| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
feat(providers): move stripe-app-sandbox appDomain to integration_config (#7227) ## Describe the problem and your solution - Moves `stripe-app-sandbox` `appDomain` from a per-connection field to a per-integration one, whoever sets up the integration can now configure it once instead of every end user having to find and enter it themselves in Connect UI or set when creating the connect session. - Existing connections and setups that haven't preconfigured it keep working: `connection_config.appDomain` is still declared as a fallback, and a merge step fills it in from the integration's config if the end user didn't provide one. <!-- Issue ticket number and link (if applicable) --> <!-- Testing instructions (skip if just adding/editing providers) --> <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7227?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 20 天前 | |
test(connect-ui): add a11y regression test suite (#6584) ## Problem Connect UI is our end-user-facing surface for connecting integrations, and it has no test runner. The WCAG 2.2 AA fixes tracked in [NAN-5906](https://linear.app/nango/issue/NAN-5906) can therefore regress silently — any future change to the main views could re-introduce keyboard, ARIA, or contrast violations with nothing to catch it. ## Solution Add an automated accessibility gate to `packages/connect-ui`, built on Vitest Browser Mode (real Chromium via Playwright) so genuine CSS, focus, and keyboard events apply — rendering with `vitest-browser-react`, querying with `vitest/browser` locators, and scanning with `axe-core` (no `@testing-library` dependency): - One axe scan (light **and** dark themes) plus a keyboard-operability test per surface: integrations list, auth form, success screen, error screen, and the loading view. - A dialog focus-trap test driven by the real Playwright `Tab` key, and an explicit check that integration cards activate via the keyboard. - Helpers split by concern under `src/test/`: `render.tsx` (app render + providers), `a11y.ts` (axe assertion), `fixtures.ts` (test data). - A path-scoped CI job (`tests-connect-ui`) that runs only when `packages/connect-ui/**` changes. Browser Mode (not jsdom) is required so real Tailwind/theme CSS applies — that is what lets axe evaluate color contrast in both themes and makes real focus/keyboard events fire. **This PR is intentionally red.** The suite is written against the accessible target behavior, so it surfaces the open [NAN-5906](https://linear.app/nango/issue/NAN-5906) violations (keyboard-inoperable cards, missing link/status accessible names, no focus trap, sub-minimum target size) until the stacked [NAN-5906](https://linear.app/nango/issue/NAN-5906) fix PR lands. The two primary-button **contrast** assertions are `it.skip`-ped pending [NAN-6055](https://linear.app/nango/issue/NAN-6055) (a design-system token fix), so they don't block. Fixes [NAN-5905](https://linear.app/nango/issue/NAN-5905) ## Testing - One-time: `npx playwright install chromium`, then `npm test -w packages/connect-ui`. 11 tests: on this branch (no fixes) **4 fail by design** (each maps to a [NAN-5906](https://linear.app/nango/issue/NAN-5906) / WCAG 2.2 AA finding), **2 are skipped** (primary-button contrast → [NAN-6055](https://linear.app/nango/issue/NAN-6055)), **5 pass** as regression guards. With the stacked [NAN-5906](https://linear.app/nango/issue/NAN-5906) fixes applied it's 9 pass / 2 skip / 0 fail. - Failure output includes the offending selector plus, for contrast, the foreground/background colors and measured-vs-required ratio. - `npm run ts-build` and `eslint` are clean. - The root `test:unit` job ignores these files (they use `*.test.tsx`, not `*.unit.test`), so existing CI is unaffected. | 3 个月前 | |
feat: connect ui (#2721) ## Describe your changes Contributes to https://linear.app/nango/issue/NAN-1703/create-ui - Setup the folder for the new Connect UI This is just this to avoid massive PR later. ```sh npm run -w @nangohq/connect-ui dev ``` | 2 年前 | |
feat: connect ui (#2721) ## Describe your changes Contributes to https://linear.app/nango/issue/NAN-1703/create-ui - Setup the folder for the new Connect UI This is just this to avoid massive PR later. ```sh npm run -w @nangohq/connect-ui dev ``` | 2 年前 | |
fix(connect-ui): keep base-path recovery out of the CDN build (#7401) ## Problem `connect.nango.dev` enforces `script-src 'self'`, so Connect UI's inline `<script>` and the `onerror` handler calling it are blocked in every browser. The slashless-base-path recovery has never run there, and the blocked scripts reported ~50k CSP violations across ~13k users since July, burying real ones in Sentry. ## Solution - Inject the recovery only when `CONNECT_UI_BASE_PATH_RECOVERY` is set, which the Docker image build passes; the CDN build ships no inline script. - Rewrite it as a capture-phase `error` listener — no inline handler — and confirm the trailing-slash URL serves JavaScript before redirecting. Only self-hosted deployments sit under a base path, and their static server sends no CSP, so no hash has to stay in sync with nango-infra. The CDN serves the root, where the recovery could never fire. Fixes [NAN-6899](https://linear.app/nango/issue/NAN-6899) ## Testing Emulated a prefix-stripping proxy with an SPA fallback. `…/nango/connect` probes the entry bundle, redirects once, renders, and keeps the query. A broken asset on `…/connect/integrations`, where the probe answers 200 `text/html`, correctly does not redirect — the previous script would have broken that URL permanently. The CDN build ships no inline script. ## Follow-ups - Sentry [REACT-XK](https://nango.sentry.io/issues/REACT-XK) and [REACT-ZH](https://nango.sentry.io/issues/REACT-ZH) stay open until this deploys. --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> | 30 天前 | |
fix: vulns (#7803) <!-- Describe the problem and your solution --> <!-- Issue ticket number and link (if applicable) --> <!-- Testing instructions (skip if just adding/editing providers) --> <!-- This is an auto-generated description by cubic. --> <a href="https://cubic.dev/pr/NangoHQ/nango/pull/7803?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. --> | 2 天前 | |
test(connect-ui): add a11y regression test suite (#6584) ## Problem Connect UI is our end-user-facing surface for connecting integrations, and it has no test runner. The WCAG 2.2 AA fixes tracked in [NAN-5906](https://linear.app/nango/issue/NAN-5906) can therefore regress silently — any future change to the main views could re-introduce keyboard, ARIA, or contrast violations with nothing to catch it. ## Solution Add an automated accessibility gate to `packages/connect-ui`, built on Vitest Browser Mode (real Chromium via Playwright) so genuine CSS, focus, and keyboard events apply — rendering with `vitest-browser-react`, querying with `vitest/browser` locators, and scanning with `axe-core` (no `@testing-library` dependency): - One axe scan (light **and** dark themes) plus a keyboard-operability test per surface: integrations list, auth form, success screen, error screen, and the loading view. - A dialog focus-trap test driven by the real Playwright `Tab` key, and an explicit check that integration cards activate via the keyboard. - Helpers split by concern under `src/test/`: `render.tsx` (app render + providers), `a11y.ts` (axe assertion), `fixtures.ts` (test data). - A path-scoped CI job (`tests-connect-ui`) that runs only when `packages/connect-ui/**` changes. Browser Mode (not jsdom) is required so real Tailwind/theme CSS applies — that is what lets axe evaluate color contrast in both themes and makes real focus/keyboard events fire. **This PR is intentionally red.