Conversation
- tests/api.test.js: CSRF enforcement on all modifying endpoints, the normal create/update/complete/trash flow, second-order SQL injection via recurring-entry reactivation, automatic reactivation, input validation, generic database errors and security headers. - tests/ui.test.js (Playwright): HTML stored in the database is rendered as text in the list, tags, list names and log; the main workflows run without JS errors or Content-Security-Policy violations. - tests/apache-access.sh: .htaccess requires authentication and denies internal files. - tests.yml workflow runs PHP lint, the Node tests against MariaDB and the Apache check. tests/ is also denied in .htaccess and nginx.conf.sample. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XgpcjUfZKQgJmGv5zfyvb1
jQuery 4 only serializes plain objects passed as ajax data; Todo instances
were sent as '[object Object]', so enter.php and update.php received no
fields ('Todo may not be empty!'). Serialize them explicitly with $.param.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XgpcjUfZKQgJmGv5zfyvb1
- API test: lists and todos of another user can neither be read nor changed (enter, update incl. moving into a foreign list, complete, trash, reactivate, empty trash, query-todos, query-tags, query-lists). - UI test: the page runs with the jQuery/jQuery UI versions from package-lock.json, and an edit made in the dialog reaches the database (this would have caught the jQuery 4 serialization bug). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01XgpcjUfZKQgJmGv5zfyvb1
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Bug fix: creating and editing todos is broken on
mainsince the jQuery 4.0.0 update (#9)jQuery 4 no longer serializes non-plain objects passed as
$.ajaxdata.addItemandstoreItemRemoteintodo.jspassTodoinstances, so the browser posted the literal body[object Object]. The server then answered "Todo may not be empty!", so adding or saving an edited todo always failed. Both calls now serialize explicitly with$.param(stuff). All other ajax calls already use plain objects. Separate commit: ed62752.CI tests (re-land of #6)
#6 was merged into its base branch
claude/magical-cray-3rk097. #5 had already been merged intomainthe day before, so the tests never reachedmain. This PR re-applies that commit on top of the currentmain:tests/api.test.js,tests/ui.test.js,tests/apache-access.sh.github/workflows/tests.yml(PHP lint, integration tests against MariaDB, Apache access rules)tests/denied in.htaccess/nginx.conf.sampleplaywrightas dev dependency (npm ci && npm run vendorleavesvendor/unchanged;npm audit --omit=devclean)New tests for changes merged since
enter,update(including moving an own todo into a foreign list),complete,trash,reactivate-one,empty-trash,query-todos,query-tagsandquery-lists.package-lock.json.Testing
Run locally with MariaDB 10.11, PHP 8.4, Chromium and Apache 2.4:
npm test: 10/10 pass, on repeated runs. Before the fix, the workflow UI test fails on currentmain.reactivate-temp.phpand unescaped todo rendering restored, the SQL injection test and both UI tests fail.tests/apache-access.sh: all 22 checks pass.php -lis clean on all PHP files.🤖 Generated with Claude Code
https://claude.ai/code/session_01XgpcjUfZKQgJmGv5zfyvb1
Generated by Claude Code