mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 06:15:09 +00:00
* fix(web): harden, polish and optimize the web UI per the September 2026 audit Works through docs/archive/WEB_UI_AUDIT_2026-09.md (health 8/20). Implementation integrity (P0) - app.css now defines every utility class the templates and JS use, including .hidden, so the ~145 JS show/hide toggles work. Button reset, and base component rules (.btn, .form-control) wrapped in :where() so utility classes on the same element win. New static-audit test fails when a used utility class has no rule. Accessibility - Focus rings render (the old ring rule referenced undefined variables); one :focus-visible outline everywhere; skip link; labelled nav landmarks. - Shared dialog helper (js/utils/dialog.js): role/aria-modal, focus trap, Escape, focus return, applied to every modal. - Named icon-only buttons and labelled ~70 form fields. - Toasts announced once; errors persist >= 10s; one showNotification. - Captive WiFi page: live region, timeouts, dark mode, 16px inputs. Performance (Pi Zero 2 W) - SSE streams and tab timers pause when hidden or off-tab; the display stream only runs while a preview is visible. app-shell.js deferred. - Widget scripts served as one versioned bundle (/assets/widgets.js): 52 -> 21 script tags, 66 -> 35 requests on first load. - Stdlib gzip fallback when flask-compress is missing: first-load JS/CSS 1358 KB -> 291 KB on the wire. SSE untouched. Theming and responsive - File managers, form fields and Fonts upload on theme tokens; bare inputs themed in dark mode; no more white surfaces. - No horizontal overflow at 375px on any tab; 44px touch targets on coarse pointers; reduced-motion respected; header title truncates. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): clear Codacy findings on #568 - json-file-manager: focus-trap releases kept in a Map (no dynamic property access or delete; no value-returning forEach callback) - notification / schedule-picker: style and day-label lookups via Map - app.js: move the pending-queue assignment out of the expression - diff_viewer / error_handler: named function declarations instead of arrow consts No behavior change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * test: check the OAuth widget ships in the widget bundle base.html no longer tags widget scripts one by one; they load through /assets/widgets.js. Assert the page requests the bundle and the bundle contains google-oauth.js, which is what the test was protecting. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): address review feedback on #568 - widget bundle version fingerprints every file (name, mtime_ns, size) - gzip fallback appends Accept-Encoding to an existing Vary header - dialog helper: releasing a non-top dialog no longer moves focus out of the dialog the user is in - labels: file-upload targets its file input; fallback config fields get label for/id pairs; native color input has a fallback name - utility audit also reads class names inside bound :class expressions Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): give the native color-picker input an accessible name CodeRabbit flagged this on PR #568 as an outside-diff finding (never posted inline, so it was missed in the round of fixes that addressed the other 6 review comments). The <input type="color"> only carried a title attribute; screen readers don't reliably announce title, and there's no other label naming the control when showHexInput is false. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): clear Codacy findings in app-shell.js - drop the unused catch binding on the SSE JSON parse - move the pending-notification queue assignment out of the expression No behavior change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): contain plugin widgets/ dir and bound style-editor retries From CodeRabbit review on #568 (code that arrived with the main merge): - serve_plugin_widget resolves widgets/ with resolve_under before resolving the manifest script under it, so a symlinked widgets directory can't become the containment base (CWE-22). New test. - style-editor init stops polling after ~10s when the widget never registers and leaves the plain fallback fields in place. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
319 lines
14 KiB
HTML
319 lines
14 KiB
HTML
<div class="space-y-6">
|
|
<!-- Config.json Editor -->
|
|
<div class="bg-white rounded-lg shadow p-6">
|
|
<div class="border-b border-gray-200 pb-4 mb-6">
|
|
<div class="flex items-center justify-between">
|
|
<div>
|
|
<h2 id="main-config-editor-title" class="text-lg font-semibold text-gray-900">config.json Editor</h2>
|
|
<p class="mt-1 text-sm text-gray-600">{{ main_config_path }}</p>
|
|
</div>
|
|
<div class="flex gap-2">
|
|
<button onclick="formatJson('main-config-editor', 'main-config-validation')"
|
|
class="inline-flex items-center px-3 py-2 border border-gray-300 text-sm font-medium rounded-md text-gray-700 bg-white hover:bg-gray-50">
|
|
<i class="fas fa-align-left mr-2"></i>
|
|
Format JSON
|
|
</button>
|
|
<button onclick="manualValidateJson('main-config-editor', 'main-config-validation')"
|
|
class="inline-flex items-center px-3 py-2 border border-transparent text-sm font-medium rounded-md text-white bg-yellow-600 hover:bg-yellow-700">
|
|
<i class="fas fa-check-circle mr-2"></i>
|
|
Validate JSON
|
|
</button>
|
|
<button onclick="saveMainConfig()"
|
|
class="inline-flex items-center px-4 py-2 border border-transparent text-sm font-medium rounded-md text-white bg-blue-600 hover:bg-blue-700">
|
|
<i class="fas fa-save mr-2"></i>
|
|
Save
|
|
</button>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div class="relative">
|
|
<textarea id="main-config-editor" aria-labelledby="main-config-editor-title"
|
|
class="w-full h-96 font-mono text-sm p-4 border border-gray-300 rounded-md focus:ring-blue-500 focus:border-blue-500"
|
|
spellcheck="false">{{ main_config_json }}</textarea>
|
|
<div id="main-config-validation" class="mt-2 text-sm"></div>
|
|
</div>
|
|
|
|
<div class="mt-4 p-4 bg-yellow-50 border border-yellow-200 rounded-md">
|
|
<div class="flex">
|
|
<div class="flex-shrink-0">
|
|
<i class="fas fa-exclamation-triangle text-yellow-600"></i>
|
|
</div>
|
|
<div class="ml-3">
|
|
<h3 class="text-sm font-medium text-yellow-800">Warning</h3>
|
|
<div class="mt-2 text-sm text-yellow-700">
|
|
<p>Editing this file directly can break your configuration. Always validate JSON syntax before saving.</p>
|
|
<p class="mt-1">After saving, you may need to restart the display service for changes to take effect.</p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<!-- Config_secrets.json Editor -->
|
|
<div class="bg-white rounded-lg shadow p-6">
|
|
<div class="border-b border-gray-200 pb-4 mb-6">
|
|
<div class="flex items-center justify-between">
|
|
<div>
|
|
<h2 id="secrets-config-editor-title" class="text-lg font-semibold text-gray-900">config_secrets.json Editor</h2>
|
|
<p class="mt-1 text-sm text-gray-600">{{ secrets_config_path }}</p>
|
|
</div>
|
|
<div class="flex gap-2">
|
|
<button onclick="formatJson('secrets-config-editor', 'secrets-config-validation')"
|
|
class="inline-flex items-center px-3 py-2 border border-gray-300 text-sm font-medium rounded-md text-gray-700 bg-white hover:bg-gray-50">
|
|
<i class="fas fa-align-left mr-2"></i>
|
|
Format JSON
|
|
</button>
|
|
<button onclick="manualValidateJson('secrets-config-editor', 'secrets-config-validation')"
|
|
class="inline-flex items-center px-3 py-2 border border-transparent text-sm font-medium rounded-md text-white bg-yellow-600 hover:bg-yellow-700">
|
|
<i class="fas fa-check-circle mr-2"></i>
|
|
Validate JSON
|
|
</button>
|
|
<button onclick="saveSecretsConfig()"
|
|
class="inline-flex items-center px-4 py-2 border border-transparent text-sm font-medium rounded-md text-white bg-blue-600 hover:bg-blue-700">
|
|
<i class="fas fa-save mr-2"></i>
|
|
Save
|
|
