fix(as-S5a): fixup from booth-dev's gate — release asks, fail-closed words, ids that cannot collide
From booth-dev's hulda bug-hunt with heid's second voice (BRINGA, thread 01M3MVGQ7QSCCK8WT59TQ4J469): - The booth page's "kept — release" asks by name, as the Desk's does. - WORDS has no prototype: data-confirm="__proto__" or "constructor" is an unknown word, and asks, instead of throwing before preventDefault. - The confirm helper moved into <head>: its capture listener exists before any form, so a click during load is asked too (the inline confirm() it replaced had that property). - shown() also marks U+2028/U+2029 and the zero-width characters. - Derived ids take ':' (bk-ask-<id>-<key>:prompt, bk-ask-<id>:title), which no id or key can contain; '-prompt' and '-title' collided with valid keys. booth-dev's chip test now looks its fragment up by [id=...]. - human_dur says "—" for a value that is not finite, instead of raising. - The tile's copy of a note drops its id (booth-dev: mark-<id> is the panel's article). - Four guards that asserted source patterns now also hold on computed effects: embed rings, rings inside clipping containers, the withdraw × on both axes, and question-level notes fields. Contract: as_antislop S5a (fixup). Falsifiers: antislop.toml 102/102 with r2_flow.toml 24/24 proved; the full gate follows.
This commit is contained in:
@@ -473,15 +473,15 @@ new = """<div class="bk-ask-opts" aria-labelledby="""
|
||||
label = "S5a the group names a prompt id that is not there"
|
||||
file = "booth/templates/_ask_inline.html"
|
||||
test = "tests/test_antislop.py::test_radio_groups_are_named_and_ids_are_unique"
|
||||
old = """<p class="bk-ask-prompt" id="bk-ask-{{ a.id }}{% if q.key %}-{{ q.key }}{% endif %}-prompt">"""
|
||||
new = """<p class="bk-ask-prompt">"""
|
||||
old = '''<p class="bk-ask-prompt" id="bk-ask-{{ a.id }}{% if q.key %}-{{ q.key }}{% endif %}:prompt">'''
|
||||
new = '''<p class="bk-ask-prompt">'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a a titled ask's title reuses the question's id"
|
||||
file = "booth/templates/_ask_inline.html"
|
||||
test = "tests/test_antislop.py::test_radio_groups_are_named_and_ids_are_unique"
|
||||
old = """<p class="bk-ask-title" id="bk-ask-{{ a.id }}-title">"""
|
||||
new = """<p class="bk-ask-title" id="bk-ask-{{ a.id }}">"""
|
||||
old = '''<p class="bk-ask-title" id="bk-ask-{{ a.id }}:title">'''
|
||||
new = '''<p class="bk-ask-title" id="bk-ask-{{ a.id }}">'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a a single-question fieldset without a legend"
|
||||
@@ -643,3 +643,126 @@ file = "booth/templates/base.html"
|
||||
test = "tests/test_antislop_browser.py::test_touch_and_scroll_behaviour"
|
||||
old = """ @media (max-width:600px){.h1-slug{white-space:normal;overflow-wrap:anywhere}}"""
|
||||
new = """ @media (max-width:600px){.h1-slug{}}"""
|
||||
|
||||
# ---- S5a fixup: booth-dev's gate (hulda + heid BRINGA, thread 01M3MVGQ7QSCCK8WT59TQ4J469)
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup the booth page's release does not ask"
|
||||
file = "booth/templates/booth.html"
|
||||
test = "tests/test_antislop.py::test_release_on_the_booth_page_asks_by_name"
|
||||
old = '''
|
||||
|
||||
data-booth="{{ name }}" data-confirm="release">'''
|
||||
new = '''>'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup the booth page's release does not ask (browser)"
|
||||
file = "booth/templates/booth.html"
|
||||
test = "tests/test_antislop_browser.py::test_release_on_the_booth_page_asks_in_the_browser"
|
||||
old = '''
|
||||
|
||||
data-booth="{{ name }}" data-confirm="release">'''
|
||||
new = '''>'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup WORDS inherits from Object.prototype"
|
||||
file = "booth/templates/base.html"
|
||||
test = "tests/test_antislop_browser.py::test_a_prototype_word_still_asks"
|
||||
old = ''' var WORDS = Object.create(null);'''
|
||||
new = ''' var WORDS = {};'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup the confirm helper leaves <head>"
|
||||
file = "booth/templates/base.html"
|
||||
test = "tests/test_antislop.py::test_the_confirm_helper_is_listening_before_the_body_exists"
|
||||
old = '''<script>
|
||||
/* as S5a: moved here from index.html'''
|
||||
new = '''</head>
|
||||
<script>
|
||||
