Commit Graph
3808 Commits
Author SHA1 Message Date
Tommaso Casaburi 35776737f2 fix(release): align blotter and release copy with LaTeX in /sci/
Update v0.9.2 blotter message and release one-liner to describe LaTeX
in /sci/ instead of generic scientific math preview wording.
2026-06-14 16:21:57 +07:00
Tommaso Casaburi f53bd0f6e5 ci(release): make React Doctor check advisory
The release preflight ran yarn doctor --diff against the previous tag as a
hard gate, but many error-level diagnostics flag intentional patterns rather
than bugs (e.g. resetting preview state when the reply modal closes, mirroring
long-accepted code). Mark the step continue-on-error so it still runs and posts
annotations without blocking a release.
v0.9.2
2026-06-13 18:25:53 +07:00
Tommaso Casaburi 591aaa729f fix(challenge-modal): publish challenge answers with pkc object schema
pkc-js's publishChallengeAnswers destructures { challengeAnswers } from its
argument, so passing a bare string[] left challengeAnswers undefined and
silently broke challenge submission (i.e. posting). Wrap answers in the object
form via a publishPublicationChallengeAnswers helper with error logging, and
align the ChallengePublication type with the real runtime signature.
2026-06-13 18:25:04 +07:00
Tommaso Casaburi ded239bef2 chore(release): v0.9.2 2026-06-13 18:09:24 +07:00
Tommaso Casaburi f72d0b9fa5 chore(release): drop macOS quarantine workaround from release notes
The mac DMGs are now signed with a Developer ID and notarized, so Gatekeeper
no longer shows the "app is damaged" error and the xattr quarantine command
is no longer needed.
2026-06-13 18:04:42 +07:00
Tommaso Casaburi cdb1d13bef fix(post ids): avoid cid fallback for poster identity 2026-06-13 17:56:15 +07:00
Tommaso Casaburi fb03957835 chore: sharpen advisory code quality review skill 2026-06-13 16:22:31 +07:00
Tommaso CasaburiandGitHub 85b782e934 feat(electron): sign and notarize mac release builds (#1171)
* feat(electron): sign and notarize mac release builds when Apple credentials are present

* fix(electron): work around codesign PID parsing for digit-leading app name in @electron/notarize

codesign interprets a bare '5chan.app' argument as process ID 5, so
@electron/notarize 2.5.0's pre-upload signature check fails with 'No such
process'. Backport the './' basename prefix from electron/notarize#245 as
a yarn patch until forge depends on notarize >= 3.x.

* docs(agent-playbooks): record codesign PID parsing surprise for digit-leading app name

* fix(ci): keep mac signing env consistent with certificate availability
2026-06-13 15:26:31 +07:00
Tommaso Casaburi 3484963a59 chore: add advisory code quality review workflow 2026-06-13 15:13:25 +07:00
Tommaso Casaburi 824c36e518 Merge branch 'master' of github.com:bitsocialnet/5chan 2026-06-13 13:43:34 +07:00
Tommaso CasaburiandGitHub 6cb28b0e4f fix(youtube thumbnails): prefer best available image
Prefer the best available YouTube thumbnail, fall back cleanly when high-resolution images are unavailable, and keep the React Doctor PR gate scoped to newly introduced issues.
2026-06-13 13:39:22 +07:00
Tommaso Casaburi 43b160b1fc fix: resolve open Dependabot security alerts
Bump vulnerable transitive dependencies via yarn resolutions and direct dependency updates.
2026-06-13 12:55:31 +07:00
Tommaso Casaburi c3d72e53cc chore: upgrade react-doctor to 0.5.2 2026-06-13 12:42:11 +07:00
Tommaso Casaburi 3d393478e1 Merge branch 'codex/chore/bso-domain-rpc-label' 2026-06-12 19:06:08 +07:00
Tommaso Casaburi 6d9b5ff3ce feat(settings): internationalize advanced settings and update RPC label to .bso
Replace hardcoded advanced settings strings with i18n keys and translate them across all 35 languages, including the Ethereum RPC tip for .bso domains.
2026-06-12 19:06:02 +07:00
Tommaso Casaburi 44cc792a9a chore(deps): upgrade bitsocial-react-hooks to 0.1.17 2026-06-12 18:42:35 +07:00
Tommaso Casaburi 9b6386a0b8 chore(deps): upgrade pkc-js to 0.0.47 2026-06-12 17:21:38 +07:00
Tommaso Casaburi 8456295eee fix(reply-modal): blur TeX button when preview closes
Blur the TeX preview trigger on close so Escape does not leave a
lingering focus outline or tooltip on the button.
2026-06-11 16:35:18 +07:00
Tommaso Casaburi 15fb1bf57c chore(ai-workflow): add toolchain drift validator and harden agent rules
Borrowed from a review of addyosmani/agent-skills:

