Skip to content

Dev - #2

Open
cr4sh0v3r wants to merge 3975 commits into
cr4sh0v3r:devfrom
nightscout:dev
Open

Dev#2
cr4sh0v3r wants to merge 3975 commits into
cr4sh0v3r:devfrom
nightscout:dev

Conversation

@cr4sh0v3r

Copy link
Copy Markdown
Owner

No description provided.

cr4sh0v3r pushed a commit that referenced this pull request Sep 17, 2018
cr4sh0v3r pushed a commit that referenced this pull request Dec 9, 2022
cr4sh0v3r pushed a commit that referenced this pull request Dec 9, 2022
starfrenzy and others added 27 commits July 7, 2026 15:58
I corrected the links to update and downgrade the Nightscout Version. 

I also found an incorrectly formatted MD link in the "Usage" section.
I added the word "update" for clarity while reading.
Add regression coverage for profile.isAPNSProduction true, explicit false, and absent-field fallback to LOOP_PUSH_SERVER_ENVIRONMENT.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…8549-8528

Wip/bewest/release prs 8547 8549 8528
Bumps [axios](https://github.com/axios/axios) from 0.21.4 to 0.33.0.
- [Release notes](https://github.com/axios/axios/releases)
- [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md)
- [Commits](axios/axios@v0.21.4...v0.33.0)

---
updated-dependencies:
- dependency-name: axios
  dependency-version: 0.33.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [engine.io](https://github.com/socketio/socket.io) to 6.6.9 and updates ancestor dependency [socket.io](https://github.com/socketio/socket.io). These dependencies need to be updated together.


Updates `engine.io` from 6.2.1 to 6.6.9
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/commits/engine.io@6.6.9)

Updates `socket.io` from 4.5.4 to 4.8.3
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/4.5.4...socket.io@4.8.3)

---
updated-dependencies:
- dependency-name: engine.io
  dependency-version: 6.6.9
  dependency-type: indirect
- dependency-name: socket.io
  dependency-version: 4.8.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
A dataloader query in flight while a delete commits can merge stale
results into the freshly flushed cache. The deleted document then stays
in ddata until the retention period expires or the server restarts,
because incremental loads only cover the last 15 minutes and never
revisit its time window. Connected and freshly loaded clients keep
rendering the deleted treatment.

Track a removal generation per datatype in the cache and retry the
entries, treatments, and devicestatus loads when a removal lands while
their query is in flight.
Bumps [body-parser](https://github.com/expressjs/body-parser) and [express](https://github.com/expressjs/express). These dependencies needed to be updated together.

Updates `body-parser` from 1.20.4 to 1.20.6
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](expressjs/body-parser@1.20.4...1.20.6)

Updates `express` from 4.17.1 to 4.22.2
- [Release notes](https://github.com/expressjs/express/releases)
- [Changelog](https://github.com/expressjs/express/blob/v4.22.2/History.md)
- [Commits](expressjs/express@4.17.1...v4.22.2)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 1.20.6
  dependency-type: direct:production
- dependency-name: express
  dependency-version: 4.22.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [d3-color](https://github.com/d3/d3-color) to 3.1.0 and updates ancestor dependency [d3](https://github.com/d3/d3). These dependencies need to be updated together.


Updates `d3-color` from 1.4.1 to 3.1.0
- [Release notes](https://github.com/d3/d3-color/releases)
- [Commits](d3/d3-color@v1.4.1...v3.1.0)

Updates `d3` from 5.16.0 to 7.9.0
- [Release notes](https://github.com/d3/d3/releases)
- [Changelog](https://github.com/d3/d3/blob/main/CHANGES.md)
- [Commits](d3/d3@v5.16.0...v7.9.0)

---
updated-dependencies:
- dependency-name: d3-color
  dependency-version: 3.1.0
  dependency-type: indirect
- dependency-name: d3
  dependency-version: 7.9.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [ip-address](https://github.com/beaugunderson/ip-address) from 10.1.0 to 10.4.0.
- [Release notes](https://github.com/beaugunderson/ip-address/releases)
- [Commits](beaugunderson/ip-address@v10.1.0...v10.4.0)

---
updated-dependencies:
- dependency-name: ip-address
  dependency-version: 10.4.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.0 to 3.1.5.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.0...v3.1.5)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [socket.io-parser](https://github.com/socketio/socket.io) from 4.2.5 to 4.2.7.
- [Release notes](https://github.com/socketio/socket.io/releases)
- [Changelog](https://github.com/socketio/socket.io/blob/main/CHANGELOG.md)
- [Commits](https://github.com/socketio/socket.io/compare/socket.io-parser@4.2.5...socket.io-parser@4.2.7)

---
updated-dependencies:
- dependency-name: socket.io-parser
  dependency-version: 4.2.7
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [dompurify](https://github.com/cure53/DOMPurify) from 2.5.8 to 3.4.13.
- [Release notes](https://github.com/cure53/DOMPurify/releases)
- [Commits](cure53/DOMPurify@2.5.8...3.4.13)

---
updated-dependencies:
- dependency-name: dompurify
  dependency-version: 3.4.13
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [js-yaml](https://github.com/nodeca/js-yaml) to 4.3.1 and updates ancestor dependencies [js-yaml](https://github.com/nodeca/js-yaml), [eslint](https://github.com/eslint/eslint), [mocha](https://github.com/mochajs/mocha) and [nyc](https://github.com/istanbuljs/nyc). These dependencies need to be updated together.


Updates `js-yaml` from 3.14.2 to 4.3.1
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md)
- [Commits](nodeca/js-yaml@3.14.2...4.3.1)

Updates `eslint` from 7.32.0 to 10.8.1
- [Release notes](https://github.com/eslint/eslint/releases)
- [Commits](eslint/eslint@v7.32.0...v10.8.1)

Updates `mocha` from 8.4.0 to 11.8.0
- [Release notes](https://github.com/mochajs/mocha/releases)
- [Changelog](https://github.com/mochajs/mocha/blob/v11.8.0/CHANGELOG.md)
- [Commits](mochajs/mocha@v8.4.0...v11.8.0)

Updates `nyc` from 14.1.1 to 18.0.0
- [Release notes](https://github.com/istanbuljs/nyc/releases)
- [Changelog](https://github.com/istanbuljs/nyc/blob/main/CHANGELOG.md)
- [Commits](istanbuljs/nyc@v14.1.1...nyc-v18.0.0)

---
updated-dependencies:
- dependency-name: js-yaml
  dependency-version: 4.3.1
  dependency-type: indirect
- dependency-name: eslint
  dependency-version: 10.8.1
  dependency-type: direct:development
- dependency-name: mocha
  dependency-version: 11.8.0
  dependency-type: direct:development
- dependency-name: nyc
  dependency-version: 18.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [nanoid](https://github.com/ai/nanoid) to 3.3.18 and updates ancestor dependency [mocha](https://github.com/mochajs/mocha). These dependencies need to be updated together.


Updates `nanoid` from 3.3.11 to 3.3.18
- [Release notes](https://github.com/ai/nanoid/releases)
- [Changelog](https://github.com/ai/nanoid/blob/3.3.18/CHANGELOG.md)
- [Commits](ai/nanoid@3.3.11...3.3.18)

Updates `mocha` from 8.4.0 to 11.8.0
- [Release notes](https://github.com/mochajs/mocha/releases)
- [Changelog](https://github.com/mochajs/mocha/blob/v11.8.0/CHANGELOG.md)
- [Commits](mochajs/mocha@v8.4.0...v11.8.0)

---
updated-dependencies:
- dependency-name: nanoid
  dependency-version: 3.3.18
  dependency-type: indirect
- dependency-name: mocha
  dependency-version: 11.8.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [postcss](https://github.com/postcss/postcss) from 8.5.6 to 8.5.26.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.5.6...8.5.26)

---
updated-dependencies:
- dependency-name: postcss
  dependency-version: 8.5.26
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps  and [brace-expansion](https://github.com/juliangruber/brace-expansion). These dependencies needed to be updated together.

Updates `brace-expansion` from 2.0.2 to 2.1.4
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.0.2...v2.1.4)

Updates `brace-expansion` from 1.1.12 to 1.1.18
- [Release notes](https://github.com/juliangruber/brace-expansion/releases)
- [Commits](juliangruber/brace-expansion@v2.0.2...v2.1.4)

---
updated-dependencies:
- dependency-name: brace-expansion
  dependency-version: 2.1.4
  dependency-type: indirect
- dependency-name: brace-expansion
  dependency-version: 1.1.18
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
The COB pill shows the carbs on board that the uploading system reports when
there is a recent device status, and falls back to the treatment based
calculation otherwise. Loop reports it in loop.cob, and OpenAPS, AndroidAPS and
Trio report it in openaps.suggested or openaps.enacted.

The plugin already preferred device status, but three things got in the way.
The treatment profile check ran before device status was read, so a site with no
profile, or a profile without sens and carbratio, showed no COB pill at all even
though the reported value needs neither. AndroidAPS sends suggested without a
timestamp and enacted with neither a COB nor a timestamp, and the old code
called moment(undefined) for both, which resolves to the current time, so those
records were dated wrong by months and the choice between the two blocks came
down to which millisecond each call landed in. The OpenAPS branch also keyed off
the openaps block being present rather than a usable COB, so it could never fall
through to loop.cob.

The extraction now lives in lib/client-core/devicestatus/cob.js alongside the
other pure device status modules. A block counts only when its COB is a finite
number, and its timestamp dates it, falling back to the record mills. The
freshness rules are unchanged.

The tooltip names the source and device and shows the treatment derived value
when that is not zero. On the properties API cob.treatmentCOB is a number now
instead of an object, and cob.source is translated.
The report keeps at most one sgv per minute, but it advanced the reference
timestamp on every entry - including the ones it rejected. The reference
therefore moved onto entries that were never kept, and the following entry
was compared against a dropped value instead of the last retained one.

Timestamps 0s / 58s / 116s show it:

  before   0 kept, 58 dropped (reference moves to 58), 116 dropped
  after    0 kept, 58 dropped (reference stays 0),     116 kept

A single close reading pulled its neighbours down with it. At the 5-minute
cadence this code was written for the filter never fires, which is why it
went unnoticed; on sub-minute series it removes a large share of entries
that are not duplicates. Since dailystats derives its percentages from the
number of remaining points, reported time in range is skewed accordingly.

The filter moves to lib/report/uniqsgv.js so it can be covered without a
browser environment, following the pattern reportstorage.js already uses in
the same directory. The logic is unchanged apart from the assignment now
sitting in the accepted branch; sorting and the dropped-entry logging stay
with the caller.

Covered by tests/uniqsgv.test.js, including the 0/58/116 regression, exact
one-minute spacing, true duplicates, and an unchanged five-minute series.
Stored-XSS: WebSocket dbAdd/dbUpdate handlers and several REST write
paths persisted attacker-controlled HTML/script markup without
calling ctx.purifier.purifyObject(), unlike POST /treatments/ which
already purified input. Any client rendering that field (e.g. via
.html()) could then execute injected script.

Root-cause fixes (input purification, matches ctx.purifier already
used by POST /treatments/):
- lib/server/websocket.js: purify data.data in processSingleDbAdd()
  and in the dbUpdate handler before persisting to Mongo.
- lib/api/treatments/index.js: purify on PUT (POST already did).
- lib/api/profile/index.js: purify on PUT (POST already did).
- lib/api/food/index.js: purify on POST and PUT (previously
  unpurified on both).
- lib/api/activity/index.js: purify on POST and PUT (previously
  unpurified on both).

tests/websocket.xss-purification.test.js: new regression suite
reproducing the exploit via dbAdd/dbUpdate on treatments and food
collections; fails before the websocket.js fix, passes after.

Verified: full suite 1360 passing, 3 pending (pre-existing), 0
failing.
… in depth)

Complements the server-side purification fix by hardening client
rendering: notes/enteredBy/reason/device/food-name/profile fields
were interpolated into strings passed to jQuery .html(), so any
value that slipped past purification (or reached the DOM via another
path) could still execute as markup.

- lib/utils.js: expose utils.escapeHtml = require('lodash/escape')
  (tree-shaken submodule import per docs/meta/modernization-roadmap.md
  §3, avoids bundling all of lodash). lodash/escape is already a
  direct dependency, has no DOM dependency, and its output is
  security-equivalent to htmlspecialchars()-style escaping (escapes
  & < > " ', sufficient to prevent markup/attribute breakout).
- lib/client/renderer.js: escape notes, enteredBy, reason, device,
  forecastType, transmitterId, sensorCode, and profile fields in all
  tooltip builders (treatmentTooltip, announcementTooltip, BG hover
  tooltip, boluscalcTooltip, profileTooltip) before they reach
  .html(). Falls back to an identity function if utils.escapeHtml is
  unavailable (e.g. test doubles).
- lib/report_plugins/daytoday.js: convert raw .html(treatment.notes)
  and food-summary .html(text) to .text(...); escape
  openaps.suggested.reason/mealAssist which remain in .html() context
  alongside surrounding <b> tags.
- lib/report_plugins/treatments.js: escape foodType/reason/
  glucoseType; convert profile/enteredBy/notes table cells from
  .append(rawString) to .text(rawString).
- lib/client/boluscalc.js: escape food name and translated unit
  inside the food-list HTML table (table structure itself still
  built via .html()).
- tests/utils.test.js: unit tests for utils.escapeHtml (special
  chars, script-tag neutralization, null/undefined, numeric
  coercion).

All escapeHtml call sites here are HTML text-node context only
(never raw unquoted attributes or URLs); jQuery's .attr(name, value)
two-arg form used elsewhere in these same files is inherently safe
regardless of escaping.

Verified: full suite 1360 passing, 3 pending (pre-existing), 0
failing. Client bundle (npm run bundle-dev) compiles cleanly.
AndyLow91 and others added 30 commits September 5, 2026 17:11
…i-f37b900b33

build(deps-dev): update compatible jsdom and analyzer ws with regression tests
…-14.0.0

test(deps): retain patched UUID 11 and protect API identifiers
Use urbanmaksim's translation from issue #8479, preserving all non-empty contributed values. Register lt, fill newer keys with English fallbacks, and replace blank time labels to prevent English fallback. Cover locale loading, placeholders, and timeago behavior.
Apply zehnBE's report in #8662 and the standalone Russian wording contributed by DobbyWanKenoby in #7459. Add locale-loading and status-placeholder regressions.
Adapt FelixKosack's contribution from #7651 with spelling and sample cleanup and AMAZON.FirstName. Document setup and validate backend identifiers, slots, and prompts.
…8675

fix: prevent failed treatments queries from crashing the server
fix: show worried emoji for low and falling clock readings
…sing-8584

fix: preprocess schedules imported by profile switches
fix: preserve valid unnamed profiles in conversion and editor
Add missing --space-after-named-function option to js-beautifly in docs.
Reduce routine log volume and add opt-in debugging (#8714)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants