diff --git a/docs/verification.md b/docs/verification.md index 6897df0..535bcbd 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -2775,3 +2775,10 @@ promoted. errors or warnings. Production and the frozen hackathon test still return `404` for `/child-safety` because neither deployment includes this later local revision. +- The child-safety reporting action now opens the public content-removal form + with the CSAE/CSAM category already selected. The controller accepts only + category values declared by the notice schema and ignores unknown query + values. ExUnit covers both paths. A headed browser check followed the Russian + reporting action without submitting the form and observed the expected + `child_sexual_abuse_material` selection, no horizontal overflow, and zero + console errors or warnings. diff --git a/lib/who_need_help_web/controllers/content_removal_controller.ex b/lib/who_need_help_web/controllers/content_removal_controller.ex index cb60273..47951f7 100644 --- a/lib/who_need_help_web/controllers/content_removal_controller.ex +++ b/lib/who_need_help_web/controllers/content_removal_controller.ex @@ -16,10 +16,9 @@ defmodule WhoNeedHelpWeb.ContentRemovalController do def new(conn, params) do attrs = - case internal_location(params["location"]) do - nil -> %{} - location -> %{"content_locations" => location} - end + %{} + |> put_if_present("content_locations", internal_location(params["location"])) + |> put_if_present("category", permitted_category(params["category"])) render_form(conn, :general, %Notice{}, attrs) end @@ -143,6 +142,16 @@ defmodule WhoNeedHelpWeb.ContentRemovalController do end end + defp put_if_present(attrs, _key, nil), do: attrs + defp put_if_present(attrs, key, value), do: Map.put(attrs, key, value) + + defp permitted_category(category) when is_binary(category) do + if category in Enum.map(Ecto.Enum.values(Notice, :category), &Atom.to_string/1), + do: category + end + + defp permitted_category(_category), do: nil + defp current_email(%{assigns: %{current_scope: %{user: %{email: email}}}}), do: email defp current_email(_conn), do: nil diff --git a/lib/who_need_help_web/controllers/page_html/child_safety.html.heex b/lib/who_need_help_web/controllers/page_html/child_safety.html.heex index a41e5fd..36f6d90 100644 --- a/lib/who_need_help_web/controllers/page_html/child_safety.html.heex +++ b/lib/who_need_help_web/controllers/page_html/child_safety.html.heex @@ -32,7 +32,10 @@ )}

- <.link href={~p"/legal/content-removal"} class="btn btn-error"> + <.link + href={~p"/legal/content-removal?category=child_sexual_abuse_material"} + class="btn btn-error" + > {gettext("Report child-safety content")} <.link href={~p"/support"} class="btn btn-outline"> diff --git a/test/who_need_help_web/controllers/page_controller_test.exs b/test/who_need_help_web/controllers/page_controller_test.exs index d0a02f5..c04b443 100644 --- a/test/who_need_help_web/controllers/page_controller_test.exs +++ b/test/who_need_help_web/controllers/page_controller_test.exs @@ -217,7 +217,10 @@ defmodule WhoNeedHelpWeb.PageControllerTest do assert html =~ "Child safety standards" assert html =~ "child sexual abuse and exploitation (CSAE)" assert html =~ "National Center for Missing & Exploited Children" - assert html =~ ~s(href="/legal/content-removal") + + assert html =~ + ~s(href="/legal/content-removal?category=child_sexual_abuse_material") + assert html =~ ~s(href="/support") assert html =~ "Child safety standards ยท Who Need Help" assert html =~ "standards against child sexual abuse and exploitation" diff --git a/test/who_need_help_web/controllers/support_controller_test.exs b/test/who_need_help_web/controllers/support_controller_test.exs index 8b0de07..5220141 100644 --- a/test/who_need_help_web/controllers/support_controller_test.exs +++ b/test/who_need_help_web/controllers/support_controller_test.exs @@ -30,6 +30,23 @@ defmodule WhoNeedHelpWeb.SupportControllerTest do get(conn, ~p"/legal/content-removal?location=/requests/specific-id"), 200 ) =~ "/requests/specific-id" + + child_safety = + html_response( + get( + conn, + ~p"/legal/content-removal?category=child_sexual_abuse_material" + ), + 200 + ) + + assert child_safety =~ + ~s() + + invalid_category = + html_response(get(conn, ~p"/legal/content-removal?category=not-a-real-category"), 200) + + refute invalid_category =~ ~s(