mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-09 10:21:03 +00:00
9a1c043189
* refactor(settings): replace modal with nested full-page route
Settings sections are now URL-addressable at /settings/:sectionId, rendered
nested inside EditorLayout alongside the stack sidebar. Browser back/forward
navigates between sections. Deep links (e.g. /settings/cloud-backup) load
the section directly on hard reload.
- Add react-router-dom v7; BrowserRouter wraps the full app tree
- New SettingsPage (scroll memory, Cmd+K palette), SettingsSidebar (NavLink
active styling, back-arrow), SectionGate (visibility + tier lock card)
- Rename SectionId 'appstore' to 'app-store' so slug === SectionId
- Decouple SystemSection, DeveloperSection, AppStoreSection from modal-
passed props; each fetches its own data on mount
- Replace onLabelsChanged prop chain with SENCHO_LABELS_CHANGED window event
- Drop onOpenSettings prop from UserProfileDropdown, HomeDashboard,
ConfigurationStatus; each calls useNavigate directly
- Delete SettingsModal.tsx
* fix(settings): validate sectionId against registry before property write
Prevents prototype pollution (CodeQL js/remote-property-injection #243).
URL param sectionId is checked against SETTINGS_ITEMS before being used
as a property key on scrollPositionsRef.
* fix(settings): eliminate remote property injection via Map and registry-sourced key
Two-part fix for CodeQL js/remote-property-injection:
1. currentSection is now derived from SETTINGS_ITEMS.find().id (trusted
registry data) instead of the raw sectionId URL param. The tainted
string never flows into any property access.
2. scrollPositionsRef uses Map<SectionId, number> with .get()/.set()
instead of a plain object. Map operations do not write to the prototype
chain, removing the prototype pollution vector entirely.
* test(e2e): align settings selectors with full-page route
The settings refactor (4475afd) replaced the modal with a nested route.
The new sidebar renders sub-sections as NavLinks (role link, not button)
and adds a "Filter settings" button that collides with the loose
/settings/i regex used in mfa and nodes specs.
- Use exact 'Settings' match for the profile-dropdown menu row
- Switch the Nodes sub-section selector from button to link role
61 lines
1.5 KiB
TypeScript
61 lines
1.5 KiB
TypeScript
import { BrowserRouter } from 'react-router-dom';
|
|
import { AuthProvider, useAuth } from './context/AuthContext';
|
|
import { NodeProvider } from './context/NodeContext';
|
|
import { LicenseProvider } from './context/LicenseContext';
|
|
import { Login } from './components/Login';
|
|
import { Setup } from './components/Setup';
|
|
import EditorLayout from './components/EditorLayout';
|
|
import { MfaChallenge } from './components/MfaChallenge';
|
|
import { DeployFeedbackProvider } from './context/DeployFeedbackContext';
|
|
import { DeployFeedbackPortal } from './components/DeployFeedbackPortal';
|
|
|
|
function AppContent() {
|
|
const { appStatus, isAuthenticated, needsSetup, completeSetup } = useAuth();
|
|
|
|
if (appStatus === 'loading') {
|
|
return (
|
|
<div className="min-h-screen flex items-center justify-center bg-background">
|
|
<div className="text-muted-foreground">Loading...</div>
|
|
</div>
|
|
);
|
|
}
|
|
|
|
if (needsSetup) {
|
|
return <Setup onComplete={completeSetup} />;
|
|
}
|
|
|
|
if (appStatus === 'mfaChallenge') {
|
|
return <MfaChallenge />;
|
|
}
|
|
|
|
if (!isAuthenticated) {
|
|
return <Login />;
|
|
}
|
|
|
|
return (
|
|
<NodeProvider>
|
|
<LicenseProvider>
|
|
<EditorLayout />
|
|
</LicenseProvider>
|
|
</NodeProvider>
|
|
);
|
|
}
|
|
|
|
import { ToastContainer } from './components/ui/toast';
|
|
|
|
function App() {
|
|
return (
|
|
<BrowserRouter>
|
|
<AuthProvider>
|
|
<DeployFeedbackProvider>
|
|
<AppContent />
|
|
<DeployFeedbackPortal />
|
|
</DeployFeedbackProvider>
|
|
<ToastContainer />
|
|
</AuthProvider>
|
|
</BrowserRouter>
|
|
);
|
|
}
|
|
|
|
export default App;
|