Skip to content

Jlc/backport last teak changes - #95

Open
johanseto wants to merge 31 commits into
open-release/teak.nelpfrom
jlc/backport-last-teak-changes
Open

johanseto wants to merge 31 commits into
open-release/teak.nelpfrom
jlc/backport-last-teak-changes

Conversation

@johanseto

Copy link
Copy Markdown

Description

Describe what this pull request changes, and why. Include implications for people using this change.
Design decisions and their rationales should be documented in the repo (docstring / ADR), per
OEP-19, and can be
linked here.

Useful information to include:

  • Which edX user roles will this change impact? Common user roles are "Learner", "Course Author",
    "Developer", and "Operator".
  • Include screenshots for changes to the UI (ideally, both "before" and "after" screenshots, if applicable).
  • Provide links to the description of corresponding configuration changes. Remember to correctly annotate these
    changes.

Supporting information

Link to other information about the change, such as Jira issues, GitHub issues, or Discourse discussions.
Be sure to check they are publicly readable, or if not, repeat the information here.

Testing instructions

Please provide detailed step-by-step instructions for testing this change.

Deadline

"None" if there's no rush, or provide a specific date or event (and reason) if there is one.

Other information

Include anything else that will help reviewers and consumers understand the change.

  • Does this change depend on other changes elsewhere?
  • Any special concerns or limitations? For example: deprecations, migrations, security, or accessibility.
  • If your database migration can't be rolled back easily.

andrey-canon and others added 30 commits August 26, 2025 15:48
…ror (#56) (#67)

* fix: implement __repr__ method in order to avoid maximum recursion error

* chore: apply pr suggestions

(cherry picked from commit 9e26088)

Co-authored-by: Andrey Cañon <36200299+andrey-canon@users.noreply.github.com>
#62)

(cherry picked from commit 8697c96)
(cherry picked from commit 0976ffb)

Co-authored-by: andrey-canon <andrey.canon@edunext.co>
(cherry picked from commit f99b720)
(cherry picked from commit 43e5740)

Co-authored-by: andrey-canon <andrey.canon@edunext.co>
(cherry picked from commit 0663883)

Co-authored-by: andrey-canon <andrey.canon@edunext.co>
(cherry picked from commit 4de5d0e)

Co-authored-by: shadinaif <shadinaif@gmail.com>
* feat: disable order history from user dropdown

* feat: invert logic due pr sugs

* chore: pr suggestion default behaviour
…ile so can be override later (#65)

(cherry picked from commit e4c6a85)

Co-authored-by: Tehreem Sadat <ts.tehreem@gmail.com>
* refactor: centralize user preference caching in the model layer

Refactored caching logic by moving cache management from the API
layer to the `UserPreference` model. This change ensures that
`get_all_preferences` handles its own caching consistently,
preventing stale data issues previously caused by the
`@request_cached` decorator and manual API-level caching.

Changes:
- Moved cache helpers to `user_api/helpers.py`.
- Updated `UserPreference.get_all_preferences` to use the new
  caching logic.
- Cleaned up `user_api/preferences/api.py` to remove redundant
  cache checks, delegating to the model instead.
- Ensured cache invalidation is triggered correctly on
  create/update/delete operations.

* docs(cache): add docstrings to user preferences cache utilities

Added comprehensive Google-style docstrings to cache key generation,
retrieval, storage, and invalidation functions. Improved code
maintainability and clarified expected parameter types.
#73)

* perf(grades): refactor course grade tasks to use keyset pagination and select_related

* refactor(grades): adapt management command and tests for keyset pagination

Updated the grading infrastructure to support the transition from
offset-based pagination to ID-based (keyset) pagination.

- Command: Modified `compute_grades` to correctly map `start_id` from
  the `_course_task_args` generator and updated task kwarg injection.
- Tests: Fixed `test_compute_grades.py` by replacing static offsets
  with dynamic ID lookups from the test database.
- Tasks Tests: Refactored `ComputeGradesForCourseTest` and
  `FreezeGradingAfterCourseEndTest` to use real enrollment IDs
  for 'start_id' arguments, fixing AssertionErrors caused by empty
  querysets and mismatched task signatures.

* refactor(grades): optimize enrollment batching and loop readability

- Replaced the manual index range loop with list slicing for better
  readability in `_course_task_args`.
- Renamed loop variable to `batch_start_id` to clarify it represents
  the starting ID of each chunk.
- Updated `enrollments` query in `compute_grades_for_course` to use
  standard list-based filtering instead of a set-like structure,
  ensuring `order_by` consistency.
)

* fix: studio api-docs crashes with 500 error

Co-authored-by: M. Sumair Khokhar <sumair.tanveer@arbisoft.com>
* feat: upgrading students_update_enrollment api to DRF

* feat: add instructor task for async batch enrollment

---------

Co-authored-by: Hunzlah Malik <50262751+hunzlahmalik@users.noreply.github.com>
Co-authored-by: Bryann Valderrama <bryann.valderrama@edunext.co>
…rdcoded LTR import (#81)

- Removed the explicit `@import 'vendor/bi-app/bi-app-ltr';` in `_builtin-block-variables.scss` that was overriding RTL configurations.
- Replaced physical CSS properties (`left`, `padding-left`, `margin-right`) with their logical equivalents (`inset-inline-start`, `padding-inline-start`, `margin-inline-end`) in `ProblemBlockDisplay.css` to natively support bidirectional layouts.
The previous vendored pdf.js was 1.0.907 (May 2013), four major versions
behind upstream and within the range covered by Mozilla's
GHSA-wgrm-67xf-hhpq (arbitrary JavaScript execution upon opening a
malicious PDF). 5.7.284 is well past the >= 4.2.67 fix line.

