If teams fail to load due to some bug, the user may lose their teams
permanently if they save their teams. In avoid to avoid a catastrophe,
we now decline to load the client if teams fail to load.
This should never happen unless a bug is introduced that breaks team
loading.
Because highlight matching was done with a global regular expression,
subsequent calls to `test` started searching after the end of the
previous match, meaning that highlight matches were often misses.
There is no reason for highlight matching to be done with a global
regular expression, so this commit fixes the issue by deleting
option 'g' from the regular expression.
In addition, I have renamed `lobby.regex` to `lobby.highlightRegExp`.
The `serverlist` action returns a list of registered servers. It accepts
cross-domain requests, which is safe since it merely returns publicly
available information.
- mute/ban/kick buttons are now only shown if the user can use the
corresponding command. This determination is based on the permissions
in use on the main server (and hardcoded as such) because the server
does not currently send the client any information about permissions.
In particular, regular users will no longer see the buttons when
viewing their own profile.
- there is now a blank line between a user's IP address and the auth
buttons.
Previously, the `yourMove` (etc.) notifications on the first turn of
a battle for player 1 did not include the opponent's name, because
the opponent's side of the battle was not yet initialised. This
commit fixes the issue by delaying the notification until the
opponent's side has initialised.
This commit makes various changes to prevent servers from injecting
arbitrary JavaScript into the client. This prevents a variety of
possible exploits. The main changes in the client are as follows:
- Raw HTML from the server is now sanitised using caja to prevent
excution of JavaScript. See
https://code.google.com/p/google-caja/wiki/JsHtmlSanitizer
for details.
- The client now has a variety of CSS classes for possible chat
command messages that can be sent from the server, rather than the
server injecting arbitrary CSS `style` attributes into the client.