Conversation
… target pages A salt is consumed on use, and these pages post a dialog with AJAX and then post the page form again with the same salt, so the second post was refused. Copy the salt issued with each AJAX response into the page's forms. Also stop the blogroll selector from submitting on mouseup, which reloaded the page as soon as the list was opened.
…ponse The page returned for a refused blogroll save has no forms, so the salt is now also issued in a roller-salt meta tag on every UI page. The blogroll dialogs looked for the bookmark duplicate-name message, so a refused blogroll name was treated as a success; they now show the action errors in the response. jQuery 3 has no .error(), so use .fail().
FolderEdit set folderId only when adding, but always read it for the folderId response header, so every rename threw after the folder was saved and the action returned INPUT with a system error. Use the saved folder's id.
The dialogs looked only for a duplicate-name message, so any other refusal (a malformed ping URL, for example) closed the dialog as if the save had worked. Show the action errors in the response instead.
Lay out both rows with the same label and control columns, and keep the rename buttons on the name field's line with flexbox instead of floats. Show the folder name with s:property; s:text looked it up as a message key and logged a warning on every page view.
- A named collection such as /resources/default was looked up as "default/", found nothing, and threw a NullPointerException, so the collection the service document advertises could not be listed. - Media posted with no Slug header and no title threw in replaceNonAlphanumeric(); createFileName() already names such files by date. - Media posted to /resources had no directory name and threw; it now goes to the default directory. An unknown directory answers 404. - The temporary upload file used the client's file name as its prefix, which createTempFile() refuses below three characters. Use a random prefix, as putMedia() does.
This was referenced Oct 4, 2026
Contributor
Author
|
Manually tested on the 6.1.7 integration build (Tomcat 9, JDK 11, MySQL 8). Pass.
|
On a new site the planet.site.* properties do not exist until Planet Config is saved. PlanetRuntimeConfig.getProperty() then threw, logged a warning with a stack trace and returned null, and the Planet feed printed $utils.escapeXML($siteName) as its title and description. Return the default from the Planet config definitions for a property that has not been saved, and pass empty strings to the feed template.
Summernote 0.8.12 inserts a pasted image file itself but does not cancel the paste, so the browser also inserted the clipboard's HTML copy of the image. Cancel the browser's paste when Summernote handles an image file.
The float settings (maximum upload file and directory size, in MB) were rendered as number inputs with the default step of 1, so browsers refused values such as 0.5 or 2.5. Use step="any".
Contributor
Author
|
Follow-up testing on the 6.1.7 integration build. Pass.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR collects general bug fixes found during manual testing of a local 6.1.7 integration branch. That branch combined
roller-6.1.xwith the open 6.1.7 PRs (#198, #199, #200, #205) and was run on Tomcat 9, JDK 11 and MySQL 8. Most of the bugs are much older than 6.1.7; none were introduced by those PRs. Each fix is a separate commit.Blogroll, category and ping target dialogs
Each Roller page carries one form salt, shared by all of its forms, and a salt can be used only once. These pages save a dialog with AJAX and then post the page form again. The second post sent the salt the AJAX request had already used, so it was refused and the user got an error page. A retry after an error in the dialog failed the same way.
Salt for AJAX responses.
head.jspnow issues the response's salt in aroller-saltmeta tag on every UI page. The newrefreshSalt(html)intheme/scripts/roller.jsreads it from an AJAX response (parsed withDOMParser, so no scripts run) and copies it into everysaltfield on the page. It is called first in each AJAXdonehandler:Bookmarks.jsp: rename blogroll, add blogroll, save bookmarkCategories.jsp: save categoryPingTargets.jsp: save ping targetThe meta tag is needed because some error responses, such as a refused blogroll save, have no forms.
Dialogs show why a save was refused. They looked only for a duplicate-name message, so any other refusal, such as a malformed ping URL, closed the dialog as if the save had worked. The add and rename blogroll dialogs looked for the bookmark message, while
FolderEditreportsfolderForm.error.duplicateName, so a refused blogroll name was posted on and ended on an error page. All five dialogs now show the action errors in the response, read with the newactionErrors(html).Renaming a blogroll threw a
NullPointerException(since 2181cb7, 2021).FolderEdit.save()readsfolderIdfor thefolderIdresponse header, butfolderIdis set only when adding. The rename was saved first, so it worked but reported "System error - check logs". The header now uses the saved folder's id.jQuery 3 has no
.error(). The five AJAX calls used.error(...), which threw, so their failure handlers never ran. They now use.fail(...)."Switch to blogroll" no longer submits on
mouseup. Chrome firesmouseupwhen the list opens, so the page reloaded before a blogroll could be picked.onchangeis kept.Blogroll page layout. The "Blogroll name" and "Switch to blogroll" rows now use the same label and control columns. The rename buttons sit on the name field's line, using flexbox instead of floats. The folder name is shown with
s:property;s:texttreated it as a message key and logged a warning on every page view.AtomPub media collections
These bugs date from 2013 and are in
MediaCollection:getCollection()added a path separator to the directory name, so the lookup asked fordefault/, found nothing and threw aNullPointerException. This affectedGET /roller-services/app/<blog>/resources/default, the URL in the service document. The name is now looked up as is, and an unknown directory answers 404.Slugor title threw inreplaceNonAlphanumeric(null). The name is now left null, andcreateFileName()names the file by date./resourceshad no directory name and threw. It now uses the default directory, and an unknown directory answers 404.postMedia()used the client's file name as thecreateTempFile()prefix, andcreateTempFile()refuses a prefix shorter than three characters. It now uses a random prefix, asputMedia()already does.Planet feed before Planet Config is saved
On a new site, the
planet.site.*properties don't exist until Planet Config is saved.PlanetRuntimeConfig.getProperty()then threw, logged a warning and returned null, so/planetrssprinted$utils.escapeXML($siteName)as its title and description. A setting that hasn't been saved now returns its default fromplanetRuntimeConfigDefs.xml, andPlanetFeedServletpasses empty strings in place of nulls.Pasted images appeared twice
Summernote 0.8.12's
pasteByEventinserts a pasted image file itself but never callspreventDefault(). So when the clipboard holds both HTML and an image file, as after "Copy Image" in a browser, the browser also pasted the HTML<img>, and each paste produced two images.EntryEditor.jspnow has anonPastecallback that cancels the browser's paste whenever Summernote handles an image file, using the same clipboard item Summernote picks.Decimal values on the configuration page
The maximum upload file and directory sizes are in megabytes with decimals (default
2.00), but they were number inputs with the default step of 1, so browsers refused values such as 0.5.GlobalConfig.jspnow usesstep="any".Testing
mvn -pl app clean teston JDK 11: 342 tests, 0 failures, 1 skipped.New
PlanetRuntimeConfigTest(3 tests): a saved setting is returned, a setting that hasn't been saved falls back to its default, and an unknown setting is null. The fallback test fails on the old code.New
MediaCollectionPathTest(5 tests): a named collection is looked up by its name; an unknown collection or directory is not found; a post to/resourcesuses the default directory; a post with no name is named by date. All 5 fail on the old code.New
FolderEditSaveTest(2 tests): renaming saves the folder and sends its id, and adding sends the new id. The rename test fails without the fix (expected <success> but was <input>).Manual, on the 6.1.7 integration build (Chrome, Tomcat 9, MySQL 8). These all work:
httpsURL is refused with "The URL is not properly formed.", and a retry with anhttpURL saves.GET /resources/defaultlists the media files; media POSTs with noSlugor title, to/resources, and with a shortSlugall return 201.<img>tags.uploads.file.maxsizecan be set to 0.30.No "Security Violation" was logged after the fix.
Not changed here: ping target URLs must be
http.JPAPingTargetManagerImpl.isUrlWellFormedrefuseshttps.Still to check by hand: picking a blogroll from "Switch to blogroll".
Targets
roller-6.1.xfor 6.1.7. It will be cherry-picked tomasterafter the 6.1.7 release.