mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 06:15:09 +00:00
* fix(web): harden, polish and optimize the web UI per the September 2026 audit Works through docs/archive/WEB_UI_AUDIT_2026-09.md (health 8/20). Implementation integrity (P0) - app.css now defines every utility class the templates and JS use, including .hidden, so the ~145 JS show/hide toggles work. Button reset, and base component rules (.btn, .form-control) wrapped in :where() so utility classes on the same element win. New static-audit test fails when a used utility class has no rule. Accessibility - Focus rings render (the old ring rule referenced undefined variables); one :focus-visible outline everywhere; skip link; labelled nav landmarks. - Shared dialog helper (js/utils/dialog.js): role/aria-modal, focus trap, Escape, focus return, applied to every modal. - Named icon-only buttons and labelled ~70 form fields. - Toasts announced once; errors persist >= 10s; one showNotification. - Captive WiFi page: live region, timeouts, dark mode, 16px inputs. Performance (Pi Zero 2 W) - SSE streams and tab timers pause when hidden or off-tab; the display stream only runs while a preview is visible. app-shell.js deferred. - Widget scripts served as one versioned bundle (/assets/widgets.js): 52 -> 21 script tags, 66 -> 35 requests on first load. - Stdlib gzip fallback when flask-compress is missing: first-load JS/CSS 1358 KB -> 291 KB on the wire. SSE untouched. Theming and responsive - File managers, form fields and Fonts upload on theme tokens; bare inputs themed in dark mode; no more white surfaces. - No horizontal overflow at 375px on any tab; 44px touch targets on coarse pointers; reduced-motion respected; header title truncates. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): clear Codacy findings on #568 - json-file-manager: focus-trap releases kept in a Map (no dynamic property access or delete; no value-returning forEach callback) - notification / schedule-picker: style and day-label lookups via Map - app.js: move the pending-queue assignment out of the expression - diff_viewer / error_handler: named function declarations instead of arrow consts No behavior change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * test: check the OAuth widget ships in the widget bundle base.html no longer tags widget scripts one by one; they load through /assets/widgets.js. Assert the page requests the bundle and the bundle contains google-oauth.js, which is what the test was protecting. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): address review feedback on #568 - widget bundle version fingerprints every file (name, mtime_ns, size) - gzip fallback appends Accept-Encoding to an existing Vary header - dialog helper: releasing a non-top dialog no longer moves focus out of the dialog the user is in - labels: file-upload targets its file input; fallback config fields get label for/id pairs; native color input has a fallback name - utility audit also reads class names inside bound :class expressions Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): give the native color-picker input an accessible name CodeRabbit flagged this on PR #568 as an outside-diff finding (never posted inline, so it was missed in the round of fixes that addressed the other 6 review comments). The <input type="color"> only carried a title attribute; screen readers don't reliably announce title, and there's no other label naming the control when showHexInput is false. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): clear Codacy findings in app-shell.js - drop the unused catch binding on the SSE JSON parse - move the pending-notification queue assignment out of the expression No behavior change. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(web): contain plugin widgets/ dir and bound style-editor retries From CodeRabbit review on #568 (code that arrived with the main merge): - serve_plugin_widget resolves widgets/ with resolve_under before resolving the manifest script under it, so a symlinked widgets directory can't become the containment base (CWE-22). New test. - style-editor init stops polling after ~10s when the widget never registers and leaves the plain fallback fields in place. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
292 lines
14 KiB
JavaScript
292 lines
14 KiB
JavaScript
/**
|
|
* LEDMatrix File Upload Single Widget
|
|
*
|
|
* Single-image upload for string fields. Uploads to the plugin's asset folder
|
|
* and sets the string field value to the returned relative path.
|
|
* Designed for per-item image fields within array-table rows.
|
|
*
|
|
* The plugin_id is injected automatically from the template context
|
|
* via options.pluginId — no need to specify it in the schema.
|
|
*
|
|
* Schema example (any plugin):
|
|
* {
|
|
* "image_path": {
|
|
* "type": "string",
|
|
* "x-widget": "file-upload-single",
|
|
* "x-upload-config": {
|
|
* "allowed_types": ["image/png", "image/jpeg", "image/bmp", "image/gif"],
|
|
* "max_size_mb": 5
|
|
* }
|
|
* }
|
|
* }
|
|
*
|
|
* @module FileUploadSingleWidget
|
|
*/
|
|
|
|
(function() {
|
|
'use strict';
|
|
|
|
if (typeof window.LEDMatrixWidgets === 'undefined') {
|
|
console.error('[FileUploadSingleWidget] LEDMatrixWidgets registry not found. Load registry.js first.');
|
|
return;
|
|
}
|
|
|
|
const base = window.BaseWidget ? new window.BaseWidget('FileUploadSingle', '1.0.0') : null;
|
|
|
|
function escapeHtml(text) {
|
|
if (base) return base.escapeHtml(text);
|
|
const div = document.createElement('div');
|
|
div.textContent = String(text);
|
|
return div.innerHTML.replace(/"/g, '"').replace(/'/g, ''');
|
|
}
|
|
|
|
function sanitizeId(id) {
|
|
if (base) return base.sanitizeId(id);
|
|
return String(id).replace(/[^a-zA-Z0-9_-]/g, '_');
|
|
}
|
|
|
|
function triggerChange(fieldId, value) {
|
|
if (base) {
|
|
base.triggerChange(fieldId, value);
|
|
} else {
|
|
document.dispatchEvent(new CustomEvent('widget-change', {
|
|
detail: { fieldId, value },
|
|
bubbles: true,
|
|
cancelable: true
|
|
}));
|
|
}
|
|
}
|
|
|
|
function isImagePath(path) {
|
|
if (!path) return false;
|
|
return /\.(png|jpg|jpeg|bmp|gif)$/i.test(path);
|
|
}
|
|
|
|
function safeSetHTML(target, html) {
|
|
target.textContent = '';
|
|
// createContextualFragment parses html relative to the document context
|
|
// without executing scripts — a widely recognised safe insertion method.
|
|
const frag = document.createRange().createContextualFragment(html);
|
|
target.appendChild(frag);
|
|
}
|
|
|
|
window.LEDMatrixWidgets.register('file-upload-single', {
|
|
name: 'File Upload Single Widget',
|
|
version: '1.0.0',
|
|
|
|
render: function(container, config, value, options) {
|
|
const fieldId = sanitizeId(options.fieldId || container.id || 'file_upload_single');
|
|
const uploadConfig = config['x-upload-config'] || config['x_upload_config'] || {};
|
|
const allowedTypes = (uploadConfig.allowed_types || ['image/png', 'image/jpeg', 'image/bmp', 'image/gif']).join(',');
|
|
const maxSizeMb = uploadConfig.max_size_mb || 5;
|
|
const pluginId = options.pluginId || '';
|
|
const currentValue = value || '';
|
|
const hasImage = isImagePath(currentValue);
|
|
|
|
let html = `<div id="${fieldId}_widget" class="file-upload-single-widget" data-field-id="${fieldId}" data-plugin-id="${escapeHtml(pluginId)}">`;
|
|
|
|
// Hidden input carries the actual string value
|
|
html += `<input type="hidden" id="${fieldId}" name="${escapeHtml(options.name || fieldId)}" value="${escapeHtml(currentValue)}">`;
|
|
|
|
// Preview area (shown when a value is set)
|
|
html += `<div id="${fieldId}_preview" class="${hasImage ? '' : 'hidden'} flex items-center space-x-3 mb-2 p-2 bg-gray-50 rounded border border-gray-200">`;
|
|
html += `<img id="${fieldId}_thumb" src="/${escapeHtml(currentValue)}" alt="Preview"
|
|
class="w-12 h-12 object-cover rounded"
|
|
onerror="this.style.display='none';document.getElementById('${fieldId}_thumb_placeholder').style.display='flex'">`;
|
|
html += `<div id="${fieldId}_thumb_placeholder" style="display:none" class="w-12 h-12 bg-gray-200 rounded flex items-center justify-center">
|
|
<i class="fas fa-image text-gray-400 text-lg"></i>
|
|
</div>`;
|
|
html += `<div class="flex-1 min-w-0">
|
|
<p id="${fieldId}_filename" class="text-xs text-gray-600 truncate">${escapeHtml(currentValue.split('/').pop() || '')}</p>
|
|
<p id="${fieldId}_fullpath" class="text-xs text-gray-400">${escapeHtml(currentValue)}</p>
|
|
</div>`;
|
|
