Fix HTML-escaped loading indicator and missing success messages

Two regressions surfaced by a fresh production install:

- formAJAX's "loading" indicator passed a raw <div class="spinner-border">
  string to app.messages.action, which HTML-escapes its message by design
  (@simpleworkjs/frontend) -- so every form submit briefly showed the
  literal markup as text instead of a spinner. Replaced with plain text
  ("Saving…"), which needs no escaping workaround.

- POST /api/user/ (create) and PUT /api/user/password didn't include a
  `message` field, so the success toast/banner rendered with an empty
  body -- a green notification with nothing in it right after adding a
  user. Added messages matching the convention already used by every
  other route in this file (activate/deactivate, group membership, etc).

Verified live: created a user through the actual modal, confirmed the
POST response now carries a message, and confirmed app.messages.toast
renders plain text cleanly with no escaping artifacts.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-28 12:52:09 -04:00
parent 1b0418e42e
commit 3a46680c8b
2 changed files with 6 additions and 9 deletions
+4 -7
View File
@@ -679,13 +679,10 @@ function formAJAX(btn){
return false; return false;
} }
app.messages.action( // Plain text: app.messages.action HTML-escapes its message (by design,
`<div class="spinner-border" role="status"> // see @simpleworkjs/frontend), so raw markup like a spinner <div> would
<span class="visually-hidden">Loading...</span> // render literally instead of as an element.
</div>`, app.messages.action('Saving…', $form, 'info');
$form,
'info'
);
app.api[method]($form.attr('action'), formData, function(error, data){ app.api[method]($form.attr('action'), formData, function(error, data){
app.messages.action(data.message, $form, error ? 'danger' : 'success'); //re-populate table app.messages.action(data.message, $form, error ? 'danger' : 'success'); //re-populate table
+2 -2
View File
@@ -49,7 +49,7 @@ router.post('/', async function(req, res, next){
} }
} }
return res.json({results: user}); return res.json({results: user, message: `User ${user.uid} created.`});
}catch(error){ }catch(error){
next(error); next(error);
} }
@@ -107,7 +107,7 @@ router.put('/password', async function(req, res, next){
const verif = await UserVerification.getOrCreate(req.user.uid); const verif = await UserVerification.getOrCreate(req.user.uid);
await verif.update({ password_must_change: false }); await verif.update({ password_must_change: false });
User.clearCache(); User.clearCache();
return res.json({results: result}); return res.json({results: result, message: 'Password changed.'});
}catch(error){ }catch(error){
next(error); next(error);
} }