Repository navigation
fix: cross-site user management and auth hardening #195
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
16ba05e
a4da9cd
109d974
955992d
e7eb9a2
8d63dbe
8af9a3f
dd9b9db
1a55d3b
e373179
24d995e
3145b01
6e60d43
73969bd
a31ab49
e9fa5be
2563ccb
016fd69
26996c4
f063eda
05fed9d
0b604b7
5ad2275
6c87017
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -3,28 +3,26 @@ | |
| #oneaccess-settings-page, | ||
| #oneaccess-manage-user { | ||
|
|
||
| &:has(.components-snackbar-list) { | ||
|
|
||
| .components-snackbar-list { | ||
| position: fixed; | ||
| bottom: 20px; | ||
| right: 20px; | ||
| z-index: 1000000; | ||
| align-items: flex-end; | ||
| justify-content: flex-end; | ||
| display: flex; | ||
| flex-direction: column; | ||
| } | ||
| .components-snackbar-list, | ||
| .components-snackbar { | ||
| position: fixed; | ||
| bottom: 20px; | ||
| right: 20px; | ||
| z-index: 1000000; | ||
| width: auto; | ||
| } | ||
|
Comment on lines
+6
to
13
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Dropping
The "several at once — toasts stack" test step only holds within a single A more robust approach:
Two smaller things:
|
||
|
|
||
| &:not(:has(.components-snackbar-list)) { | ||
| .components-snackbar-list { | ||
| align-items: flex-end; | ||
| justify-content: flex-end; | ||
| display: flex; | ||
| flex-direction: column; | ||
|
|
||
| /* Snackbars in a list are laid out by the list itself. */ | ||
| .components-snackbar { | ||
| position: fixed; | ||
| bottom: 20px; | ||
| right: 20px; | ||
| z-index: 1000000; | ||
| width: auto; | ||
| position: static; | ||
| bottom: auto; | ||
| right: auto; | ||
| } | ||
| } | ||
|
|
||
|
|
@@ -41,8 +39,6 @@ | |
| background-color: #e11d1d; | ||
| color: #fff; | ||
| } | ||
|
|
||
|
|
||
| } | ||
|
|
||
| .toplevel_page_oneaccess { | ||
|
|
@@ -52,7 +48,6 @@ | |
| } | ||
| } | ||
|
|
||
|
|
||
| body { | ||
|
|
||
| &.oneaccess-missing-brand-sites, | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good: per-site failures are visible now. Two follow-ups:
! response.okbranch, never reads the body. Any 4xx/5xx shows "Failed to create user. Please try again later.", including the new 400 password message. Parse the JSON and preferdata.message.site_nameis'', so the notice reads "API key not found for site .". The server could fall back to the URL.The same per-site treatment is still missing in the delete flow (
SharedUsers.tsx), which is this PR's main fix. See the review summary.