Follow-ups to the mobile rework: caching, dialogs, time zones, ownership checks, cleanup - #4
Merged
Merged
Conversation
Browsers kept using cached versions of todo-common.js, todo.css etc. after an update, so fixes only showed up after a forced reload (e.g. a newly added todo showing no start/due date until reload, or the modify dialog being too wide on mobile). With ?v=<mtime> the new files are loaded as soon as they change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
The dialog width was only adapted when opening a dialog; after rotating a phone (or resizing the window) an open dialog could stick out of the screen. Open dialogs are now resized and re-centered on window resize, and a CSS max-width serves as fallback. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
- lang.php and todo-core.php now work from any working directory, so the query scripts can use the language files; all hard-coded (partly German) messages in queries/*.php are now translated - queries taking a list or todo id check that it belongs to the current user ($curUserID, still fixed to the default user as there is no login yet) and reply "access denied" otherwise - query-lists.php uses $curUserID instead of a hard-coded 0 - reactivate-one.php used the query result instead of the affected row count, so it always reported success Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
The settings INSERT had no VALUES clause and failed. There was also no list 0, which todo.list_id defaults to and the frontend starts with. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
- viewport meta, charts scroll horizontally on narrow screens - the optional site navigation was included with a short open tag (disabled by default), so it was printed as text; it is now included properly if the file exists - remove the commented-out references to files that no longer exist - only count todos in lists of the current user Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
Start and due dates are calendar days, but were parsed as UTC midnight and formatted in local time, so west of UTC they were shown (and saved back from the modify dialog) one day early. They are now parsed as local days; creation/completion timestamps are still UTC. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
Clicking them added "#" to the URL and jumped to the top of the page. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
- remove the texts of the removed jQuery UI datepicker and the texts only used by the removed mobile version (CANCEL, LOG, NEW_TODO, REFRESH, TOGGLE) - add missing DOTODAY and EDITED_TAG_SUCCESSFUL, rename MERGE_SUCCESSFUL to MERGE_TAG_SUCCESSFUL as used in the code (the raw keys were shown) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
All icons are inlined into todo.css as data URIs; the last reference (calendar.svg for the jQuery UI datepicker) is gone. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
They were only available as a tooltip on the todo, which touch devices can't show. Recurrence and notes are already fields in the dialog. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
Without a separate mobile version, the split into common and desktop code no longer has a purpose. Also remove emptyModifyForm(), which was only used by the mobile version. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
Conflict resolution: - query scripts: main's prepared statements, POST+CSRF and generic database errors, with this branch's translated messages and list/todo ownership checks on top (requireOwnList/requireOwnTodo now use dbExec); main's new validation messages and the session/database error messages are translated as well - todo.js: main's todo-desktop.js changes (HTML escaping, POST for tag requests) ported into the merged file - index.php: vendor/ paths from main, all local JS/CSS via assetUrl() - statistik.php: keep main's removal of the external navigation include - install.sql: explicit column list plus the default list 0 - todo.css, todo-core.php: keep both sides Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
getRecurrenceString() reads the option label from the DOM (.text()), which was inserted unescaped into the title attribute (CodeQL js/xss-through-dom). The label comes from the language file, so this was not exploitable, but it is now escaped like the other values. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #3:
assetUrl()intodo-core.phpadds?v=<filemtime>, so changed files are fetched again. This includes thevendor/files.max-widthas fallback.Open issues from the previous review
../common/navigation.phpinclude was removed by Security fixes: SQL injection, CSRF, XSS, access control; npm-managed JS libs #5; this PR keeps it removed.)start → duefor open todos.parseDay()reads them as local calendar days. Creation/completion timestamps are still read as UTC.enter()no longer sendsrecurrenceAnchor=NaN.href="#".queries/*.phpare translated; some were hard-coded in German.lang.php/todo-core.phpnow work from any working directory, so the query scripts can load the language files.DOTODAY,EDITED_TAG_SUCCESSFUL, andMERGE_TAG_SUCCESSFUL(was namedMERGE_SUCCESSFUL).images/directory.$curUserID, and reply "access denied" otherwise. They are written as prepared statements, like the rest of Security fixes: SQL injection, CSRF, XSS, access control; npm-managed JS libs #5.$curUserIDstays the default user 0. Tags are global, so the tag queries are not restricted.todo-common.jsandtodo-desktop.jsare merged intotodo.js, and the unusedemptyModifyForm()is removed.Also found while testing:
sql/install.sql: it created no list 0, whichtodo.list_iddefaults to, so a fresh install couldn't add todos. The insert now also names its columns.Merge with main (#5)
The conflicts are resolved in a merge commit.
todo-desktop.js(HTML escaping, POST for the tag requests) are ported intotodo.js.Testing
After the merge, tested against a real MariaDB 10.11 database created from the merged
sql/install.sql:php -lpasses on all changed PHP files.🤖 Generated with Claude Code
https://claude.ai/code/session_019bDAqsvVCaQoaCKwFYcnDN