Release 0.80.17 - #3987
Merged
Merged
Release 0.80.17#3987
Conversation
* Track begin-checkout analytics for enrollments Adds `trackBeginCheckout` when a user starts checkout from both the dashboard enrollment flow and the course enrollment dialog. This complements the existing enrollment and cart analytics so purchase funnel tracking reflects the full enrollment journey. * Add trackBeginCheckout and trackAddToCart assertions to enrollment tests Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * Enrich begin checkout analytics event Update begin-checkout GTM tracking to send GA4-friendly checkout data, including course ID, value, currency, and item details. The enrollment flow and related tests now pass structured checkout params instead of only the course name. * Pass course metadata to checkout tracking Update course enrollment to call `trackBeginCheckout` with structured analytics data instead of only the course title. The payload now includes the course name, readable ID, and parsed product price so checkout events capture the metadata expected by downstream tracking. --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…bel in engagement chart (#3966)
…ies (#3972) * fix(news): escape interpolated text/attrs when extracting news summaries _extract_text_from_paragraph built anchor tags (and returned plain text) by directly interpolating editor-supplied text, href, target, and rel into an f-string, with no escaping and no restriction on href's scheme. Since this text is stored in FeedItem.summary and rendered on the public /news page via dangerouslySetInnerHTML, any account in the website_content_editors group (a real, non-admin role) could inject arbitrary HTML/JS -- either by breaking out of the href attribute (e.g. `" onmouseover="...`), by using a javascript: URI, or simply via plain paragraph text containing a literal `<script>` tag with no link at all. Ports over the same escaping and href-scheme-restriction already used safely by the client-side reimplementation of this logic in frontends/main/src/common/websiteContentUtils.ts: HTML-escape all interpolated values (Python's stdlib html.escape, matching that file's own escapeHtml), and replace any non-http(s) href with a safe "#" placeholder rather than passing it through. Verified this produces byte-identical output to before for every existing legitimate test case (plain http(s) links with ordinary target/rel values contain no characters escaping would change). Fixes mitodl/hq#13456 * fix(news): harden against non-string/malformed JSON attrs and malformed URLs Addresses Copilot review feedback on the XSS escaping fix: - urlparse() raises ValueError on malformed URLs like "http://[", which would abort the whole feed sync since transform_items has no per-article exception isolation. Now caught and treated as unsafe. - ProseMirror content is unvalidated JSON, so href/target/rel/text/marks/ attrs can be null, a number, a list, etc. instead of the expected type. Added _safe_str_attr() and applied type guards throughout so a single malformed article can't crash the sync. - Replaced the javascript:-scheme test with one using a valid https:// href and hostile target/rel values, since the javascript: case never actually exercised target/rel escaping. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(news): allow mailto/tel/relative links, not just http(s) The scheme allow-list only permitted http(s), so legitimate mailto:, tel:, and site-relative links (e.g. /news/foo) that editors can create via the link popover (@tiptap/extension-link accepts these) were being replaced with a dead "#" placeholder. Widen _is_safe_link_href to allow mailto/tel schemes and paths starting with a single "/", while still rejecting protocol-relative ("//host") and backslash ("/\host") variants, which browsers treat as other-host URLs. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
OpenAPI ChangesNo changes detected Unexpected changes? Ensure your branch is up-to-date with |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Danielle Frappier
Sar
cp-at-mit