You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
feat(settings): Discord section in the local settings page (#272) - #318
Adds /settings to the running app with a Discord section:
on/off, timer (time played and left, played, left, none) and album art lookup (MusicBrainz or server art only)
saves to config.json in one step (temp file + rename), checked by the same rules as setup
applies without a restart: the Discord loop stops and starts again with the new settings
plain layout on the status page's styles; state text uses the existing blue/orange classes, no red/green
Security: the app server now has a session secret. Saves (PUT /api/settings) need the SameSite=Strict cookie the app's own pages set, JSON content type, and a same-origin request; /api/settings also refuses cross-site fetches. Only the discord section with enabled, timestamps and artworkLookup is accepted; errors return a short code, never paths or values.
Config: discord.timestamps is new and optional. Left out means "both", so configs written by setup are unchanged. The Discord presence loop now takes the timer setting.
Status and Settings pages link to each other. Not in this PR: the other settings sections.
Tests: store, handler and an end-to-end run against the real app (cookie required, other origins refused, bad values rejected, Discord turned off live).
CodeQL is right about this one: test/settings-page-handler.test.js:18 reintroduces the case-sensitive <script> assertion regex that #311 just fixed in the sibling test files (assert.doesNotMatch(page.body, /<script>|\sstyle=|\son[a-z]+=/)). As written the check would pass even if the page served an uppercase <SCRIPT> tag, which is exactly the alert CodeQL is gating on.
Same fix as #311 - make it case-insensitive and cover attribute-bearing tags:
Fixed in 45cc5af: the check now counts <script occurrences on the lowercased page instead of using a tag regex. CodeQL on the latest head is green. No Mira review here (auto-paused).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #272. Part of #253.
Adds
/settingsto the running app with a Discord section:Security: the app server now has a session secret. Saves (
PUT /api/settings) need the SameSite=Strict cookie the app's own pages set, JSON content type, and a same-origin request;/api/settingsalso refuses cross-site fetches. Only thediscordsection withenabled,timestampsandartworkLookupis accepted; errors return a short code, never paths or values.Config:
discord.timestampsis new and optional. Left out means "both", so configs written by setup are unchanged. The Discord presence loop now takes the timer setting.Status and Settings pages link to each other. Not in this PR: the other settings sections.
Tests: store, handler and an end-to-end run against the real app (cookie required, other origins refused, bad values rejected, Discord turned off live).