The replacement comes from Mozilla's prebuilt
`pdfjs-5.7.284-legacy-dist.zip` GitHub Release artifact rather than the
`pdfjs-dist` npm package because the npm package is library-only -- it
ships `pdf.mjs` plus a bare `PDFViewer` component class, but no
`viewer.html` / `viewer.mjs` / `viewer.css` / locale files. A full npm
integration would mean rewriting the viewer page against the bare
component, which is appropriate as a non-security follow-up but not as
the fix here.

The viewer page (`lms/templates/pdf_viewer.html`) is rewritten as a Mako
adaptation of upstream `web/viewer.html`. A `<base href>` makes the
viewer's relative asset URLs resolve against the vendored copy.

The analytics shim (`lms/static/js/pdf-analytics.js`) is rewritten in
vanilla JS against `PDFViewerApplication.eventBus`. Four analytics
events (`textbook.pdf.thumbnails.toggled`,
`textbook.pdf.thumbnail.navigated`, `textbook.pdf.outline.toggled`,
`textbook.pdf.page.scrolled`) no longer fire because the corresponding
UI elements were refactored away in pdf.js 4.x's Views Manager
redesign.

A new `scripts/refresh-pdfjs-vendor.sh` is the tool for future bumps:
update PDFJS_VERSION + PDFJS_LEGACY_ZIP_SHA256, re-run, commit.

Closes GHSA-mj74-gfq3-2v9f.

Co-authored-by: Feanil Patel <feanil@axim.org>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Studio course assets are served by the contentserver with the uploader-supplied
Content-Type and no neutralizing headers, on a route mounted on the Studio (CMS)
origin. An author with file-upload permission can upload an HTML or SVG file
containing script; when another user opens the asset URL it runs same-origin
with the Studio session, enabling privilege escalation (self-granting
course-admin, or Django superuser via same-origin /admin/ when a global-staff
user views it).

Send `Content-Security-Policy: sandbox` on every course-asset response so the
asset loads in an opaque origin and cannot script against the Studio/LMS
session. A per-course escape-hatch flag, course_assets.allow_unsafe_asset_rendering,
lets operators temporarily disable sandboxing for a course whose content must be
migrated first.

Closes GHSA-c6xg-fh3c-vvhh.


(cherry picked from commit b5fc56a)

Co-authored-by: Feanil Patel <feanil@axim.org>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
…its from libraries [FC-0097] (openedx#37282)

* Show disabled edit button and tooltip to component in units from libraries
We previously fixed this when the CourseLimitedStaffRole was applied to
a course but did not handle the case where the role is applied to a user
for a whole org.  The underlying issue is that the CourseLimitedStaffRole
is a subclass of the CourseStaffRole and much of the system assumes that
subclesses are for giving more access not less access.

To prevent that from happening for the case of the CourseLimitedStaffRole,
when we do CourseStaffRole access checks, we use the strict_role_checking
context manager to ensure that we're not accidentally granting the
limited_staff role too much access.
Co-authored-by: ayesha waris <73840786+ayesha-waris@users.noreply.github.com>
Bumps the `openedx-forum` pin from 0.4.0 to 0.4.1 on `release/teak`
to pull in the fix for the "pinned"-NULL sort bug
(openedx/forum#270, commit 78b36e4) where discussion threads were
not ordering correctly when users selected "recent first" — old
threads with NULL `pinned` values floated above newer threads.

Reported in:
https://discuss.openedx.org/t/discuss-forum-messages-order-not-organized-as-expected-in-teak/18665

Caps openedx-forum at <=0.4.1 in constraints.txt to avoid:
  * 0.4.2 — drops Python 3.11 support (Teak still supports 3.11)
  * 0.4.3 — removes the MongoDB backend (Teak deployments may rely on it)

The 0.4.0 -> 0.4.1 delta also adds the optional Typesense search
backend (additive, off by default), pulling in `typesense==2.0.0`
as a new transitive dependency. That pin is added to the compiled
requirements files. The constraint should be removed on master /
post-Teak release lines.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
openedx-forum 0.4.1 adds the (off-by-default) Typesense search backend,
which transitively requires `typesense`. typesense>=2.0.0 requires
httpx>=0.28.1, but pact-python==2.0.1 — a transitive test dependency
already pinned on release/teak — requires httpx==0.23.3. That is an
unresolvable pip conflict and causes CI's "Compile requirements" step
to fail with ResolutionImpossible.

typesense==1.3.0 only requires `requests`+`typing-extensions` (both
already present on teak) and is sufficient since the Typesense backend
is off by default on Teak; the active search backends are Meilisearch
and Elasticsearch which do not depend on the typesense client.

Adds `typesense<2.0.0` to requirements/constraints.txt with an
explanatory comment and regenerates the compiled requirements files
via `pip-compile --upgrade-package openedx-forum`.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@andrey-canon
andrey-canon force-pushed the open-release/teak.nelp branch from fa870d0 to e57b2e4 Compare October 1, 2026 20:57
@johanseto

Copy link
Copy Markdown
Author

Closed in favour of #97 and the last rebase of open-release/teak.nelp of release/teak from upstream

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants