Skip to content

[pull] main from forem:main - #401

Merged
pull[bot] merged 2 commits into
amishakov:mainfrom
forem:main
Sep 25, 2026
Merged

pull[bot] merged 2 commits into
amishakov:mainfrom
forem:main

Conversation

@pull

@pull pull Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Banyel3 and others added 2 commits September 25, 2026 13:29
… paste import (#23186)

* Add one-time XML paste import for bot-protected RSS feeds

Users whose feed URLs are blocked by Cloudflare or other bot protection
can paste raw RSS/Atom XML directly to import articles as drafts.

- Feeds::ImportFromXml service parses pasted XML via Feedjira and
  creates articles using existing AssembleArticleMarkdown and
  CheckItemPreviouslyImported services (max 500KB, dedup safe)
- Feeds::XmlImportsController handles POST /feeds/xml_imports
- Dashboard UI adds always-visible XML import card with one-time-only
  warning and a hint near the feed URL form linking to it
- i18n strings added for en, fr, pt

* Improve error message when RSS feed URL returns non-2xx response

Non-2xx responses (e.g. Cloudflare 403) now raise a descriptive error
instead of falling through to Feedjira and showing the misleading
'is not a valid RSS feed URL' message.

* Fix failing CI specs for XML import

- Fix unauthenticated redirect expectation: app redirects to
  /magic_links/new not /enter
- Fix ordered Article.create! mock in error-recovery test; use
  AssembleArticleMarkdown raise instead to avoid RSpec double ordering
  issues

* Address Copilot feedback: improve link safety, URL normalization, and logging

* Address Copilot feedback: raise descriptive error for all non-2xx feed responses

* Harden XML paste import authorization, URL validation i18n, and test coverage

* Address Copilot feedback: prevent SSRF, handle concurrency, and add textarea label

- Disable remote network fetches during AssembleArticleMarkdown in XML imports and restrict Medium iframe host parsing
- Wrap ImportFromXml execution in user.with_lock to serialize concurrent submissions and prevent duplicate drafts
- Add accessible label for XML content textarea with en, fr, and pt translations
- Add regression specs for SSRF prevention, per-user locking, and textarea label rendering

* Refactor: simplify medium host validation and consolidate XML import specs

- Reuse medium_host? helper in AssembleArticleMarkdown to deduplicate URL parsing
- Inline user.with_lock block in ImportFromXml
- Consolidate duplicate draft and per-user locking spec in import_from_xml_spec

* Test(feeds): add controller and deduplication unit specs for XML import

- Add XmlImportsController spec verifying authorization, redirects, and flash notices
- Add CheckItemPreviouslyImported unit spec verifying title/URL matching and nil guards

* Fix(feeds): sanitize and strip feed_url in ValidateUrl

---------

Co-authored-by: Mikey Dorje <mikeydorje@gmail.com>
Allows hiding the "You're now a part of the community!" onboarding task
card on the home feed entirely. Default behavior is unchanged.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
@pull pull Bot locked and limited conversation to collaborators Sep 25, 2026
@pull pull Bot added the ⤵️ pull label Sep 25, 2026
@pull
pull Bot merged commit 15a9934 into amishakov:main Sep 25, 2026
2 of 4 checks passed

This branch had an error being deployed

1 failed deployment
staging — 15a9934d Deployed Sep 25, 2026 by pull[bot] via deploy (staging) #377
production — 15a9934d Deployed Sep 25, 2026 by pull[bot] via deploy (production) #377
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants