Dev - #2
Open
cr4sh0v3r wants to merge 3975 commits into
Open
Conversation
cr4sh0v3r
pushed a commit
that referenced
this pull request
Sep 17, 2018
cr4sh0v3r
pushed a commit
that referenced
this pull request
Dec 9, 2022
cr4sh0v3r
pushed a commit
that referenced
this pull request
Dec 9, 2022
I corrected the links to update and downgrade the Nightscout Version. I also found an incorrectly formatted MD link in the "Usage" section.
I added the word "update" for clarity while reading.
Add regression coverage for profile.isAPNSProduction true, explicit false, and absent-field fallback to LOOP_PUSH_SERVER_ENVIRONMENT. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…8549-8528 Wip/bewest/release prs 8547 8549 8528
Bumps [axios](https://github.com/axios/axios) from 0.21.4 to 0.33.0. - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](axios/axios@v0.21.4...v0.33.0) --- updated-dependencies: - dependency-name: axios dependency-version: 0.33.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [engine.io](https://github.com/socketio/socket.io) to 6.6.9 and updates ancestor dependency [socket.io](https://github.com/socketio/socket.io). These dependencies need to be updated together. Updates `engine.io` from 6.2.1 to 6.6.9 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md) - [Commits](https://github.com/socketio/socket.io/commits/engine.io@6.6.9) Updates `socket.io` from 4.5.4 to 4.8.3 - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md) - [Commits](https://github.com/socketio/socket.io/compare/4.5.4...socket.io@4.8.3) --- updated-dependencies: - dependency-name: engine.io dependency-version: 6.6.9 dependency-type: indirect - dependency-name: socket.io dependency-version: 4.8.3 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
A dataloader query in flight while a delete commits can merge stale results into the freshly flushed cache. The deleted document then stays in ddata until the retention period expires or the server restarts, because incremental loads only cover the last 15 minutes and never revisit its time window. Connected and freshly loaded clients keep rendering the deleted treatment. Track a removal generation per datatype in the cache and retry the entries, treatments, and devicestatus loads when a removal lands while their query is in flight.
Bumps [body-parser](https://github.com/expressjs/body-parser) and [express](https://github.com/expressjs/express). These dependencies needed to be updated together. Updates `body-parser` from 1.20.4 to 1.20.6 - [Release notes](https://github.com/expressjs/body-parser/releases) - [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md) - [Commits](expressjs/body-parser@1.20.4...1.20.6) Updates `express` from 4.17.1 to 4.22.2 - [Release notes](https://github.com/expressjs/express/releases) - [Changelog](https://github.com/expressjs/express/blob/v4.22.2/History.md) - [Commits](expressjs/express@4.17.1...v4.22.2) --- updated-dependencies: - dependency-name: body-parser dependency-version: 1.20.6 dependency-type: direct:production - dependency-name: express dependency-version: 4.22.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [d3-color](https://github.com/d3/d3-color) to 3.1.0 and updates ancestor dependency [d3](https://github.com/d3/d3). These dependencies need to be updated together. Updates `d3-color` from 1.4.1 to 3.1.0 - [Release notes](https://github.com/d3/d3-color/releases) - [Commits](d3/d3-color@v1.4.1...v3.1.0) Updates `d3` from 5.16.0 to 7.9.0 - [Release notes](https://github.com/d3/d3/releases) - [Changelog](https://github.com/d3/d3/blob/main/CHANGES.md) - [Commits](d3/d3@v5.16.0...v7.9.0) --- updated-dependencies: - dependency-name: d3-color dependency-version: 3.1.0 dependency-type: indirect - dependency-name: d3 dependency-version: 7.9.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.1.0 to 10.4.0. - [Release notes](https://github.com/beaugunderson/ip-address/releases) - [Commits](beaugunderson/ip-address@v10.1.0...v10.4.0) --- updated-dependencies: - dependency-name: ip-address dependency-version: 10.4.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.0 to 3.1.5. - [Release notes](https://github.com/fastify/fast-uri/releases) - [Commits](fastify/fast-uri@v3.1.0...v3.1.5) --- updated-dependencies: - dependency-name: fast-uri dependency-version: 3.1.5 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [socket.io-parser](https://github.com/socketio/socket.io) from 4.2.5 to 4.2.7. - [Release notes](https://github.com/socketio/socket.io/releases) - [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md) - [Commits](https://github.com/socketio/socket.io/compare/socket.io-parser@4.2.5...socket.io-parser@4.2.7) --- updated-dependencies: - dependency-name: socket.io-parser dependency-version: 4.2.7 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 