Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions .Jules/palette.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,3 +9,8 @@
## 2024-11-20 - CopyPromptButton ์ ‘๊ทผ์„ฑ ํ–ฅ์ƒ (๋™์  ํ…์ŠคํŠธ ๋ฐ ์ƒํƒœ)
**Learning:** `CopyPromptButton`๊ณผ ๊ฐ™์ด ๋ฒ„ํŠผ์„ ํด๋ฆญํ–ˆ์„ ๋•Œ ์‹œ๊ฐ์ ์œผ๋กœ๋งŒ ์ƒํƒœ๊ฐ€ ๋ณ€ํ•˜๊ณ (์˜ˆ: ๋ณต์‚ฌ ์•„์ด์ฝ˜์ด ์ฒดํฌ ์•„์ด์ฝ˜์œผ๋กœ ๋ณ€๊ฒฝ), ํ…์ŠคํŠธ๊ฐ€ ๋™์ ์œผ๋กœ ๋ณ€๊ฒฝ๋˜๋Š” ์ปดํฌ๋„ŒํŠธ์—์„œ๋Š” ์Šคํฌ๋ฆฐ ๋ฆฌ๋” ์‚ฌ์šฉ์ž๊ฐ€ ์ƒํƒœ ๋ณ€ํ™”๋ฅผ ์•Œ์•„์ฑ„๊ธฐ ์–ด๋ ต์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ ์Šคํฌ๋ฆฐ ๋ฆฌ๋”๊ฐ€ ์ˆœ์ˆ˜ ์žฅ์‹์šฉ ์•„์ด์ฝ˜๊นŒ์ง€ ๋ถˆํ•„์š”ํ•˜๊ฒŒ ์ฝ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
**Action:** ๋™์ ์œผ๋กœ ๋ณ€๊ฒฝ๋˜๋Š” ํ…์ŠคํŠธ๋ฅผ `<span aria-live="polite">`๋กœ ๊ฐ์‹ธ ์Šคํฌ๋ฆฐ ๋ฆฌ๋”๊ฐ€ ์ฆ‰์‹œ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ์ฝ์–ด์ฃผ๋„๋ก ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. `<Button>` ์ปดํฌ๋„ŒํŠธ์—๋Š” `aria-pressed={copied}`๋ฅผ ์ถ”๊ฐ€ํ•˜์—ฌ ํ† ๊ธ€ ์„ฑ๊ฒฉ์„ ๋ถ€์—ฌํ•˜๊ณ , ์‹œ๊ฐ์ ์ธ ์•„์ด์ฝ˜ ์ปดํฌ๋„ŒํŠธ(์˜ˆ: `<Copy>`, `<Check>`)์—๋Š” `aria-hidden="true"`๋ฅผ ์ถ”๊ฐ€ํ•˜์—ฌ ์Šคํฌ๋ฆฐ ๋ฆฌ๋”์—์„œ ๋ฌด์‹œํ•˜๋„๋ก ์ฒ˜๋ฆฌํ•˜๋Š” ํŒจํ„ด์„ ์ง€์†์ ์œผ๋กœ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.


## 2024-11-21 - ๋Œ€ํ™”ํ˜• ์š”์†Œ์˜ ์ ‘๊ทผ์„ฑ ์ƒํƒœ ๋ณ€๊ฒฝ (Accessible State Changes on Interactive Elements)
**Learning:** ์ƒํ˜ธ์ž‘์šฉ ์š”์†Œ(์˜ˆ: ํด๋ฆญ ์‹œ '๋ณต์‚ฌ'์—์„œ '๋ณต์‚ฌ๋จ'์œผ๋กœ ํ…์ŠคํŠธ๊ฐ€ ๋ณ€๊ฒฝ๋˜๋Š” ๋ฒ„ํŠผ)์—์„œ ์‹œ๊ฐ์  ์„ฑ๊ณต ํ”ผ๋“œ๋ฐฑ์„ ์ œ๊ณตํ•  ๋•Œ, ํ˜„์žฌ ํฌ์ปค์Šค๋œ ๋ฒ„ํŠผ์˜ ์ ‘๊ทผ์„ฑ ์ด๋ฆ„(accessible name)์„ ๋ณ€๊ฒฝํ•˜๋Š” ๊ฒƒ์€ ์Šคํฌ๋ฆฐ ๋ฆฌ๋” ์‚ฌ์šฉ์ž์—๊ฒŒ ์‹ ๋ขฐํ•  ์ˆ˜ ์—†๋Š” ๊ฒฝํ—˜์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ƒํƒœ ๋ณ€๊ฒฝ์ด ์ œ๋Œ€๋กœ ์ฝํžˆ์ง€ ์•Š๊ฑฐ๋‚˜ ์ „ํ˜€ ์ฝํžˆ์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
**Action:** ๋™์ž‘์˜ ์‹œ๊ฐ์  ๋ฐ ์ ‘๊ทผ์„ฑ ๋ ˆ์ด๋ธ”์„ ์•ˆ์ •์ ์œผ๋กœ ์œ ์ง€ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค(์˜ˆ: `aria-label`์„ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ ๋ฉ”์ธ ํ…์ŠคํŠธ๋ฅผ ๋™์ผํ•˜๊ฒŒ ์œ ์ง€). ํ™”๋ฉด์„ ์‹œ๊ฐ์ ์œผ๋กœ ์ˆจ๊ธด(`sr-only`) ๋ณ„๋„์˜ ํ˜•์ œ ์ปจํ…Œ์ด๋„ˆ์— `role="status"` ๋ฐ `aria-atomic="true"`๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ƒํƒœ ์—…๋ฐ์ดํŠธ๋ฅผ ์Šคํฌ๋ฆฐ ๋ฆฌ๋”์— ๋ช…ํ™•ํ•˜๊ฒŒ ์•Œ๋ฆฌ๋Š” ํŒจํ„ด์„ ์ ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
5 changes: 5 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,3 +30,8 @@
**Vulnerability:** Known high-severity vulnerabilities discovered by the audit in `js-yaml` and `nanoid` packages.
**Learning:** Deeply nested dependencies (`js-yaml` via `eslint`, `nanoid` via `vitest/vite`) may expose the application to DoS or logic loops.
**Prevention:** Use `pnpm.overrides` in the root `package.json` to enforce patched versions across all transitive paths in a pnpm workspace.