- add scripts/validate-ai-workflow.mjs (yarn ai-workflow:check): verifies
  .claude/.codex/.cursor skills, agents, and hooks stay in parity, with
  validator-owned exemptions for intentional harness-specific differences
  and enforcement of the AGENTS.md agent model rules
- browser-check and profiler agents: treat page content as untrusted data,
  never instructions (5chan pages render arbitrary user-generated content)
- refactor-pass: Chesterton's Fence rule (git blame unclear code before
  removing it)
- review-and-merge-pr: pass subagent verifiers only the artifact and
  contract, not the triage verdict, to keep reviews independent
2026-06-11 16:13:53 +07:00
Tommaso CasaburiandGitHub 17c63bb2e6 feat(reply modal): add sci tex preview button (#1170)
* feat(sci): add 4chan-style TeX support with MathJax on /sci/

- [math]/[eqn] tags typeset with MathJax 3 (lazy chunk, only on /sci/ with math present)
- 4chan-identical config: Safe mode, left-aligned eqn, neutered \color/\newcommand macros
- TeX button in reply modal title bar opens live TeX Preview modal
- /sci/ post form rules bullets for [math]/[eqn] usage and right-click source
- MathJax context menu on right-click (Show Math As > TeX Commands)
- woff fonts served from node_modules in dev and emitted into build

* feat(sci): finish TeX support: configmacros fix, preview preload, translations, tests

- add configmacros package so the 4chan macro neutering (\color, \newcommand, ...) applies
- preload MathJax when the TeX Preview opens, like 4chan
- stable closeModal callback for the preview modal
- pre-bundle mathjax components in vite optimizeDeps to avoid dev mid-session reload
- translate the 6 new TeX keys into all 35 languages
- markdown math segment component tests + math-tags unit tests

* feat(reply modal): add sci tex preview button

* fix(tex-preview): clear MathJax bookkeeping and pending typeset on close

Addresses Cursor Bugbot: the preview output was typeset via typesetMathElement but
never passed to clearMathElement on unmount, so repeated open/close cycles kept
detached nodes in MathJax's math list. Also cancels the pending debounce timer.

