diff options
| author | Danilo M. <danix@danix.xyz> | 2026-08-07 17:51:52 +0200 |
|---|---|---|
| committer | Danilo M. <danix@danix.xyz> | 2026-08-07 17:51:52 +0200 |
| commit | 334b510e2673a6ab3875ffa7a4c5b3b2dd09a369 (patch) | |
| tree | 59b38af32af41d629a0c02ecd8e0fcfcddbb60e6 /tests/test_messageview.cpp | |
| parent | 6003bab2d4c491a857b7a728f2f23c719723ef1a (diff) | |
| download | qtmaildir-334b510e2673a6ab3875ffa7a4c5b3b2dd09a369.tar.gz qtmaildir-334b510e2673a6ab3875ffa7a4c5b3b2dd09a369.zip | |
feat(ui): fill the blank message pane with a branded placeholder
An empty right pane said nothing, and multi-select made it a routine
sight. It now carries the wordmark, thread counts that run their query
when clicked, and a sync line that appears only when something needs
attention.
Rendered into the existing web view as a third document shape, so there
is one document path and one set of security rules. The brand palette is
a deliberate exception to deriving colours from the desktop theme, since
a logo is brand rather than chrome; the theme still picks which of the
two sets is used.
Counts refresh when the pane is about to show rather than in the
background: one goes stale the moment a tag is edited, and refreshing one
nobody is looking at is work for nothing. A generation counter discards a
superseded reply, and a late answer cannot repaint over an opened thread.
The helper lines are real links because JavaScript is off in this
profile. The handler is gated on the placeholder actually being
displayed, so the same URL inside a message body is dropped: a stranger's
mail must not drive the thread list, even to run a harmless query.
Three defects found while building, all silent:
- Every CSS percentage was invalid. QString::arg does not collapse "%%"
into "%", so the document carried "50%%" and the browser dropped each
declaration holding one, disabling the mask, the glow and both radial
gradients while still rendering something plausible. Substitution is by
named token now, which cannot collide with a percent sign.
- A geometry probe endorsed the layout while that was live, because it
measured only properties without percentages.
- The font test passed against a build with one face missing, since the
other satisfied both of its checks on its own.
The mockup's light values needed correcting against a real pane: the grid
vanished at a 2% luminance step on white, and the glow subtracts light
there rather than adding it, washing the pane. Strength only, not hue.
Diffstat (limited to 'tests/test_messageview.cpp')
| -rw-r--r-- | tests/test_messageview.cpp | 74 |
1 files changed, 74 insertions, 0 deletions
diff --git a/tests/test_messageview.cpp b/tests/test_messageview.cpp index 57d7b42..e94fb86 100644 --- a/tests/test_messageview.cpp +++ b/tests/test_messageview.cpp @@ -47,6 +47,8 @@ private slots: void headerEscapesUntrustedValues(); void headerOmitsAnAbsentCc(); void detailsDialogIsOfferedForEveryThread(); + void placeholderRendersAndReportsItself(); + void aMessageBodyCannotRunAQuery(); private: QWebEngineView *webViewOf(MessageView *view) const @@ -492,5 +494,77 @@ void TestMessageView::detailsDialogIsOfferedForEveryThread() QVERIFY(!button || !button->isVisible()); } +void TestMessageView::placeholderRendersAndReportsItself() +{ + MessageView view; + QWebEngineView *web = webViewOf(&view); + QVERIFY(web); + + QSignalSpy loaded(web, &QWebEngineView::loadFinished); + view.showPlaceholder({ { QStringLiteral("7 unread"), + QStringLiteral("tag:unread") } }); + + QVERIFY2(loaded.wait(15000), "the placeholder document never loaded"); + QVERIFY2(loaded.last().at(0).toBool(), + "loadFinished reported failure: the navigation was rejected, " + "which is what a base-URL mismatch looks like"); + + // Rendered, not merely loaded. The wordmark is split across elements by + // the accent span, so the helper line is what proves the content arrived. + QString text; + bool done = false; + web->page()->toPlainText([&](const QString &result) { + text = result; + done = true; + }); + QTRY_VERIFY_WITH_TIMEOUT(done, 15000); + QVERIFY2(text.contains(QStringLiteral("7 unread")), qPrintable(text)); + + QVERIFY(view.showingPlaceholder()); +} + +void TestMessageView::aMessageBodyCannotRunAQuery() +{ + // The gate behind queryRequested(). A message body is attacker-controlled + // HTML and can carry a qtmaildir-query: link; the view only honours one + // while the placeholder is what is displayed, so this asserts the state + // that decides it rather than synthesising a click, which would need the + // page's protected navigation handler. + MessageView view; + QSignalSpy queries(&view, &MessageView::queryRequested); + + view.showPlaceholder({ { QStringLiteral("7 unread"), + QStringLiteral("tag:unread") } }); + QVERIFY(view.showingPlaceholder()); + + ParsedMessage message; + message.ok = true; + message.from = QStringLiteral("Mallory <mallory@example.org>"); + message.subject = QStringLiteral("Click me"); + message.htmlBody = QStringLiteral( + "<a href=\"qtmaildir-query:tag%3Adeleted\">a link</a>"); + + ThreadRenderItem item; + item.message = message; + item.cidPrefix = QStringLiteral("m0"); + item.expanded = true; + + view.showThread({ item }); + + // Showing any message closes the gate, so a link in that message's own + // body has nothing to reach. + QVERIFY2(!view.showingPlaceholder(), + "the gate stayed open while a message was displayed: a link in a " + "message body could run a query"); + + view.clear(); + QVERIFY(!view.showingPlaceholder()); + + view.showError(QStringLiteral("broken"), QStringLiteral("/tmp/x")); + QVERIFY(!view.showingPlaceholder()); + + QVERIFY(queries.isEmpty()); +} + QTEST_MAIN(TestMessageView) #include "test_messageview.moc" |
