Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Binary file removed archive/folderview.plus-2026.08.11.13.txz
Binary file not shown.
1 change: 0 additions & 1 deletion archive/folderview.plus-2026.08.11.13.txz.sha256

This file was deleted.

Binary file removed archive/folderview.plus-2026.08.11.14.txz
Binary file not shown.
1 change: 0 additions & 1 deletion archive/folderview.plus-2026.08.11.14.txz.sha256

This file was deleted.

Binary file removed archive/folderview.plus-2026.08.12.01.txz
Binary file not shown.
1 change: 0 additions & 1 deletion archive/folderview.plus-2026.08.12.01.txz.sha256

This file was deleted.

Binary file removed archive/folderview.plus-2026.08.20.02.txz
Binary file not shown.
1 change: 0 additions & 1 deletion archive/folderview.plus-2026.08.20.02.txz.sha256

This file was deleted.

Binary file added archive/folderview.plus-2026.08.24.01.txz
Binary file not shown.
1 change: 1 addition & 0 deletions archive/folderview.plus-2026.08.24.01.txz.sha256
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
abb24d180ae0b29aa30e46c9a9bb22550e53a930f6d2cda60e071dcea093d574 folderview.plus-2026.08.24.01.txz
Binary file added archive/folderview.plus-2026.08.24.02.txz
Binary file not shown.
1 change: 1 addition & 0 deletions archive/folderview.plus-2026.08.24.02.txz.sha256
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
665ad6a547d62a834faf4c329e4f7df6b5767500701e992cd63b55db737a1d23 folderview.plus-2026.08.24.02.txz
Binary file added archive/folderview.plus-2026.08.24.03.txz
Binary file not shown.
1 change: 1 addition & 0 deletions archive/folderview.plus-2026.08.24.03.txz.sha256
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
8e9a71b2985f065f9f21416dfce6dcb10cd72c1e24e34a00edf5508734b3f1f4 folderview.plus-2026.08.24.03.txz
Binary file added archive/folderview.plus-2026.08.24.04.txz
Binary file not shown.
1 change: 1 addition & 0 deletions archive/folderview.plus-2026.08.24.04.txz.sha256
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
9f4eca819eddf4f5a501137f13b743a259a52fff7a35d6e74278b797641ff259 folderview.plus-2026.08.24.04.txz
8 changes: 8 additions & 0 deletions docs/TROUBLESHOOTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -113,6 +113,12 @@ User-uploaded icons are separate from the asset pack. Their persistent source is

Standard, Adaptive, and Maximum must preserve configured preview content. If only expanded rows appear, copy runtime diagnostics and attach a sanitized support bundle before changing the folder membership.

### A Preview Container Menu Does Not Open

Confirm the folder uses the Default preview context, then test the icon, name, and status in both the first visible preview row and the affected later row. Also test keyboard activation with Enter or Space. If the failure depends on Preview Rows `2`, `3`, `4`, or `Unlimited`, leave that setting unchanged while exporting the support bundle.

The sanitized bundle retains a privacy-safe `uiTelemetry.dockerDiagnostics.previewContextBridge` summary across navigation to Settings. It records row-mode and numeric row-index buckets, eligible and bound bridge counts, post-layout handler-integrity results, dispatch attempts and outcomes, mouse or keyboard input, and icon/name/status/card trigger categories. It never records folder names, container names, IDs, selectors, URLs, or click coordinates.

### Native Rows Briefly Appear Before Folders

This is expected during initial Docker or VM bootstrap. FolderView Plus lets Unraid render its native rows first, then performs one uninterrupted folder conversion. The page should not remain half grouped or paint folder rows one at a time.
Expand Down Expand Up @@ -185,6 +191,8 @@ The v2 bundle also includes exact build/package identity, loaded plugin script/s

Docker support evidence includes recent session summaries, reload-source counts, the refresh-loop verdict, native busy-cycle recovery, and aggregate API identity mismatches. API mismatches record counts and first/last timestamps only. They never include container names or IDs, and they state the `native-structure-authoritative` policy and that an API mismatch did not request a host reload.

Docker preview-context evidence adds bounded bridge-binding, row-finalization, handler-integrity, and dispatch counters. Row modes distinguish `1`, `2`, `3`, `4`, and `Unlimited`; row positions are numeric buckets, and the most recent event contains only an outcome, bounded failure reason, trigger category, input method, row mode, row index, and timestamp.

To compare two systems without exposing their identities, export sanitized bundles from both and run:

```bash
Expand Down
5 changes: 5 additions & 0 deletions docs/releases/2026.08.24.01.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
- Fix: Restore Docker preview context menus when Preview Rows is set to 2, 3, 4, or Unlimited, including first-click activation from the icon, name, and status area.
- Compatibility: Route compact Default-context previews through the original Unraid Docker control instead of copying host IDs or inline handlers into preview cards.
- Accessibility: Support Enter and Space on the preview context control without nesting the existing WebUI, console, or log actions inside another interactive element.
- Fix: Apply the correct started, paused, or stopped color classes to compact preview status text and icons.
- Test: Add accessibility-enabled Chromium and Firefox coverage for multi-row and Unlimited previews, keyboard activation, quick-action isolation, duplicate-ID prevention, and status styling.
3 changes: 3 additions & 0 deletions docs/releases/2026.08.24.02.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
- Fix: Keep Docker container preview context menus clickable after multi-row layout when Preview Rows is set to 2, 3, 4, or Unlimited.
- Reliability: Preserve preview interactions across repeated Docker and VM row layout reconciliation instead of removing their event handlers while rebuilding rows.
- Test: Exercise mouse, keyboard, status-area, and quick-action behavior after repeated two-row and Unlimited preview layout in Chromium and Firefox.
3 changes: 3 additions & 0 deletions docs/releases/2026.08.24.03.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
- Diagnostics: Add privacy-safe Docker preview context-menu evidence to support bundles, including configured row mode, numeric preview-row position, binding integrity, trigger and input categories, dispatch outcomes, and bounded failure reasons.
- Privacy: Retain the diagnostic record briefly across page navigation without collecting folder or container names, identifiers, selectors, URLs, or pointer coordinates.
- Test: Verify multi-row and Unlimited preview context-menu diagnostics, persistence, failure detection, and privacy boundaries in Chromium and Firefox.
10 changes: 10 additions & 0 deletions docs/releases/2026.08.24.04.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
- Fix: Keep Docker preview context menus clickable in every visible row when Preview Rows is set to 2, 3, 4, or Unlimited, including after repeated layout reconciliation.
- Compatibility: Route Default-context preview activation through the original Unraid Docker control without copying host IDs or inline handlers, while preserving WebUI, logs, and console quick actions.
- Accessibility: Support first-click mouse activation from the preview icon, name, and status plus Enter and Space keyboard activation.
- Fix: Preserve the correct started, paused, and stopped styling on compact Docker preview status text and icons.
- Diagnostics: Add a short-lived, privacy-safe support-bundle summary of preview row mode and numeric row position, bridge binding and handler integrity, activation category, input method, dispatch outcomes, and bounded failure reasons.
- Privacy: Exclude folder and container identities, selectors, URLs, and pointer coordinates from preview context diagnostics.
- Maintenance: Add daily public-contract monitoring for Unraid stable and prerelease versions, PHP runtimes, Docker/VM/Dashboard and plugin-manager surfaces, Docker API/native-page signals, and Community Applications publication without live-Unraid credentials.
- Security: Add weekly OSV scanning of the generated SBOM, scheduled-workflow health coverage, and tool-scoped CodeQL alert enforcement so unrelated Scorecard findings do not fail CodeQL analysis.
- Compatibility: Refresh the reviewed Unraid/API baseline while retaining native-Docker safe mode and human approval for every upstream baseline change.
- Test: Cover multi-row and Unlimited preview interaction, repeated finalization, handler-loss detection, persistence, accessibility, status styling, and privacy boundaries in Chromium and Firefox.
4 changes: 2 additions & 2 deletions docs/sbom.cdx.json
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
{
"bomFormat": "CycloneDX",
"specVersion": "1.5",
"serialNumber": "urn:uuid:fc08839a-71b1-8d83-9a91-89ef86f15baa",
"serialNumber": "urn:uuid:8d6ef646-c87b-8601-8d30-57908769da9d",
"version": 1,
"metadata": {
"component": {
"type": "application",
"name": "FolderView Plus",
"version": "2026.08.20.02",
"version": "2026.08.24.04",
"properties": [
{
"name": "folderview-plus:runtime-dependencies",
Expand Down
2 changes: 1 addition & 1 deletion docs/security/csp-readiness.json
Original file line number Diff line number Diff line change
Expand Up @@ -102,7 +102,7 @@
},
{
"path": "src/folderview.plus/usr/local/emhttp/plugins/folderview.plus/scripts/docker.js",
"line": 3468,
"line": 3395,
"sink": ".innerHTML =",
"risk": "high",
"dataClass": "persisted-or-runtime-data",
Expand Down
43 changes: 34 additions & 9 deletions folderview.plus.plg
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,9 @@
<!ENTITY launch "Settings/FolderViewPlus">
<!ENTITY plugdir "/usr/local/emhttp/plugins/&name;">
<!ENTITY pluginURL "https://raw.githubusercontent.com/&github;/main/folderview.plus.plg">
<!ENTITY version "2026.08.20.02">
<!ENTITY md5 "c58c8bb851e14cbdc2764b50cfbb322b">
<!ENTITY sha256 "f0b2143536d393b8c641b9ac154795230aae5a3eb3ff319facbfc13bdb871b46">
<!ENTITY version "2026.08.24.04">
<!ENTITY md5 "40bc8d9fb97c06c9b5025cef2660e157">
<!ENTITY sha256 "9f4eca819eddf4f5a501137f13b743a259a52fff7a35d6e74278b797641ff259">
<!ENTITY iconPackVersion "1.0.0">
<!ENTITY iconPackMd5 "a149c36b41339949bb5c1eecad550704">
<!ENTITY iconPackSha256 "992f6c3544a8a3c1db80b861472fdd8b3d499f20f81796ed71405a10beb750bd">
Expand All @@ -18,12 +18,37 @@
<PLUGIN name="&name;" author="&author;" version="&version;" launch="&launch;" pluginURL="&pluginURL;" icon="folder-icon.png" support="https://forums.unraid.net/topic/197631-plugin-folderview-plus/" min="7.0.0">
<CHANGES>

###2026.08.20.02
- Fix: Allow protected FolderView Plus actions through a correctly configured TLS-terminating reverse proxy by validating the external host, protocol, and port as one coherent authority.
- Security: Keep strict POST, request-marker, install-token, one-time nonce, transaction, same-origin, and rate-limit controls while rejecting partial, repeated, malformed, spoofed-host, or conflicting forwarded headers.
- Diagnostics: Add privacy-safe request-security reason codes to diagnostics and support bundles without recording hostnames, addresses, ports, or raw forwarded-header values.
- Docs: Document supported SWAG forwarding, recovery from `Blocked by request guard`, and unsafe proxy workarounds to avoid.
- Test: Cover direct HTTP/HTTPS, standard and nonstandard proxy ports, IPv6, malformed or spoofed forwarded values, and Origin/Referer disagreements.
###2026.08.24.04
- Fix: Keep Docker preview context menus clickable in every visible row when Preview Rows is set to 2, 3, 4, or Unlimited, including after repeated layout reconciliation.
- Compatibility: Route Default-context preview activation through the original Unraid Docker control without copying host IDs or inline handlers, while preserving WebUI, logs, and console quick actions.
- Accessibility: Support first-click mouse activation from the preview icon, name, and status plus Enter and Space keyboard activation.
- Fix: Preserve the correct started, paused, and stopped styling on compact Docker preview status text and icons.
- Diagnostics: Add a short-lived, privacy-safe support-bundle summary of preview row mode and numeric row position, bridge binding and handler integrity, activation category, input method, dispatch outcomes, and bounded failure reasons.
- Privacy: Exclude folder and container identities, selectors, URLs, and pointer coordinates from preview context diagnostics.
- Maintenance: Add daily public-contract monitoring for Unraid stable and prerelease versions, PHP runtimes, Docker/VM/Dashboard and plugin-manager surfaces, Docker API/native-page signals, and Community Applications publication without live-Unraid credentials.
- Security: Add weekly OSV scanning of the generated SBOM, scheduled-workflow health coverage, and tool-scoped CodeQL alert enforcement so unrelated Scorecard findings do not fail CodeQL analysis.
- Compatibility: Refresh the reviewed Unraid/API baseline while retaining native-Docker safe mode and human approval for every upstream baseline change.
- Test: Cover multi-row and Unlimited preview interaction, repeated finalization, handler-loss detection, persistence, accessibility, status styling, and privacy boundaries in Chromium and Firefox.


###2026.08.24.03
- Diagnostics: Add privacy-safe Docker preview context-menu evidence to support bundles, including configured row mode, numeric preview-row position, binding integrity, trigger and input categories, dispatch outcomes, and bounded failure reasons.
- Privacy: Retain the diagnostic record briefly across page navigation without collecting folder or container names, identifiers, selectors, URLs, or pointer coordinates.
- Test: Verify multi-row and Unlimited preview context-menu diagnostics, persistence, failure detection, and privacy boundaries in Chromium and Firefox.


###2026.08.24.02
- Fix: Keep Docker container preview context menus clickable after multi-row layout when Preview Rows is set to 2, 3, 4, or Unlimited.
- Reliability: Preserve preview interactions across repeated Docker and VM row layout reconciliation instead of removing their event handlers while rebuilding rows.
- Test: Exercise mouse, keyboard, status-area, and quick-action behavior after repeated two-row and Unlimited preview layout in Chromium and Firefox.


###2026.08.24.01