</button>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<div class="relative">
|
|
<textarea id="secrets-config-editor" aria-labelledby="secrets-config-editor-title"
|
|
class="w-full h-96 font-mono text-sm p-4 border border-gray-300 rounded-md focus:ring-blue-500 focus:border-blue-500"
|
|
spellcheck="false">{{ secrets_config_json }}</textarea>
|
|
<div id="secrets-config-validation" class="mt-2 text-sm"></div>
|
|
</div>
|
|
|
|
<div class="mt-4 p-4 bg-red-50 border border-red-200 rounded-md">
|
|
<div class="flex">
|
|
<div class="flex-shrink-0">
|
|
<i class="fas fa-shield-alt text-red-600"></i>
|
|
</div>
|
|
<div class="ml-3">
|
|
<h3 class="text-sm font-medium text-red-800">Security Notice</h3>
|
|
<div class="mt-2 text-sm text-red-700">
|
|
<p>This file contains sensitive information like API keys and passwords.</p>
|
|
<p class="mt-1">Never share this file or commit it to version control.</p>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
|
|
<script>
|
|
// Format JSON with proper indentation
|
|
function formatJson(editorId, validationDivId) {
|
|
const textarea = document.getElementById(editorId);
|
|
const jsonText = textarea.value;
|
|
|
|
try {
|
|
const parsed = JSON.parse(jsonText);
|
|
const formatted = JSON.stringify(parsed, null, 4);
|
|
textarea.value = formatted;
|
|
|
|
// Auto-validate after formatting
|
|
validateJSON(editorId, validationDivId);
|
|
showNotification('JSON formatted successfully!', 'success');
|
|
} catch (error) {
|
|
showNotification('Cannot format invalid JSON: ' + error.message, 'error');
|
|
validateJSON(editorId, validationDivId);
|
|
}
|
|
}
|
|
|
|
// Manual validation with detailed feedback
|
|
function manualValidateJson(editorId, validationDivId) {
|
|
const textarea = document.getElementById(editorId);
|
|
const validation = document.getElementById(validationDivId);
|
|
const jsonText = textarea.value;
|
|
|
|
if (!textarea || !validation) return;
|
|
|
|
try {
|
|
const parsed = JSON.parse(jsonText);
|
|
validation.innerHTML = `
|
|
<div class="p-3 bg-green-50 border border-green-200 rounded-md">
|
|
<div class="flex items-start">
|
|
<i class="fas fa-check-circle text-green-600 text-xl mr-3 mt-1"></i>
|
|
<div>
|
|
<div class="font-semibold text-green-800">✓ JSON is valid!</div>
|
|
<div class="text-sm text-green-700 mt-1">
|
|
✓ Valid JSON syntax<br>
|
|
✓ Proper structure<br>
|
|
✓ No syntax errors detected
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
`;
|
|
showNotification('JSON validation successful!', 'success');
|
|
} catch (e) {
|
|
validation.innerHTML = `
|
|
<div class="p-3 bg-red-50 border border-red-200 rounded-md">
|
|
<div class="flex items-start">
|
|
<i class="fas fa-times-circle text-red-600 text-xl mr-3 mt-1"></i>
|
|
<div>
|
|
<div class="font-semibold text-red-800">✗ Invalid JSON syntax</div>
|
|
<div class="text-sm text-red-700 mt-1">
|
|
<strong>Error:</strong> ${e.message}
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
`;
|
|
showNotification('JSON validation failed: ' + e.message, 'error');
|
|
}
|
|
}
|
|
|
|
// Auto-validate JSON as user types (simple version)
|
|
function validateJSON(editor, validationDiv) {
|
|
const textarea = document.getElementById(editor);
|
|
const validation = document.getElementById(validationDiv);
|
|
|
|
if (!textarea || !validation) return true;
|
|
|
|
try {
|
|
JSON.parse(textarea.value);
|
|
validation.innerHTML = '<span class="text-green-600"><i class="fas fa-check-circle mr-1"></i>Valid JSON</span>';
|
|
return true;
|
|
} catch (e) {
|
|
validation.innerHTML = '<span class="text-red-600"><i class="fas fa-times-circle mr-1"></i>Invalid JSON: ' + e.message + '</span>';
|
|
return false;
|
|
}
|
|
}
|
|
|
|
// Auto-validate on input
|
|
document.getElementById('main-config-editor')?.addEventListener('input', function() {
|
|
validateJSON('main-config-editor', 'main-config-validation');
|
|
});
|
|
|
|
document.getElementById('secrets-config-editor')?.addEventListener('input', function() {
|
|
validateJSON('secrets-config-editor', 'secrets-config-validation');
|
|
});
|
|
|
|
// Initial validation
|
|
setTimeout(() => {
|
|
validateJSON('main-config-editor', 'main-config-validation');
|
|
validateJSON('secrets-config-editor', 'secrets-config-validation');
|
|
}, 100);
|
|
|
|
function saveMainConfig() {
|
|
const textarea = document.getElementById('main-config-editor');
|
|
|
|
// Validate JSON first
|
|
if (!validateJSON('main-config-editor', 'main-config-validation')) {
|
|
showNotification('Invalid JSON! Please fix errors before saving.', 'error');
|
|
return;
|
|
}
|
|
|
|
try {
|
|
const config = JSON.parse(textarea.value);
|
|
|
|
// Save via API
|
|
fetch('/api/v3/config/raw/main', {
|
|
method: 'POST',
|
|
headers: {
|
|
'Content-Type': 'application/json'
|
|
},
|
|
body: JSON.stringify(config)
|
|
})
|
|
.then(async response => {
|
|
// Store status and statusText before parsing
|
|
const status = response.status;
|
|
const statusText = response.statusText;
|
|
|
|
// Try to parse JSON response
|
|
let data;
|
|
try {
|
|
data = await response.json();
|
|
} catch (parseError) {
|
|
// If JSON parsing fails, throw generic HTTP error
|
|
throw new Error(`HTTP ${status}: ${statusText}`);
|
|
}
|
|
|
|
// Handle non-OK responses
|
|
if (!response.ok) {
|
|
// Extract specific error message from API response if available
|
|
const errorMessage = data.message || data.status || statusText;
|
|
throw new Error(errorMessage);
|
|
}
|
|
|
|
// Handle successful responses
|
|
if (data.status === 'success') {
|
|
showNotification('config.json saved successfully!', 'success');
|
|
} else {
|
|
showNotification('Error saving config.json: ' + (data.message || 'Unknown error'), 'error');
|
|
}
|
|
})
|
|
.catch(error => {
|
|
// Preserve the error message that was intentionally thrown
|
|
showNotification('Error saving config.json: ' + (error.message || 'An error occurred'), 'error');
|
|
});
|
|
} catch (e) {
|
|
showNotification('Invalid JSON: ' + e.message, 'error');
|
|
}
|
|
}
|
|
|
|
function saveSecretsConfig() {
|
|
const textarea = document.getElementById('secrets-config-editor');
|
|
|
|
// Validate JSON first
|
|
if (!validateJSON('secrets-config-editor', 'secrets-config-validation')) {
|
|
showNotification('Invalid JSON! Please fix errors before saving.', 'error');
|
|
return;
|
|
}
|
|
|
|
try {
|
|
const config = JSON.parse(textarea.value);
|
|
|
|
// Save via API
|
|
fetch('/api/v3/config/raw/secrets', {
|
|
method: 'POST',
|
|
headers: {
|
|
'Content-Type': 'application/json'
|
|
},
|
|
body: JSON.stringify(config)
|
|
})
|
|
.then(async response => {
|
|
// Store status and statusText before parsing
|
|
const status = response.status;
|
|
const statusText = response.statusText;
|
|
|
|
// Try to parse JSON response
|
|
let data;
|
|
try {
|
|
data = await response.json();
|
|
} catch (parseError) {
|
|
// If JSON parsing fails, throw generic HTTP error
|
|
throw new Error(`HTTP ${status}: ${statusText}`);
|
|
}
|
|
|
|
// Handle non-OK responses
|
|
if (!response.ok) {
|
|
// Extract specific error message from API response if available
|
|
const errorMessage = data.message || data.status || statusText;
|
|
throw new Error(errorMessage);
|
|
}
|
|
|
|
// Handle successful responses
|
|
if (data.status === 'success') {
|
|
showNotification('config_secrets.json saved successfully!', 'success');
|
|
} else {
|
|
showNotification('Error saving config_secrets.json: ' + (data.message || 'Unknown error'), 'error');
|
|
}
|
|
})
|
|
.catch(error => {
|
|
// Preserve the error message that was intentionally thrown
|
|
showNotification('Error saving config_secrets.json: ' + (error.message || 'An error occurred'), 'error');
|
|
});
|
|
} catch (e) {
|
|
showNotification('Invalid JSON: ' + e.message, 'error');
|
|
}
|
|
}
|
|
|
|
// showNotification is provided by the notification widget (notification.js)
|
|
// No local definition needed - uses window.showNotification from the widget
|
|
</script>
|
|
|