diff --git a/.eslintignore b/.eslintignore
index 21af2df92..fc0214dd2 100644
--- a/.eslintignore
+++ b/.eslintignore
@@ -25,5 +25,6 @@ plugins/*
!plugins/talk-plugin-moderation-actions
!plugins/talk-plugin-toxic-comments
!plugins/talk-plugin-remember-sort
+!plugins/talk-plugin-deep-reply-count
node_modules
diff --git a/.eslintrc.json b/.eslintrc.json
index 8ca153cbc..d7ed3908e 100644
--- a/.eslintrc.json
+++ b/.eslintrc.json
@@ -1,63 +1,74 @@
{
- "env": {
- "es6": true,
- "node": true
- },
- "extends": [
- "eslint:recommended"
- ],
- "parserOptions": {
- "ecmaVersion": 2017
- },
- "plugins": [
- "promise",
- "json"
- ],
- "rules": {
- "indent": ["error", 2],
- "no-console": "off",
- "linebreak-style": ["error", "unix"],
- "quotes": ["error", "single"],
- "semi": ["error", "always"],
- "no-template-curly-in-string": "warn",
- "no-unsafe-negation": "warn",
- "array-callback-return": "warn",
- "arrow-parens": ["warn", "always"],
- "template-curly-spacing": "warn",
- "eqeqeq": ["error", "smart"],
- "no-eval": "error",
- "no-global-assign": "error",
- "no-implied-eval": "error",
- "lines-around-comment": ["warn", {"beforeLineComment": true}],
- "spaced-comment": ["warn", "always", {"line": {"exceptions": ["-", "="]}}],
- "no-script-url": "error",
- "no-throw-literal": "error",
- "yoda": "warn",
- "no-path-concat": "error",
- "eol-last": "warn",
- "no-nested-ternary": "warn",
- "no-tabs": "error",
- "no-unneeded-ternary": "warn",
- "object-curly-spacing": "warn",
- "space-infix-ops": ["error"],
- "space-in-parens": ["error", "never"],
- "space-unary-ops": ["error", {"words": true, "nonwords": false}],
- "no-const-assign": "error",
- "no-duplicate-imports": "error",
- "prefer-template": "warn",
- "comma-spacing": ["error", {"after": true}],
- "no-var": "error",
- "no-lonely-if": "error",
- "curly": "error",
- "no-unused-vars": ["error", {"argsIgnorePattern": "^_|next", "varsIgnorePattern": "^_"}],
- "no-multiple-empty-lines": ["error", {"max": 1}],
- "newline-per-chained-call": ["error", {"ignoreChainWithDepth": 2}],
- "promise/no-return-wrap": "error",
- "promise/param-names": "error",
- "promise/catch-or-return": "warn",
- "promise/no-native": "off",
- "promise/no-nesting": "warn",
- "promise/no-promise-in-callback": "warn",
- "promise/no-callback-in-promise": "warn"
- }
+ "env": {
+ "es6": true,
+ "node": true
+ },
+ "extends": [
+ "eslint:recommended",
+ "plugin:react/recommended"
+ ],
+ "parserOptions": {
+ "ecmaVersion": 2017
+ },
+ "plugins": [
+ "json",
+ "promise",
+ "react"
+ ],
+ "rules": {
+ "promise/no-return-wrap": "error",
+ "promise/param-names": "error",
+ "promise/catch-or-return": "warn",
+ "promise/no-native": "off",
+ "promise/no-nesting": "warn",
+ "promise/no-promise-in-callback": "warn",
+ "promise/no-callback-in-promise": "warn",
+
+ // TODO: Change all these to "error", or remove and use defaults.
+ "react/display-name": "off",
+ "react/jsx-no-duplicate-props": "warn",
+ "react/jsx-no-target-blank": "warn",
+ "react/no-find-dom-node": "warn",
+ "react/no-unknown-property": "warn",
+ "react/prop-types": "off",
+
+ "array-callback-return": "warn",
+ "arrow-parens": ["warn", "always"],
+ "comma-spacing": ["error", {"after": true}],
+ "curly": "error",
+ "eol-last": "warn",
+ "eqeqeq": ["error", "smart"],
+ "indent": ["error", 2],
+ "linebreak-style": ["error", "unix"],
+ "lines-around-comment": ["warn", {"beforeLineComment": true}],
+ "newline-per-chained-call": ["error", {"ignoreChainWithDepth": 2}],
+ "no-console": "off",
+ "no-const-assign": "error",
+ "no-duplicate-imports": "error",
+ "no-eval": "error",
+ "no-global-assign": "error",
+ "no-implied-eval": "error",
+ "no-lonely-if": "error",
+ "no-multiple-empty-lines": ["error", {"max": 1}],
+ "no-nested-ternary": "warn",
+ "no-path-concat": "error",
+ "no-script-url": "error",
+ "no-tabs": "error",
+ "no-template-curly-in-string": "warn",
+ "no-throw-literal": "error",
+ "no-unneeded-ternary": "warn",
+ "no-unsafe-negation": "warn",
+ "no-unused-vars": ["error", {"argsIgnorePattern": "^_|next", "varsIgnorePattern": "^_"}],
+ "no-var": "error",
+ "object-curly-spacing": "warn",
+ "prefer-template": "warn",
+ "quotes": ["error", "single"],
+ "semi": ["error", "always"],
+ "space-in-parens": ["error", "never"],
+ "space-infix-ops": ["error"],
+ "space-unary-ops": ["error", {"words": true, "nonwords": false}],
+ "spaced-comment": ["warn", "always", {"line": {"exceptions": ["-", "="]}}],
+ "template-curly-spacing": "warn",
+ "yoda": "warn"
+ }
}
diff --git a/.gitignore b/.gitignore
index bba75a377..bcc7c89b1 100644
--- a/.gitignore
+++ b/.gitignore
@@ -42,5 +42,6 @@ plugins/*
!plugins/talk-plugin-moderation-actions
!plugins/talk-plugin-toxic-comments
!plugins/talk-plugin-remember-sort
+!plugins/talk-plugin-deep-reply-count
**/node_modules/*
diff --git a/README.md b/README.md
index 4bec86d07..57562fc1a 100644
--- a/README.md
+++ b/README.md
@@ -6,11 +6,14 @@ Online comments are broken. Our open-source Talk tool rethinks how moderation, c
Third party licenses are available via the `/client/3rdpartylicenses.txt`
endpoint when the server is running with built assets.
-## Important Links
+## Try Talk!
-- Developer Documentation & Setup Guides: https://coralproject.github.io/talk/
+- Developer Documentation & Setup Guides: https://coralproject.github.io/talk/ (includes Installation Guide, Quickstart, Plugin Guide, API Docs, and more)
+
+## Roadmap and Release Schedule
+
+- Talk Roadmap: https://www.pivotaltracker.com/n/projects/1863625
-- Pivotal Tracker Backlog & Release Schedule: https://www.pivotaltracker.com/n/projects/1863625
## Learn More about Coral
diff --git a/client/coral-admin/src/actions/userDetail.js b/client/coral-admin/src/actions/userDetail.js
index fe9aa2df5..504183f97 100644
--- a/client/coral-admin/src/actions/userDetail.js
+++ b/client/coral-admin/src/actions/userDetail.js
@@ -4,10 +4,8 @@ export const viewUserDetail = (userId) => ({type: actions.VIEW_USER_DETAIL, user
export const hideUserDetail = () => ({type: actions.HIDE_USER_DETAIL});
export const changeUserDetailStatuses = (tab) => {
- let statuses;
- if (tab === 'all') {
- statuses = ['NONE', 'ACCEPTED', 'REJECTED', 'PREMOD'];
- } else if (tab === 'rejected') {
+ let statuses = [];
+ if (tab === 'rejected') {
statuses = ['REJECTED'];
}
return {type: actions.CHANGE_USER_DETAIL_STATUSES, tab, statuses};
diff --git a/client/coral-admin/src/components/CommentBodyHighlighter.js b/client/coral-admin/src/components/CommentBodyHighlighter.js
index 9a430f7c7..e27d3ce6d 100644
--- a/client/coral-admin/src/components/CommentBodyHighlighter.js
+++ b/client/coral-admin/src/components/CommentBodyHighlighter.js
@@ -1,25 +1,78 @@
import React from 'react';
-import Highlighter from 'react-highlight-words';
-import Linkify from 'react-linkify';
-const linkify = new Linkify();
+import {matchLinks} from '../utils';
+import memoize from 'lodash/memoize';
+
+function escapeRegExp(string) {
+ return string.replace(/[.*+?^${}()|[\]\\]/g, '\\$&'); // $& means the whole matched string
+}
+
+// generate a regulare expression that catches the `phrases`.
+function generateRegExp(phrases) {
+ const inner = phrases
+ .map((phrase) =>
+ phrase.split(/\s+/)
+ .map((word) => escapeRegExp(word))
+ .join('[\\s"?!.]+')
+ ).join('|');
+
+ return new RegExp(`(^|[^\\w])(${inner})(?=[^\\w]|$)`, 'iu');
+}
+
+// Generate a regular expression detecting `suspectWords` and `bannedWords` phrases.
+function getPhrasesRegexp(suspectWords, bannedWords) {
+ return generateRegExp([...suspectWords, ...bannedWords]);
+}
+
+// Memoized version as arguments rarely change.
+const getPhrasesRegexpMemoized = memoize(getPhrasesRegexp);
+
+// markPhrases looks for `supsectWords` and `bannedWords` inside `body` and highlights them by returning
+// an array of React Elements.
+function markPhrases(body, suspectWords, bannedWords, keyPrefix) {
+ const regexp = getPhrasesRegexpMemoized(suspectWords, bannedWords);
+ const tokens = body.split(regexp);
+ return tokens.map((token, i) =>
+ i % 3 === 2
+ ? {token}
+ : token
+ );
+}
+
+// markLinks looks for links inside `body` and highlights them by returning
+// an array of React Elements.
+function markLinks(body) {
+ const matches = matchLinks(body);
+ const content = [];
+ let index = 0;
+ if (matches) {
+ matches
+ .forEach((match, i) => {
+ content.push(body.substring(index, match.index));
+ content.push({match.text});
+ index = match.lastIndex;
+ });
+ }
+ content.push(body.substring(index));
+ return content;
+}
export default ({suspectWords, bannedWords, body, ...rest}) => {
- const links = linkify.getMatches(body);
- const linkText = links ? links.map((link) => link.raw) : [];
+ // First highlight links.
+ const content = markLinks(body)
+ .map((element, index) => {
- const searchWords = [
- ...suspectWords,
- ...bannedWords,
- ...linkText
- ];
+ // Keep highlighted links.
+ if (typeof element !== 'string') {
+ return element;
+ }
+ // Highlight suspect and banned phrase inside this part of text.
+ return markPhrases(element, suspectWords, bannedWords, index);
+ });
return (
-
+
+ {content}
+
);
};
diff --git a/client/coral-admin/src/components/IfHasLink.js b/client/coral-admin/src/components/IfHasLink.js
index cd37ea951..73b335815 100644
--- a/client/coral-admin/src/components/IfHasLink.js
+++ b/client/coral-admin/src/components/IfHasLink.js
@@ -1,9 +1,8 @@
import React from 'react';
-import Linkify from 'react-linkify';
-const linkify = new Linkify();
+import {matchLinks} from '../utils';
export default ({text, children}) => {
- const hasLinks = !!linkify.getMatches(text);
+ const hasLinks = !!matchLinks(text);
if (!hasLinks) {
return null;
diff --git a/client/coral-admin/src/reducers/userDetail.js b/client/coral-admin/src/reducers/userDetail.js
index 8e1d35885..524dcfa31 100644
--- a/client/coral-admin/src/reducers/userDetail.js
+++ b/client/coral-admin/src/reducers/userDetail.js
@@ -3,7 +3,7 @@ import * as actions from '../constants/userDetail';
const initialState = {
userId: null,
activeTab: 'all',
- statuses: ['NONE', 'ACCEPTED', 'REJECTED', 'PREMOD'],
+ statuses: [],
selectedCommentIds: [],
};
diff --git a/client/coral-admin/src/routes/Configure/components/EmbedLink.js b/client/coral-admin/src/routes/Configure/components/EmbedLink.js
index be0a13d5e..1ce3d5304 100644
--- a/client/coral-admin/src/routes/Configure/components/EmbedLink.js
+++ b/client/coral-admin/src/routes/Configure/components/EmbedLink.js
@@ -1,6 +1,6 @@
import React, {Component} from 'react';
import t from 'coral-framework/services/i18n';
-import {join} from 'path';
+import join from 'url-join';
import styles from './Configure.css';
import {Button, Card} from 'coral-ui';
import {BASE_URL} from 'coral-framework/constants/url';
diff --git a/client/coral-admin/src/routes/Moderation/components/Comment.js b/client/coral-admin/src/routes/Moderation/components/Comment.js
index 9d9428bc4..a3edb4196 100644
--- a/client/coral-admin/src/routes/Moderation/components/Comment.js
+++ b/client/coral-admin/src/routes/Moderation/components/Comment.js
@@ -127,7 +127,7 @@ class Comment extends React.Component {
-
+
{t('comment.view_context')}
-
+
mod === 'PRE';
export const getModPath = (type = 'all', assetId) =>
assetId ? `/admin/moderate/${type}/${assetId}` : `/admin/moderate/${type}`;
+
diff --git a/client/coral-embed-stream/src/components/Comment.js b/client/coral-embed-stream/src/components/Comment.js
index 2b8c565da..c6a3b740d 100644
--- a/client/coral-embed-stream/src/components/Comment.js
+++ b/client/coral-embed-stream/src/components/Comment.js
@@ -341,8 +341,8 @@ export default class Comment extends React.Component {
emit,
commentClassNames = []
} = this.props;
-
- if (this.commentIsRejected(comment)) {
+
+ if (!highlighted && this.commentIsRejected(comment)) {
return ;
}
diff --git a/client/coral-embed-stream/src/components/Stream.js b/client/coral-embed-stream/src/components/Stream.js
index 43176353f..af2ec698b 100644
--- a/client/coral-embed-stream/src/components/Stream.js
+++ b/client/coral-embed-stream/src/components/Stream.js
@@ -201,7 +201,7 @@ class Stream extends React.Component {
data,
root,
appendItemArray,
- root: {asset, asset: {comment: highlightedComment, comments}},
+ root: {asset, asset: {comment: highlightedComment}},
postComment,
notify,
updateItem,
@@ -222,9 +222,8 @@ class Stream extends React.Component {
const slotProps = {data};
const slotQueryData = {root, asset};
- if (!highlightedComment && !comments) {
- console.error('Talk: No comments came back from the graph given that query. Please, check the query params.');
- return ;
+ if (highlightedComment === null) {
+ return {t('stream.comment_not_found')};
}
return (
diff --git a/client/coral-embed-stream/src/components/StreamError.js b/client/coral-embed-stream/src/components/StreamError.js
index 2e8b8ff96..2c381c720 100644
--- a/client/coral-embed-stream/src/components/StreamError.js
+++ b/client/coral-embed-stream/src/components/StreamError.js
@@ -1,9 +1,8 @@
import React from 'react';
import styles from './StreamError.css';
-import t from 'coral-framework/services/i18n';
-export const StreamError = () => (
+export const StreamError = ({children}) => (
- {t('common.error')}
+ {children}
);
diff --git a/client/coral-embed-stream/src/containers/Stream.js b/client/coral-embed-stream/src/containers/Stream.js
index 273d39589..6c3d7b02c 100644
--- a/client/coral-embed-stream/src/containers/Stream.js
+++ b/client/coral-embed-stream/src/containers/Stream.js
@@ -51,7 +51,7 @@ class StreamContainer extends React.Component {
return prev;
}
- if (['PREMOD', 'REJECTED'].includes(commentEdited.status)) {
+ if (['PREMOD', 'REJECTED', 'SYSTEM_WITHHELD'].includes(commentEdited.status)) {
return removeCommentFromEmbedQuery(prev, commentEdited.id);
}
},
@@ -178,7 +178,7 @@ class StreamContainer extends React.Component {
render() {
if (!this.props.root.asset
- || !this.props.root.asset.comment
+ || this.props.root.asset.comment === undefined
&& !this.props.root.asset.comments
) {
return ;
diff --git a/client/coral-embed-stream/src/graphql/index.js b/client/coral-embed-stream/src/graphql/index.js
index ad281ce0c..dc81b56a4 100644
--- a/client/coral-embed-stream/src/graphql/index.js
+++ b/client/coral-embed-stream/src/graphql/index.js
@@ -77,6 +77,14 @@ export default {
title
url
}
+ actions {
+ __typename
+ id
+ ... on FlagAction {
+ reason
+ message
+ }
+ }
tags {
tag {
name
@@ -166,7 +174,7 @@ export default {
},
updateQueries: {
CoralEmbedStream_Embed: (prev, {mutationResult: {data: {createComment: {comment}}}}) => {
- if (prev.asset.settings.moderation === 'PRE' || comment.status === 'PREMOD' || comment.status === 'REJECTED') {
+ if (prev.asset.settings.moderation === 'PRE' || comment.status === 'PREMOD' || comment.status === 'REJECTED' || comment.status === 'SYSTEM_WITHHELD') {
return prev;
}
return insertCommentIntoEmbedQuery(prev, comment);
@@ -185,7 +193,7 @@ export default {
EditComment: () => ({
updateQueries: {
CoralEmbedStream_Embed: (prev, {mutationResult: {data: {editComment: {comment}}}}) => {
- if (!['PREMOD', 'REJECTED'].includes(comment.status)) {
+ if (!['PREMOD', 'REJECTED', 'SYSTEM_WITHHELD'].includes(comment.status)) {
return null;
}
return removeCommentFromEmbedQuery(prev, comment.id);
diff --git a/client/coral-embed-stream/src/index.js b/client/coral-embed-stream/src/index.js
index c8d3101ab..841b7b3d0 100644
--- a/client/coral-embed-stream/src/index.js
+++ b/client/coral-embed-stream/src/index.js
@@ -42,7 +42,7 @@ function preInit({store, pym}) {
return new Promise((resolve) => {
pym.sendMessage('getConfig');
pym.onMessage('config', (config) => {
- store.dispatch(addExternalConfig(config));
+ store.dispatch(addExternalConfig(JSON.parse(config)));
store.dispatch(checkLogin());
resolve();
});
diff --git a/client/talk-plugin-commentbox/CommentBox.js b/client/talk-plugin-commentbox/CommentBox.js
index 8bdfb9a24..c85dfb306 100644
--- a/client/talk-plugin-commentbox/CommentBox.js
+++ b/client/talk-plugin-commentbox/CommentBox.js
@@ -13,10 +13,10 @@ export const name = 'talk-plugin-commentbox';
// Given a newly posted comment's status, show a notification to the user
// if needed
-export const notifyForNewCommentStatus = (notify, status) => {
- if (status === 'REJECTED') {
+export const notifyForNewCommentStatus = (notify, comment) => {
+ if (comment.status === 'REJECTED') {
notify('error', t('comment_box.comment_post_banned_word'));
- } else if (status === 'PREMOD') {
+ } else if (comment.status === 'PREMOD' || comment.status === 'SYSTEM_WITHHELD') {
notify('success', t('comment_box.comment_post_notif_premod'));
}
};
@@ -74,7 +74,7 @@ class CommentBox extends React.Component {
// Execute postSubmit Hooks
this.state.hooks.postSubmit.forEach((hook) => hook(data));
- notifyForNewCommentStatus(notify, postedComment.status);
+ notifyForNewCommentStatus(notify, postedComment);
if (commentPostedHandler) {
commentPostedHandler();
diff --git a/docs/_docs/01-03-install-source.md b/docs/_docs/01-03-install-source.md
index da6fa120d..443d233c4 100644
--- a/docs/_docs/01-03-install-source.md
+++ b/docs/_docs/01-03-install-source.md
@@ -56,7 +56,7 @@ yarn build
## Running
-Refer to the `README.md` file for required configuration variables to add to the
+Refer to the [configuration](https://coralproject.github.io/talk/docs/running/configuration/) page for required configuration variables to add to the
environment.
