Skip to content

Add bounty board filtering/sorting/pagination and validate avatar image URLs - #574

Merged
chonilius merged 1 commit into
MergeFi:mainfrom
Godbrand0:fix/issues-28-20-bounty-filters-avatar-validation
Sep 28, 2026
Merged

chonilius merged 1 commit into
MergeFi:mainfrom
Godbrand0:fix/issues-28-20-bounty-filters-avatar-validation

Conversation

@Godbrand0

@Godbrand0 Godbrand0 commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

closes #28 and
closes #20 .

#28 — bounty board pagination/filtering/sorting

  • New src/lib/bounty-query.ts: parses status/difficulty/asset/minReward/maxReward/sort/page from searchParams, with every value degrading to a sane default instead of erroring (unrecognized enum, non-numeric or out-of-range page, inverted reward range, out-of-range page number all clamp/degrade gracefully).
  • /issues reads and renders these from the URL (Server Component searchParams, no client state), so every filter/sort/page combination is a shareable, bookmarkable link. Difficulty/asset/reward-range/sort are a plain <form method="get"> so the page works with JS disabled; the status pills stay <Link>s.
  • filterBounties/applyBountyQuery run against whatever fetchBounties returns — live or mock fallback — so the mock-data path has full filter/sort/pagination parity with live data by construction, with no separate mock-only logic to keep in sync.
  • fetchBounties now forwards the query as backend query params via buildBountyQueryString. The backend doesn't currently honor them (confirmed: /bounties returns the full unfiltered collection regardless), so the client-side pass above is still the source of truth — this is forward-compatible with server-side filtering landing later without needing another frontend change.
  • Empty state distinguishes "your filter matches nothing" from "the platform has nothing" (already existed for status; now covers all facets).

#20 — avatar URL validation

  • Avatar.tsx now rejects any src that isn't an https: URL on the same host allowlist as next.config.ts's images.remotePatterns (avatars.githubusercontent.com, api.dicebear.com) before it reaches next/image — blocks javascript:/data: schemes and any unexpected third-party host, falling back to the dicebear identicon.
  • Also falls back on a genuine load failure (404/unreachable) via onError, tracking the specific failed src so it doesn't retry the same failing URL in a loop but does retry if the prop later changes to a different URL.

Test plan

  • npx jest — all suites pass except 3 pre-existing failures unrelated to this change (timezone-dependent locale.test.ts, and CallbackClient.test.tsx failures present on main before this branch)
  • New tests: src/lib/bounty-query.test.ts (parsing, filtering, sorting, pagination, href-building) and expanded src/components/ui/Avatar.test.tsx (allowlisted host, non-allowlisted host, javascript:/data: schemes, load-failure fallback)
  • npx eslint clean on all changed files
  • npx tsc --noEmit — no new errors (pre-existing unrelated errors confirmed present on main)

Fixes MergeFi#28: /issues now reads status, difficulty, asset, reward-range,
sort, and page from searchParams (shareable/bookmarkable URLs), filters
and paginates in a way that works identically against live and mock
data, and clamps an invalid page/filter combo instead of erroring or
blanking the page. fetchBounties forwards the same params to the
backend so nothing needs to change here once /bounties supports them
server-side.

Fixes MergeFi#20: Avatar now rejects any src that isn't an https(s) URL on the
GitHub-avatar/dicebear allowlist (blocking javascript:/data: schemes and
unexpected hosts) before it ever reaches next/image, and falls back to
the dicebear identicon on a real load failure too, without an infinite
retry loop.
@vercel

vercel Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Godbrand0 is attempting to deploy a commit to the chonilius' projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Godbrand0 Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@chonilius
chonilius merged commit 455a22c into MergeFi:main Sep 28, 2026
1 check failed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants