Skip to content

feat: support complete list items in itemSource - #1354

Open
briantstephan wants to merge 3 commits into
mainfrom
photo-gallery-v2-port
Open

briantstephan wants to merge 3 commits into
mainfrom
photo-gallery-v2-port

Conversation

@briantstephan

@briantstephan briantstephan commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Add complete-item selection and $item resolution through existing itemSource options. Clear old mappings when the source changes and automatically map complete items when exactly one mapping matches.

This represents a subset of the changes from #1339, and is necessary to get the Photo Gallery itemSource changes working in standard-library since that uses a 2.x release.

Tested alongside the aforementioned Photo Gallery changes in standard-library's local-editor and confirmed that everything worked as expected.

Comment thread pnpm-lock.yaml Outdated
}
engines: { node: ">= 0.4" }

esbuild@0.21.5:

@semgrep-code-yext semgrep-code-yext Bot Oct 6, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Medium severity issue identified in your code:

Risk: Affected versions of esbuild are vulnerable to Origin Validation Error. esbuild's development server responds to every request, including Server-Sent Events connections, with Access-Control-Allow-Origin: *. Any website a developer visits can therefore make cross-origin requests to the local dev server and read the responses, leaking bundled source code, source maps, and served file paths. Starting the dev server via serve() reaches the vulnerable code path.

Manual Review Advice: A vulnerability from this advisory is reachable if you run esbuild with the --serve flag to start the development server

Fix: Upgrade this library to at least version 0.25.0 at visual-editor/pnpm-lock.yaml:5131.

Reference(s): GHSA-67mh-4wv8-2f99

🎈 Fixed in commit 636a599 🎈

Comment thread pnpm-lock.yaml Outdated
@@ -6034,10 +6477,10 @@ packages:
}
engines: { node: ^18.17.0 || >=20.5.0 }

mapbox-gl@3.30.0:
mapbox-gl@3.32.0:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Legal Risk

mapbox-gl 3.32.0 was released under the non-standard license, a license that
is currently prohibited by your organization. Merging is blocked until this is resolved.

Recommendation

Reach out to your security team or Semgrep admin to address this issue. In special cases, exceptions may be made for dependencies with violating licenses, however, the general recommendation is to avoid using a dependency under such a license.

@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 46 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 69bd5799-96e1-4c46-a395-a69432a5673b
📥 Commits

Reviewing files that changed from the base of the PR and between f5153f9 and 636a599.

📒 Files selected for processing (14)
  • packages/visual-editor/src/components/migrations/0083_photo_gallery_item_source.ts
  • packages/visual-editor/src/components/migrations/migrationRegistry.ts
  • packages/visual-editor/src/editor/yextEntityFieldUtils.test.ts
  • packages/visual-editor/src/editor/yextEntityFieldUtils.ts
  • packages/visual-editor/src/fields/EntityFieldSelectorField.test.tsx
  • packages/visual-editor/src/fields/EntityFieldSelectorField.tsx
  • packages/visual-editor/src/fields/YextAutoField.tsx
  • packages/visual-editor/src/fields/fields.test.tsx
  • packages/visual-editor/src/fields/fields.ts
  • packages/visual-editor/src/internal/components/InternalLayoutEditor.tsx
  • packages/visual-editor/src/utils/cardSlots/mappedSource.ts
  • packages/visual-editor/src/utils/itemSource/createItemSource.test.ts
  • packages/visual-editor/src/utils/itemSource/itemSourceResolution.ts
  • packages/visual-editor/src/utils/itemSource/itemSourceTypes.ts
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@jwartofsky-yext jwartofsky-yext left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@@ -0,0 +1,68 @@
import { type Migration } from "../../utils/migrate.ts";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I guess the migration is a little weird since the photo gallery is not included in this branch, but I think we should keep the builtIn migration registry in sync until we stop supporting the OOTB artifact 👍

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants