Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -313,8 +313,7 @@ class SubmissionsComponent extends React.Component {

isMM() {
const { challenge } = this.props;
const trackName = getTrackName(challenge);
return (trackName || '').toLowerCase() === 'data science' || checkIsMM(challenge);
return checkIsMM(challenge);
}

/**
Expand Down
7 changes: 6 additions & 1 deletion src/shared/containers/challenge-detail/index.jsx
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ import { getService } from 'services/contentful';
import { getSubmissionArtifacts as getSubmissionArtifactsService } from 'services/submissions';
import getReviewSummationsService from 'services/reviewSummations';
import { buildMmSubmissionData, buildStatisticsData } from 'utils/mm-review-summations';
import { appendUtmParamsToUrl } from 'utils/utm';
// import {
// getDisplayRecommendedChallenges,
// getRecommendedTags,
Expand Down Expand Up @@ -349,7 +350,11 @@ class ChallengeDetailPageContainer extends React.Component {
} = this.props;
if (!auth.tokenV3) {
const utmSource = communityId || 'community-app-main';
window.location.href = `${config.URL.AUTH}/member?retUrl=${encodeURIComponent(`${window.location.origin}${window.location.pathname}`)}&utm_source=${utmSource}&regSource=challenges`;
window.location.href = appendUtmParamsToUrl(

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[❗❗ security]
The appendUtmParamsToUrl function is used to construct a URL with query parameters. Ensure that this function properly encodes all URL components to prevent potential security issues such as URL injection.

`${config.URL.AUTH}/member?retUrl=${encodeURIComponent(`${window.location.origin}${window.location.pathname}`)}&regSource=challenges`, {
utm_source: utmSource,
},
);
} else {
// Show security reminder to all registrants
this.setState({
Expand Down
69 changes: 69 additions & 0 deletions src/shared/utils/utm.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
// UTM cookie configuration constants
const TC_UTM_COOKIE_NAME = 'tc_utm';

/**
* Retrieves and parses the tc_utm cookie
* @returns Parsed UTM parameters or null if cookie doesn't exist
*/
export function getUtmCookie() {
try {
const cookies = document.cookie.split(';');
const cookieStr = cookies.find(cookie => cookie.trim().startsWith(`${TC_UTM_COOKIE_NAME}=`));

if (!cookieStr) {
return null;
}

// handle values that might contain '='
const cookieValue = decodeURIComponent(cookieStr.split('=').slice(1).join('='));
return JSON.parse(cookieValue);

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[⚠️ maintainability]
Consider logging the error or handling it in a way that provides more context. Swallowing errors silently can make debugging difficult.

} catch (error) {
return null;
}
}

/**
* Appends UTM parameters from the tc_utm cookie to a given URL
* Only appends parameters that exist in the cookie
* @param url - The base URL to append parameters to
* @returns URL with UTM parameters appended, or original URL if no cookie exists
*/
export function appendUtmParamsToUrl(url, defaultParams = {}) {

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[⚠️ correctness]
The function appendUtmParamsToUrl should validate the url parameter more robustly. Currently, it only checks for falsy values, but malformed URLs could still cause issues.

if (!url) {
return url;
}

const utmParams = getUtmCookie();

// If there are no cookie params and no defaults, nothing to do
if (
(!utmParams || Object.keys(utmParams).length === 0)
&& (!defaultParams || Object.keys(defaultParams).length === 0)
) {
return url;
}

try {
const urlObj = new URL(url, window.location.origin);
const paramNames = ['utm_source', 'utm_medium', 'utm_campaign'];

paramNames.forEach((param) => {
const cookieVal = utmParams && utmParams[param];
const defaultVal = defaultParams && defaultParams[param];

// Cookie takes precedence and will overwrite existing query param
if (cookieVal) {
urlObj.searchParams.set(param, cookieVal);
} else if (defaultVal) {
// Only apply default if the URL does not already have the param
if (!urlObj.searchParams.has(param)) {
urlObj.searchParams.set(param, defaultVal);
}
}
});

return urlObj.toString();
} catch (error) {
return url;

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[⚠️ maintainability]
Consider logging the error or handling it in a way that provides more context. Swallowing errors silently can make debugging difficult.

}
}
Loading