Files
sim/packages/utils
Waleed 1242301bd3 improvement(emcn): share one emails/domains chip input across share and deploy modals (#6226)
* improvement(emcn): share one emails/domains chip input across share and deploy modals

Extracts the emails chip lifecycle out of ChipModalField type='emails' into a
standalone ChipEmailsInput, and points both the file share modal and the deploy
modal's chat tab at it instead of their hand-rolled TagInput wiring.

- add ChipEmailsInput (dedupe, normalize, format gate, paste, per-chip errors)
  with an allowDomains opt-in for bare @domain.tld entries
- share modal and deploy modal chat tab now use it; drop both hand-rolled
  add/remove/validate implementations and the dead emailError state
- move the shared allowlist policy into validateAllowlistEntry
- drop the "Add specific emails or whole domains" hint text
- give OutputSelect a size prop; the deploy modal chat tab uses the 30px chip
  trigger so it lines up with the Title field above it
- drop overflow-y-auto from the chat deploy form, which was promoting overflow-x
  to auto and rendering a stray horizontal scrollbar

* improvement(utils): one email syntax gate, drop the backtracking placeholder regex

Audit follow-ups on the emails chip input.

- move EMAIL_SYNTAX_REGEX and the new @domain pattern into @sim/utils/string as
  isValidEmailSyntax, so emcn and lib/messaging/email/validation.ts stop keeping
  byte-identical copies of the RFC 5322 regex
- allow single-label domains (@intranet) again — requiring a dot rejected
  entries the old startsWith('@') check accepted, which self-hosted
  deployments use. A lone @ and malformed labels stay rejected
- replace derivePlaceholderWithTags' /^Enter\s+(.+?)s?$/i with string ops;
  CodeQL flagged it as polynomial backtracking (js/redos). Verified identical
  output across the placeholder shapes in use
- forward the emails control's props explicitly instead of underscore-discard
  destructuring, matching ChipModalFileControl in the same file

* test(email): pin the allowlist entry rules

Covers isValidEmailSyntax's allowDomains branch (single-label domains stay
valid, malformed bare domains that the old startsWith('@') check accepted do
not), the 254-character cap, the DNS label limit, and validateAllowlistEntry
waiving address-level policy for bare domains. Verified both new rules fail
when the behavior is reverted.
2026-08-03 14:40:41 -07:00
..