You can start the server after configuring the server using the command:
diff --git a/graph/mutators/comment.js b/graph/mutators/comment.js
index c6e335018..75cad99b7 100644
--- a/graph/mutators/comment.js
+++ b/graph/mutators/comment.js
@@ -6,7 +6,10 @@ const ActionsService = require('../../services/actions');
const TagsService = require('../../services/tags');
const CommentsService = require('../../services/comments');
const KarmaService = require('../../services/karma');
-const linkify = require('linkify-it')();
+const tlds = require('tlds');
+const merge = require('lodash/merge');
+const linkify = require('linkify-it')()
+ .tlds(tlds);
const Wordlist = require('../../services/wordlist');
const {
CREATE_COMMENT,
@@ -154,7 +157,7 @@ const adjustKarma = (Comments, id, status) => async () => {
* @param {String} [status='NONE'] the status of the new comment
* @return {Promise} resolves to the created comment
*/
-const createComment = async (context, {tags = [], body, asset_id, parent_id = null, metadata = {}}, status = 'NONE') => {
+const createComment = async (context, {tags = [], body, asset_id, parent_id = null, status = 'NONE', metadata = {}}) => {
const {user, loaders: {Comments}, pubsub} = context;
// Resolve the tags for the comment.
@@ -222,6 +225,173 @@ const filterNewComment = async (context, {body, asset_id}) => {
];
};
+/**
+ * moderationPhases is an array of phases carried out in order until a status is
+ * returned.
+ */
+const moderationPhases = [
+
+ // This phase checks to see if the comment is long enough.
+ (context, comment) => {
+
+ // Check to see if the body is too short, if it is, then complain about it!
+ if (comment.body.length < 2) {
+ throw errors.ErrCommentTooShort;
+ }
+ },
+
+ // This phase checks to see if the asset being processed is closed or not.
+ (context, comment, {asset}) => {
+
+ // Check to see if the asset has closed commenting...
+ if (asset.isClosed) {
+ throw new errors.ErrAssetCommentingClosed(asset.closedMessage);
+ }
+ },
+
+ // This phase checks the comment against the wordlist.
+ (context, comment, {wordlist}) => {
+
+ // Decide the status based on whether or not the current asset/settings
+ // has pre-mod enabled or not. If the comment was rejected based on the
+ // wordlist, then reject it, otherwise if the moderation setting is
+ // premod, set it to `premod`.
+ if (wordlist.banned) {
+
+ // Add the flag related to Trust to the comment.
+ return {
+ status: 'REJECTED',
+ actions: [{
+ action_type: 'FLAG',
+ user_id: null,
+ group_id: 'BANNED_WORD',
+ metadata: {}
+ }]
+ };
+ }
+
+ // If the comment has a suspect word or a link, we need to add a
+ // flag to it to indicate that it needs to be looked at.
+ // Otherwise just return the new comment.
+
+ // If the wordlist has matched the suspect word filter and we haven't disabled
+ // auto-flagging suspect words, then we should flag the comment!
+ if (wordlist.suspect && !DISABLE_AUTOFLAG_SUSPECT_WORDS) {
+
+ // TODO: this is kind of fragile, we should refactor this to resolve
+ // all these const's that we're using like 'COMMENTS', 'FLAG' to be
+ // defined in a checkable schema.
+ return {
+ actions: [{
+ action_type: 'FLAG',
+ user_id: null,
+ group_id: 'Matched suspect word filter',
+ metadata: {}
+ }],
+ };
+ }
+ },
+
+ // This phase checks to see if the comment's length exeeds maximum.
+ (context, comment, {assetSettings: {charCountEnable, charCount}}) => {
+
+ // Reject if the comment is too long
+ if (charCountEnable && comment.body.length > charCount) {
+
+ // Add the flag related to Trust to the comment.
+ return {
+ status: 'REJECTED',
+ actions: [{
+ action_type: 'FLAG',
+ user_id: null,
+ group_id: 'BODY_COUNT',
+ metadata: {
+ count: comment.body.length,
+ }
+ }]
+ };
+ }
+ },
+
+ // This phase checks the comment if it has any links in it if the check is
+ // enabled.
+ (context, comment, {assetSettings: {premodLinksEnable}}) => {
+ if (premodLinksEnable && linkify.test(comment.body)) {
+
+ // Add the flag related to Trust to the comment.
+ return {
+ status:'SYSTEM_WITHHELD',
+ actions: [{
+ action_type: 'FLAG',
+ user_id: null,
+ group_id: 'LINKS',
+ metadata: {
+ links: comment.body,
+ }
+ }],
+ };
+ }
+ },
+
+ // This phase checks to see if the user making the comment is allowed to do so
+ // considering their reliability (Trust) status.
+ (context) => {
+ if (context.user && context.user.metadata) {
+
+ // If the user is not a reliable commenter (passed the unreliability
+ // threshold by having too many rejected comments) then we can change the
+ // status of the comment to `SYSTEM_WITHHELD`, therefore pushing the user's
+ // comments away from the public eye until a moderator can manage them. This of
+ // course can only be applied if the comment's current status is `NONE`,
+ // we don't want to interfere if the comment was rejected.
+ if (KarmaService.isReliable('comment', context.user.metadata.trust) === false) {
+
+ // Add the flag related to Trust to the comment.
+ return {
+ status: 'SYSTEM_WITHHELD',
+ actions: [{
+ action_type: 'FLAG',
+ user_id: null,
+ group_id: 'TRUST',
+ metadata: {
+ trust: context.user.metadata.trust,
+ }
+ }],
+ };
+ }
+ }
+ },
+
+ // This phase checks to see if the comment was already perscribed a status.
+ (context, comment) => {
+
+ // If the status was already defined, don't redefine it. It's only defined
+ // when specific external conditions exist, we don't want to override that.
+ if (comment.status && comment.status.length > 0) {
+ return {
+ status: comment.status,
+ };
+ }
+ },
+
+ // This phase checks to see if the settings have premod enabled, if they do,
+ // the comment is premod, otherwise, it's just none.
+ (context, comment, {assetSettings: {moderation}}) => {
+
+ // If the settings say that we're in premod mode, then the comment is in
+ // premod status.
+ if (moderation === 'PRE') {
+ return {
+ status: 'PREMOD',
+ };
+ }
+
+ return {
+ status: 'NONE',
+ };
+ }
+];
+
/**
* This resolves a given comment's status to take into account moderator actions
* are applied.
@@ -231,62 +401,44 @@ const filterNewComment = async (context, {body, asset_id}) => {
* @param {Object} [wordlist={}] the results of the wordlist scan
* @return {Promise} resolves to the comment's status
*/
-const resolveNewCommentStatus = async (context, {asset_id, body, status}, wordlist = {}, settings = {}) => {
- let {user} = context;
+const resolveCommentModeration = async (context, comment) => {
- // Check to see if the body is too short, if it is, then complain about it!
- if (body.length < 2) {
- throw errors.ErrCommentTooShort;
- }
+ // First we filter the comment contents to ensure that we note any validation
+ // issues.
+ let [wordlist, settings] = await filterNewComment(context, comment);
- // Decide the status based on whether or not the current asset/settings
- // has pre-mod enabled or not. If the comment was rejected based on the
- // wordlist, then reject it, otherwise if the moderation setting is
- // premod, set it to `premod`.
- if (wordlist.banned) {
- return 'REJECTED';
- }
-
- if (settings.premodLinksEnable && linkify.test(body)) {
- return 'PREMOD';
- }
-
- let asset = await AssetsService.findById(asset_id);
+ // Get the asset from the loader.
+ const asset = await context.loaders.Assets.getByID.load(comment.asset_id);
if (!asset) {
+
+ // And leave now if this asset wasn't found.
throw errors.ErrNotFound;
}
- // Check to see if the asset has closed commenting...
- if (asset.isClosed) {
- throw new errors.ErrAssetCommentingClosed(asset.closedMessage);
- }
+ // Combine the asset and the settings to get the asset settings.
+ const assetSettings = await AssetsService.rectifySettings(asset, settings);
- // Return `premod` if pre-moderation is enabled and an empty "new" status
- // in the event that it is not in pre-moderation mode.
- let {moderation, charCountEnable, charCount} = await AssetsService.rectifySettings(asset, settings);
+ // Loop over all the moderation phases and see if we've resolved the status.
+ for (const phase of moderationPhases) {
+ const result = await phase(context, comment, {
+ asset,
+ assetSettings,
+ settings,
+ wordlist,
+ });
- // Reject if the comment is too long
- if (charCountEnable && body.length > charCount) {
- return 'REJECTED';
- }
+ if (result) {
- if (user && user.metadata) {
+ // Merge the comment and the result together.
+ comment = merge(comment, result);
- // If the user is not a reliable commenter (passed the unreliability
- // threshold by having too many rejected comments) then we can change the
- // status of the comment to `PREMOD`, therefore pushing the user's comments
- // away from the public eye until a moderator can manage them. This of
- // course can only be applied if the comment's current status is `NONE`,
- // we don't want to interfere if the comment was rejected.
- if (KarmaService.isReliable('comment', user.metadata.trust) === false) {
-
- // Update the response from the comment creation to add the PREMOD so that
- // that user's UI will reflect the fact that their comment is in pre-mod.
- return 'PREMOD';
+ // If this result contained a status, then we've finished resolving
+ // phases!
+ if (result.status) {
+ return comment.actions;
+ }
}
}
-
- return (moderation === 'PRE' || status === 'PREMOD') ? 'PREMOD' : 'NONE';
};
/**
@@ -297,47 +449,31 @@ const resolveNewCommentStatus = async (context, {asset_id, body, status}, wordli
* @param {Object} commentInput the new comment to be created
* @return {Promise} resolves to a new comment
*/
-const createPublicComment = async (context, commentInput) => {
-
- // First we filter the comment contents to ensure that we note any validation
- // issues.
- let [wordlist, settings] = await filterNewComment(context, commentInput);
+const createPublicComment = async (context, comment) => {
// We then take the wordlist and the comment into consideration when
// considering what status to assign the new comment, and resolve the new
// status to set the comment to.
- let status = await resolveNewCommentStatus(context, commentInput, wordlist, settings);
+ let actions = await resolveCommentModeration(context, comment);
// Then we actually create the comment with the new status.
- let comment = await createComment(context, commentInput, status);
+ comment = await createComment(context, comment);
- // If the comment has a suspect word or a link, we need to add a
- // flag to it to indicate that it needs to be looked at.
- // Otherwise just return the new comment.
-
- // TODO: Check why the wordlist is undefined
-
- // If the wordlist has matched the suspect word filter and we haven't disabled
- // auto-flagging suspect words, then we should flag the comment!
- if (wordlist != null && wordlist.suspect != null && !DISABLE_AUTOFLAG_SUSPECT_WORDS) {
-
- // TODO: this is kind of fragile, we should refactor this to resolve
- // all these const's that we're using like 'COMMENTS', 'FLAG' to be
- // defined in a checkable schema.
- await ActionsService.create({
- item_id: comment.id,
- item_type: 'COMMENTS',
- action_type: 'FLAG',
- user_id: null,
- group_id: 'Matched suspect word filter',
- metadata: {}
- });
- }
+ // Create all the actions that were determined during the moderation check
+ // phase.
+ await createActions(comment.id, actions);
// Finally, we return the comment.
return comment;
};
+// createActions will for each of the provided actions, create the given action
+// on the comment at the same time using Promise.all.
+const createActions = async (item_id, actions = []) => Promise.all(actions.map((action) => merge(action, {
+ item_id,
+ item_type: 'COMMENTS',
+})).map((action) => ActionsService.create(action)));
+
/**
* Sets the status of a comment
* @param {Object} context graphql context
@@ -374,14 +510,19 @@ const setStatus = async ({user, loaders: {Comments}}, {id, status}) => {
*/
const edit = async (context, {id, asset_id, edit: {body}}) => {
- // Get the wordlist and the settings object.
- const [wordlist, settings] = await filterNewComment(context, {asset_id, body});
+ // Build up the new comment we're setting. We need to check this with
+ // moderation now.
+ let comment = {id, asset_id, body};
// Determine the new status of the comment.
- const status = await resolveNewCommentStatus(context, {asset_id, body}, wordlist, settings);
+ const actions = await resolveCommentModeration(context, comment);
// Execute the edit.
- const comment = await CommentsService.edit({id, author_id: context.user.id, body, status});
+ comment = await CommentsService.edit({id, author_id: context.user.id, body, status: comment.status});
+
+ // Create all the actions that were determined during the moderation check
+ // phase.
+ await createActions(comment.id, actions);
// Publish the edited comment via the subscription.
context.pubsub.publish('commentEdited', comment);
diff --git a/graph/typeDefs.graphql b/graph/typeDefs.graphql
index 3191ddf06..e9d850bd3 100644
--- a/graph/typeDefs.graphql
+++ b/graph/typeDefs.graphql
@@ -242,6 +242,10 @@ enum COMMENT_STATUS {
# new comments that haven't been moderated yet are referred to as
# "premoderated" or "premod" comments.
PREMOD
+
+ # SYSTEM_WITHHELD represents a comment that was withheld by the system because
+ # it was flagged by an internal process for further review.
+ SYSTEM_WITHHELD
}
# The types of action there are as enums.
@@ -378,7 +382,8 @@ type Comment {
# the replies that were made to the comment.
replies(query: RepliesQuery = {}): CommentConnection!
- # The count of replies on a comment.
+ # replyCount is the number of replies with a depth of 1. Only direct replies
+ # to this comment are counted.
replyCount: Int
# Actions completed on the parent. Requires the `ADMIN` role.
diff --git a/locales/en.yml b/locales/en.yml
index 6d94393b2..9e1bf1056 100644
--- a/locales/en.yml
+++ b/locales/en.yml
@@ -323,6 +323,7 @@ en:
user_no_comment: "You've never left a comment. Join the conversation!"
stream:
temporarily_suspended: "In accordance with {0}'s community guidelines, your account has been temporarily suspended. Please rejoin the conversation {1}."
+ comment_not_found: "Comment was not found"
step_1_header: "Report an issue"
step_2_header: "Help us understand"
step_3_header: "Thank you for your input"
diff --git a/locales/es.yml b/locales/es.yml
index db25ab527..83edac80b 100644
--- a/locales/es.yml
+++ b/locales/es.yml
@@ -349,6 +349,7 @@ es:
step_3_header: "Gracias por tu participación"
stream:
temporarily_suspended: "De acuerdo con la guía de la comunidad de {0}, su cuenta ha sido temporalmente suspendida. Por favor unirse a la conversación {1}."
+ comment_not_found: "Comentario no encontrado"
streams:
all: "Todos"
article: "Artículo"
diff --git a/models/enum/comment_status.js b/models/enum/comment_status.js
index 64633e9de..a0648f72e 100644
--- a/models/enum/comment_status.js
+++ b/models/enum/comment_status.js
@@ -2,5 +2,6 @@ module.exports = [
'ACCEPTED',
'REJECTED',
'PREMOD',
+ 'SYSTEM_WITHHELD',
'NONE'
];
diff --git a/package.json b/package.json
index 29ba80ae8..1bae1f243 100644
--- a/package.json
+++ b/package.json
@@ -136,7 +136,6 @@
"morgan": "^1.8.2",
"ms": "^2.0.0",
"murmurhash-js": "^1.0.0",
- "natural": "^0.5.4",
"node-emoji": "^1.8.1",
"node-fetch": "^1.7.2",
"nodemailer": "^2.6.4",
@@ -154,9 +153,7 @@
"react": "^15.4.2",
"react-apollo": "^1.4.12",
"react-dom": "^15.4.2",
- "react-highlight-words": "^0.6.0",
"react-input-autosize": "^1.1.4",
- "react-linkify": "^0.1.3",
"react-mdl": "^1.7.2",
"react-mdl-selectfield": "^0.2.0",
"react-recaptcha": "^2.2.6",
@@ -177,6 +174,8 @@
"subscriptions-transport-ws": "^0.7.2",
"timeago.js": "^2.0.3",
"timekeeper": "^1.0.0",
+ "tlds": "^1.196.0",
+ "url-join": "^2.0.2",
"url-loader": "^0.5.9",
"url-search-params": "^0.9.0",
"uuid": "^3.1.0",
diff --git a/plugins/talk-plugin-deep-reply-count/index.js b/plugins/talk-plugin-deep-reply-count/index.js
new file mode 100644
index 000000000..f46386c62
--- /dev/null
+++ b/plugins/talk-plugin-deep-reply-count/index.js
@@ -0,0 +1,81 @@
+const _ = require('lodash');
+const DataLoader = require('dataloader');
+
+const CommentModel = require('../../models/comment');
+
+console.warn('Enabling the talk-plugin-deep-reply-count plugin introduces a signifigant performance impact on larger sites, use with care.');
+
+// genDeepCommentCount will return the deep comment count for a given parent id.
