Close the gaps an audit of courses, tasks, files and grades turned up

Every area — courses, rooms, boards, topics, tasks, files, quizzes, teams,
groups, submissions, grades — was checked for data the instance has and the
tools did not show.

Grades and feedback. A teacher's /homework page is a different page from a
student's: grade and comment live in the grading form, one block per
submission, so a teacher account reported every graded submission as having
neither. parseTeacherGrading reads the form, and list_submissions can now
include the written feedback and who handed the work in.

Names. /api/v1 is partly served: courses, users and classes survive in the
deployment's ingress table, and users/{id} is the only route from an id to a
name. Submitters, file creators and course teachers resolve through it, and
degrade to "not visible to this account" where a student may not read them.

Courses, rooms and classes. get_course adds the description, teachers,
member count and weekly timetable from /api/v1/courses. list_classes is new.
get_room reports what the account may do — allowedOperations is an object of
booleans, not the list it was typed as — and applicants and invitation links
where it may manage them.

Board and topic content. Link descriptions, image alt text, drawing and
video-conference titles, the ids behind external tools and H5P content (the
only thing resembling a quiz), and what a deleted element used to be. Topic
Etherpad pads are read like board pads, and htmlToText keeps table columns
apart and drops template indentation.

Files. A scan with no text layer falls back to the preview endpoint, whose
width and outputFormat are undocumented enums, so Claude gets a picture of
the page; list_files reports counts and sizes. Teams stay documented as
unreadable at any API version; their files come later.

What the crawl missed. Tasks attached to topics (18 of 60 on the live
account), each course's own file area, and — behind INDEX_PERSONAL_FILES —
personal files and submissions with their grade comments, so search and
what_changed cover grading. A submission hit points at get_task.

The local instance's preview profile gets an ImageMagick policy that allows
the coders its 7.1.2 build needs; the image's own denies them all.

110 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
MechaCat02
2026-09-16 20:19:16 +02:00
parent a3b17a680c
commit 5ae2210459
25 changed files with 1462 additions and 89 deletions

View File

@@ -23,7 +23,35 @@ describe('htmlToText', () => {
});
it('decodes entities, ampersand last so &amp;lt; stays literal', () => {
assert.equal(htmlToText('<p>a &amp;lt; b &lt; c &nbsp;d</p>'), 'a &lt; b < c d');
assert.equal(htmlToText('<p>a &amp;lt; b &lt; c</p>'), 'a &lt; b < c');
});
it('collapses runs of spaces, including the non-breaking ones', () => {
// Schulcloud content is full of &nbsp; used as padding; keeping it would
// reproduce that padding in the plain-text output for no benefit.
assert.equal(htmlToText('<p>a &nbsp;b</p>'), 'a b');
});
it('strips the source template\'s indentation from every line', () => {
// Paragraphs still separate with a blank line; what goes is the leading
// run of spaces the server-side template left on each line.
const html = '<p>\n first line<br>\n second line</p>';
assert.equal(htmlToText(html), 'first line\nsecond line');
});
it('separates table cells so columns do not run together', () => {
const html = '<table><tr><td>Bestandteil</td><td>Funktion</td></tr>' +
'<tr><td>Gehirn</td><td>steuert</td></tr></table>';
assert.equal(htmlToText(html), 'Bestandteil | Funktion\nGehirn | steuert');
});
it('keeps a cell that wraps its text in a paragraph on one row', () => {
const html = '<table><tr><td><p>Bestandteil</p></td><td>Gehirn</td></tr></table>';
assert.equal(htmlToText(html), 'Bestandteil | Gehirn');
});
it('separates paragraphs with a blank line', () => {
assert.equal(htmlToText('<p>first</p>\n <p>second</p>'), 'first\n\nsecond');
});
it('returns an empty string for missing input', () => {