forked from fixin.me/fixin.me
Compare commits
11 Commits
pr69-multi
...
68695bced9
| Author | SHA1 | Date | |
|---|---|---|---|
| 68695bced9 | |||
| 6717b1d4c1 | |||
| d7fd8f1c45 | |||
| c367009347 | |||
| 1efb1ad86e | |||
| 238e8eb846 | |||
| 37199f85df | |||
| 7e1eacbc33 | |||
| f3cb8db1f4 | |||
| 7904ff3ef9 | |||
| 9ad922e3a1 |
@@ -1 +1 @@
|
|||||||
<svg xmlns="http://www.w3.org/2000/svg" id="icon" viewBox="0 0 24 24"><path fill="#ffffff" d="M12,2L1,21H23M12,6L19.53,19H4.47M11,10V14H13V10M11,16V18H13V16" /></svg>
|
<svg xmlns="http://www.w3.org/2000/svg" id="icon" viewBox="0 0 24 24"><path d="M12,2L1,21H23M12,6L19.53,19H4.47M11,10V14H13V10M11,16V18H13V16" /></svg>
|
||||||
|
|||||||
|
Before Width: | Height: | Size: 167 B After Width: | Height: | Size: 152 B |
@@ -1 +1 @@
|
|||||||
<svg xmlns="http://www.w3.org/2000/svg" id="icon" viewBox="0 0 24 24"><path fill="#ffffff" d="M12 2C6.5 2 2 6.5 2 12S6.5 22 12 22 22 17.5 22 12 17.5 2 12 2M12 20C7.59 20 4 16.41 4 12S7.59 4 12 4 20 7.59 20 12 16.41 20 12 20M16.59 7.58L10 14.17L7.41 11.59L6 13L10 17L18 9L16.59 7.58Z" /></svg>
|
<svg xmlns="http://www.w3.org/2000/svg" id="icon" viewBox="0 0 24 24"><path d="M12 2C6.5 2 2 6.5 2 12S6.5 22 12 22 22 17.5 22 12 17.5 2 12 2M12 20C7.59 20 4 16.41 4 12S7.59 4 12 4 20 7.59 20 12 16.41 20 12 20M16.59 7.58L10 14.17L7.41 11.59L6 13L10 17L18 9L16.59 7.58Z" /></svg>
|
||||||
|
|||||||
|
Before Width: | Height: | Size: 293 B After Width: | Height: | Size: 278 B |
@@ -18,10 +18,14 @@
|
|||||||
/* Strive for simplicity:
|
/* Strive for simplicity:
|
||||||
* * style elements/tags only - if possible,
|
* * style elements/tags only - if possible,
|
||||||
* * replace element/tag name with class name - if element has to be styled
|
* * replace element/tag name with class name - if element has to be styled
|
||||||
* differently depending on context (e.g. form)
|
* differently depending on context (e.g. <form>; <a> as link/button),
|
||||||
|
* * styles with multiple selectors should have all selectors with same
|
||||||
|
* specificity, to allow proper rule specificity vs order management.
|
||||||
*
|
*
|
||||||
* NOTE: Style in a modular way, similar to how CSS @scope would be used,
|
* NOTE: style in a modular way, similar to how CSS @scope would be used,
|
||||||
* to make transition easier once @scope is widely available */
|
* to make transition easier once @scope is widely available. */
|
||||||
|
/* TODO: review styles with multiple selectors and try to convert them to the same
|
||||||
|
* specificity. */
|
||||||
:root {
|
:root {
|
||||||
--color-focus-gray: #f3f3f3;
|
--color-focus-gray: #f3f3f3;
|
||||||
--color-border-gray: #dddddd;
|
--color-border-gray: #dddddd;
|
||||||
@@ -53,12 +57,26 @@
|
|||||||
:focus-visible {
|
:focus-visible {
|
||||||
outline: none;
|
outline: none;
|
||||||
}
|
}
|
||||||
|
/* NOTE: move to higher priority layer instead of using !important? */
|
||||||
|
[disabled] {
|
||||||
|
border-color: var(--color-border-gray) !important;
|
||||||
|
color: var(--color-border-gray) !important;
|
||||||
|
/* NOTE: cannot set cursor with `pointer-events: none`; can be fixed by setting
|
||||||
|
* `cursor` on wrapping element.
|
||||||
|
cursor: not-allowed; */
|
||||||
|
fill: var(--color-border-gray) !important;
|
||||||
|
pointer-events: none !important;
|
||||||
|
}
|
||||||
|
/* [hidden] submit elements cannot have `display` set as it makes them visible. */
|
||||||
|
[hidden] {
|
||||||
|
display: none !important;
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
/* Color coding of input controls' background:
|
/* Color coding of input controls' background:
|
||||||
* blue - target for interaction with pointer
|
* blue - target for interaction with pointer,
|
||||||
* gray - target for interaction with keyboard
|
* gray - target for interaction with keyboard,
|
||||||
* red - destructive, non-undoable action
|
* red - destructive, non-undoable action.
|
||||||
*/
|
*/
|
||||||
button,
|
button,
|
||||||
details,
|
details,
|
||||||
@@ -73,56 +91,17 @@ input,
|
|||||||
select {
|
select {
|
||||||
text-align: inherit;
|
text-align: inherit;
|
||||||
}
|
}
|
||||||
a,
|
|
||||||
button,
|
|
||||||
input[type=submit] {
|
|
||||||
cursor: pointer;
|
|
||||||
text-decoration: none;
|
|
||||||
white-space: nowrap;
|
|
||||||
}
|
|
||||||
/* [hidden] submit controls cannot have `display` set as it makes them visible */
|
|
||||||
.button,
|
|
||||||
button:not([hidden]),
|
|
||||||
input[type=submit]:not([hidden]),
|
|
||||||
.tab {
|
|
||||||
align-items: center;
|
|
||||||
color: var(--color-gray);
|
|
||||||
display: flex;
|
|
||||||
fill: var(--color-gray);
|
|
||||||
font-weight: bold;
|
|
||||||
}
|
|
||||||
.button,
|
|
||||||
button,
|
|
||||||
input[type=submit] {
|
|
||||||
font-size: 0.8rem;
|
|
||||||
padding: 0.6em 0.5em;
|
|
||||||
width: fit-content;
|
|
||||||
}
|
|
||||||
input:not([type=submit]):not([type=checkbox]),
|
|
||||||
select,
|
|
||||||
summary,
|
|
||||||
textarea {
|
|
||||||
padding: 0.2em 0.4em;
|
|
||||||
}
|
|
||||||
.button,
|
|
||||||
button,
|
|
||||||
input,
|
input,
|
||||||
select,
|
select,
|
||||||
summary,
|
summary,
|
||||||
textarea {
|
textarea {
|
||||||
border: solid 1px var(--color-gray);
|
border: 1px solid var(--color-gray);
|
||||||
border-radius: 0.25em;
|
border-radius: 0.25em;
|
||||||
|
padding: 0.2em 0.4em;
|
||||||
}
|
}
|
||||||
[name=cancel],
|
|
||||||
.auxiliary {
|
|
||||||
border-color: var(--color-border-gray);
|
|
||||||
color: var(--color-nav-gray);
|
|
||||||
fill: var(--color-nav-gray);
|
|
||||||
}
|
|
||||||
input[type=checkbox],
|
|
||||||
svg,
|
svg,
|
||||||
textarea {
|
textarea {
|
||||||
margin: 0
|
margin: 0;
|
||||||
}
|
}
|
||||||
input[type=checkbox] {
|
input[type=checkbox] {
|
||||||
accent-color: var(--color-blue);
|
accent-color: var(--color-blue);
|
||||||
@@ -130,14 +109,16 @@ input[type=checkbox] {
|
|||||||
-webkit-appearance: none;
|
-webkit-appearance: none;
|
||||||
display: flex;
|
display: flex;
|
||||||
height: 1.1em;
|
height: 1.1em;
|
||||||
|
margin: 0;
|
||||||
|
padding: 0;
|
||||||
width: 1.1em;
|
width: 1.1em;
|
||||||
}
|
}
|
||||||
input[type=checkbox]:checked {
|
input[type=checkbox]:checked {
|
||||||
appearance: checkbox;
|
appearance: checkbox;
|
||||||
-webkit-appearance: checkbox;
|
-webkit-appearance: checkbox;
|
||||||
}
|
}
|
||||||
/* Hide spin buttons in input number fields */
|
/* Hide spin buttons of <input type=number>. */
|
||||||
/* TODO: add spin buttons inside input[number]: before (-) and after (+) input */
|
/* TODO: add spin buttons inside <input type=number>: before (-) and after (+) input. */
|
||||||
input[type=number] {
|
input[type=number] {
|
||||||
appearance: textfield;
|
appearance: textfield;
|
||||||
-moz-appearance: textfield;
|
-moz-appearance: textfield;
|
||||||
@@ -149,52 +130,21 @@ input::-webkit-outer-spin-button {
|
|||||||
-webkit-appearance: none;
|
-webkit-appearance: none;
|
||||||
margin: 0;
|
margin: 0;
|
||||||
}
|
}
|
||||||
.button > svg,
|
|
||||||
.tab > svg,
|
|
||||||
button > svg {
|
|
||||||
height: 1.4em;
|
|
||||||
width: 1.4em;
|
|
||||||
}
|
|
||||||
.button > svg:not(:last-child),
|
|
||||||
.tab > svg:not(:last-child),
|
|
||||||
button > svg:not(:last-child) {
|
|
||||||
margin-right: 0.2em;
|
|
||||||
}
|
|
||||||
/* TODO: move normal non-button links (<a>:hover/:focus) styling here (i.e.
|
|
||||||
* page-wide, top-level) and remove from table.items - as the style should be
|
|
||||||
* same everywhere */
|
|
||||||
.button:focus-visible,
|
|
||||||
button:focus-visible,
|
|
||||||
input[type=submit]:focus-visible {
|
|
||||||
background-color: var(--color-focus-gray);
|
|
||||||
}
|
|
||||||
input:focus-visible,
|
input:focus-visible,
|
||||||
select:focus-visible,
|
select:focus-visible,
|
||||||
select:focus-within,
|
select:focus-within,
|
||||||
/* TODO: how to achieve summary:focus-within for ::details-content? */
|
/* TODO: how to achieve `summary:focus-within` for `::details-content`? */
|
||||||
summary:focus-visible,
|
summary:focus-visible,
|
||||||
textarea:focus-visible {
|
textarea:focus-visible {
|
||||||
accent-color: var(--color-dark-blue);
|
accent-color: var(--color-dark-blue);
|
||||||
background-color: var(--color-focus-gray);
|
background-color: var(--color-focus-gray);
|
||||||
}
|
}
|
||||||
.button:hover,
|
|
||||||
button:hover,
|
|
||||||
input[type=submit]:hover {
|
|
||||||
background-color: var(--color-blue);
|
|
||||||
border-color: var(--color-blue);
|
|
||||||
color: white;
|
|
||||||
fill: white;
|
|
||||||
}
|
|
||||||
.dangerous:hover {
|
|
||||||
background-color: var(--color-red);
|
|
||||||
border-color: var(--color-red);
|
|
||||||
}
|
|
||||||
input:hover,
|
input:hover,
|
||||||
select:hover,
|
select:hover,
|
||||||
summary:hover,
|
summary:hover,
|
||||||
textarea:hover {
|
textarea:hover {
|
||||||
border-color: var(--color-blue);
|
border-color: var(--color-blue);
|
||||||
outline: solid 1px var(--color-blue);
|
outline: 1px solid var(--color-blue);
|
||||||
}
|
}
|
||||||
select:hover,
|
select:hover,
|
||||||
summary:hover {
|
summary:hover {
|
||||||
@@ -204,8 +154,68 @@ input:invalid,
|
|||||||
select:invalid,
|
select:invalid,
|
||||||
textarea:invalid {
|
textarea:invalid {
|
||||||
border-color: var(--color-red);
|
border-color: var(--color-red);
|
||||||
outline: solid 1px var(--color-red);
|
outline-color: var(--color-red);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* `.button`: button-styled <a>, <button>, <input type=submit>.
|
||||||
|
* `.link`: any other <a>.
|
||||||
|
* `.tab`: tab-styled <a>.
|
||||||
|
*/
|
||||||
|
.button,
|
||||||
|
.link,
|
||||||
|
.tab {
|
||||||
|
cursor: pointer;
|
||||||
|
text-decoration: none;
|
||||||
|
white-space: nowrap;
|
||||||
|
}
|
||||||
|
.button,
|
||||||
|
.tab {
|
||||||
|
align-items: center;
|
||||||
|
color: var(--color-gray);
|
||||||
|
display: flex;
|
||||||
|
fill: var(--color-gray);
|
||||||
|
font-weight: bold;
|
||||||
|
}
|
||||||
|
.button {
|
||||||
|
border: 1px solid var(--color-gray);
|
||||||
|
border-radius: 0.25em;
|
||||||
|
font-size: 0.8rem;
|
||||||
|
padding: 0.6em 0.5em;
|
||||||
|
width: fit-content;
|
||||||
|
}
|
||||||
|
[name=cancel],
|
||||||
|
.auxiliary {
|
||||||
|
border-color: var(--color-border-gray);
|
||||||
|
color: var(--color-nav-gray);
|
||||||
|
fill: var(--color-nav-gray);
|
||||||
|
}
|
||||||
|
.button > svg,
|
||||||
|
.tab > svg {
|
||||||
|
height: 1.4em;
|
||||||
|
width: 1.4em;
|
||||||
|
}
|
||||||
|
.button > svg:not(:last-child),
|
||||||
|
.tab > svg:not(:last-child) {
|
||||||
|
margin-right: 0.2em;
|
||||||
|
}
|
||||||
|
.button:focus-visible,
|
||||||
|
.tab:focus-visible,
|
||||||
|
.tab:hover {
|
||||||
|
background-color: var(--color-focus-gray);
|
||||||
|
}
|
||||||
|
.button:hover {
|
||||||
|
background-color: var(--color-blue);
|
||||||
|
border-color: var(--color-blue);
|
||||||
|
color: white;
|
||||||
|
fill: white;
|
||||||
|
}
|
||||||
|
.dangerous:hover {
|
||||||
|
background-color: var(--color-red);
|
||||||
|
border-color: var(--color-red);
|
||||||
|
}
|
||||||
|
/* TODO: move normal, non-button links (<a>:hover/:focus) styling here (i.e.
|
||||||
|
* page-wide, top-level) and remove from `table.items` - as the style should be
|
||||||
|
* same everywhere. */
|
||||||
input[type=text]:read-only,
|
input[type=text]:read-only,
|
||||||
textarea:read-only {
|
textarea:read-only {
|
||||||
border: none;
|
border: none;
|
||||||
@@ -213,8 +223,8 @@ textarea:read-only {
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
/* NOTE: collapse gaps around empty rows (`topside`) once possible
|
/* NOTE: collapse gaps around empty rows (`topside`) once possible with
|
||||||
* with grid-collapse property and remove alternative grid-template
|
* `grid-collapse` property and remove alternative `grid-template-areas`.
|
||||||
* https://github.com/w3c/csswg-drafts/issues/5813 */
|
* https://github.com/w3c/csswg-drafts/issues/5813 */
|
||||||
body {
|
body {
|
||||||
display: grid;
|
display: grid;
|
||||||
@@ -247,18 +257,14 @@ header {
|
|||||||
margin-inline-start: 4%;
|
margin-inline-start: 4%;
|
||||||
}
|
}
|
||||||
.navigation > .tab {
|
.navigation > .tab {
|
||||||
border-bottom: solid 2px var(--color-nav-gray);
|
border-bottom: 2px solid var(--color-nav-gray);
|
||||||
flex: 1;
|
flex: 1;
|
||||||
font-size: 1rem;
|
font-size: 1rem;
|
||||||
justify-content: center;
|
justify-content: center;
|
||||||
padding-block: 0.4em;
|
padding-block: 0.4em;
|
||||||
}
|
}
|
||||||
.navigation > .tab:hover,
|
|
||||||
.navigation > .tab:focus-visible {
|
|
||||||
background-color: var(--color-focus-gray);
|
|
||||||
}
|
|
||||||
.navigation > .tab.active {
|
.navigation > .tab.active {
|
||||||
border-bottom: solid 4px var(--color-blue);
|
border-bottom: 4px solid var(--color-blue);
|
||||||
color: var(--color-blue);
|
color: var(--color-blue);
|
||||||
fill: var(--color-blue);
|
fill: var(--color-blue);
|
||||||
}
|
}
|
||||||
@@ -290,7 +296,7 @@ header {
|
|||||||
|
|
||||||
#flashes {
|
#flashes {
|
||||||
display: grid;
|
display: grid;
|
||||||
gap: 0.2em;
|
row-gap: 0.4em;
|
||||||
grid-template-columns: 1fr auto auto auto 1fr;
|
grid-template-columns: 1fr auto auto auto 1fr;
|
||||||
left: 0;
|
left: 0;
|
||||||
pointer-events: none;
|
pointer-events: none;
|
||||||
@@ -306,49 +312,42 @@ header {
|
|||||||
display: grid;
|
display: grid;
|
||||||
grid-column: 2/5;
|
grid-column: 2/5;
|
||||||
grid-template-columns: subgrid;
|
grid-template-columns: subgrid;
|
||||||
|
line-height: 2.2em;
|
||||||
pointer-events: auto;
|
pointer-events: auto;
|
||||||
}
|
}
|
||||||
.flash.alert:before {
|
.flash:before {
|
||||||
content: url('pictograms/alert-outline.svg');
|
filter: invert();
|
||||||
height: 1.4em;
|
height: 1.4em;
|
||||||
margin: 0 0.5em;
|
margin: 0 0.5em;
|
||||||
width: 1.4em;
|
width: 1.4em;
|
||||||
}
|
}
|
||||||
|
.flash.alert:before {
|
||||||
|
content: url('pictograms/alert-outline.svg');
|
||||||
|
}
|
||||||
.flash.alert {
|
.flash.alert {
|
||||||
border-color: var(--color-red);
|
border-color: var(--color-red);
|
||||||
background-color: var(--color-red);
|
background-color: var(--color-red);
|
||||||
}
|
}
|
||||||
.flash.notice:before {
|
.flash.notice:before {
|
||||||
content: url('pictograms/check-circle-outline.svg');
|
content: url('pictograms/check-circle-outline.svg');
|
||||||
height: 1.4em;
|
|
||||||
margin: 0 0.5em;
|
|
||||||
width: 1.4em;
|
|
||||||
}
|
}
|
||||||
.flash.notice {
|
.flash.notice {
|
||||||
border-color: var(--color-blue);
|
border-color: var(--color-blue);
|
||||||
background-color: var(--color-blue);
|
background-color: var(--color-blue);
|
||||||
}
|
}
|
||||||
.flash > div {
|
.flash svg {
|
||||||
grid-column: 2;
|
|
||||||
}
|
|
||||||
/* NOTE: currently flash button inherits some unnecessary styles from generic
|
|
||||||
* button. */
|
|
||||||
.flash > button {
|
|
||||||
border: none;
|
|
||||||
color: inherit;
|
|
||||||
cursor: pointer;
|
cursor: pointer;
|
||||||
font-size: 1.4em;
|
fill: white;
|
||||||
font-weight: bold;
|
height: 2.2em;
|
||||||
grid-column: 3;
|
|
||||||
opacity: 0.6;
|
opacity: 0.6;
|
||||||
padding: 0.2em 0.4em;
|
padding: 0.4em 0.5em;
|
||||||
|
width: 2.4em;
|
||||||
}
|
}
|
||||||
.flash > button:hover {
|
.flash svg:hover {
|
||||||
opacity: 1;
|
opacity: 1;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
/* TODO: Hover over invalid should work like in measurements (thin vs thick border) */
|
|
||||||
.labeled-form {
|
.labeled-form {
|
||||||
align-items: center;
|
align-items: center;
|
||||||
display: grid;
|
display: grid;
|
||||||
@@ -365,7 +364,7 @@ header {
|
|||||||
.labeled-form label.required {
|
.labeled-form label.required {
|
||||||
font-weight: bold;
|
font-weight: bold;
|
||||||
}
|
}
|
||||||
/* Don't style `label.error + input` if case already covered by input:invalid */
|
/* Don't style `label.error + input` if case already covered by `input:invalid`. */
|
||||||
.labeled-form label.error {
|
.labeled-form label.error {
|
||||||
color: var(--color-red);
|
color: var(--color-red);
|
||||||
}
|
}
|
||||||
@@ -385,17 +384,17 @@ header {
|
|||||||
.labeled-form .auxiliary {
|
.labeled-form .auxiliary {
|
||||||
grid-column: 3;
|
grid-column: 3;
|
||||||
/* If more buttons are needed, `grid-row` can be replaced with
|
/* If more buttons are needed, `grid-row` can be replaced with
|
||||||
* `reading-flow: grid-columns` to ensure proper tabindex order */
|
* `reading-flow: grid-columns` to ensure proper [tabindex] order. */
|
||||||
grid-row: 1;
|
grid-row: 1;
|
||||||
height: 100%;
|
height: 100%;
|
||||||
padding-block: 0;
|
padding-block: 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
/* TODO: remove .items class (?) and make 'form table' work properly */
|
/* TODO: remove `.items` class (?) and make `form table` work properly. */
|
||||||
table.items {
|
table.items {
|
||||||
border-spacing: 0;
|
border-spacing: 0;
|
||||||
border: solid 1px var(--color-border-gray);
|
border: 1px solid var(--color-border-gray);
|
||||||
border-radius: 0.25em;
|
border-radius: 0.25em;
|
||||||
font-size: 0.85rem;
|
font-size: 0.85rem;
|
||||||
text-align: left;
|
text-align: left;
|
||||||
@@ -418,7 +417,7 @@ table.items th,
|
|||||||
table.items td {
|
table.items td {
|
||||||
padding-inline: 1em 0;
|
padding-inline: 1em 0;
|
||||||
}
|
}
|
||||||
/* For <a> to fill <td> completely, we use an ::after pseudoelement. */
|
/* For <a> to fill <td> completely, we use an `::after` pseudoelement. */
|
||||||
table.items td.link {
|
table.items td.link {
|
||||||
padding: 0;
|
padding: 0;
|
||||||
position: relative;
|
position: relative;
|
||||||
@@ -448,7 +447,7 @@ table.items td:last-child {
|
|||||||
padding-inline-end: 0.1em;
|
padding-inline-end: 0.1em;
|
||||||
}
|
}
|
||||||
table.items td {
|
table.items td {
|
||||||
border-top: solid 1px var(--color-border-gray);
|
border-top: 1px solid var(--color-border-gray);
|
||||||
height: 2.4em;
|
height: 2.4em;
|
||||||
padding-block: 0.1em;
|
padding-block: 0.1em;
|
||||||
}
|
}
|
||||||
@@ -467,7 +466,7 @@ table.items tr.dropzone::after {
|
|||||||
content: '';
|
content: '';
|
||||||
inset: 1px 0 0 0;
|
inset: 1px 0 0 0;
|
||||||
position: absolute;
|
position: absolute;
|
||||||
outline: dashed 2px var(--color-blue);
|
outline: 2px dashed var(--color-blue);
|
||||||
outline-offset: -1px;
|
outline-offset: -1px;
|
||||||
z-index: var(--z-index-table-row-outline);
|
z-index: var(--z-index-table-row-outline);
|
||||||
}
|
}
|
||||||
@@ -478,8 +477,8 @@ table.items tr.form td {
|
|||||||
vertical-align: top;
|
vertical-align: top;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* TODO: replace :hover:focus-visible combos with proper LOVE stye order */
|
/* TODO: replace `:hover:focus-visible` combos with proper LOVE style order. */
|
||||||
/* TODO: Update table styling: simplify selectors, deduplicate, remove non-font rem. */
|
/* TODO: update table styling: simplify selectors, deduplicate, remove non-font rem. */
|
||||||
table.items td.link a:hover,
|
table.items td.link a:hover,
|
||||||
table.items td.link a:focus-visible,
|
table.items td.link a:focus-visible,
|
||||||
table.items td.link a:hover:focus-visible {
|
table.items td.link a:hover:focus-visible {
|
||||||
@@ -517,9 +516,7 @@ table.items td.svg {
|
|||||||
table.items td.number {
|
table.items td.number {
|
||||||
text-align: right;
|
text-align: right;
|
||||||
}
|
}
|
||||||
table.items .button,
|
table.items .button {
|
||||||
table.items button,
|
|
||||||
table.items input[type=submit] {
|
|
||||||
font-weight: normal;
|
font-weight: normal;
|
||||||
height: 100%;
|
height: 100%;
|
||||||
padding: 0.4em;
|
padding: 0.4em;
|
||||||
@@ -529,25 +526,26 @@ table.items select,
|
|||||||
table.items textarea {
|
table.items textarea {
|
||||||
padding-block: 0.375em;
|
padding-block: 0.375em;
|
||||||
}
|
}
|
||||||
/* TODO: find a way (layers?) to style inputs differently while making sure
|
|
||||||
* hover works properly without using :not(:hover) selectors here. */
|
table input,
|
||||||
table.items .button:not(:hover),
|
table select,
|
||||||
table.items button:not(:hover),
|
table summary,
|
||||||
table.items input:not(:hover),
|
table textarea {
|
||||||
table.items select:not(:hover),
|
|
||||||
table.items textarea:not(:hover) {
|
|
||||||
border-color: var(--color-border-gray);
|
border-color: var(--color-border-gray);
|
||||||
}
|
}
|
||||||
table.items .button:not(:hover),
|
table select {
|
||||||
table.items button:not(:hover),
|
|
||||||
table.items input[type=submit]:not(:hover),
|
|
||||||
table.items select:not(:hover) {
|
|
||||||
color: var(--color-table-gray);
|
color: var(--color-table-gray);
|
||||||
}
|
}
|
||||||
table.items select:focus-within,
|
table select:hover,
|
||||||
table.items select:focus-visible {
|
table select:focus-within,
|
||||||
|
table select:focus-visible {
|
||||||
color: black;
|
color: black;
|
||||||
}
|
}
|
||||||
|
table .button {
|
||||||
|
border-color: var(--color-border-gray);
|
||||||
|
color: var(--color-table-gray);
|
||||||
|
}
|
||||||
|
|
||||||
form table.items {
|
form table.items {
|
||||||
border: none;
|
border: none;
|
||||||
}
|
}
|
||||||
@@ -559,6 +557,9 @@ form table.items td {
|
|||||||
form table.items td:first-child {
|
form table.items td:first-child {
|
||||||
color: inherit;
|
color: inherit;
|
||||||
}
|
}
|
||||||
|
form table select {
|
||||||
|
color: black;
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
.centered {
|
.centered {
|
||||||
@@ -591,17 +592,6 @@ form table.items td:first-child {
|
|||||||
gap: 0.8em;
|
gap: 0.8em;
|
||||||
flex-direction: column;
|
flex-direction: column;
|
||||||
}
|
}
|
||||||
[disabled] {
|
|
||||||
/* label:has(input[disabled]) {
|
|
||||||
* TODO: disabled checkbox blue square focus removal; disabled label styling;
|
|
||||||
* focused label styling (currently only checkbox has focus)
|
|
||||||
* */
|
|
||||||
border-color: var(--color-border-gray) !important;
|
|
||||||
color: var(--color-border-gray) !important;
|
|
||||||
cursor: not-allowed;
|
|
||||||
fill: var(--color-border-gray) !important;
|
|
||||||
pointer-events: none;
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
details {
|
details {
|
||||||
@@ -629,7 +619,7 @@ summary:has(.button) {
|
|||||||
padding-inline-end: 0;
|
padding-inline-end: 0;
|
||||||
}
|
}
|
||||||
summary .button {
|
summary .button {
|
||||||
border: solid 1px var(--color-border-gray);
|
border: 1px solid var(--color-border-gray);
|
||||||
border-radius: inherit;
|
border-radius: inherit;
|
||||||
border-top-left-radius: 0;
|
border-top-left-radius: 0;
|
||||||
border-bottom-left-radius: 0;
|
border-bottom-left-radius: 0;
|
||||||
@@ -645,10 +635,10 @@ details[open] summary::before {
|
|||||||
summary::marker {
|
summary::marker {
|
||||||
padding-left: 0.25em;
|
padding-left: 0.25em;
|
||||||
}
|
}
|
||||||
/* NOTE: use details[open]::details-content once widely available */
|
/* NOTE: use `details[open]::details-content` once widely available. */
|
||||||
details[open] ul {
|
details[open] ul {
|
||||||
background: white;
|
background: white;
|
||||||
border: solid 1px var(--color-border-gray);
|
border: 1px solid var(--color-border-gray);
|
||||||
border-radius: 0.25em;
|
border-radius: 0.25em;
|
||||||
box-shadow: 1px 1px 3px var(--color-border-gray);
|
box-shadow: 1px 1px 3px var(--color-border-gray);
|
||||||
margin: -1px 0 0 0;
|
margin: -1px 0 0 0;
|
||||||
@@ -670,3 +660,10 @@ li input[type=checkbox] {
|
|||||||
li::marker {
|
li::marker {
|
||||||
content: '';
|
content: '';
|
||||||
}
|
}
|
||||||
|
/*
|
||||||
|
* TODO:
|
||||||
|
* * disable <label> containing disabled checkbox: `label:has(input[disabled])`,
|
||||||
|
* * disabled label styling,
|
||||||
|
* * focused label styling (currently only checkbox has focus),
|
||||||
|
* * disabled checkbox blue square focus removal.
|
||||||
|
* */
|
||||||
|
|||||||
@@ -9,6 +9,7 @@ class ApplicationController < ActionController::Base
|
|||||||
helper_method :current_user_disguised?
|
helper_method :current_user_disguised?
|
||||||
helper_method :current_tab
|
helper_method :current_tab
|
||||||
|
|
||||||
|
before_action :redirect_to_setup_if_needed
|
||||||
before_action :authenticate_user!
|
before_action :authenticate_user!
|
||||||
|
|
||||||
class AccessForbidden < StandardError; end
|
class AccessForbidden < StandardError; end
|
||||||
@@ -25,18 +26,6 @@ class ApplicationController < ActionController::Base
|
|||||||
# Turbo will reload 2nd time with HTML format and flashes will be lost.
|
# Turbo will reload 2nd time with HTML format and flashes will be lost.
|
||||||
rescue_from *ActionDispatch::ExceptionWrapper.rescue_responses.keys, with: :rescue_turbo
|
rescue_from *ActionDispatch::ExceptionWrapper.rescue_responses.keys, with: :rescue_turbo
|
||||||
|
|
||||||
# Required by #respond_with (gem `responders`) used by Devise controllers.
|
|
||||||
respond_to :html, :turbo_stream
|
|
||||||
|
|
||||||
def after_sign_in_path_for(resource)
|
|
||||||
# TODO: allow setting path per-user or save last path in session and restore
|
|
||||||
units_path
|
|
||||||
end
|
|
||||||
|
|
||||||
def after_sign_out_path_for(resource)
|
|
||||||
new_user_session_path
|
|
||||||
end
|
|
||||||
|
|
||||||
protected
|
protected
|
||||||
|
|
||||||
def current_user_disguised?
|
def current_user_disguised?
|
||||||
@@ -55,6 +44,16 @@ class ApplicationController < ActionController::Base
|
|||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
|
# Redirect to the web setup wizard when the application has not yet been
|
||||||
|
# initialised (i.e. no admin account exists in the database).
|
||||||
|
def redirect_to_setup_if_needed
|
||||||
|
return if User.exists?(status: :admin)
|
||||||
|
redirect_to new_setup_path
|
||||||
|
rescue ActiveRecord::StatementInvalid
|
||||||
|
# Tables may not exist yet (migrations not run). Fall through and let the
|
||||||
|
# normal request handling surface a meaningful error.
|
||||||
|
end
|
||||||
|
|
||||||
def render_no_content(record)
|
def render_no_content(record)
|
||||||
helpers.render_errors(record)
|
helpers.render_errors(record)
|
||||||
render html: nil, layout: true
|
render html: nil, layout: true
|
||||||
|
|||||||
39
app/controllers/registrations_controller.rb
Normal file
39
app/controllers/registrations_controller.rb
Normal file
@@ -0,0 +1,39 @@
|
|||||||
|
class RegistrationsController < Devise::RegistrationsController
|
||||||
|
before_action :authenticate_user!, only: [:edit, :update, :destroy]
|
||||||
|
|
||||||
|
def destroy
|
||||||
|
if current_user.sole_admin?
