From 4a3b21b4f7c43393e20f78b164c25a5cab8e1bb3 Mon Sep 17 00:00:00 2001 From: Russ T Fugal Date: Mon, 23 Feb 2026 23:22:20 -0700 Subject: [PATCH] appview: validate repo description length (max 140 chars) The description field had no length validation, so long descriptions would pass the form but fail at the DB INSERT (CHECK constraint) or lexicon layer (maxGraphemes: 140), after the PDS record and bare repo were already created. Add client-side maxlength and server-side rune count validation to reject early and avoid partial rollback state. --- appview/pages/templates/repo/new.html | 3 ++- appview/state/state.go | 4 ++++ 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/appview/pages/templates/repo/new.html b/appview/pages/templates/repo/new.html index 2edc04b8..a117c74b 100644 --- a/appview/pages/templates/repo/new.html +++ b/appview/pages/templates/repo/new.html @@ -110,11 +110,12 @@ type="text" id="description" name="description" + maxlength="140" class="w-full w-full dark:bg-gray-700 dark:text-white dark:border-gray-600 border border-gray-300 rounded px-3 py-2" placeholder="A brief description of your project..." />

- Optional. A short description to help others understand what your project does. + Optional. A short description to help others understand what your project does (max 140 characters).

{{ end }} diff --git a/appview/state/state.go b/appview/state/state.go index 604a33a8..fd5b85ae 100644 --- a/appview/state/state.go +++ b/appview/state/state.go @@ -469,6 +469,10 @@ func (s *State) NewRepo(w http.ResponseWriter, r *http.Request) { l = l.With("defaultBranch", defaultBranch) description := r.FormValue("description") + if len([]rune(description)) > 140 { + s.pages.Notice(w, "repo", "Description must be 140 characters or fewer.") + return + } // ACL validation ok, err := s.enforcer.E.Enforce(user.Active.Did, domain, domain, "repo:create") -- 2.51.2