mirror of
https://github.com/GSA/notifications-admin.git
synced 2026-07-25 18:38:57 -04:00
In user research, we’ve seen users copy/pasting the contents of the inbound SMS page into a spreadsheet, in order to keep a record of the messages they receive. They even went as far as to write a macro which fixed the errors caused by copying and pasting. It would be much easier if we just gave them the data already in a spreadsheet format. Which is what this commit does. One caveat is that, because spreadsheets can contain executable code (ie formulas), and because we’re populating the spreadsheet with user-submitted data (albeit via SMS) we need to be careful about injection attacks. The details of how these attacks work are detailed here (interesting reading): http://georgemauer.net/2017/10/07/csv-injection.html The mitigation is to not allow characters which initialise a formula at the start of the cell.
43 lines
1.6 KiB
HTML
43 lines
1.6 KiB
HTML
{% from "components/table.html" import list_table, field, hidden_field_heading, right_aligned_field_heading, row_heading %}
|
||
{% from "components/message-count-label.html" import message_count_label %}
|
||
|
||
<div class="ajax-block-container">
|
||
{% if messages %}
|
||
<p class="bottom-gutter-2-3 top-gutter-2-3">
|
||
<a href="{{ url_for('.inbox_download', service_id=current_service.id) }}" download="download" class="heading-small">Download these messages</a>
|
||
</p>
|
||
{% endif %}
|
||
{% call(item, row_number) list_table(
|
||
messages,
|
||
caption="Inbox",
|
||
caption_visible=False,
|
||
empty_message='When users text your service’s phone number ({}) you’ll see the messages here'.format(inbound_number),
|
||
field_headings=[
|
||
'From',
|
||
'First two lines of message'
|
||
],
|
||
field_headings_visible=False
|
||
) %}
|
||
{% call field() %}
|
||
<a
|
||
class="file-list-filename"
|
||
href="{{ url_for('.conversation', service_id=current_service.id, notification_id=item.id) }}#n{{ item.id }}"
|
||
>
|
||
{{ item.user_number | format_phone_number_human_readable }}
|
||
</a>
|
||
<span class="file-list-hint">{{ item.content }}</span>
|
||
{% endcall %}
|
||
{% call field(align='right') %}
|
||
<span class="align-with-message-body">
|
||
{{ item.created_at | format_delta }}
|
||
</span>
|
||
{% endcall %}
|
||
{% endcall %}
|
||
{% if messages %}
|
||
<p class="table-show-more-link">
|
||
{{ count_of_messages }} message{{ '' if 1 == count_of_messages else 's' }}
|
||
from {{ count_of_users }} user{{ '' if 1 == count_of_users else 's' }}
|
||
</p>
|
||
{% endif %}
|
||
</div>
|