|
||||||
|
redirect_back fallback_location: edit_user_registration_path,
|
||||||
|
alert: t(".sole_admin")
|
||||||
|
return
|
||||||
|
end
|
||||||
|
super
|
||||||
|
end
|
||||||
|
|
||||||
|
protected
|
||||||
|
|
||||||
|
def build_resource(hash = {})
|
||||||
|
super
|
||||||
|
# Skip the email confirmation step when the admin has enabled this option
|
||||||
|
# via the web setup wizard (stored as the "skip_email_confirmation" Setting).
|
||||||
|
# The account becomes active immediately so the user can sign in right after
|
||||||
|
# registering.
|
||||||
|
resource.skip_confirmation! if Setting.get("skip_email_confirmation") == "true"
|
||||||
|
end
|
||||||
|
|
||||||
|
def update_resource(resource, params)
|
||||||
|
# Based on update_with_password()
|
||||||
|
if params[:password].blank?
|
||||||
|
params.delete(:password)
|
||||||
|
params.delete(:password_confirmation) if params[:password_confirmation].blank?
|
||||||
|
end
|
||||||
|
|
||||||
|
result = resource.update(params)
|
||||||
|
resource.clean_up_passwords
|
||||||
|
result
|
||||||
|
end
|
||||||
|
|
||||||
|
def after_inactive_sign_up_path_for(resource)
|
||||||
|
new_user_session_path
|
||||||
|
end
|
||||||
|
end
|
||||||
59
app/controllers/setup_controller.rb
Normal file
59
app/controllers/setup_controller.rb
Normal file
@@ -0,0 +1,59 @@
|
|||||||
|
# Handles the one-time web-based installation wizard.
|
||||||
|
#
|
||||||
|
# The wizard is only accessible when no admin account exists yet. Once an
|
||||||
|
# admin has been created the controller redirects every request to the root
|
||||||
|
# path, so it can never be used to overwrite an existing installation.
|
||||||
|
class SetupController < ActionController::Base
|
||||||
|
# Use the full application layout (header, flash, etc.) so the page looks
|
||||||
|
# consistent with the rest of the site.
|
||||||
|
layout "application"
|
||||||
|
|
||||||
|
before_action :redirect_if_installed
|
||||||
|
|
||||||
|
def new
|
||||||
|
end
|
||||||
|
|
||||||
|
def create
|
||||||
|
email = params[:admin_email].to_s.strip
|
||||||
|
password = params[:admin_password].to_s
|
||||||
|
confirm = params[:admin_password_confirmation].to_s
|
||||||
|
|
||||||
|
errors = []
|
||||||
|
errors << t(".email_blank") if email.blank?
|
||||||
|
errors << t(".password_blank") if password.blank?
|
||||||
|
errors << t(".password_mismatch") if password != confirm
|
||||||
|
|
||||||
|
if errors.any?
|
||||||
|
flash.now[:alert] = errors.join(" ")
|
||||||
|
return render :new, status: :unprocessable_entity
|
||||||
|
end
|
||||||
|
|
||||||
|
user = User.new(email: email, password: password, status: :admin)
|
||||||
|
user.skip_confirmation!
|
||||||
|
|
||||||
|
unless user.save
|
||||||
|
flash.now[:alert] = user.errors.full_messages.join(" ")
|
||||||
|
return render :new, status: :unprocessable_entity
|
||||||
|
end
|
||||||
|
|
||||||
|
# Persist runtime settings chosen during setup.
|
||||||
|
Setting.set("skip_email_confirmation",
|
||||||
|
params[:skip_email_confirmation] == "1")
|
||||||
|
|
||||||
|
# Optionally seed the built-in default units.
|
||||||
|
if params[:seed_units] == "1"
|
||||||
|
load Rails.root.join("db/seeds/units.rb")
|
||||||
|
end
|
||||||
|
|
||||||
|
redirect_to new_user_session_path, notice: t(".success")
|
||||||
|
end
|
||||||
|
|
||||||
|
private
|
||||||
|
|
||||||
|
def redirect_if_installed
|
||||||
|
redirect_to root_path if User.exists?(status: :admin)
|
||||||
|
rescue ActiveRecord::StatementInvalid
|
||||||
|
# Tables are not yet migrated — stay on the setup page so the user sees a
|
||||||
|
# meaningful error rather than a crash.
|
||||||
|
end
|
||||||
|
end
|
||||||
@@ -1,24 +0,0 @@
|
|||||||
class User::ProfilesController < Devise::RegistrationsController
|
|
||||||
def destroy
|
|
||||||
# TODO: Disallow/disable deletion for last admin account; update :edit view
|
|
||||||
super
|
|
||||||
end
|
|
||||||
|
|
||||||
protected
|
|
||||||
|
|
||||||
def update_resource(resource, params)
|
|
||||||
# Based on update_with_password()
|
|
||||||
if params[:password].blank?
|
|
||||||
params.delete(:password)
|
|
||||||
params.delete(:password_confirmation) if params[:password_confirmation].blank?
|
|
||||||
end
|
|
||||||
|
|
||||||
result = resource.update(params)
|
|
||||||
resource.clean_up_passwords
|
|
||||||
result
|
|
||||||
end
|
|
||||||
|
|
||||||
def after_inactive_sign_up_path_for(resource)
|
|
||||||
new_user_session_path
|
|
||||||
end
|
|
||||||
end
|
|
||||||
@@ -37,7 +37,7 @@ class UsersController < ApplicationController
|
|||||||
end
|
end
|
||||||
|
|
||||||
# NOTE: limited actions availabe to :admin by design. Users are meant to
|
# NOTE: limited actions availabe to :admin by design. Users are meant to
|
||||||
# manage their accounts by themselves through profiles. :admin
|
# manage their accounts by themselves through registrations. :admin
|
||||||
# is allowed to sign-in (disguise) as user and make changes from there.
|
# is allowed to sign-in (disguise) as user and make changes from there.
|
||||||
|
|
||||||
protected
|
protected
|
||||||
|
|||||||
@@ -12,6 +12,12 @@ module ApplicationHelper
|
|||||||
labeled_field_for(method, options) { super }
|
labeled_field_for(method, options) { super }
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def submit(value = nil, options = {})
|
||||||
|
value, options = nil, value if value.is_a?(Hash)
|
||||||
|
options[:class] = @template.class_names('button', options[:class])
|
||||||
|
super
|
||||||
|
end
|
||||||
|
|
||||||
private
|
private
|
||||||
|
|
||||||
def labeled_field_for(method, options)
|
def labeled_field_for(method, options)
|
||||||
@@ -108,8 +114,12 @@ module ApplicationHelper
|
|||||||
end
|
end
|
||||||
|
|
||||||
def button(value = nil, options = {}, &block)
|
def button(value = nil, options = {}, &block)
|
||||||
# button does not use #objectify_options
|
# #button does not use #objectify_options/@default_options
|
||||||
options.merge!(@options.slice(:form))
|
value, options = nil, value if value.is_a?(Hash)
|
||||||
|
options = options.merge(
|
||||||
|
@default_options.slice(:form),
|
||||||
|
class: @template.class_names('button', options[:class])
|
||||||
|
)
|
||||||
super
|
super
|
||||||
end
|
end
|
||||||
|
|
||||||
@@ -143,7 +153,8 @@ module ApplicationHelper
|
|||||||
end
|
end
|
||||||
|
|
||||||
def svg_tag(source, label = nil, options = {})
|
def svg_tag(source, label = nil, options = {})
|
||||||
svg_tag = tag.svg(options) do
|
label, options = nil, label if label.is_a? Hash
|
||||||
|
svg_tag = tag.svg(**options) do
|
||||||
tag.use(href: "#{image_path(source + ".svg")}#icon")
|
tag.use(href: "#{image_path(source + ".svg")}#icon")
|
||||||
end
|
end
|
||||||
label.blank? ? svg_tag : svg_tag + tag.span(label)
|
label.blank? ? svg_tag : svg_tag + tag.span(label)
|
||||||
@@ -212,9 +223,8 @@ module ApplicationHelper
|
|||||||
# Conversion of flash to Array only required because of Devise
|
# Conversion of flash to Array only required because of Devise
|
||||||
Array(messages).map do |message|
|
Array(messages).map do |message|
|
||||||
tag.div class: "flash #{entry}" do
|
tag.div class: "flash #{entry}" do
|
||||||
# TODO: change button text to svg to make it aligned vertically
|
tag.span(sanitize(message)) +
|
||||||
tag.div(sanitize(message)) + tag.button(sanitize("×"), tabindex: -1,
|
svg_tag('pictograms/close-outline', {onclick: "this.parentElement.remove()"})
|
||||||
onclick: "this.parentElement.remove();")
|
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
end.join.html_safe
|
end.join.html_safe
|
||||||
|
|||||||
@@ -37,18 +37,6 @@ window.detailsObserver = new MutationObserver((mutations) => {
|
|||||||
mutations[0].target.dispatchEvent(new Event('change', {bubbles: true}))
|
mutations[0].target.dispatchEvent(new Event('change', {bubbles: true}))
|
||||||
});
|
});
|
||||||
|
|
||||||
function formValidate(event) {
|
|
||||||
var id = event.submitter.getAttribute("data-validate")
|
|
||||||
if (!id) return;
|
|
||||||
|
|
||||||
var input = document.getElementById(id)
|
|
||||||
if (!input.checkValidity()) {
|
|
||||||
input.reportValidity()
|
|
||||||
event.preventDefault()
|
|
||||||
}
|
|
||||||
}
|
|
||||||
window.formValidate = formValidate
|
|
||||||
|
|
||||||
|
|
||||||
/* Turbo stream actions */
|
/* Turbo stream actions */
|
||||||
Turbo.StreamElement.prototype.disableElement = function(element) {
|
Turbo.StreamElement.prototype.disableElement = function(element) {
|
||||||
|
|||||||
@@ -15,8 +15,8 @@ class Quantity < ApplicationRecord
|
|||||||
errors.add(:parent, :descendant_reference) if ancestor_of?(parent)
|
errors.add(:parent, :descendant_reference) if ancestor_of?(parent)
|
||||||
end
|
end
|
||||||
validates :name, presence: true, uniqueness: {scope: [:user_id, :parent_id]},
|
validates :name, presence: true, uniqueness: {scope: [:user_id, :parent_id]},
|
||||||
length: {maximum: type_for_attribute(:name).limit}
|
length: {maximum: type_for_attribute(:name).limit || Float::INFINITY}
|
||||||
validates :description, length: {maximum: type_for_attribute(:description).limit}
|
validates :description, length: {maximum: type_for_attribute(:description).limit || Float::INFINITY}
|
||||||
|
|
||||||
# Update :depths of progenies after parent change
|
# Update :depths of progenies after parent change
|
||||||
before_save if: :parent_changed? do
|
before_save if: :parent_changed? do
|
||||||
|
|||||||
20
app/models/setting.rb
Normal file
20
app/models/setting.rb
Normal file
@@ -0,0 +1,20 @@
|
|||||||
|
# Key-value store for runtime application settings that are configured through
|
||||||
|
# the web setup wizard (or updated by an administrator) rather than hard-coded
|
||||||
|
# in application.rb.
|
||||||
|
#
|
||||||
|
# Known keys:
|
||||||
|
# skip_email_confirmation – "true"/"false", mirrors the homonymous option
|
||||||
|
# that was previously in application.rb.
|
||||||
|
class Setting < ApplicationRecord
|
||||||
|
validates :key, presence: true, uniqueness: true
|
||||||
|
|
||||||
|
# Return the string value stored for +key+, or +default+ when absent.
|
||||||
|
def self.get(key, default: nil)
|
||||||
|
find_by(key: key)&.value || default
|
||||||
|
end
|
||||||
|
|
||||||
|
# Persist +value+ for +key+, creating the record if it does not yet exist.
|
||||||
|
def self.set(key, value)
|
||||||
|
find_or_initialize_by(key: key).update!(value: value.to_s)
|
||||||
|
end
|
||||||
|
end
|
||||||
@@ -12,8 +12,8 @@ class Unit < ApplicationRecord
|
|||||||
errors.add(:base, :multilevel_nesting) if base.base_id?