html += `<button type="button"
|
|
onclick="window.LEDMatrixWidgets.getHandlers('file-upload-single').onClear('${fieldId}')"
|
|
class="flex-shrink-0 text-red-400 hover:text-red-600 p-1" title="Remove image" aria-label="Remove image">
|
|
<i class="fas fa-times" aria-hidden="true"></i>
|
|
</button>`;
|
|
html += '</div>';
|
|
|
|
// Upload drop zone — keyboard accessible via tabindex + Enter/Space
|
|
html += `<div id="${fieldId}_drop_zone"
|
|
class="border-2 border-dashed border-gray-300 rounded-lg p-3 text-center hover:border-blue-400 transition-colors cursor-pointer"
|
|
role="button" tabindex="0"
|
|
aria-label="${hasImage ? 'Replace image' : 'Upload image'}"
|
|
ondrop="window.LEDMatrixWidgets.getHandlers('file-upload-single').onDrop(event, '${fieldId}')"
|
|
ondragover="event.preventDefault()"
|
|
onclick="document.getElementById('${fieldId}_file_input').click()"
|
|
onkeydown="if(event.key==='Enter'||event.key===' '){event.preventDefault();document.getElementById('${fieldId}_file_input').click();}">
|
|
<input type="file"
|
|
id="${fieldId}_file_input"
|
|
accept="${escapeHtml(allowedTypes)}"
|
|
style="display:none"
|
|
data-field-id="${fieldId}"
|
|
data-plugin-id="${escapeHtml(pluginId)}"
|
|
data-max-size-mb="${maxSizeMb}"
|
|
data-allowed-types="${escapeHtml(allowedTypes)}"
|
|
onchange="window.LEDMatrixWidgets.getHandlers('file-upload-single').onFileSelect(event, '${fieldId}')">
|
|
<i class="fas fa-cloud-upload-alt text-xl text-gray-400 mb-1"></i>
|
|
<p class="text-xs text-gray-500">${hasImage ? 'Click to replace image' : 'Click or drag to upload image'}</p>
|
|
<p class="text-xs text-gray-400">Max ${maxSizeMb}MB</p>
|
|
</div>`;
|
|
|
|
// Status area for upload feedback
|
|
html += `<div id="${fieldId}_status" class="mt-1 text-xs hidden"></div>`;
|
|
|
|
html += '</div>';
|
|
safeSetHTML(container, html);
|
|
},
|
|
|
|
getValue: function(fieldId) {
|
|
const safeId = sanitizeId(fieldId);
|
|
const input = document.getElementById(safeId);
|
|
return input ? input.value : '';
|
|
},
|
|
|
|
setValue: function(fieldId, value) {
|
|
const safeId = sanitizeId(fieldId);
|
|
const hidden = document.getElementById(safeId);
|
|
const preview = document.getElementById(`${safeId}_preview`);
|
|
const thumb = document.getElementById(`${safeId}_thumb`);
|
|
const thumbPlaceholder = document.getElementById(`${safeId}_thumb_placeholder`);
|
|
const filename = document.getElementById(`${safeId}_filename`);
|
|
const dropZone = document.getElementById(`${safeId}_drop_zone`);
|
|
|
|
if (hidden) hidden.value = value || '';
|
|
|
|
const hasImage = isImagePath(value);
|
|
if (preview) preview.classList.toggle('hidden', !hasImage);
|
|
if (thumb && hasImage) {
|
|
thumb.src = `/${value}`;
|
|
thumb.style.display = '';
|
|
if (thumbPlaceholder) thumbPlaceholder.style.display = 'none';
|
|
}
|
|
if (filename) filename.textContent = hasImage ? value.split('/').pop() : '';
|
|
const fullpath = document.getElementById(`${safeId}_fullpath`);
|
|
if (fullpath) fullpath.textContent = value || '';
|
|
|
|
// Update drop zone hint text
|
|
const hint = dropZone ? dropZone.querySelector('p') : null;
|
|
if (hint) hint.textContent = hasImage ? 'Click to replace image' : 'Click or drag to upload image';
|
|
},
|
|
|
|
handlers: {
|
|
onFileSelect: function(event, fieldId) {
|
|
const files = event.target.files;
|
|
if (files && files.length > 0) {
|
|
window.LEDMatrixWidgets.getHandlers('file-upload-single').uploadFile(fieldId, files[0]);
|
|
}
|
|
},
|
|
|
|
onDrop: function(event, fieldId) {
|
|
event.preventDefault();
|
|
const files = event.dataTransfer.files;
|
|
if (files && files.length > 0) {
|
|
window.LEDMatrixWidgets.getHandlers('file-upload-single').uploadFile(fieldId, files[0]);
|
|
}
|
|
},
|
|
|
|
onClear: function(fieldId) {
|
|
const widget = window.LEDMatrixWidgets.get('file-upload-single');
|
|
widget.setValue(fieldId, '');
|
|
triggerChange(fieldId, '');
|
|
// Reset file input so the same file can be re-selected
|
|
const fileInput = document.getElementById(`${sanitizeId(fieldId)}_file_input`);
|
|
if (fileInput) fileInput.value = '';
|
|
},
|
|
|
|
uploadFile: async function(fieldId, file) {
|
|
const safeId = sanitizeId(fieldId);
|
|
const fileInput = document.getElementById(`${safeId}_file_input`);
|
|
const statusDiv = document.getElementById(`${safeId}_status`);
|
|
const notifyFn = window.showNotification || console.log;
|
|
|
|
// Read config from the file input data attributes
|
|
const pluginId = (fileInput && fileInput.dataset.pluginId) || '';
|
|
const maxSizeMb = parseFloat((fileInput && fileInput.dataset.maxSizeMb) || '5');
|
|
const allowedTypes = ((fileInput && fileInput.dataset.allowedTypes) || 'image/png,image/jpeg,image/bmp,image/gif')
|
|
.split(',').map(t => t.trim());
|
|
|
|
if (!pluginId) {
|
|
notifyFn('Plugin ID not set — cannot upload', 'error');
|
|
return;
|
|
}
|
|
|
|
// Validate type
|
|
if (!allowedTypes.includes(file.type)) {
|
|
notifyFn(`File type "${file.type}" not allowed`, 'error');
|
|
return;
|
|
}
|
|
|
|
// Validate size
|
|
if (file.size > maxSizeMb * 1024 * 1024) {
|
|
notifyFn(`File exceeds ${maxSizeMb}MB limit`, 'error');
|
|
return;
|
|
}
|
|
|
|
// Show uploading status — use DOM methods to avoid innerHTML with dynamic data
|
|
if (statusDiv) {
|
|
statusDiv.className = 'mt-1 text-xs text-gray-500';
|
|
statusDiv.textContent = '';
|
|
const spinner = document.createElement('i');
|
|
spinner.className = 'fas fa-spinner fa-spin mr-1';
|
|
statusDiv.appendChild(spinner);
|
|
statusDiv.appendChild(document.createTextNode('Uploading…'));
|
|
}
|
|
|
|
const formData = new FormData();
|
|
formData.append('plugin_id', pluginId);
|
|
formData.append('files', file);
|
|
|
|
try {
|
|
const response = await fetch('/api/v3/plugins/assets/upload', {
|
|
method: 'POST',
|
|
body: formData
|
|
});
|
|
|
|
if (!response.ok) {
|
|
const body = await response.text();
|
|
throw new Error(`Server error ${response.status}: ${body}`);
|
|
}
|
|
|
|
const data = await response.json();
|
|
|
|
if (data.status === 'success' && data.uploaded_files && data.uploaded_files.length > 0) {
|
|
const uploadedPath = data.uploaded_files[0].path;
|
|
const widget = window.LEDMatrixWidgets.get('file-upload-single');
|
|
widget.setValue(fieldId, uploadedPath);
|
|
triggerChange(fieldId, uploadedPath);
|
|
|
|
if (statusDiv) {
|
|
statusDiv.className = 'mt-1 text-xs text-green-600';
|
|
statusDiv.textContent = '';
|
|
const icon = document.createElement('i');
|
|
icon.className = 'fas fa-check-circle mr-1';
|
|
statusDiv.appendChild(icon);
|
|
statusDiv.appendChild(document.createTextNode('Uploaded successfully'));
|
|
setTimeout(() => { statusDiv.className = 'mt-1 text-xs hidden'; statusDiv.textContent = ''; }, 3000);
|
|
}
|
|
notifyFn('Image uploaded successfully', 'success');
|
|
} else {
|
|
throw new Error(data.message || 'Upload failed');
|
|
}
|
|
} catch (error) {
|
|
if (statusDiv) {
|
|
statusDiv.className = 'mt-1 text-xs text-red-600';
|
|
statusDiv.textContent = '';
|
|
const errIcon = document.createElement('i');
|
|
errIcon.className = 'fas fa-exclamation-circle mr-1';
|
|
statusDiv.appendChild(errIcon);
|
|
statusDiv.appendChild(document.createTextNode(error.message || 'Upload failed'));
|
|
}
|
|
notifyFn(`Upload error: ${error.message}`, 'error');
|
|
} finally {
|
|
if (fileInput) fileInput.value = '';
|
|
}
|
|
}
|
|
}
|
|
});
|
|
|
|
console.log('[FileUploadSingleWidget] File upload single widget registered');
|
|
})();
|