Repository navigation
Security
decode_webr_link()anddecode_shinylive_link()now refuse file names that
escapeoutput_dir, such as../../.Rprofile. Names holding a subdirectory,
likeR/helpers.R, are unaffected.
Encoding
- webR links now use msgpack rather than JSON, so a link ends in
mzwhere it
used to end injz. This is the same form the webR share button writes. A
one-line snippet comes out about 11% shorter, and links you have already
shared keep working, since both forms still decode.
Bug fixes
-
webr_repl_link()now handles a braced expression whose code cannot be read
back, which failed in an unsaved buffer in Positron, when the file was shorter
than the expression, and when the block was empty. Where the code can be read
its comments survive, and where it cannot the code is rebuilt without them. -
webr_repl_link()andwebr_repl_project()now refuse input that cannot
become a script, rather than building a link that will not open. That covers
several file paths given to a single script, a file that is not valid UTF-8 or
holds an embedded NUL,NA, and empty input. -
webr_repl_project()now warns whenautorun_filesnames a file webR cannot
run on opening, andprint()marks the files that really do run. -
decode_webr_link()writes a binary file back exactly as it was, rather than
as text listing its byte values. -
decode_webr_link()andpreview_webr_link()now read links built against a
webR site you host yourself, and report a malformed link when the ending of
the link does not describe the code inside it. -
shinylive_directory()now includes the.cssand.jsfiles an app needs,
leaves out only files that cannot be read as text, and checksapp_file. -
link.only = TRUEno longer leaves an empty code block above the link.
Error messages
-
webr_repl_project()andshinylive_project()now explain a missinginput
instead of reporting the name of an internal variable. -
Errors about an invalid argument now name the value at fault.
NAgiven to
version,panels, ormodefailed withmissing value where TRUE/FALSE needed, an invalidpanelsdid not say which component was wrong, andNULL
left a blankYou provided:line. -
preview_webr_link()andpreview_shinylive_link()now keep the explanation
from the underlying error rather than replacing it.
Documentation
- Every help page now lists what a returned object holds, one entry at a time,
rather than describing it only as an object with metadata.