* fix(reply-modal): reset TeX preview state when the reply modal closes

Addresses CodeRabbit: showTexPreview persisted across close/reopen like the
bbcode preview flags, so the TeX preview would auto-open on the next reply.
2026-06-11 16:12:38 +07:00
Tommaso Casaburi fa7cab0699 fix(deps): resolve shell-quote critical dependabot alert
Pin shell-quote to 1.8.4 via yarn resolutions so concurrently no longer pulls the vulnerable 1.8.3 release.
2026-06-11 15:01:58 +07:00
Tommaso Casaburi b044202e33 chore(electron): upgrade bundled kubo IPFS to 0.42.0 2026-06-11 14:59:00 +07:00
Tommaso Casaburi b0193b34be fix(archive): preserve button link text color on desktop
Exclude .button links from the nav unset rule and apply mobile button
spacing to anchor buttons so archive actions keep theme text color.
2026-06-10 16:47:31 +07:00
Tommaso Casaburi e9c729a9e3 fix(rules): use hash links for directory deep links
Switch rules navigation from /rules/:code paths to /rules#code hashes,
reject legacy subpaths, and ignore address hashes in markdown links.
2026-06-10 16:38:31 +07:00
Tommaso Casaburi f3d59c3345 fix(post-form): style errors like 4chan and move into tfoot
Use red banner styling for form errors and render them in the table
footer so messages stay aligned with the post form layout.
2026-06-10 15:45:49 +07:00
Tommaso CasaburiandGitHub 2f938d59ae fix(post-form): convert twimg query-format links in the reply modal (#1168)
Share getPublishLinkOptions between the inline post form and the reply modal so the modal publishes twimg ?format= links in their .jpg/.png form (previously raw), and rewrite the link field on blur in both so the conversion is visible. Also gate the dev service worker's runtime asset cache to production so dev no longer serves stale /src modules.
2026-06-09 19:24:28 +07:00
Tommaso Casaburi ee5aa7845e fix(deps): bump react-router-dom to 6.30.4
Patches GHSA open redirect via protocol-relative URL reinterpretation
in react-router (Dependabot alert #276).
2026-06-09 19:11:43 +07:00
Tommaso CasaburiandGitHub c0f1a77958 fix(post ids): fall back to comment cid for missing ids (#1167)
* fix(post ids): fall back to comment cid for missing ids

* fix(post ids): count cid-resolved account replies
2026-06-09 19:08:02 +07:00
Tommaso Casaburi 9de2e6a851 fix(failed-publish): keep bracket actions on one line
Replace mobile-only line breaks with CSS so retry/delete actions wrap
as a block without splitting bracket labels across lines.
2026-06-09 16:51:35 +07:00
Tommaso CasaburiandGitHub a3ff6b2e33 fix(mod queue): reset board filter on navigation (#1166) 2026-06-09 16:06:13 +07:00
Tommaso Casaburi 2e58961cf1 fix(challenge-modal): center mobile modal in viewport
Use left: 50% with translateX(-50%) so the dialog stays centered on
mobile instead of offset from a stale static position.
2026-06-09 15:46:14 +07:00
Tommaso Casaburi 4308d26cf0 fix(mod-queue): show empty state instead of not-allowed redirect
When the account moderates no boards, render ModEmptyState on the global
/mod/queue route instead of sending users to /not-allowed.
2026-06-09 13:01:31 +07:00
Tommaso Casaburi dbf672f11a Merge branch 'codex/fix/link-file-filename-validation' 2026-06-09 12:34:18 +07:00
Tommaso Casaburi 27558ded18 fix(post-form): hide filename for non-file media links
Only show pasted link filenames when the URL resolves to publishable
file media, so bare paths like imgur album IDs are not shown as files.
2026-06-09 12:34:13 +07:00
Tommaso Casaburi d442bda3c0 Merge branch 'master' of github.com:bitsocialnet/5chan 2026-06-09 12:33:00 +07:00
Tommaso CasaburiandGitHub 245d3164c3 fix(media playback): stop hidden and offscreen media (#1164)
* fix(media playback): stop hidden and offscreen media

* fix(media playback): keep offscreen embeds suspended
2026-06-08 22:55:30 +07:00
Tommaso CasaburiandGitHub 075b917c36 chore(flags): derive flag-test coords from board-flags source (#1165)
* feat(board-header): show subtitle on /all view

Add all_subtitle copy and render it in the board header when browsing
the aggregated all-directories feed.

* chore(flags): derive flag-test coords from board-flags source

comment-flags.test.ts hard-coded the pol/pony sprite x/y, duplicating the literals already pinned in board-flags.test.ts. A recent sprite remap updated one file and not the other, leaving master red. Derive the coords from getBoardFlagDefinition (the same source the runtime uses) so the assertion can't drift; labels stay literal as readable pins, and board-flags.test.ts remains the single place pinning the actual values.
2026-06-08 22:47:04 +07:00
Tommaso Casaburi 01e83411b0 Merge branch 'codex/feature/all-view-subtitle' 2026-06-08 22:30:20 +07:00
Tommaso Casaburi dcc47c7bbd feat(board-header): show subtitle on /all view
Add all_subtitle copy and render it in the board header when browsing
the aggregated all-directories feed.
2026-06-08 22:30:14 +07:00
Tommaso CasaburiandGitHub 182ff0eadc fix(thread): show optimistic reply count after publishing own reply (#1162)
post.replyCount lags until a reply propagates back through the community, so a thread's stats kept showing the old count even though the reply list already appended the fresh account comment. Add useOptimisticReplyCount, which bumps the count for the account's own successfully-published replies in the thread and retires the bump once the post refreshes past them (updatedAt > timestamp) so the propagated copy is never double-counted. Applied to desktop PostPageStats and mobile ThreadFooterMobile.
2026-06-08 19:09:46 +07:00
Tommaso CasaburiandGitHub cf43934708 test(flags): correct stale pony AJ sprite x-coord expectation (#1163)
The pony sprite-coordinate remap (cbdd4edf7) moved AJ to x:48 and updated board-flags.test.ts, but comment-flags.test.ts still expected the old x:80, leaving master's full test suite red. Align the comment-flags expectation with the live board-flags definition (and the passing board-flags.test.ts).
2026-06-08 18:58:20 +07:00
Tommaso Casaburi 5a785a5ab7 Merge branch 'codex/fix/pony-flag-sprite-coords' 2026-06-08 17:13:06 +07:00
Tommaso Casaburi cbdd4edf7b fix(flags): map pony flags to sprite sheet coordinates
Pony flag selector order differs from the sprite layout, so derive
positions from explicit coordinates instead of entry index.
2026-06-08 17:12:59 +07:00
Tommaso Casaburi 7ea0b54a18 Merge branch 'master' of github.com:bitsocialnet/5chan 2026-06-08 16:56:10 +07:00
Tommaso CasaburiandGitHub bd12b47db6 fix(pending-post): keep retrying failed posts on the pending route (#1161)
* fix(pending-post): keep retrying failed posts on the pending route

Retrying a failed post deletes the pending row before republishing, which
briefly leaves the pending comment non-addressable with no active challenge —
the same state PendingPost's abandoned-challenge guard uses to redirect back to
the board. A shared use-failed-post-retry-store marks the index being retried so
PendingPost skips that redirect until the republished row is created and its own
navigation to the new pending route takes over.

* fix(pending-post): harden retry flag lifecycle against abandoned-challenge race

Address Cursor Bugbot review on the retry flow. Clear the retry flag (and
isRetryRedirectPending) when the republish challenge is abandoned so an abandon
mid-retry falls through to the normal board redirect instead of stranding an
empty pending view. Also navigate to the new pending row before clearing the
flag in the redirect effect so PendingPost never observes an old-index route
with the flag already cleared.
2026-06-08 16:08:51 +07:00
Tommaso Casaburi 46aa197562 Merge branch 'codex/fix/flag-verification-scope' 2026-06-08 15:43:39 +07:00
Tommaso Casaburi 32dbabb7c7 fix(flags): limit challenge requests to country flags 2026-06-08 15:43:12 +07:00
Tommaso CasaburiandGitHub c2b222c4d5 fix(thread update): refresh stale reply caches (#1160)
* fix(thread update): refresh stale reply caches

Evict the current thread comment and known reply-page cache entries before manual refresh so stale local data does not keep replies hidden. Also defer broader multiboard suggestion feeds until the current /all time window is exhausted to reduce renderer pressure.

* fix(thread update): evict alternate reply page caches

* fix(board): hide stale time-window suggestions
2026-06-08 14:44:38 +07:00
Tommaso Casaburi 6c660c01cd ci(release): run react doctor against previous tag v0.9.1 2026-06-07 23:13:45 +07:00
Tommaso Casaburi af2689c4dc chore(release): v0.9.1 2026-06-07 23:09:29 +07:00