- Fix: Restore Docker preview context menus when Preview Rows is set to 2, 3, 4, or Unlimited, including first-click activation from the icon, name, and status area.
- Compatibility: Route compact Default-context previews through the original Unraid Docker control instead of copying host IDs or inline handlers into preview cards.
- Accessibility: Support Enter and Space on the preview context control without nesting the existing WebUI, console, or log actions inside another interactive element.
- Fix: Apply the correct started, paused, or stopped color classes to compact preview status text and icons.
- Test: Add accessibility-enabled Chromium and Firefox coverage for multi-row and Unlimited previews, keyboard activation, quick-action isolation, duplicate-ID prevention, and status styling.


###2026.08.20.01
Expand Down
2 changes: 1 addition & 1 deletion folderview.plus.xml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
<Description>
FolderView Plus organizes Docker, VM, and Dashboard views into folders in Unraid, with starter setup tools, rules, bulk assignment, recovery, templates, and diagnostics.
</Description>
<Date>2026-08-20</Date>
<Date>2026-08-24</Date>
<MinVer>7.0.0</MinVer>
<ExtraSearchTerms>folder view docker vm dashboard organization groups sorting import export backup recovery rules templates diagnostics</ExtraSearchTerms>
<Support>https://forums.unraid.net/topic/197631-plugin-folderview-plus/</Support>
Expand Down
5 changes: 3 additions & 2 deletions scripts/codeql_alert_guard.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,9 @@ import fs from 'node:fs';
import path from 'node:path';
import { pathToFileURL } from 'node:url';

export const actionableAlertsForCommit = (alerts, commitSha) => (Array.isArray(alerts) ? alerts : [])
export const actionableAlertsForCommit = (alerts, commitSha, toolName = 'CodeQL') => (Array.isArray(alerts) ? alerts : [])
.filter((alert) => String(alert?.state || '') === 'open')
.filter((alert) => !toolName || String(alert?.tool?.name || '') === toolName)
.filter((alert) => !commitSha || String(alert?.most_recent_instance?.commit_sha || '') === commitSha);

export const analysisAvailableForCommit = (analyses, commitSha, ref = '') => (Array.isArray(analyses) ? analyses : [])
Expand Down Expand Up @@ -32,7 +33,7 @@ const parseArgs = (argv) => {
const fetchOpenAlerts = async ({ repository, token, ref }) => {
const alerts = [];
for (let page = 1; page <= 10; page += 1) {
const query = new URLSearchParams({ state: 'open', per_page: '100', page: String(page) });
const query = new URLSearchParams({ state: 'open', tool_name: 'CodeQL', per_page: '100', page: String(page) });
if (ref) query.set('ref', ref);
const endpoint = `https://api.github.com/repos/${repository}/code-scanning/alerts?${query}`;
const response = await fetch(endpoint, {
Expand Down
2 changes: 1 addition & 1 deletion scripts/csp_readiness_guard.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ const patterns = {
const lineNumberAt = (source, index) => source.slice(0, index).split('\n').length;
const explicitHtmlSinkReviews = new Map([
['src/folderview.plus/usr/local/emhttp/plugins/folderview.plus/scripts/docker.js:1294', 'Port endpoints and protocols are escaped by buildDockerPortEndpoint before the markup builder returns.'],
['src/folderview.plus/usr/local/emhttp/plugins/folderview.plus/scripts/docker.js:3468', 'The loading overlay contains plugin-authored static markup only.'],
['src/folderview.plus/usr/local/emhttp/plugins/folderview.plus/scripts/docker.js:3395', 'The loading overlay contains plugin-authored static markup only.'],
['src/folderview.plus/usr/local/emhttp/plugins/folderview.plus/scripts/docker.runtime.action-bar.js:274', 'Action, label, icon, title, and menu values are escaped by the local markup builders.'],
['src/folderview.plus/usr/local/emhttp/plugins/folderview.plus/scripts/docker.runtime.command-view.js:504', 'Names, identifiers, states, actions, and error text are escaped; counts are normalized numbers and image sources are sanitized.'],
['src/folderview.plus/usr/local/emhttp/plugins/folderview.plus/scripts/runtime.shared-controls.js:221', 'The stable-toggle controller accepts only plugin-owned markup builders and validates the expected input after mounting.'],
Expand Down
11 changes: 6 additions & 5 deletions scripts/test_runner_contracts.json
Original file line number Diff line number Diff line change
Expand Up @@ -48,12 +48,13 @@
"supportFiles": [
"scripts/fixture_browser_tests.mjs",
"scripts/lib/fixture-browser-server.mjs",
"scripts/lib/fixture-browser-runner.mjs"
"scripts/lib/fixture-browser-runner.mjs",
"tests/browser/helpers/docker-preview-context.mjs"
],
"testCount": 42,
"assertionCount": 534,
"pageEvaluateCount": 105,
"orderedTitleSha256": "ee3028477ae78db47c8f3487c5c43a5779b5b75e80a0f05e1f2c498a53116b44"
"testCount": 43,
"assertionCount": 557,
"pageEvaluateCount": 109,
"orderedTitleSha256": "491369c2cae7533952fe8634ccef5185f1a713d57d2b440273973accb8d212aa"
}
}
}
Loading