Skip to content

Release 0.80.17 - #3987

Merged
odlbot merged 8 commits into
releasefrom
release-candidate
Sep 24, 2026
Merged

odlbot merged 8 commits into
releasefrom
release-candidate

Conversation

@odlbot

@odlbot odlbot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Danielle Frappier

Sar

cp-at-mit

cp-at-mit and others added 8 commits September 23, 2026 11:55
* Track begin-checkout analytics for enrollments

Adds `trackBeginCheckout` when a user starts checkout from both the dashboard enrollment flow and the course enrollment dialog. This complements the existing enrollment and cart analytics so purchase funnel tracking reflects the full enrollment journey.

* Add trackBeginCheckout and trackAddToCart assertions to enrollment tests

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Enrich begin checkout analytics event

Update begin-checkout GTM tracking to send GA4-friendly checkout data, including course ID, value, currency, and item details. The enrollment flow and related tests now pass structured checkout params instead of only the course name.

* Pass course metadata to checkout tracking

Update course enrollment to call `trackBeginCheckout` with structured analytics data instead of only the course title. The payload now includes the course name, readable ID, and parsed product price so checkout events capture the metadata expected by downstream tracking.

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
…ies (#3972)

* fix(news): escape interpolated text/attrs when extracting news summaries

_extract_text_from_paragraph built anchor tags (and returned plain text) by
directly interpolating editor-supplied text, href, target, and rel into an
f-string, with no escaping and no restriction on href's scheme. Since this
text is stored in FeedItem.summary and rendered on the public /news page via
dangerouslySetInnerHTML, any account in the website_content_editors group
(a real, non-admin role) could inject arbitrary HTML/JS -- either by
breaking out of the href attribute (e.g. `" onmouseover="...`), by using a
javascript: URI, or simply via plain paragraph text containing a literal
`<script>` tag with no link at all.

Ports over the same escaping and href-scheme-restriction already used
safely by the client-side reimplementation of this logic in
frontends/main/src/common/websiteContentUtils.ts: HTML-escape all
interpolated values (Python's stdlib html.escape, matching that file's own
escapeHtml), and replace any non-http(s) href with a safe "#" placeholder
rather than passing it through. Verified this produces byte-identical
output to before for every existing legitimate test case (plain http(s)
links with ordinary target/rel values contain no characters escaping would
change).

Fixes mitodl/hq#13456

* fix(news): harden against non-string/malformed JSON attrs and malformed URLs

Addresses Copilot review feedback on the XSS escaping fix:
- urlparse() raises ValueError on malformed URLs like "http://[", which
  would abort the whole feed sync since transform_items has no per-article
  exception isolation. Now caught and treated as unsafe.
- ProseMirror content is unvalidated JSON, so href/target/rel/text/marks/
  attrs can be null, a number, a list, etc. instead of the expected type.
  Added _safe_str_attr() and applied type guards throughout so a single
  malformed article can't crash the sync.
- Replaced the javascript:-scheme test with one using a valid https://
  href and hostile target/rel values, since the javascript: case never
  actually exercised target/rel escaping.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(news): allow mailto/tel/relative links, not just http(s)

The scheme allow-list only permitted http(s), so legitimate mailto:,
tel:, and site-relative links (e.g. /news/foo) that editors can create
via the link popover (@tiptap/extension-link accepts these) were being
replaced with a dead "#" placeholder.

Widen _is_safe_link_href to allow mailto/tel schemes and paths starting
with a single "/", while still rejecting protocol-relative ("//host")
and backslash ("/\host") variants, which browsers treat as other-host
URLs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
@odlbot
odlbot requested a review from a team as a code owner September 24, 2026 15:04
@github-actions

Copy link
Copy Markdown

OpenAPI Changes

No changes detected

View full changelog

Unexpected changes? Ensure your branch is up-to-date with main (consider rebasing).

@odlbot
odlbot merged commit 30e6aac into release Sep 24, 2026
25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants