fix: restore account and profile pages and enforce Chinese UI - #1040
Conversation
Reviewer's GuideUpdates account navigation and userscript processing for XMOJ’s migration to /modify_user_info.php without taking over the site’s native form, while retaining legacy behavior and adding offline Chromium coverage for the affected routes and features. Sequence diagram for migrated account settings processingsequenceDiagram
participant User
participant Page as AccountPage
participant Script as XMOJScript
participant API as BadgeAPI
participant Storage as LocalStorage
User->>Page: Visit /modify_user_info.php
Script->>Page: IsAccountSettingsPage(pathname)
alt ByUserScript parameter present
Script->>Page: Render changelog
else Normal account visit
Script->>API: RequestAPI(GetBadge)
API-->>Script: Badge data
Script->>Page: InitializeAccountBadgeEditor(container)
User->>Script: Click badge submit button
Script->>API: RequestAPI(EditBadge)
API-->>Script: Success or error result
alt Success
Script->>Storage: Remove cached UserScript-User badge keys
end
end
Page-->>User: Preserve native account form and messages
Flow diagram for account route compatibilityflowchart TD
Menu[Account and changelog navigation] --> Migrated["/modify_user_info.php"]
Legacy["/modifypage.php"] --> Detect[IsAccountSettingsPage]
Migrated --> Detect
Detect -->|ByUserScript| Changelog[Render update changelog]
Detect -->|Normal visit| Native[Keep site native form and CSRF fields]
Native --> Badge[Add separate badge editor on migrated route]
Native --> Export[Keep AC code export available]
Detect -->|Missing structure or login/error page| Preserve[Preserve site messages]
File-Level Changes
Possibly linked issues
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Deploying xmoj-script-dev-channel with
|
| Latest commit: |
4593892
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://27aaaaec.xmoj-script-dev-channel.pages.dev |
| Branch Preview URL: | https://codex-fix-account-page-migra.xmoj-script-dev-channel.pages.dev |
There was a problem hiding this comment.
Hey - I've found 1 issue
Fixed security issues:
- Cross-site scripting (XSS) via untrusted HTML/JS injection in web rendering sinks (link)
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="XMOJ.user.js" line_range="2178-2183" />
<code_context>
+ button.addEventListener("click", () => {
+ button.disabled = true;
+ status.innerText = "";
+ RequestAPI("EditBadge", {
+ "UserID": String(CurrentUsername),
+ "Content": content.value,
+ "BackgroundColor": background.value,
+ "Color": color.value
+ }, (result) => {
+ button.disabled = false;
+ status.innerText = result.Success ? "修改成功" : result.Message;
</code_context>
<issue_to_address>
**issue (bug_risk):** When the EditBadge request fails at the transport layer or returns invalid JSON, `RequestAPI` does not invoke the callback, so the badge button remains disabled permanently and the user receives no failure status.
**Triggers:** When saving a badge encounters a network error or malformed API response.
**Suggested fix:** Add an error callback or make `RequestAPI` reject/notify callers on transport and parsing failures, then re-enable the button and display an error message.
</issue_to_address>Sourcery assessment
Needs a human reviewer. 1 finding to address first, and a faulty badge editor could persist an incorrect badge value or colors through the EditBadge API, and reverting the script would not undo that server-side change. The value is bounded and can be corrected by editing the badge again; the native account form and its CSRF fields are preserved.
Blocking findings: XMOJ.user.js:2183
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 67dccb0e83
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
All reported issues were addressed
Reply with feedback, questions, or to request a fix.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 4 files
Requires human review: Auto-approval blocked because this review re-detected 3 unresolved issues already reported by Cubic.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 3 files (changes from recent commits).
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
|
我感觉看上去不错 |
…-migration # Conflicts: # Update.json
There was a problem hiding this comment.
All reported issues were addressed across 5 files (changes from recent commits).
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 5 files (changes from recent commits).
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
There was a problem hiding this comment.
All reported issues were addressed across 4 files (changes from recent commits).
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
5b82e34 to
6737a97
Compare
There was a problem hiding this comment.
All reported issues were addressed across 3 files (changes from recent commits).
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
2f21606 to
f5eaedb
Compare
There was a problem hiding this comment.
1 issue found across 5 files (changes from recent commits).
Prompt for AI agents (unresolved issues)
Check if these issues are valid — if so, understand the root cause of each and fix them. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. If appropriate, use sub-agents to investigate and fix each issue separately.
<file name="XMOJ.user.js">
<violation number="1" location="XMOJ.user.js:2448">
P3: These transparent circles still receive SVG pointer events, so on dense timelines they intercept short accepted bars and hide their `<title>` tooltips. Use a shared tooltip or non-overlapping hit targets so both counts remain discoverable.</violation>
</file>
Tip: Review your code locally with the cubic CLI to iterate faster.
Re-trigger cubic
| const submitted = Node("g", {"data-layer": "submitted"}); | ||
| if (data[0].length) Node("path", {d: data[0].map(([timestamp, count], index) => (index ? "L" : "M") + X(timestamp) + " " + Y(count)).join(" "), fill: "none", stroke: colors[0], "stroke-width": "1.25", "stroke-opacity": "0.8", "data-series": "submitted"}, null, submitted); | ||
| for (const [timestamp, count] of data[0]) { | ||
| const point = Node("circle", {cx: X(timestamp), cy: Y(count), r: data[0].length === 1 ? "3" : "5", fill: data[0].length === 1 ? colors[0] : "transparent", "data-series": "submitted"}, null, submitted); |
There was a problem hiding this comment.
