fix(web-ui): MQTT password without TLS, Overview poll that never stopped, brightness slider error, token form left dirty - #745
Merged
Conversation
PUT /api/v3/integrations/mqtt-bridge/config refuses a stored password while mqtt_tls is off unless allow_insecure_mqtt is set (the CWE-319 guard in api_v3/misc.py). The Tools tab form neither rendered a control for that flag nor sent it, so a password-protected broker on a LAN without TLS could never be saved from the UI, and once such a password was in bridge_config.json every later save from the form was refused. The form now shows "Allow without TLS (trusted network)" while "Use TLS" is unchecked, prefilled from the GET's config.allow_insecure_mqtt, and mqttBody() sends its state as allow_insecure_mqtt. The box is off until the user ticks it, so the server's guard still refuses a cleartext password by default. Tests: the Tools DOM suite checks the control, its show/hide with the TLS box, the prefill and the value saved; a Flask test pins that the GET reports the opt-in (false until saved on). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The reconciliation banner script in partials/overview.html re-asked /api/v3/plugins/reconciliation-status every 2 s until the answer said done, with no limit. The route answers done: false whenever ledmatrix_reconciliation.json is missing or unreadable, which happens when _run_startup_reconciliation raises before writing it or when /tmp is cleaned under a long-running web service (reconciliation runs once per process). The browser then sent that request every 2 s for as long as the page stayed open, on every tab, since the poll was never tied to the Overview being visible. The poll now gives up after 30 tries (a minute) and runs only while the Overview is the active, visible tab, registered with LEDVisibility under its own key like the other partials' pollers. Dismissing the banner ends it too. Test: test/js/unit/test_overview_reconciliation_poll.js runs the shipped script in a vm with fake timers and fetch. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The brightness slider's input handler in partials/display.html set the text of both #brightness-value and #brightness-display. #387 (978a03b) removed the "LED brightness: N%" line that carried #brightness-display, so getElementById returned null and every step of the slider threw "Cannot set properties of null" into the console. The visible label still updated, because it is written first. The dead lookup is removed. Test: test/js/unit/test_display_partial_ids.js checks every literal getElementById() in the partial's inline scripts against the ids its markup renders, and runs the shipped script in a vm to move the slider. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
app.js marks a form data-dirty on any input inside it and removes the mark only after a successful htmx request; its beforeunload handler asks "Leave site?" while a visible form is still dirty. The API token form in partials/general.html posts through window.webLogin.createToken with fetch, so the mark survived the token being created and a reload of the page with the General tab open prompted about a change that had already been saved. createToken now removes data-dirty after a successful create, next to the form.reset() it already did. A refused request keeps the mark. Test: test/js/unit/test_general_web_login_token.js runs the shipped script in a vm with a fake fetch and DOM. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Contributor
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 12 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (12)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Up to standards ✅🟢 Issues
|
The three new suites pull the inline scripts out of their partials with /<script>([\s\S]*?)<\/script>/g. CodeQL flags that shape as a bad HTML filtering regexp (js/bad-tag-filter: misses upper case and tags with attributes or whitespace), four high alerts that blocked the PR. These are our own templates read by tests, not user input, but the stricter pattern costs nothing: /<script\b[^>]*>(...)<\/script[^>]*>/gi, as test_html_escaping.js already uses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
CodeQL read the script-stripping replace() as an incomplete HTML sanitizer (js/incomplete-multi-character-sanitization). The test only reads our own template, but slicing between the matched blocks gives the same markup without the pattern. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Four front-end fixes, one commit each.
allow_insecure_mqttis set, and the form had no way to set it. Once a password was stored without TLS, every later save failed, even a log-level change./plugins/reconciliation-statusevery 2 s forever when the status file was missing (reconciliation raised, or/tmpwas cleaned).LEDVisibility, under its own key).Not fixed, needs an owner decision
scripts/install/lib_sudoers.shonly allowssystemctlforledmatrixandledmatrix-web, and the install script needssudo teeanddaemon-reload.ledmatrix-mqtt-bridge.service;Tests
test_overview_reconciliation_poll.js,test_display_partial_ids.js,test_general_web_login_token.js. Also an extendeddom/test_tools_sections.jsand a Flask test for the MQTT GET.REQUIRE_DOM=1 node test/js/run_all.jsagainst the live emulator web UI: 26 of 26 suites, all 9 DOM suites included.Part of a bug sweep
This is one of 10 independent fix PRs from one sweep, all based on
mainef69201.main: the same 62 failures and 6 errors on both. These are the known Windows path and file-locking tests. 191 more tests pass.test_backup_manager.py::test_create_backup_contents(os.replace→WinError 5on a temp zip), was a Windows file-lock flake. It passes on rerun, and nothing here touchescreate_backup.main, with a clean start and no errors or render stalls in the journal. ledpi is back on plainmain.🤖 Generated with Claude Code