Prefill child safety removal reports

This commit is contained in:
SimpleTest 2026-08-10 14:49:57 +03:00
parent 2a17a23f95
commit 8449ee696f
5 changed files with 45 additions and 6 deletions

View File

@ -2775,3 +2775,10 @@ promoted.
errors or warnings. Production and the frozen hackathon test still return errors or warnings. Production and the frozen hackathon test still return
`404` for `/child-safety` because neither deployment includes this later local `404` for `/child-safety` because neither deployment includes this later local
revision. revision.
- The child-safety reporting action now opens the public content-removal form
with the CSAE/CSAM category already selected. The controller accepts only
category values declared by the notice schema and ignores unknown query
values. ExUnit covers both paths. A headed browser check followed the Russian
reporting action without submitting the form and observed the expected
`child_sexual_abuse_material` selection, no horizontal overflow, and zero
console errors or warnings.

View File

@ -16,10 +16,9 @@ defmodule WhoNeedHelpWeb.ContentRemovalController do
def new(conn, params) do def new(conn, params) do
attrs = attrs =
case internal_location(params["location"]) do %{}
nil -> %{} |> put_if_present("content_locations", internal_location(params["location"]))
location -> %{"content_locations" => location} |> put_if_present("category", permitted_category(params["category"]))
end
render_form(conn, :general, %Notice{}, attrs) render_form(conn, :general, %Notice{}, attrs)
end end
@ -143,6 +142,16 @@ defmodule WhoNeedHelpWeb.ContentRemovalController do
end end
end end
defp put_if_present(attrs, _key, nil), do: attrs
defp put_if_present(attrs, key, value), do: Map.put(attrs, key, value)
defp permitted_category(category) when is_binary(category) do
if category in Enum.map(Ecto.Enum.values(Notice, :category), &Atom.to_string/1),
do: category
end
defp permitted_category(_category), do: nil
defp current_email(%{assigns: %{current_scope: %{user: %{email: email}}}}), do: email defp current_email(%{assigns: %{current_scope: %{user: %{email: email}}}}), do: email
defp current_email(_conn), do: nil defp current_email(_conn), do: nil

View File

@ -32,7 +32,10 @@
)} )}
</p> </p>
<div class="mt-4 flex flex-col gap-3 sm:flex-row"> <div class="mt-4 flex flex-col gap-3 sm:flex-row">
<.link href={~p"/legal/content-removal"} class="btn btn-error"> <.link
href={~p"/legal/content-removal?category=child_sexual_abuse_material"}
class="btn btn-error"
>
{gettext("Report child-safety content")} {gettext("Report child-safety content")}
</.link> </.link>
<.link href={~p"/support"} class="btn btn-outline"> <.link href={~p"/support"} class="btn btn-outline">

View File

@ -217,7 +217,10 @@ defmodule WhoNeedHelpWeb.PageControllerTest do
assert html =~ "Child safety standards" assert html =~ "Child safety standards"
assert html =~ "child sexual abuse and exploitation (CSAE)" assert html =~ "child sexual abuse and exploitation (CSAE)"
assert html =~ "National Center for Missing &amp; Exploited Children" assert html =~ "National Center for Missing &amp; Exploited Children"
assert html =~ ~s(href="/legal/content-removal")
assert html =~
~s(href="/legal/content-removal?category=child_sexual_abuse_material")
assert html =~ ~s(href="/support") assert html =~ ~s(href="/support")
assert html =~ "Child safety standards · Who Need Help" assert html =~ "Child safety standards · Who Need Help"
assert html =~ "standards against child sexual abuse and exploitation" assert html =~ "standards against child sexual abuse and exploitation"

View File

@ -30,6 +30,23 @@ defmodule WhoNeedHelpWeb.SupportControllerTest do
get(conn, ~p"/legal/content-removal?location=/requests/specific-id"), get(conn, ~p"/legal/content-removal?location=/requests/specific-id"),
200 200
) =~ "/requests/specific-id" ) =~ "/requests/specific-id"
child_safety =
html_response(
get(
conn,
~p"/legal/content-removal?category=child_sexual_abuse_material"
),
200
)
assert child_safety =~
~s(<option selected value="child_sexual_abuse_material">Sexual material involving a minor</option>)
invalid_category =
html_response(get(conn, ~p"/legal/content-removal?category=not-a-real-category"), 200)
refute invalid_category =~ ~s(<option selected value="not-a-real-category">)
end end
test "creates support request without exposing its status token in the redirect", %{ test "creates support request without exposing its status token in the redirect", %{