Changes for page LiveTable View Sheet
Last modified by Сергей Коршунов on 2025/05/01 21:19
From version 5.1
edited by Сергей Коршунов
on 2023/04/25 14:43
on 2023/04/25 14:43
Change comment:
Install extension [org.xwiki.platform:xwiki-platform-appwithinminutes-ui/15.3]
To version 2.1
edited by Сергей Коршунов
on 2022/03/08 16:59
on 2022/03/08 16:59
Change comment:
Install extension [org.xwiki.platform:xwiki-platform-appwithinminutes-ui/14.1]
Summary
-
Page properties (1 modified, 0 added, 0 removed)
-
Objects (1 modified, 0 added, 0 removed)
Details
- Page properties
-
- Content
-
... ... @@ -11,8 +11,16 @@ 11 11 ## Display the live table only if it was generated. 12 12 #if ($doc.content.length() > 0) 13 13 = $services.localization.render('platform.appwithinminutes.appLiveTableHeading') = 14 - 15 - {{include reference="" author="target"/}} 14 + ## We don't use the Include macro (with empty reference) because we want the content to be executed with the rights 15 + ## of the current document rather than the rights of the sheet. This is important because the user can modify the 16 + ## content of the application home page which means we could execute untrusted content with the rights of the sheet. 17 + ## Ideally we should use the Display macro with a parameter to disable the sheet, but we don't have this parameter. 18 + ## We don't clean the HTML content because getRenderedContent() should produce clean HTML, unless the user has 19 + ## disabled the HTML cleaning, in which case he will get what he asked for. Note that one good reason to disable 20 + ## HTML cleaning is to preserve the whitespaces in the attribute values. 21 + ## Escape {{ in the rendered content to be sure that the HTML macro is not closed unintentionally. 22 + {{html clean="false"}}$doc.getRenderedContent($doc.content, 23 + $doc.syntax.toIdString()).replace('{{', '&#123;&#123;'){{/html}} 16 16 #end 17 17 #end 18 18 ... ... @@ -60,7 +60,6 @@ 60 60 #end 61 61 ## We need to set the title if we want to be able to sort or filter the doc.title live table column. 62 62 #set ($params = { 63 - 'form_token': $services.csrf.token, 64 64 'template': "${className}Template", 65 65 'title': '__entryName__', 66 66 'parent': $services.model.serialize($doc.documentReference, 'local') ... ... @@ -115,30 +115,23 @@ 115 115 data-backdrop="static" data-keyboard="false"> 116 116 <div class="modal-dialog" role="document"> 117 117 <form class="modal-content xform"> 118 - ## The fieldset allows us to disable and enable the entire form quickly and easy. 119 - <fieldset> 120 - <div class="modal-header"> 121 - <button type="button" class="close" data-dismiss="modal" 122 - title="$escapetool.xml($services.localization.render('appWithinMinutes.renameApp.close'))" 123 - aria-label="$escapetool.xml($services.localization.render('appWithinMinutes.renameApp.close'))"> 124 - <span aria-hidden="true">×</span> 125 - </button> 126 - <span class="modal-title" id="renameAppModal-label"> 127 - $escapetool.xml($services.localization.render('appWithinMinutes.renameApp.label')) 128 - </span> 129 - </div> 130 - <div class="modal-body"> 131 - #renameAppModalBody 132 - </div> 133 - <div class="modal-footer"> 134 - <button type="button" class="btn btn-default" data-dismiss="modal"> 135 - $escapetool.xml($services.localization.render('cancel')) 136 - </button> 137 - <button type="submit" class="btn btn-primary" disabled="disabled"> 138 - $escapetool.xml($services.localization.render('core.rename.submit')) 139 - </button> 140 - </div> 141 - </fieldset> 125 + <div class="modal-header"> 126 + <button type="button" class="close" data-dismiss="modal" aria-label="Close"> 127 + <span aria-hidden="true">×</span> 128 + </button> 129 + <span class="modal-title" id="renameAppModal-label">Rename Application</span> 130 + </div> 131 + <div class="modal-body"> 132 + #renameAppModalBody 133 + </div> 134 + <div class="modal-footer"> 135 + <button type="button" class="btn btn-default" data-dismiss="modal"> 136 + $escapetool.xml($services.localization.render('cancel')) 137 + </button> 138 + <button type="submit" class="btn btn-primary" disabled="disabled"> 139 + $escapetool.xml($services.localization.render('core.rename.submit')) 140 + </button> 141 + </div> 142 142 </form> 143 143 </div> 144 144 </div>
- XWiki.JavaScriptExtension[0]
-
- Code
-