|
errors.add(:base, :multilevel_nesting) if base.base_id?
|
||||||
end
|
end
|
||||||
validates :symbol, presence: true, uniqueness: {scope: :user_id},
|
validates :symbol, presence: true, uniqueness: {scope: :user_id},
|
||||||
length: {maximum: type_for_attribute(:symbol).limit}
|
length: {maximum: type_for_attribute(:symbol).limit || Float::INFINITY}
|
||||||
validates :description, length: {maximum: type_for_attribute(:description).limit}
|
validates :description, length: {maximum: type_for_attribute(:description).limit || Float::INFINITY}
|
||||||
validates :multiplier, numericality: {equal_to: 1}, unless: :base
|
validates :multiplier, numericality: {equal_to: 1}, unless: :base
|
||||||
validates :multiplier, numericality: {greater_than: 0, precision: true, scale: true}, if: :base
|
validates :multiplier, numericality: {greater_than: 0, precision: true, scale: true}, if: :base
|
||||||
|
|
||||||
|
|||||||
@@ -29,4 +29,11 @@ class User < ApplicationRecord
|
|||||||
def at_least(status)
|
def at_least(status)
|
||||||
User.statuses[self.status] >= User.statuses[status]
|
User.statuses[self.status] >= User.statuses[status]
|
||||||
end
|
end
|
||||||
|
|
||||||
|
# Returns true when this user is the only admin account in the system.
|
||||||
|
# Used to block actions that would leave the application without an admin
|
||||||
|
# (account deletion, status demotion).
|
||||||
|
def sole_admin?
|
||||||
|
admin? && !User.admin.where.not(id: id).exists?
|
||||||
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
39
app/views/setup/new.html.erb
Normal file
39
app/views/setup/new.html.erb
Normal file
@@ -0,0 +1,39 @@
|
|||||||
|
<%= form_with url: setup_path, method: :post, class: "labeled-form main-area" do %>
|
||||||
|
|
||||||
|
<h3 style="grid-column: 1 / -1; text-align: left; margin: 0;">
|
||||||
|
<%= t(".admin_account") %>
|
||||||
|
</h3>
|
||||||
|
|
||||||
|
<label for="admin_email"><%= t(".admin_email") %></label>
|
||||||
|
<%= email_field_tag :admin_email, params[:admin_email],
|
||||||
|
id: "admin_email", required: true, size: 30, autofocus: true,
|
||||||
|
autocomplete: "email" %>
|
||||||
|
|
||||||
|
<label for="admin_password"><%= t(".admin_password") %></label>
|
||||||
|
<%= password_field_tag :admin_password, nil,
|
||||||
|
id: "admin_password", required: true, size: 30,
|
||||||
|
autocomplete: "new-password" %>
|
||||||
|
|
||||||
|
<label for="admin_password_confirmation"><%= t(".admin_password_confirmation") %></label>
|
||||||
|
<%= password_field_tag :admin_password_confirmation, nil,
|
||||||
|
id: "admin_password_confirmation", required: true, size: 30,
|
||||||
|
autocomplete: "off" %>
|
||||||
|
|
||||||
|
<h3 style="grid-column: 1 / -1; text-align: left; margin: 0.5em 0 0 0;">
|
||||||
|
<%= t(".options") %>
|
||||||
|
</h3>
|
||||||
|
|
||||||
|
<label for="skip_email_confirmation" style="grid-column: 1 / 3; text-align: left;">
|
||||||
|
<%= check_box_tag :skip_email_confirmation, "1",
|
||||||
|
params[:skip_email_confirmation] == "1",
|
||||||
|
id: "skip_email_confirmation" %>
|
||||||
|
<%= t(".skip_email_confirmation") %>
|
||||||
|
</label>
|
||||||
|
|
||||||
|
<label for="seed_units" style="grid-column: 1 / 3; text-align: left;">
|
||||||
|
<%= check_box_tag :seed_units, "1", true, id: "seed_units" %>
|
||||||
|
<%= t(".seed_units") %>
|
||||||
|
</label>
|
||||||
|
|
||||||
|
<%= submit_tag t(".submit") %>
|
||||||
|
<% end %>
|
||||||
@@ -1 +0,0 @@
|
|||||||
<% flash.discard %>
|
|
||||||
9
app/views/users/confirmations/new.html.erb
Normal file
9
app/views/users/confirmations/new.html.erb
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
<%= labeled_form_for resource, url: user_confirmation_path,
|
||||||
|
html: {class: 'main-area'} do |f| %>
|
||||||
|
|
||||||
|
<%= f.email_field :email, required: true, size: 30, autofocus: true,
|
||||||
|
autocomplete: 'email', value:
|
||||||
|
resource.pending_reconfirmation? ? resource.unconfirmed_email : resource.email %>
|
||||||
|
|
||||||
|
<%= f.submit t(:resend_confirmation) %>
|
||||||
|
<% end %>
|
||||||
@@ -1,2 +0,0 @@
|
|||||||
<%# For some reason flash messages are duplicated in bot flash and flash.now %>
|
|
||||||
<% flash.discard %>
|
|
||||||
@@ -1,5 +1,5 @@
|
|||||||
<%= labeled_form_for resource, url: user_password_path,
|
<%= labeled_form_for resource, url: user_password_path,
|
||||||
html: {method: :put, class: 'main-area', data: {turbo: false}} do |f| %>
|
html: {method: :put, class: 'main-area'} do |f| %>
|
||||||
|
|
||||||
<%= f.hidden_field :reset_password_token %>
|
<%= f.hidden_field :reset_password_token %>
|
||||||
|
|
||||||
|
|||||||
8
app/views/users/passwords/new.html.erb
Normal file
8
app/views/users/passwords/new.html.erb
Normal file
@@ -0,0 +1,8 @@
|
|||||||
|
<%= labeled_form_for resource, url: user_password_path,
|
||||||
|
html: {class: 'main-area'} do |f| %>
|
||||||
|
|
||||||
|
<%= f.email_field :email, required: true, size: 30, autofocus: true,
|
||||||
|
autocomplete: 'email' %>
|
||||||
|
|
||||||
|
<%= f.submit t(:recover_password) %>
|
||||||
|
<% end %>
|
||||||
@@ -1,17 +0,0 @@
|
|||||||
<%= labeled_form_for resource, url: user_registration_path,
|
|
||||||
html: {class: 'main-area', onsubmit: 'formValidate(event)'} do |f| %>
|
|
||||||
|
|
||||||
<%= f.email_field :email, required: true, size: 30, autofocus: true,
|
|
||||||
autocomplete: 'email' %>
|
|
||||||
<%= f.password_field :password, required: true, size: 30,
|
|
||||||
minlength: @minimum_password_length, autocomplete: 'new-password' %>
|
|
||||||
<%= f.password_field :password_confirmation, required: true, size: 30,
|
|
||||||
minlength: @minimum_password_length, autocomplete: 'off' %>
|
|
||||||
|
|
||||||
<%= f.submit t(:register), data: {turbo: false} %>
|
|
||||||
|
|
||||||
<%# TODO: fix button text color after change link -> button %>
|
|
||||||
<%= image_button_tag t(:resend_confirmation), 'email-sync-outline',
|
|
||||||
class: 'auxiliary', formaction: user_confirmation_path, formnovalidate: true,
|
|
||||||
data: {validate: f.field_id(:email)} %>
|
|
||||||
<% end %>
|
|
||||||
@@ -4,9 +4,8 @@
|
|||||||
<% end %>
|
<% end %>
|
||||||
|
|
||||||
<div class="rightside-area buttongrid">
|
<div class="rightside-area buttongrid">
|
||||||
<%#= TODO: Disallow/disable deletion for last admin account, image_button_to_if %>
|
<%= image_button_to_if !current_user.sole_admin?, t('.delete'), 'account-remove-outline',
|
||||||
<%= image_button_to t('.delete'), 'account-remove-outline', user_registration_path,
|
user_registration_path, form_class: 'tools-area', method: :delete, data: {turbo: false},
|
||||||
form_class: 'tools-area', method: :delete, data: {turbo: false},
|
|
||||||
onclick: {confirm: t('.confirm_delete')} %>
|
onclick: {confirm: t('.confirm_delete')} %>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
16
app/views/users/registrations/new.html.erb
Normal file
16
app/views/users/registrations/new.html.erb
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
<div class="main-area">
|
||||||
|
<%= labeled_form_for resource, url: user_registration_path do |f| %>
|
||||||
|
<%= f.email_field :email, required: true, size: 30, autofocus: true,
|
||||||
|
autocomplete: 'email' %>
|
||||||
|
<%= f.password_field :password, required: true, size: 30,
|
||||||
|
minlength: @minimum_password_length, autocomplete: 'new-password' %>
|
||||||
|
<%= f.password_field :password_confirmation, required: true, size: 30,
|
||||||
|
minlength: @minimum_password_length, autocomplete: 'off' %>
|
||||||
|
|
||||||
|
<%= f.submit t(:register) %>
|
||||||
|
<% end %>
|
||||||
|
|
||||||
|
<%= content_tag :p, t(:or), style: 'text-align: center;' %>
|
||||||
|
<%= image_link_to t(:resend_confirmation), 'email-sync-outline',
|
||||||
|
new_user_confirmation_path, class: 'centered' %>
|
||||||
|
</div>
|
||||||
@@ -1,19 +1,18 @@
|
|||||||
<%= labeled_form_for resource, url: user_session_path,
|
<div class="main-area">
|
||||||
html: {class: 'main-area', onsubmit: 'formValidate(event)'} do |f| %>
|
<%= labeled_form_for resource, url: user_session_path do |f| %>
|
||||||
|
<%= f.email_field :email, required: true, size: 30, autofocus: true,
|
||||||
|
autocomplete: 'email' %>
|
||||||
|
<%= f.password_field :password, required: true, size: 30,
|
||||||
|
minlength: @minimum_password_length, autocomplete: 'current-password' %>
|
||||||
|
|
||||||
<%= f.email_field :email, required: true, size: 30, autofocus: true,
|
<% if devise_mapping.rememberable? %>
|
||||||
autocomplete: 'email' %>
|
<%= f.check_box :remember_me %>
|
||||||
<%= f.password_field :password, required: true, size: 30,
|
<% end %>
|
||||||
autocomplete: 'current-password' %>
|
|
||||||
|
|
||||||
<% if devise_mapping.rememberable? %>
|
<%= f.submit t(:sign_in) %>
|
||||||
<%= f.check_box :remember_me %>
|
|
||||||
<% end %>
|
<% end %>
|
||||||
|
|
||||||
<%# /sign_in as HTML; /password as TURBO_STREAM %>
|
<%= content_tag :p, t(:or), style: 'text-align: center;' %>
|
||||||
<%= f.submit t(:sign_in), data: {turbo: false} %>
|
<%= image_link_to t(:recover_password), 'lock-reset', new_user_password_path,
|
||||||
|
class: 'centered' %>
|
||||||
<%= image_button_tag t(:recover_password), 'lock-reset', class: 'auxiliary',
|
</div>
|
||||||
formaction: user_password_path, formnovalidate: true,
|
|
||||||
data: {validate: f.field_id(:email)} %>
|
|
||||||
<% end %>
|
|
||||||
|
|||||||
@@ -54,5 +54,9 @@ module FixinMe
|
|||||||
|
|
||||||
# Sender address of account registration-related messages
|
# Sender address of account registration-related messages
|
||||||
Devise.mailer_sender = 'noreply@localhost'
|
Devise.mailer_sender = 'noreply@localhost'