/* as S5a: moved here from index.html'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup shown() lets line separators and zero-widths through"
|
||||
file = "booth/templates/base.html"
|
||||
test = "tests/test_antislop_browser.py::test_the_dialog_shows_hidden_breaks_and_zero_widths_visibly"
|
||||
old = ''' return n.replace(/[\u0000-\u001f\u007f-\u009f\u061c\u200b-\u200f\u2028\u2029\u202a-\u202e\u2060\u2066-\u2069\ufeff]/g, '\ufffd');'''
|
||||
new = ''' return n.replace(/[\u0000-\u001f\u007f-\u009f\u061c\u200e\u200f\u202a-\u202e\u2066-\u2069]/g, '\ufffd');'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup a question's prompt id collides with a key ending -prompt"
|
||||
file = "booth/templates/_ask_inline.html"
|
||||
test = "tests/test_antislop.py::test_no_id_repeats_on_any_page"
|
||||
old = '''id="bk-ask-{{ a.id }}{% if q.key %}-{{ q.key }}{% endif %}:prompt"'''
|
||||
new = '''id="bk-ask-{{ a.id }}{% if q.key %}-{{ q.key }}{% endif %}-prompt"'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup the title's id collides with a key named title"
|
||||
file = "booth/templates/_ask_inline.html"
|
||||
test = "tests/test_antislop.py::test_no_id_repeats_on_any_page"
|
||||
old = '''id="bk-ask-{{ a.id }}:title"'''
|
||||
new = '''id="bk-ask-{{ a.id }}-title"'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup the tile's note repeats the article's id"
|
||||
file = "booth/templates/booth.html"
|
||||
test = "tests/test_antislop.py::test_no_id_repeats_on_any_page"
|
||||
old = ''' <div class="item-note">'''
|
||||
new = ''' <div class="item-note" id="mark-{{ m.id }}">'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup human_dur raises on nan"
|
||||
file = "booth/app.py"
|
||||
test = "tests/test_antislop.py::test_human_dur_never_raises"
|
||||
old = ''' if not math.isfinite(seconds): # as S5a fixup: int(nan) raises; say nothing we cannot know
|
||||
return "—"
|
||||
'''
|
||||
new = ''''''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup a question's notes field named only by its placeholder"
|
||||
file = "booth/templates/_ask_inline.html"
|
||||
test = "tests/test_antislop.py::test_fields_are_named"
|
||||
old = '''aria-label="notes on this one" placeholder="notes on this one (optional)">'''
|
||||
new = '''placeholder="notes on this one (optional)">'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup the marks page's question notes named only by their placeholder"
|
||||
file = "booth/templates/_marks.html"
|
||||
test = "tests/test_antislop.py::test_fields_are_named"
|
||||
old = '''aria-label="notes on this one" placeholder="notes on this one (optional)">'''
|
||||
new = '''placeholder="notes on this one (optional)">'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup the embed chip's ring is transparent"
|
||||
file = "booth/static/embed.js"
|
||||
test = "tests/test_antislop_browser.py::test_the_embed_draws_visible_rings"
|
||||
old = '''outline:2px solid #fff;outline-offset:1px;box-shadow:0 0 0 4px #15191d}'''
|
||||
new = '''outline:2px solid transparent;outline-offset:1px;box-shadow:0 0 0 4px #15191d}'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup the embed submit's ring is transparent"
|
||||
file = "booth/static/embed.js"
|
||||
test = "tests/test_antislop_browser.py::test_the_embed_draws_visible_rings"
|
||||
old = '''".bk-ask-go:focus-visible{outline:2px solid var(--bk-accent);outline-offset:2px}"'''
|
||||
new = '''".bk-ask-go:focus-visible{outline:2px solid transparent;outline-offset:2px}"'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup an image tile's ring is drawn outside its clip"
|
||||
file = "booth/templates/base.html"
|
||||
test = "tests/test_antislop_browser.py::test_rings_inside_clipping_containers_are_drawn_inside"
|
||||
old = '''.theme button:focus-visible,.vtoggle button:focus-visible,.item a:focus-visible,'''
|
||||
new = '''.theme button:focus-visible,.vtoggle button:focus-visible,'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup a Desk panel's ring is drawn outside its clip (computed)"
|
||||
file = "booth/templates/base.html"
|
||||
test = "tests/test_antislop_browser.py::test_rings_inside_clipping_containers_are_drawn_inside"
|
||||
old = ''' .desk-panel a:focus-visible{outline-offset:-2px}'''
|
||||
new = ''' .desk-panel a:focus-visible{outline-offset:2px}'''
|
||||
|
||||
[[mutation]]
|
||||
label = "S5a fixup the withdraw × narrower than 24px"
|
||||
file = "booth/templates/base.html"
|
||||
test = "tests/test_antislop_browser.py::test_withdraw_buttons_are_big_enough_to_hit"
|
||||
old = ''' .mark-x{min-width:24px;min-height:24px}'''
|
||||
new = ''' .mark-x{min-height:24px}'''
|
||||
|
||||
+56
-2
@@ -329,6 +329,12 @@ def _s5_booth(data):
|
||||
write_note(b, "a.png", "soft edges")
|
||||
write_note(b, None, "about the booth")
|
||||
declare_pick(b, "p1", {"title": "Round one", "prompt": "Which?", "options": ["North", "South"]})
|
||||
# S5a fixup: a multi-question ask with per-question notes, and keys that end
|
||||
# like the ids S5a derives from them (`-prompt`, `title`)
|
||||
declare_pick(b, "p2", {"title": "Round two", "questions": [
|
||||
{"key": "x-prompt", "prompt": "First?", "options": ["keep", "cut"], "notes": True},
|
||||
{"key": "x", "prompt": "Second?", "options": ["keep", "cut"], "notes": True},
|
||||
{"key": "title", "prompt": "Third?", "options": ["keep", "cut"]}]})
|
||||
_s5_board(data)
|
||||
return b
|
||||
|
||||
@@ -415,7 +421,7 @@ def test_fields_are_named(client):
|
||||
def test_radio_groups_are_named_and_ids_are_unique(client):
|
||||
c, data = client
|
||||
_s5_booth(data)
|
||||
(m,) = c.get("/b/b/embed.json").json()["marks"]
|
||||
(m,) = [m for m in c.get("/b/b/embed.json").json()["marks"] if m["id"] == "p1"]
|
||||
# The embed places an ask one of two ways: `whole` (title, questions and
|
||||
# submit in one piece), or its questions one by one plus `submit`. Never both.
|
||||
placements = {"whole": m["whole"], "parts": "".join(q["html"] for q in m["questions"]) + m["submit"]}
|
||||
@@ -466,7 +472,7 @@ def test_wipe_now_asks_by_name(client):
|
||||
page = c.get("/b/b/").text
|
||||
form = re.search(r'<form class="wipe wipe-lg"[^>]*>', page, flags=re.S).group(0)
|
||||
assert 'data-booth="b"' in form and 'data-confirm="wipe"' in form and "onsubmit" not in form, form
|
||||
assert "var WORDS = {" in page, "the shared confirm helper is on the booth page"
|
||||
assert "var WORDS = Object.create(null);" in page, "the shared confirm helper is on the booth page"
|
||||
|
||||
|
||||
def test_human_dur_rolls_up_to_days():
|
||||
@@ -497,3 +503,51 @@ def test_a_truncated_why_carries_its_full_text(client):
|
||||
(b / ".booth.json").write_text('{"handle": "design-dev", "why": "a long reason that the Desk truncates with an ellipsis"}')
|
||||
page = c.get("/").text
|
||||
assert re.search(r'<span class="prov-why" title="a long reason that the Desk truncates with an ellipsis">', page)
|
||||
|
||||
|
||||
|
||||
# ---- S5a fixup: booth-dev's gate (hulda bug-hunt + heid BRINGA, thread 01M3MVGQ7QSCCK8WT59TQ4J469) ----
|
||||
|
||||
def test_no_id_repeats_on_any_page(client):
|
||||
"""An id names one element. The tile's copy of a note used to repeat the
|
||||
panel article's `mark-<id>` (booth-dev: the id is the article's); a question
|
||||
key ending in `-prompt`, or named `title`, repeated the ids S5a derived."""
|
||||
c, data = client
|
||||
_s5_booth(data)
|
||||
pages = _pages(c)
|
||||
for m in c.get("/b/b/embed.json").json()["marks"]:
|
||||
pages[f"embed {m['id']} whole"] = m["whole"]
|
||||
pages[f"embed {m['id']} parts"] = "".join(q["html"] for q in m["questions"]) + m["submit"]
|
||||
for url, page in pages.items():
|
||||
ids = re.findall(r'\sid="([^"]+)"', _markup(page))
|
||||
dupes = sorted({i for i in ids if ids.count(i) > 1})
|
||||
assert not dupes, (url, dupes[:5])
|
||||
for ref in re.findall(r'aria-labelledby="([^"]+)"', page):
|
||||
assert f'id="{ref}"' in page, (url, ref)
|
||||
|
||||
|
||||
def test_release_on_the_booth_page_asks_by_name(client):
|
||||
c, data = client
|
||||
b = data / "k"
|
||||
b.mkdir()
|
||||
(b / "x.txt").write_text("x")
|
||||
(b / ".forever").write_text("")
|
||||
page = c.get("/b/k/").text
|
||||
form = re.search(r'<form class="keep-lg"[^>]*>', page).group(0)
|
||||
assert 'data-booth="k"' in form and 'data-confirm="release"' in form, form
|
||||
|
||||
|
||||
def test_the_confirm_helper_is_listening_before_the_body_exists(client):
|
||||
"""A click while the page is still loading must be asked too: the capture
|
||||
listener is registered in <head>, not after the footer."""