... ... @@ -58,7 +58,7 @@ 58 58 /** 59 59 * Rename Application 60 60 */ 61 -require(['jquery', 'bootstrap' , 'xwiki-form-validation-async'], function($) {61 +require(['jquery', 'bootstrap'], function($) { 62 62 #set ($currentDocReference = $xwiki.getDocument($request.currentApp).getDocumentReference()) 63 63 // if we cannot find any extension related to this page app, it's not part of an extension. 64 64 var isNotAnExtension = $services.extension.xar.getInstalledExtensions($currentDocReference).isEmpty(); ... ... @@ -77,6 +77,7 @@ 77 77 // Form validation. 78 78 var appNameInput = $('#renameAppTitle'); 79 79 var appParentInput = $('#renameAppParentReference'); 80 + var submitButton = renameAppModal.find('.btn-primary[type="submit"]'); 80 80 81 81 var appNameEmptyError = renameAppModal.find('.appNameEmptyError'); 82 82 var pageExistsError = renameAppModal.find('.pageExistsError'); ... ... @@ -99,44 +99,49 @@ 99 99 100 100 var startValidation = function() { 101 101 if (appNameInput.val() === '') { 102 - returnPromise.reject(appNameEmptyError);103 + endValidation(appNameEmptyError); 103 103 } else { 104 104 var newAppHomePage = getNewAppHomePage(); 105 105 if (newAppHomePage.documentReference.equals(XWiki.currentDocument.documentReference)) { 106 - returnPromise.reject(pageExistsError);107 + endValidation(pageExistsError); 107 107 } else { 108 - return new Promise((resolve, reject) => { 109 - $.ajax({ 110 - type: 'HEAD', 111 - url: newAppHomePage.getURL() 112 - }).then(reject.bind(null, pageExistsError), response => { 113 - if (response.status === 404) { 114 - $.ajax({ 115 - type: 'HEAD', 116 - url: newAppHomePage.getURL('edit') 117 - }).then( 118 - () => resolve(), 119 - () => reject(locationForbiddenError) 120 - ); 121 - } else if (response.status === 403) { 122 - reject(locationForbiddenError); 123 - } else { 124 - resolve(); 125 - } 126 - }); 109 + $.ajax({ 110 + type: 'HEAD', 111 + url: newAppHomePage.getURL() 112 + }).then(endValidation.bind(null, pageExistsError), response => { 113 + if (response.status === 404) { 114 + $.ajax({ 115 + type: 'HEAD', 116 + url: newAppHomePage.getURL('edit') 117 + }).then( 118 + () => endValidation(), 119 + () => endValidation(locationForbiddenError) 120 + ); 121 + } else if (response.status === 403) { 122 + endValidation(locationForbiddenError); 123 + } else { 124 + endValidation(); 125 + } 127 127 }); 128 128 } 129 129 } 130 130 }; 131 131 131 + var endValidation = function(error) { 132 + if (error) { 133 + error.show(); 134 + } 135 + appNameInput.removeClass('loading'); 136 + submitButton.prop('disabled', !!error); 137 + }; 138 + 139 + var validationTimeout; 132 132 var scheduleValidation = function() { 133 - // Hide allerror messages before starting theasynchronousvalidation.141 + clearTimeout(validationTimeout); 134 134 renameAppModal.find('.xErrorMsg').hide(); 135 - appNameInput.addClass('loading').validateAsync(startValidation, 500, 'awm').catch((error) => { 136 - error.show(); 137 - }).finally(() => { 138 - appNameInput.removeClass('loading'); 139 - }); 143 + appNameInput.addClass('loading'); 144 + submitButton.prop('disabled', true); 145 + validationTimeout = setTimeout(startValidation, 500); 140 140 }; 141 141 142 142 appNameInput.add(appParentInput).on('input', scheduleValidation); ... ... @@ -185,13 +185,13 @@ 185 185 186 186 var renameApp = function(data) { 187 187 // Disable the form to prevent it from being submitted twice. 188 - renameAppModal.find(' fieldset').prop('disabled', true);194 + renameAppModal.find(':input').prop('disabled', true); 189 189 var notification = new XWiki.widgets.Notification( 190 190 $jsontool.serialize($services.localization.render('appWithinMinutes.renameApp.inProgress')), 191 191 'inprogress' 192 192 ); 193 193 var renameAppURL = new XWiki.Document('RenameApplication', 'AppWithinMinutes').getURL('get'); 194 - Promise.resolve($.post(renameAppURL, data)).then(updateAppHomePage).then(function() {200 + $.post(renameAppURL, data).then(updateAppHomePage).then(function() { 195 195 renameAppModal.modal('hide'); 196 196 notification.replace(new XWiki.widgets.Notification( 197 197 $jsontool.serialize($services.localization.render('appWithinMinutes.renameApp.done')), ... ... @@ -208,7 +208,7 @@ 208 208 )); 209 209 }).finally(function() { 210 210 // Re-enable the form. 211 - renameAppModal.find(' fieldset').prop('disabled', false);217 + renameAppModal.find(':input').prop('disabled', false); 212 212 }); 213 213 }; 214 214