|
||||||
|
|
||||||
|
# Whether to skip e-mail confirmation for new registrations is configured
|
||||||
|
# through the web setup wizard and stored in the database (Setting model),
|
||||||
|
# so it does not need to be set here.
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|||||||
@@ -1 +1 @@
|
|||||||
3nm9KZNtyLhPgZBVzOOkN2FXHD0uEMuzgb5Sl1MrAMmi6+iEFSzyTHfZFW2mz18VyNz5DDYvTODZqBDQKK+FQh70uEQkmGqaY5XsTOzUFzk56quaPNtZvFEGux1nX2avSbYQBs3HeyYyWyTAFhez5j8tVb6sZD2xZ8twa9KAB42j86NIHT9w/ZMFqZbGbdBoR1Mrqoy9/IWv2QgxMTpGR6JBpTUwauXm6wS/bTt8SCXF57JSVgvdw/BxFzoA3Xj6N5E89LbMfh54W2ruMhybka5E7zXN9z0v4oXt8GiYZFIODEYZwqzEVaUK1WXS5qb5OrDJFAzs29Uf/gDrIDx71Lot+jejCS+xFfI9454EnHcVH66wKuwF6ylKupJDffM0hQHplcEfVSq5UiDfbPXm46Vr0g1A--2RrmuzCBuHvYpPNA--ugbuRe7ivfDqeUCt6ahciA==
|
OOGMGhfQuV67kqlMecZLcNfgrGS81KPAGmY27GnohtcGSPtiaqL8OZYsVf5IIOaI1K14ZEflln+E2deaIJ5apaq98f+1gJawGbAJeEfLCskJV/03nT8ICpRk+bxT/lzqeCIaUJOLk4708ufC9EpdpJD/jgVSAuI/iNMzzwMbNFvqNmx0Kmgp0mRpHSDGLZZkaP3GW7wdsJEVsNpSPIrkkGL1BvD+nHbmHjuGkn4MMsmm1Yz0M31jkJiDksT0SVeOcxWvOApclxm6VZOAws2l6YKEs/XoE7ye3ssjxdjdwjMzRXV7dwYclNBQGRoERVTozdYiFR4eAGMdlG0RsnUAp+edILH5nvHCIPb3la/dUTOzAQMNY0TqMMVUHGqGuVS/EMCX/w7zrmYN5C+2W8SfugrvTpAL--dUdvsDfbUdVrbmmo--fUwsWUp+DQGPtEF+Zq4ZTw==
|
||||||
@@ -91,7 +91,7 @@ Devise.setup do |config|
|
|||||||
# It will change confirmation, password recovery and other workflows
|
# It will change confirmation, password recovery and other workflows
|
||||||
# to behave the same regardless if the e-mail provided was right or wrong.
|
# to behave the same regardless if the e-mail provided was right or wrong.
|
||||||
# Does not affect registerable.
|
# Does not affect registerable.
|
||||||
config.paranoid = true
|
# config.paranoid = true
|
||||||
|
|
||||||
# By default Devise will store the user in session. You can skip storage for
|
# By default Devise will store the user in session. You can skip storage for
|
||||||
# particular strategies by setting this option.
|
# particular strategies by setting this option.
|
||||||
|
|||||||
@@ -4,15 +4,15 @@ en:
|
|||||||
devise:
|
devise:
|
||||||
confirmations:
|
confirmations:
|
||||||
confirmed: "Your email address has been successfully confirmed."
|
confirmed: "Your email address has been successfully confirmed."
|
||||||
send_paranoid_instructions: >
|
send_instructions: "You will receive an email with instructions for how to confirm your email address in a few minutes."
|
||||||
If your email address is in our database, a message with instructions on how
|
send_paranoid_instructions: "If your email address exists in our database, you will receive an email with instructions for how to confirm your email address in a few minutes."
|
||||||
to confirm your email address has been sent to you.
|
|
||||||
failure:
|
failure:
|
||||||
already_authenticated: "You are already signed in."
|
already_authenticated: "You are already signed in."
|
||||||
inactive: "Your account is not activated yet."
|
inactive: "Your account is not activated yet."
|
||||||
invalid: "Invalid <b>%{authentication_keys}</b> or <b>password</b>."
|
invalid: "Invalid %{authentication_keys} or password."
|
||||||
locked: "Your account is locked."
|
locked: "Your account is locked."
|
||||||
last_attempt: "You have one more attempt before your account is locked."
|
last_attempt: "You have one more attempt before your account is locked."
|
||||||
|
not_found_in_database: "Invalid %{authentication_keys} or password."
|
||||||
timeout: "Your session expired. Please sign in again to continue."
|
timeout: "Your session expired. Please sign in again to continue."
|
||||||
unauthenticated: "You need to sign in or sign up before continuing."
|
unauthenticated: "You need to sign in or sign up before continuing."
|
||||||
unconfirmed: "You have to confirm your email address before continuing."
|
unconfirmed: "You have to confirm your email address before continuing."
|
||||||
@@ -32,9 +32,8 @@ en:
|
|||||||
success: "Successfully authenticated from %{kind} account."
|
success: "Successfully authenticated from %{kind} account."
|
||||||
passwords:
|
passwords:
|
||||||
no_token: "You can't access this page without coming from a password reset email. If you do come from a password reset email, please make sure you used the full URL provided."
|
no_token: "You can't access this page without coming from a password reset email. If you do come from a password reset email, please make sure you used the full URL provided."
|
||||||
send_paranoid_instructions: >
|
send_instructions: "You will receive an email with instructions on how to reset your password in a few minutes."
|
||||||
If your email address is in our database, the password recovery link has been
|
send_paranoid_instructions: "If your email address exists in our database, you will receive a password recovery link at your email address in a few minutes."
|
||||||
sent to you.
|
|
||||||
updated: "Your password has been changed successfully. You are now signed in."
|
updated: "Your password has been changed successfully. You are now signed in."
|
||||||
updated_not_active: "Your password has been changed successfully."
|
updated_not_active: "Your password has been changed successfully."
|
||||||
registrations:
|
registrations:
|
||||||
@@ -51,6 +50,7 @@ en:
|
|||||||
signed_out: "Signed out successfully."
|
signed_out: "Signed out successfully."
|
||||||
already_signed_out: "Signed out successfully."
|
already_signed_out: "Signed out successfully."
|
||||||
unlocks:
|
unlocks:
|
||||||
|
send_instructions: "You will receive an email with instructions for how to unlock your account in a few minutes."
|
||||||
send_paranoid_instructions: "If your account exists, you will receive an email with instructions for how to unlock it in a few minutes."
|
send_paranoid_instructions: "If your account exists, you will receive an email with instructions for how to unlock it in a few minutes."
|
||||||
unlocked: "Your account has been unlocked successfully. Please sign in to continue."
|
unlocked: "Your account has been unlocked successfully. Please sign in to continue."
|
||||||
errors:
|
errors:
|
||||||
|
|||||||
@@ -150,7 +150,7 @@ en:
|
|||||||
edit:
|
edit:
|
||||||
password_html: 'New password:%{password_length_hint_html}'
|
password_html: 'New password:%{password_length_hint_html}'
|
||||||
update_password: Update password
|
update_password: Update password
|
||||||
profiles:
|
registrations:
|
||||||
new:
|
new:
|
||||||
password_html: 'Password:%{password_length_hint_html}'
|
password_html: 'Password:%{password_length_hint_html}'
|
||||||
password_confirmation: 'Retype password:'
|
password_confirmation: 'Retype password:'
|
||||||
@@ -162,13 +162,34 @@ en:
|
|||||||
New password:
|
New password:
|
||||||
<br><em>leave blank to keep unchanged</em>
|
<br><em>leave blank to keep unchanged</em>
|
||||||
%{password_length_hint_html}
|
%{password_length_hint_html}
|
||||||
|
registrations:
|
||||||
|
destroy:
|
||||||
|
sole_admin: You cannot delete the only admin account.
|
||||||
actions: Actions
|
actions: Actions
|
||||||
|
setup:
|
||||||
|
new:
|
||||||
|
admin_account: Admin account
|
||||||
|
admin_email: 'E-mail:'
|
||||||
|
admin_password: 'Password:'
|
||||||
|
admin_password_confirmation: 'Retype password:'
|
||||||
|
options: Options
|
||||||
|
skip_email_confirmation: Skip e-mail confirmation for new registrations
|
||||||
|
seed_units: Seed built-in default units
|
||||||
|
submit: Set up
|
||||||
|
create:
|
||||||
|
email_blank: E-mail cannot be blank.
|
||||||
|
password_blank: Password cannot be blank.
|
||||||
|
password_mismatch: Passwords do not match.
