diff options
context:
space:
mode:
authorBryce Kwon <bryce@brycekwon.com>
committerBryce Kwon <bryce@brycekwon.com>
commit
parent
tree
download
Remove the auto-submitting selects
Diffstat (limited to '')
-rw-r--r--assets/cgit.js29
-rw-r--r--source/ui-diff.c8
-rw-r--r--source/ui-shared.c2
-rw-r--r--source/ui-stats.c6
-rwxr-xr-xtests/t0301-security.sh8
5 files changed, 16 insertions, 37 deletions
diff --git a/assets/cgit.js b/assets/cgit.js
index 636ad33..c5bdf33 100644
--- a/assets/cgit.js
+++ b/assets/cgit.js
@@ -2,11 +2,10 @@
* The client side script that cgit serves with every page. Its main job is
* to refresh the relative ages that cgit_print_age renders in
* source/ui-shared.c, so the thresholds, suffixes and class names tabulated
- * below mirror the constants there and the two have to move together. Two
- * smaller pieces follow, the selects that reload the page when they change,
- * and the highlight laid over the source line a URL fragment names. Each
- * piece is wrapped in a function of its own so that nothing is left behind
- * in the global scope.
+ * below mirror the constants there and the two have to move together. One
+ * smaller piece follows, the highlight laid over the source line a URL
+ * fragment names. Each piece is wrapped in a function of its own so that
+ * nothing is left behind in the global scope.
*/
(function () {
@@ -97,26 +96,6 @@ document.addEventListener("DOMContentLoaded", function () {
})();
/*
- * Selects marked data-autosubmit reload the page with the new setting. They
- * are wired up from here rather than with an inline onchange handler because
- * a strict Content-Security-Policy blocks those, and a reader without
- * scripting still has the noscript reload button the forms carry.
- */
-
-(function () {
-
-document.addEventListener("DOMContentLoaded", function () {
- var i, selects = document.querySelectorAll("select[data-autosubmit]");
-
- for (i = 0; i < selects.length; i++)
- selects[i].addEventListener("change", function () {
- this.form.submit();
- });
-}, false);
-
-})();
-
-/*
* Washes a faded highlight over the source line a URL fragment names, either
* a single line as in #n231 or a range as in #n5-n12. The line anchors live
* in the number gutter, so the anchor is measured and a bar of the same
diff --git a/source/ui-diff.c b/source/ui-diff.c
index 63c0148..e08b096 100644
--- a/source/ui-diff.c
+++ b/source/ui-diff.c
@@ -578,7 +578,7 @@ void cgit_print_diff_ctrls(void)
html("<tr>");
html("<td class='label'>context:</td>");
html("<td class='ctrl'>");
- html("<select name='context' data-autosubmit='1'>");
+ html("<select name='context'>");
selected = ctx.qry.context;
if (!selected)
selected = DEFAULT_CONTEXT_LINES;
@@ -591,7 +591,7 @@ void cgit_print_diff_ctrls(void)
html("</tr><tr>");
html("<td class='label'>space:</td>");
html("<td class='ctrl'>");
- html("<select name='ignorews' data-autosubmit='1'>");
+ html("<select name='ignorews'>");
html_intoption(0, "include", ctx.qry.ignorews);
html_intoption(1, "ignore", ctx.qry.ignorews);
html("</select>");
@@ -599,14 +599,14 @@ void cgit_print_diff_ctrls(void)
html("</tr><tr>");
html("<td class='label'>mode:</td>");
html("<td class='ctrl'>");
- html("<select name='dt' data-autosubmit='1'>");
+ html("<select name='dt'>");
selected = ctx.qry.has_difftype ? ctx.qry.difftype : ctx.cfg.difftype;
html_intoption(0, "unified", selected);
html_intoption(1, "ssdiff", selected);
html_intoption(2, "stat only", selected);
html("</select></td></tr>");
html("<tr><td></td><td class='ctrl'>");
- html("<noscript><input type='submit' value='reload'></noscript>");
+ html("<input type='submit' value='reload'>");
html("</td></tr></table>");
html("</form>\n");
html("</div>\n");
diff --git a/source/ui-shared.c b/source/ui-shared.c
index 307dba0..a79c291 100644
--- a/source/ui-shared.c
+++ b/source/ui-shared.c
@@ -529,7 +529,7 @@ static void print_header(void)
cgit_add_hidden_formfields(0, 1, ctx.qry.page);
ctx.qry.oid = oid;
ctx.qry.oid2 = oid2;
- html("<select name='h' aria-label='Branch' data-autosubmit='1'>\n");
+ html("<select name='h' aria-label='Branch'>\n");
if (pinned) {
const char *hex = oid_to_hex(pinned);
diff --git a/source/ui-stats.c b/source/ui-stats.c
index 97918e0..5b36f54 100644
--- a/source/ui-stats.c
+++ b/source/ui-stats.c
@@ -385,7 +385,7 @@ static void print_options_form(const struct cgit_period *period, int top)
if (ctx.repo->max_stats > 1) {
choices = ctx.repo->max_stats;
html("<tr><td class='label'>Period:</td>");
- html("<td class='ctrl'><select name='period' data-autosubmit='1'>");
+ html("<td class='ctrl'><select name='period'>");
for (i = 0; i < choices; i++)
html_option(cgit_fmt("%c", periods[i].code),
periods[i].name,
@@ -393,7 +393,7 @@ static void print_options_form(const struct cgit_period *period, int top)
html("</select></td></tr>\n");
}
html("<tr><td class='label'>Authors:</td>");
- html("<td class='ctrl'><select name='ofs' data-autosubmit='1'>");
+ html("<td class='ctrl'><select name='ofs'>");
html_intoption(10, "10", top);
html_intoption(25, "25", top);
html_intoption(50, "50", top);
@@ -401,7 +401,7 @@ static void print_options_form(const struct cgit_period *period, int top)
html_intoption(-1, "all", top);
html("</select></td></tr>\n");
html("<tr><td></td><td class='ctrl'>");
- html("<noscript><input type='submit' value='Reload'></noscript>");
+ html("<input type='submit' value='reload'>");
html("</td></tr></table>");
html("</form>\n");
html("</div>\n");
diff --git a/tests/t0301-security.sh b/tests/t0301-security.sh
index 8fce5f4..9a3af3c 100755
--- a/tests/t0301-security.sh
+++ b/tests/t0301-security.sh
@@ -118,12 +118,12 @@ test_expect_success 'non-markdown readme keeps its line structure' '
'
# A Content-Security-Policy without unsafe-inline stops an inline onchange
-# handler from ever running, so the option forms only mark their selects and
-# cgit.js wires the submit up from outside the page.
-test_expect_success 'diff option selects use the autosubmit marker' '
+# handler from ever running, so the option form submits through a plain
+# button and its selects carry no handlers at all.
+test_expect_success 'diff options submit through a button' '
sha=$(git -C repos/foo rev-parse HEAD) &&
cgit_query "url=foo/commit&id=$sha" >tmp &&
- grep "data-autosubmit" tmp &&
+ grep "type=.submit. value=.reload." tmp &&
! grep "onchange" tmp
'