feat(about): the third-party open-source licenses, in the About dialog (v0.18.0) - #321
Merged
Merged
Conversation
…g (v0.18.0) Part of #301, the second of its two pull requests. Version 0.18.0. - About Loop Studio gains a "Third-party open-source licenses" button that turns the same dialog into its licence view, not a second modal. The view says first that these are the notices of the third-party software Loop Studio includes and that they cover those components only, not Loop Studio itself; then the build's own notices, unchanged and in English, in a scrollable, focusable <pre dir="ltr" lang="en"> that the browser can search, select and copy. Back to About returns focus to the button; Escape, the backdrop and x close the whole dialog, and the next opening starts on About. Loading and a failed read have their own states, with Try again. - src/licenses/notices.ts reads the text: the same-origin THIRD_PARTY_NOTICES.txt on the web and PWA builds (precached by the PWA, so it opens offline; a non-plain-text answer such as a host's index.html fallback is refused), and template.content.textContent in the portable file. The web and PWA builds also offer the file in a new tab with rel="noopener noreferrer"; the portable file has no separate file and no link. The text is a React text child; a new check, check:licence-screen, parses the loader, the view and the dialog with the TypeScript parser and fails on any HTML sink (dangerouslySetInnerHTML, innerHTML / outerHTML, insertAdjacentHTML, document.write, createContextualFragment, DOMParser, setHTMLUnsafe) or a loader that does not read the template's content. - The dev server serves THIRD_PARTY_NOTICES.txt too (thirdPartyNoticesDev): the web build's text rebuilt in memory from the committed manifest and the installed packages (noticesFromManifest), with every licence file, NOTICE file and the whole text checked against the manifest's SHA-256; nothing is written to disk or fetched. A unit test rebuilds all three sections and compares them with the manifest. - e2e: on the dev server, the production bundle, the PWA with the network down and the portable file, the text on screen is one text node whose SHA-256 is the manifest's for that build; the file link opens the same bytes with no opener (offline from the precache on the PWA); a failed read, Back, Escape, 18 languages and a 320 px phone are covered. The PWA test server now serves .txt as text/plain, as Cloudflare Pages does. - The About dialog's links take the dialog's ink, underlined: the browser's default link blue was unreadable on the dark panel. - Declared user-facing: version 0.18.0 and release note release:0.18.0, three lines; nine new interface strings; all in 18 languages, 16 without native review. The per-language copy tests move their pinned counts by those twelve keys, as each release does, and declare the loanwords Italian and Dutch use (open source, software, copyright) and two Spanish homographs; pt-PT stays under its quarter bound. scripts/arrow-units.json records the view's external-link icon. - Docs: docs/guided-tour.md §GT7.1, licenses/README.md, and README's release section (it still said "Latest — v0.15.3") and Copyright section; CHANGELOG.md gains v0.16.0 to v0.18.0, which it did not have.
Deploying cozy-loop-studio with
|
| Latest commit: |
869b892
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://8262080c.cozy-loop-studio.pages.dev |
| Branch Preview URL: | https://feat-licence-screen.cozy-loop-studio.pages.dev |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part of #301 — the second of its two pull requests: the licence screen, its documentation and the release note. Version 0.18.0.
What a person sees
<pre dir="ltr" lang="en">that the browser can search, select and copy.Open as a text filelink to the same-originTHIRD_PARTY_NOTICES.txtin a new tab (rel="noopener noreferrer"); the PWA has the file precached, so the view and the link work offline. The portable file has no separate file, so no link.Where the text comes from
THIRD_PARTY_NOTICES.txt, same originwebpwatemplate.content.textContentof<template id="third-party-notices">portable/THIRD_PARTY_NOTICES.txt, rebuilt in memorywebsrc/licenses/notices.tsreads it once per page; a non-plain-text answer (a host'sindex.htmlfallback) or a text that does not start like the notices is a failure, not shown.thirdPartyNoticesDev:noticesFromManifestfinds each package of the manifest's web section innode_modulesby name and version, checks every licence and NOTICE file's SHA-256 and the whole text's, and serves it from memory or answers 500 with the reason. Nothing is written to disk or fetched. A unit test rebuilds all three sections and compares them with the manifest.Text, never HTML
check:licence-screen(also a CI step), parsesnotices.ts,LicensesView.tsxandAboutDialog.tsxwith the TypeScript parser and fails ondangerouslySetInnerHTML,innerHTML/outerHTML,insertAdjacentHTML,document.write,createContextualFragment,DOMParserorsetHTMLUnsafe, or a loader that does not read the template through.content.textContent; a file that does not parse is a failure. Its rule is tested on 15 made-up sources.Tests
e2e/licenses.spec.ts(dev server): the text on screen is one text node with the manifest's web SHA-256; a selection gives it back (Chrome's selection drops the one final newline, measured and pinned); the link opens the same bytes with no opener; Escape, Back and focus; a refused read, then Try again; a host that answers with HTML; the dev server's file; the name in all 18 languages with the text left English and left to right; a 320 px phone through the More sheet, nothing cut off and no sideways scroll.dist.spec.ts(production bundle),pwa.spec.ts(network down: the view and the link from the precache) andportable-file.spec.ts(the template, no link): the same SHA-256 comparison for each build..txtastext/plain, as Cloudflare Pages does; it answeredapplication/octet-stream, which the loader rightly refused.Release, strings and docs
release:0.18.0(three lines, dated 2026-10-05), nine interface strings, all in 18 languages. The 16 languages other than English and Korean have not been reviewed by a native speaker.Tentar novamente, the same as pt-PT, so pt-PT stays under its quarter bound (240 of 963), which is unchanged.scripts/arrow-units.jsonrecords the view's external-link icon.docs/guided-tour.md§GT7.1,licenses/README.md, README's release section (it still said "Latest — v0.15.3") and Copyright section, andCHANGELOG.md, which gains v0.16.0 to v0.18.0. The entries for v0.16.0 to v0.17.2 are written from those releases' squash commits.Verification (local)
npx tsc -b, oxlint (39 warnings, the existing baseline), 3,107 unit tests and every check pass; the web, portable and PWA builds and the Cloudflare Production path build with the third-party notices unchanged.#301 stays open until this is verified in production.