|
||||||
|
success: >
|
||||||
|
Installation complete. You can now sign in with the admin account you
|
||||||
|
just created.
|
||||||
add: Add
|
add: Add
|
||||||
apply: Apply
|
apply: Apply
|
||||||
back: Back
|
back: Back
|
||||||
cancel: Cancel
|
cancel: Cancel
|
||||||
delete: Delete
|
delete: Delete
|
||||||
:no: 'no'
|
:no: 'no'
|
||||||
|
or: or
|
||||||
register: Register
|
register: Register
|
||||||
sign_in: Sign in
|
sign_in: Sign in
|
||||||
recover_password: Recover password
|
recover_password: Recover password
|
||||||
|
|||||||
@@ -1,4 +1,7 @@
|
|||||||
Rails.application.routes.draw do
|
Rails.application.routes.draw do
|
||||||
|
# Web-based installation wizard — only reachable when no admin exists yet.
|
||||||
|
resource :setup, only: [:new, :create], controller: :setup
|
||||||
|
|
||||||
resources :measurements
|
resources :measurements
|
||||||
|
|
||||||
resources :readouts, only: [:new] do
|
resources :readouts, only: [:new] do
|
||||||
@@ -24,9 +27,8 @@ Rails.application.routes.draw do
|
|||||||
# https://github.com/heartcombo/devise/issues/5786
|
# https://github.com/heartcombo/devise/issues/5786
|
||||||
connection = ActiveRecord::Base.connection
|
connection = ActiveRecord::Base.connection
|
||||||
if connection.schema_version && connection.table_exists?(:users)
|
if connection.schema_version && connection.table_exists?(:users)
|
||||||
# NOTE: change helper prefix from *_registration to *_profile once possible
|
|
||||||
devise_for :users, path: '', path_names: {registration: 'profile'},
|
devise_for :users, path: '', path_names: {registration: 'profile'},
|
||||||
controllers: {registrations: 'user/profiles'}
|
controllers: {registrations: :registrations}
|
||||||
end
|
end
|
||||||
|
|
||||||
resources :users, only: [:index, :show, :update] do
|
resources :users, only: [:index, :show, :update] do
|
||||||
@@ -35,7 +37,9 @@ Rails.application.routes.draw do
|
|||||||
end
|
end
|
||||||
|
|
||||||
unauthenticated do
|
unauthenticated do
|
||||||
root to: redirect('/sign_in')
|
as :user do
|
||||||
|
root to: redirect('/sign_in')
|
||||||
|
end
|
||||||
end
|
end
|
||||||
root to: redirect('/units'), as: :user_root
|
root to: redirect('/units'), as: :user_root
|
||||||
|
|
||||||
|
|||||||
12
db/migrate/20260228171524_create_settings.rb
Normal file
12
db/migrate/20260228171524_create_settings.rb
Normal file
@@ -0,0 +1,12 @@
|
|||||||
|
class CreateSettings < ActiveRecord::Migration[7.2]
|
||||||
|
def change
|
||||||
|
create_table :settings do |t|
|
||||||
|
t.string :key, null: false
|
||||||
|
t.string :value
|
||||||
|
|
||||||
|
t.timestamps
|
||||||
|
end
|
||||||
|
|
||||||
|
add_index :settings, :key, unique: true
|
||||||
|
end
|
||||||
|
end
|
||||||
11
db/seeds.rb
11
db/seeds.rb
@@ -3,6 +3,17 @@
|
|||||||
# bin/rails db:seed
|
# bin/rails db:seed
|
||||||
# command (or created alongside the database with db:setup).
|
# command (or created alongside the database with db:setup).
|
||||||
# Seeding process should be idempotent.
|
# Seeding process should be idempotent.
|
||||||
|
#
|
||||||
|
# Admin account setup
|
||||||
|
# -------------------
|
||||||
|
# The preferred way to create the first admin account is through the web setup
|
||||||
|
# wizard, which is shown automatically on the first visit when no admin exists.
|
||||||
|
# The wizard also lets you configure runtime options (e.g. skip e-mail
|
||||||
|
# confirmation) and seed the default units without using the command line.
|
||||||
|
#
|
||||||
|
# The block below provides an alternative CLI path for headless / automated
|
||||||
|
# deployments. It is skipped when an admin account already exists (e.g. after
|
||||||
|
# the web wizard has run).
|
||||||
|
|
||||||
User.transaction do
|
User.transaction do
|
||||||
break if User.find_by status: :admin
|
break if User.find_by status: :admin
|
||||||
|
|||||||
@@ -1,7 +1,6 @@
|
|||||||
require "test_helper"
|
require "test_helper"
|
||||||
|
|
||||||
class ApplicationSystemTestCase < ActionDispatch::SystemTestCase
|
class ApplicationSystemTestCase < ActionDispatch::SystemTestCase
|
||||||
include ActionView::Helpers::SanitizeHelper
|
|
||||||
include ActionView::Helpers::UrlHelper
|
include ActionView::Helpers::UrlHelper
|
||||||
|
|
||||||
# NOTE: geckodriver installed with Firefox, ignore incompatibility warning
|
# NOTE: geckodriver installed with Firefox, ignore incompatibility warning
|
||||||
@@ -33,8 +32,7 @@ class ApplicationSystemTestCase < ActionDispatch::SystemTestCase
|
|||||||
# Allow skipping interpolations when translating for testing purposes
|
# Allow skipping interpolations when translating for testing purposes
|
||||||
INTERPOLATION_PATTERNS = Regexp.union(I18n.config.interpolation_patterns)
|
INTERPOLATION_PATTERNS = Regexp.union(I18n.config.interpolation_patterns)
|
||||||
def translate(key, **options)
|
def translate(key, **options)
|
||||||
translation = options.empty? ? super.split(INTERPOLATION_PATTERNS, 2).first : super
|
options.empty? ? super.split(INTERPOLATION_PATTERNS, 2).first : super
|
||||||
sanitize(translation, tags: [])
|
|
||||||
end
|
end
|
||||||
alias :t :translate
|
alias :t :translate
|
||||||
|
|
||||||
|
|||||||
18
test/controllers/registrations_controller_test.rb
Normal file
18
test/controllers/registrations_controller_test.rb
Normal file
@@ -0,0 +1,18 @@
|
|||||||
|
require "test_helper"
|
||||||
|
|
||||||
|
class RegistrationsControllerTest < ActionDispatch::IntegrationTest
|
||||||
|
test "sole admin cannot delete account" do
|
||||||
|
sign_in users(:admin)
|
||||||
|
delete user_registration_path
|
||||||
|
assert_redirected_to edit_user_registration_path
|
||||||
|
assert_equal t("registrations.destroy.sole_admin"), flash[:alert]
|
||||||
|
assert User.exists?(users(:admin).id)
|
||||||
|
end
|
||||||
|
|
||||||
|
test "non-admin can delete account" do
|
||||||
|
sign_in users(:alice)
|
||||||
|
assert_difference ->{ User.count }, -1 do
|
||||||
|
delete user_registration_path
|
||||||
|
end
|
||||||
|
end
|
||||||
|
end
|
||||||
@@ -5,8 +5,8 @@ class UsersTest < ApplicationSystemTestCase
|
|||||||
@admin = users(:admin)
|
@admin = users(:admin)
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'sign in' do
|
test "sign in" do
|
||||||
visit root_url
|
visit new_user_session_path
|
||||||
assert find_link(href: new_user_session_path)[:disabled]
|
assert find_link(href: new_user_session_path)[:disabled]
|
||||||
|
|
||||||
sign_in
|
sign_in
|
||||||
@@ -14,23 +14,16 @@ class UsersTest < ApplicationSystemTestCase
|
|||||||
assert_text t('devise.sessions.signed_in')
|
assert_text t('devise.sessions.signed_in')
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'sign in fails with invalid credentials' do
|
test 'sign in fails with invalid password' do
|
||||||
label = User.human_attribute_name(:email)
|
sign_in password: random_password
|
||||||
# Both: valid and invalid emails should give the same (paranoid) error message.
|
|
||||||
email = [users.sample.email, random_email].sample
|
|
||||||
|
|
||||||
visit root_url
|
|
||||||
fill_in label, with: email
|
|
||||||
fill_in User.human_attribute_name(:password), with: random_password
|
|
||||||
click_on t(:sign_in)
|
|
||||||
|
|
||||||
assert_current_path new_user_session_path
|
assert_current_path new_user_session_path
|
||||||
assert_text t('devise.failure.invalid', authentication_keys: label.downcase_first)
|
assert_text t('devise.failure.not_found_in_database',
|
||||||
|
authentication_keys: User.human_attribute_name(:email))
|
||||||
assert find_link(href: new_user_session_path)[:disabled]
|
assert find_link(href: new_user_session_path)[:disabled]
|
||||||
assert has_field?(label, with: email)
|
assert_not_empty find_field(User.human_attribute_name(:email)).value
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'sign out' do
|
test "sign out" do
|
||||||
sign_in
|
sign_in
|
||||||
visit root_url
|
visit root_url
|
||||||
click_on t("layouts.application.sign_out")
|
click_on t("layouts.application.sign_out")
|
||||||
@@ -38,106 +31,79 @@ class UsersTest < ApplicationSystemTestCase
|
|||||||
assert_text t("devise.sessions.signed_out")
|
assert_text t("devise.sessions.signed_out")
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'recover password' do
|
test "recover password" do
|
||||||
label = User.human_attribute_name(:email)
|
visit new_user_session_url
|
||||||
email = users.select(&:confirmed?).sample.email
|
click_on t(:recover_password)
|
||||||
|
|
||||||
visit root_url
|
|
||||||
fill_in label, with: email
|
|
||||||
# Form validations should allow empty password.
|
|
||||||
assert has_field?(User.human_attribute_name(:password), with: nil)
|
|
||||||
|
|
||||||
|
fill_in User.human_attribute_name(:email),
|
||||||
|
with: users.select(&:confirmed?).sample.email
|
||||||
assert_emails 1 do
|
assert_emails 1 do
|
||||||
click_on t(:recover_password)
|
click_on t(:recover_password)
|
||||||
|
# Wait until redirected to make sure async request has been processed
|
||||||
assert_current_path new_user_session_path
|
assert_current_path new_user_session_path
|
||||||
# Wait for flash message to make sure async request has been processed.
|
|
||||||
assert_text t("devise.passwords.send_paranoid_instructions")
|
|
||||||
end
|
end
|
||||||
assert has_field?(label, with: email)
|
assert_text t("devise.passwords.send_instructions")
|
||||||
|
|
||||||
with_last_email do |mail|
|
with_last_email do |mail|
|
||||||
visit Capybara.string(mail.body.to_s).find_link("Change my password")[:href]
|
visit Capybara.string(mail.body.to_s).find_link("Change my password")[:href]
