diff --git a/docs/verification.md b/docs/verification.md index 6897df0..535bcbd 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -2775,3 +2775,10 @@ promoted. errors or warnings. Production and the frozen hackathon test still return `404` for `/child-safety` because neither deployment includes this later local revision. +- The child-safety reporting action now opens the public content-removal form + with the CSAE/CSAM category already selected. The controller accepts only + category values declared by the notice schema and ignores unknown query + values. ExUnit covers both paths. A headed browser check followed the Russian + reporting action without submitting the form and observed the expected + `child_sexual_abuse_material` selection, no horizontal overflow, and zero + console errors or warnings. diff --git a/lib/who_need_help_web/controllers/content_removal_controller.ex b/lib/who_need_help_web/controllers/content_removal_controller.ex index cb60273..47951f7 100644 --- a/lib/who_need_help_web/controllers/content_removal_controller.ex +++ b/lib/who_need_help_web/controllers/content_removal_controller.ex @@ -16,10 +16,9 @@ defmodule WhoNeedHelpWeb.ContentRemovalController do def new(conn, params) do attrs = - case internal_location(params["location"]) do - nil -> %{} - location -> %{"content_locations" => location} - end + %{} + |> put_if_present("content_locations", internal_location(params["location"])) + |> put_if_present("category", permitted_category(params["category"])) render_form(conn, :general, %Notice{}, attrs) end @@ -143,6 +142,16 @@ defmodule WhoNeedHelpWeb.ContentRemovalController do end end + defp put_if_present(attrs, _key, nil), do: attrs + defp put_if_present(attrs, key, value), do: Map.put(attrs, key, value) + + defp permitted_category(category) when is_binary(category) do + if category in Enum.map(Ecto.Enum.values(Notice, :category), &Atom.to_string/1), + do: category + end + + defp permitted_category(_category), do: nil + defp current_email(%{assigns: %{current_scope: %{user: %{email: email}}}}), do: email defp current_email(_conn), do: nil diff --git a/lib/who_need_help_web/controllers/page_html/child_safety.html.heex b/lib/who_need_help_web/controllers/page_html/child_safety.html.heex index a41e5fd..36f6d90 100644 --- a/lib/who_need_help_web/controllers/page_html/child_safety.html.heex +++ b/lib/who_need_help_web/controllers/page_html/child_safety.html.heex @@ -32,7 +32,10 @@ )}