") => "Nothing here yet.",
|
||||
("en", "nothing_here") => "Nothing here",
|
||||
("en", "back_to_start") => "back to the start",
|
||||
("en", "done") => "Done.",
|
||||
("en", "follows_answer") => {
|
||||
"This page follows from an answer you don't seem to carry yet."
|
||||
}
|
||||
("en", "owners_only") => {
|
||||
"This part of the site is for organizational owners — sign in with that account to take a look."
|
||||
}
|
||||
("en", "announcements") => "Announcements",
|
||||
|
||||
("no", "also_worth_asking") => "Også verdt å spørre",
|
||||
("no", "asked_by") => "Stilt av ",
|
||||
("no", "contact_them") => "ta kontakt",
|
||||
("no", "if_stuck") => " om du står fast.",
|
||||
("no", "send") => "Send",
|
||||
("no", "sign_in") => "Logg inn",
|
||||
("no", "nothing_here_yet") => "Ingenting her ennå.",
|
||||
("no", "nothing_here") => "Ingenting her",
|
||||
("no", "back_to_start") => "tilbake til start",
|
||||
("no", "done") => "Ferdig.",
|
||||
("no", "follows_answer") => {
|
||||
"Denne siden følger av et svar du ikke ser ut til å bære ennå."
|
||||
}
|
||||
("no", "owners_only") => {
|
||||
"Denne delen av siden er for organisasjonens eiere — logg inn med den kontoen for å ta en titt."
|
||||
}
|
||||
("no", "announcements") => "Kunngjøringer",
|
||||
|
||||
_ => return None,
|
||||
})
|
||||
}
|
||||
|
||||
/// A missing key is a programmer error; render the key itself so it
|
||||
/// is findable, never a panic in a view.
|
||||
fn key_missing(key: &str) -> &'static str {
|
||||
// Leak is bounded: keys are a small fixed set of literals.
|
||||
Box::leak(key.to_string().into_boxed_str())
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn norwegian_covers_the_english_table() {
|
||||
for key in [
|
||||
"also_worth_asking",
|
||||
"asked_by",
|
||||
"contact_them",
|
||||
"if_stuck",
|
||||
"send",
|
||||
"sign_in",
|
||||
"nothing_here_yet",
|
||||
"nothing_here",
|
||||
"back_to_start",
|
||||
"done",
|
||||
"follows_answer",
|
||||
"owners_only",
|
||||
"announcements",
|
||||
] {
|
||||
assert!(lookup("en", key).is_some(), "en missing {key}");
|
||||
assert!(lookup("no", key).is_some(), "no missing {key}");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unknown_language_falls_back_to_english() {
|
||||
assert_eq!(t("de", "sign_in"), "Sign in");
|
||||
assert_eq!(t("en", "sign_in"), "Sign in");
|
||||
}
|
||||
}
|
||||
@@ -4,6 +4,7 @@ pub mod auth;
|
||||
pub mod chain;
|
||||
pub mod content;
|
||||
pub mod events;
|
||||
pub mod i18n;
|
||||
pub mod resource;
|
||||
|
||||
#[cfg(feature = "ssr")]
|
||||
|
||||
@@ -68,6 +68,16 @@ pub async fn get_requirement_options(
|
||||
.iter()
|
||||
.find(|r| r.name == requirement_name)
|
||||
.ok_or_else(|| ServerFnError::new("unknown requirement"))?;
|
||||
// Inline options: return them as {id,label} objects, the shape the
|
||||
// SelectField renders, without touching a resource.
|
||||
if !requirement.options.is_empty() {
|
||||
let items: Vec<serde_json::Value> = requirement
|
||||
.options
|
||||
.iter()
|
||||
.map(|o| serde_json::json!({ "id": o, "label": o }))
|
||||
.collect();
|
||||
return Ok(serde_json::Value::Array(items));
|
||||
}
|
||||
let resource = requirement
|
||||
.resource
|
||||
.as_ref()
|
||||
|
||||
+26
-4
@@ -33,6 +33,13 @@ type OidcClient = CoreClient<
|
||||
>;
|
||||
|
||||
pub struct Oidc {
|
||||
/// `None` when `KANIDM_URL` is unset: a content-only instance with
|
||||
/// sign-in disabled - auth routes answer 503, everything public
|
||||
/// renders as usual.
|
||||
inner: Option<OidcInner>,
|
||||
}
|
||||
|
||||
struct OidcInner {
|
||||
client: OidcClient,
|
||||
http: openidconnect::reqwest::Client,
|
||||
}
|
||||
@@ -45,7 +52,13 @@ const REDIRECT_KEY: &str = "oidc_post_login_redirect";
|
||||
impl Oidc {
|
||||
/// Discovers the provider and builds the client from environment:
|
||||
/// `KANIDM_URL`, `OAUTH2_CLIENT_ID`, `OAUTH2_CLIENT_SECRET`, `PUBLIC_URL`.
|
||||
/// With `KANIDM_URL` unset, sign-in is disabled instead of fatal -
|
||||
/// the shape of a public content instance without a review desk.