+const genDeepCommentCount = async (context, parent_ids) => {
+
+ // Get all the replies to the parent comments.
+ const replies = await CommentModel
+ .find({
+ parent_id: {
+ $in: _.uniq(parent_ids),
+ },
+ }, {
+ id: 1,
+ reply_count: 1,
+ parent_id: 1,
+ });
+
+ // Get all the replies that have comments on them.
+ const commentedOnReplies = replies.filter(({reply_count}) => {
+ return reply_count && reply_count > 0;
+ });
+
+ let deepReplyCount = [];
+
+ // And if there were any..
+ if (commentedOnReplies.length > 0) {
+
+ // Load the reply count for each of them.
+ deepReplyCount = await context.loaders.Comments.getDeepCount.loadMany(_.uniq(commentedOnReplies.map(({id}) => {
+ return id;
+ })));
+ }
+
+ // Get all the direct replies to the parent comments.
+ const allDirectReplies = _.groupBy(replies, 'parent_id');
+
+ // Collect all the ancestor replies.
+ const allAncestorReplies = _.groupBy(_.zip(commentedOnReplies, deepReplyCount), ([{parent_id}]) => {
+ return parent_id;
+ });
+
+ // Return the replies in an array matching that of the input parent_ids array.
+ return parent_ids.map((parent_id) => {
+
+ // Get the direct replies to this comment.
+ const directReplies = parent_id in allDirectReplies ? allDirectReplies[parent_id] : [];
+ const ancestorReplies = parent_id in allAncestorReplies ? allAncestorReplies[parent_id] : [];
+
+ // Reduce this array.
+ return ancestorReplies.reduce((acc, [, count]) => {
+ return acc + count;
+ }, directReplies.length);
+ });
+};
+
+module.exports = {
+ typeDefs: `
+ type Comment {
+
+ # deepReplyCount is the count of all decendant replies.
+ deepReplyCount: Int
+ }
+ `,
+ loaders: (context) => ({
+ Comments: {
+ getDeepCount: new DataLoader((parent_ids) => genDeepCommentCount(context, parent_ids)),
+ }
+ }),
+ resolvers: {
+ Comment: {
+ deepReplyCount({id}, args, {loaders: {Comments}}) {
+ return Comments.getDeepCount.load(id);
+ }
+ }
+ }
+};
diff --git a/plugins/talk-plugin-toxic-comments/server/hooks.js b/plugins/talk-plugin-toxic-comments/server/hooks.js
index 7fd138641..a74c61a8c 100644
--- a/plugins/talk-plugin-toxic-comments/server/hooks.js
+++ b/plugins/talk-plugin-toxic-comments/server/hooks.js
@@ -1,6 +1,5 @@
const {getScores, isToxic} = require('./perspective');
const {ErrToxic} = require('./errors');
-const ActionsService = require('../../../services/actions');
// We don't add the hooks during _test_ as the perspective API is not available.
if (process.env.NODE_ENV === 'test') {
@@ -12,55 +11,36 @@ module.exports = {
createComment: {
async pre(_, {input}, _context, _info) {
- let scores;
-
// Try getting scores.
+ let scores;
try {
scores = await getScores(input.body);
- }
- catch(err) {
+ } catch(err) {
// Warn and let mutation pass.
console.trace(err);
return;
}
- const commentIsToxic = isToxic(scores);
-
- if (input.checkToxicity && commentIsToxic) {
- throw ErrToxic;
- }
-
- // attach scores to metadata.
+ // Attach scores to metadata.
input.metadata = Object.assign({}, input.metadata, {
perspective: scores,
});
- if (commentIsToxic) {
+ if (isToxic(scores)) {
+ if (input.checkToxicity) {
+ throw ErrToxic;
+ }
- // TODO: this should have a different status than Premod.
- input.status = 'PREMOD';
- }
- },
- async post(_, _input, _context, _info, result) {
- const metadata = result.comment.metadata;
- if (metadata.perspective && isToxic(metadata.perspective)) {
-
- // TODO: this is kind of fragile, we should refactor this to resolve
- // all these const's that we're using like 'COMMENTS', 'FLAG' to be
- // defined in a checkable schema.
-
- // Add a flag to the comment.
- await ActionsService.create({
- item_id: result.comment.id,
- item_type: 'COMMENTS',
+ input.status = 'SYSTEM_WITHHELD';
+ input.actions = input.actions && input.actions.length >= 0 ? input.actions : [];
+ input.actions.push({
action_type: 'FLAG',
user_id: null,
- group_id: 'Comment contains toxic language',
+ group_id: 'TOXIC_COMMENT',
metadata: {}
});
}
- return result;
},
},
},
diff --git a/routes/api/assets/index.js b/routes/api/assets/index.js
index 87014b86e..1b2b0c7a9 100644
--- a/routes/api/assets/index.js
+++ b/routes/api/assets/index.js
@@ -1,5 +1,6 @@
const express = require('express');
const router = express.Router();
+const authorization = require('../../../middleware/authorization');
const errors = require('../../../errors');
const AssetsService = require('../../../services/assets');
@@ -33,7 +34,7 @@ const FilterOpenAssets = (query, filter) => {
};
// List assets.
-router.get('/', async (req, res, next) => {
+router.get('/', authorization.needed('ADMIN', 'MODERATOR'), async (req, res, next) => {
const {
limit = 20,
@@ -72,7 +73,7 @@ router.get('/', async (req, res, next) => {
});
// Get an asset by id.
-router.get('/:asset_id', async (req, res, next) => {
+router.get('/:asset_id', authorization.needed('ADMIN', 'MODERATOR'), async (req, res, next) => {
try {
// Send back the asset.
@@ -87,7 +88,7 @@ router.get('/:asset_id', async (req, res, next) => {
}
});
-router.put('/:asset_id/settings', async (req, res, next) => {
+router.put('/:asset_id/settings', authorization.needed('ADMIN'), async (req, res, next) => {
try {
await AssetsService.overrideSettings(req.params.asset_id, req.body);
res.status(204).end();
@@ -96,7 +97,7 @@ router.put('/:asset_id/settings', async (req, res, next) => {
}
});
-router.put('/:asset_id/status', async (req, res, next) => {
+router.put('/:asset_id/status', authorization.needed('ADMIN'), async (req, res, next) => {
const {
closedAt,
closedMessage
diff --git a/routes/api/index.js b/routes/api/index.js
index eccd8d435..e44f1e7e5 100644
--- a/routes/api/index.js
+++ b/routes/api/index.js
@@ -1,5 +1,4 @@
const express = require('express');
-const authorization = require('../../middleware/authorization');
const pkg = require('../../package.json');
const router = express.Router();
@@ -8,8 +7,8 @@ router.get('/', (req, res) => {
res.json({version: pkg.version});
});
-router.use('/assets', authorization.needed('ADMIN'), require('./assets'));
-router.use('/settings', authorization.needed('ADMIN'), require('./settings'));
+router.use('/assets', require('./assets'));
+router.use('/settings', require('./settings'));
router.use('/auth', require('./auth'));
router.use('/users', require('./users'));
router.use('/account', require('./account'));
diff --git a/routes/api/settings/index.js b/routes/api/settings/index.js
index fb54494d1..5202f9a56 100644
--- a/routes/api/settings/index.js
+++ b/routes/api/settings/index.js
@@ -1,9 +1,10 @@
const express = require('express');
const SettingsService = require('../../../services/settings');
+const authorization = require('../../../middleware/authorization');
const router = express.Router();
-router.get('/', async (req, res, next) => {
+router.get('/', authorization.needed('ADMIN', 'MODERATOR'), async (req, res, next) => {
try {
let settings = await SettingsService.retrieve();
res.json(settings);
@@ -12,7 +13,7 @@ router.get('/', async (req, res, next) => {
}
});
-router.put('/', async (req, res, next) => {
+router.put('/', authorization.needed('ADMIN'), async (req, res, next) => {
try {
await SettingsService.update(req.body);
res.status(204).end();
diff --git a/services/comments.js b/services/comments.js
index 82914bcd0..ec55cfb4d 100644
--- a/services/comments.js
+++ b/services/comments.js
@@ -81,11 +81,13 @@ module.exports = class CommentsService {
* @param {String} status the new Comment status
*/
static async edit({id, author_id, body, status}) {
+ const EDITABLE_STATUSES = ['NONE', 'PREMOD', 'ACCEPTED'];
+
const query = {
id,
author_id,
status: {
- $in: ['NONE', 'PREMOD', 'ACCEPTED'],
+ $in: EDITABLE_STATUSES,
},
};
@@ -130,7 +132,7 @@ module.exports = class CommentsService {
}
// Check to see if the comment had a status that was editable.