2.5.8 to 3.4.13. - [Release notes](https://github.com/cure53/DOMPurify/releases) - [Commits](cure53/DOMPurify@2.5.8...3.4.13) --- updated-dependencies: - dependency-name: dompurify dependency-version: 3.4.13 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [js-yaml](https://github.com/nodeca/js-yaml) to 4.3.1 and updates ancestor dependencies [js-yaml](https://github.com/nodeca/js-yaml), [eslint](https://github.com/eslint/eslint), [mocha](https://github.com/mochajs/mocha) and [nyc](https://github.com/istanbuljs/nyc). These dependencies need to be updated together. Updates `js-yaml` from 3.14.2 to 4.3.1 - [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md) - [Commits](nodeca/js-yaml@3.14.2...4.3.1) Updates `eslint` from 7.32.0 to 10.8.1 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v7.32.0...v10.8.1) Updates `mocha` from 8.4.0 to 11.8.0 - [Release notes](https://github.com/mochajs/mocha/releases) - [Changelog](https://github.com/mochajs/mocha/blob/v11.8.0/CHANGELOG.md) - [Commits](mochajs/mocha@v8.4.0...v11.8.0) Updates `nyc` from 14.1.1 to 18.0.0 - [Release notes](https://github.com/istanbuljs/nyc/releases) - [Changelog](https://github.com/istanbuljs/nyc/blob/main/CHANGELOG.md) - [Commits](istanbuljs/nyc@v14.1.1...nyc-v18.0.0) --- updated-dependencies: - dependency-name: js-yaml dependency-version: 4.3.1 dependency-type: indirect - dependency-name: eslint dependency-version: 10.8.1 dependency-type: direct:development - dependency-name: mocha dependency-version: 11.8.0 dependency-type: direct:development - dependency-name: nyc dependency-version: 18.0.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [nanoid](https://github.com/ai/nanoid) to 3.3.18 and updates ancestor dependency [mocha](https://github.com/mochajs/mocha). These dependencies need to be updated together. Updates `nanoid` from 3.3.11 to 3.3.18 - [Release notes](https://github.com/ai/nanoid/releases) - [Changelog](https://github.com/ai/nanoid/blob/3.3.18/CHANGELOG.md) - [Commits](ai/nanoid@3.3.11...3.3.18) Updates `mocha` from 8.4.0 to 11.8.0 - [Release notes](https://github.com/mochajs/mocha/releases) - [Changelog](https://github.com/mochajs/mocha/blob/v11.8.0/CHANGELOG.md) - [Commits](mochajs/mocha@v8.4.0...v11.8.0) --- updated-dependencies: - dependency-name: nanoid dependency-version: 3.3.18 dependency-type: indirect - dependency-name: mocha dependency-version: 11.8.0 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.6 to 8.5.26. - [Release notes](https://github.com/postcss/postcss/releases) - [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md) - [Commits](postcss/postcss@8.5.6...8.5.26) --- updated-dependencies: - dependency-name: postcss dependency-version: 8.5.26 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together. Updates `brace-expansion` from 2.0.2 to 2.1.4 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v2.0.2...v2.1.4) Updates `brace-expansion` from 1.1.12 to 1.1.18 - [Release notes](https://github.com/juliangruber/brace-expansion/releases) - [Commits](juliangruber/brace-expansion@v2.0.2...v2.1.4) --- updated-dependencies: - dependency-name: brace-expansion dependency-version: 2.1.4 dependency-type: indirect - dependency-name: brace-expansion dependency-version: 1.1.18 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
The COB pill shows the carbs on board that the uploading system reports when there is a recent device status, and falls back to the treatment based calculation otherwise. Loop reports it in loop.cob, and OpenAPS, AndroidAPS and Trio report it in openaps.suggested or openaps.enacted. The plugin already preferred device status, but three things got in the way. The treatment profile check ran before device status was read, so a site with no profile, or a profile without sens and carbratio, showed no COB pill at all even though the reported value needs neither. AndroidAPS sends suggested without a timestamp and enacted with neither a COB nor a timestamp, and the old code called moment(undefined) for both, which resolves to the current time, so those records were dated wrong by months and the choice between the two blocks came down to which millisecond each call landed in. The OpenAPS branch also keyed off the openaps block being present rather than a usable COB, so it could never fall through to loop.cob. The extraction now lives in lib/client-core/devicestatus/cob.js alongside the other pure device status modules. A block counts only when its COB is a finite number, and its timestamp dates it, falling back to the record mills. The freshness rules are unchanged. The tooltip names the source and device and shows the treatment derived value when that is not zero. On the properties API cob.treatmentCOB is a number now instead of an object, and cob.source is translated.
The report keeps at most one sgv per minute, but it advanced the reference timestamp on every entry - including the ones it rejected. The reference therefore moved onto entries that were never kept, and the following entry was compared against a dropped value instead of the last retained one. Timestamps 0s / 58s / 116s show it: before 0 kept, 58 dropped (reference moves to 58), 116 dropped after 0 kept, 58 dropped (reference stays 0), 116 kept A single close reading pulled its neighbours down with it. At the 5-minute cadence this code was written for the filter never fires, which is why it went unnoticed; on sub-minute series it removes a large share of entries that are not duplicates. Since dailystats derives its percentages from the number of remaining points, reported time in range is skewed accordingly. The filter moves to lib/report/uniqsgv.js so it can be covered without a browser environment, following the pattern reportstorage.js already uses in the same directory. The logic is unchanged apart from the assignment now sitting in the accepted branch; sorting and the dropped-entry logging stay with the caller. Covered by tests/uniqsgv.test.js, including the 0/58/116 regression, exact one-minute spacing, true duplicates, and an unchanged five-minute series.
Stored-XSS: WebSocket dbAdd/dbUpdate handlers and several REST write paths persisted attacker-controlled HTML/script markup without calling ctx.purifier.purifyObject(), unlike POST /treatments/ which already purified input. Any client rendering that field (e.g. via .html()) could then execute injected script. Root-cause fixes (input purification, matches ctx.purifier already used by POST /treatments/): - lib/server/websocket.js: purify data.data in processSingleDbAdd() and in the dbUpdate handler before persisting to Mongo. - lib/api/treatments/index.js: purify on PUT (POST already did). - lib/api/profile/index.js: purify on PUT (POST already did). - lib/api/food/index.js: purify on POST and PUT (previously unpurified on both). - lib/api/activity/index.js: purify on POST and PUT (previously unpurified on both). tests/websocket.xss-purification.test.js: new regression suite reproducing the exploit via dbAdd/dbUpdate on treatments and food collections; fails before the websocket.js fix, passes after. Verified: full suite 1360 passing, 3 pending (pre-existing), 0 failing.
… in depth)
Complements the server-side purification fix by hardening client
rendering: notes/enteredBy/reason/device/food-name/profile fields
were interpolated into strings passed to jQuery .html(), so any
value that slipped past purification (or reached the DOM via another
path) could still execute as markup.
- lib/utils.js: expose utils.escapeHtml = require('lodash/escape')
(tree-shaken submodule import per docs/meta/modernization-roadmap.md
§3, avoids bundling all of lodash). lodash/escape is already a
direct dependency, has no DOM dependency, and its output is
security-equivalent to htmlspecialchars()-style escaping (escapes
& < > " ', sufficient to prevent markup/attribute breakout).
- lib/client/renderer.js: escape notes, enteredBy, reason, device,
forecastType, transmitterId, sensorCode, and profile fields in all
tooltip builders (treatmentTooltip, announcementTooltip, BG hover
tooltip, boluscalcTooltip, profileTooltip) before they reach
.html(). Falls back to an identity function if utils.escapeHtml is
unavailable (e.g. test doubles).
- lib/report_plugins/daytoday.js: convert raw .html(treatment.notes)
and food-summary .html(text) to .text(...); escape
openaps.suggested.reason/mealAssist which remain in .html() context
alongside surrounding <b> tags.
- lib/report_plugins/treatments.js: escape foodType/reason/
glucoseType; convert profile/enteredBy/notes table cells from
.append(rawString) to .text(rawString).
- lib/client/boluscalc.js: escape food name and translated unit
inside the food-list HTML table (table structure itself still
built via .html()).
- tests/utils.test.js: unit tests for utils.escapeHtml (special
chars, script-tag neutralization, null/undefined, numeric
coercion).
All escapeHtml call sites here are HTML text-node context only
(never raw unquoted attributes or URLs); jQuery's .attr(name, value)
two-arg form used elsewhere in these same files is inherently safe
regardless of escaping.
Verified: full suite 1360 passing, 3 pending (pre-existing), 0
failing. Client bundle (npm run bundle-dev) compiles cleanly.
…i-f37b900b33 build(deps-dev): update compatible jsdom and analyzer ws with regression tests
…-14.0.0 test(deps): retain patched UUID 11 and protect API identifiers
[ci skip]
[ci skip]
Use urbanmaksim's translation from issue #8479, preserving all non-empty contributed values. Register lt, fill newer keys with English fallbacks, and replace blank time labels to prevent English fallback. Cover locale loading, placeholders, and timeago behavior.
Adapt FelixKosack's contribution from #7651 with spelling and sample cleanup and AMAZON.FirstName. Document setup and validate backend identifiers, slots, and prompts.
New Crowdin updates
…8675 fix: prevent failed treatments queries from crashing the server
fix: show worried emoji for low and falling clock readings
…sing-8584 fix: preprocess schedules imported by profile switches
fix: preserve valid unnamed profiles in conversion and editor
Add missing --space-after-named-function option to js-beautifly in docs.
Reduce routine log volume and add opt-in debugging (#8714)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.