|
||||
pub async fn from_env() -> anyhow::Result<Self> {
|
||||
if std::env::var("KANIDM_URL").is_err() {
|
||||
tracing::warn!("KANIDM_URL not set - sign-in disabled on this instance");
|
||||
return Ok(Self { inner: None });
|
||||
}
|
||||
let kanidm_url = require_env("KANIDM_URL")?;
|
||||
let client_id = require_env("OAUTH2_CLIENT_ID")?;
|
||||
let client_secret = require_env("OAUTH2_CLIENT_SECRET")?;
|
||||
@@ -75,7 +88,16 @@ impl Oidc {
|
||||
)
|
||||
.set_redirect_uri(redirect);
|
||||
|
||||
Ok(Self { client, http })
|
||||
Ok(Self {
|
||||
inner: Some(OidcInner { client, http }),
|
||||
})
|
||||
}
|
||||
|
||||
fn configured(&self) -> Result<&OidcInner, HandlerError> {
|
||||
self.inner.as_ref().ok_or((
|
||||
StatusCode::SERVICE_UNAVAILABLE,
|
||||
"sign-in is not configured on this instance".to_string(),
|
||||
))
|
||||
}
|
||||
}
|
||||
|
||||
@@ -118,10 +140,10 @@ pub async fn login(
|
||||
session.insert(REDIRECT_KEY, redirect).await.map_err(internal)?;
|
||||
}
|
||||
|
||||
let oidc = state.oidc.configured()?;
|
||||
let (pkce_challenge, pkce_verifier) = PkceCodeChallenge::new_random_sha256();
|
||||
|
||||
let (auth_url, csrf_state, nonce) = state
|
||||
.oidc
|
||||
let (auth_url, csrf_state, nonce) = oidc
|
||||
.client
|
||||
.authorize_url(
|
||||
CoreAuthenticationFlow::AuthorizationCode,
|
||||
@@ -182,7 +204,7 @@ pub async fn callback(
|
||||
));
|
||||
}
|
||||
|
||||
let oidc = &state.oidc;
|
||||
let oidc = state.oidc.configured()?;
|
||||
let token_response = oidc
|
||||
.client
|
||||
.exchange_code(AuthorizationCode::new(params.code))
|
||||
|
||||
+54
-6
@@ -99,10 +99,10 @@
|
||||
--hero-glow: rgba(246, 245, 241, 0.85);
|
||||
}
|
||||
|
||||
/* The wordmark SVG is a hardcoded white stroke (also used raw in
|
||||
dark contexts elsewhere) - flip it to ink here rather than fork
|
||||
the asset. */
|
||||
.wordmark img {
|
||||
/* The house wordmark SVG is a hardcoded white stroke (also used
|
||||
raw in dark contexts elsewhere) - flip it to ink here rather
|
||||
than fork the asset. A content-provided logo keeps its colors. */
|
||||
.wordmark-house img {
|
||||
filter: invert(0.92);
|
||||
}
|
||||
|
||||
@@ -193,6 +193,10 @@ main.not-found {
|
||||
color: var(--ink-dim);
|
||||
font-size: 1.05rem;
|
||||
max-width: 46ch;
|
||||
/* The measure cap shrinks the box below the copy column; without
|
||||
auto margins the box left-anchors and its centered text centers
|
||||
in the wrong frame. */
|
||||
margin-inline: auto;
|
||||
}
|
||||
|
||||
/* A content-shipped hero module (site.yaml hero.kind: module) draws
|
||||
@@ -364,8 +368,12 @@ main.not-found {
|
||||
.alt-image {
|
||||
display: block;
|
||||
width: 100%;
|
||||
max-height: 14rem;
|
||||
object-fit: cover;
|
||||
height: auto;
|
||||
/* Natural aspect, not a cropped band; a very tall image is still
|
||||
bounded so it can't tower. The deck below overrides for its
|
||||
fixed-height cards. */
|
||||
max-height: 32rem;
|
||||
object-fit: contain;
|
||||
border-radius: calc(var(--radius) - 0.3rem);
|
||||
margin-bottom: 1.1rem;
|
||||
}
|
||||
@@ -536,6 +544,42 @@ main.not-found {
|
||||
color: var(--accent);
|
||||
}
|
||||
|
||||
/* images inside markdown descriptions: full-width figures in the
|
||||
card's flow, framed like the rest of the press sheet */
|
||||
.alt-description img,
|
||||
.item-card-description img,
|
||||
.feature p img {
|
||||
display: block;
|
||||
width: 100%;
|
||||
margin: 0.6rem 0 0.2rem;
|
||||
border-radius: 0.5rem;
|
||||
border: 0.06rem solid var(--line);
|
||||
}
|
||||
|
||||
/* Content hint via a markdown image title (``):
|
||||
float and shrink so text wraps around a portrait. */
|
||||
.alt-description img.md-float-left,
|
||||
.item-card-description img.md-float-left,
|
||||
.feature p img.md-float-left,
|
||||
.alt-description img.md-float-right,
|
||||
.item-card-description img.md-float-right,
|
||||
.feature p img.md-float-right {
|
||||
width: auto;
|
||||
max-width: 45%;
|
||||
}
|
||||
.alt-description img.md-float-left,
|
||||
.item-card-description img.md-float-left,
|
||||
.feature p img.md-float-left {
|
||||
float: left;
|
||||
margin: 0.2rem 1.1rem 0.5rem 0;
|
||||
}
|
||||
.alt-description img.md-float-right,
|
||||
.item-card-description img.md-float-right,
|
||||
.feature p img.md-float-right {
|
||||
float: right;
|
||||
margin: 0.2rem 0 0.5rem 1.1rem;
|
||||
}
|
||||
|
||||
.alt-description code,
|
||||
.feature p code {
|
||||
font-size: 0.9em;
|
||||
@@ -845,6 +889,10 @@ textarea:focus {
|
||||
padding: 0.75rem 1.4rem;
|
||||
cursor: pointer;
|
||||
transition: filter 120ms, transform 120ms;
|
||||
/* A gateway alternative renders this as an <a> (navigation, no POST);
|
||||
kill the link chrome so it reads as the button it looks like. */
|
||||
text-decoration: none;
|
||||
display: inline-block;
|
||||
}
|
||||
|
||||
.alt-submit:hover {
|
||||
|
||||
Reference in New Issue
Block a user