|
||||
c, data = client
|
||||
_s5_booth(data)
|
||||
for url in ("/", "/b/b/"):
|
||||
page = c.get(url).text
|
||||
assert page.index("function shown(n)") < page.index("</head>"), url
|
||||
|
||||
|
||||
def test_human_dur_never_raises():
|
||||
from booth.app import human_dur
|
||||
for bad in (float("nan"), float("inf"), float("-inf")):
|
||||
assert isinstance(human_dur(bad), str), bad
|
||||
|
||||
@@ -188,7 +188,8 @@ def test_withdraw_buttons_are_big_enough_to_hit(browser, live):
|
||||
ctx = browser.new_context(**ctx_args)
|
||||
page = ctx.new_page()
|
||||
page.goto(f"{base}/b/g/marks", wait_until="load") # visible at both widths
|
||||
box = page.locator(".mark-x").first.evaluate("e => e.getBoundingClientRect().height")
|
||||
box = page.locator(".mark-x").first.evaluate(
|
||||
"e => { const r = e.getBoundingClientRect(); return Math.min(r.width, r.height); }")
|
||||
assert box >= floor, (ctx_args, box)
|
||||
ctx.close()
|
||||
|
||||
@@ -231,3 +232,119 @@ def test_touch_and_scroll_behaviour(browser, live):
|
||||
"e => ({ws: getComputedStyle(e).whiteSpace, r: e.getBoundingClientRect().right, vw: innerWidth})")
|
||||
assert slug["ws"] == "normal" and slug["r"] <= slug["vw"], slug
|
||||
page.close()
|
||||
|
||||
|
||||
|
||||
# ---- S5a fixup: the confirm helper, and the rings on COMPUTED style ------------------------
|
||||
|
||||
def _dialog_texts(page):
|
||||
said = []
|
||||
page.on("dialog", lambda d: (said.append(d.message), d.dismiss()))
|
||||
return said
|
||||
|
||||
|
||||
def test_release_on_the_booth_page_asks_in_the_browser(browser, live):
|
||||
base, root = live
|
||||
b = root / "kept"
|
||||
b.mkdir()
|
||||
(b / "x.txt").write_text("x")
|
||||
(b / ".forever").write_text("")
|
||||
page = browser.new_page(viewport={"width": 1280, "height": 800})
|
||||
page.goto(f"{base}/b/kept/", wait_until="load")
|
||||
said = _dialog_texts(page)
|
||||
page.locator(".keep-lg button").click()
|
||||
page.wait_for_timeout(300)
|
||||
page.close()
|
||||
assert said and "“kept”" in said[0] and "Release" in said[0], said
|
||||
assert (b / ".forever").exists(), "dismissing must not release"
|
||||
|
||||
|
||||
def test_a_prototype_word_still_asks(browser, live):
|
||||
"""A `data-confirm` naming a property every object inherits is an unknown
|
||||
word, and an unknown word asks (fail closed)."""