|
||||||
assert_current_path edit_user_password_path, ignore_query: true
|
|
||||||
# Make sure flash message is not displayed twice.
|
|
||||||
assert_no_text t("devise.passwords.send_paranoid_instructions")
|
|
||||||
end
|
end
|
||||||
new_password = random_password
|
new_password = random_password
|
||||||
fill_in t("users.passwords.edit.password_html"), with: new_password
|
fill_in t("users.passwords.edit.password_html"), with: new_password
|
||||||
fill_in t("helpers.label.user.password_confirmation"), with: new_password
|
fill_in t("helpers.label.user.password_confirmation"), with: new_password
|
||||||
assert_emails 1 do
|
assert_emails 1 do
|
||||||
click_on t("users.passwords.edit.update_password")
|
click_on t("users.passwords.edit.update_password")
|
||||||
|
# Wait until redirected to make sure async request has been processed
|
||||||
assert_current_path units_path
|
assert_current_path units_path
|
||||||
assert_text t("devise.passwords.updated")
|
|
||||||
end
|
end
|
||||||
|
assert_text t("devise.passwords.updated")
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'recover password for nonexistent user' do
|
test "register" do
|
||||||
label = User.human_attribute_name(:email)
|
visit new_user_session_url
|
||||||
email = random_email
|
|
||||||
|
|
||||||
visit root_url
|
|
||||||
fill_in label, with: email
|
|
||||||
|
|
||||||
assert_no_emails do
|
|
||||||
click_on t(:recover_password)
|
|
||||||
assert_current_path new_user_session_path
|
|
||||||
assert_text t("devise.passwords.send_paranoid_instructions")
|
|
||||||
end
|
|
||||||
end
|
|
||||||
|
|
||||||
test 'register' do
|
|
||||||
visit root_url
|
|
||||||
click_on t(:register)
|
click_on t(:register)
|
||||||
assert find_link(href: new_user_registration_path)[:disabled]
|
|
||||||
|
|
||||||
fill_in User.human_attribute_name(:email), with: random_email
|
fill_in User.human_attribute_name(:email), with: random_email
|
||||||
password = random_password
|
password = random_password
|
||||||
fill_in User.human_attribute_name(:password), with: password
|
fill_in User.human_attribute_name(:password), with: password
|
||||||
fill_in t("users.profiles.new.password_confirmation"), with: password
|
fill_in t("users.registrations.new.password_confirmation"), with: password
|
||||||
assert_difference ->{ User.count }, 1 do
|
assert_difference ->{User.count}, 1 do
|
||||||
assert_emails 1 do
|
assert_emails 1 do
|
||||||
click_on t(:register)
|
click_on t(:register)
|
||||||
|
# Wait until redirected to make sure async request has been processed
|
||||||
assert_current_path new_user_session_path
|
assert_current_path new_user_session_path
|
||||||
assert_text t("devise.registrations.signed_up_but_unconfirmed")
|
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
assert_text t("devise.registrations.signed_up_but_unconfirmed")
|
||||||
|
|
||||||
assert_changes ->{ User.last.confirmed? }, from: false, to: true do
|
with_last_email do |mail|
|
||||||
with_last_email do |mail|
|
visit Capybara.string(mail.body.to_s).find_link("Confirm my account")[:href]
|
||||||
visit Capybara.string(mail.body.to_s).find_link("Confirm my account")[:href]
|
|
||||||
assert_current_path new_user_session_path
|
|
||||||
assert_text t("devise.confirmations.confirmed")
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
|
assert_current_path new_user_session_path
|
||||||
|
assert_text t("devise.confirmations.confirmed")
|
||||||
|
assert User.last.confirmed?
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'resend confirmation' do
|
test "resend confirmation" do
|
||||||
label = User.human_attribute_name(:email)
|
visit new_user_session_url
|
||||||
user = users.reject(&:confirmed?).sample
|
|
||||||
|
|
||||||
visit root_url
|
|
||||||
click_on t(:register)
|
click_on t(:register)
|
||||||
fill_in label, with: user.email
|
click_on t(:resend_confirmation)
|
||||||
assert has_field?(User.human_attribute_name(:password), with: nil)
|
|
||||||
|
|
||||||
|
fill_in User.human_attribute_name(:email),
|
||||||
|
with: users.reject(&:confirmed?).sample.email
|
||||||
assert_emails 1 do
|
assert_emails 1 do
|
||||||
click_on t(:resend_confirmation)
|
click_on t(:resend_confirmation)
|
||||||
assert_current_path new_user_registration_path
|
# Wait until redirected to make sure async request has been processed
|
||||||
assert_text t("devise.confirmations.send_paranoid_instructions")
|
assert_current_path new_user_session_path
|
||||||
end
|
end
|
||||||
assert has_field?(label, with: user.email)
|
assert_current_path new_user_session_path
|
||||||
|
assert_text t("devise.confirmations.send_instructions")
|
||||||
|
|
||||||
assert_changes ->{ user.reload.confirmed? }, from: false, to: true do
|
with_last_email do |mail|
|
||||||
with_last_email do |mail|
|
visit Capybara.string(mail.body.to_s).find_link("Confirm my account")[:href]
|
||||||
visit Capybara.string(mail.body.to_s).find_link("Confirm my account")[:href]
|
|
||||||
assert_current_path new_user_session_path
|
|
||||||
assert_no_text t("devise.confirmations.send_paranoid_instructions")
|
|
||||||
assert_text t("devise.confirmations.confirmed")
|
|
||||||
end
|
|
||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'show profile' do
|
test "show profile" do
|
||||||
sign_in user: users.select(&:admin?).select(&:confirmed?).sample
|
sign_in user: users.select(&:admin?).select(&:confirmed?).sample
|
||||||
click_on t("users.navigation")
|
click_on t("users.navigation")
|
||||||
within all('tr').drop(1).sample do |tr|
|
within all('tr').drop(1).sample do |tr|
|
||||||
@@ -147,7 +113,7 @@ class UsersTest < ApplicationSystemTestCase
|
|||||||
end
|
end
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'disguise' do
|
test "disguise" do
|
||||||
user = users.select(&:admin?).select(&:confirmed?).sample
|
user = users.select(&:admin?).select(&:confirmed?).sample
|
||||||
sign_in user: user
|
sign_in user: user
|
||||||
|
|
||||||
@@ -163,7 +129,7 @@ class UsersTest < ApplicationSystemTestCase
|
|||||||
assert_link user.email
|
assert_link user.email
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'disguise fails for admin when disallowed' do
|
test "disguise fails for admin when disallowed" do
|
||||||
user = users.select(&:admin?).select(&:confirmed?).sample
|
user = users.select(&:admin?).select(&:confirmed?).sample
|
||||||
sign_in user: user
|
sign_in user: user
|
||||||
|
|
||||||
@@ -176,37 +142,45 @@ class UsersTest < ApplicationSystemTestCase
|
|||||||
assert_title 'The change you wanted was rejected (422)'
|
assert_title 'The change you wanted was rejected (422)'
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'disguise forbidden for non admin' do
|
test "disguise forbidden for non admin" do
|
||||||
sign_in user: users.reject(&:admin?).select(&:confirmed?).sample
|
sign_in user: users.reject(&:admin?).select(&:confirmed?).sample
|
||||||
visit disguise_user_path(User.all.sample)
|
visit disguise_user_path(User.all.sample)
|
||||||
assert_title 'Access is forbidden to this page (403)'
|
assert_title 'Access is forbidden to this page (403)'
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'delete profile' do
|
test "delete profile" do
|
||||||
user = sign_in
|
user = sign_in user: users.reject(&:admin?).select(&:confirmed?).sample
|
||||||
# TODO: remove condition after root_url changed to different path than
|
# TODO: remove condition after root_url changed to different path than
|
||||||
# profile in routes.rb
|
# profile in routes.rb
|
||||||
unless has_current_path?(edit_user_registration_path)
|
unless has_current_path?(edit_user_registration_path)
|
||||||
first(:link_or_button, user.email).click
|
first(:link_or_button, user.email).click
|
||||||
end
|
end
|
||||||
assert_difference ->{ User.count }, -1 do
|
assert_difference ->{ User.count }, -1 do
|
||||||
accept_confirm { click_on t("users.profiles.edit.delete") }
|
accept_confirm { click_on t("users.registrations.edit.delete") }
|
||||||
assert_current_path new_user_session_path
|
assert_current_path new_user_session_path
|
||||||
end
|
end
|
||||||
assert_text t("devise.registrations.destroyed")
|
assert_text t("devise.registrations.destroyed")
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'index forbidden for non admin' do
|
test "sole admin cannot delete profile" do
|
||||||
|
sign_in user: users(:admin)
|
||||||
|
unless has_current_path?(edit_user_registration_path)
|
||||||
|
first(:link_or_button, users(:admin).email).click
|
||||||
|
end
|
||||||
|
assert find(:button, t("users.registrations.edit.delete"))[:disabled]
|
||||||
|
end
|
||||||
|
|
||||||
|
test "index forbidden for non admin" do
|
||||||
sign_in user: users.reject(&:admin?).select(&:confirmed?).sample
|
sign_in user: users.reject(&:admin?).select(&:confirmed?).sample
|
||||||
visit users_path
|
visit users_path
|
||||||
assert_title "Access is forbidden to this page (403)"
|
assert_title "Access is forbidden to this page (403)"
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'update profile' do
|
test "update profile" do
|
||||||
# TODO
|
# TODO
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'update status' do
|
test "update status" do
|
||||||
sign_in user: users.select(&:admin?).select(&:confirmed?).sample
|
sign_in user: users.select(&:admin?).select(&:confirmed?).sample
|
||||||
visit users_path
|
visit users_path
|
||||||
|
|
||||||
@@ -221,7 +195,7 @@ class UsersTest < ApplicationSystemTestCase
|
|||||||
assert_current_path users_path
|
assert_current_path users_path
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'update status fails for admin when disallowed' do
|
test "update status fails for admin when disallowed" do
|
||||||
sign_in user: users.select(&:admin?).select(&:confirmed?).sample
|
sign_in user: users.select(&:admin?).select(&:confirmed?).sample
|
||||||
visit users_path
|
visit users_path
|
||||||
|
|
||||||
@@ -234,7 +208,7 @@ class UsersTest < ApplicationSystemTestCase
|
|||||||
assert_title 'The change you wanted was rejected (422)'
|
assert_title 'The change you wanted was rejected (422)'
|
||||||
end
|
end
|
||||||
|
|
||||||
test 'update status forbidden for non admin' do
|
test "update status forbidden for non admin" do
|
||||||
sign_in user: users.reject(&:admin?).select(&:confirmed?).sample
|
sign_in user: users.reject(&:admin?).select(&:confirmed?).sample
|
||||||
visit units_path
|
visit units_path
|
||||||
inject_button_to find('body'), "update status", user_path(User.all.sample), method: :patch,
|
inject_button_to find('body'), "update status", user_path(User.all.sample), method: :patch,
|
||||||
|
|||||||
Reference in New Issue
Block a user