** The suite is written against the accessible target behavior, so it surfaces the open [NAN-5906](https://linear.app/nango/issue/NAN-5906) violations (keyboard-inoperable cards, missing link/status accessible names, no focus trap, sub-minimum target size) until the stacked [NAN-5906](https://linear.app/nango/issue/NAN-5906) fix PR lands. The two primary-button **contrast** assertions are `it.skip`-ped pending [NAN-6055](https://linear.app/nango/issue/NAN-6055) (a design-system token fix), so they don't block. Fixes [NAN-5905](https://linear.app/nango/issue/NAN-5905) ## Testing - One-time: `npx playwright install chromium`, then `npm test -w packages/connect-ui`. 11 tests: on this branch (no fixes) **4 fail by design** (each maps to a [NAN-5906](https://linear.app/nango/issue/NAN-5906) / WCAG 2.2 AA finding), **2 are skipped** (primary-button contrast → [NAN-6055](https://linear.app/nango/issue/NAN-6055)), **5 pass** as regression guards. With the stacked [NAN-5906](https://linear.app/nango/issue/NAN-5906) fixes applied it's 9 pass / 2 skip / 0 fail. - Failure output includes the offending selector plus, for contrast, the foreground/background colors and measured-vs-required ratio. - `npm run ts-build` and `eslint` are clean. - The root `test:unit` job ignores these files (they use `*.test.tsx`, not `*.unit.test`), so existing CI is unaffected. | 3 个月前 | |
fix(connect-ui): keep base-path recovery out of the CDN build (#7401) ## Problem `connect.nango.dev` enforces `script-src 'self'`, so Connect UI's inline `<script>` and the `onerror` handler calling it are blocked in every browser. The slashless-base-path recovery has never run there, and the blocked scripts reported ~50k CSP violations across ~13k users since July, burying real ones in Sentry. ## Solution - Inject the recovery only when `CONNECT_UI_BASE_PATH_RECOVERY` is set, which the Docker image build passes; the CDN build ships no inline script. - Rewrite it as a capture-phase `error` listener — no inline handler — and confirm the trailing-slash URL serves JavaScript before redirecting. Only self-hosted deployments sit under a base path, and their static server sends no CSP, so no hash has to stay in sync with nango-infra. The CDN serves the root, where the recovery could never fire. Fixes [NAN-6899](https://linear.app/nango/issue/NAN-6899) ## Testing Emulated a prefix-stripping proxy with an SPA fallback. `…/nango/connect` probes the entry bundle, redirects once, renders, and keeps the query. A broken asset on `…/connect/integrations`, where the probe answers 200 `text/html`, correctly does not redirect — the previous script would have broken that URL permanently. The CDN build ships no inline script. ## Follow-ups - Sentry [REACT-XK](https://nango.sentry.io/issues/REACT-XK) and [REACT-ZH](https://nango.sentry.io/issues/REACT-ZH) stay open until this deploys. --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> | 30 天前 | |
fix(connect-ui): pre-bundle react/jsx-runtime in vitest config (#7205) ## Problem `tests-connect-ui`, which is required on `master` via the merge queue, occasionally fails with `Failed to fetch dynamically imported module` for a test file. Root cause: `@vitejs/plugin-react-swc` injects the `react/jsx-runtime` import at transform time, so Vite's dep scanner never sees it and discovers it mid-run, triggering a page reload that cancels whatever module was mid-import. This happens on every run of the suite (visible as a "Vite unexpectedly reloaded a test" warning in the logs) but only fails the suite when the reload lands during a test file's import. ## Solution - Pre-bundle `react/jsx-runtime` via `optimizeDeps.include` in `packages/connect-ui/vitest.config.ts` so Vite has it up front and never needs to re-optimize mid-run Fixes [NAN-6714](https://linear.app/nango/issue/NAN-6714/fix-rare-flake-in-tests-connect-ui-ci-job) ## Testing - Ran `vitest run` locally with a cold Vite cache (`rm -rf node_modules/.vite`) repeatedly — the reload warning no longer appears and the suite passes each time, versus appearing on every run before the fix | 1 个月前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 20 天前 | ||
| 3 个月前 | ||
| 2 年前 | ||
| 2 年前 | ||
| 30 天前 | ||
| 2 天前 | ||
| 3 个月前 | ||
| 30 天前 | ||
| 1 个月前 |