P3: These transparent circles still receive SVG pointer events, so on dense timelines they intercept short accepted bars and hide their <title> tooltips. Use a shared tooltip or non-overlapping hit targets so both counts remain discoverable.
Prompt for AI agents
Check if this issue is valid — if so, understand the root cause and fix it. When an issue isn't valid or won't be fixed in this PR, reply in its thread with the reason and then resolve the thread. At XMOJ.user.js, line 2448:
<comment>These transparent circles still receive SVG pointer events, so on dense timelines they intercept short accepted bars and hide their `<title>` tooltips. Use a shared tooltip or non-overlapping hit targets so both counts remain discoverable.</comment>
<file context>
@@ -2424,32 +2425,34 @@ function InitializeProfileActivityChart(chart) {
+ const submitted = Node("g", {"data-layer": "submitted"});
+ if (data[0].length) Node("path", {d: data[0].map(([timestamp, count], index) => (index ? "L" : "M") + X(timestamp) + " " + Y(count)).join(" "), fill: "none", stroke: colors[0], "stroke-width": "1.25", "stroke-opacity": "0.8", "data-series": "submitted"}, null, submitted);
+ for (const [timestamp, count] of data[0]) {
+ const point = Node("circle", {cx: X(timestamp), cy: Y(count), r: data[0].length === 1 ? "3" : "5", fill: data[0].length === 1 ? colors[0] : "transparent", "data-series": "submitted"}, null, submitted);
+ Node("title", {}, DateLabel(timestamp) + " 提交:" + count, point);
+ }
</file context>
What does this PR aim to accomplish?:
Fix account navigation and userscript features after XMOJ migrated account editing from
/modifypage.phpto/modify_user_info.php. Restore missing profile sections when optional requests fail or stall, and replace the broken native submission-history renderer. Remove language selectors and enforce Chinese across the classic and/webUIs.Closes #920.
Closes #618.
How does this PR accomplish the above?:
/modify_user_info.php. Redirect defunct/modifypage.phplinks to the current endpoint, preserving their query and fragment; remove the obsolete account/password form replacement and POST handler.<form>and is separate from native account controls. Preserve native fields, CSRF data, and submit listeners; keep AC-code export available./weblanguage cookie at document-start and hide navigation, statement, and native account-form language selectors. Select the Chinese account radio and preserve that value on native submit and FormData serialization without disabling its inputs or disturbing other account fields. Persist the classic preference when the current account form is saved; remove calls to the broken/change_lang.phpendpoint and the resulting classic-page reloads. Keep Chinese statements selected after Vue navigation, and prevent/webreload loops with a retry message if its cookie preference is refused.stash@{0}request safeguards: ordinary API requests time out after 30 seconds and report transport failures once; requests with recovery callbacks retain their 15-second limit. The stashes’ contest compatibility, Markdown/TeX copying, and ended-contest fallback are already included through prior merges. Preserve both stash entries and retain the current implementations when resolving their older code. Update the compatibility documentation to reflect Chinese-only UI.Validation: all 90 tests pass using the installed Chromium via
XMOJ_CHROMIUM.node --check XMOJ.user.jsandgit diff --checkpass. Use the actual relative-time formatter in profile tests and verify readable last-online text plus the native date tooltip. Exercise the actual document-start redirect and verify classic pages never call the broken language endpoint or reload. Cover wrapped and direct account radio groups, numeric language values, preservation of nickname/CSRF fields and submit handlers, and Chinese serialization after English is reselected programmatically. Visually checked the profile layout using the configured Bootstrap stylesheet and monochrome skin. For the replacement graph, rendered 290 submission records and 224 accepted records from the live profile in light, dark, and mobile layouts; tested rendering with Flot absent, both cleanup settings, safe parsing, sorting/deduplication, data/tooltips, narrow axes, and empty/unavailable history. Verify that both series share one graph and baseline, matching dates align, accepted bars paint behind the thin submission line, both layers use transparency, and dense submission markers remain invisible. Verify that a lone history point is visible and single-date histories render only one centered date label.Live authenticated account editing was not tested. The final checklist remains unchecked because template item 11 requires human verification with the installed userscript.
By submitting this pull request, I confirm the following:
git rebase)Summary by Sourcery
Restore userscript account features across XMOJ’s migrated and legacy settings pages.
New Features:
Bug Fixes:
Enhancements:
Build:
Tests:
Summary by cubic
Restores XMOJ account and profile pages after account editing moved to
/modify_user_info.php, replaces the broken native submission-history renderer, and enforces Chinese across the classic and/webUIs. Closes #920 and #618, and bumps the userscript and package to 3.8.3.Bug Fixes
/modifypage.phplinks redirect with query and fragment preserved, and legacy account editing stays available./webcookie is set at document-start, classic English sessions are switched via the native endpoint, and reload loops are prevented.Verification note: Live authenticated editing wasn't tested; please verify with the installed userscript in both the new and classic XMOJ UIs before merging.
Written for commit 4593892. Summary will update on new commits.