|
||||
base, root = live
|
||||
b = root / "g"
|
||||
b.mkdir()
|
||||
(b / "x.txt").write_text("x")
|
||||
page = browser.new_page()
|
||||
page.goto(f"{base}/b/g/", wait_until="load")
|
||||
said = _dialog_texts(page)
|
||||
words = ["__proto__", "constructor", "toString", "hasOwnProperty", "valueOf"]
|
||||
for w in words:
|
||||
page.evaluate("""w => { const f = document.createElement('form');
|
||||
f.method = 'post'; f.action = '/b/g/delete';
|
||||
f.setAttribute('data-confirm', w); f.setAttribute('data-booth', 'g');
|
||||
document.body.appendChild(f); f.requestSubmit(); f.remove(); }""", w)
|
||||
page.wait_for_timeout(100)
|
||||
page.close()
|
||||
assert len(said) == len(words), said
|
||||
assert (b / "x.txt").exists()
|
||||
|
||||
|
||||
def test_the_dialog_shows_hidden_breaks_and_zero_widths_visibly(browser, live):
|
||||
import urllib.parse
|
||||
base, root = live
|
||||
name = "a
b
cde"
|
||||
b = root / name
|
||||
b.mkdir()
|
||||
(b / "x.txt").write_text("x")
|
||||
page = browser.new_page()
|
||||
page.goto(f"{base}/b/{urllib.parse.quote(name)}/", wait_until="load")
|
||||
said = _dialog_texts(page)
|
||||
page.locator(".wipe-lg button").click()
|
||||
page.wait_for_timeout(300)
|
||||
page.close()
|
||||
assert said, "positive control: Wipe now asked"
|
||||
for ch in "
":
|
||||
assert ch not in said[0], (hex(ord(ch)), said[0])
|
||||
assert said[0].count("�") == 5, said[0]
|
||||
|
||||
|
||||
_RING = """e => { const cs = getComputedStyle(e);
|
||||
return {fv: e.matches(':focus-visible'), style: cs.outlineStyle, width: cs.outlineWidth,
|
||||
color: cs.outlineColor, offset: cs.outlineOffset}; }"""
|
||||
|
||||
_ALPHA = """c => { const m = c.match(/rgba?\\(([^)]+)\\)/); const p = m ? m[1].split(',') : [];
|
||||
return p.length > 3 ? parseFloat(p[3]) : 1; }"""
|
||||
|
||||
|
||||
def _keyboard_focus(page, selector):
|
||||
page.keyboard.press("Shift") # keyboard modality: focus() is then :focus-visible
|
||||
loc = page.locator(selector).first
|
||||
loc.focus()
|
||||
return loc.evaluate(_RING)
|
||||
|
||||
|
||||
def test_rings_inside_clipping_containers_are_drawn_inside(browser, live):
|
||||
from booth.benches import upsert_bench
|
||||
base, root = live
|
||||
g = root / "g"
|
||||
g.mkdir()
|
||||
(g / "a.png").write_bytes(_png(64, 48))
|
||||
upsert_bench(root, "http://10.100.10.50:5173/", "peedlar desk", "peedlar-dev") # a Desk panel with a link
|
||||
page = browser.new_page(viewport={"width": 1280, "height": 800})
|
||||
for url, sel in (("/", ".theme button"), ("/", ".desk-panel a"), ("/b/g/", ".item a")):
|
||||
page.goto(base + url, wait_until="load")
|
||||
ring = _keyboard_focus(page, sel)
|
||||
assert ring["fv"] and ring["offset"] == "-2px", (url, sel, ring)
|
||||
page.close()
|
||||
|
||||
|
||||
def test_the_embed_draws_visible_rings(browser, live):
|
||||
from booth.marks import declare_pick
|
||||
base, root = live
|
||||
b = root / "r"
|
||||
b.mkdir()
|
||||
declare_pick(b, "winner", {"prompt": "Which?", "options": ["A", "B"]})
|
||||
(b / "index.html").write_text(
|
||||
'<!doctype html><html><head><script src="/_booth/embed.js" defer></script>'
|
||||
'<style>*:focus{outline:none}</style></head>' # a host that removes rings
|
||||
'<body><h1>Report</h1><div data-booth-ask="winner"></div></body></html>')
|
||||
page = browser.new_page()
|
||||
page.goto(f"{base}/b/r/", wait_until="networkidle")
|
||||
page.wait_for_selector(".bk-ask-go", timeout=10000)
|
||||
for sel in (".booth-nav-home", ".bk-ask-go"):
|
||||
ring = _keyboard_focus(page, sel)
|
||||
alpha = page.evaluate(_ALPHA, ring["color"])
|
||||
assert ring["fv"] and ring["style"] == "solid" and ring["width"] == "2px" and alpha == 1, (sel, ring)
|
||||
page.close()
|
||||
|
||||
@@ -489,7 +489,9 @@ def test_the_chip_does_not_jump_to_a_mark_that_merely_shares_a_prefix(browser, l
|
||||
target = page.locator(".booth-nav-asks").get_attribute("href")
|
||||
assert "batch2" not in target, f"the chip landed on the sibling mark: {target}"
|
||||
assert target.startswith("#bk-ask-batch")
|
||||
assert page.locator(target).count() == 1
|
||||
# as S5a fixup: derived ids take a `:` (`bk-ask-batch:title`) so they cannot
|
||||
# collide with a question key; a fragment may hold one, a #selector cannot
|
||||
assert page.locator(f'[id="{target[1:]}"]').count() == 1
|
||||
page.close()
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user