- if (!['NONE', 'PREMOD', 'ACCEPTED'].includes(comment.status)) {
+ if (!EDITABLE_STATUSES.includes(comment.status)) {
debug('rejecting comment edit because original comment has a non-editable status');
throw errors.ErrNotAuthorized;
}
diff --git a/services/wordlist.js b/services/wordlist.js
index 3a0cc2c71..8d9ee95bb 100644
--- a/services/wordlist.js
+++ b/services/wordlist.js
@@ -1,13 +1,39 @@
const debug = require('debug')('talk:services:wordlist');
const _ = require('lodash');
-const {RegexpTokenizer} = require('natural');
-const tokenizer = new RegexpTokenizer({pattern: /[.\s'"?!]/});
-const nameTokenizer = new RegexpTokenizer({pattern: /_/});
const SettingsService = require('./settings');
const Errors = require('../errors');
+const memoize = require('lodash/memoize');
-// REGEX to prevent emoji's from entering the wordlist.
-const EMOJI_REGEX = /(?:[\u2700-\u27bf]|(?:\ud83c[\udde6-\uddff]){2}|[\ud800-\udbff][\udc00-\udfff])[\ufe0e\ufe0f]?(?:[\u0300-\u036f\ufe20-\ufe23\u20d0-\u20f0]|\ud83c[\udffb-\udfff])?(?:\u200d(?:[^\ud800-\udfff]|(?:\ud83c[\udde6-\uddff]){2}|[\ud800-\udbff][\udc00-\udfff])[\ufe0e\ufe0f]?(?:[\u0300-\u036f\ufe20-\ufe23\u20d0-\u20f0]|\ud83c[\udffb-\udfff])?)*/;
+/**
+ * Escape string for special regular expression characters.
+ */
+function escapeRegExp(string) {
+ return string.replace(/[.*+?^${}()|[\]\\]/g, '\\$&'); // $& means the whole matched string
+}
+
+/**
+ * Generate a regulare expression that catches the `phrases`.
+ */
+function generateRegExp(phrases) {
+ const inner = phrases
+ .map((phrase) =>
+ phrase.split(/\s+/)
+ .map((word) => escapeRegExp(word))
+ .join('[\\s"?!.]+')
+ ).join('|');
+
+ return new RegExp(`(^|[^\\w])(${inner})(?=[^\\w]|$)`, 'iu');
+}
+
+/**
+ * Memoized version of generateRegExp.
+ */
+const generateRegExpMemoized = memoize(generateRegExp, (phrases) => phrases.join(','));
+
+/**
+ * Never matching regexp that exits immediately.
+ */
+const neverMatch = /(?!)/;
/**
* The root wordlist object.
@@ -16,9 +42,9 @@ const EMOJI_REGEX = /(?:[\u2700-\u27bf]|(?:\ud83c[\udde6-\uddff]){2}|[\ud800-\ud
class Wordlist {
constructor() {
- this.lists = {
- banned: [],
- suspect: []
+ this.regexp = {
+ banned: neverMatch,
+ suspect: neverMatch,
};
}
@@ -48,7 +74,9 @@ class Wordlist {
return;
}
- this.lists[k] = Wordlist.parseList(lists[k]);
+ this.regexp[k] = lists[k] && lists[k].length > 0
+ ? generateRegExpMemoized(lists[k])
+ : neverMatch;
debug(`Added ${lists[k].length} words to the ${k} wordlist.`);
});
@@ -56,92 +84,6 @@ class Wordlist {
return Promise.resolve(this);
}
- /**
- * Parses the list content.
- * @param {Array} list array of words to parse for a list.
- * @return {Array} the parsed list
- */
- static parseList(list) {
- return _.uniq(list.filter((word) => {
- if (EMOJI_REGEX.test(word)) {
- return false;
- }
-
- return true;
- })
- .map((word) => {
- if (word.length === 1) {
- return [word];
- }
-
- return tokenizer.tokenize(word.toLowerCase());
- })
- .filter((tokens) => {
- if (tokens.length === 0) {
- return false;
- }
-
- return true;
- }));
- }
-
- /**
- * Tests the phrase to see if it contains any of the defined blockwords.
- * @param {String} phrase value to check for blockwords.
- * @return {Boolean} true if a blockword is found, false otherwise.
- */
- match(list, phrase, tk = tokenizer) {
-
- // Lowercase the word to ensure that we don't miss a match due to
- // capitalization.
- let lowerPhraseWords = tk.tokenize(phrase.toLowerCase());
-
- // This will return true in the event that at least one blockword is found
- // in the phrase.
- return list.some((blockphrase) => {
-
- // First, let's see if we can find the first word in the blockphrase in the
- // source phrase.
- let idx = lowerPhraseWords.indexOf(blockphrase[0]);
-
- if (idx === -1) {
-
- // The first blockword in the blockphrase did not match the source phrase
- // anywhere.
- return false;
- }
-
- // Here we'll quick respond with true in the event that the blockphrase was
- // just a single word.
- if (blockphrase.length === 1) {
- return true;
- }
-
- // We found the first word in the source phrase! Lets ensure it matches the
- // rest of the blockphrase...
-
- // Check to see if it even has the length to support this word!
- if (lowerPhraseWords.length < idx + blockphrase.length - 1) {
-
- // We couldn't possibly have the entire phrase here because we don't have
- // enough entries!
- return false;
- }
-
- for (let i = 1; i < blockphrase.length; i++) {
-
- // Check to see if the next word also matches!
- if (lowerPhraseWords[idx + i] !== blockphrase[i]) {
- return false;
- }
- }
-
- // We've walked over all the words of the blockphrase, and haven't had a
- // mismatch... It does contain the whole word!
- return true;
- });
- }
-
/**
* Scans a specific field for wordlist violations.
*/
@@ -156,7 +98,7 @@ class Wordlist {
}
// Check if the field contains a banned word.
- if (this.match(this.lists.banned, phrase)) {
+ if (this.regexp.banned.test(phrase)) {
debug(`the field "${fieldName}" contained a phrase "${phrase}" which contained a banned word/phrase`);
errors.banned = Errors.ErrContainsProfanity;
@@ -166,8 +108,8 @@ class Wordlist {
return errors;
}
- // Check if the field contains a banned word.
- if (this.match(this.lists.suspect, phrase)) {
+ // Check if the field contains a suspected word.
+ if (this.regexp.suspect.test(phrase)) {
debug(`the field "${fieldName}" contained a phrase "${phrase}" which contained a suspected word/phrase`);
errors.suspect = Errors.ErrContainsProfanity;
@@ -176,6 +118,8 @@ class Wordlist {
// word (suspect).
return errors;
}
+
+ return errors;
}
/**
@@ -231,16 +175,12 @@ class Wordlist {
return wl
.load()
.then(() => {
- if (!wl.checkName(wl.lists.banned, username)) {
+ if (wl.regexp.banned.test(username)) {
return Errors.ErrContainsProfanity;
}
});
}
- checkName(list, name) {
- return !this.match(list, name, nameTokenizer);
- }
-
/**
* Connect middleware for scanning request bodies for wordlisted words and
* attaching a ErrContainsProfanity to the req.wordlisted parameter, otherwise
diff --git a/test/server/graph/mutations/createComment.js b/test/server/graph/mutations/createComment.js
index 72c163d35..9583c2066 100644
--- a/test/server/graph/mutations/createComment.js
+++ b/test/server/graph/mutations/createComment.js
@@ -167,7 +167,7 @@ describe('graph.mutations.createComment', () => {
[
{message: 'comment does not contain banned/suspect words', body: 'This is such a nice comment!', status: 'NONE', flagged: false},
- {message: 'comment contains banned words', body: 'This is the WORST comment!', status: 'REJECTED', flagged: false},
+ {message: 'comment contains banned words', body: 'This is the WORST comment!', status: 'REJECTED', flagged: true},
{message: 'comment contains suspect words', body: 'This is the EH comment!', status: 'NONE', flagged: true}
].forEach(({message, body, status, flagged}) => {
describe(message, () => {
@@ -222,6 +222,9 @@ describe('graph.mutations.createComment', () => {
return graphql(schema, query, {}, context)
.then(({data, errors}) => {
+ if (errors) {
+ console.error(errors);
+ }
expect(errors).to.be.undefined;
expect(data.createComment).to.have.property('comment').not.null;
expect(data.createComment).to.have.property('errors').null;
diff --git a/test/server/graph/mutations/editComment.js b/test/server/graph/mutations/editComment.js
index 8507fdc36..234bb308e 100644
--- a/test/server/graph/mutations/editComment.js
+++ b/test/server/graph/mutations/editComment.js
@@ -215,7 +215,7 @@ describe('graph.mutations.editComment', () => {
body: 'I have been edited to add a link: https://coralproject.net/'
},
afterEdit: {
- status: 'PREMOD',
+ status: 'SYSTEM_WITHHELD',
},
},
].forEach(({description, settings, beforeEdit, edit, afterEdit, error}) => {
diff --git a/test/server/routes/api/assets/index.js b/test/server/routes/api/assets/index.js
index 855b30271..a07b154d4 100644
--- a/test/server/routes/api/assets/index.js
+++ b/test/server/routes/api/assets/index.js
@@ -37,78 +37,88 @@ describe('/api/v1/assets', () => {
describe('#get', () => {
it('should return all assets without a search query', async () => {
- const res = await chai.request(app)
- .get('/api/v1/assets')
- .set(passport.inject({roles: ['ADMIN']}));
+ for (const role of ['ADMIN', 'MODERATOR']) {
+ const res = await chai.request(app)
+ .get('/api/v1/assets')
+ .set(passport.inject({roles: [role]}));
- const body = res.body;
+ const body = res.body;
- expect(body).to.have.property('count', 2);
- expect(body).to.have.property('result');
+ expect(body).to.have.property('count', 2);
+ expect(body).to.have.property('result');
- const assets = body.result;
+ const assets = body.result;
- expect(assets).to.have.length(2);
+ expect(assets).to.have.length(2);
+ }
});
it('should return assets that we search for', async () => {
- const res = await chai.request(app)
- .get('/api/v1/assets?search=term2')
- .set(passport.inject({roles: ['ADMIN']}));
+ for (const role of ['ADMIN', 'MODERATOR']) {
+ const res = await chai.request(app)
+ .get('/api/v1/assets?search=term2')
+ .set(passport.inject({roles: [role]}));
- const body = res.body;
+ const body = res.body;
- expect(body).to.have.property('count', 1);
- expect(body).to.have.property('result');
+ expect(body).to.have.property('count', 1);
+ expect(body).to.have.property('result');
- const assets = body.result;
+ const assets = body.result;
- expect(assets).to.have.length(1);
+ expect(assets).to.have.length(1);
- const asset = assets[0];
+ const asset = assets[0];
- expect(asset).to.have.property('url', 'https://coralproject.net/news/asset2');
- expect(asset).to.have.property('title', 'Asset 2');
+ expect(asset).to.have.property('url', 'https://coralproject.net/news/asset2');
+ expect(asset).to.have.property('title', 'Asset 2');
+ }
});
it('should not return assets that we do not search for', async () => {
- const res = await chai.request(app)
- .get('/api/v1/assets?search=term3')
- .set(passport.inject({roles: ['ADMIN']}));
- const body = res.body;
+ for (const role of ['ADMIN', 'MODERATOR']) {
+ const res = await chai.request(app)
+ .get('/api/v1/assets?search=term3')
+ .set(passport.inject({roles: [role]}));
+ const body = res.body;
- expect(body).to.have.property('count', 0);
- expect(body).to.have.property('result');
+ expect(body).to.have.property('count', 0);
+ expect(body).to.have.property('result');
- expect(body.result).to.be.empty;
+ expect(body.result).to.be.empty;
+ }
});
it('should return only closed assets', async () => {
- const res = await chai.request(app)
- .get('/api/v1/assets?filter=closed')
- .set(passport.inject({roles: ['ADMIN']}));
- const body = res.body;
+ for (const role of ['ADMIN', 'MODERATOR']) {
+ const res = await chai.request(app)
+ .get('/api/v1/assets?filter=closed')
+ .set(passport.inject({roles: [role]}));
+ const body = res.body;
- expect(body).to.have.property('count', 1);
- expect(body).to.have.property('result');
+ expect(body).to.have.property('count', 1);
+ expect(body).to.have.property('result');
- const assets = body.result;
+ const assets = body.result;
- expect(assets[0]).to.have.property('title', 'Asset 1');
+ expect(assets[0]).to.have.property('title', 'Asset 1');
+ }
});
it('should return only opened assets', async () => {
- const res = await chai.request(app)
- .get('/api/v1/assets?filter=open')
- .set(passport.inject({roles: ['ADMIN']}));
- const body = res.body;
+ for (const role of ['ADMIN', 'MODERATOR']) {
+ const res = await chai.request(app)
+ .get('/api/v1/assets?filter=open')
+ .set(passport.inject({roles: [role]}));
+ const body = res.body;
- expect(body).to.have.property('count', 1);
- expect(body).to.have.property('result');
+ expect(body).to.have.property('count', 1);
+ expect(body).to.have.property('result');
- const assets = body.result;
+ const assets = body.result;
- expect(assets[0]).to.have.property('title', 'Asset 2');
+ expect(assets[0]).to.have.property('title', 'Asset 2');
+ }
});
});
@@ -133,6 +143,20 @@ describe('/api/v1/assets', () => {
expect(closedAsset).to.have.property('isClosed', true);
expect(closedAsset).to.have.property('closedAt').and.to.not.equal(null);
});
+
+ it('should require ADMIN role', async () => {
+ const today = Date.now();
+
+ const asset = await AssetsService.findOrCreateByUrl('http://test.com');
+ expect(asset).to.have.property('isClosed', false);
+ expect(asset).to.have.property('closedAt', null);
+
+ const promise = chai.request(app)
+ .put(`/api/v1/assets/${asset.id}/status`)
+ .set(passport.inject({roles: ['MODERATOR']}))
+ .send({closedAt: today});
+ await expect(promise).to.eventually.be.rejected;
+ });
});
});
diff --git a/test/server/routes/api/settings/index.js b/test/server/routes/api/settings/index.js
index c7704fc7e..d3728ff2c 100644
--- a/test/server/routes/api/settings/index.js
+++ b/test/server/routes/api/settings/index.js
@@ -16,17 +16,17 @@ describe('/api/v1/settings', () => {
describe('#get', () => {
- it('should return a settings object', () => {
- return chai.request(app)
- .get('/api/v1/settings')
- .set(passport.inject({
- roles: ['ADMIN']
- }))
- .then((res) => {
- expect(res).to.have.status(200);
- expect(res).to.be.json;
- expect(res.body).to.have.property('moderation', 'PRE');
- });
+ it('should return a settings object', async () => {
+ for (let role of ['ADMIN', 'MODERATOR']) {
+ const res = await chai.request(app)
+ .get('/api/v1/settings')
+ .set(passport.inject({
+ roles: [role]
+ }));
+ expect(res).to.have.status(200);
+ expect(res).to.be.json;
+ expect(res.body).to.have.property('moderation', 'PRE');
+ }
});
});
@@ -46,6 +46,14 @@ describe('/api/v1/settings', () => {
expect(settings).to.have.property('moderation', 'POST');
});
});
+
+ it('should require ADMIN role', () => {
+ const promise = chai.request(app)
+ .put('/api/v1/settings')
+ .set(passport.inject({roles: ['MODERATOR']}))
+ .send({moderation: 'POST'});
+ return expect(promise).to.eventually.be.rejected;
+ });
});
});
diff --git a/test/server/services/wordlist.js b/test/server/services/wordlist.js
index 27460f049..5a2422b89 100644
--- a/test/server/services/wordlist.js
+++ b/test/server/services/wordlist.js
@@ -27,44 +27,10 @@ describe('services.Wordlist', () => {
beforeEach(() => SettingsService.init(settings));
- describe('#init', () => {
+ describe('#regexp', () => {
before(() => wordlist.upsert(wordlists));
- it('parses the wordlists correctly', () => {
- expect(wordlist.lists.banned).to.deep.equal([
- [ 'cookies' ],
- [ 'how', 'to', 'do', 'bad', 'things' ],
- [ 'how', 'to', 'do', 'really', 'bad', 'things' ],
- [ 's', 'h', 'i', 't' ],
- [ '$hit' ],
- [ 'p**ch' ],
- [ 'p*ch' ],
- ]);
- expect(wordlist.lists.suspect).to.deep.equal([
- [ 'do', 'bad', 'things' ],
- ]);
- });
-
- });
-
- describe('#parseList', () => {
- it('does not include emojis in the wordlist', () => {
- let list = Wordlist.parseList([
- '🖕',
- '🖕 asdf',
- 'asd🖕asdf',
- 'asd🖕',
- ]);
-
- expect(list).to.have.length(0);
- });
- });
-
- const bannedList = Wordlist.parseList(wordlists.banned);
-
- describe('#match', () => {
-
it('does match on a bad word', () => {
[
'how to do really bad things',
@@ -76,7 +42,7 @@ describe('services.Wordlist', () => {
'This stuff is $hit!',
'That\'s a p**ch!',
].forEach((word) => {
- expect(wordlist.match(bannedList, word)).to.be.true;
+ expect(wordlist.regexp.banned.test(word)).to.be.true;
});
});
@@ -90,7 +56,7 @@ describe('services.Wordlist', () => {
'I have bad $ hit lling',
'That\'s a p***ch!',
].forEach((word) => {
- expect(wordlist.match(bannedList, word)).to.be.false;
+ expect(wordlist.regexp.banned.test(word)).to.be.false;
});
});
@@ -123,32 +89,12 @@ describe('services.Wordlist', () => {
'I have bad $ hit lling',
'That\'s a p***ch!',
].forEach((word) => {
- expect(wordlist.scan('body', word)).to.be.undefined;
+ expect(wordlist.scan('body', word)).to.be.deep.equal({});
});
});
});
- describe('#checkName', () => {
- [
- 'flowers',
- 'joy',
- 'lots_of_candy'
- ].forEach((username) => {
- it(`does not match on list=banned name=${username}`, () => {
- expect(wordlist.checkName(bannedList, username)).to.be.true;
- });
- });
-
- [
- 'cookies'
- ].forEach((username) => {
- it(`does match on list=banned name=${username}`, () => {
- expect(wordlist.checkName(bannedList, username)).to.be.false;
- });
- });
- });
-
describe('#filter', () => {
before(() => wordlist.upsert(wordlists));
diff --git a/yarn.lock b/yarn.lock
index 1ca8acdbb..5451ae7bd 100644
--- a/yarn.lock
+++ b/yarn.lock
@@ -922,7 +922,7 @@ babel-register@^6.26.0:
mkdirp "^0.5.1"
source-map-support "^0.4.15"
-babel-runtime@^6.11.6, babel-runtime@^6.18.0, babel-runtime@^6.2.0, babel-runtime@^6.22.0, babel-runtime@^6.26.0, babel-runtime@^6.6.1:
+babel-runtime@^6.18.0, babel-runtime@^6.2.0, babel-runtime@^6.22.0, babel-runtime@^6.26.0, babel-runtime@^6.6.1:
version "6.26.0"
resolved "https://registry.yarnpkg.com/babel-runtime/-/babel-runtime-6.26.0.tgz#965c7058668e82b55d7bfe04ff2337bc8b5647fe"
dependencies:
@@ -1016,10 +1016,6 @@ binary-extensions@^1.0.0:
version "1.8.0"
resolved "https://registry.yarnpkg.com/binary-extensions/-/binary-extensions-1.8.0.tgz#48ec8d16df4377eae5fa5884682480af4d95c774"
-bindings@^1.2.1:
- version "1.2.1"
- resolved "https://registry.yarnpkg.com/bindings/-/bindings-1.2.1.tgz#14ad6113812d2d37d72e67b4cacb4bb726505f11"
-
block-stream@*:
version "0.0.9"
resolved "https://registry.yarnpkg.com/block-stream/-/block-stream-0.0.9.tgz#13ebfe778a03205cfe03751481ebb4b3300c126a"
@@ -3396,12 +3392,6 @@ hide-powered-by@1.0.0:
version "1.0.0"
resolved "https://registry.yarnpkg.com/hide-powered-by/-/hide-powered-by-1.0.0.tgz#4a85ad65881f62857fc70af7174a1184dccce32b"
-highlight-words-core@^1.0.2:
- version "1.0.3"
- resolved "https://registry.yarnpkg.com/highlight-words-core/-/highlight-words-core-1.0.3.tgz#0886d0e757c8ca3928cbc873042bd544f8f6b2e5"
- dependencies:
- babel-runtime "^6.11.6"
-
history@^3.0.0:
version "3.3.0"
resolved "https://registry.yarnpkg.com/history/-/history-3.3.0.tgz#fcedcce8f12975371545d735461033579a6dae9c"
@@ -4395,12 +4385,6 @@ license-webpack-plugin@^1.0.0:
dependencies:
ejs "^2.5.7"
-linkify-it@^1.2.0:
- version "1.2.4"
- resolved "https://registry.yarnpkg.com/linkify-it/-/linkify-it-1.2.4.tgz#0773526c317c8fd13bd534ee1d180ff88abf881a"
- dependencies:
- uc.micro "^1.0.1"
-
linkify-it@^2.0.3:
version "2.0.3"
resolved "https://registry.yarnpkg.com/linkify-it/-/linkify-it-2.0.3.tgz#d94a4648f9b1c179d64fa97291268bdb6ce9434f"
@@ -4982,7 +4966,7 @@ mute-stream@0.0.7:
version "0.0.7"
resolved "https://registry.yarnpkg.com/mute-stream/-/mute-stream-0.0.7.tgz#3075ce93bc21b8fab43e1bc4da7e8115ed1e7bab"
-nan@^2.3.0, nan@^2.4.0:
+nan@^2.3.0:
version "2.5.0"
resolved "https://registry.yarnpkg.com/nan/-/nan-2.5.0.tgz#aa8f1e34531d807e9e27755b234b4a6ec0c152a8"
@@ -5002,16 +4986,6 @@ natural@^0.2.0:
sylvester ">= 0.0.12"
underscore ">=1.3.1"
-natural@^0.5.4:
- version "0.5.4"
- resolved "https://registry.yarnpkg.com/natural/-/natural-0.5.4.tgz#ace41c1655daca2912dfbf99ad7b05314e205f54"
- dependencies:
- apparatus ">= 0.0.9"
- sylvester ">= 0.0.12"
- underscore ">=1.3.1"
- optionalDependencies:
- webworker-threads ">=0.6.2"
-
negotiator@0.6.1:
version "0.6.1"
resolved "https://registry.yarnpkg.com/negotiator/-/negotiator-0.6.1.tgz#2b327184e8992101177b28563fb5e7102acd0ca9"
@@ -6379,12 +6353,6 @@ react-dom@^15.3.1, react-dom@^15.4.2:
object-assign "^4.1.0"
prop-types "~15.5.7"
-react-highlight-words@^0.6.0:
- version "0.6.0"
- resolved "https://registry.yarnpkg.com/react-highlight-words/-/react-highlight-words-0.6.0.tgz#e12e9fedda4333e410ea408cdedffc77122020aa"
- dependencies:
- highlight-words-core "^1.0.2"
-
react-input-autosize@^1.1.4:
version "1.1.4"
resolved "https://registry.yarnpkg.com/react-input-autosize/-/react-input-autosize-1.1.4.tgz#cbc45072d4084ddc57806db8e3b34e644b8366ac"
@@ -6392,13 +6360,6 @@ react-input-autosize@^1.1.4:
create-react-class "^15.5.2"
prop-types "^15.5.8"
-react-linkify@^0.1.3:
- version "0.1.3"
- resolved "https://registry.yarnpkg.com/react-linkify/-/react-linkify-0.1.3.tgz#6e886180bda6c8fdc5f9f8a7ebe82fc0f48db7ad"
- dependencies:
- linkify-it "^1.2.0"
- tlds "^1.57.0"
-
react-mdl-selectfield@^0.2.0:
version "0.2.0"
resolved "https://registry.yarnpkg.com/react-mdl-selectfield/-/react-mdl-selectfield-0.2.0.tgz#36e1a97233036c057ab2bdb31ec09ad8d9988411"
@@ -7456,9 +7417,9 @@ title-case-minors@^1.0.0:
version "1.0.0"
resolved "https://registry.yarnpkg.com/title-case-minors/-/title-case-minors-1.0.0.tgz#51f17037c294747a1d1cda424b5004c86d8eb115"
-tlds@^1.57.0:
- version "1.185.0"
- resolved "https://registry.yarnpkg.com/tlds/-/tlds-1.185.0.tgz#9d5ddaae379778a98e3edc3a131d46a40cbc3ba4"
+tlds@^1.196.0:
+ version "1.196.0"
+ resolved "https://registry.yarnpkg.com/tlds/-/tlds-1.196.0.tgz#49d74ddbd1f9df30238b3bfef4df82862b5bbb48"
tmp@^0.0.31:
version "0.0.31"
@@ -7667,6 +7628,10 @@ update-notifier@0.5.0:
semver-diff "^2.0.0"
string-length "^1.0.0"
+url-join@^2.0.2:
+ version "2.0.2"
+ resolved "https://registry.yarnpkg.com/url-join/-/url-join-2.0.2.tgz#c072756967ad24b8b59e5741551caac78f50b8b7"
+
url-loader@^0.5.9:
version "0.5.9"
resolved "https://registry.yarnpkg.com/url-loader/-/url-loader-0.5.9.tgz#cc8fea82c7b906e7777019250869e569e995c295"
@@ -7819,13 +7784,6 @@ webpack@^2.3.1:
webpack-sources "^0.2.3"
yargs "^6.0.0"
-webworker-threads@>=0.6.2:
- version "0.7.11"
- resolved "https://registry.yarnpkg.com/webworker-threads/-/webworker-threads-0.7.11.tgz#9d54dfaa8d5ea3308833084680636b584a8aacaa"
- dependencies:
- bindings "^1.2.1"
- nan "^2.4.0"
-
whatwg-fetch@>=0.10.0, whatwg-fetch@^2.0.0:
version "2.0.3"
resolved "https://registry.yarnpkg.com/whatwg-fetch/-/whatwg-fetch-2.0.3.tgz#9c84ec2dcf68187ff00bc64e1274b442176e1c84"