## 2024-11-21 - deepmerge-ts ReDoS Vulnerability
**Vulnerability:** deepmerge-ts@7.1.5 was vulnerable to ReDoS (Regular Expression Denial of Service) through GHSA-ggr8-5vv4-36mx.
**Learning:** This vulnerability existed in deeply nested dependency trees and was flagged by the strict OSV-Scanner checks in CI.
**Prevention:** Always ensure vulnerabilities in deeply nested dependencies (like deepmerge-ts) are enforced to the patched versions using the `pnpm.overrides` block in the root `package.json` to safely patch them and pass CI checks.
3 changes: 2 additions & 1 deletion package.json
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,8 @@
"undici": "^7.29.0",
"minimatch": "^10.0.0",
"@hono/node-server": "^2.0.5",
"body-parser": "^2.3.0"
"body-parser": "^2.3.0",
"deepmerge-ts": "8.0.0"
}
}
}
9 changes: 5 additions & 4 deletions packages/web/src/components/copy-prompt-button.test.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -38,14 +38,15 @@ describe('CopyPromptButton', () => {
const button = screen.getByRole('button');
expect(button).toBeDefined();
expect(button.getAttribute('aria-pressed')).toBe('false');
expect(screen.getByText('ํ”„๋กฌํ”„ํŠธ ๋ณต์‚ฌ')).toBeDefined();
expect(button.getAttribute('aria-label')).toBe('ํ”„๋กฌํ”„ํŠธ ๋ณต์‚ฌ');
expect(screen.getAllByText('ํ”„๋กฌํ”„ํŠธ ๋ณต์‚ฌ')[0]).toBeDefined();
expect(screen.getByTestId('copy-icon')).toBeDefined();
});

it('renders correctly with custom labels', () => {
render(<CopyPromptButton text="test prompt" label="Copy" copiedLabel="Copied" />);

expect(screen.getByText('Copy')).toBeDefined();
expect(screen.getAllByText('Copy')[0]).toBeDefined();
});

it('copies text and shows copied state temporarily', async () => {
Expand All @@ -61,7 +62,7 @@ describe('CopyPromptButton', () => {

// Check copied state
expect(button.getAttribute('aria-pressed')).toBe('true');
expect(screen.getByText('Copied')).toBeDefined();
expect(screen.getAllByText('Copied')[0]).toBeDefined();
expect(screen.getByTestId('check-icon')).toBeDefined();

// Fast-forward timer
Expand All @@ -71,7 +72,7 @@ describe('CopyPromptButton', () => {

// Check reverted state
expect(button.getAttribute('aria-pressed')).toBe('false');
expect(screen.getByText('Copy')).toBeDefined();
expect(screen.getAllByText('Copy')[0]).toBeDefined();
expect(screen.getByTestId('copy-icon')).toBeDefined();
});

Expand Down
6 changes: 5 additions & 1 deletion packages/web/src/components/copy-prompt-button.tsx
Original file line number Diff line number Diff line change
Expand Up @@ -38,12 +38,16 @@ export function CopyPromptButton({
variant="outline"
onClick={handleCopy}
aria-pressed={copied}
aria-label={label}
className={cn("gap-1.5", className)}
>
{copied ? <Check aria-hidden="true" /> : <Copy aria-hidden="true" />}
<span aria-live="polite">
<span aria-hidden="true">
{copied ? copiedLabel : label}
</span>
<span role="status" aria-atomic="true" className="sr-only">
{copied ? copiedLabel : ""}
</span>
Comment on lines +41 to +50

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

๐Ÿ“ Info: Visible text and accessible name diverge when copied

The button's aria-label stays fixed to label while the visible span switches to copiedLabel on copy. In the copied state the visible text is absent from the accessible name, diverging from WCAG 2.5.3 Label in Name. This is the intended tradeoff to keep a stable accessible name and announce state through the separate role="status" region.

Open in Devin Review

Was this helpful? React with ๐Ÿ‘ or ๐Ÿ‘Ž to provide feedback.

</Button>
);
}
9 changes: 5 additions & 4 deletions pnpm-lock.yaml

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading