overleaf/services/web
Alf Eaton 869bdf89e0 Merge pull request #3722 from overleaf/as-fix-project-invite-xss
Prevent stored XSS on project invite page

GitOrigin-RevId: ada89c46d62e64d794edacc9be3c08b622ce433c
2021-03-05 03:04:39 +00:00
..
.github
.storybook Merge pull request #3645 from overleaf/ae-import-config 2021-03-04 03:04:21 +00:00
.vscode
app Merge pull request #3722 from overleaf/as-fix-project-invite-xss 2021-03-05 03:04:39 +00:00
bin
config Merge pull request #3645 from overleaf/ae-import-config 2021-03-04 03:04:21 +00:00
data
frontend Merge pull request #3682 from overleaf/bg-check-maintenance-file 2021-02-26 03:04:07 +00:00
locales auto update translation 2021-02-25 03:04:16 +00:00
modules
public
scripts Merge pull request #3678 from overleaf/jpa-back-fill-deleted-files-handle-duplicates 2021-02-20 03:04:25 +00:00
test Merge pull request #3703 from overleaf/jpa-spd-mocks-reset-is-optional 2021-02-26 03:04:37 +00:00
transform/o-error
.dockerignore
.eastrc
.eslintignore
.eslintrc Merge pull request #3715 from overleaf/ae-eslint-config-prettier 2021-03-04 03:04:17 +00:00
.gitignore Merge pull request #3645 from overleaf/ae-import-config 2021-03-04 03:04:21 +00:00
.prettierignore
.prettierrc
app.js
babel.config.json
docker-compose.ci.yml
docker-compose.yml
Dockerfile Merge pull request #3660 from overleaf/ae-dockerfile 2021-02-19 03:04:29 +00:00
Dockerfile.frontend
Dockerfile.frontend.ci
i18next-scanner.config.js
install_deps.sh
karma.conf.js
LICENSE
Makefile
Makefile.module
nodemon.json
package-lock.json Merge pull request #3715 from overleaf/ae-eslint-config-prettier 2021-03-04 03:04:17 +00:00
package.json Merge pull request #3715 from overleaf/ae-eslint-config-prettier 2021-03-04 03:04:17 +00:00
README.md
webpack.config.dev.js Merge pull request #3676 from overleaf/ae-webpack-live-reload 2021-02-23 03:04:27 +00:00
webpack.config.js
webpack.config.prod.js
webpack.config.test.js

overleaf/web

overleaf/web is the front-end web service of the open-source web-based collaborative LaTeX editor, Overleaf. It serves all the HTML pages, CSS and javascript to the client. overleaf/web also contains a lot of logic around creating and editing projects, and account management.

The rest of the Overleaf stack, along with information about contributing can be found in the overleaf/overleaf repository.

Build process

overleaf/web uses Grunt to build its front-end related assets.

Image processing tasks are commented out in the gruntfile and the needed packages aren't presently in the project's package.json. If the images need to be processed again (minified and sprited), start by fetching the packages (npm install grunt-contrib-imagemin grunt-sprity), then decomment the tasks in Gruntfile.coffee. After this, the tasks can be called (explicitly, via grunt imagemin and grunt sprity).

New Docker-based build process

Note that the Grunt workflow from above should still work, but we are transitioning to a Docker based testing workflow, which is documented below:

Running the app

The app runs natively using npm and Node on the local system:

$ npm install
$ npm run start

Ideally the app would run in Docker like the tests below, but with host networking not supported in OS X, we need to run it natively until all services are Dockerised.

Running Tests

To run all tests run:

make test

To run both unit and acceptance tests for a module run:

make test_module MODULE=overleaf-integration

Unit Tests

The test suites run in Docker.

Unit tests can be run in the test_unit container defined in docker-compose.tests.yml.

The makefile contains a short cut to run these:

make test_unit

During development it is often useful to only run a subset of tests, which can be configured with arguments to the mocha CLI:

make test_unit MOCHA_GREP='AuthorizationManager'

To run only the unit tests for a single module do:

make test_unit_module MODULE=overleaf-integration

Module tests can also use a MOCHA_GREP argument:

make test_unit_module MODULE=overleaf-integration MOCHA_GREP=SSO

Acceptance Tests

Acceptance tests are run against a live service, which runs in the acceptance_test container defined in docker-compose.tests.yml.

To run the tests out-of-the-box, the makefile defines:

make test_acceptance

However, during development it is often useful to leave the service running for rapid iteration on the acceptance tests. This can be done with:

make test_acceptance_app_start_service
make test_acceptance_app_run # Run as many times as needed during development
make test_acceptance_app_stop_service

make test_acceptance just runs these three commands in sequence and then runs make test_acceptance_modules which performs the tests for each module in the modules directory. (Note that there is not currently an equivalent to the -start / -run x n / -stop series for modules.)

During development it is often useful to only run a subset of tests, which can be configured with arguments to the mocha CLI:

make test_acceptance_run MOCHA_GREP='AuthorizationManager'

To run only the acceptance tests for a single module do:

make test_acceptance_module MODULE=overleaf-integration

Module tests can also use a MOCHA_GREP argument:

make test_acceptance_module MODULE=overleaf-integration MOCHA_GREP=SSO

Routes

Run bin/routes to print out all routes in the project.

License and Credits

This project is licensed under the AGPLv3 license

Stylesheets

Overleaf is based on Bootstrap, which is licensed under the MIT license. All modifications (*.less files in public/stylesheets) are also licensed under the MIT license.

Artwork

Silk icon set 1.3

We gratefully acknowledge Mark James for releasing his Silk icon set under the Creative Commons Attribution 2.5 license. Some of these icons are used within Overleaf inside the public/img/silk and public/brand/icons directories.

IconShock icons

We gratefully acknowledge IconShock for use of the icons in the public/img/iconshock directory found via findicons.com