Skip to content

fix: delete acknowledgments for project removal - #20531

Open
miketheman wants to merge 17 commits into
pypi:mainfrom
miketheman:miketheman/delete-confirmation
Open

miketheman wants to merge 17 commits into
pypi:mainfrom
miketheman:miketheman/delete-confirmation

Conversation

@miketheman

Copy link
Copy Markdown
Member

The checkboxes carried no name, so they never reached the server and a
crafted POST could delete a project or release without them. Enforce them
the way confirm_project already enforces the typed name.

Three templates render these modals against the two views, so the functional
tests assert each rendered form carries exactly the names the view checks.

Includes other refactors - see each commit for easier review.

The login-and-TOTP dance is copied into every functional test that needs an
authenticated user. Move the admin conftest's version up a level so the rest
of tests/functional can reach it, and convert the manage project tests.

The shared copy reuses the IpAddress row the request already inserted rather
than colliding with it.
The checkboxes sat outside the modal and gated an anchor carrying a disabled
attribute, which browsers ignore. Only `pointer-events: none` ever blocked
the click, and that went away in pypi#14244, so the boxes have been decorative
since. Rendering them inside the modal lets the existing confirm controller
gate a real submit button, and delete_confirm can go.

Wrapping each box in a label makes its text a click target and ties the two
together for screen readers. confirm_button's additional_attributes is how
disabled reached an anchor in the first place; nothing passes it now.

Seven acknowledgments plus a warning and a text field need the room, so
these modals opt into the modal--wide the stylesheet already
implemented.
The checkboxes carried no name, so they never reached the server and a
crafted POST could delete a project or release without them. Enforce them
the way confirm_project already enforces the typed name.

Three templates render these modals against the two views, so the functional
tests assert each rendered form carries exactly the names the view checks.
@nlhkabu nlhkabu self-assigned this Sep 18, 2026
@nlhkabu

nlhkabu commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

Hi @miketheman

Wondering why the delete file modal on the release detail page is out of scope here? These checkboxes also appear not to carry a name:

<input class="inline-checkbox" type="checkbox" data-action="input-&gt;confirm#check" data-confirm-target="checkbox">

The modal styling is also different:

image

The file delete modal on the release page had the same unnamed checkboxes
as the project and release modals. Name them through a shared macro and
have delete_project_release_file enforce them.
@miketheman

Copy link
Copy Markdown
Member Author

Wondering why the delete file modal on the release detail page is out of scope here?

It wasn't explicitly out of scope, it was overlooked - thanks!

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants